Andreas Schaad

dblp:79/4385 · DBLP profile ↗
← Back
35ranked-venue papers
14as first author
2since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 29 · 14 first-author · 2 since 2021Software engineering, systems software and programming languages · 2Systems, architecture and hardware · 1Computer networks · 1Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2025 You Still have to Study On the Security of LLM Generated Code
Andreas Schaad, Stefan Götz 0007, Dominik Binder
SEC (2)1
2021 FEX - A Feature Extractor for Real-Time IDS
Andreas Schaad, Dominik Binder
ISC1
2020 ML-Supported Identification and Prioritization of Threats in the OVVL Threat Modelling Tool
Andreas Schaad, Dominik Binder
DBSec1
2019 CloudProtect - A Cloud-based Software Protection Service
abstract
Protecting software from illegal access, intentional modification or reverse engineering is an inherently difficult practical problem involving code obfuscation techniques and real-time cryptographic protection of code. In traditional systems a secure element (the "dongle") is used to protect software. However, this approach suffers from several technical and economical drawbacks such as the dongle being lost or broken.
Andreas Schaad, Björn Grohmann, Oliver Winzenried
SACMAT1
2017 Short Paper: Industrial Feasibility of Private Information Retrieval
abstract
A popular security problem in database management is how to guarantee to a querying party that the database owner will not learn anything about the data that is retrieved -a problem known as Private Information Retrieval (PIR).While a variety of PIR schemes are known, they are rarely considered for practical use cases yet.We investigate the feasibility of PIR in the telecommunications world to open up data of carriers to external parties.To this end, we first provide a comparative survey of the current PIR state of the art (including ORAM schemes as a generalized concept) as well as implementation and analysis of two PIR schemes for the considered use case.While an overall conclusion is that PIR techniques are not too far away from practical use in specific cases, we see ORAM as a more suitable candidate for further R&D investment.
Angela Jäschke, Björn Grohmann, Frederik Armknecht, Andreas Schaad
SECRYPT4
2015 Initial Encryption of large Searchable Data Sets using Hadoop
abstract
With the introduction and the widely use of external hosted infrastructures, secure storage of sensitive data becomes more and more important. There are systems available to store and query encrypted data in a database, but not all applications may start with empty tables rather than having sets of legacy data. Hence, there is a need to transform existing plaintext databases to encrypted form. Usually existing enterprise databases may contain terabytes of data. A single machine would require many months for the initial encryption of a large data set. We propose encrypting data in parallel using a Hadoop cluster which is a simple five step process including the Hadoop set up, target preparation, source data import, encrypting the data, and finally exporting it to the target. We evaluated our solution on real world data and report on performance and data consumption. The results show that encrypting data in parallel can be done in a very scalable manner. Using a parallelized encryption cluster compared to a single server machine reduces the encryption time from months down to days or even hours.
Mathias Kohler, Andreas Schaad
SACMAT3
2014 Optimized and controlled provisioning of encrypted outsourced data
abstract
Recent advances in encrypted outsourced databases support the direct processing of queries on encrypted data. Depend- ing on functionality (i.e. operators) required in the queries the database has to use different encryption schemes with different security properties. Next to these functional re-quirements a security administrator may have to address security policies that may equally determine the used en-cryption schemes. We present an algorithm and tool set that determines an optimal balance between security and functionality as well as helps to identify and resolve possible conflicts. We test our solution on a database benchmark and business-driven security policies.
Andreas Schaad, Anis Bkakria, Florian Kerschbaum, Frédéric Cuppens, Nora Cuppens, David Gross-Amblard
SACMAT1
2013 Adjustably encrypted in-memory column-store
abstract
Recent databases are implemented as in-memory column-stores. Adjustable encryption offers a solution to encrypted database processing in the cloud. We show that the two technologies play well together by providing an analysis and prototype results that demonstrate the impact of mechanisms at the database side (dictionaries and their compression) and cryptographic mechanisms at the adjustable encryption side (order-preserving, homomorphic, deterministic and probabilistic encryption).
Florian Kerschbaum, Patrick Grofig, Isabelle Hang, Martin Härterich, Mathias Kohler, Andreas Schaad, Axel Schröpfer, Walter Tighzert
CCS6
2013 Optimal Re-encryption Strategy for Joins in Encrypted Databases
Florian Kerschbaum, Martin Härterich, Patrick Grofig, Mathias Kohler, Andreas Schaad, Axel Schröpfer, Walter Tighzert
DBSec5
2013 Secure benchmarking in the cloud
abstract
Benchmarking is the comparison of one company's key performance indicators (KPI) to the statistics of the same KPIs of its peer group. A KPI is a statistical quantity measuring the performance of a business process. Privacy by means of controlling access to data is of the utmost importance in benchmarking. Companies are reluctant to share their business performance data due to the risk of losing a competitive advantage or being embarrassed. We present a cryptographic protocol for securely computing benchmarks between multiple parties and describe the technical aspects of a proof of concept implementation of SAP's research prototype Global Benchmarking Service (GBS) on Microsoft's cloud technology Windows Azure.
Axel Schröpfer, Andreas Schaad, Florian Kerschbaum, Heiko Boehm, Joerg Jooss
SACMAT2
2012 Automating architectural security analysis
abstract
In earlier work [1] we had looked at implementing the Microsoft STRIDE methodology in the context of evaluating security properties of FMC/TAM architectural diagrams. However, a major drawback of this approach is that it requires significant manual work to assess all reported potential threats, as well as identify concrete follow-ups. Equally, it is not possible to analyse an architecture from the perspective of the primary assets that require protection. This led us to two questions:
Andreas Schaad, Alexandr Garaga
SACMAT1
2011 Visualizing security in business processes
abstract
Defining constraints at the business process level is an often demanded feature. Our approach guides a business user in the analysis of threats to resources used in a business process, and provides the means to specify appropriate controls on the identified threats. These controls are of a highly visual nature and address both safety as well as security concerns.
Ganna Monakova, Andreas Schaad
SACMAT2
2009 Towards Secure Content Based Dissemination of XML Documents
abstract
Collaborating on complex XML data structures is a nontrivial task in domains such as the public sector,healthcare or engineering. Specifically, providing scalable XML content dissemination services in a selective and secure fashion is a challenging task. This paper describes a publish/subscribe middleware infrastructure to achieve a content-based dissemination of XML documents. Our approach relies on the dissemination of XML documents based on their semantics, as described by concepts that form an interoperable description of documents. This infrastructure leverages our earlier scheme for protecting the integrity and confidentiality of XML content during dissemination.
Mohammad Ashiqur Rahaman, Henrik Plate, Yves Roudier, Andreas Schaad
IAS4
2009 A Secure Comparison Technique for Tree Structured Data
abstract
Comparing different versions of large tree structured data is a CPU and memory intensive task. State of the art techniques require the complete XML trees and their internal representations to be loaded into memory before any comparison may start. Furthermore, comparing sanitized XML trees is not addressed by these techniques. We propose a comparison technique for sanitized XML documents which ultimately results into a minimum cost edit script transforming the initial tree into the target tree. This method uses encrypted integer labels to encode the original XML structure and content, making the encrypted XML readable only by a legitimate party. Encoded tree nodes can be compared by a third party with a limited intermediate representation.
Mohammad Ashiqur Rahaman, Yves Roudier, Andreas Schaad
ICIW3
2009 Practical privacy-preserving protocols for criminal investigations
abstract
Social Network Analysis (SNA) is now a commonly used tool in criminal investigations, but evidence gathering and analysis is often restricted by data privacy laws. We consider the case where multiple investigators want to collaborate but do not yet have sufficient evidence that justifies a plaintext data exchange. We propose a practical solution that allows an investigator to expand his current view without actually exchanging sensitive private information. The investigator gets a partially anonymized view of the entire social network, while preserving his known view.
Florian Kerschbaum, Andreas Schaad, Debmalya Biswas
ISI2
2009 Ontology-Based Secure XML Content Distribution
Mohammad Ashiqur Rahaman, Yves Roudier, Philip Miseldine, Andreas Schaad
SEC4
2009 Model-driven business process security requirement specification
Christian Wolter, Michael Menzel 0001, Andreas Schaad, Philip Miseldine, Christoph Meinel
J. Syst. Archit.3
2008 Avoiding Policy-based Deadlocks in Business Processes
abstract
In the field of business process management, deadlocks describe a situation where a workflow execution is blocked and cannot be completed. We speak of policy-based deadlocks if such a situation is caused by unsatisfiable resource requirements due to security constraints specified as part of the business process. In this paper we propose a method to avoid policy-based deadlocks by analyzing a workflow's security constraints, determine the minimal required number of users, and provide an optimal user-activity assignment for a deadlock-free workflow execution. We will finally validate our proposed approach by applying it to a real-world scenario.
Mathias Kohler, Andreas Schaad
ARES2
2008 ProActive Access Control for Business Process-Driven Environments
abstract
Users expect that systems react instantly. This is specifically the case for user-centric workflows in business process-driven environments. In today's enterprise systems most actions executed by a user have to be checked against the system's access control policy and require a call to the access control component. Hence, improving the performance of access control decisions will improve the overall performance experienced by the end user significantly. In this paper we propose a caching strategy which pre-computes caching entries by exploiting the fact that the executions of business processes are based on the execution of actions in a predefined order. We propose an accompanying architecture and present the results of our conducted benchmark.
Mathias Kohler, Andreas Schaad
ACSAC2
2008 Distributed Access Control For XML Document Centric Collaborations
abstract
This paper introduces a distributed and fine grained access control mechanism based on encryption for XML document centric collaborative applications. This mechanism also makes it possible to simultaneously protect the confidentiality of a document and to verify its authenticity and integrity, as well to trace its updates. The enforcement of access control is distributed to participants and does not rely on a central authority. Novel aspects of the proposed framework include the adoption of a decentralized key management scheme to support the client-based enforcement of the access control policy. This scheme is driven by the expression of access patterns of interest of the participants over document parts to determine the keys required. A lazy rekeying protocol is also defined to accommodate the delegation of access control decisions that in particular reduces rekeying latency when faced with the addition and removal of participants.
Mohammad Ashiqur Rahaman, Yves Roudier, Andreas Schaad
EDOC3
2008 Task-based entailment constraints for basic workflow patterns
abstract
Access Control decisions are based on the authorisation policies defined for a system as well as observed context and behaviour when evaluating these constraints at runtime. Workflow management systems have been recognised as a primary source for defining authorisation policies at workflow designtime, as well as generating context at runtime.
Christian Wolter, Andreas Schaad, Christoph Meinel
SACMAT2
2007 Modeling of Task-Based Authorization Constraints in BPMN
Christian Wolter, Andreas Schaad
BPM2
2007 SOAP-based Secure Conversation and Collaboration
abstract
Web services in different trust boundaries interact with each other via SOAP messages to realize functionality in a collaborative environment. Exchanging SOAP messages for remote service invocation has gained wide acceptance among web service developers. Several web service security standards are widely deployed aiming at securing exchanges of a single SOAP message and a conversation of SOAP messages among partners in a collaborative environment. Concerns have been raised about the possibility of XML rewriting attacks within this context and their early detection. In this paper, we demonstrate such possible attacks with respect to WS* policy based scenarios to set a security context and to use a security context for conversations of SOAP messages. We show how our proposed SOAP Account [21] solution could be applied for early detection of XML rewriting attacks, specifically regarding secure SOAP-based conversations. A simulation-based performance analysis and comparison of our SOAP Account approach vs. a WS* policy based approach complements our observations.
Mohammad Ashiqur Rahaman, Andreas Schaad
ICWS2
2007 Classification Model for Access Control Constraints
abstract
Whether access is given to a protected entity is decided upon evaluation of access control constraints. Though some initial approaches to classify access control constraints can be identified in the current literature, they must be considered as too broad with respect to today's multi-layered system landscapes. In this paper we present a classification model for authorization constraint types extracted from recent publications. We identify common restriction characteristics and classify the constraint types depending on their information sources necessary for constraint evaluation. We identified the following authorization classes: authentication, ontology, environment, and activity. We further propose a system architecture supporting these classes. We map our model architecture onto the Windows 2003 Authorization Manager, identify the components equal to our proposed architecture and emphasize which authorization classes are supported. We therefore show the applicability of our model to analyze existing authorization systems and determine the supported constraints.
Mathias Kohler, Christian Liesegang, Andreas Schaad
IPCCC3
2006 From Business Process Choreography to Authorization Policies
Florian Kerschbaum, Andreas Schaad
DBSec3
2006 Security in enterprise resource planning systems and service-oriented architectures
abstract
No abstract available.
Andreas Schaad
SACMAT1
2006 A model-checking approach to analysing organisational controls in a loan origination process
abstract
Demonstrating the safety of a system (ie. avoiding the undesired propagation of access rights or indirect access through some other granted resource) is one of the goals of access control research, e.g. [1-4]. However, the flexibility required from enterprise resource management (ERP) systems may require the implementation of seemingly contradictory requirements (e.g. tight access control but at the same time support for discretionary delegation of workflow tasks and rights).To aid in the analysis of safety problems in workflow-based ERP system, this paper presents a model-checking based approach for automated analysis of delegation and revocation functionalities. This is done in the context of a real-world banking workflow requiring static and dynamic separation of duty properties.We derived information about the workflow from BPEL specifications and ERP business object repositories. This was captured in a SMV specification together with a definition of possible delegation and revocation scenarios. The required separation properties were translated into a set of LTL-based constraints. In particular, we analyse the interaction between delegation and revocation activities in the context of dynamic separation of duty policies.
Andreas Schaad, Volkmar Lotz, Karsten Sohr
SACMAT1
2005 Revocation of Obligation and Authorisation Policy Objects
Andreas Schaad
DBSec1
2004 An Extended Analysis of Delegating Obligations
abstract
In [1] we have presented our initial investigations into the delegation of obligations and the concept of review as one kind of organisational principle to control such delegation activities. However, this initial approach was too simplistic and failed to explain how a principal may be related to an obligation; how obligations relate to roles; and how the delegation of specific and general obligations may be controlled through the concepts of review and supervision. As a result, we presented a more detailed and refined analysis of organisational controls in the context of a formal framework [2]. This paper summarises some of our investigations.
Andreas Schaad
DBSec1
2003 An administration concept for the enterprise role-based access control model
abstract
Using an underlying role-based model for the administration of roles has proved itself to be a successful approach. This paper sets out to describe the enterprise role-based access control model (ERBAC) in the context of SAM Jupiter, a commercial enterprise security management software.We provide an overview of the role-based conceptual model underlying SAM Jupiter. Having established this basis, we describe how the model is used to facilitate a role-based administration approach. In particular, we discuss our notion of 'scopes', which describe the objects over which an administrator has authority. The second part provides a case study based on our real-world experiences in the implementation of role-based administrative infrastructures. Finally, a critical evaluation and comparison with current approaches to administrative role-based access control is provided.
Axel Kern, Andreas Schaad, Jonathan D. Moffett
SACMAT2
2002 A Framework for Organisational Control Principles
abstract
Organisational control principles, such as those expressed in the separation of duties, supervision, review and delegation, support the main business goals and activities of an organisation. Some of these principles have previously been described and analysed within the context of role- and policy-based distributed systems, but little has been done with respect to the more general context they are placed in and the analysis of relationships between them. This paper presents a framework in which organisational control principles can be formally expressed and analysed using the Alloy specification language and its constraint analysis tools.
Andreas Schaad, Jonathan D. Moffett
ACSAC1
2002 Observations on the role life-cycle in the context of enterprise security management
abstract
Roles are a powerful and policy neutral concept for facilitating distributed systems management and enforcing access control. Models which are now subject to becoming a standard have been proposed and much work on extensions to these models has been done over the last years as documented in the recent RBAC/SACMAT workshops. When looking at these extensions we can often observe that they concentrate on a particular stage in the life of a role. We investigate how these extensions fit into a more general theoretical framework in order to give practitioners a starting point from which to develop role-based systems. We believe that the life-cycle of a role could be seen as the basis for such a framework and we provide an initial discussion on such a role life-cycle, based on our experiences and observations in enterprise security management. We propose a life-cycle model that is based on an iterative-incremental process similar to those found in the area of software development.
Axel Kern, Martin Kuhlmann, Andreas Schaad, Jonathan D. Moffett
SACMAT3
2002 A lightweight approach to specification and analysis of role-based access control extensions
abstract
Role-based access control is a powerful and policy-neutral concept for enforcing access control. Many extensions have been proposed, the most significant of which are the decentralised administration of role-based systems and the enforcement of constraints. However, the simultaneous integration of these extensions can cause conflicts in a later system implementation. We demonstrate how we use the Alloy language for the specification of a conflict-free role-based system. This specification provides us at the same time with a suitable basis for further analysis by the Alloy constraint analyser.
Andreas Schaad, Jonathan D. Moffett
SACMAT1
2001 Detecting Conflicts in a Role-Based Delegation Model
abstract
The RBAC96 access control model has been the basis for extensive work on role-based constraint specification and role-based delegation. However these practical extensions can also lead to conflicts at compile and run-time. We demonstrate, following a role-based, declarative approach, how conflicts between specified separation of duty constraints and delegation activities can be detected. This approach also demonstrates the general suitability of Prolog as an executable specification language for the simulation and analysis of role-based systems. Using an extended definition of a role we show how at least one of the conflicts can be resolved and discuss the impacts of this extension on the specified constraints.
Andreas Schaad
ACSAC1
2001 The role-based access control system of a European bank: a case study and discussion
abstract
Research in the area of role-based access control has made fast progress over the last few years. However, little has been done to identify and describe existing role-based access control systems within large organisations. This paper describes the access control system of a major European Bank. An overview of the systems structure, its administration and existing control principles constraining the administration is given. In addition, we provide an answer to a key question - the ratio of the number of roles to the system user population - which was raised in the recent RBAC2000 Workshop. Having described certain weaknesses of the Banks system, the case study is extended to a comparison between the system and the RBAC96 models. In particular the issues of inheritance and grouping are addressed.
Andreas Schaad, Jonathan D. Moffett, Jeremy L. Jacob
SACMAT1