English
Related papers

Related papers: Characterizing the Root Landscape of Certificate T…

200 papers

A large user base relies on software updates provided through package managers. This provides a unique lever for improving the security of the software update process. We propose a transparency system for software updates and implement it…

Cryptography and Security · Computer Science 2017-11-21 Benjamin Hof , Georg Carle

Recent measurements of the Windows code-signing certificate ecosystem have highlighted various forms of abuse that allow malware authors to produce malicious code carrying valid digital signatures. However, the underground trade that allows…

Cryptography and Security · Computer Science 2019-02-15 Kristián Kozák , Bum Jun Kwon , Doowon Kim , Tudor Dumitraş

Blockchains offer a useful abstraction: a trustworthy, decentralized log of totally ordered transactions. Traditional blockchains have problems with scalability and efficiency, preventing their use for many applications. These limitations…

Distributed, Parallel, and Cluster Computing · Computer Science 2018-06-20 Isaac Sheff , Xinwen Wang , Andrew C. Myers , Robbert van Renesse

Typical users are known to use and reuse weak passwords. Yet, as cybersecurity concerns continue to rise, understanding the password practices of software developers becomes increasingly important. In this work, we examine developers'…

Software Engineering · Computer Science 2023-07-04 Nikolaos Lykousas , Constantinos Patsakis

Products certified under security certification frameworks such as Common Criteria undergo significant scrutiny during the costly certification process. Yet, critical vulnerabilities, including private key recovery (ROCA, Minerva,…

Cryptography and Security · Computer Science 2024-07-02 Adam Janovsky , Jan Jancar , Petr Svenda , Łukasz Chmielewski , Jiri Michalik , Vashek Matyas

Managed TLS has become a common approach for deploying HTTPS, with platforms generating and storing private keys and automating certificate issuance on behalf of domain operators. This model simplifies operational management but shifts…

Cryptography and Security · Computer Science 2025-12-09 Daniyal Ganiuly , Nurzhau Bolatbek , Assel Smaiyl

Federated learning (FL) provides an emerging approach for collaboratively training semantic encoder/decoder models of semantic communication systems, without private user data leaving the devices. Most existing studies on trustworthy FL aim…

Cryptography and Security · Computer Science 2023-02-02 Gaolei Li , Yuanyuan Zhao , Yi Li

Auditing plays a pivotal role in the development of trustworthy AI. However, current research primarily focuses on creating auditable AI documentation, which is intended for regulators and experts rather than end-users affected by AI…

Computers and Society · Computer Science 2023-05-31 Nicolas Scharowski , Michaela Benk , Swen J. Kühne , Léane Wettstein , Florian Brühlmann

Privacy enhancing technologies, or PETs, have been hailed as a promising means to protect privacy without compromising on the functionality of digital services. At the same time, and partly because they may encode a narrow conceptualization…

Cryptography and Security · Computer Science 2023-12-06 Ero Balsa , Yan Shvartzshnaider

Contemporary IoT environments, such as smart buildings, require end-users to trust data-capturing rules published by the systems. There are several reasons why such a trust is misplaced --- IoT systems may violate the rules deliberately or…

Cryptography and Security · Computer Science 2019-08-28 Nisha Panwar , Shantanu Sharma , Guoxi Wang , Sharad Mehrotra , Nalini Venkatasubramanian , Mamadou H. Diallo , Ardalan Amiri Sani

In recent years the cybersecurity policy debate in Washington has been dominated by calls for greater information sharing within the private sector, and between the private sector and the federal government. The passage of the Cybersecurity…

Computers and Society · Computer Science 2018-06-01 Elaine M. Sedenberg , James X. Dempsey

There is often a fundamental mismatch between programmable privacy frameworks, on the one hand, and the ever shifting privacy expectations of computer system users, on the other hand. Based on the theory of contextual integrity (CI), our…

Cryptocurrencies (CCs) become more interesting for institutional investors' strategic asset allocation and will be a fixed component of professional portfolios in future. This asset class differs from established assets especially in terms…

Portfolio Management · Quantitative Finance 2022-05-25 Christoph J. Börner , Ingo Hoffmann , Jonas Krettek , Lars M. Kürzinger , Tim Schmitz

Blockchain technology promises to democratize finance and promote social equity through decentralization, but questions remain about whether current implementations advance or hinder these goals. Through a mixed-methods study combining…

Human-Computer Interaction · Computer Science 2025-05-13 Faisal Haque Bappy , EunJeong Cheon , Tariqul Islam

Confidentiality, integrity protection, and high availability, abbreviated to CIA, are essential properties for trustworthy data systems. The rise of cloud computing and the growing demand for multiparty applications however means that…

The integration of Generative Artificial Intelligence (GenAI) in healthcare is impeded by significant security challenges unaddressed by traditional frameworks, precisely the data-in-use gap where sensitive patient data and proprietary AI…

Cryptography and Security · Computer Science 2025-11-18 Adaobi Amanna , Ishana Shinde

The goal of this paper is to propose a blockchain-based platform to enhance transparency and traceability of cybersecurity certification information motivated by the recently adopted EU Cybersecurity Act. The proposed platform is generic…

Cryptography and Security · Computer Science 2019-09-17 Ricardo Neisse , José L. Hernández-Ramos , Sara N. Matheu , Gianmarco Baldini , Antonio Skarmeta

Kettle is an attested build system that produces cryptographically verifiable provenance for software built inside Trusted Execution Environments (TEEs). A Kettle build records the source commit, dependency set, toolchain, build…

Cryptography and Security · Computer Science 2026-05-12 Amean Asad , André Arko

Local certification consists in assigning labels (called \emph{certificates}) to the nodes of a network to certify a property of the network or the correctness of a data structure distributed on the network. The verification of this…

Distributed, Parallel, and Cluster Computing · Computer Science 2022-02-15 Nicolas Bousquet , Laurent Feuilloley , Théo Pierron

We define a method how digital ecosystems (including data spaces) may autonomously define and "advertise" credentials they issue or they trust in the form of so-called ecosystem trust profiles. An ecosystem trust profile collects all…

Cryptography and Security · Computer Science 2026-03-25 Christoph F. Strnadl