Skip to main content

Showing 1–4 of 4 results for author: Focardi, R

.
  1. arXiv:2404.09518  [pdf, ps, other

    cs.CR

    Bridging the Gap: Automated Analysis of Sancus

    Authors: Matteo Busi, Riccardo Focardi, Flaminia Luccio

    Abstract: Techniques for verifying or invalidating the security of computer systems have come a long way in recent years. Extremely sophisticated tools are available to specify and formally verify the behavior of a system and, at the same time, attack techniques have evolved to the point of questioning the possibility of obtaining adequate levels of security, especially in critical applications. In a recent… ▽ More

    Submitted 15 April, 2024; originally announced April 2024.

    Comments: To appear at IEEE CSF 2024

  2. A Formally Verified Configuration for Hardware Security Modules in the Cloud

    Authors: Riccardo Focardi, Flaminia L. Luccio

    Abstract: Hardware Security Modules (HSMs) are trusted machines that perform sensitive operations in critical ecosystems. They are usually required by law in financial and government digital services. The most important feature of an HSM is its ability to store sensitive credentials and cryptographic keys inside a tamper-resistant hardware, so that every operation is done internally through a suitable API,… ▽ More

    Submitted 28 September, 2021; originally announced September 2021.

    Comments: To appear at ACM CCS 2021

  3. arXiv:2001.10405  [pdf, ps, other

    cs.CR

    Language-Based Web Session Integrity

    Authors: Stefano Calzavara, Riccardo Focardi, Niklas Grimm, Matteo Maffei, Mauro Tempesta

    Abstract: Session management is a fundamental component of web applications: despite the apparent simplicity, correctly implementing web sessions is extremely tricky, as witnessed by the large number of existing attacks. This motivated the design of formal methods to rigorously reason about web session security which, however, are not supported at present by suitable automated verification techniques. In th… ▽ More

    Submitted 2 June, 2020; v1 submitted 28 January, 2020; originally announced January 2020.

  4. arXiv:1806.09111  [pdf, other

    cs.CR

    WPSE: Fortifying Web Protocols via Browser-Side Security Monitoring

    Authors: Stefano Calzavara, Riccardo Focardi, Matteo Maffei, Clara Schneidewind, Marco Squarcina, Mauro Tempesta

    Abstract: We present WPSE, a browser-side security monitor for web protocols designed to ensure compliance with the intended protocol flow, as well as confidentiality and integrity properties of messages. We formally prove that WPSE is expressive enough to protect web applications from a wide range of protocol implementation bugs and web attacks. We discuss concrete examples of attacks which can be prevente… ▽ More

    Submitted 24 June, 2018; originally announced June 2018.