logo-ri

Repositório Institucional da Produção Científica da Marinha do Brasil (RI-MB)

Use este identificador para citar ou linkar para este item: https://hdl.handle.net/20.500.14867/848484
Título: Security Strategies to Enforce Current-state opacity of Discrete-Event Systems using Segmented Networks
Autor(es): Reis, Lucas Nelson Ribeiro
Orientador(es): Moreira, Marcos Vicente de Brito
Carvalho, Lilian Kawakami
Palavras-chave: Automação
Sistemas a eventos discretos
Cibersegurança
Áreas de conhecimento da DGPM: Controle e automação
Setor(es) da Marinha: Diretoria-Geral do Desenvolvimento Nuclear e Tecnologia da Marinha (DGDNTM)
Data do documento: 2026
Editor: Universidade Federal do Rio de Janeiro (UFRJ)
Descrição: Cyber-Physical Systems (CPS) can be vulnerable to passive attacks, and one of the strategies proposed in the literature to ensure data security in CPS abstracted as Network Discrete Event Systems (NDES) is opacity enforcement. In this work, we consider a new notion of utility, called current-state utility (CSU), in which the intended receiver must always be certain of the current state of the system. To address this notion of utility, we propose two approaches based on network segmentation, which is a security method that divides the communication network into isolated subnets to prevent the attacker from accessing all the data communicated on the network. In the first approach, we propose a network segmentation by partitioning the event set in a way that guarantees current-state opacity (CSO) in each of the subnets. The number of subnets directly impacts the implementation cost; therefore, we propose an optimal solution to find the partition with the fewest subnets. The optimal solution has high computational complexity, so to implement network segmentation guaranteeing CSO while mitigating computational cost, we present a suboptimal solution to the problem. In the second approach, we propose a strategy to guarantee CSO and CSU for the receiver, based on cryptography and routing control, called multipath event routing, in which events are replaced and communicated to the receiver through different subnets. To solve the second approach, we present a method with necessary and sufficient conditions to compute an automaton that represents all event replacement functions that guarantee CSO and CSU.
Tipo de Acesso: Acesso aberto
URI: https://hdl.handle.net/20.500.14867/848484
Tipo: Tese
Aparece nas coleções:Ciência, Tecnologia e Inovação: Coleção de Teses

Arquivos associados a este item:
Arquivo Descrição TamanhoFormato 
tese_lucas_reis_20260410153926888.pdf1,22 MBAdobe PDFVisualizar/Abrir


Os itens no repositório estão protegidos por copyright, com todos os direitos reservados, salvo quando é indicado o contrário.