首页> 外文会议>International Conference on Information, Intelligence, Systems and Applications >A trusted computing architecture for critical infrastructure protection
【24h】

A trusted computing architecture for critical infrastructure protection

机译:可信赖的计算架构可用于关键基础架构保护

获取原文

摘要

Most critical infrastructures can be modeled as cyber-physical systems whose cyber components control underlying physical processes so as to optimize system objectives based on physical properties/constraints and the current and estimated state of the system. Such systems usually require performance guarantees and support for security: wrongly received or missed commands can render the entire system unstable. Yet, securing cyber-physical systems with heterogeneous components is still an open and challenging problem. In this paper we propose a trusted computing architecture for critical infrastructure protection based on the trusted computing paradigm. We discuss the threat model, the vulnerabilities, real-time availability, run-time integrity and show how to get resilience against intentional and unintentional faults by using trusted computing enabled components and an access control structure that enforces need-to-get-now (availability) policies. We conclude by showing how this approach can be used to secure substation automation systems of an IEC/TR 61850–90–5-compliant electricity grid.
机译:可以将大多数关键基础结构建模为网络物理系统,其网络组件控制底层物理过程,从而根据物理属性/约束以及系统的当前和估计状态优化系统目标。此类系统通常需要性能保证和对安全性的支持:错误接收或丢失命令会导致整个系统不稳定。但是,使用异构组件保护网络物理系统仍然是一个开放且具有挑战性的问题。在本文中,我们提出了一种基于可信计算范式的用于关键基础设施保护的可信计算体系结构。我们讨论了威胁模型,漏洞,实时可用性,运行时完整性,并展示了如何通过使用受信任的支持计算的组件和强制实施即需即用的访问控制结构来获得针对有意和无意的故障的恢复能力(可用性)政策。最后,我们将展示如何使用这种方法来保护符合IEC / TR 61850–90–5的电网的变电站自动化系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号