...
首页> 外文期刊>Frontiers of computer science >A topology and risk-aware access control framework for cyber-physical space
【24h】

A topology and risk-aware access control framework for cyber-physical space

机译:网络物理空间的拓扑和风险感知访问控制框架

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Cyber-physical space is a spatial environment that integrates the cyber world and the physical world, aiming to provide an intelligent environment for users to conduct their day-to-day activities. The interplay between the cyber space and physical space proposes specific security requirements that are not captured by traditional access control frameworks. On one hand, the security of the physical space and the cyber space should be both concerned in the cyber-physical space. On the other hand, the bad results caused by failure in providing secure policy enforcement may directly affect the controlled physical world. In this paper, we propose an effective access control framework for the cyber-physical space. Firstly, a topology-aware access control (TAAC) model is proposed. It can express the cyber access control, the physical access control, and the interaction access control simultaneously. Secondly, a risk assessment approach is proposed for the policy enforcement phase. It is used to evaluate the user behavior and ensures that the suspicious behaviors executed by authorized users can be handled correctly. Thirdly, we propose a role activation algorithm to ensure that the objects are accessed only by legal and honest users. Finally, we evaluate our approach by using an illustrative example and the performance analysis. The results demonstrate the feasibility of our approach.
机译:网络物理空间是一个空间环境,整合网络世界和物理世界,旨在为用户提供智能环境来进行日常活动。网络空间和物理空间之间的相互作用提出了传统访问控制框架未捕获的特定安全要求。一方面,物理空间和网络空间的安全性应该在网络物理空间中关注。另一方面,由于提供安全策略执行而导致的不良结果可能直接影响受控的物理世界。在本文中,我们为网络物理空间提出了有效的访问控制框架。首先,提出了一种拓扑意识的访问控制(TAAC)模型。它可以同时表达网络访问控制,物理访问控制和交互访问控制。其次,提出了策略执法阶段的风险评估方法。它用于评估用户行为,并确保可以正确处理由授权用户执行的可疑行为。第三,我们提出了一个角色激活算法,以确保仅通过合法和诚实的用户访问对象。最后,我们通过使用说明性示例和性能分析来评估我们的方法。结果表明了我们方法的可行性。

著录项

  • 来源
    《Frontiers of computer science》 |2020年第4期|144805.1-144805.15|共15页
  • 作者单位

    School of Computer Science and Technology Nanjing University of Aeronautics and Astronautics Nanjing 211106 China Key Laboratory of Safety-Critical Software(Ministry of Industry and Information Technology) Nanjing 211106 China;

    School of Computer Science and Technology Nanjing University of Aeronautics and Astronautics Nanjing 211106 China Key Laboratory of Safety-Critical Software(Ministry of Industry and Information Technology) Nanjing 211106 China Collaborative Innovation Center of Novel Software Technology and Industrialization Nanjing 211106 China;

    School of Computer Science and Technology Nanjing University of Aeronautics and Astronautics Nanjing 211106 China Key Laboratory of Safety-Critical Software(Ministry of Industry and Information Technology) Nanjing 211106 China;

    School of Computer Science and Technology Nanjing University of Aeronautics and Astronautics Nanjing 211106 China School of Computer Science Nanjing University of Posts and Telecommunications Nanjing 210023 China;

    School of Computer Science and Technology Nanjing University of Aeronautics and Astronautics Nanjing 211106 China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    cyber-physical space; access control; risk management; role activation;

    机译:网络物理空间;访问控制;风险管理;角色激活;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号