首页> 外文期刊>Computers & Security >A constraint and risk-aware approach to attribute-based access control for cyber-physical systems
【24h】

A constraint and risk-aware approach to attribute-based access control for cyber-physical systems

机译:网络物理系统基于属性的访问控制的约束和风险感知方法

获取原文
获取原文并翻译 | 示例
           

摘要

Cyber-physical systems (CPSs) integrate cyber components and physical processes. This integration enhances the capabilities of physical systems by incorporating intelligence into objects and services. On the other hand, the integration of cyber and physical components and the interaction between them introduce new security threats. Since CPSs are mostly safety-critical systems, data stored and communicated in them are highly critical. Hence, there is a crucial need for protecting the data and resources in CPSs against unauthorized accesses. In this paper, we propose an access control (AC) framework to address CPS related security issues. The proposed framework consists of two parts: a Cyber-Physical Access Control model (CPAC) and a Generalized Action Generation Model (GAGM). CPAC utilizes an attribute-based approach and extends it with cyber-physical components and cyber-physical interactions. In addition, we incorporate Separation of Duty (SoD) constraints into the CPAC model. GAGM is used to augment the enforcement of access policies. We present formal representations of CPAC and GAGM and demonstrate their use in a sample scenario for a medical CPS. We propose an algorithm for enforcing authorization policies. We implement the CPAC model and compare its performance against the core attribute-based access control model. We present an authorization enforcement approach and show through our experimental results its feasibility.
机译:网络物理系统(CPSS)集成网络组件和物理过程。这种集成通过将智能结合到物体和服务来增强物理系统的能力。另一方面,网络和物理成分的整合以及它们之间的互动引入了新的安全威胁。由于CPS主要是安全关键系统,因此存储和传送的数据非常关键。因此,对于保护CPS中的数据和资源,对未经授权的访问来说是至关重要的。在本文中,我们提出了一个访问控制(AC)框架来解决CPS相关的安全问题。所提出的框架由两部分组成:网络物理访问控制模型(CPAC)和广义动作生成模型(GAGM)。 CPAC利用基于属性的方法,并将其与网络物理分量和网络物理交互扩展。此外,我们将占空比(SOD)限​​制的分离纳入CPAC模型。 GAGM用于增强访问策略的执行。我们呈现CPAC和GAGM的正式陈述,并展示他们在医疗CPS的示例场景中使用。我们提出了一种算法来执行授权策略。我们实现了CPAC模型,并将其对基于核心属性的访问控制模型进行了性能。我们介绍了一项授权执法方法,并通过我们的实验结果显示其可行性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号