Takashi Matsunaka

dblp:35/2278 · DBLP profile ↗
← Back
21ranked-venue papers
7as first author
4since 2021 · last 2024
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 1 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2024 Secured tracing for group signatures from attribute-based encryption
abstract
Summary This article presents a tracing mechanism for group signatures answering the security threats of malicious authorities and users' forgeries. The proposal weakens the high trust placed on the centralized tracing party in previous group signatures by decentralizing tracing power using a multiple tracer setting and limiting the tracers' access using attribute‐based encryption and the requirement of the group manager's agreement. We allow the group manager to control tracers identifying his group users. Instead of a centralized tracer, our setting has multiple tracers possessing attribute sets. Thus, after getting the group manager's permission, a tracer should satisfy the access policy in a given signature to identify the signer. On the other hand, our group signature scheme decentralizes the tracing key generation and removes the group manager's tracing ability. Thus, it ensures that only the attribute‐satisfying and permitted tracers can identify the signer. Moreover, this article delivers security against malicious users. It presents a verification process of access policy of the signatures to prevent users from utilizing invalid attributes for signing. In addition, the article delivers a collaborative tracing mechanism to satisfy attribute sets that a tracer fails to fulfill alone for identifying a signer. Thus, our tracing mechanism ensures security against malicious authorities and group users in group signatures. The article gives the general construction of the scheme and discusses the security.
Maharage Nisansala Sevwandi Perera, Takashi Matsunaka, Hiroyuki Yokoyama, Kouichi Sakurai
Concurr. Comput. Pract. Exp.2
2023 Machine Learning Based Prediction of Vulnerability Information Subject to a Security Alert
Ryu Watanabe, Takashi Matsunaka, Ayumu Kubota, Junpei Urakawa
ICISSP2
2023 Group Oriented Attribute-Based Encryption Scheme from Lattices with the Employment of Shamir's Secret Sharing Scheme
Maharage Nisansala Sevwandi Perera, Toru Nakamura, Takashi Matsunaka, Hiroyuki Yokoyama, Kouichi Sakurai
NSS3
2022 Attribute Based Tracing for Securing Group Signatures Against Centralized Authorities
Maharage Nisansala Sevwandi Perera, Toru Nakamura, Takashi Matsunaka, Hiroyuki Yokoyama, Kouichi Sakurai
ISPEC3
2018 Runtime Attestation for IAAS Clouds
Jesse Elwell, Angelo Sapello, Alexander Poylisher, Giovanni Di Crescenzo, Abhrajit Ghosh, Ayumu Kubota, Takashi Matsunaka
CLOSER7
2017 ROP Defense in the Cloud through LIve Text Page-level Re-ordering - The LITPR System
Angelo Sapello, C. Jason Chiang, Jesse Elwell, Abhrajit Ghosh, Ayumu Kubota, Takashi Matsunaka
CLOSER6
2014 On the Feasibility of Deploying Software Attestation in Cloud Environments
abstract
We present XSWAT (Xen SoftWare ATtestation), a system that makes use of timing based software attestation to verify the integrity of cloud computing platforms. We believe that ours is the first instance of a system that uses this attestation technique in a cloud environment and results obtained indicate the feasibility of its deployment. An overview of the XSWAT system and the associated threat model, along with a study of cloud environment impacts on performance, is presented. Environmental parameters include types of interconnects between the XSWAT verifier and measurement agent as well as the number of concurrently executing virtual machines on the platform being verified. Conversely, we also study the impact of XSWAT execution using well known system benchmarks and find this to be insignificant, thereby strengthening the case for XSWAT. We also discuss novel XSWAT mechanisms for addressing TOCTOU attacks.
Abhrajit Ghosh, Angelo Sapello, Alexander Poylisher, C. Jason Chiang, Ayumu Kubota, Takashi Matsunaka
IEEE CLOUD6
2013 Passive OS Fingerprinting by DNS Traffic Analysis
abstract
In this paper, we propose a new passive OS fingerprinting method which only requires DNS traffic analysis. The method utilizes characteristics on DNS queries specific to each OS, e.g. unique domain names, query patterns, time interval etc. The method can estimate the number of devices with each OS from the number of queries by utilizing the characteristics of the time interval patterns. The method considers the likelihood of irregular events that some queries are sent at less than regular time intervals, and some other queries are sent at more than regular time intervals. We analyze DNS traffic sent by each OS and extract the characteristics for OS fingerprinting. Then, we examine our estimation method by using DNS traffic in our intra-network. According to our examination, some results of our estimation method are close to the results of DHCP fingerprinting.
Takashi Matsunaka, Akira Yamada 0001, Ayumu Kubota
AINA1
2012 A Cell-Planning Model for HetNet with CRE and TDM-ICIC in LTE-Advanced
abstract
Heterogeneous Network (HetNet) in 3GPP is a technique to increase network capacity. In order to further increase network capacity, Cell Range Expansion (CRE) and Time Domain Multiplexing Inter-Cell Interference Coordination (TDM-ICIC) have been discussed for LTE-Advanced. Since the parameter values for CRE and TDM-ICIC have a huge effect on network capacity expansion, in this paper, a cell-planning model for the downlink in HetNet with CRE and TDM-ICIC is presented in order to find the minimum number of installed pico BSs under the constraint of covering all user data traffic. The constraint condition is formulated by using an overload indicator for the cases of between normal subframes and muted subframes, because different interference sources are considered for these subframes by adopting TDM-ICIC. The appropriate parameter values of not only CRE and TDM-ICIC but also the location, transmission power, and antenna tilt for each pico BS are determined. Cell planning is conducted for traffic distribution generated by reference to realistic traffic distribution by a greedy algorithm based on the proposed cell-planning model. The result shows that the solution algorithm finds a good approximate solution which covers all data traffic by installing one pico BS with CRE bias value = 8 dB and setting the muted subframe ratio = 0.2.
Shoji Kaneko, Takashi Matsunaka, Yoji Kishi
VTC Spring2
2010 A Study on Security Management Architecture for Personal Networks
Takashi Matsunaka, Takayuki Warabino, Yoji Kishi, Takeshi Umezawa, Kiyohide Nakauchi, Masugi Inoue
MobiQuitous1
2009 Device Authentication and Registration Method Assisted by a Cellular System for User-Driven Service Creation Architecture
abstract
Personal devices and access systems have recently become more diversified, and there is a need for technology that enables users to flexibly and securely create their own private services in a user-driven manner, utilizing the presently available access systems and devices. To this end, the authors have designed user-driven service creation architecture (USCA). It enables users to create a secure private network as a substrate for such services. This network is called a personal network (PN) and is an extension of the concept of personal area network (PAN). It is organized by the personal devices related to services that users wish to enjoy or offer. This paper focuses on the security issue of USCA: how to certify the eligibility of users or devices wishing to join a PN. It proposes a device authentication and registration method, with the assistance of cellular systems, IMS/MMD (IP multimedia system/ multimedia domain). By means of this method, users can bind the correctness of devices to their cellular phone, and can thus create secure PNs only with solicited devices.
Takashi Matsunaka, Takayuki Warabino, Yoji Kishi, Kiyohide Nakauchi, Takeshi Umezawa, Masugi Inoue
CCNC1
2009 Basic Design of a User-Driven Service Creation Platform Assisted by Cellular Systems
abstract
In spite of recent advances of personal communication devices and access network technology, users are still facing the issues such as high device maintenance costs, complication of inter-device cooperation, illegal access to devices, and leakage of personal information. Consequently, it is difficult for users to securely construct a network with local as well as remote personal devices. We propose a User-driven Service Creation Platform (USCP), which enables users to construct a secure private network in a simple and intuitive way, making the most of the authentication mechanism in cellular networks. USCP separates signaling and data paths in a flat structure of a virtual network topology. In this paper, we describe the basic design of USCP.
Takeshi Umezawa, Kiyohide Nakauchi, Ved P. Kafle, Masugi Inoue, Takashi Matsunaka, Takayuki Warabino, Yoji Kishi
CCNC5
2008 Secure Data Sharing in Mobile Environments
abstract
This paper proposes an approach for secure data sharing on mobile terminals with members of a particular group. To avoid the data being compromised due to loss or theft, this approach prevents data leakage, while allowing the correct members to recover the data to a new mobile terminal thanks to cooperation between a mobile terminal and a network server. The fundamental concept used to achieve data security involves applying data encryption and secret sharing of the encryption key. In addition, this approach newly introduces a key encapsulation mechanism (KEM) and threshold cryptography. The approach also combines the use of a data protection approach, based on a secret sharing scheme, in order to achieve an efficient data reading process. Once one of the members reads the data, he/she need not use threshold cryptography to reconstruct the encrypted key, but instead uses a secret sharing scheme. This paper confirms the potential of this approach via the prototype implementation onto a mobile phone.
Takashi Matsunaka, Takayuki Warabino, Yoji Kishi
MDM1
2008 Load sharing of location-based routing in overlay networks
abstract
This paper proposes a load sharing method of location-based routing in overlay networks. In previous works, the authors have proposed location-based routing, in which a sender designates the destination location (e.g. latitude and longitude) in packets and the overlay network delivers the packets to receivers residing in the designated location. While overlay network technologies facilitate the network deployment of robust distributed systems, proprietary identifier composition achieves high performances in an overlay server. This paper focuses on a load sharing method to enhance the scalability of previous works. With this method, when the number of receivers registering a single service exceeds a certain threshold, the server delegates the handling of a portion of receivers to other servers. This paper defines the design policies and also shows their applicable protocol sequence. For example, while tree-based identifier partitioning ensures compatibility with existing mechanisms, the selection method applied to the designated servers avoids a long detour for packet transmission etc. This paper also discusses performance evaluations on a developed test-bed system. Evaluations confirm that the proposed method improves system throughput and eases processing burden in an overlay server for large-scale information delivery.
Takayuki Warabino, Takashi Matsunaka, Yoji Kishi
PIMRC2
2007 A Lightweight Approach to Protect Mobile Data
abstract
This paper proposes a lightweight approach for protecting data on mobile terminals by improving our former approach [Warabino et al., 2006]. In order for the data not to be compromised due to loss or theft, our approach prevents data leaks and allows the correct user to recover the data to a new mobile terminal thanks to cooperation between a mobile terminal and a network server. The fundamental concept used to achieve data security involves applying data encryption and secret sharing of the encryption key. The master share is newly introduced to generate all the encryption keys for data on a mobile terminal. A user simply need reconstruct the master share onto a new mobile terminal to recover the environment of that lost. We confirmed the effectiveness of our approach through the implementation of both approaches onto a mobile phone.
Takashi Matsunaka, Takayuki Warabino, Keizo Sugiyama
ISCC1
2007 User-Centric Seamless Handover Scheme for Realtime Applications
abstract
We bring a new perspective on a vertical handover scheme, a user-centric seamless handover, toward a next generation network where heterogeneous network systems converge. The proposed scheme allows us to provide users with the optimal service quality for real-time applications in respective network systems, as well as sustaining on-going sessions. Firstly we propose SIP-based bi-casting technology using a Handover Assistant Server to provide optimal service quality in respective network systems and avoid packet loss during handover. The delay difference absorption method is also proposed to adjust the service quality smoothly to the newly connected network. Evaluation results show that the scheme works well for the handover between cellular and high speed wireless access via the implementation of a prototype system.
Haruki Izumikawa, Tadayuki Fukuhara, Takashi Matsunaka, Keizo Sugiyama
PIMRC3
2007 Proposal of ID Composition for Fast Location Lookup in Overlay Nodes
abstract
This paper proposes an ID composition for fast location lookup in overlay nodes. In the paper, we assume a location-based routing system constructed on an overlay network. While the overlay approach facilitates network deployment, recent DHT (Distributed Hash Table) technologies allow us to construct robust and high-scalable distributed systems. The point of our proposal is how to map physical location with ID space in DHT. The proposed ID composition realizes fast location lookup only by bit comparisons of IDs. Performance evaluations show that the processing time of location lookup is less than 5 microseconds, even when the number of registered locations is 1 million. The ID composition also allows unicast and multicast transport operations to support both service discovery and information delivery. In addition, this paper discusses how to effectively conduct information delivery within a circular area. Two rules, such as the 4-packet rule and rectangle rule, reduce communication traffic between overlay nodes and receivers to be one third of the simplest method.
Takayuki Warabino, Takashi Matsunaka, Keizo Sugiyama
VTC Fall2
2006 An Effective Authentication Procedure Considering User Expiry Time During Handover
abstract
This paper describes an approach to authentication during handover. In order to reduce the authentication delay, information is shared between users and the targeted network using two hash-chains. Users who are likely to change networks are assigned an expiration time. Therefore, in order to apply the new approach to a real environment, we propose `pre-auth' type in the extensible authentication protocol (EAP) authentication process to utilize the authentication information. The new approach offers a solution that reduces the authentication delay without reducing the security level of the system
Takashi Matsunaka, Haruki Izumikawa, Keizo Sugiyama
PIMRC1
2005 Proposed relay method with P-MP structure of IEEE 802.16-2004
abstract
This paper presents a relay method with a P-MP (point to multipoint) structure by extending the IEEE 802.16-2004 standard in order to expand the coverage area (2004). In the proposed relay method, a RS (relay station) sends a polling message for the SSs (subscriber station) assigned to the former to forward uplink data in terms of the contention opportunities in the uplink subframe, and obtains a contention request period to communicate between the RS and these SSs. The feature of the proposed relay method is that it can be applied to TDD (time division duplex) and FDD (frequency division duplex), and both BS (base station) and RS operating at the same and at different carrier frequencies respectively. In this paper, we evaluated the basic characteristics of the proposed relay method in terms of throughput and delay time through computer simulations. We show that the introduction of the proposed relay method is effective in expanding the coverage area, and that the proposed relay method has an effect on the increase of the system throughput without affecting the delay time by adjusting the time interval parameter for BW requests of SSs assigned to the RS correctly
Shoji Kaneko, Kenji Saito, Haruki Izumikawa, Takashi Matsunaka, Keizo Sugiyama, Hideyuki Shinonaga
PIMRC4
2004 Success Probability in Chi2-Attacks
Takashi Matsunaka, Atsuko Miyaji, Yuuki Takano
ACNS1
2003 Optimized Chi2-Attack against RC6
Norihisa Isogai, Takashi Matsunaka, Atsuko Miyaji
ACNS2