Stelvio Cimato

dblp:60/3624 · DBLP profile ↗
← Back
52ranked-venue papers
17as first author
15since 2021 · last 2026
0000-0003-1737-6218ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Applied, interdisciplinary, general and emerging computing · 18 · 4 first-author · 8 since 2021Security and privacy · 17 · 7 first-author · 5 since 2021Software engineering, systems software and programming languages · 15 · 4 first-author · 7 since 2021Theory of computation · 5 · 3 first-authorSystems, architecture and hardware · 4 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-authorArtificial intelligence and machine learning · 2Computer networks · 2
YearPublicationVenuePosition
2026 A Post-Processing Heuristic for the Static Separation of Permissions Problem
Carlo Blundo, Stelvio Cimato
COMPSAC2
2026 Post-Quantum Signature Migration for Ethereum Blockchain: A Verification Metrics Study
Muhammad Taha Ramzan, Stelvio Cimato
COMPSAC2
2026 Scalable Approach for Zero-Knowledge Proofs (ZKP): Reducing Proving Time with KZG Commitments
Jahanzeb Shahid, Stelvio Cimato
COMPSAC2
2026 Security-by-Design Reference Architecture for Data Governance in Healthcare Digital Twins
Chiara Braghin, Stelvio Cimato, Andrea Marchesini, Fabio Palazzesi, Elvinia Riccobene
SECRYPT (1)2
2026 A bag of words model for efficient discovery of roles in access control systems
abstract
The popularity of the Role-based Access Control (RBAC) model is determined by its flexibility and its adaptability in different contexts, easing the enforcement and the management of security policy. In some cases, different kinds of (cardinality) constraints are considered to adjust and adapt roles and their assignment to best represent the organization’s security policy. However, the process of role mining, whether based on an organizational scenario or on existing permission assignments, is a hard task, since the problem shows NP-hard computational complexity and in case of frequent policy updates, the dynamic adaptation of the roles can be challenging. Then, the only possibility of producing an RBAC model compliant with the security policy is to resort to heuristics, which may return an approximation of the optimal solution. In this paper, we propose an innovative approach to explore the space of the solution based on the bag of word value, which is commonly deployed in the field of document representation and knowledge extraction. We propose different heuristics and validate our approach reporting the results of the application to standard datasets, and providing an evaluation under different metrics and indicators. We show that our technique returns improved results and provides an alternative way to produce valid solutions for constrained RBAC.
Carlo Blundo, Stelvio Cimato
Comput. Secur.2
2025 A Framework for Secure Sharing of Medical Images Based on Visual Cryptography
abstract
In the domain of medical data security, the confidentiality and integrity of diagnostic exam results is crucial. However, the use of DICOM files, the standard format for storing and sharing medical images like X-rays and MRIs, can pose security risks because they are not subject to encryption requirements. As a result, these files rely heavily on the security measures implemented within the healthcare institution’s networks and databases, which are often inadequate in preventing unauthorized access, data tampering, or malicious injections.The goal of this paper is to propose a secure method for sharing and storing diagnostic exam results, ensuring the confidentiality of the information while safeguarding patient privacy. The proposed solution operates directly on DICOM files, utilizing steganography and visual secret sharing to protect and maintain the security of both metadata and pixel data.
Christian Coduri, Stelvio Cimato
COMPSAC2
2025 Blockchain in the Quantum Era: Surveying Security Challenges and Post-Quantum Cryptography
abstract
Recent advances in quantum technology are impacting cryptographic primitives, affecting their security. In this paper, we will survey the impact of these technologies on blockchain and distributed ledgers, and analyze the post-quantum primitives available to restore their security guarantees, including the latest NIST PQC standards ML-DSA-44 and SLH-DSA-SHA2-128s. Our analysis reveals critical trade-offs in signature size, key storage, and consensus resilience, highlighting challenges for IoT and PoW blockchains. Results underscore the urgency of improvements to the standardized NIST PQC algorithms to mitigate quantum risks to the blockchain without compromising throughput and decentralization.
Muhammad Taha Ramzan, Stelvio Cimato
COMPSAC2
2025 A State Channel Based Approach to Address Scalability of Healthcare Data Sharing
abstract
The process of exchanging healthcare data introduces stringent requirements regarding users’ privacy. Federated learning (FL) is a novel model-sharing technique that aims to give additional privacy guarantees during machine learning process. Blockchain, as a form of distributed ledger technology, possesses the characteristic of trustworthiness; however, it is deficient in terms of computational capacity with a high-latency network due to its laborious consensus protocols. In this paper we present a distributed healthcare FL-based secure model sharing architecture to ensure healthcare data privacy and scalability. The solution relies on state channels technique to reduce on-chain transactions, contrast architecture latency, and reduce bandwidth consumption, alleviating the burden on the blockchain. State channels can be utilized to efficiently execute the tasks of federated learning models sharing and to solve the scalability problem.
Jahanzeb Shahid, Stelvio Cimato
COMPSAC2
2025 Google Map-Based Password Authentication Systems Using Tolerant Distance and Homomorphic Encryption
abstract
Passwords are widely used for authentication in Internet applications. Recently, users tend to adopt graphical passwords instead of traditional alphanumeric passwords, since it is much easier for humans to remember images than verbal representations. However, the existing graphical password authentication systems generally suffer from three main issues. 1) It is required to remember and perform complicated operations during the registration/login phases, which significantly limits the systems’ usability; 2) The users’ passwords are simply stored as plaintexts in servers, and thus the security is compromised; 3) The users need to register/login to each server separately when they are applied in multi-server environment. To address the above issues, we propose a user-friendly and secure Google map-based graphical password (FS-GMGP) system using tolerant distance and homomorphic encryption. By using a homomorphic encryption scheme, each user encrypts his password point and response point selected on Google map, while the servers compute and decrypt the distance between the two encrypted points and then compare the resulting value with a tolerant distance for authentication. Moreover, the FS-GMGP system is extended for multi-server environment. The evaluation results and security analysis show that the FS-GMGP and its extended version achieve desirable usability and security in single-server environment and multi-server environment, respectively.
Zhili Zhou 0001, Ching-Nung Yang, Shaowei Wang 0003, Guoshun Nan, Stelvio Cimato, Yifeng Zheng 0001, Qian Wang 0002
IEEE Trans. Dependable Secur. Comput.5
2024 A Sharded Blockchain Architecture for Healthcare Data
abstract
The application of machine learning (ML) techniques to electronic health records (EHR) is gaining more and more attention as a method to extract valuable information that has the potential to enhance the decision-making process within the healthcare domain. A useful approach comes from the fed-erated learning (FL) scenario, which facilitates the decentralised training of machine learning models using datasets that are stored locally, hence eliminating the necessity of data aggregation on a central server. Federated learning also ensures data privacy because the federated devices do not share the actual data and store it locally. It becomes a useful tool when integrated with blockchain technology, which provides some properties such as immutability and traceability that are useful to enhance the security of such applications. With the growing use of IoT health care (loHT) devices, it is becoming challenging to manage them centrally and ensuring the health care data privacy. In this work, we propose an architecture to address the scalability issue related to the healthcare data management for federated learning networks with a sharding-based blockchain technique. We discuss some basic properties and report some results also coming from the implementation in Hyperledger Fabric.
Jahanzeb Shahid, Stelvio Cimato, Muhammad Zia
COMPSAC2
2024 Efficient Secure Computation of Edit Distance on Genomic Data
abstract
Genetic data are the most sensitive information for a person, containing many specific features that uniquely determine an individual and also make it possible to trace relationships with other people or evaluate the predisposition to particular diseases.For this reason, any processing of genetic data should be carefully performed and any threat to their privacy properly considered.A very important computation in medical and public health domains involves the evaluation of the edit distance between human genomes, that can eventually lead to a better diagnosis of several diseases.To maintain the privacy of the genetic data, it is possible to apply secure computation protocols and then, in this context, the improvement of the computational performance of such techniques is a key factor for real-world application scenarios.In this paper we focus on the application of the garbling circuit technique for the computation of the edit distance, showing its efficiency.We apply the technique considering four different algorithms and compare their performances to the best previous results found in literature.We show that the Ukkonen algorithm with generalized cut-off is the one that performed better among the considered algorithms, reporting some experimental results obtained considering datasets composed of both randomly generated and real genomic strings.
Andrea Migliore, Stelvio Cimato, Gabriella Trucco
ICISSP2
2023 Role mining under User-Distribution cardinality constraint
Carlo Blundo, Stelvio Cimato
J. Inf. Secur. Appl.2
2022 Role Mining Heuristics for Permission-Role-Usage Cardinality Constraints
abstract
Abstract Role-based access control (RBAC) has become a de facto standard to control access to restricted resources in complex systems and is widely deployed in many commercially available applications, including operating systems, databases and other softwares. The migration process towards RBAC, starting from the current access configuration, relies on the design of role mining techniques, whose aim is to define suitable roles that implement the given access policies. Some constraints can be used to transform the roles automatically output by the mining procedures and effectively capture the organization’s status under analysis. Such constraints can limit the final configuration characteristics, such as the number of roles assigned to a user, or the number of permissions included in a role, and produce a resulting role set that is effectively usable in real-world situations. In this paper, we consider two constraints: the number of permissions a role can include and the number of roles assigned to any user. In particular, we present two heuristics that produce roles compliant with both constraints and evaluate their performances using both real-world and synthetic datasets.
Carlo Blundo, Stelvio Cimato, Luisa Siniscalchi
Comput. J.2
2022 Multiplicative Complexity of XOR Based Regular Functions
abstract
XOR-AND Graphs (XAGs) are an enrichment of the classical AND-Inverter Graphs (AIGs) with XOR nodes. In particular, XAGs are networks composed by ANDs, XORs, and inverters. Besides several emerging technologies applications, XAGs are often exploited in cryptography-related applications based on the multiplicative complexity of a Boolean function. The multiplicative complexity of a function is the minimum number of AND gates (i.e., multiplications) that are sufficient to represent the function over the basis {AND, XOR, NOT}. In fact, the minimization of the number of AND gates is important for high-level cryptography protocols such as secure multiparty computation, where processing AND gates is more expensive than processing XOR gates. Moreover, it is an indicator of the degree of vulnerability of the circuit, as a small number of AND gates corresponds to a high vulnerability to algebraic attacks. In this paper we study the multiplicative complexity of Boolean functions characterized by two particular regularities, called autosymmetry and D-reducibility. Moreover, we exploit these regularities for decreasing the number of AND nodes in XAGs. The experimental results validate the proposed approaches.
Anna Bernasconi 0001, Stelvio Cimato, Valentina Ciriani, Maria Chiara Molteni
IEEE Trans. Computers2
2021 Towards a Trustworthy Semantic-Aware Marketplace for Interoperable Cloud Services
Emanuele Bellini 0001, Stelvio Cimato, Ernesto Damiani, Beniamino Di Martino, Antonio Esposito 0001
CISIS2
2020 Be Your Neighbor's Miner: Building Trust in Ledger Content via Reciprocally Useful Work
abstract
Distributed Ledgers (DLs) like Blockchain have become a popular technique to build collective trust in digital records. The rationale is that any agent wishing to append a block to a DL needs to provide proof of holding some property/asset or having performed some costly activity. Thus, “poisoning” a DL with spurious content requires much more effort than poisoning a conventional shared data structure. Based on this idea, DLs are now being deployed as community stores of trusted transaction records, reputation values and even of trustworthy training data for Machine Learning (ML) models. Certainly, when injecting spurious or hostile content in a DL, a rational attacker has to consider whether the damage δ caused by a spurious block B is worth the effort ε needed to append B to the DL; but practical experience has shown that being certain to disrupt a DL-supported application may be a powerful motivator for digital vandalism even when it is costly. In this paper, we put out an alternative idea: Reciprocally Useful Work (RUW), a novel DL update mechanism where any agent wishing to add a block B to the ledger must first perform an activity that will improve the utility for the DL-supported application of some other agent's block B'. We discuss in detail how to apply RUW to DLs storing training data for Machine Learning (ML) models, in order to show that reciprocity can play the role of a direct compensation of the potential disruption, which is measurable in term of the performance of the ML model trained on the DL content.
Lara Mauri, Ernesto Damiani, Stelvio Cimato
CLOUD3
2020 Towards Efficient and Secure Analysis of Large Datasets
Stelvio Cimato, Stefano Nicolò
COMPSAC1
2020 Multiplicative Complexity of Autosymmetric Functions: Theory and Applications to Security
abstract
The multiplicative complexity of a Boolean function is the minimum number of AND gates (i.e., multiplications) that are sufficient to represent the function over the basis {AND, XOR, NOT}. The multiplicative complexity measure plays a crucial role in cryptography-related applications. In fact, the minimization of the number of AND gates is important for high-level cryptography protocols such as secure multiparty computation, where processing AND gates is more expensive than processing XOR gates. Moreover, it is an indicator of the degree of vulnerability of the circuit, as a small number of AND gates corresponds to a high vulnerability to algebraic attacks. In this paper we study a particular structure regularity of Boolean functions, called autosymmetry, and exploit it to decrease the number of ANDs in XOR-AND Graphs (XAGs), i.e., Boolean networks composed by ANDs, XORs, and inverters. The interest in autosymmetric functions is motivated by the fact that a considerable amount of standard Boolean functions of practical interest presents this regularity; indeed, about 24% of the functions in the classical ESPRESSO benchmark suite have at least one autosymmetric output. The experimental results validate the proposed approach.
Anna Bernasconi 0001, Stelvio Cimato, Valentina Ciriani, Maria Chiara Molteni
DAC2
2020 A Formal Approach for the Analysis of the XRP Ledger Consensus Protocol
abstract
Distributed ledger technology is envisioned as one of the cornerstones of promising solutions for building the next generation of critical applications.However, there is still quite a bit of confusion and hype around the real security guarantees this technology offers.This is especially due to the fact that for the vast majority of existing blockchain-based consensus protocols it is really hard to find sufficiently detailed documentation that fully captures their behavior.A number of recent papers have formalized the behavior of Bitcoin-like protocols in order to rigorously study the security and privacy properties of their underlying structure, but surprisingly very little work has been devoted to the formalization of distributed ledger systems using BFTlike approaches.In this work, we focus on XRP Ledger, better known as Ripple, and take the first steps towards the complete formalization of its consensus protocol.To this end, we have investigated all the existing documentation and analyzed its source code.We present a formal description of its consensus protocol for every step.Furthermore, we provide an accurate view of its security guarantees in terms of safety and liveness and show how to increase the desired tolerance by changing the value of specific protocol parameters.
Lara Mauri, Stelvio Cimato, Ernesto Damiani
ICISSP2
2020 A cryptographic cloud-based approach for the mitigation of the airline cargo cancellation problem
Stelvio Cimato, Gabriele Gianini, Maryam Sepehri, Rasool Asal, Ernesto Damiani
J. Inf. Secur. Appl.1
2018 Are mHealth Apps Secure? A Case Study
abstract
mHealth applications are becoming increasingly widespread since they have the potential to reduce the cost of health care by favoring self-management of chronic diseases or to improve fitness activities. By their very nature, health applications collect and manage health sensitive data, therefore several concerns exist about how privacy, security, and confidentiality are handled. In this paper, we analyze the security issues of mHealth apps from two different perspectives: first, we highlight the security and privacy requirements on health data defined by data protection laws such as the General Data Protection Regulation (GDPR) in the EU, or the Health Insurance Portability and Accountability Act (HIPAA) in US. Then, we consider the security issues from a technological point of view, discussing how the app may protect user data. However, by analyzing a fitness app, we show that, at the moment, none of the well-known practices to protect data is followed, thus often mHealth apps are insecure.
Chiara Braghin, Stelvio Cimato, Alessio Della Libera
COMPSAC (2)2
2018 Message from the SAPSE 2018 Workshop Organizers
abstract
Presents the introductory welcome message from the conference proceedings. May include the conference officers' congratulations to all involved with the conference event and publication of the proceedings record.
Stelvio Cimato
COMPSAC (2)1
2018 A Comparative Analysis of Current Cryptocurrencies
abstract
Blockchain technology is having a deep impact on the financial and technical sectors providing a mechanism for the creation of decentralized currencies and a number of applications in different fields.At the core of the technology there is a consensus protocol enabling the maintenance of a distributed ledger.In general current systems are complex schemes that implement a combination of cryptographic algorithm, distributed techniques, and incentive driven behaviour.In this paper we focus on three of the most diffused platforms, i.e.Bitcoin, Ripple, and Ethereum, and provide a comparative analysis of their most important features such as the architecture, the scripting language, the economic and security properties.
Lara Mauri, Stelvio Cimato, Ernesto Damiani
ICISSP2
2018 PostProcessing in Constrained Role Mining
Carlo Blundo, Stelvio Cimato, Luisa Siniscalchi
IDEAL (1)2
2017 PRUCC-RM: Permission-Role-Usage Cardinality Constrained Role Mining
abstract
Role Based Access Control (RBAC) models have been adopted in many organizations as the standard way to implement security policies and assign access to restricted resources to roles and roles to users. To capture the business relationships within the organization and efficiently migrate towards RBAC, several role mining techniques have been defined. Constraints on the resulting roles and assignments to users can be imposed to filter out inconsistent situations produced by the automatic algorithm and to better capture the status of the organization. In this paper we are interested in constraints on the number of permissions that can be included in a role and on the number of persons a role can be assigned to. We analyze the problem and propose a couple of heuristics. The heuristics have been applied to standard datasets to validate their performance.
Carlo Blundo, Stelvio Cimato, Luisa Siniscalchi
COMPSAC (2)2
2017 Exploiting Quantum Gates in Secure Computation
abstract
Secure Multi-party Computation (SMC) has been introduced to allow the computation of generic functions between two parties that want to keep secret the input they use, and share only the computed result. One of the approach proposed to solve the SMC problem relies on the design of Garbled Circuits (GC), that are Boolean circuits that can be evaluated collaboratively achieving the SMC goal. Recently, there is a growing interest on the efficiency of this technique and on its potential applications to computation outsourcing in untrusted environments. One of the possible ways to reduce the complexity of the computation is to lower the number of non-EXOR gates in the Boolean circuit, since those gates have no cost for the execution of the secure computation protocol. In this work, we discuss the possibility to construct Garbled Circuit using quantum gates (QG), observing that, in some cases, the quantum GC requires a lower number of non-EXOR gates with respect to the corresponding classical GC implementations, thus improving the overall efficiency of the execution of the SMC protocol.
Maryam Ehsanpour, Stelvio Cimato, Valentina Ciriani, Ernesto Damiani
DSD2
2017 A multiple valued logic approach for the synthesis of garbled circuits
abstract
Secure Multi-party Computation (SMC) protocols enable two or more parties to compute collaboratively generic functions while keeping secret their inputs, sharing only the final result. To achieve this goal, a technique relying on the design of Garbled Circuits (GC) has been firstly proposed by Yao. Garbled circuits are Boolean circuits that can be evaluated using a distributed protocol for computing the result for each gate, till computing the output values. To improve the efficiency of this technique and exploit SMC protocols in practical applications, such as computation outsourcing in untrusted environments, a number of optimizations have been introduced. In this paper we analyze the deployment of Multiple Valued Logic techniques for the design of GC, discussing their impact on the overall computation and communication costs.
Stelvio Cimato, Valentina Ciriani, Ernesto Damiani, Maryam Ehsanpour
VLSI-SoC1
2016 3-Out-of-n Cheating Prevention Visual Cryptographic Schemes
Ching-Nung Yang, Stelvio Cimato, Jihi-Han Wu, Song-Ruei Cai
ICISSP2
2015 New Results for Partial Key Exposure on RSA with Exponent Blinding
abstract
In 1998, Boneh, Durfee and Frankel introduced partial key exposure attacks, a novel application of Coppersmith's method, to retrieve an RSA private key given only a fraction of its bits.This type of attacks is of particular interest in the context of side-channel attacks.By applying the exponent blinding technique as a countermeasure for side-channel attacks, the private exponent becomes randomized at each execution.Thus the attacker has to rely only on a single trace, significantly incrementing the noise, making the exponent bits recovery less effective.This countermeasure has also the side-effect of modifying the RSA equation used by partial key exposure attacks, in a way studied by Joye and Lepoint in 2012.We improve their results by providing a simpler technique in the case of known least significant bits and a better bound for the known most significant bits case.Additionally, we apply partial key exposure attacks to CRT-RSA when exponent blinding is used, a case not yet analyzed in literature.Our findings, for which we provide theoretical and experimental results, aim to reduce the number of bits to be recovered through side-channel attacks in order to factor an RSA modulus when the implementation is protected by exponent blinding.
Stelvio Cimato, Silvia Mella, Ruggero Susella
SECRYPT1
2015 Privacy-Preserving Query Processing by Multi-Party Computation
abstract
In this paper, we investigate privacy-preserving query processing (P3Q) techniques on partitioned databases, where relational queries have to be executed on horizontal data partitions held by different data owners. In our scenario, data owners use Secure Multi-party Computation (SMC) to compute privacy-preserving queries on entire relation(s) without sharing their private partitions. Our solution is applicable to a subset of SQL query language called SQL−− including selection and equi-join queries. To nicely scale up with large size data, we show that computation and communication costs can be reduced via a novel bucketization technique. We consider the classical notion of query privacy, where the querier only learns query results (and what can be inferred from it), and data owners learn as little as possible (in a computational sense) about the query. To ensure such privacy, our technique involves a trusted party only at the beginning of the protocol execution. Experimental results on horizontally partitioned, distributed data show the effectiveness of our approach.
Maryam Sepehri, Stelvio Cimato, Ernesto Damiani
Comput. J.2
2013 Towards the Certification of Cloud Services
abstract
The need of a certification process for cloud-based services is emerging as a way to address some of the remaining obstacles facing the effective development and diffusion of the cloud-computing paradigm. In this paper we move the first steps towards a complete approach containing a conceptual framework where the specifications of basic, hybrid and incremental certification models for cloud-based services can be given. Specifically, we focus on the definition of a unifying meta-model to provide representational guidelines for (i) the definition of the security properties to be certified, (ii) the types of evidence underlying them, (iii) the phases of the certificate life cycle, as well as of all mechanisms for generating supporting evidence.
Stelvio Cimato, Ernesto Damiani, Francesco Zavatarelli, Renato Menicocci
SERVICES1
2012 Visual Cryptography Based Watermarking: Definition and Meaning
Stelvio Cimato, Ching-Nung Yang, Chih-Cheng Wu
IWDW1
2010 Using incentive schemes to alleviate supply chain risks
abstract
This paper describes a methodology and toolkit for the analysis of risks due to insiders' dysfunctional behavior in supply chains. It shows how risk analysis techniques based on value models [15] can incorporate the design and distribution of incentives as a risk-alleviation technique. Some important new functionalities of our SCRS (Supply Chain Risk Simulator v1 [14]) tool are presented. Such functionalities allow for (i) import/export of value models and (ii) execution of incentive-aware risk analysis. Functionality (i) fully integrates the SCRS tool with the e3-value tool suite, increasing synergy with existing value model toolkits. Functionality (ii) substantially extends the original palette of techniques for risk analysis and alleviation. Finally, the paper presents the results of an extensive experimentation of our methodology and simulation tool taking into account different combinations of incentive schemes and simulation options.
Marco Anisetti, Ernesto Damiani, Fulvio Frati, Stelvio Cimato, Gabriele Gianini
MEDES4
2010 Managing key hierarchies for access control enforcement: Heuristic approaches
Carlo Blundo, Stelvio Cimato, Sabrina De Capitani di Vimercati, Alfredo De Santis, Sara Foresti, Stefano Paraboschi, Pierangela Samarati
Comput. Secur.2
2009 Efficient Key Management for Enforcing Access Control in Outsourced Scenarios
Carlo Blundo, Stelvio Cimato, Sabrina De Capitani di Vimercati, Alfredo De Santis, Sara Foresti, Stefano Paraboschi, Pierangela Samarati
SEC2
2008 Privacy-Aware Biometrics: Design and Implementation of a Multimodal Verification System
abstract
A serious concern in the design and use of biometric authentication systems is the privacy protection of the information derived from human biometric traits, especially since such traits cannot be replaced. Combining cryptography and biometrics, several recent works proposed to build the protection in the biometric templates themselves. While these solutions can increase the confidence in biometric systems when biometric information is stored for verification, they have been shown difficult to apply to real biometrics. In this work we present a biometric authentication technique that exploits multiple biometric traits. It is privacy-aware as it ensures privacy protection and allows the extraction of secure identifiers by means of cryptographic primitives. We also discuss the implementation of our approach by considering, as a significant example, the combination of iris and fingerprint biometrics and present experimental results obtained from real data. The implementation shows the feasibility of the scheme in practical applications.
Stelvio Cimato, Marco Gamassi, Vincenzo Piuri, Roberto Sassi, Fabio Scotti
ACSAC1
2008 A Lightweight Protocol for Dynamic RFID Identification
abstract
RFID technology is widely used worldwide in a broad range of applications. Such technology however raises security concerns about the protection of the information stored in the RFID tags and exchanged during the wireless communication with the readers. In this work we propose an efficient protocol for tag identification which improves on previous proposals and provides an increased level of security, allowing dynamic addition or remotion of tags from the set of recognized tags. The protocol relies on the use of skip lists, authenticated data structures previously used in other fields of application.
Stelvio Cimato
COMPSAC1
2007 Colored visual cryptography without color darkening
Stelvio Cimato, Roberto De Prisco, Alfredo De Santis
Theor. Comput. Sci.1
2006 A Web Service Based Micro-payment System
abstract
The number of online commercial transactions involving small amount of money is more and more increasing. For these transactions, different payment mechanisms from traditional ones are needed in order to reduce the overall costs. To answer to the growing demand for micropayment technologies, several commercial companies have recently started offering micropayment services, which offer reduced costs per transactions. In this work we present the design and the implementation of a micropayment system relying on Web service technology to conclude commercial transactions. The proposed system enables clients to access the restricted resources offered by the merchants and to pay for the received service by invoking the Web services exposed by a Payment Service Provider, acting like an online bank.
Vincenzo Auletta, Carlo Blundo, Stelvio Cimato, Guerriero Raimato
ISCC3
2006 Probabilistic Visual Cryptography Schemes
abstract
Visual cryptography schemes allow the encoding of a secret image, consisting of black or white pixels, into n shares which are distributed to the participants. The shares are such that only qualified subsets of participants can ‘visually’ recover the secret image. The secret pixels are shared with techniques that subdivide each secret pixel into a certain number m, m ≥ 2 of subpixels. Such a parameter m is called pixel expansion. Recently Yang introduced a probabilistic model. In such a model the pixel expansion m is 1, that is, there is no pixel expansion. The reconstruction of the image however is probabilistic, meaning that a secret pixel will be correctly reconstructed only with a certain probability. In this paper we propose a generalization of the model proposed by Yang. In our model we fix the pixel expansion m ≥ 1 that can be tolerated and we consider probabilistic schemes attaining such a pixel expansion. For m = 1 our model reduces to the one of Yang. For big enough values of m, for which a deterministic scheme exists, our model reduces to the classical deterministic model. We show that between these two extremes one can trade the probability factor of the scheme with the pixel expansion. Moreover, we prove that there is a one-to-one mapping between deterministic schemes and probabilistic schemes with no pixel expansion, where contrast is traded for the probability factor.
Stelvio Cimato, Roberto De Prisco, Alfredo De Santis
Comput. J.1
2006 A unified model for unconditionally secure key distribution
abstract
A key distribution scheme is a method by means of which a trusted party distributes pieces of information among a set of users in such a way that each group of them can compute a common key for secure communication. In this paper we present a model for unconditionally secure key distribution schemes, i.e., schemes whose security is independent of the power of the adversary. We prove lower bounds on the amount of information the trusted party has to generate and each user has to keep secret in such schemes, and we show that some previous unconditionally secure models for key distribution fall in our model. As a consequence, the lower bounds given in the literature for these models can be seen as corollaries of our results. Hence, the main contribution of the paper consists in pointing out a sort of common structure underlying some apparently different key distribution techniques.
Stelvio Cimato, Antonella Cresti, Paolo D'Arco
J. Comput. Secur.1
2006 Visual cryptography schemes with optimal pixel expansion
Carlo Blundo, Stelvio Cimato, Alfredo De Santis
Theor. Comput. Sci.2
2005 Design and Implementation of an Inline Certified E-mail Service
Stelvio Cimato, Clemente Galdi, Raffaella Giordano, Barbara Masucci, Gildo Tomasco
CANS1
2005 Optimal Colored Threshold Visual Cryptography Schemes
Stelvio Cimato, Roberto De Prisco, Alfredo De Santis
Des. Codes Cryptogr.1
2005 Ideal contrast visual cryptography schemes with reversing
Stelvio Cimato, Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
Inf. Process. Lett.1
2005 Overcoming the obfuscation of Java programs by identifier renaming
Stelvio Cimato, Alfredo De Santis, Umberto Ferraro Petrillo
J. Syst. Softw.1
2003 Certified Email: Design and Implementation of a New Optimistic Protocol
abstract
Nowadays email has become the most widely used means in daily communication on the net and is increasingly used in place of ordinary mail. Certified email protocols aim to provide additional properties to the standard email service. In this paper we provide a novel optimistic protocol for certified email satisfying nine of the most important properties usually considered in the literature. We give a formal description of the protocol with the input/output automation (IOA) framework and provide a prototype implementation for the Windows platform.
Carlo Blundo, Stelvio Cimato, Roberto De Prisco
ISCC2
2003 Contrast optimal colored visual cryptography schemes
abstract
Visual cryptography schemes allow the encoding of a secret image into n shares which are distributed to the participants, such that only qualified subsets of participants can "visually" recover the secret image. In colored threshold visual cryptography schemes, the secret image is composed of pixels taken from a given set of c colors. We study c-color (k, n)-threshold visual cryptography schemes and provide a characterization of contrast optimal schemes. More specifically, we prove that there exists a contrast optimal scheme that is a member of a special set of schemes, which we call canonical schemes, and that satisfy strong symmetry properties. Then we use canonical schemes to provide a constructive proof of optimality, with respect to the pixel expansion, of c-color (n, n)-threshold visual cryptography schemes.
Stelvio Cimato, Roberto De Prisco, Alfredo De Santis
ITW1
2002 SAWM: a tool for secure and authenticated web metering
abstract
The aim of a metering system is the accurate measure of the number of accesses to a Web page in order to have feedback on the effectiveness of the advertising on the net. At the present, there are no standard means to measure the exposure of Web pages as well as the impact of online advertising campaigns. Indeed "traditional" metering techniques are afflicted by hit inflation and hit shaving attacks. In this paper we propose a framework to accurately count the number of visits to a Web site relying on cryptographic primitives. In this way it is possible to avoid cheating by any of the agents in such a framework. Furthermore, a viable implementation of a tool to securely monitor a Web site is discussed.
Carlo Blundo, Stelvio Cimato
SEKE2
2002 A lightweight protocol for the generation and distribution of secure e-coupons
abstract
A form of advertisement which is becoming very popular on the web is based on electronic coupon (e-coupon) distribution. E-coupons are the digital analogue of paper coupons which are used to provide customers with discounts or gift in order to incentive the purchase of some products. Nowadays, the potential of digital coupons has not been fully exploited on the web. This is mostly due to the lack of "efficient" techniques to handle the generation and distribution of e-coupons. In this paper we discuss models and protocols for e-coupons satisfying a number of security requirements. Our protocol is lightweight and preserves the privacy of the users, since it does not require any registration phase.
Carlo Blundo, Stelvio Cimato, Annalisa De Bonis
WWW2
2002 A note on optimal metering schemes
Carlo Blundo, Stelvio Cimato, Barbara Masucci
Inf. Process. Lett.2
1996 Engineering Formal Requirements: Analysis and Testing
Paolo Ciancarini, Stelvio Cimato, Cecilia Mascolo
SEKE2