A topology-aware access control model for collaborative cyber-physical spaces: Specification and verification

被引:8
|
作者
Cao, Yan [1 ,3 ]
Huang, Zhiqiu [1 ,3 ,4 ]
Ke, Changbo [2 ,5 ]
Xie, Jian [1 ,3 ]
Wang, Jinyong [1 ,3 ]
机构
[1] Nanjing Univ Aeronaut & Astronaut, Dept Comp Sci & Technol, Nanjing 211106, Jiangsu, Peoples R China
[2] Nanjing Univ Aeronaut & Astronaut, Nanjing 211106, Jiangsu, Peoples R China
[3] Minist Ind & Informat Technol, Key Lab Safety Crit Software, Nanjing 211106, Jiangsu, Peoples R China
[4] Collaborat Innovat Ctr Novel Software Technol & I, Nanjing 211106, Jiangsu, Peoples R China
[5] Nanjing Univ Posts & Telecommun, Nanjing 210023, Jiangsu, Peoples R China
基金
中国国家自然科学基金;
关键词
Cross-domain authorization; Access control; Cyber-physical space; Bigraphs; Model checking; MULTI-DOMAINS; ENFORCEMENT; CHECKING;
D O I
10.1016/j.cose.2019.02.013
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In collaborative environment, distributed multiple cyber-physical spaces interoperate with each other aiming to provide an intelligent spatial environment for their users to conduct their collaborative activities. Subjects and objects roam in the physical and cyber spaces among domains to support the completion of the activities. These dynamic behaviors bring great challenges to security issue. The actions of roaming subjects and roaming objects need to be specified and checked against security requirements of constituent domains. However, the existing inter-domain access control models was proposed for the traditional information system and focus on the cyber security. They cannot deal with the intricacies of cross-domain access requests in cyber-physical spaces. In this paper, we propose a formal inter-domain model to specify cyber-physical access control policies and a model checking approach to ensure security requirements hold in these policies. We first present a formal definition of the topology configuration to capture the environment characteristics of the cyber-physical spaces. It provides important contextual information for the access control system. Then, based on topology attributes defined in the topology configuration, a topology-aware inter-domain access control model TA-CPAC is proposed. It can adjust the permission assignment adaptively to react to the behaviors changes of subjects and objects. Next, the topology configuration and TA-CPAC model are formalized by the use of bigraphs and bigraphs reactive systems respectively, which allows us to utilize the model checking technology to reason about that whether the behaviors of roaming subjects and objects satisfy security requirements of all constituent domains. Finally, the effectiveness of our approach is evaluated by a collaborative scenario in a smart city. (C) 2019 Elsevier Ltd. All rights reserved.
引用
收藏
页数:17
相关论文
共 50 条
  • [21] Computationally Aware Switching Criteria for Hybrid Model Predictive Control of Cyber-Physical Systems
    Zhang, Kun
    Sprinkle, Jonathan
    Sanfelice, Ricardo G.
    IEEE TRANSACTIONS ON AUTOMATION SCIENCE AND ENGINEERING, 2016, 13 (02) : 479 - 490
  • [22] A Cyber-Physical Systems Approach to Collaborative Intersection Management and Control
    Guzman, Jose A.
    Nunez, Felipe
    IEEE ACCESS, 2021, 9 : 99617 - 99632
  • [23] The Integrated Model of Secure Cyber-Physical Systems for Their Design and Verification
    Levshun, Dmitry
    Kotenko, Igor
    Chechulin, Andrey
    INTELLIGENT DISTRIBUTED COMPUTING XIII, 2020, 868 : 333 - 343
  • [24] Security Verification for Cyber-Physical Systems Using Model Checking
    Chan, Ching-Chieh
    Yang, Cheng-Zen
    Fan, Chin-Feng
    IEEE ACCESS, 2021, 9 : 75169 - 75186
  • [25] A constraint and risk-aware approach to attribute-based access control for cyber-physical systems
    Akhuseyinoglu, Nuray Baltaci
    Joshi, James
    COMPUTERS & SECURITY, 2020, 96
  • [26] Modeling access control for cyber-physical systems using reputation
    Chen, Dong
    Chang, Guiran
    Sun, Dawei
    Jia, Jie
    Wang, Xingwei
    COMPUTERS & ELECTRICAL ENGINEERING, 2012, 38 (05) : 1088 - 1101
  • [27] CPAC: Securing Critical Infrastructure with Cyber-Physical Access Control
    Etigowni, Sriharsha
    Tian, Dave
    Hernandez, Grant
    Zonouz, Saman
    Butler, Kevin
    32ND ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE (ACSAC 2016), 2016, : 139 - 152
  • [28] A Simple Scheme for Security and Access Control in Cyber-Physical Systems
    Vegh, Laura
    Miclea, Liviu
    2015 20TH INTERNATIONAL CONFERENCE ON CONTROL SYSTEMS AND COMPUTER SCIENCE, 2015, : 294 - 299
  • [29] Fidelity-Aware Utilization Control for Cyber-Physical Surveillance Systems
    Chen, Jinzhu
    Tan, Rui
    Xing, Guoliang
    Wang, Xiaorui
    Fu, Xing
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2012, 23 (09) : 1739 - 1751
  • [30] Channel-Aware Congestion Control in Vehicular Cyber-Physical Systems
    Cho, Byeong-Moon
    Jang, Min-Seong
    Park, Kyung-Joon
    IEEE ACCESS, 2020, 8 : 73193 - 73203