Authentication and Capability-based Access Control: An Integrated Approach for IoT Environment

被引:0
|
作者
Sivaselvan, N. [1 ,3 ]
Asif, Waqar [2 ]
Bhat, Vivekananda K. [3 ]
Rajarajan, Muttukrishnan [1 ]
机构
[1] City Univ London, Dept Elect & Elect Engn, London, England
[2] Univ West London, Dept Comp & Engn, London, England
[3] Manipal Acad Higher Educ, Manipal Inst Technol, Dept Comp Sci & Engn, Manipal 576104, India
关键词
Authentication; Capability; Access control; IoT; EFFICIENT USER AUTHENTICATION; KEY AGREEMENT SCHEME; INTERNET; SECURE;
D O I
10.1109/iccsn49894.2020.9139051
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
User authentication and capability-based access control approaches have been widely studied in the past. These approaches make the perspective of effortlessly carrying out the authentication and authorization processes non-viable thus limiting their usability in the heterogeneous Internet-of-Things (IoTs). In this paper, we propose an integrated authentication and capability-based access control approach for increased usability in IoT environments. The important characteristic of the approach is that the capability metric generated during authentication is used to perform access control. The proposed approach allows lightweight operations to be performed on IoT devices and computation intensive operations on the cloud server. The security evaluation also shows that the proposed approach is secure against various attack vectors predominant in IoT. The experimental results show that the proposed approach incurs a maximum CPU usage of 29.35%, a maximum memory usage of 2.79% and total computational overhead of 809.26ms in a real IoT testbed which is quite acceptable. The bandwidth requirement for the proposed approach is less because of the comparatively reduced size of the longest message.
引用
收藏
页码:110 / 117
页数:8
相关论文
共 50 条
  • [1] Blockchain-based Scheme for Authentication and Capability-based Access Control in IoT Environment
    Sivaselvan, N.
    Bhat, Vivekananda K.
    Rajarajan, Muttukrishnan
    2020 11TH IEEE ANNUAL UBIQUITOUS COMPUTING, ELECTRONICS & MOBILE COMMUNICATION CONFERENCE (UEMCON), 2020, : 323 - 330
  • [2] A Traceable Capability-based Access Control for IoT
    Li, Chao
    Li, Fan
    Huang, Cheng
    Yin, Lihua
    Luo, Tianjie
    Wang, Bin
    CMC-COMPUTERS MATERIALS & CONTINUA, 2022, 72 (03): : 4967 - 4982
  • [3] Capability-based IoT access control using blockchain
    Liu, Yue
    Lu, Qinghua
    Chen, Shiping
    Qu, Qiang
    O'Connor, Hugo
    Choo, Kim-Kwang Raymond
    Zhang, He
    DIGITAL COMMUNICATIONS AND NETWORKS, 2021, 7 (04) : 463 - 469
  • [4] Capability-based IoT access control using blockchain
    Yue Liu
    Qinghua Lu
    Shiping Chen
    Qiang Qu
    Hugo OConnor
    KimKwang Raymond Choo
    He Zhang
    Digital Communications and Networks, 2021, 7 (04) : 463 - 469
  • [5] CAPLets: Resource Aware, Capability-Based Access Control for IoT
    Bakir, Fatih
    Krintz, Chandra
    Wolski, Rich
    2021 ACM/IEEE 6TH SYMPOSIUM ON EDGE COMPUTING (SEC 2021), 2021, : 106 - 120
  • [6] Information Flow Control Based on the CapBAC (Capability-Based Access Control) Model in the IoT
    Nakamura, Shigenari
    Enokido, Tomoya
    Takizawa, Makoto
    INTERNATIONAL JOURNAL OF MOBILE COMPUTING AND MULTIMEDIA COMMUNICATIONS, 2019, 10 (04) : 13 - 25
  • [7] CoAP Option for Capability-Based Access Control for IoT-Applications
    Chen, Borting
    Guenes, Mesut
    Huang, Yu-Lun
    IOTBD: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON INTERNET OF THINGS AND BIG DATA, 2016, : 266 - 274
  • [8] A capability-based security approach to manage access control in the Internet of Things
    Gusmeroli, Sergio
    Piccione, Salvatore
    Rotondi, Domenico
    MATHEMATICAL AND COMPUTER MODELLING, 2013, 58 (5-6) : 1189 - 1205
  • [9] BlendCAC: A Smart Contract Enabled Decentralized Capability-Based Access Control Mechanism for the IoT
    Xu, Ronghua
    Chen, Yu
    Blasch, Erik
    Chen, Genshe
    COMPUTERS, 2018, 7 (03)
  • [10] VirtusCap: Capability-based Access Control for Unikernels
    Sfyrakis, Ioannis
    Gross, Thomas
    2017 IEEE INTERNATIONAL CONFERENCE ON CLOUD ENGINEERING (IC2E 2017), 2017, : 226 - 237