Timothy E. Levin

dblp:29/754 · DBLP profile ↗
← Back
17ranked-venue papers
2as first author
0since 2021 · last 2013
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 12 · 2 first-authorSystems, architecture and hardware · 4Software engineering, systems software and programming languages · 2

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
5 papers
Systems and software security · 61% Hardware security and side channels · 34% Privacy and data protection · 4%
Computer architecture, parallel and distributed computing, and storage systems
3 papers
Reconfigurable computing and FPGAs · 40% Integrated circuit design · 27% Processor architecture and microarchitecture · 21%

Topics — the 13 heaviest of 14, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Hardware security and side channels › hardware obfuscation
split manufacturing
0.212013
A 3-D Split Manufacturing Approach to Trustworthy System Development · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2013
Systems and software security
supply chain security
0.212013
A 3-D Split Manufacturing Approach to Trustworthy System Development · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2013
Systems and software security
operating system security
0.122011
Crafting a usable microkernel, processor, and I/O system with strict and provable information flow security · ISCA 2011
A Formal Model for UNIX Setuid · S&P 1989
Systems and software security
information flow control
0.112011
Crafting a usable microkernel, processor, and I/O system with strict and provable information flow security · ISCA 2011
Hardware security and side channels › trusted execution environments
hardware isolation
0.112007
Moats and Drawbridges: An Isolation Primitive for Reconfigurable Hardware Based Systems · S&P 2007
Reconfigurable computing and FPGAs
FPGA security
0.112007
Moats and Drawbridges: An Isolation Primitive for Reconfigurable Hardware Based Systems · S&P 2007
Integrated circuit design
3d integration
0.012013
A 3-D Split Manufacturing Approach to Trustworthy System Development · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2013
Processor architecture and microarchitecture › hardware-assisted security
secure processor architecture
0.012011
Crafting a usable microkernel, processor, and I/O system with strict and provable information flow security · ISCA 2011
Embedded and real-time systems
reconfigurable embedded systems
0.012007
Moats and Drawbridges: An Isolation Primitive for Reconfigurable Hardware Based Systems · S&P 2007
Authentication and access control
access control
0.011989
A Formal Model for UNIX Setuid · S&P 1989
Authentication and access control › access control models
discretionary access control
0.011989
A Formal Model for UNIX Setuid · S&P 1989
Systems and software security › operating system security
setuid
0.011989
A Formal Model for UNIX Setuid · S&P 1989
Systems and software security
formal security model
0.011989
A Formal Model for UNIX Setuid · S&P 1989

Methods — techniques the papers use, named apart from their topics

formal verification · 0.23d integration · 0.23-d integration · 0.2interconnect traceability · 0.1configuration scrubbing · 0.1formal modeling · 0.0
YearPublicationVenuePosition
2013 A 3-D Split Manufacturing Approach to Trustworthy System Development
abstract
Securing the supply chain of integrated circuits is of utmost importance to computer security. In addition to counterfeit microelectronics, the theft or malicious modification of designs in the foundry can result in catastrophic damage to critical systems and large projects. In this letter, we describe a 3-D architecture that splits a design into two separate tiers: one tier that contains critical security functions is manufactured in a trusted foundry; another tier is manufactured in an unsecured foundry. We argue that a split manufacturing approach to hardware trust based on 3-D integration is viable and provides several advantages over other approaches.
Jonathan Valamehr, Timothy Sherwood, Ryan Kastner, David Marangoni-Simonsen, Ted Huffmire, Cynthia E. Irvine, Timothy E. Levin
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.7
2011 Crafting a usable microkernel, processor, and I/O system with strict and provable information flow security
abstract
High assurance systems used in avionics, medical implants, and cryptographic devices often rely on a small trusted base of hardware and software to manage the rest of the system. Crafting the core of such a system in a way that achieves flexibility, security, and performance requires a careful balancing act. Simple static primitives with hard partitions of space and time are easier to analyze formally, but strict approaches to the problem at the hardware level have been extremely restrictive, failing to allow even the simplest of dynamic behaviors to be expressed.
Mohit Tiwari, Jason Oberg, Xun Li 0001, Jonathan Valamehr, Timothy E. Levin, Ben Hardekopf, Ryan Kastner, Fred Chong, Timothy Sherwood
ISCA5
2010 Hardware assistance for trustworthy systems through 3-D integration
abstract
Hardware resources are abundant; state-of-the-art processors have over one billion transistors. Yet for a variety of reasons, specialized hardware functions for high assurance processing are seldom (i.e., a couple of features per vendor over twenty years) integrated into these commodity processors, despite a small flurry of late (e.g., ARM TrustZone, Intel VT-x/VT-d and AMD-V/AMD-Vi, Intel TXT and AMD SVM, and Intel AES-NI). Furthermore, as chips increase in complexity, trustworthy processing of sensitive information can become increasingly difficult to achieve due to extensive on-chip resource sharing and the lack of corresponding protection mechanisms. In this paper, we introduce a method to enhance the security of commodity integrated circuits, using minor modifications, in conjunction with a separate integrated circuit that can provide monitoring, access control, and other useful security functions. We introduce a new architecture using a separate control plane, stacked using 3D integration, that allows for the function and economics of specialized security mechanisms, not available from a co-processor alone, to be integrated with the underlying commodity computing hardware. We first describe a general methodology to modify the host computation plane by attaching an optional control plane using 3-D integration. In a developed example we show how this approach can increase system trustworthiness, through mitigating the cache-based side channel problem by routing signals from the computation plane through a cache monitor in the 3-D control plane. We show that the overhead of our example application, in terms of area, delay and performance impact, is negligible.
Jonathan Valamehr, Mohit Tiwari, Timothy Sherwood, Ryan Kastner, Ted Huffmire, Cynthia E. Irvine, Timothy E. Levin
ACSAC7
2010 Security Primitives for Reconfigurable Hardware-Based Systems
abstract
Computing systems designed using reconfigurable hardware are increasingly composed using a number of different Intellectual Property (IP) cores, which are often provided by third-party vendors that may have different levels of trust. Unlike traditional software where hardware resources are mediated using an operating system, IP cores have fine-grain control over the underlying reconfigurable hardware. To address this problem, the embedded systems community requires novel security primitives that address the realities of modern reconfigurable hardware. In this work, we propose security primitives using ideas centered around the notion of “moats and drawbridges.” The primitives encompass four design properties: logical isolation, interconnect traceability, secure reconfigurable broadcast, and configuration scrubbing. Each of these is a fundamental operation with easily understood formal properties, yet they map cleanly and efficiently to a wide variety of reconfigurable devices. We carefully quantify the required overheads of the security techniques on modern FPGA architectures across a number of different applications.
Ted Huffmire, Timothy E. Levin, Thuy D. Nguyen, Cynthia E. Irvine, Brett Brotherton, Gang Wang 0015, Timothy Sherwood, Ryan Kastner
ACM Trans. Reconfigurable Technol. Syst.2
2008 An Ontological Approach to Secure MANET Management
abstract
Mobile ad hoc networks (MANETs) rely on dynamic configuration decisions to efficiently operate in a rapidly changing environment of limited resources. The ability of a MANET to make decisions that accurately reflect the real environment depends on the quality of the input to those decisions. However, collecting and processing of the multitudinous factors related to the operation of a MANET is a significant challenge. Equally significant in current approaches to dynamic MANET management is the lack of consideration given to security factors. We show how our ontology of MANET attributes including device security and performance characteristics can be leveraged to efficiently and effectively make dynamic configuration decisions for managing a MANET.
Mark E. Orwat, Timothy E. Levin, Cynthia E. Irvine
ARES2
2008 Enforcing memory policy specifications in reconfigurable hardware
Ted Huffmire, Timothy Sherwood, Ryan Kastner, Timothy E. Levin
Comput. Secur.4
2007 Toward a Medium-Robustness Separation Kernel Protection Profile
abstract
A protection profile for high-robustness separation kernels has recently been validated and several implementations are under development. However, medium-robustness separation kernel development efforts have no protection profile, although the US Government has published guidance for authoring such a profile. As a step toward a protection profile, a set of security requirements for medium-robustness separation kernels is proposed. These requirements result from an informal, yet principled, approach. By bracketing the problem with appropriate reference points and elaborating a method for interpolating the requirements both a measure of uniformity and a basis for further discussion are achieved. Our reference points include the high robustness protection profile, the existing medium robustness consistency instruction, and our familiarity with the nuances of separation kernels. This practitioner-oriented study is intended to advance the prevailing practices for commercial software development, which presently falls far short of the rigor needed for either high-robustness or medium-robustness systems. These requirements represent an incremental improvement in the pursuit of secure software - and is intended to be a step forward on the road to higher assurance.
Rance J. DeLong, Thuy D. Nguyen, Cynthia E. Irvine, Timothy E. Levin
ACSAC4
2007 Moats and Drawbridges: An Isolation Primitive for Reconfigurable Hardware Based Systems
abstract
Blurring the line between software and hardware, reconfigurable devices strike a balance between the raw high speed of custom silicon and the post-fabrication flexibility of general-purpose processors. While this flexibility is a boon for embedded system developers, who can now rapidly prototype and deploy solutions with performance approaching custom designs, this results in a system development methodology where functionality is stitched together from a variety of "soft IP cores," often provided by multiple vendors with different levels of trust. Unlike traditional software where resources are managed by an operating system, soft IP cores necessarily have very fine grain control over the underlying hardware. To address this problem, the embedded systems community requires novel security primitives which address the realities of modern reconfigurable hardware. We propose an isolation primitive, moats and drawbridges, that are built around four design properties: logical isolation, interconnect traceability, secure reconfigurable broadcast, and configuration scrubbing. Each of these is a fundamental operation with easily understood formal properties, yet maps cleanly and efficiently to a wide variety of reconfigurable devices. We carefully quantify the required overheads on real FPGAs and demonstrate the utility of our methods by applying them to the practical problem of memory protection.
Ted Huffmire, Brett Brotherton, Gang Wang 0015, Timothy Sherwood, Ryan Kastner, Timothy E. Levin, Thuy D. Nguyen, Cynthia E. Irvine
S&P6
2006 Least Privilege in Separation Kernels
Timothy E. Levin, Cynthia E. Irvine, Thuy D. Nguyen
SECRYPT1
2003 An Editor for Adaptive XML-Based Policy Management of IPsec
abstract
The IPsec protocol provides a mechanism to enforce a range of security services for both confidentiality and integrity, enabling secure transmission of information across networks. Dynamic parameterization of IPsec, via the KeyNote trust management system, further enables security mechanisms to adjust the level of security service "on-the-fly" to respond to changing network and operational conditions. However KeyNote requires that an IPsec policy be defined in the KeyNote specification syntax. Defining such a dynamic security policy in the KeyNote policy specification language is complicated and can lead to incorrect specification of the desired policy, thus degrading the security of the network. We present an alternative XML representation of this language and a graphical user interface to create and manage a consistent and correct security policy. The interface has the simplicity of a simple menu-driven editor that not only provides KeyNote with a policy in the specified syntax but also integrates techniques to support administrative policy verification.
Raj Mohan, Timothy E. Levin, Cynthia E. Irvine
ACSAC2
2002 An Approach to Security Requirements Engineering for a High Assurance System
Cynthia E. Irvine, Timothy E. Levin, Jeffery D. Wilson, David J. Shifflett, Barbara Pereira
Requir. Eng.2
2001 Collective Value of QoS: A Performance Measure Framework for Distributed Heterogeneous Networks
abstract
When user's tasks in a distributed heterogeneous computing environment are allocated resources, and the total demand placed on system resources by the tasks, for a given interval of time, exceeds the resources available, some tasks will receive degraded service, receive no service at all, or may be dropped from the system. One part of a measure to quantify the success of a resource management system (RMS) in such an environment is the collective value of the tasks completed during an interval of time, as perceived by the user, the application, or the policy maker. For the case where a task may be a data communication request, the collective value of data communication requests that are satisfied during an interval of time is measured. The Flexible Integrated System Capability (FISC) measure defined here is one way of obtaining a multi-dimensional measure for quantifying this collective value. While the FISC measure itself is not sufficient for scheduling purposes, it can be a critical part of a scheduler or a scheduling heuristic. The primary contribution of this work is providing a way to measure the collective value accrued by an RMS using a broad range of attributes and to construct a flexible framework that can be extended for particular problem domains.
Jong-Kook Kim, Taylor Kidd, Howard Jay Siegel, Cynthia E. Irvine, Timothy E. Levin, Debra A. Hensgen, David St. John, Viktor Prasanna 0001, Richard F. Freund, N. Wayne Porter
IPDPS5
2000 Calculating Costs for Quality of Security Service
abstract
Presents a quality-of-security-service (QoSS) costing framework and a demonstration of it. A method for quantifying costs related to the security service and for storing and retrieving security information is illustrated. We describe a security model for tasks, which incorporates the ideas of variant security services invoked by the task, dynamic network modes, abstract security level choices and resource utilization costs. The estimated costs can be fed into a resource management system to facilitate the process of estimating efficient task schedules. Integration and scalability issues have been taken into account during the design of the QoSS costing demonstration, which we believe is suitable for incorporation into a resource management system research prototype.
E. Spyropoulou, Timothy E. Levin, Cynthia E. Irvine
ACSAC2
2000 Quality of security service
abstract
Abstract 1. We examine the concept of security as a dimension of Quality of Service in distributed systems. Implicit to the concept of Quality of Service is the notion of choice or variation. Security services also offer a range of choice both from the user perspective and among the underlying resources. We provide a discussion and examples of user-specified security variables and show how the range of service levels associated with these variables can support the provision of Quality of Security Service, whereby security is a constructive network management tool rather than a performance obstacle. We also discuss various design implications regarding security ranges provided in a QoS-aware distributed system.
Cynthia E. Irvine, Timothy E. Levin
NSPW2
2000 Is Electronic Privacy Achievable?
Cynthia E. Irvine, Timothy E. Levin
S&P2
1999 Toward a Taxonomy and Costing Method for Security Services
abstract
A wide range of security services may be available to applications in a heterogeneous computer network environment. Resource management systems (RMSs) responsible for assigning computing and network resources to tasks need to know the resource-utilization costs associated with the various network security services. In order to understand the range of security services all RMS needs to manage, a preliminary security service taxonomy is defined. The taxonomy is used as a framework for defining the costs associated with network security services.
Cynthia E. Irvine, Timothy E. Levin
ACSAC2
1989 A Formal Model for UNIX Setuid
abstract
The Unix setuid (set user identification) mechanism is described in the context of the GEMSOS architecture. Motivation for modeling setuid is given, and modeling and policy requirements for the control of the setuid mechanism are presented. The GEMSOS formal security policy model is compared with the Bell and LaPadula model. The Bell and LaPadula model is shown not to admit the actions of a setuid mechanism. Features of the GEMSOS DAC (discretionary access control) model are described that represent the actions of the Unix setuid mechanism while limiting their negative effect on the DAC policy.>
Timothy E. Levin, S. J. Padilla, Cynthia E. Irvine
S&P1