EDBT 2026 Demo / reviewers in the wild / expert
Kent E. Seamons
dblp:s/KentESeamons
· DBLP profile ↗
52ranked-venue papers
6as first author
9since 2021 · last 2026
0000-0002-1482-492XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 37 · 1 first-author · 8 since 2021Human-computer interaction and ubiquitous computing · 10 · 2 since 2021Databases, data management, data science and information retrieval · 6 · 2 first-authorSystems, architecture and hardware · 4 · 3 first-authorApplied, interdisciplinary, general and emerging computing · 2Computer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Passkeys in the Wild: A Systematic Study of FIDO2 User Experience Consistency Across Websites
Bernhardt Ramat, David Kartchner, Michael Clark, Kent E. Seamons |
SOUPS | 4 |
| 2025 | Passwords and FIDO2 Are Meant To Be Secret: A Practical Secure Authentication Channel for Web BrowsersabstractPassword managers provide significant security benefits to users. However, malicious client-side scripts and browser extensions can steal passwords after the manager has autofilled them into the web page. In this paper, we extend prior work by Stock and Johns, showing how password autofill can be hardened to prevent these local attacks. We implement our design in the Firefox browser and conduct experiments demonstrating that our defense successfully protects passwords from XSS attacks and malicious extensions. We also show that our implementation is compatible with 97% of the Alexa top 1000 websites. Next, we generalize our design, creating a second defense that prevents recently discovered local attacks against the FIDO2 protocols. We implement this second defense into Firefox, demonstrating that it protects the FIDO2 protocol against XSS attacks and malicious extensions. This defense is compatible with all websites, though it does require a small change (2-3 lines) to web servers implementing FIDO2. Anuj Gautam, Tarun Kumar Yadav, Garrett Smith, Kent E. Seamons, Scott Ruoti |
CCS | 4 |
| 2025 | Choose From a List: A User Study of Random Password Memorability
Michael Clark, Gregory L. Snow, Kent E. Seamons |
CHI | 3 |
| 2024 | A Security and Usability Analysis of Local Attacks Against FIDO2
Tarun Kumar Yadav, Kent E. Seamons |
NDSS | 2 |
| 2023 | "If I could do this, I feel anyone could: " The Design and Evaluation of a Secondary Authentication Factor Manager
Garrett Smith, Tarun Kumar Yadav, Jonathan Dutson, Scott Ruoti, Kent E. Seamons |
USENIX Security Symposium | 5 |
| 2023 | Cryptographic Deniability: A Multi-perspective Study of User Perceptions and Expectations
Tarun Kumar Yadav, Devashish Gosain, Kent E. Seamons |
USENIX Security Symposium | 3 |
| 2022 | Automatic Detection of Fake Key Attacks in Secure MessagingabstractPopular instant messaging applications such as WhatsApp and Signal provide end-to-end encryption for billions of users. These applications often rely on a centralized, application-specific server to distribute public keys and relay encrypted messages between the users. As a result, they prevent passive attacks but are vulnerable to some active attacks. A malicious or hacked server can distribute fake keys to users to perform man-in-the-middle or impersonation attacks. While typical secure messaging applications provide a manual method for users to detect these attacks, this burdens users, and studies show it is ineffective in practice. This paper presents KTACA, a completely automated approach for key verification that is oblivious to users and easy to deploy. We motivate KTACA by designing two approaches to automatic key verification. One approach uses client auditing (KTCA) and the second uses anonymous key monitoring (AKM). Both have relatively inferior security properties, leading to KTACA, which combines these approaches to provide the best of both worlds. We provide a security analysis of each defense, identifying which attacks they can automatically detect. We implement the active attacks to demonstrate they are possible, and we also create a prototype implementation of all the defenses to measure their performance and confirm their feasibility. Finally, we discuss the strengths and weaknesses of each defense, the load they impose on clients and service providers, and their deployment considerations. Tarun Kumar Yadav, Devashish Gosain, Amir Herzberg, Daniel Zappala, Kent E. Seamons |
CCS | 5 |
| 2022 | Poster: User-controlled System-level Encryption for all ApplicationsabstractToday, some applications encrypt our data, while many others do not. Users must accept the level of protection the application provides. Our research aims to support client-to-client encryption at the system level so that users can enable encryption for data in any application (e.g., email, Slack), even if the application does not support it. Two users can exchange sensitive data without it being accessible to any applications or systems along the path. We will describe the challenges to designing the system, the techniques we will use to build the system, and the advantages of encryption at the system level. Tarun Kumar Yadav, Justin Hales, Kent E. Seamons |
CCS | 3 |
| 2022 | Passwords and Cryptwords: The Final Limits on LengthsabstractComputers get faster every year; brains don’t. Passwords and other memorized credentials have unique usability advantages over tokens and biometrics, so we desire to design secure systems that maintain lengths that users can memorize. Some passwords are subject primarily to online attacks, and are simple to defend with rate limits and lockouts. Others, used to generate encryption keys, must be secure against offline attacks. We coin the term “cryptword” to distinguish these from passwords subject primarily to online attacks. Michael Clark, Kent E. Seamons |
NSPW | 2 |
| 2020 | Let's Revoke: Scalable Global Certificate Revocation
Trevor Smith 0002, Luke Dickenson, Kent E. Seamons |
NDSS | 3 |
| 2019 | Leveraging locality of reference for certificate revocationabstractX.509 certificate revocation defends against man-in-the-middle attacks involving a compromised certificate. Certificate revocation strategies face scalability, effectiveness, and deployment challenges as HTTPS adoption rates have soared. We propose Certificate Revocation Table (CRT), a new revocation strategy that is competitive with or exceeds alternative state-of-the-art solutions in effectiveness, efficiency, certificate growth scalability, mass revocation event scalability, revocation timeliness, privacy, and deployment requirements. The CRT design assumes that locality of reference applies to the certificates accessed by an organization. The CRT periodically checks the revocation status of X.509 certificates recently used by the organization. Pre-checking the revocation status of certificates the clients are likely to use avoids the security problems of on-demand certificate revocation checking. Luke Dickinson, Trevor Smith 0002, Kent E. Seamons |
ACSAC | 3 |
| 2019 | I Don't Even Have to Bother Them!: Using Social Media to Automate the Authentication Ceremony in Secure MessagingabstractThe privacy guaranteed by secure messaging applications relies on users completing an authentication ceremony to verify they are using the proper encryption keys. We examine the feasibility of social authentication, which partially automates the ceremony using social media accounts. We implemented social authentication in Signal and conducted a within-subject user study with 42 participants to compare this with existing methods. To generalize our results, we conducted a Mechanical Turk survey involving 421 respondents. Our results show that users found social authentication to be convenient and fast. They particularly liked verifying keys asynchronously, and viewing social media profiles naturally coincided with how participants thought of verification. However, some participants reacted negatively to integrating social media with Signal, primarily because they distrust social media services. Overall, automating the authentication ceremony and distributing trust with additional service providers is promising, but this infrastructure needs to be more trusted than social media companies. Elham Vaziripour, Devon Howard, Jake Tyler, Mark O'Neill, Justin Wu, Kent E. Seamons, Daniel Zappala |
CHI | 6 |
| 2019 | A Usability Study of Four Secure Email Tools Using Paired ParticipantsabstractSecure email is increasingly being touted as usable by novice users, with a push for adoption based on recent concerns about government surveillance. To determine whether secure email is ready for grassroots adoption, we employ a laboratory user study that recruits pairs of novice users to install and use several of the latest systems to exchange secure messages. We present both quantitative and qualitative results from 28 pairs of novices as they use Private WebMail (Pwm), Tutanota, and Virtru and 10 pairs of novices as they use Mailvelope. Participants report being more at ease with this type of study and better able to cope with mistakes since both participants are “on the same page.” We find that users prefer integrated solutions over depot-based solutions and that tutorials are important in helping first-time users. Finally, our results demonstrate that Pretty Good Privacy using manual key management is still unusable for novice users, with 9 of 10 participant pairs failing to complete the study. Scott Ruoti, Jeff Andersen, Luke Dickinson, Scott Heidbrink, Tyler Monson, Mark O'Neill, Ken Reese, Brad Spendlove, Elham Vaziripour, Justin Wu, Daniel Zappala, Kent E. Seamons |
ACM Trans. Priv. Secur. | 12 |
| 2018 | A Tale of Two Studies: The Best and Worst of YubiKey UsabilityabstractTwo-factor authentication (2FA) significantly improves the security of password-based authentication. Recently, there has been increased interest in Universal 2nd Factor (U2F) security keys-small hardware devices that require users to press a button on the security key to authenticate. To examine the usability of security keys in non-enterprise usage, we conducted two user studies of the YubiKey, a popular line of U2F security keys. The first study tasked 31 participants with configuring a Windows, Google, and Facebook account to authenticate using a YubiKey. This study revealed problems with setup instructions and workflow including users locking themselves out of their operating system or thinking they had successfully enabled 2FA when they had not. In contrast, the second study had 25 participants use a YubiKey in their daily lives over a period of four weeks, revealing that participants generally enjoyed the experience. Conducting both a laboratory and longitudinal study yielded insights into the usability of security keys that would not have been evident from either study in isolation. Based on our analysis, we recommend standardizing the setup process, enabling verification of success, allowing shared accounts, integrating with operating systems, and preventing lockouts. Joshua Reynolds, Trevor Smith 0002, Ken Reese, Luke Dickinson, Scott Ruoti, Kent E. Seamons |
IEEE Symposium on Security and Privacy | 6 |
| 2018 | The Secure Socket API: TLS as an Operating System Service
Mark O'Neill, Scott Heidbrink, Jordan Whitehead, Tanner Perdue, Luke Dickinson, Torstein Collett, Nick Bonner, Kent E. Seamons, Daniel Zappala |
USENIX Security Symposium | 8 |
| 2017 | End-to-End PasswordsabstractPasswords continue to be an important means for users to authenticate themselves to applications, websites, and backend services. However, password theft continues to be a significant issue, due in large part to the significant attack surface for passwords, including the operating system (e.g., key loggers), application (e.g., phishing websites in browsers), during transmission (e.g., TLS man-in-the-middle proxies), and at password verification services (e.g., theft of passwords stored at a server). Relatedly, even though there is a large body of research on improving passwords, the massive number of application verification services that use passwords stymie the diffusion of improvements---i.e., it does not scale for each improvement to require an update to every application and verification service. Scott Ruoti, Kent E. Seamons |
NSPW | 2 |
| 2017 | Weighing Context and Trade-offs: How Suburban Adults Selected Their Online Security Posture
Scott Ruoti, Tyler Monson, Justin Wu, Daniel Zappala, Kent E. Seamons |
SOUPS | 5 |
| 2017 | Augmenting Centralized Password Management with Application-Specific Passwords
Trevor Smith 0002, Scott Ruoti, Kent E. Seamons |
SOUPS | 3 |
| 2017 | Is that you, Alice? A Usability Study of the Authentication Ceremony of Secure Messaging Applications
Elham Vaziripour, Justin Wu, Mark O'Neill, Jordan Whitehead, Scott Heidbrink, Kent E. Seamons, Daniel Zappala |
SOUPS | 6 |
| 2017 | TrustBase: An Architecture to Repair and Strengthen Certificate-based Authentication
Mark O'Neill, Scott Heidbrink, Scott Ruoti, Jordan Whitehead, Dan Bunker, Luke Dickinson, Travis Hendershot, Joshua Reynolds, Kent E. Seamons, Daniel Zappala |
USENIX Security Symposium | 9 |
| 2016 | "We're on the Same Page": A Usability Study of Secure Email Using Pairs of Novice UsersabstractSecure email is increasingly being touted as usable by novice users, with a push for adoption based on recent concerns about government surveillance. To determine whether secure email is ready for grassroots adoption, we employ a laboratory user study that recruits pairs of novice users to install and use several of the latest systems to exchange secure messages. We present both quantitative and qualitative results from 25 pairs of novice users as they use Pwm, Tutanota, and Virtru. Participants report being more at ease with this type of study and better able to cope with mistakes since both participants are "on the same page". We find that users prefer integrated solutions over depot-based solutions, and that tutorials are important in helping first-time users. Hiding the details of how a secure email system provides security can lead to a lack of trust in the system. Participants expressed a desire to use secure email, but few wanted to use it regularly and most were unsure of when they might use it. Scott Ruoti, Jeff Andersen, Scott Heidbrink, Mark O'Neill, Elham Vaziripour, Justin Wu, Daniel Zappala, Kent E. Seamons |
CHI | 8 |
| 2016 | TLS Proxies: Friend or Foe?
Mark O'Neill, Scott Ruoti, Kent E. Seamons, Daniel Zappala |
Internet Measurement Conference | 3 |
| 2016 | Content-based security for the webabstractThe World Wide Web has become the most common platform for building applications and delivering content. Yet despite years of research, the web continues to face severe security challenges related to data integrity and confidentiality. Rather than continuing the exploit-and-patch cycle, we propose addressing these challenges at an architectural level, by supplementing the web's existing connection-based and server-based security models with a new approach: content-based security. With this approach, content is directly signed and encrypted at rest, enabling it to be delivered via any path and then validated by the browser. We explore how this new architectural approach can be applied to the web and analyze its security benefits. We then discuss a broad research agenda to realize this vision and the challenges that must be overcome. Alexander Afanasyev, J. Alex Halderman, Scott Ruoti, Kent E. Seamons, Yingdi Yu, Daniel Zappala, Lixia Zhang 0001 |
NSPW | 4 |
| 2016 | User Attitudes Toward the Inspection of Encrypted Traffic
Scott Ruoti, Mark O'Neill, Daniel Zappala, Kent E. Seamons |
SOUPS | 4 |
| 2016 | Private Webmail 2.0: Simple and Easy-to-Use Secure EmailabstractPrivate Webmail 2.0 (Pwm 2.0) improves upon the current state of the art by increasing the usability and practical security of secure email for ordinary users. More users are able to send and receive encrypted emails without mistakenly revealing sensitive information. In this paper we describe four user interface traits that positively affect the usability and security of Pwm 2.0. In a user study involving 51 participants we validate that these interface modifications result in high usability, few mistakes, and a strong understanding of the protection provided to secure email messages. We also show that the use of manual encryption has no effect on usability or security. Scott Ruoti, Jeff Andersen, Travis Hendershot, Daniel Zappala, Kent E. Seamons |
UIST | 5 |
| 2015 | Authentication Melee: A Usability Analysis of Seven Web Authentication SystemsabstractPasswords continue to dominate the authentication landscape in spite of numerous proposals to replace them. Even though usability is a key factor in replacing passwords, very few alternatives have been subjected to formal usability studies, and even fewer have been analyzed using a standard metric. We report the results of four within-subjects usability studies for seven web authentication systems. These systems span federated, smartphone, paper tokens, and email-based approaches. Our results indicate that participants prefer single sign-on systems. We report several insightful findings based on participants' qualitative responses: (1) transparency increases usability but also leads to confusion and a lack of trust, (2) participants prefer single sign-on but wish to augment it with site-specific low-entropy passwords, and (3) participants are intrigued by biometrics and phone-based authentication. We utilize the Systems Usability Scale (SUS) as a standard metric for empirical analysis and find that it produces reliable, replicable results. SUS proves to be an accurate measure of baseline usability. We recommend that new authentication systems be formally evaluated for usability using SUS, and should meet a minimum acceptable SUS score before receiving serious consideration. Scott Ruoti, Brent Roberts, Kent E. Seamons |
WWW | 3 |
| 2014 | POSTER: TLS Proxies: Friend or Foe?abstractThe use of TLS proxies to intercept encrypted traffic is controversial since the same mechanism can be used for both benevolent purposes, such as protecting against malware, and for malicious purposes, such as identity theft or warrantless government surveillance. To understand the prevalence and uses of these proxies, we build a TLS proxy measurement tool and deploy it via a Google AdWords campaign. We generate 2.9 million certificate tests and find that 1 in 250 TLS connections are proxied. The majority of these proxies appear to be benevolent, however we identify over 1,000 cases where three malware products are using this technology nefariously. We also find numerous instances of negligent and duplicitous behavior, some of which degrade security for users without their knowledge. Mark O'Neill, Scott Ruoti, Kent E. Seamons, Daniel Zappala |
CCS | 3 |
| 2013 | Confused Johnny: when automatic encryption leads to confusion and mistakesabstractA common approach to designing usable security is to hide as many security details as possible from the user to reduce the amount of information and actions a user must encounter. This paper gives an overview of Pwm (Private Webmail), our secure webmail system that uses security overlays to integrate tightly with existing webmail services like Gmail. Pwm's security is mostly transparent, including automatic key management and automatic encryption. We describe a series of Pwm user studies indicating that while nearly all users can use the system without any prior training, the security details are so transparent that a small percentage of users mistakenly sent out unencrypted messages and some users are unsure whether they should trust Pwm. We then conducted user studies with an alternative prototype to Pwm that uses manual encryption. Surprisingly users were accepting of the extra steps of cutting and pasting ciphertext themselves. They avoided mistakes and had more trust in the system with manual encryption. Our results suggest that designers may want to reconsider manual encryption as a way to reduce transparency and foster greater trust. Scott Ruoti, Nathan Kim, Ben Burgon, Timothy W. van der Horst, Kent E. Seamons |
SOUPS | 5 |
| 2013 | A middleware approach for outsourcing data securely
Ravi Chandra Jammalamadaka, Roberto Gamboni, Sharad Mehrotra, Kent E. Seamons, Nalini Venkatasubramanian |
Comput. Secur. | 4 |
| 2008 | pwdArmor: Protecting Conventional Password-Based AuthenticationsabstractpwdArmor is a framework for fortifying conventional password-based authentications. Many password protocols are performed within an encrypted tunnel (e.g., TLS) to prevent the exposure of the password itself, or of material for an offline password guessing attack. Failure to establish, or to correctly verify, this tunnel completely invalidates its protections. The rampant success of phishing demonstrates the risk of relying solely on the user to ensure that a tunnel is established with the correct entity. pwdArmor wraps around existing password protocols. It thwarts passive attacks and improves detection, by both users and servers, of man-in-the middle attacks. If a user is tricked into authenticating to an attacker, instead of the real server, the user's password is never disclosed. Although pwdArmor does not require an encrypted tunnel, it gains added protection from active attack if one is employed; even if the tunnel is established with an attacker and not the real server. These assurances significantly reduce the effectiveness of password phishing. Wrapping a protocol with pwdArmor requires no modification to the underlying protocol or to its existing database of password verifiers. Timothy W. van der Horst, Kent E. Seamons |
ACSAC | 2 |
| 2008 | iDataGuard: middleware providing a secure network drive interface to untrusted internet data storageabstractIn this demonstration, we present the design and features of iDataGuard. iDataGuard is an interoperable security middleware that allows users to outsource their file systems to heterogeneous data storage providers available on the Internet. Examples of data storage providers include Amazon S3 service, Rapidshare. de and Nivarnix. In the iDataGuard architecture, data storage providers are untrusted. Therefore, iDataGuard preserves data confidentiality and integrity of outsourced information by using cryptographic techniques. iDataGuard effectively builds a secure network drive on top of any data storage provider on the Internet. We propose techniques that realize a secure file system over the heterogeneous data models offered by the diverse storage providers. iDataGuard significantly reduces the development effort required to build applications on top of the storage offered by the IDPs. Applications written to be compatible with iDataGuard, do not have to worry where the data is stored and how the security is enforced. iDataGuard automatically provides such functionality to application developers. To evaluate the practicality of iDataGuard, we implemented a version of the middleware layer to test its performance. Ravi Chandra Jammalamadaka, Roberto Gamboni, Sharad Mehrotra, Kent E. Seamons, Nalini Venkatasubramanian |
EDBT | 4 |
| 2008 | Wireless authentication using remote passwordsabstractCurrent wireless authentication mechanisms typically rely on inflexible shared secrets or a heavyweight public-key infrastructure with user-specific digital certificates and, as such, lack general support for environments with dynamic user bases where guest access is frequent. Simple Authentication for the Web (SAW) facilitates dynamic user bases in the context of web site logins by enabling users to authenticate to personal messaging identifiers (e.g., email addresses, IM handles, cell phone numbers). SAW, however, is ill-suited for wireless authentication because, in most cases, it is dependent on client-side Internet connectivity. Wireless Authentication using Remote Passwords (WARP) overcomes this constraint by building a hybrid protocol that combines the principles of SAW authentication with the Secure Remote Password (SRP) protocol. Andrew Harding, Timothy W. van der Horst, Kent E. Seamons |
WISEC | 3 |
| 2007 | Extensible Pre-authentication KerberosabstractKerberos is a well-established authentication system. As new authentication methods arise, incorporating them into Kerberos is desirable. However, extending Kerberos poses challenges due to a lack of source code availability for some implementations and a lengthy standardization process. This paper presents Extensible Pre-Authentication in Kerberos (EPAK), a Kerberos extension that enables many authentication methods to be loosely coupled with Ker- beros, without further modification to Kerberos. To demon- strate the utility of the framework, two authentication meth- ods for open systems are presented that have been imple- mented as Kerberos extensions using EPAK. These exten- sions illustrate the flexibility EPAK brings to Kerberos while maintaining backwards compatibility. Phillip L. Hellewell, Kent E. Seamons |
ACSAC | 2 |
| 2007 | gVault: A Gmail Based Cryptographic Network File System
Ravi Chandra Jammalamadaka, Roberto Gamboni, Sharad Mehrotra, Kent E. Seamons, Nalini Venkatasubramanian |
DBSec | 4 |
| 2007 | Simple authentication for the webabstractAutomated email-based password reestablishment (EBPR) is an efficient, cost-effective means to deal with forgotten passwords. In this technique, email providers authenticate users on behalf of web sites. This method works because web sites trust email providers to deliver messages to their intended recipients. Simple Authentication for the Web (SAW) improves upon this basic approach to user authentication to create an alternative to password-based logins. SAW: 1) Removes the setup and management costs of passwords at sites that accept the risks of EBPR; 2) Provides single sign-on without a specialized identity provider; 3) Thwarts all passive attacks. Timothy W. van der Horst, Kent E. Seamons |
WWW | 2 |
| 2006 | Delegate: A Proxy Based Architecture for Secure Website Access from an Untrusted MachineabstractPerforming sensitive online transactions using computers found in cybercafes and public libraries is risky. The untrusted nature of these machines creates a target rich environment. A simple keystroke logger, a common pay load of many viruses, records and transmits the secret information (e.g., passwords, credit card numbers, PIN numbers) entered into these machines. In addition, sophisticated malware can hijack a user's authenticated session to perform unauthorized transactions masquerading as the user. This paper presents Delegate, a proxy-based architecture that enables a user to access Web sites without disclosing personal information to untrusted machines. Delegate enforces rules at the proxy to detect and prevent session hijacking. This architecture leverages users' trusted mobile devices, e.g., cell phones, and requires no modification to Web servers or the untrusted machines. Delegate is designed to provide a balance between security and usability Ravi Chandra Jammalamadaka, Timothy W. van der Horst, Sharad Mehrotra, Kent E. Seamons, Nalini Venkatasubramanian |
ACSAC | 4 |
| 2005 | Adaptive trust negotiation and access controlabstractElectronic transactions regularly occur between business partners in separate security domains. Trust negotiation is an approach that provides an open authentication and access-control environment for such transactions, but it is vulnerable to malicious attacks leading to denial of service or leakage of sensitive information. This paper introduces an Adaptive Trust Negotiation and Access Control (ATNAC) framework to solve these problems. The framework combines two existing systems, TrustBuilder and GAA-API, to create a system with more flexibility and responsiveness to attack than either system currently provides. Tatyana Ryutov, B. Clifford Neuman, Travis Leithead, Kent E. Seamons |
SACMAT | 5 |
| 2005 | Short Paper: Thor - The Hybrid Online RepositoryabstractMobile environments create significant challenges for secure credential repositories. We examine these challenges with respect to existing repository practices and produce a set of requirements that a repository must meet in order to cope with the harshness of a mobile environment. We also present Thor (The hybrid online repository), a system that fulfills these requirements. Thor leverages preexisting local and remote repositories and enhances their usability and security through virtual organization, credential identifier obfuscation, and password management Timothy W. van der Horst, Kent E. Seamons |
SecureComm | 2 |
| 2004 | Concealing complex policies with hidden credentialsabstractHidden credentials are useful in protecting sensitive resource requests, resources, policies, and credentials. We propose a significant performance improvement when implementing hidden credentials using Boneh/Franklin Identity Based Encryption. We also propose a substantially improved secret splitting scheme for enforcing complex policies, and show how it improves concealment of policies from nonsatisfying recipients. Robert W. Bradshaw, Jason E. Holt, Kent E. Seamons |
CCS | 3 |
| 2004 | Content-triggered trust negotiationabstractThe focus of access control in client/server environments is on protecting sensitive server resources by determining whether or not a client is authorized to access those resources. The set of resources is usually static, and an access control policy associated with each resource specifies who is authorized to access the resource. In this article, we turn the traditional client/server access control model on its head and address how to protect the sensitive content that clients disclose to and receive from servers. Since client content is often dynamically generated at run-time, the usual approach of associating a policy with the resource (content) a priori does not work. We propose a general-purpose access control model designed to detect whenever sensitive information is being transmitted, and determine whether the sender or receiver is authorized. The model identifies sensitive content, maps the sensitive content to an access control policy, and establishes the trustworthiness of the sender or receiver before the sensitive content is disclosed or received. We have implemented the model within TrustBuilder, an architecture for negotiating trust between strangers based on properties other than identity. The implementation targets open systems, where clients and servers do not have preexisting trust relationships. The implementation is the first example of content-triggered trust negotiation. It currently supports access control for sensitive content disclosed by web and email clients. Adam Hess, Jason E. Holt, Jared Jacobson, Kent E. Seamons |
ACM Trans. Inf. Syst. Secur. | 4 |
| 2003 | An access control model for dynamic client-side contentabstractThe focus of access control in client/server environments is on protecting sensitive server resources by determining whether or not a client is authorized to access those resources. The set of resources are usually static, and an access control policy associated with each resource specifies who is authorized to access the resource. In this paper, we turn the traditional client/server access control model on its head, and address how to protect the sensitive content that clients disclose to servers. Since client content is dynamically generated at runtime, the usual approach of associating a policy with the resource (content) a priori does not work. In this paper, we propose an access control model for protecting client-side content that is dynamically generated and disclosed at runtime. Our model identifies sensitive content, maps the sensitive content to an access control policy, and establishes the trustworthiness of the server before disclosing the sensitive content to the server. The model targets open systems, where clients and servers do not have preexisting trust relationships. We have implemented the model within TrustBuilder, an architecture for negotiating trust between strangers based on properties other than identity. The implementation is the first example of content-triggered trust negotiation and currently supports access control for sensitive content disclosed by web and email clients. Adam Hess, Kent E. Seamons |
SACMAT | 2 |
| 2003 | Supporting structured credentials and sensitive policies through interoperable strategies for automated trust negotiationabstractBusiness and military partners, companies and their customers, and other closely cooperating parties may have a compelling need to conduct sensitive interactions on line, such as accessing each other's local services and other local resources. Automated trust negotiation is an approach to establishing trust between parties so that such interactions can take place, through the use of access control policies that specify what combinations of digital credentials a stranger must disclose to gain access to a local resource. A party can use many different strategies to negotiate trust, offering tradeoffs between the length of the negotiation, the amount of extraneous information disclosed, and the computational effort expended. To preserve parties' autonomy, each party should ideally be able to choose its negotiation strategy independently, while still being guaranteed that negotiations will succeed whenever possible---that the two parties' strategies will interoperate. In this paper we provide the formal underpinnings for that goal, by formalizing the concepts of negotiation protocols, strategies, and interoperation. We show how to model the information flow of a negotiation for use in analyzing strategy interoperation. We also present two large sets of strategies whose members all interoperate with one another, and show that these sets contain many practical strategies. We develop the theory for black-box propositional credentials as well as credentials with internal structure, and for access control policies whose contents are (respectively are not) sensitive. We also discuss how these results fit into TrustBuilder, our prototype system for trust negotiation. Ting Yu 0001, Marianne Winslett, Kent E. Seamons |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2002 | Advanced Client/Server Authentication in TLS
Adam Hess, Jared Jacobson, Hyrum Mills, Ryan Wamsley, Kent E. Seamons, Bryan Smith |
NDSS | 5 |
| 2001 | Interoperable strategies in automated trust negotiationabstractAutomated trust negotiation is an approach to establishing trust between strangers through the exchange of digital credentials and the use of access control policies that specify what combinations of credentials a stranger must disclose in order to gain access to each local service or credential. We introduce the concept of a trust negotiation protocol, which defines the ordering of messages and the type of information messages will contain. To carry out trust negotiation, a party pairs its negotiation protocol with a trust negotiation strategy that controls the exact content of the messages, i.e., which credentials to disclose, when to disclose them, and when to terminate a negotiation. There are a huge number of possible strategies for negotiating trust, each with different properties with respect to speed of negotiations and caution in giving out credentials and policies. In the autonomous world of the Internet, entities will want the freedom to choose negotiation strategies that meet their own goals, which means that two strangers who negotiate trust will often not use the same strategy. To date, only a tiny fraction of the space of possible negotiation strategies has been explored, and no two of the strategies proposed so far will interoperate. In this paper, we define a large set of strategies called the disclosure tree strategy (DTS) family. Then we prove that if two parties each choose strategies from the DTS family, then they will be able to negotiate trust as well as if they were both using the same strategy. Further, they can change strategies at any point during negotiation. We also show that the DTS family is closed, i.e., any strategy that can interoperate with every strategy in the DTS family must also be a member of the DTS family. We also give examples of practical strategies that belong to the DTS family and fit within the TrustBuilder architecture and protocol for trust negotiation. Ting Yu 0001, Marianne Winslett, Kent E. Seamons |
CCS | 3 |
| 2001 | Limiting the Disclosure of Access Control Policies during Automated Trust Negotiation
Kent E. Seamons, Marianne Winslett, Ting Yu 0001 |
NDSS | 1 |
| 1997 | Parallel Input/Output with Heterogeneous DisksabstractPanda is a high performance library for accessing large multidimensional array data on secondary storage of parallel platforms and networks of workstations. When using Panda as the I/O component of a scientific application, H3expresso, on the IBM SP2 at Cornell Theory Center, we found that some nodes are more powerful with respect to I/O than others, requiring the introduction of load balancing techniques to maintain high performance. We expect that heterogeneity will also be a big issue for DBMSs or parallel I/O libraries designed for scientific applications running on networks of workstations, and the methods of allocating data to servers in these environments will need to be upgraded to take heterogeneity into account, while still allowing users to exert control over data layout. We propose such an approach to load balancing, under which we respect the user's choice of high level disk layout, but introduce automatic subchunking. The use of subchunks allows us to divide the very large chunks typically specified by the user's disk layout into more manageable size units that can be allocated to I/O nodes in a manner that fairly distributes the load. We also present two techniques for allocating subchunks to nodes, static and dynamic, and evaluate their performance on the SP2. Szu-Wen Kuo, Marianne Winslett, Ying Chen 0001, Yong Cho, Mahesh Subramaniam, Kent E. Seamons |
SSDBM | 6 |
| 1996 | Performance Modeling for the Panda Array I/O LibraryabstractWe present an analytical performance model for Panda, a library for synchronized i/o of large multidimensional arrays on parallel and sequential platforms, and show how the Panda developers use this model to evaluate Panda's parallel i/o performance and guide future Panda development. The model validation shows that system developers can simplify performance analysis, identify potential performance bottlenecks, and study the design trade-offs for Panda on massively parallel platforms more easily than by conducting empirical experiments. More importantly, we show that the outputs of the performance model can be used to help make optimal plans for handling application i/o requests, the first step toward our long-term goal of automatically optimizing i/o request handling in Panda. Ying Chen 0001, Marianne Winslett, Szu-Wen Kuo, Yong Cho, Mahesh Subramaniam, Kent E. Seamons |
SC | 6 |
| 1996 | Persistent Array Access Using Server-Directed I/OabstractLarge multidimensional arrays are a common data type in high-performance scientific applications. Without special techniques for handling access to these arrays, I/O can easily become a large fraction of execution time for applications using these arrays, especially on parallel platforms. We show how to reduce the parallel I/O bottleneck for array data in closely-synchronized SPMD applications on distributed-memory platforms, through the use of server-directed I/O. This method allows array data requests on parallel platforms to be translated into long sequential disk reads and writes, while also minimizing the cost of rearranging data as they move between on-disk and in-memory schemas. We present experimental results from the implementation of server-directed I/O in Panda, showing that for I/O of large arrays, Panda utilizes nearly the maximum throughput of the underlying AIX file system on an IBM SP2. We also discuss Panda's user interface, an essential factor in Panda's high performance. Kent E. Seamons, Ying Chen 0001, Marianne Winslett, Yong Cho, Szu-Wen Kuo, Mahesh Subramaniam |
SSDBM | 1 |
| 1996 | Multidimensional array I/O in Panda 1.0
Kent E. Seamons, Marianne Winslett |
J. Supercomput. | 1 |
| 1995 | Server-Directed Collective I/O in PandaabstractWe present the architecture and implementation results for Panda 2.0, a library for input and output of multidimensional arrays on parallel and sequential platforms. Panda achieves remarkable performance levels on the IBM SP2, showing excellent scalability as data size increases and as the number of nodes increases, and provides throughputs close to the full capacity of the AIX file system on the SP2 we used. We argue that this good performance can be traced to Panda's use of server-directed i/o (a logical-level version of disk-directed i/o [Kotz94b]) to perform array i/o using sequential disk reads and writes, a very high level interface for collective i/o requests, and built-in facilities for arbitrary rearrangements of arrays during i/o. Other advantages of Panda's approach are ease of use, easy application portability, and a reliance on commodity system software. Kent E. Seamons, Ying Chen 0001, J. Jozwiak, Marianne Winslett |
SC | 1 |
| 1994 | An efficient abstract interface for multidimensional array I/OabstractOur research seeks to provide scientific programmers with simpler, more abstract interfaces for accessing persistent multidimensional arrays, and to produce advanced I/O libraries supporting more efficient layout alternatives for these arrays on disk and in main memory. We report on our experience to date applying these techniques to applications in computational fluid dynamics in the areas of checkpoint/restart, output data, and visualization. In the applications we have studied, we find that a simple, abstract interface can be used to insulate programmers from physical storage implementation details, while providing improved I/O performance at the same time. For example, we found that the use of "chunked" physical schemas for arrays gave approximately a factor of 10 improvement in time step output performance on the Intel iPSC/860.> Kent E. Seamons, Marianne Winslett |
SC | 1 |
| 1994 | Physical Schemas for Large Multidimensional Arrays in Scientific Computing ApplicationsabstractWe describe physical schemas for storing multidimensional arrays on disk. We have developed an i/o library supporting these schemas that provides an abstract interface shielding scientific application developers from physical storage details. Our library has resulted in simplified programming and improved i/o performance in the applications we have studied.> Kent E. Seamons, Marianne Winslett |
SSDBM | 1 |