EDBT 2026 Demo / reviewers in the wild / expert
Timothy E. Levin
dblp:29/754
· DBLP profile ↗
17ranked-venue papers
2as first author
0since 2021 · last 2013
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 2 first-authorSystems, architecture and hardware · 4Software engineering, systems software and programming languages · 2
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
5 papers |
Systems and software security · 61% Hardware security and side channels · 34% Privacy and data protection · 4% | |
| Computer architecture, parallel and distributed computing, and storage systems
3 papers |
Reconfigurable computing and FPGAs · 40% Integrated circuit design · 27% Processor architecture and microarchitecture · 21% |
Topics — the 13 heaviest of 14, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Hardware security and side channels › hardware obfuscation
split manufacturing |
0.2 | 1 | 2013 | A 3-D Split Manufacturing Approach to Trustworthy System Development · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2013 |
Systems and software security
supply chain security |
0.2 | 1 | 2013 | A 3-D Split Manufacturing Approach to Trustworthy System Development · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2013 |
Systems and software security
operating system security |
0.1 | 2 | 2011 | Crafting a usable microkernel, processor, and I/O system with strict and provable information flow security · ISCA 2011 A Formal Model for UNIX Setuid · S&P 1989 |
Systems and software security
information flow control |
0.1 | 1 | 2011 | Crafting a usable microkernel, processor, and I/O system with strict and provable information flow security · ISCA 2011 |
Hardware security and side channels › trusted execution environments
hardware isolation |
0.1 | 1 | 2007 | Moats and Drawbridges: An Isolation Primitive for Reconfigurable Hardware Based Systems · S&P 2007 |
Reconfigurable computing and FPGAs
FPGA security |
0.1 | 1 | 2007 | Moats and Drawbridges: An Isolation Primitive for Reconfigurable Hardware Based Systems · S&P 2007 |
Integrated circuit design
3d integration |
0.0 | 1 | 2013 | A 3-D Split Manufacturing Approach to Trustworthy System Development · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2013 |
Processor architecture and microarchitecture › hardware-assisted security
secure processor architecture |
0.0 | 1 | 2011 | Crafting a usable microkernel, processor, and I/O system with strict and provable information flow security · ISCA 2011 |
Embedded and real-time systems
reconfigurable embedded systems |
0.0 | 1 | 2007 | Moats and Drawbridges: An Isolation Primitive for Reconfigurable Hardware Based Systems · S&P 2007 |
Authentication and access control
access control |
0.0 | 1 | 1989 | A Formal Model for UNIX Setuid · S&P 1989 |
Authentication and access control › access control models
discretionary access control |
0.0 | 1 | 1989 | A Formal Model for UNIX Setuid · S&P 1989 |
Systems and software security › operating system security
setuid |
0.0 | 1 | 1989 | A Formal Model for UNIX Setuid · S&P 1989 |
Systems and software security
formal security model |
0.0 | 1 | 1989 | A Formal Model for UNIX Setuid · S&P 1989 |
Methods — techniques the papers use, named apart from their topics
formal verification · 0.23d integration · 0.23-d integration · 0.2interconnect traceability · 0.1configuration scrubbing · 0.1formal modeling · 0.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2013 | A 3-D Split Manufacturing Approach to Trustworthy System DevelopmentabstractSecuring the supply chain of integrated circuits is of utmost importance to computer security. In addition to counterfeit microelectronics, the theft or malicious modification of designs in the foundry can result in catastrophic damage to critical systems and large projects. In this letter, we describe a 3-D architecture that splits a design into two separate tiers: one tier that contains critical security functions is manufactured in a trusted foundry; another tier is manufactured in an unsecured foundry. We argue that a split manufacturing approach to hardware trust based on 3-D integration is viable and provides several advantages over other approaches. Jonathan Valamehr, Timothy Sherwood, Ryan Kastner, David Marangoni-Simonsen, Ted Huffmire, Cynthia E. Irvine, Timothy E. Levin |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 7 |
| 2011 | Crafting a usable microkernel, processor, and I/O system with strict and provable information flow securityabstractHigh assurance systems used in avionics, medical implants, and cryptographic devices often rely on a small trusted base of hardware and software to manage the rest of the system. Crafting the core of such a system in a way that achieves flexibility, security, and performance requires a careful balancing act. Simple static primitives with hard partitions of space and time are easier to analyze formally, but strict approaches to the problem at the hardware level have been extremely restrictive, failing to allow even the simplest of dynamic behaviors to be expressed. Mohit Tiwari, Jason Oberg, Xun Li 0001, Jonathan Valamehr, Timothy E. Levin, Ben Hardekopf, Ryan Kastner, Fred Chong, Timothy Sherwood |
ISCA | 5 |
| 2010 | Hardware assistance for trustworthy systems through 3-D integrationabstractHardware resources are abundant; state-of-the-art processors have over one billion transistors. Yet for a variety of reasons, specialized hardware functions for high assurance processing are seldom (i.e., a couple of features per vendor over twenty years) integrated into these commodity processors, despite a small flurry of late (e.g., ARM TrustZone, Intel VT-x/VT-d and AMD-V/AMD-Vi, Intel TXT and AMD SVM, and Intel AES-NI). Furthermore, as chips increase in complexity, trustworthy processing of sensitive information can become increasingly difficult to achieve due to extensive on-chip resource sharing and the lack of corresponding protection mechanisms. In this paper, we introduce a method to enhance the security of commodity integrated circuits, using minor modifications, in conjunction with a separate integrated circuit that can provide monitoring, access control, and other useful security functions. We introduce a new architecture using a separate control plane, stacked using 3D integration, that allows for the function and economics of specialized security mechanisms, not available from a co-processor alone, to be integrated with the underlying commodity computing hardware. We first describe a general methodology to modify the host computation plane by attaching an optional control plane using 3-D integration. In a developed example we show how this approach can increase system trustworthiness, through mitigating the cache-based side channel problem by routing signals from the computation plane through a cache monitor in the 3-D control plane. We show that the overhead of our example application, in terms of area, delay and performance impact, is negligible. Jonathan Valamehr, Mohit Tiwari, Timothy Sherwood, Ryan Kastner, Ted Huffmire, Cynthia E. Irvine, Timothy E. Levin |
ACSAC | 7 |
| 2010 | Security Primitives for Reconfigurable Hardware-Based SystemsabstractComputing systems designed using reconfigurable hardware are increasingly composed using a number of different Intellectual Property (IP) cores, which are often provided by third-party vendors that may have different levels of trust. Unlike traditional software where hardware resources are mediated using an operating system, IP cores have fine-grain control over the underlying reconfigurable hardware. To address this problem, the embedded systems community requires novel security primitives that address the realities of modern reconfigurable hardware. In this work, we propose security primitives using ideas centered around the notion of “moats and drawbridges.” The primitives encompass four design properties: logical isolation, interconnect traceability, secure reconfigurable broadcast, and configuration scrubbing. Each of these is a fundamental operation with easily understood formal properties, yet they map cleanly and efficiently to a wide variety of reconfigurable devices. We carefully quantify the required overheads of the security techniques on modern FPGA architectures across a number of different applications. Ted Huffmire, Timothy E. Levin, Thuy D. Nguyen, Cynthia E. Irvine, Brett Brotherton, Gang Wang 0015, Timothy Sherwood, Ryan Kastner |
ACM Trans. Reconfigurable Technol. Syst. | 2 |
| 2008 | An Ontological Approach to Secure MANET ManagementabstractMobile ad hoc networks (MANETs) rely on dynamic configuration decisions to efficiently operate in a rapidly changing environment of limited resources. The ability of a MANET to make decisions that accurately reflect the real environment depends on the quality of the input to those decisions. However, collecting and processing of the multitudinous factors related to the operation of a MANET is a significant challenge. Equally significant in current approaches to dynamic MANET management is the lack of consideration given to security factors. We show how our ontology of MANET attributes including device security and performance characteristics can be leveraged to efficiently and effectively make dynamic configuration decisions for managing a MANET. Mark E. Orwat, Timothy E. Levin, Cynthia E. Irvine |
ARES | 2 |
| 2008 | Enforcing memory policy specifications in reconfigurable hardware
Ted Huffmire, Timothy Sherwood, Ryan Kastner, Timothy E. Levin |
Comput. Secur. | 4 |
| 2007 | Toward a Medium-Robustness Separation Kernel Protection ProfileabstractA protection profile for high-robustness separation kernels has recently been validated and several implementations are under development. However, medium-robustness separation kernel development efforts have no protection profile, although the US Government has published guidance for authoring such a profile. As a step toward a protection profile, a set of security requirements for medium-robustness separation kernels is proposed. These requirements result from an informal, yet principled, approach. By bracketing the problem with appropriate reference points and elaborating a method for interpolating the requirements both a measure of uniformity and a basis for further discussion are achieved. Our reference points include the high robustness protection profile, the existing medium robustness consistency instruction, and our familiarity with the nuances of separation kernels. This practitioner-oriented study is intended to advance the prevailing practices for commercial software development, which presently falls far short of the rigor needed for either high-robustness or medium-robustness systems. These requirements represent an incremental improvement in the pursuit of secure software - and is intended to be a step forward on the road to higher assurance. Rance J. DeLong, Thuy D. Nguyen, Cynthia E. Irvine, Timothy E. Levin |
ACSAC | 4 |
| 2007 | Moats and Drawbridges: An Isolation Primitive for Reconfigurable Hardware Based SystemsabstractBlurring the line between software and hardware, reconfigurable devices strike a balance between the raw high speed of custom silicon and the post-fabrication flexibility of general-purpose processors. While this flexibility is a boon for embedded system developers, who can now rapidly prototype and deploy solutions with performance approaching custom designs, this results in a system development methodology where functionality is stitched together from a variety of "soft IP cores," often provided by multiple vendors with different levels of trust. Unlike traditional software where resources are managed by an operating system, soft IP cores necessarily have very fine grain control over the underlying hardware. To address this problem, the embedded systems community requires novel security primitives which address the realities of modern reconfigurable hardware. We propose an isolation primitive, moats and drawbridges, that are built around four design properties: logical isolation, interconnect traceability, secure reconfigurable broadcast, and configuration scrubbing. Each of these is a fundamental operation with easily understood formal properties, yet maps cleanly and efficiently to a wide variety of reconfigurable devices. We carefully quantify the required overheads on real FPGAs and demonstrate the utility of our methods by applying them to the practical problem of memory protection. Ted Huffmire, Brett Brotherton, Gang Wang 0015, Timothy Sherwood, Ryan Kastner, Timothy E. Levin, Thuy D. Nguyen, Cynthia E. Irvine |
S&P | 6 |
| 2006 | Least Privilege in Separation Kernels
Timothy E. Levin, Cynthia E. Irvine, Thuy D. Nguyen |
SECRYPT | 1 |
| 2003 | An Editor for Adaptive XML-Based Policy Management of IPsecabstractThe IPsec protocol provides a mechanism to enforce a range of security services for both confidentiality and integrity, enabling secure transmission of information across networks. Dynamic parameterization of IPsec, via the KeyNote trust management system, further enables security mechanisms to adjust the level of security service "on-the-fly" to respond to changing network and operational conditions. However KeyNote requires that an IPsec policy be defined in the KeyNote specification syntax. Defining such a dynamic security policy in the KeyNote policy specification language is complicated and can lead to incorrect specification of the desired policy, thus degrading the security of the network. We present an alternative XML representation of this language and a graphical user interface to create and manage a consistent and correct security policy. The interface has the simplicity of a simple menu-driven editor that not only provides KeyNote with a policy in the specified syntax but also integrates techniques to support administrative policy verification. Raj Mohan, Timothy E. Levin, Cynthia E. Irvine |
ACSAC | 2 |
| 2002 | An Approach to Security Requirements Engineering for a High Assurance System
Cynthia E. Irvine, Timothy E. Levin, Jeffery D. Wilson, David J. Shifflett, Barbara Pereira |
Requir. Eng. | 2 |
| 2001 | Collective Value of QoS: A Performance Measure Framework for Distributed Heterogeneous NetworksabstractWhen user's tasks in a distributed heterogeneous computing environment are allocated resources, and the total demand placed on system resources by the tasks, for a given interval of time, exceeds the resources available, some tasks will receive degraded service, receive no service at all, or may be dropped from the system. One part of a measure to quantify the success of a resource management system (RMS) in such an environment is the collective value of the tasks completed during an interval of time, as perceived by the user, the application, or the policy maker. For the case where a task may be a data communication request, the collective value of data communication requests that are satisfied during an interval of time is measured. The Flexible Integrated System Capability (FISC) measure defined here is one way of obtaining a multi-dimensional measure for quantifying this collective value. While the FISC measure itself is not sufficient for scheduling purposes, it can be a critical part of a scheduler or a scheduling heuristic. The primary contribution of this work is providing a way to measure the collective value accrued by an RMS using a broad range of attributes and to construct a flexible framework that can be extended for particular problem domains. Jong-Kook Kim, Taylor Kidd, Howard Jay Siegel, Cynthia E. Irvine, Timothy E. Levin, Debra A. Hensgen, David St. John, Viktor Prasanna 0001, Richard F. Freund, N. Wayne Porter |
IPDPS | 5 |
| 2000 | Calculating Costs for Quality of Security ServiceabstractPresents a quality-of-security-service (QoSS) costing framework and a demonstration of it. A method for quantifying costs related to the security service and for storing and retrieving security information is illustrated. We describe a security model for tasks, which incorporates the ideas of variant security services invoked by the task, dynamic network modes, abstract security level choices and resource utilization costs. The estimated costs can be fed into a resource management system to facilitate the process of estimating efficient task schedules. Integration and scalability issues have been taken into account during the design of the QoSS costing demonstration, which we believe is suitable for incorporation into a resource management system research prototype. E. Spyropoulou, Timothy E. Levin, Cynthia E. Irvine |
ACSAC | 2 |
| 2000 | Quality of security serviceabstractAbstract 1. We examine the concept of security as a dimension of Quality of Service in distributed systems. Implicit to the concept of Quality of Service is the notion of choice or variation. Security services also offer a range of choice both from the user perspective and among the underlying resources. We provide a discussion and examples of user-specified security variables and show how the range of service levels associated with these variables can support the provision of Quality of Security Service, whereby security is a constructive network management tool rather than a performance obstacle. We also discuss various design implications regarding security ranges provided in a QoS-aware distributed system. Cynthia E. Irvine, Timothy E. Levin |
NSPW | 2 |
| 2000 | Is Electronic Privacy Achievable?
Cynthia E. Irvine, Timothy E. Levin |
S&P | 2 |
| 1999 | Toward a Taxonomy and Costing Method for Security ServicesabstractA wide range of security services may be available to applications in a heterogeneous computer network environment. Resource management systems (RMSs) responsible for assigning computing and network resources to tasks need to know the resource-utilization costs associated with the various network security services. In order to understand the range of security services all RMS needs to manage, a preliminary security service taxonomy is defined. The taxonomy is used as a framework for defining the costs associated with network security services. Cynthia E. Irvine, Timothy E. Levin |
ACSAC | 2 |
| 1989 | A Formal Model for UNIX SetuidabstractThe Unix setuid (set user identification) mechanism is described in the context of the GEMSOS architecture. Motivation for modeling setuid is given, and modeling and policy requirements for the control of the setuid mechanism are presented. The GEMSOS formal security policy model is compared with the Bell and LaPadula model. The Bell and LaPadula model is shown not to admit the actions of a setuid mechanism. Features of the GEMSOS DAC (discretionary access control) model are described that represent the actions of the Unix setuid mechanism while limiting their negative effect on the DAC policy.> Timothy E. Levin, S. J. Padilla, Cynthia E. Irvine |
S&P | 1 |