www.sunshineproject.eu
SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161)
D6.4 S3.4
Security and Privacy
www.sunshineproject.eu
SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161)
Highlights
• Publication of D1.3 now being updated from T1.6
Following on from T1.6 we’re re-viewing and revising D1.3
throughout the project
Focus on what we’re doing and ensuring it works with SUNSHINE
to counter risk, maximise privacy protection, comply to standards
including the development of new standards and best practices
• Architecture based on XACML/SAML with federated IdM
• Result is rule based access control in a number of flavours:
• Role Based Access Control
• Attribute Based Access Control
• Consent Based Access Control
www.sunshineproject.eu
SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161)
Update of D1.3
Taken alongside developments in
T4.8
Reviews newer attack models
Heartbleed as an example
Introduces metrics from MITRE, ISO
and Common Criteria in
developing products and services
Considering use of STIX for incident
reports
www.sunshineproject.eu
SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161)
Identity management - generic
www.sunshineproject.eu
SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161)
Access control – generic XACML
www.sunshineproject.eu
SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161)
Identity and access
management in SUNSHINE
Implemented using WSO2 toolkit
Identity Manager
XACML policy engine
SAML policy engine
X509 certificate generator, verifier
Multiple algorithms (RSA, ECC, etc.)
www.sunshineproject.eu
SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161)
Sunshine’s XACML implementation
www.sunshineproject.eu
SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161)
Sunshine’s XACML implementation
www.sunshineproject.eu
SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161)
Sunshine’s XACML implementation
PEP
PAP/PDP
User Directory
www.sunshineproject.eu
SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161)
Principles involved
Rule processing
Attestation creation using signed
attributes
Attestation verification
www.sunshineproject.eu
SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161)
www.sunshineproject.eu
SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161)
Process
www.sunshineproject.eu
SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161)
Next steps #1
Testing of implementation
Done by Sinergis
SUNSHINE specific scripts
Re-analysis of data and user model to
assign rules for access
Determine authority for each rule
Distribute rules and collate policies
More testing
www.sunshineproject.eu
SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161)
Next steps #2
Creation of new work item in ETSI
CYBER for Access Control scripting
Extending rules for good XACML
essentially
Building towards introducing the cPP
concept to GML through OGC
Reviewing algorithms for asymmetric
access control attestations in a
quantum safe cryptographic world
www.sunshineproject.eu
SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161)
Next steps #3
Working with OGC to tighten up
geoXACML
As part of smart city initiatives in OGC
Preparing report on anonymisation
Current anonymisation practices in
SUNSHINE are adequate
Concern is linkage and inference from
other data sources (much more
complex anti-privacy attack but
concern has been raised in the EU)
www.sunshineproject.eu
SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161)
Standards development goals
• Developments with ETSI at
smartM2M, ITS and CYBER
TR 102 893
Risk analysis TVRA
TS 103 097
Security data
definitions
TS 102 940
ITS security
architecture & sec
management
TS 102 941
Trust & Privacy
TS 102 942
Confidentiality
TS 102 943
Access control
All published
and in
revision/mai
ntenance
mode
www.sunshineproject.eu
SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161)
Credits
For more training material and courses visit http://www.sunshineproject.eu/solutions/training
or contact us directly at training@sunshineproject.eu
Source:www.unionegeometri.com
Thank you!
Scott CADZOW
C3L

More Related Content

PDF
S.3.1 Introduction to Scenario 3
PDF
S 2.1 Introduction to Scenario 2
PDF
S.1.5 Map4Data App
PDF
S.2.f Specifications for Data Ingestion via Green Button
PDF
S.3.k Security Layer
PDF
S.1.4 Model for Energy Map Calculation
PDF
S.2.h Meter Data Management Service
PDF
S.1.1 Introduction to Scenario 1
S.3.1 Introduction to Scenario 3
S 2.1 Introduction to Scenario 2
S.1.5 Map4Data App
S.2.f Specifications for Data Ingestion via Green Button
S.3.k Security Layer
S.1.4 Model for Energy Map Calculation
S.2.h Meter Data Management Service
S.1.1 Introduction to Scenario 1

What's hot (20)

PDF
S.2.i Suggestion Service
PDF
S.3.l Lamp Control Service
PDF
S.2.g Meter and Sensor Data Management Service
PDF
S.1.c Building Energy Performance Estimation
PDF
Servizio Gestione Flussi Dati Energetici Edifici
PDF
S.1.3 INSPIRE Directive
PDF
S.1.b Building Energy Pre Certification Service
PDF
SUNSHINE Project: Romain Nouvel, Jean Marie Bahu
PPT
Energy efficiency in buildings
PPTX
Álvaro Sicilia, ARC Engineering and Architecture La Salle, Barcelona, Spain.
PDF
Assisting Energy Management in Smart Buildings and Microgrids
PPTX
Leandro Madrazo, ARC Engineering and Architecture La Salle, Barcelona, Spain.
PPTX
Benjamín González, CYPE Ingenieros, S.A., Alicante, Spain.
PPTX
Aitor Elorriaga, Institut für Angewandte Systemtechnik Bremen, Germany.
PPTX
Gašper Stegnar, Jožef Stefan Institute, Ljubljana, Slovenia.
PDF
Ijariie1172
PPTX
Niagara Dashboard Application
PPTX
Leandro Madrazo, ARC Engineering and Architecture La Salle, Barcelona, Spain.
PPTX
Gonçal Costa, ARC Engineering and Architecture La Salle, Barcelona, Spain.
PDF
Deimos energy suite eng
S.2.i Suggestion Service
S.3.l Lamp Control Service
S.2.g Meter and Sensor Data Management Service
S.1.c Building Energy Performance Estimation
Servizio Gestione Flussi Dati Energetici Edifici
S.1.3 INSPIRE Directive
S.1.b Building Energy Pre Certification Service
SUNSHINE Project: Romain Nouvel, Jean Marie Bahu
Energy efficiency in buildings
Álvaro Sicilia, ARC Engineering and Architecture La Salle, Barcelona, Spain.
Assisting Energy Management in Smart Buildings and Microgrids
Leandro Madrazo, ARC Engineering and Architecture La Salle, Barcelona, Spain.
Benjamín González, CYPE Ingenieros, S.A., Alicante, Spain.
Aitor Elorriaga, Institut für Angewandte Systemtechnik Bremen, Germany.
Gašper Stegnar, Jožef Stefan Institute, Ljubljana, Slovenia.
Ijariie1172
Niagara Dashboard Application
Leandro Madrazo, ARC Engineering and Architecture La Salle, Barcelona, Spain.
Gonçal Costa, ARC Engineering and Architecture La Salle, Barcelona, Spain.
Deimos energy suite eng
Ad

Similar to S.3.4 Security and Privacy (20)

PDF
Taking the fire drill out of making firewall changes
PDF
Demystifying Control Towers: What Drives Effectiveness?
PPTX
Cisco Firepower Migration | Cisco and AlgoSec Joint Webinar
PPT
Addressing the challenge of energy efficiency through ICT
PPTX
Cisco ACI & Hybrid Networks - Breaking Down Silos with Central Policy Management
PDF
Security Assessment (SECA)_English_PDF.pdf
PDF
Leverage IoT to Setup Smart Manufacturing Solutions
PPTX
Microsoft Power & Utilities POV
PDF
Cybersecurity for Smart Grids: Technical Approaches to Provide Cybersecurity
PDF
SolarWinds.pdf
PPTX
IREC part 02
PPTX
DigitalClone Live Product Update
PDF
Pres Final Taube ConnWeek 2012
PPTX
Mastering Surveying Efficiency: Tips and Tricks with Nikon Total Station Online
PDF
Best Practices for Network Security Management
PDF
GDPR Compliance Countdown - Is your Application environment ready?
PPT
TAC by Schneider Electric Corporate Presentation
PDF
redhat-IoT_use_cases-DavidBericat
PPTX
Cisco Enterprise Cloud Suite for Service Providers
PPTX
A3 cloud computing
Taking the fire drill out of making firewall changes
Demystifying Control Towers: What Drives Effectiveness?
Cisco Firepower Migration | Cisco and AlgoSec Joint Webinar
Addressing the challenge of energy efficiency through ICT
Cisco ACI & Hybrid Networks - Breaking Down Silos with Central Policy Management
Security Assessment (SECA)_English_PDF.pdf
Leverage IoT to Setup Smart Manufacturing Solutions
Microsoft Power & Utilities POV
Cybersecurity for Smart Grids: Technical Approaches to Provide Cybersecurity
SolarWinds.pdf
IREC part 02
DigitalClone Live Product Update
Pres Final Taube ConnWeek 2012
Mastering Surveying Efficiency: Tips and Tricks with Nikon Total Station Online
Best Practices for Network Security Management
GDPR Compliance Countdown - Is your Application environment ready?
TAC by Schneider Electric Corporate Presentation
redhat-IoT_use_cases-DavidBericat
Cisco Enterprise Cloud Suite for Service Providers
A3 cloud computing
Ad

More from SUNSHINEProject (11)

PDF
Sunshine lamia greek native language
PDF
S.2.e Specifications for Data Ingestion via Sunshine FTP
PDF
SUNSHINE Project: Francesco Pignatelli, Maria Teresa Borzacchiello
PDF
SUNSHINE Project: Bart delathouwer
PDF
SUNSHINE Project: Paolo Conci
PDF
Sunshine Project: Energy Maps Trenta
PDF
S.1.a Data Model for Energy Map Data Collection
PDF
S.2.4 Validation Activities for Scenario 2 (case Ferrara)
PDF
S.1.2 Data Model for Energy Maps
PDF
SUNSHINE Project - Scenario 2 (HR)
PDF
SUNSHINE Project - Map4data App (IT)
Sunshine lamia greek native language
S.2.e Specifications for Data Ingestion via Sunshine FTP
SUNSHINE Project: Francesco Pignatelli, Maria Teresa Borzacchiello
SUNSHINE Project: Bart delathouwer
SUNSHINE Project: Paolo Conci
Sunshine Project: Energy Maps Trenta
S.1.a Data Model for Energy Map Data Collection
S.2.4 Validation Activities for Scenario 2 (case Ferrara)
S.1.2 Data Model for Energy Maps
SUNSHINE Project - Scenario 2 (HR)
SUNSHINE Project - Map4data App (IT)

Recently uploaded (20)

PDF
Convolutional neural network based encoder-decoder for efficient real-time ob...
PDF
CloudStack 4.21: First Look Webinar slides
PDF
Developing a website for English-speaking practice to English as a foreign la...
PDF
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
PDF
How ambidextrous entrepreneurial leaders react to the artificial intelligence...
PDF
Comparative analysis of machine learning models for fake news detection in so...
PDF
Produktkatalog für HOBO Datenlogger, Wetterstationen, Sensoren, Software und ...
PDF
The influence of sentiment analysis in enhancing early warning system model f...
PPT
What is a Computer? Input Devices /output devices
PPT
Galois Field Theory of Risk: A Perspective, Protocol, and Mathematical Backgr...
PPTX
MicrosoftCybserSecurityReferenceArchitecture-April-2025.pptx
PDF
OpenACC and Open Hackathons Monthly Highlights July 2025
PPTX
Final SEM Unit 1 for mit wpu at pune .pptx
PPTX
Build Your First AI Agent with UiPath.pptx
PPTX
The various Industrial Revolutions .pptx
PDF
Hybrid horned lizard optimization algorithm-aquila optimizer for DC motor
DOCX
search engine optimization ppt fir known well about this
PPTX
Chapter 5: Probability Theory and Statistics
PDF
UiPath Agentic Automation session 1: RPA to Agents
PPTX
Custom Battery Pack Design Considerations for Performance and Safety
Convolutional neural network based encoder-decoder for efficient real-time ob...
CloudStack 4.21: First Look Webinar slides
Developing a website for English-speaking practice to English as a foreign la...
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
How ambidextrous entrepreneurial leaders react to the artificial intelligence...
Comparative analysis of machine learning models for fake news detection in so...
Produktkatalog für HOBO Datenlogger, Wetterstationen, Sensoren, Software und ...
The influence of sentiment analysis in enhancing early warning system model f...
What is a Computer? Input Devices /output devices
Galois Field Theory of Risk: A Perspective, Protocol, and Mathematical Backgr...
MicrosoftCybserSecurityReferenceArchitecture-April-2025.pptx
OpenACC and Open Hackathons Monthly Highlights July 2025
Final SEM Unit 1 for mit wpu at pune .pptx
Build Your First AI Agent with UiPath.pptx
The various Industrial Revolutions .pptx
Hybrid horned lizard optimization algorithm-aquila optimizer for DC motor
search engine optimization ppt fir known well about this
Chapter 5: Probability Theory and Statistics
UiPath Agentic Automation session 1: RPA to Agents
Custom Battery Pack Design Considerations for Performance and Safety

S.3.4 Security and Privacy

  • 1. www.sunshineproject.eu SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161) D6.4 S3.4 Security and Privacy
  • 2. www.sunshineproject.eu SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161) Highlights • Publication of D1.3 now being updated from T1.6 Following on from T1.6 we’re re-viewing and revising D1.3 throughout the project Focus on what we’re doing and ensuring it works with SUNSHINE to counter risk, maximise privacy protection, comply to standards including the development of new standards and best practices • Architecture based on XACML/SAML with federated IdM • Result is rule based access control in a number of flavours: • Role Based Access Control • Attribute Based Access Control • Consent Based Access Control
  • 3. www.sunshineproject.eu SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161) Update of D1.3 Taken alongside developments in T4.8 Reviews newer attack models Heartbleed as an example Introduces metrics from MITRE, ISO and Common Criteria in developing products and services Considering use of STIX for incident reports
  • 4. www.sunshineproject.eu SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161) Identity management - generic
  • 5. www.sunshineproject.eu SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161) Access control – generic XACML
  • 6. www.sunshineproject.eu SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161) Identity and access management in SUNSHINE Implemented using WSO2 toolkit Identity Manager XACML policy engine SAML policy engine X509 certificate generator, verifier Multiple algorithms (RSA, ECC, etc.)
  • 7. www.sunshineproject.eu SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161) Sunshine’s XACML implementation
  • 8. www.sunshineproject.eu SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161) Sunshine’s XACML implementation
  • 9. www.sunshineproject.eu SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161) Sunshine’s XACML implementation PEP PAP/PDP User Directory
  • 10. www.sunshineproject.eu SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161) Principles involved Rule processing Attestation creation using signed attributes Attestation verification
  • 11. www.sunshineproject.eu SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161)
  • 12. www.sunshineproject.eu SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161) Process
  • 13. www.sunshineproject.eu SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161) Next steps #1 Testing of implementation Done by Sinergis SUNSHINE specific scripts Re-analysis of data and user model to assign rules for access Determine authority for each rule Distribute rules and collate policies More testing
  • 14. www.sunshineproject.eu SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161) Next steps #2 Creation of new work item in ETSI CYBER for Access Control scripting Extending rules for good XACML essentially Building towards introducing the cPP concept to GML through OGC Reviewing algorithms for asymmetric access control attestations in a quantum safe cryptographic world
  • 15. www.sunshineproject.eu SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161) Next steps #3 Working with OGC to tighten up geoXACML As part of smart city initiatives in OGC Preparing report on anonymisation Current anonymisation practices in SUNSHINE are adequate Concern is linkage and inference from other data sources (much more complex anti-privacy attack but concern has been raised in the EU)
  • 16. www.sunshineproject.eu SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161) Standards development goals • Developments with ETSI at smartM2M, ITS and CYBER TR 102 893 Risk analysis TVRA TS 103 097 Security data definitions TS 102 940 ITS security architecture & sec management TS 102 941 Trust & Privacy TS 102 942 Confidentiality TS 102 943 Access control All published and in revision/mai ntenance mode
  • 17. www.sunshineproject.eu SUNSHINE - Smart UrbaN ServIces for Higher eNergy Efficiency (GA no: 325161) Credits For more training material and courses visit http://www.sunshineproject.eu/solutions/training or contact us directly at training@sunshineproject.eu Source:www.unionegeometri.com Thank you! Scott CADZOW C3L