项目名称: 面向异构物联网的安全融合理论及关键技术研究
项目编号: No.U1405255
项目类型: 联合基金项目
立项/批准年度: 2015
项目学科: 管理科学
项目作者: 马建峰
作者单位: 西安电子科技大学
项目金额: 245万元
中文摘要: 本项目针对物联网环境下异构多域网络并存、多源异构数据海量、多样化服务并发等核心问题,以提高物联网网络、数据及服务的安全和效率为目标,围绕网络互联、数据存储和服务协同三个方面,构建安全高效的物联网信息安全体系。在异构网络安全互联方面,以通用可组合理论及博弈论模型为基础,研究形式化的安全协议设计方法,设计分层分布式的多域网络密钥管理模型,进而构建自适应可扩展的异构多域物联网安全互联体系。在数据存储安全方面,以同态认证技术为基础,研究高效的数据完整性验证技术,加密数据搜索技术以及高动态性的基于属性的数据访问控制技术。在服务协同安全方面,基于信任模型对服务的安全属性进行形式化描述和评估,并提出基于信任度的服务安全组合方法。通过本项目的研究,为异构物联网建设提供协同式、综合化的安全保障。
中文关键词: 异构网络融合安全;加密数据检索;数据隐私;服务安全组合
英文摘要: Heterogeneous networks, massive data and diversified services pose as a great challenge for the information security architecture for the Internet of Things (IoT). Thus the IoT information security architecture is studied, which includes three key aspects, i.e. the interworking of networks, big data and service cooperation. In the security of interworking, we study the formal approach for designing efficient and secure protocols based on Universal Composability model (UC) and game theory, and design the layered and distributed key management model, to construct the adaptive and extensible interworking security architecture for heterogeneous and multi-domain networks in IoT. In the data security, our research is focused on efficient secure storage approach and query algorithms based on homomorphic encryption. Besides, fine-grained access control system based on ABAC(Attribute based Access Control) model is designed for the dynamic privacy protection in IoT. In the security of service cooperation, secure service composition approach is designed based on the trust model which can formalize and quantize the security properties of the services. Based on all these researches, we aim at providing a comprehensive secure communication and service environment for the IoT.
英文关键词: heterogeneous networks convergence security;encrypted data query;data privacy;secure service composition