【24h】

Data Centered and Usage-Based Security Service

机译:数据居中和基于使用的安全服务

获取原文

摘要

Protecting Information Systems (IS) relies traditionally on security risk analysis methods. Designed for well-perimetrised environments, these methods rely on a systematic identification of threats and vulnerabilities to identify efficient control-centered protection countermeasures. Unfortunately, this does not fit security challenges carried out by the opened and agile organizations provided by the Social, Mobile, big data Analytics, Cloud and Internet of Things (SMACIT) environment. Due to their inherently collaborative and distributed organization, such multi-tenancy systems require the integration of contextual vulnerabilities, depending on the a priori unknown way of using, storing and exchanging data in opened cloud environment. Moreover, as data can be associated to multiple copies, different protection requirements can be set for each of these copies, which may lead the initial data owner lose control on the data protection. This involves (1) turning the traditional control-centered security vision to a dynamic data-centered protection and even (2) considering that the way a data is used can be a potential threat that may corrupt data protection efficiency. To fit these challenges, we propose a Data-centric Usage-based Protection service (DUP). This service is based on an information system meta-model, used to identify formally data assets and store the processes using copies of these assets. To define a usage-entered protection, we extend the Usage Based Access Control model, which is mostly focused on managing CRUD operations, to more complex operation fitting the SMACIT context. These usage rules are used to generate smart contracts, storing usage consents and managing usage control for cloud services.
机译:保护信息系统(IS)传统上依靠安全风险分析方法。这些方法专为围栏环境而设计,这些方法依赖于系统的识别威胁和漏洞,以确定有效的控制中心保护对策。不幸的是,这并不符合社会,移动,大数据分析,云和互联网(SMACIT)环境提供的开放和敏捷组织进行的安全挑战。由于其固有的协作和分布式组织,这种多租户系统需要集成上下文漏洞,具体取决于使用,存储和交换已打开的云环境中的数据的先验方式。此外,随着数据可以与多个副本相关联,可以为每个副本设置不同的保护要求,每个副本都可以引导初始数据所有者对数据保护进行控制。这涉及(1)将传统的控制中心的安全视觉转到动态数据中心保护甚至(2),考虑到使用数据的方式可能是可能损坏数据保护效率的潜在威胁。为了符合这些挑战,我们提出了一种以数据为中心的基于使用的保护服务(DUP)。此服务基于信息系统元模型,用于识别正式数据资产并使用这些资产的副本存储流程。要定义使用输入的保护,我们扩展了基于使用的访问控制模型,这些访问控制模型主要集中在管理CRUD操作,更复杂的操作拟合SMACIT上下文。这些使用规则用于生成智能合同,存储使用率同意并管理云服务的使用控制。

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号