<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:prism="http://prismstandard.org/namespaces/1.2/basic/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns="http://purl.org/rss/1.0/">
<channel rdf:about="http://www.inderscience.com/current_issue_rss/index.php?journal=ijitst">
<title>Most recent issue published online for the International Journal of Internet Technology and Secured Transactions.</title>
<description>International Journal of Internet Technology and Secured Transactions</description>
<link>http://www.inderscience.com/browse/index.php?journalID=190&amp;year=2012&amp;vol=4&amp;issue=1</link>
<dc:publisher>Inderscience Publishers Ltd</dc:publisher>
<dc:language>en-uk</dc:language>
<prism:publicationName>International Journal of Internet Technology and Secured Transactions</prism:publicationName>
<prism:issn>1748-569X</prism:issn>
<prism:eIssn>1748-5703</prism:eIssn>
<prism:copyright>&#169; 2012 Inderscience Publishers Ltd</prism:copyright>
<prism:rightsAgent>editor@inderscience.com</prism:rightsAgent>
<image rdf:resource="https://www.inderscience.com/images/files/coverImgs/ijitst_scoverijitst.jpg" />
<items>
<rdf:Seq>
<rdf:li rdf:resource="http://dx.doi.org/10.1504/IJITST.2012.045160" />
<rdf:li rdf:resource="http://dx.doi.org/10.1504/IJITST.2012.045161" />
<rdf:li rdf:resource="http://dx.doi.org/10.1504/IJITST.2012.045147" />
<rdf:li rdf:resource="http://dx.doi.org/10.1504/IJITST.2012.045149" />
<rdf:li rdf:resource="http://dx.doi.org/10.1504/IJITST.2012.045150" />
<rdf:li rdf:resource="http://dx.doi.org/10.1504/IJITST.2012.045153" />
</rdf:Seq>
</items>
</channel>
<image rdf:about="https://www.inderscience.com/images/files/coverImgs/ijitst_scoverijitst.jpg">
<title>International Journal of Internet Technology and Secured Transactions</title>
<url>https://www.inderscience.com/images/files/coverImgs/ijitst_scoverijitst.jpg</url>
<link>http://www.inderscience.com/browse/index.php?journalID=190&amp;year=2012&amp;vol=4&amp;issue=1</link>
</image>
<item rdf:about="http://dx.doi.org/10.1504/IJITST.2012.045160">
<title>Secret image sharing with reversible capabilities</title>
<link>http://www.inderscience.com/link.php?id=45160</link>
<description>Secret image sharing is a technique to share a secret image among n participants using Shamir&#39;s secret sharing scheme. Secret image is revealed if any k of the n shares is processed according to the scheme. Research reported in the literature is focused on improving known issues of the method. Reconstruction without distortion, reducing the size expansion of the share images, improving stego image quality and enhancing authentication ability of the method are some of the issues. Recovering cover images after the revealing procedure is an important issue. In 2009, Wu et al. proposed a technique based on reversible steganography to solve this problem. A location map is used to recover cover images, which needs extra information. The proposed method outlined in this paper does not need any information except shares to recover cover images. In addition, visual quality of the shares or the peak signal to noise ratio &#40;PSNR&#41; values of stego images are improved which is used to demonstrate the effectiveness of the method. Experimental results indicate a 3 dB PSNR improvement on the average compared to Wu et al.&#39;s method.</description>
<content:encoded><![CDATA[<p><a href="http://www.inderscience.com/link.php?id=45160"><b>Secret image sharing with reversible capabilities</b></A><br />Guzin Ulutas; Mustafa Ulutas; Vasif V. Nabiyev<br /><i>International Journal of Internet Technology and Secured Transactions, Vol. 4, No. 1 (2012) pp. 1 - 11</i><br />Secret image sharing is a technique to share a secret image among n participants using Shamir&#39;s secret sharing scheme. Secret image is revealed if any k of the n shares is processed according to the scheme. Research reported in the literature is focused on improving known issues of the method. Reconstruction without distortion, reducing the size expansion of the share images, improving stego image quality and enhancing authentication ability of the method are some of the issues. Recovering cover images after the revealing procedure is an important issue. In 2009, Wu et al. proposed a technique based on reversible steganography to solve this problem. A location map is used to recover cover images, which needs extra information. The proposed method outlined in this paper does not need any information except shares to recover cover images. In addition, visual quality of the shares or the peak signal to noise ratio &#40;PSNR&#41; values of stego images are improved which is used to demonstrate the effectiveness of the method. Experimental results indicate a 3 dB PSNR improvement on the average compared to Wu et al.&#39;s method.</p>]]></content:encoded>
<dc:identifier>10.1504/IJITST.2012.045160</dc:identifier>
<dc:source>International Journal of Internet Technology and Secured Transactions, Vol. 4, No. 1 (2012) pp. 1 - 11</dc:source>
<dc:creator>Guzin Ulutas; Mustafa Ulutas; Vasif V. Nabiyev</dc:creator>
<dc:contributor>Department of Computer Engineering, Karadeniz Technical University, Trabzon, 61080, Turkey. &#39; Department of Computer Engineering, Karadeniz Technical University, Trabzon, 61080, Turkey. &#39; Department of Computer Engineering, Karadeniz Technical University, Trabzon, 61080, Turkey</dc:contributor>
<dc:subject>secret image sharing</dc:subject>
<dc:subject>peak signal to noise ratio</dc:subject>
<dc:subject>PSNR</dc:subject>
<dc:subject>peak SNR</dc:subject>
<dc:subject>reversible steganography</dc:subject>
<dc:subject>secret images</dc:subject>
<dc:subject>image quality</dc:subject>
<dc:subject>authentication.</dc:subject>
<dc:date>2012-01-29T23:20:50-05:00</dc:date>
<prism:volume>4</prism:volume>
<prism:number>1</prism:number>
<prism:startingPage>1</prism:startingPage>
<prism:endingPage>11</prism:endingPage>
<prism:publicationDate>2012-01-29T23:20:50-05:00</prism:publicationDate>
</item>
<item rdf:about="http://dx.doi.org/10.1504/IJITST.2012.045161">
<title>Differential power analysis&#58; a serious threat for FPGA security</title>
<link>http://www.inderscience.com/link.php?id=45161</link>
<description>Although cryptosystem designers frequently assume that secret parameters will be manipulated in closed reliable computing environments, Kocher et al. reported in 1998 that microchips leak information correlated with the data handled and introduced a new kind of attacks which were radically different from software and algorithmic attacks. These attacks use leaking or side&#45;channel information, like power consumption data, electromagnetic emanations or computing time to recover the secret key. While FPGAs are becoming increasingly popular for cryptographic applications, there are only a few articles that assess their vulnerability to such attacks. This paper describes the principles of differential power analysis &#40;DPA&#41; attack and also illustrates a practical and successful implementation of this attack against an FPGA implementation of the advanced encryption standard &#40;AES&#41; algorithm. The results obtained in this work clearly demonstrate that DPA is a serious threat against realisation of encryption algorithms on SRAM&#45;based FPGAs without effective countermeasures.</description>
<content:encoded><![CDATA[<p><a href="http://www.inderscience.com/link.php?id=45161"><b>Differential power analysis&#58; a serious threat for FPGA security</b></A><br />Massoud Masoumi<br /><i>International Journal of Internet Technology and Secured Transactions, Vol. 4, No. 1 (2012) pp. 12 - 25</i><br />Although cryptosystem designers frequently assume that secret parameters will be manipulated in closed reliable computing environments, Kocher et al. reported in 1998 that microchips leak information correlated with the data handled and introduced a new kind of attacks which were radically different from software and algorithmic attacks. These attacks use leaking or side&#45;channel information, like power consumption data, electromagnetic emanations or computing time to recover the secret key. While FPGAs are becoming increasingly popular for cryptographic applications, there are only a few articles that assess their vulnerability to such attacks. This paper describes the principles of differential power analysis &#40;DPA&#41; attack and also illustrates a practical and successful implementation of this attack against an FPGA implementation of the advanced encryption standard &#40;AES&#41; algorithm. The results obtained in this work clearly demonstrate that DPA is a serious threat against realisation of encryption algorithms on SRAM&#45;based FPGAs without effective countermeasures.</p>]]></content:encoded>
<dc:identifier>10.1504/IJITST.2012.045161</dc:identifier>
<dc:source>International Journal of Internet Technology and Secured Transactions, Vol. 4, No. 1 (2012) pp. 12 - 25</dc:source>
<dc:creator>Massoud Masoumi</dc:creator>
<dc:contributor>Islamshahr Azad University, Islamshahr Branch, P.O. Box&#58; 33135&#45;369, Sayad Shirazi Ave., Namaz Sqr., Tehran, Iran</dc:contributor>
<dc:subject>side&#45;channel attacks</dc:subject>
<dc:subject>differential power analysis</dc:subject>
<dc:subject>FPGA implementation</dc:subject>
<dc:subject>advanced encryption standard</dc:subject>
<dc:subject>AES algorithm</dc:subject>
<dc:subject>cryptography</dc:subject>
<dc:subject>FPGA vulnerability</dc:subject>
<dc:subject>power consumption</dc:subject>
<dc:subject>electromagnetic emanations</dc:subject>
<dc:subject>computing time</dc:subject>
<dc:subject>field programmable gate arrays</dc:subject>
<dc:subject>SRAM</dc:subject>
<dc:subject>static RAM</dc:subject>
<dc:subject>random access memory.</dc:subject>
<dc:date>2012-01-29T23:20:50-05:00</dc:date>
<prism:volume>4</prism:volume>
<prism:number>1</prism:number>
<prism:startingPage>12</prism:startingPage>
<prism:endingPage>25</prism:endingPage>
<prism:publicationDate>2012-01-29T23:20:50-05:00</prism:publicationDate>
</item>
<item rdf:about="http://dx.doi.org/10.1504/IJITST.2012.045147">
<title>Cultural and organisational commitment in the context of e&#45;banking</title>
<link>http://www.inderscience.com/link.php?id=45147</link>
<description>Although information security is critical for organisations to survive, a number of studies continue to report incidents of critical information loss. To this end, there is still an increasing interest to study information security from a non&#45;technical perspective. In doing so, this research focuses on the effect of strong corporate cultures and organisational commitment as important aspects in managing information security through e&#45;banking. That is, manipulating more effectively e&#45;banking security development and management within organisations. Achieving the required level of e&#45;banking security within organisations usually requires more than security awareness and control but also a better understanding of the organisations&#39; culture in which e&#45;banking security measures are developed and tailored to. In effect, organisations may have a clearer insight into how to commit more effectively to such security measures and ultimately, offer more secure e&#45;banking services to their customers.</description>
<content:encoded><![CDATA[<p><a href="http://www.inderscience.com/link.php?id=45147"><b>Cultural and organisational commitment in the context of e&#45;banking</b></A><br />Ioannis V. Koskosas<br /><i>International Journal of Internet Technology and Secured Transactions, Vol. 4, No. 1 (2012) pp. 26 - 41</i><br />Although information security is critical for organisations to survive, a number of studies continue to report incidents of critical information loss. To this end, there is still an increasing interest to study information security from a non&#45;technical perspective. In doing so, this research focuses on the effect of strong corporate cultures and organisational commitment as important aspects in managing information security through e&#45;banking. That is, manipulating more effectively e&#45;banking security development and management within organisations. Achieving the required level of e&#45;banking security within organisations usually requires more than security awareness and control but also a better understanding of the organisations&#39; culture in which e&#45;banking security measures are developed and tailored to. In effect, organisations may have a clearer insight into how to commit more effectively to such security measures and ultimately, offer more secure e&#45;banking services to their customers.</p>]]></content:encoded>
<dc:identifier>10.1504/IJITST.2012.045147</dc:identifier>
<dc:source>International Journal of Internet Technology and Secured Transactions, Vol. 4, No. 1 (2012) pp. 26 - 41</dc:source>
<dc:creator>Ioannis V. Koskosas</dc:creator>
<dc:contributor>Department of Informatics and Telecommunications Engineering, University of Western Macedonia; Department of Finance, Technological Educational Institute of Western Macedonia, 50100, Kozani, Greece</dc:contributor>
<dc:subject>electronic banking</dc:subject>
<dc:subject>e&#45;banking security</dc:subject>
<dc:subject>corporate culture</dc:subject>
<dc:subject>organisational commitment</dc:subject>
<dc:subject>information technology</dc:subject>
<dc:subject>organisational culture</dc:subject>
<dc:subject>information security</dc:subject>
<dc:subject>secure services</dc:subject>
<dc:subject>banking industry</dc:subject>
<dc:subject>bank information.</dc:subject>
<dc:date>2012-01-29T23:20:50-05:00</dc:date>
<prism:volume>4</prism:volume>
<prism:number>1</prism:number>
<prism:startingPage>26</prism:startingPage>
<prism:endingPage>41</prism:endingPage>
<prism:publicationDate>2012-01-29T23:20:50-05:00</prism:publicationDate>
</item>
<item rdf:about="http://dx.doi.org/10.1504/IJITST.2012.045149">
<title>An effective spam filter based on a combined support vector machine approach</title>
<link>http://www.inderscience.com/link.php?id=45149</link>
<description>The volume of mass unsolicited e&#45;mail, often known as spam, has recently increased enormously and has become a serious threat to not only internet but also to society. It is challenging to develop spam filters that can effectively eliminate the increasing volume of unwanted e&#45;mails automatically. The present work presents a combination of support vector machine classifier for non&#45;linear data &#40;using an eligible kernel function&#41; with appropriate data pre&#45;processing as a spam filter. Data pre&#45;processing is a vital part of text classification where the objective is to generate feature vectors usable by SVM kernels. The pre&#45;processing steps include HTML removal, HTML replacement, de&#45;obfuscation and stop&#45;word&#45;remover. The results obtained using the pre&#45;processing level showed an improvement in the classification level. The estimated training and classification time for different document sizes indicate that the adopted method is practical and computationally efficient. Experimental results show that the approach can enhance the filtering performance effectively.</description>
<content:encoded><![CDATA[<p><a href="http://www.inderscience.com/link.php?id=45149"><b>An effective spam filter based on a combined support vector machine approach</b></A><br />Mumtaz M. Al&#45;Mukhtar; Yasmine M. Tabra<br /><i>International Journal of Internet Technology and Secured Transactions, Vol. 4, No. 1 (2012) pp. 42 - 54</i><br />The volume of mass unsolicited e&#45;mail, often known as spam, has recently increased enormously and has become a serious threat to not only internet but also to society. It is challenging to develop spam filters that can effectively eliminate the increasing volume of unwanted e&#45;mails automatically. The present work presents a combination of support vector machine classifier for non&#45;linear data &#40;using an eligible kernel function&#41; with appropriate data pre&#45;processing as a spam filter. Data pre&#45;processing is a vital part of text classification where the objective is to generate feature vectors usable by SVM kernels. The pre&#45;processing steps include HTML removal, HTML replacement, de&#45;obfuscation and stop&#45;word&#45;remover. The results obtained using the pre&#45;processing level showed an improvement in the classification level. The estimated training and classification time for different document sizes indicate that the adopted method is practical and computationally efficient. Experimental results show that the approach can enhance the filtering performance effectively.</p>]]></content:encoded>
<dc:identifier>10.1504/IJITST.2012.045149</dc:identifier>
<dc:source>International Journal of Internet Technology and Secured Transactions, Vol. 4, No. 1 (2012) pp. 42 - 54</dc:source>
<dc:creator>Mumtaz M. Al&#45;Mukhtar; Yasmine M. Tabra</dc:creator>
<dc:contributor>Department of Internet Engineering, College of Information Engineering, Al&#45;Nahrain University, P.O. Box 64074, Aljadria, Baghdad, Iraq. &#39; Department of Internet Engineering, College of Information Engineering, Al&#45;Nahrain University, P.O. Box 64074, Aljadria, Baghdad, Iraq</dc:contributor>
<dc:subject>spam filters</dc:subject>
<dc:subject>kernel function</dc:subject>
<dc:subject>classification</dc:subject>
<dc:subject>support vector machines</dc:subject>
<dc:subject>SVM</dc:subject>
<dc:subject>unsolicited email</dc:subject>
<dc:subject>filtering performance.</dc:subject>
<dc:date>2012-01-29T23:20:50-05:00</dc:date>
<prism:volume>4</prism:volume>
<prism:number>1</prism:number>
<prism:startingPage>42</prism:startingPage>
<prism:endingPage>54</prism:endingPage>
<prism:publicationDate>2012-01-29T23:20:50-05:00</prism:publicationDate>
</item>
<item rdf:about="http://dx.doi.org/10.1504/IJITST.2012.045150">
<title>Enforcing access control in workflow systems with a task engineering approach</title>
<link>http://www.inderscience.com/link.php?id=45150</link>
<description>The need for &#39;role engineering&#39; becomes evident once a decision has been made to adopt role&#45;based access control &#40;RBAC&#41; to ensure access control in a computer system. Role engineering is a process to define roles, permissions, and role hierarchies. Therefore, it is a critical step in deploying any RBAC&#45;oriented system. The question is even more crucial for workflow management systems&#58; additionally to role engineering, a &#39;task engineering&#39; process could be needed to allow the satisfaction of access control constraints even in critical situations. In this paper, we propose an approach of task engineering to improve access control enforcement in workflow management systems. By task engineering, we mean the process to examine the granularity of each workflow&#39;s task in a way to meet &#150; at run time &#150; the main access control requirements, precisely the least privilege and separation of duties principles. This approach uses the constraints satisfaction problem &#40;CSP&#41; formulation and resolution method.</description>
<content:encoded><![CDATA[<p><a href="http://www.inderscience.com/link.php?id=45150"><b>Enforcing access control in workflow systems with a task engineering approach</b></A><br />Hamid Hatim; Hanan El Bakkali; Ilham Berrada<br /><i>International Journal of Internet Technology and Secured Transactions, Vol. 4, No. 1 (2012) pp. 55 - 70</i><br />The need for &#39;role engineering&#39; becomes evident once a decision has been made to adopt role&#45;based access control &#40;RBAC&#41; to ensure access control in a computer system. Role engineering is a process to define roles, permissions, and role hierarchies. Therefore, it is a critical step in deploying any RBAC&#45;oriented system. The question is even more crucial for workflow management systems&#58; additionally to role engineering, a &#39;task engineering&#39; process could be needed to allow the satisfaction of access control constraints even in critical situations. In this paper, we propose an approach of task engineering to improve access control enforcement in workflow management systems. By task engineering, we mean the process to examine the granularity of each workflow&#39;s task in a way to meet &#150; at run time &#150; the main access control requirements, precisely the least privilege and separation of duties principles. This approach uses the constraints satisfaction problem &#40;CSP&#41; formulation and resolution method.</p>]]></content:encoded>
<dc:identifier>10.1504/IJITST.2012.045150</dc:identifier>
<dc:source>International Journal of Internet Technology and Secured Transactions, Vol. 4, No. 1 (2012) pp. 55 - 70</dc:source>
<dc:creator>Hamid Hatim; Hanan El Bakkali; Ilham Berrada</dc:creator>
<dc:contributor>Universit&#233; Mohammed V&#45;Souissi, ENSIAS, BP&#58; 713, Agdal &#150; Rabat, Morocco. &#39; Universit&#233; Mohammed V&#45;Souissi, ENSIAS, BP&#58; 713, Agdal &#150; Rabat, Morocco. &#39; Universit&#233; Mohammed V&#45;Souissi, ENSIAS, BP&#58; 713, Agdal &#150; Rabat, Morocco</dc:contributor>
<dc:subject>workflow</dc:subject>
<dc:subject>role&#45;based access control</dc:subject>
<dc:subject>RBAC</dc:subject>
<dc:subject>role engineering</dc:subject>
<dc:subject>task engineering</dc:subject>
<dc:subject>granulatrity</dc:subject>
<dc:subject>atomicity</dc:subject>
<dc:subject>constraints satisfaction problem</dc:subject>
<dc:subject>CSP.</dc:subject>
<dc:date>2012-01-29T23:20:50-05:00</dc:date>
<prism:volume>4</prism:volume>
<prism:number>1</prism:number>
<prism:startingPage>55</prism:startingPage>
<prism:endingPage>70</prism:endingPage>
<prism:publicationDate>2012-01-29T23:20:50-05:00</prism:publicationDate>
</item>
<item rdf:about="http://dx.doi.org/10.1504/IJITST.2012.045153">
<title>A new mobile payment system with formal verification</title>
<link>http://www.inderscience.com/link.php?id=45153</link>
<description>In this paper, we propose a new payment instrument, i.e., mobile traveller&#39;s check &#40;MTC&#41; in the realm of mobile commerce. This payment instrument provides the merits of both e&#45;cash and e&#45;check, i.e., MTC can be used freely as an e&#45;cash and it is as secure as an e&#45;check. We present the mobile payment protocol based on MTC which uses elliptic curve digital signature algorithm &#40;ECDSA&#41; for generating and verifying digital signatures and DES for encrypting and decrypting the messages which are suitable for resource constrained devices like mobile phones. We use &#39;extended BAN&#39; logic &#40;Abadi et al., 1993&#41; to provide a concise and clear understanding of this secure payment instrument &#40;MTC&#41;. We formalise and verify the interactions and trust relationships among engaging entities.</description>
<content:encoded><![CDATA[<p><a href="http://www.inderscience.com/link.php?id=45153"><b>A new mobile payment system with formal verification</b></A><br />Shaik Shakeel Ahamad; Siba K. Udgata; V.N. Sastry<br /><i>International Journal of Internet Technology and Secured Transactions, Vol. 4, No. 1 (2012) pp. 71 - 103</i><br />In this paper, we propose a new payment instrument, i.e., mobile traveller&#39;s check &#40;MTC&#41; in the realm of mobile commerce. This payment instrument provides the merits of both e&#45;cash and e&#45;check, i.e., MTC can be used freely as an e&#45;cash and it is as secure as an e&#45;check. We present the mobile payment protocol based on MTC which uses elliptic curve digital signature algorithm &#40;ECDSA&#41; for generating and verifying digital signatures and DES for encrypting and decrypting the messages which are suitable for resource constrained devices like mobile phones. We use &#39;extended BAN&#39; logic &#40;Abadi et al., 1993&#41; to provide a concise and clear understanding of this secure payment instrument &#40;MTC&#41;. We formalise and verify the interactions and trust relationships among engaging entities.</p>]]></content:encoded>
<dc:identifier>10.1504/IJITST.2012.045153</dc:identifier>
<dc:source>International Journal of Internet Technology and Secured Transactions, Vol. 4, No. 1 (2012) pp. 71 - 103</dc:source>
<dc:creator>Shaik Shakeel Ahamad; Siba K. Udgata; V.N. Sastry</dc:creator>
<dc:contributor>Institute for Development and Research in Banking Technology &#40;IDRBT&#41;, Castle Hills, Masab Tank, Hyderabad&#45;57, India; Department Computers and Information Sciences, University of Hyderabad, Hyderabad&#45;46, India. &#39; Department of Computers and Information Sciences, University of Hyderabad, Hyderabad&#45;46, India. &#39; Institute for Development and Research in Banking Technology &#40;IDRBT&#41;, Castle Hills, Masab Tank, Hyderabad&#45;57, India</dc:contributor>
<dc:subject>mobile payment</dc:subject>
<dc:subject>m&#45;payment</dc:subject>
<dc:subject>mobile travellers checks</dc:subject>
<dc:subject>travellers cheques</dc:subject>
<dc:subject>MTC</dc:subject>
<dc:subject>extended BAN logic</dc:subject>
<dc:subject>elliptic curve digital signature algorithm</dc:subject>
<dc:subject>ECDSA</dc:subject>
<dc:subject>DES</dc:subject>
<dc:subject>digital signatures</dc:subject>
<dc:subject>electronic signatures</dc:subject>
<dc:subject>mobile commerce</dc:subject>
<dc:subject>m&#45;commerce</dc:subject>
<dc:subject>signature verification</dc:subject>
<dc:subject>encryption</dc:subject>
<dc:subject>mobile phones</dc:subject>
<dc:subject>cell phones</dc:subject>
<dc:subject>trust</dc:subject>
<dc:subject>secure payment</dc:subject>
<dc:subject>payment security</dc:subject>
<dc:subject>authentication.</dc:subject>
<dc:date>2012-01-29T23:20:50-05:00</dc:date>
<prism:volume>4</prism:volume>
<prism:number>1</prism:number>
<prism:startingPage>71</prism:startingPage>
<prism:endingPage>103</prism:endingPage>
<prism:publicationDate>2012-01-29T23:20:50-05:00</prism:publicationDate>
</item>
</rdf:RDF>

