...
首页> 外文期刊>Future generation computer systems >Engineering security-aware control applications for data authentication in smart industrial cyber-physical systems
【24h】

Engineering security-aware control applications for data authentication in smart industrial cyber-physical systems

机译:工程安全感知控制应用程序,用于智能工业网络物理系统中的数据认证

获取原文
获取原文并翻译 | 示例
           

摘要

The massive proliferation of sophisticated technologies into the heart of traditional Industrial Control Systems has given birth to "smart Industrial Cyber-Physical Systems" (ICPS). While this industrial revolution has brought upon a wide range of advantages, it also raised new design challenges and exposed ICPS to a new breed of cyber-physical attacks. This paper aims to integrate security primitives (e.g., enforcing/verifying data authenticity) in control applications by formulating an innovative architectural paradigm shift. More specifically, our proposal is twofold. We elaborate a novel security-aware control application, which: (i) defines a new control application architecture embracing two security primitives that are called at the beginning and at the end of each program to verify and to enforce the required security properties; and (ii) runs the key management code as a separate program in order to isolate its implementation and to ensure its minimal interference with the rest of the programs. Then, we design a lightweight key distribution protocol exploiting the characteristics and computational advantages of symmetric key cryptography and hash functions. Extensive experimental results on a testbed replicating the precise hardware and software of a node from a Romanian gas transportation network, demonstrate the effectiveness of the proposed scheme and its applicability to resource-constrained ICPS. (C) 2018 Elsevier B.V. All rights reserved.
机译:先进技术的大量涌入传统工业控制系统的心脏,催生了“智能工业网络物理系统”(ICPS)。尽管这场工业革命带来了广泛的优势,但它也提出了新的设计挑战,并使ICPS遭受了新型的网络物理攻击。本文旨在通过制定创新的体系结构范式转移,将安全原语(例如,强制/验证数据的真实性)集成到控制应用程序中。更具体地说,我们的建议是双重的。我们精心设计了一种新颖的安全感知控制应用程序,该应用程序:(i)定义了一种新的控制应用程序体系结构,该体系结构包含两个安全原语,在每个程序的开头和结尾都调用了它们,以验证并强制执行所需的安全属性; (ii)将密钥管理代码作为单独的程序运行,以隔离其实现并确保其与其余程序的干扰最小。然后,我们利用对称密钥加密和哈希函数的特性和计算优势,设计了一种轻量级的密钥分发协议。在测试台上的大量实验结果从罗马尼亚的天然气运输网络复制了节点的精确硬件和软件,证明了该方案的有效性及其在资源受限的ICPS中的适用性。 (C)2018 Elsevier B.V.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号