Enforcing security and safety policies in IoT applications

在物联网应用中执行安全策略

基本信息

  • 批准号:
    RGPIN-2020-04283
  • 负责人:
  • 金额:
    $ 1.75万
  • 依托单位:
  • 依托单位国家:
    加拿大
  • 项目类别:
    Discovery Grants Program - Individual
  • 财政年份:
    2020
  • 资助国家:
    加拿大
  • 起止时间:
    2020-01-01 至 2021-12-31
  • 项目状态:
    已结题

项目摘要

Smart devices (IoT) are omnipresent in both private and public spaces. There are now billions of them worldwide and this number is still growing. IoT devices are composed of sensors, actuators and software components. While these devices contribute to offering a better lifestyle and better performances their extensive use and their interconnectivity pose many challenges in terms of safety, security and privacy. The purpose of this proposal is to address some of these challenges by developing formally based techniques and mechanisms to detect security flaws in IoT applications and enforcement mechanisms aimed at correcting or avoiding them. More precisely, we will strive to bring relevant answers to the following challenges. a) In order to operate adequately, smart devices have access to sensitive information on which they base decisions. We must ensure that this sensitive information does not leak to untrusted parties. b) Applications may trigger via actuators, actions on physical devices such as open or close a door, put on a heater or an engine, etc. We seek to find how to ensure that these actions do not compromise safety or security and that they are compliant to the end-user intents. c) An IoT application may control many devices. Many applications can work concurrently in an interconnected way. Which models should be used to allow the best trade-off between acceptable performances and solid guarantees concerning safety, security and privacy. d) Which security and safety policies should be enforced and which mechanisms should be used to enforce them? The challenge is that halting-based enforcement mechanisms are not adequate in the IoT context. We must find corrective enforcement mechanisms that do not interrupt vital services. e) How to scale the proposed techniques to a context where smart devices generate a huge number of events and have to comply with a huger number of rules? Some of the challenges are related to security issues in general but many are IoT specific. Smart devices have limited memories and computation capabilities. Physical events are sensed by captors and actuated by smart devices. These events constitute a part of the communication paradigm in an IoT environment and must be dealt with appropriately. Representing these events in a relevant way is challenging. The environment that communicates with smart devices is not only physical but it includes web-based services such that IFTTT (IF This Then That) applets. These applets have to be considered when we devise our analyses and enforcement mechanisms. The research work proposed in this program is an opportunity to train students in computing security, a domain where the lack of highly qualified personnel is important and where the needs are tremendous. Enforcing security and safety of IoT environments operating is urgent and the success of this kind of research will bring benefits not only to the Canadian society but also worldwide.
智能设备(IoT)在私人和公共空间中无处不在。现在全世界有数十亿人,而且这个数字还在增长。物联网设备由传感器、执行器和软件组件组成。虽然这些设备有助于提供更好的生活方式和更好的性能,但它们的广泛使用及其互连性在安全性,保密性和隐私方面提出了许多挑战。该提案的目的是通过开发正式的技术和机制来解决其中的一些挑战,以检测物联网应用程序中的安全缺陷以及旨在纠正或避免这些缺陷的执行机制。更准确地说,我们将努力为以下挑战提供相关答案。 a)为了充分运行,智能设备可以访问它们基于决策的敏感信息。我们必须确保这些敏感信息不会泄露给不受信任的各方。 B)应用程序可以通过执行器触发物理设备上的动作,例如打开或关闭门,打开加热器或发动机等。我们试图找到如何确保这些动作不会危及安全性或安全性,并且它们符合最终用户的意图。 c)IoT应用程序可以控制许多设备。许多应用程序可以以互连的方式并发工作。应使用哪些模型来在可接受的性能和有关安全、安保和隐私的可靠保证之间进行最佳权衡。 d)应执行哪些安全和安保政策,应使用哪些机制来执行这些政策?面临的挑战是,基于暂停的执行机制在物联网环境中是不够的。我们必须找到不中断重要服务的纠正性执行机制。 e)如何将所提出的技术扩展到智能设备生成大量事件并且必须遵守胡格规则的上下文? 其中一些挑战与一般的安全问题有关,但许多是物联网特有的。智能设备的内存和计算能力有限。物理事件由捕获者感知并由智能设备驱动。这些事件构成了物联网环境中通信范式的一部分,必须妥善处理。以相关的方式呈现这些事件是一项挑战。与智能设备通信的环境不仅是物理的,而且还包括基于Web的服务,例如IFTTT(IF This Then That)小程序。当我们设计分析和执行机制时,必须考虑这些小程序。 该计划中提出的研究工作是培养学生计算安全的机会,这是一个缺乏高素质人才的重要领域,需求巨大。 加强物联网环境运行的安全性是当务之急,这种研究的成功不仅会给加拿大社会带来好处,也会给全世界带来好处。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Tawbi, Nadia其他文献

Tawbi, Nadia的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Tawbi, Nadia', 18)}}的其他基金

Enforcing security and safety policies in IoT applications
在物联网应用中执行安全策略
  • 批准号:
    RGPIN-2020-04283
  • 财政年份:
    2022
  • 资助金额:
    $ 1.75万
  • 项目类别:
    Discovery Grants Program - Individual
Enforcing security and safety policies in IoT applications
在物联网应用中执行安全策略
  • 批准号:
    RGPIN-2020-04283
  • 财政年份:
    2021
  • 资助金额:
    $ 1.75万
  • 项目类别:
    Discovery Grants Program - Individual
Hybrid approaches for enforcing security policies.
执行安全策略的混合方法。
  • 批准号:
    RGPIN-2015-04461
  • 财政年份:
    2019
  • 资助金额:
    $ 1.75万
  • 项目类别:
    Discovery Grants Program - Individual
Hybrid approaches for enforcing security policies.
执行安全策略的混合方法。
  • 批准号:
    RGPIN-2015-04461
  • 财政年份:
    2018
  • 资助金额:
    $ 1.75万
  • 项目类别:
    Discovery Grants Program - Individual
Hybrid approaches for enforcing security policies.
执行安全策略的混合方法。
  • 批准号:
    RGPIN-2015-04461
  • 财政年份:
    2017
  • 资助金额:
    $ 1.75万
  • 项目类别:
    Discovery Grants Program - Individual
Hybrid approaches for enforcing security policies.
执行安全策略的混合方法。
  • 批准号:
    RGPIN-2015-04461
  • 财政年份:
    2016
  • 资助金额:
    $ 1.75万
  • 项目类别:
    Discovery Grants Program - Individual
Hybrid approaches for enforcing security policies.
执行安全策略的混合方法。
  • 批准号:
    RGPIN-2015-04461
  • 财政年份:
    2015
  • 资助金额:
    $ 1.75万
  • 项目类别:
    Discovery Grants Program - Individual
Security policy enforcement mechanisms
安全策略执行机制
  • 批准号:
    194380-2010
  • 财政年份:
    2014
  • 资助金额:
    $ 1.75万
  • 项目类别:
    Discovery Grants Program - Individual
Security policy enforcement mechanisms
安全策略执行机制
  • 批准号:
    194380-2010
  • 财政年份:
    2013
  • 资助金额:
    $ 1.75万
  • 项目类别:
    Discovery Grants Program - Individual
Security policy enforcement mechanisms
安全策略执行机制
  • 批准号:
    194380-2010
  • 财政年份:
    2012
  • 资助金额:
    $ 1.75万
  • 项目类别:
    Discovery Grants Program - Individual

相似国自然基金

黄淮海平原典型区域土壤盐渍化演变机制与发生风险防控对策研究
  • 批准号:
    41171178
  • 批准年份:
    2011
  • 资助金额:
    65.0 万元
  • 项目类别:
    面上项目
存储安全中介系统理论、仿真和实现技术研究
  • 批准号:
    61070154
  • 批准年份:
    2010
  • 资助金额:
    30.0 万元
  • 项目类别:
    面上项目
最优证券设计及完善中国资本市场的路径选择
  • 批准号:
    70873012
  • 批准年份:
    2008
  • 资助金额:
    27.0 万元
  • 项目类别:
    面上项目

相似海外基金

An Integrated Model of Contextual Safety, Social Safety, and Social Vigilance as Psychosocial Contributors to Cardiovascular Disease
情境安全、社会安全和社会警惕作为心血管疾病社会心理因素的综合模型
  • 批准号:
    10749134
  • 财政年份:
    2024
  • 资助金额:
    $ 1.75万
  • 项目类别:
Collaborative Research: CPS: Medium: Enabling Data-Driven Security and Safety Analyses for Cyber-Physical Systems
协作研究:CPS:中:为网络物理系统实现数据驱动的安全和安全分析
  • 批准号:
    2414176
  • 财政年份:
    2023
  • 资助金额:
    $ 1.75万
  • 项目类别:
    Standard Grant
Elucidating the Factors of Institutional Abuse in Children's Homes: Aiming for the Safety and Security of Resident Children
阐明儿童之家机构虐待的因素:以居住儿童的安全为目标
  • 批准号:
    23K18848
  • 财政年份:
    2023
  • 资助金额:
    $ 1.75万
  • 项目类别:
    Grant-in-Aid for Research Activity Start-up
Enhance the security and resilience of the national food safety system
增强国家食品安全体系的安全性和韧性
  • 批准号:
    10783485
  • 财政年份:
    2023
  • 资助金额:
    $ 1.75万
  • 项目类别:
Characterizing chemical threat agent exposures using a lung-on-a-chip platform and multi-omic analysis of common pathophysiological mechanisms
使用芯片肺平台和常见病理生理机制的多组学分析来表征化学威胁剂暴露
  • 批准号:
    10708553
  • 财政年份:
    2023
  • 资助金额:
    $ 1.75万
  • 项目类别:
Resources and Workforce Development for the Regional Biocontainment Laboratories
区域生物防护实验室的资源和劳动力发展
  • 批准号:
    10791947
  • 财政年份:
    2023
  • 资助金额:
    $ 1.75万
  • 项目类别:
Facility Management, Maintenance and Operation Core
设施管理、维护和运营核心
  • 批准号:
    10793828
  • 财政年份:
    2023
  • 资助金额:
    $ 1.75万
  • 项目类别:
Operations Core
运营核心
  • 批准号:
    10793943
  • 财政年份:
    2023
  • 资助金额:
    $ 1.75万
  • 项目类别:
SaTC: CORE: Small: Mitigating Threats of Physical-Domain Signal Injections on Security, Reliability, and Safety of Sensing and Control Systems
SaTC:核心:小型:减轻物理域信号注入对传感和控制系统的安全性、可靠性和安全性的威胁
  • 批准号:
    2231682
  • 财政年份:
    2023
  • 资助金额:
    $ 1.75万
  • 项目类别:
    Continuing Grant
RAPID/Collaborative Research: Households' Immediate Protective Actions and Trade-Off Processes Between Property Security and Life Safety in Response to 2022 Hurricane Ian
快速/协作研究:应对 2022 年伊恩飓风时家庭的立即保护行动以及财产安全和生命安全之间的权衡过程
  • 批准号:
    2303578
  • 财政年份:
    2023
  • 资助金额:
    $ 1.75万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了