Publications

Consequence Overview (1,2 MB)

A. Arenas, Usage Control for Collaborative Systems, High Integrity Systems Engineering Seminar, University of York, November 2008. Link

Arenas A., Benjamin Aziz, Juan Bicarregui and Michael Wilson, An Event-B Approach to data sharing agreements, 8th International Conference on Integrated Formal Methods (iFM 2010), Oct 2010, Nancy, France. Link

A. Arenas, M. D, Wilson, Contracts as Trust Substitutes in Collaborative Business, IEEE Computer, 41 (7) 80-83, 2008. Link

B. Aziz, Detecting Man-in-the-Middle Attacks by Precise Timing, The Third International Conference on Emerging Security Information, Systems and Technologies (SecurWare 2009), Athens, Greece, June 18-23, 2009. Link

B. Aziz, A. Arenas, F. Martinelli, I. Matteucci, P. Mori, Controlling usage in business process workflows through fine-grained security policies. In TrustBus '08, pages 100-117, 2008. Link

Aziz B., Alvaro Arenas and Michael Wilson, Model-based Refinement of Security Policies in Collaborative Virtual Organisations, International Symposium on Engineering Secure Software and Systems (ESSoS11), Feb 2011, Madrid, Spain (to appear).

S. Barker, D. Chadwick, J. Crampton, E. Lupu, B. M. Thuraisingham, Panel Session: What Are the Key Challenges in Distributed Security? 2nd IFIP WG 11.3 Working Conference on Data and Applications Security, London, UK, July 13-16, 2008, pp. 219-221. Link

Colombo M., Fabio Martinelli, Ilaria Matteucci, Marinella Petrocchi. “Context-Aware Analysis of Data Sharing Agreements” to appear in Proceedings of EuroCat10, 2010. Link

S. Crompton, B Aziz, M. Wilson, Sharing scientific data : scenarios and challenges, W3C Workshop on Access Control Application Scenarios, Luxembourg, Nov 17-18, 2009. Link

J. Claessens. Consequence vision and research, 4th July 2008, EC TG6 Trust and Security meeting, 2008

G. Costa, F. Martinelli, P. Mori, C. Schaefer, T. Walter. Runtime monitoring for next generation Java ME platform Computer & Security (COSE), 2009. Link

G. Costa, P. Degano, F. Martinelli, Secure Service Composition with Symbolic Effects. In 4th South-East European Workshop on Formal Methods (SEEFM), 2009. Link

Costa G., F. Martinelli, P. Mori, C. Schaefer and T. Walter. “Runtime monitoring for next generation Java ME platform”. In Computers & Security. Vol 29 N.1. 2010 Link

Costa G., P.Degano and F.Martinelli. “Modular Plans for Secure Service Composition”. In Joint Workshop on Automated Reasoning for Security Protocol Analysis and Issues in the Theory of Security, 2010. Link

R. Gorrieri, F. Martinelli, I. Matteucci, Towards information flow properties for distributed systems. Proceedings of the 3rd VODCA Views On Designing Complex Architectures, 2008. Link

V. Gowadia, E. Scalavino, E. Lupu, A. Orlov, D. Starostin, Secure Cross-Domain Data Sharing Architecture for Crisis Management, ACM Workshop on Digital Rights Management, Chicago, USA, October 2010. Link to extended version

Ion M., G. Russello, and B. Crispo, Supporting Publication and Subscription Confidentiality in Pub/Sub Networks Proceeding of the 6th International ICST Conference on Security and Privacy in Communication Networks (SecureComm 2010), Singapore, September 2010.

Krautsevich L., A. Lazouski, F. Martinelli, A. Yautsiukhin. "Risk-Aware Usage Decision Making in Highly Dynamic Systems", In Proceedings of ICIMP '10, IEEE, 2010. Link

Krautsevich L., A. Lazouski, F. Martinelli, A. Yautsiukhin. "Influence of Attribute Freshness on Decision Making in Usage Control" to appear in Proceedings of STM '10, Springer, 2010.

Krautsevich L., A. Lazouski, F. Martinelli, P. Mori, A. Yautsiukhin. Usage Control, risk and trust, in Proc. of TRUSTBUS 2010, LNCS. Link

Krautsevich L., F. Martinelli, A. Yautsiukhin. "Formal approach to security metrics. What does "more secure" mean for you?", In Proceedings of MeSSa '10, ACM, 2010. Link

E. Lupu, Keynote address: Consequence vision and approach, 1st International Workshop on Middleware Security (MidSec 2008), Leuven, Belgium, December 2, 2008. Link

F. Martinelli, Invited presentation: Identity and Trust - Usage control, Future Internet Conference, Prague, 2009

F. Martinelli, EC-ERCIM Seminar on ICT Security: "Engineering Secure Complex Software Systems and Services", Brussels, 16th October, 2008. Link

F. Martinelli, I. Matteucci. Idea: Action Refinement for Security Properties Enforcement. In F. Massacci, S.T. Redwine Jr., and N. Zannone (Eds.): ESSoS 2009, LNCS 5429, pp. 37--42, 2009. Springer-Verlag Berlin Heidelberg. Link

Martinelli F., Invited Talk: TRUSTBUS 2010 conference, Bilbao 30 August 2010 Risk, trust and usage control.

Martinelli F., Lectures at the FOSAD research school on Usage Control, Sept 2010.

Martinelli F. and I. Matteucci. "A framework for automatic generation of security controller". Accepted to the STVR Journal. June 2010.

Martini B., P. Mori, F. Martinelli, A. Lazouski, P. Castoldi. Time-continuous Authorization of Network Resources based on Usage Control. To appear in Proc. of 21st Tyrrhenian Workshop on Digital Communications: Trustworthy Internet, Springer 2010.

I. Matteucci, M. Petrocchi, M. L. Sbodio, CNL4DSA – a Controlled Natural Language for Data Sharing Agreements. In proceedings of SAC2010, Privacy on the Web track, 2010. Link

A. Orlov, Project Consequence, Science and Technology Magazine, Issue 1, pp. 62-63, PSCA International Ltd., 2008. Link

G. Russello, N. Dulay, xDUCON: Coordinating Usage Control Policies in Distributed Domains, Proceedings of 3rd IEEE International Conference on Network & System Security (NSS 2009), Gold Coast, Australia, October 2009. Link

G. Russello, N. Dulay, xDUCON: Cross Domain Usage Control through Shared Data Spaces, Proceedings of 2009 IEEE Symposium on Policies for Distributed Systems and Networks (Policy 09) short paper, London, UK, July, 2009. Link

G. Russello, E. Scalavino, Exploiting Node Mobility for Coordinating
Data Usage in Crisis Scenarios, Proceeding of the 4th Workshop in Information Security Theory and Practices, Passau, Germany, April, 2010.
Link

Russello G. and E. Scalavino, Exploiting Node Mobility for Coordinating Data Usage in Crisis Scenarios Proceeding of the 4th Workshop in Information Security Theory and Practices, Passau, Germany, April, 2010. Link

Russello G., E. Scalavino, N. Dulay, and E. Lupu, Coordinating Data Usage Control in Loosely-Connected Networks Proceeding of the 2010 IEEE Symposium on Policies for Distributed Systems and Networks (Policy 10), Fairfax, Virginia, US, July 2010.

E. Scalavino, G. Russello, R. Ball, V. Gowadia, E. Lupu, An Opportunistic Authority Evaluation Scheme for Data Security in Crisis Management Scenarios. Proceedings of 5th ACM Symposium on Information, Computer and Communication Security (ASIACCS 2010), Beijing, China, April 13–16, 2010. Link

E. Scalavino, V. Gowadia, E. Lupu, PAES: Policy-based Authority Evaluation Scheme. DBSec 2009. Montreal, Canada, July 2009. Link

Scalavino E., V. Gowadia, and E. C. Lupu. A Labelling System for Derived Data Control. DBSec 2010. Link

Scalavino E., V. Gowadia, R. Ball and E. C. Lupu. Mobile PAES: Devolved Authority for Policy Evaluation in Crisis Management Scenarios. IEEE Policy Symposium 2010.

Scalavino E., Giovanni Russello, Rudi Ball et al. (2010) An opportunistic authority evaluation scheme for data security in crisis management scenarios, 157. In Proceedings of the 5th ACM Symposium on Information, Computer and Communications Security - ASIACCS '10.

A. U. Schmidt, A. Leicher, I. Cha, Scaling Concepts between Trust and Enforcement. To appear in, Zheng Yan (Ed.), Trust Modeling and Management in Digital Environments: From Social Concept to System Development. IGI Global Publishing, 2009

M. Wilson, Security Policies in Scientific Data Sharing Agreements, UK e-Science All Hands Meeting, Edinburgh, UK, 2008. Link