Diana Berbecaru

dblp:72/1568 · also Diana Gratiela Berbecaru · DBLP profile ↗
← Back
30ranked-venue papers
25as first author
14since 2021 · last 2026
0000-0003-1930-9473ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 13 · 11 first-author · 9 since 2021Software engineering, systems software and programming languages · 5 · 5 first-author · 1 since 2021Security and privacy · 4 · 3 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 An Approach for Detecting Vulnerable TLS Connections Through Network Monitoring, Intrusion Detection and TLS Testing Tools
Diana Berbecaru, Antonio Lioy
COMPSAC1
2026 An Automatic Large-scale Tool for X.509v3 Certificate Collection and Analysis
Diana Berbecaru, Antonio Lioy, Anuar Elio Magliari
ICC1
2025 TC-NetTrack: An Approach for Creating Digital Evidences for Flows in IP Networks
abstract
Effective network forensics analysis necessitates the capability to reproduce any network event, irrespective of the user’s motivation, the characteristics of earlier events, and whether the origin of the events was an unauthorized intruder or a legitimate user. Numerous packet analyzers, network monitoring systems, and intrusion detection tools today enable network measurement and analysis through packet capturing, which facilitates the examination and reconstruction of network events and user activities. However, they lack the ability to offer cryptographic proof for the packet flows that have been captured. Building on this motivation, we provide the initial steps toward the development of TC-NetTrack: a device that utilizes trusted computing to generate digital proof for specific packet flows captured either on a node’s network interface or across a network link. Since TC-NetTrack needs to produce evidence that holds probative value, the most suitable method to achieve this is through digital signatures. However, signing each packet individually is not practical or efficient; therefore, we adopted a method known as tree chaining. We implemented this using Merkle trees alongside an optimized algorithm for traversing the tree, which conserves both space and time when the signer generates packet flow evidence. We assessed the tree chaining technique on three different platforms, each featuring varying processors and memory capacities. TC-NetTrack could be beneficial in application scenarios or use cases that demand verification of the recorded packet flows, including stock trading, financial applications, attack analysis, or military operations.
Diana Berbecaru
ISCC1
2025 TPValCert: Privacy-Preserving Trusted Proxy for Public Key Certificate Validation
abstract
Public key X. 509 certificates play a powerful role in promoting effective electronic identification, but some significant practical issues still affect their scalability. Every time a public key certificate is used, it must be validated by the system or application relying on it for security services, generically called also relying party. The validation involves several processing steps and checks, and it has been measured that many applications (still) perform it incompletely. Furthermore, privacy issues may occur when validating certificates, for example a website visited by a user could be revealed to external parties. We propose TPValCert, an architecture tailoring a trusted proxy to provide privacy-preserving certificate validation service to the relying parties. By exploiting TPValCert, a desktop, IoT, or mobile system that needs to validate a public-key certificate may execute a transaction with a trusted proxy, which performs validation by considering certificate policy parameters, privacy, and validation options received from the client and returns the validation status. Besides reducing complexity on the client, exploiting such trusted validation parties may also bring privacy benefits. To communicate with the clients, we consider the SCVP (Server-based Certificate Validation Protocol) or DVCS (Data Validation and Certification Server) protocols, even though, depending on the context, lighter formats could be considered. Our implementation efforts emphasize the possibility of pursuing a tradeoff between timeliness, privacy, and computational resource usage, via dynamic selection of several configurable options.
Diana Berbecaru
ISCC1
2024 Threat-TLS: A Tool for Threat Identification in Weak, Malicious, or Suspicious TLS Connections
abstract
Various applications running in network-based, mobile, Internet of Things, or embedded systems environments exploit the Transport Layer Security (TLS) protocol to secure communication channels. However, in the last decade, several attacks have been discovered that exploit weaknesses in the protocol specification, the extensions, the cryptographic algorithms, or in the implementation and deployment of TLS-enabled software or libraries. A classical solution to counter TLS attacks on a target is to scan the installed TLS software (via dedicated software or services) and update it with versions that are resistant to attacks. However, an (internal) attacker might even temporarily corrupt the end node so that it becomes vulnerable to TLS attacks. So, the TLS scanning operations should be performed often, wasting resources of the monitored target. We propose a network-based intrusion detection tool named Threat-TLS, aimed to individuate weak, suspicious, or malicious TLS connections in intercepted traffic by looking for TLS patterns that contain features exploited to perform attacks, like old protocol versions, weak algorithms, or extensions. We have tested the proposed tool in a testbed environment by exploiting two famous tools, namely Suricata and Zeek, illustrating its performance in detecting some TLS attacks.
Diana Berbecaru, Antonio Lioy
ARES1
2024 On Detecting Anomalous TLS Connections with Artificial Intelligence Models
abstract
In recent years, anomaly-based intrusion detection systems using machine learning (ML) and deep learning techniques have started to be developed to mitigate cybersecurity attacks. An anomaly-based intrusion detection system performs traffic analysis by exploiting supervised or unsupervised ML algorithms and raises alerts if a suspicious pattern is encountered. In this paper, we exploit the Autoencoder neural network model to detect variants of a very famous attack discovered in 2014, namely Heartbleed. The attack was caused by an implementation flaw in the OpenSSL library, widely used in web servers, database systems, or e-mail servers to support the Transport Layer Security (TLS) protocol. To evaluate our model, we exploited the CIC-IDS2017 dataset and a custom one created on purpose. The proposed model recognized the anomalous TLS connections containing variants of the Heartbleed attack and distinguished them from the benign traffic in 85% of the cases.
Diana Berbecaru, Stefano Giannuzzi
ISCC1
2024 On the evaluation of X.509 certificate processing in Transport Layer Security interceptors
abstract
The Transport Layer Security (TLS) interceptors are applications running on client devices or on separate machines that filter TLS-protected traffic between two endpoints. They split the original TLS channel into two TLS channels and they might significantly impact the security obtained. They are increasingly used and installed by numerous end users or network administrators. It is necessary to assess X.509 certificate processing in TLS interceptors since flaws or problems in performing this task correctly and completely may weaken the client’s communication security. We define X.509-related tests, which are divided into five categories based on which part(s) of the X.509 certificate fields or extensions get analyzed. We propose a method for automatically generating wrong, malformed, or unusual X.509 certificates (and chains) and configuration files suitable for the most common web servers, like Apache or Nginx. We deploy the generated configuration files on the TLS-aware web servers in an experimental testbed set up for testing the behavior of four selected TLS interceptors, two antivirus, and two proxy applications running on different operating systems. We report the results obtained, underlining the need to test in-depth such applications so that they would not decrease the security levels achieved by the clients.
Diana Berbecaru, Silvia Sisinni, Matteo Simone
ISCC1
2024 Shaping a Quantum-Resistant Future: Strategies for Post-Quantum PKI
abstract
As the quantum computing era approaches, securing classical cryptographic protocols becomes imperative. Public key cryptography is widely used for signature and key exchange but it’s the type of cryptography more threatened by quantum computing. Its application typically requires support via a public-key certificate, which is a signed data structure and must therefore face twice the quantum challenge: for the certified keys and for the signature itself. We present the latest developments in selecting robust Post-Quantum algorithms and investigate their applicability in the Public Key Infrastructure context. Our contribution entails defining requirements for a secure transition to a quantum-resistant Public Key Infrastructure, with a focus on adaptations for the X.509 certificate format. Additionally, we explore transitioning Certificate Revocation List and Online Certificate Status Protocol to support quantum-resistant algorithms. Through comparative analysis, we elucidate the complex transition to a quantum-resistant PKI.
Grazia D'Onghia, Diana Berbecaru, Antonio Lioy
ISCC2
2024 MATCH-IN: Mutual Attestation for Trusted Collaboration in Heterogeneous IoT Networks
abstract
As the Internet of Things (IoT) continues to evolve, ensuring the security and trustworthiness of devices within heterogeneous IoT networks becomes of paramount importance. This paper presents MATCH-IN (Mutual Attestation for Trusted Collaboration in Heterogeneous IoT Networks), a novel approach to establish trusted connections based on mutual attestation between IoT devices that dynamically join a network. Drawing inspiration from the Trusted Computing Group’s "Device Identifier Composition Engine" specification, MATCH-IN introduces a comprehensive scheme for device mutual attestation. The proposed schema enhances the security posture of unstructured IoT networks by enabling devices to mutually attest their identities and configurations, without the need for a centralized verifier for checking the trustworthiness of devices, while these operate in the field. Through a detailed exploration of the DICE specification, this paper provides insights into the integration of MATCH-IN within the context of diverse IoT environments. Our approach aims to foster trusted collaboration among heterogeneous IoT devices, laying the foundation for enhanced security and reliability in the rapidly expanding IoT landscape.
Silvia Sisinni, Diana Berbecaru, Valerio Donnini, Antonio Lioy
ISCC2
2024 Integrity Management in Softwarized Networks
abstract
Nowadays, there is a growing inclination towards network softwarization, wherein functions once handled by specialized hardware are now executed as software components on general-purpose nodes. This can be achieved with Network Function Virtualization (NFV) and Software Defined Networking (SDN), offering advantages such as flexibility and reduced equipment costs. However, these paradigms, reliant on software and operating as a distributed system, introduce security challenges, including threats to software integrity through network or physical manipulation. To address these concerns, Remote Attestation techniques can be employed to enable a party to assess the software and configuration integrity of a network node. In complex network environments, different attestation frameworks may be deployed, depending on the type of hardware and software to be attested. To streamline this process, we present an extended design and implementation of our Trust Monitor architecture, implementing the Trust Manager defined by ETSI for NFV environments. This enhances flexibility by supporting the integration of multiple attestation frameworks based on different technologies. We present also how the Trust Monitor integrates into the IETF RATS architecture and how it interacts with its other elements. Through experimental tests, we demonstrate that the proposed implementation is scalable and effective in attesting both physical and virtual entities, such as Kubernetes pods.
Enrico Bravi, Antonio Lioy, Diana Berbecaru
NOMS3
2023 TLS-Monitor: A Monitor for TLS Attacks
abstract
The Transport Layer Security (TLS) protocol is subject to intensive research resulting in a long list of TLS attacks discovered in the last decade. To test the resistance of a TLS server to attacks, several tools or services can be used nowadays, such as the famous Qualys SSL Server Test. Nevertheless, although a security administrator updates the TLS software and configuration, internal attacks or malicious code could change that TLS-installed code or its setting at any time to make it prone to attacks. Thus, either the TLS server configuration is checked continuously, or other techniques are needed to indicate that a running TLS server is potentially vulnerable to attacks. We propose TLS-Monitor, a TLS attack-aware network monitoring tool that inspects the traffic for a target system looking for known TLS vulnerabilities that may lead to attacks. Examples are the self-signed certificate(s) allowing to set up a man-in-the-middle attack or the TLS heartbeat extension for the Heartbleed attack. If a vulnerability is found, the proposed tool checks if the threat applies by launching specific TLS attacks. Ultimately it raises alarms and creates a report. The TLS-Monitor tool employs network monitoring tools, like Suricata and Zeek, and TLS attack tools, like TLS-Attacker or Metasploit. We successfully tested TLS-Monitor in a testbed environment for some selected attacks, including Heartbleed, MITM, and Bleichenbacher. We foresee to extend the tool in the future to support other TLS attacks.
Diana Berbecaru, Giuseppe Petraglia
CCNC1
2023 A Flexible Trust Manager for Remote Attestation in Heterogeneous Critical Infrastructures
abstract
Nowadays, critical infrastructures are managed through paradigms such as cloud/fog/edge computing and Network Function Virtualization (NFV), providing advantages as flexibility, availability, and reduced management costs. These paradigms introduce several advantages but – given their nature of physically distributed systems – leave room for various security threats, such as software integrity attacks. To counter these threats, Trusted Computing and Remote Attestation (RA) techniques can be used, to allow a third party (Verifier) to verify the software and configuration integrity of a platform (Attester). In environments composed of different objects, several RA frameworks (hardware-based, software-based, or hybrid) might need to be deployed, depending on the capabilities of the attested elements. To ease this process, we propose a new design and implementation of our Trust Monitor (TM) architecture, which implements the Trust Manager specified by ETSI for NFV environments, making it more flexible and usable in different contexts. In addition, we define a generic model for performing RA in heterogeneous environments by employing various RA technologies. More specifically, the extended TM allows flexible RA in hybrid infrastructures composed of different objects, i.e., physical nodes, virtual machines, containers, pods, and enclaves. Through tests performed in an experimental testbed, we show that the proposed implementation is scalable and usable in heterogeneous contexts.
Enrico Bravi, Diana Berbecaru, Antonio Lioy
CloudCom2
2023 Autoencoder-SAD: An Autoencoder-based Model for Security Attacks Detection
abstract
In recent years, a variety of cybersecurity attacks affected national infrastructures, big companies, and even medium size organizations. As countermeasures are implemented, new attack variants appear. Historically, signature-based and anomaly-based Intrusion Detection Systems (IDSs) are used for detecting abnormal network behavior. The signature-based IDS is typically effective against attacks for which attack signatures exist. The anomaly-based IDS instead performs traffic analysis and raises alerts when encountering suspicious network patterns. They can detect attacks without registered signatures through different mechanisms, including machine learning (ML) techniques. We propose Autoencoder-SAD, an anomaly-based detection model, which can individuate new cybersecurity attacks by exploiting the Autoencoder model. Through empirical tests with two datasets (CIC-IDS2017 and TORSEC), we evaluated Autoencoder-SAD against two supervised ML models (Random Forest and Extreme Gradient Boosting) and one semi-supervised Autoencoder-based model. The results are promising since our approach shows an AUC of 0.94 for known attacks and 0.68 for unknown attacks.
Diana Berbecaru, Stefano Giannuzzi, Daniele Canavese
ISCC1
2023 Exploiting Emercoin Blockchain and Trusted Computing for IoT Scenarios: A Practical Approach
abstract
Traditional Public Key Infrastructures (PKIs) seem not adequate for some Internet of Things (IoT) environments asking for fast, flexible, and secure solutions. Alternatively, IoT devices could generate asymmetric key pairs on their own, and store the relative public keys or X.509 certificates into a blockchain, e.g., Emercoin. Nevertheless, in some contexts, reliable device identification is still required. We extended an Emercoin-based decentralized PKI solution for IoT scenarios, by integrating the device's identification with a TPM (Trusted Platform Module) 2.0 to a specific trusted node in an IoT network named Device Manager (DM). Through experimental tests performed with a TPM 2.0-equipped Raspberry Pi 4 device, we evaluated the time spent registering the IoT devices into the blockchain, or establishing secure (TLS) channels. Even though the Emercoin-based TLS handshake time is higher than the standard one, the proposed solution remains a viable alternative in scenarios requiring flexibility and device identification.
Diana Berbecaru, Lorenzo Pintaldi
ISCC1
2019 Providing digital identity and academic attributes through European eID infrastructures: Results achieved, limitations, and future steps
abstract
Summary Electronic identity is getting an increased importance nowadays since relentless digitalization and 24/7 connectivity continue to transform everyday life. To support the recognition of electronic identification cross‐border within the European Union, the European Commission (EC) released the eIDAS Regulation, which became effective on September 2018. To put eIDAS in practice, the EC has supported the definition of the technical specification; it provides a sample implementation; and it coordinates the eIDAS Network composed of eIDAS nodes of various countries. Each eIDAS node has a generic part required for the communication with the other nodes, and a specific part that each country has to modify independently according to its legal, operational, and technical requirements. Although this specific part is very important because it affects the node flexibility and the interaction with the other actors at the national level, it is less known in practice. We describe the adaptation of this specific part in Italy to perform authentication and provision of attributes through the STORK and STORK 2.0 infrastructures (the predecessors of eIDAS), based on our experience in the homonym projects. Significant effort is spent currently to build real services exploiting the eIDAS infrastructure, eg, the eID4U project proposes eIDAS node extension with new attributes required by some common academic services, such as student registration at a foreign university. We describe the support for these new attributes in the eIDAS nodes and the modification of the specific part of the Italian eIDAS node to allow attributes retrieval from different authorities.
Diana Berbecaru, Antonio Lioy, Cesare Cameroni
Softw. Pract. Exp.1
2017 Towards Stronger Data Security in an eID Management Infrastructure
abstract
Electronic identity (eID) is on everyone's lips as is increasingly used in various services nowadays. In Europe, the EU (European Union) Regulation N.910/2014 on electronic identification and trust services for electronic transactions in the internal market (eIDAS Regulation) has also created a legal structure for electronic identification, signatures, seals and documents throughout EU, so an intensive work is spent on putting it in practice. In this paper, we describe first the e-SENS (Electronic Simple European Networked Services) infrastructure, which is composed of (national) nodes set as part of the STORK 2.0 eID infrastructure and new nodes implementing the eIDAS specification. Since the e-SENS infrastructure uses the SAML (Security Assertion Markup Language) for authentication and attribute transfer, the data security is strongly related to SAML security. Moreover, it depends also on architecture complexity. We analyze two possible solutions for stronger data security in e-SENS: one is based on the exploitation of the SAML Holderof-Key web browser profile, while the other one exploits the encryption of the SAML tokens. We present details in adopting such solutions in e-SENS infrastructure and we discuss their pros and cons.
Diana Berbecaru, Andrea S. Atzeni, Marco de Benedictis, Paolo Smiraglia
PDP1
2016 On the design, implementation and integration of an Attribute Provider in the Pan-European eID infrastructure
abstract
This paper describes the design and implementation of an Attribute Provider (AP), compatible with the protocol defined in the STORK 2.0 electronic identity European infrastructure that provides cross-border authentication and attribute management in web-based services. Currently, this infrastructure is used as basis in some European countries to implement the recently adopted eIDAS Regulation on electronic identification and trust services for electronic transactions in the internal market. For example, in the e-SENS project the existing nodes of the STORK 2.0 infrastructure are linked to new nodes implementing the eIDAS technical specification, to create a unique interoperability platform. In our work, we considered several key aspects that have been underlined by the National Strategy for Trusted Identities in Cyberspace in USA, e.g. the possibility to incorporate attribute services in identity architectures, the principle of data minimization (provide the minimum set of attributes required so the AP should not overshare as default), and the problem of user consent. We provide also a solution to integrate the proposed AP with an existing database. We believe our work is useful for various identity, attribute and service providers that would connect in the future to the eIDAS interoperability framework.
Diana Berbecaru, Antonio Lioy
ISCC1
2016 Efficient Attribute Management in a Federated Identity Management Infrastructure
abstract
Federated Identity Management technologies are exploited for user authentication in a number of network services but their ease of use and efficient attribute handling are still open issues. We present the STORK 2.0 pan-European infrastructure which supports attribute management, and we propose a data structure, named Attribute Object Identifier (AOI), and its integration into the STORK 2.0 architecture to allow faster access to attributes.
Diana Berbecaru, Antonio Lioy
PDP1
2015 Exploiting the European Union trusted service status list for certificate validation in STORK: design, implementation, and lessons learnt
abstract
Summary Since December 2009, the European Union Trusted Service Status Lists (TSLs) have been specified and adopted across European Union countries in order to enable the verification of digital signatures with legal values. This paper deals with the exploitation of TSLs in real digital services, other than electronic signatures, that is for certificate validation service. In particular, we used such lists in the service provided by the pan‐European Secure identTities acRoss boRders linKed identity management infrastructure in order to validate X.509 public key certificates. In addition, we propose an XML data structure to be used in conjunction with a TSL, in the form of a Trust Service Association (TrSA) file, to hold trust relationships between different services in a TSL. The TrSA file in conjunction with the TSLs may be used directly by the service providers or users to validate certificates. For the generation of the TSLs, we propose also a tool for automatic generation of the TSLs, named TSLGenerator. Copyright © 2014 John Wiley & Sons, Ltd.
Diana Berbecaru, Antonio Lioy
Softw. Pract. Exp.1
2013 FcgiOCSP: a scalable OCSP-based certificate validation system exploiting the FastCGI interface
abstract
SUMMARY Certificate validation, one of the most important and complex tasks in Public Key Infrastructures, is still a challenging topic nowadays because of the scalability and complexity issues related to this process. Validation of an X.509 certificate requires checking its revocation status, either by consulting the so‐called Certificate Revocation Lists or by contacting a specific server via the Online Certificate Status Protocol (OCSP). Because more and more entities extensively need to validate the certificates used for various purposes (such as digital signature, server authentication, and secure e‐mail), the OCSP servers become overloaded. Thus, an increasing effort is currently dedicated to the creation and management of scalable certificate validation architectures. In this work, we discuss scalability challenges in OCSP‐based certificate validation, and we propose a method to evaluate the OCSP server performance in stress conditions. Next, we experimentally measure the performance, expressed in terms of response time and throughput, of some open‐source OCSP implementations. Finally, we propose and evaluate our own scalable OCSP‐based certificate validation system, named FcgiOCSP, as it exploits the FastCGI interface. Experimental results demonstrate the high performance of FcgiOCSP with respect to other OCSP implementations evaluated in this work. Copyright © 2012 John Wiley & Sons, Ltd.
Diana Berbecaru, Matteo Maria Casalino, Antonio Lioy
Softw. Pract. Exp.1
2011 LRAP: A Location-Based Remote Client Authentication Protocol for Mobile Environments
abstract
Mobile networks are driven by the need to provide more advanced services to mobile or nomadic computing devices, such as security services requiring remote client authentication. In such services, the user's location might be used as authentication factor, in addition to the typical authentication factors, like passwords, or one time tokens combined with the use of a physical device that a person owns, such as a card or a phone. Since the location information itself is subject to forging attacks, additional mechanisms must be used to certify its integrity. We propose LRAP, a novel protocol combining several authentication factors to securely authenticate a mobile user. In LRAP, the user's location can be determined and its correctness is certified by a third trusted party, called Local Element. As use case, we considered the payment service at the self-service gas stations, a widely available service vulnerable to several types of security attacks, and we proposed an LRAP-based service exploiting one time codes and certified position for secure payment operations.
Diana Berbecaru
PDP1
2011 Exploiting Proxy-Based Federated Identity Management in Wireless Roaming Access
Diana Berbecaru, Antonio Lioy, Marco Domenico Aime
TrustBus1
2010 The ForwardDiffSig Scheme for Multicast Authentication
abstract
This paper describes ForwardDiffSig, an efficient scheme for multicast authentication with forward security. This scheme provides source authentication, data integrity, and non-repudiation since it is based on the use of asymmetric cryptography. At the same time, it offers also protection against key exposure as it exploits OptiSum, our optimized implementation of the ISum forward-secure signature scheme. A tradeoff exists in the used keys: Short keys provide speed at the signer, whereas long keys are preferable for long-term non-repudiation. Performance has been evaluated with a custom packet simulator and shows that, by grouping the packets, ForwardDiffSig is efficient in terms of speed even for long keys at the price of a significant signature overhead. Therefore, ForwardDiffSig is fast, exhibits low delay, and provides non-repudiation and protection against key exposure, but has a nonnegligible impact in applications with strict energy or bandwidth constraints.
Diana Berbecaru, Luca Albertalli, Antonio Lioy
IEEE/ACM Trans. Netw.1
2009 A unified and flexible solution for integrating CRL and OCSP into PKI applications
abstract
Abstract Public key certificates (PKCs) are used nowadays in several security protocols and applications, so as to secure data exchange via transport layer security channels, or to protect data at the application level by means of digital signatures. However, many security applications often fail to manage properly the PKCs, in particular when checking their validity status. These failures are partly due to the lack of experience (or training) of the users who configure these applications or protocols, and partly due to the scarce support offered by some common cryptographic libraries to the application developers. This paper describes the design and implementation of a light middleware dealing with certificate validation in a unified way. Our middleware exploits on one side the libraries that have already been defined or implemented for certificate validation, and it constructs a thin layer, which provides flexibility and security features to the upper layer applications. In our current approach, this layer boasts an integrated approach to support various certificate revocation mechanisms, it protects the applications from some common security attacks, and offers several configuration and performance options to the programmers and to the end users. We describe the architecture of this approach as well as its practical implementation in the form of a library based on the famous OpenSSL security library, and that can be easily integrated with other certificate‐aware security applications. Copyright © 2009 John Wiley & Sons, Ltd.
Diana Berbecaru, Amarkumar Desai, Antonio Lioy
Softw. Pract. Exp.1
2008 An Optimized Double Cache Technique for Efficient Use of Forward-secure Signature Schemes
abstract
The greatest threat against the security of a digital signature scheme is the exposure of the secret (signing) key, due to the compromise of the security of the underlying system or machine storing the key. This attack is known as key exposure attack, and hypothetically any security service that is provided via an online server digitally signing in real time the data (e.g. timestamping server) is exposed to such an attack. In this paper we perform one step forward towards optimizing the usage of Forward Secure Signature (FSS) schemes on large scale to mitigate key exposure attacks. First of all, we have performed extended tests with the already implemented OpenSSL-based libfss library, which supports several generic FSS schemes, such as ISum, BMTree or MMM schemes. We observed that one critical phase is the key update phase, which typically requires a large amount of time and resources. Thus, we propose an optimization technique for ISum scheme's implementation (named double cache updating technique), which makes use of two dedicated caches: one for the keys and one for the intermediate (hash) nodes. The results obtained are encouraging since the proposed double cache technique provides a constant key update time and a low memory footprint.
Diana Berbecaru, Luca Albertalli
PDP1
2008 On the Performance and Use of a Space-Efficient Merkle Tree Traversal Algorithm in Real-Time Applications for Wireless and Sensor Networks
abstract
With the advance of technology, Public key cryptography (PKC) will be used - sooner or later - in wireless and sensor applications not only to provide security services like authentication, integrity and non-repudiation on the data provided, but also to achieve a perfect connectivity and a perfect resilience in large-scale wireless and sensor networks. One of the weak points of PKC is its performance, and because of this reason several authentication approaches use efficient structures, like the Merkle hash trees (MHT), which are combined with the traditional PKC operations to produce secure but also time-efficient authentication solutions.This paper investigates the performance of a popular algorithm for traversal of large MHTs authored by M. Szydlo and demonstrates that several other parameters (not just the CPU processor) need to be taken into consideration when designing applications that use MHTs, like the signing time, the hash time, the depth of the MHT and the space available, since they impact directly on the performance of the overall application. Moreover, we construct two models to simulate the behaviour of a device that uses Szydlo's algorithm to authenticate large amounts of data, like a real-time data flow. We chose Szydlo's algorithm because it saves more space than other MHT traversal algorithms and we assumed that in our case study the space (and not necessarily the CPU power) is the resource to be considered critical.
Diana Berbecaru, Luca Albertalli
WiMob1
2006 On the Tradeoff between Performance and Security in OCSP-Based Certificate Revocation Systems for Wireless Environments
abstract
The Online Certificate Status Protocol (OCSP) specifies a mechanism used to determine the status of public-key certificates (PKC). OCSP deployments have been used so far to ensure timely and secure certificate status information for high-value electronic transactions, like in the banking environments. Nevertheless, since an OCSP responder operates always online it could be subject to the key exposure attack (problem). A solution to the last problem is given by the forward secure signature (FSS) schemes. This paper investigates various modifications of the OCSP-based certificate revocation systems for wireless environments using efficient generic FSS schemes, i.e. Bellare-Minner tree, the Iterated Sum construction and the MMM scheme. In the proposed systems we evaluate the tradeoff between the performance (i.e. response size and amount of computation required) and security (vulnerability to forgery).
Diana Berbecaru
ISCC1
2002 Security aspects in standard certificate revocation mechanisms: a case study for OCSP
abstract
One of the highly sensitive problems that need careful consideration when employing public-key technology in IT systems is the validation of the digital certificates used. In particular, one of the steps that must be performed is checking the revocation status of the certificate. With real-time revocation checking, a PKI-enabled system that needs to validate a certificate executes an on-line transaction with a specialized server - designated by a certification authority to provide signed responses containing certificate status information. At the end of the transaction, an indication of the current revocation status of the certificate is returned. This paper presents the implementation of a system providing online certificate status service to end entities and proposes a simple OCSP (on-line certificate status protocol) client API which can be easily integrated into PKI-aware applications with the aim of performing on-line revocation-checking. Finally, the implementation's performance was measured and the acquired results are presented and analyzed.
Diana Berbecaru, Antonio Lioy, Marius Marian
ISCC1
2001 On the Complexity of Public-Key Certificate Validation
Diana Berbecaru, Antonio Lioy, Marius Marian
ISC1
2000 A Flexible Management Framework for Certificate Status Validation
Antonio Corradi, Rebecca Montanari, Cesare Stefanelli, Diana Berbecaru, Antonio Lioy, Fabio Maino
SEC4