Implementation and evaluation of the information flow control for the Internet of Things

Implementation and evaluation of the information flow control for the Internet of Things
复制标题

物联网信息流控制的实现与评估

DOI:
10.1002/cpe.6311
复制
发表时间:
2021
期刊:
Concurrency and Computation: Practice and Experience
影响因子:
--
通讯作者:
Takizawa Makoto
Takizawa Makoto
中科院分区:
--
文献类型:
--
作者:
Nakamura Shigenari;Enokido Tomoya;Takizawa Makoto

文献摘要

相似文献

在物联网中,提出了基于能力的访问控制(CBAC)模型,以保证设备的安全访问。这里,设备的所有者向主题发出一个功能令牌,即一组访问权限。允许主体根据能力令牌中的访问权限操作设备中的ROs(资源对象)。在CBAC模型中,存在一个问题,即在数据被带到RO后,受试者可以通过访问RO中的数据来获取RO的数据,即使受试者不被允许从RO获取数据。在这里,RO中的数据非法流向受试者。在我们之前的研究中,提出并在仿真中评估了中断非法操作的OI (operation interruption)协议。在本文中,我们将实现OI协议,并根据执行时间评估OI协议的授权流程。在评估中,我们明确了OI协议中GET、PUT、POST和DELETE操作的授权流程的执行时间特征。
In the Internet of Things, the CBAC (capability‐based access control) model is proposed to make devices securely accessed. Here, an owner of a device issues a capability token, that is, a set of access rights, to a subject. The subject is allowed to manipulate ROs (resource objects) in the device according to access rights in the capability token. In the CBAC model, there is a problem a subjectsbican obtain data of an RO by accessing the data in an RO after the data are brought to the RO even if the subjectsbiis not allowed to obtain the data from the RO . Here, the data in the RO illegally flow to the subjectsbi. In our previous studies, the OI (operation interruption) protocol where illegal operations are interrupted is proposed and evaluated in the simulation. In this article, we implement the OI protocol and evaluate the authorization process of the OI protocol in terms of the execution time. In the evaluation, we make clear the features of the execution time of authorization processes for GET, PUT, POST, and DELETE operations in the OI protocol.