DocumentCode
2839143
Title
Security architecture for system wide information management
Author
Stephens, Bob
Author_Institution
Tectura Corp., Bellevue, WA, USA
Volume
2
fYear
2005
fDate
30 Oct.-3 Nov. 2005
Abstract
Air Traffic Service Providers (ATSPs) are embarking on a transition of their information systems to a new paradigm of System Wide Information Management (SWIM). SWIM defines an enterprise-wide open, flexible, modular, manageable and secure architecture that is transparent to users. Information sharing, including real-time capability, enables operational improvements and facilitates a reduction in the overall cost of operation and maintenance. SWIM enables decision support systems that connect many stakeholders including the ATSPs and the Airline Operations Centers. For the National Airspace System (NAS), SWIM also facilitates information sharing between with other agencies such as the Department of Homeland Security (DHS). Due to the increased interconnection of ATSP systems and connections to outside enterprises and agencies, security requirements have expanded. New SWIM applications will be written using new technologies. Adapters will be developed to connect legacy applications. The new technologies introduced by SWIM allow a more standardized approach to security, while supporting existing security mechanisms in legacy applications. This paper proposes a security architecture for SWIM, including Identity and Access Management, Registry-Directory-Naming services security, Messaging security, Digital Rights Management and Security Information Management. It also describes the security requirements for the Common Data Transport (CDT) that underlies SWIM, including link and network security, firewalls and intrusion detection systems.
Keywords
aerospace computing; air traffic control; authorisation; decision support systems; safety-critical software; Department of Homeland Security; National Airspace System; air traffic service provider; airline operations center; common data transport; decision support systems; digital rights management; firewalls; identity and access management; information sharing; intrusion detection systems; messaging security; network security; registry-directory-naming services security; security architecture; security information management; system wide information management; Costs; Data security; Decision support systems; Identity management systems; Information management; Information security; Intrusion detection; Management information systems; National security; Terrorism;
fLanguage
English
Publisher
ieee
Conference_Titel
Digital Avionics Systems Conference, 2005. DASC 2005. The 24th
Print_ISBN
0-7803-9307-4
Type
conf
DOI
10.1109/DASC.2005.1563474
Filename
1563474
Link To Document