共享移动集成中的安全风险管理

A. O. Affia, Raimundas Matulevičius
{"title":"共享移动集成中的安全风险管理","authors":"A. O. Affia, Raimundas Matulevičius","doi":"10.1145/3538969.3543797","DOIUrl":null,"url":null,"abstract":"Urbanization pushes toward the need for integrated shared mobility solutions such as bike-sharing, car-sharing, and other public transport schemes to provide seamless inter-modal journeys to users. Achieving shared mobility integration can be done by tickets and payments, leveraging access to user data and payment information across mobility systems to allow access to and payment for transport services, and making multi-modal transport more accessible. Providing such mobility services requires access to and use of sensitive user data and sensitive safety-related functions vulnerable to cyberattacks. However, research examining the security and privacy concerns in shared mobility integration is limited. Thus, we evaluate shared mobility integration components, stakeholders, and processes based on literature, to provide an abstract integration model when integrating shared mobility schemes. We also highlight mentions of security related issues and the potential security risks as a result of implementing shared mobility integration. We then applied lessons from our analysis to a real-world bike-sharing integration case study, analyzing potential security risks, proposing appropriate suggestions to manage discovered security risks. Our findings and discussions benefit transport operators, authorities, and mobility stakeholders by encouraging security-by-design and security risk management practices when implementing shared mobility integration schemes.","PeriodicalId":306813,"journal":{"name":"Proceedings of the 17th International Conference on Availability, Reliability and Security","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2022-08-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"Security Risk Management in Shared Mobility Integration\",\"authors\":\"A. O. Affia, Raimundas Matulevičius\",\"doi\":\"10.1145/3538969.3543797\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Urbanization pushes toward the need for integrated shared mobility solutions such as bike-sharing, car-sharing, and other public transport schemes to provide seamless inter-modal journeys to users. Achieving shared mobility integration can be done by tickets and payments, leveraging access to user data and payment information across mobility systems to allow access to and payment for transport services, and making multi-modal transport more accessible. Providing such mobility services requires access to and use of sensitive user data and sensitive safety-related functions vulnerable to cyberattacks. However, research examining the security and privacy concerns in shared mobility integration is limited. Thus, we evaluate shared mobility integration components, stakeholders, and processes based on literature, to provide an abstract integration model when integrating shared mobility schemes. We also highlight mentions of security related issues and the potential security risks as a result of implementing shared mobility integration. We then applied lessons from our analysis to a real-world bike-sharing integration case study, analyzing potential security risks, proposing appropriate suggestions to manage discovered security risks. Our findings and discussions benefit transport operators, authorities, and mobility stakeholders by encouraging security-by-design and security risk management practices when implementing shared mobility integration schemes.\",\"PeriodicalId\":306813,\"journal\":{\"name\":\"Proceedings of the 17th International Conference on Availability, Reliability and Security\",\"volume\":null,\"pages\":null},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2022-08-23\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Proceedings of the 17th International Conference on Availability, Reliability and Security\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1145/3538969.3543797\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 17th International Conference on Availability, Reliability and Security","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3538969.3543797","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

摘要

城市化推动了对综合共享出行解决方案的需求,如自行车共享、汽车共享和其他公共交通方案,为用户提供无缝的多式联运旅程。通过购票和支付,利用跨移动系统的用户数据和支付信息,实现交通服务的获取和支付,并使多式联运更容易实现,从而实现共享交通一体化。提供此类移动服务需要访问和使用易受网络攻击的敏感用户数据和敏感的安全相关功能。然而,关于共享移动集成中的安全和隐私问题的研究是有限的。因此,我们基于文献对共享移动出行集成组件、利益相关者和流程进行评估,以提供集成共享移动出行方案时的抽象集成模型。我们还强调了与安全相关的问题以及实现共享移动集成所带来的潜在安全风险。然后,我们将分析的经验教训应用到现实世界的共享单车整合案例研究中,分析潜在的安全风险,提出适当的建议来管理发现的安全风险。我们的研究结果和讨论通过鼓励在实施共享交通一体化方案时采用安全设计和安全风险管理实践,使交通运营商、当局和交通利益相关者受益。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Security Risk Management in Shared Mobility Integration
Urbanization pushes toward the need for integrated shared mobility solutions such as bike-sharing, car-sharing, and other public transport schemes to provide seamless inter-modal journeys to users. Achieving shared mobility integration can be done by tickets and payments, leveraging access to user data and payment information across mobility systems to allow access to and payment for transport services, and making multi-modal transport more accessible. Providing such mobility services requires access to and use of sensitive user data and sensitive safety-related functions vulnerable to cyberattacks. However, research examining the security and privacy concerns in shared mobility integration is limited. Thus, we evaluate shared mobility integration components, stakeholders, and processes based on literature, to provide an abstract integration model when integrating shared mobility schemes. We also highlight mentions of security related issues and the potential security risks as a result of implementing shared mobility integration. We then applied lessons from our analysis to a real-world bike-sharing integration case study, analyzing potential security risks, proposing appropriate suggestions to manage discovered security risks. Our findings and discussions benefit transport operators, authorities, and mobility stakeholders by encouraging security-by-design and security risk management practices when implementing shared mobility integration schemes.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Web Bot Detection Evasion Using Deep Reinforcement Learning Cyber-security measures for protecting EPES systems in the 5G area An Internet-Wide View of Connected Cars: Discovery of Exposed Automotive Devices Secure Mobile Agents on Embedded Boards: a TPM based solution SoK: Applications and Challenges of using Recommender Systems in Cybersecurity Incident Handling and Response
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1