Open Access. Powered by Scholars. Published by Universities.®
- Institution
-
- Singapore Management University (1107)
- Embry-Riddle Aeronautical University (768)
- Edith Cowan University (532)
- Kennesaw State University (300)
- Old Dominion University (256)
-
- Air Force Institute of Technology (181)
- San Jose State University (117)
- Bridgewater State University (73)
- Clark University (71)
- University of New Haven (65)
- United Arab Emirates University (64)
- University of Arkansas, Fayetteville (59)
- City University of New York (CUNY) (55)
- Dakota State University (49)
- California State University, San Bernardino (34)
- Nova Southeastern University (33)
- Maurer School of Law: Indiana University (32)
- University for Business and Technology in Kosovo (30)
- University of Central Florida (24)
- University of South Alabama (23)
- University of Dayton (22)
- Franklin University (21)
- LSU New Orleans (21)
- University of Nebraska at Omaha (20)
- Wayne State University (20)
- California Polytechnic State University, San Luis Obispo (18)
- University of Kentucky (18)
- Florida Institute of Technology (17)
- Louisiana State University (16)
- Portland State University (16)
- Keyword
-
- Cybersecurity (317)
- Security (247)
- Privacy (163)
- Computer security (101)
- Digital forensics (89)
-
- Information security (89)
- Blockchain (88)
- Machine learning (82)
- Authentication (71)
- Cryptography (71)
- Cloud computing (68)
- Encryption (65)
- Data privacy (62)
- [RSTDPub] (54)
- Cyber security (53)
- Access control (50)
- Data protection (47)
- Network security (45)
- Malware (41)
- Machine Learning (39)
- Android (38)
- Artificial intelligence (38)
- Computer networks--Security measures (38)
- Cybercrime (38)
- Internet of Things (36)
- Deep learning (34)
- Digital Forensics (34)
- Intrusion detection (33)
- MPA (33)
- Forensics (31)
- Publication Year
- Publication
-
- Research Collection School Of Computing and Information Systems (1056)
- Journal of Digital Forensics, Security and Law (536)
- Australian Information Security Management Conference (224)
- Theses and Dissertations (212)
- Annual ADFSL Conference on Digital Forensics, Security and Law (186)
-
- Journal of Cybersecurity Education, Research and Practice (171)
- Master's Projects (107)
- KSU Proceedings on Cybersecurity Education, Research and Practice (97)
- Cybersecurity Undergraduate Research Showcase (90)
- Research outputs 2022 to 2026 (84)
- International Journal of Cybersecurity Intelligence & Cybercrime (72)
- School of Professional Studies (71)
- Electrical & Computer Engineering and Computer Science Faculty Publications (58)
- Australian Digital Forensics Conference (50)
- Theses (45)
- Australian Information Warfare and Security Conference (44)
- Research outputs 2014 to 2021 (41)
- Computer Science Faculty Publications (40)
- Masters Theses & Doctoral Dissertations (34)
- CCAC Theses and Dissertations (33)
- Graduate Theses and Dissertations (33)
- Articles by Maurer Faculty (31)
- Publications (29)
- Electronic Theses and Dissertations (25)
- UBT International Conference (24)
- VMASC Publications (24)
- Electrical & Computer Engineering Faculty Publications (23)
- Open Educational Resources (23)
- Faculty Publications (22)
- LSU New Orleans Theses and Dissertations (21)
- Publication Type
Articles 1591 - 1620 of 4676
Full-Text Articles in Computer Sciences
قبول المعلومات الأمنية وردها في ضوء مناهج المحدثين, Hicham Almaghari
قبول المعلومات الأمنية وردها في ضوء مناهج المحدثين, Hicham Almaghari
Al Jinan الجنان
عالج الباحث الموضوع في مبحثين: قدّم في الأول تعريف المعلومة الأمنية لغة واصطلاحا، وأشار إلى مجالات النشاط الاستخباري بشكل عام، ثم عرّف المعلومة الأمنية، وأصل في المبحث الثاني طرققبول المعلومة الأمنية وردها مستفيدا من مناهج المحدثين. اتبع الباحث المنهج الوصفي بغرض التعريف بالأمن والمعلومات، وتتبع منهج المحدثين في قبول ورد الرواية، كما اتبع المنهج التحليلي في مقاربة طرق المحدثين عند قبولهم أو ردهم للرواية، ومقارنة ذلك مع المعلومة الأمنية للوصول إلى النتائج المرجوة . توصل الباحث إلى وجود كثير من القواسم المشتركة بين صناعة المعلومة الأمنية ومنهج المدثين في التعاطي مع الرواية. خلص الباحث إلى ضرورة الاستفادة من مناهج المحدّثين …
Integrated Cyberattack Detection And Resilient Control Strategies Using Lyapunov-Based Economic Model Predictive Control, Henrique Oyama, Helen Durand
Integrated Cyberattack Detection And Resilient Control Strategies Using Lyapunov-Based Economic Model Predictive Control, Henrique Oyama, Helen Durand
Chemical Engineering and Materials Science Faculty Research Publications
The use of an integrated system framework, characterized by numerous cyber/physical components (sensor measurements, signals to actuators) connected through wired/wireless networks, has not only increased the ability to control industrial systems, but also the vulnerabilities to cyberattacks. State measurement cyberattacks could pose threats to process control systems since feedback control may be lost if the attack policy is not thwarted. Motivated by this, we propose three detection concepts based on Lyapunov‐based economic model predictive control (LEMPC) for nonlinear systems. The first approach utilizes randomized modifications to an LEMPC formulation online to potentially detect cyberattacks. The second method detects attacks when …
A Survey On Securing Personally Identifiable Information On Smartphones, Dar’Rell Pope, Yen-Hung (Frank) Hu, Mary Ann Hoppa
A Survey On Securing Personally Identifiable Information On Smartphones, Dar’Rell Pope, Yen-Hung (Frank) Hu, Mary Ann Hoppa
Virginia Journal of Science
With an ever-increasing footprint, already topping 3 billion devices, smartphones have become a huge cybersecurity concern. The portability of smartphones makes them convenient for users to access and store personally identifiable information (PII); this also makes them a popular target for hackers. This survey shares practical insights derived from analyzing 16 real-life case studies that exemplify: the vulnerabilities that leave smartphones open to cybersecurity attacks; the mechanisms and attack vectors typically used to steal PII from smartphones; the potential impact of PII breaches upon all parties involved; and recommended defenses to help prevent future PII losses. The contribution of this …
The Hidden Advantage Among Digital Natives Within Bug Bounty Programs, James (Jimmy) Allah-Mensah
The Hidden Advantage Among Digital Natives Within Bug Bounty Programs, James (Jimmy) Allah-Mensah
Cybersecurity Undergraduate Research Showcase
Bug bounty programs are a great way for companies and organizations to help keep their systems and information secure; however, there are only a limited number of white hat hacking participant spots. With only so many seats available at the table, being able to determine the most qualified group of individuals is critical to the efficiency of the program at large. Digital natives, people born into the digital age, provide an instinctive approach when dealing with technology. On the other hand, digital immigrants, people who grew up before the digital age and had to adapt to new technology, evidently utilize …
The Internet Never Forgets: Image-Based Sexual Abuse And The Workplace, John Schriner, Melody Lee Rood
The Internet Never Forgets: Image-Based Sexual Abuse And The Workplace, John Schriner, Melody Lee Rood
Publications and Research
Image-based sexual abuse (IBSA), commonly known as revenge pornography, is a type of cyberharassment that often results in detrimental effects to an individual's career and livelihood. Although there exists valuable research concerning cyberharassment in the workplace generally, there is little written about specifically IBSA and the workplace. This chapter examines current academic research on IBSA, the issues with defining this type of abuse, victim blaming, workplace policy, and challenges to victim-survivors' redress. The authors explore monetary motivation for websites that host revenge pornography and unpack how the dark web presents new challenges to seeking justice. Additionally, this chapter presents recommendations …
Lecture - Csci 275: Linux Systems Administration And Security, Moe Hassan, Nyc Tech-In-Residence Corps
Lecture - Csci 275: Linux Systems Administration And Security, Moe Hassan, Nyc Tech-In-Residence Corps
Open Educational Resources
Lecture for CSCI 275: Linux Systems Administration and Security
Revisiting The Law Of Confidence In Singapore And A Proposal For A New Tort Of Misuse Of Private Information, Cheng Lim Saw, Zheng Wen Samuel Chan, Wen Min Chai
Revisiting The Law Of Confidence In Singapore And A Proposal For A New Tort Of Misuse Of Private Information, Cheng Lim Saw, Zheng Wen Samuel Chan, Wen Min Chai
Research Collection Yong Pung How School Of Law
This article critically examines the recent Court of Appeal decision in I-Admin (Singapore) Pte Ltd v Hong Ying Ting [2020] 1 SLR 1130 and its implications for the law of confidence. The article begins by setting out the decision at first instance, and then on appeal. It argues that the Court of Appeal’s “modified approach” fails to meaningfully engage the plaintiff ’s wrongful gain interest and places the law’s emphasis primarily, if not wholly, on the plaintiff ’s wrongful loss interest. The new framework also appears to have been influenced by English jurisprudence, which has had a long but unhelpful …
Presentation Of Computer Security Risk Information: Impact Of Framing And Base Size, Xinhui Zhan, Fiona Fui-Hoon Nah, Keng Siau, Richard Hall, Maggie Cheng
Presentation Of Computer Security Risk Information: Impact Of Framing And Base Size, Xinhui Zhan, Fiona Fui-Hoon Nah, Keng Siau, Richard Hall, Maggie Cheng
Research Collection School Of Computing and Information Systems
This research explores how the presentation of computer security risks impacts users’ risk perceptions and behavior. It draws on Prospect Theory to generate hypotheses related to users’ decision-making in the computer security context. A 2 × 3 mixed factorial experimental design (N = 178) was carried out and the results show that framing and base size of information on computer security risks influence users’ perceived risk and risk-taking behavior. More specifically, negative framing and large base size increase users’ perceived risk and reduce users’ risk-taking behavior. The findings from this research suggest that using negative framing and large base size …
Catch You If You Deceive Me: Verifiable And Privacy-Aware Truth Discovery In Crowdsensing Systems, Guowen Xu, Hongwei Li, Shengmin Xu, Hao Ren, Yonghui Zhang, Jianfei Sun, Robert H. Deng
Catch You If You Deceive Me: Verifiable And Privacy-Aware Truth Discovery In Crowdsensing Systems, Guowen Xu, Hongwei Li, Shengmin Xu, Hao Ren, Yonghui Zhang, Jianfei Sun, Robert H. Deng
Research Collection School Of Computing and Information Systems
Truth Discovery (TD) is to infer truthful information by estimating the reliability of users in crowdsensing systems. To protect data privacy, many Privacy-Preserving Truth Discovery (PPTD) approaches have been proposed. However, all existing PPTD solutions do not consider a fundamental issue of trust. That is, if the data aggregator (e.g., the cloud server) is not trustworthy, how can an entity be convinced that the data aggregator has correctly performed the PPTD? A "lazy"cloud server may partially follow the deployed protocols to save its computing and communication resources, or worse, maliciously forge the results for some shady deals. In this paper, …
Lis: Lightweight Signature Schemes For Continuous Message Authentication In Cyber-Physical Systems, Zheng Yang, Chenglu Jin, Yangguang Tian, Junyu Lai, Jianying Zhou
Lis: Lightweight Signature Schemes For Continuous Message Authentication In Cyber-Physical Systems, Zheng Yang, Chenglu Jin, Yangguang Tian, Junyu Lai, Jianying Zhou
Research Collection School Of Computing and Information Systems
Cyber-Physical Systems (CPS) provide the foundation of our critical infrastructures, which form the basis of emerging and future smart services and improve our quality of life in many areas. In such CPS, sensor data is transmitted over the network to the controller, which will make real-time control decisions according to the received sensor data. Due to the existence of spoofing attacks (more specifically to CPS, false data injection attacks), one has to protect the authenticity and integrity of the transmitted data. For example, a digital signature can be used to solve this issue. However, the resource-constrained field devices like sensors …
Revocable And Certificateless Public Auditing For Cloud Storage, Yinghui Zhang, Tiantian Zhang, Shengmin Xu, Guowen Xu, Dong Zheng
Revocable And Certificateless Public Auditing For Cloud Storage, Yinghui Zhang, Tiantian Zhang, Shengmin Xu, Guowen Xu, Dong Zheng
Research Collection School Of Computing and Information Systems
Plenty of computing and storage resources in the cloud are provided for users with restricted computing and storage resources, which has attracted the attention of many researchers. A generic blockchain-based cloud data auditing scheme is proposed, which is compatible with any blockchains including the bitcoin blockchain. In the data integrity checking scheme, certificateless signature (CLS) can be used to verify the identity of users. Besides, the key exchange is utilized in the key generation, which can eliminate the security channel to achieve system robustness. Considering the real situation, the users who join the cloud storage system may be revoked for …
White-Box Fairness Testing Through Adversarial Sampling, Peixin Zhang, Jingyi Wang, Jun Sun, Guoliang Dong, Xinyu Wang, Xingen Wang, Jin Song Dong, Dai Ting
White-Box Fairness Testing Through Adversarial Sampling, Peixin Zhang, Jingyi Wang, Jun Sun, Guoliang Dong, Xinyu Wang, Xingen Wang, Jin Song Dong, Dai Ting
Research Collection School Of Computing and Information Systems
Although deep neural networks (DNNs) have demonstrated astonishing performance in many applications, there are still concerns on their dependability. One desirable property of DNN for applications with societal impact is fairness (i.e., non-discrimination). In this work, we propose a scalable approach for searching individual discriminatory instances of DNN. Compared with state-of-the-art methods, our approach only employs lightweight procedures like gradient computation and clustering, which makes it significantly more scalable than existing methods. Experimental results show that our approach explores the search space more effectively (9 times) and generates much more individual discriminatory instances (25 times) using much less time (half …
Efficient Ciphertext-Policy Attribute-Based Encryption With Blackbox Traceability, Shengmin Xu, Jiaming Yuan, Guowen Xu, Yingjiu Li, Ximeng Liu, Yinghui Zhang, Zuobin Yang
Efficient Ciphertext-Policy Attribute-Based Encryption With Blackbox Traceability, Shengmin Xu, Jiaming Yuan, Guowen Xu, Yingjiu Li, Ximeng Liu, Yinghui Zhang, Zuobin Yang
Research Collection School Of Computing and Information Systems
Traitor tracing scheme is a paradigm to classify the users who illegal use of their decryption keys in cryptosystems. In the ciphertext-policy attribute-based cryptosystem, the decryption key usually contains the users’ attributes, while the real identities are hidden. The decryption key with hidden identities enables malicious users to intentionally leak decryption keys or embed the decryption keys in the decryption device to gain illegal profits with a little risk of being discovered. To mitigate this problem, the concept of blackbox traceability in the ciphertext-policy attribute-based scheme was proposed to identify the malicious user via observing the I/O streams of the …
Attribute-Based Fine-Grained Access Control For Outscored Private Set Intersection Computation, Mohammad Ali, Mohajeri Javad, Mohammad-Reza Sadeghi, Ximeng Liu
Attribute-Based Fine-Grained Access Control For Outscored Private Set Intersection Computation, Mohammad Ali, Mohajeri Javad, Mohammad-Reza Sadeghi, Ximeng Liu
Research Collection School Of Computing and Information Systems
Private set intersection (PSI) is a fundamental cryptographic protocol which has a wide range of applications. It enables two clients to compute the intersection of their private datasets without revealing non-matching elements. The advent of cloud computing drives the ambition to reduce computation and data management overhead by outsourcing such computations. However, since the cloud is not trustworthy, some cryptographic methods should be applied to maintain the confidentiality of datasets. But, in doing so, data owners may be excluded from access control on their outsourced datasets. Therefore, to control access rights and to interact with authorized users, they have to …
Towards Systematically Deriving Defence Mechanisms From Functional Requirements Of Cyber-Physical Systems, Cheah Huei Yoong, Venkata Reddy Palleti, Arlindo Silva, Christopher M. Poskitt
Towards Systematically Deriving Defence Mechanisms From Functional Requirements Of Cyber-Physical Systems, Cheah Huei Yoong, Venkata Reddy Palleti, Arlindo Silva, Christopher M. Poskitt
Research Collection School Of Computing and Information Systems
The threats faced by cyber-physical systems (CPSs) in critical infrastructure have motivated the development of different attack detection mechanisms, such as those that monitor for violations of invariants, i.e. properties that always hold in normal operation. Given the complexity of CPSs, several existing approaches focus on deriving invariants automatically from data logs, but these can miss possible system behaviours if they are not represented in that data. Furthermore, resolving any design flaws identified in this process is costly, as the CPS is already built. In this position paper, we propose a systematic method for deriving invariants before a CPS is …
Hierarchical Identity-Based Signature In Polynomial Rings, Zhichao Yang, Dung H. Duong, Willy Susilo, Guomin Yang, Chao Li, Rongmao Chen
Hierarchical Identity-Based Signature In Polynomial Rings, Zhichao Yang, Dung H. Duong, Willy Susilo, Guomin Yang, Chao Li, Rongmao Chen
Research Collection School Of Computing and Information Systems
Hierarchical identity-based signature (HIBS) plays a core role in a large community as it significantly reduces the workload of the root private key generator. To make HIBS still available and secure in post-quantum era, constructing lattice-based schemes is a promising option. In this paper, we present an efficient HIBS scheme in polynomial rings. Although there are many lattice-based signatures proposed in recent years, to the best of our knowledge, our HIBS scheme is the first ring-based construction. In the center of our construction are two new algorithms to extend lattice trapdoors to higher dimensions, which are non-trivial and of independent …
Two-Stage Photograph Cartoonization Via Line Tracing, Simin Li, Qiang Wen, Shuang Zhao, Zixun Sun, Shengfeng He
Two-Stage Photograph Cartoonization Via Line Tracing, Simin Li, Qiang Wen, Shuang Zhao, Zixun Sun, Shengfeng He
Research Collection School Of Computing and Information Systems
Cartoon is highly abstracted with clear edges, which makes it unique from the other art forms. In this paper, we focus on the essential cartoon factors of abstraction and edges, aiming to cartoonize real-world photographs like an artist. To this end, we propose a two-stage network, each stage explicitly targets at producing abstracted shading and crisp edges respectively. In the first abstraction stage, we propose a novel unsupervised bilateral flattening loss, which allows generating high-quality smoothing results in a label-free manner. Together with two other semantic-aware losses, the abstraction stage imposes different forms of regularization for creating cartoon-like flattened images. …
Memory Foreshadow: Memory Forensics Of Hardware Cryptocurrency Wallets – A Tool And Visualization Framework, Tyler Thomas, Mathew Piscitelli, Ilya Shavrov, Ibrahim Baggili
Memory Foreshadow: Memory Forensics Of Hardware Cryptocurrency Wallets – A Tool And Visualization Framework, Tyler Thomas, Mathew Piscitelli, Ilya Shavrov, Ibrahim Baggili
Electrical & Computer Engineering and Computer Science Faculty Publications
We present Memory FORESHADOW: Memory FOREnSics of HArDware cryptOcurrency Wallets. To the best of our knowledge, this is the primary account of cryptocurrency hardware wallet client memory forensics. Our exploratory analysis revealed forensically relevant data in memory including transaction history, extended public keys, passphrases, and unique device identifiers. Data extracted with FORESHADOW can be used to associate a hardware wallet with a computer and allow an observer to deanonymize all past and future transactions due to hierarchical deterministic wallet address derivation. Additionally, our novel visualization framework enabled us to measure both the persistence and integrity of artifacts produced by the …
Exploring The Learning Efficacy Of Digital Forensics Concepts And Bagging & Tagging Of Digital Devices In Immersive Virtual Reality, Courtney Hassenfeldt, Jillian Jacques, Ibrahim Baggili
Exploring The Learning Efficacy Of Digital Forensics Concepts And Bagging & Tagging Of Digital Devices In Immersive Virtual Reality, Courtney Hassenfeldt, Jillian Jacques, Ibrahim Baggili
Electrical & Computer Engineering and Computer Science Faculty Publications
This work presents the first account of evaluating learning inside a VR experience created to teach Digital Forensics (DF) concepts, and a hands-on laboratory exercise in Bagging & Tagging a crime scene with digital devices. First, we designed and developed an immersive VR experience which included a lecture and a lab. Next, we tested it with (n = 57) participants in a controlled experiment where they were randomly assigned to a VR group or a physical group. Both groups were subjected to the same lecture and lab, but one was in VR and the other was in the real world. …
Implement Multi-Factor Authentication On All Federal Systems Now, Megan Walsh
Implement Multi-Factor Authentication On All Federal Systems Now, Megan Walsh
Student Papers in Public Policy
The White House Office of Management and Budget recorded 31,107 information security incidents in fiscal year 2018. The most common attacks to gain access to a user’s login credentials were e-mail/phishing, web-based attack, and brute force entering of username/password combinations. Given this high number of incidents, strong reliance on computers for everyday business, and common attacks that target passwords, information security should be a priority for information technology administrators working in federal agencies.
Toward A Sustainable Cybersecurity Ecosystem, Shahrin Sadik, Mohiuddin Ahmed, Leslie F. Sikos, A.K.M. Najmul Islam
Toward A Sustainable Cybersecurity Ecosystem, Shahrin Sadik, Mohiuddin Ahmed, Leslie F. Sikos, A.K.M. Najmul Islam
Research outputs 2014 to 2021
© 2020 by the authors. Licensee MDPI, Basel, Switzerland. Cybersecurity issues constitute a key concern of today’s technology-based economies. Cybersecurity has become a core need for providing a sustainable and safe society to online users in cyberspace. Considering the rapid increase of technological implementations, it has turned into a global necessity in the attempt to adapt security countermeasures, whether direct or indirect, and prevent systems from cyberthreats. Identifying, characterizing, and classifying such threats and their sources is required for a sustainable cyber-ecosystem. This paper focuses on the cybersecurity of smart grids and the emerging trends such as using blockchain in …
An Enhancement Of Age And Gender Classification Accuracy With Hybrid Handcrafted And Deep Features Using Hierarchical Extreme Learning Machine, Mohammad Javidan Darugar
An Enhancement Of Age And Gender Classification Accuracy With Hybrid Handcrafted And Deep Features Using Hierarchical Extreme Learning Machine, Mohammad Javidan Darugar
Student Works (2020-2029)
Age and gender classification are some of the essential algorithms that have many use cases in our everyday life. For example, in robotics, field robots can interact with a human base on their gender in data analysis, to have statistics about age and gender of audiences in social events, YouTube video analysis, and many other applications. In this research, we have addressed limitations in deep neural networks, which by overcoming this limitation, we can gain better accuracy and performance. Our study has several other possible applications which are not limited only to age and gender classification. This dissertation is about …
Coronavirus: Pandemics, Artificial Intelligence And Personal Data: How To Manage Pandemics Using Ai And What That Means For Personal Data Protection, Warren B. Chik
Research Collection Yong Pung How School Of Law
This chapter discusses the hearing of essential and urgent court matters in the Singapore courts during the COVID-19 pandemic. On 27 march 2020, the Singapore judiciary notified courst users that remote hearings were to be implemented for certain types of hearings by means of video and telephone conferencing facilities. Court users were also provided with indicative lists of matters which might be considered essential and urgent.
Coronavirus: Pandemics, Artificial Intelligence And Personal Data: How To Manage Pandemics Using Ai And What That Means For Personal Data Protection, Warren B. Chik
Research Collection Yong Pung How School Of Law
This chapter discusses the hearing of essential and urgent court matters in the Singapore courts during the COVID-19 pandemic. On 27 march 2020, the Singapore judiciary notified courst users that remote hearings were to be implemented for certain types of hearings by means of video and telephone conferencing facilities. Court users were also provided with indicative lists of matters which might be considered essential and urgent.
Is The Transit Industry Prepared For The Cyber Revolution? Policy Recommendations To Enhance Surface Transit Cyber Preparedness, Scott Belcher, Terri Belcher, Eric Greenwald, Brandon Thomas
Is The Transit Industry Prepared For The Cyber Revolution? Policy Recommendations To Enhance Surface Transit Cyber Preparedness, Scott Belcher, Terri Belcher, Eric Greenwald, Brandon Thomas
Mineta Transportation Institute
The intent of this study is to assess the readiness, resourcing, and structure of public transit agencies to identify, protect from, detect, respond to, and recover from cybersecurity vulnerabilities and threats. Given the multitude of connected devices already in use by the transit industry and the vast amount of data generated (with more coming online soon), the transit industry is vulnerable to malicious cyber-attack and other cybersecurity-related threats. This study reviews the state of best cybersecurity practices in public surface transit; outlines U.S. public surface transit operators’ cybersecurity operations; assesses U.S. policy on cybersecurity in public surface transportation; and provides …
Pine: Enabling Privacy-Preserving Deep Packet Inspection On Tls With Rule-Hiding And Fast Connection Establishment, Jianting Ning, Xinyi Huang, Geong Sen Poh, Shengmin Xu, Jia-Chng Loh, Jain Weng, Robert H. Deng
Pine: Enabling Privacy-Preserving Deep Packet Inspection On Tls With Rule-Hiding And Fast Connection Establishment, Jianting Ning, Xinyi Huang, Geong Sen Poh, Shengmin Xu, Jia-Chng Loh, Jain Weng, Robert H. Deng
Research Collection School Of Computing and Information Systems
Transport Layer Security Inspection (TLSI) enables enterprises to decrypt, inspect and then re-encrypt users’ traffic before it is routed to the destination. This breaks the end-to-end security guarantee of the TLS specification and implementation. It also raises privacy concerns since users’ traffic is now known by the enterprises, and third-party middlebox providers providing the inspection services may additionally learn the inspection or attack rules, policies of the enterprises. Two recent works, BlindBox (SIGCOMM 2015) and PrivDPI (CCS 2019) propose privacy-preserving approaches that inspect encrypted traffic directly to address the privacy concern of users’ traffic. However, BlindBox incurs high preprocessing overhead …
Privacy-Preserving Outsourced Calculation Toolkit In The Cloud, Ximeng Liu, Robert H. Deng, Kim-Kwang Raymond Choo, Yang Yang, Hwee Hwa Pang
Privacy-Preserving Outsourced Calculation Toolkit In The Cloud, Ximeng Liu, Robert H. Deng, Kim-Kwang Raymond Choo, Yang Yang, Hwee Hwa Pang
Research Collection School Of Computing and Information Systems
In this paper, we propose a privacy-preserving outsourced calculation toolkit, Pockit, designed to allow data owners to securely outsource their data to the cloud for storage. The outsourced encrypted data can be processed by the cloud server to achieve commonly-used plaintext arithmetic operations without involving additional servers. Specifically, we design both signed and unsigned integer circuits using a fully homomorphic encryption (FHE) scheme, construct a new packing technique (hereafter referred to as integer packing), and extend the secure circuits to its packed version. This achieves significant improvements in performance compared with the original secure signed/unsigned integer circuit. The secure integer …
Attribute-Based Encryption For Cloud Computing Access Control: A Survey, Yinghui Zhang, Robert H. Deng, Shengmin Xu, Jianfei Sun, Qi Li, Dong Zheng
Attribute-Based Encryption For Cloud Computing Access Control: A Survey, Yinghui Zhang, Robert H. Deng, Shengmin Xu, Jianfei Sun, Qi Li, Dong Zheng
Research Collection School Of Computing and Information Systems
Attribute-based encryption (ABE) for cloud computing access control is reviewed in this article. A taxonomy and comprehensive assessment criteria of ABE are first proposed. In the taxonomy, ABE schemes are assorted into key-policy ABE (KP-ABE) schemes, ciphertext-policy ABE (CP-ABE) schemes, anti-quantum ABE schemes, and generic constructions. In accordance with cryptographically functional features, CP-ABE is further divided into nine subcategories with regard to basic functionality, revocation, accountability, policy hiding, policy updating, multi-authority, hierarchy, offline computation, and outsourced computation. In addition, a systematical methodology for discussing and comparing existing ABE schemes is proposed. For KP-ABE and each type of CP-ABE, the corresponding …
Efficient Fine-Grained Data Sharing Mechanism For Electronic Medical Record Systems With Mobile Devices, Hui Ma, Rui Zhang, Guomin Yang, Zishuai Zong, Kai He, Yuting Xiao
Efficient Fine-Grained Data Sharing Mechanism For Electronic Medical Record Systems With Mobile Devices, Hui Ma, Rui Zhang, Guomin Yang, Zishuai Zong, Kai He, Yuting Xiao
Research Collection School Of Computing and Information Systems
Sharing digital medical records on public cloud storage via mobile devices facilitates patients (doctors) to get (offer) medical treatment of high quality and efficiency. However, challenges such as data privacy protection, flexible data sharing, efficient authority delegation, computation efficiency optimization, are remaining toward achieving practical fine-grained access control in the Electronic Medical Record (EMR) system. In this work, we propose an innovative access control model and a fine-grained data sharing mechanism for EMR, which simultaneously achieves the above-mentioned features and is suitable for resource-constrained mobile devices. In the model, complex computation is outsourced to public cloud servers, leaving almost no …
A Lattice-Based Key-Insulated And Privacy-Preserving Signature Scheme With Publicly Derived Public Key, Wenling Liu, Zhen Liu, Khoa Nguyen, Guomin Yang, Yu Yu
A Lattice-Based Key-Insulated And Privacy-Preserving Signature Scheme With Publicly Derived Public Key, Wenling Liu, Zhen Liu, Khoa Nguyen, Guomin Yang, Yu Yu
Research Collection School Of Computing and Information Systems
As a widely used privacy-preserving technique for cryptocurrencies, Stealth Address constitutes a key component of Ring Confidential Transaction (RingCT) protocol and it was adopted by Monero, one of the most popular privacy-centric cryptocurrencies. Recently, Liu et al. [EuroS&P 2019] pointed out a flaw in the current widely used stealth address algorithm that once a derived secret key is compromised, the damage will spread to the corresponding master secret key, and all the derived secret keys thereof. To address this issue, Liu et al. introduced Key-Insulated and Privacy-Preserving Signature Scheme with Publicly Derived Public Key (PDPKS scheme), which captures the functionality, …