Author

Yuling Zhang

1 paper indexed here

Fetches their full publication history.

Not the right person? Other researchers publish under this name.

2026

Opacity in Discrete Event Systems and Its Enforcement via State Encryption

Opacity is an information-flow property that determines whether an intruder, by observing the dynamic behavior of a system, can infer private information (e.g., a set of secret states). Standard current-state opacity requires that no subset of secret states be fully disclosed to an intruder. In practice, however, the disclosure of some secret states may be tolerable, whereas only certain state combinations pose a genuine risk of secret exposure. In this paper, we introduce two extensions of opacity to address broader and more practical security requirements. In these extended notions of opacity, only specific combinations of secret states (referred to as secret groups) are regarded as true secrets. Furthermore, considering that most private information is encrypted before transmission, we propose encrypted opacity under a state-based encryption function. Under a bounded adversary model, in which the intruder holds at most one set of decryption credentials for standard-strength encryption protocols, encrypted opacity ensures that the intruder cannot distinguish among encrypted secret groups, thereby mitigating the risk of disclosing the true secrets. To transform a non-opaque system into one that satisfies encrypted opacity, two algorithms are developed to design the state-based encryption function. The proposed notions and approach are demonstrated through a robot data-delivery case study and experiments on randomly generated automata. Note to Practitioners—Typically, the description of the secret behavior of a system is based on a set of secret states, denoted by $S$ , with the system considered opaque if an intruder (using its knowledge of the system model and activity) cannot infer that the state of the system is within any subset of $S$ . In many practical scenarios, however, only specific combinations of certain states pose real security threats. For instance, an intruder who independently acquires several confidential datasets (such as a person’s age, postal code, and shopping records) may not be able to match them to an individual; only when these datasets are combined and analyzed together, the intruder may succeed in obtaining a true secret, i.e., the person’s identity. The extended concept of opacity presented in this paper can characterize the confidentiality of secret-state combinations, which conventional opacity cannot. In networked computer systems, critical information is generally encrypted during storage and transmission (to reduce the risk of unauthorized access or tampering). Thus, we introduce the concept of encrypted opacity. When a system fails to satisfy conventional opacity, the encryption-based approach developed in this paper provides an alternative solution for system operators to ensure that the system becomes opaque in an encrypted domain. The proposed encryption scheme determines the minimal number of protocols required and identifies which secret states can securely share an encryption protocol, supporting practitioners and engineers towards ensuring the confidentiality of secrets in information-intensive systems.

Yuling Zhang, Tenglong Kang, C. Hadjicostis et al. · 0 citations