首页> 外文会议>International conference on business process management >Secured and Flexible Blockchain-Based Non-governmental Identity-Authentication for Sociotechnical Systems Applications
【24h】

Secured and Flexible Blockchain-Based Non-governmental Identity-Authentication for Sociotechnical Systems Applications

机译:基于SocioTechnical Systems应用的安全和灵活的基于区块链的非政府身份认证

获取原文

摘要

In his talk, the author aims to give an overview of his curious way into security research that culminates in experiencing the Estonian elD system with all its pros and cons. Realizing that government-based identity authentication is potentially a threat to the freedoms of individual citizens, the keynote speech focuses on ongoing research about the non-governmental blockchain-based Authcoin system that is developed formally using Colored Petri Nets (CPN) and further security checked with a set of security risk-oriented patterns (SRP). The initial formal model of Authcoin facilitates the detection and elimination of design flaws, missing specifications as well as security-and privacy issues. The additional risk- and threat analysis based on the Information Systems Security Risk Management (ISSRM) domain model, we perform on the formal CPN models of the protocol. The identified risks are mitigated by applying security risk patterns (SRP) to the formal model of the Authcoin protocol. SRPs are a means to mitigate common security- and privacy risks in a business-process context by applying thoroughly tested and proven best-practice solutions. Thus, by applying such a security test on the untypical domain of the highly distributed CPN-formalized Authcoin protocol, we perform a stress test for the ISSRM and existing set of SRPs that yields limitations, open issues and scope for future work. Since Authcoin is implemented as a first feasibility prototype with the blockchain-based Qtum smart-contracts system for which Alex wrote the ICO-whitepaper, he presents also the planned technical realization path for Authcoin.
机译:在他的谈话中,提交人旨在概述他对安全研究的好奇方式,以至于经历Estonian ELD系统的所有优缺点。意识到基于政府的身份认证可能对个人公民的自由造成威胁,主题演讲侧重于关于非政府区块基因的持续研究,该系统是在正式使用彩色Petri网(CPN)和进一步的安全检查的基于非政府区块基因的Authcoin系统。使用一系列安全风险风险模式(SRP)。 Authcoin的初始正式模型有助于检测和消除设计缺陷,缺少规格以及安全和隐私问题。基于信息系统安全风险管理(ISSRM)域模型的额外风险和威胁分析,我们在协议的正式CPN模型上执行。通过将安全风险模式(SRP)应用于Authcoin议定书的正式模型来缓解所识别的风险。 SRPS是一种通过应用彻底测试和经过验证的最佳实践解决方案来缓解业务过程上下文中的常见安全性和隐私风险的方法。因此,通过对高度分布式CPN形式的Authcoin协议的无典型领域应用此类安全测试,我们对ISSRM和现有SRP组的应力测试产生了产生的限制,开放问题和未来工作的范围。由于Authcoin被实施为具有基于区块链的Qtum Smart-Contracts系统的第一个可行性原型,因为亚历克斯写了ICO-WhitePaper,但他也提出了针对Authcoin的计划技术实现路径。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号