Swedish Institute of Computer Science Publications Database
Not a member yet
2787 research outputs found
Sort by
A Holistic Data Privacy and Security by Design Platform-as-a-Service Framework Introducing Distributed Encrypted Persistence in Cloud-based Applications
PaaSword’s vision is three-fold; i) maximize and fortify the trust of individual, professional and corporate customers to Cloud-enabled services and applications; ii) safeguard both corporate and personal sensitive data stored on Cloud infrastructures and Cloud-based storage services, and iii) enable the acceleration of Cloud computing technologies adoption and paradigm shift in the European industry. PaaSword will introduce a holistic data privacy and security by design framework enhanced by sophisticated context-aware policy access models and robust policy access, decision, enforcement and governance mechanisms, which will enable the implementation of secure and transparent Cloud-based applications and services, that will maintain a fully distributed and totally encrypted data persistence layer, and, thus, will ensure data protection, integrity and confidentiality, even in the case wherein there is no control over the underlying third-party Cloud resources utilised
SMACK: Short Message Authentication ChecK Against Battery Exhaustion in the Internet of Things
Internet of Things (IoT) commonly identifies the upcoming network society where all connectable devices will be able to communicate with one another. In addition, IoT devices are supposed to be directly connected to the Internet, and many of them are likely to be battery powered. Hence, they are particularly vulnerable to Denial of Service (DoS) attacks specifically aimed at quickly draining battery and severely reducing device lifetime. In this paper, we propose SMACK, a security service which efficiently identifies invalid messages early after their reception, by checking a short and lightweight Message Authentication Code (MAC). So doing, further useless processing on invalid messages can be avoided, thus reducing the impact of DoS attacks and preserving battery life. In particular, we provide an adaptation of SMACK for the standard Constrained Application Protocol (CoAP). Finally, we experimentally evaluate SMACK performance through our prototype implementation for the resource constrained CC2538 platform. Our results show that SMACK is efficient and affordable in terms of memory requirements, computing time, and energy consumption
Designing for Interactional Empowerment
This thesis further defines how to reach Interactional Empowerment through design for users. Interactional Empowerment is an interaction design program within the general area of affective interaction, focusing on the users’ ability to reflect, express themselves and engage in profound meaning-making.
This has been explored through design of three systems eMoto, Affective Diary and Affective Health, which all mirror users’ emotions or bodily reactions in interaction in some way. From these design processes and users’ encounters with the system I have extracted one experiential quality, Evocative Balance, and several embryos to experiential qualities. Evocative Balance refers to interaction experiences in which familiarity and resonance with lived experience are balanced with suggestiveness and openness to interpretation. The development of the concept of evocative balance is reported over the course of the three significant design projects, each exploring aspects of Interactional Empowerment in terms of representing bodily experiences in reflective and communicative settings. By providing accounts of evocative balance in play in the three projects, analyzing a number of other relevant interaction design experiments, and discussing evocative balance in relation to existing concepts within affective interaction, we offer a multi-grounded construct that can be appropriated by other interaction design researchers and designers.
This thesis aims to mirror a designerly way of working, which is recognized by its multigroundedness, focus on the knowledge that resides in the design process, a slightly different approach to the view of knowledge, its extension and its rigour. It provides a background to the state-of-the-art in the design community and exemplifies these theoretical standpoints in the design processes of the three design cases. This practical example of how to extend a designer’s knowledge can work as an example for design researchers working in a similar way
An analysis of a layered system architecture for autonomous construction vehicles
It has been suggested in the literature to organize software in autonomous vehicles as hierarchical layers where each layer makes its own decisions based on its own world model. This paper presents two alternative designs for autonomous construction vehicles based on the layered framework 4D/RCS. As a first step, the typical use cases for these vehicles were defined. Then one use case for a hauler was traversed through the two alternatives to see how they supported safety, flexibility and the use of a product platform. We found that the coordination between bucket control and motion control must be done at a low level in the hierarchy and that the relationship between the vehicle actuators and the built-in autonomous system is important for how the software is organized
Strategic maintenance planning by fuzzy AHP and Markov Decision Processes
The work of engineering and business professionals includes making a series of decisions and optimizations.
Real world decision making problems faced by decision makers (DM) involve multiple, usually conflicting, criteria.
These multi-criteria decision making problems (MCDM) are usually complicated and large in scale.
In strategic Maintenance planning, choices are made on where to focus time and effort, where to spend money.
We consider a framework for strategic maintenance planning in a modern maintenance driven organization.
Our focus is on a multi-stage framework in which the planning is divided into two stages, identifying an optimal set of possible actions and finding the optimal decision policy for these actions for each point in time as a function of the stochastically evolving system state.
To this respect we consider the MCDM method of AHP (Analytical hierarchical programming) in a fuzzy environment, and Markov decision processes (MDP)
Architectural Allocation Alternatives and Associated Concerns in Cyber-Physical Systems: A Case Study
Cyber-physical systems is an extension of traditional embedded systems, where communication to the outside world is given more emphasis. This leads to a new design space also for software development, allowing new allocation strategies for functionality. In traditional embedded systems, all functionality was inside the product, but now it becomes possible to partition the software between the embedded systems and IT systems outside the product. This paper investigates, through a case study from the automotive domain, possible new allocation alternatives where computation is offloaded from the embedded system to a server, and what additional architectural concerns this leads to, including performance, resource utilization, robustness, and lifecycle aspects. In addition, the paper addresses new opportunities created by allocating functionality outside the embedded systems, and thus making data available for extended services, as well as the larger concerns that result on the organizational level, including new competency in architecture and DevOps
Applicability of LTE Public Key Infrastructure Based Device Authentication in Industrial Plants
The security in industrial automation domain using cryptography mechanisms is being discussed in both industry and academia. An efficient key management system is required to support cryptography for both symmetric key and public/private key encryption. The key management should ensure that the device is verified before distributing the initial key parameters to devices. The software/firmware used in the device comes from manufacturers, therefore the initial authenticity of the device can be easily verified with the help of manufacturers. Mobile telecommunication is an industrial segment where wireless devices are being used for a long time and the security of the wireless device management has been considered through a standard driven approach. Therefore, it is interesting to analyse the security authentication mechanisms used in mobile communication, specified in Long-Term-Evolution (LTE) standard. This paper analyses the initial device authentication using public key infrastructure in LTE standard, and discusses if, where and how the studied solutions can be tailored for device authenticity verification in industrial plant automation systems