DATOVÝ A BEZPEČNOSTNÍ MODEL PRO ZAJIŠTĚNÍ BEZPEČNOSTI SMART CITY
Identifikátory výsledku
Kód výsledku v IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F62690094%3A18450%2F25%3A50023150" target="_blank" >RIV/62690094:18450/25:50023150 - isvavai.cz</a>
Výsledek na webu
—
DOI - Digital Object Identifier
—
Alternativní jazyky
Jazyk výsledku
čeština
Název v původním jazyce
DATOVÝ A BEZPEČNOSTNÍ MODEL PRO ZAJIŠTĚNÍ BEZPEČNOSTI SMART CITY
Popis výsledku v původním jazyce
Souhrnná výzkumná zpráva „Využití umělé inteligence pro zajištění kybernetické bezpečnosti Smart City“ (projekt VJ02010016) představuje komplexní metodický rámec pro návrh datového a bezpečnostního modelu chytrých měst. Dokument reflektuje globální trendy urbanizace, klimatické výzvy a strategické rámce (Agenda 2030, SDGs), které formují koncept Smart City. Zdůrazňuje technologické pilíře – IoT, Big Data, AI, Cloud/Fog/Edge computing a digitální dvojčata – a jejich roli při zajištění efektivní správy městských procesů, udržitelnosti a participace obyvatel.Zpráva detailně popisuje architekturu IoT, charakteristiku Big Data (5V), integraci AI pro prediktivní řízení a adaptivní rozhodování, a rozlišuje výhody a limity cloudových, fog a edge řešení. Klíčovou část tvoří návrh bezpečnostního modelu založeného na principu CIA triády (Confidentiality, Integrity, Availability) a souladu s legislativou (NIS2, GDPR). Identifikována jsou hlavní rizika – od kybernetických útoků, zneužití identity, malware až po fyzické hrozby – a navržen katalog 50 opatření pokrývajících síťovou ochranu, kryptografii, autentizaci, monitoring, organizační i fyzickou bezpečnost.Významnou část práce pak tvoří kapitola 4, která se zaměřuje na bezpečnostní analýzu datových modelů. Popisuje procesy zpracování otevřených dat na Datovém portálu KHK, které jsou modelovány pomocí BPMN. Součástí je CIA analýza a BIA (Business Impact Analysis), na jejichž základě jsou definovány parametry MIPD, MTD a MTDL pro obnovu po výpadku. Dokument uvádí klasifikaci aktiv (informační, infrastrukturní, provozní) a jejich hodnocení z pohledu důvěrnosti, integrity a dostupnosti. Zvláštní pozornost je věnována návrhu logovací architektury (Syslog, Windows Event Log, Log4j, Oracle, MySQL) a stanovení mezí logování dle klasifikace aktiv. Kapitola obsahuje také návrh technických a procesních opatření pro ochranu integrity dat (digitální podpisy, hashování, šifrování, kontrolní součty, monitoring změn, řízení přístupů) a zdůrazňuje nutnost compliance s normami ISO/IEC 27001 a legislativou NIS2.Významné výstupy jsou pak v kapitole 5, která analyzuje společná rizika pro všechna aktiva. Identifikuje kritické hrozby vycházející z aktuálních varování organizací jako NÚKIB, CISA a ENISA. Rizika jsou hodnocena jako vysoce pravděpodobná, zejména zneužití identity, kybernetické útoky z komunikační sítě, zavedení škodlivého kódu, výpadky infrastruktury či neúmyslné chyby obsluhy. Dokument upozorňuje na nedostatečnou realizaci bezpečnostních opatření a absenci kontroly jejich účinnosti. Popsán je scénář výpadku systému a nutnost duplikace řešení (primární a sekundární konfigurace) s důrazem na synchronizaci komponent, aby se předešlo Split Brain Syndromu, který může vést k nekonzistentním datům po obnovení spojení. Součástí kapitoly je katalog technických, organizačních a kontrolních opatření (O1–O50), zahrnující segmentaci sítě, kryptografii, správu identit, MFA, monitoring, penetrační testy a školení. Optimalizace výběru opatření je formulována jako matematický problém pokrytí množiny rizik, řešitelný metodami ILP nebo heuristickými algoritmy.Významnou část zprávy tvoří aplikace konceptu Smart City v doménách dopravy (ITS, smart parking, mikromobilita), energetiky (smart grids, obnovitelné zdroje), zdravotnictví (telemedicína, asistivní technologie), veřejné správy (digitalizace procesů, otevřená data) a životního prostředí (monitoring kvality ovzduší, klimatické senzory). Zpráva uzavírá přehledem publikačních výstupů, které se zaměřují na návrh doménového modelu Smart City, využití fuzz testování pro odhalení zranitelností a aplikaci BIA v systémech smart meteringu.Projekt přináší metodický rámec pro integraci umělé inteligence do kybernetické bezpečnosti chytrých měst, s důrazem na interoperabilitu, odolnost a ochranu dat, čímž vytváří základ pro bezpečnou a udržitelnou digitalizaci městských ekosystémů.
Název v anglickém jazyce
DATA AND SECURITY MODEL FOR ENSURING SMART CITY SECURITY
Popis výsledku anglicky
The research report, "The Use of Artificial Intelligence to Ensure Cyber Security in Smart Cities" (project VJ02010016), presents a comprehensive methodological framework for designing a data and security model for smart cities. The document is indicative of global urbanisation trends, climate challenges, and strategic frameworks (Agenda 2030, SDGs) that shape the Smart City concept. The text emphasises the technological pillars of the Internet of Things (IoT), big data, artificial intelligence (AI), cloud/fog/edge computing, and digital twins, and their role in ensuring effective urban process management, sustainability, and citizen participation.The report provides a comprehensive overview of the architecture of IoT, the characteristics of Big Data (5V), the integration of AI for predictive management and adaptive decision-making, and a thorough analysis of the advantages and limitations of cloud, fog, and edge solutions. A pivotal element of this initiative involves the proposal of a security model grounded in the CIA triad (Confidentiality, Integrity, Availability) and adherence to pertinent legislation (NIS2, GDPR). The primary risks have been identified, ranging from cyberattacks, identity theft, and malware to physical threats. In response, a catalogue of 50 measures has been proposed, encompassing network protection, cryptography, authentication, monitoring, organisational, and physical security.A substantial proportion of the work is dedicated to Chapter 4, which focuses on the security analysis of data models. The text provides a detailed description of the processes of open data processing on the KHK Data Portal, with the use of BPMN to model these processes. The document incorporates a CIA analysis and BIA (Business Impact Analysis), on the basis of which the parameters MIPD, MTD, and MTDL for recovery after failure are defined. The document presents a classification of assets (information, infrastructure, operational) and their evaluation in terms of confidentiality, integrity, and availability. It is imperative to emphasise the significance of meticulous attention to the configuration of the logging architecture, encompassing Syslog, Windows Event Log, Log4j, Oracle, and MySQL. Moreover, the establishment of logging limits is to be conducted in accordance with asset classification. The chapter also includes a proposal for technical and procedural measures to protect data integrity (e.g. digital signatures, hashing, encryption, checksums, change monitoring, access control). It is also important to note the emphasis placed on the need for compliance with ISO/IEC 27001 standards and NIS2 legislation.As outlined in Chapter 5, significant outputs are presented for analysis, with a focus on the common risks associated with all assets. The system has been developed to identify critical threats based on current warnings from organisations such as NÚKIB, CISA, and ENISA. The risks are assessed as being highly probable, in particular identity theft, cyber attacks from communication networks, the introduction of malicious code, infrastructure failures, and unintentional operator errors. The document highlights the inadequate implementation of security measures and the absence of effective oversight. The system failure scenario under discussion is accompanied by a discussion of the requirement for solution duplication (primary and secondary configurations), with particular emphasis on component synchronisation as a means of preventing Split Brain Syndrome. This condition, if it occurs, can result in data becoming inconsistent following connection restoration. The chapter comprises a compendium of technical, organisational, and control measures (O1–O50), encompassing network segmentation, cryptography, identity management, MFA, monitoring, penetration testing, and training. The optimisation of the selection of measures is formulated as a mathematical problem of covering a set of risks, which can be solved by ILP methods or heuristic algorithms.A substantial proportion of the report is dedicated to the implementation of the Smart City concept in various domains, including transport (Intelligent Transport Systems, smart parking, micromobility), energy (smart grids, renewable sources), healthcare (telemedicine, assistive technologies), public administration (process digitisation, open data), and the environment (air quality monitoring, climate sensors). The report concludes with an overview of publications focusing on the design of a Smart City domain model, the use of fuzz testing to detect vulnerabilities, and the application of BIA in smart metering systems.The project provides a methodological framework for integrating artificial intelligence into the cybersecurity of smart cities, with an emphasis on interoperability, resilience, and data protection, thereby laying the foundation for the secure and sustainable digitisation of urban ecosystems.
Klasifikace
Druh
V<sub>souhrn</sub> - Souhrnná výzkumná zpráva
CEP obor
—
OECD FORD obor
10201 - Computer sciences, information science, bioinformathics (hardware development to be 2.2, social aspect to be 5.8)
Návaznosti výsledku
Projekt
<a href="/cs/project/VJ02010016" target="_blank" >VJ02010016: Využití umělé inteligence pro zajištění kybernetické bezpečnosti Smart City</a><br>
Návaznosti
P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)
Ostatní
Rok uplatnění
2025
Kód důvěrnosti údajů
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Údaje specifické pro druh výsledku
Počet stran výsledku
133
Místo vydání
—
Název nakladatele resp. objednatele
Královéhradecký kraj
Verze
—