1,720,981 research outputs found

    Robust, Revocable and Adaptively Secure Attribute-Based Encryption with Outsourced Decryption

    No full text
    International audienceAttribute based encryption (ABE) is a cryptographic technique allowing  ne-grainedaccess control by enabling one-to-many encryption. Existing ABE constructions su er from at leastone of the following limitations. First, single point of failure on security meaning that, once anauthority is compromised, an adversary can either easily break the con dentiality of the encrypteddata or e ortlessly prevent legitimate users from accessing data; second, the lack of user and/orattribute revocation mechanism achieving forward secrecy; third, a heavy computation workload isplaced on data user; last but not least, the lack of adaptive security in standard models.In this paper, we propose the  rst single-point-of-failure free multi-authority ciphertext-policy ABEthat simultaneously (1) ensures robustness for both decryption key issuing and access revocationwhile achieving forward secrecy; (2) enables outsourced decryption to reduce the decryption over-head for data users that have limited computational resources; and (3) achieves adaptive (full)security in standard models. The provided theoretical complexity comparison shows that our con-struction introduces linear storage and computation overheads that occurs only once during itssetup phase, which we believe to be a reasonable price to pay to achieve all previous features

    Expression et déploiement de politiques de sécurité intégrés pour données externalisées

    No full text
    Recent advance in cloud computing has transformed the way information is managed and consumed. Cloud service providers are increasingly required to take responsibility for the storage as well as the effcient and reliable sharing of information, thus carrying out a "data outsourcing" architecture. Despite that outsourcing information on Cloud service providers may cut down data owners' responsibility of managing data while increasing data availability, data owners hesitate to fully trust Cloud service providers to protect their outsourced data. Recent data breaches on Cloud storage providers have exacerbated these security concerns. In response, security designers defined approaches that provide high level security assurance, such as encrypting data before outsourcing them to Cloud servers. Such traditional approaches bring however the disadvantage of prohibiting useful information release. This raises then the need to come up with new models and approaches for defining and enforcing security and utility policies on outsourced data. This thesis aims to address this trade-off, while considering two kind of security policies. In the first hand, we focus on confidentiality policies specification and enforcement, which requires enforcing the secrecy of outsourced data stored by an untrusted Cloud service provider, while providing an efficient use (e.g., searching and computing) of the outsourced data by different authorized users. On the other hand, we address the problem of heterogeneous security policies (e.g., confidentiality requirements, privacy requirements, ownership requirements, etc) specification and deployment.Les avancées récentes dans les domaines de l'informatique en nuage sont en train de transformer la manière dont les informations sont gérées et consommées. Les fournisseurs de services de l'informatique en nuage sont de plus en plus tenus d'assumer leur responsabilité par rapport au stockage, ainsi que du partage efficace et fiable des données externalisées. Les propriétaires des données hésitent à accorder une confiance aveugle aux fournisseurs de services Cloud quant à la protection de leurs données externalisées. Ceci est dû au fait que, pour les récentes fuites de données externalisées, des vulnérabilités au sein des services Cloud ont été exploitées. Cela soulève alors la nécessité d'inventer de nouveaux modèles et de nouvelles approches permettant la définition et la mise en application des politiques de sécurité et de fonctionnalité sur les données externalisées. Cette dissertation vise à surmonter ce dilemme, tout en tenant compte de deux types de politiques de sécurité. En premier lieu, nous nous concentrons sur la spécification et le déploiement des politiques de confidentialité, qui nécessite : (1) la protection des données sensibles externalisées stockées dans des serveurs Cloud considérés comme étant non fiables, et (2) l¿utilisation efficace des données externalisées par les utilisateurs autorisés. En deuxième lieu, nous abordons la problématique de la spécification et le déploiement des politiques de sécurité hétérogènes (par exemple, les politiques de confidentialité, de protection de la vie privée, d'intégrité, etc.) sur les données externalisées

    Expression et déploiement de politiques de sécurité intégrés pour données externalisées

    No full text
    Recent advance in cloud computing has transformed the way information is managed and consumed. Cloud service providers are increasingly required to take responsibility for the storage as well as the effcient and reliable sharing of information, thus carrying out a "data outsourcing" architecture. Despite that outsourcing information on Cloud service providers may cut down data owners' responsibility of managing data while increasing data availability, data owners hesitate to fully trust Cloud service providers to protect their outsourced data. Recent data breaches on Cloud storage providers have exacerbated these security concerns. In response, security designers defined approaches that provide high level security assurance, such as encrypting data before outsourcing them to Cloud servers. Such traditional approaches bring however the disadvantage of prohibiting useful information release. This raises then the need to come up with new models and approaches for defining and enforcing security and utility policies on outsourced data. This thesis aims to address this trade-off, while considering two kind of security policies. In the first hand, we focus on confidentiality policies specification and enforcement, which requires enforcing the secrecy of outsourced data stored by an untrusted Cloud service provider, while providing an efficient use (e.g., searching and computing) of the outsourced data by different authorized users. On the other hand, we address the problem of heterogeneous security policies (e.g., confidentiality requirements, privacy requirements, ownership requirements, etc) specification and deployment.Les avancées récentes dans les domaines de l'informatique en nuage sont en train de transformer la manière dont les informations sont gérées et consommées. Les fournisseurs de services de l'informatique en nuage sont de plus en plus tenus d'assumer leur responsabilité par rapport au stockage, ainsi que du partage efficace et fiable des données externalisées. Les propriétaires des données hésitent à accorder une confiance aveugle aux fournisseurs de services Cloud quant à la protection de leurs données externalisées. Ceci est dû au fait que, pour les récentes fuites de données externalisées, des vulnérabilités au sein des services Cloud ont été exploitées. Cela soulève alors la nécessité d'inventer de nouveaux modèles et de nouvelles approches permettant la définition et la mise en application des politiques de sécurité et de fonctionnalité sur les données externalisées. Cette dissertation vise à surmonter ce dilemme, tout en tenant compte de deux types de politiques de sécurité. En premier lieu, nous nous concentrons sur la spécification et le déploiement des politiques de confidentialité, qui nécessite : (1) la protection des données sensibles externalisées stockées dans des serveurs Cloud considérés comme étant non fiables, et (2) l¿utilisation efficace des données externalisées par les utilisateurs autorisés. En deuxième lieu, nous abordons la problématique de la spécification et le déploiement des politiques de sécurité hétérogènes (par exemple, les politiques de confidentialité, de protection de la vie privée, d'intégrité, etc.) sur les données externalisées

    Expression et déploiement de politiques de sécurité intégrés pour données externalisées

    No full text
    Recent advance in cloud computing has transformed the way information is managed and consumed. Cloud service providers are increasingly required to take responsibility for the storage as well as the effcient and reliable sharing of information, thus carrying out a "data outsourcing" architecture. Despite that outsourcing information on Cloud service providers may cut down data owners' responsibility of managing data while increasing data availability, data owners hesitate to fully trust Cloud service providers to protect their outsourced data. Recent data breaches on Cloud storage providers have exacerbated these security concerns. In response, security designers defined approaches that provide high level security assurance, such as encrypting data before outsourcing them to Cloud servers. Such traditional approaches bring however the disadvantage of prohibiting useful information release. This raises then the need to come up with new models and approaches for defining and enforcing security and utility policies on outsourced data. This thesis aims to address this trade-off, while considering two kind of security policies. In the first hand, we focus on confidentiality policies specification and enforcement, which requires enforcing the secrecy of outsourced data stored by an untrusted Cloud service provider, while providing an efficient use (e.g., searching and computing) of the outsourced data by different authorized users. On the other hand, we address the problem of heterogeneous security policies (e.g., confidentiality requirements, privacy requirements, ownership requirements, etc) specification and deployment.Les avancées récentes dans les domaines de l'informatique en nuage sont en train de transformer la manière dont les informations sont gérées et consommées. Les fournisseurs de services de l'informatique en nuage sont de plus en plus tenus d'assumer leur responsabilité par rapport au stockage, ainsi que du partage efficace et fiable des données externalisées. Les propriétaires des données hésitent à accorder une confiance aveugle aux fournisseurs de services Cloud quant à la protection de leurs données externalisées. Ceci est dû au fait que, pour les récentes fuites de données externalisées, des vulnérabilités au sein des services Cloud ont été exploitées. Cela soulève alors la nécessité d'inventer de nouveaux modèles et de nouvelles approches permettant la définition et la mise en application des politiques de sécurité et de fonctionnalité sur les données externalisées. Cette dissertation vise à surmonter ce dilemme, tout en tenant compte de deux types de politiques de sécurité. En premier lieu, nous nous concentrons sur la spécification et le déploiement des politiques de confidentialité, qui nécessite : (1) la protection des données sensibles externalisées stockées dans des serveurs Cloud considérés comme étant non fiables, et (2) l¿utilisation efficace des données externalisées par les utilisateurs autorisés. En deuxième lieu, nous abordons la problématique de la spécification et le déploiement des politiques de sécurité hétérogènes (par exemple, les politiques de confidentialité, de protection de la vie privée, d'intégrité, etc.) sur les données externalisées

    Going Beyond Counting First Authors in Author Co-citation Analysis

    Get PDF
    The present study examines one of the fundamental aspects of author co-citation analysis (ACA) - the way co-citation counts are defined. Co-citation counting provides the data on which all subsequent statistical analyses and mappings are based, and we compare ACA results based on two different types of co-citation counting - the traditional type that only counts the first one among a cited work's authors on the one hand and a non-traditional type that takes into account the first 5 authors of a cited work on the other hand. Results indicate that the picture produced through this non-traditional author co-citation counting contains more coherent author groups and is therefore considerably clearer. However, this picture represents fewer specialties in the research field being studied than that produced through the traditional first-author co-citation counting when the same number of top-ranked authors is selected and analyzed. Reasons for these effects are discussed

    A privacy-preserving graph encryption scheme based on oblivious RAM

    No full text
    Part 2: Crypto ApplicationInternational audienceGraph encryption schemes play a crucial role in facilitating secure queries on encrypted graphs hosted on untrusted servers. With applications spanning navigation systems, network topology, and social networks, the need to safeguard sensitive data becomes paramount. Existing graph encryption methods, however, exhibit vulnerabilities by inadvertently revealing aspects of the graph structure and query patterns, posing threats to security and privacy. In response, we propose a novel graph encryption scheme designed to mitigate access pattern and query pattern leakage through the integration of oblivious RAM and trusted execution environment techniques, exemplified by a Trusted Execution Environment (TEE). Our solution establishes two key security objectives: (1) ensuring that adversaries, when presented with an encrypted graph, remain oblivious to any information regarding the underlying graph, and (2) achieving query indistinguishability by concealing access patterns. Additionally, we conducted experimentation to evaluate the efficiency of the proposed schemes when dealing with real-world location navigation services

    A Framework for Managing Multifaceted Privacy Leakage While Optimizing Utility in Continuous LBS Interactions

    Get PDF
    Privacy in Location-Based Services (LBS) has become a paramount concern with the ubiquity of mobile devices and the increasing integration of location data into various applications. This paper presents several novel contributions to advancing the understanding and management of privacy leakage in LBS. Our contributions provide a more comprehensive framework for analyzing privacy concerns across different facets of location-based interactions. Specifically, we introduce (ε,δ)(ε, δ)-location privacy, (ε,δ,θ)(ε, δ, θ)-trajectory privacy, and (ε,δ,θ)(ε, δ, θ)-POI privacy, which offer refined mechanisms for quantifying privacy risks associated with location, trajectory, and points of interest (POI) when continuously interacting with LBS. Furthermore, we establish fundamental connections between these privacy notions, facilitating a holistic approach to privacy preservation in LBS. Additionally, we present a lower bound analysis to evaluate the utility of the proposed privacy-preserving mechanisms, offering insights into the trade-offs between privacy protection and data utility. Finally, we instantiate our framework with the Plannar Isotopic Mechanism to demonstrate its practical applicability while ensuring optimal utility and quantifying privacy leakages across various dimensions. The evaluations provided provide a comprehensive insight into the efficacy of our framework in capturing privacy loss on location, trajectory, and points of interest while enabling quantification of the ensured accuracy

    Variations on the Author

    Get PDF
    “Variations on the Author” discusses two of Eduardo Coutinho’s recent films (Um Dia na Vida, from 2010, and Últimas Conversas, posthumously released in 2015) and their contribution to the general question of documentary authorship. The director’s filmography is characterized by a consistent yet self-effacing form of authorial self-inscription: Coutinho often features as an interviewer that rather than express opinions propels discourses; an interviewer that is good at listening. This mode of self-inscription characterizes him as an author who is not expressive but who is nonetheless markedly present on the screen. In Um Dia na Vida, however, Coutinho is completely absent form the image, while Últimas Conversas, on the contrary, includes a confessional prologue that moves the director from the margins to the center of his films. This article examines the ways in which these works stand out in the filmography of a director who offers new insights into the notion of cinematic authorship

    Appropriate Similarity Measures for Author Cocitation Analysis

    Get PDF
    We provide a number of new insights into the methodological discussion about author cocitation analysis. We first argue that the use of the Pearson correlation for measuring the similarity between authors’ cocitation profiles is not very satisfactory. We then discuss what kind of similarity measures may be used as an alternative to the Pearson correlation. We consider three similarity measures in particular. One is the well-known cosine. The other two similarity measures have not been used before in the bibliometric literature. Finally, we show by means of an example that our findings have a high practical relevance.information science;Pearson correlation;cosine;similarity measure;author cocitation analysis
    corecore