
We provide a symbolic model for multi-party computation based on linear secret-sharing scheme, and prove that this model is computationally sound: if there is an attack in the computational world, then there is an attack in the symbolic (abstract) model. Our original contribution is that we deal with the uniformity properties, which cannot be described using a single execution trace, while considering an unbounded number of sessions of the protocols in the presence of active and adaptive adversaries.
The ability to describe the trustworthiness of a computing device is an important part of the process to establish end-to-end trust. With the understanding that the trustworthiness of a computing device relies on its capabilities, we report on and contribute a novel causality-based model. This causality-based model represents information about the dependencies between trust notions, capabilities, computing mechanisms and their configurations. In this work, the concept of causality within the model is defined first. This involves detailing the semantic meaning of the terms used in the model. A pictorial representation is then developed to show the causal dependencies as a graph. This step specifies the vertices and edges used in the causal graph. To implement the causality-based model, the causal graph was translated into an eXtensible Markup Language schema and added to the Metadata Access Point database server of the Trusted Network Connect open architecture. Finally, the trust assessment of the causal graph is explained.
Trusted computing provides an efficient and practical way out for system security problems based on a trusted hardware, namely the root of trust, e.g., Trusted Platform Module (TPM), Trusted Cryptographic Module (TCM), Trusted Platform Control Module (TPCM), so on and so forth. However, current applications calling for trusted functions have to use either the user-space trusted interfaces (e.g., Trusted Software Stack (TSS) API) or to implement customized APIs on top of the trusted hardware driver; both of them are well known of steep learning curve, which indicates error prone and low-efficient development and complex maintenance for the application of trusted software. This paper presents a new trusted encapsulation architecture and the proof-of-concept system with the aim to mitigate the gap between the current obscure trusted APIs and the actual trusted applications for trusted software development. Our system can provide high-level and much simplified trusted transaction interfaces for user applications, which can rapidly reduce the development and maintenance work for the developers and users without too much performance costs. We also present a secure remote login use-case using mainly the binding and unbinding trusted functions of our trusted encapsulation architecture.
Software Defined Network (SDN) separates control plane from data plane and provides programmability which adds rich function for anomaly detection. In this case, every organization can manage their own network and detect anomalous traffic data using SDN architecture. Moreover, detection of malicious traffic, such as DDoS attack, would be dealt with much higher accuracy if these organizations shared their data. Unfortunately, they are unwilling to do so due to privacy consideration. To address this contradiction, we propose an efficient and privacy-preserving collaborative anomaly detection scheme. We extend prior work on SDN-based anomaly detection method to guarantee accuracy and privacy at the same time. The implementation of our design on simulated data shows that it performs well for network-wide anomaly detection with little overhead.
In this paper we introduce Threshold Public Key Encryption with Keyword Search TPEKS, a variant of PEKS where the search procedure for encrypted keywords is distributed across multiple servers in a threshold manner. TPEKS schemes offer stronger privacy protection for keywords in comparison to traditional PEKS schemes. In particularly, they prevent keyword guessing attacks by malicious servers. This protection is not achievable in a single-server PEKS setting. We show how TPEKS can be built generically from any anonymous Identity-Based Threshold Decryption IBTD, assuming the latter is indistinguishable, anonymous and robust. In order to instantiate our TPEKS construction we describe an efficient IBTD variant of the Boneh-Franklin IBE scheme. We provide an appropriate security model for such IBTD schemes and give an efficient construction in the random oracle model. TPEKS constructions are particularly useful in distributed cloud storage systems where none of the servers alone is sufficiently trusted to perform the search procedure and where there is a need to split this functionality across multiple servers to enhance security and reliability.
With the rapid development of Android-based smart phones and pads, android applications show explosive growth. Because third-party application market regulation is lax, many normal applications are embedded malicious code and then many security issues occur. The existing antivirus software cannot intercept malicious behaviors from those repackaged applications in many cases. To solve these problems, we propose a new method called RbacIP, which integrates RBAC into intercept and disposal process of malicious android applications. In RbacIP, the malicious behaviors of applications are monitored by inserting Linux kernel function call dynamically. Exploiting the Netlike technology, the information of malicious behaviors are feedback from the kernel layer to the user layer. On the user layer, depending on the roles assigned, android applications are authorized to the corresponding permissions. According to the characteristics of RBAC, it can achieve the minimum authorization for malicious applications. Meanwhile, to balance the user experience and his privacy protection needs, users are allowed to make fine-grained decision based on RBAC policy, rather than permit or prohibit. Finally, we implemented RbacIP in real android platform. Comprehensive experiments have been conducted, which demonstrate the effectiveness of the proposed method by the comparison with traditional HIPS systems at the malicious programs detection performance and resource consumption.
We introduce Attribute-Based Signatures with Controllable Linkability ABS-CL. In general, Attribute-Based Signatures allow a signer who possesses enough attributes to satisfy a predicate to sign a message without revealing either the attributes utilized for signing or the identity of the signer. These signatures are an alternative to Identity-Based Signatures for more fine-grained policies or enhanced privacy. On the other hand, the Controllable Linkability notion introduced by Hwang et al. [14] allows an entity in possession of the linking key to determine if two signatures were created by the same signer without breaking anonymity. This functionality is useful in applications where a lower level of anonymity to enable linkability is acceptable, such as some cases of vehicular ad-hoc networks, data mining, and voting schemes. The ABS-CL scheme we present allows a signer with enough attributes satisfying a predicate to sign a message, while an entity with the linking key may test if two such signatures were created by the same signer, all without revealing the satisfying attributes or the identity of the signer.
The core technique for constructing oblivious database is to get efficient implementations of oblivious transfer. This paper studies universally composable 1-out-of-n oblivious transfer (OT $$_1 ^n$$ ) in the presence of malicious adversaries under the standard cryptographic assumptions. Our oblivious transfer protocol is constructed from the Damgård and Jurik’s double trapdoor encryption scheme and the Damgård and Nielsen’s mixed commitment scheme, where the master key of the underlying double trapdoor cryptosystem is used to extract implicit input of a corrupted sender while the corresponding local keys are used to extract implicit input of a corrupted receiver. We claim that the proposed oblivious transfer framework realizes the universally composable security in the common reference model under the joint assumptions that the decisional Diffie-Hellman problem and the decisional composite residuosity problem are hard as well as all knowledge proof protocols applied are zero-knowledge.
The trusted boot is a hot spot in trusted computing field. User’s identity authentication and trusted measurement are used to deal with security threats. But it is difficult to implement the general trusted boot based on hardware, which can be bypassed easily by software. In order to solve the above problem, a scheme of trusted boot is presented based on the universal smart card. It does not change the hardware and the firmware of the smart card and the terminal device. The core method combines user’s identity authentication with trusted measurement. It binds user’s identity, smart card and terminal device to ensure the trusted boot of terminal device. The trusted computing mechanism can be extended from power on to the application layer. Ultimately, experiments prove the security of boot and simplification of the implementation.
Audit logs can be used to detect the intrusion behavior. So it has become the main target of attack invaders. The existing technologies of logging protection mainly depend on software and have some inherent defects. The actual demand from this, presents an audit logging protection mechanism based on security chip, to provide hardware protection when the log is stored and accessed. Introduction of the security chip makes the audit log to store and access are in the trusted environment, to ensure the confidentiality and integrity of the log.
In this paper, a construction of distributed multi-user, multi-key searchable encryptions is proposed and analyzed. Our scheme leverages a combination of the Shamir's threshold secret key sharing, the Pohlig-Hellman function and the ElGamal encryption scheme to provide high reliability with limited storage overhead. It achieves the semantic security in the context of the keyword hiding, the search token hiding and the data hiding under the joint assumptions that the decisional Diffie-Hellman problem is hard and the pseudo-random number generator deployed is cryptographically strong.
Partial decryption enables a ciphertext to be decrypted partially according to provided secret keys. In this paper, we propose a public key encryption scheme with the functionality of partial decryption. Our strategy is to use the NTRU cryptosystem. Under a design principle of the mathematical structure “group ring”, we extend the original NTRU into group ring NTRU (GR-NTRU). First, we propose a generic framework of our GR-NTRU. Our GR-NTRU allows partial decryption with a single encryption process using a single public key. Besides, when we execute partial decryption under a secret key of GR-NTRU, we need no information to identify each part in a whole ciphertext. Consequently, management of a public key and a corresponding set of secret keys is rather easier than the naive method. Next, we propose a concrete instantiation of our generic GR-NTRU. A multivariate polynomial ring NTRU scheme is obtained by employing a product of different cyclic groups as the basis of the group ring structure. We will show examples of those new variants of NTRU schemes with concrete parameter values, and explain how we can employ them to use the functionality of partial decryption.
To prevent worms from propagating rapidly, it is essential to generate worm signatures quickly and accurately. However, existing methods for generating worm signatures either cannot handle noise well or assume there is only one kind of worm sequence in the suspicious flow pool. We propose an approach based on seed extending signature generation SESG to generate polymorphic worm signatures from a suspicious flow pool which includes several kinds of worm and noise sequences. The proposed SESG algorithm computes the weight of every sequence, the sequences are queued based on their weight, and then classified. Worm signatures are then generated from the classified worm sequences. We compare SESG with other approaches. SESG can classify worm and noise sequences from a suspicious flow pool, and generate effective worm signatures more easily.
Aggregate signatures are digital signatures where n signers sign n individual documents and can aggregate individual signatures into a single short signature. Although aggregate signatures are expected to enhance the security of network applications, the capability and the security of aggregate signatures have not yet been discussed when the signatures are generated by a group of signers whose relationships are expressed as network. In this paper, we take into account the fact that various network applications can be mathematically idealized as network called network graphs, and discuss the properties of aggregate signatures on network graphs. We show that it is difficult to apply aggregate signatures to the network graphs. More precisely, we show that sequential aggregate signatures Eurocrypt 2004 are incompatible with the network graphs and also general aggregate signatures Crypto 2003 are broken by some generic attack. Additionally, we propose two generic approaches to overcoming the problems: restricting the number of signers and utilizing ring homomorphism, and give a security proof of aggregate signatures in each of these approaches.
In the last few years several practitioners have proposed different strategies for implementing Attribute-based credentials (ABCs) on smart cards. ABCs allow citizens to prove certain properties about themselves without necessarily revealing their full identity. The Idemix ABC is the most versatile ABC system proposed in the literature, supporting peudonyms, equality proofs of representation, verifiable encryption of attributes and proving properties of attributes via AND, NOT and OR operators. Recently, Vullers et al. and De La Piedra et al. addressed the implementation of the selective disclosure operations, pseudonyms and multi-credential proofs such as equality proofs of representation. In this manuscript, we present implementation strategies for proving properties of user attributes via these operators and show how to combine them via external and internal commitment reordering.
Security issues have become a significant barrier to the adoption of cloud computing services. Most existing security enhancements lack a well defined Root-of-Trust (RoT). Models for Trusted Clouds have been proposed, which establish RoT inside the cloud and vouch for the trustworthiness of the cloud services. However, these are often impractical due to cloud’s dynamics and complexity. In this paper, we present the NeuronVisor, an abstract Cloud Root-of-Trust (cRoT) framework. NeuronVisor enforces decentralized attestations to capture trust dependency among interacting software components inside the cloud, and determines a single cRoT for each cloud application. This cRoT hides the cloud’s internal by presenting a uniform interface for attesting to the trustworthiness of the entire cloud application and all its dependent services inside the cloud (the Cloud TCB). Our simulations show that, for more than 98 % times, one interrogation to the dynamically formed cRoT is able to identify the properties of more than 90 % of the nodes hosting a cloud application and its cloud TCB. Meanwhile, NeuronVisor achieves higher fault detection rate than the prevalent centralized cloud attestation scheme (CEN). It still achieves the same fault detection rate with CEN even when 90 % of the NeuronVisors are constantly tampered with and maliciously collaborating with each other.
Piccolo is a 64-bit lightweight block cipher proposed by SONY corporation to be used in the constrained environments such as wireless sensor net work environments. In this paper, by algebraic analysis, we give some observations on Piccolo, including the linear analysis of the F-function, and a weakness of key scheduling. We found that the F-function could be matched with linear permutation with high probability. We revealed the statistical character of the F-function, which gives the attackers chance to distinguish piccolo from random permutation. We attack two rounds Piccolo-80 with the computational complexity 2 17 two rounds Piccolo-80 encryptions. We found that the subkeys in last two rounds of Piccolo-80 do not play the roles of hide information of internal states well, 16 bits of cipher text can be represented by the state of last but one round.
Recently, more and more enterprises and individuals have moved their data into the cloud. To meet this practical requirement, this paper addresses how to establishes a bridge between role-based access control (RBAC) and cloud storage in order to fully preserve investment in existing RBAC systems. We present a new scheme for secure migrating the resources from RBAC systems to cloud storage. This scheme takes full advantage of RBAC, which provides a well-designed and easy-to-manage approach for accessing cloud resources without user intervention. This scheme, called Partially-ordered Hierarchical Encryption (PHE), which implements the partial-order key hierarchy, similar to role hierarchy in RBAC, in public-key infrastructure. In addition, this construction provides traitor tracing to support efficient digital forensics. The performance analysis shows that our construction has following features: dynamic joining and revoking users, constant-size ciphertexts and decryption keys, and lower overloads for large-scale systems.