FACT: Functionality-centric Access Control System for IoT Programming Frameworks

被引:25
|
作者
Lee, Sanghak [1 ]
Choi, Jiwon [1 ]
Kim, Jihun [1 ]
Cho, Beumjin [1 ]
Lee, Sangho [2 ]
Kim, Hanjun [1 ]
Kim, Jong [1 ]
机构
[1] POSTECH, Pohang, South Korea
[2] Georgia Tech, Atlanta, GA USA
来源
PROCEEDINGS OF THE 22ND ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES (SACMAT'17) | 2017年
关键词
Internet of Things; Functionality-centric; Access control; Over-privileged application; Denial-of-Service; INTERNET;
D O I
10.1145/3078861.3078864
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Improvement in the security and availability is important for the success of the Internet of Things (IoT). Given that recent IoT devices are likely to have multiple functionalities and support third-party applications, this goal becomes challenging to achieve. Through an in-depth investigation of existing IoT frameworks, we focused on two inherent security flaws in their design caused by their device-centric approaches: (1) coarse-grained access control and (2) lack of resource isolation. Because of the coarse-grained access control, IoT devices suffer from over-privileged applications. Furthermore, the lack of resource isolation allows the possibility of Denial-of-Service attacks. In this paper, we propose a functionality-centric approach to managing IoT devices, called FACT, which has two design goals, namely, the principle of least privilege and the availability in terms of device functionalities. FACT isolates each functionality of the device using Linux Containers and grants a subject the privilege to access for each required functionality. We provide the overall framework and detailed working procedures between components that constitute FACT. We built a prototype of FACT on IoTivity and show that it accomplishes secure and efficient linkages between applications and functionalities of IoT devices through analysis and experiments.
引用
收藏
页码:43 / 54
页数:12
相关论文
共 50 条
  • [21] User-trust centric lightweight access control for smart IoT crowd sensing applications in healthcare systems
    Mahmood Z.
    Ashraf Z.
    Iqbal M.
    Farooq B.
    Personal and Ubiquitous Computing, 2025, 29 (1) : 31 - 44
  • [22] Towards unobtrusive patient-centric access-control for Health Information System
    de Carvalho Junior, Marcelo Antonio
    Bandiera-Paiva, Paulo
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2020, 32 (22):
  • [23] Development biometric IoT access control system for employees at the example of KazPost branch
    Uskenbayeva, R. K.
    Kuandykov, A. A.
    Kuatbayeva, A. A.
    Kassymova, A. B.
    Kuatbayeva, G. K.
    Zhussipbek, B. K.
    Khamzina, Zh
    2021 IEEE 23RD CONFERENCE ON BUSINESS INFORMATICS, CBI 2021, VOL 2, 2021, : 202 - 206
  • [24] Internet of Things (IoT)-Based System for Classroom Access Control and Resource Management
    Guerrero-Ulloa, Gleiston
    Villafuerte-Solorzano, Jonathan
    Yanez, Michael
    Hornos, Miguel J.
    Rodriguez-Dominguez, Carlos
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON UBIQUITOUS COMPUTING & AMBIENT INTELLIGENCE (UCAMI 2022), 2023, 594 : 604 - 615
  • [25] Secure and Dynamic Access Control for the Internet of Things (IoT) Based Traffic System
    Aftab M.U.
    Oluwasanmi A.
    Alharbi A.
    Sohaib O.
    Nie X.
    Qin Z.
    Ngo S.T.
    PeerJ Computer Science, 2021, 7 : 1 - 26
  • [26] A Context-Aware Break Glass Access Control System for IoT Environments
    Van Bael, Dries
    Kalantari, Shirin
    Put, Andreas
    De Decker, Bart
    2020 7TH INTERNATIONAL CONFERENCE ON INTERNET OF THINGS: SYSTEMS, MANAGEMENT AND SECURITY (IOTSMS), 2020,
  • [27] Secure and dynamic access control for the Internet of Things (IoT) based traffic system
    Aftab, Muhammad Umar
    Oluwasanmi, Ariyo
    Alharbi, Abdullah
    Sohaib, Osama
    Nie, Xuyun
    Qin, Zhiguang
    Ngo, Son Tung
    PEERJ COMPUTER SCIENCE, 2021,
  • [28] ReACt: A Resource-centric Access Control System for Web-app Interactions on Android
    Zhang, Xin
    Zhang, Yifan
    PROCEEDINGS OF THE WORLD WIDE WEB CONFERENCE 2021 (WWW 2021), 2021, : 1459 - 1470
  • [29] Automated System for Testing and Verification of Control Access Kernel Functionality in Set-Top Boxes
    Pekovic, Vukota
    Zlokolica, Vladimir
    Zloh, Jan
    Katona, Mihajlo
    Teslic, Nikola
    2012 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS (ICCE), 2012, : 25 - 26
  • [30] BBAD: Blockchain-based data assured deletion and access control system for IoT
    Meng, Yuxuan
    Wang, Baosheng
    Xing, Qianqian
    Wang, Xiaofeng
    Liu, Jian
    Xu, Xinyue
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2025, 18 (02)