VLDB 2026 Research / reviewers in the wild / expert
Christian Damsgaard Jensen
dblp:j/ChristianDamsgaardJensen
· DBLP profile ↗
27ranked-venue papers
3as first author
5since 2021 · last 2023
0000-0002-0921-7148ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 23 · 3 first-author · 4 since 2021Systems, architecture and hardware · 2 · 1 since 2021Computer networks · 1Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | A comparative risk analysis on CyberShip system with STPA-Sec, STRIDE and CORASabstractThe widespread use of software-intensive cyber systems in critical infrastructures such as ships (CyberShips) has brought huge benefits, yet it has also opened new avenues for cyber attacks to potentially disrupt operations. Cyber risk assessment plays a vital role in identifying cyber threats and vulnerabilities that can be exploited to compromise cyber systems. Understanding the nature of cyber threats and their potential risks and impact is essential to improve the security and resilience of cyber systems, and to build systems that are secure by design and better prepared to detect and mitigate cyber attacks. A number of methodologies have been proposed to carry out these analyses. This paper evaluates and compares the application of three risk assessment methodologies: system theoretic process analysis (STPA-Sec), STRIDE and CORAS for identifying threats and vulnerabilities in a CyberShip system. We specifically selected these three methodologies because they identify threats not only at the component level, but also threats or hazards caused due to the interaction between components, resulting in sets of threats identified with each methodology and relevant differences. Moreover, STPA-Sec, which is a variant of the STPA, is widely used for safety and security analysis of cyber physical systems (CPS); CORAS offers a framework to perform cyber risk assessment in a top-down approach that aligns with STPA-Sec; and STRIDE (Spoofing, Tampering, Repudiation,Information disclosure, Denial of Service, Elevation of Privilege) considers threat at the component level as well as during the interaction that is similar to STPA-Sec. As a result of this analysis, this paper highlights the pros and cons of these methodologies, illustrates areas of special applicability, and suggests that their complementary use as threats identified through STRIDE can be used as an input to CORAS and STPA-Sec to make these methods more structured. Rishikesh Sahay, Daniel A. Sepulveda Estay, Weizhi Meng 0001, Christian Damsgaard Jensen, Michael Bruhn Barfod |
Comput. Secur. | 4 |
| 2021 | An Architecture for Processing a Dynamic Heterogeneous Information Network of Security Intelligence
Marios Anagnostopoulos, Egon Kidmose, Amine Laghaout, Rasmus L. Olsen, Sajad Homayoun, Christian Damsgaard Jensen, Jens Myrup Pedersen |
NSS | 6 |
| 2021 | Metadata based need-to-know view in large-scale video surveillance systems
Shizra Sultan, Christian Damsgaard Jensen |
Comput. Secur. | 2 |
| 2021 | Corrigendum to "CyberShip-IoT: A Dynamic and Adaptive SDN-Based Security Policy Enforcement Framework for Ships" [Future Gener. Comput. Syst. 100 (2019) 736-750]
Rishikesh Sahay, Weizhi Meng 0001, Daniel A. Sepulveda Estay, Christian Damsgaard Jensen, Michael Bruhn Barfod |
Future Gener. Comput. Syst. | 4 |
| 2021 | My data, my control: A secure data sharing and access scheme over blockchain
Wei-Yang Chiu, Weizhi Meng 0001, Christian Damsgaard Jensen |
J. Inf. Secur. Appl. | 3 |
| 2020 | Privacy-preserving Measures in Smart City Video Surveillance SystemsabstractSmart city video surveillance systems collect data from all around the city, and this aggregated data is used by several entities for achieving different city administrative tasks such as ensuring public safety and traffic management, to provide citizens with better services. This data, when combined with other smart city data sources, can reveal sensitive information about individuals, which if not used carefully can spawn grave privacy breach. In order to extract useful information from surveillance data without causing privacy invasion, it is important to see how, where and what information is collected about individuals, and how it is further used for said purposes. Shizra Sultan, Christian Damsgaard Jensen |
ICISSP | 2 |
| 2020 | A systematic review of cyber-resilience assessment frameworks
Daniel A. Sepulveda Estay, Rishikesh Sahay, Michael Bruhn Barfod, Christian Damsgaard Jensen |
Comput. Secur. | 4 |
| 2019 | CyberShip-IoT: A dynamic and adaptive SDN-based security policy enforcement framework for ships
Rishikesh Sahay, Weizhi Meng 0001, Daniel A. Sepulveda Estay, Christian Damsgaard Jensen, Michael Bruhn Barfod |
Future Gener. Comput. Syst. | 4 |
| 2019 | The application of Software Defined Networking on securing computer networks: A survey
Rishikesh Sahay, Weizhi Meng 0001, Christian Damsgaard Jensen |
J. Netw. Comput. Appl. | 3 |
| 2018 | Analyzing the Communication Security Between Smartphones and IoT Based on CORAS
Motalib Hossain Bhuyan, Nur A. Azad, Weizhi Meng 0001, Christian Damsgaard Jensen |
NSS | 4 |
| 2015 | Integrating Attributes into Role-Based Access Control
Qasim Mahmood Rajpoot, Christian Damsgaard Jensen, Ram Krishnan |
DBSec | 2 |
| 2015 | Physical trust-based persistent authenticationabstractRecently companies have applied two-factor user authentication. Persistent Authentication is one of the interesting authentication mechanisms to establish security and usability of two-factor authentication systems. However, there is room to improve its feasibility and usability. In this paper, we propose a new type of persistent authentication, called Persistent Authentication Based On physical Trust (PABOT). PABOT uses a context of “physical trust relationship” that is built by visual contact between users, and thus can offer a persistent authentication mechanism with better usability and higher feasibility. Christian Damsgaard Jensen, Shiori Arimura, Yuki Ikeya, Masakatsu Nishigaki |
PST | 2 |
| 2015 | Attributes Enhanced Role-Based Access Control Model
Qasim Mahmood Rajpoot, Christian Damsgaard Jensen, Ram Krishnan |
TrustBus | 2 |
| 2014 | Improving usability of passphrase authenticationabstractThe combination of user-names and passwords has become the predominant method of user authentication in computer systems. Most users have multiple accounts on different systems, which impose different constraints on the length and complexity of passwords that the user is allowed to select. This is done to ensure an appropriate degree of security, but instead, it makes it difficult for users to remember their password, which results in passwords that are either insecure, but easy to remember, or written down on paper. In this paper we address the problem of usability in user authentication. We promote the use of passphrases, which provide better security and are often easier to remember than passwords. Passphrases will be significantly longer than passwords, which makes them more difficult to enter correctly on a keyboard. We solve this problem by proposing a new passphrase validation algorithm, which accepts the most common typing mistakes. The proposed algorithm has been implemented in secure hardware and integrated into a standard Unix system. We present the design, implementation and preliminary evaluation of the developed passphrase authentication prototype. Glen Nielsen, Michael Vedel, Christian Damsgaard Jensen |
PST | 3 |
| 2014 | Security and Privacy in Video Surveillance: Requirements and Challenges
Qasim Mahmood Rajpoot, Christian Damsgaard Jensen |
SEC | 2 |
| 2013 | Error-rate-based fusion of biometric expertsabstractUser verification using biometrics is not completely reliable due to false acceptances and false rejections. By employing multiple biometric experts and fusing their output, the reliability of the verification process can be improved. A common approach is score-level fusion, in which the match scores generated by each experts are fused into a combined score, which is then used to decide whether a claimant is genuine. Since different experts may have incompatible score distributions, score-level fusion requires careful considerations. We propose a novel solution to this problem with an error-rate-based fusion strategy, which relies on the false acceptance and false rejection rates of each individual expert to compute the overall confidence of the user verification. We demonstrate that our fusion strategy outperforms the sum rule score combination scheme and that it is robust to changes in the quality of the biometric samples. Mads I. Ingwar, Naveed Ahmed 0005, Christian Damsgaard Jensen |
PST | 3 |
| 2012 | Towards Symbolic Encryption Schemes
Naveed Ahmed 0005, Christian Damsgaard Jensen, Erik Zenner |
ESORICS | 2 |
| 2012 | Collaborative trust evaluation for wiki securityabstractWiki systems form a subclass of the more general Open Collaborative Authoring Systems, where content is created and maintained by a user community. The ability of anyone to edit the content is, at the same time, their strength and their weakness. Anyone can write documents that improve the value of the wiki-system, but at the same time, anyone can also introduce errors into these documents, by accident or on purpose. A security model for wiki-style authoring systems has previously been proposed. This model is based on both static and dynamic document access controls that enforce a simple integrity based security policy. In this paper, we present a new policy for the existing wiki security model, which provides a higher degree of parameterization and adaptability. The new policy is analyzed and compared to the original policy. Our evaluation shows that this new policy provides stronger security when the number of malicious and colluding users is low, but it has a clearly defined level of tolerance in terms of the amount of work required by an attacker to achieve a given probability of violating the policy. Efforts beyond that level, can allow such users to take control of the system, but this is true for all soft security systems. We show that the system parameters can be tuned so that the amount of work required by malicious and colluding users to reach this level is well beyond most attackers' capabilities. Kasper Lindberg, Christian Damsgaard Jensen |
PST | 2 |
| 2010 | Supporting multi-agent reputation calculation in the Wikipedia Recommender SystemabstractThe Wikipedia is a web-based encyclopedia, written and edited collaboratively by Internet users. Over the past decade, the Wikipedia has experienced a dramatic growth in popularity and is considered by many the primary source of information on the Internet. The Wikipedia has an extremely open editorial policy that allows anybody, to create or modify articles. This has resulted in a broad and detailed coverage of subjects, but it has also caused problems relating to the quality of articles. The Wikipedia Recommender System (WRS) was developed to help human users determine the credibility of an article based on feedback from other Wikipedia users. The WRS calculates a personalised rating for any Wikipedia article based on feedback (recommendations) provided by other Wikipedia users. As part of this process, WRS users are expected to provide their own feedback about the quality of Wikipedia articles that they have read. This makes the WRS a rating-based collaborative filtering system, which implements trust metrics to determine the weight of feedback from different recommenders. In this paper the authors describe the WRS outlining some of the requirements and constraints that shaped the design of the system. The authors also provide a brief overview of the implementation of the WRS prototype. The WRS addresses the general problem of establishing trust in a collaboratively generated resource in a distributed multi-agent system, so the authors believe that the general architecture that underlies the WRS applies to many other applications in such systems. Christian Damsgaard Jensen |
IET Inf. Secur. | 1 |
| 2008 | Dynamics of Trust Evolution - Auto-configuration of Dispositional Trust Dynamics
Christian Damsgaard Jensen, Thomas Rune Korsgaard |
SECRYPT | 1 |
| 2005 | The Claim Tool Kit for ad hoc recognition of peer entities
Jean-Marc Seigneur, Christian Damsgaard Jensen |
Sci. Comput. Program. | 2 |
| 2004 | Zero-knowledge Device Authentication: Privacy & Security Enhanced RFID preserving Business Value and Consumer Convenience
Stephan J. Engberg, Morten Borup Harning, Christian Damsgaard Jensen |
PST | 3 |
| 2004 | Combating Spam with TEA
Jean-Marc Seigneur, Nathan Dimmock, Ciarán Bryce, Christian Damsgaard Jensen |
PST | 4 |
| 2003 | Partial outsourcing: a new paradigm for access controlabstractVarious security models have been proposed in recent years for different purposes. Each of these aims to ease administration by introducing new types of security policies and models. This increases the complexity a system administrator is faced with. Ultimately, the resources expended in choosing amongst all of these models leads to less efficient administration.In this paper, we propose a new access control paradigm, which is already well established in virus and SPAM protection as partial delegation of administration to external expertise centres. Well-known vulnerabilities can be filtered out and known sources of attacks can be automatically blocked. We describe how partial outsourcing can be achieved in a secure way. A framework, which enables this process has already been developed. Joerg Abendroth, Christian Damsgaard Jensen |
SACMAT | 2 |
| 2003 | Cryptographic access control in a distributed file systemabstractTraditional access control mechanisms rely on a reference monitor to mediate access to protected resources. Reference monitors are inherently centralized and existing attempts to distribute the functionality of the reference monitor suffer from problems of scalability.Cryptographic access control is a new distributed access control paradigm designed for a global federation of information systems. It defines an implicit access control mechanism, which relies exclusively on cryptography to provide confidentiality and integrity of data managed by the system. It is particularly designed to operate in untrusted environments where the lack of global knowledge and control are defining characteristics.The proposed mechanism has been implemented in a distributed file system, which is presented in this paper along with a preliminary evaluation of the proposed mechanism. Anthony Harrington, Christian Damsgaard Jensen |
SACMAT | 2 |
| 2001 | Fingerprinting Text in Logical Markup Languages
Christian Damsgaard Jensen |
ISC | 1 |
| 2001 | Capability File Names: Separating Authorisation From User Management in an Internet File System
Jude T. Regan, Christian Damsgaard Jensen |
USENIX Security Symposium | 2 |