Barbara Masucci

dblp:39/5874 · DBLP profile ↗
← Back
44ranked-venue papers
4as first author
8since 2021 · last 2026
0000-0002-1570-8576ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 23 · 3 first-author · 7 since 2021Theory of computation · 13 · 1 first-authorDatabases, data management, data science and information retrieval · 9Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Anonymous Hierarchical Key Assignment Schemes
Roberta Cimorelli Belfiore, Alfredo De Santis, Anna Lisa Ferrara, Manuela Flores, Barbara Masucci
DBSec5
2026 Perfectly-Secure Graph-Based Distributed Secret Sharing Protocols
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
DBSec3
2026 A Framework for Context-Aware Read Authorization over Encrypted Data
Roberta Cimorelli Belfiore, Anna Lisa Ferrara, Barbara Masucci
SECRYPT (1)3
2024 An Information-Theoretic Approach to Anonymous Access Control
abstract
In this paper, we introduce an information-theoretic approach to the access control problem within a scenario where a trusted central authority is tasked with user registration, and a set of guards is responsible for granting anonymous access to a restricted resource. More precisely, we consider access schemes with centralized user registration, where a trusted authority is responsible for the generation of access tokens assigned to users, while preserving user anonymity with respect to the guards. We first propose an information-theoretic model for anonymous access schemes with centralized user registration, then we show a lower bound on the size of the private information that each guard has to store. Finally, we propose a simple and optimal construction for anonymous access schemes with centralized registration.
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci, Giorgio Venditti
ISIT3
2024 Hierarchical Key Assignment Schemes with Key Rotation
abstract
Hierarchical structures are frequently used to manage access to sensitive data in various contexts, ranging from organizational settings to IoT networks.
Roberta Cimorelli Belfiore, Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
SACMAT4
2024 Cryptographic Enforcement of Access Control Policies: Models, Applications, and Future Directions
abstract
Cryptographic enforcement of access control policies is a rapidly evolving field with ongoing research and development aimed at addressing emerging security challenges and requirements.
Barbara Masucci
SACMAT1
2024 Provably-Secure One-Message Unilateral Entity Authentication Schemes
abstract
Aone-message unilateral entity authentication schemeallows one party, called theprover, to authenticate himself, i.e., to prove his identity, to another party, called theverifier, by sending a singleauthentication message. We consider schemes where the prover and the verifier do not share any secret information, such as a password, in advance. We propose thefirst theoretical characterizationfor one-message unilateral entity authentication schemes, by formalizing the security requirements for such schemes with respect to different kinds ofpassiveandactiveadversarial behaviours. In particular, we consider bothstaticandadaptiveadversaries for each kind of attack (passive/active). Afterwards, we explore the relationships between the security notions resulting from different adversarial behaviours for one-message unilateral entity authentication schemes. Finally, we propose three different constructions for one-message unilateral entity authentication schemes and we analyze their security with respect to the different definitions introduced in this paper.
Alfredo De Santis, Anna Lisa Ferrara, Manuela Flores, Barbara Masucci
IEEE Trans. Dependable Secur. Comput.4
2023 New Results on Distributed Secret Sharing Protocols
Alfredo De Santis, Barbara Masucci
DBSec2
2017 One-Message Unilateral Entity Authentication Schemes
abstract
A one-message unilateral entity authentication scheme allows one party, called the prover, to authenticate himself, i.e., to prove his identity, to another party, called the verifier, by sending a single authentication message.
Alfredo De Santis, Manuela Flores, Barbara Masucci
ARES3
2017 Supporting dynamic updates in storage clouds with the Akl-Taylor scheme
Arcangelo Castiglione, Alfredo De Santis, Barbara Masucci, Francesco Palmieri 0002, Xinyi Huang 0001, Aniello Castiglione
Inf. Sci.3
2017 On-Board Format-Independent Security of Functional Magnetic Resonance Images
abstract
Functional magnetic resonance imaging (fMRI) provides an effective and noninvasive tool for researchers to understand cerebral functions and correlate them with brain activities. In addition, with the ever-increasing diffusion of the Internet, such images may be exchanged in several ways, allowing new research and medical services. On the other hand, ensuring the security of exchanged fMRI data becomes a main concern due to their special characteristics arising from strict ethics and legislative and diagnostic implications. Again, the risks increase when dealing with open environments like the Internet. For this reason, security mechanisms that ensure protection of such data are strongly required. However, we remark that the mechanisms commonly employed for data protection are doomed to fail when dealing with imaging data. In this article, we propose a novel watermarking scheme explicitly addressed for this type of imaging. Such a scheme can be used for several purposes, particularly to ensure authenticity and integrity. Moreover, we show how to integrate our scheme within commercial off-the-shelf fMRI system. Finally, the validity and the efficiency of our scheme has been assessed through testing.
Arcangelo Castiglione, Raffaele Pizzolante, Francesco Palmieri 0002, Barbara Masucci, Bruno Carpentieri, Alfredo De Santis, Aniello Castiglione
ACM Trans. Embed. Comput. Syst.4
2016 On the Relations Between Security Notions in Hierarchical Key Assignment Schemes for Dynamic Structures
Arcangelo Castiglione, Alfredo De Santis, Barbara Masucci, Francesco Palmieri 0002, Aniello Castiglione
ACISP (2)3
2016 Key Indistinguishability versus Strong Key Indistinguishability for Hierarchical Key Assignment Schemes
abstract
A hierarchical key assignment scheme is a method to assign some private information and encryption keys to a set of classes in a partially ordered hierarchy, in such a way that the private information of a higher class can be used to derive the keys of all classes lower down in the hierarchy. In this paper we analyze the security of hierarchical key assignment schemes according to different notions: security with respect to key indistinguishability and against key recovery, as well as the two recently proposed notions of security with respect to strong key indistinguishability and against strong key recovery . We first explore the relations between all security notions and, in particular, we prove that security with respect to strong key indistinguishability is not stronger than the one with respect to key indistinguishability. Afterwards, we propose a general construction yielding a hierarchical key assignment scheme offering security against strong key recovery, given any hierarchical key assignment scheme which guarantees security against key recovery.
Arcangelo Castiglione, Alfredo De Santis, Barbara Masucci
IEEE Trans. Dependable Secur. Comput.3
2016 Hierarchical and Shared Access Control
abstract
Access control ensures that only the authorized users of a system are allowed to access certain resources or tasks. Usually, according to their roles and responsibilities, users are organized in hierarchies formed by a certain number of disjoint classes. Such hierarchies are implemented by assigning a key to each class, so that the keys for descendant classes can be efficiently derived from classes higher in the hierarchy. However, pure hierarchical access may represent a limitation in many real-world cases. In fact, sometimes it is necessary to ensure access to a resource or task by considering both its directly responsible user and a group of users possessing certain credentials. In this paper, we first propose a novel model that generalizes the conventional hierarchical access control paradigm, by extending it to certain additional sets of qualified users. Afterward, we propose two constructions for hierarchical key assignment schemes in this new model, which are provably secure with respect to key indistinguishability. In particular, the former construction relies on both symmetric encryption and perfect secret sharing, whereas, the latter is based on public-key threshold broadcast encryption.
Arcangelo Castiglione, Alfredo De Santis, Barbara Masucci, Francesco Palmieri 0002, Aniello Castiglione, Jin Li 0002, Xinyi Huang 0001
IEEE Trans. Inf. Forensics Secur.3
2016 Cryptographic Hierarchical Access Control for Dynamic Structures
abstract
A hierarchical key assignment scheme is a method to assign some private information and encryption keys to a set of classes in a partially ordered hierarchy, in such a way that the private information of a higher class can be used to derive the keys of all classes lower down in the hierarchy. Sometimes, it is necessary to make dynamic updates to the hierarchy, in order to implement an access control policy which evolves with time. All security models for hierarchical key assignment schemes have been designed to cope with static hierarchies and do not consider the issue of performing dynamic updates to the hierarchy. In this paper, we define the concept of hierarchical key assignment schemes supporting dynamic updates, formalizing the relative security model. In particular, we provide the notion of security with respect to key indistinguishability, by considering the dynamic changes to the hierarchy. Moreover, we show how to construct a hierarchical key assignment scheme supporting dynamic updates, by using as a building block a symmetric encryption scheme. The proposed construction is provably secure with respect to key indistinguishability, and provides efficient key derivation and updating procedures, while requiring each user to store only a single private key.
Arcangelo Castiglione, Alfredo De Santis, Barbara Masucci, Francesco Palmieri 0002, Aniello Castiglione, Xinyi Huang 0001
IEEE Trans. Inf. Forensics Secur.3
2015 On the Equivalence of Two Security Notions for Hierarchical Key Assignment Schemes in the Unconditional Setting
abstract
The access control problem in a hierarchy can be solved by using a hierarchical key assignment scheme, where each class is assigned an encryption key and some private information. A formal security analysis for hierarchical key assignment schemes has been traditionally considered in two different settings, i.e., the unconditionally secure and the computationally secure setting, and with respect to two different notions: security against key recovery (KR-security) and security with respect to key indistinguishability (KI-security), with the latter notion being cryptographically stronger. Recently, Freire, Paterson and Poettering proposed strong key indistinguishability (SKI-security) as a new security notion in the computationally secure setting, arguing that SKI-security is strictly stronger than KI-security in such a setting. In this paper we consider tthehe unconditionally secure setting for hierarchical key assignment schemes. In such a setting the security of the schemes is not based on specific unproven computational assumptions, i.e., it relies on the theoretical impossibility of breaking them, despite the computational power of an adversary coalition. We prove that, in this setting, SKI-security is not stronger than KI-security, i.e., the two notions are fully equivalent from an information-theoretic point of view.
Massimo Cafaro, Roberto Civino, Barbara Masucci
IEEE Trans. Dependable Secur. Comput.3
2013 A note on time-bound hierarchical key assignment schemes
Giuseppe Ateniese, Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
Inf. Process. Lett.4
2012 Provably-Secure Time-Bound Hierarchical Key Assignment Schemes
Giuseppe Ateniese, Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
J. Cryptol.4
2011 Efficient provably-secure hierarchical key assignment schemes
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
Theor. Comput. Sci.3
2010 Variations on a theme by Akl and Taylor: Security and tradeoffs
Paolo D'Arco, Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
Theor. Comput. Sci.4
2009 Security and Tradeoffs of the Akl-Taylor Scheme and Its Variants
Paolo D'Arco, Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
MFCS4
2008 An attack on a payment scheme
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
Inf. Sci.3
2008 New constructions for provably-secure time-bound hierarchical key assignment schemes
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
Theor. Comput. Sci.3
2007 Efficient Provably-Secure Hierarchical Key Assignment Schemes
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
MFCS3
2007 New constructions for provably-secure time-bound hierarchical key assignment schemes
abstract
A time-bound hierarchical key assignment scheme is a method to assign time-dependent encryption keys to a set of classes in a partially ordered hierarchy, in such a way that each class can derive the keys of all classes lower down in the hierarchy, according to temporal constraints.
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
SACMAT3
2007 New results on non-perfect sharing of multiple secrets
Alfredo De Santis, Barbara Masucci
J. Syst. Softw.2
2006 Provably-secure time-bound hierarchical key assignment schemes
abstract
A time-bound hierarchical key assignment scheme is a method to assign time-dependent encryption keys to a set of classes in a partially ordered hierarchy, in such a way that the key of a higher class can be used to derive the keys of all classes lower down in the hierarchy, according to temporal constraints.In this paper we design and analyze time-bound hierarchical key assignment schemes which are provably-secure and efficient. We first consider the unconditionally secure setting and we show a tight lower bound on the size of the private information distributed to each class. Then, we consider the computationally secure setting and obtain several results: We first prove that a recently proposed scheme is insecure against collusion attacks. Hence, motivated by the need for provably-secure schemes, we propose two different constructions for time-bound hierarchical key assignment schemes. The first one is based on symmetric encryption schemes, whereas, the second one makes use of bilinear maps. These appear to be the first constructions of time-bound hierarchical key assignment schemes which are simultaneously practical and provably-secure.
Giuseppe Ateniese, Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
CCS4
2006 Unconditionally secure key assignment schemes
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
Discret. Appl. Math.3
2006 Sharing Multiple Secrets: Models, Schemes and Analysis
Barbara Masucci
Des. Codes Cryptogr.1
2006 Enforcing the security of a time-bound hierarchical key assignment scheme
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
Inf. Sci.3
2005 Design and Implementation of an Inline Certified E-mail Service
Stelvio Cimato, Clemente Galdi, Raffaella Giordano, Barbara Masucci, Gildo Tomasco
CANS4
2005 Ideal contrast visual cryptography schemes with reversing
Stelvio Cimato, Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
Inf. Process. Lett.4
2004 A Linear Algebraic Approach to Metering Schemes
Carlo Blundo, Sebastià Martín Molleví, Barbara Masucci, Carles Padró
Des. Codes Cryptogr.3
2004 Anonymous Membership Broadcast Schemes
Alfredo De Santis, Barbara Masucci
Des. Codes Cryptogr.2
2004 Cryptographic key assignment schemes for any access control policy
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
Inf. Process. Lett.3
2002 Constructions and Bounds for Unconditionally Secure Non-Interactive Commitment Schemes
Carlo Blundo, Barbara Masucci, Douglas Robert Stinson, Ruizhong Wei
Des. Codes Cryptogr.2
2002 A note on optimal metering schemes
Carlo Blundo, Stelvio Cimato, Barbara Masucci
Inf. Process. Lett.3
2001 Efficient metering schemes with pricing
abstract
In order to decide on advertisement fees for Web servers, Naor and Pinkas (see Proc. Advances in Cryptology-EUROCRYPT'98 (Lecture Notes in Computer Science). New York: Springer-Verlag, vol.1403, p.576-590, 1998) introduced metering schemes. They proposed metering schemes in which any server is able to compute a proof to be sent to an audit agency if and only if it has been visited by at least a certain number, say h, of clients. In such schemes, any server which has been visited by less than h clients has no information about the proof; consequently, it does not receive any money from the audit agency. In order to have a more flexible payment system, Blundo, De Bonis, and Masucci (see Proc. 4th Int. Symp. Distributed Computing-2000 (Lecture Notes in Computer Science). New York: Springer-Verlag, vol.1914, p.194-208,2000) introduced metering schemes with pricing. These schemes allow different rates of payments based on the number of visits that each server has received. In this paper, we are interested in the efficiency of metering schemes with pricing. We propose a new model for metering schemes with pricing and we provide lower bounds on the size of the information distributed to clients and servers, and on the number of random bits needed by the audit agency to set up a metering scheme with pricing. These bounds are tight, as we provide a scheme which achieves them with equality. Compared to the scheme presented by Blundo, De Bonis, and Masucci, our scheme distributes less information to clients and servers. The drawback of our scheme is that it requires servers to interact with the audit agency in order to compute their proofs.
Barbara Masucci, Douglas Robert Stinson
IEEE Trans. Inf. Theory1
2000 Metering Schemes for General Access Structures
Barbara Masucci, Douglas Robert Stinson
ESORICS1
2000 Metering Schemes with Pricing
Carlo Blundo, Annalisa De Bonis, Barbara Masucci
DISC3
2000 On secret set schemes
Alfredo De Santis, Barbara Masucci
Inf. Process. Lett.2
1999 A Lower Bound on the Encoding Length in Lossy Transmission
Alfredo De Santis, Barbara Masucci
Inf. Sci.2
1999 A Note on the Randomness in Dynamic Threshold Schemes
abstract
In dynamic threshold schemes the dealer is able (after a preprocessing stage) to allow sets of participants of a given cardinality to reconstruct different secrets (in different time instants) by sending them the same broadcast message. In this paper we provide a tight lower bound on the number of random bits needed by the dealer to set up a dynamic threshold scheme.
Carlo Blundo, Barbara Masucci
J. Comput. Secur.2
1999 Multiple ramp schemes
abstract
A (t,k,n,S) ramp scheme is a protocol to distribute a secret s chosen in S among a set P of n participants in such a way that: (1) sets of participants of cardinality greater than or equal to k can reconstruct the secret s; (2) sets of participants of cardinality less than or equal to t have no information on s, whereas (3) sets of participants of cardinality greater than t and less than k might have "some" information on s. In this correspondence we analyze multiple ramp schemes, which are protocols to share many secrets among a set P of participants, using different ramp schemes. In particular, we prove a tight lower bound on the size of the shares held by each participant and on the dealer's randomness in multiple ramp schemes.
Alfredo De Santis, Barbara Masucci
IEEE Trans. Inf. Theory2