首页> 外文期刊>Computers & Security >Safeguarding a formalized Blockchain-enabled identity-authentication protocol by applying security risk-oriented patterns
【24h】

Safeguarding a formalized Blockchain-enabled identity-authentication protocol by applying security risk-oriented patterns

机译:通过应用面向安全风险的模式来保护正式的启用了区块链的身份认证协议

获取原文
获取原文并翻译 | 示例
       

摘要

Designing government independent and secure identification- and authentication protocols is a challenging task. Design flaws and missing specifications as well as security- and privacy issues of such protocols pose considerable user risks. Formal methods, such as Colored Petri Nets (CPN), are utilised for the design, development and analysis of such new protocols in order to detect flaws and mitigate identified security risks before deployment. This paper fills the gap, by applying in a novel way a set of security risk-oriented patterns (SRP) to the so-called Authcoin protocol that we formalise using CPN. The initial formal model of Authcoin facilitates the detection and elimination of design flaws, missing specifications as well as security- and privacy issues. The additional risk- and threat analysis based on the Information Systems Security Risk Management (ISSRM) domain model we perform on the formal CPN models of the protocol. The identified risks are mitigated by applying SRPs to the formal model of the Authcoin protocol. SRPs are a means to mitigate common security- and privacy risks in a business-process context by applying thoroughly tested and proven best-practice solutions. The goal of this work is to test the utility of SRPs outside of the the usual application domain, to reduce the risks and vulnerabilities of the Authcoin protocol. (C) 2019 Elsevier Ltd. All rights reserved.
机译:设计政府独立且安全的标识和认证协议是一项艰巨的任务。这种协议的设计缺陷和规范缺失以及安全性和隐私性问题给用户带来了很大的风险。诸如彩色Petri网(CPN)之类的正式方法用于此类新协议的设计,开发和分析,以便在部署之前检测缺陷并减轻已识别的安全风险。本文通过以新颖的方式将一组面向安全风险的模式(SRP)应用于我们使用CPN形式化的所谓Authcoin协议,填补了这一空白。 Authcoin的初始正式模型有助于检测和消除设计缺陷,规范缺失以及安全和隐私问题。我们基于协议的正式CPN模型执行的基于信息系统安全风险管理(ISSRM)域模型的其他风险和威胁分析。通过将SRP应用于Authcoin协议的正式模型,可以减轻已识别的风险。 SRP是一种通过应用经过全面测试和验证的最佳实践解决方案来减轻业务流程环境中常见的安全和隐私风险的方法。这项工作的目标是在常规应用程序域之外测试SRP的实用程序,以降低Authcoin协议的风险和漏洞。 (C)2019 Elsevier Ltd.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号