This document summarizes the running example used in the LINDDUN paper. Be advised that the example is based on the original LINDDUN methodology and threat trees and thus not fully maps on the current LINDDUN methodology. Nevertheless, the general ideas remain the same and thus running example provides an interesting illustration of the overall LINDDUN methodology.
Cloud computing is one of the emerging technologies that has an increasing impact on both private and public sectors. It represents an on-demand service model for delivering computing resources ranging from storage and data access, via computation and software provisioning. This chapter describes an application of Cloud Computing in home healthcare by introducing several use cases and application architecture based on the cloud. A comprehensive methodology is used to integrate security and privacy engineering process into the development lifecycle and to identify challenges for building security and privacy in the proposed cloud-based home healthcare system. Moreover, a functional infrastructure plan is provided to demonstrate the integration between the proposed application architecture with the cloud infrastructure. Finally, this chapter discusses several mitigation techniques putting the focus on patient-centric control and policy enforcement via cryptographic technologies, and consequently on digital rights management and attribute-based encryption technologies.
To address today’s major concerns of health service providers regarding security, resilience and data protection when moving on the cloud, we propose an approach to build a trustworthy healthcare platform cloud, based on a trustworthy cloud infrastructure. This paper first highlights the main security and privacy risks of market available commodity clouds, and outlines security and privacy requirements of a trustworthy health platform cloud, on top of which to deploy various health applications, in compliance with EU data protection legislation. Results from the recent EU TClouds project will be described as a possible solution towards trustworthy cloud architecture, based on a federated cloud-of-clouds, while enforcing security, resilience and data protection in various cloud layers for provisioning trustworthy IaaS, PaaS and SaaS healthcare services.
Establishing trust in systems is a difficult problem to tackle. In the Cloud, establishing trust is even more complicated considering its dynamic nature and distributed resources. One of the Cloud's potential feature is providing transparent management of resources at Cloud's infrastructure. This would hide technical complexities from Cloud's customers, which could be provided using middleware services. Establishing trustworthy middleware services would help in moving in the direction of establishing trust in the Cloud. In this paper we mainly focus on identifying the functions for establishing trustworthy middleware services for supporting home healthcare application. Specifically, we focus on the ones that are required to address the security, privacy, and resilience properties of home healthcare application.
Ready or not, the digitalization of information has come, and privacy is standing out there, possibly at stake. Although digital privacy is an identified priority in our society, few systematic, effective methodologies exist that deal with privacy threats thoroughly. This paper presents a comprehensive framework to model privacy threats in software-based systems. First, this work provides a systematic methodology to model privacy-specific threats. Analogous to STRIDE, an information flow–oriented model of the system is leveraged to guide the analysis and to provide broad coverage. The methodology instructs the analyst on what issues should be investigated, and where in the model those issues could emerge. This is achieved by (i) defining a list of privacy threat types and (ii) providing the mappings between threat types and the elements in the system model. Second, this work provides an extensive catalog of privacy-specific threat tree patterns that can be used to detail the threat analysis outlined above. Finally, this work provides the means to map the existing privacy-enhancing technologies (PETs) to the identified privacy threats. Therefore, the selection of sound privacy countermeasures is simplified.
Cloud computing is an emerging technology that is expected to support Internet scale critical applications which could be essential to the healthcare sector. Its scalability, resilience, adaptability, connectivity, cost reduction, and high performance features have high potential to lift the efficiency and quality of healthcare. However, it is also important to understand specific risks related to security and privacy that this technology brings. This paper focuses on a home healthcare system based on cloud computing. It introduces several use cases and draws an architecture based on the cloud. A comprehensive methodology is used to integrate security and privacy engineering process into the software development lifecycle. In particular, security and privacy challenges are identified in the proposed cloud-based home healthcare system. Moreover, a functional infrastructure plan is provided to demonstrate the integration between the proposed application architecture with the cloud infrastructure. Finally, the paper discusses several mitigation techniques putting the focus on patient-centric control and policy enforcement via cryptographic technologies, and consequently on digital rights management and attribute based encryption technologies.
Buyer-seller watermarking protocols incorporate digital watermarking with cryptography, in order to protect digital copyrights and privacy rights for the seller and the buyer before, during, and after trading activities in e-commerce. In this paper, we present attacks on two recently proposed buyer-seller watermarking protocols, and prove that these protocols are not able to provide security for both the buyer and the seller simultaneously. Further, we point out that both protocols don't function properly when employing homomorphic probabilistic cryptosystems. We also show that the buyer's anonymity and/or the transaction unlinkability is not achieved in these protocols. We propose an improved secure and anonymous buyer-seller protocol, which is secure and fair for both the seller and the buyer. In contrast to early work, our scheme is able to provide all the security properties that a secure buyer-seller watermarking protocol is expected to hold.
Buyer-seller watermarking (BSW) protocols allow copyright protection of digital content. The protocol is anonymous when the identity of buyers is not revealed if they do not release pirated copies. Existing BSW protocols are not provided with a formal analysis of their security properties. We employ the ideal-world/real-world paradigm to propose a formal security definition for copyright protection protocols, and we analyze an anonymous BSW protocol and prove that it fulfills our definition. Additionally, we implement the protocol and measure its efficiency.
Buyer-seller watermarking (BSW) protocols allow copyright protection of digital content. The protocol is anonymous when the identity of buyers is not revealed if they do not release pirated copies. Existing BSW protocols are not provided with a formal analysis of their security properties. We employ the ideal-world/real-world paradigm to propose a formal security definition for copyright protection protocols, and we analyze an anonymous BSW protocol and prove that it fulfills our defini- tion. Additionally, we implement the protocol and measure its efficiency. Index Terms—Buyer-seller watermarking (BSW) protocol, ideal-world/real-world paradigm.
Buyer-seller watermarking protocols integrate watermarking techniques with cryptography, for copyright protection, piracy traci ng, and privacy protec- tion. In this paper, our main contribution is the development of an efficient buyer- seller watermarking protocol based on homomorphic public-key cryptosystem, and the use of composite signal representation in the encrypted domain to re- duce both the computational overhead and the large communication bandwidth which are due to the use of homomorphic public-key encryption schemes. Both complexity analysis and simulation results confirm the effic iency of the proposed solution, suggesting that this technique can be successful ly used in practical ap- plications.
Buyer-seller watermarking protocols integrate watermarking techniques with cryptography, for copyright protection, piracy tracing, and privacy protection. In this paper, we propose an efficient buyer-seller watermarking protocol based on homomorphic public-key cryptosystem and composite signal representation in the encrypted domain. A recently proposed composite signal representation allows us to reduce both the computational overhead and the large communication bandwidth which are due to the use of homomorphic public-key encryption schemes. Both complexity analysis and simulation results confirm the efficiency of the proposed solution, suggesting that this technique can be successfully used in practical applications.
PurposeModern e‐health systems incorporate different healthcare providers in one system and provide an electronic platform to share medical information efficiently. In cross‐context communications between healthcare providers, the same information can be interpreted as different types or values, so that one patient will be issued different identifiers by different healthcare providers. This paper aims to provide a solution to ensure interoperability so that multiple healthcare providers will be able to collaborate in one e‐health system.Design/methodology/approachThis paper primarily focuses on how different healthcare providers, instead of the patients, are able to interact and share information on a common e‐health platform.FindingsIn the course of the work, it was found that previous e‐health solutions mainly have a limited view of patient information, where a user‐centric approach for identity management is usually restricted to a single healthcare provider. Interoperability in an e‐health system becomes more problematic when more actors collaborate, and hence linkability from one context to another should not be straightforward. However, some form of linkability, such as the possibility to follow up a patient's medical treatment, is desirable in the e‐health sector, even when it needs to cross different contexts. Therefore, the authors have designed an identity management mechanism to ensure semantic interoperability when data is exchanged among different authorized healthcare providers.Research limitations/implicationsThe paper points out that the next generation of e‐health will move towards federated e‐health and will require user‐centricity and transparency properties so that patients are able to specify and verify the disclosure of their medical information.Originality/valueThis paper proposes a new service for cross‐context identity management in e‐health systems, improving interoperability between agencies when context‐specific information is transferred from one healthcare provider to another. How the proposed cross‐context identity management service can be integrated in an e‐health system is explained with a use case scenario.
Buyer-seller watermarking protocols integrate multimedia watermarking and fingerprinting with cryptography, for copyright protection, piracy tracing, and privacy protection. We propose an efficient buyer-seller watermarking protocol based on dynamic group signatures and additive homomorphism, to provide all the required security properties, namely traceability, anonymity, unlinkability, dispute resolution, non-framing, and non-repudiation. Another distinct feature is the improvement of the protocol's utility, such that the double watermark insertion mechanism is avoided; the final quality of the distributed content is improved; the communication expansion ratio and computation complexity are reduced, comparing with conventional schemes.
Buyer-seller watermarking protocols incorporate digital watermarking with cryptography, in order to protect digital copyrights and privacy rights for the seller and the buyer before, during, and after purchase activities in e-commerce. In this paper, we analyze the security of some previously proposed protocols, and propose a secure and anonymous buyer-seller watermarking protocol. In contrast to early work, our improvement on the protocol's security properties ensures that the design requirements are fulfilled. The proposed protocol is able to simultaneously solve the piracy tracing problem, the customer's rights problem, the unbinding problem, the anonymity problem, the conspiracy problem, and the dispute problem. In the proposed protocol, a buyer can purchase digital contents anonymously but his anonymity can be revoked as soon as he is adjudicated to be guilty by a legal institute, such as civil court.
In electronic healthcare several research and standardization activities are emerging that promote federation. In this scenario, the medical information present at different healthcare providers, such as hospitals, general practitioners, test laboratories, etc., are shared for an improved quality of experience from the patient perspective. However, sharing of medical data on a large scale exposes the patient to several privacy-related threats, such as massive data aggregation or profiling. Therefore, the selection of a privacy-preserving identification scheme is a primary requirement in federated e-health. This paper presents an identity management infrastructure that minimizes the above-mentioned threats.
Milan Petković合作论文数Philips Research Laboratories, Koninklijke Philips Electronics N.V.;Faculty of Mathematics and Computer Science, Eindhoven University of Technology6