Browse Topic: Data privacy

Items (37)
Challenges in Integrating Cybersecurity into Existing Development Processes2020-01-01444/14/2020
For an established development process and a team accustomed to this process, adding cybersecurity features to the product initially means inconvenience and reduced productivity without perceivable benefits. Adapting development processes to take cybersecurity into account introduces challenges not present in engineering divisions so far. Strategies designed to deal with these challenges differ in the way in which added duties are assigned and cybersecurity topics are integrated into the already existing process steps. Cybersecurity requirements often clash with existing system requirements or established development methods, leading to low acceptance among developers, and introducing the need to have clear policies on how friction between cybersecurity and other fields is handled. A cybersecurity development approach is frequently perceived as introducing impediments, that bear the risk of cybersecurity measures receiving a lower priority to reduce inconvenience. Moreover, this leads to frustration among cybersecurity developers when their proposals are not accepted, and they feel their work is not appreciated. On the other hand, putting too much emphasis on cybersecurity leads to feature creep and makes the development unnecessarily complicated without producing appropriate results. It seems natural to orientate oneself by how safety topics are handled in the development process and adjust this to accommodate cybersecurity. It is, however, not clear in which way these added responsibilities should be assigned, as conflicts of interest occur when a single person must additionally take cybersecurity goals into account, which might be clashing with other project goals this person is responsible for. Ideally, cybersecurity aspects are considered and integrated into development processes not only to fulfill customer and legal requirements, but also to enable developers of functionalities not directly related to cybersecurity to produce better and more robust results as shortcuts are no longer easily possible.
Lenhart, PatricArndt, Paulvon Wedel, JanaBeul, ChristianWeldert, Jan
A Blockchain-Backed Database for Qualified Parts2019-01-13433/19/2019
Certain standard parts in the aerospace industry require qualification as a prerequisite to manufacturing, signifying that the manufacturer’s capacity to produce parts consistent with the performance specifications has been audited by a neutral third-party auditor, key customer, and/or group of customers. In at least some cases, a certifying authority provides manufacturers with certificates of qualification which they can then present to prospective customers, and/or lists qualified suppliers in a Qualified Parts List or Qualified Supplier List available from that qualification authority. If this list is in an infrequently updated and/or inconsistently styled format as might be found in a print or PDF document, potential customers wishing to integrate qualification information into their supplier tracking systems must use a potentially error-prone manual process that could lead to later reliance on out-of-date or even forged data. This paper proposes a blockchain-backed database for such applications, facilitating integration with integrators’ electronic systems including near real-time data updates and a reliable audit trail of changes, certificates that provide more reliable signals of data integrity, and a better user interface with enhanced search capabilities. Though piloted with some centralized control related to the centralized issuance of qualifications, the paper describes how blockchain technology in this application could allow a consortium of companies to manage such a database in a decentralized structure like a decentralized autonomous organization. The proposed database also introduces generalizable data structures which can lend powerful dynamism to other data stores in domains with similar data structures or challenges. This paper describes an example implementation converting the TS200 Qualified Manufacturers List to a blockchain-backed database with search and administrative interfaces. The paper further discusses practical challenges associated with implementing such a database and future directions for additional capabilities.
Towne, W. Ben
Risk Analysis of Blockchain Application for Aerospace Records Management2019-01-13443/19/2019
Blockchain as a technology has been successfully deployed in the financial industry. As the technology continues to mature, there are opportunities to use this to solve operational challenges in Aerospace. One of the common use cases is replacing paper records as a proof of compliance with a blockchain enabled distributed ledger. Commonly available open source blockchain frameworks have security ingrained in the components. However, replacing paper records with a blockchain based distributed ledger will require investigation of potential risks involved in the end to end usage of this technology for records management. The objective of this paper is to elucidate potential risks in an aviation record management workflow environment enabled by blockchain and suggest requirements to mitigate the risks. In addition requirements for Blockchain based systems will be proposed, which will guarantee minimum functional requirements like Protection of confidential information Integrity of the information in a record Safeguards against unauthorized access The potential gaps are understood using an illustrative end to end blockchain based process along with their conceptual high level intermediate steps. For example: Authenticated trusted digital identities of the participants whose transactions are recorded in distributed ledgers Trusted source which distributes these identities and has a mechanism to update, revoke and safely secure these identities Trusted methods to ensure detection if the digital identities are compromised Trusted method to demonstrate controlled authorization process for digital identities as per access control rules Trusted methods to demonstrate the generation of accounting logs
Kar, SatyanarayanKasimsetty, VinayBarlow, SusanRao, Sujay
Secure and Privacy-Preserving Data Collection Mechanisms for Connected Vehicles2017-01-16603/28/2017
Nowadays, the automotive industry is experiencing the advent of unprecedented applications with connected devices, such as identifying safe users for insurance companies or assessing vehicle health. To enable such applications, driving behavior data are collected from vehicles and provided to third parties (e.g., insurance firms, car sharing businesses, healthcare providers). In the new wave of IoT (Internet of Things), driving statistics and users’ data generated from wearable devices can be exploited to better assess driving behaviors and construct driver models. We propose a framework for securely collecting data from multiple sources (e.g., vehicles and brought-in devices) and integrating them in the cloud to enable next-generation services with guaranteed user privacy protection. To achieve this goal, we design fine-grained privacy-aware data collection and upload policies that balance between enforcing privacy requirements and optimizing resource consumption (e.g., processing, network bandwidth). The optimal policy will be determined by the privacy index of the integrated multi-source data to be used by the specific service and the desired resource usage. Real-world experiments and privacy leakage analysis are conducted to address privacy issues in vehicle data collection and integration, raise public awareness around privacy leakage, and validate the proposed system.
Li, HuaxinMa, DiMedjahed, BrahimWang, QianyiKim, Yu SeungMitra, Pramita
Google Glass is equipped with a head-up display, camera, microphone, and bone conduction audio transducer serving as a loudspeaker. It also has vibration sensors and a touchpad integrated in the sidepieces of the headset. With these features, Google Glass is well suited for visualization, diagnostics, and service purposes, as well as for technical interventions and person-to-person communication.
For the defense industry, NAND Flash, with its lack of moving parts, has made it the common storage medium for a variety of field applications. With its small size, low power usage, high performance and robustness in extreme environments, choosing solid state storage has been a clear choice from the beginning.
G-33 Configuration Management
Items per page:
1 – 37 of 37