首页> 外文会议>International Conference on Formal Methods in Software Engineering >Formally Verified Credentials Management for Industrial Control Systems
【24h】

Formally Verified Credentials Management for Industrial Control Systems

机译:用于工业控制系统的正式验证凭证管理

获取原文

摘要

The field of industrial automation is experiencing growth in interconnectivity and digital interaction. This growth is slower than in a consumer segment due to often critical nature of industrial control systems. Security of such systems is an important aspect as malicious behaviors could lead to potential system malfunction, injuries or financial losses. As control networks are becoming more complex, having a robust credential management for system operators and users that could interact with the system components is an essential need. One way of assuring the robustness of the credential management is by using formal methods. In this paper we present a formally verified credential management system for use within industrial control systems. We demonstrate that the credential management can use centralized credential storage with secret passwords available only to system administrators. We use UPPAAL to formally analyze security properties based on requirements defined by our industrial partner and present the viability of formal verification to a real-world industrial case study.
机译:工业自动化领域正在经历互连和数字互动的增长。由于工业控制系统的经常危急性质,这种增长速度慢于消费者群体。这种系统的安全性是一个重要方面,因为恶意行为可能导致潜在的系统故障,伤害或金融损失。由于控制网络变得越来越复杂,具有适用于系统运营商和可以与系统组件交互的用户的强大凭证管理是必不可少的需求。确保凭证管理的稳健性的一种方法是使用正式方法。在本文中,我们提供了一个正式验证的凭证管理系统,用于工业控制系统。我们展示凭证管理可以使用仅使用秘密密码的集中凭证存储来提供给系统管理员。我们使用UPPAAL根据我们的工业合作伙伴定义的要求正式分析安全性质,并将正式验证的可行性呈现给现实世界的工业案例研究。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号