EDBT 2026 Demo / reviewers in the wild / expert
David W. Chadwick
dblp:c/DavidWChadwick
· DBLP profile ↗
50ranked-venue papers
21as first author
4since 2021 · last 2025
0000-0003-3145-055XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 24 · 11 first-author · 3 since 2021Systems, architecture and hardware · 9 · 6 first-authorComputer networks · 4 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 4Applied, interdisciplinary, general and emerging computing · 4 · 1 first-authorArtificial intelligence and machine learning · 2Human-computer interaction and ubiquitous computing · 2Theory of computation · 2 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Enhancing the ACME protocol to automate the management of all X.509 web certificates (Extended version)
David Cordova Morales, Ahmad Samer Wazan, David W. Chadwick, Romain Laborde, April Rains Maramara |
Comput. Commun. | 3 |
| 2023 | Enhancing the ACME Protocol to Automate the Management of All X.509 Web Certificates
David Cordova Morales, Ahmad Samer Wazan, David W. Chadwick, Romain Laborde, April Rains Maramara, Kalil Cabral |
SEC | 3 |
| 2022 | On the Validation of Web X.509 Certificates by TLS Interception ProductsabstractThe Transport Layer Security (TLS) protocol aims to provide confidentiality and integrity of data. It is based on X.509 Certificates. Our previous research showed that popular Web Browsers exhibit non-standardized behaviour with respect to the certificate validation process[1]. This article extends that work by examining their handling of OCSP Stapling. We also examine several popular HTTPS interception products, including proxies and anti-virus tools, regarding their certificate validation processes. We analyse and compare their behaviour to that described in the relative standards. Ahmad Samer Wazan, Romain Laborde, David W. Chadwick, Rémi Venant, Benzekri Abdelmalek, Eddie Billoir, Omar Alfandi |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2021 | RootAsRole: Towards a Secure Alternative to sudo/su Commands for Home Users and SME Administrators
Ahmad Samer Wazan, David W. Chadwick, Rémi Venant, Romain Laborde, Benzekri Abdelmalek |
SEC | 2 |
| 2020 | Know Your Customer: Opening a new bank account online using UAAFabstractUniversal Authentication and Authorization Framework is a user-centric, privacy by design and decentralized system that allows anyone to easily benefit from a reliable digital identity made of multi-purpose and multi-origin attributes. In this article, we present the implementation of this framework in the context of online banking. We demonstrate how it can facilitate enforcing Know Your Customer when opening a new bank account online by allowing users to combine verifiable identity attributes issued by different organizations. Romain Laborde, Arnaud Oglaza, Ahmad Samer Wazan, François Barrère, Benzekri Abdelmalek, David W. Chadwick, Rémi Venant |
CCNC | 6 |
| 2020 | A User-Centric Identity Management Framework based on the W3C Verifiable Credentials and the FIDO Universal Authentication FrameworkabstractWe present a user-centric and decentralized digital identity system that allows anyone to easily benefit from an enriched digital identity made of multi-purpose and multi-origin attributes. It increases usability by the elimination of user passwords. It also makes this digital identity highly trustworthy both for the user (in terms of privacy and sovereignty) and the service provider who requires highly certified information about the user being enrolled to and/or authenticated on its services. We built our system based on the Universal Authentication Framework specified by the FIDO Alliance and the data model proposed by the W3C Verifiable Credentials WG. The whole system has been implemented in a banking scenario. Romain Laborde, Arnaud Oglaza, Ahmad Samer Wazan, François Barrère, Benzekri Abdelmalek, David W. Chadwick, Rémi Venant |
CCNC | 6 |
| 2020 | A cloud-edge based data security architecture for sharing and analysing cyber threat informationabstractCyber-attacks affect every aspect of our lives. These attacks have serious consequences, not only for cyber-security, but also for safety, as the cyber and physical worlds are increasingly linked. Providing effective cyber-security requires cooperation and collaboration among all the entities involved. Increasing the amount of cyber threat information (CTI) available for analysis allows better prediction, prevention and mitigation of cyber-attacks. However, organizations are deterred from sharing their CTI over concerns that sensitive and confidential information may be revealed to others. We address this concern by providing a flexible framework that allows the confidential sharing of CTI for analysis between collaborators. We propose a five-level trust model for a cloud-edge based data sharing infrastructure. The data owner can choose an appropriate trust level and CTI data sanitization approach, ranging from plain text, through anonymization/pseudonymization to homomorphic encryption, in order to manipulate the CTI data prior to sharing it for analysis. Furthermore, this sanitization can be performed by either an edge device or by the cloud service provider, depending upon the level of trust the organization has in the latter. We describe our trust model, our cloud-edge infrastructure, and its deployment model, which are designed to satisfy the broadest range of requirements for confidential CTI data sharing. Finally we briefly describe our implementation and the testing that has been carried out so far by four pilot projects that are validating our infrastructure. David W. Chadwick, Wenjun Fan, Gianpiero Costantino, Rogério de Lemos, Francesco Di Cerbo, Ian Herwono, Mirko Manea, Paolo Mori, Ali Sajjad, Xiao-Si Wang |
Future Gener. Comput. Syst. | 1 |
| 2017 | TLS Connection Validation by Web Browsers: Why do Web Browsers Still Not Agree?abstractThe TLS protocol is the primary technology used for securing web transactions. It is based on X.509 certificates that are used for binding the identity of web servers' owners to their public keys. Web browsers perform the validation of X.509 certificates on behalf of Web users. Our previous research in 2009 showed that the validation process of Web browsers is inconsistent and flawed. We showed how this situation might have a negative impact on Web users. From 2009 until now, many new X.509 related standards have been created or updated. In this paper, we performed an increased set of experiments over our 2009 study in order to highlight the improvements and/or regressions in Web browsers' behaviours. Ahmad Samer Wazan, Romain Laborde, David W. Chadwick, François Barrère, Benzekri Abdelmalek |
COMPSAC (1) | 3 |
| 2017 | Integrating an AAA-based federation mechanism for OpenStack - The CLASSe viewabstractSummary Identity federations enable users, service providers, and identity providers from different organizations to exchange authentication and authorization information in a secure way. In this paper, we present a novel identity federation architecture for cloud services based on the integration of a cloud identity management service with an authentication, authorization, and accounting infrastructure. Specifically, we analyse how this type of authentication, authorization, and accounting–based federation can be smoothly integrated into OpenStack, the leading open source cloud software solution, using the Internet Engineering Task Force (IETF) Application Bridging for Federated Access Beyond web specification for authentication and authorization. We provide details of the implementation undertaken in GÉANT's CLASSe project and show its validation in a real testbed. Alejandro Pérez-Méndez, Gabriel López Millán, Rafael Marín López, David W. Chadwick, Ioram Schechtman Sette |
Concurr. Comput. Pract. Exp. | 4 |
| 2017 | Trust Management for Public Key Infrastructures: Implementing the X.509 Trust BrokerabstractA Public Key Infrastructure (PKI) is considered one of the most important techniques used to propagate trust in authentication over the Internet. This technology is based on a trust model defined by the original X.509 (1988) standard and is composed of three entities: the certification authority (CA), the certificate holder (or subject), and the Relying Party (RP). The CA plays the role of a trusted third party between the certificate holder and the RP. In many use cases, this trust model has worked successfully. However, we argue that the application of this model on the Internet implies that web users need to depend on almost anyone in the world in order to use PKI technology. Thus, we believe that the current TLS system is not fit for purpose and must be revisited as a whole. In response, the latest draft edition of X.509 has proposed a new trust model by adding new entity called the Trust Broker (TB). In this paper, we present an implementation approach that a Trust Broker could follow in order to give RPs trust information about a CA by assessing the quality of its issued certificates. This is related to the quality of the CA’s policies and procedures and its commitment to them. Finally, we present our Trust Broker implementation that demonstrates how RPs can make informed decisions about certificate holders in the context of the global web, without requiring large processing resources themselves. Ahmad Samer Wazan, Romain Laborde, David W. Chadwick, François Barrère, Benzekri Abdelmalek, Mustafa Kaiiali, Adib Habbal |
Secur. Commun. Networks | 3 |
| 2016 | How Can I Trust an X.509 Certificate? An Analysis of the Existing Trust ApproachesabstractA Public Key Infrastructure (PKI) is based on a trust model defined by the original X.509 standard and is composed of three entities: the Certification Authority, the certificate holder (subject) and the Relying Party. The CA plays the role of a trusted third party between the subject and the RP. A trust evaluation problem is raised when an RP receives a certificate from an unknown subject that is signed by an unknown CA. Different approaches have been proposed to handle this trust problem. We argue that these approaches work only in the closed deployment model where RPs are also subjects, but cannot work in the open deployment model where they are not. Our objective is to identify the deficiencies in the existing trust approaches that try to help RPs to make trust decisions about certificates in the Internet, and to introduce the new X.509 approach based on a trust broker. Ahmad Samer Wazan, Romain Laborde, David W. Chadwick, François Barrère, Benzekri Abdelmalek |
LCN | 3 |
| 2014 | Adding Federated Identity Management to OpenStackabstractOpenStack is an open source cloud computing project that is enjoying wide. While many cloud deployments may be stand-alone, it is clear that secure federated community clouds, i.e., inter-clouds, are needed. Hence, there must be methods for federated identity management (FIM) that enable authentication and authorisation to be flexibly enforced across federated environments. Since there are many different FIM protocols either in use or in development today, this paper addresses the goal of adding protocol independent federated identity management to the OpenStack services. After giving a motivating example for secure cloud federation, and describing the conceptual design for protocol independent federated access, a detailed federated identity protocol sequence is presented. The paper then describes the implementation of the protocol independent system components, along with the incorporation of two different FIM protocols, namely SAML and Keystone proprietary. Finally performance measurements of the protocol independent components, and the two different protocols dependent components are presented, before the paper concludes with the current limitations. David W. Chadwick, Kristy W. S. Siu, Craig A. Lee, Yann Fouillat, Damien Germonville |
J. Grid Comput. | 1 |
| 2014 | Self-adaptive federated authorization infrastructures
Christopher Bailey 0003, David W. Chadwick, Rogério de Lemos |
J. Comput. Syst. Sci. | 2 |
| 2013 | The Trusted Attribute Aggregation Service (TAAS) - Providing an Attribute Aggregation Layer for Federated Identity ManagementabstractWe describe a web based federated identity management system loosely based on the user centric Windows Card Space model. Unlike Card Space that relies on a fat desktop client (the identity selector) in which the user can only select a single card per session, our model uses a standard web browser with a simple plugin that connects to a trusted attribute aggregation web service (TAAS). TAAS supports the aggregation of attributes from multiple identity providers (IdPs) and allows the user to select multiple single attribute "cards" in a session, which more accurately reflects real life in which users may present several plastic cards and self-asserted attributes in a single session. Privacy protection, user consent, and ease of use are critical success factors. Consequently TAAS does not know who the user is, the user consents by selecting the attributes she wants to release, and she only needs to authenticate to a single IdP even though attributes may be aggregated from multiple IdPs. The system does not limit the authentication mechanisms that can be used, and it protects the user from phishing attacks by malicious SPs. David W. Chadwick, George Inman |
ARES | 1 |
| 2012 | A privacy preserving authorisation system for the cloud
David W. Chadwick, Kaniz Fatema |
J. Comput. Syst. Sci. | 1 |
| 2011 | Federated Authentication and Authorisation in the Social Science DomainabstractThe use of Shibboleth as a mechanism for implementing federated authentication is commonplace in many countries. The ability of Shibboleth to transmit extra information about a user, including licenses, roles and other attributes, is not exploited for many reasons, mainly because institional Identity Providers (IdPs) are not maintainable sources of fine grained authorisation information. The JlSC-funded Shintau project has produced an extension to the Shibboleth profile which allows a user to link information from more than one IdP together utilising a custom Linking Service (LS). This paper describes both the application and independent evaluation of this software by the National e-Science Centre (NeSC) at the University of Glasgow within the context of the ESRC-funded Data Management through e-Social Science (DAMES) project. John P. Watt, Richard O. Sinnott, George Inman, David W. Chadwick |
ARES | 4 |
| 2011 | My Private Cloud Overview: A Trust, Privacy and Security Infrastructure for the CloudabstractBased on the assumption that cloud providers can be trusted (to a certain extent) we define a trust, security and privacy preserving infrastructure that relies on trusted cloud providers to operate properly. Working in tandem with legal agreements, our open source software supports: trust and reputation management, sticky policies with fine grained access controls, privacy preserving delegation of authority, federated identity management, different levels of assurance and configurable audit trails. Armed with these tools, cloud service providers are then able to offer a reliable privacy preserving infrastructure-as-a-service to their clients. David W. Chadwick, Stijn F. Lievens, Jerry den Hartog, Andreas Pashalidis, Joseph Alhadeff |
IEEE CLOUD | 1 |
| 2011 | Security APIs for My Private Cloud - Granting access to anyone, from anywhere at any timeabstractWe describe a set of security APIs that grant federated access to a user's cloud resources, and that also allow the user to grant access to his resources to anyone from anywhere at any time. The APIs implement federated access to clouds, fine grained access controls and delegation of authority. We have integrated these APIs into two cloud applications in order to validate their utility. This paper describes the conceptual model and architecture of the APIs, as well as their integration into the Eucalyptus S3 service. The paper concludes by specifying the current limitations. David W. Chadwick, Matteo Casenove |
CloudCom | 1 |
| 2011 | Self-Adaptive Authorization Framework for Policy Based RBAC/ABAC ModelsabstractAuthorization systems are an integral part of any network where resources need to be protected. They act as the gateway for providing (or denying) subjects (users) access to resources. As networks expand and organisations start to federate access to their resources, authorization infrastructures become increasingly difficult to manage. In this paper, we explore the potential of self-adaptive authorization as a means to automate the management of the access control configuration. We propose a Self-Adaptive Authorization Framework (SAAF) that is capable of managing any policy based distributed RBAC/ABAC authorization infrastructure. SAAF relies on a feedback control loop to monitor decisions (by policy decision points) of a target authorization infrastructure. These decisions are analysed to form a view of the subject's behaviour to decide whether to adapt the target authorization infrastructure. Adaptations are made in order to either endorse or restrict the identified behaviour, e.g. by loosening or tightening the current authorization policy. We demonstrate in terms of representative scenarios SAAF's ability for detecting abnormal behaviour, such as, misuse of access to system resources, proposing solutions that either prevent/endorse such behaviour, applying a cost function to each of these solutions, and executing the adaptive changes against a target authorization infrastructure. Christopher Bailey 0003, David W. Chadwick, Rogério de Lemos |
DASC | 2 |
| 2010 | CardSpace in the cloudabstractThis paper describes a web based federated identity management system which is based on the user centric approach of the Information Card model, and has been enhanced to remove many of the problems inherent in Microsoft's original design. Furthermore the new design is adapted to interwork with existing SAML 2 federations. Our model supports not only improved user mobility and the aggregation of claims from multiple identity providers (IdPs), but also user authentication via just one of the IdPs without placing any constraints on the authentication mechanism that is used. This is achieved by introducing a new component, the Linking Identity Selector, which allows the user to select multiple cards at service provision time. Users can then use the combined set of credentials to access a wider range of web based resources. We describe our first example application which allows the user to present a credit card, a self asserted card, a hotel loyalty card and a frequent flyer card in order to make an online hotel booking, using voice biometrics for authentication. David W. Chadwick, George Inman, Paul Coxwell |
CCS | 1 |
| 2010 | A conceptual model for attribute aggregation
David W. Chadwick, George Inman, Nate Klingenstein |
Future Gener. Comput. Syst. | 1 |
| 2010 | Instant certificate revocation and publication using WebDAVabstractThere are several problems associated with the current ways that certificates are published and revoked. This paper discusses these problems, and then proposes a solution based on the use of WebDAV, an enhancement to the HTTP protocol. The proposed solution provides instant certificate revocation, minimizes the processing costs of the certificate issuer and relying party, and eases the administrative burden of publishing certificates and certificate revocation lists (CRLs). We describe how WebDAV can be used for X.509 certificate revocation, and describe how we have implemented it in the PERMIS authorization infrastructure. David W. Chadwick, Sean Anthony, Rune Bjerk |
J. Comput. Secur. | 1 |
| 2009 | How to Securely Break into RBAC: The BTG-RBAC ModelabstractAccess control models describe frameworks that dictate how subjects (e.g. users) access resources. In the role-based access control (RBAC) model access to resources is based on the role the user holds within the organization. RBAC is a rigid model where access control decisions have only two output options: grant or deny. break the glass (BTG) policies on the other hand are flexible and allow users to break or override the access controls in a controlled and justifiable manner. The main objective of this paper is to integrate BTG within the NIST/ANSI RBAC model in a transparent and secure way so that it can be adopted generically in any domain where unanticipated or emergency situations may occur. The new proposed model, called BTG-RBAC, provides a third decision option BTG, which grants authorized users permission to break the glass rather than be denied access. This can easily be implemented in any application without major changes to either the application code or the RBAC authorization infrastructure, apart from the decision engine. Finally, in order to validate the model, we discuss how the BTG-RBAC model is being introduced within a Portuguese healthcare institution where the legislation requires that genetic information must be accessed by a restricted group of healthcare professionals. These professionals, advised by the ethical committee, have required and asked for the implementation of the BTG concept in order to comply with the said legislation. Ana Ferreira 0001, David W. Chadwick, Pedro Farinha, Ricardo João Cruz Correia, Gansen Zhao, Rui Chilro, Luis Filipe Coelho Antunes |
ACSAC | 2 |
| 2009 | Which Web Browsers Process SSL Certificates in a Standardized Way?
Ahmad Samer Wazan, Romain Laborde, David W. Chadwick, François Barrère, Benzekri Abdelmalek |
SEC | 3 |
| 2008 | Advanced Security for Virtual Organizations: The Pros and Cons of Centralized vs Decentralized Security ModelsabstractGrids allow for collaborative e-Research to be undertaken, often across institutional and national boundaries. Typically this is through the establishment of virtual organizations (VOs) where policies on access and usage of resources across partner sites are defined and subsequently enforced. For many VOs, these agreements have been lightweight and erred on the side of flexibility with minimal constraints on the kinds of jobs a user is allowed to run or the amount of resources that can be consumed. For many new domains such as e-Health, such flexibility is simply not tenable. Instead, precise definitions of what jobs can be run, and what data can be accessed by who need to be defined and enforced by sites. The role based access control model (KBAC) provides a well researched paradigm for controlling access to large scale dynamic VOs. However, the standard RBAC model assumes a single domain with centralised role management. When RBAC is applied to VOs, it does not specify how or where roles should be defined or made known to the distributed resource sites (who are always deemed to be autonomous to make access control decisions). Two main possibilities exist based on either a centralized or decentralized approach to VO role management. We present the advantages and disadvantages of the centralized and decentralized role models and describe how we have implemented them in a range of security focused e-Research domains at the National e-Science Centre (NeSC) at the University of Glasgow. Richard O. Sinnott, David W. Chadwick, Thomas Doherty, Anthony Stell, Gordon Stewart 0002, Linying Su, John P. Watt |
CCGRID | 2 |
| 2008 | Panel Session: What Are the Key Challenges in Distributed Security?
Steve Barker, David W. Chadwick, Jason Crampton, Emil C. Lupu, Bhavani Thuraisingham |
DBSec | 2 |
| 2008 | Expressions of expertness: the virtuous circle of natural language for access control policy specificationabstractThe implementation of usable security is particularly challenging in the growing field of Grid computing, where control is decentralised, systems are heterogeneous, and authorization applies across administrative domains. PERMIS, based on the Role-Based Access Control (RBAC) model, provides a unified infrastructure to address these challenges. Previous research has found that resource owners who do not understand the PERMIS RBAC model have difficulty expressing access control policies. We have addressed this issue by investigating the use of a controlled natural language parser for expressing these policies. In this paper, we describe our experiences in the design, implementation, and evaluation of this parser for the PERMIS Editor. We began by understanding Grid access control needs as expressed by resource owners, through interviews and focus groups with 45 Grid practitioners. We found that the many areas of Grid computing use present varied security requirements; this suggests a minimal, open design. We designed and implemented a controlled natural language system to support these needs, which we evaluated with a cross-section of 17 target users. We found that participants were not daunted by the text editor, and understood the syntax easily. However, some strict requirements of the controlled language were problematic. Using controlled natural language helps overcome some conceptual mis-matches between PERMIS RBAC and older paradigms; however, there are still subtleties which are not always understood. In conclusion, the parser is not sufficient on its own, and should be seen in the interplay with other parts of the PERMIS Editor, so that, iteratively, users are helped to understand the underlying PERMIS model and to express their security policies more accurately and more completely. Philip Inglesant, M. Angela Sasse, David W. Chadwick, Lei Lei Shi |
SOUPS | 3 |
| 2008 | Coordinating access control in grid servicesabstractAbstract We describe how to control the cumulative use of distributed grid resources by using coordination‐aware policy decision points (coordinated PDPs) and an SQL database to hold ‘coordination’ data. When access to a resource is granted, obligations in the security policy ensure that the coordination database is updated. The coordination database is a normal grid service providing distributed access to the coordinated PDPs. Access to the databases is secured by the grid security infrastructure (GSI) and its own PDP, so that only authorized users (the coordinated PDPs) can access it. A coordinated PDP is imbedded into the Globus Toolkitv4 authorization chain as a custom PDP so that any grid service can be protected by a security policy that provides a coordination capability. Each coordinated PDP uses the services of an uncoordinated PDP to make its access control decisions, so that any existing stateless PDP can be supplemented with a coordination capability. We provide performance results for the coordinated PDPs and compare these with two stateless PDPs. Virtually the entire performance penalty of using coordinated PDPs is accounted for by the heavy costs of using GSI to secure communications between the coordinated PDPs and the coordination database. Copyright © 2007 John Wiley & Sons, Ltd. David W. Chadwick, Linying Su, Romain Laborde |
Concurr. Comput. Pract. Exp. | 1 |
| 2008 | PERMIS: a modular authorization infrastructureabstractAbstract Authorization infrastructures manage privileges and render access control decisions, allowing applications to adjust their behavior according to the privileges allocated to users. This paper describes the PERMIS role‐based authorization infrastructure along with its conceptual authorization, access control, and trust models. PERMIS has the novel concept of a credential validation service, which verifies a user's credentials prior to access control decision‐making and enables the distributed management of credentials. PERMIS also supports delegation of authority; thus, credentials can be delegated between users, further decentralizing credential management. Finally, PERMIS supports history‐based decision‐making, which can be used to enforce such aspects as separation of duties and cumulative use of resources. Details of the design and the implementation of PERMIS are presented along with details of its integration with Globus Toolkit, Shibboleth, and GridShib. A comparison of PERMIS with other authorization and access control implementations is given, along with suggestions where future research and development are still needed. Copyright © 2008 John Wiley & Sons, Ltd. David W. Chadwick, Gansen Zhao, Sassa Otenko, Romain Laborde, Linying Su |
Concurr. Comput. Pract. Exp. | 1 |
| 2007 | Recognition of Authority in Virtual Organisations
David W. Chadwick, Bassem Nasser |
TrustBus | 2 |
| 2007 | Achieving fine-grained access control in virtual organizationsabstractAbstract In a virtual organization environment, where services and data are provided and shared among organizations from different administrative domains and protected with dissimilar security policies and measures, there is a need for a flexible authentication framework that supports the use of various authentication methods and tokens. The authentication strengths derived from the authentication methods and tokens should be incorporated into an access‐control decision‐making process, so that more sensitive resources are available only to users authenticated with stronger methods. This paper reports our on‐going efforts in designing and implementing such a framework to facilitate multi‐level and multi‐factor adaptive authentication and authentication strength linked fine‐grained access control. The proof‐of‐concept prototype is designed and implemented in the Shibboleth and PERMIS infrastructures, which specifies protocols to federate authentication and authorization information and provides a policy‐driven, role‐based, access‐control decision‐making capability. Copyright © 2006 John Wiley & Sons, Ltd. Ning Zhang 0001, Aleksandra Nenadic, Jay Chin, Carole A. Goble, Alan L. Rector, David W. Chadwick, Sassa Otenko, Qi Shi 0001 |
Concurr. Comput. Pract. Exp. | 7 |
| 2007 | Coordinated decision making in distributed applications
David W. Chadwick |
Inf. Secur. Tech. Rep. | 1 |
| 2006 | Distributed Key Management for Secure Role based MessagingabstractSecure role based messaging (SRBM) augments messaging systems with role oriented communication in a secure manner. Role occupants can sign and decrypt messages on behalf of roles. This paper identifies the requirements of SRBM and recognises the need for: distributed key shares, fast membership revocation, mandatory security controls and detection of identity spoofing. A shared RSA scheme is constructed. RSA keys are shared and distributed to role occupants and role gate keepers. Role occupants and role gate keepers must cooperate together to use the key shares to sign and decrypt the messages. Role occupant signatures can be verified by an audit service. SRBM system architecture is developed to show the security related performance of the proposed scheme, which also demonstrates the implementation of fast membership revocation, mandatory security control and prevention of spoofing. It is shown that the proposed scheme has successfully coupled distributed security with mandatory security controls to realize secure role based messaging. Gansen Zhao, Sassa Otenko, David W. Chadwick |
AINA (1) | 3 |
| 2006 | How to Break Access Control in a Controlled MannerabstractThe Electronic Medical Record (EMR) integrates heterogeneous information within a Healthcare Institution stressing the need for security and access control. The Biostatistics and Medical Informatics Department from Porto Faculty of Medicine has recently implemented a Virtual EMR (VEMR) in order to integrate patient information and clinical reports within a university hospital. With more than 500 medical doctors using the system on a daily basis, an access control policy and model were implemented. However, the healthcare environment has unanticipated situations (i.e. emergency situations) where access to information is essential. Most traditional policies do not allow for overriding. A policy that allows for "Break-The-Glass (BTG)" was implemented in order to override access control whilst providing for non-repudiation mechanisms for its usage. The policy was easily integrated within the model confirming its modularity and the fact that user intervention in defining security procedures is crucial to its successful implementation and use. Ana Ferreira 0001, Ricardo João Cruz Correia, Luis Filipe Coelho Antunes, Pedro Farinha, E. Oliveira-Palhares, David W. Chadwick, Altamiro da Costa Pereira |
CBMS | 6 |
| 2006 | Supporting Decentralized, Security Focused Dynamic Virtual Organizations across the GridabstractThe ability to dynamically create and subsequently manage secure virtual organisations (VO) is one of the key challenges facing the Grid community. Existing approaches for establishing and managing VOs typically suffer from lack of fine grained security since they largely focus on public key infrastructures with statically defined access control lists, or they are based upon a centralised site for storage of VO specific security information. What is really needed is a federated model of security where sites are able to manage their own security information for their own institutional members, delegating where necessary to trusted local or remote entities, as well as defining and enforcing authorisation policies for their own resources. In this paper we present tools that support such capabilities and highlight how they have been applied to dynamically create and manage security focused VOs in the education domain. We believe that this federated VO security model for fine grained access to Grid services and resources should be the future model upon which security focused Grids are based. Richard O. Sinnott, David W. Chadwick, Jos Koetsier, O. Otenko, John P. Watt |
e-Science | 2 |
| 2006 | Privacy Preserving Trust Authorization Framework Using XACMLabstractNowadays many organizations share sensitive services through open network systems and this raises the need for an authorization framework that can interoperate even when the parties have no pre-existing relationships. Trust negotiation is the process used to establish these first relationships, through the transfer of attributes, embedded in digital credentials, between the two parties. However, these attributes may themselves be considered sensitive and so may need protection from disclosure. In some environments, the policies that govern the protected services may also be considered sensitive and their release to arbitrary strangers may leak confidential business information. This paper describes a way to unify the protection of services, sensitive credentials and policies in a synchronized trustworthy manner. We propose a trust authorization framework (TAF) that builds on the capabilities of XACML to support the bilateral exchange of policies and credentials through trust negotiation Uche M. Mbanaso, G. S. Cooper, David W. Chadwick, Seth Proctor |
WOWMOM | 3 |
| 2005 | Evolving Messaging Systems for Secure Role Based MessagingabstractThis paper articulates a system design for the secure role based messaging model built based on existing messaging systems, public key infrastructures, and a privilege management infrastructure, which enables role-oriented secure communication. Users can send and access messages on behalf of a role. Access to the messages is authorized dynamically according to the authorization policies conveyed by X.509 attribute certificates. The architecture design extends the current messaging systems without invalidating the system's compliance with existing standards, and enables easy integration with existing messaging systems. This paper also contributes to providing security features based on architecture design, and demonstrates the deliberative architecture design for information confidentiality and privacy. Gansen Zhao, David W. Chadwick |
ICECCS | 2 |
| 2005 | Authorisation in Grid computing
David W. Chadwick |
Inf. Secur. Tech. Rep. | 1 |
| 2005 | 'R-What?' Development of a role-based access control policy-writing tool for e-ScientistsabstractAbstract A lightweight role‐based access control policy authoring tool was developed for e‐Scientists, a community for which access policies have to be implemented for an increasingly heterogeneous group of local and remote users. Two fundamental problems were identified: (1) lack of understanding of what the policy components are (i.e. how authorization policies are structured), and (2) lack of understanding of the underlying policy paradigm (i.e. what should go into the policy, and what should be left out). Conceptual design (CD) techniques were used to revise the user interface (UI) labels so that e‐Scientists and developers were better able to describe access policy components from labels, and match labels with components (t = 6.28, df = 7, p = 0.000 two‐tailed). CD, instructional text, bubble help, UI behaviour and alert boxes were used to shape users' models of the policy paradigm. The final prototype improved users' efficiency and effectiveness by more than doubling the speed with which expert users could write authorization policies, and facilitating users without specialist security knowledge to overcome the policy paradigm and components problems, enabling them to complete 80% of basic and 75% of advanced authorization policy‐writing tasks in a usability trial. Copyright © 2005 John Wiley & Sons, Ltd. Sacha Brostoff, M. Angela Sasse, David W. Chadwick, Jim Cunningham, Uche M. Mbanaso, Sassa Otenko |
Softw. Pract. Exp. | 3 |
| 2003 | Persistent versus Dynamic Role Membership
Jean Bacon, David W. Chadwick, Sassa Otenko, Ken Moody |
DBSec | 2 |
| 2003 | Modifying LDAP to Support PKI
David W. Chadwick, Edward Ball 0002, M. V. Sahalayev |
DBSec | 1 |
| 2003 | Experiences of using a PKI to access a hospital information system by high street opticians
David W. Chadwick, Darren P. Mundy, John P. New |
Comput. Commun. | 1 |
| 2003 | The PERMIS X.509 role based privilege management infrastructure
David W. Chadwick, Sassa Otenko |
Future Gener. Comput. Syst. | 1 |
| 2002 | Privacy and Civil Liberties
David W. Chadwick, Martin S. Olivier, Pierangela Samarati, Eleanor Sharpston, Bhavani Thuraisingham |
DBSec | 1 |
| 2002 | The PERMIS X.509 role based privilege management infrastructureabstractThis paper describes the EC PERMIS project, which has developed a role based access control infrastructure that uses X.509 attribute certificates (ACs) to store the users’ roles. All access control decisions are driven by an authorization policy, which is itself stored in an X.509 AC, thus guaranteeing its integrity. All the ACs can be stored in one or more LDAP directories, thus making them widely available. Authorization policies are written in XML according to a DTD that has been published at XML.org. The Access Control Decision Function (ADF) is written in Java and the Java API is simple to use, comprising of just 3 methods and a constructor. There is also a Privilege Allocator, which is a tool that constructs and signs ACs and stores them in an LDAP directory for subsequent use by the ADF. David W. Chadwick, Sassa Otenko |
SACMAT | 1 |
| 2002 | RBAC Policies in XML for X.509 Based Privilege Management
David W. Chadwick, Sassa Otenko |
SEC | 1 |
| 2001 | Evaluating Trust in a Public Key Certification Authority
David W. Chadwick, Andrew Basden |
Comput. Secur. | 1 |
| 2001 | Knowledge Issues Raised in Modelling Trust in a Public Key InfrastructureabstractThe paper describes a knowledge‐based system for modelling trust in the certification authority (CA) of a public key infrastructure. It was built using a graphical knowledge‐based system toolkit, Istar, that allows the knowledge builder to easily model the important relationships between concepts of the domain. The knowledge base was initially built using published work and was subsequently extended by knowledge obtained from leading public key infrastructure experts. The first prototype system computes the trust in a CA by asking the user a series of questions about the CA's Certification Practice Statement. Examples of its use with two well‐known public CAs is discussed. An important issue raised and discussed in this paper is how to map symbols in the knowledge base to the knowledge level of human trust and beliefs, for such an ill‐defined area of knowledge as trust, and four main mappings have been identified. Another issue that emerged relates to the use of questionnaires during knowledge acquisition. The expert system is currently available online via the Istar knowledge server, and future work is discussed. Andrew Basden, Edward Ball 0002, David W. Chadwick |
Expert Syst. J. Knowl. Eng. | 3 |
| 1998 | Enabling the Internet White Pages Service - the Directory Guardian
David W. Chadwick, Andrew J. Young |
NDSS | 1 |
| 1997 | Trust Models in ICE-TELabstractPublic key certification provides mechanisms that can be used to build truly scaleable security services, such as allowing people who have never met to have assurance of each other's identity. Authentication involves syntactic verification of a certificate chain followed by a semantic look at the policies under which the certificates were issued. This results in a level of assurance that the identity of the person to be authenticated is an accurate description of the person involved, and requires verifiers to specify who they trust and what they trust them to do. Two widely discussed mechanisms for specifying this trust, the PEM and PGP trust models, approach the problem from fundamentally different directions. The EC funded ICE-TEL project, which is deploying a security infrastructure and application set for the European research community, has described a new trust model that attempts to be equally applicable to organisation-centric PEM users and user-centric PGP users. Andrew J. Young, Nada Kapidzic Cicovic, David W. Chadwick |
NDSS | 3 |