Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

2000

Discipline
Institution
Keyword
Publication
Publication Type

Articles 1 - 13 of 13

Full-Text Articles in Information Security

An Efficient And Practical Scheme For Privacy Protection In E-Commerce Of Digital Goods, Feng Bao, Robert H. Deng, Peirong Feng Dec 2000

An Efficient And Practical Scheme For Privacy Protection In E-Commerce Of Digital Goods, Feng Bao, Robert H. Deng, Peirong Feng

Research Collection School Of Computing and Information Systems

It is commonly acknowledged that customers’ privacy in electronic commerce should be well protected. The solutions may come not only from the ethics education and legislation, but also from cryptographic technologies. In this paper we propose and analyze a privacy protection scheme for e-commerce of digital goods. The scheme takes cryptography as its technical means to realize privacy protection for online customers. It is efficient in both computational cost and communication cost. It is very practical for real e-commerce systems compared with previous solutions. The cryptographic technique presented in this paper is rather simple. But the scheme has great application …


The Cracker Patch Choice: An Analysis Of Post Hoc Security Techniques, Crispin Cowan, Heather Hinton, Calton Pu, Jonathan Walpole Oct 2000

The Cracker Patch Choice: An Analysis Of Post Hoc Security Techniques, Crispin Cowan, Heather Hinton, Calton Pu, Jonathan Walpole

Computer Science Faculty Publications and Presentations

It has long been known that security is easiest to achieve when it is designed in from the start. Unfortunately, it has also become evident that systems built with security as a priority are rarely selected for wide spread deployment, because most consumers choose features, convenience, and performance over security. Thus security officers are often denied the option of choosing a truly secure solution, and instead must choose among a variety of post hoc security adaptations. We classify security enhancing methods, and compare and contrast these methods in terms of their effectiveness vs. cost of deployment. Our analysis provides practitioners …


Cryptanalysis Of The M-Permutation Protection Schemes, Hongjun Wu, Feng Bao, Dingfeng Ye, Robert H. Deng Jul 2000

Cryptanalysis Of The M-Permutation Protection Schemes, Hongjun Wu, Feng Bao, Dingfeng Ye, Robert H. Deng

Research Collection School Of Computing and Information Systems

Anderson and Kuhn have proposed the EEPROM modification attack to recover the secret key stored in the EEPROM. At ACISP ’98, Fung and Gray proposed an m-permutation protection scheme against the EEPROM modification attack. At ACISP ’99, Fung and Gray pointed out that in their original scheme, a secret key with too small or too large Hamming weight could be recovered easily. Then they proposed a revised m- permutation protection scheme and claimed that their revised scheme does not leak any information of the secret key. In this paper, we break completely both the original and the revised …


Multicast Internet Protocol, X. K. Wang, Robert H. Deng, Feng Bao Jun 2000

Multicast Internet Protocol, X. K. Wang, Robert H. Deng, Feng Bao

Research Collection School Of Computing and Information Systems

In this paper, we first review the existing IPv4 based multicast protocols and identify their shortcomings. We then proposed a new multicast protocol, called Multicast Internet Protocol (MIP), which is both scalable and flexible. The design principle of MIP is fundamentally different from the existing IPv4 based multicast protocols. The issues related to MIP routing and implementations are also studied in this paper.


On The Validity Of Digital Signatures, Jianying Zhou, Robert H. Deng Apr 2000

On The Validity Of Digital Signatures, Jianying Zhou, Robert H. Deng

Research Collection School Of Computing and Information Systems

An important feature of digital signatures is to serve as non-repudiation evidence. To be eligible as non-repudiation evidence, a digital signature on an electronic document should remain valid until its expiry date which is specified by some non-repudiation policy. As signature keys may be compromised and the validity of signatures may become questionable, additional security mechanisms need to be imposed on digital signatures. This paper examines the mechanisms for maintaining the validity of digital signatures, and provides a guideline on the use of these mechanisms in various context of applications.


A Distributed Agent Architecture For A Computer Virus Immune System, Paul K. Harmer Mar 2000

A Distributed Agent Architecture For A Computer Virus Immune System, Paul K. Harmer

Theses and Dissertations

Information superiority is identified as an Air Force core competency and is recognized as a key enabler for the success of future missions. Information protection and information assurance are vital components required for achieving superiority in the Infosphere, but these goals are threatened by the exponential birth rate of new computer viruses. The increased global interconnectivity that is empowering advanced information systems is also increasing the spread of malicious code and current anti-virus solutions are quickly becoming overwhelmed by the burden of capturing and classifying new viral stains. To overcome this problem, a distributed computer virus immune system (CVIS) based …


Human Fallacies And Personnel Security: James Deutch And Wen Ho Lee, Ibpp Editor Feb 2000

Human Fallacies And Personnel Security: James Deutch And Wen Ho Lee, Ibpp Editor

International Bulletin of Political Psychology

This article describes psychological phenomena that can easily subvert personnel security standards in government, the military, and business.


Security In Distributed Systems - A Framework For Different Application Types, Ingo Stengel Jan 2000

Security In Distributed Systems - A Framework For Different Application Types, Ingo Stengel

Theses

Security is a factor which decides upon the applicability of distributed applications. Therefore this thesis deals with security in distributed systems. The complexity of the existing distributed technologies makes it necessary to reduce the number of distributed technologies considered in this thesis, i.e. concentrating on: Java, Mobile Agents and CORBA, where only Java-based mobile agents will be considered.

After a short review of basic security principles including firewalls, existing security problems in the above mentioned distributed technologies are analysed. Additional generic problems in distributed systems are outlined.

Solutions are referring to two different areas: those regarding security problems with firewalls …


System Login Authentication Using Voice Recognition And Other Ai Methods, Azizul Hasan Zati Hakim Jan 2000

System Login Authentication Using Voice Recognition And Other Ai Methods, Azizul Hasan Zati Hakim

Student Works (2000-2009)

As computer becomes a commodity in work places and households appliances used by all - be it male or female young or old - the issue of security and privacy are increasing from day to day. Today, every user wishes for a better way to protect sensitive data. For all the talk about beefing up system security, the most effective way to breach a user's personal files and applications is to guess his or her password. That's because in the interest of easy recall, familiar terms are most preferred by users in general when it come too remembering a password. …


Packet Sniffer & Analyzer, Khoon Kok Ong Jan 2000

Packet Sniffer & Analyzer, Khoon Kok Ong

Student Works (2000-2009)

The communication of network is a complex process which cannot be seen by human beings. Even a computer that sit on a network can only knows the conversation within itself and others computer it talk to but not others computers· conversation that it didn't take part. Furthermore, the communication in network can be viewed as traffic which always triggers a lot of unsolved problems for computers to "talk. Therefore, to solve the problems we need to exactly know what really happened inside the network traffic. A variety of sniffing tools are invented for these purpose. All of these tools have …


Some Remarks On Fair Exchange Protocol, Jianying Zhou, Robert H. Deng, Feng Bao Jan 2000

Some Remarks On Fair Exchange Protocol, Jianying Zhou, Robert H. Deng, Feng Bao

Research Collection School Of Computing and Information Systems

Fair exchange turns out to be an increasingly important topic due to the rapid growth of electronic commerce. An exchange is deemed to be fair if at the end of exchange, either each party receives the expected item or neither party receives any useful information about the other’s item. Several protocols for fair exchange have been proposed in recent years. In this paper, we first examine a newly published fair exchange protocol and point out its flaws and weaknesses. We then put forward a more efficient and secure protocol and give an informal analysis.


Enhanced Password-Based Authentication Protocol, Chee Kiam Lee Jan 2000

Enhanced Password-Based Authentication Protocol, Chee Kiam Lee

Student Works (2000-2009)

This dissertation introduces Enhanced Password-Based Authentication Protocol (E­PAP) System. E-PAP System combines asymmetric (public-key) and symmetric (secret-key) cryptography that allow two parties sharing a small shared secret to provide authentication service, exchange confidential and authenticated information over an insecure network like lntemet. E-PAP System also provides authentication service by using somelhing you know concept. It has some advantages over biometric which uses something you are concept and smancard that uses something you have concept, as it is free of equipment's physical limitations, accuracy and cost problem as well as other constraints. The core for E-PAP System is FreeSPEKE SDK, a …


Disaster Recovery Planning : Local And Remote Data Backup System, Chin Seng Low Jan 2000

Disaster Recovery Planning : Local And Remote Data Backup System, Chin Seng Low

Student Works (2000-2009)

This dissertation studies about the disaster recovery planning focusing on data backup and which there is a data recovery capability in the event of a sudden, severe and unplanned disruption in an organization with network computing environment. The planning must ensure continuity of all the critical data and functions with minimum disruption and recover quickly during such calamity. The elements of a comprehensive and complete disaster recovery planning must include risk analysis, business impact analysis in order to recommend a suitable disaster recovery strategy. Hence, Local and Remote Data Backup System is the designed strategy based on the literature review …