FACT: Functionality-centric Access Control System for IoT Programming Frameworks

被引:25
|
作者
Lee, Sanghak [1 ]
Choi, Jiwon [1 ]
Kim, Jihun [1 ]
Cho, Beumjin [1 ]
Lee, Sangho [2 ]
Kim, Hanjun [1 ]
Kim, Jong [1 ]
机构
[1] POSTECH, Pohang, South Korea
[2] Georgia Tech, Atlanta, GA USA
关键词
Internet of Things; Functionality-centric; Access control; Over-privileged application; Denial-of-Service; INTERNET;
D O I
10.1145/3078861.3078864
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Improvement in the security and availability is important for the success of the Internet of Things (IoT). Given that recent IoT devices are likely to have multiple functionalities and support third-party applications, this goal becomes challenging to achieve. Through an in-depth investigation of existing IoT frameworks, we focused on two inherent security flaws in their design caused by their device-centric approaches: (1) coarse-grained access control and (2) lack of resource isolation. Because of the coarse-grained access control, IoT devices suffer from over-privileged applications. Furthermore, the lack of resource isolation allows the possibility of Denial-of-Service attacks. In this paper, we propose a functionality-centric approach to managing IoT devices, called FACT, which has two design goals, namely, the principle of least privilege and the availability in terms of device functionalities. FACT isolates each functionality of the device using Linux Containers and grants a subject the privilege to access for each required functionality. We provide the overall framework and detailed working procedures between components that constitute FACT. We built a prototype of FACT on IoTivity and show that it accomplishes secure and efficient linkages between applications and functionalities of IoT devices through analysis and experiments.
引用
收藏
页码:43 / 54
页数:12
相关论文
共 50 条
  • [1] POSTER: IoT Application-Centric Access Control (ACAC)
    Al-Shaboti, Mohammed
    Welch, Ian
    Chen, Aaron
    PROCEEDINGS OF THE 2019 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (ASIACCS '19), 2019, : 685 - 687
  • [2] IaaS-Aided Access Control for Information-Centric IoT
    Carofiglio, Giovanna
    Compagno, Alberto
    Conti, Mauro
    De Gaspari, Fabio
    Muscariello, Luca
    PROCEEDINGS OF THE 2018 IEEE 43RD CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN), 2018, : 208 - 216
  • [3] A Blockchain-Based Auditable Access Control System for Private Data in Service-Centric IoT Environments
    Han, Dezhi
    Zhu, Yujie
    Li, Dun
    Liang, Wei
    Souri, Alireza
    Li, Kuan-Ching
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2022, 18 (05) : 3530 - 3540
  • [4] Application frameworks aid complex control system programming
    Murphy, B
    CONTROL ENGINEERING, 2001, 48 (02) : 12 - 12
  • [5] Access Control Models and Frameworks for the IoT Environment: Review, Challenges, and Future Direction
    Mishra, Rajiv Kumar
    Yadav, Rajesh K.
    Nath, Prem
    WIRELESS PERSONAL COMMUNICATIONS, 2024, 138 (03) : 1671 - 1701
  • [6] A generic discretionary access control system for reuse frameworks
    Wei, LK
    Jarzabek, S
    TWENTY-SECOND ANNUAL INTERNATIONAL COMPUTER SOFTWARE & APPLICATIONS CONFERENCE - PROCEEDINGS, 1998, : 356 - 361
  • [7] IoT Mechatronic Access Control System ePRO 1.4
    Myska, Vojtech
    Burget, Radim
    Kolarik, Marin
    Levek, Vladimir
    Steffan, Pavel
    Haze, Jiri
    IEEE CONSUMER ELECTRONICS MAGAZINE, 2024, 13 (05) : 83 - 92
  • [8] Trust Management in Decentralized IoT Access Control System
    Putra, Guntur Dharma
    Dedeoglu, Volkan
    Kanhere, Saul S.
    Jurdak, Raja
    2020 IEEE INTERNATIONAL CONFERENCE ON BLOCKCHAIN AND CRYPTOCURRENCY (IEEE ICBC), 2020,
  • [9] A Permissioned Blockchain based Access Control System for IOT
    Islam, M. D. Azharul
    Madria, Sanjay K.
    2019 IEEE INTERNATIONAL CONFERENCE ON BLOCKCHAIN (BLOCKCHAIN 2019), 2019, : 469 - 476
  • [10] Fabric-iot: A Blockchain-Based Access Control System in IoT
    Liu, Han
    Han, Dezhi
    Li, Dun
    IEEE ACCESS, 2020, 8 : 18207 - 18218