Situational Access Control in the Internet of Things

被引:54
|
作者
Schuster, Roei [1 ,2 ]
Shmatikov, Vitaly [2 ]
Tromer, Eran [1 ,3 ]
机构
[1] Tel Aviv Univ, Tel Aviv, Israel
[2] Cornell Tech, New York, NY 10044 USA
[3] Columbia Univ, New York, NY 10027 USA
基金
美国国家科学基金会;
关键词
Access control; Internet of Things;
D O I
10.1145/3243734.3243817
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Access control in the Internet of Things (IoT) often depends on a situation- for example, "the user is at home"-that can only be tracked using multiple devices. In contrast to the (well-studied) smartphone frameworks, enforcement of situational constraints in the IoT poses new challenges because access control is fundamentally decentralized. It takes place in multiple independent frameworks, subjects are often external to the enforcement system, and situation tracking requires cross-framework interaction and permissioning. Existing IoT frameworks entangle access-control enforcement and situation tracking. This results in overprivileged, redundant, inconsistent, and inflexible implementations. We design and implement a new approach to IoT access control. Our key innovation is to introduce "environmental situation oracles" (ESOs) as first-class objects in the IoT ecosystem. An ESO encapsulates the implementation of how a situation is sensed, inferred, or actuated. IoT access-control frameworks can use ESOs to enforce situational constraints, but ESOs and frameworks remain oblivious to each other's implementation details. A single ESO can be used by multiple access-control frameworks across the ecosystem. This reduces inefficiency, supports consistent enforcement of common policies, and-because ESOs encapsulate sensitive device-access rights-reduces overprivileging. ESOs can be deployed at any layer of the IoT software stack where access control is applied. We implemented prototype ESOs for the IoT resource layer, based on the IoTivity framework, and for the IoT Web services, based on the Passport middleware.
引用
收藏
页码:1056 / 1073
页数:18
相关论文
共 50 条
  • [1] Access Control for the Internet of Things
    Fotiou, Nikos
    Kotsonis, Theodore
    Marias, Giannis F.
    Polyzos, George C.
    [J]. 2016 INTERNATIONAL WORKSHOP ON SECURE INTERNET OF THINGS (SIOT), 2016, : 29 - 38
  • [2] Access Control and the Internet of Things
    Cerf, Vinton G.
    [J]. IEEE INTERNET COMPUTING, 2015, 19 (05) : 96 - 97
  • [3] Internet of things' authentication and access control
    Liu, Jing
    Xiao, Yang
    Chen, C.L. Philip
    [J]. International Journal of Security and Networks, 2012, 7 (04) : 228 - 241
  • [4] Access control in Internet of Things: A survey
    Trabelsi, Rahma
    Fersi, Ghofrane
    Jmaiel, Mohamed
    [J]. COMPUTERS & SECURITY, 2023, 135
  • [5] Access Control with RFID in the Internet of Things
    Jensen, Steffen Elmstrom Holst
    Jacobsen, Rune Hylsberg
    [J]. 2013 IEEE 27TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS WORKSHOPS (WAINA), 2013, : 554 - 559
  • [6] Access Control for Physical Objects in Internet of Things
    Li, Rongyang
    Cui, Shan
    Yao, Xuanxia
    [J]. 2019 IEEE SMARTWORLD, UBIQUITOUS INTELLIGENCE & COMPUTING, ADVANCED & TRUSTED COMPUTING, SCALABLE COMPUTING & COMMUNICATIONS, CLOUD & BIG DATA COMPUTING, INTERNET OF PEOPLE AND SMART CITY INNOVATION (SMARTWORLD/SCALCOM/UIC/ATC/CBDCOM/IOP/SCI 2019), 2019, : 202 - 206
  • [7] Survey on Internet of Things Access Control Security
    Liu, Qixu
    Jin, Ze
    Chen, Canhua
    Gao, Xinbo
    Zheng, Ningjun
    Fang, Yiwei
    Feng, Yun
    [J]. Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2022, 59 (10): : 2190 - 2211
  • [8] A Survey on Access Control in the Age of Internet of Things
    Qiu, Jing
    Tian, Zhihong
    Du, Chunlai
    Zuo, Qi
    Su, Shen
    Fang, Binxing
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2020, 7 (06) : 4682 - 4696
  • [9] Access control in Internet-of-Things: A survey
    Ravidas, Sowmya
    Lekidis, Alexios
    Paci, Federica
    Zannone, Nicola
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2019, 144 : 79 - 101
  • [10] Overview Access and Control Considerations for Internet of Things
    Gomba, M.
    Nleya, Bakhe
    [J]. 2018 INTERNATIONAL CONFERENCE ON ADVANCES IN BIG DATA, COMPUTING AND DATA COMMUNICATION SYSTEMS (ICABCD), 2018,