论文标题
蓝军:活动控制:智能协作系统的“主动”安全模型的愿景
BlueSky: Activity Control: A Vision for "Active" Security Models for Smart Collaborative Systems
论文作者
论文摘要
网络物理生态系统将不同的智能设备连接到异质网络。对智能对象进行了各种操作,以确保效率并支持智能环境中的自动化。一项活动(由Gupta和Sandhu定义)反映了对象的当前状态,该对象对所需操作的响应发生了变化。由于在不同对象上进行了多次运行活动,因此确保考虑因相关活动(和其他参数)支持主动执行访问控制决策而影响的运行时间决策的协作系统至关重要。最近,古普塔(Gupta)和桑德胡(Sandhu)提出了以活动为中心的访问控制(ACAC),并讨论了活动的概念,作为协作系统中访问控制的主要抽象。该模型提供了一种主动的安全方法,该方法考虑了相关设备活动之间的活动决策因素,例如授权,义务,条件和依赖关系。本文向前迈出了一步,并介绍了ACAC模型的核心组成部分,并与其他安全模型进行了比较,从而区分ACAC的新型特性。我们强调了现有模型如何(或在有限的范围内)如何支持“主动”决策和协作系统中授权的执行。我们通过逐渐添加与活动概念相关的属性并讨论活动状态,为ACAC模型家族提出了分层结构。我们强调了ACAC与零信任原则的融合,以反映ACAC如何支持分布式和连接的智能生态系统的必要安全姿势。本文旨在在支持新颖的抽象,属性和要求的协作系统中更好地了解ACAC。
Cyber physical ecosystem connects different intelligent devices over heterogeneous networks. Various operations are performed on smart objects to ensure efficiency and to support automation in smart environments. An Activity (defined by Gupta and Sandhu) reflects the current state of an object, which changes in response to requested operations. Due to multiple running activities on different objects, it is critical to secure collaborative systems considering run-time decisions impacted due to related activities (and other parameters) supporting active enforcement of access control decision. Recently, Gupta and Sandhu proposed Activity-Centric Access Control (ACAC) and discussed the notion of activity as a prime abstraction for access control in collaborative systems. The model provides an active security approach that considers activity decision factors such as authorizations, obligations, conditions, and dependencies among related device activities. This paper takes a step forward and presents the core components of an ACAC model and compares with other security models differentiating novel properties of ACAC. We highlight how existing models do not (or in limited scope) support `active' decision and enforcement of authorization in collaborative systems. We propose a hierarchical structure for a family of ACAC models by gradually adding the properties related to notion of activity and discuss states of an activity. We highlight the convergence of ACAC with Zero Trust tenets to reflect how ACAC supports necessary security posture of distributed and connected smart ecosystems. This paper aims to gain a better understanding of ACAC in collaborative systems supporting novel abstractions, properties and requirements.