EP2097878A2 - Verfahren und vorrichtung zur anpassung einer anwendung mit neukonfigurierbarem sicherheitsmechanismus an einen physischen kontext - Google Patents
Verfahren und vorrichtung zur anpassung einer anwendung mit neukonfigurierbarem sicherheitsmechanismus an einen physischen kontextInfo
- Publication number
- EP2097878A2 EP2097878A2 EP07871991A EP07871991A EP2097878A2 EP 2097878 A2 EP2097878 A2 EP 2097878A2 EP 07871991 A EP07871991 A EP 07871991A EP 07871991 A EP07871991 A EP 07871991A EP 2097878 A2 EP2097878 A2 EP 2097878A2
- Authority
- EP
- European Patent Office
- Prior art keywords
- context information
- application
- context
- security
- determined
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07C—TIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
- G07C9/00—Individual registration on entry or exit
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/554—Detecting local intrusion or implementing counter-measures involving event detection and direct action
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/62—Protecting access to data via a platform, e.g. using keys or access control rules
- G06F21/6218—Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/102—Entity profiles
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2111—Location-sensitive, e.g. geographical location, GPS
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/08—Access security
Definitions
- the present invention relates to a method and a device for adapting the security level of an application according to the physical environment in which at least a part of the application runs.
- the invention relates to ambient intelligence environments that require that the security of the applications is adapted to adapt to particular environmental conditions.
- the complexity and heterogeneity of these environments introduces many vulnerabilities giving rise to new security requirements.
- Physical context refers to the physical environment in which at least part of the application runs; this context is, in particular, that of the main user of the application. According to a method described in the document entitled "Cerberus: A
- security policies in particular in terms of authentication and access control, defining different levels security, take into account contextual information, especially for the physical context.
- This contextual information is obtained by means of a context management infrastructure.
- this method can only manage one type of context data, that relating to the location. In addition, it limits itself to a single way of describing the confidence that one can have in these data, being limited to the authentication of the data of context to qualify this confidence.
- this method does not disclose the adaptation of the security mechanisms of the system based on these context data.
- the invention aims to remedy at least one of the disadvantages of the prior art by proposing a dynamic adaptation method of an application implementing security mechanisms, characterized in that it comprises the following steps: - determination at least one context information of the physical environment in which at least part of the application runs; determining a security level according to said at least one determined context information;
- the present invention automatically adapts security policies and mechanisms used in an ambient intelligence environment based on context information about the physical environment in which the application is running, including the environment. of the user.
- the invention establishes a stronger link between the security level of the application and the physical environment detected, for example by networked sensors in ambient intelligence environments, so as to make it possible to adapt the mechanisms from security to physical context.
- the application undergoes a dynamic reconfiguration, including security mechanisms, depending on the state of the determined environment, for example by sensors.
- a dynamic reconfiguration including security mechanisms, depending on the state of the determined environment, for example by sensors.
- the dynamic adaptation of the security of an application to a physical context can go as far as a complete reconfiguration of the security mechanism, notably by adding or removing features in the application, for example by introducing new security components.
- the step of determining at least one context information of the physical environment comprises at least one contextual data acquisition step.
- the acquisition of the contextual data is carried out directly from the physical environment, for example by means of sensors present in the physical environment.
- the method comprises a step of authenticating said at least one context information.
- the adaptation of the security of the application depends on the level of authentication of the context information.
- the authentication of context information also makes it possible to lighten the security mechanisms, taking into account, for example, physical protection devices already present in the environment.
- the method comprises a step of associating at least one degree of confidence with said at least one determined context information.
- the decision step is furthermore a function of said at least one degree of confidence associated with said at least one determined context information.
- the security level of the application is updated by reconfiguration based on the reliability of the context information.
- the adaptation of the security of an application to a low security level can only take place on the basis of context information whose reliability is sufficient.
- said at least one degree of confidence is defined according to an ontology.
- the ontology defines at least one rule for processing said at least one associated context information.
- the method comprises a step of building a reputation for at least one context information determined according to said at least one degree of confidence associated with said at least one context information determined.
- said reputation comprises a plurality of dimensions, each dimension being a degree of confidence that qualifies confidence in the context information or its processing.
- said reputation includes at least one relationship between the qualification dimensions of the trust.
- an ontology defines the at least one relationship between the qualification dimensions of the trust.
- the method comprises a step of associating at least one contextuality information with said at least one determined context information qualifying said at least one context information according to its level of importance.
- the invention also provides a device for dynamically adapting an application implementing security mechanisms, characterized in that it comprises the following means:
- This device has essentially the same advantages as the method of adapting an application implementing security mechanisms briefly described above.
- the invention relates to a computer program loadable into a computer system, said program containing instructions for implementing the adaptation method of an application implementing security mechanisms such as discussed above, when this program is loaded and executed by the computer system.
- the invention also provides a computer program product that can be loaded into a programmable device, characterized in that it comprises an application implementing security mechanisms, means for determining at least one context information of the physical environment in which at least part of the application executes, means for determining a security level according to said at least one determined context information, reconfiguration decision means / no reconfiguration based at least on means of comparison between the determined security level and the current security level applied by the security mechanisms and means for reconfiguring the application to adapt the application to the determined security level.
- FIG. 1 illustrates a component architecture model
- FIG. 2 illustrates a software or hardware architecture for adapting the security functionalities of an application according to the physical environment in accordance with the invention
- FIG. 3 represents an algorithm for adapting the security level of an application according to the invention
- Figure 4 illustrates an authentication operation based on location information
- Figure 5 illustrates the nodes of the context management system
- Figure 6 illustrates a structural ontology for a context management system
- Figure 7 illustrates a trust qualification ontology
- Figure 8 illustrates the relationship between trust qualification ontology and structural ontology
- Figure 9 illustrates an architecture of a context management node
- Figure 11 illustrates a global context management architecture
- Figure 12 illustrates an implementation of the context management system
- FIG. 13 illustrates a location-based access control with an adaptation of the system to a change in the characteristics of this location
- Figure 14 illustrates location-based access control with prevention of spoofing of location information
- the security of an application running in an ambient intelligence environment is automatically adapted by dynamic reconfiguration of the application according to policies and security mechanisms used in that environment. This adaptation is performed based on information about the state of the environment in which at least part of the application runs.
- the environment conditions conditions, according to the invention, the physical context in which runs at least part of the application.
- the physical context is determined from information acquired through sensors distributed in the environment.
- the sensors are able, for example, to determine the position of the user, and more generally the relevant elements of the context in which the user is (alone in an office, in a meeting, engaged in a non-interruptible activity, and so on. right now).
- the physical context can be managed by means of a context management system.
- the adaptation of the application can also be performed according to the level of confidence of the contextual information obtained.
- adapting the security of an application to a lower level of security can only be done based on contextual information about which one can have a sufficient degree of confidence, and whose authenticity is assured.
- the purpose of adjusting the security level of an application is to provide "just enough" protection, without overloading the user with oversized, redundant, or unsuitable security mechanisms.
- the security of the application is adapted to, or even associated with, the security of the physical protection devices that exist elsewhere in the user's environment.
- the authentication process of the application can be alleviated if the user is present in a premises whose access is already protected by a traditional physical security mechanism, for example, a lockable door or a biometric security device.
- the contextual information determined in particular by means of the sensors, for example the nature of the activity in progress, are used to trigger an adaptation of the security mechanisms of the application, if necessary. It is thus possible to automatically select the security level of the application adapted to its proper functioning, without unnecessarily overloading the user's attention by asking, for example, its approval for each operation of adaptation of the level of security of the application.
- these are designed according to an approach based on software components as illustrated in Figure 1.
- the software components are defined as entities encapsulating code and data that appear in software systems as threads, configuration / reconfiguration, deployment, or administration.
- An application designed according to a component model makes it possible to control the complexity of implementation of the software infrastructure, since the components can themselves be composed to form high-level code units.
- An application designed according to a component model also allows flexibility in the chosen configuration since the functionality of the application can be adapted or introduced by adding or replacing components in the application.
- an application is reconfigurable and thus makes the choice of components flexible.
- a component is an executable entity built from a controller that oversees its execution.
- a composite component is like a white box in which components, called primitive components, are interconnected. These primitive components are considered black boxes. Indeed, they encapsulate the software code.
- a component can only interact with its environment through a set of well-defined access points called interfaces. The interactions between the components require the establishment of links between the interfaces of these components.
- Figure 2 illustrates a software architecture and / or hardware adaptation of an application according to its physical execution environment according to the invention.
- This architecture includes a flexible security service 21 adapted to allow the adaptation of the security mechanism or the security level of an application, then an acquisition infrastructure, aggregation and context management 22 called below "Context management system", an inference engine 23 of the security context from the determined physical context and a security service adaptation decision mechanism 24 based on information on the security context.
- this architecture can also include a context information authentication service 25.
- this architecture can also include a context information authentication service 25.
- the adaptation of the security of an application according to the physical context of the user is carried out according to the following process.
- the distributed or centralized context management system 22 obtains low level context data.
- This data relates in particular to physical quantities, for example, provided by a network of sensors Ci arranged in the environment in which the application is running.
- These quantities may be, for example, a temperature, a pressure, a distance from a reference point, a location. These quantities are then aggregated to determine context information of more or less high level, such as, for example, the position or position of the user with respect to a relevant reference system, the state of the environment, the activity within that environment, the situation, the ambient noise level. It is thus possible to infer from the low-level context data, information on the current activities in the environment that will adapt the security of the application running in this environment.
- An embodiment of the context management system 22 is described hereinafter with reference to Figures 5 to 12.
- the context information authentication service 25 can associate with the previously determined context information a degree of contextuality which would be for example strictly between 0 and 1, 0 corresponding to useless information and 1 to important information for the context. system.
- This degree (s) of contextuality can later be taken into account when adapting the security level of the application by the security service 21.
- qualifying this context information makes it possible to modulate their use for the application. adaptation of the security of an application.
- the context information is associated with a security degree of confidence provided by the context information authentication service and a reliability degree of confidence. .
- the context information is "low trust", it will typically not be used for critical adaptations as it could be for security-inconsequential adaptations.
- This notion of trust or quality of contextual data can take on many aspects. It can be trusted in terms of reliability, accuracy, standard security, privacy (non-spyware), integrity (data not tampered with in a malicious way), or authenticity (a data source is not substituted by another). This trust can also be related to respect for privacy (more or less restricted access to data by third parties).
- the context information authentication service 25 is able to attach to the context information, or even the raw data acquired, metadata integrating these different confidence dimensions.
- This metadata can also be modified by taking into account the processing applied to the data throughout their processing and aggregation.
- the inference engine 23 deduces the appropriate security context Cs.
- the latter is, for example, the security level for the application adapted to the activity or the current situation of execution of the application in terms of environment.
- the context information from which the inference engine deduces the current security context can be described in a formal security ontology, and the same is true for information from the inference engine.
- the appropriate security context Cs is then securely transmitted to the adaptation decision mechanism of the security service 24.
- This appropriate security context Cs can also be used to adapt the context information authentication service 25.
- the level of authentication is higher or lower depending on the required level of security. .
- the decision mechanism 24 triggers or not the reconfiguration or parameterization of the adaptation of the security service 21.
- the security level is high during communications sent and received by the user's terminal present in a hostile and insecure environment.
- a hostile environment where the risk of interception of communications is not negligible is, for example, a country at risk or a competing enterprise.
- the high level of security is achieved, in particular, by the use of a robust encryption algorithm, for example, by means of an algorithm cryptographic type AES or advanced encryption standard ("Advanced Encryption Standard" in English terminology).
- the security level of the application can be mitigated, particularly in terms of the protection of communications.
- the security service considered in this example is a cryptographic library used to encrypt and / or sign communications.
- the application designed according to a component model can undergo a reconfiguration operation in order to change the application to a higher level of security. To do this, the reconfiguration is performed by downloading a new cryptographic library providing algorithms more robust or with longer key lengths.
- the reconfiguration of an application is performed, for example, according to the steps described below with reference to FIG.
- the algorithm starts at step 31 consisting of the acquisition of context data from the user's environment, in particular by means of the context management system 22.
- this step is performed by means of a location determination system which makes it possible to locate the user with respect to a repository, namely the country in which the user is located, the position of the user. the user in relation to an already secure environment, for example, an indoor or outdoor environment of the home, a meeting room, or a business.
- a location determination system which makes it possible to locate the user with respect to a repository, namely the country in which the user is located, the position of the user. the user in relation to an already secure environment, for example, an indoor or outdoor environment of the home, a meeting room, or a business.
- this step is performed by aggregating low level information from several location determination systems.
- the location data thus aggregated and consolidated are then transmitted to the authentication service 25 to ensure their authenticity.
- Step 31 is followed by step 32 of authenticating the user context, in particular by means of the authentication service 25. During this step, it is ensured that the context data produced during step 31 are authentic, that they were generated by a trustworthy localization infrastructure, and that they were not modified by a malicious third party.
- step 31 an attribute certificate is generated and signed by the location infrastructure where the attribute of the certificate contains the location information, in step 32, this The last step is to verify the certificate, ensuring that the signature of the location infrastructure is valid.
- Step 32 is followed by step 33 during which the security context is inferred, in particular by means of the inference engine 23.
- the inference engine derives the level of security from the environment by comparing the location data provided in steps 31 and 32 to the security level of the application.
- This policy includes, for example, the rules for using cryptography in the country where the user is located. These rules can be of the form:
- step 33 is followed by step 34 of securely transmitting the determined security context, i.e. the appropriate current security level, including the decision mechanism 24.
- step 33 the attribute key_length updated in step 33 is then transmitted securely to the decision mechanism 24, for example, after being encrypted using a symmetric key shared between the engine d. inference and the decision mechanism.
- Step 34 is followed by step 35 during which the decision to reconfigure or not the application is made, in particular by means of the decision mechanism 24.
- the decision mechanism 24 makes the decision or not to trigger the reconfiguration operation of the reconfigurable security mechanism component 21.
- the reconfiguration operation is, for example, a modification or a change of the encryption and signature algorithms.
- the decision making is, in particular, performed by comparing the security level determined in steps 31 to 34 to the current level (that is, current just before the decision is made) of the security of the application, and the reconfiguration consists for example in selecting a more or less robust encryption algorithm, or having a key length more or less important.
- Key_Length 128 bits Reconfigure (_crypto Algorithm, Key_Length) If current_security_ level ⁇ current_security_ level then
- Step 35 is followed by step 36 in which the reconfiguration is performed by means of the reconfigurable security mechanism 21.
- this operation is performed, in particular by reconfiguring the cryptographic system from a different composition of modules from the same cryptographic library, or by downloading into the user's terminal a new cryptographic component providing algorithms more or less robust or with more or less important key lengths.
- the goal is not to impose an authentication step that would be redundant in this case with physical security. Indeed, it is assumed that the persons authorized to enter these perimeters are trusted persons, and they are given access to a number of specific services of the house without imposing additional authentication.
- This application case can be transposed from a residential environment to any place receiving "controlled" visitors such as a hotel, an association room, or even an office space, and which would implicitly give access to a certain number of services for them. visitors authenticated by their location.
- password authentication requested on a network may be replaced by an authenticated location certificate to prohibit persons outside the secure perimeter from accessing the services offered to legitimate visitors.
- a network for example a WLAN type network or wireless local area network (“Wireless Local "Network” in English terminology
- Wired Local "Network” in English terminology
- password authentication may be replaced by an authenticated location certificate to prohibit persons outside the secure perimeter from accessing the services offered to legitimate visitors.
- people outside the secure perimeter may be able to access these same services using traditional password authentication or other means.
- the architecture described above is feasible using a software or hardware infrastructure providing aggregated location information, and more generally physical context, from data from a sensor network.
- an implementation is possible by using the Prolog logic programming language as a translator of physical context data into security context information, for example, degrees of trust, by representing this information in ontologies. appropriate.
- the context information authentication service is adapted to be implemented using a privilege management infrastructure (PMI), the security context being stored in attribute certificates passed on secure channels.
- PMI privilege management infrastructure
- the reconfigurable security service is able to be implemented on a mobile terminal or PDA using component technologies that facilitate the dynamic insertion of new classes of security policies to be applied in the context of the application. system.
- context management system 22 As well as the different types of metadata that can be associated by the context information authentication service 25 to qualify the trust of the context information, or even raw data acquired by means of sensors.
- the context management system is considered to consist of an acyc ⁇ c oriented graph whose nodes represent its computing elements that will manipulate and transform the context data and the arcs or links represent the information flows between these nodes. According to this graph, illustrated in Figure 5, there are three categories of nodes represented.
- the producers or context sources 51 are able to produce one or more types of context data related to the ambient environment. These are typically sensors for acquiring data on the physical context, eg, temperature, pressure, location. This data is the lowest level abstraction context information handled by the context management system.
- context consumers 52 are notably modules intervening in the target applications, and implementing particular functionalities that take as input a certain number of types of context data, which they will take into account for the adaptation of context. their current processing then says adaptive or context-sensitive. This data is typically higher level context information in the context management system.
- the context transformers (or interpreters) 53 input a number of context data types, for example, physical quantities and will output one or more other types of context information, for example, the type of activity in progress.
- the context data produced is generally higher than that provided at input and is called context information.
- These nodes will typically perform context data aggregation operations from upstream context producers or transformers. They transmit the result of this operation to downstream transformers or context consumers. These nodes thus accumulate the functions of producer and consumer of context.
- the structure of the context management system can be described in a so-called structural ontology including nodes, links and context data, as well as producers, consumers and context interpreters.
- each node has an identity that serves in particular to characterize the trust relationships between the nodes of the system.
- Each context information manipulated by the context management system is associated with a number of metadata describing the confidence that can be had in this information. This metadata can also be associated with each node of the system to qualify the confidence that can be had in the process of processing the context information made by this node.
- This metadata allows the construction of a reputation regarding context information or the process of processing this information.
- This reputation includes different dimensions that are different ways of qualifying trust in context information or its treatment. The relationships between these dimensions, the number of which can be extended, are described using a so-called "trust" ontology. This ontology can also be extended to enrich the description of this reputation.
- the trusted ontology comprises the elements illustrated in FIG.
- the primitive concept of this ontology is that of "reputation” which qualifies the confidence which one can have in a information of context or in the treatment of this information which will be realized by a node of the context management system.
- Reputation can be used to assess the trust that a node can have in its peers and the trust that can be had in the reliability of context information.
- reputation is "what is generally asserted or believed about the characteristics or situation / importance of a person or thing" ("A Survey of Trust and Reputation Systems for Online Service Provision").
- the "protection of personal data” is the fact for an individual or an organization to control the collection, storage, sharing, and the dissemination of personal data or data relating to this organization (document by Mr. Abrams, S. Jajodia, and H. Podeil entitled “Information Security: An Integrated Collection of Essays", and published in 1995 by IEEE Computer Society Press).
- Contextuality a concept that does not fit directly into the definition of reputation, but which serves to characterize the more or less secondary nature of context information. It measures the degree of closeness of the context to the primary function of the application / system, ranging from unnecessary or redundant context data to essential information to be taken into account by the system.
- confidentiality is the non-occurrence or prevention of unauthorized disclosure of information; more specifically, “confidentiality may be defined as the ability of a computer system to prevent the disclosure of information, that is, to make the information inaccessible (or incomprehensible) to non-designated users as authorized to access it "(Y. Deswartes in the document” Construction of Distributed Farming Systems ", published in the INRIA Didactic Collection in 1991);
- Integrity is the non-occurrence or prevention of inappropriate alterations of information (see Nicomette in his above-mentioned thesis); more precisely, "the integrity can be defined as the ability of the computer system to prevent corruption of information by accidental or intentional misconduct” (Y. Deswartes in “Construction of distributed operating systems", published in the Collection Didactics of INRIA in 1991);
- non-repudiation is "the characteristic of a cryptographic system preventing a sender from being able to deny having sent a message or performing a certain action" (Mr. CISCO Press);
- criticality or risk is "a measure of a hazard expressed as a function of the occurrence of an adverse event (probability, frequency) and a measure of its effects or consequences section
- the risk scale is often associated with the hazard so that it can be classified into criticality levels "(Air Navigation Studies Center in the" Safety Glossary "published at: http: // www.
- fuzzy logic crisp vs. fuzzy in English terminology. Saxon; a "crisp” size corresponds to a traditional numerical value; on the contrary, a fuzzy quantity associates with the numerical value a degree of belonging (between 0 and 1) to a set called fuzzy set.
- the "pseudonymat" is the fact of using a pseudonym to be identified, the anonymity is the fact of not being able to be identifiable among a set of subjects, said set of anonymity;
- unlinkability is the fact that a user may have multiple access to resources or services without the other entities forming part of the system being able to establish relationships between them. uses.
- the elements of trust ontology and those of structural ontology maintain the relationships illustrated in Figure 8.
- the notion of criticality can be applied to consumers or context producers (and therefore a fortiori to intermediate nodes).
- Precision, vagueness, reliability, confidentiality, authenticity, integrity, and non-repudiation are features of context information. However, these characteristics may also qualify the nodes of the system in terms of reliability, authenticity, or confidentiality. Nodes, links, and possibly context information have identities.
- contextuality can be applied to the links of the context management system.
- the coupling between the reputation management and the context management system itself is allowed.
- a software and / or hardware implementation architecture of a context management node consists of the elements described below and illustrated in FIG. 9.
- each producer, transformer or context consumer node is, for example, consisting of the elements now described.
- this architecture includes, in particular, a so-called basic component 91.
- This component is able to perform the processing that would perform the node of the context management system without taking into account reputation management. Thus, it takes as input a number of context inputs from other transformers or context producers, and outputs a number of context outputs to transformers or context consumers.
- the architecture includes a reputational management component 92 for each dimension d of the reputation described in the terms of the trust qualification ontology, for example, accuracy, reliability, or security. .
- These components perform metadata manipulation specific processing describing each dimension of the reputation.
- the reputation-precision 93, 94 reputation-security, 95 reputation-reputation and reputation-reliability components are obtained.
- This architecture of a context management node is open and reconfigurable.
- the number of dimensions describing the reputation is not limiting, it is thus possible to extend the behavior of a context management node to manage additional dimensions of. This is done by inserting a new reputation management component. It is also possible to modify the processing a given dimension d by performing the replacement of the reputation management component with another performing the new processing on the metadata corresponding to dimension d.
- the reputation management components for this dimension d communicate in specific channels in a peer-to-peer fashion, similar to a typical trust management infrastructure, as shown in Figure 10.
- Each reputation component is responsible for updating metadata about reputation, for each node and / or for each arc depending on the choice of d.
- these metadata concern only the arcs, for example the values of confidence between two nodes, while for others, the metadata are applicable to the nodes themselves, for example, criticality. .
- This architecture allows the support of several update protocols, and thus the coupling of the context management infrastructure with several types of trust management infrastructure ("trust management systems" in English terminology).
- the information used by the context consumers serves as an optional input, relative to the system in which these context consumers are integrated.
- a specific dimension of reputation can thus be used to characterize the more or less contextual nature of these data.
- This contextuality is therefore a parameter between 0 and 1 measuring the degree of reconciliation with the main system, 0 corresponding to an unnecessary context data to be taken into account, 1 to a control data unavoidable to be taken into account by the main system, that is, which is a primary input of the system.
- This parameter is derived in particular from context consumers and can be propagated in context management infrastructure in the opposite direction of producer data, since it is a downward constraint from consumers to producers. It can, in fact, condition the processing of context data, but also that of the other dimensions of metadata as described below.
- context attributes do not take any values, but are framed by the laws of physics.
- a metadata dimension can thus characterize the conformity of these metadata with respect to the physical constraints and make it possible to validate their use by the lower floors of the infrastructure.
- the different dimensions of the reputation can be prioritized and prioritized according to the application to determine which contextual elements to prioritize for the consideration by the system.
- the context sources as well as the context interpreters are made as components (called “bundles” in English terminology) implementing a Java interface, described below, called “iContextSource” referenced CSI and s exposing context-consuming applications or other context interpreters such as web services.
- a library called “ExBindEv library” is also used to implement mechanisms exposing these components as a web service.
- the "IContextSource” interface referenced CSI consists in particular of the three methods described below.
- the query (String sparql_str) method allows a client application or context interpreter to query the context source on a particular value or set of context information values.
- the method “subscribe (String sparqlevent str, String URL)” allows the context source to save in a list, the interest of a client application or a context interpreter for a query on the element particular context information, in order to inform it later as soon as the response to this request changes.
- ContextBroker allows context-consuming applications to discover context sources and context interpreters that interest it through an interface called “CBDI”, if they have registered with the client.
- CcntextBroker This recording is performed using for example an interface called “CBRI” described below.
- the "CBDI" interface includes the method
- DiscoverContextSource (String context lnf oDesc j" which allows an application to discover a context source based on a description of its needs in terms of the desired context nature, for example ambient temperature, but also in terms of the quality of the information, for example the accuracy of the temperature measurement This method returns the list of context source identifiers satisfying these needs.
- the "CBRI” interface consists of the following two methods. First, this interface includes the "registerContextSource (Stri ⁇ g contextlnfoDesc, String cSRef)” method, which allows a context source to declare itself to the ContextBroker component by providing a description of its capabilities in the same terms used. for the "discoverContexrSource” method described above, as well as its identifier that will allow applications to connect to the context source.
- CBRI ContextBroker
- deregisterContextSource String cSRef
- the representation of the needs and capacities used in the contextlnfcDesc parameter of the methods discoverContextSource and registerContextSource is based on the language called RDF ("Resource Description Format" in English terminology).
- RDF Resource Description Format
- the RDF language allows a flexible and flexible formalism that allows to represent heterogeneous information in large quantities if needed.
- the representation can be expressed as a text document in XML.
- the authentication must be able to also take into account the more or less security / safety of the locating mechanism used as well as its accuracy.
- a constructionally limited perimeter network such as a broadcast infrared network that can not cross walls, it can be considered that in a windowless room the security and accuracy of a location based on the connection to this network is perfect.
- a constructionally limited perimeter network such as a broadcast infrared network that can not cross walls, it can be considered that in a windowless room the security and accuracy of a location based on the connection to this network is perfect.
- such a room has open windows, such technology is no longer entirely safe and the corresponding "reputation" will be modified.
- the access control performed requires a very strong security and security of the location used by the application. This degree of safety / security must be provided to him in real time to be adapted to his behavior according to the situation. Indeed, if the security is no longer sufficient compared to the requirements of the application, the application can return to the use of a traditional authentication method and no longer be satisfied with the location as a means of authentication .
- this is a set-type precision, which is not necessarily homogeneous in space. Indeed, it is necessary to ensure that the person is well inside the secure perimeter, but without needing to know its exact location within this perimeter.
- This precision could be characterized by a membership function of fuzzy type ("fuzzy" in English terminology).
- a user interacts with services on the basis of his own location, which thus serves as an input to the system instead of what would be a mouse position in a traditional graphical interface.
- This location can be used for different types of adaptation.
- an interface functionality based on physical proximity, it may be a change in "focal length" of the communication if the person approaches an interface device to move a communication "wide-angle" to a more focused communication.
- Another parameter that can qualify the location is in this case the fact that a target can be identified uniquely.
- This example can be generalized in particular to all communication applications in smart spaces ("smart spaces" in English terminology) integrating an instrument for the acquisition of context data.
- the invention can be applied in particular to contextual assistance in the intelligent spaces, for example, to ambient assistance in the activities of daily life.
Landscapes
- Engineering & Computer Science (AREA)
- Physics & Mathematics (AREA)
- Theoretical Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- General Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Computer Hardware Design (AREA)
- Signal Processing (AREA)
- Computer Networks & Wireless Communication (AREA)
- Computing Systems (AREA)
- Databases & Information Systems (AREA)
- Health & Medical Sciences (AREA)
- Bioethics (AREA)
- General Health & Medical Sciences (AREA)
- Storage Device Security (AREA)
- Telephone Function (AREA)
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR0656051 | 2006-12-29 | ||
| PCT/FR2007/052580 WO2008087331A2 (fr) | 2006-12-29 | 2007-12-20 | Procede et dispositif d'adaptation au contexte physique d'une application mettant en oeuvre des mecanismes de securite reconfigurables |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP2097878A2 true EP2097878A2 (de) | 2009-09-09 |
Family
ID=38261599
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP07871991A Ceased EP2097878A2 (de) | 2006-12-29 | 2007-12-20 | Verfahren und vorrichtung zur anpassung einer anwendung mit neukonfigurierbarem sicherheitsmechanismus an einen physischen kontext |
Country Status (2)
| Country | Link |
|---|---|
| EP (1) | EP2097878A2 (de) |
| WO (1) | WO2008087331A2 (de) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN105447931B (zh) * | 2015-03-09 | 2017-10-24 | 北京天诚盛业科技有限公司 | 门禁远程授权的方法、装置和系统 |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20020152382A1 (en) * | 1999-06-11 | 2002-10-17 | Sihai Xiao | Trust information delivery scheme for certificate validation |
| US20040122704A1 (en) * | 2002-12-18 | 2004-06-24 | Sabol John M. | Integrated medical knowledge base interface system and method |
| US20060265324A1 (en) * | 2005-05-18 | 2006-11-23 | Alcatel | Security risk analysis systems and methods |
Family Cites Families (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6636983B1 (en) * | 1999-10-07 | 2003-10-21 | Andrew E. Levi | Method and system for uniform resource locator status tracking |
| US20030191949A1 (en) * | 2000-08-30 | 2003-10-09 | Akihiro Odagawa | Authentication system, authentication request device, validating device and service medium |
| US7260555B2 (en) * | 2001-12-12 | 2007-08-21 | Guardian Data Storage, Llc | Method and architecture for providing pervasive security to digital assets |
| US7591020B2 (en) * | 2002-01-18 | 2009-09-15 | Palm, Inc. | Location based security modification system and method |
| US8359645B2 (en) * | 2005-03-25 | 2013-01-22 | Microsoft Corporation | Dynamic protection of unpatched machines |
-
2007
- 2007-12-20 EP EP07871991A patent/EP2097878A2/de not_active Ceased
- 2007-12-20 WO PCT/FR2007/052580 patent/WO2008087331A2/fr not_active Ceased
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20020152382A1 (en) * | 1999-06-11 | 2002-10-17 | Sihai Xiao | Trust information delivery scheme for certificate validation |
| US20040122704A1 (en) * | 2002-12-18 | 2004-06-24 | Sabol John M. | Integrated medical knowledge base interface system and method |
| US20060265324A1 (en) * | 2005-05-18 | 2006-11-23 | Alcatel | Security risk analysis systems and methods |
Non-Patent Citations (1)
| Title |
|---|
| AL-MUHTADI J ET AL: "Cerberus: a context-aware security scheme for smart spaces", PERCOM '03 PROCEEDINGS OF THE FIRST IEEE INTERNATIONAL CONFERENCE ON PERVASIVE COMPUTING AND COMMUNICATIONS, IEEE, US, 26 March 2003 (2003-03-26), pages 489 - 496, XP032384629, ISBN: 978-0-7695-1893-0, DOI: 10.1109/PERCOM.2003.1192774 * |
Also Published As
| Publication number | Publication date |
|---|---|
| WO2008087331A3 (fr) | 2008-11-06 |
| WO2008087331A2 (fr) | 2008-07-24 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| Sicari et al. | Security policy enforcement for networked smart objects | |
| Sinha et al. | Building an E Ective IoT Ecosystem for Your Business | |
| Barka et al. | Securing the web of things with role-based access control | |
| US20100122318A1 (en) | Policy-based service managment system | |
| Gabillon et al. | Access controls for IoT networks | |
| US20150135277A1 (en) | Methods for Generating and Using Trust Blueprints in Security Architectures | |
| FR3007551A1 (fr) | Procede et serveur de traitement d'une requete d'acces d'un terminal a une ressource informatique | |
| Moghaddam et al. | Policy Engine as a Service (PEaaS): An approach to a reliable policy management framework in cloud computing environments | |
| Kapitsaki | Reflecting user privacy preferences in context-aware web services | |
| EP3367290A1 (de) | Systeme, verfahren und computerprogrammprodukte für die kombination von privatsphäre-verbessernden technologien | |
| Akaichi et al. | Usage control specification, enforcement, and robustness: A survey | |
| Kishor et al. | SPAM: an enhanced performance of security and privacy-aware model over split learning in consumer electronics | |
| Bandara et al. | Generative-AI (with Custom-Trained Meta's Llama2 LLM), Blockchain, NFT, Federated Learning and PBOM Enabled Data Security Architecture for Metaverse on 5G/6G Environment | |
| Beltran et al. | An ARM‐Compliant Architecture for User Privacy in Smart Cities: SMARTIE—Quality by Design in the IoT | |
| Pereira et al. | The XACML standard-addressing architectural and security aspects | |
| WO2008087331A2 (fr) | Procede et dispositif d'adaptation au contexte physique d'une application mettant en oeuvre des mecanismes de securite reconfigurables | |
| Bruno et al. | Enforcing access controls in IoT networks | |
| Yee et al. | Security personalization for internet and web services | |
| Zheng-qiu et al. | Semantic security policy for web service | |
| Agazzi et al. | Trust negotiation for automated service integration | |
| Olmedilla | Security and privacy on the semantic web | |
| Neisse et al. | An information model and architecture for context-aware management domains | |
| Bhattacharjee | Integrity and privacy protection for cyber-physical systems (cps) | |
| Singh | Reputation based distributed trust model for P2P networks | |
| US20240334313A1 (en) | Secure network identification for active scanning device |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20090702 |
|
| AK | Designated contracting states |
Kind code of ref document: A2 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IS IT LI LT LU LV MC MT NL PL PT RO SE SI SK TR |
|
| DAX | Request for extension of the european patent (deleted) | ||
| RAP1 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: ORANGE |
|
| 17Q | First examination report despatched |
Effective date: 20140204 |
|
| REG | Reference to a national code |
Ref country code: DE Ref legal event code: R003 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION HAS BEEN REFUSED |
|
| 18R | Application refused |
Effective date: 20190926 |