Notions of security and opacity in discrete event systems

Notions of security and opacity in discrete event systems
复制标题

DOI:
10.1109/cdc.2007.4434515
复制
发表时间:
2007-12
期刊:
2007 46th IEEE Conference on Decision and Control
影响因子:
--
通讯作者:
A. Saboori;C. Hadjicostis
A. Saboori;C. Hadjicostis
中科院分区:
其他
文献类型:
--
作者:
A. Saboori;C. Hadjicostis

文献摘要

被引文献

相似文献

在本文中,我们遵循基于状态的方法将计算机安全中的不透明度的概念扩展到离散事件系统。一个系统是(S,P)-不透明的,如果它的真实状态通过一组秘密状态的演化对于通过投影映射P观察系统中的活动的观察者来说仍然是不透明的。换句话说,基于通过映射P的观察,观察者永远不确定系统的当前状态是否在秘密状态集合S内。K)-不透明度,它要求在系统状态偏离集合S之后,K个观测的不透明度保持为真。我们表明,基于状态的不透明度定义使得能够使用观测器构造来进行验证。特别地,(S,P,K)-不透明度的验证是通过具有K-延迟的观测器来完成的,该观测器被构造为捕获具有K-延迟的状态估计。这些是对系统K个观测之前的状态的估计,与所有观测(包括最后的K个观测)一致。我们还分析了K时滞观测器的性质和复杂性。
In this paper, we follow a state-based approach to extend the notion of opacity in computer security to discrete event systems. A system is (S, P)-opaque if the evolution of its true state through a set of secret states S remains opaque to an observer who is observing activity in the system through the projection map P. In other words, based on observations through the mapping P, the observer is never certain that the current state of the system is within the set of secret states S. We also introduce the stronger notion of (S,P, K)-opacity which requires opacity to remain true for K observations following the departure of the system's state from the set S. We show that the state-based definition of opacity enables the use of observer constructions for verification purposes. In particular, the verification of (S,P, K)-opacity is accomplished via an observer with K-delay which is constructed to capture state estimates with K-delay. These are the estimates of the state of the system K observations ago and are consistent with all observations (including the last K observations). We also analyze the properties and complexity of the observer with K- delay.