发表机构
University of Padua(帕多瓦大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
提出安全感知零信任(SA-ZT),将限制引起的物理后果纳入策略,扩展NIST架构,通过安全引擎和遥测代理平衡网络风险与物理影响,并在IEEE 30节点案例中验证。
AI 中文摘要
零信任(Zero Trust, ZT)以显式、持续且上下文感知的授权取代了基于边界安全中的隐式信任。这一转变对物联网(IoT)和信息物理系统(CPS)尤为重要,因为其异构、长寿命且远程连接的组件使得持续信任难以维持。然而,物理耦合使得零信任的采用变得复杂:限制可疑组件可能降低网络暴露,但同时会移除运行所需的遥测或控制能力。现有工作主要关注攻击造成的物理损害,而对执行机制本身引入的后果关注较少。我们提出了安全感知的零信任(Safety-Aware Zero Trust, SA-ZT),将限制引起的物理后果作为策略输入。我们将NIST零信任原则映射为九种物联网/信息物理系统收敛压力,区分了物联网放大挑战与物理耦合特有挑战,并推导出相应的操作需求。SA-ZT扩展了NIST零信任架构,增加了安全引擎(Safety Engine)和遥测代理(Telemetry Broker)。安全引擎通过联合考虑残余网络风险与限制引起的后果来选择可接受响应,而遥测代理则调解原始遥测可见性和估计器影响。通过命令侧执行,这些实体分离了原始可见性、自动影响和状态改变权限,保留了用于监控的观测,同时限制了其对自动控制的影响。在IEEE 30节点系统上,针对虚假数据注入攻击的案例研究展示了SA-ZT如何使网络遏制、遥测可见性与影响、物理后果及授权时序变得显式,提供了可实现且可检查的网络物理执行权衡表示。
英文摘要
Zero Trust (ZT) replaces the implicit trust of perimeter-based security with explicit, continuous, context-aware authorization. This shift is particularly relevant to IoT and cyber-physical systems, whose heterogeneous, long-lived, and remotely connected components make persistent trust untenable. Yet their physical coupling complicates ZT adoption: restricting a suspicious component can reduce cyber exposure while removing telemetry or control capabilities required for operation. Existing work mainly models physical harm caused by attacks, with less attention to consequences introduced by enforcement itself. We introduce Safety-Aware Zero Trust (SA-ZT), which treats restriction-induced physical consequences as policy inputs. We map the NIST ZT tenets to nine IoT/CPS convergence strains, distinguish IoT-amplified challenges from those specific to cyber-physical coupling, and derive corresponding operational requirements. SA-ZT extends the NIST ZT Architecture with a Safety Engine and a Telemetry Broker. The Safety Engine selects among admissible responses by jointly considering residual cyber risk and restriction-induced consequences, while the Telemetry Broker mediates raw telemetry visibility and estimator influence. With command-side enforcement, these entities separate raw visibility, automated influence, and state-changing authority, preserving observations for monitoring while constraining their influence on automated control. An IEEE 30-bus case study under false-data-injection attack illustrates how SA-ZT makes cyber containment, telemetry visibility and influence, physical consequences, and authorization timing explicit, providing an implementable and inspectable representation of cyber-physical enforcement trade-offs.