EDBT 2026 Demo / reviewers in the wild / expert
Barbara Masucci
dblp:39/5874
· DBLP profile ↗
44ranked-venue papers
4as first author
8since 2021 · last 2026
0000-0002-1570-8576ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 23 · 3 first-author · 7 since 2021Theory of computation · 13 · 1 first-authorDatabases, data management, data science and information retrieval · 9Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Anonymous Hierarchical Key Assignment Schemes
Roberta Cimorelli Belfiore, Alfredo De Santis, Anna Lisa Ferrara, Manuela Flores, Barbara Masucci |
DBSec | 5 |
| 2026 | Perfectly-Secure Graph-Based Distributed Secret Sharing Protocols
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci |
DBSec | 3 |
| 2026 | A Framework for Context-Aware Read Authorization over Encrypted Data
Roberta Cimorelli Belfiore, Anna Lisa Ferrara, Barbara Masucci |
SECRYPT (1) | 3 |
| 2024 | An Information-Theoretic Approach to Anonymous Access ControlabstractIn this paper, we introduce an information-theoretic approach to the access control problem within a scenario where a trusted central authority is tasked with user registration, and a set of guards is responsible for granting anonymous access to a restricted resource. More precisely, we consider access schemes with centralized user registration, where a trusted authority is responsible for the generation of access tokens assigned to users, while preserving user anonymity with respect to the guards. We first propose an information-theoretic model for anonymous access schemes with centralized user registration, then we show a lower bound on the size of the private information that each guard has to store. Finally, we propose a simple and optimal construction for anonymous access schemes with centralized registration. Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci, Giorgio Venditti |
ISIT | 3 |
| 2024 | Hierarchical Key Assignment Schemes with Key RotationabstractHierarchical structures are frequently used to manage access to sensitive data in various contexts, ranging from organizational settings to IoT networks. Roberta Cimorelli Belfiore, Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci |
SACMAT | 4 |
| 2024 | Cryptographic Enforcement of Access Control Policies: Models, Applications, and Future DirectionsabstractCryptographic enforcement of access control policies is a rapidly evolving field with ongoing research and development aimed at addressing emerging security challenges and requirements. Barbara Masucci |
SACMAT | 1 |
| 2024 | Provably-Secure One-Message Unilateral Entity Authentication SchemesabstractAone-message unilateral entity authentication schemeallows one party, called theprover, to authenticate himself, i.e., to prove his identity, to another party, called theverifier, by sending a singleauthentication message. We consider schemes where the prover and the verifier do not share any secret information, such as a password, in advance. We propose thefirst theoretical characterizationfor one-message unilateral entity authentication schemes, by formalizing the security requirements for such schemes with respect to different kinds ofpassiveandactiveadversarial behaviours. In particular, we consider bothstaticandadaptiveadversaries for each kind of attack (passive/active). Afterwards, we explore the relationships between the security notions resulting from different adversarial behaviours for one-message unilateral entity authentication schemes. Finally, we propose three different constructions for one-message unilateral entity authentication schemes and we analyze their security with respect to the different definitions introduced in this paper. Alfredo De Santis, Anna Lisa Ferrara, Manuela Flores, Barbara Masucci |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | New Results on Distributed Secret Sharing Protocols
Alfredo De Santis, Barbara Masucci |
DBSec | 2 |
| 2017 | One-Message Unilateral Entity Authentication SchemesabstractA one-message unilateral entity authentication scheme allows one party, called the prover, to authenticate himself, i.e., to prove his identity, to another party, called the verifier, by sending a single authentication message. Alfredo De Santis, Manuela Flores, Barbara Masucci |
ARES | 3 |
| 2017 | Supporting dynamic updates in storage clouds with the Akl-Taylor scheme
Arcangelo Castiglione, Alfredo De Santis, Barbara Masucci, Francesco Palmieri 0002, Xinyi Huang 0001, Aniello Castiglione |
Inf. Sci. | 3 |
| 2017 | On-Board Format-Independent Security of Functional Magnetic Resonance ImagesabstractFunctional magnetic resonance imaging (fMRI) provides an effective and noninvasive tool for researchers to understand cerebral functions and correlate them with brain activities. In addition, with the ever-increasing diffusion of the Internet, such images may be exchanged in several ways, allowing new research and medical services. On the other hand, ensuring the security of exchanged fMRI data becomes a main concern due to their special characteristics arising from strict ethics and legislative and diagnostic implications. Again, the risks increase when dealing with open environments like the Internet. For this reason, security mechanisms that ensure protection of such data are strongly required. However, we remark that the mechanisms commonly employed for data protection are doomed to fail when dealing with imaging data. In this article, we propose a novel watermarking scheme explicitly addressed for this type of imaging. Such a scheme can be used for several purposes, particularly to ensure authenticity and integrity. Moreover, we show how to integrate our scheme within commercial off-the-shelf fMRI system. Finally, the validity and the efficiency of our scheme has been assessed through testing. Arcangelo Castiglione, Raffaele Pizzolante, Francesco Palmieri 0002, Barbara Masucci, Bruno Carpentieri, Alfredo De Santis, Aniello Castiglione |
ACM Trans. Embed. Comput. Syst. | 4 |
| 2016 | On the Relations Between Security Notions in Hierarchical Key Assignment Schemes for Dynamic Structures
Arcangelo Castiglione, Alfredo De Santis, Barbara Masucci, Francesco Palmieri 0002, Aniello Castiglione |
ACISP (2) | 3 |
| 2016 | Key Indistinguishability versus Strong Key Indistinguishability for Hierarchical Key Assignment SchemesabstractA hierarchical key assignment scheme is a method to assign some private information and encryption keys to a set of classes in a partially ordered hierarchy, in such a way that the private information of a higher class can be used to derive the keys of all classes lower down in the hierarchy. In this paper we analyze the security of hierarchical key assignment schemes according to different notions: security with respect to key indistinguishability and against key recovery, as well as the two recently proposed notions of security with respect to strong key indistinguishability and against strong key recovery . We first explore the relations between all security notions and, in particular, we prove that security with respect to strong key indistinguishability is not stronger than the one with respect to key indistinguishability. Afterwards, we propose a general construction yielding a hierarchical key assignment scheme offering security against strong key recovery, given any hierarchical key assignment scheme which guarantees security against key recovery. Arcangelo Castiglione, Alfredo De Santis, Barbara Masucci |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2016 | Hierarchical and Shared Access ControlabstractAccess control ensures that only the authorized users of a system are allowed to access certain resources or tasks. Usually, according to their roles and responsibilities, users are organized in hierarchies formed by a certain number of disjoint classes. Such hierarchies are implemented by assigning a key to each class, so that the keys for descendant classes can be efficiently derived from classes higher in the hierarchy. However, pure hierarchical access may represent a limitation in many real-world cases. In fact, sometimes it is necessary to ensure access to a resource or task by considering both its directly responsible user and a group of users possessing certain credentials. In this paper, we first propose a novel model that generalizes the conventional hierarchical access control paradigm, by extending it to certain additional sets of qualified users. Afterward, we propose two constructions for hierarchical key assignment schemes in this new model, which are provably secure with respect to key indistinguishability. In particular, the former construction relies on both symmetric encryption and perfect secret sharing, whereas, the latter is based on public-key threshold broadcast encryption. Arcangelo Castiglione, Alfredo De Santis, Barbara Masucci, Francesco Palmieri 0002, Aniello Castiglione, Jin Li 0002, Xinyi Huang 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2016 | Cryptographic Hierarchical Access Control for Dynamic StructuresabstractA hierarchical key assignment scheme is a method to assign some private information and encryption keys to a set of classes in a partially ordered hierarchy, in such a way that the private information of a higher class can be used to derive the keys of all classes lower down in the hierarchy. Sometimes, it is necessary to make dynamic updates to the hierarchy, in order to implement an access control policy which evolves with time. All security models for hierarchical key assignment schemes have been designed to cope with static hierarchies and do not consider the issue of performing dynamic updates to the hierarchy. In this paper, we define the concept of hierarchical key assignment schemes supporting dynamic updates, formalizing the relative security model. In particular, we provide the notion of security with respect to key indistinguishability, by considering the dynamic changes to the hierarchy. Moreover, we show how to construct a hierarchical key assignment scheme supporting dynamic updates, by using as a building block a symmetric encryption scheme. The proposed construction is provably secure with respect to key indistinguishability, and provides efficient key derivation and updating procedures, while requiring each user to store only a single private key. Arcangelo Castiglione, Alfredo De Santis, Barbara Masucci, Francesco Palmieri 0002, Aniello Castiglione, Xinyi Huang 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2015 | On the Equivalence of Two Security Notions for Hierarchical Key Assignment Schemes in the Unconditional SettingabstractThe access control problem in a hierarchy can be solved by using a hierarchical key assignment scheme, where each class is assigned an encryption key and some private information. A formal security analysis for hierarchical key assignment schemes has been traditionally considered in two different settings, i.e., the unconditionally secure and the computationally secure setting, and with respect to two different notions: security against key recovery (KR-security) and security with respect to key indistinguishability (KI-security), with the latter notion being cryptographically stronger. Recently, Freire, Paterson and Poettering proposed strong key indistinguishability (SKI-security) as a new security notion in the computationally secure setting, arguing that SKI-security is strictly stronger than KI-security in such a setting. In this paper we consider tthehe unconditionally secure setting for hierarchical key assignment schemes. In such a setting the security of the schemes is not based on specific unproven computational assumptions, i.e., it relies on the theoretical impossibility of breaking them, despite the computational power of an adversary coalition. We prove that, in this setting, SKI-security is not stronger than KI-security, i.e., the two notions are fully equivalent from an information-theoretic point of view. Massimo Cafaro, Roberto Civino, Barbara Masucci |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2013 | A note on time-bound hierarchical key assignment schemes
Giuseppe Ateniese, Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci |
Inf. Process. Lett. | 4 |
| 2012 | Provably-Secure Time-Bound Hierarchical Key Assignment Schemes
Giuseppe Ateniese, Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci |
J. Cryptol. | 4 |
| 2011 | Efficient provably-secure hierarchical key assignment schemes
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci |
Theor. Comput. Sci. | 3 |
| 2010 | Variations on a theme by Akl and Taylor: Security and tradeoffs
Paolo D'Arco, Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci |
Theor. Comput. Sci. | 4 |
| 2009 | Security and Tradeoffs of the Akl-Taylor Scheme and Its Variants
Paolo D'Arco, Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci |
MFCS | 4 |
| 2008 | An attack on a payment scheme
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci |
Inf. Sci. | 3 |
| 2008 | New constructions for provably-secure time-bound hierarchical key assignment schemes
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci |
Theor. Comput. Sci. | 3 |
| 2007 | Efficient Provably-Secure Hierarchical Key Assignment Schemes
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci |
MFCS | 3 |
| 2007 | New constructions for provably-secure time-bound hierarchical key assignment schemesabstractA time-bound hierarchical key assignment scheme is a method to assign time-dependent encryption keys to a set of classes in a partially ordered hierarchy, in such a way that each class can derive the keys of all classes lower down in the hierarchy, according to temporal constraints. Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci |
SACMAT | 3 |
| 2007 | New results on non-perfect sharing of multiple secrets
Alfredo De Santis, Barbara Masucci |
J. Syst. Softw. | 2 |
| 2006 | Provably-secure time-bound hierarchical key assignment schemesabstractA time-bound hierarchical key assignment scheme is a method to assign time-dependent encryption keys to a set of classes in a partially ordered hierarchy, in such a way that the key of a higher class can be used to derive the keys of all classes lower down in the hierarchy, according to temporal constraints.In this paper we design and analyze time-bound hierarchical key assignment schemes which are provably-secure and efficient. We first consider the unconditionally secure setting and we show a tight lower bound on the size of the private information distributed to each class. Then, we consider the computationally secure setting and obtain several results: We first prove that a recently proposed scheme is insecure against collusion attacks. Hence, motivated by the need for provably-secure schemes, we propose two different constructions for time-bound hierarchical key assignment schemes. The first one is based on symmetric encryption schemes, whereas, the second one makes use of bilinear maps. These appear to be the first constructions of time-bound hierarchical key assignment schemes which are simultaneously practical and provably-secure. Giuseppe Ateniese, Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci |
CCS | 4 |
| 2006 | Unconditionally secure key assignment schemes
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci |
Discret. Appl. Math. | 3 |
| 2006 | Sharing Multiple Secrets: Models, Schemes and Analysis
Barbara Masucci |
Des. Codes Cryptogr. | 1 |
| 2006 | Enforcing the security of a time-bound hierarchical key assignment scheme
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci |
Inf. Sci. | 3 |
| 2005 | Design and Implementation of an Inline Certified E-mail Service
Stelvio Cimato, Clemente Galdi, Raffaella Giordano, Barbara Masucci, Gildo Tomasco |
CANS | 4 |
| 2005 | Ideal contrast visual cryptography schemes with reversing
Stelvio Cimato, Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci |
Inf. Process. Lett. | 4 |
| 2004 | A Linear Algebraic Approach to Metering Schemes
Carlo Blundo, Sebastià Martín Molleví, Barbara Masucci, Carles Padró |
Des. Codes Cryptogr. | 3 |
| 2004 | Anonymous Membership Broadcast Schemes
Alfredo De Santis, Barbara Masucci |
Des. Codes Cryptogr. | 2 |
| 2004 | Cryptographic key assignment schemes for any access control policy
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci |
Inf. Process. Lett. | 3 |
| 2002 | Constructions and Bounds for Unconditionally Secure Non-Interactive Commitment Schemes
Carlo Blundo, Barbara Masucci, Douglas Robert Stinson, Ruizhong Wei |
Des. Codes Cryptogr. | 2 |
| 2002 | A note on optimal metering schemes
Carlo Blundo, Stelvio Cimato, Barbara Masucci |
Inf. Process. Lett. | 3 |
| 2001 | Efficient metering schemes with pricingabstractIn order to decide on advertisement fees for Web servers, Naor and Pinkas (see Proc. Advances in Cryptology-EUROCRYPT'98 (Lecture Notes in Computer Science). New York: Springer-Verlag, vol.1403, p.576-590, 1998) introduced metering schemes. They proposed metering schemes in which any server is able to compute a proof to be sent to an audit agency if and only if it has been visited by at least a certain number, say h, of clients. In such schemes, any server which has been visited by less than h clients has no information about the proof; consequently, it does not receive any money from the audit agency. In order to have a more flexible payment system, Blundo, De Bonis, and Masucci (see Proc. 4th Int. Symp. Distributed Computing-2000 (Lecture Notes in Computer Science). New York: Springer-Verlag, vol.1914, p.194-208,2000) introduced metering schemes with pricing. These schemes allow different rates of payments based on the number of visits that each server has received. In this paper, we are interested in the efficiency of metering schemes with pricing. We propose a new model for metering schemes with pricing and we provide lower bounds on the size of the information distributed to clients and servers, and on the number of random bits needed by the audit agency to set up a metering scheme with pricing. These bounds are tight, as we provide a scheme which achieves them with equality. Compared to the scheme presented by Blundo, De Bonis, and Masucci, our scheme distributes less information to clients and servers. The drawback of our scheme is that it requires servers to interact with the audit agency in order to compute their proofs. Barbara Masucci, Douglas Robert Stinson |
IEEE Trans. Inf. Theory | 1 |
| 2000 | Metering Schemes for General Access Structures
Barbara Masucci, Douglas Robert Stinson |
ESORICS | 1 |
| 2000 | Metering Schemes with Pricing
Carlo Blundo, Annalisa De Bonis, Barbara Masucci |
DISC | 3 |
| 2000 | On secret set schemes
Alfredo De Santis, Barbara Masucci |
Inf. Process. Lett. | 2 |
| 1999 | A Lower Bound on the Encoding Length in Lossy Transmission
Alfredo De Santis, Barbara Masucci |
Inf. Sci. | 2 |
| 1999 | A Note on the Randomness in Dynamic Threshold SchemesabstractIn dynamic threshold schemes the dealer is able (after a preprocessing stage) to allow sets of participants of a given cardinality to reconstruct different secrets (in different time instants) by sending them the same broadcast message. In this paper we provide a tight lower bound on the number of random bits needed by the dealer to set up a dynamic threshold scheme. Carlo Blundo, Barbara Masucci |
J. Comput. Secur. | 2 |
| 1999 | Multiple ramp schemesabstractA (t,k,n,S) ramp scheme is a protocol to distribute a secret s chosen in S among a set P of n participants in such a way that: (1) sets of participants of cardinality greater than or equal to k can reconstruct the secret s; (2) sets of participants of cardinality less than or equal to t have no information on s, whereas (3) sets of participants of cardinality greater than t and less than k might have "some" information on s. In this correspondence we analyze multiple ramp schemes, which are protocols to share many secrets among a set P of participants, using different ramp schemes. In particular, we prove a tight lower bound on the size of the shares held by each participant and on the dealer's randomness in multiple ramp schemes. Alfredo De Santis, Barbara Masucci |
IEEE Trans. Inf. Theory | 2 |