Michael Hitchens

dblp:89/6080 · DBLP profile ↗
← Back
64ranked-venue papers
5as first author
12since 2021 · last 2026
0000-0001-6320-9184ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 20 · 5 first-author · 1 since 2021Computer networks · 16 · 6 since 2021Human-computer interaction and ubiquitous computing · 11 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 8 · 2 since 2021Software engineering, systems software and programming languages · 7 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 since 2021Artificial intelligence and machine learning · 3Systems, architecture and hardware · 2Databases, data management, data science and information retrieval · 1Theory of computation · 1
YearPublicationVenuePosition
2026 Zero trust-driven access control delegation using blockchain
abstract
As digital ecosystems become more complex with decentralized technologies like the Internet of Things (IoT) and blockchain, traditional access control models fail to meet the security needs of dynamic, high-risk environments. The need for dynamic, fine-grained access control mechanisms has become critical, particularly in environments where trust must be continuously evaluated, and access decisions must adapt to real-time conditions. Traditional models often rely on static identity management and centralized trust assumptions, which are inadequate for modern, decentralized, and highly dynamic environments such as IoT ecosystems. Consequently, existing solutions lack fine-grained identity management, flexible delegation, and continuous trust evaluation, highlighting the need for a more robust, adaptive, and decentralized access control architecture. To address these gaps, this paper presents a novel access control architecture that integrates self-sovereign identity (SSI) and decentralized identifier (DID)-based access control with zero trust principles, enhanced by a flexible capability-based access control (CapBAC) approach. Leveraging SSI and DID allows entities to manage their identities without relying on a central authority, aligning with zero-trust principles. The integration of CapBAC ensures flexible, context-aware, and attribute-based access control, where access rights are dynamically granted based on the requester's capabilities. This enables fine-grained delegation of access rights, allowing trusted entities to delegate specific privileges to others without compromising overall security. Continuous trust evaluation is employed to assess the authenticity of access requests, mitigating the risks posed by compromised devices or users. The proposed architecture also incorporates blockchain technology to ensure transparent, immutable, and secure management of access logs, providing traceability and accountability for all access events. We demonstrate the feasibility and effectiveness of this solution through performance evaluations and comparisons with existing access control schemes, showing its superior security, scalability, and adaptability in real-world scenarios. Our work demonstrates a comprehensive, decentralized, and scalable solution for secure access control delegation using zero trust-driven principles.
Rahma Mukta, Shantanu Pal, Kowshik Chowdhury, Michael Hitchens, Hye-Young Paik, Salil S. Kanhere
Blockchain Res. Appl.4
2024 Experiential Learning or Direct Training: Fostering Ethical Cybersecurity Decision-Making via Serious Games
Bakhtiar Sadeghi, Debbie Richards 0001, Paul Formosa, Michael Hitchens
PERSUASIVE4
2024 A Blockchain-Based Approach for Parametric Insurance Under Multiple Sources of Truth
abstract
The use of parametric insurance is promising as its payouts can be directly tied to hazard indicators and thus provide a fast-tracked claim-to-payout process, which improves liquidity in times of disaster. In parametric insurance, policies are determined by a loss threshold (modelled or sustained) or physical hazard severity (e.g., rainfall or wind speed). In the latter, when the severity of the hazard exceeds a threshold, a payout is automatically triggered according to the insurance contract terms to compensate the policyholder without needing a loss assessment. Recently, blockchains have been proposed to improve the efficiency of insurance product offerings (e.g., to cut administrative costs associated with the premium collection and claim processing) and to efficiently store and maintain information (e.g., immutable distributed storage for audits). While parametric insurance would certainly benefit from these blockchain implementations, existing proposals mostly depend on a single source of truth for payout calculations. In this paper, we present a novel trust-based framework to handle multiple sources of truth in parametric insurance products which use blockchain technology. This framework alleviates the reliance on a single point of failure (either through accidents or malicious abuses) and outperforms its statistical counterparts. We discuss how parametric insurance would work under such a framework using real-world use-case scenarios, show the use of subjective logic to reason about multiple sources of truth, present the architecture of the framework, and examine a detailed blockchain-based implementation using an Ethereum private blockchain. Our results show the feasibility of the proposed system in practice.
Tahiry M. Rabehaja, Shantanu Pal, Ambrose Hill, Michael Hitchens
IEEE Trans. Serv. Comput.4
2023 A Blockchain-Based Interoperable Architecture for IoT with Selective Disclosure of Information
abstract
With the improvement of Internet of Things (IoT) technologies, services, and applications, there is a proliferation of access to smart devices in everyday life. However, granting access and controlling access rights for each resource is challenging in highly dynamic and large-scale IoT deployments. In particular, multiple access information may need to be provided to an entity when granting access rights to several resources. The situation becomes more complex when an entity is required to share its identity attribute to receive the access information. These raise the question of what identity information an entity needs to provide to obtain the required access to a particular resource and, subsequently, what access information needs to be provided when accessing that resource. That said, there is a need for a flexible approach where an entity can share a distinct identity and access attributes for accessing a resource without revealing additional information. Such flexibility in sharing information is significant given the privacy risk of an entity’s identity. This paper presents an architecture that delivers access rights to an entity with selective disclosure of information. Our approach ensures the minimum exchange of information (identity and access attribute) to enhance an entity’s privacy when granting access rights to an entity. We use blockchain to provide data authenticity (i.e., tamper-proof), transparency and automatic execution of access rights based on shared attributes using smart contracts. We implement a proof of concept of the proposed system using Hyperledger fabric as a permissioned blockchain network. Our results demonstrate the feasibility of the proposed system showing efficiency in granting access rights.
Rahma Mukta, Shantanu Pal, Hye-Young Paik, Salil S. Kanhere, Michael Hitchens
PRDC6
2023 A trust-aware openflow switching framework for software defined networks (SDN)
abstract
Software Defined Networks (SDN) and Network Function Virtualisation (NFV) are prime driving technologies behind 5G and Beyond 5G (B5G) communications. The network control intelligence segregation in the SDN infrastructure enables dynamic network features (such as dynamic end-to-end management of security and quality of service (QoS)) offering significantly improved network performance. Even if one assumes that the centralised SDN controller can be security hardened and hence can be trusted, a fundamental challenge in such networks is that the data plane and switching devices are susceptible to cyberattacks. A malicious adversary can compromise them during run-time making them unreliable for secure and trusted communications. Furthermore, the controller communicating with OpenFlow switching devices is unable to accurately assess the state of the switching devices, which serves as the communication base for NFVs in 5G networks. Vulnerable switching devices can put the whole 5G network infrastructure at risk. Hence, there is a clear need for the controller and the management layer to determine the trustworthiness of the switching devices at run-time. The current trend is for many such devices to deploy trusted computing functionality such as Trusted Platform Module (TPM) or Software Guard Extension (SGx) to achieve local as well as remote attestation. In this paper, we present a dynamic trust management framework for evaluating the trustworthiness of the OpenFlow switching devices deployed in the SDN based networks. We formulate device properties that need to be assessed to determine the trust status of the device. We develop a trust enhanced security architecture which can be used to evaluate the trustworthiness of devices and determine their deployment in the provision of network services. The proposed framework uses subjective logic based techniques to derive trust levels of the switching devices at run-time, which are then used by the architecture to make trust enhanced decisions on the provision of network services. A prototype implementation of the proposed architecture is described, which demonstrates how the trustworthiness of the OpenFlow devices are assessed at run-time. The paper concludes with the performance and security analysis of the implemented trust enhanced architecture services.
Kallol Krishna Karmakar, Vijay Varadharajan, Michael Hitchens, Udaya Kiran Tupakula, Prajna Sariputra
Comput. Networks3
2022 Design of a Serious Game for Cybersecurity Ethics Training
Malcolm R. K. Ryan, Mitchell W. McEwan, Vedant Sansare, Paul Formosa, Debbie Richards 0001, Michael Hitchens
DiGRA6
2022 An Exploitation Ecosystem Model for Fan-based Labour in the Games Industry
Christopher McCutcheon, Michael Hitchens, Mitchell W. McEwan
DiGRA2
2022 VeriBlock: A Blockchain-Based Verifiable Trust Management Architecture with Provable Interactions
abstract
There has been considerable advancement in the use of blockchain for trust management in large-scale dynamic systems. In such systems, blockchain is mainly used to store the trust score or trust-related information of interactions among the various entities. However, present trust management archi-tectures using blockchain lack verifiable interactions among the entities on which the trust score is calculated. In this paper, we propose a blockchain-based trust management framework that allows independent trust providers to implement different trust metrics on a common set of trust evidence and provide individual trust value. We employ geo-location as proof of interaction. Some of the existing proposals rely upon geo-location data, but they do not support trust calculation by multiple trust providers. Instead, they can only support a centralised system. Our proposed architecture does not depend upon a single centralised third-party entity to ensure trusted interactions. Our architecture is supported by provable interactions that can easily be verified using blockchain. Therefore, it allows a high degree of confidence in trust management by ensuring the actual interactions between the entities. We provide a detailed design and development of the architecture using real-world use case examples. The proof of prototype was implemented on the Ethereum blockchain platform. Experimental results demonstrate that the employment of independent trust providers adequately provides a high degree of trust scores and that the proposed architecture can be used in a real-world environment.
Shantanu Pal, Ambrose Hill, Tahiry M. Rabehaja, Michael Hitchens
ICCCN4
2022 SDPM: A Secure Smart Device Provisioning and Monitoring Service Architecture for Smart Network Infrastructure
abstract
The Internet of Things (IoT) are becoming a prevalent part of our society offering operational flexibility and convenience. However, insecure provisioning makes the IoT devices susceptible to various cyberattacks. For instance, mal-provisioned devices may leak sensitive information allowing the attackers to eavesdrop or disrupt communication infrastructures. Furthermore, compromised devices can act as zombies to intensify the scale of the attack. Hence, we need secure device provisioning services which can counteract such attacks and adverse circumstances. This article proposes a secure smart device provisioning and monitoring service architecture (SDPM) for smart network infrastructures, such as IoT-enabled smart home or office and Industrial IoT infrastructures. Our architecture allows the provisioning of devices in such a way that the malicious devices can be controlled and their activities using a dynamic policy-based approach. SDPM introduces an IoT device ontology for device registration and authentication and uses the ontology to construct device category and service-specific policies. SDPM provides a fine granular pre and post condition-based policies to provision securely the IoT devices and control their runtime operations. Furthermore, SDPM utilizes the digital twin concept, to monitor dynamically the security status of IoT devices at runtime. The policies associated with a device’s twin enables the SDPM to automate security capabilities, such as device firmware updating and patching for security vulnerabilities.
Kallol Krishna Karmakar, Vijay Varadharajan, Pete Speirs, Michael Hitchens, Aron Robertson
IEEE Internet Things J.4
2022 Toward a Trust Aware Network Slice-Based Service Provision in Virtualized Infrastructures
abstract
Future communication networks such as 5G are expected to support end-to-end delivery of services for several vertical markets with diverging requirements. Network slicing is a key construct that is used to provide end to end logical virtual networks running on a common virtualised infrastructure, which are mutually isolated. Having different network slices operating over the same 5G infrastructure creates several challenges in security and trust. This paper addresses the fundamental issue of trust of a network slice. It presents a trust model and property-based trust attestation mechanisms, which can be used to evaluate the trust of the virtual network functions that compose the network slice. The proposed model helps to determine the trust of the virtual network functions, as well as the properties that should be satisfied by the virtual platforms (both at boot and run time), on which these network functions are deployed for them to be trusted. We present a logic-based language that defines simple rules for the specification of properties and the conditions under which these properties need to be satisfied for trusted virtualized platforms. The proposed trust model and mechanisms enable the service providers to determine the trustworthiness of the network services as well as the users to develop trustworthy applications. We have developed a trust management architecture that enables the service providers to determine the trustworthiness of the network slices providing the network services. We have implemented a prototype of the trust management architecture using the Open Source MANO Platform and presented the performance results. The results show that our trust mechanisms cause only a slight reduction in the performance of network slices over virtualized infrastructure. We have also discussed how the proposed architecture can be used to detect and mitigate the impact of malicious virtual network functions in a dynamic manner.
Vijay Varadharajan, Kallol Krishna Karmakar, Udaya Kiran Tupakula, Michael Hitchens
IEEE Trans. Netw. Serv. Manag.4
2021 A blockchain-based trust management framework with verifiable interactions
Shantanu Pal, Ambrose Hill, Tahiry M. Rabehaja, Michael Hitchens
Comput. Networks4
2021 A Graph-Based Fault-Tolerant Approach to Modeling QoS for IoT-Based Surveillance Applications
abstract
Node scheduling provides an effective way to prolong the network lifetime of Internet-of-Things (IoT) networks comprising of energy-constrained sensor nodes. Barrier scheduling is a special type of node scheduling scheme that targets IoT-based surveillance applications. An efficient barrier scheduling scheme must address the key Quality-of-Service (QoS) requirements of smart surveillance applications, such as coverage, connectivity, and energy efficiency. Moreover, such a scheme must be capable of dynamically adapting its execution strategy in the event of node failures caused due to faults arising out of unexpected battery depletion. This article proposes a fault-tolerant barrier scheduling scheme that satisfies the key QoS requirements of surveillance applications in the event of such faults. The approach is based on a novel fully weighted dynamic graph model. This article suggests two novel heuristics to guarantee fault tolerance and recovery. Extensive simulation studies are conducted to evaluate and compare the performance and effectiveness of this scheme with other such approaches.
Diya Thomas, Mehmet A. Orgun, Michael Hitchens, Rajan Shankaran, Subhas Mukhopadhyay, Wei Ni 0001
IEEE Internet Things J.3
2020 Towards a Dynamic Policy Enhanced Integrated Security Architecture for SDN Infrastructure
abstract
Enterprise networks are increasingly moving towards Software Defined Networking, which is becoming a major trend in the networking arena. With the increased popularity of SDN, there is a greater need for security measures for protecting the enterprise networks. This paper focuses on the design and implementation of an integrated security architecture for SDN based enterprise networks. The integrated security architecture uses a policy-based approach to coordinate different security mechanisms to detect and counteract a range of security attacks in the SDN. A distinguishing characteristic of the proposed architecture is its ability to deal with dynamic changes in the security attacks as well as changes in trust associated with the network devices in the infrastructure. The adaptability of the proposed architecture to dynamic changes is achieved by having feedback between the various security components/mechanisms in the architecture and managing them using a dynamic policy framework. The paper describes the prototype implementation of the proposed architecture and presents security and performance analysis for different attack scenarios. We believe that the proposed integrated security architecture provides a significant step towards achieving a secure SDN for enterprises.
Kallol Krishna Karmakar, Vijay Varadharajan, Udaya Kiran Tupakula, Michael Hitchens
NOMS4
2020 On the Integration of Blockchain to the Internet of Things for Enabling Access Right Delegation
abstract
With the advancement of the Internet of Things (IoT) in recent years, there is a bigger potential to use online services than ever before. The use of the IoT brings numerous opportunities for both service providers and end users, however, it faces critical questions of security and privacy. Toward this, access control is one of the significant security challenges for the IoT, in particular, considering the characteristics of such IoT systems. To develop a secure access control architecture for the IoT, the propagation of access right delegation is a major issue. Many proposals present access control issues for the IoT but given the specific context of access right delegation, it is still in its infancy. This article presents an approach to address such a delegation issue for the IoT using the blockchain technology. We propose a delegation model that employv the critical issues, e.g., the use of nonunique identities, asynchronous and flexible delegation nature of communication for the IoT without the need of a centralized system. The goal of our primitive is to use attributes for validating the identity of an entity instead of relying on a concrete unique identity of an entity. To provide privacy for the attributes, we propose a dual blockchain architecture that moves the attribute storage and access of the public blockchain and onto a secure private blockchain. To demonstrate the feasibility of our proposed approach, we evaluate the system performances using the Ethereum blockchain network.
Shantanu Pal, Tahiry M. Rabehaja, Ambrose Hill, Michael Hitchens, Vijay Varadharajan
IEEE Internet Things J.4
2020 On the Design of a Flexible Delegation Model for the Internet of Things Using Blockchain
abstract
The Internet of things (IoT) presents new opportunities and challenges due to its scale and dynamic nature. One significant challenge for the IoT is the need for security, in particular access control solutions, that are designed to meet the characteristics of these systems. Delegation of rights, from one entity to another, is a crucial component of an access control system. The IoT requires a secure, flexible, and fine-grained delegation model. While there has been considerable work in the area of delegation, much of it assumes a centralized, well-resourced system and these solutions have limited capacity in the context of the IoT. Where delegation models for the IoT have been proposed they typically provide only coarse-grained control over the delegation of rights. Moreover, many of them require a centralized trusted authority, which can suffer from a single-point failure and is not an ideal base for a large and dynamic system like the IoT. In this paper, we propose an identity-less, asynchronous, and decentralized delegation model for the IoT based on blockchain technology. We describe system components, architecture, and key aspects related to the security of the system. We use attributes to validate an entity rather than depending upon unique identities. We demonstrate the feasibility of our model through use-case examples and analyze the performance with a proof of concept testbed implementation using Ethereum private blockchain.
Shantanu Pal, Tahiry M. Rabehaja, Michael Hitchens, Vijay Varadharajan, Ambrose Hill
IEEE Trans. Ind. Informatics3
2019 Design and implementation of a secure and flexible access-right delegation for resource constrained environments
Tahiry M. Rabehaja, Shantanu Pal, Michael Hitchens
Future Gener. Comput. Syst.3
2019 Policy-based access control for constrained healthcare resources in the context of the Internet of Things
Shantanu Pal, Michael Hitchens, Vijay Varadharajan, Tahiry M. Rabehaja
J. Netw. Comput. Appl.2
2019 A Policy-Based Security Architecture for Software-Defined Networks
abstract
As networks expand in size and complexity, they pose greater administrative and management challenges. Software-defined networks (SDNs) offer a promising approach to meeting some of these challenges. In this paper, we propose a policy-driven security architecture for securing end-to-end services across multiple SDN domains. We develop a language-based approach to design security policies that are relevant for securing SDN services and communications. We describe the policy language and its use in specifying security policies to control the flow of information in a multi-domain SDN. We demonstrate the specification of fine-grained security policies based on a variety of attributes, such as parameters associated with users and devices/switches, context information, such as location and routing information, and services accessed in SDN as well as security attributes associated with the switches and controllers in different domains. An important feature of our architecture is its ability to specify path- and flow-based security policies that are significant for securing end-to-end services in SDNs. We describe the design and the implementation of our proposed policy-based security architecture and demonstrate its use in scenarios involving both intra- and inter-domain communications with multiple SDN controllers. We analyze the performance characteristics of our architecture as well as discuss how our architecture is able to counteract various security attacks. The dynamic security policy-based approach and the distribution of corresponding security capabilities intelligently as a service layer that enables flow-based security enforcement and protection of multitude of network devices against attacks are important contributions of this paper.
Vijay Varadharajan, Kallol Krishna Karmakar, Udaya Kiran Tupakula, Michael Hitchens
IEEE Trans. Inf. Forensics Secur.4
2018 Incremental Acquisition of Values to Deal with Cybersecurity Ethical Dilemmas
Debbie Richards 0001, Virginia Dignum, Malcolm R. K. Ryan, Michael Hitchens
PKAW4
2018 Policy-Based Access Control for Constrained Healthcare Resources
abstract
In this paper, we propose an access control architecture for constrained healthcare resources in the IoT. Our policy-based approach provides fine-grained access for authorised users to services while protecting valuable resources from unauthorised access. We use a hybrid approach by employing attributes, roles and capabilities for our authorisation design. We apply attributes for role membership assignment and in permission evaluation. Membership of roles grants capabilities. The capabilities which are issued may be parameterised based on further attributes of the user and are then used to access specific services provided by IoT devices. This significantly reduces the number of policies required for specifying access control settings. The proposed scheme is XACML driven. Our approach requires very little additional overhead when compared to other proposals employing capabilities for access control in the IoT. We have implemented a proof of concept prototype and provide a performance evaluation of the implementation.
Shantanu Pal, Michael Hitchens, Vijay Varadharajan, Tahiry M. Rabehaja
WOWMOM2
2017 eSport vs irlSport
abstract
This paper examines in-real-life (irl) sport and eSports in an attempt to clarify the definition of eSport. The notion of physicality and embodiment are central to the need for clarity in understanding of what eSports are and whether they are sport or some other activity. By examining existing definitions of eSport and irlSport we can identify the similarities and differences between these activities. Methodologically the paper uses the philosophical process of critical thinking and analysis to examine the various approaches taken to defining both eSport and irlSports. Our aim is to highlight the inherent problem of the definition of eSports and irlSports (and the privileging of the term sport as it currently applies only to irlSports). We find that eSports are sports and that the definition of sport should be expanded to include sub-categories of irlSports and eSports.
Christopher McCutcheon, Michael Hitchens, Anders Drachen
ACE2
2017 Towards a Secure Access Control Architecture for the Internet of Things
abstract
In this paper, we propose an access control architecture for IoT systems by developing a hybrid model with attributes, capabilities and role-based access control. We apply attributes for role-membership assignment and in permission evaluation, Membership of roles grants capabilities which are used to access specific services provided by things. This approach improves policy management for IoT systems with a large number of things and users.
Shantanu Pal, Michael Hitchens, Vijay Varadharajan
LCN2
2017 On Design of A Fine-Grained Access Control Architecture for Securing IoT-Enabled Smart Healthcare Systems
abstract
The Internet of Things (IoT) is facilitating the development of novel and cost-effective applications that promise to deliver efficient and improved medical facilities to patients and health organisations. This includes the use of smart 'things' as medical sensors attached to patients to deliver real-time data. However, the security of patient data is an ever-present concern in the healthcare arena. In the wider deployment of IoT-enabled smart healthcare systems one particular issue is the need to protect smart 'things' from unauthorised access. Commonly used access control approaches e.g. Attribute Based Access Control (ABAC), Role Based Access Control (RBAC) and capability based access control do not, in isolation, provide a complete solution for securing access to IoT-enabled smart healthcare devices. They may, for example, require an overly-centralised solution or an unmanageably large policy base. To address these issues we propose a novel access control architecture which improves policy management by reducing the required number of authentication policies in a large-scale healthcare system while providing fine-grained access control. We devise a hybrid access control model employing attributes, roles and capabilities. We apply attributes for role-membership assignment and in permission evaluation. Membership of roles grants capabilities. The capabilities which are issued may be parameterised based on further attributes of the user and are then used to access specific services provided by IoT 'things'. We also provide a formal specification of the model and a description of its implementation and demonstrate its application through different use-case scenarios. Evaluation results of core functionality of our architecture are provided.
Shantanu Pal, Michael Hitchens, Vijay Varadharajan, Tahiry M. Rabehaja
MobiQuitous2
2017 An empirical investigation of the influence of persona with personality traits on conceptual design
Farshid Anvari, Debbie Richards 0001, Michael Hitchens, Muhammad Ali Babar 0001, Hien Minh Thi Tran, Peter Busch 0001
J. Syst. Softw.3
2015 Cross-Domain Attribute Conversion for Authentication and Authorization
abstract
In bio-security emergencies, such as an outbreak of an exotic animal disease, it is essential that the organizations involved in combating this outbreak collaborate effectively and efficiently. To achieve such a collaboration potentially confidential infrastructure and resources need to be shared amongst members of the participating organizations. In AU2EU we demonstrate the combination of existing data minimizing authentication, attribute-based authorization technologies to dynamically enable collaborations between these organization. However, a key problem that occurs during the establishment of such collaboration is different terminologies for similar authorization attributes. To overcome these differences and to minimize the overhead for new organizations to join an existing consortium we propose an ontology-based solution for converting attributes from one domain vocabulary to another. Additionally, we propose a methodology to construct a shared domain vocabulary. Using a shared domain vocabulary in the conversion process decreases the amount of alignments required for collaborating. We integrate and demonstrate the feasibility of this approach in a real-life scenario within the scope of AU2EU. This paper presents preliminary work, which is currently being deployed and will be evaluated in the upcoming months.
Stefan Thaler, Jerry den Hartog, Dhouha Ayed, Dieter Sommer, Michael Hitchens
ARES5
2015 Effectiveness of Persona with Personality Traits on Conceptual Design
abstract
Conceptual design is an important skill in Software Engineering. Teaching conceptual design that can deliver a useful product is challenging, particularly when access to real users is limited. This study explores the effects of the use of Holistic Personas (i.e. a persona enriched with personality traits) on students' performance in creating conceptual designs. Our results indicate that the students were able to identify the personality traits of personas and their ratings of the personalities match closely with the intended personalities. A majority of the participants stated that their designs were tailored to meet the needs of the given personas' personality traits. Results suggest that the Holistic Personas can help students to take into account personality traits in the conceptual design process. Further studies are warranted to assess the value of incorporating Holistic Personas in conceptual design training for imparting skills of producing in-depth design by taking personalities into account.
Farshid Anvari, Debbie Richards 0001, Michael Hitchens, Muhammad Ali Babar 0001
ICSE (2)3
2015 Provenance Based Classification Access Policy System Based on Encrypted Search for Cloud Data Storage
Vijay Varadharajan, Michael Hitchens
ISC3
2015 Trust Enhanced Cryptographic Role-Based Access Control for Secure Cloud Data Storage
abstract
Cloud data storage has provided significant benefits by allowing users to store massive amount of data on demand in a cost-effective manner. To protect the privacy of data stored in the cloud, cryptographic role-based access control (RBAC) schemes have been developed to ensure that the data can only be accessed by those who are allowed by access policies. However, these cryptographic approaches do not address the issues of trust. In this paper, we propose trust models to reason about and to improve the security for stored data in cloud storage systems that use cryptographic RBAC schemes. The trust models provide an approach for the owners and roles to determine the trustworthiness of individual roles and users, respectively, in the RBAC system. The proposed trust models consider role inheritance and hierarchy in the evaluation of trustworthiness of roles. We present a design of a trust-based cloud storage system, which shows how the trust models can be integrated into a system that uses cryptographic RBAC schemes. We have also considered practical application scenarios and illustrated how the trust evaluations can be used to reduce the risks and to enhance the quality of decision making by data owners and roles of cloud storage service.
Vijay Varadharajan, Michael Hitchens
IEEE Trans. Inf. Forensics Secur.3
2014 Cultivation Planning Application to Enhance Decision Making among Sri Lankan Farmers
Tamara Ginige, Debbie Richards 0001, Michael Hitchens
PKAW3
2014 Secure administration of cryptographic role-based access control for large-scale cloud storage systems
Vijay Varadharajan, Michael Hitchens
J. Comput. Syst. Sci.3
2014 Antivirus security: naked during updates
abstract
The security of modern computer systems heavily depends on security tools, especially on antivirus software solutions. In the anti-malware research community, development of techniques for evading detection by antivirus software is an active research area. This has led to malware that can bypass or subvert antivirus software. The common strategies deployed include the use of obfuscated code and staged malware whose first instance (usually installer such as dropper and downloader) is not detected by the antivirus software. Increasingly, most of the modern malware are staged ones in order for them to be not detected by antivirus solutions at the early stage of intrusion. The installers then determine the method for further intrusion including antivirus bypassing techniques. Some malware target boot and/or shutdown time when antivirus software may be inactive so that they can perform their malicious activities. However, there can be another time frame where antivirus solutions may be inactive, namely, during the time of update. All antivirus software share a unique characteristic that they must be updated at a very high frequency to provide up-to-date protection of their system. In this paper, we suggest a novel attack vector that targets antivirus updates and show practical examples of how a system and antivirus software itself can be compromised during the update of antivirus software. Local privilege escalation using this vulnerability is also described. We have investigated this design vulnerability with several of the major antivirus software products such as Avira, AVG, McAfee, Microsoft, and Symantec and found that they are vulnerable to this new attack vector. The paper also discusses possible solutions that can be used to mitigate the attack in the existing versions of the antivirus software as well as in the future ones. Copyright © 2013 John Wiley & Sons, Ltd.
Byungho Min, Vijay Varadharajan, Udaya Kiran Tupakula, Michael Hitchens
Softw. Pract. Exp.4
2013 Evaluating the Impact of the Human-Agent Teamwork Communication Model (HAT-CoM) on the Development of a Shared Mental Model
Nader Hanna, Debbie Richards 0001, Michael Hitchens
PRIMA3
2013 Trust-based Secure Cloud Data Storage with Cryptographic Role-based Access Control
Vijay Varadharajan, Michael Hitchens
SECRYPT3
2013 Achieving Secure Role-Based Access Control on Encrypted Data in Cloud Storage
abstract
With the rapid developments occurring in cloud computing and services, there has been a growing trend to use the cloud for large-scale data storage. This has raised the important security issue of how to control and prevent unauthorized access to data stored in the cloud. One well known access control model is the role-based access control (RBAC), which provides flexible controls and management by having two mappings, users to roles and roles to privileges on data objects. In this paper, we propose a role-based encryption (RBE) scheme that integrates the cryptographic techniques with RBAC. Our RBE scheme allows RBAC policies to be enforced for the encrypted data stored in public clouds. Based on the proposed scheme, we present a secure RBE-based hybrid cloud storage architecture that allows an organization to store data securely in a public cloud, while maintaining the sensitive information related to the organization's structure in a private cloud. We describe a practical implementation of the proposed RBE-based architecture and discuss the performance results. We demonstrate that users only need to keep a single key for decryption, and system operations are efficient regardless of the complexity of the role hierarchy and user membership in the system.
Vijay Varadharajan, Michael Hitchens
IEEE Trans. Inf. Forensics Secur.3
2012 Trusted Administration of Large-Scale Cryptographic Role-Based Access Control Systems
abstract
There has been an increasing trend towards outsourcing data to the cloud to cope with the massive increase in the amount of data. Hence trusted enforcement of access control policies on outsourced data in the cloud has become a significant issue. In this paper we address trusted administration and enforcement of role-based access control policies on data stored in the cloud. Role-based access control (RBAC) simplifies the management of access control policies by creating two mappings; roles to permissions and users to roles. Recently crypto-based RBAC (C-RBAC) schemes have been developed which combine cryptographic techniques and access control to secured data in an outsourced environment. In such schemes, data is encrypted before outsourcing it and the ciphertext data is stored in the untrusted cloud. This ciphertext can only be decrypted by those users who satisfy the role-based access control policies. However such schemes assume the existence of a trusted administrator managing all the users and roles in the system. Such an assumption is not realistic in large-scale systems as it is impractical for a single administrator to manage the entire system. Though administrative models for RBAC systems have been proposed decentralize the administration tasks associated with the roles, these administrative models cannot be used in the C-RBAC schemes, as the administrative policies cannot be enforced in an untrusted distributed cloud environment. In this paper, we propose a trusted administrative model AdC-RBAC to manage and enforce role-based access policies for C-RBAC schemes in large-scale cloud systems. The AdC-RBAC model uses cryptographic techniques to ensure that the administrative tasks such as user, permission and role management are performed only by authorized administrative roles. Our proposed model uses role-based encryption techniques to ensure that only administrators who have the permissions to manage a role can add/revoke users to/from the role and owners can verify that a role is created by qualified administrators before giving out their data. We show how the proposed model can be used in an untrusted cloud while guaranteeing its security using cryptographic and trusted access control enforcement techniques.
Vijay Varadharajan, Michael Hitchens
TrustCom3
2011 Enforcing Role-Based Access Control for Secure Data Storage in the Cloud
abstract
In recent times, there has been increasing interest in storing data securely in the cloud environment. To provide owners of data stored in the cloud with flexible control over access to their data by other users, we propose a role-based encryption (RBE) scheme for secure cloud storage. Our scheme allows the owner of data to store it in an encrypted form in the cloud and to grant access to that data for users with specific roles. The scheme specifies a set of roles to which the users are assigned, with each role having a set of permissions. The data owner can encrypt the data and store it in the cloud in such a way that only users with specific roles can decrypt the data. Anyone else, including the cloud providers themselves, will not be able to decrypt the data. We describe such an RBE scheme using a broadcast encryption algorithm. The paper describes the security analysis of the proposed scheme and gives proofs showing that the proposed scheme is secure against attacks. We also analyse the efficiency and performance of our scheme and show that it has superior characteristics compared with other previously published schemes.
Vijay Varadharajan, Michael Hitchens
Comput. J.3
2010 Analysis of Property Based Attestation in Trusted Platforms
abstract
Binary attestation in trusted computing platforms provide the ability to reason about the state of a system using hash measurements. Property based attestation on the other hand enables more meaningful attestation by abstracting low level binary values to high level security properties or functions of systems. In this paper, we try to understand the kind of security properties that trusted platforms can attest. We propose that security properties can have different levels of granularity and provide a pyramid model that classifies properties at four different levels. We leverage the Common Criteria framework for security requirements to provide examples of such properties. The model is then implemented in the context of authorisation for Web services.
Aarthi Nagarajan, Vijay Varadharajan, Michael Hitchens
EUC3
2009 ALOPA: Authorization Logic for Property Attestation in Trusted Platforms
Aarthi Nagarajan, Vijay Varadharajan, Michael Hitchens
ATC3
2009 Context-Aware Trust Management for Peer-to-Peer Mobile Ad-Hoc Networks
abstract
Mobile ad hoc networks (MANETs) are self-organizing and adaptive, and securing such networks is non-trivial. Most security schemes suggested for MANETs tend to build upon some fundamental assumptions regarding the trustworthiness of the participating hosts and the underlying networking systems without presenting any definite scheme for trust establishment. If MANET is to achieve the same level of acceptance as traditional wired and wireless network, then a formal specification of trust and a framework for trust management must become an intrinsic part of its infrastructure. The goal of this paper is to highlight issues relating to trust in MANETs and describe a context-aware, reputation-based approach for establishing trust that assesses the trustworthiness of the participating nodes in a dynamic and uncertain MANET environment.
Rajan Shankaran, Vijay Varadharajan, Mehmet A. Orgun, Michael Hitchens
COMPSAC (2)4
2009 Role-Playing Games: The State of Knowledge [Panel Abstracts]
Anders Drachen, Marinka Copier, Markus Montola, Mirjam Palosaari Eladhari, Michael Hitchens, Jaakko Stenros
DiGRA Conference5
2009 Towards Data-Driven Drama Management: Issues in Data Collection and Annotation
Anders Drachen, Michael Hitchens, Arnav Jhala, Georgios N. Yannakakis
DiGRA Conference2
2009 Property Based Attestation and Trusted Computing: Analysis and Challenges
abstract
Trusted computing attestation mechanism relies on hash measurements to realize remote party attestation in distributed systems. Property based attestation enables more meaningful attestation by abstracting low level binary values to high level security properties or functions of systems. The contribution of this paper is two fold. In the first part of the paper, we provide an analysis of the different types of property based attestation mechanisms that have been proposed in the recent years. We categorize these mechanisms as derivation based, delegation based and enforcement based and analyze each of them with a particular focus on their limitations. In the second part, we provide a list of challenges for property based attestation. We believe this to be an useful exercise to help better understand the issues that limit the practical applicability of property based attestation in real world systems.
Aarthi Nagarajan, Vijay Varadharajan, Michael Hitchens, Eimear Gallery
NSS3
2008 On the Applicability of Trusted Computing in Distributed Authorization Using Web Services
Aarthi Nagarajan, Vijay Varadharajan, Michael Hitchens, Saurabh Arora
DBSec3
2008 Verbal Communication of Story Facilitators in Multi-player Role-Playing Games
Anders Drachen, Thea Marie Drachen, Michael Hitchens
ICIDS3
2007 Player-Character Dynamics in Multi-Player Role Playing Games
Anders Drachen, Doris McIlwain, Thea Marie Drachen, Michael Hitchens
DiGRA Conference4
2007 Cross-format analysis of the gaming experience in multi-player role-playing games
Anders Drachen, Ken Newman, Thea Marie Drachen, Michael Hitchens
DiGRA Conference4
2007 Trust Management and Negotiation for Attestation in Trusted Platforms Using Web Services
abstract
The concept of trusted computing technology is becoming significant in that such technologies are being increasingly available in PCs and mobile devices. With the advent of this technology, one can move from traditional user-only based trust management systems to user and platform-based trust management systems. In this paper, we propose a TCP based trust management and negotiation framework for better security decision making. In this regard, we outline a 3-stage property model that can be leveraged to define policies of different granularities. We then propose how Trust Policy Language (TPL) can be used to create compositions of properties. Finally, the paper discusses the different architectural design choices (such as push, pull and delegation based models) in negotiating trust using these policies and their implications in a distributed Web service based environment.
Aarthi Nagarajan, Vijay Varadharajan, Michael Hitchens
PDCAT3
2004 Authorization Service for Web Services and its Implementation
abstract
In this paper, we introduce the authorization issues for Web Services. We introduce the authorization service provided by Microsoft/spl reg/ .NET MyServices and then briefly describe our proposed modifications and extensions to the authorization service. We discuss the application of the extended authorization model to a healthcare system built using Web Services. We used the XML access control language (XACL) to specify policies in XML and control access to the patient records stored in XML format. We then evaluated the suitability of XACL as an authorization policy language for Web Services.
Sarath Indrakanti, Vijay Varadharajan, Michael Hitchens
ICWS3
2004 Security for cluster based ad hoc networks
Vijay Varadharajan, Rajan Shankaran, Michael Hitchens
Comput. Commun.3
2003 Secure Authorisation for Web Services
Sarath Indrakanti, Vijay Varadharajan, Michael Hitchens, Rajat Kumar Todi
DBSec3
2003 Role-Based Access Control and the Access Control Matrix
Gregory Saunders, Michael Hitchens, Vijay Varadharajan
ICICS2
2003 A secure multicast support framework for Mobile IP
abstract
More and more applications are relying on underlying IP multicast facility to disseminate information to several receivers simultaneously with minimum overheads. These include real time applications such as video conferencing and Internet audio as well as non real time services. Concurrently, there is a paradigm shift from wired to wireless communication. As portable computers proliferate, networks rely on a limited number of stationary hosts and aim to provide seamless connectivity to mobile hosts. Hence, there is an urgent need to integrate these two facilities together. However, there are serious security concerns that need to be addressed before one can exploit this combined facility. Security issues in multicasting such as dynamic group management are further aggravated due in the mobile environment. In this paper, we describe the security issues in multicasting and propose a secure multicast framework for Mobile IP.
Rajan Shankaran, Vijay Varadharajan, Michael Hitchens
WCNC3
2002 Policy Administration Domains
Michael Hitchens, Vijay Varadharajan, Gregory Saunders
ACISP1
2001 RBAC for XML Document Stores
Michael Hitchens, Vijay Varadharajan
ICICS1
2001 A Distributed Location Management Scheme for Mobile Hosts
abstract
With the increasing growth in mobile computing devices and wireless networks, users are able to access information from anywhere and at anytime. In such situations, the issues of location management for mobile hosts are becoming increasingly significant. Different location management schemes such as Columbia University's mobile IP scheme and IETF mobile IP have been proposed. In this paper, we propose a new distributed location management scheme and discuss the advantages of the proposed scheme over the others. The paper then considers the issues of multicasting in the proposed architecture.
Rajan Shankaran, Vijay Varadharajan, Michael Hitchens
ICPADS3
2001 Secure Distributed Location Management Scheme for Mobile Hosts
abstract
With the increasing growth in mobile computing devices and wireless networks, users are able to access information from anywhere and at anytime. In such situations, the issues of location management for mobile hosts are becoming increasingly significant. Different location management schemes such as Columbia University's mobile IP scheme and IETF Mobile IP have been proposed. In this paper, we propose a distributed location management scheme and discuss the advantages of the proposed scheme over the others. It seems that the proposed scheme is easy to implement and achieves optimal routing. The paper then considers the issues of multicasting in the proposed scheme. Finally, the paper describes security protocols for authentication and data privacy for the proposed architecture.
Rajan Shankaran, Vijay Varadharajan, Michael Hitchens
LCN3
2000 Elements of a Language for Role-Based Access Control
Michael Hitchens, Vijay Varadharajan
SEC1
1999 An Analysis of Access Control Models
Gregory Saunders, Michael Hitchens, Vijay Varadharajan
ACISP2
1999 Issues in the Design of a Language for Role Based Access Control
Michael Hitchens, Vijay Varadharajan
ICICS1
1999 Secure Multicast Extensions for Mobile Networks
abstract
There has been a considerable interest shown in the area of mobility. With the advent of powerful portable devices such as laptop and palmtop there is a growing trend amongst users to go the nomadic way. This implies that a user can get access to any service at any time without any interruption. Such nomadic computing poses several challenges in multicasting and security. We first consider a framework that has been proposed by Acharya, Bakre and Badrinath (see Rutgers DCS TechReport LCS R-TR 243, 1995) for multicasting in mobile IP networks. We extend this framework to support a secure multicasting service. We describe secure schemes for a mobile host to initiate, join and leave a multicast group. We also discuss the secure movement of mobile hosts in intra and inter campus environments.
Rajan Shankaran, Vijay Varadharajan, Michael Hitchens
LCN3
1999 On the design of secure ATM networks
Vijay Varadharajan, Rajan Shankaran, Michael Hitchens
Comput. Commun.3
1997 Security Issues in Asynchronous Transfer Mode
Vijay Varadharajan, Rajan Shankaran, Michael Hitchens
ACISP3
1997 Security services and public key infrastructure for ATM networks
abstract
The paper addresses the design of security services for ATM networks. First various options for the placement of security services within the ATM protocol stack are outlined. Then a security layer between the AAL and ATM layer is considered. The proposed security layer provides confidentiality, integrity and data origin authentication in the user plane. The paper then presents an authentication scheme and a key establishment protocol. This protocol is integrated with the existing ATM signaling protocol, as part of the call setup procedures. The authors also consider the design of protocols between ATM nodes and Certification Authority for initializing retrieving and distributing public key certificates. The developed security design can be transparently integrated into the B-ISDN Protocol Reference Model without violating the existing standards.
Vijay Varadharajan, Rajan Shankaran, Michael Hitchens
LCN3
1996 esign Choices For Symmetric Key Based Inter-Domain Authentication Protocols In Distributed Systems
abstract
Authentication is a key requirement in the establishment of secure interactions between network entities. Several authentication and key establishment protocols have been proposed in recent years. Most of these protocols were designed for an intra-domain environment (i.e. one where the communicating parties reside in a single domain) and then extrapolated to the inter-domain environment. In this paper, the design of inter-domain protocols is investigated. We present the different design choices that need to be carefully considered when designing inter-domain protocols in large distributed systems. We propose three different inter-domain protocols with varying degrees of responsibility placed on the client and the trusted servers. In each case, the assumptions made in the design are explicitly stated. This helps to illustrate the rationale behind the choices made. The proposed protocols use symmetric key systems and are based on Kerberos. The arguments, rationales and designs presented in this paper are also applicable to OSF's Distributed Computing Environment (DCE).
Michael Hitchens, Vijay Varadharajan
ACSAC1