Open Access. Powered by Scholars. Published by Universities.®
- Institution
-
- Singapore Management University (148)
- University for Business and Technology in Kosovo (29)
- University of Dayton (21)
- Nova Southeastern University (16)
- Dakota State University (14)
-
- University of Arkansas, Fayetteville (14)
- Old Dominion University (9)
- University of Malaya (7)
- California State University, San Bernardino (6)
- Institute of Business Administration (6)
- San Jose State University (6)
- Air Force Institute of Technology (5)
- Kennesaw State University (5)
- United Arab Emirates University (5)
- University of Kentucky (5)
- University of Denver (4)
- University of South Alabama (4)
- California Polytechnic State University, San Luis Obispo (3)
- Embry-Riddle Aeronautical University (3)
- James Madison University (3)
- Montclair State University (3)
- Technological University Dublin (3)
- The University of San Francisco (3)
- University of New Haven (3)
- University of Texas Rio Grande Valley (3)
- Western Kentucky University (3)
- Arkansas Tech University (2)
- Boise State University (2)
- Columbus State University (2)
- Hunan Provincial Institute of Scientific and Technology Information (2)
- Keyword
-
- Cybersecurity (20)
- Blockchain (18)
- Privacy (17)
- Security (16)
- Information security (12)
-
- Cloud computing (11)
- Access control (9)
- Information technology (9)
- Cryptography (8)
- Data privacy (8)
- Machine learning (8)
- Big data (7)
- Computer science (7)
- Information systems (7)
- Attribute-based encryption (6)
- Bitcoin (6)
- Data security (6)
- Encryption (6)
- Information science (6)
- Cryptocurrency (5)
- Differential privacy (5)
- Homomorphic encryption (5)
- Technology (5)
- Authentication (4)
- Daniel Felix Ritchie School of Engineering and Computer Science (4)
- Data outsourcing (4)
- Data sharing (4)
- Database security (4)
- Delay (4)
- GDPR (4)
- Publication Year
- Publication
-
- Research Collection School Of Computing and Information Systems (142)
- UBT International Conference (23)
- Computer Science Faculty Publications (21)
- CCAC Theses and Dissertations (16)
- Graduate Theses and Dissertations (13)
-
- Masters Theses & Doctoral Dissertations (12)
- Theses and Dissertations (10)
- Electronic Theses and Dissertations (6)
- Electronic Theses, Projects, and Dissertations (6)
- International Conference on Information and Communication Technologies (6)
- International Journal of Business and Technology (6)
- Student Works (2020-2029) (5)
- Theses (5)
- Cybersecurity Undergraduate Research Showcase (4)
- Master's Projects (4)
- Master's Theses (4)
- Department of Computer Science Faculty Scholarship and Creative Works (3)
- Dissertations and Theses Collection (Open Access) (3)
- Media Studies (3)
- Shelby Hall Graduate Research Forum Posters (3)
- ATU Scholars Symposium (2)
- African Conference on Information Systems and Technology (2)
- Computer Science Working Papers (2)
- Dissertations (2)
- Electrical and Computer Engineering Publications (2)
- Honors Theses (2)
- Informatics and Engineering Systems Faculty Publications (2)
- Journal of Humanities and Social Sciences (2)
- Journal of Scientific Information Research (2)
- Masters Theses & Specialist Projects (2)
- Publication Type
- File Type
Articles 181 - 210 of 394
Full-Text Articles in Information Security
Querying Over Encrypted Databases In A Cloud Environment, Jake Douglas
Querying Over Encrypted Databases In A Cloud Environment, Jake Douglas
Boise State University Theses and Dissertations
The adoption of cloud computing has created a huge shift in where data is processed and stored. Increasingly, organizations opt to store their data outside of their own network to gain the benefits offered by shared cloud resources. With these benefits also come risks; namely, another organization has access to all of the data. A malicious insider at the cloud services provider could steal any personal information contained on the cloud or could use the data for the cloud service provider's business advantage. By encrypting the data, some of these risks can be mitigated. Unfortunately, encrypting the data also means …
Building Consumer Trust In The Cloud: An Experimental Analysis Of The Cloud Trust Label Approach, Lisa Van Der Werff, Grace Fox, Ieva Masevic, Vincent C. Emeakaroha, John P. Morrison, Theo Lynn
Building Consumer Trust In The Cloud: An Experimental Analysis Of The Cloud Trust Label Approach, Lisa Van Der Werff, Grace Fox, Ieva Masevic, Vincent C. Emeakaroha, John P. Morrison, Theo Lynn
Department of Computer Science Publications
The lack of transparency surrounding cloud service provision makes it difficult for consumers to make knowledge based purchasing decisions. As a result, consumer trust has become a major impediment to cloud computing adoption. Cloud Trust Labels represent a means of communicating relevant service and security information to potential customers on the cloud service provided, thereby facilitating informed decision making. This research investigates the potential of a Cloud Trust Label system to overcome the trust barrier. Specifically, it examines the impact of a Cloud Trust Label on consumer perceptions of a service and cloud service provider trustworthiness and trust in the …
Testing The Fault Tolerance Of A Wide Area Backup Protection System Using Spin, Kenneth James
Testing The Fault Tolerance Of A Wide Area Backup Protection System Using Spin, Kenneth James
Theses and Dissertations
Cyber-physical systems are increasingly prevalent in daily life. Smart grids in particular are becoming more interconnected and autonomously operated. Despite the advantages, new challenges arise in the form of defending these assets. Recent studies reveal that small-scale, coordinated cyber-attacks on only a few substations across the U.S. could result in cascading failures affecting the entire nation. In support of defending critical infrastructure, this thesis tests the fault tolerance of a backup protection system. Each transmission line in the system incorporates autonomous agents which monitor the status of the line and make decisions regarding the safety of the grid. Various malfunctions …
Evaluating Machine Learning Techniques For Smart Home Device Classification, Angelito E. Aragon Jr.
Evaluating Machine Learning Techniques For Smart Home Device Classification, Angelito E. Aragon Jr.
Theses and Dissertations
Smart devices in the Internet of Things (IoT) have transformed the management of personal and industrial spaces. Leveraging inexpensive computing, smart devices enable remote sensing and automated control over a diverse range of processes. Even as IoT devices provide numerous benefits, it is vital that their emerging security implications are studied. IoT device design typically focuses on cost efficiency and time to market, leading to limited built-in encryption, questionable supply chains, and poor data security. In a 2017 report, the United States Government Accountability Office recommended that the Department of Defense investigate the risks IoT devices pose to operations security, …
Flashlight In A Dark Room: A Grounded Theory Study On Information Security Management At Small Healthcare Provider Organizations, Gerald Auger
Masters Theses & Doctoral Dissertations
Healthcare providers have a responsibility to protect patient’s privacy and a business motivation to properly secure their assets. These providers encounter barriers to achieving these objectives and limited academic research has been conducted to examine the causes and strategies to overcome them. A subset of this demographic, businesses with less than 10 providers, compose a majority 57% of provider organizations in the United States. This grounded theory study provides exploratory findings, discovering these small healthcare provider organizations (SHPO) have limited knowledge on information technology (IT) and information security that results in assumptions and misappropriations of information security implementation, who is …
Advanced Code-Reuse Attacks: A Novel Framework For Jop, Bramwell J. Brizendine
Advanced Code-Reuse Attacks: A Novel Framework For Jop, Bramwell J. Brizendine
Masters Theses & Doctoral Dissertations
Return-oriented programming is the predominant code-reuse attack, where short gadgets or borrowed chunks of code ending in a RET instruction can be discovered in binaries. A chain of ROP gadgets placed on the stack can permit control flow to be subverted, allowing for arbitrary computation. Jump-oriented programming is a class of code-reuse attack where instead of using RET instructions, indirect jumps and indirect calls are utilized to subvert the control flow. JOP is important because can allow for important mitigations and protections against ROP to be bypassed, and some protections against JOP are imperfect. This dissertation presents a design science …
Mirai Bot Scanner Summation Prototype, Charles V. Frank Jr.
Mirai Bot Scanner Summation Prototype, Charles V. Frank Jr.
Masters Theses & Doctoral Dissertations
The Mirai botnet deploys a distributed mechanism with each Bot continually scanning for a potential new Bot Victim. A Bot continually generates a random IP address to scan the network for discovering a potential new Bot Victim. The Bot establishes a connection with the potential new Bot Victim with a Transmission Control Protocol (TCP) handshake. The Mirai botnet has recruited hundreds of thousands of Bots. With 100,000 Bots, Mirai Distributed Denial of Service (DDoS) attacks on service provider Dyn in October 2016 triggered the inaccessibility to hundreds of websites in Europe and North America (Sinanović & Mrdovic, 2017). A month …
Towards Secure Data Flow Oriented Multi-Vendor Ict Governance Model, Lars Magnusson, Patrik Elm, Anita Mirijamdotter
Towards Secure Data Flow Oriented Multi-Vendor Ict Governance Model, Lars Magnusson, Patrik Elm, Anita Mirijamdotter
International Journal of Business and Technology
Today, still, ICT Governance is being regarded as a departmental concern, not an overall organizational concern. History has shown us that implementation strategies, which are based on departments, results in fractional implementations leading to ad hoc solutions with no central control and stagnation for the in-house ICT strategy. Further, this recently has created an opinion trend; many are talking about the ICT department as being redundant, a dying out breed, which should be replaced by on-demand specialized external services. Clearly, the evermore changing surroundings do force organizations to accelerate the pace of new adaptations within their ICT plans, more vivacious …
Implications Of Eu-Gdpr In Low-Grade Social, Activist And Ngo Settings, Lars Magnusson, Sarfraz Iqbal
Implications Of Eu-Gdpr In Low-Grade Social, Activist And Ngo Settings, Lars Magnusson, Sarfraz Iqbal
International Journal of Business and Technology
Social support services are becoming popular among the citizens of every country and every age. Though, social support services easily accessible on mobile phones are used in different contexts, ranging from extending your presence and connectivity to friends, family and colleagues to using social media services for being a social activist seeking to help individuals confined in miserable situations such as homeless community, drug addicts or even revolutionists fighting against dictatorships etc. However, a very recent development in the European Parliament’s law (2016/679) on the processing and free movement of personal data in terms of EU-GDPR (General data protection rules) …
An Approach To Information Security For Smes Based On The Resource-Based View Theory, Blerton Abazi
An Approach To Information Security For Smes Based On The Resource-Based View Theory, Blerton Abazi
International Journal of Business and Technology
The main focus of this proposal is to analyze implementation challenges, benefits and requirements in implementation of Information Systems and managing information security in small and medium size companies in Western Balkans countries. In relation to the study, the proposal will focus in the following questions to investigate: What are the benefits that companies mostly find after the implementation of Information Systems has been implemented, efficiency, how to they manage security of the information’s, competitive advantage, return of investments etc. The study should give a clear approach to Information Systems implementation, information security, maintenance, measurable benefits, challenges companies have gone …
Some Issues In The Testing Of Computer Simulation Models, David J. Murray-Smith
Some Issues In The Testing Of Computer Simulation Models, David J. Murray-Smith
International Journal of Business and Technology
The testing of simulation models has much in common with testing processes in other types of application involving software development. However, there are also important differences associated with the fact that simulation model testing involves two distinct aspects, which are known as verification and validation. Model validation is concerned with investigation of modelling errors and model limitations while verification involves checking that the simulation program is an accurate representation of the mathematical and logical structure of the underlying model. Success in model validation depends upon the availability of detailed information about all aspects of the system being modelled. It also …
Probabilistic Record Linkage With Elliptic Curve Operations, Shreya Dhiren Patel
Probabilistic Record Linkage With Elliptic Curve Operations, Shreya Dhiren Patel
Electronic Theses and Dissertations
Federated query processing for an electronic health record infrastructure enables large epidemiology studies using data integrated from geographically dispersed medical institutions. However, government imposed privacy regulations prohibit disclosure of patient's health record outside the context of clinical care, thereby making it difficult to determine which records correspond to the same entity in the process of query aggregation.
Privacy-preserving record linkage is an actively pursued research area to facilitate the linkage of database records under the constraints of regulations that do not allow the linkage agents to learn sensitive identities of record owners. In earlier works, scalability has been shown to …
Procure-To-Pay Software In The Digital Age: An Exploration And Analysis Of Efficiency Gains And Cybersecurity Risks In Modern Procurement Systems, Drew Lane
MPA/MPP/MPFM Capstone Projects
Procure-to-Pay (P2P) softwares are an integral part of the payment and procurement processing functions at large-scale governmental institutions. These softwares house all of the financial functions related to procurement, accounts payable, and often human resources, helping to facilitate and automate the process from initiation of a payment or purchase, to the actual disbursal of funds. Often, these softwares contain budgeting and financial reporting tools as part of the offering. As such an integral part of the financial process, these softwares obviously come at an immense cost from a set of reputable vendors. In the case of government, these vendors mainly …
Agent-Based Iot Coordination For Smart Cities Considering Security And Privacy, Iván García-Magariño, Geraldine Gray, Rajarajan Muttukrishnan, Waqar Asif
Agent-Based Iot Coordination For Smart Cities Considering Security And Privacy, Iván García-Magariño, Geraldine Gray, Rajarajan Muttukrishnan, Waqar Asif
Conference papers
The interest in Internet of Things (IoT) is increasing steeply, and the use of their smart objects and their composite services may become widespread in the next few years increasing the number of smart cities. This technology can benefit from scalable solutions that integrate composite services of multiple-purpose smart objects for the upcoming large-scale use of integrated services in IoT. This work proposes an agent-based approach for supporting large-scale use of IoT for providing complex integrated services. Its novelty relies in the use of distributed blackboards for implicit communications, decentralizing the storage and management of the blackboard information in the …
Russia Today, Cyberterrorists Tomorrow: U.S. Failure To Prepare Democracy For Cyberspace, Jonathan F. Lancelot
Russia Today, Cyberterrorists Tomorrow: U.S. Failure To Prepare Democracy For Cyberspace, Jonathan F. Lancelot
Journal of Digital Forensics, Security and Law
This paper is designed to expose vulnerabilities within the US electoral system, the use of cyberspace to exploit weaknesses within the information assurance strategies of the democratic and republican party organizations, and deficiencies within the social media communications and voting machine exploits. A brief history of discriminatory practices in voting rights and voting access will be set as the foundation for the argument that the system is vulnerable in the cyber age, and the need for reform at the local, state and national levels will be emphasized. The possibility of a foreign nation-state influencing the outcome of an election by …
Gradubique: An Academic Transcript Database Using Blockchain Architecture, Thinh Nguyen
Gradubique: An Academic Transcript Database Using Blockchain Architecture, Thinh Nguyen
Master's Projects
Blockchain has been widely adopted in the last few years even though it is in its infancy. The first well-known application built on blockchain technology was Bitcoin, which is a decentralized and distributed ledger to record crypto-currency transactions. All of the transactions in Bitcoin are anonymously transferred and validated by participants in the network. Bitcoin protocol and its operations are so reliable that technologists have been inspired to enhance blockchain technologies and deploy it outside of the crypto-currency world. The demand for private and non-crypto-currency solutions have surged among consortiums because of the security and fault tolerant features of blockchain. …
Performance Indicators Analysis Inside A Call Center Using A Simulation Program, Ditila Ekmekçiu, Markela Muça, Adrian Naço
Performance Indicators Analysis Inside A Call Center Using A Simulation Program, Ditila Ekmekçiu, Markela Muça, Adrian Naço
International Journal of Business and Technology
This paper deals with and shows the results of different performance indicators analyses made utilizing the help of Simulation and concentrated on dimensioning problems of handling calls capacity in a call center. The goal is to measure the reactivity of the call center’s performance to potential changes of critical variables. The literature related to the employment of this kind of instrument in call centers is reviewed, and the method that this problem is treated momentarily is precisely described. The technique used to obtain this paper’s goal implicated a simulation model using Arena Contact Center software that worked as a key …
Modelling Business And Management Systems Using Fuzzy Cognitive Maps: A Critical Overview, Peter P. Groumpos
Modelling Business And Management Systems Using Fuzzy Cognitive Maps: A Critical Overview, Peter P. Groumpos
International Journal of Business and Technology
A critical overview of modelling Business and Management (B&M) Systems using Fuzzy Cognitive Maps is presented. A limited but illustrative number of specific applications of Fuzzy Cognitive Maps in diverse B&M systems, such as e business, performance assessment, decision making, human resources management, planning and investment decision making processes is provided and briefly analyzed. The limited survey is given in a table with statics of using FCMs in B&M systems during the last 15 years. The limited survey shows that the applications of Fuzzy Cognitive Maps to today’s Business and Management studies has been steadily increased especially during the last …
Vpsearch: Achieving Verifiability For Privacy-Preserving Multi-Keyword Search Over Encrypted Cloud Data, Zhiguo Wan, Robert H. Deng
Vpsearch: Achieving Verifiability For Privacy-Preserving Multi-Keyword Search Over Encrypted Cloud Data, Zhiguo Wan, Robert H. Deng
Research Collection School Of Computing and Information Systems
Although cloud computing offers elastic computation and storage resources, it poses challenges on verifiability of computations and data privacy. In this work we investigate verifiability for privacy-preserving multi-keyword search over outsourced documents. As the cloud server may return incorrect results due to system faults or incentive to reduce computation cost, it is critical to offer verifiability of search results and privacy protection for outsourced data at the same time. To fulfill these requirements, we design aVerifiablePrivacy-preserving keywordSearch scheme, called VPSearch, by integrating an adapted homomorphic MAC technique with a privacy-preserving multi-keyword search scheme. The proposed scheme enables the client to …
Vulnerability Assessment & Penetration Testing: Case Study On Web Application Security, Gazmend Krasniqi, Veton Bejtullahu
Vulnerability Assessment & Penetration Testing: Case Study On Web Application Security, Gazmend Krasniqi, Veton Bejtullahu
UBT International Conference
Complexity of information systems are increasing day by day. The security of information systems that are connected to public networks can be compromised by unauthorized, and usually anonymous, attempts to access them. By using public networks businesses and other institutions are exposed to numerous risks. This leads to more and more vulnerabilities in Information Systems. This situation calls for test methods that are devised from the attacker’s perspective to ensure that test conditions are as realistic as possible. In this paper we will describe complete stages of Vulnerability Assessment and Penetration Testing on some systems in UBT and proactive action …
Secure And Efficient Outsourcing Of Large-Scale Overdetermined Systems Of Linear Equations, Shiran Pan, Wen-Tao Zhu, Qiongxiao Wang, Bing Chang
Secure And Efficient Outsourcing Of Large-Scale Overdetermined Systems Of Linear Equations, Shiran Pan, Wen-Tao Zhu, Qiongxiao Wang, Bing Chang
Research Collection School Of Computing and Information Systems
We address overdetermined systems of linear equations, where the number of unknowns is smaller than the number of equations so that only approximate solutions exist instead of exact solutions. Such systems are prevalent in many areas of science and engineering, and finding the optimal solutions is mathematically known as the linear least squares (LLS) problem. Real-world overdetermined systems are often large-scale and computationally expensive to solve. Consequently, we are interested in connecting the LLS problem with cloud computing, where a resource-constrained client outsources the problem to a powerful but untrusted cloud. Among several security considerations is that the input of …
Is Information Systems Misuse Always Bad? A New Perspective On Is Misuse In Hospitals Under The Context Of Disasters, Dheyaaldin Alsalman
Is Information Systems Misuse Always Bad? A New Perspective On Is Misuse In Hospitals Under The Context Of Disasters, Dheyaaldin Alsalman
Masters Theses & Doctoral Dissertations
Although the extant literature has investigated how individuals engage in inappropriate behaviors based on the rational choice theory (RCT) (e.g., computer misconduct), the neutralization theory (e.g., IS security policies violation), and workarounds under normal situations, it has given little consideration to how individuals are involved in misuse of information systems with a good intention under the context of disasters. To fill this research gap, we propose a selfless misuse model, which offers a theoretical explanation for the concept of individuals’ selfless misuse intention under uncertainty caused by disasters. In this study, we show why employees make decisions to misuse the …
An Assessment Of Users’ Cyber Security Risk Tolerance In Reward-Based Exchange, Xinhui Zhan, Fiona Fui-Hoon Nah, Maggie X. Cheng
An Assessment Of Users’ Cyber Security Risk Tolerance In Reward-Based Exchange, Xinhui Zhan, Fiona Fui-Hoon Nah, Maggie X. Cheng
Research Collection School Of Computing and Information Systems
This study examines users’ risk-taking behavior in software downloads. We are interested in quantifying the degree of risks that users are willing to take in the cyber security context. We propose conducting an experiment using Amazon’s Mechanical Turk to assess the degree of risks that people are willing to take for monetary gains when they download software from uncertified sources.
Tanzanian Adolescents In The Digital Age Of Cell Phones And The Internet: Access, Use And Risks, Hezron Zacharia Onditi
Tanzanian Adolescents In The Digital Age Of Cell Phones And The Internet: Access, Use And Risks, Hezron Zacharia Onditi
Journal of Humanities and Social Sciences
This study explored cell phones and internet access, use, and potential risks among Tanzanian secondary school adolescents. A total of 778 students aged 14-18 in Form I to Form IV responded to a self-report questionnaire, and a subset of 20 participants participated in semi-structured interviews. Results revealed a remarkable uptake of cell phones and internet technologies among Tanzanian adolescents. In particular, whereas about 50% of the students reported to own cell phones (nearly 60% own simcards), 76% admitted using cell phones at home, and 86% reported to connect to the Internet. Results showed that male and older adolescents seem to …
Deaddrop: Message Passing Without Metadata Leakage, Davis Mike Arndt
Deaddrop: Message Passing Without Metadata Leakage, Davis Mike Arndt
Computer Science and Software Engineering
Even when network data is encrypted, observers can make inferences about content based on collected metadata. DeadDrop is an exploratory API designed to protect the metadata of a conversation from both outside observers and the facilitating server. To do so, DeadDrop servers are passed no recipient address, instead relying upon the recipient to check for messages of their own volition. In addition, the recipient downloads a copy of every encrypted message on the server to prevent even the server from knowing to whom each message is intended. To these purposes, DeadDrop is mostly successful. However, it does not obscure all …
Verifiably Encrypted Cascade-Instantiable Blank Signatures To Secure Progressive Decision Management, Yujue Wang, Hwee Hwa Pang, Robert H. Deng
Verifiably Encrypted Cascade-Instantiable Blank Signatures To Secure Progressive Decision Management, Yujue Wang, Hwee Hwa Pang, Robert H. Deng
Research Collection School Of Computing and Information Systems
In this paper, we introduce the notion of verifiably encrypted cascade-instantiable blank signatures (CBS) in a multi-user setting. In CBS, there is a delegation chain that starts with an originator and is followed by a sequence of proxies. The originator creates and signs a template, which may comprise fixed fields and exchangeable fields. Thereafter, each proxy along the delegation chain is able to make an instantiation of the template from the choices passed down from her direct predecessor, before generating a signature for her instantiation. First, we present a non-interactive basic CBS construction that does not rely on any shared …
Trade-Offs Between Monetary Gain And Risk Taking In Cybersecurity Behavior, X. Zhan, Fiona Fui-Hoon Nah, M. Cheng
Trade-Offs Between Monetary Gain And Risk Taking In Cybersecurity Behavior, X. Zhan, Fiona Fui-Hoon Nah, M. Cheng
Research Collection School Of Computing and Information Systems
Phishers and hackers exploit users’ susceptibility to deception by providing incentives. This research focuses on studying the risk-taking behavior of users in downloading software from the Internet. We proposed an experimental study to assess the degree of risks that people are willing to take for monetary gains when they download software from uncertified sources.
Effect Of Probable And Guaranteed Monetary Value Gains And Losses On Cybersecurity Behavior Of Users, S. Ravindran, Fiona Fui-Hoon Nah, M. Cheng
Effect Of Probable And Guaranteed Monetary Value Gains And Losses On Cybersecurity Behavior Of Users, S. Ravindran, Fiona Fui-Hoon Nah, M. Cheng
Research Collection School Of Computing and Information Systems
The objective of this research is to examine users’ cybersecurity behavior in monetary gain and loss scenarios. Using Prospect Theory, we hypothesize that users are more likely to engage in risky cybersecurity behavior to avoid monetary losses than to benefit from monetary gains. We also hypothesize that guaranteed gains have a greater effect on a user’s risk-taking behavior than potential gains, and potential losses have a greater effect on a user’s risk-taking behavior than guaranteed losses. An experimental study is proposed to test the research hypotheses.
Surveying Digital Collections Stewardship In Nebraska [Original Survey Form], Jennifer L. Thoegersen, Blake Graham
Surveying Digital Collections Stewardship In Nebraska [Original Survey Form], Jennifer L. Thoegersen, Blake Graham
University of Nebraska-Lincoln Data Repository
No abstract provided.
Every Step You Take, I’Ll Be Watching You: Practical Stepauth-Entication Of Rfid Paths, Kai Bu, Yingjiu Li
Every Step You Take, I’Ll Be Watching You: Practical Stepauth-Entication Of Rfid Paths, Kai Bu, Yingjiu Li
Research Collection School Of Computing and Information Systems
Path authentication thwarts counterfeits in RFID-based supply chains. Its motivation is that tagged products taking invalid paths are likely faked and injected by adversaries at certain supply chain partners/steps. Existing solutions are path-grained in that they simply regard a product as genuine if it takes any valid path. Furthermore, they enforce distributed authentication by offloading the sets of valid paths to some or all steps from a centralized issuer. This not only imposes network and storage overhead but also leaks transaction privacy. We present StepAuth, the first step-grained path authentication protocol that is practically efficient for authenticating products with strict …