首页> 外文会议>IEEE/IFIP Network Operations and Management Symposium >Trustworthy configuration management for networked devices using distributed ledgers
【24h】

Trustworthy configuration management for networked devices using distributed ledgers

机译:使用分布式分类帐的网络设备的可信配置管理

获取原文

摘要

Numerous IoT applications, like building automation or process control of industrial sites, exist today. These applications inherently have a strong connection to the physical world. Hence, IT security threats cannot only cause problems like data leaks but also safety issues which might harm people. Attacks on IT systems are not only performed by outside attackers but also insiders like administrators. For this reason, we present ongoing work on a Byzantine fault tolerant configuration management system (CMS) that provides control over administrators, restrains their rights, and enforces separation of concerns. We reach this goal by conducting a configuration management process that requires multi-party authorization for critical configurations to prevent individual malicious administrators from performing undesired actions. Only after a configuration has been authorized by multiple experts, it is applied to the targeted devices. For the whole configuration management process, our CMS guarantees accountability and traceability. Lastly, our system is tamper-resistant as we leverage Hyperledger Fabric, which provides a distributed execution environment for our CMS and a blockchain-based distributed ledger that we use to store the configurations. A beneficial side effect of this approach is that our CMS is also suitable to manage configurations for infrastructure shared across different organizations that do not need to trust each other.
机译:今天,存在许多物联网应用,例如楼宇自动化或工业现场的过程控制。这些应用程序本质上与物理世界有着紧密的联系。因此,IT安全威胁不仅会导致诸如数据泄漏之类的问题,而且还会导致可能危害人员的安全问题。对IT系统的攻击不仅由外部攻击者执行,而且还由管理员等内部人员执行。因此,我们提出了拜占庭容错配置管理系统(CMS)正在进行的工作,该系统可对管理员进行控制,限制其权限并强制分离关注点。我们通过执行配置管理过程来实现此目标,该过程要求对关键配置进行多方授权,以防止单个恶意管理员执行不希望的操作。仅在多个专家授权配置后,该配置才会应用于目标设备。在整个配置管理过程中,我们的CMS保证了责任制和可追溯性。最后,由于我们利用Hyperledger Fabric,因此我们的系统具有防篡改功能,它为CMS提供了分布式执行环境,并为我们提供了用于存储配置的基于区块链的分布式分类帐。这种方法的一个有益的副作用是,我们的CMS也适用于管理不需要相互信任的不同组织之间共享的基础结构的配置。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号