Rethinking Access Control and Authentication for the Home Internet of Things (IoT)
Rethinking Access Control and Authentication for the Home Internet of Things (IoT)
复制标题
DOI:
--
复制
发表时间:
2018
影响因子:
13.5
通讯作者:
Weijia He;Maximilian Golla;Roshni Padhi;Jordan Ofek;Markus Dürmuth;Earlence Fernandes;Blase Ur
中科院分区:
文献类型:
--
作者:
Weijia He;Maximilian Golla;Roshni Padhi;Jordan Ofek;Markus Dürmuth;Earlence Fernandes;Blase Ur
Computing is transitioning from single-user devices to the Internet of Things (IoT), in which multiple users with complex social relationships interact with a single device. Currently deployed techniques fail to provide usable access-control specification or authentication in such settings. In this paper, we begin reenvisioning access control and authentication for the home IoT. We pro-pose that access control focus on IoT capabilities (i. e., certain actions that devices can perform), rather than on a per-device granularity. In a 425-participant online user study, we find stark differences in participants’ desired access-control policies for different capabilities within a single device, as well as based on who is trying to use that capability. From these desired policies, we identify likely candidates for default policies. We also pinpoint necessary primitives for specifying more complex, yet desired, access-control policies. These primitives range from the time of day to the current location of users. Finally, we discuss the degree to which different authentication methods potentially support desired policies.