Modelling and Verification of Secure Exams
暫譯: 安全考試的建模與驗證

Giustolisi, Rosario

  • 出版商: Springer
  • 出版日期: 2019-01-04
  • 售價: $2,320
  • 貴賓價: 9.5$2,204
  • 語言: 英文
  • 頁數: 133
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 3030097897
  • ISBN-13: 9783030097899
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

In this book the author introduces a novel approach to securing exam systems. He provides an in-depth understanding, useful for studying the security of exams and similar systems, such as public tenders, personnel selections, project reviews, and conference management systems.

After a short chapter that explains the context and objectives of the book, in Chap. 2 the author introduces terminology for exams and the foundations required to formulate their security requirements. He describes the tasks that occur during an exam, taking account of the levels of detail and abstraction of an exam specification and the threats that arise out of the different exam roles. He also presents a taxonomy that classifies exams by types and categories. Chapter 3 contains formal definitions of the authentication, privacy, and verifiability requirements for exams, a framework based on the applied pi-calculus for the specification of authentication and privacy, and a more abstract approach based on set-theory that enables the specification of verifiability. Chapter 4 describes the Huszti-Pethő protocol in detail and proposes a security enhancement. In Chap. 5 the author details Remark , a protocol for Internet-based exams, discussing its cryptographic building blocks and some security considerations. Chapter 6 focuses on WATA, a family of computer-assisted exams that employ computer assistance while keeping face-to-face testing. The chapter also introduces formal definitions of accountability requirements and details the analysis of a WATA protocol against such definitions. In Chaps. 4, 5, and 6 the author uses the cryptographic protocol verifier ProVerif for the formal analyses. Finally, the author outlines future work in Chap. 7.

The book is valuable for researchers and graduate students in the areas of information security, in particular for people engaged with exams or protocols.

商品描述(中文翻譯)

在本書中,作者介紹了一種新穎的考試系統安全保障方法。他提供了深入的理解,對於研究考試及類似系統的安全性非常有用,例如公共招標、人員選拔、專案審查和會議管理系統。

在簡短的章節中,作者解釋了本書的背景和目標,接著在第二章中介紹了考試的術語以及制定其安全需求所需的基礎知識。他描述了考試過程中發生的任務,考慮到考試規範的詳細程度和抽象層次,以及不同考試角色所帶來的威脅。他還提出了一個分類法,根據類型和類別對考試進行分類。第三章包含了考試的身份驗證、隱私和可驗證性要求的正式定義,基於應用π演算的身份驗證和隱私規範框架,以及基於集合論的更抽象的方法,使得可驗證性的規範成為可能。第四章詳細描述了Huszti-Pethő協議並提出了一項安全增強。在第五章中,作者詳細介紹了Remark,一種基於互聯網的考試協議,討論其加密構建塊和一些安全考量。第六章專注於WATA,一系列在保持面對面測試的同時使用計算機輔助的考試。該章還介紹了問責要求的正式定義,並詳細分析了WATA協議與這些定義的對比。在第四、第五和第六章中,作者使用加密協議驗證器ProVerif進行正式分析。最後,作者在第七章中概述了未來的工作。

本書對於信息安全領域的研究人員和研究生具有重要價值,特別是對於從事考試或協議相關工作的人士。

作者簡介

Rosario Giustolisi is an assistant professor at the IT University of Copenhagen. He received his PhD from the University of Luxembourg where he worked on a formal framework for the security analysis of exam protocols and on the design of protocols for computer-assisted and Internet-based exams. As a postdoc at SICS RISE and a member of the Security Lab in Lund, he investigated group-based authentication mechanisms for future 5G networks. His research interests include the modeling and formal analysis of secure network protocols and the sociotechnical security aspects of real-world systems.

作者簡介(中文翻譯)

羅薩里奧·吉斯托利西(Rosario Giustolisi)是哥本哈根資訊科技大學的助理教授。他在盧森堡大學獲得博士學位,研究主題為考試協議的安全分析的正式框架,以及計算機輔助和基於互聯網的考試協議的設計。作為瑞典資訊與計算科學研究所(SICS RISE)的博士後研究員及隆德安全實驗室的成員,他研究了未來5G網絡的基於群組的身份驗證機制。他的研究興趣包括安全網絡協議的建模與正式分析,以及現實系統的社會技術安全方面。