|
This article is cited in 7 scientific papers (total in 7 papers)
Information Security
Analysis of modern methods to ensure data integrity in cyber-physical system management protocols
R. Meshcheryakova, A. Iskhakova, O. Evsutinba a V.A. Trapeznikov Institute of Control Sciences of Russian Academy of Sciences (ICS RAS)
b Moscow Institute of Electronics and Mathematics (MIEM HSE)
Abstract:
At present, the problem of creating methodological security of cyberphysical systems, in particular, the design and implementation of information security subsystems is acute. At the same time, the landscape of threats and vulnerabilities typical for a wide range of hardware and software technologies used in cyberphysical systems is extremely wide and complex. In this context, the security of application layer protocols is of paramount importance, as these protocols are the basis for interaction between applications and services running on different devices, as well as in cloud infrastructures. With the constant interaction of the systems under study with the real physical infrastructure, the challenge is to determine effective measures to ensure the integrity of the transferred control commands, as disruption of the performed critical processes can affect human life and health. The paper provides an analytical review of the main methods of data integrity assurance in management protocol of cyberphysical systems, as well as an overview of application layer protocols vulnerabilities widely used in cyberphysical systems of different types. Classical methods of data integrity assurance, new methods, in particular, blockchain, as well as the main directions of increasing the efficiency of data integrity protocols in cyberphysical systems are considered. Analysis of application layer vulnerabilities is carried out on the example of the most popular MQTT, CoAP, AMQP, DDS, XMPP specifications and their implementations. It is established that despite the presence of basic security mechanisms in all these protocols, researchers continue to regularly identify vulnerabilities in popular implementations, that often endangers critical infrastructure services. In the course of preparing the review of the existing methods of data integrity assurance for the examined class of systems, the key problems of these methods integration and ways of their solution were defined.
Keywords:
cyberphysical system, internet of things, protocol, blockchain, watermarking, authentication.
Received: 09.08.2020
Citation:
R. Meshcheryakov, A. Iskhakov, O. Evsutin, “Analysis of modern methods to ensure data integrity in cyber-physical system management protocols”, Tr. SPIIRAN, 19:5 (2020), 1089–1122
Linking options:
https://www.mathnet.ru/eng/trspy1127 https://www.mathnet.ru/eng/trspy/v19/i5/p1089
|
Statistics & downloads: |
Abstract page: | 212 | Full-text PDF : | 258 |
|