Expressive Search On Encrypted Data,
2013
Singapore Management University
Expressive Search On Encrypted Data, Junzuo Lai, Xuhua Zhou, Robert H. Deng, Yingjiu Li, Kefei Chen
Research Collection School Of Computing and Information Systems
Different from the traditional public key encryption, searchable public key encryption allows a data owner to encrypt his data under a user’s public key in such a way that the user can generate search token keys using her secret key and then query an encryption storage server. On receiving such a search token key, the server filters all or related stored encryptions and returns matched ones as response. Searchable pubic key encryption has many promising applications. Unfortunately, existing schemes either only support simple query predicates, such as equality queries and conjunctive queries, or have a superpolynomial blowup in ciphertext size …
Anonymous Authentication Of Visitors For Mobile Crowd Sensing At Amusement Parks,
2013
Singapore Management University
Anonymous Authentication Of Visitors For Mobile Crowd Sensing At Amusement Parks, Divyan Konidala, Robert H. Deng, Yingjiu Li, Hoong Chuin Lau, Stephen Fienberg
Research Collection School Of Computing and Information Systems
In this paper we focus on authentication and privacy aspects of an application scenario that utilizes mobile crowd sensing for the benefit of amusement park operators and their visitors. The scenario involves a mobile app that gathers visitors’ demographic details, preferences, and current location coordinates, and sends them to the park’s sever for various analyses. These analyses assist the park operators to efficiently deploy their resources, estimate waiting times and queue lengths, and understand the behavior of individual visitors and groups. The app server also offers visitors optimal recommendations on routes and attractions for an improved dynamic experience and minimized …
Leakage Resilient Authenticated Key Exchange Secure In The Auxiliary Input Model,
2013
Singapore Management University
Leakage Resilient Authenticated Key Exchange Secure In The Auxiliary Input Model, Guomin Yang, Yi Mu, Willy Susilo, Duncan S. Wong
Research Collection School Of Computing and Information Systems
Authenticated key exchange (AKE) protocols allow two parties communicating over an insecure network to establish a common secret key. They are among the most widely used cryptographic protocols in practice. In order to resist key-leakage attacks, several leakage resilient AKE protocols have been proposed recently in the bounded leakage model. In this paper, we initiate the study on leakage resilient AKE in the auxiliary input model. A promising way to construct such a protocol is to use a digital signature scheme that is entropically-unforgeable under chosen message and auxiliary input attacks. However, to date we are not aware of any …
Information Security As A Credence Good,
2013
Singapore Management University
Information Security As A Credence Good, Ping Fan Ke, Kai-Lung Hui, Wei Thoo Yue
Research Collection School Of Computing and Information Systems
With increasing use of information systems, many organizations are outsourcing information security protection to a managed security service provider (MSSP). However, diagnosing the risk of an information system requires special expertise, which could be costly and difficult to acquire. The MSSP may exploit their professional advantage and provide fraudulent diagnosis of clients’ vulnerabilities. Such an incentive to mis-represent clients’ risks is often called the credence goods problem in the economics literature[3]. Although different mechanisms have been introduced to tackle the credence goods problem, in the information security outsourcing context, such mechanisms may not work well with the presence of system …
Cross-Domain Password-Based Authenticated Key Exchange Revisited,
2013
Singapore Management University
Cross-Domain Password-Based Authenticated Key Exchange Revisited, Liqun Chen, Hoon Wei Lim, Guomin Yang
Research Collection School Of Computing and Information Systems
We revisit the problem of secure cross-domain communication between two users belonging to different security domains within an open and distributed environment. Existing approaches presuppose that either the users are in possession of public key certificates issued by a trusted certificate authority (CA), or the associated domain authentication servers share a long-term secret key. In this paper, we propose a generic framework for designing four-party password-based authenticated key exchange (4PAKE) protocols. Our framework takes a different approach from previous work. The users are not required to have public key certificates, but they simply reuse their login passwords they share with …
Front Matter,
2013
Embry-Riddle Aeronautical University
Masthead,
2013
Embry-Riddle Aeronautical University
Back Matter,
2013
Embry-Riddle Aeronautical University
Rootkit Detection Using A Cross-View Clean Boot Method,
2013
Air Force Institute of Technology
Rootkit Detection Using A Cross-View Clean Boot Method, Bridget N. Flatley
Theses and Dissertations
In cyberspace, attackers commonly infect computer systems with malware to gain capabilities such as remote access, keylogging, and stealth. Many malware samples include rootkit functionality to hide attacker activities on the target system. After detection, users can remove the rootkit and associated malware from the system with commercial tools. This research describes, implements, and evaluates a clean boot method using two partitions to detect rootkits on a system. One partition is potentially infected with a rootkit while the other is clean. The method obtains directory listings of the potentially infected operating system from each partition and compares the lists to …
Mobile Network Defense Interface For Cyber Defense And Situational Awareness,
2013
Air Force Institute of Technology
Mobile Network Defense Interface For Cyber Defense And Situational Awareness, James C. Hannan
Theses and Dissertations
Today's computer networks are under constant attack. In order to deal with this constant threat, network administrators rely on intrusion detection and prevention services (IDS) (IPS). Most IDS and IPS implement static rule sets to automatically alert administrators and resolve intrusions. Network administrators face a difficult challenge, identifying attacks against a vast number of benign network transactions. Also after a threat is identified making even the smallest policy change to the security software potentially has far-reaching and unanticipated consequences. Finally, because the administrator is primarily responding to alerts they may lose situational awareness of the network. During this research a …
Accountable Authority Identity-Based Encryption With Public Traceability,
2013
Singapore Management University
Accountable Authority Identity-Based Encryption With Public Traceability, Junzuo Lai, Robert H. Deng, Yunlei Zhao, Jian Weng
Research Collection School Of Computing and Information Systems
At Crypto’07, Goyal introduced the notion of accountable authority identity-based encryption (A-IBE) in order to mitigate the inherent key escrow problem in identity-based encryption, and proposed two concrete constructions. In an A-IBE system, if the private key generator (PKG) distributes a decryption key or produces an unauthorized decryption box for a user maliciously, it runs the risk of being caught and sued in the court of law with the help of a tracing algorithm. Subsequent efforts focused on constructions of A-IBE schemes with enhanced security. In these A-IBE constructions, the tracing algorithm needs to take a user’s decryption key as …
Almost Touching: Parent-Child Remote Communication Using The Sharetable System,
2013
Singapore Management University
Almost Touching: Parent-Child Remote Communication Using The Sharetable System, Svetlana Yarosh, Anthony Tang, Sanika Mokashi, Gregory D. Abowd
Research Collection School Of Computing and Information Systems
We deployed the ShareTable - a system that provides easy-to-initiate videochat and a shared tabletop task space - in four divorced households. Throughout the month of its use, the families employed the ShareTable to participate in shared activities, share emotional moments, and communicate closeness through metaphorical touch. The ShareTable provided a number of advantages over the phone and was easier to use than standard videoconferencing. However, it did also introduce concerns over privacy and new sources of conflict about appropriate calling practices. We relate our findings to the larger research landscape and present implications for future work.
Simple Identity-Based Encryption With Mediated Rsa,
2013
Singapore Management University
Simple Identity-Based Encryption With Mediated Rsa, Xuhua Ding, Gene Tsudik
Research Collection School Of Computing and Information Systems
Identity-based encryption (IBE) [5] and digital signatures are important tools in modern secure communication. In general, identity-based cryptographic methods facilitate easy introduction of public key cryptography by allowing an entity’s public key to be derived from some arbitrary identification value such as an email address or a phone number. Identity-based cryptography greatly reduces the need for, and reliance on, public key certificates. Mediated RSA (mRSA) [4] is a simple and practical method of splitting RSA private keys between the user and the Security Mediator (SEM). Neither the user nor the SEM can cheat one another since each signature or decryption …
Comparing Mobile Privacy Protection Through Cross-Platform Applications,
2013
Singapore Management University
Comparing Mobile Privacy Protection Through Cross-Platform Applications, Jin Han, Qiang Yan, Debin Gao, Jianying Zhou, Robert H. Deng
Research Collection School Of Computing and Information Systems
With the rapid growth of the mobile market, security of mobile platforms is receiving increasing attention from both research community as well as the public. In this paper, we make the first attempt to establish a baseline for security comparison between the two most popular mobile platforms. We investigate applications that run on both Android and iOS and examine the difference in the usage of their security sensitive APIs (SS-APIs). Our analysis over 2,600 applications shows that iOS applications consistently access more SS-APIs than their counterparts on Android. The additional privileges gained on iOS are often associated with accessing private …
I Can Be You: Questioning The Use Of Keystroke Dynamics As Biometrics,
2013
Singapore Management University
I Can Be You: Questioning The Use Of Keystroke Dynamics As Biometrics, Chee Meng Tey, Payas Gupta, Debin Gao
Research Collection School Of Computing and Information Systems
Keystroke dynamics refer to information about the typing patterns of individuals, such as the relative timing when the individual presses and releases each key. Prior studies suggest that such patterns are unique and cannot be easily imitated. This lays the foundation for the use of keystroke biometrics in authentication systems. The research effort in this area has thus far focused on novel detection techniques to differentiate between legitimate users and imposters. In this paper, we demonstrate a novel feedback and training interface named Mimesis. Mimesis provides both positive and negative feedback on the differences between a submitted pattern vs. a …
Raising The Game: Applying Theory And Analytics To Real-World Threats,
2013
Singapore Management University
Raising The Game: Applying Theory And Analytics To Real-World Threats, Singapore Management University
Perspectives@SMU
Safety and security are, on many levels, essential priorities for governments, businesses and individuals. While an increase of defence and security budgets may bring some assurance of peaceful times to come, it seems the world has no lack of insane perpetrators who can still somehow evade, breach, ambush, assail and attack as they please. Enter the “Bayesian Stackelberg Game”, a game theory model that can, and has been applied rather successfully to the allocation of security resources in the United States by Prof Milind Tambe, University of Southern California.
Developing Focused Auditing Tools: A Practical Framework For Creating Formalized Multi-Level Security Policy Specifications,
2013
California State University, San Bernardino
Developing Focused Auditing Tools: A Practical Framework For Creating Formalized Multi-Level Security Policy Specifications, Barbara Ann Brough
Theses Digitization Project
The purpose of this study is that formalized policy specifications and focused penetration testing are needed to effectively audit any information system. Designing and maintaining the security system information is the primary duty of the cyber security professional. In today's world, nearly all government agencies manage some form of financial, defense, national security, and/or privacy information security policies. It is also necessary in this environment that agencies are accountable for auditing the security systems that protect this information.
The Implementation Of A Thin Client In The Department Of Defense Network System,
2013
California State University, San Bernardino
The Implementation Of A Thin Client In The Department Of Defense Network System, Sung Ju In
Theses Digitization Project
The purpose of this project is to introduce and analyze a thin client solution that could enhance the overall Department of Defense (DoD) network system as well as its IT security posture, minimize risk from external threats, and ease of network operations.
Quantum Cryptography,
2013
California State University, San Bernardino
Quantum Cryptography, Razvan Augustin Dinu
Theses Digitization Project
This study builds a case for using a quantum computer for solving cryptographic problems. It looks at the quantum turing machine concept, explores why use quantum computers and presents Deutsch's problem which allows one to select from amongst the parallel paths a quantum computer calculates.
Security Risks And Protection In Online Learning: A Survey,
2013
Old Dominion University
Security Risks And Protection In Online Learning: A Survey, Yong Chen, Wu He
Distance Learning Faculty & Staff Publications
This paper describes a survey of online learning which attempts to determine online learning providers' awareness of potential security risks and the protection measures that will diminish them. The authors use a combination of two methods: blog mining and a traditional literature search. The findings indicate that, while scholars have identified diverse security risks and have proposed solutions to mitigate the security threats in online learning, bloggers have not discussed security in online learning with great frequency. The differences shown in the survey results generated by the two different methods confirm that online learning providers and practitioners have not considered …
