{"title":"Supervisory enforcement of current-state opacity with uncomparable observations","authors":"Yin Tong, Ziyue Ma, Zhiwu Li, C. Seatzu, A. Giua","doi":"10.1109/WODES.2016.7497865","DOIUrl":null,"url":null,"abstract":"Current-state opacity is a key security property in discrete event systems. A system is said to be current-state opaque if the intruder, who only has partial observations on the system's evolution, is never able to infer that the current state of the system is within a set of secret states. In this work, we address the problem of enforcing current-state opacity by supervisory control. Given a system that is modeled with a finite automaton and that is not current-state opaque with respect to a given secret, the enforcement problem consists in designing a supervisor so that the controlled system is current-state opaque. We assume that the supervisor can only observe and control a subset of events. To be more general, we assume no specific containment relationship exists between the sets of events that can be observed by the intruder and the supervisor, respectively. We call this general setting uncomparable observations. We show that the maximally permissive supervisor always exists and propose a novel approach for its design.","PeriodicalId":268613,"journal":{"name":"2016 13th International Workshop on Discrete Event Systems (WODES)","volume":"55 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-05-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"8","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 13th International Workshop on Discrete Event Systems (WODES)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/WODES.2016.7497865","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 8
Abstract
Current-state opacity is a key security property in discrete event systems. A system is said to be current-state opaque if the intruder, who only has partial observations on the system's evolution, is never able to infer that the current state of the system is within a set of secret states. In this work, we address the problem of enforcing current-state opacity by supervisory control. Given a system that is modeled with a finite automaton and that is not current-state opaque with respect to a given secret, the enforcement problem consists in designing a supervisor so that the controlled system is current-state opaque. We assume that the supervisor can only observe and control a subset of events. To be more general, we assume no specific containment relationship exists between the sets of events that can be observed by the intruder and the supervisor, respectively. We call this general setting uncomparable observations. We show that the maximally permissive supervisor always exists and propose a novel approach for its design.