Securing Building Management Systems Using Named Data Networking

Securing Building Management Systems Using Named Data Networking
复制标题

DOI:
10.1109/mnet.2014.6843232
复制
发表时间:
2014-05-01
期刊:
影响因子:
9.3
通讯作者:
Zhang, Lixia
Zhang, Lixia
中科院分区:
计算机科学2区
文献类型:
--
作者:
Shang, Wentao;Ding, Qiuhan;Zhang, Lixia

文献摘要

被引文献

相似文献

最近,楼宇自动化和管理系统(BAS和BMS)已经从使用专有协议和专用硬件转向广泛采用基于IP的开放标准技术。虽然IP协议套件提高了软件和硬件的互操作性,但实际的大规模BMS部署面临着挑战,包括网络寻址和其他配置的复杂性,即使是相对简单的任务也依赖于中间件,以及缺乏安全性。在这篇文章中,我们提出了一个以数据为中心的BMS设计,使用命名的数据网络,提出了以信息为中心的网络架构设计之一。我们的传感器数据采集系统使用分层命名空间的数据,加密密钥和访问控制列表,实现基于防御的访问控制,并提供了一个基于Web浏览器的数据可视化接口,在NDN通信。我们的设计已部署在加州大学洛杉矶分校的校园测试平台上,该平台可以捕获,存档和可视化来自行业标准传感器的数据。
Recently, building automation and management systems, BASs and BMSs, have shifted from using proprietary protocols and specialized hardware toward widespread adoption of IP-based open standard technologies. While the IP protocol suite improves software and hardware interoperability, practical large-scale BMS deployments face challenges, including the complexity of network addressing and other configuration, reliance on middleware for even relatively simple tasks, and a lack of security. In this article, we propose a data-centric BMS design that uses named data networking, one of the proposed information-centric networking architecture designs. Our sensor data acquisition system uses a hierarchical namespace for data, encryption keys, and access control lists, implements encryption-based access control, and provides a web browser-based data visualization interface that communicates in NDN. Our design has been deployed on a UCLA campus testbed that captures, archives, and visualizes data from industry standard sensors.