
This paper describes a mechanism for secure online user authentication and document signature with a cryptogram Java card in an insecure environment. The mechanism requires possession of both the card and some secrets, known as Concepts, to authenticate the user. The concepts are represented in image form. A method of secure document signing with the concept-based images is also outlined. Possible security weakness and attack methods are analysed in the paper. An implementation of the mechanism is also described in brief. It is anticipated that the mechanism would provide security and non-repudiation for e-Commerce customers in an insecure operating
In many practical contexts, it is necessary to certify that the content of a web server log file is correct with respect to real client traffic. This certification should be carried out by an independent third party, which we will call a certification agency, that is trusted by the web server owner and by the log file user. The certification agency should use adequate technology to perform the requested certification. The used technology must ensure that the log file was not altered or, in case of modifications to the log file, it should detect individual items that were added or removed. In this paper a novel technique for web server access certification based on software is presented, and its reliability and performance is discussed. A case study and experimental data from a web site with significant traffic is also presented.
Is it possible to implement practical Internet Polls that fulfill even the weakest security requirements? The technology available today would lead to a negative answer, because of the following practical constraints: standard, unmodified browsers are used, it is not economically possible to distribute certificates or even just user names and passwords, users connect from different workstations, possibly behind firewalls, proxies and address translation nodes. In this paper, we define an innovative notion of Internet Poll security, namely “Security against Massive Falsification”, and we present a method that we consider to be secure with respect to this definition. We discuss the security properties of the method with respect to existing techniques, and then propose a public challenge for testing the strength of our claim.
Trust management has been addressed recently to provide networked systems with the appropriate mechanisms to perform any conformance checking with respect to a security policy in e-business and e-government. Trust management is an important issue for the deployment and success of e-government. Besides, public-key infrastructures manage trust in data exchanges through email, over the web and using other electronic means. The principal elements used for maintaining that trust are the contents of the certificates and the security safeguards established in the environments where various parties are involved. These two elements are derived from the business requirements, according to the stipulations of the certificate policy and the applicable regulation. We show in this paper the need to introduce the paradigm of multi-level trust in e-government systems, and propose a solution that provides X.509 standards with the modifications to allow multi-level trust certificate management, publication, and efficient
In many countries, public institutions, as the main producers and distributors of legal source of information, have promoted projects aimed at improving the availability and the free access to information via the web as a significant component of the process of transparency in citizen/institution interaction. This paper describes the state of the art in terms of European projects created by public institutions for facilitating access to regulatory information and it focuses the necessity of integrating structural documentary standards with semantic ones for the description of content. The Italian JurWordNet project is a source of semantic metadata aimed at supporting the semantic interoperability between sectors of Public Administration; the creation of a multilingual lexicon that extends the Italian model to five European languages (the aim of the Lois Project that has recently been approved by the EU) is also described.
The ease of reproducing digital data in their exact original form is likely to encourage copyright violation, data misappropriation and abuse. Watermarking security enhancement is highly required for multimedia copyright applications. This work enhances the security of watermarking algorithm without affecting the robustness of the watermark by implementing the wavelet filter parameterization (WPF). The experimental results show that the watermarking algorithm based WPF robustness can enhance the security of watermarking.
Trust Management represents a vital component for the protection of business transactions. This paper considers the application of a relational-based model for Trust Management in Electronic Payment Systems. We introduce a generic payment model that provides a good framework to validate our trust model. We use the special features, new extensions and relational techniques provided by the Trust Management model to specify entities, actions and security policy axioms and rules in the generic payment system. We also discuss compliance correctness issues such as security policy specification correctness and validation, certificate chain discovery and revocation as well as performance issues. Finally, we consider some implementation issues.
Security over the Internet depends on a clear distinction between authorized and un-authorized principals. Discriminating between the two involves: identification (user identifies himself/herself), authentication (the system validates the user’s identity) and authorization (specific rights granted). Thus, it is important to develop specifications for access control that realize the above properties with ease. Public Key Infrastructures (PKIs) provide a basis for specifying access-control to the users in a secure and non-reputable fashion. Some of the general deficiencies of PKIs are: (i) they are rigid and cannot scale across different PKI frameworks, (ii) due to efficiency reasons, PKIs are constrained to be just static data-structures shipped across domains and hence cannot carry any dynamic or state-based information, and (iii) for reasons of (ii) the recipients are not explicitly defined. In this paper, we shall argue that a judicious mix of digital certificates and authentication mechanisms would lead to a flexible security policy specification having both static and dynamic capabilities and lead to user-friendly mechanisms to achieve availability of secure services in e-commerce.
European, international and Internet standards are available to support electronic signatures. The most common signature formats are defined via the ASN.1 syntax with DER encoding, or the XML language. Furthermore PDF is a widespread document format with support for e-signatures. Application of signatures to e-documents must consider several aspects: long term signature validity, non-repudiation, qualified certificates, and many others. This paper focuses on the relationships among multiple documents and multiple signatures and analyses the support provided by current formats to this problem. Where lack of standardization or standard profiling is found, a proposal is made towards better application of e-signatures.
Virtual private networks (VPNs) are becoming more and more important for all kinds of businesses with a wide spectrum of applications and configurations. This paper presents the basic concepts related to VPNs. These include the different types of VPN services, namely Intranet, Extranet and Remote Access VPNs. The concept of tunneling, which is fundamental in VPNs, is discussed in great detail. The tunneling protocols that are employed by VPNs, such as PPTP, L2TP and IPSec are also presented. Furthermore, the issue of Quality of Service, QoS, support in VPN configurations is briefly
Security policies are abstract descriptions of how a system should behave to be secure. They typically express what is obligatory, permitted, or forbidden in the system. When the system is implemented, its formal verification consists in checking whether it conforms to the norms that its policy stated. Hence, security policies significantly influence the final assessment of real systems. Experience shows that important policies suffering inconsistencies have reached the final stage of implementation in a real system. Here comes the need for formal analysis at the abstract level of policies. It is advocated that known inductive techniques and a general-purpose proof assistant can be used profitably for the proof of correctness of security policies.