【24h】

LUCON: Data Flow Control for Message-Based IoT Systems

机译:LUCON:基于消息的物联网系统的数据流控制

获取原文
获取原文并翻译 | 示例

摘要

Today's emerging Industrial Internet of Things (IIoT) scenarios are characterized by the exchange of data between services across enterprises. Traditional access and usage control mechanisms are only able to determine if data may be used by a subject, but lack an understanding of how it may be used. The ability to control the way how data is processed is however crucial for enterprises to guarantee (and provide evidence of) compliant processing of critical data, as well as for users who need to control if their private data may be analyzed or linked with additional information - a major concern in IoT applications processing personal information. In this paper, we introduce LUCON, a data-centric security policy framework for distributed systems that considers data flows by controlling how messages may be routed across services and how they are combined and processed. LUCON policies prevent information leaks, bind data usage to obligations, and enforce data flows across services. Policy enforcement is based on a dynamic taint analysis at runtime and an upfront static verification of message routes against policies. We discuss the semantics of these two complementing enforcement models and illustrate how LUCON policies are compiled from a simple policy language into a first-order logic representation. We demonstrate the practical application of LUCON in a real-world IoT middleware and discuss its integration into Apache Camel. Finally, we evaluate the runtime impact of LUCON and discuss performance and scalability aspects.
机译:当今新兴的工业物联网(IIoT)场景的特征在于企业之间服务之间的数据交换。传统的访问和使用控制机制仅能够确定对象是否可以使用数据,但缺乏对如何使用数据的理解。但是,控制数据处理方式的能力对于企业保证(并提供证据)对关键数据的合规处理以及对于需要控制是否可以分析其私人数据或将其与其他信息链接的用户而言至关重要。 -物联网应用程序处理个人信息中的主要问题。在本文中,我们介绍LUCON,这是一种用于分布式系统的以数据为中心的安全策略框架,该框架通过控制如何跨服务路由消息以及如何对其进行组合和处理来考虑数据流。 LUCON策略可防止信息泄漏,将数据使用情况与义务绑定在一起并在服务之间强制执行数据流。策略实施基于运行时的动态污点分析和针对策略的消息路由的前期静态验证。我们讨论了这两个互补的执行模型的语义,并说明了LUCON策略如何从简单的策略语言编译成一阶逻辑表示形式。我们演示了LUCON在实际的IoT中间件中的实际应用,并讨论了其在Apache Camel中的集成。最后,我们评估LUCON对运行时的影响,并讨论性能和可伸缩性方面。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号