Securing Smart Home IoT Systems with Attribute-Based Access Control

被引:5
|
作者
Goyal, Gaurav [1 ]
Liu, Peng [2 ]
Sural, Shamik [1 ]
机构
[1] Indian Inst Technol, Kharagpur, W Bengal, India
[2] Penn State Univ, University Pk, PA 16802 USA
关键词
Attribute-Based Access Control; Home IoT; Security Policy; SmartThnigs; IoT Cloud; INTERNET;
D O I
10.1145/3510547.3517920
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Over the last few years, there has been an increased proliferation of IoT systems for smart homes, enabling owners to remotely manage a variety of devices and gadgets installed on their properties. This growth was made possible due to several innovative contributions from the industry in device & sensor technology, efficient networking protocols, as well as extensive deployment of cloud infrastructure, and the development of user-friendly smartphone applications. However, the security of such systems, especially controlled access to the devices and their functionality, is still lagging. There were some recent attempts to develop access control methods for smart home IoTs. While the solutions appear to be interesting, they either ignore the practical issues faced during real-world deployment in IoT systems or do not support fine-grained access control as required by such applications. In this paper, we show how the security of smart home IoT systems can be strengthened through the use of attribute-based access control, which has been considered due to its several distinct advantages including the ability to specify fine-grained security policies and consideration of environmental conditions for making access decisions. A prototype implementation of the proposed framework has been done in the SmartThings IoT platform. An extensive set of experiments show that the approach is quite promising.
引用
收藏
页码:37 / 46
页数:10
相关论文
共 50 条
  • [41] Smart contracts attribute-based access control model for security & privacy of IoT system using blockchain and edge computing
    Chen, Zhonghua
    Goyal, S. B.
    Rajawat, Anand Singh
    [J]. JOURNAL OF SUPERCOMPUTING, 2024, 80 (02): : 1396 - 1425
  • [42] Smart contracts attribute-based access control model for security & privacy of IoT system using blockchain and edge computing
    Chen Zhonghua
    S. B. Goyal
    Anand Singh Rajawat
    [J]. The Journal of Supercomputing, 2024, 80 : 1396 - 1425
  • [43] SmartAccess: Attribute-Based Access Control System for Medical Records Based on Smart Contracts
    De Oliveira, Marcela Tuler
    Reis, Lucio Henrik Amorim
    Verginadis, Yiannis
    Mattos, Diogo Menezes Ferrazani
    Olabarriaga, Silvia Delgado
    [J]. IEEE ACCESS, 2022, 10 : 117836 - 117854
  • [44] Attribute-based Access Control Model in Healthcare Systems with Blockchain Technology
    Arora, Prince
    Bhagat, Avinash
    Kumar, Mukesh
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2023, 14 (05) : 793 - 803
  • [45] Enabling Workforce Optimization in Constrained Attribute-Based Access Control Systems
    Roy, Arindam
    Sural, Shamik
    Majumdar, Arun Kumar
    Vaidya, Jaideep
    Atluri, Vijayalakshmi
    [J]. IEEE TRANSACTIONS ON EMERGING TOPICS IN COMPUTING, 2021, 9 (04) : 1901 - 1913
  • [46] An attribute-based access control scheme using blockchain technology for IoT data protection
    Yang, Zenghui
    Chen, Xiubo
    He, Yunfeng
    Liu, Luxi
    Che, Yinmei
    Wang, Xiao
    Xiao, Ke
    Xu, Gang
    [J]. HIGH-CONFIDENCE COMPUTING, 2024, 4 (03):
  • [47] Mining Attribute-Based Access Control Policies
    Davari, Maryam
    Zulkernine, Mohammad
    [J]. INFORMATION SYSTEMS SECURITY, ICISS 2022, 2022, 13784 : 186 - 201
  • [48] Monotonicity and Completeness in Attribute-Based Access Control
    Crampton, Jason
    Morisset, Charles
    [J]. SECURITY AND TRUST MANAGEMENT (STM 2014), 2014, 8743 : 33 - 48
  • [49] Attribute-Based Access Control with Efficient Revocation in Data Outsourcing Systems
    Hur, Junbeom
    Noh, Dong Kun
    [J]. IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2011, 22 (07) : 1214 - 1221
  • [50] Revocable attribute-based access control in mutli-autority systems
    Imine, Youcef
    Lounis, Ahmed
    Bouabdallah, Abdelmadjid
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2018, 122 : 61 - 76