【24h】

DPWSec: Devices profile for Web Services Security

机译:DPWSec:Web服务安全性的设备配置文件

获取原文

摘要

As cyber-physical systems (CPS) build a foundation for visions such as the Internet of Things (IoT) or Ambient Assisted Living (AAL), their communication security is crucial so they cannot be abused for invading our privacy and endangering our safety. In the past years many communication technologies have been introduced for critically resource-constrained devices such as simple sensors and actuators as found in CPS. However, many do not consider security at all or in a way that is not suitable for CPS. Also, the proposed solutions are not interoperable although this is considered a key factor for market acceptance. Instead of proposing yet another security scheme, we looked for an existing, time-proven solution that is widely accepted in a closely related domain as an interoperable security framework for resource-constrained devices. The candidate of our choice is the Web Services Security specification suite. We analysed its core concepts and isolated the parts suitable and necessary for embedded systems. In this paper we describe the methodology we developed and applied to derive the Devices Profile for Web Services Security (DPWSec). We discuss our findings by presenting the resulting architecture for message level security, authentication and authorization and the profile we developed as a subset of the original specifications. We demonstrate the feasibility of our results by discussing the proof-of-concept implementation of the developed profile and the security architecture.
机译:随着网络物理系统(CPS)为诸如物联网(IoT)或环境辅助生活(AAL)之类的愿景奠定基础,它们的通信安全至关重要,因此不能滥用它们来侵犯我们的隐私并危及我们的安全。在过去的几年中,已为严重限制资源的设备引入了许多通信技术,例如CPS中的简单传感器和执行器。但是,许多人根本没有考虑安全性,或者根本不考虑CPS的安全性。而且,尽管这被认为是市场接受的关键因素,但提出的解决方案也不是可互操作的。我们没有提出另一种安全方案,而是寻找一种经过时间验证的现有解决方案,该解决方案在密切相关的领域中被广泛接受为资源受限设备的可互操作的安全框架。我们选择的候选者是Web服务安全性规范套件。我们分析了其核心概念,并隔离了适用于嵌入式系统的必要部件。在本文中,我们描述了我们开发并应用于导出Web服务安全设备配置文件(DPWSec)的方法。我们通过介绍用于消息级别安全性,身份验证和授权的最终体系结构以及作为原始规范的子集而开发的配置文件来讨论我们的发现。我们通过讨论开发的配置文件和安全体系结构的概念验证实现来证明我们的结果的可行性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号