Security‐ and safety‐critical cyber‐physical systems
Atif Mashkoor, Johannes Sametinger, Miklós Bíró, Alexander Egyed
- 发表年份
- 2019
- 引用次数
- 16
- 访问权限
- 开放获取
摘要
Cyber-physical systems (CPSs) are physical embedded systems with enhanced operations for monitoring, coordination, control, and integration by a computing and communication core.1 Examples of CPSs include transportations systems,2 medical systems,3 and manufacturing systems.4 A CPS can be security-critical, safety-critical, or both. A CPS communicating with the outside world and thus opening an attack vector through the communication channel is considered to be a security-critical CPS. On the other hand, a CPS is considered to be safety-critical if it can harm its environment, eg, a malfunctioning autonomous vehicle might harm its passengers.5 A CPS dealing with both security and safety concerns is considered to be a security- and safety-critical CPS. Contemporary systems and software engineering methods often prove inadequate for the trustworthy and reliable design and engineering of CPSs. Traditional engineering deals with security and safety issues as separate problems. However, given the coordination and communication features of CPSs, such a “separation-of-concerns” approach is no longer adequate. We need integrated methods to deal with security and safety concerns within CPSs. The focus of this special issue is to highlight and foster research on security and safety issues in CPSs. This special issue enhances previous efforts by providing an updated and extended view on the implications of security and safety aspects in the CPSs arena. Some of the articles presented in this special issue have been selected from the 2nd International Workshop on Cybersecurity and Functional Safety of Cyber-Physical Systems (IWCFS'19).6 The selected papers have been extended and further improved for this special issue. The remaining articles were solicited using an open call for papers. The paper “A Security Risk Mitigation Framework for Cyber Physical Systems” by Maryam Zahid, Irum Inayat, Maya Daneva and Zahid Mehmood proposes an application layer-specific security risk mitigation framework for CPSs focusing on constraints such as authentication, data-integrity, data-freshness, non-repudiation, and confidentiality. The proposed approach is evaluated on a fire alarm system for railway cabins. The obtained results show a decrease in the severity of the identified security risks such as Man-in-the-Middle attack, spoofing, and data-tempering. The paper “Design and Validation of a C++ Code generator from Abstract State Machines Specifications” by Silvia Bonfanti, Angelo Gargantini and Atif Mashkoor presents a methodology to generate C++ code from Abstract State Machine models using the Asm2C++ tool.7 The advantage of the Asm2C++ tool is that the implementation is generated in a seamless manner with an assurance of potential bug freeness of the generated code. The paper extends the Asm2C++ tool in such a way that it can automatically produce unit tests for the generated code: abstract test sequences, either generated randomly or through model checking, are translated to concrete C++ unit tests. In a similar manner, scenarios are also generated in a behavior-driven development-style approach. To guarantee the correctness of the code generation process, authors define a mechanism based on the criteria (syntactical correctness and semantic correctness), which are based on the definition of conformance between the specification and the generated code. The paper “Formal Design of Scalable Conversation Protocols using Event-B: Validation, Experiments and Benchmarks” by Sarah Benyagoub, Yamine Aït-Ameur, Meriem Ouederni, Atif Mashkoor and Ahmed Medeghri addresses the design of distributed systems composed of peers (state-transitions systems) communicating through message exchanges. The authors consider choreographies as the formal model allowing developers to describe and specify peers coordination as a set of conversations, ie, all sequences of messages exchanged between the communicating peers. Proceeding this way neither require building the indiv
关键词
相关论文
Statistical Learning Theory
Yuhai Wu, Vladimir Vapnik
1999
Artificial intelligence: a modern approach
1995
Fractional Differential Equations
Igor Podlubný
2025
Applied Nonlinear Control
Jean-Jacques Slotine, Weiping Li
1991