More Info
Contributions to Internal Research Projects
- FORMULA – Modeling Foundations: FORMULA (Formal Modeling Using Logic Programming and Analysis) is a modern formal specification language targeting model-based development (MBD). It is based on algebraic data types (ADTs) and strongly-typed constraint logic programming (CLP), which support concise specifications of abstractions and model transformations. Around this core is a set of composition operators for composing specifications in the style of MBD.
- Data Usage and Privacy Policies: This project involves developing a new language for specifying data usage and privacy policies in the context of distributed web services, using SecPAL as a starting point. The new language lets services specify how they will handle user data and to which third parties this data may be disclosed. On the user side, the language specifies restrictions and obligations on data usage and forwarding.
Interests
Research
- Applications of logical inference to policies and management.
- Specification and enforcement of privacy. Usage control in terms of authorizations, delegations and obligations.
- Credentials combining unlinkability and non-transferability
- Proof of proximity and location
Engineering
- Scalable application of inference engines to real problems.
- Security of distributed systems (Web Services, STS, WCF)
- Secure software engineering, threat modeling.
- Project management, agile development.
- Other interests: Trusted Computing Platforms, Rights Managements.
Collaborative Research Projects
- PrimeLife (opens in new tab): Bringing sustainable privacy and identity management to future networks and services
- SeCSE (opens in new tab): Service Centric System Engineering
- FIDIS (opens in new tab): Future of Identity in the Information Society (Network of Excellence)
- MOSQUITO: Mobile Workers’ Secure Business Applications in Ubiquitous Environments (STREP FP6)
- WiTness (opens in new tab): WIreless Trust for mobile busiNESS (STREP FP5)
Program Committees
- SAR-SSI (opens in new tab) Conf. on Network Architectures and Information Systems Security (2007-2008, 2010-2012).
- SEC 2010 (opens in new tab), 25th IFIP International Information Security Conference – Security & Privacy − Silver Linings in the Cloud.
- W3C Workshop on Access Control Application Scenarios (opens in new tab), November 2009 — Luxembourg.
- Privacy on the Web special track at SAC 2010 (opens in new tab)
- PESOS 2009 (opens in new tab), Principles of Engineering Service Oriented Systems.
- SecureComm 2007 (opens in new tab), International Conference on Security and Privacy in Communication Networks.
- CANS’06 (opens in new tab), International Conference on Cryptology and Network Security.
- ESAS 2005, European Workshop on Security and Privacy in Ad hoc and Sensor Networks.