A topology-aware access control model for collaborative cyber-physical spaces: Specification and verification

被引:8
|
作者
Cao, Yan [1 ,3 ]
Huang, Zhiqiu [1 ,3 ,4 ]
Ke, Changbo [2 ,5 ]
Xie, Jian [1 ,3 ]
Wang, Jinyong [1 ,3 ]
机构
[1] Nanjing Univ Aeronaut & Astronaut, Dept Comp Sci & Technol, Nanjing 211106, Jiangsu, Peoples R China
[2] Nanjing Univ Aeronaut & Astronaut, Nanjing 211106, Jiangsu, Peoples R China
[3] Minist Ind & Informat Technol, Key Lab Safety Crit Software, Nanjing 211106, Jiangsu, Peoples R China
[4] Collaborat Innovat Ctr Novel Software Technol & I, Nanjing 211106, Jiangsu, Peoples R China
[5] Nanjing Univ Posts & Telecommun, Nanjing 210023, Jiangsu, Peoples R China
基金
中国国家自然科学基金;
关键词
Cross-domain authorization; Access control; Cyber-physical space; Bigraphs; Model checking; MULTI-DOMAINS; ENFORCEMENT; CHECKING;
D O I
10.1016/j.cose.2019.02.013
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In collaborative environment, distributed multiple cyber-physical spaces interoperate with each other aiming to provide an intelligent spatial environment for their users to conduct their collaborative activities. Subjects and objects roam in the physical and cyber spaces among domains to support the completion of the activities. These dynamic behaviors bring great challenges to security issue. The actions of roaming subjects and roaming objects need to be specified and checked against security requirements of constituent domains. However, the existing inter-domain access control models was proposed for the traditional information system and focus on the cyber security. They cannot deal with the intricacies of cross-domain access requests in cyber-physical spaces. In this paper, we propose a formal inter-domain model to specify cyber-physical access control policies and a model checking approach to ensure security requirements hold in these policies. We first present a formal definition of the topology configuration to capture the environment characteristics of the cyber-physical spaces. It provides important contextual information for the access control system. Then, based on topology attributes defined in the topology configuration, a topology-aware inter-domain access control model TA-CPAC is proposed. It can adjust the permission assignment adaptively to react to the behaviors changes of subjects and objects. Next, the topology configuration and TA-CPAC model are formalized by the use of bigraphs and bigraphs reactive systems respectively, which allows us to utilize the model checking technology to reason about that whether the behaviors of roaming subjects and objects satisfy security requirements of all constituent domains. Finally, the effectiveness of our approach is evaluated by a collaborative scenario in a smart city. (C) 2019 Elsevier Ltd. All rights reserved.
引用
收藏
页数:17
相关论文
共 50 条
  • [1] Specification and Verification of a Topology-Aware Access Control Model for Cyber-Physical Space
    Cao, Yan
    Huang, Zhiqiu
    Kan, Shuanglong
    Fan, Dajuan
    Yang, Yang
    TSINGHUA SCIENCE AND TECHNOLOGY, 2019, 24 (05) : 497 - 519
  • [2] Specification and Verification of a Topology-Aware Access Control Model for Cyber-Physical Space
    Yan Cao
    Zhiqiu Huang
    Shuanglong Kan
    Dajuan Fan
    Yang Yang
    Tsinghua Science and Technology, 2019, 24 (05) : 497 - 519
  • [3] Topology-Aware Access Control of Smart Spaces
    Pasquale, Liliana
    Ghezzi, Carlo
    Pasi, Edoardo
    Tsigkanos, Christos
    Boubekeur, Menouer
    Florentino-Liano, Blanca
    Hadzic, Tarik
    Nuseibeh, Bashar
    COMPUTER, 2017, 50 (07) : 54 - 63
  • [4] A topology and risk-aware access control framework for cyber-physical space
    Yan Cao
    Zhiqiu Huang
    Yaoshen Yu
    Changbo Ke
    Zihao Wang
    Frontiers of Computer Science, 2020, 14
  • [5] A topology and risk-aware access control framework for cyber-physical space
    Cao, Yan
    Huang, Zhiqiu
    Yu, Yaoshen
    Ke, Changbo
    Wang, Zihao
    FRONTIERS OF COMPUTER SCIENCE, 2020, 14 (04)
  • [6] Specification and adaptive verification of access control policy for cyber-physical-social spaces
    Cao, Yan
    Ping, Yuan
    Tao, Shaohua
    Chen, YongGang
    Zhu, YanXia
    COMPUTERS & SECURITY, 2022, 114
  • [7] Modeling and Verification of Evolving Cyber-Physical Spaces
    Tsigkanos, Christos
    Kehrer, Timo
    Ghezzi, Carlo
    ESEC/FSE 2017: PROCEEDINGS OF THE 2017 11TH JOINT MEETING ON FOUNDATIONS OF SOFTWARE ENGINEERING, 2017, : 38 - 48
  • [8] A Risk-Aware Access Control Framework for Cyber-Physical Systems
    Akhuseyinoglu, Nuray Baltaci
    Joshi, James
    2017 IEEE 3RD INTERNATIONAL CONFERENCE ON COLLABORATION AND INTERNET COMPUTING (CIC), 2017, : 349 - 358
  • [9] Generic Negative Scenarios for the Specification of Collaborative Cyber-Physical Systems
    Stenkova, Viktoria
    Brings, Jennifer
    Daun, Marian
    Weyer, Thorsten
    CONCEPTUAL MODELING, ER 2019, 2019, 11788 : 412 - 419
  • [10] Ariadne: Topology Aware Adaptive Security for Cyber-Physical Systems
    Tsigkanos, Christos
    Pasquale, Liliana
    Ghezzi, Carlo
    Nuseibeh, Bashar
    2015 IEEE/ACM 37TH IEEE INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, VOL 2, 2015, : 729 - 732