论文标题
通过动态策略更新的价值链中的最终安全数据交换
End to End Secure Data Exchange in Value Chains with Dynamic Policy Updates
论文作者
论文摘要
价值链合作伙伴之间的数据交换为他们提供了竞争优势,但是暴露敏感数据的风险越来越多。必须在存储和传输中保护信息,以降低这种风险,因此只有数据生产者和最终消费者才能访问或修改它。端到端(E2E)的安全机制应对这一挑战,保护公司免受价值链攻击引起的数据泄露。此外,还必须考虑价值链特殊性。多个实体都参与此类动态环境,无论是在数据生成还是消费中。因此,需要灵活的访问策略,以确保可以随时更新它们。本文介绍了具有E2E安全性的价值链的CP-ABE依赖数据交换系统。它考虑了价值链的最相关的安全性和工业要求。提出的解决方案可以根据访问策略保护数据,并在不破坏E2E安全性或过载现场设备的情况下更新这些策略。在大多数情况下,现场设备是IIOT设备,在处理和内存功能方面有限。实验评估表明该解决方案对IIT平台的可行性。
Data exchange among value chain partners provides them with a competitive advantage, but the risk of exposing sensitive data is ever-increasing. Information must be protected in storage and transmission to reduce this risk, so only the data producer and the final consumer can access or modify it. End-to-end (E2E) security mechanisms address this challenge, protecting companies from data breaches resulting from value chain attacks. Moreover, value chain particularities must also be considered. Multiple entities are involved in dynamic environments like these, both in data generation and consumption. Hence, a flexible generation of access policies is required to ensure that they can be updated whenever needed. This paper presents a CP-ABE-reliant data exchange system for value chains with E2E security. It considers the most relevant security and industrial requirements for value chains. The proposed solution can protect data according to access policies and update those policies without breaking E2E security or overloading field devices. In most cases, field devices are IIoT devices, limited in terms of processing and memory capabilities. The experimental evaluation has shown the proposed solution's feasibility for IIoT platforms.