Article (Scientific journals)
Formal Security Analysis of Traditional and Electronic Exams
Dreier, Jannik; Giustosi, Rosario; Kassem, Ali et al.
2015In Communications in Computer and Information Science, 554, p. 294-318
Peer reviewed
 

Files


Full Text
submitted.pdf
Author preprint (332.66 kB)
Request a copy

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Electronic Exams; Formal Verification; Authentication; Privacy; Applied pi-calculus; Proverif
Abstract :
[en] Nowadays, students can be assessed not only by means of pencil-and-paper tests but also by electronic exams which they take in examination centers or even from home. Electronic exams are appealing as they can reach larger audiences, but they are exposed to new threats that can potentially ruin the whole exam business. These threats are amplified by two issues: the lack of understanding of what security means for electronic exams (except the old concern about students cheating), and the absence of tools to verify whether an exam process is secure. This paper addresses both issues by introducing a formal description of several fundamental authentication and privacy properties, and by establishing the first theoretical framework for an automatic analysis of exam security. It uses the applied π-calculus as a framework and ProVerif as a tool. Three exam protocols are checked in depth: two Internet exam protocols of recent design, and the pencil-and-paper exam used by the University of Grenoble. The analysis highlights several weaknesses. Some invalidate authentication and privacy even when all parties are honest; others show that security depends on the honesty of parties, an often unjustified assumption in modern exams.
Research center :
SnT
Disciplines :
Computer science
Author, co-author :
Dreier, Jannik
Giustosi, Rosario
Kassem, Ali
Lafourcade, Pascal
Lenzini, Gabriele ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Ryan, Peter ;  University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
External co-authors :
yes
Language :
English
Title :
Formal Security Analysis of Traditional and Electronic Exams
Publication date :
30 December 2015
Journal title :
Communications in Computer and Information Science
ISSN :
1865-0929
Publisher :
Springer
Special issue title :
E-Business and Telecommunications
Volume :
554
Pages :
294-318
Peer reviewed :
Peer reviewed
Funders :
University of Luxembourg - UL
Available on ORBilu :
since 28 January 2016

Statistics


Number of views
161 (12 by Unilu)
Number of downloads
1 (1 by Unilu)

Scopus citations®
 
2
Scopus citations®
without self-citations
1
OpenCitations
 
0
WoS citations
 
1

Bibliography


Similar publications



Contact ORBilu