Hussein Joumaa

dblp:77/2900 · DBLP profile ↗
← Back
5ranked-venue papers
4as first author
3since 2021 · last 2025
0009-0009-5684-1689ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 2 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-author
YearPublicationVenuePosition
2025 Coordinated Enforcement of Obligations in Distributed Usage Control Systems [Work In Progress Paper]
abstract
Access and usage control have evolved to include obligations, which are mandatory actions that must be fulfilled as part of authorization decisions. However, standards such as Abbreviated Language For Authorization (ALFA) and eXtensible Access Control Markup Language (XACML) specify that Policy Enforcement Points (PEPs) are responsible for enforcing obligations but leave execution aspects unspecified. They assume that obligations will be fulfilled without addressing how enforcement should be carried out. This paper introduces an enforcement framework based on structured enforcement messages to address these challenges. It defines two types of messages to coordinate enforcement execution across PEPs: Declaration and Execution Records. These records provide information about PEP capabilities, action dependencies, and fallback strategies for synchronized enforcement. Secondly, we propose a hierarchical policy model to separate concerns between the functionality of policy logic and enforcement. The model is composed of Governance, Authorization, and Enforcement Policies. Constraints flow across these three levels, allowing policy selection and execution to adapt to the authorization context and enforcement. Finally, we illustrate a high-level architecture that integrates the three policy layers with distributed enforcement logic across multiple PEPs.
Hussein Joumaa, Ali Hariri, Theodosis Dimitrakos, Bruno Crispo
SACMAT1
2024 Obligation Management Framework for Usage Control
abstract
Obligations were introduced in access and usage control as a mechanism to specify mandatory actions to be fulfilled as part of authorization. In this paper, we address challenges related to obligation management in access and usage control, focusing on the Abbreviated Language For Authorization (ALFA) and eXtensible Access Control Markup Language (XACML) standards. Firstly, we provide a comprehensive analysis of Combining Algorithms (CAs) to determine their influence on the selection and ordering of obligations and identify nondeterminism. We then propose solutions to eliminate such nondeterminism enabling policy authors to explicitly specify the intended behavior. Secondly, we discuss the recurrence of obligations in usage control that occurs due to policy re-evaluations, highlighting the need to execute some obligations only once. We address this problem by introducing a parameter that enables policy authors to explicitly specify whether they intend an obligation to recur or not. Thirdly, we highlight an ambiguity in obligation applicability to lifecycle phases (e.g., ongoing) in usage control, arising from the lack of explicit associations between obligations and phases in particular cases. To address this issue, we introduce a parameter that explicitly specifies the scope of an obligation, allowing policy authors to restrict obligations to a single phase or apply them to the entire authorization. Finally, we extend the functionality of the Obligation Manager (OM) component to combine all three solutions, providing deterministic obligation management.
Hussein Joumaa, Ali Hariri, Ana Petrovska, Oleksii Osliak, Theodosis Dimitrakos, Bruno Crispo
SACMAT1
2024 Static and Dynamic Analysis of a Usage Control System
abstract
The ability to exchange data while maintaining sovereignty is fundamental to emerging decentralized data-driven ecosystems. Data sovereignty refers to the entity's capability to be self-determined concerning data usage. As such, a data usage control system (UCON) is critical for sovereignty. UCON, a generalization of attribute-based access control, enforces continuous authorization, allowing attribute mutability after access is granted. In theory, UCON comprises a policy language to express constraints and obligations of data usage, and a technology to evaluate and enforce them. In practice, realizing the above is challenging and poses trust concerns. Partly, this is due to the complexity of UCON (continuous authorization, obligations) and the advanced usage constraints (stemming from, e.g., regulations or business contracts) combined with the decentralized nature of data ecosystems that allow different actors (e.g., data provider, security engineers) to author policies, and operate UCON. To that end, we propose to aid actors with automated policy analysis and verification methods. We present a new policy analysis method based on the combination of symbolic execution for policy evaluation and SMT solving to compute concrete scenarios answering queries on the policies. Our approach supports symbolic queries, where attribute values may be concrete values, a range of values, or symbolic variables. We also propose a monitoring approach using RTLola tool to verify the correctness of UCON's behavior in terms of decisions, obligations, and user-specified properties. To monitor obligations, we define their essential parameters and show how to monitor their fulfillment based on the configuration. We also present eight templates that allow users to generate the most important properties for monitoring UCON.
Ulrich Schöpp, Fathiyeh Faghih, Subhajit Bandopadhyay, Hussein Joumaa, Amjad Ibrahim, Chuangjie Xu, Xin Ye 0013, Theodosis Dimitrakos
SACMAT4
2005 An ICA based algorithm for video watermarking
abstract
In this paper, a new video watermarking scheme is proposed. We adapt two watermarking algorithms, originally proposed for still image watermarking, to embed data in a set of statistically independent sources, extracted from a video sequence. We show the interest of applying such an approach to video watermarking. The proposed scheme offers good robustness against MPEG compression attack, as well as an important capacity level. We consider, in this paper, data hiding in digital TV channels where data are compressed using MPEG-2. The main contribution of our study is to compare two different watermarking approaches applied to error prediction frames transformed by ICA.
Hussein Joumaa, Franck Davoine
ICASSP (2)1
2005 Performance of an ICA video watermarking scheme using informed techniques
abstract
Independent component analysis (ICA) techniques have been recently used in different watermarking schemes. However, performance of an ICA video watermarking scheme in comparison with those using classical domains, such as the discrete Fourier transform (DCT) domain, is still not clear. In this paper, we attempt to fill this gap. Therefore, we propose a video watermarking scheme, using an informed trellis, applied in two transformed domains obtained by using respectively the DCT transform and an ICA coding technique. We show that, for both domains, the scheme offers a good robustness against MPEG-2 compression, as well as an important capacity level. We consider in this paper data hiding in digital TV channels where data are compressed using MPEG-2.
Hussein Joumaa, Franck Davoine
ICIP (1)1