Security and Privacy by Declarative Design

被引:13
|
作者
Maffei, Matteo [1 ]
Pecina, Kim [1 ]
Reinert, Manuel [1 ]
机构
[1] Univ Saarland, D-66123 Saarbrucken, Germany
关键词
ACCESS-CONTROL; AUTHENTICATION; AUTHORIZATION; LANGUAGE; SYSTEMS;
D O I
10.1109/CSF.2013.13
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The privacy of users has rapidly become one of the most pervasive and stringent requirements in distributed computing. Designing and implementing privacy-preserving distributed systems, however, is challenging since these systems also have to fulfill seemingly conflicting security properties and system requirements: e. g., authorization and accountability require some form of user authentication and session management necessarily involves some form of user tracking. In this work, we present a solution based on declarative design. The core component of our framework is a logic-based declarative API for data processing that exports methods to conveniently specify the system architecture and the intended security properties, and conceals the cryptographic realization. Invisible to the programmer, the implementation of this API relies on a powerful combination of digital signatures, non-interactive zero-knowledge proofs of knowledge, pseudonyms, and reputation lists. We formally proved that the cryptographic implementation enforces the security properties expressed in the declarative specification. The systems produced by our framework enjoy interoperability and open-endedness: they can easily be extended to offer new services and cryptographic data can be shared and processed by different services, without requiring any extra bootstrapping phase or interaction among parties. We implemented the API in Java and conducted an experimental evaluation to demonstrate the practicality of our approach.
引用
收藏
页码:81 / 96
页数:16
相关论文
共 50 条
  • [41] Towards Understanding Family Privacy and Security Literacy Conversations at Home: Design Implications for Privacy Literacy Interfaces
    Alghythee, Kenan Kamel A.
    Hrncic, Adel
    Singh, Karthik
    Kunisetty, Sumanth
    Yao, Yaxing
    Soni, Nikita
    PROCEEDINGS OF THE 2024 CHI CONFERENCE ON HUMAN FACTORS IN COMPUTING SYTEMS, CHI 2024, 2024,
  • [42] Digital Energy Platforms Considering Digital Privacy and Security by Design Principles
    Cali, Umit
    Dynge, Marthe Fogstad
    Idries, Ahmed
    Mishra, Sambeet
    Dmytro, Ivanko
    Hashemipour, Naser
    Kuzlu, Murat
    PROCEEDINGS OF THE 2023 EUROPEAN INTERDISCIPLINARY CYBERSECURITY CONFERENCE, EICC 2023, 2023, : 167 - 173
  • [43] Design and Development of Case Studies in Security and Privacy for Health Informatics Education
    Amro, Belal M.
    Al-Jabari, Mohanad O.
    Jabareen, Hussein M.
    Khader, Yousef S.
    Taweel, Adel
    2018 IEEE/ACS 15TH INTERNATIONAL CONFERENCE ON COMPUTER SYSTEMS AND APPLICATIONS (AICCSA), 2018,
  • [44] Privacy Preserving Network Security Data Analytics: Architectures and System Design
    DeYoung, Mark E.
    Kobezak, Philip
    Raymond, David
    Marchany, Randy
    Tront, Joseph
    PROCEEDINGS OF THE 51ST ANNUAL HAWAII INTERNATIONAL CONFERENCE ON SYSTEM SCIENCES (HICSS), 2018, : 4504 - 4512
  • [45] Design Evolution of a Tool for Privacy and Security Protection for Activists Online: Cyberactivist
    Tadic, Borislav
    Rohde, Markus
    Randall, Dave
    Wulf, Volker
    INTERNATIONAL JOURNAL OF HUMAN-COMPUTER INTERACTION, 2023, 39 (01) : 249 - 271
  • [46] A security architecture for data privacy and security
    Weaver, Alfred C.
    ETFA 2005: 10TH IEEE INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES AND FACTORY AUTOMATION, VOL 1, PTS 1 AND 2, PROCEEDINGS, 2005, : 673 - 676
  • [47] A NEW DESIGN OF CRYPTOGRAPHIC KEY MANAGEMENT FOR HIPAA PRIVACY AND SECURITY REGULATIONS
    Huang, Hui-Feng
    Liu, Kuo-Ching
    Wang, Hsin-Wei
    INTERNATIONAL JOURNAL OF INNOVATIVE COMPUTING INFORMATION AND CONTROL, 2009, 5 (11A): : 3923 - 3931
  • [48] PaaSword: A Holistic Data Privacy and Security by Design Framework for Cloud Services
    Yiannis Verginadis
    Antonis Michalas
    Panagiotis Gouvas
    Gunther Schiefer
    Gerald Hübsch
    Iraklis Paraskakis
    Journal of Grid Computing, 2017, 15 : 219 - 234
  • [49] Internet of Things and Blockchain Integration: Security, Privacy, Technical, and Design Challenges
    Alzoubi, Yehia Ibrahim
    Al-Ahmad, Ahmad
    Kahtan, Hasan
    Jaradat, Ashraf
    FUTURE INTERNET, 2022, 14 (07)
  • [50] PaaSword: A Holistic Data Privacy and Security by Design Framework for Cloud Services
    Verginadis, Yiannis
    Michalas, Antonis
    Gouvas, Panagiotis
    Schiefer, Gunther
    Huebsch, Gerald
    Paraskakis, Iraklis
    JOURNAL OF GRID COMPUTING, 2017, 15 (02) : 219 - 234