• DocumentCode
    2839143
  • Title

    Security architecture for system wide information management

  • Author

    Stephens, Bob

  • Author_Institution
    Tectura Corp., Bellevue, WA, USA
  • Volume
    2
  • fYear
    2005
  • fDate
    30 Oct.-3 Nov. 2005
  • Abstract
    Air Traffic Service Providers (ATSPs) are embarking on a transition of their information systems to a new paradigm of System Wide Information Management (SWIM). SWIM defines an enterprise-wide open, flexible, modular, manageable and secure architecture that is transparent to users. Information sharing, including real-time capability, enables operational improvements and facilitates a reduction in the overall cost of operation and maintenance. SWIM enables decision support systems that connect many stakeholders including the ATSPs and the Airline Operations Centers. For the National Airspace System (NAS), SWIM also facilitates information sharing between with other agencies such as the Department of Homeland Security (DHS). Due to the increased interconnection of ATSP systems and connections to outside enterprises and agencies, security requirements have expanded. New SWIM applications will be written using new technologies. Adapters will be developed to connect legacy applications. The new technologies introduced by SWIM allow a more standardized approach to security, while supporting existing security mechanisms in legacy applications. This paper proposes a security architecture for SWIM, including Identity and Access Management, Registry-Directory-Naming services security, Messaging security, Digital Rights Management and Security Information Management. It also describes the security requirements for the Common Data Transport (CDT) that underlies SWIM, including link and network security, firewalls and intrusion detection systems.
  • Keywords
    aerospace computing; air traffic control; authorisation; decision support systems; safety-critical software; Department of Homeland Security; National Airspace System; air traffic service provider; airline operations center; common data transport; decision support systems; digital rights management; firewalls; identity and access management; information sharing; intrusion detection systems; messaging security; network security; registry-directory-naming services security; security architecture; security information management; system wide information management; Costs; Data security; Decision support systems; Identity management systems; Information management; Information security; Intrusion detection; Management information systems; National security; Terrorism;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Digital Avionics Systems Conference, 2005. DASC 2005. The 24th
  • Print_ISBN
    0-7803-9307-4
  • Type

    conf

  • DOI
    10.1109/DASC.2005.1563474
  • Filename
    1563474