Home     Top: Security: Access Control    [Access Control   Encryption   Information Warfare   Intellectual Property Protection   Intrusion Detection]

Change ordering:   Authority   Hubs (tutorials)   Date   Expected authority       Show titles only
Reverse date order

This directory is created automatically and some papers may be mislabeled. Only document within the CiteSeer database are listed. The directory is intended to provide entry points for browsing the database and is not intended to be authoritative. Papers may not appear in all relevant categories. For example, papers in a sub-category may not appear in higher level categories.

Theories and Models for Internet Quality of Service - Firoiu, Le Boudec, Towsley, Zhang (2002)   (Correct)
We survey recent advances in theories and models for Internet Quality of Service (QoS). We start with the theory of network calculus, which lays the foundation for support of deterministic performance... /

Language-Based Information-Flow Security - Sabelfeld, Myers (2002)   (Correct)
Current standard security practices do not provide substantial assurance that the end-to-end behavior of a computing system satisfies important security policies such as confidentiality. An end-to-end... / Language-Based Information-Flow Security Andrei Sabelfeld and Andrew C.

Towards An Extensible Virtual Machine - Boyapati (2002)   (Correct)
The Java Virtual Machine Language (JVML) is rapidly emerging as the de-facto standard for representing portable code and Java Virtual Machines (JVMs) are increasingly being used as standard platforms ... / of the JVM platform is its security. JVML is a type safe language. br to provide ne-grained access control. Code from multiple

Gothic: A Group Access Control Architecture for Secure Multicast and.. - Judge, Ammar (2002)   (Correct)
Multicast and anycast have received considerable attention due to their ability to support networked services. There are distinct and significant security vulnerabilities in both the multicast and any... / are distinct and significant security vulnerabilities in both the br Gothic A Group Access Control Architecture for Secure

A Simple View of Type-Secure Information Flow in the pi-Calculus - Pottier (2002)   (Correct)
One way of enforcing a mandatory access control policy is to use a static type system capable of guaranteeing a non-interference property. Non-interference states that two processes with distinct ... / mandatory access control security policies e.g. to prevent secret br way of enforcing a mandatory access control policy is to use a static

Declarative Update Policies for Nonmonotonic Knowledge Bases - Eiter, al. (2002)   (Correct)
Updating databases, and in particular relational databases, is a central issue which has been well-studied in the database field for many years, and solutions have been incorporated into commercial ... / area of network management and security For nonmonotonic br . . Access control policies .

Information Fusion and Person Verification Using Speech & Face.. - Sanderson, Paliwal (2002)   (Correct)
This report provides an overview of important concepts in the field of information fusion, followed by a review of literature pertaining to audio-visual person identification & verification. Several r... /

Giggle: A Framework for Constructing Scalable Replica Location.. - Chervenak, Deelman, Foster, Guy.. (2002)   (Correct)
This paper makes the following contributions to our understanding of Data Grid systems and data replication: . We introduce the notion of a RLS as a distinct component and characterize RLS requiremen... / of scalability reliability and security-concerns that arise in br the LRC may be subject to access control and therefore must support

Static Confidentiality Enforcement for Distributed Programs - Sabelfeld, Mantel (2002)   (Correct)
Preserving the con dentiality of data in a distributed system is an increasingly important problem of current security research. unknown Static Con dentiality Enforcement for Distributed Programs ... / important problem of current security research. Distributed

A Security Architecture for Application Session Handoff - Skow, Kong, Phan, Cheng, Guy.. (2002)   (Correct)
Ubiquitous computing across a variety of wired and wireless connections still lacks an effective security architecture. In our research work, we address the specific issue of designing and building a ... /

Trustless Grid Computing in ConCert - Chang, Crary, DeLap, Harper, Liszka, .. (2002)   (Correct)
We believe that fundamental to the establishment of a grid computing framework where all (not just large organizations) are able to effectively tap into the resources available on the global network i... /

Guardians for Ambient-Based Monitoring - Ferrari, Moggi, Pugliese (2002)   (Correct)
In the Mobile Ambients of Cardelli and Gordon an ambient is a unit for mobility, which may contain processes (data) and sub-ambients. Since the seminal work of Cardelli and Gordon, several ambient-bas... /

Active Certificates: A Framework for Delegation - Borisov, Brewer (2002)   (Correct)
In this paper, we present a novel approach to delegation in computer systems. We exploit mobile code capabilities of today's systems to build active certificates: cryptographically signed mobile agent... / for the task at hand. This security concern is especially relevant in br of rights involves weakening access control restrictions that would

Nodes Bearing Grudges: Towards Routing Security, Fairness, and.. - Buchegger, Le Boudec (2002)   (Correct)
Nodes in mobile ad hoc networks do not rely on a central infrastructure but relay packets originated by other nodes. Mobile ad hoc networks can work properly only if the participating nodes cooperate ... /

Vigil: Providing Trust for Enhanced Security in Pervasive Systems - Kagal, Undercoffer, Perich, Joshi.. (2002)   (Correct)
Computing today is moving away from the desktop, becoming diffused into our surroundings and onto our personal digital devices. Moreover, ad-hoc networks such as Bluetooth provide for spontaneous con... / Providing Trust for Enhanced Security in Pervasive Systems Lalana br on user authentication and access control to provide security. These

Bytecode verification on Java smart cards - Leroy (2002)   (Correct)
This article presents a novel approach to the problem of bytecode verification for Java Card applets. By relying on prior off-card bytecode transformations, we simplify the bytecode verifier and reduc... /

Transactional Rollback for Language-Based Systems - Rudys, Wallach (2002)   (Correct)
Language run-time systems are routinely used to host potentially buggy or malicious codelets --- software modules, agents, applets, etc. --- in a secure environment. A number of techniques exist for m... /

ConChord: Cooperative SDSI Certificate Storage and Name Resolution - Ajmani, Clarke, Moh, Richman (2002)   (Correct)
SDSI is a proposed public key infrastructure that allows principals to define local names and link their namespaces to delegate trust. Unlike DNS, SDSI's egalitarian design resists deployment on tradi... /

Proxy-Based Security Protocols in Networked Mobile Devices - Burnside, Clarke, Mills, Devadas.. (2002)   (Correct)
We describe a resource discovery and communication system designed for security and privacy. All objects in the system, e.g., appliances, wearable gadgets, software agents, and users have associated t... /

Linux Security Modules: General Security Support for the Linux Kernel - Wright, Cowan, Morris (2002)   (Correct)
The access control mechanisms of existing mainstream operating systems are inadequate to provide strong system security. Enhanced access control mechanisms have failed to win acceptance into mainstrea... / Linux Security Modules General Security

A Law-Abiding Peer-to-Peer Network for Free-Software Distribution - Bakker, van Steen, Tanenbaum (2002)   (Correct)
The Globe Distribution Network (GDN) is an application for worldwide distribution of freely redistributable software packages. The GDN takes a novel, optimistic approach to stop the illegal distributi... / users high communication delays security threats and machine and network br Service gids The Gdn Access Control Service gdn Acs Is A

Efficient Frequency Domain Selective Scrambling of Digital Video - Zeng, Lei (2002)   (Correct)
Multimedia data security is very important for multimedia commerce on the Internet such as videoon -demand and real-time video multicast. Traditional cryptographic algorithms/systems for data security... / ABSTRACT Multimedia data security is very important for multimedia br Multimedia security contents access control video scrambling multimedia

Scheduling Under Uncertainty: Planning for the Ubiquitous Grid - Sample, Keyani, Wiederhold (2002)   (Correct)
Computational Grid projects are ushering in an environment where clients make use of resources and services that are far too expensive for single clients to manage or maintain. Clients compose a megap... /

Strong Security for Network-Attached Storage - Miller, Freeman, Long, Reed (2002)   (Correct)
We have developed a scheme to secure networkattached storage systems against many types of attacks. Our system uses strong cryptography to hide data from unauthorized users; someone gaining complete a... /

STAR: Secure Real-Time Transaction Processing with Timeliness.. - Kang, Son, Stankovic (2002)   (Correct)
Real-time databases are needed in security-critical applications, e.g., e-commerce, agile manufacturing, and military applications. In these applications, transactions and data items can be classified... / Real-time databases are needed in security-critical applications e.g. br In our approach mandatory access control mechanisms are applied for

Towards an Access Control Mechanism for Wide-area Publish/Subscribe.. - Miklos (2002)   (Correct)
The publish/subscribe communication model is increasingly considered for implementing middleware infrastructures for widely distributed applications. Scalability issues and routing algorithms of such ... / attention has been given to security and management issues. In br Towards an Access Control Mechanism for Wide-area

A Community Authorization Service for Group Collaboration - Pearlman, Von Welch, Foster.. (2002)   (Correct)
In "Grids" and "collaboratories," we find distributed communities of resource providers and resource consumers, within which often complex and dynamic policies govern who can use which resources for w... /

A General and Flexible Access-Control System for the Web - Bauer, Schneider, Felten (2002)   (Correct)
We describe the design, implementation, and performance of a new system for access control on the web. To achieve greater flexibility in forming accesscontrol policies -- in particular, to allow bette... /

On Probabilistic Combination of Face and Gait Cues for Identification - Shakhnarovich, Darrell (2002)   (Correct)
We approach the task of person identification based on face and gait cues. The cues are derived from multiple simultaneous camera views, combined through the visual hull algorithm to create imagery in... / activity monitoring and covert security and access control can all br and covert security and access control can all benefit from

A Calculus for Composing Security Policies - Bauer, Ligatti, Walker (2002)   (Correct)
A runtime monitor is a program that runs in parallel with an untrusted application and examines actions from the application's instruction stream. If the sequence of program actions deviates from a sp... /

Using Process Models to Analyze Health Care Security Requirements - Rohrig (2002)   (Correct)
Even though most information systems need to be secured in a cost-effective manner, "appropriate" security is difficult to specify. This article presents an approach to re-use existing business proces... /

Exploring the Design Space of Distributed and Peer-to-Peer Systems.. - Stefan Saroiu Krishna (2002)   (Correct)
Despite the existence of many peer-to-peer systems, some of their design choices and implications are not well understood. This paper compares several distributed and peer-to-peer systems by evaluatin... /

Denali: A Scalable Isolation Kernel - Whitaker, Shaw, Gribble (2002)   (Correct)
The Denali project provides system support for running several mutually distrusting Internet services on the same physical infrastructure. For example, this would enable a developer to push dynamic co... /

Structural Constraints For Noise Resistant Multi-Modal Verification - Sanderson (2002)   (Correct)
In this paper we propose a piece-wise linear classifier for use as the decision stage in a two-modal verification system, comprised of a face and a speech expert. unknown STRUCTURAL CONSTRAINTS FOR NO... /

Energy-Aware Routing in Cluster-Based Sensor Networks - Younis, Youssef, Arisha (2002)   (Correct)
Recently there has been a growing interest in the applications of sensor networks. Since sensors are generally constrained in on-board energy supply, efficient management of the network is crucial in ... / such as combat field surveillance security and disaster management. These br time-based approach for media access control that enables the maintenance

Polynomial Features For Robust Face Authentication - Sanderson, Paliwal (2002)   (Correct)
In this paper we introduce the DCT-mod2 facial feature extraction technique which utilizes polynomial coefficients derived from 2-D DCT coefficients of spatially neighbouring blocks. We evaluate its r... /

Meta-Policies for Distributed Role-Based Access Control Systems - Belokosztolszki, Moody (2002)   (Correct)
In this paper meta-policies for access control policies are presented. There has been a lot of research into the various ways of specifying policy for a single domain. Such domains are autonomous and ... /

Likelihood Normalization For Face Authentication In Variable.. - Sanderson, Paliwal (2002)   (Correct)
In this paper we evaluate the effectiveness of two likelihood normalization techniques, the Background Model Set (BMS) and the Universal Background Model (UBM), for improving performance and robustnes... /

Towards Practical Automated Trust Negotiation - Winsborough, Li (2002)   (Correct)
Exchange of attribute credentials is a means to establish mutual trust between strangers that wish to share resources or conduct business transactions. Automated Trust Negotiation (ATN) is an approach... / them belong to different security domains controlled by different br sensitive credentials by using access control policies. Existing ATN work

Scalable Management and Data Mining using Astrolabe - van Renesse, Birman (2002)   (Correct)
this paper, we describe a new information management service called Astrolabe. Astrolabe monitors the dynamically changing state of a collection of distributed resources, reporting summaries of this i... /

UMLsec: Extending UML for Secure Systems Development - Jürjens (2002)   (Correct)
Developing secure-critical systems is difficult and there are many well-known examples of security weaknesses exploited in practice. Thus a sound methodology... unknown UMLsec: Extending UML for Secu... / are many well-known examples of security weaknesses exploited in practice. br FH de nes role-based access control rights from object-oriented

Authorization And Access Control Of Application Data In Worlflow.. - Wu, Sheth, Miller, Luo (2002)   (Correct)
Worlcfiow Management Systems (WJMSs) are used to support the modeling and coordinated execution of business processes within an organization or across organizational boundaries. Although some research... /

PAMINA: A Certificate Based Privilege Management System - Nochta, Ebinger, Abeck (2002)   (Correct)
In this paper we present PAMINA (Privilege Administration and Management INfrAstructure), a privilege management system using authorization certificates. Our system supports distributed environments w... / the development of different security systems and services which are br need not to be involved in the access control decision process. PAMINA

Coalition Signature Scheme in Multi-agent Systems - Yiming Ye Ibm (2002)   (Correct)
The Internet will never reach its full potential as an electronic marketplace unless e-commerce agents, or proactive Web Programs, are used to automatically or semi-automatically perform e-commerce ta... /

Implementing Policies in Programs using - Labelled Transition Systems (2002)   (Correct)
This paper describes our current work on programming language support for policy specification and implementation. The aim of this work is to design language mechanisms that enable program behaviour t... /

A Security Architecture Based on Trust Management for Pervasive.. - Systems Lalana Kagal (2002)   (Correct)
Traditionally, stand-alone computers and small networks rely on user authentication and access control to provide security. These physical methods use system-based controls to verify the identity of a... /

Developing Secure Agent Systems Using Delegation Based Trust.. - Kagal, Finin, Joshi (2002)   (Correct)
We present an approach to some security problems in multi-agent systems based on distributed trust and the delegation of permissions, and credibility. We assume an open environment in which agents mus... /

Security Requirements Engineering : When Anti-requirements Hit the Fan - Crook, Ince, Lin, Nuseibeh (2002)   (Correct)
Everyone agrees that security is a problem, ranging from Microsoft to the banks that have been recent victims of rogue traders. What is paradoxical is that there does not seem to be a wholehearted com... /

Security Architectures Revisited - Härtig (2002)   (Correct)
The knowledge in technologies needed to build secure platforms, or Security Architectures, has significantly matured over the recent years. These include small interface technologies, access-control c... /

More Enforceable Security Policies - Bauer, Ligatti, Walker (2002)   (Correct)
We analyze the space of security policies that can be enforced by monitoring programs at runtime. Our program monitors are automata that examine the sequence of program actions and transform the seque... /

A Protocol to Improve the State Scalability of Source Specific.. - Cui, Maggiorini, Kim, Boussetta.. (2002)   (Correct)
Source Specific Multicast (SSM) is a viable solution for current multicast applications, since the driving applications to date are one to many, including Internet TV, distance learning, file distribu... / billing address allocation and security. However SSM still confronts the br gives a better solution to the access control problem. When a receiver

Aspect-oriented Composition in Extensible Collaborative Applications - Barthelmess, Ellis (2002)   (Correct)
We describe the coordination model of the Neem Platform, a research test bed for Project Neem, concerned with the development of socially and culturally aware collaborative systems in a wide range of ... /

Specifying and Analysing Trust for Internet Applications - Grandison, Sloman (2002)   (Correct)
Key words: The Internet is now being used for commercial, social and educational interactions, which previously relied on direct face-to-face contact in order to establish trust relationships. Thus, ... / of supporting different types of security policy Applications will br are aimed at authentication or access control whereas we are aiming at a

The CVS-Server Case Study: - Formalized Security Architecture (2002)   (Correct)
Achim D. Brucker, Frank Rittinger, and Burkhart Wol# {brucker,rittinge,wolff}@informatik.uni-freiburg.de 1 unknown The CVS-Server Case Study: A Formalized Security Architecture Extended /

Hiding a Face in a Fingerprint Image - Jain, Uludag, Hsu (2002)   (Correct)
With the wide spread utilization of biometric identification systems, establishing the authenticity of biometric data itself has emerged as an important research issue. We present a fingerprint image ... /

The BANCA Database and Experimental Protocol for Speaker Verification - Porée, Mariéthoz, Bengio, al. (2002)   (Correct)
Identity verification has become a very important research topic recently, particularly using methods based on the face or the voice of the individuals. In the context of the BANCA european project, a... / project is to obtain an enhanced security system by combining classical br authentication and access control schemes for applications over

A Grid Monitoring Architecture - Tierney, Aydt, Gunter, Smith, Swany, .. (2002)   (Correct)
Large distributed systems such as Computational and Data Grids require that a substantial amount of monitoring data be collected for various tasks such as fault detection, performance analysis, perfor... /

Unknown - Infrastructure For Service (2002)   (Correct)
Security is paramount to the success of pervasive computing environments. The system presented in this paper provides a communications and security infrastructure that goes far in advancing the goal o... /

SINS: A Middleware for Autonomous Agents and Secure - Code Mobility In (2002)   (Correct)
Ramesh Bharadwaj Center for High Assurance Computer Systems Naval Research Laboratory Washington, DC, 20375-5320 USA ramesh@itd.nrl.navy.mil 1. unknown SINS: A Middleware for Autonomous Agents a... /

Online Workspaces for Annotation and Discussion of Documents - Toshiyuki Takeda Center (2002)   (Correct)
Pink is a system that supports threaded discussions about artifacts (such as source code or security bulletins) by making it easy for users to refer to and annotate parts of the artifacts. This system... /

An Authorization Control Framework to Enable Service Composition.. - Takashi Suzuki University (2002)   (Correct)
This paper contributes a comprehensive authorization control framework that enables service composition across administrative domains. The first feature of the proposed framework is a generic authoriz... /

PKI based Access Control with Attribute-Certificates for Data hold on .. - Suhrbier, Hildmann (2002)   (Correct)
Common smartcard systems are not capable of providing effective Data Access Control in distributed IT-infrastructures with high configuration dynamics. The crucial points of that approach are resource... /

Storage Area Networks and the High Performance Storage System - Harry Hulen And (2002)   (Correct)
The High Performance Storage System (HPSS) is a mature Hierarchical Storage Management (HSM) system that was developed around a network-centered architecture, with client access to storage provided th... /

High Router Flexibility and Performance by Combining Dedicated Lookup .. - Duret, Rischette, Lattmann.. (2002)   (Correct)
In this paper we propose a new router architecture that combines both flexibility and performance. This router architecture aims at combining the best of two worlds: the commercial routers, which ha... /

Security Attributes Based Digital Rights Management - Chong, van Buuren, Hartel, Kleinhuis (2002)   (Correct)
di#erent authorities. We apply this model to a digital rights management system, to achieve flexible security. In our model a hierarchy of authorities issues certificates that are linked by cryptograp... /

A dynamic service delivery framework based on the OSGi model - Vos, Buytaert, Buytaert (2002)   (Correct)
Many services that were previously offered only on a specific device, now have become available on a wide range of devices. For example, E-mail is not only checked on a PC anymore, E-mail clients also... /

AWeb-based System for Prevention of - Information Leakage Yasuhiro (2002)   (Correct)
In this paper, we propose a web-based system for prevention of the confidential information leakage caused by the person who is authorized to access. This system realizes the centralized access contro... /

From Protocol Stack to Protocol Heap - Role-Based Architecture - Braden, Faber, Handley (2002)   (Correct)
Questioning whether layering is still an adequate foundation for networking architectures, this paper investigates non-layered approaches to the design and implementation of network protocols. The goa... / layer . and Transport-Layer Security at layer . For br them unnecessary and suitable access controls over metadata can make them

Compressed Accessibility Map: Efficient Access Control for XML - Yu, Srivastava, Lakshmanan (2002)   (Correct)
XML is widely regm'ded as a promising memm for data representation integq'ation, md exchmge. As compmfies trmmact business over the Internet, the sensitive nature of the information mmdates that a... / it raises the question of security. Given the sensitive nature of br Accessibility Map Efficient Access Control for XML Ting Yu

Platform for Enterprise Privacy Practices: Privacy-enabled Management .. - Karjoth, Schunter, Waidner (2002)   (Correct)
Enterprises collect a large amount of personal data about their customers. unknown Platform for Enterprise Privacy Practices: Privacy-enabled Management of Customer Data G unter Karjoth, Matthias Sc... /

Reasoning about Joint Administration of Access Policies for Coalition .. - Khurana, Gligor, Linn (2002)   (Correct)
Virgil Gligor University of Maryland College Park, MD gligor@eng.umd.edu John Linn RSA Laboratories Bedford, MA jlinn@rsasecurit.com We argue that joint administration of access policies for a... / Area distributed systems security network protocols. . br relations we extend existing access control logics and show that the

A New Avenue of Attack: Event-driven System Vulnerabilities - Xenitellis (2002)   (Correct)
Hacker Warfare is the type of Information Warfare that involves the inflicting of damage to the digital infrastructure of the enemy by exploiting security vulnerabilities. In this paper we discuss for... /

A Survey of Policy Specification Approaches - Damianou, Bandara, Sloman, Lupu (2002)   (Correct)
Policies are rules governing the choices in behaviour of a system. They are often used as a means of implementing flexible and adaptive systems for management of internet services, distributed systems... / distributed systems and security systems. There is also a need for br systems where access control is implemented in a variety of

The HP Time Vault Service: Innovating the Way Confidential.. - Mont, Harrison, Sadler (2002)   (Correct)
This paper focuses on the problem of protecting confidential information from unauthorized disclosures, subject to time-based criteria: it is a common issue in the industry, government and day-to-day ... / has strong implication in term of security and privacy. In involves the br conditions and constraints access control the satisfaction of trading

Access Control Lists for the Self-Certifying Filesystem - Savvides (2002)   (Correct)
The Self-certifying File System (SFS) currently exports Unix filesystems. Consequently, file owners on SFS servers who want to give other users access to their files can do so only through the coarse-... /

Offering a Multicast Delivery Service in a Programmable Secure IP VPN .. - Alchaal, Roca, Habert (2002)   (Correct)
The programmable network approach is one possible solution to quickly adapt existing infrastructures to new requirements. This paper shows how programmable networking can be exploited within a VPN env... / How The Ip Vpn Approach O oads Security Management And Administration br only include authentication and access control but also the cryptographic

Lightweight Flexible Isolation for Language-based Extensible Systems - Daynès, Czajkowski (2002)   (Correct)
Safe programming languages encourage the development of dynamically extensible systems, such as extensible Web servers and mobile agent platforms. Although protection is of utmost importance in th... / includes programmable built-in security mechanisms that programmers can br invocation and by introducing access control on the latter BR RSC

A Framework for Smart Proxies and Interceptors in RMI - Santos, Marques, Silva (2002)   (Correct)
The Java Remote Method Invocation (RMI) API shields the developer from the details of distributed programming, allowing him to concentrate on application specific code. But to perform some operations ... / QoS fault tolerance and security sometimes it is necessary to br authentication and fine-grained access control in RMI. Keywords Java

Fast Inter-Ap Handoff Using Predictive Authentication Scheme in a.. - Pack, Choi (2002)   (Correct)
this paper, we proposed a fast Inter-AP handoff scheme based on a predictive authentication method. In our scheme, a mobile host entering the area covered by an AP, performs authentication procedur... / mechanism. In terms of security it is suggested that the br areas requires a system of access control for unauthorized users. In

Fine-Grain Authorization for Resource Management in The Grid.. - Keahey, Welch (2002)   (Correct)
In this document we describe our work-in-progress for enabling fine-grain authorization of resource management. In particular we address the needs of Virtual Organizations O/Os) to enforce their ow... / using GRAM and the Grid Security Infrastructure mechanisms. br user's grid credential and an access control list contained in a

Advanced Business Models And Flexible Service Provision For.. - Houssos, Panagiotakis, Gazis.. (2002)   (Correct)
Reconfigurability is an important aspect of future mobile systems. It has enabled and introduced innovative perspectives in service provision. The support of advanced business models and flexible serv... /

Can the same directory structure fulfill the requirements ofor the .. - Julien (2002)   (Correct)
uthor The author reserves other publication rights, an neither the research project nor extensive extracts from it may be printed or otherwise reproduced without the authors written permission.... /

Gridella: an open and efficient Gnutella-compatible Peer-to-Peer.. - Schmidt (2002)   (Correct)
This thesis describes the Peer-to-Peer Application Gridella. The decentralized architecture of P2P systems enables each peer to fulfill search requests solely by local interactions. The system describ... /

A Privacy Policy Model for Enterprises - Karjoth, Schunter (2002)   (Correct)
Privacy is an increasing concern in the marketplace. Although enterprises promise sound privacy practices to their customers, there is no technical mechanism to enforce them internally. In this paper,... /

Cryptology and Physical Security: Rights Amplification in.. - Blaze (2002)   (Correct)
This paper describes new attacks for amplifying rights in mechanical pin tumbler locks. Given access to a single master-keyed lock and its associated change key, an procedure is given that allows di... /

Secure Method Invocation in Jason - Brinkman, Hoepman (2002)   (Correct)
In this paper we describe the Secure Method Invocation (SMI) framework implemented for Jason, our Javacard As Secure Objects Networks platform. Jason realises the secure object store paradigm, that re... /

Design of the Local Authorization Checker - Abghour, Deswarte, Nicomette, Powell (2002)   (Correct)
this report, we have described the functions of the local authorization checker to be located on every host participating in a MAFTIA application, whether the host is a personal workstation or a serve... /

Resource Annotation Framework in a Georeferenced and Geospatial.. - Liu, Lim, Goh (2002)   (Correct)
G-Portal is a georeferenced and geospatial digital library that aims to identify, classify and organize geospatial and georeferenced resources on the web and to provide digital library services for th... /

Preface: Proceedings of the ICDM 2002 Workshop on Privacy, Security.. - Estivill-Castro, Clifton (2002)   (Correct)
This paper appeared at IEEE International Conference on Data Mining Workshop on Privacy, Security, and Data Mining, Maebashi City, Japan. Conferences in Research and Practice in Information Techno... /

Security in the Jini Networking Technology: A Decentralized Trust.. - Eronen (2001)   (Correct)
OF TECHNOLOGY MASTER'S THESIS Author: Pasi Eronen Title: Security in the Jini Networking Technology: A Decentralized Trust Management Approach Date: March 6, 2001 Pages: 8 + 60 Department: Depa... / Engineering Pasi Eronen Security In The Jini Networking

Authenticity by Typing for Security Protocols - Gordon, Jeffrey (2001)   (Correct)
We propose a new method to check authenticity properties of cryptographic protocols. First, code up the protocol in the spi-calculus of Abadi and Gordon. Second, specify authenticity properties by ann... / Authenticity by Typing for Security Protocols Andrew D. Gordon br Nec GS for checking access control HR SS and most

Principles of Policy in Secure Groups - Harney, Colgrove, McDaniel (2001)   (Correct)
Security policy is increasingly being used as a vehicle for specifying complex entity relationships. When used to define group security, policy must be extended to state the entirety of the security c... / Abstract Security policy is increasingly being used br the group audit group monitor access control messages or membership

MSR, Access Control, and the Most Powerful Attacker - Cervesato (2001)   (Correct)
Most systems designed for the verification of security protocols operated under the unproved assumption that an attack can only result from the combination of a fixed number of message transformations... / designed for the verification of security protocols operated under the br MSR Access Control and the Most Powerful

The Active Process Interaction with its Environment - Kornblum, Raz, Shavitt (2001)   (Correct)
Adding programmability to the interior of the network provides an infrastructure for distributed applications. Speci cally, network management and control applications require access to and contro... / and application exibility vs. security. We demonstrate the advantages br have complete monitoring and control access over all active sessions to

Decentralized Jini Security - Eronen, Nikander (2001)   (Correct)
Among the different approaches to distributed computing, the Jini technology provides a number of very promising methods for attacking the fundamental problems involved. Programs built according to th... / Decentralized Jini Security Pasi Eronen and Pekka Nikander

Generating Wrappers for Command Line Programs: The Cal-Aggie.. - Wohlstadter, Jackson, Devanbu (2001)   (Correct)
Software developers writing new software have strong incentives to make their products compliant to standards such as corba, com, and JavaBeans. Standards-compliance facilitates inter-operability, com... / mediated by corba- compliant security services. While CAWOM has some br implement far more intricate access control policies. Our research goal

Typed MSR: Syntax and Examples - Cervesato (2001)   (Correct)
Many design flaws and incorrect analyses of cryptographic protocols can be traced to inadequate specification languages for message components, environment assumptions, and goals. In this paper, we pr... / typed specification language for security protocols which is intended br that include type-checking and access control validation. It uses multiset

A Specification Language for Crypto-Protocols based on Multiset.. - Cervesato (2001)   (Correct)
MSR is an unambiguous, flexible, powerful and relatively Submitted to the Seventeenth Conference on the Mathematical Foundations of Programming Semantics --- MFPS-XVII, Aarhus, Denmark, 24--27 May 200... / known as the Dolev-Yao model of security the cryptography is br that include type-checking and access control. In this paper we give a

Limiting the Disclosure of Access Control Policies during Automated.. - Seamons, Winslett, Yu (2001)   (Correct)
Automated trust negotiation is a new approach to establishing trust between strangers through the exchange of property-based digital credentials, and the use of mobile access control policies that spe... / than is possible with traditional security approaches that are based on br Limiting the Disclosure of Access Control Policies during Automated

The Ponder Policy Specification Language - Damianou, Dulay, Lupu, al. (2001)   (Correct)
The Ponder language provides a common means of specifying security policies that map onto various access control implementation mechanisms for firewalls, operating systems, databases and Java. It ... / a common means of specifying security policies that map onto various br policies that map onto various access control implementation mechanisms for

Untrusted Hosts and Confidentiality: Secure Program Partitioning - Zdancewic, Zheng, Nystrom, Myers (2001)   (Correct)
This paper presents secure program partitioning, a language-based technique for protecting confidential data during computation in distributed systems containing mutually untrusted hosts. Confidential... / by annotating programs with security types that constrain information

Secure Information Flow and CPS - Zdancewic, Myers (2001)   (Correct)
Security-typed languages enforce secrecy or integrity policies by type-checking. This paper investigates continuation-passing style as a means of proving that such languages enforce non-interference... / Abstract. Security-typed languages enforce secrecy br because unlike ordinary access control static information flow can

The Anatomy of the Grid - Enabling Scalable Virtual Organizations - Foster, Kesselman, Tuecke (2001)   (Correct)
Grid" computing has emerged as an important new field, distinguished from conventional distributed computing by its focus on large-scale resource sharing, innovative applications, and, in some cases, ... / VOs. These technologies include security solutions that support management br and multi-stakeholder access control delegation and application

Systematic Construction of Security Types - Pottier, Skalka, Smith (2001)   (Correct)
The Java JDK 1.2 Security Architecture includes a dynamic mechanism for enforcing access control checks, so-called stack inspection. This paper studies type systems which can statically guarantee ... / Systematic Construction of Security Types Franois Pottier br mechanism for enforcing access control checks so-called stack

An Access Control Architecture for Programmable Routers - Jun Gao Peter (2001)   (Correct)
Programmable networks allow the router's functionality to be extended dynamically through the use of active extensions. This flexible architecture facilitates the deployment of new network protocols a... / also raises serious safety and security concerns. These concerns must be br An Access Control Architecture for Programmable

Grid Information Services for Distributed Resource Sharing - Czajkowski, Fitzgerald, Foster.. (2001)   (Correct)
Grid technologies enable large-scale sharing of resources within formal or informal consortia of individuals and/or institutions: what are sometimes called virtual organizations. In these settings, th... / that addresses performance security scalability and robustness br for authentication and access control to information. Our

Micro-Mobility within Wireless Ad Hoc Networks: Towards Hybrid.. - Typpö (2001)   (Correct)
This work studies two different approaches for mobile networking and examines the integration of them. Protocol proposals for micro-mobility management within wireless access networks on the edge of t... / Source Routing ESP Encrypted Security Payload FA Foreign Agent FORP br Care-of-Address MAC Medium Access Control MACA Multiple Access with

A Survey of Energy Efficient Network Protocols for Wireless Networks - Jones, Sivalingam, Agrawal, Chen (2001)   (Correct)
Wireless networking has witnessed an explosion of interest from consumers in recent years for its applications in mobile and personal communications. As wireless networks become an integral component ... / for wireless link error control security encryption decryption br the data link layer the media access control MAC protocol layer is

Java bytecode verification: an overview - Leroy (2001)   (Correct)
Bytecode verification is a crucial security component for Java applets, on the Web and on embedded devices such as smart cards. This paper describes the main bytecode verification algorithms and surve... / Bytecode veri cation is a crucial security component for Java applets on br and implementing a suitable access control policy The

SIP: Session Initiation Protocol - Handley, Schulzrinne, Schooler.. (2001)   (Correct)
The Session Initiation Protocol (SIP) is an application-layer control (signaling) protocol for creating, modifying and terminating sessions with one or more participants. These sessions include Intern... /

LegionFS: A Secure and Scalable File System Supporting Cross-Domain.. - White, Walker, Humphrey, Grimshaw (2001)   (Correct)
Realizing that current file systems can not cope with the diverse requirements of wide-area collaborations, researchers have developed data access facilities to meet their needs. Recent work has focus... / the fundamental tenets of naming security scalability extensibility and br controlled by fine-grained Access Control Lists ACLs The security

Applying decentralized trust management to DNS dynamic updates - Eronen, Sars (2001)   (Correct)
DNS dynamic updates can be used to modify the data of a DNS zone. This can be used to update DNS records of hosts with dynamic IP addresses, for example. DNS dynamic updates can be authenticated using... / been a good example of the lack of security in the basic Internet br restrictions than the use of access control lists. Introduction DNS

The Price of Safety in an Active Network - Alexander, Menage, Keromytis.. (2001)   (Correct)
Security is a major challenge for "Active Networking", as accessible programmability creates numerous opportunities for mischief. The point at which programmability is exposed, e.g., through the loadi... / and Jonathan M. Smith Abstract Security is a major challenge for Active br and integrity resource and access control and name-space protection.

A Proposal for A Scalable Internet Multicast Architecture - Shi (2001)   (Correct)
We propose a new network and system architecture for multicast in the Internet. Our main objectives are to find a cost-effective way to scale to a large number of multicast groups whose members are ge... / of the IP multicast model raises security concerns since it magni es the br of IP multicast lacks adequate access control and authentication mechanisms

Secure Information Flow via Linear Continuations - Zdancewic, Myers (2001)   (Correct)
Security-typed languages enforce secrecy or integrity policies by type-checking. This paper investigates continuation-passing style (CPS) as a means of proving that such languages enforce noninterfere... / Cornell University Abstract. Security-typed languages enforce secrecy

MetaKlaim: Meta-Programming for Global Computing - Ferrari, Moggi, Pugliese (2001)   (Correct)
Most foundational models for global computing have focused on the spatial dimension, however global computing requires also new ways of thinking about the temporal dimension. In particular, with no ce... / and linking of code fragments security checks like type-checking at br e.g. authentication and access control increase the exibility of

Goal-Oriented Elaboration of Security Requirements - Fontaine, van Lamsweerde, Letier.. (2001)   (Correct)
We suggest an approach to software development that integrates elaboration of security requirements at an early stage of the software life cycle. Reasoning about security in goal-oriented requirements... / Goal-Oriented Elaboration of Security Requirements Promoteur Pr.

Model-Carrying Code (MCC): A New Paradigm for Mobile-Code Security - Sekar, Ramakrishnan, Ramakrishnan.. (2001)   (Correct)
A new approach to ensuring the security of mobile code is presented. Our approach enables a mobile-code consumer to understand and formally reason about what a piece of mobile code can do; check if t... / A New Paradigm for Mobile-Code Security R. Sekar C.R. Ramakrishnan br Java provides an access control mechanism that can limit

Kerberized Credential Translation: A Solution to Web Access Control - Kornievskaia, Honeyman, Doster.. (2001)   (Correct)
Kerberos, a widely used network authentication mechanism, is integrated into numerous applications, UNIX and Windows 2000 login, AFS, Telnet, and SSH to name a few. Yet, Web applications rely on SSL ... / location for enforcing security policies controlling Web br Translation A Solution to Web Access Control Olga Kornievskaia Peter

Framework for Authentication and Access Control of Client-Server.. - Amir, Nita-Rotaru, Stanton (2001)   (Correct)
Researchers have made much progress in designing secure and scalable protocols to provide speci c security services, such as data secrecy, data integrity, entity authentication and access control,... / protocols to provide speci c security services such as data secrecy br for Authentication and Access Control of Client-Server Group

A Formal Analysis of the CORBA Security Service - Basin, Rittinger, Vigano (2001)   (Correct)
We give a formal speci cation of the security service of CORBA, the Common Object Request Broker Architecture speci ed by the Object Management Group, OMG. In doing so, we tackle the problem of how on... / A Formal Analysis of the CORBA Security Service David Basin Frank

An Integrated Solution for Secure Group Communication in Wide-Area.. - Agarwal, Chevassut, Thompson, Tsudik (2001)   (Correct)
Many distributed applications require a secure reliable group communication system to provide coordination among the application components. This paper describes a secure group layer (SGL) which bundl... / encapsulates the standard message security services i.e confidentiality br a group authorization and access control mechanism and a group key

Attacks and benchmarking - Voloshynovskiy, Pereira, Pun.. (2001)   (Correct)
Watermarking is a potential method for protection of ownership rights on digital audio, image and video data. Benchmarks are used to evaluate the performance of different watermarking algorithms. For ... / data without cracking the security of the watermarking algorithm br authentication and conditional-access control. Thus the information b

SPKI/SDSI HTTP Server / Certificate Chain Discovery in SPKI/SDSI - Clarke (2001)   (Correct)
The issue of trust is of growing importance as our communities become increasingly interconnected. When resources are shared over an untrusted network, how are decisions on which principals are author... / actions determined SPKI SDSI a security infrastructure based on br It provides finegrained access control using a local name space

An Identity Escrow Scheme with Appointed Verifiers - Camenisch, Lysyanskaya (2001)   (Correct)
An identity escrow scheme allows a member of a group to prove membership in this group without revealing any extra information. At the same time, in case of abuse, his identity can still be discovered... / We provide a formal de nition of security against such attacks. For the br Such a scheme allows anonymous access control. In this paper we put

On Regions and Linear Types (Extended Abstract) - Walker, Watkins (2001)   (Correct)
We explore how two different mechanisms for reasoning about state, linear typing and the type, region and effect discipline, complement one another in the design of a strongly typed functional program... / Logics for Reasoning about Network Security.The views and conclusions br on linear type systems to help control access to and deallocation of

Higher-Order Types and Meta-Programming for Global Computing - Ferrari (2001)   (Correct)
MetaKlaim is a case study in modeling the spatial, temporal and security aspects necessary for global computing. MetaKlaim integrates MetaML (an extension of SML for multi-stage programming) and Klaim... / modeling the spatial temporal and security aspects necessary for global br checks e.g. authentication and access control increase the exibility of

Instantaneous Offloading of Transient Web Server Load - Panteleenko, Freeh (2001)   (Correct)
A modern web-hosting site is designed to handle load that is sometimes an order of magnitude greater than the average load. Such a site can be expensive and is underutilized most of the time. We des... / reside on dedicated servers for security or other reasons. This paper br through a combination of access control and read-only sharing.

Dynamic Homogenous AOP with PROSE - Popovici, Gross, Alonso (2001)   (Correct)
Aspect Oriented Programming (AOP) is an important technique to express modular and orthogonal adaptations of existing software components. Woven into a program, an aspect may change several units of f... / such concerns are transactions security distribution or logging. As a br contains the aspect code for access control and the code for accounting

On-card Bytecode Verification for Java Card - Leroy (2001)   (Correct)
This paper presents a novel approach to the problem of bytecode verification for Java Card applets. Owing to its low memory requirements, our verification algorithm is the first that can be embedded o... / thus increasing tremendously the security of post-issuance downloading of br and implementing a suitable access control policy The security of

Intercepting Mobile Communications: The Insecurity of 802.11 - Borisov, Goldberg, Wagner (2001)   (Correct)
The 802.11 standard for wireless networks includes a Wired Equivalent Privacy (WEP) protocol, used to protect link-layer communications from eavesdropping and other attacks. We have discovered several... / have discovered several serious security flaws in the protocol stemming br casual eavesdropping. Access control A second goal of the

Joint efforts to dispel an approaching modularity crisis - Divide et.. - Herrmann, Mezini, Ostermann (2001)   (Correct)
In this paper we consider two important trends in improving separation of concerns: (a) the emergence of server-side component frameworks, and (b) the emergence of advanced approaches to software deco... / added due to distribution security database etc. issues. Managing br as distribution persistency access control resource management

Why Autonomy Makes the Agent - Joseph, Kawamura (2001)   (Correct)
This paper works on the premise that the position stated by Jennings et al. [17] is correct. Specifically that, amongst other things, the agent metaphor is a useful extension of the object-oriented me... /

Robust Declassification - Zdancewic, Myers (2001)   (Correct)
Security properties based on information flow, such as noninterference, provide strong guarantees that confidentiality is maintained. However, programs often need to leak some amount of confidential i... / Abstract Security properties based on information br have the advantage over access control policies in that they can

Building a Web-Based Federated Simulation System with Jini and XML - Huang, Miller (2001)   (Correct)
In a Web-Based federated simulation system, a group of simulation models residing on different machines attached to the Internet, called federates, collaborate with each other to accomplish a common t... / distributed object invocation security load balancing and connection br a service is ensured through an access control list. A lease-based service

Astrolabe: A Robust and Scalable Technology For Distributed System.. - van Renesse, Birman (2001)   (Correct)
this paper, we describe a new information management service called Astrolabe. Astrolabe monitors the dynamically changing state of a collection of distributed resources, reporting summaries of this i... / D. . Operating Systems Security and Protection - br with integrity and write access control not confidentiality

Analysis of Source Code: A Case Study - Hartley, Krishnan (2001)   (Correct)
This paper summarises our experience in using model checking technology to understand concurrent programs. We use Verisoft to understand various aspects of a firewall tool kit. The main conclusion i... / reliability especially related to security issues owing to the internet and br of programs including access control netacl authentication

Best Practices for Secure Development - Peteanu (2001)   (Correct)
this document: http://members.rogers.com/razvan.peteanu -2- Revision History Version Release Date Notes 4.03 October 12, 2001 fixed a few other typos 4.02 October 11, 2001 added a missing reference ... /

Enhancing Survivability of Security Services using Redundancy - Hiltunen, Schlichting, Ugarte (2001)   (Correct)
Traditional distributed system services that provide guarantees related to confidentiality, integrity, and authenticity enhance security, but are not survivable since each attribute is implemented by ... / Enhancing Survivability of Security Services using Redundancy

Mobile Code Security by Java Bytecode Instrumentation - Chander, Mitchell (2001)   (Correct)
Mobile code provides significant opportunities and risks. Java bytecode is used to provide executable content to web pages and is the basis for dynamic service configuration in the Jini framework. Whi... / Mobile Code Security by Java Bytecode Instrumentation br conditions and basic resource access control. For example these tests

The Marvel Programming Model: a higher-order distributed process.. - Schmitt, Stefani (2001)   (Correct)
Contents 1 Introduction 2 1.1 Requirements for a distributed programming model . . . . . . . . . . . . . . . . . . . . . 3 1.2 Introducing the M-calculus . . . . . . . . . . . . . . . . . . . . . . .... / quality of service security fault management etc. The br both process mobility and access control. In our view these calculi

Multilevel Security and Information Flow in Petri Net Workflows - Knorr (2001)   (Correct)
In information systems --- especially with the growing importance of electronic commerce --- the modeling and analysis of business processes has raised interest over the last years. If combined with... / Multilevel Security and Information Flow in Petri br information flow mandatory access control multilevel security Petri

Certificate Chain Discovery in SPKI/SDSI - Clarke, Elien, Ellison, Fredette.. (2001)   (Correct)
SPKI/SDSI is a novel public-key infrastructure emphasizing naming, groups, ease-of-use, and flexible authorization. To access a protected resource, a client must present to the server a proof that the... / here is a fundamental one. Any security mechanism should be able to br or G That is the access-control list ACL for the protected

A Policy Deployment Model for the Ponder Language - Dulay, Lupu, Sloman, Damianou (2001)   (Correct)
Policies are rules that govern the choices in behaviour of a system. Security policies define what actions are permitted or not permitted, for what or for whom, and under what conditions. Management p... / choices in behaviour of a system. Security policies define what actions are br policies with role-based access control as well as general-purpose

A Java Commodity Grid Kit - von Laszewski, Foster, Gawor, Lane (2001)   (Correct)
In this paper we report on the features of the Java Commodity Grid Kit. The Java CoG Kit provides middleware for accessing Grid functionality from the Java framework. Java CoG Kit middleware is genera... / The community is also addressing security solutions that support br ranging from fine-grained access control to delegation single user to

Security Attributes in CORBA - Lang, al. (2001)   (Correct)
This paper discusses the difficulties of describing an appropriate notion of the security attributes caller and target in object-oriented middleware systems such as CORBA. Our analysis points out that... / to IEEE Symposium on Security and Privacy Security Attributes

LOTTERYBUS: A New High-Performance Communication Architecture for.. - Lahiri, Raghunathan, Lakshminarayana (2001)   (Correct)
This paper presents LOTTERYBUS, a novel high-performance communication architecture for system-on-chip (SoC) designs. The LOTTERYBUS architecture was designed to address the following limitations of c... / architecture needs to ensure security and insulation between competing br in the context of shared media access control in local area networks

Understanding Trust Management Systems - Weeks (2001)   (Correct)
This paper presents a mathematical framework for expressing trust management systems. The framework makes it easier to understand existing systems and to compare them to one another, as well as to des... / the domain of interest is often security related. Finally because there br share resources often use an access control mechanism. The problem of

Communication-Efficient Group Key Agreement - Kim, Perrig, Tsudik (2001)   (Correct)
Traditionally, research in secure group key agreement focuses on minimizing the computational overhead for cryptographic operations, and minimizing the communication overhead and the number of protoco... / the need for group-oriented security mechanisms in addition to the br integrity authentication and access control. These are achieved through

Beyond Address Spaces - Flexibility, Performance, Protection, and.. - Golm, Kleinöder, Bellosa (2001)   (Correct)
Early type-safe operating systems were hampered by poor performance. Contrary to these experiences we show that an operating system that is founded on an object-oriented, type-safe intermediate code c... / -they are no longer done for security reasons but for robustness br it appropriate abstractions for access control page tags are not

ALMI: An Application Level Multicast Infrastructure - Pendarakis, Shi, Verma, Waldvogel (2001)   (Correct)
The IP multicast model allows scalable and efficient multi-party communication, particularly for groups of large size. However, deployment of IP multicast requires substantial infrastructure modificat... / flow and congestion control security and access control. Motivated by br control security and access control. Motivated by these problems

Fine Grained Access Control for SOAP E-Services - Damiani, De Capitani (2001)   (Correct)
Lightweight protocols for remote service invocation via HTTP and XML, suchasSOAP, are rapidly gaining acceptance among developers of Internet-based e-services, especially because of their rewall-trav... / technique for access control security is currently de ned for either br Fine Grained Access Control for SOAP E-Services Ernesto

Formally Testing Fail-Safety of Electronic Purse Protocols - Jürjens, Wimmel (2001)   (Correct)
Designing and implementing security-critical systems correctly is very difficult. In practice, most vulnerabilities arise from bugs in implementations. We present work towards systematic specification... / Designing and implementing security-critical systems correctly is br consideration. When considering access control for example fail-safety

Indra: A peer-to-peer approach to network intrusion detection and.. - Janakiraman, Waldvogel, Zhang (2001)   (Correct)
While advances in computer and communications technology have made the network ubiquitous, they have also rendered networked systems vulnerable to malicious attacks orchestrated from a distance. These... / and P P approach to network security. It is often the case that br attempts and also enforces access control based on its memory of

M-Calculus: A Higher-Order Distributed Process Calculus - Schmitt, Stefani (2001)   (Correct)
this paper a new process calculus, called the M-calculus, which represents an attempt at defining a formal distributed programming model. Key insights for the calculus are similar to those laid out in... / quality of service security fault management etc. The br both process mobility and access control. In our view these calculi

HOUSe-KEEPER, a vendor-independent architecture for easy management.. - Seigneur (2001)   (Correct)
Home-networking is gaining momentum. In a couple of months, Windows XP will be launched with the connected home experience as one of its core areas of interest. In the medium term at least, there will... / The answer to the multi-user security requirement br as well as to easily grant access control and add some context

Stack Inspection: Theory and Variants - Fournet, Gordon (2001)   (Correct)
Stack inspection is a security mechanism implemented in runtimes such as the JVM and the CLR to accommodate components with diverse levels of trust. Although stack inspection enables the finegrained e... / Abstract Stack inspection is a security mechanism implemented in runtimes br the finegrained expression of access control policies it has rather a

Streaming Video and Rate Scalable Compression: What Are the.. - Lin, Podilchuk, Kalker, Delp (2001)   (Correct)
Video streaming, or the real-time delivery of video over a data network, is the underlying technology behind many applications including video conferencing, video-on-demand, and the delivery of educat... /

A Framework for Distributed Trust Management - Kagal, Cost, Finin, Peng (2001)   (Correct)
This paper discusses our infrastructure for handling distributed security and trust. It outlines a method for access control across domains that handles complex inter domain trust relationships. We ha... / for handling distributed security and trust. It outlines a method br trust. It outlines a method for access control across domains that handles

Access Control Mechanisms for Inter-organizational Workflow - Kang, Park, Froscher (2001)   (Correct)
As more businesses engage in globalization, inter-organizational collaborative computing grows in importance. Since we cannot expect homogeneous computing environments in participating organization... / the scalability of existing security solutions the separation of br Access Control Mechanisms for

Why Information Security is Hard - An Economic Perspective - Anderson (2001)   (Correct)
Introduction In a 1993 survey of fraud against automatic teller machines (ATMs) [2], it was found that patterns of fraud depended on who was liable for them. In the USA, if a customer disputed an ATM ... / Why Information Security is Hard An Economic br measures. Given better access control policy models formal proofs

A CORBA Commodity Grid Kit - von Laszewski, Parashar, Verma.. (2001)   (Correct)
This paper reports on an ongoing research project aimed at designing and deploying a CORBA Commodity Grid (CoG) Kit. The overall goal of this project is to enable the development of advanced Grid appl... /

Internet Access to a Home Area Network - Saif, Gordon, Greaves (2001)   (Correct)
This article describes one such access unknown Umar Saif, Daniel Gordon, and David J. Greaves University of Cambridge, Computer Laboratory Internet Access to a Home Area Network The AutoHan proj... / cannot watch the closed-circuit security camera you installed so that br a security model based on an access control list. Why XML Entities

SIMS: A Secure Information Management System for Large-Scale Dynamic.. - Jiang, Dasgupta (2001)   (Correct)
When two (or more) entities (or members) enter into a coalition, they agree to share information, resources and other assets according to some set of negotiated rules. This paper addresses the issue o... / the same id and password is a security risk This is impractical. . br the authentication and the access control at these service points. The

An Integrated IPSEC and Mobile-IP for FreeBSD - Binkley (2001)   (Correct)
Recently the Layer 2 802.11 link-layer security mechanism called WEP has been shown to be flawed. In this paper we present a combined layer 3 Mobile-IP and IPSEC routing architecture that is superio... / the Layer . link-layer security mechanism called WEP has been br is based on a more traditional access control list association between the

Interoperable Strategies in Automated Trust Negotiation - Yu, Winslett, Seamons (2001)   (Correct)
Automated trust negotiation is an approach to establishing trust between strangers through the exchange of digital credentials and the use of access control policies that specify what combinations o... / and may not share a common security domain. In order for strangers br credentials and the use of access control policies that specify what

Distributed Credential Chain Discovery in Trust Management - Li, Winsborough, Mitchell (2001)   (Correct)
We give goal-oriented algorithms for discovering credential chains in RT 0 , a role-based trust management language introduced in this paper. The algorithms search credential graphs, a representatio... / on Computer and Communication Security CCS' November - br The process of making access control decisions involves finding a

A Model for Integrating Security Technologies on JaCoWeb.. - Wangham, Lung, Westphall, Fraga.. (2001)   (Correct)
An integration of SSL and JacORB, according to the CORBA security model -- which does not unknown A Model for Integrating Security Technologies on JaCoWeb Authorization Scheme Michelle Silva Wangham... / A Model for Integrating Security Technologies on JaCoWeb

Dimensioning Server Access Bandwidth and Multicast Routing in Overlay .. - Shi, Turner, Waldvogel (2001)   (Correct)
Application-level multicast is a new mechanism for enabling multicast in the Internet. Driven by the fast growth of network audio/video streams, application-level multicast has become increasingly imp... / reliable transport and multicast security have been hot research topics br and the lack of support in access control and transport services.

Secure Anonymous Group Infrastructure for Common and Future Internet.. - Nathalie Weiler Computer (2001)   (Correct)
Secure group communication protocols, in particular multi-party key agreement and update algorithms, help promote traditional and new Internet multi-party applications such as video conferencing or di... / multicast accentuates certain security threats esp. active attacks such br because of missing access control mechanisms A typical

Herald: Achieving a Global Event Notification Service - Cabrera, Jones, Theimer (2001)   (Correct)
This paper presents the design philosophy and initial design decisions of Herald: a highly scalable global event notification system that is being designed and built at Microsoft Research. Herald is a... / upon reconnection. Security It should be possible to br of each Herald operation via access control to authenticated authorized

A Model of OASIS Role-Based Access Control and its Support for Active .. - Yao, Moody (2001)   (Correct)
OASIS is a role-based access control architecture for achieving secure interoperation of services in an open, distributed environment. Services de ne roles and implement formally speci ed policy for r... / and its Support for Active Security Walt Yao University of br A Model of OASIS Role-Based Access Control and its Support for Active

Don't Trust Your File Server - Mazieres, Shasha (2001)   (Correct)
All too often, decisions about whom to trust in computer systems are driven by the needs of system management rather than data security. In particular, data storage is often entrusted to people who ha... / management rather than data security. In particular data storage is br cryptography to enforce access control. Clients encrypted files

Some aspects of Unix file-system security - Wenzel (2001)   (Correct)
Unix is a simple but powerful system where everything is either a process or a file. Access to system resources works mainly via the filesystem, including special files and devices. Most Unix security... / Some aspects of Unix file-system security Markus Wenzel TU Munchen br This includes any kind of access control such as read write access to

A Stream Redirection Architecture for Pervasive Computing Environments - Nogueras (2001)   (Correct)
We describe a framework for redirecting data streams to devices best equipped to handle them as users move around in a building. This is a useful capability for emerging pervasive computing environmen... / . . . Authentication and Security . br . . . Resource Access Control .

Maintaining the Confidentiality of Interoperable Databases with a.. - Oliva, Saltor (2001)   (Correct)
When several databases with multilevel security policies are federated to form a tightly coupled federated database management system, heterogeneities such as different accreditation ranges must b... / with a Multilevel Federated Security System Marta Oliva and

CiteSeer - citeseer.org - Terms of Service - Privacy Policy - Copyright © 1997-2002 NEC Research Institute