Publications

47 of 47 publications

2026

2026Full papersEnglishConference

OIDC4AC: Extending OpenID Connect for Structured and Negotiable Authentication Contexts

Brendon V. Silva, Frederico Schardong, Ricardo Custódio

Proceedings of the XXVI Brazilian Symposium on Cybersecurity

OpenID ConnectAuthentication ContextOIDC4ACMulti-Factor AuthenticationAuditability

OpenID Connect (OIDC) is a widely adopted authentication protocol on the web. Despite its popularity, it provides limited expressiveness for describing how users are authenticated, constraining its applicability in highassurance, auditable scenarios. To understand the extent of this gap, a Multivocal Literature Review was conducted, revealing the absence of an integrated, OIDC-native model for representing factors and specifying authentication requirements. To address these gaps, this paper proposes OpenID Connect for Authentication Context (OIDC4AC), a new OIDC protocol extension that enables fine-grained specification and detailed representation of authentication factors, improving interoperability and auditability.

2026Full papersEnglishJournal

Redefining Digital Web Signature Secrecy: A Client-Side Model for Enhanced Security and Compliance

Wellington F. Silvano, Lucas Mayr, Enzo Brum, Gabriel Cabral, Frederico Schardong, Ricardo Custódio

Journal of the Brazilian Computer Society

Digital signaturesecrecyWeb signatureclient-side signature

Web-based digital signature platforms prioritize convenience but often compromise secrecy, exposing sensitive documents and private keys to third-party systems. This paper introduces a client-side cryptographic model that eliminates such vulnerabilities by performing all cryptographic operations within the user's browser. Leveraging One-Time Certificates and adhering to Claude Shannon's secrecy principles, the model ensures that documents and keys remain secure by never leaving the client environment. The proposed approach addresses critical risks, including document exposure, metadata leakage, and key compromise, while maintaining compatibility with public key infrastructure standards and legacy systems. Performance evaluations show efficient signing and verification processes, with documents up to 5 MB signed in approximately 1 second and verified in 0.15 seconds. By removing reliance on external servers for sensitive operations, the model mitigates platform vulnerabilities, reduces liability, and ensures compliance with regulations like GDPR and LGPD. Key contributions include enhanced secrecy, simplified key management, and scalable real-world use-case performance. This work redefines digital signature security, offering a robust, privacy-preserving alternative for secrecy document signature and verification workflows.

2026Full papersPortugueseJournal

Construction of the Rolante River Experimental Basin, Rio Grande do Sul, for integrated disaster and water resources management

Fernando L. Hillebrand, Masato Kobiyama, Caroline H. Flores, Alessandro G. Franck, Fernando C. Zambrano, Frederico Schardong, Rayane M. Castilhos, Dilcenei Nunes

Brazilian Journal of Physical Geography

Rolantehydrometeorological monitoringlandslidesexperimental basin

The experimental basin is a space that integrates science, education, local communities, and territorial governance, promoting water security and population resilience in the face of disasters. The objective of this study was to present the implementation of an experimental basin through hydrometeorological monitoring and diagnosis, as well as mass movement monitoring. This implementation has been carried out in the Rolante River basin (815 km²), located in the state of Rio Grande do Sul, Brazil. For hydrological monitoring, staff gauges and water level sensors were installed in the main streams and tributary rivers, in addition to the implementation of meteorological monitoring through automated weather stations. All generated information is systematized and made freely available to the population through an institutional website. In this way, the experimental basin offers a social technology in which the equipment is not intended only for scientific research but also for the development of citizen science actions. These actions are made possible through training activities in schools and with local residents, as well as by supporting municipal decision-making processes. Thus, the implementation of the experimental basin contributes to strengthening hydrosolidarity and participatory territorial governance with the local population.

2026Short papersPortugueseConference

Metadata Aggregation vs. Chain of Trust: Comparing CAFe SAML and CAFe OpenID Federation

Eduardo Perottoni, Brendon Vicente, Frederico Schardong, Ricardo Custódio, Laerte Belotto, Reinaldo Matushima, Jean Faustino

Extended Proceedings of the XXVI Brazilian Symposium on Cybersecurity

CAFeSAMLOpenID FederationChain of TrustIdentity Federation

The Brazilian Federated Academic Community (CAFe), operated by the National Research and Education Network (RNP), is built on the Security Assertion Markup Language (SAML) protocol. This paper compares today's CAFe with CAFe 2.0, a redesign of the federation on top of the OpenID Federation protocol. The comparison is organised around the topology of the federation, which moves from a two level structure to a multilevel one, and around the trust model, which moves from a static aggregation of metadata to a dynamic and cryptographically verifiable chain of trust.

2026Short papersPortugueseConference

Federation Architectures and OpenID Federation: Provider Onboarding and Data Sovereignty

Eduardo Perottoni, Brendon V. Silva, Frederico Schardong, Ricardo Custódio

Extended Proceedings of the XXVI Brazilian Symposium on Cybersecurity

OpenID FederationFederation ArchitectureHub-and-SpokeData SovereigntyProvider Onboarding

Academic identity federations are beginning to migrate from the Security Assertion Markup Language (SAML) to OpenID Federation. Adopting the new protocol, however, introduces complexities. To reduce the friction of that process, this work proposes a federation architecture close to the hub-and-spoke model, in which components are hosted by the federation operator, making it easier for providers to join than in a full mesh. The paper discusses the trade-off between ease of adoption and data sovereignty, addressing the risks of centralisation and how to mitigate them.

2026Short papersPortugueseConference

Identity and Access Management for Intelligent Agents

Andrey Brito, Augusto Suruagy, Emerson Mello, Frederico Schardong

Extended Proceedings of the XXVI Brazilian Symposium on Cybersecurity

AI AgentsIdentity and Access ManagementIAMPermission DelegationGIAAI

The rise of autonomous AI agents introduces a new class of actor in distributed systems, combining the speed and scalability of services with the autonomy and unpredictability of humans. Identity and access management models designed for users and deterministic services fail in scenarios with multiple trust domains, asynchronous operations and dynamic delegation of permissions. This paper presents GIAAI, an initiative of the EMBRAPII Competence Centre in Cybersecurity (CISSA), which evaluates traditional identity and access management tools and proposes practices, adaptations and extensions for managing agents securely.

2026Short papersPortugueseConference

Managed Identity Providers in CAFe: Sovereignty and Inclusion for Organisations without Technical Staff

Frederico Schardong, Eduardo Perottoni, Brendon V. Silva, Laerte Belotto, Reinaldo Matushima, Jean Faustino

Extended Proceedings of the XXVI Brazilian Symposium on Cybersecurity

CAFeManaged Identity ProviderIdentity SovereigntyDigital InclusionAcademic Federation

The Brazilian Federated Academic Community (CAFe), operated by the National Research and Education Network (RNP), assumes that every participating institution runs its own Identity Provider. That assumption excludes teaching and research organisations without technical capacity, such as scientific societies, support foundations and technical schools. Faced with this barrier, they tend to stay outside the federation or to delegate identity management to international commercial providers. This paper argues that identity management sovereignty is unreachable on their own for organisations without technical staff, and proposes offering a managed Identity Provider as a service run by a national operator.

2026Short papersEnglishConference

The De-Provisioning Gap in Identity Management for Agentic AI

Fernanda Jablonski, Fernanda Müller, Julio S. Ana, Yuri Schoenardie, Kléber Silva, Frederico Schardong

Extended Proceedings of the XXVI Brazilian Symposium on Cybersecurity

Agentic AIDe-ProvisioningIdentity and Access ManagementCredential RevocationSPIFFE

Various proposals have emerged to address challenges related to identity, authentication, and authorization in agentic systems. Given this context, this article compiles key proposals, such as OIDC-A, SPIFFE, A-JWT, A2A, and LDP, and compares them based on five criteria derived from the “Identity Management for Agentic AI” white paper. The results show that, although current proposals are robust in specific areas, none satisfies all analyzed criteria. The main limitation is the lack of rapid, verifiable de-provisioning, highlighting challenges in the reliable revocation of identities and permissions in agentic AI.

2026Short papersEnglishConference

Pioneering the Future of Electronic Identity: From Post-Quantum Cryptography to Fiduciary Principles

Frederico Schardong, Ricardo Custódio

Extended Proceedings of the XXVI Brazilian Symposium on Cybersecurity

Electronic IdentityPost-Quantum CryptographyOpenID ConnectOAuth 2.0Fiduciary Identity

Electronic identity (e-ID) underpins online security and privacy, yet faces two threats: the cryptography behind today's protocols will fall to quantum computers, and concentrating identities in a few providers erodes privacy while overburdening users. This thesis advances e-ID on both fronts. It makes OAuth 2.0 and OpenID Connect resistant to the quantum threat under realistic networks, and charts a more private, usable path through a rigorous taxonomy of self-sovereign identity, tools to search and compare identity models, and the Fiduciary Identity model, which delegates decisions to accountable, auditable fiduciaries. Several results reached national scale: this work's technology signs every electronic birth, marriage, and death certificate issued in Brazil.

2026Technical reportsPortuguese

Executive Summary of the Future Vision Report of the Identity Management Technical Committee

Emerson R. Mello, Shirlei A. Chaves, Marco A. A. Henriques, Andrey E. M. Brito, Frederico Schardong

Brazilian National Research and Education Network (RNP)

Identity ManagementIAMCT-GIdFuture Vision

This document presents drivers of change and future scenarios for digital identity management in Brazilian academia, focused on the period between 2026 and 2030. The aim is to offer a strategic view that can guide the actions of RNP and of the academic community in the face of the technological, regulatory and social shifts that affect identity management.

2025

2025Technical reportsPortuguese

Future Vision Report: Identity Management Technical Committee

Emerson R. Mello, Shirlei A. Chaves, Andrey E. M. Brito, Caciano Machado, Frederico Schardong, Edelberto F. Silva, Ioram S. Sette, Carla M. Westphall

Brazilian National Research and Education Network (RNP)

Identity ManagementAccess ManagementInnovationTechnology TrendsRNP

This technical report offers a forward looking view of the trends and challenges in identity and access management, highlighting technological innovations and strategies for the evolution of the services of the Brazilian National Research and Education Network (RNP), drawing on contributions from a range of specialists and on the Three Horizons of Innovation methodology.

2025Short papersEnglishConference

Bringing Semantics to Authentication: An OpenID Connect Extension

Brendon Silva, Frederico Schardong, Ricardo Custódio

Extended Proceedings of the XXV Brazilian Symposium on Cybersecurity

OpenID ConnectOIDCAuthentication Methods ReferencesAMRSemantic

OpenID Connect (OIDC) is a widely adopted authentication protocol, yet it offers limited expressiveness when conveying details about how a user was authenticated. The Authentication Methods References (amr) claim used for this purpose lacks structure and semantic clarity, hindering scenarios that require higher assurance. This paper proposes an extension to OIDC that introduces the amr details claim — a structured, interoperable mechanism for describing authentication factors along with relevant metadata, such as assurance levels and trust frameworks. By enhancing the protocol’s expressiveness without compromising compatibility, the extension enables granular access control, thereby contributing to increased trust in distributed identity systems.

2025Short papersPortugueseConference

Future Vision: Brazil's Civil Registry as an Issuer of Verifiable Credentials

Brendon Silva, Frederico Schardong, Luis Vendramin Junior, Ricardo Custódio

Extended Proceedings of the XXV Brazilian Symposium on Cybersecurity

Verifiable CredentialsVCCivil Registry

The digitalisation of public services intensifies the demand for identity models that are more secure, portable and centred on the citizen. This work proposes that the Civil Registry of Natural Persons, which holds the foundational identity of the citizen, take on that role in the digital realm by issuing Verifiable Credentials. The paper presents the technical foundations of these credentials, analyses the Brazilian digital identity landscape and discusses the main challenges to their adoption.

2024

2024Full papersEnglishConference

From Self-Sovereign Identity to Fiduciary Identity: A Journey Towards Greater User Privacy and Usability

Frederico Schardong, Ricardo Custódio

Proceedings of the 38th ACM/SIGAPP Symposium on Applied Computing

Identity and Access ManagementDigital IdentityElectronic IdentitySelf-Sovereign IdentitySSIFiduciary Identity

In an era defined by the evolving Identity and Access Management (IAM) landscape, this paper shines a spotlight on the critical aspect of usability limitations inherent in the Self-Sovereign Identity (SSI) paradigm. While SSI holds the promise of returning control and privacy to individuals, it presents challenges in terms of user experience for the layman, particularly concerning the management of cryptographic keys, credentials, and the evaluation of service provider requests for private information. To tackle these inherent limitations of SSI, this paper introduces a new digital identity model named Fiduciary Identity. It is constructed over the fiduciary relationship, a poorly explored topic in IAM. The fiduciary acts on behalf of the user, simplifying interactions and enhancing usability, bridging the gap between the potential advantages of SSI and the practicality of everyday digital life. The innovative concept of the fiduciary identity acts as a bridge toward achieving a user-centric, secure, and privacy-preserving IAM ecosystem.

2024Full papersEnglishConference

Automated Issuance of Post-Quantum Certificates: A New Challenge

Alexandre A. Giron, Frederico Schardong, Lucas P. Perin, Ricardo Custódio, Victor Valle, Victor Mateu

Applied Cryptography and Network Security

Post-Quantum CryptographyACME ProtocolCertificate Management

The Automatic Certificate Management Environment protocol (ACME) has significantly contributed to the widespread use of digital certificates in safeguarding the authenticity and privacy of Internet data. These certificates are required for implementing the Transport Layer Security (TLS) protocol. However, it is well known that the cryptographic algorithms employed in these certificates will become insecure with the emergence of quantum computers. This study assesses the challenges in transitioning ACME to the post-quantum landscape using Post-Quantum Cryptography (PQC). To evaluate the cost of ACME's PQC migration, we create a simulation environment for issuing PQC-only and hybrid digital certificates. Our experiments reveal performance drawbacks associated with the switch to PQC or hybrid solutions. However, considering the high volume of certificates issued daily by organizations like Let's Encrypt, the performance of ACME is of utmost importance. To address this concern, we propose a novel challenge method for ACME. Compared to the widely used HTTP-01 method, our findings indicate an average PQC certificate issuance time that is 4.22 times faster, along with a potential reduction of up to 35% in communication size.

2024Full papersEnglishConference

The Role-Artifact-Function Framework for Understanding Digital Identity Models

Frederico Schardong, Ricardo Custódio

Conceptual Modeling: 43rd International Conference, ER 2024, Pittsburgh, PA, USA, October 28-31, 2024, Proceedings

Identity and Access ManagementDigital IdentitySelf-Sovereign IdentityMetamodel

Identity and Access Management (IAM) is a crucial aspect of online interactions, and researchers and practitioners have been exploring this area since the early days of the Internet. Over the years, many digital identity protocols and standards were created. While OAuth 2.0 and OpenID Connect (OIDC) are currently the most widely used and mature protocols, the emerging concept of Self-Sovereign Identity (SSI) and its underlying protocols promise greater user privacy and control. Although much emphasis has been placed on new protocols and implementations, the ontological and formal understanding of digital identity models still needs to be addressed. In this paper, we make three contributions: (i) introduce the Role-Artifact-Function (RAF) framework, which comprises a meta-metamodel and a metamodel; (ii) describe and compare digital identity models through the instantiation of the RAF metamodel; and (iii) present significant insights, including the conceptual equivalence between the established family of x509-based protocols and SSI, as well as the correlation between the chronological evolution of identity models and their increasing linguistic complexity.

2024Full papersEnglishConference

Exploring Digital Signatures Secrecy in Web-Platform: Client-Side Cryptographic Operations

Wellington Silvano, Gabriel Cabral, Lucas Mayr, Frederico Schardong, Ricardo Custódio

Annals of the XXIV Brazilian Symposium on Information and Computational Systems Security

Digital SignatureClient-Side Cryptographic OperationsDocument SecrecyPrivate Key ManagementOne-Time CertificatesPublic Key InfrastructurePKIShannon's SecrecyWeb-Based Signature Platforms

Online signature platforms confront critical security challenges, notably exposing sensitive documents to third-party applications. This paper presents a novel client-side cryptographic model that enhances document secrecy and key management by performing cryptographic operations within the user's browser. By employing one-time certificates, our model eliminates document uploads, reducing the risk of leakage and private key compromise. Aligned with Claude Shannon's information theory, our approach ensures robust secrecy while remaining compatible with existing digital signatures. Our implementation demonstrates practical performance, offers a significant advancement in secure digital signatures, addressing vulnerabilities in traditional web-based platforms.

2024Short papersEnglishConference

Bridging the Gap: Managing Dual Assurance Levels in OpenID Connect

Brendon Silva, Frederico Schardong, Ricardo Custódio

Extended annals of the XXIV Brazilian Symposium on Information and Computational Systems Security

OpenID ConnectOIDCElectronic IdentityAssurance LevelLoA

This paper introduces and addresses challenges in managing electronic identity's Level of Assurance (LoA), which has two types: LoA of authentication and LoA of identity. We explore different technical specifications, protocols, and concrete identity providers' strategies for managing these two levels of assurance, highlighting the implications of protocols supporting only a single LoA instead of two. An extension to the OpenID Connect protocol is proposed to support both LoA types, instituting a new claim, the Identity Context Class Reference (ICR). This approach ensures compatibility and versatility with existing technical specifications.

2024Short papersEnglishConference

Enhancing Keycloak: Implementing OpenID Connect for Identity Assurance

Brendon Silva, Frederico Schardong, Ricardo Custódio

Extended annals of the XXIV Brazilian Symposium on Information and Computational Systems Security

OpenID ConnectOIDCOpenID Connect for Identity AssuranceOIDC4IDAKeycloakElectronici Ientity

Electronic identities are pivotal in a world where digital interactions are evolving fast. In this context, OpenID Connect, a cornerstone of user identification and authentication, plays an important role in the operation of electronic identification services. This paper describes a novel implementation of the OpenID Connect for Identity Assurance 1.0 (OIDC4IDA), an extension to OpenID Connect, on Keycloak, the leading open-source identity provider.

2024Short papersPortugueseConference

Experience Report: Adopting a Trusted Service List at the Brazilian National Research and Education Network

Nicole Rieckmann, Eduardo Perottoni, Frederico Schardong, Lucas Mayr, Ricardo Custódio, Luciano Rocha, Reinaldo Matushima

Extended Proceedings of the XXIII Brazilian Symposium on Information and Computational Systems Security

Trusted Service ListTSLETSIRNP

This paper examines how the Brazilian National Research and Education Network (RNP) developed and manages its Trusted Service List (TSL), a repository that holds information about trusted services in an interoperable XML document. The list plays a crucial role in the security and integrity of digital services, supporting processes such as electronic signatures and authenticity checks. Managing it requires strict compliance with the technical and security requirements set by ETSI. The work details the structure of the list and the macro processes for including and removing services created by RNP, showing why they matter for trust in the catalogued services.

2024Theses and dissertationsEnglish

Pioneering the Future of Electronic Identity: From Post-Quantum Cryptography to Fiduciary Principles

Frederico Schardong

Federal University of Santa Catarina

Electronic IdentityDigital IdentityIdentity ManagementPost-Quantum CryptographySelf-Sovereign IdentityFiduciary Identity

The security, privacy, and functionality of online interactions are integrally tied to Electronic IDentity (e-ID). As foundational components, Identity Provider (IdP) and Service Provider (SP) have traditionally been separated, an architecture further enhanced by standards such as Open Authorization 2.0 (OAuth 2.0) and OpenID Connect (OIDC). These protocols are critical in streamlining end-user authentication and authorization across digital platforms. Concurrently, the emergent Self-Sovereign Identity (SSI) paradigm redefines user privacy by empowering individuals with direct control over their e-IDs without intermediary oversight by IdPs, thereby preventing undue surveillance and data access by SPs. This thesis addresses pressing challenges in e-ID management, emphasizing the urgent need for Post-Quantum Cryptography (PQC) to safeguard authentication systems against the theoretical threat of quantum computing. Through advanced modifications to OAuth 2.0 and OIDC, particularly in their cryptographic foundations — JSON Web Key and Transport Layer Security (TLS) — this work pioneers the development of quantum-resistant methodologies. The proposed quantum-safe protocols are evaluated in a comprehensive real-world OIDC case study to validate their effectiveness and practicality. In addition to fortifying current standards, this research critically assesses the relatively nascent field of SSI. A thorough systematic literature review is conducted, culminating in a novel, meticulously crafted taxonomy of SSI. This taxonomy categorizes existing scholarly and practical efforts and identifies persistent gaps and future research directions. By rigorously analyzing emergent themes and findings from the literature, this thesis provides a roadmap for deepening the theoretical and practical understanding of SSI frameworks. Exploring practical implementations of SSI, the thesis also tackles the inherent challenges of utilizing distributed ledger technology for identity management. The focus is improving the efficiency and accuracy of searching metadata stored on blockchain systems commonly employed in SSI solutions. A novel search mechanism is proposed and empirically validated, demonstrating superior performance over existing methods for natural language processing tasks, thereby enhancing the operational feasibility of blockchain in supporting complex identity queries. The theoretical contributions of this thesis are further augmented by the introduction of the Role-Artifact-Function (RAF) framework. This dual-layer conceptual model, consisting of a meta-metamodel and a metamodel, provides a robust structure for examining and contrasting e-ID models. Through detailed application, the RAF framework aids in elucidating the ontological structures underlying various identity models, offering a comprehensive analytical tool that advances the discourse on e-ID. Lastly, the thesis confronts the user-centric challenges associated with SSI, particularly the complexities related to user interactions and management of cryptographic credentials. To address these issues, the innovative Fiduciary Identity model is introduced. Inspired by fiduciary legal principles, this model reduces user burden by automating consent processes and delegating decision-making to trusted entities, simplifying interactions and enhancing user experience in e-ID transactions.

2024Technical reportsEnglish

Confidentiality of Electronic Documents in the Civil Registry of Brazil

Wellington F. Silvano, Frederico Schardong, Lucas Mayr, Eduardo Perottoni, Ricardo Custódio

Document ConfidentialityCivil RegistryCryptographic ProtocolKey ManagementCloud Storage

This work presents a cryptographic protocol for securing electronic documents in the Civil Registry of Brazil. The protocol is innovative because the document is encrypted and stored in the cloud but can be easily recovered by the owner if she has the access credentials, that is, a simple password and the owner identifier. The main objective is to keep the management of credentials by users as simple as possible while preventing anyone from accessing the stored document. The protocol was implemented using advanced electronic signature services of PDF standard. The implementation separates the public parts of the document, storing, in encrypted form, exclusively the private data and cryptographic artifacts.

2023

2023Full papersEnglishJournal

Concentration and thickness of sea ice in the Weddell Sea from SSM/I passive microwave radiometer data

Fernando L. Hillebrand, Marcos W.D. Freitas, Ulisses F. Bremer, Tales C. Abrantes, Jefferson C. Simões, Cláudio W. Mendes, Frederico Schardong, Jorge Arigony-Neto

Annals of the Brazilian Academy of Sciences

Spectral Linear Mixing ModelMultiple Linear RegressionSea Ice ConcentrationBrightness Temperature

This study evaluated feasibility statistically and analyzed, during the freezing period, the relationship between brightness temperature (Tb) data of the 37V polarisation and the GR3719 (Gradient Ratio 37V and 19V) obtained by Special Sensor Microwave/Imager from F11 and F13 satellites with sea ice thickness (SIT) data obtained in the Weddell Sea through Antarctic Sea Ice Processes and Climate program. The multiple linear regression (MLR) was applied at 1,520 points, with 70% of these points being randomly separated to generate the MLR and 30% to carry out the validation. To perform the temporal mapping, the MLR was applied only to pixels with sea ice concentration (SIC) ≥ 90%, obtained through the fraction image calculated from the spectral linear mixing model (SLMM) using the Tb in the channels and polarizations 19H, 19V and 37V. The results of the SLMM validation process for estimating the SIC were σ = 10.5%, RMSE = 11.0%, and bias = -2.8%, and the SIT based on the MLR, the results were R² = 0.57, RMSE = 0.268 m, and bias = 0.103 m. In the SIT mapping, we highlight the trend of thickness reduction on the east coast of the Antarctic Peninsula during the period 1992-2009.

2023Technical reportsPortuguese

Future Vision Report: Identity Management Technical Committee

Emerson R. Mello, Andrey E. M. Brito, Antônio T. A. Gomes, Frederico Schardong, Marco A. A. Henriques, Michelle S. Wangham, Shirlei A. Chaves, Edelberto F. Silva

Brazilian National Research and Education Network (RNP)

Identity ManagementAccess ManagementInnovationTechnology TrendsRNP

This technical report offers a forward looking view of the trends and challenges in identity and access management, highlighting technological innovations and strategies for the evolution of the services of the Brazilian National Research and Education Network (RNP), drawing on contributions from a range of specialists and on the Three Horizons of Innovation methodology.

2023Short papersPortugueseConference

Less Digital Certification and More Electronic Identity: ICPEdu and CAFe in an Inclusive Digital Signer

Eduardo D. Perottoni, Bernardo P. Costa, Fernanda L. Müller, Victor S. Camargo, Frederico Schardong, Wellington Silvano, Lucas Mayr, Ricardo Custódio, Luciano Rocha, Christian Lyra, Reinaldo Matushima, Nicole Rieckmann

Extended Proceedings of the XXIII Brazilian Symposium on Information and Computational Systems Security

PKIICPEduElectronic IdentityCAFeRNPDigital Signature

This paper presents the architecture and the features of a technically inclusive digital signer. The signer uses electronic identities from the Brazilian Federated Academic Community (CAFe) to issue Single Signature Certificates (CertAU) in the Education Public Key Infrastructure (ICPEdu). It allows documents to be signed simply, quickly and securely.

2023Short papersPortugueseConference

Electronic Identification of Brazil's Civil Registry

Brendon Silva, Frederico Schardong, Luis C. Vendramin Junior, Ricardo Custódio

Extended Proceedings of the XXIII Brazilian Symposium on Information and Computational Systems Security

Electronic IdentityCivil RegistryIdRCAuthenticationIdentity

This paper presents the Civil Registry Identification (IdRC), an electronic identity provider integrated with the biographic databases of Brazilian citizens through the public records of birth, marriage and death kept by the Civil Registry Offices of Natural Persons. Because it draws on primary data, IdRC differs from other electronic identity providers: with the user's authorisation, it can supply service providers with foundational attributes, proof of life and other information.

2022

2022Full papersEnglishConference

Touchless Authentication for Health Professionals: Analyzing the Risks and Proposing Alternatives to Dirty Interfaces

Chiarelli A. Vale, Frederico Schardong, Maurício Barros, Ricardo Custódio

2022 IEEE 35th International Symposium on Computer-Based Medical Systems (CBMS)

AuthenticationMedical ServicesSecurityRisk ManagementAuthenticationHealthTouchlessLevel of AssuranceIdentity and Access Management

One of the most significant challenges for electronic services is ensuring that the person using a service is who they claim to be with an adequate level of trust. The user identity is confirmed through authentication. However, depending on the authentication method used, this process may not provide the expected security and is often bureaucratic. The authentication of healthcare professionals imposes additional challenges. For instance, they should not be exposed to touching peripherals nor remove their masks. This article presents: (i) a risk assessment of fraudulent authentication of health professionals; (ii) a proposal of authentication assurance levels for health professionals; (iii) a discussion of touchless authentication factors for health professionals; and (iv) an empirical evaluation of the proposals.

2022Full papersEnglishConference

Post-Quantum Electronic Identity: Adapting OpenID Connect and OAuth 2.0 to the Post-Quantum Era

Frederico Schardong, Alexandre Giron, Fernanda Müller, Ricardo Custódio

Cryptology and Network Security

Post-Quantum CryptographyPQCOpenID ConnectOAuthOAuth 2.0Electronic IdentityIdentity

The quantum threat affects a multitude of network protocols, frameworks, and systems that use public-key cryptography. OpenID Connect (OIDC) and OAuth 2.0 are no exception, which means they must transition to Post-Quantum Cryptography (PQC). However, the long lifetime of access tokens necessitates this shift, if we consider the possibility of a record-now-decrypt-later attacker retrieving and subsequently impersonating users with these tokens. In this research, we conduct a thorough literature review to identify existing solutions to this problem, suggest modifications to OAuth 2.0 and OIDC and their underlying protocols to make them quantum-safe, then implement and evaluate the effects of PQC on a realistic OIDC study case. Our findings reveal that PQC-based OIDC has the same or better performance in low-latency settings, but the handshake of PQC-based TLS accounts for fifty percent of the overall duration in high-latency scenarios.

2022Full papersEnglishJournal

Self-Sovereign Identity: A Systematic Review, Mapping and Taxonomy

Frederico Schardong, Ricardo Custódio

Sensors

Self-Sovereign IdentitySSIIdentity ManagementIdentity and Access ManagementPrivacySystematic Literature ReviewSystematic MappingSurveyReviewTaxonomy

Self-Sovereign Identity (SSI) is an identity model centered on the user. The user maintains and controls their data in this model. When a service provider requests data from the user, the user sends it directly to the service provider, bypassing third-party intermediaries. Thus, SSI reduces identity providers’ involvement in the identification, authentication, and authorization, thereby increasing user privacy. Additionally, users can share portions of their personal information with service providers, significantly improving user privacy. This identity model has drawn the attention of researchers and organizations worldwide, resulting in an increase in both scientific and non-scientific literature on the subject. This study conducts a comprehensive and rigorous systematic review of the literature and a systematic mapping of theoretical and practical advances in SSI. We identified and analyzed evidence from reviewed materials to address four research questions, resulting in a novel SSI taxonomy used to categorize and review publications. Additionally, open challenges are discussed along with recommendations for future work.

2022PatentsPortuguese

Processes for Verifying and Digitally Signing Electronic Documents Based on Electronic Identity, Single-Use Digital Certificates and Blockchain

Frederico Schardong, Lucas Mayr, Ricardo Custódio

Digital SignatureSingle-Use CertificateDigital CertificateBlockchain

A process for signing documents and for verifying digital signatures. This invention concerns a new process for digitally signing digital documents, such as a text written in a word processor and saved as a PDF. Digital signatures can currently be produced in several ways, the most widely accepted being a digital certificate. A digital signature is analogous to a handwritten signature on a physical document. What sets this process apart from the state of the art is the concept of a single-use certificate: a document is bound to a certificate, and that certificate cannot be used for anything other than signing that specific document. A second difference is that the validity of a signature depends on three records in a blockchain, one for each entity involved in the signature, namely the identity provider, the signature service and the certification authority. Forging a signature therefore requires corrupting all three entities, which raises the security of the signature.

2022PreprintsEnglishJournal

Leveraging self-sovereign identity, blockchain, and zero-knowledge proof to build a privacy-preserving vaccination pass

Mauricio V. Barros, Frederico Schardong, Ricardo Custódio

SSRN preprint

Vaccination PassPrivacySelf-Sovereign IdentityZero-Knowledge ProofBlockchain

The current humanitarian health crisis popularized the debate on data privacy. At the same time, several cities, states, and even countries put the mandatory presentation of health pass to access services into practice. In this article, we explore the concepts of self-sovereign identity, blockchain, and zero-knowledge proofs to propose a solution to the problem of presenting proof of vaccination. This solution allows users to prove that they are vaccinated for different pathogens without revealing their identity. The architecture is loosely coupled, allowing components to be exchanged, which we discuss when we present the implementation of a working prototype.

2022PreprintsEnglishJournal

Simplifying Electronic Document Digital Signatures

Lucas Mayr, Frederico Schardong, Ricardo Custódio

Cryptographic Key ManagementDigital CertificatePublic-Key InfrastructureDigital Document

Electronic documents are signed using private keys and verified using the corresponding digital certificates through the well-known public key infrastructure model. Private keys must be kept in a safe container so they can be reused. This makes private key management a critical component of public key infrastructures with no failproof answer. Therefore, existing solutions must employ cumbersome and often expensive revocation methods to handle private key compromises. We propose a new cryptographic key management model built with long-term, irrevocable digital certificates, each bound to a single document. Our model issues a unique digital certificate for each new document to be signed. We demonstrate that private keys associated with these certificates should be deleted after each signature, eliminating the need to store those keys. Furthermore, we show that these certificates do not require any revocation mechanism to be trusted. We analyze the overhead caused by the frequent generation of new key pairs for each document, provide a security overview and show the advantages over the traditional model.

2022Tool demonstrationsEnglishConference

TLS 1.3 Handshake Analyzer

Alexandre A. Giron, Frederico Schardong, Ricardo Custódio

Extended Proceedings of XXII Brazilian Symposium on Information and Computational Systems Security

TLS 1.3SecurityPerformance Analysis

The Transport Layer Security (TLS) protocol is the de facto standard for global Internet security. Despite its performance and security improvements over previous versions, there are still challenges regarding user privacy and security against future quantum attackers. Although there are several initiatives to address these challenges, there is no specialized tool to analyze these new features. This paper presents the TLS 1.3 Handshake Analyzer, a tool for security and performance analysis of TLS connections. Users can obtain security information about their connections, and server administrators can use it to validate the effects of TLS in their network applications, such as handshake timings and the sizes of transferred cryptographic objects.

2021

2021Full papersEnglishJournal

NFV resource allocation: A systematic review and taxonomy of VNF forwarding graph embedding

Frederico Schardong, Ingrid Nunes, Alberto Schaeffer-Filho

Computer Networks

Network Functions VirtualisationVirtualised Network FunctionsVNF forwarding graph embedding

The emergence of Network Functions Virtualisation (NFV) is drastically reshaping the arrangement of network functions. Instead of being built on dedicated hardware (network appliances), network functions are now implemented as software components that run on top of general purpose hardware through virtualisation, namely virtualised network functions (VNFs). From this paradigm-shifting technology arise two problems: (i) how to place VNFs in an NFV-enabled network; and (ii) how to chain these VNFs. These problems are jointly referred to as the VNF forwarding graph embedding (VNF-FGE) problem. Having efficient solutions to the VNF-FGE problem is key to the success of NFV because placing and chaining VNFs automatically and efficiently reduces network and computing resources, thus reducing capital expenditure (CAPEX) and operating expenditure (OPEX). In this work, we systematically review the literature on the VNF-FGE problem. We present a novel taxonomy for the classification and study of proposed solutions to this problem. Research challenges that remain unaddressed are also discussed, providing recommendations for future work.

2021Full papersEnglishJournal

Comparison between atmospheric reanalysis models ERA5 and ERA-Interim at the North Antarctic Peninsula region

Fernando L. Hillebrand, Ulisses F. Bremer, Jorge Arigony-Neto, Cristiano N. Rosa, Cláudio W. Mendes Jr, Juliana Costi, Marcos W. D. Freitas, Frederico Schardong

Annals of the American Association of Geographers

Air TemperatureAntarctic Atmospheric PressureWeather Stations

The availability of accurate meteorological data is important for the modeling of atmospheric flows, enabling the understanding of climate change in a given environment over time. Therefore, this study aimed to evaluate the quality of the meteorological data of 2 m temperature (T) and mean sea level pressure (MSLP), obtained through the atmospheric reanalysis models ERA5 and ERA-Interim (ERA-i) in the northern region of the Antarctic Peninsula, covering the period from 1979 to 2018. To carry out the statistical process, local observations from nine weather stations installed in the study region were used, with data available from the Scientific Committee on Antarctic Research. Statistical analysis evaluated Pearson's linear correlation coefficient (R), standard deviation (σ), normalized bias, normalized mean absolute error, and normalized root mean square error. Regarding the difference in between weather stations and reanalysis models, we found a better result for ERA5 ( = -0.34 °C) compared to ERA-i ( = 0.37 °C); however, for the difference in the ERA-i ( = -0.04 hPa) presented a better response in relation to ERA5 ( = 0.24 hPa). When verifying the local meteorological observations trend, an increase of T in 0.31 °C decade-1 (Esperanza station) and a reduction of MSLP between -0.56 (Bellingshausen station) and -0.80 hPa decade-1 (Jubany station) were recorded.

2021Workshop papersEnglishConference

Matching Metadata on Blockchain for Self-Sovereign Identity

Frederico Schardong, Ricardo Custódio, Láercio Pioli, João Meyer

Business Process Management Workshops

Self-Sovereign IdentitySSIBlockchainSchema MatchingMetadata Matching

Self-Sovereign Identity (SSI) is a privacy-preserving identity paradigm where users own and manage their digital identities. SSI is also referred to as blockchain identity, as it is commonly implemented using distributed ledger technologies. In this work, we describe the problem of schema matching on blockchain-based SSI implementations, systematically review the literature for tools that attack this problem, introduce a novel solution, and empirically compare it with the works reported from our literature review. Our solution uses pre-trained word vectors to find semantic similarities between user queries and schemas on the blockchain. Experimental evaluation shows that it outperforms existing solutions regarding queries that approach natural language.

2019

2019Short papersPortugueseConference

Implementation and Comparison of Cryptanalytic Trade-offs

Lívia R. E. Silva, Fernanda L. Müller, Yolanda C. Colombo, Frederico Schardong

Proceedings of the IV Teaching, Research and Outreach Showcase of IFRS Campus Rolante

CryptographyHash FunctionsTrade-off

Information security plays a central role in today's society, protecting sensitive communications and financial transactions and authenticating entities on the Internet. Hash functions are widely used in these applications. These deterministic one way functions take any input and produce a random fixed size output that cannot be reversed back to the input. This experimental research empirically compares three computational characteristics, namely disk storage, memory use and processing, of three cryptanalytic trade-off techniques that invert the output of hash functions. The techniques were implemented in Python and compared along three dimensions: a brute force attack for processing, and a dictionary attack for memory and for disk. Since the Hellman and Rainbow Tables techniques are probabilistic, that is, they offer no guarantee that every hash in the database can be inverted, only the tests in which all submitted hashes were inverted were analysed. The third algorithm, called Vanilla, is the only non-probabilistic one, so every hash in its database is always reversible. Each technique was submitted to multiple runs with varying configuration parameters over the same input set. Considering only the runs with full success that use half of the disk space of a dictionary attack, Rainbow Tables, Hellman and Vanilla required 0.0038, 0.0055 and 0.213 times the processing of a brute force attack, and used 3, 0.15 and 0.002 times the memory of a dictionary attack. The probabilistic algorithms need about 45 times less processing than Vanilla, while Hellman and Rainbow Tables use roughly 75 and 1500 times more memory during inversion. The conclusion is that, despite performing more hash operations, Vanilla uses exponentially less memory than the probabilistic algorithms, which makes it competitive on architectures that favour processing over memory, such as GPUs and FPGAs.

2018

2018Full papersEnglishConference

Providing cognitive components with a bidding heuristic for emergent NFV orchestration

Frederico Schardong, Ingrid Nunes, Alberto Schaeffer-Filho

NOMS 2018-2018 IEEE/IFIP Network Operations and Management Symposium

Network Functions VirtualisationVirtual Network FunctionsEmergent BehaviorReverse Auction

Network function virtualisation (NFV) decouples network functions from the underlying hardware by means of virtualisation, thus enabling the replacement of proprietary middleboxes by software components that can be dynamically deployed and configured on demand. The selection of the most appropriate virtual network functions (VNFs) to achieve a particular objective, and the decision on where to deploy these VNFs and through which paths they will communicate, are the responsibilities of an NFV orchestrator. In this paper, we propose to orchestrate VNFs using interacting cognitive components structured with the BDI architecture, leading to emergent solutions to address network challenges. More specifically, we extend a previously proposed reverse auction protocol and propose a novel bidding heuristic that can be used to make decisions regarding the orchestration tasks. We validate our model in a DDoS attack case study, in which we demonstrate that our components can successfully mitigate the attack.

2018Theses and dissertationsEnglish

Taming NFV orchestration using decentralised cognitive components

Frederico Schardong

Federal University of Rio Grande do Sul

Network Functions VirtualisationMulti-agent SystemsBDI Architecture

Network Functions Virtualisation (NFV) decouples network functions from physical devices, simplifying the deployment of new services. Typical network functions, like firewalls, traffic accelerators, intrusion detection systems and intrusion prevention systems, are traditionally performed by proprietary physical appliances, which must be manually installed by network operators. Their deployment is challenging because they have specific chaining requirements. As opposed to traditional physical appliances, virtual network functions (VNFs) can be dynamically deployed and reconfigured on demand, posing strict management challenges to networked systems. The selection of the most appropriate VNFs to achieve a particular objective, the decision on where to deploy these VNFs and through which paths they will communicate are the responsibilities of an NFV orchestrator. In this dissertation, we propose to orchestrate VNFs using interacting cognitive components structured with the belief-desire-intention (BDI) architecture, leading to emergent solutions to address network challenges. The BDI architecture includes a reasoning cycle, which provides agents with rational behaviour, allowing agents to deal with different scenarios in which flexible and intelligent behaviour is needed. We extend the NFV architecture, replacing its centralised orchestrator with BDI agents. Our proposal includes a reverse auction protocol and a novel bidding heuristic that allow agents to make decisions regarding the orchestration tasks. Finally, we provide a testbed that integrates a platform for developing BDI agents with a network emulator, allowing agents to control VNFs and perceive the network. This testbed is used to implement VNFs and empirically evaluate our theoretical model in a distributed denial-of-service (DDoS) attack. The evaluation results show that a solution to the DDoS attack emerges through the negotiation of agents, successfully mitigating the attack.

2018Short papersPortugueseConference

Supporting Distance Education with Moodle

Sabrina F. Antunes, Frederico Schardong, Gabriela C. Santos

Proceedings of the III Teaching, Research and Outreach Showcase of IFRS Campus Rolante

Virtual Learning EnvironmentsDistance EducationMoodle

The technological complexity brought by information and communication technologies has immersed contemporary society in a context where these technologies strongly shape people's lives, changing how they communicate and how they reach information. New forms of teaching and, above all, of learning emerged with them, making distance education possible. A key element of this form of education is the virtual learning environment, the software that supports teaching and learning activities. IFRS adopts Moodle as its standard environment, which demands a degree of confidence with computing resources from students. This project therefore set out to build technological fluency among students and teachers at IFRS Campus Rolante so that they can carry out distance education activities. The work has been conducted through in person support offered by the scholarship holder and through training sessions shaped by the demands of each class. Since the project began, the use of Moodle as a teaching and learning resource has grown steadily.

2017

2017Full papersEnglishJournal

BDI2DoS: An application using collaborating BDI agents to combat DDoS attacks

Ingrid Nunes, Frederico Schardong, Alberto Schaeffer-Filho

Journal of Network and Computer Applications

Network ResilienceMulti-Agent SystemsBDI Architecture

Computer networks are critical to many tasks in our daily lives. Therefore, mechanisms that guarantee the resilience of the network must be provided. Different approaches have been proposed to address potential challenges to network operation, but they rely on rigid solutions, which work only in anticipated scenarios. To address this issue, this paper presents BDI2DoS, which is a multi-agent innovative application that ensures the resilience of networks against the widely known Distributed Denial-of-Service (DDoS) attack. We take an existing network resilience strategy based on event–condition–action (ECA) policies to combat DDoS attacks, and use it as a requirement to specify the behaviour that must emerge from the interaction among agents, which together are capable of detecting and remediating anomalies that are considered a DDoS threat, in a flexible way. Agents in our multi-agent system follow the widely used BDI architecture, and were implemented with the BDI4JADE agent platform. In order to evaluate the effectiveness of BDI2DoS, we used the PReSET resilience simulator and BDI4JADE to build an integrated testbed. Our experiments compare the effectiveness of the ECA and the BDI-based resilience strategies and show that the latter is more flexible and able to cope with problems that occur during the execution of the anticipated behaviour.

2017Full papersEnglishConference

A distributed NFV orchestrator based on BDI reasoning

Frederico Schardong, Ingrid Nunes, Alberto Schaeffer-Filho

2017 IFIP/IEEE Symposium on Integrated Network and Service Management (IM)

BDI ArchitectureNetwork Functions VirtualisationOrchestrationMulti-Agent Systems

Network function virtualisation (NFV) decouples network functions from physical devices, simplifying the deployment of new services. As opposed to traditional middleboxes, VNFs can be dynamically deployed and reconfigured on demand, posing strict management challenges to networked systems. Selecting VNFs from a repository, defining where they will be placed in the virtualised network as well as chaining them to achieve the desired behaviour are problems that have to be tackled by an orchestrator. In this paper, we propose a distributed approach to NFV orchestration using belief-desire-intention (BDI) reasoning, addressing the selection, placement and chaining problems through the interaction among autonomous software agents, which collectively work in a distributed and decentralised manner. Agents are capable of bidding on the allocation of resources for new VNFs, as well as managing the chaining of VNFs. Further, we validate our theoretical model through a DDoS attack case study, in which we analyse the emergent behaviour of the autonomous agents.

2016

2016Full papersEnglishConference

A Non-Probabilistic Time-Storage Trade-off for Unsalted Hashes

Frederico Schardong, Daniel Formolo

Annals of the XVI Brazilian Symposium on Information and Computational Systems Security

HashtableAlgorithmsSecurityRainbow Tables

This work proposes a new cryptanalytic non-probabilistic trade-off for unsalted hashes. It presents the main cryptanalytic trade-offs, making a comparison with the proposed method. Although the number of hash operations to recover an element is high compared with the traditional methods, the new method has the advantage of guaranteed success on the recovery of hashes, minimal and sequential disk read operations, unlike the existing probabilistic trade-offs.

2015

2015Full papersEnglishConference

EXCITE: Exploring collaborative interaction in tracked environments

Nicolai Marquardt, Frederico Schardong, Anthony Tang

Human-Computer Interaction–INTERACT 2015: 15th IFIP TC 13 International Conference, Bamberg, Germany, September 14-18, 2015, Proceedings, Part II 15

Interaction AnalysisCollaborative InteractionTracked Environments

A central issue in designing collaborative multi-surface environments is evaluating the interaction techniques, tools, and applications that we design. We often analyse data from studies using inductive video analysis, but the volume of data makes this a time-consuming process. We designed EXCITE, which gives analysts the ability to analyse studies by quickly querying aspects of people's interactions with applications and devices around them using a declarative programmatic syntax. These queries provide simple, immediate visual access to matching incidents in the interaction stream, video data, and motion-capture data. The query language filters the volume of data that needs to be reviewed based on criteria such as application events, and proxemics events, such as distance or orientation between people and devices. This general approach allows analysts to provisionally develop theories about the use of multi-surface environments, and to evaluate them rapidly through video-based evidence.

2014

2014Theses and dissertationsPortuguese

A Proposal for a Non-Probabilistic Cryptanalytic Trade-off

Frederico Schardong

University of Vale do Rio dos Sinos

Trade-offHashCryptanalysis

This work proposes a new non-probabilistic cryptanalytic trade-off method. It reviews the main cryptanalytic trade-offs and draws a parallel with the proposed method. Although the number of hash operations needed to recover an element is high compared to traditional methods, the new method guarantees successful recovery and requires a minimal number of sequential disk reads, unlike the main probabilistic trade-offs in use.

2012

2009

2009Theses and dissertationsPortuguese

Computer Numerical Control: Building the Hardware and Software of a Printer

Frederico Schardong

Estrela State School of Professional Education

Computer Numerical ControlAutomationMechatronicsPrinterMicrocontrollerPICCGTK

This work built the hardware and the software of a Computer Numerical Control (CNC) machine that draws on paper with a ballpoint pen. The hardware was assembled from parts of other printers and electronic scrap. The software consists of two programs. The first is a desktop application written in C with a GTK+ interface that offers the operator several ways of interacting with the machine: driving both axes with a joystick, drawing in a graphical editor, and selecting images from the computer for printing. In the latter case, the application previews how the image will look once printed in two colours. The second program runs on the microcontroller and carries out the high level commands received from the desktop application over a network protocol designed as part of the work. Because of the memory limit, images are sent in parts while they are being printed. The microcontroller drives the stepper motors of the X and Y axes and the direct current motor of the Z axis as it interprets the commands or the image it receives.