The POLIPO security framework
Autor: | Trivellato, D., Etalle, S., Luit, E.J., Zannone, N., Laar, van de, P., Tretmans, J., Borth, M. |
---|---|
Přispěvatelé: | Security, Interconnected Resource-aware Intelligent Systems |
Jazyk: | angličtina |
Rok vydání: | 2013 |
Předmět: |
System of systems
Engineering business.industry computer.internet_protocol SCS-Cybersecurity IR-85242 Interoperability EWI-23168 Framework Security domain Access control Service-oriented architecture Ontology (information science) Security policy Computer security computer.software_genre POLIPO Security Trust management (information system) business computer METIS-296355 |
Zdroj: | Situation Awareness with Systems of Systems, 189-208 STARTPAGE=189;ENDPAGE=208;TITLE=Situation Awareness with Systems of Systems Situation Awareness with Systems of Systems ISBN: 9781461462293 Situation Awareness with Systems of Systems |
Popis: | Systems of systems are dynamic coalitions of distributed, autonomous and heterogeneous systems that collaborate to achieve a common goal. While offering several advantages in terms of scalability and flexibility, the systems of systems paradigm has a significant impact on systems interoperability and on the security requirements of the collaborating systems. In this chapter we introduce POLIPO, a security framework that protects the information exchanged among the systems in a system of systems, while preserving systems’ autonomy and interoperability. Information is protected from unauthorized access and improper modification by combining context-aware access control with trust management. Autonomy and interoperability are enabled by the use of ontology-based services. More precisely, each authority may refer to different ontologies to define the semantics of the terms used in the security policy of the system it governs and to describe domain knowledge and context information. A semantic alignment technique is then employed to map concepts from different ontologies and align the systems’ vocabularies. We demonstrate the applicability of our solution with a prototype implementation of the framework for a scenario in the maritime safety and security domain. |
Databáze: | OpenAIRE |
Externí odkaz: |