Tamper-Resistant Ubiquitous Data Management - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Article Dans Une Revue International Journal of Computer Systems Science & Engineering Année : 2005

Tamper-Resistant Ubiquitous Data Management

Résumé

Chip-Secured XML Access (C-SXA) is a versatile and tamper-resistant XML-based Access Right Controller embedded in a smart card. C-SXA can be used either to protect the privacy of onboard personal data or to control the flow of data extracted from an external source. Tamperresistance is inherited from the smart card for on-board data or achieved using cryptographic techniques for external data. C-SXA can provide different views of the same on-board or external data depending on the user or application accessing them. Moreover, access control on external data can benefit from on-board storage to enforce powerful, context dependant access control policies. These two features allow C-SXA to address a wide range of applications such as secure portable folders, data sharing among a community of users, parental control and Digital Right Management, in a more secure and accurate way than existing technologies. This work relates the C-SXA experience. We first motivate the interest of the approach and describe different usage scenarios. We then present the internals of C-SXA and show how they tackle the smart card's hardware limitations. Finally, we demonstrate its viability showing how our smart card engine can be integrated in a distributed architecture including the smart card, the server and the user terminal, making the complete chain from the user to the data secure
Fichier principal
Vignette du fichier
BDP05a.pdf (526.71 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

inria-00316020 , version 1 (02-09-2008)

Identifiants

  • HAL Id : inria-00316020 , version 1

Citer

Luc Bouganim, François Dang Ngoc, Philippe Pucheral. Tamper-Resistant Ubiquitous Data Management. International Journal of Computer Systems Science & Engineering, 2005, 20 (2). ⟨inria-00316020⟩
125 Consultations
165 Téléchargements

Partager

Gmail Facebook X LinkedIn More