Resilient Authentication and Authorization for the Internet of Things (IoT) Using Edge Computing

Resilient Authentication and Authorization for the Internet of Things (IoT) Using Edge Computing
复制标题

DOI:
10.1145/3375837
复制
发表时间:
2020-03
期刊:
ACM Transactions on Internet of Things
影响因子:
--
通讯作者:
Hokeun Kim;Eunsuk Kang;David Broman;Edward A. Lee
Hokeun Kim;Eunsuk Kang;David Broman;Edward A. Lee
中科院分区:
其他
文献类型:
--
作者:
Hokeun Kim;Eunsuk Kang;David Broman;Edward A. Lee

文献摘要

被引文献

相似文献

一种称为边缘计算的新兴网络体系结构有可能提高物联网服务在网络故障或拒绝服务(DoS)攻击等异常情况下的可用性和弹性。然而,即使当提供关键安全服务(例如,认证和授权)的边缘计算机本身变得不可用时,关于确保可用性的问题也相对较少被探索。本文提出了一种具有弹性的身份验证和授权框架,以增强物联网服务在DoS攻击或故障下的可用性。建议的方法利用一种称为安全迁移的技术,该技术允许物联网设备在其自身的本地授权服务变得不可用时迁移到另一台受信任的边缘计算机。具体地说,我们描述了一个安全迁移框架及其支持机制的设计,包括(1)自动构建迁移策略和(2)准备和执行安全迁移的协议。我们将安全迁移策略构造形式化为一个整数线性规划(ILP)问题,并通过对智能建筑的案例研究验证了该方法的有效性,在模拟的授权服务攻击下,该方案获得了显著更高的可用性。
An emerging type of network architecture called edge computing has the potential to improve the availability and resilience of IoT services under anomalous situations such as network failures or denial-of-service (DoS) attacks. However, relatively little has been explored on the problem of ensuring availability even when edge computers that provide key security services (e.g., authentication and authorization) become unavailable themselves. This article proposes a resilient authentication and authorization framework to enhance the availability of IoT services under DoS attacks or failures. The proposed approach leverages a technique called secure migration, which allows an IoT device to migrate to another trusted edge computer when its own local authorization service becomes unavailable. Specifically, we describe the design of a secure migration framework and its supporting mechanisms, including (1) automated migration policy construction and (2) protocols for preparing and executing the secure migration. We formalize secure migration policy construction as an integer linear programming (ILP) problem and show its effectiveness using a case study on smart buildings, where the proposed solution achieves significantly higher availability under simulated attacks on authorization services.