EDBT 2026 Demo / reviewers in the wild / expert
Bart De Decker
dblp:59/4614
· DBLP profile ↗
33ranked-venue papers
2as first author
2since 2021 · last 2023
0000-0003-2287-5249ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 31 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | A User-Centric Approach to API Delegations - Enforcing Privacy Policies on OAuth Delegations
Shirin Kalantari, Pieter Philippaerts, Yana Dimova, Danny Hughes 0001, Wouter Joosen, Bart De Decker |
ESORICS (2) | 6 |
| 2022 | Listing the ingredients for IFTTT recipesabstractThe Internet of Things (IoT) is increasingly connecting the most intimate parts of our daily lives to the Internet via connected ecosystems of hardware and software products. However, how these ecosystems operate and, in particular their impact on user privacy remains an open question. In this paper, we explore this question by analysing IFTTT, a popular task automation platform based on trigger-action programming. Through IFTTT, end users can easily create applets, aka recipes, that glue different IoT devices and online services together. While IFTTT brings many online services together, such as social media and mobile applications, its use for IoT automation is appealing for many users. Hence, analyzing the IFTTT ecosystem over time, enables us to study IoT trends and adaptation rate in real-user settings. In this paper we describe the IFTTT evolution by analyzing two existing IFTTT data sets and compiling a recent data set of its services and applets. This analysis exposes new platform characteristics and trends. Our data set, which was collected in October 2021, contains data about 694 services, 50898 applets, and 7003 endpoints. It also contains data about the information exchange in the platform via ingredients. In addition, we identify applets that might impose privacy risks for their users by detecting sensitive information flows in the system. We find that almost 30% of installations in the platform involve applets that utilize privacy-sensitive information such as users’ personal information, location, and health data. This trend is consistently present in the three analyzed data sets and, disturbingly, increases over time. Shirin Kalantari, Danny Hughes 0001, Bart De Decker |
TrustCom | 3 |
| 2017 | Security Evaluation of Cyber-Physical Systems Using Automatically Generated Attack Trees
Laurens Lemaire, Jan Vossaert, Bart De Decker, Vincent Naessens |
CRITIS | 3 |
| 2016 | PACCo: Privacy-friendly Access Control with ContextabstractWe propose a secure and privacy friendly way to strengthen authentication mechanisms of online services by
taking context into account. The use of context, however, is often of a personal nature (e.g. location) and
introduces privacy risks. Furthermore, some context sources can be spoofed, and hence, the level of trust of a
verifier in a context source can vary.
In this paper, a policy language to express contextual constraints is proposed. In addition, a set of protocols
to gather, verify and use contextual information in access control decisions is described. The system protects
user privacy as service providers do not learn precise context information, and avoids linkabilities. Finally, we
have implemented this system and our experimental evaluation shows that it is practical to use. Andreas Put, Bart De Decker |
SECRYPT | 2 |
| 2016 | Symmetric key infrastructure for authenticated key establishment between resource constrained nodes and powerful devicesabstractAbstract This paper presents a generic lightweight solution for authentication between powerful devices and resource constrained nodes. The approach is validated through the architectural design of multiple applications in different domains. The paper further discusses variants that might increase the usability of the approach in different settings. More precisely, the solution is tuned for open systems, closed systems and hierarchically structured systems. Further, two use cases are presented in which the open system and closed system approach is applied. Copyright © 2011 John Wiley & Sons, Ltd. Jan Vossaert, Jorn Lapon, Bart De Decker, Vincent Naessens |
Secur. Commun. Networks | 3 |
| 2015 | Privacy-Preserving Public Transport Ticketing System
Milica Milutinovic, Koen Decroix, Vincent Naessens, Bart De Decker |
DBSec | 4 |
| 2015 | An Efficient, Anonymous and Unlinkable Incentives SchemeabstractIncentives systems, such as loyalty schemes or reputation systems, are a popular way to encourage user actions or build a user-service provider relationship. In this paper, the authors describe uCentive, a privacy-preserving incentives scheme that allows users to earn and redeem incentives that cannot be linked to their identities or actions. In addition, users can prove ownership of their incentives without breaking unlinkability guarantees. uCentive also supports forward unlinkability – even if the user's secrets are compromised, they cannot be linked to previous user's actions. Milica Milutinovic, Andreas Put, Bart De Decker |
Int. J. Inf. Secur. Priv. | 3 |
| 2014 | EmailCloak: A Practical and Flexible Approach to Improve Email PrivacyabstractMillions of users rely on email providers to manage and store their personal communications. This vast amount of private information, however, is often misused not only by adversaries, but also by the providers themselves. End-to-end email encryption is considered the most robust defense against this threat, however, its many requirements make this approach impractical for protecting everyday emails. In this paper, we present Email Cloak, an email alias service with public key encryption capabilities. Email Cloak relaxes email encryption requirements by relying on a privacy-respecting third-party. Emails sent and received by the user are automatically encrypted with her public key by Email Cloak before being forwarded to, and stored by her email provider. This approach, while seemingly straightforward, offers multiple benefits: simplified key management, selective and automatic encryption, advanced deployment options and transparency towards other parties. Moreover, our experimental evaluation shows that the overhead introduced by Email Cloak is adequate for email communications. We have also made our implementation publicly available. In doing so, we deliver a practical and flexible tool that provides privacy-concerned users with greater control over their stored emails. Italo Dacosta, Andreas Put, Bart De Decker |
ARES | 3 |
| 2014 | PriMan: Facilitating the Development of Secure and Privacy-Preserving Applications
Andreas Put, Italo Dacosta, Milica Milutinovic, Bart De Decker |
SEC | 4 |
| 2014 | Trusted Computing to Increase Security and Privacy in eID Authentication
Jan Vossaert, Jorn Lapon, Bart De Decker, Vincent Naessens |
SEC | 3 |
| 2014 | inShopnito: An Advanced yet Privacy-Friendly Mobile Shopping ApplicationabstractMobile Shopping Applications (MSAs) are rapidly gaining popularity. They enhance the shopping experience, by offering customized recommendations or incorporating customer loyalty programs. Although MSAs are quite effective at attracting new customers and binding existing ones to a retailer's services, existing MSAs have several shortcomings. The data collection practices involved in MSAs and the lack of transparency thereof are important concerns for many customers. This paper presents inShopnito, a privacy-preserving mobile shopping application. All transactions made in inShopnito are unlinkable and anonymous. However, the system still offers the expected features from a modern MSA. Customers can take part in loyalty programs and earn or spend loyalty points and electronic vouchers. Furthermore, the MSA can suggest personalized recommendations even though the retailer cannot construct rich customer profiles. These profiles are managed on the smartphone and can be partially disclosed in order to get better, customized recommendations. Finally, we present an implementation called inShopnito, of which the security and performance is analyzed. In doing so, we show that it is possible to have a privacy-preserving MSA without having to sacrifice practicality. Andreas Put, Italo Dacosta, Milica Milutinovic, Bart De Decker, Stefaan Seys, Faysal Boukayoua, Vincent Naessens, Kris Vanhecke, Toon De Pessemier, Luc Martens |
SERVICES | 4 |
| 2012 | Analyzing Value Conflicts for a Work-Friendly ISS Policy Implementation
Ella Kolkowska, Bart De Decker |
SEC | 2 |
| 2012 | Privacy-Preserving Mechanisms for Organizing Tasks in a Pervasive eHealth System
Milica Milutinovic, Vincent Naessens, Bart De Decker |
SEC | 3 |
| 2010 | PriMan : A Privacy-Preserving Identity Framework
Kristof Verslype, Pieter Verhaeghe, Jorn Lapon, Vincent Naessens, Bart De Decker |
DBSec | 5 |
| 2010 | Performance Analysis of Accumulator-Based Revocation Mechanisms
Jorn Lapon, Markulf Kohlweiss, Bart De Decker, Vincent Naessens |
SEC | 3 |
| 2010 | Building advanced applications with the Belgian eIDabstractAbstract The Belgian Electronic Identity Card (eID) was introduced in 2002. The card enables Belgian citizens to digitally prove their identity and to sign electronic documents. Today, only a limited number of citizens really use the card in electronic applications. An important reason is the lack of killer functionality and killer applications. This paper presents two reusable extensions to the Belgian eID technology that opens up new opportunities for application developers. First, a secure and ubiquitously accessible remote storage service is presented. Second, it is shown how the eID card can be used to issue new certificates. The feasibility and reusability of both extensions are validated through the development of several applications in different domains. Copyright © 2010 John Wiley & Sons, Ltd. Jorn Lapon, Vincent Naessens, Bram Verdegem, Pieter Verhaeghe, Bart De Decker |
Secur. Commun. Networks | 5 |
| 2009 | Linking Privacy Solutions to Developer GoalsabstractPrivacy is gaining importance since more and more data becomes digitalized. There is also a growing interest from the security community because of the existing synergy between security and privacy. Unfortunately, the privacy development life cycle is less advanced than the security one. A clear classification into different objectives is not available yet. This paper attempts to scope the privacy landscape for software engineering by proposing an operational definition for privacy and by describing a privacy taxonomy. The taxonomy is rooted in the definition and presents a classification of privacy objectives, which correspond to the developer's goals. Each objective can be achieved by one or more strategies. As a validation for the taxonomy, existing privacy solutions are matched to each strategy. Kim Wuyts, Riccardo Scandariato, Bart De Decker, Wouter Joosen |
ARES | 3 |
| 2009 | Privacy-Preserving Telemonitoring for eHealth
Mohamed Layouni, Kristof Verslype, Mehmet Tahir Sandikkaya, Bart De Decker, Hans Vangheluwe |
DBSec | 4 |
| 2009 | Security and Privacy Improvements for the Belgian eID Technology
Pieter Verhaeghe, Jorn Lapon, Bart De Decker, Vincent Naessens, Kristof Verslype |
SEC | 3 |
| 2009 | Service and Timeframe Dependent Unlinkable One-time Pseudonyms
Kristof Verslype, Bart De Decker |
SECRYPT | 2 |
| 2008 | A Privacy-Preserving Ticketing System
Kristof Verslype, Bart De Decker, Vincent Naessens, Girma Nigusse, Jorn Lapon, Pieter Verhaeghe |
DBSec | 2 |
| 2008 | Ubiquitous Privacy-Preserving Identity Managment
Kristof Verslype, Bart De Decker |
SEC | 2 |
| 2007 | A Practical System for Globally Revoking the Unlinkable Pseudonyms of Unknown Users
Stefan Brands, Liesje Demuynck, Bart De Decker |
ACISP | 3 |
| 2007 | A Credential-Based System for the Anonymous Delegation of Rights
Liesje Demuynck, Bart De Decker, Wouter Joosen |
SEC | 2 |
| 2006 | A Methodology for Designing Controlled Anonymous Applications
Vincent Naessens, Bart De Decker |
SEC | 2 |
| 2005 | Towards a software architecture for DRMabstractThe domain of digital rights management (DRM) is currently lacking a generic architecture that supports interoperability and reuse of specific DRM technologies. This lack of architectural support is a serious drawback in light of the rapid evolution of a complex domain like DRM. It is highly unlikely that a single DRM technology or standard will be able to support the diversity of devices, users, platforms, and media, or the wide variety of system requirements concerning security, flexibility, and efficiency. This paper analyses state-of-the-art DRM technologies and extracts from them high level usage scenarios according to content consumers, producers, and publishers. In addition, the key services are identified both from a functional and security perspective. Identifying key DRM services and locating them in an overall structure brings us one step closer to a software architecture for DRM. Having available a software architecture should help the DRM community in reasoning about DRM systems, and in achieving reuse and interoperability of multiple domain-specific DRM technologies and standards. Sam Michiels, Kristof Verslype, Wouter Joosen, Bart De Decker |
Digital Rights Management Workshop | 4 |
| 2005 | Accountable Anonymous E-Mail
Vincent Naessens, Bart De Decker, Liesje Demuynck |
SEC | 2 |
| 2003 | Secure Vickrey Auctions without a Trusted Third Party
Bart De Decker, Gregory Neven, Frank Piessens |
SEC | 1 |
| 2001 | Second Price Auctions - A Case Study of Secure Distributed Computating
Bart De Decker, Gregory Neven, Frank Piessens, Erik Van Hoeymissen |
DAIS | 1 |
| 2001 | On Securely Scheduling a Meeting
T. Herlea, Joris Claessens, Bart Preneel, Gregory Neven, Frank Piessens, Bart De Decker |
SEC | 6 |
| 2000 | On the Practical Feasibiltiy of Secure Distributed Computing: A Case Study
Gregory Neven, Frank Piessens, Bart De Decker |
SEC | 3 |
| 2000 | A Security Architecture for Electronic Commerce Applications
Bart De Win, Jan Van den Bergh 0002, Frank Matthijs, Bart De Decker, Wouter Joosen |
SEC | 4 |
| 1993 | Interconnecting domains with heterogeneous key distribution and authentication protocolsabstractA number of mechanisms are described that can be used in the design of a protocol converter for authentication and key distribution protocols. First, the scope of the mechanisms is defined. The authors outline the class of authentication systems that were considered during the design of the mechanisms. A first mechanism, based on proxies and a synchronization protocol, allows for a transparent protocol conversion. It is generic, and can be tailored to different specific situations. The second mechanism addresses the problem of the state of the protocol converter. Both mechanisms can be used separately or in combination. When properly combined, they provide for a robust, transparent, and safe protocol converter for authentication and key distribution protocols. Example applications are described in some detail.> Frank Piessens, Bart De Decker, Phil Janson |
S&P | 2 |