The Experts below are selected from a list of 4164 Experts worldwide ranked by ideXlab platform

Carl Hewitt - One of the best experts on this subject based on the ideXlab platform.

  • Islets Protect Sensitive IoT Information: Verifiably Ending Use of Sensitive IoT Information for Mass Surveillance Fosters (International) Commerce
    2016
    Co-Authors: Carl Hewitt
    Abstract:

    Islets is a system for citizens to coordinate with IoT devices and other citizens while protecting their Sensitive Information and fostering (international) commerce. IoT poses extreme security and privacy challenges for Sensitive personal Information, including psychological, sexual, social, financial, legal, and medical. Enormous amounts of Sensitive Information that can be used against citizens is being Stored in datacenters controlled by foreign-domiciled companies and extensively sold on multiple markets by data brokers. Consumer health and medical IoT involve the most Sensitive of Information that can be used against citizens. For example, pacemakers and insulin pumps are becoming ever more common. Mixed-reality glasses are likely to become as common as cell phones because they offer heads-up, hands-free, transparent operation. Further out, DARPA is developing an implantable neural interface able to provide unprecedented signal resolution and data-transfer bandwidth between the human brain and the digital world. Many workers and military personnel may someday not be competitive if they lack a brain prosthetic.IoT will soon be in almost all manufactured devices thereby threatening the economic survival of tans-national manufacturers as well as Internet companies because of their current Internet business model of storing the most Sensitive of personal Information in their datacenters from IoT devices. Cyberspace Administration of China, European Court of Justice and other national governments have announced their intention to verifiably end mass surveillance of their citizens by foreign governments using datacenters of foreign-domiciled companies because Information Stored in the datacenters of foreign domiciled corporations will inevitably at some future time become accessible to the government of the country in which the company is domiciled. Consequently, companies that Store Sensitive Information in their datacenters must be domestically incorporated to be able to verify that foreign governments do not have bulk access to the Information. Islets are a means for trans-national companies (including both IoT manufacturers and Internet service providers) to escape this trap by storing Sensitive Information of users' IoT devices in Islets and storing only non-Sensitive Information in their datacenters.Sensitive Information can be Stored locally in Islets on users' own equipment encrypted with user keys and can be backed up elsewhere encrypted using users' keys. Furthermore, users can share Islet Information that they select with other parties -- encrypted with the public keys of other parties so that it be read only by the intended party.Islets can improve Information coordination over current systems that cannot coordinate among numerous competing services (such as Facebook and Google) and numerous fiercely competing merchants (such as Amazon, Home Depot, and Walmart using multiple IoT devices from competing manufacturers (such as LG, Nest, Samsung, and Whirlpool). Islet-facilitated coordination can include integration of commerce (such as home, retail, food, travel, and auto), wellness (such as recreation, biometrics, nutrition, exercise, spirituality, medical, and learning), finance (such as banking, investments, and taxes), IoT (such as food management, security, energy management, infotainment, transportation, and communication), social (such as schedule, friends, and family), and work (such as contacts, schedule, and colleagues). Islets can provide lower communications cost than current systems because it is not necessary for users and their IoT devices to always communicate with datacenters.[6][14][22] Islets also can provide faster response and more robustness because local operations can be faster and more reliable than being required to always use communication links with potentially-overloaded remote datacenters.Islets need a convenient, effective, high-profitable business model, which must be more effective and efficient than the current datacenters system based on consumer surveillance to improve advertising targeting. Instead, an Islet running on a consumer's equipment can seek out and help evaluate appropriate offers from commerce agents. Such commerce agents can earn commissions and fees from merchants when the referral is exercised. Consequently, merchants will no longer be burdened by having to pay for grossly inefficient advertising that annoys potential customers. Instead, businesses can provide their Information to commerce agents that aggregate and package it for users' Islets to be used in evaluating offers that can be filtered and ranked according to citizen needs and preferences. All of the convenience currently available through individual company access points must be improved in effectiveness and response time including scalable search and operations coordinate use of commercial datacenters (such as Amazon, Facebook, Google, and LinkedIn) as well as other Islets.Outside of citizens' Islets Information protected against self-incrimination, governments (through subpoena) will be able to obtain sufficient Information for law enforcement including financial transactions, physical movements outside the home, and cell tower tracking Information.

  • Islets Protect Sensitive IoT Information: Verifiably Ending Use of Sensitive IoT Information for Mass Surveillance Can Foster (International) Commerce and Law Enforcement
    2016
    Co-Authors: Carl Hewitt
    Abstract:

    Islets is a system for users to coordinate with IoT devices and other users. They serve two important functions 1) protect Sensitive citizen Information and 2) foster international commerce.IoT poses extreme challenges for Sensitive personal Information, including psychological, sexual, social, financial, legal, and medical. Enormous amounts of Sensitive Information is being Stored in datacenters controlled by foreign-domiciled companies and extensively sold on the market by data brokers.Consumer health and medical IoT are becoming ever more intimate. Many people have pacemakers and even more have insulin pumps. Soon mixed reality glasses are likely to become as common as cell phones because they offer heads-up, hands-free, transparent operation. DARPA is developing an implantable neural interface able to provide unprecedented signal resolution and data-transfer bandwidth between the human brain and the digital world. Before long, many workers and military personnel may not be competitive unless they have brain implants.IoT will soon be in almost all manufactured devices thereby threatening the economic survival of tans-national manufacturers as well as Internet companies because of their current Internet business model of storing Information in their datacenters. EU, China, and other nations are absolutely determined to verifiably end mass surveillance of the their citizens by foreign intelligence agencies using datacenters of foreign-domiciled companies. However, Information Stored in the datacenters of foreign domiciled corporations will inevitably become accessible to the government in which the company is domiciled. Consequently corporations that Store Sensitive Information in their datacenters must be domestically incorporated to ensure that foreign intelligence agencies do not have bulk access to the Information. Islets provide a means for trans-national companies to escape this trap by storing Sensitive Information of users IoT in Islets and only storing non-Sensitive Information in their datacenters.

  • Citadels: Increased Robustness and Better Information Integration Than Datacenters of Competing Companies
    2016
    Co-Authors: Carl Hewitt
    Abstract:

    Islets is a system for citizens to coordinate with IoT devices and other citizens while protecting their Sensitive Information and fostering (international) commerce. IoT poses extreme security and privacy challenges for Sensitive personal Information, including psychological, sexual, social, financial, legal, and medical. Enormous amounts of Sensitive Information that can be used against citizens is being Stored in datacenters controlled by foreign-domiciled companies and extensively sold on multiple markets by data brokers. Consumer health and medical IoT involve the most Sensitive of Information that can be used against citizens. For example, pacemakers and insulin pumps are becoming ever more common. Mixed-reality glasses are likely to become as common as cell phones because they offer heads-up, hands-free, transparent operation. Further out, DARPA is developing an implantable neural interface able to provide unprecedented signal resolution and data-transfer bandwidth between the human brain and the digital world. Many workers and military personnel may someday not be competitive if they lack a brain prosthetic.IoT will soon be in almost all manufactured devices thereby threatening the economic survival of tans-national manufacturers as well as Internet companies because of their current Internet business model of storing the most Sensitive of personal Information in their datacenters from IoT devices. Cyberspace Administration of China, European Court of Justice and other national governments have announced their intention to verifiably end mass surveillance of their citizens by foreign governments using datacenters of foreign-domiciled companies because Information Stored in the datacenters of foreign domiciled corporations will inevitably at some future time become accessible to the government of the country in which the company is domiciled. Consequently, companies that Store Sensitive Information in their datacenters must be domestically incorporated to be able to verify that foreign governments do not have bulk access to the Information. Islets are a means for trans-national companies (including both IoT manufacturers and Internet service providers) to escape this trap by storing Sensitive Information of users' IoT devices in Islets and storing only non-Sensitive Information in their datacenters.Sensitive Information can be Stored locally in Islets on users' own equipment encrypted with user keys and can be backed up elsewhere encrypted using users' keys. Furthermore, users can share Islet Information that they select with other parties -- encrypted with the public keys of other parties so that it be read only by the intended party.Islets can improve Information coordination over current systems that cannot coordinate among numerous competing services (such as Facebook and Google) and numerous fiercely competing merchants (such as Amazon, Home Depot, and Walmart using multiple IoT devices from competing manufacturers (such as LG, Nest, Samsung, and Whirlpool). Islet-facilitated coordination can include integration of commerce (such as home, retail, food, travel, and auto), wellness (such as recreation, biometrics, nutrition, exercise, spirituality, medical, and learning), finance (such as banking, investments, and taxes), IoT (such as food management, security, energy management, infotainment, transportation, and communication), social (such as schedule, friends, and family), and work (such as contacts, schedule, and colleagues). Islets can provide lower communications cost than current systems because it is not necessary for users and their IoT devices to always communicate with datacenters.[6][14][22] Islets also can provide faster response and more robustness because local operations can be faster and more reliable than being required to always use communication links with potentially-overloaded remote datacenters.Islets need a convenient, effective, high-profitable business model, which must be more effective and efficient than the current datacenters system based on consumer surveillance to improve advertising targeting. Instead, an Islet running on a consumer's equipment can seek out and help evaluate appropriate offers from commerce agents. Such commerce agents can earn commissions and fees from merchants when the referral is exercised. Consequently, merchants will no longer be burdened by having to pay for grossly inefficient advertising that annoys potential customers. Instead, businesses can provide their Information to commerce agents that aggregate and package it for users' Islets to be used in evaluating offers that can be filtered and ranked according to citizen needs and preferences. All of the convenience currently available through individual company access points must be improved in effectiveness and response time including scalable search and operations coordinate use of commercial datacenters (such as Amazon, Facebook, Google, and LinkedIn) as well as other Islets.Outside of citizens' Islets Information protected against self-incrimination, governments (through subpoena) will be able to obtain sufficient Information for law enforcement including financial transactions, physical movements outside the home, and cell tower tracking Information.

Aravind Prakash - One of the best experts on this subject based on the ideXlab platform.

  • Simplex: Repurposing Intel Memory Protection Extensions for Information Hiding.
    arXiv: Cryptography and Security, 2020
    Co-Authors: Matthew Cole, Aravind Prakash
    Abstract:

    With the rapid increase in software exploits, the last few decades have seen several hardware-level features to enhance security (e.g., Intel MPX, ARM TrustZone, Intel SGX, Intel CET). Due to security, performance and/or usability issues these features have attracted steady criticism. One such feature is the Intel Memory Protection Extensions (MPX), an instruction set architecture extension promising spatial memory safety at a lower performance cost due to hardware-accelerated bounds checking. However, recent investigations into MPX have found that is neither as performant, accurate, nor precise as cutting-edge software-based spatial memory safety. As a direct consequence, compiler and operating system support for MPX is dying, and Intel has begun to manufacture desktop CPUs without MPX. Nonetheless, given how ubiquitous MPX is, it provides an excellent yet under-utilized hardware resource that can be aptly salvaged for security purposes. In this paper, we propose Simplex, a library framework that re-purposes MPX registers as general purpose registers. Using Simplex, we demonstrate how MPX registers can be used to Store Sensitive Information (e.g., encryption keys) directly on the hardware. We evaluate Simplex for performance and find that its overhead is small enough to permit its deployment in all but the most performance-intensive code. We refactored the string.h buffer manipulation functions and found a geometric mean 0.9% performance overhead. We also modified the deepsjeng and lbm SPEC CPU2017 benchmarks to use Simplex and found a 1% and 0.98% performance overhead respectively. Finally, we investigate the behavior of the MPX context with regards to multi-process and multi-thread programs.

Prakash Aravind - One of the best experts on this subject based on the ideXlab platform.

  • Simplex: Repurposing Intel Memory Protection Extensions for Information Hiding
    2020
    Co-Authors: Cole Matthew, Prakash Aravind
    Abstract:

    With the rapid increase in software exploits, the last few decades have seen several hardware-level features to enhance security (e.g., Intel MPX, ARM TrustZone, Intel SGX, Intel CET). Due to security, performance and/or usability issues these features have attracted steady criticism. One such feature is the Intel Memory Protection Extensions (MPX), an instruction set architecture extension promising spatial memory safety at a lower performance cost due to hardware-accelerated bounds checking. However, recent investigations into MPX have found that is neither as performant, accurate, nor precise as cutting-edge software-based spatial memory safety. As a direct consequence, compiler and operating system support for MPX is dying, and Intel has begun to manufacture desktop CPUs without MPX. Nonetheless, given how ubiquitous MPX is, it provides an excellent yet under-utilized hardware resource that can be aptly salvaged for security purposes. In this paper, we propose Simplex, a library framework that re-purposes MPX registers as general purpose registers. Using Simplex, we demonstrate how MPX registers can be used to Store Sensitive Information (e.g., encryption keys) directly on the hardware. We evaluate Simplex for performance and find that its overhead is small enough to permit its deployment in all but the most performance-intensive code. We refactored the string.h buffer manipulation functions and found a geometric mean 0.9% performance overhead. We also modified the deepsjeng and lbm SPEC CPU2017 benchmarks to use Simplex and found a 1% and 0.98% performance overhead respectively. Finally, we investigate the behavior of the MPX context with regards to multi-process and multi-thread programs.Comment: 10 pages, 5 figure

Christoph Herbst - One of the best experts on this subject based on the ideXlab platform.

  • Side-Channel Leakage across Borders
    2010
    Co-Authors: Jörn-marc Schmidt, Thomas Plos, Mario Kirschbaum, Michael Hutter, Marcel Medwed, Christoph Herbst
    Abstract:

    More and more embedded devices Store Sensitive Information that is protected by means of cryptography. The confidentiality of this data is threatened by Information leakage via side channels like the power consumption or the electromagnetic radiation. In this paper, we show that the side-channel leakage in the power consumption is not limited to the power-supply lines and that any input/output (I/O) pin can comprise secret Information. The amount of leakage depends on the design and on the state of the I/O pin. All devices that we examined leaked secret Information through their I/O pins. This implies that any I/O pin that is accessible for an adversary could be a security hole. Moreover, we demonstrate that the leakage is neither prevented by transmitter/receiver circuits as they are used in serial interfaces, nor by a galvanic isolation of a chip and its output signals via optocouplers. An adversary that is able to manipulate, for example, the pins of a PC's I/O port, can attack any device that is connected to this port without being detected from outside.

  • CARDIS - Side-Channel leakage across borders
    Lecture Notes in Computer Science, 2010
    Co-Authors: Jörn-marc Schmidt, Thomas Plos, Mario Kirschbaum, Michael Hutter, Marcel Medwed, Christoph Herbst
    Abstract:

    More and more embedded devices Store Sensitive Information that is protected by means of cryptography. The confidentiality of this data is threatened by Information leakage via side channels like the power consumption or the electromagnetic radiation. In this paper, we show that the side-channel leakage in the power consumption is not limited to the power-supply lines and that any input/output (I/O) pin can comprise secret Information. The amount of leakage depends on the design and on the state of the I/O pin. All devices that we examined leaked secret Information through their I/O pins. This implies that any I/O pin that is accessible for an adversary could be a security hole. Moreover, we demonstrate that the leakage is neither prevented by transmitter/receiver circuits as they are used in serial interfaces, nor by a galvanic isolation of a chip and its output signals via optocouplers. An adversary that is able to manipulate, for example, the pins of a PC's I/O port, can attack any device that is connected to this port without being detected from outside.

Martin S. Olivier - One of the best experts on this subject based on the ideXlab platform.

  • NoSQL databases : forensic attribution implications
    SAIEE Africa Research Journal, 2018
    Co-Authors: Werner K. Hauger, Martin S. Olivier
    Abstract:

    NoSQL databases have gained a lot of popularity over the last few years. They are now used in many new system implementations that work with vast amounts of data. Such data will typically also include Sensitive Information that needs to be secured. NoSQL databases are also underlying a number of cloud implementations which are increasingly being used to Store Sensitive Information by various organisations. This has made NoSQL databases a new target for hackers and other state sponsored actors. Forensic examinations of compromised systems will need to be conducted to determine what exactly transpired and who was responsible. This paper examines specifically if NoSQL databases have security features that leave relevant traces so that accurate forensic attribution can be conducted. The seeming lack of default security measures such as access control and logging has prompted this examination. A survey into the top ranked NoSQL databases was conducted to establish what authentication and authorisation features are available. Additionally the provided logging mechanisms were also examined since access control without any auditing would not aid forensic attribution tremendously. Some of the surveyed NoSQL databases do not provide adequate access control mechanisms and logging features that leave relevant traces to allow forensic attribution to be done using those. The other surveyed NoSQL databases did provide adequate mechanisms and logging traces for forensic attribution, but they are not enabled or configured by default. This means that in many cases they might not be available, leading to insufficient Information to perform accurate forensic attribution even on those databases.

  • ISSA - Forensic attribution in NoSQL databases
    2017 Information Security for South Africa (ISSA), 2017
    Co-Authors: Werner K. Hauger, Martin S. Olivier
    Abstract:

    NoSQL databases have gained a lot of popularity over the last few years. They are now used in many new system implementations that work with vast amounts of data. This data will typically also include Sensitive Information that needs to be secured. NoSQL databases are also underlying a number of cloud implementations which are increasingly being used to Store Sensitive Information by various organisations. This has made NoSQL databases a new target for hackers and other state sponsored actors. Forensic examinations of compromised systems will need to be conducted to determine what exactly transpired and who was responsible. This paper examines specifically if NoSQL databases have security features that leave relevant traces so that accurate forensic attribution can be conducted. The seeming lack of default security measures such as access control and logging has prompted this examination. A survey into the top ranked NoSQL databases was conducted to establish what authentication and authorisation features are available. Additionally the provided logging mechanisms were also examined since access control without any auditing would not aid forensic attribution tremendously. Some of the surveyed NoSQL databases do not provide adequate access control mechanisms and logging features that leave relevant traces to allow forensic attribution to be done using those. The other surveyed NoSQL databases did provide adequate mechanisms and logging traces for forensic attribution, but they are not enabled or configured by default. This means that in many cases they might not be available, leading to insufficient Information to perform accurate forensic attribution even on those databases.