13.07.2015 Views

System Architecture Design

System Architecture Design

System Architecture Design

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

pSHIELD<strong>System</strong> <strong>Architecture</strong> <strong>Design</strong>enforcing actions communicated from the PDP at the device-level. Those actions reflect the policy orpolicies to be deployed at the local level.3.5 Overlay Layer DefinitionsPUOverlay: is a pSHIELD-specific vertical layer which is technology-independent and interoperates with thethree pSHIELD horizontal layers (node, network and middleware) aiming at inter-layer SPD optimizationand composability of heterogeneous SPD technologies.In particular the Overlay is in charge of:• elaborating, according to specific policies, the SPD related information coming from the horizontallayers• taking consistent SPD related decisions concerning which SPD components have to becomposed and the related configuration and composition rules• enforcing the taken decisions back into the selected SPD components of the three horizontallayersThe Overlay takes its SPD composition decisions on the basis of a very rich information, consisting ofdynamic, semantically enriched, multi-layer, aggregated SPD-related metadata expressed using acommon, formal, technology-independent language.The Overlay consists of a set of SPD Security Agents, each one controlling a given pSHIELD subsystem.The expandability of such a framework is obtained by enabling communication between SPD SecurityAgents controlling different sub-systems.Security Agent (SA): a security agent is an entity, hardware or software, that performs Overlayfunctionalities. Usually there is one security agent per network, so that each agent is in charge of assuringSPD in its segment and, if necessary, exchange information with the neighbouring security agents if this isrequired to satisfy the application needs.Semantic Information: the semantic information is a representation of hardware or software componentsthat constitute the pSHIELD system and is modelled by means of ontologies.PUD2.3.2Issue 5 Page 47 of 122

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!