Anna Lisa Ferrara

dblp:60/6199 · DBLP profile ↗
← Back
35ranked-venue papers
8as first author
9since 2021 · last 2026
0000-0002-1026-5729ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 19 · 6 first-author · 8 since 2021Theory of computation · 11 · 1 first-authorDatabases, data management, data science and information retrieval · 6Software engineering, systems software and programming languages · 2 · 2 first-authorArtificial intelligence and machine learning · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Anonymous Hierarchical Key Assignment Schemes
Roberta Cimorelli Belfiore, Alfredo De Santis, Anna Lisa Ferrara, Manuela Flores, Barbara Masucci
DBSec3
2026 Perfectly-Secure Graph-Based Distributed Secret Sharing Protocols
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
DBSec2
2026 A Framework for Context-Aware Read Authorization over Encrypted Data
Roberta Cimorelli Belfiore, Anna Lisa Ferrara, Barbara Masucci
SECRYPT (1)2
2024 Identity-Based Matchmaking Encryption from Standard Lattice Assumptions
Roberta Cimorelli Belfiore, Andrea De Cosmo, Anna Lisa Ferrara
ACNS (2)3
2024 An Information-Theoretic Approach to Anonymous Access Control
abstract
In this paper, we introduce an information-theoretic approach to the access control problem within a scenario where a trusted central authority is tasked with user registration, and a set of guards is responsible for granting anonymous access to a restricted resource. More precisely, we consider access schemes with centralized user registration, where a trusted authority is responsible for the generation of access tokens assigned to users, while preserving user anonymity with respect to the guards. We first propose an information-theoretic model for anonymous access schemes with centralized user registration, then we show a lower bound on the size of the private information that each guard has to store. Finally, we propose a simple and optimal construction for anonymous access schemes with centralized registration.
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci, Giorgio Venditti
ISIT2
2024 Hierarchical Key Assignment Schemes with Key Rotation
abstract
Hierarchical structures are frequently used to manage access to sensitive data in various contexts, ranging from organizational settings to IoT networks.
Roberta Cimorelli Belfiore, Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
SACMAT3
2024 Provably-Secure One-Message Unilateral Entity Authentication Schemes
abstract
Aone-message unilateral entity authentication schemeallows one party, called theprover, to authenticate himself, i.e., to prove his identity, to another party, called theverifier, by sending a singleauthentication message. We consider schemes where the prover and the verifier do not share any secret information, such as a password, in advance. We propose thefirst theoretical characterizationfor one-message unilateral entity authentication schemes, by formalizing the security requirements for such schemes with respect to different kinds ofpassiveandactiveadversarial behaviours. In particular, we consider bothstaticandadaptiveadversaries for each kind of attack (passive/active). Afterwards, we explore the relationships between the security notions resulting from different adversarial behaviours for one-message unilateral entity authentication schemes. Finally, we propose three different constructions for one-message unilateral entity authentication schemes and we analyze their security with respect to the different definitions introduced in this paper.
Alfredo De Santis, Anna Lisa Ferrara, Manuela Flores, Barbara Masucci
IEEE Trans. Dependable Secur. Comput.2
2023 Security Analysis of Access Control Policies for Smart Homes
abstract
Ensuring security is crucial in smart home settings, where only authorized users should have access to home devices. Over the past decade, researchers have focused on developing access control policies and evaluating their efficacy in preventing unauthorized access. A new variant of Role-Based Access Control (RBAC), called Extended Generalized Role-Based Access Control (EGRBAC), has recently been introduced to capture the intricate user-device-context interactions that are prevalent in smart home environments. In this paper, we demonstrate that the task of analyzing administrative EGRBAC policies for security can be performed by reducing it to the security analysis of administrative RBAC policies. We also conducted a case study on a realistic smart home to prove the viability of our approach with respect of security requirements such as availability and privilege escalation.
Roberta Cimorelli Belfiore, Anna Lisa Ferrara
SACMAT2
2021 Verifiable Hierarchical Key Assignment Schemes
Anna Lisa Ferrara, Federica Paci, Chiara Ricciardi
DBSec1
2020 Fuzzy-based approach to assess and prioritize privacy risks
Stephen Hart, Anna Lisa Ferrara, Federica Paci
Soft Comput.2
2017 Toward Group-Based User-Attribute Policies in Azure-Like Access Control Systems
Anna Lisa Ferrara, Anna Cinzia Squicciarini, Cong Liao, Truc L. Nguyen
DBSec1
2017 Preventing Unauthorized Data Flows
Emre Uzun, Gennaro Parlato, Vijayalakshmi Atluri, Anna Lisa Ferrara, Jaideep Vaidya, Shamik Sural, David Lorenzi
DBSec4
2015 Policy Privacy in Cryptographic Access Control
abstract
Cryptographic access control offers selective access to encrypted data via a combination of key management and functionality-rich cryptographic schemes, such as attribute-based encryption. Using this approach, publicly available meta-data may inadvertently leak information on the access policy that is enforced by cryptography, which renders cryptographic access control unusable in settings where this information is highly sensitive. We begin to address this problem by presenting rigorous definitions for policy privacy in cryptographic access control. For concreteness we set our results in the model of Role-Based Access Control (RBAC), where we identify and formalize several different flavors of privacy, however, our framework should serve as inspiration for other models of access control. Based on our insights we propose a new system which significantly improves on the privacy properties of state-of-the-art constructions. Our design is based on a novel type of privacy-preserving attribute-based encryption, which we introduce and show how to instantiate. We present our results in the context of a cryptographic RBAC system by Ferrara et al. (CSF'13), which uses cryptography to control read access to files, while write access is still delegated to trusted monitors. We give an extension of the construction that permits cryptographic control over write access. Our construction assumes that key management uses out-of-band channels between the policy enforcer and the users but eliminates completely the need for monitoring read/write access to the data.
Anna Lisa Ferrara, Georg Fuchsbauer, Bogdan Warinschi
CSF1
2014 Vac - Verifier of Administrative Role-Based Access Control Policies
Anna Lisa Ferrara, P. Madhusudan, Truc L. Nguyen, Gennaro Parlato
CAV1
2014 Security analysis for temporal role based access control
abstract
Providing restrictive and secure access to resources is a challenging and socially important problem. Among the many formal security models, Role Based Access Control (RBAC) has become the norm in many of today's organizations for enforcing security. For every model, it is necessary to analyze and prove that the corresponding system is secure. Such analysis helps understand the implications of security policies and helps organizations gain confidence on the control they have on resources while providing access, and devise and maintain policies. In this paper, we consider security analysis for the Temporal RBAC (TRBAC), one of the extensions of RBAC. The TRBAC considered in this paper allows temporal restrictions on roles themselves, user-permission assignments (UA), permission-role assignments (PA), as well as role hierarchies (RH). Towards this end, we first propose a suitable administrative model that governs changes to temporal policies. Then we propose our security analysis strategy, that essentially decomposes the temporal security analysis problem into smaller and more manageable RBAC security analysis sub-problems for which the existing RBAC security analysis tools can be employed. We then evaluate them from a practical perspective by evaluating their performance using simulated data sets.
Emre Uzun, Vijayalakshmi Atluri, Jaideep Vaidya, Shamik Sural, Anna Lisa Ferrara, Gennaro Parlato, P. Madhusudan
J. Comput. Secur.5
2013 Cryptographically Enforced RBAC
abstract
Cryptographic access control promises to offer easily distributed trust and broader applicability, while reducing reliance on low-level online monitors. Traditional implementations of cryptographic access control rely on simple cryptographic primitives whereas recent endeavors employ primitives with richer functionality and security guarantees. Worryingly, few of the existing cryptographic access-control schemes come with precise guarantees, the gap between the policy specification and the implementation being analyzed only informally, if at all. In this paper we begin addressing this shortcoming. Unlike prior work that targeted ad-hoc policy specification, we look at the well-established Role-Based Access Control (RBAC) model, as used in a typical file system. In short, we provide a precise syntax for a computational version of RBAC, offer rigorous definitions for cryptographic policy enforcement of a large class of RBAC security policies, and demonstrate that an implementation based on attribute-based encryption meets our security notions. We view our main contribution as being at the conceptual level. Although we work with RBAC for concreteness, our general methodology could guide future research for uses of cryptography in other access-control models.
Anna Lisa Ferrara, Georg Fuchsbauer, Bogdan Warinschi
CSF1
2013 Policy Analysis for Self-administrated Role-Based Access Control
Anna Lisa Ferrara, P. Madhusudan, Gennaro Parlato
TACAS1
2013 A note on time-bound hierarchical key assignment schemes
Giuseppe Ateniese, Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
Inf. Process. Lett.3
2012 Security Analysis of Role-Based Access Control through Program Verification
abstract
We propose a novel scheme for proving administrative role-based access control (ARBAC) policies correct with respect to security properties using the powerful abstraction-based tools available for program verification. Our scheme uses a combination of abstraction and reduction to program verification to perform security analysis. We convert ARBAC policies to imperative programs that simulate the policy abstractly, and then utilize further abstract-interpretation techniques from program analysis to analyze the programs in order to prove the policies secure. We argue that the aggressive set-abstractions and numerical-abstractions we use are natural and appropriate in the access control setting. We implement our scheme using a tool called VAC that translates ARBAC policies to imperative programs followed by an interval-based static analysis of the program, and show that we can effectively prove access control policies correct. The salient feature of our approach are the abstraction schemes we develop and the reduction of role-based access control security (which has nothing to do with programs) to program verification problems.
Anna Lisa Ferrara, P. Madhusudan, Gennaro Parlato
CSF1
2012 Analyzing temporal role based access control models
abstract
Today, Role Based Access Control (RBAC) is the de facto model used for advanced access control, and is widely deployed in diverse enterprises of all sizes. Several extensions to the authorization as well as the administrative models for RBAC have been adopted in recent years. In this paper, we consider the temporal extension of RBAC (TRBAC), and develop safety analysis techniques for it. Safety analysis is essential for understanding the implications of security policies both at the stage of specification and modification. Towards this end, in this paper, we first define an administrative model for TRBAC. Our strategy for performing safety analysis is to appropriately decompose the TRBAC analysis problem into multiple subproblems similar to RBAC. Along with making the analysis simpler, this enables us to leverage and adapt existing analysis techniques developed for traditional RBAC. We have adapted and experimented with employing two state of the art analysis approaches developed for RBAC as well as tools developed for software testing. Our results show that our approach is both feasible and flexible.
Emre Uzun, Vijayalakshmi Atluri, Shamik Sural, Jaideep Vaidya, Gennaro Parlato, Anna Lisa Ferrara, P. Madhusudan
SACMAT6
2012 Provably-Secure Time-Bound Hierarchical Key Assignment Schemes
Giuseppe Ateniese, Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
J. Cryptol.3
2011 Efficient provably-secure hierarchical key assignment schemes
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
Theor. Comput. Sci.2
2010 Variations on a theme by Akl and Taylor: Security and tradeoffs
Paolo D'Arco, Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
Theor. Comput. Sci.3
2009 Practical Short Signature Batch Verification
Anna Lisa Ferrara, Matthew Green 0001, Susan Hohenberger, Michael Østergaard Pedersen
CT-RSA1
2009 Security and Tradeoffs of the Akl-Taylor Scheme and Its Variants
Paolo D'Arco, Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
MFCS3
2008 An attack on a payment scheme
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
Inf. Sci.2
2008 New constructions for provably-secure time-bound hierarchical key assignment schemes
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
Theor. Comput. Sci.2
2007 Efficient Provably-Secure Hierarchical Key Assignment Schemes
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
MFCS2
2007 New constructions for provably-secure time-bound hierarchical key assignment schemes
abstract
A time-bound hierarchical key assignment scheme is a method to assign time-dependent encryption keys to a set of classes in a partially ordered hierarchy, in such a way that each class can derive the keys of all classes lower down in the hierarchy, according to temporal constraints.
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
SACMAT2
2006 Provably-secure time-bound hierarchical key assignment schemes
abstract
A time-bound hierarchical key assignment scheme is a method to assign time-dependent encryption keys to a set of classes in a partially ordered hierarchy, in such a way that the key of a higher class can be used to derive the keys of all classes lower down in the hierarchy, according to temporal constraints.In this paper we design and analyze time-bound hierarchical key assignment schemes which are provably-secure and efficient. We first consider the unconditionally secure setting and we show a tight lower bound on the size of the private information distributed to each class. Then, we consider the computationally secure setting and obtain several results: We first prove that a recently proposed scheme is insecure against collusion attacks. Hence, motivated by the need for provably-secure schemes, we propose two different constructions for time-bound hierarchical key assignment schemes. The first one is based on symmetric encryption schemes, whereas, the second one makes use of bilinear maps. These appear to be the first constructions of time-bound hierarchical key assignment schemes which are simultaneously practical and provably-secure.
Giuseppe Ateniese, Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
CCS3
2006 Unconditionally secure key assignment schemes
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
Discret. Appl. Math.2
2006 Enforcing the security of a time-bound hierarchical key assignment scheme
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
Inf. Sci.2
2005 Ideal contrast visual cryptography schemes with reversing
Stelvio Cimato, Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
Inf. Process. Lett.3
2004 A simple algorithm for the constrained sequence problems
Francis Y. L. Chin, Alfredo De Santis, Anna Lisa Ferrara, Ngai Lam Ho, S. K. Kim
Inf. Process. Lett.3
2004 Cryptographic key assignment schemes for any access control policy
Alfredo De Santis, Anna Lisa Ferrara, Barbara Masucci
Inf. Process. Lett.2