课题基金 / 基金详情

Enforcing security and safety policies in IoT applications

Enforcing security and safety policies in IoT applications
在物联网应用中执行安全策略
批准号:
RGPIN-2020-04283
负责人:
Tawbi, Nadia
金额:
$1.75万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2021
资助国家:
加拿大
项目状态:
已结题
起止时间:
2021-01-01 至 2022-12-31

项目摘要

项目成果

Tawbi, Nadia的其他基金

相似基金

相关文献

中文摘要
翻译
智能设备(IoT)在私人和公共空间无处不在。现在全世界有数十亿人,而且这个数字还在增长。物联网设备由传感器、执行器和软件组件组成。虽然这些设备有助于提供更好的生活方式和更好的性能,但它们的广泛使用和相互连接在安全、安保和隐私方面构成了许多挑战。这项提议的目的是通过开发基于正式的技术和机制来检测物联网应用程序中的安全缺陷,以及旨在纠正或避免这些缺陷的执行机制,来应对其中一些挑战。更准确地说,我们将努力为以下挑战带来相关答案。A)为了充分运作,智能设备可以访问敏感信息,作为决策的基础。我们必须确保这些敏感信息不会泄露给不可信方。B)应用程序可能通过执行器、对物理设备的操作(如打开或关闭门、安装加热器或发动机等)触发。我们试图找到如何确保这些操作不会损害安全或安保,并且它们符合最终用户的意图。C)一个物联网应用可以控制许多设备。许多应用程序可以以互连的方式同时工作。应该使用哪些型号,以便在可接受的性能和关于安全、安保和隐私的坚实保证之间进行最佳权衡。D)应执行哪些安保和安全政策,应使用哪些机制来执行这些政策?挑战在于,在物联网背景下,基于暂停的执法机制是不够的。我们必须找到不中断重要服务的纠正性执行机制。E)如何将建议的技术扩展到智能设备生成大量事件并必须遵守更多规则的环境中?一些挑战总体上与安全问题有关,但许多都是物联网特有的。智能设备的内存和计算能力有限。物理事件由捕获器感知,并由智能设备驱动。这些事件构成了物联网环境中通信范式的一部分,必须妥善处理。以一种相关的方式呈现这些事件是具有挑战性的。与智能设备通信的环境不仅是物理的,而且包括基于Web的服务,以便IFTTT(如果是这样的话就是那样)小程序。当我们设计我们的分析和执行机制时,这些小应用程序必须被考虑在内。这个项目中提出的研究工作是一个在计算安全方面培训学生的机会,在这个领域,高素质人才的缺乏是重要的,需求也是巨大的。加强物联网运营环境的安全保障迫在眉睫,此类研究的成功不仅将为加拿大社会带来好处,也将为全球带来好处。
英文摘要
Smart devices (IoT) are omnipresent in both private and public spaces. There are now billions of them worldwide and this number is still growing. IoT devices are composed of sensors, actuators and software components. While these devices contribute to offering a better lifestyle and better performances their extensive use and their interconnectivity pose many challenges in terms of safety, security and privacy. The purpose of this proposal is to address some of these challenges by developing formally based techniques and mechanisms to detect security flaws in IoT applications and enforcement mechanisms aimed at correcting or avoiding them. More precisely, we will strive to bring relevant answers to the following challenges. a) In order to operate adequately, smart devices have access to sensitive information on which they base decisions. We must ensure that this sensitive information does not leak to untrusted parties. b) Applications may trigger via actuators, actions on physical devices such as open or close a door, put on a heater or an engine, etc. We seek to find how to ensure that these actions do not compromise safety or security and that they are compliant to the end-user intents. c) An IoT application may control many devices. Many applications can work concurrently in an interconnected way. Which models should be used to allow the best trade-off between acceptable performances and solid guarantees concerning safety, security and privacy. d) Which security and safety policies should be enforced and which mechanisms should be used to enforce them? The challenge is that halting-based enforcement mechanisms are not adequate in the IoT context. We must find corrective enforcement mechanisms that do not interrupt vital services. e) How to scale the proposed techniques to a context where smart devices generate a huge number of events and have to comply with a huger number of rules? Some of the challenges are related to security issues in general but many are IoT specific. Smart devices have limited memories and computation capabilities. Physical events are sensed by captors and actuated by smart devices. These events constitute a part of the communication paradigm in an IoT environment and must be dealt with appropriately. Representing these events in a relevant way is challenging. The environment that communicates with smart devices is not only physical but it includes web-based services such that IFTTT (IF This Then That) applets. These applets have to be considered when we devise our analyses and enforcement mechanisms.  The research work proposed in this program is an opportunity to train students in computing security, a domain where the lack of highly qualified personnel is important and where the needs are tremendous. Enforcing security and safety of IoT environments operating is urgent and the success of this kind of research will bring benefits not only to the Canadian society but also worldwide.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Enforcing security and safety policies in IoT applications
  • 批准号:
    RGPIN-2020-04283
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.75万
  • 财政年份:
    2022
  • 负责人:
    Tawbi, Nadia
  • 依托单位:
Enforcing security and safety policies in IoT applications
  • 批准号:
    RGPIN-2020-04283
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.75万
  • 财政年份:
    2020
  • 负责人:
    Tawbi, Nadia
  • 依托单位:
Hybrid approaches for enforcing security policies.
  • 批准号:
    RGPIN-2015-04461
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.31万
  • 财政年份:
    2019
  • 负责人:
    Tawbi, Nadia
  • 依托单位:
Hybrid approaches for enforcing security policies.
  • 批准号:
    RGPIN-2015-04461
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.31万
  • 财政年份:
    2018
  • 负责人:
    Tawbi, Nadia
  • 依托单位:
国内基金
海外基金
黄淮海平原典型区域土壤盐渍化演变机制与发生风险防控对策研究
存储安全中介系统理论、仿真和实现技术研究
  • 批准号:
    61070154
  • 项目类别:
    面上项目
  • 资助金额:
    30.0万元
  • 批准年份:
    2010
  • 负责人:
    韩德志
  • 依托单位:
最优证券设计及完善中国资本市场的路径选择
  • 批准号:
    70873012
  • 项目类别:
    面上项目
  • 资助金额:
    27.0万元
  • 批准年份:
    2008
  • 负责人:
    彭龙
  • 依托单位: