Distributed Capability-based Access Control for the Internet of Things

Distributed Capability-based Access Control for the Internet of Things
复制标题

DOI:
10.22667/jisis.2013.11.31.001
复制
发表时间:
2013
期刊:
J. Internet Serv. Inf. Secur.
影响因子:
--
通讯作者:
José Luis Hernández Ramos;A. Jara;Leandro Marín;A. Gómez-Skarmeta
José Luis Hernández Ramos;A. Jara;Leandro Marín;A. Gómez-Skarmeta
中科院分区:
其他
文献类型:
--
作者:
José Luis Hernández Ramos;A. Jara;Leandro Marín;A. Gómez-Skarmeta

文献摘要

被引文献

相似文献

互联网向物联网的演变正被部署在新兴的网络物理系统中,如门禁解决方案、警报网络、楼宇自动化,以及所有这些系统向智慧城市的扩展。这种技术在我们生活中的扩展和扩散也带来了安全挑战,因为意想不到的信息泄露,以及对数据和物理系统的非法访问可能会对我们的生活产生很大的影响。这项工作提出了一种通过基于分布式能力的访问控制来对抗内部威胁的加密解决方案。该访问控制解决方案支持对证书、身份验证和授权过程的管理。基于功能的方法在分布式管理、对委托的支持、访问的可追溯性、扩展可伸缩性的身份验证链和基于椭圆曲线加密(ECC)的标准证书支持方面提供了好处。具体来说,它为CoAP资源设计了一个功能令牌,并使用椭圆曲线数字签名算法(ECDSA)对其进行签名,以确保端到端身份验证、完整性和不可否认性。这种分布式解决方案允许在没有任何中间实体干预的情况下部署场景,基于Jennic/NXP JN5139模块实现、部署和评估了具有端到端访问控制验证的分布式场景。通过我们的实验获得的结果证明了所提出方法的可行性,在数字上,这平均需要480 ms来执行所有验证过程(包括智能对象中的签名验证)。
The evolution of the Internet towards the Internet of Things is being deployed in emerging cyberphysical systems such as access control solutions, alert networks, building automation, and the extension of all these systems into Smarter Cities. This extension and proliferation of the technology in our lives is also presenting security challenges, since the unexpected leaks of information, and illegitimate access to data and physical systems could present a high impact in our lives. This work proposes a cryptographic solution against insider threats through a distributed capability-based access control. This access control solution supports the management of certificates, authentication, and authorization processes. The capability-based approach offers benefits in terms of distributed management, support for delegation, traceability of the access, authentication chains to extend scalability and support of standard certificates based on Elliptic Curve Cryptography (ECC). Specifically, it has been designed a capability token for CoAP Resources, which is signed with the Elliptic Curve Digital Signature Algorithm (ECDSA) in order to ensure end-to-end authentication, integrity and non-repudiation. This distributed solution allows the deployment of scenarios without the intervention of any intermediate entity, a distributed scenario with end-to-end access control validation has been implemented, deployed, and evaluated based on the Jennic/NXP JN5139 module. The results obtained through our experiments demonstrate the feasibility of the proposed approach, in numbers, this has required an average of 480 ms to carry out all the validation process (included signature validation in the smart objects).