Helmholtz Center for Information Security
CISPA – Helmholtz-Zentrum für InformationssicherheitNot a member yet
3406 research outputs found
Sort by
Getting to Know the Unknown Unknowns: Destructive-Noise Resistant Boolean Matrix Factorization
Proceedings of the ACM SIGKDD Workshop on Interactive Data Exploration and Analytics (IDEA)
See the Difference: Direct Pre-Image Reconstruction and Pose Estimation by Differentiating HOG
Data Lineage in Malicious Environments
Intentional or unintentional leakage of confidential data is undoubtedly one of the most severe security threats that organizations face in the digital era. The threat now extends to our personal lives: a plethora of personal information is available to social networks and smartphone providers and is indirectly transferred to untrustworthy third party and fourth party applications. In this work, we present a generic data lineage framework Lime for data flow across multiple entities that take two characteristic, principal roles (i.e., owner and consumer). We define the exact security guarantees required by such a data lineage mechanism toward identification of a guilty entity, and identify the simplifying non-repudiation and honesty assumptions. We then develop and analyze a novel accountable data transfer protocol between two entities within a malicious environment by building upon oblivious transfer, robust watermarking, and signature primitives. Finally, we perform an experimental evaluation to demonstrate the practicality of our protocol and apply our framework to the important data leakage scenarios of data outsourcing and social networks. In general, we consider Lime, our lineage framework for data transfer, to be an key step towards achieving accountability by design
Ein Bild der Zukunft? – Selbstentwickelte Betriebssysteme für Prüfungen am Beispiel des Saarbrücker Prüfungsrechner-Toolkits "Challenge OS"
Hausautomationssysteme im Datenschutzrecht
Hausautomationssysteme erfreuen sich immer größerer Beliebtheit. Eine mittlerweile gängige Praxis ist, die gesammelten Daten im Rahmen einer Cloud-Anwendung an den Anbieter der Hausautomationslösung zu übertragen. Neben den Komfortfunktionen wie visueller Aufbereitung und Benachrichtigungen ermöglichen diese Daten dem Anbieter aber auch Rückschlüsse über das Verhalten der Bewohner, die zu detaillierten Profilen verknüpft werden können. Unser Beitrag erörtert die Frage, welche Probleme diese Entwicklung aus rechtlicher Sicht mit sich bringt und kommt zu dem Ergebnis, dass trotz dieser Probleme ein legaler Einsatz möglich ist