Leonardo A. Martucci

dblp:12/3968 · DBLP profile ↗
← Back
13ranked-venue papers
1as first author
2since 2021 · last 2024
0000-0002-9980-3473ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 10 · 1 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 4Artificial intelligence and machine learning · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2024 A Secure and Privacy-Preserving Authentication Scheme with a Zero-Trust Approach to Vehicle Renting in VANETs
abstract
Contains fulltext : 308843.pdf (Publisher’s version ) (Open Access)
Mahdi Akil, Leonardo A. Martucci, Jaap-Henk Hoepman
SECRYPT2
2023 Designing for privacy: Exploring the influence of affect and individual characteristics on users' interactions with privacy policies
abstract
Consenting to digital services' privacy policies is standard practice. It often occurs at the early stage of interactions with a given service—during the sign-up process. Still, the most common way of acquiring consent from users is through their acknowledgment of policies by ticking a box. Consequently, users consent, mostly blindly, as they are unlikely to review the full text of policies. The current article presents research investigating factors that may impact user interaction with privacy policies, focusing on the underresearched topic of affective states (valence and arousal). The results of an online experiment (N=88) indicate that privacy policy design can elicit specific affective responses and, when accounting for some characteristics of individuals (e.g., personality traits), it can influence users' attitudes and behaviors. Particularly, the findings show that privacy awareness and willingness to disclose information might be impacted. Additionally, the analysis of collected data suggests significant associations between some personality traits and affective states, as well as a strong relationship between privacy concerns and willingness to disclose information, contradicting the concept of privacy paradox, often discussed in the privacy literature. Moreover, the results of our qualitative inquiry, where the study respondents had a chance to elaborate on their decisions to agree or disagree with the privacy policy by answering an open-ended question, confirm the quantitative findings, and reveal some of the users needs considering the sign-up process.
Agnieszka Kitkowska, Yefim Shulman, Leonardo A. Martucci, Erik Wästlund
Comput. Secur.3
2020 Facilitating Privacy Attitudes and Behaviors with Affective Visual Design
Agnieszka Kitkowska, Yefim Shulman, Leonardo A. Martucci, Erik Wästlund
SEC3
2018 mHealth: A Privacy Threat Analysis for Public Health Surveillance Systems
abstract
Community Health Workers (CHWs) have been using Mobile Health Data Collection Systems (MDCSs) for supporting the delivery of primary healthcare and carrying out public health surveys, feeding national-level databases with families' personal data. Such systems are used for public surveillance and to manage sensitive data (i.e., health data), so addressing the privacy issues is crucial for successfully deploying MDCSs. In this paper we present a comprehensive privacy threat analysis for MDCSs, discuss the privacy challenges and provide recommendations that are specially useful to health managers and developers. We ground our analysis on a large-scale MDCS used for primary care (GeoHealth) and a well-known Privacy Impact Assessment (PIA) methodology. The threat analysis is based on a compilation of relevant privacy threats from the literature as well as brain-storming sessions with privacy and security experts. Among the main findings, we observe that existing MDCSs do not employ adequate controls for achieving transparency and interveinability. Thus, threatening fundamental privacy principles regarded as data quality, right to access and right to object. Furthermore, it is noticeable that although there has been significant research to deal with data security issues, the attention with privacy in its multiple dimensions is prominently lacking.
Leonardo H. Iwaya, Simone Fischer-Hübner, Rose-Mharie Åhlfeldt, Leonardo A. Martucci
CBMS4
2016 Privacy Impact Assessment Template for Provenance
abstract
Provenance data can be expressed as a graph with links informing who and which activities created, used and modified entities. The semantics of these links and domain specific reasoning can support the inference of additional information about the elements in the graph. If such elements include personal identifiers and/or personal identifiable information, then inferences may reveal unexpected links between elements, thus exposing personal data beyond an individual's intentions. Provenance graphs often entangle data relating to multiple individuals. It is therefore a challenge to protect personal data from unintended disclosure in provenance graphs. In this paper, we provide a Privacy Impact Assessment (PIA) template for identifying imminent privacy threats that arise from provenance graphs in an application-agnostic setting. The PIA template identifies privacy threats, lists potential countermeasures, helps to manage personal data protection risks, and maintains compliance with privacy data protection laws and regulations.
Jenni Reuben, Leonardo A. Martucci, Simone Fischer-Hübner, Heather S. Packer, Hans Hedbom, Luc Moreau 0001
ARES2
2014 Secure and Privacy-Friendly Public Key Generation and Certification
abstract
Digital societies increasingly rely on secure communication between parties. Certificate enrollment protocols are used by certificate authorities to issue public key certificates to clients. Key agreement protocols, such as Diffie-Hellman, are used to compute secret keys, using public keys as input, for establishing secure communication channels. Whenever the keys are generated by clients, the bootstrap process requires either (a) an out-of-band verification for certification of keys when those are generated by the clients themselves, or (b) a trusted server to generate both the public and secret parameters. This paper presents a novel constrained key agreement protocol, built upon a constrained Diffie-Hellman, which is used to generate a secure public-private key pair, and to set up a certification environment without disclosing the private keys. In this way, the servers can guarantee that the generated key parameters are safe, and the clients do not disclose any secret information to the servers.
Fábio Borges, Leonardo A. Martucci, Filipe Beato, Max Mühlhäuser
TrustCom2
2013 Formal definitions for usable access control rule sets from goals to metrics
abstract
Access control policies describe high level requirements for access control systems. Access control rule sets ideally translate these policies into a coherent and manageable collection of Allow/Deny rules. Designing rule sets that reflect desired policies is a difficult and time-consuming task. The result is that rule sets are difficult to understand and manage. The goal of this paper is to provide means for obtaining usable access control rule sets, which we define as rule sets that (i) reflect the access control policy and (ii) are easy to understand and manage. In this paper, we formally define the challenges that users face when generating usable access control rule sets and provide formal tools to handle them more easily. We started our research with a pilot study in which specialists were interviewed. The objective was to list usability challenges regarding the management of access control rule sets and verify how those challenges were handled by specialists. The results of the pilot study were compared and combined with results from related work and refined into six novel, formally defined metrics that are used to measure the security and usability aspects of access control rule sets. We validated our findings with two user studies, which demonstrate that our metrics help users generate statistically significant better rule sets.
Matthias Beckerle, Leonardo A. Martucci
SOUPS2
2013 IncogniSense: An anonymity-preserving reputation framework for participatory sensing applications
Delphine Reinhardt, Christian Roßkopf, Matthias Hollick, Leonardo A. Martucci, Salil S. Kanhere
Pervasive Mob. Comput.4
2012 IncogniSense: An anonymity-preserving reputation framework for participatory sensing applications
abstract
Reputation systems rate the contributions to participatory sensing campaigns from each user by associating a reputation score. The reputation scores are used to weed out incorrect sensor readings. However, an adversary can deanonmyize the users even when they use pseudonyms by linking the reputation scores associated with multiple contributions. Since the contributed readings are usually annotated with spatiotemporal information, this poses a serious breach of privacy for the users. In this paper, we address this privacy threat by proposing a framework called IncogniSense. Our system utilizes periodic pseudonyms generated using blind signature and relies on reputation transfer between these pseudonyms. The reputation transfer process has an inherent trade-off between anonymity protection and loss in reputation. We investigate by means of extensive simulations several reputation cloaking schemes that address this tradeoff in different ways. Our system is robust against reputation corruption and a prototype implementation demonstrates that the associated overheads are minimal.
Delphine Reinhardt, Christian Roßkopf, Matthias Hollick, Leonardo A. Martucci, Salil S. Kanhere
PerCom4
2011 Learning Whom to Trust in a Privacy-Friendly Way
abstract
The topics of trust and privacy are more relevant to users of online communities than ever before. Trust models provide excellent means for supporting users in their decision making process. However, those models require an exchange of information between users, which can pose a threat to the users' privacy. In this paper, we present a novel approach for a privacy preserving computation of trust. Besides preserving the privacy of the recommenders by exchanging and aggregating recommendations under encryption, the proposed approach is the first that enables the trusting entities to learn about the trustworthiness of their recommenders at the same time. This is achieved by linking the minimum amount of information that is required for the learning process to the actual recommendation and by using zero-knowledge proofs for assuring the correctness of this additional information.
Sebastian Ries, Marc Fischlin, Leonardo A. Martucci, Max Mühlhäuser
TrustCom3
2009 Revealing the Calling History of SIP VoIP Systems by Timing Attacks
abstract
Many emergent security threats which did not exist in the traditional telephony network are introduced in SIP VoIP services. To provide high-level security assurance to SIP VoIP services, an inter-domain authentication mechanism is defined in RFC 4474. However, this mechanism introduces another vulnerability: a timing attack which can be used for effectively revealing the calling history of a group of VoIP users. The idea here is to exploit the certificate cache mechanisms supported by SIP VoIP infrastructures, in which the certificate from a caller's domain will be cached by the callee's proxy to accelerate subsequent requests. Therefore, SIP processing time varies depending whether the two domains had been into contact beforehand or not. The attacker can thus profile the calling history of a SIP domain by sending probing requests and observing the time required for processing. The result of our experiments demonstrates that this attack can be easily launched. We also discuss countermeasures to prevent such attacks.
Ge Zhang 0001, Simone Fischer-Hübner, Leonardo A. Martucci, Sven Ehlert
ARES3
2008 Self-certified Sybil-free pseudonyms
abstract
Accurate and trusted identifiers are a centerpiece for any security architecture. Protecting against Sybil attacks in a privacy-friendly manner is a non-trivial problem in wireless infrastructureless networks, such as mobile ad hoc networks. In this paper, we introduce self-certified Sybil-free pseudonyms as a means to provide privacy-friendly Sybil-freeness without requiring continuous online availability of a trusted third party. These pseudonyms are self-certified and computed by the users themselves from their cryptographic long term identities. Contrary to identity certificates, we preserve location privacy and improve protection against some notorious attacks on anonymous communication systems.
Leonardo A. Martucci, Markulf Kohlweiss, Christer Andersson, Andriy Panchenko 0001
WISEC1
2008 A Self-certified and Sybil-Free Framework for Secure Digital Identity Domain Buildup
Christer Andersson, Markulf Kohlweiss, Leonardo A. Martucci, Andriy Panchenko 0001
WISTP3