Architecture de sécurité des données basée sur HSM et la blockchain
Bibliographic record
Abstract
RÉSUMÉ: L’importance de l’informatique dans la vie quotidienne ne fait qu’augmenter. Entre les téléphones intelligents, les électroménagers intelligents, les automobiles intelligentes et toute autre forme d’objets connectés, le nombre de dispositifs reliés au réseau internet est en forte croissance. Avec cette croissance, la quantité de données générées, transférées et stockées est tout aussi affectée. Ceci crée alors une problématique essentielle liée à la sécurité de ces données. En effet, les nombreuses expériences connues de vol de données, d’usurpation d’identité ou encore de destruction d’information nous montrent que les données informatiques sont à grand risque. De plus, certains événements récents nous rappellent que parmi ces attaques, un tiers provient de l’intérieur de l’organisation ciblée. La littérature propose des solutions de sécurité, certaines liées aux attaques internes, d’autres à la distribution des données dans les larges systèmes informatiques. Cependant, ces solutions ont souvent des failles qui les rendent inadéquates. Ainsi, cette thèse propose une architecture de sécurité basée sur les technologies « Hardware Security Module » et Blockchain pour protéger les données sur les serveurs dans des systèmes locaux et distribués. Ainsi, cette architecture se base sur trois modèles pour atteindre son objectif. Tout d’abord, en harmonie avec la méthodologie de gestion des attaques internes, nous proposons un modèle d’attaques internes qui permet d’identifier les attaques possibles dans une architecture basée sur HSM. La seconde composante de l’architecture est un modèle de détection des attaques internes grâce à des mécanismes de défenses basés sur la cryptographie. Ce modèle se base sur les attaques identifiées par le modèle d’attaques internes afin de proposer quatre mécanismes de défense pour la confidentialité, l’intégrité et la disponibilité des données. Finalement, le dernier modèle relève de la distribution sécurisée des données en proposant un Système de Gestion de Bases de Données (SGBD) distribué basé sur la blockchain et HSM. Ce SGBD distribué fait usage des contrats intelligents pour garantir la distribution sécurisée des données. ABSTRACT: Electronic devices are becoming more and more present with every passing day. Between smartphones, smart appliances, smart cars, and every type of connected device, the number of nodes on the worldwide internet is growing strongly. This growth also affects the amount of data generated, stored, and transferred, bringing new problems related to data and information security. Lately, we have seen many cases of data and identity theft and data destruction, and a third of these events originate from inside the targeted organization. The literature offers security solutions for insider attacks and data distribution in large cyber systems. However, these solutions are flawed and cannot be used as is. Therefore, we propose in this thesis a security architecture based on the blockchain and Hardware Security Module (HSM) technologies to protect server-side data for local and distributed cyber systems. This architecture is based on the combination of three models. First, in alignment with the Insider Attack Mitigation Methodology, we propose an insider attack model to identify the possible attacks on an HSM-based architecture. The second component is an insider attack detection model relying on cryptography-based defense mechanisms. This model uses the identified attacks in the first model to propose four defense mechanisms for data confidentiality, integrity, and availability. Finally, the last model focuses on secure data distribution by proposing a Distributed Database Management System (DDBMS) based on blockchain and HSM. This DDBMS uses smart contracts to guarantee secure data distribution.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame machine prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.
Distilled classifier scores by category (both heads)
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.003 | 0.004 |
| Meta-epidemiology (narrow) | 0.001 | 0.001 |
| Meta-epidemiology (broad) | 0.001 | 0.001 |
| Bibliometrics | 0.001 | 0.001 |
| Science and technology studies | 0.001 | 0.001 |
| Scholarly communication | 0.004 | 0.004 |
| Open science | 0.002 | 0.003 |
| Research integrity | 0.002 | 0.002 |
| Insufficient payload (model declined to judge) | 0.011 | 0.004 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".