1,721,278 research outputs found
Challenges in Delivering Software in the Cloud as Microservices
Microservices can be broadly defined as the design of service-oriented software using a set of small services. In a microservice architecture, application complexity is distributed among narrowly focused and independently deployable units of computation. Such complexity can result in security vulnerabilities. Trustworthiness is also an issue when dealing with microservices. Moreover, there may be gaps in existing legal frameworks with regard to this technology. Solutions to these issues must seek balance between security and performance
TRUST: TRust Unguarded Service Terminals
Nowadays, plenty of digital services are provided to citizens by means of terminals located in public unguarded places. In order to access the desired service, users, authenticate themselves by providing their credentials through such terminals. This approach opens up to the problem of fraudulent devices that could be installed in place of regular terminals to capture users' confidential information. Indeed, despite the development of increasingly secure systems aiming at guaranteeing an acceptable security level, users are frequently unable to distinguish between terminals on which security measures are enforced (trusted terminals) and malicious terminals that pretend to be trusted
Key establishment : proofs and refutations
We study the problem of secure key establishment. We critically examine the security models of Bellare and Rogaway (1993) and Canetti and Krawczyk (2001) in the computational complexity approach, as these models are central in the understanding of the provable security paradigm. We show that the partnership definition used in the three-party key distribution (3PKD) protocol of Bellare and Rogaway (1995) is flawed, which invalidates the proof for the 3PKD protocol. We present an improved protocol with a new proof of security. We identify several variants of the key sharing requirement (i.e., two entities who have completed matching sessions, partners, are required to accept the same session key). We then present a brief discussion about the key sharing requirement. We identify several variants of the Bellare and Rogaway (1993) model. We present a comparative study of the relative strengths of security notions between the several variants of the Bellare-Rogaway model and the Canetti-Krawczyk model. In our comparative study, we reveal a drawback in the Bellare, Pointcheval, and Rogaway (2000) model with the protocol of Abdalla and Pointcheval (2005) as a case study.\ud
\ud
We prove a revised protocol of Boyd (1996) secure in the Bellare-Rogaway model. We then extend the model in order to allow more realistic adversary capabilities by incorporating the notion of resetting the long-term compromised key of some entity. This allows us to detect a known weakness of the protocol that cannot be captured in the original model. We also present an alternative protocol that is efficient in both messages and rounds. We prove the protocol secure in the extended model. We point out previously unknown flaws in several published protocols and a message authenticator of Bellare, Canetti, and Krawczyk (1998) by refuting claimed proofs of security. We also point out corresponding flaws in their existing proofs. We propose fixes to these protocols and their proofs. In some cases, we present new protocols with full proofs of security. We examine the role of session key construction in key establishment protocols, and demonstrate that a small change to the way that session keys are constructed can have significant benefits. Protocols that were proven secure in a restricted Bellare-Rogaway model can then be proven secure in the full model. We present a brief discussion on ways to construct session keys in key establishment protocols and also prove the protocol of Chen and Kudla (2003) secure in a less restrictive Bellare-Rogaway model. To complement the computational complexity approach, we provide a formal specification and machine analysis of the Bellare-Pointcheval-Rogaway model using an automated model checker, Simple Homomorphism Verification Tool (SHVT). We demonstrate that structural flaws in protocols can be revealed using our framework. We reveal previously unknown flaws in the unpublished preproceedings version of the protocol due to Jakobsson and Pointcheval (2001) and several published protocols with only heuristic security arguments. We conclude this thesis with a listing of some open problems that were encountered in the study
Encryption-Based Solution for Data Sovereignty in Federated Clouds
The rapidly growing demand for cloud services in the current business practice has favored the success of the hybrid clouds and the advent of cloud federation. The available literature of this topic has focused on middleware abstraction to interoperate heterogeneous cloud platforms and orchestrate different management and business models. However, cloud federation implies serious security and privacy issues with respect to data sovereignty when data is outsourced across different judicial and legal systems. This column describes a solution that applies encryption to protect data sovereignty in federated clouds rather than restricting the elasticity and migration of data across federated clouds
Cloud Manufacturing: Security, Privacy, and Forensic Concerns
Cloud computing benefits from widespread adoption in every sector of our society and economy, due, at least in part, to the promise of cost-effective and elastic provisioning of computing resources. Manufacturing is one domain where cloud computing is starting to be seen as a promising solution to strengthen collaboration and cooperation capabilities, fostered by novel organization models and strategies. The combination of the cloud computing and manufacturing domains has brought the advent of 'cloud manufacturing,' which is rethinking the way manufacturing enterprises are organized and how they can realize the advantages of cloud computing in their operations. However, the full application of cloud manufacturing is hindered by several issues, of which security is one of the most challenging. This column presents an overview of the key security issues relating to cloud manufacturing and briefly surveys the state of the art on this topic
Security analysis and improvement of a mutual authentication and key agreement solution for wireless sensor networks using chaotic maps
Abstract A characteristic of wireless sensor networks (WSNs) different from traditional networks is that WSNs are vulnerable to various types of attacks because of their distinctive features, involving distributed and nomadic attribute, wireless transmission medium, and lack of centralized infrastructure of security protection. Recently, Kumari et al presented a mutual authentication and key agreement scheme for WSNs using chaotic maps. Unfortunately, we find that the scheme of Kumari et al cannot resist sensor node capture attack, session‐specific temporary information attack, sensor node impersonation attack, and man‐in‐the‐middle attack. To overcome the security weaknesses in the solution of Kumari et al, this paper introduces a secure and efficient mutual authentication and key agreement scheme for heterogeneous ad hoc WSNs in fully public channel. Consequently, compared with the solution of Kumari et al, while providing relatively higher level of security and more security features, the proposed solution remains a favorable performance on communication overhead, computation overhead, and storage overhead separately
CL-CPPA: Certificate-Less Conditional Privacy-Preserving Authentication Protocol for the Internet of Vehicles
Biometrics in the Cloud: Challenges and Research Opportunities
Privacy is one of several key concerns in the current “Cloudification” trend, such as ensuring the privacy of user data and transactions during the outsourcing of data, applications, and infrastructure to the cloud. This is due to a wide range of factors, such as changing societal expectations, and the delegation of the control of the data and transactions to geographically distributed datacenters, including in regimes that may not share the same underpinning legislative framework
- …
