Rethinking Access Control and Authentication for the Home Internet of Things (IoT)

Rethinking Access Control and Authentication for the Home Internet of Things (IoT)
复制标题

DOI:
--
复制
发表时间:
2018
影响因子:
13.5
通讯作者:
Weijia He;Maximilian Golla;Roshni Padhi;Jordan Ofek;Markus Dürmuth;Earlence Fernandes;Blase Ur
Weijia He;Maximilian Golla;Roshni Padhi;Jordan Ofek;Markus Dürmuth;Earlence Fernandes;Blase Ur
中科院分区:
工程技术1区
文献类型:
--
作者:
Weijia He;Maximilian Golla;Roshni Padhi;Jordan Ofek;Markus Dürmuth;Earlence Fernandes;Blase Ur

文献摘要

被引文献

相似文献

计算正在从单用户设备向物联网(IoT)转变,在物联网中,具有复杂社会关系的多个用户与单个设备进行交互。目前所采用的技术无法在这种环境下提供可用的访问控制规范或认证。在本文中,我们开始重新构想家庭物联网的访问控制和认证。我们提出访问控制应侧重于物联网的功能(即设备能够执行的某些操作),而非单个设备的粒度。在一项有425名参与者的在线用户研究中,我们发现参与者对于单个设备内不同功能以及基于试图使用该功能的人员所期望的访问控制策略存在显著差异。从这些期望的策略中,我们确定了默认策略的可能候选方案。我们还明确了用于指定更复杂但期望的访问控制策略的必要原语。这些原语涵盖从一天中的时间到用户的当前位置。最后,我们讨论了不同认证方法在多大程度上可能支持期望的策略。
Computing is transitioning from single-user devices to the Internet of Things (IoT), in which multiple users with complex social relationships interact with a single device. Currently deployed techniques fail to provide usable access-control specification or authentication in such settings. In this paper, we begin reenvisioning access control and authentication for the home IoT. We pro-pose that access control focus on IoT capabilities (i. e., certain actions that devices can perform), rather than on a per-device granularity. In a 425-participant online user study, we find stark differences in participants’ desired access-control policies for different capabilities within a single device, as well as based on who is trying to use that capability. From these desired policies, we identify likely candidates for default policies. We also pinpoint necessary primitives for specifying more complex, yet desired, access-control policies. These primitives range from the time of day to the current location of users. Finally, we discuss the degree to which different authentication methods potentially support desired policies.