Maryline Laurent

dblp:04/1082 · also Maryline Laurent-Maknavicius · DBLP profile ↗
← Back
73ranked-venue papers
3as first author
12since 2021 · last 2026
0000-0002-7256-3721ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 35 · 3 first-author · 4 since 2021Computer networks · 18 · 3 since 2021Systems, architecture and hardware · 6 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 2 since 2021
YearPublicationVenuePosition
2026 GeoFINDR: Practical approach to verify cloud instances geolocation in multicloud
abstract
In multicloud environments, where legal obligations, technical constraints and economic interests are at stake, it is of interest for stakeholders to be able to locate cloud data or the cloud instance where data are decrypted for processing. This paper proposes an original and practical delay-based approach, called GeoFINDR, to locate a cloud instance, e.g. a Virtual Machine (VM), over the Internet, based on RIPE Atlas landmarks. First, the assumed threat model and assumptions are more modern than in existing solutions, e.g. VM-scale localization in multicloud environments, a Cloud Service Provider (CSP) lying over the location of the VM. Second, the originality of the approach lies in four original ideas: (1) geolocation is performed from the VM, (2) a Greedy algorithm selects a first set LM A of distributed audit landmarks in the vicinity of the declared area, (3) a sectorization algorithm identifies a set LM S of other landmarks with distance-delay behavior similar to that of the VM to estimate the sector of the VM, and (4) the estimated location of the VM is calculated as the barycentre position of the LM S landmarks. An open source tool is published on GitHub and experiments show that the localization accuracy can be as high as 22.1 km , under adverse conditions, where the CSP lies about the location of the VM.
Said Ider, Maryline Laurent
Comput. Networks2
2025 Blockchain and emerging technologies for next generation secure healthcare: A comprehensive survey of applications, challenges, and future directions
abstract
Faced with multiple societal challenges, the healthcare sector has been compelled to leverage recent and emerging technologies to adapt. Blockchain is one of the leading technologies, offering transparency, process automation, immutability of traces and the ability to scale up in terms of both the volume of processes and the number of players interacting. The goal of the paper is to show the potential of blockchain technology - alone or merged with other technologies - to help the healthcare system evolve and provide scalable, efficient and secure solutions to four healthcare applications: electronic health record (EHR) storage, health data sharing, remote patient monitoring, and pharmaceutical supply chains. After identifying the functional and security requirements of healthcare systems, the paper conducts an in-depth review of the literature. The survey assesses the effectiveness of blockchain-based solutions in meeting functional, privacy and security needs. It is completed by an analysis of the synergies that can be expected between blockchain and emerging technologies, e.g. artificial intelligence, federated learning, the Internet of Things (IoT), and Large Language Models (LLM), to the benefit of security or privacy in healthcare.
Omar Cheikhrouhou, Khaleel Mershad 0001, Maryline Laurent, Anis Koubaa
Blockchain Res. Appl.3
2024 A decentralized model for usage and information flow control in distributed systems
abstract
Data usage control enables data owners to enforce policies for their data, by defining authorizations, but also obligations, which are actions to be performed before, during or after being granted access such as accepting web cookies, and conditions bearing on the system and environment attributes, e.g., the time. Usage control is often coupled with information flow control to monitor how data are propagated. While usage control is well established and modeled in centralized systems, the literature has only partially addressed usage control for distributed systems, for instance by distributing the usage control system components. However, when it comes to assigning policy to certain data, it is always enforced by a central authority. This paper proposes an extended usage control model to integrate decentralized information flow control (DIFC), which enables users to decide collectively which policy to apply to their common data. Functions to handle connection status aspects are also considered, for dynamic Internet of Things (IoT) or peer-to-peer networks where parts of the distributed network can be disconnected. Architectural aspects and formal definitions to enable decentralized policies for shared data are proposed as a novelty, resulting from the integration of DIFC. We used the TLA+ formal specification language on the proposed model and its attached model checker TLC to detect potential issues. We detected potential deadlocks due to the new connection functions as well as temporal ordering issues then suggested mitigations accordingly. A privacy analysis is provided using a car-sharing scenario to highlight the benefits of usage control.
Nathanaël Denis, Maryline Laurent, Sophie Chabridon
Comput. Secur.2
2023 Integrating Usage Control Into Distributed Ledger Technology for Internet of Things Privacy
abstract
The Internet of Things (IoT) brings new ways to collect privacy-sensitive data from billions of devices. Well-tailored distributed ledger technologies (DLTs) can provide high transaction processing capacities to IoT devices in a decentralized fashion. However, privacy aspects are often neglected or unsatisfying, with a focus mainly on performance and security. In this article, we introduce decentralized usage control mechanisms to empower IoT devices to control the data they generate. Usage control defines obligations, i.e., actions to be fulfilled to be granted access, and conditions on the system in addition to data dissemination control. The originality of this article is to consider the usage control system as a component of distributed ledger networks, instead of an external tool. With this integration, both technologies work in synergy, benefiting their privacy, security, and performance. We evaluated the performance improvements of integration using the IOTA technology, particularly suitable due to the participation of small devices in the consensus. The results of the tests on a private network show an approximate 90% decrease of the time needed for the usage control system to push a transaction and make its access decision in the integrated setting, regardless of the number of nodes in the network.
Nathanaël Denis, Maryline Laurent, Sophie Chabridon
IEEE Internet Things J.2
2023 Securing Organization's Data: A Role-Based Authorized Keyword Search Scheme With Efficient Decryption
abstract
For better data availability and accessibility while ensuring data secrecy, organizations often tend to outsource their encrypted data to the cloud storage servers, thus bringing the challenge of keyword search over encrypted data. In this article, we propose a novel authorized keyword search scheme using Role-Based Encryption (RBE) technique in a cloud environment. The contributions of this article are multi-fold. First, it presents a keyword search scheme which enables only authorized users, having properly assigned roles, to delegate keyword-based data search capabilities over encrypted data to the cloud providers without disclosing any sensitive information. Second, it supports a multi-organization cloud environment, where the users can be associated with more than one organization. Third, the proposed scheme provides efficient decryption, conjunctive keyword search and revocation mechanisms. Fourth, the proposed scheme outsources expensive cryptographic operations in decryption to the cloud in a secure manner. Fifth, we have provided a formal security analysis to prove that the proposed scheme is semantically secure against Chosen Plaintext and Chosen Keyword Attacks. Finally, our performance analysis shows that the proposed scheme is suitable for practical applications.
Nazatul Haque Sultan, Maryline Laurent, Vijay Varadharajan
IEEE Trans. Cloud Comput.2
2022 SEVIL: Secure and Efficient VerifIcation over Massive Proofs of KnowLedge
abstract
International audience
Souha Masmoudi, Maryline Laurent, Nesrine Kaaniche
SECRYPT2
2022 PIMA: A Privacy-preserving Identity management system based on an unlinkable MAlleable signature
Souha Masmoudi, Maryline Laurent, Nesrine Kaaniche
J. Netw. Comput. Appl.2
2022 Authorized Keyword Search over Outsourced Encrypted Data in Cloud Environment
abstract
For better data availability and accessibility while ensuring data secrecy, end-users often tend to outsource their data to the cloud servers in an encrypted form. However, this brings a major challenge to perform the search for some keywords over encrypted content without disclosing any information to unintended entities. This paper proposes a novel expressive authorized keyword search scheme relying on the concept of ciphertext-policy attribute-based encryption. The originality of the proposed scheme is multifold. First, it supports the generic and convenient multi-owner and multi-user scenario, where the encrypted data are outsourced by several data owners and searchable by multiple users. Second, the formal security analysis proves that the proposed scheme is semantically secure against chosen keyword and outsiders keyword guessing attacks. Third, an interactive protocol is introduced which avoids the need of any secure-channels between users and service provider. Fourth, due to the concept of bilinear-map accumulator, the system can efficiently revoke users and/or their attributes, and authenticate them prior to launching any expensive search operations. Fifth, conjunctive keyword search is provided thus enabling to search for multiple keywords simultaneously, with minimal cost. Sixth, the performance analysis shows that the proposed scheme outperforms closely-related works.
Nazatul Haque Sultan, Nesrine Kaaniche, Maryline Laurent, Ferdous A. Barbhuiya
IEEE Trans. Cloud Comput.3
2021 Personal Information Self-Management: A Survey of Technologies Supporting Administrative Services
Paul Marillonnet, Maryline Laurent, Mikaël Ates
J. Comput. Sci. Technol.2
2021 Privacy-Preserving Publication of Time-Series Data in Smart Grid
abstract
The collection of fine-grained consumptions of users in the smart grid enables energy suppliers and grid operators to propose new services (e.g., consumption forecasts and demand-response protocols) allowing to improve the efficiency and reliability of the grid. These services require the knowledge of aggregate consumption of users. However, an aggregate can be vulnerable to reidentification attacks which allow revealing the users’ individual consumption. Revealing an aggregate data is a key privacy concern. This paper focuses on publishing an aggregate of time-series data such as fine-grained consumptions, without indirectly disclosing individual consumptions. We propose novel algorithms which guarantee differential privacy, based on the discrete Fourier transform and the discrete wavelet transform. Experimental results using real data from the Irish Commission for Regulation of Utilities (CRU) demonstrate that our algorithms achieve better utility than previously proposed algorithms.
Franklin Leukam Lako, Paul Lajoie-Mazenc, Maryline Laurent
Secur. Commun. Networks3
2021 An Efficient User-Centric Consent Management Design for Multiservices Platforms
abstract
This paper presents an efficient user-centric consent management system to access online services of the Territorial Collectivities and Public Administration (TCPA) as well as user-authorized third parties. It defines a novel PII manager that supports a set of sources obeying to different authorization and PII retrieval protocols. This contribution is motivated by the necessity to interface TCPA services with remote sources that provide Personally Identifiable Information (PII). Hence, the originality of our solution is multifold. First, the burden for enforcing the interoperability between the sources and the TCPA services collecting the PII is reduced from the point of view of the user, the administrator of the User-Relationship Management (URM) platform, and the territorial agent responsible for processing the user’s queries. Second, it defines a unified consent model supporting four types of sources. Third, it goes into details of practical implementations. Fourth, the relevance of the proposed PII manager for a relevant TCPA use case is demonstrated through a functional analysis.
Paul Marillonnet, Mikaël Ates, Maryline Laurent, Nesrine Kaaniche
Secur. Commun. Networks3
2021 Cooperative Set Homomorphic Proofs for Data Possession Checking in Clouds
abstract
Outsourcing an increasing amount of data to a third party raises a number of security and privacy challenges, namely remote data integrity verification. Indeed, proofs for data possession checking address the verification that some previously outsourced data blocks across multiple storing nodes are correctly stored and fully available. In this paper, we propose a new set homomorphic proof of data possession, referred to as SHoPS, supporting several operations like aggregation of proofs. SHoPS is a deterministic Proof of Data Possession (PDP) scheme, based on an interactive proof protocol. Our approach has several advantages. First, it enables several proofs to be aggregated and a subset of data files' proofs to be verified, while providing an attractive communication overhead. Second, it supports public verifiability where the verification process can be delegated to another entity, thus releasing the data owner from the cumbersome task of periodical verifications. Third, SHoPS is efficient and provably secure, as it is resistant to the fraudulence of the prover and the leakage of verified data. Finally, a theoretical performances' analysis shows that SHoPS performs better in terms of functionality, communication and computation overhead compared to closely related works and experimental results point out the applicability of the proposed scheme in real world scenarios.
Nesrine Kaaniche, Maryline Laurent, Sébastien Canard
IEEE Trans. Cloud Comput.2
2020 CoRA: A Scalable Collective Remote Attestation Protocol for Sensor Networks
abstract
International audience
Aïda Diop, Maryline Laurent, Jean Leneutre, Jacques Traoré
ICISSP2
2020 Privacy preservation for social networks sequential publishing
Safia Bourahla, Maryline Laurent, Yacine Challal
Comput. Networks2
2020 Privacy enhancing technologies for solving the privacy-personalization paradox: Taxonomy and survey
Nesrine Kaaniche, Maryline Laurent, Sana Belguith
J. Netw. Comput. Appl.2
2020 Accountable privacy preserving attribute based framework for authenticated encrypted access in clouds
Sana Belguith, Nesrine Kaaniche, Maryline Laurent, Abderrazak Jemai, Rabah Attia
J. Parallel Distributed Comput.3
2019 Distributed access control solution for the IoT based on multi-endorsed attributes and smart contracts
abstract
The ever-growing world of the Internet of Things (IoT) is yet to agree on an effective and practical access control solution. To overcome challenges such as limited resources, or unreliable connectivity, a number of schemes offload heavy computations onto a central entity, thus creating a single point of failure. Our contribution consists in the construction of a distributed attribute-based access control mechanism, relying on the blockchain technology to dynamically manage multi-endorsed attributes and trust anchors. The originality of our proposal is multifold. First, it enables the integration of multiple security domains into a single resilient access control system. Second, its focus on attributes offers flexibility, expressiveness, and user-centricity, accommodating the dynamic addition of subjects. Third, our attribute endorsement is open, scalable, and flexible, enabling multiple administrators without sacrificing ease of management. Finally, the final access control decision is taken by the device and only requires local connection to its gateway.
Sophie Dramé-Maigné, Maryline Laurent, Laurent Castillo
IWCMC2
2019 Guest Editorial The Convergence of Blockchain and IoT: Opportunities, Challenges and Solutions
abstract
Internet of Things (IoT), coming with billions of connected devices, could potentially transform our daily life but could also create a serious security headache. It brings greater complications in securely accessing these devices with privacy protection guaranteed, and several research issues need to be investigated in detail, e.g., access control, traceability, anonymity, authentication, security bootstrap, etc. Most of the traditional security protection mechanisms are centralized, which make them difficult to scale up to meet the security demands of the IoT.
Qing Yang 0003, Rongxing Lu, Chunming Rong, Yacine Challal, Maryline Laurent, Shengling Wang 0001
IEEE Internet Things J.5
2018 Privacy-Preserving Multi-User Encrypted Access Control Scheme for Cloud-Assisted IoT Applications
abstract
In this paper, we present a privacy preserving encrypted access control scheme to aggregate data for Cloud assisted IoT applications. Our scheme is based on attribute based encryption mechanisms and consists in enciphering a set of data contents, with respect to sub-sets of a general access policy. As such, the gateway is able to decrypt the resulting aggregated data only if it holds the matching certified attributes and it has received a sufficient number of partial ciphertexts. Our construction has several advantages. First, it provides a fine-grained access to aggregated data contents that are enciphered by different multiple encrypting entities. Second, it provides a privacy preserving encryption process, such that a curious gateway can neither identify the enciphering IoT device nor decipher single data chunks. Third, our concrete construction provides low computation and communication costs, adapted to resource-constrained devices, compared to most closely related schemes.
Nesrine Kaaniche, Maryline Laurent
IEEE CLOUD2
2018 BDUA: Blockchain-Based Data Usage Auditing
abstract
Personal data are often collected and processed in a decentralized fashion, within different contexts. For instance, with the emergence of distributed applications, several providers are used to correlate their records, to provide personalized services to their clients. As such, to protect users' privacy, different pseudonyms are generally used for different contexts. These pseudonyms have to be unlinkable to prevent identifying records to be associated to the same user. Although unlinkable, these pseudonyms have to be processed and exchanged according to their owners' consent and in a privacy-preserving fashion. In this paper, we propose BDUA, a new Blockchain-based Data Usage Auditing system, that ensures a controlled yet privacy preserving exchange of distributed data, such that a set of authorized auditing entities are able to conduct an accurate auditing relying on registered blockchains' transactions.
Nesrine Kaaniche, Maryline Laurent
IEEE CLOUD2
2018 Augmented Chain of Ownership: Configuring IoT Devices with the Help of the Blockchain
Sophie Dramé-Maigné, Maryline Laurent, Laurent Castillo, Hervé Ganem
SecureComm (1)2
2018 Questioning the security and efficiency of the ESIoT approach
abstract
ESIoT is a secure access control and authentication protocol introduced for Internet of Things (IoT) applications. The core primitive of ESIoT is an identity-based broadcast encryption scheme called Secure Identity-Based Broadcast Encryption (SIBBE). SIBBE is designed to provide secure key distribution among a group of devices in IoT networks, and enable devices in each group to perform mutual authentication. The scheme is also designed to hide the structure of the group from nodes outside of the group. We identify multiple efficiency and security issues in this primitive that prove SIBBE unsuitable for IoT applications. First, we show that contrary to what was claimed, the size of the ciphertexts generated by the encryption function is not constant but in fact linear in the number of devices in the group. Additionally, we demonstrate that the encryption and decryption costs are also linear in the number of nodes in the group, implying scalability issues thus inefficiency for IoT applications. In terms of security, we prove that SIBBE does not achieve the desired property of anonymity and allows an attacker to gain information on the structure of any given group. Finally, we demonstrate how SIBBE does not achieve the claimed chosen-ciphertext security. We however prove its security for a weaker security notion (namely selective-ID indistinguishability against chosen-plaintext attacks) under a variant of the GDDHE assumption.
Aïda Diop, Said Gharout, Maryline Laurent, Jean Leneutre, Jacques Traoré
WISEC3
2018 PHOABE: Securely outsourcing multi-authority attribute based encryption with policy hidden for cloud assisted IoT
Sana Belguith, Nesrine Kaaniche, Maryline Laurent, Abderrazak Jemai, Rabah Attia
Comput. Networks3
2018 ICAuth: A secure and scalable owner delegated inter-cloud authorization
Nazatul Haque Sultan, Ferdous A. Barbhuiya, Maryline Laurent
Future Gener. Comput. Syst.3
2018 Securely outsourcing the ciphertext-policy attribute-based encryption
Kim Thuat Nguyen, Nouha Oualha, Maryline Laurent
World Wide Web3
2017 A blockchain-based data usage auditing architecture with enhanced privacy and availability
abstract
Recent years have witnessed the trend of increasingly relying on distributed infrastructures. This increased the number of reported incidents of security breaches compromising users' privacy, where third parties massively collect, process and manage users' personal data. Towards these security and privacy challenges, we combine hierarchical identity based cryptographic mechanisms with emerging blockchain infrastructures and propose a blockchain-based data usage auditing architecture ensuring availability and accountability in a privacy-preserving fashion. Our approach relies on the use of auditable contracts deployed in blockchain infrastructures. Thus, it offers transparent and controlled data access, sharing and processing, so that unauthorized users or untrusted servers cannot process data without client's authorization. Moreover, based on cryptographic mechanisms, our solution preserves privacy of data owners and ensures secrecy for shared data with multiple service providers. It also provides auditing authorities with tamper-proof evidences for data usage compliance.
Nesrine Kaaniche, Maryline Laurent
NCA2
2017 Constant-size Threshold Attribute based SignCryption for Cloud Applications
abstract
In this paper, we propose a novel constant-size threshold attribute-based signcryption scheme for securely \nsharing data through public clouds. Our proposal has several advantages. First, it provides flexible cryptographic access control, while preserving users’ privacy as the identifying information for satisfying the access \ncontrol policy are not revealed. Second, the proposed scheme guarantees both data origin authentication and \nanonymity thanks to the novel use of attribute based signcryption mechanism, while ensuring the unlinkability \nbetween the different access sessions. Third, the proposed signcryption scheme has efficient computation cost \nand constant communication overhead whatever the number of involved attributes. Finally, our scheme satisfies strong security properties in the random oracle model, namely Indistinguishability against the Adaptive \nChosen Ciphertext Attacks (IND-CCA2), Existential Unforgeability against Chosen Message Attacks (EUFCMA) and privacy preservation of the attributes involved in the signcryption process, based on the assumption \nthat the augmented Multi-Sequence of Exponents Decisional Diffie-Hellman (aMSE-DDH) problem and the \nComputational Diffie Hellman Assumption (CDH) are hard.
Sana Belguith, Nesrine Kaaniche, Maryline Laurent, Abderrazak Jemai, Rabah Attia
SECRYPT3
2017 Attribute based Encryption for Multi-level Access Control Policies
abstract
International audience
Nesrine Kaaniche, Maryline Laurent
SECRYPT2
2017 The Semantic Discrimination Rate Metric for Privacy Measurements which Questions the Benefit of t-closeness over l-diversity
abstract
International audience
Louis Philippe Sondeck, Maryline Laurent, Vincent Frey
SECRYPT2
2017 Data security and privacy preservation in cloud storage environments based on cryptographic mechanisms
Nesrine Kaaniche, Maryline Laurent
Comput. Commun.2
2017 Diet-ESP: IP layer security for IoT
abstract
The number of devices connected through the Internet of Things (IoT) will significantly grow in the next few years while security of their interconnections is going to be a major challenge. For many devices in IoT scenarios, the necessary resources to send and receive bytes are extremely high and when such devices are powered with battery the amount of exchanged bytes directly impacts their life time. As a result, compression of existing protocols is a widely accepted technique to make IoT benefit from the protocols developed over the last decades. This paper presents ESP Header Compression (EHC), a framework that enables compression of packets protected with Encapsulating Security Payload (ESP). EHC is composed of EHC Rules, targeting the compression of a specific field and organized according to EHC Strategies. Further, the paper presents Diet-ESP, an EHC Strategy that highly reduces the networking overhead of ESP packets to address the IoT security and bandwidth requirements. Diet-ESP results in sending fewer bytes which in turn reduces the number of required radio frames and thus battery consumption. The measurements showed that sending 10 byte application data on IEEE 802.15.4 radio networks secured with the standard ESP requires sending an additional frame. This results into a 95% energy overhead compared to the unprotected data, while Diet-ESP results only in a 3% overhead compared to unprotected data. This small overhead is achievable with some compressions being performed within the ESP stack which requires altering the same. Nevertheless, Diet-ESP remains fully security compliant to ESP and performs better than any other compression framework as far as ESP is considered.
Daniel Migault, Tobias Guggemos, Sylvain Killian, Maryline Laurent, Guy Pujolle, Jean-Philippe Wary
J. Comput. Secur.4
2017 Security and Privacy in Emerging Wireless Networks
abstract
Introduction to a special issue of the journal Security and Communication Networks covering security and privacy in emerging wireless networks.
Qing Yang 0003, Rongxing Lu, Yacine Challal, Maryline Laurent
Secur. Commun. Networks4
2016 Attribute-Based Signatures for Supporting Anonymous Certification
Nesrine Kaaniche, Maryline Laurent
ESORICS (1)2
2016 Authenticated Key Agreement Mediated by a Proxy Re-encryptor for the Internet of Things
Kim Thuat Nguyen, Nouha Oualha, Maryline Laurent
ESORICS (2)3
2016 PAbAC: A Privacy Preserving Attribute based Framework for Fine Grained Access Control in Clouds
abstract
International audience
Sana Belguith, Nesrine Kaaniche, Abderrazak Jemai, Maryline Laurent, Rabah Attia
SECRYPT4
2016 Novel Lightweight Signcryption-Based Key Distribution Mechanisms for MIKEY
Kim Thuat Nguyen, Nouha Oualha, Maryline Laurent
WISTP3
2016 Efficient serverless radio-frequency identification mutual authentication and secure tag search protocols with untrusted readers
abstract
Radio‐frequency identification (RFID) technology's potential relies on advances made by researchers for addressing the technology's security and privacy vulnerabilities, and making data collection and storage in an RFID system safe. Privacy and security are key concerns, as paramount as efficiency and reliability, in raising the confidence of end users towards RFID technologies. This study proposes two complementary lightweight and efficient serverless security protocols in the presence of untrusted RFID readers. The first one is used for mass authentication of RFID tags and supports mutual authentication with key establishment. The second one is an RFID tag search protocol that helps interacting with one specific tag surrounded by a huge number of other tags. The originality of both protocols holds that no shared parameters are required between tags and readers for mutual authentication support, they refer to the same basic material, and they have low resource demands in storage, bandwidth, energy and computation for both RFID readers and tags. Finally, the authors’ protocols have been formally verified under the computational model using CryptoVerif tool.
Collins Mtita, Maryline Laurent, Jacques Delort
IET Inf. Secur.2
2015 SHoPS: Set Homomorphic Proof of Data Possession Scheme in Cloud Storage Applications
abstract
The prospect of outsourcing an increasing amount of data to a third party and the abstract nature of the cloud promote the proliferation of security and privacy challenges, namely, the remote data possession checking. This paper addresses this security concern, while supporting the verification of several data blocks outsourced across multiple storing nodes. We propose a new set homomorphic proof of data possession, called SHoPS, supporting the verification of aggregated proofs. It proposes a deterministic Proof of Data Possession (PDP) scheme based on interactive proof protocols. Our approach has several advantages. First, it supports public verifiability where the data owner delegates the verification process to another entity, thus releasing him from the burden of periodical verifications. Second, it allows the aggregation of several proofs and the verification of a subset of data files' proofs while providing an attractive communication overhead.
Nesrine Kaaniche, Maryline Laurent
SERVICES2
2015 Survey on secure communication protocols for the Internet of Things
Kim Thuat Nguyen, Maryline Laurent, Nouha Oualha
Ad Hoc Networks2
2014 A Novel Zero-Knowledge Scheme for Proof of Data Possession in Cloud Storage Applications
abstract
Recent technological advances have given rise to the popularity and success of cloud storage. However, the prospect of outsourcing an increasing amount of data to a third party and the abstract nature of the cloud foster the proliferation of security and privacy challenges, namely, the remote data possession checking. This paper addresses this critical security concern, when storing sensitive data in a cloud storage service, and the need for users to trust commercial cloud providers. It proposes a deterministic Proof of Data Possession (PDP) scheme based on Interactive Proof System(IPS) and an original usage of the GPS scheme. Our approach has several advantages. First, it supports public verifiability which releases data owners from the burden of a periodical verification. Second, it provides constant communication complexity, where the exchanged messages between the storage server and the client are composed of constant number of group elements. Third, our solution is efficient and provably secure, as it is resistant to the fraudulence of the prover and the leakage of verified data.
Nesrine Kaaniche, Ethmane El Moustaine, Maryline Laurent
CCGRID3
2014 CloudaSec: A Novel Public-key Based Framework to Handle Data Sharing Security in Clouds
abstract
International audience
Nesrine Kaaniche, Maryline Laurent, Mohammed El-Barbori
SECRYPT2
2014 Lightweight collaborative key establishment scheme for the Internet of Things
Yosra Ben Saied, Alexis Olivereau, Djamal Zeghlache, Maryline Laurent
Comput. Networks4
2014 A survey of collaborative services and security-related issues in modern wireless Ad-Hoc communications
Yosra Ben Saied, Alexis Olivereau, Djamal Zeghlache, Maryline Laurent
J. Netw. Comput. Appl.4
2013 High Availability for IPsec VPN Platforms: ClusterIP Evaluation
abstract
To manage the huge demand on traffic, the Internet Service Providers (ISP) are offloading its mobile data from Radio Access Networks (RAN) to Wireless Access Networks (WLAN). While these RANs are considered trusted networks, WLANs need to build a similar trusted zone in order to offer the same security level and Quality of Service (QoS) to End-Users (EU). Although IPsec is widely implemented to create trusted environments through untrusted networks, the industry is increasingly interested in providing IPsec-based services with High Availability (HA) features in order to ensure reliability, QoS and security. Even though IPsec is not originally well suited to provide HA features, some mechanisms like VRRP or ClusterIP can work together with IPsec in order to offer HA capabilities. ClusterIP is actually used by strong Swan (an open source IPsec-based VPN solution) to build a cluster of IPsec Security Gateways (SG) offering HA features. This paper concentrates on how to build a cluster of IPsec SGs based on ClusterIP. We describe the main issues to overcome HA within IPsec. Then, we measure how HA may affect the EU experience, and provide recommendations on how to deploy ClusterIP. Finally, our tests over an HTTP connection showed that ClusterIP allows fast recovering during a failure.
Daniel Palomares, Daniel Migault, Wolfgang Velasquez, Maryline Laurent
ARES4
2013 ID Based Cryptography for Cloud Data Storage
abstract
This paper addresses the security issues of storing sensitive data in a cloud storage service and the need for users to trust the commercial cloud providers. It proposes a cryptographic scheme for cloud storage, based on an original usage of ID-Based Cryptography. Our solution has several advantages. First, it provides secrecy for encrypted data which are stored in public servers. Second, it offers controlled data access and sharing among users, so that unauthorized users or untrusted servers cannot access or search over data without client's authorization.
Nesrine Kaaniche, Aymen Boudguiga, Maryline Laurent
IEEE CLOUD3
2013 Routing tables building methods for increasing DNS(SEC) resolving platforms efficiency
Emmanuel Herbert, Daniel Migault, Stéphane Sénécal, Stanislas Francfort, Maryline Laurent
IM5
2013 Overcoming DNSSEC performance issues with DHT-based architectures
Daniel Migault, Stanislas Francfort, Stéphane Sénécal, Emmanuel Herbert, Maryline Laurent
IM5
2013 GPS+: a back-end coupons identification for low-cost RFID
abstract
Security and privacy for RFID systems are very challenging topics. First, the RFID passive tags prevailing in most of the RFID applications are very limited in processing power, thus making most of the ordinary security mechanisms inappropriate. Second, tags do answer to any reader requests, for this the most innovative RFID proposed protocols are not suitable whether for privacy problems or the high cost of tags.
Ethmane El Moustaine, Maryline Laurent
WISEC2
2013 Trust management system design for the Internet of Things: A context-aware and multi-service approach
Yosra Ben Saied, Alexis Olivereau, Djamal Zeghlache, Maryline Laurent
Comput. Secur.4
2012 Dynamic DNS Update Security, Based on Cryptographically Generated Addresses and ID-Based Cryptography, in an IPv6 Autoconfiguration Context
abstract
This paper proposes a new security method for protecting signalling for Domain Name System (DNS) architecture. That is, it makes secure DNS update messages for binding a Fully Qualified Domain Name (FQDN) of an IPv6 node and the IPv6 address of the node owning this FQDN. This method is based on the use of Cryptographically Generated Addresses (CGA) and IDBased Cryptography (IBC). Combination of these two techniques allows DNS server to check the ownership of the IPv6 address and the FQDN, sent by the DNS client. In addition, this paper describes how this method has been implemented.
Jean Michel Combes, Ghada Arfaoui, Maryline Laurent
ARES3
2012 E2E: An Optimized IPsec Architecture for Secure and Fast Offload
abstract
When mobile End Users are offloaded from a Radio Access Network (RAN) to a WLAN, current I-WLAN [1] offloaded architectures consider traffic converging to a common Security Gateway. In this paper, we propose an alternative End-to-End security (E2E) architecture based on the MOBIKE-X [2] protocol, which extends the MOBIKE [3] Mobility and Multihoming features to Multiple Interfaces and to the Transport mode of IPsec. The benefits of this E2E architecture are mostly load reduction and a better End User experience. First, E2E offloads the ISP CORE and backhaul networks, then E2E uses IPsec Transport mode instead of Tunnel mode, which removes networking and security overhead. This reduces CPU load by 20%, enhances Mobility and Multihoming operations by about 15%, and makes the system 2.9 times more reactive for detecting modifications of interfaces.
Daniel Migault, Daniel Palomares, Emmanuel Herbert, Gabriel Ganne, Ghada Arfaoui, Maryline Laurent
ARES7
2012 ISP Offload Infrastructure to minimize cost and time deployment
abstract
To face the huge demand on mobile traffic, ISPs are looking to offload traffic of their Radio Access Network to WLAN. Currently I-WLAN is the proposed offload architecture by 3GPP which tunnels the traffic to a Security Gateway. This paper proposes for ISPs an ISP Offload Infrastructure which minimizes the infrastructure cost deployment, and which can be deployed in a very short term. The ISP Offload Infrastructure classifies the EU traffic into 3 distinct classes and assigns each class a specific and adapted offload architecture: ForWarD Architecture (FWDA), Offload Service Architecture (OSA) and Offload Access Architecture (OAA). This paper shows how to deploy each Offload Architecture by using SCTP in conjunction to MOBIKE(-X) or only MOBIKE(-X). Then we measure how each Offload Architecture may affect the EU experience, and provide recommendations on how to deploy and implement the ISP Offload Infrastructure.
Daniel Migault, Daniel Palomares, Emmanuel Herbert, Gabriel Ganne, Ghada Arfaoui, Maryline Laurent
GLOBECOM7
2012 Context-Aware Decentralized Approach for Web Services
abstract
This paper presents a context-aware and decentralized identity platform, which in turn can be used to create social networks or collaboration platforms. Its originality lies in providing an increased privacy and control over a user's online identity, user group management, resource ownership and content sharing. This paper addresses the shortcomings of current identity and resource management systems, especially the lack of context in which data sharing takes place on the Internet. Moreover, it discusses the advantages for users to have a decentralized resource management system, while at the same time remaining in control of the data they share, as well as the device on which it is stored.
Andrei Vlad Sambra, Maryline Laurent
SERVICES2
2011 Towards multiple-exchange protocol use in distributed AAA frameworks for more autonomy in MANETs
abstract
In previous work, we designed a distributed AAA framework for MANETs for which we defined a simple and robust AAA authentication and authorization protocol whose specification carries some implementation latitude. The protocol, therefore, offers several options. In this paper, we propose some of the possible implementation options for which we conducted an analytical study and computationally intensive simulations to evaluate their performances. The objective is to provide guidelines for a fine tuning of this protocol.
Sondes Larafa, Maryline Laurent
ISCC2
2011 A Trustful Authentication and Key Exchange Scheme (TAKES) for ad hoc networks
abstract
This paper presents a new public key distribution scheme adapted to ad hoc networks called TAKES for Trustful Authentication and Key Exchange Scheme. Its originality lies in performing authentication and key distribution with no need for a trusted authority or access to any infrastructure-based network, thanks to the use of Cryptographically Generated Addresses. Moreover the solution is very convenient having a simple operational mode at no extra hardware cost. TAKES aims to build a trust association between a person, his/her communicating device, the IP address of the device, and his/her public key. As a direct result, new security functions like associating a misbehaving node to its owner, securing end-to-end communications through tunnels, or even implementing a light naming system can be enabled on top of ad hoc networks. TAKES is formally proven using BAN logic and a proof-of-concept implementation demonstrates its feasibility within ad hoc networks.
Tony Cheneau, Andrei Vlad Sambra, Maryline Laurent
NSS3
2011 Defeating pharming attacks at the client-side
abstract
With the deployment of “always-connected” broadband Internet access, personal networks are a privileged target for attackers and DNS-based corruption. Pharming attacks - an enhanced version of phishing attacks - aim to steal users' credentials by redirecting them to a fraudulent login website, using DNS-based techniques that make the attack imperceptible to the end-user. In this paper, we define an advanced approach to alert the end-user in case of pharming attacks at the client-side. With a success rate over 95%, we validate a solution that can help differentiating legitimate from fraudulent login websites, based on a dual-step analysis (IP address check and webpage content comparison) performed using multiple DNS servers information.
Sophie Gastellier-Prevost, Maryline Laurent
NSS2
2011 Key-escrow resistant ID-based authentication scheme for IEEE 802.11s mesh networks
abstract
Nowadays, ID-based cryptography is reported as an alternative to Public Key Infrastructures (PKI). It proposes to derive the public key from the node's identity directly. As such, there is no need for public key certifcates, and direct beneft of this is to remove the burdensome management of certifcates. However, the drawback is the need for a Private Key Generator (PKG) entity which can perform a key escrow attack. In this article, we present an ID-based authentication scheme that is adapted to the IEEE 802.11s mesh networks and resistant against key escrow attacks.
Aymen Boudguiga, Maryline Laurent
WCNC2
2010 A performance view on DNSSEC migration
abstract
In July 2008, the Kaminsky attack showed that DNS is sensitive to cache poisoning, and DNSSEC is considered the long term solution to mitigate this attack. A lot of technical documents provide configuration and security guide lines to deploy DNSSEC on organization's servers. However, such documents do not provide ISP or network administrators inputs to plan or evaluate the cost of the migration. This paper describes current deployment of DNSSEC and provides key elements to consider when planning DNSSEC deployment. Then we focus our work on performance aspects and provide experimental measurements for both DNS and DNSSEC architecture. Experimental results evaluate the cost of DNSSEC for authoritative and recursive server with different implementations.
Daniel Migault, Cedric Girard, Maryline Laurent
CNSM3
2010 An ID-based authentication scheme for the IEEE 802.11s Mesh Network
abstract
Nowadays authentication in Wireless Mesh Networks (WMN) refers to the 802.1X authentication methods or a Preshared key authentication, and makes use of certificates or shared secrets. In wireless environments, management of certificates is disadvantageous. Certificates require deploying a Public Key Infrastructure (PKI) and Certification Authorities (CA) and they require defining a certificate management policy to control the generation, transmission and revocation of certificates. Management of certificates is a cumbersome task and does not match the limited (power and memory) resources available at wireless nodes. Moreover it does not match the non permanent connectivity to CA. In this paper, we propose an ID-based method, as an alternative to the PKI, to provide nodes with private and public keys, and we present an authentication scheme that uses the ID-based cryptographic concepts. As illustrated in the paper, the authentication scheme is shown as suitable to the WMN networks.
Aymen Boudguiga, Maryline Laurent
WiMob2
2010 Significantly improved performances of the cryptographically generated addresses thanks to ECC and GPGPU
Tony Cheneau, Aymen Boudguiga, Maryline Laurent
Comput. Secur.3
2010 A secure peer-to-peer backup service keeping great autonomy while under the supervision of a provider
Houssem Jarraya, Maryline Laurent
Comput. Secur.2
2008 WATCHMAN: An Overlay Distributed AAA Architecture for Mobile Ad hoc Networks
abstract
Access control concerns in MANETs are very serious and considered as a crucial challenge for operators who prospects to employ unrivaled capabilities of such networks for different applications. We propose a novel hierarchical distributed AAA architecture for proactive link state routing protocols notably OLSR. This proposal contains a lightweight and secure design of an overlay authentication and authorization paradigm for mobile nodes as well as a reliable accounting system to enable operators to charge nodes based on their connection duration time. We also suggest a hierarchical distributed AAA (Authentication, Authorization, and Accounting) server architecture with resource and location aware election mechanism. Moreover, this proposal mitigates the OLSR security issues noticeably and eventually defines a node priority-based quality of service.
Amir R. Khakpour, Maryline Laurent, Hakima Chaouchi
ARES2
2007 SAPC: A Secure Aggregation Protocol for Cluster-Based Wireless Sensor Networks
Chakib Bekara, Maryline Laurent, Kheira Dari Bekara
MSN2
2007 Using PANA for Mobile IPv6 Bootstrapping
Julien Bournelle, Jean Michel Combes, Maryline Laurent, Sondes Larafa
Networking3
2007 A New Protocol for Securing Wireless Sensor Networks against Nodes Replication Attacks
Chakib Bekara, Maryline Laurent
WiMob2
2007 A New Resilient Key Management Protocol for Wireless Sensor Networks
Chakib Bekara, Maryline Laurent
WISTP2
2006 Improved EAP keying framework for a secure mobility access service
abstract
Users roaming is an important feature to be provided by current ISPs. The goal is to allow users to access to the Internet from everywhere without the need to have multiple subscriptions.A suitable authentication and key distribution mechanism between different domains involved is required to provide a secure network access service. The IETF solution for this is the Extensible Authentication Protocol (EAP) which supports various authentication methods while defining a keying framework. However, this framework suffers from some limitations in roaming scenario, specially in a mobility context. The reason is that each time the visited network needs to reauthenticate the client, the home domain must be contacted. This may introduce some consequent delay if the client is far from it.This paper proposes a new design which improves the current EAP keying distribution framework. The basic idea is to allow the visited domain to play a more active role in the key distribution. For this, we introduce a new level in the key hierarchy defined in the EAP keying framework. Thanks to this one, a new key can be used between the mobile and the visited network. This brings better performance during reauthentication as the home domain is no longer solicited.
Rafael Marín López, Antonio F. Skarmeta, Julien Bournelle, Maryline Laurent, Jean Michel Combes
IWCMC4
2002 For a Secure Mobile IP and Mobile IPv6 Deployment
Maryline Laurent
SEC1
2000 A Full Bandwidth ATM Firewall
Olivier Paul, Maryline Laurent, Sylvain Gombault
ESORICS2
2000 Improving Packet Filters Management through Automatic and Dynamic Schemes
Olivier Paul, Maryline Laurent
SEC2
1999 Secure Communications in ATM Networks
abstract
The ATM Forum international consortium recently approved the first version of its security specifications aiming to protect communications over Asynchronous Transfer Mode (ATM) networks by offering data confidentiality, partner authentication, etc. The paper describes the architecture of one of the first ATM Forum compliant security prototypes being currently developed in the European project SCAN (Secure Communications in ATM Networks). Additionally to the security management functions specified by the ATM Forum to exchange encryption keys and negotiate security services, SCAN implements the possibility for end users to modify the data flow encryption algorithm during a connection in progress, and the possibility to keep the encryption algorithm choice confidential. Moreover, a flexible implementation is offered allowing future users to develop their own security protocols and their own ATM security monitoring applications.
Maryline Laurent, Ahmed Bouabdallah, Christophe Delahaye, Herbert Leitold, Reinhard Posch, Enrique Areizaga, Juàn Manuel Mateos
ACSAC1
1999 An Asynchronous Distributed Access Control Architecture for IP over ATM Networks
abstract
We describe a new architecture providing an access control service in both ATM and IP-over-ATM networks. This architecture is based on agents distributed in network equipment. It is well known that distribution makes the management process more difficult. This issue is raised and we provide an algorithm to distribute the access control policy on our agents. The comparison with other approaches shows that this architecture provides big improvements in ATM-level access control, scalability and QoS preservation.
Olivier Paul, Maryline Laurent, Sylvain Gombault
ACSAC2
1997 Securing communications over ATM networks
Maryline Laurent, Olivier Paul, Pierre Rolin
SEC1