Data centered Usage based Protection in a SMACIT context - TEL - Thèses en ligne Accéder directement au contenu
Thèse Année : 2021

Data centered Usage based Protection in a SMACIT context

Protection basée sur l'utilisation centrée sur les données dans un contexte SMACIT

Résumé

Protecting Information Systems (IS) relies traditionally on security risk analysis methods. Designed for well-perimetrised environments, these methods rely on a systematic identification of threats and vulnerabilities to identify efficient control-centered protection countermeasures. Unfortunately, this does not fit security challenges carried out by the opened and agile organizations provided by the Social, Mobile, big data Analytics, Cloud and Internet of Things (SMACIT) environment. Due to their inherently collaborative and distributed organization, such multi-tenancy systems require the integration of contextual vulnerabilities, depending on the a priori unknown way of using, storing and exchanging data in opened cloud environment. Moreover, as data can be associated to multiple copies, different protection requirements can be set for each of these copies, which may lead the initial data owner lose control on the data protection. To overcome these limits, we propose a Data centered Usage based Protection model relying on an IS description model to set a consistent protection for data assets. Protection means are defined according to both organizational and technical risks. To this end, we propose a GDPR compliant security and extended usage ontology which is used to define usage-control assertions coupling usage rights to security countermeasures so that data assets can be efficiently protected according to both organizational and technical dimensions. Thanks to a Blockchain-based usage control, our Data centered and Usage based Protection architecture also allows tracking the way assets are used so their life-long protection can be checked.
Protecting Information Systems (IS) relies traditionally on security risk analysis methods. Designed for well-perimetrised environments, these methods rely on a systematic identification of threats and vulnerabilities to identify efficient control-centered protection countermeasures. Unfortunately, this does not fit security challenges carried out by the opened and agile organizations provided by the Social, Mobile, big data Analytics, Cloud and Internet of Things (SMACIT) environment. Due to their inherently collaborative and distributed organization, such multi-tenancy systems require the integration of contextual vulnerabilities, depending on the a priori unknown way of using, storing and exchanging data in opened cloud environment. Moreover, as data can be associated to multiple copies, different protection requirements can be set for each of these copies, which may lead the initial data owner lose control on the data protection. To overcome these limits, we propose a Data centered Usage based Protection model relying on an IS description model to set a consistent protection for data assets. Protection means are defined according to both organizational and technical risks. To this end, we propose a GDPR compliant security and extended usage ontology which is used to define usage-control assertions coupling usage rights to security countermeasures so that data assets can be efficiently protected according to both organizational and technical dimensions. Thanks to a Blockchain-based usage control, our Data centered and Usage based Protection architecture also allows tracking the way assets are used so their life-long protection can be checked.
Fichier principal
Vignette du fichier
these.pdf (8.61 Mo) Télécharger le fichier
Origine : Version validée par le jury (STAR)

Dates et versions

tel-03406822 , version 1 (28-10-2021)

Identifiants

  • HAL Id : tel-03406822 , version 1

Citer

Yuan Jingya. Data centered Usage based Protection in a SMACIT context. Cryptography and Security [cs.CR]. Université de Lyon, 2021. English. ⟨NNT : 2021LYSEI044⟩. ⟨tel-03406822⟩
289 Consultations
180 Téléchargements

Partager

Gmail Facebook X LinkedIn More