Rethinking Access Control and Authentication for the Home Internet of Things (IoT)

被引:0
|
作者
He, Weijia [1 ]
Golla, Maximilian [2 ]
Padhi, Roshni [1 ]
Ofek, Jordan [1 ]
Duermuth, Markus [2 ]
Fernandes, Earlence [3 ]
Ur, Blase [1 ]
机构
[1] Univ Chicago, Chicago, IL 60637 USA
[2] Ruhr Univ Bochum, Bochum, Germany
[3] Univ Washington, Seattle, WA 98195 USA
基金
美国国家科学基金会;
关键词
SECURITY;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Computing is transitioning from single-user devices to the Internet of Things (IoT), in which multiple users with complex social relationships interact with a single device. Currently deployed techniques fail to provide usable access-control specification or authentication in such settings. In this paper, we begin reenvisioning access control and authentication for the home IoT. We propose that access control focus on IoT capabilities (i.e., certain actions that devices can perform), rather than on a per-device granularity. In a 425-participant online user study, we find stark differences in participants' desired access-control policies for different capabilities within a single device, as well as based on who is trying to use that capability. From these desired policies, we identify likely candidates for default policies. We also pinpoint necessary primitives for specifying more complex, yet desired, access-control policies. These primitives range from the time of day to the current location of users. Finally, we discuss the degree to which different authentication methods potentially support desired policies.
引用
收藏
页码:255 / 272
页数:18
相关论文
共 50 条
  • [21] Access Control and the Internet of Things
    Cerf, Vinton G.
    [J]. IEEE INTERNET COMPUTING, 2015, 19 (05) : 96 - 97
  • [22] Internet of Things (IoT)-Based System for Classroom Access Control and Resource Management
    Guerrero-Ulloa, Gleiston
    Villafuerte-Solorzano, Jonathan
    Yanez, Michael
    Hornos, Miguel J.
    Rodriguez-Dominguez, Carlos
    [J]. PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON UBIQUITOUS COMPUTING & AMBIENT INTELLIGENCE (UCAMI 2022), 2023, 594 : 604 - 615
  • [23] Secure and Dynamic Access Control for the Internet of Things (IoT) Based Traffic System
    Aftab M.U.
    Oluwasanmi A.
    Alharbi A.
    Sohaib O.
    Nie X.
    Qin Z.
    Ngo S.T.
    [J]. PeerJ Computer Science, 2021, 7 : 1 - 26
  • [24] Secure and dynamic access control for the Internet of Things (IoT) based traffic system
    Aftab, Muhammad Umar
    Oluwasanmi, Ariyo
    Alharbi, Abdullah
    Sohaib, Osama
    Nie, Xuyun
    Qin, Zhiguang
    Ngo, Son Tung
    [J]. PEERJ COMPUTER SCIENCE, 2021,
  • [26] An overview of potential authentication threats and attacks on Internet of Things(IoT): A focus on Smart home applications.
    Gamundani, Attlee M.
    Phillips, Amelia
    Muyingi, Hippolyte N.
    [J]. IEEE 2018 INTERNATIONAL CONGRESS ON CYBERMATICS / 2018 IEEE CONFERENCES ON INTERNET OF THINGS, GREEN COMPUTING AND COMMUNICATIONS, CYBER, PHYSICAL AND SOCIAL COMPUTING, SMART DATA, BLOCKCHAIN, COMPUTER AND INFORMATION TECHNOLOGY, 2018, : 50 - 57
  • [27] A Hierarchical Authentication System for Access Equipment in Internet of Things
    Zhang, Hui-Juan
    He, Shen
    Chen, Jia
    Yang, Kai
    Ran, Peng
    Chen, Jiake
    [J]. INTERNATIONAL JOURNAL OF INTELLIGENT SYSTEMS, 2023, 2023
  • [28] Design and Implementation of a Lightweight Authentication Framework for the Internet of Things (IoT)
    Alshahrani, Mohammed
    Traore, Issa
    Woungang, Isaac
    [J]. 2019 SIXTH INTERNATIONAL CONFERENCE ON INTERNET OF THINGS: SYSTEMS, MANAGEMENT AND SECURITY (IOTSMS), 2019, : 185 - 194
  • [29] Distributed Key Management Authentication algorithm in Internet of Things (IOT)
    Rachini, Ali S.
    Khatoun, R.
    [J]. 2020 SIXTH INTERNATIONAL CONFERENCE ON MOBILE AND SECURE SERVICES (MOBISECSERV)), 2020,
  • [30] Biometric-Based Authentication in Internet of Things (IoT): A Review
    Singh, Vijender
    Kant, Chander
    [J]. ADVANCES IN INFORMATION COMMUNICATION TECHNOLOGY AND COMPUTING, AICTC 2021, 2022, 392 : 309 - 317