Authorization Framework for Secure Cloud Assisted Connected Cars and Vehicular Internet of Things

Authorization Framework for Secure Cloud Assisted Connected Cars and Vehicular Internet of Things
复制标题

DOI:
10.1145/3205977.3205994
复制
发表时间:
2018-06
期刊:
Proceedings of the 23nd ACM on Symposium on Access Control Models and Technologies
影响因子:
--
通讯作者:
Maanak Gupta;R. Sandhu
Maanak Gupta;R. Sandhu
中科院分区:
其他
文献类型:
--
作者:
Maanak Gupta;R. Sandhu

文献摘要

被引文献

相似文献

物联网已成为智能生活各个领域的主导现象。互联汽车和车辆物联网涉及车辆、交通基础设施或其他实体之间的通信和数据交换,是实现智慧城市和智能交通愿景的关键。车辆云提供了一种有前途的架构,其中智能对象的存储和处理能力被用来提供动态雾平台。研究人员已经证明了这个新兴的车辆物联网生态系统中的漏洞,其中数据已从关键传感器和远程控制的智能车辆中窃取。安全和隐私在车联网(IoV)中非常重要,在车联网中,只有合法用户、传感器或车辆才能访问联网汽车中的电子控制单元、应用程序和数据。在本文中,我们提出了一个授权框架,以确保这个动态系统中的实体之间的相互作用是没有预先定义的。我们提供了一个扩展的访问控制导向(E-ACO)架构相关的车联网,并讨论了车辆云在这个时间和位置敏感的环境中的需求。我们概述了不同的访问控制模型,可以在E-ACO体系结构的各个层和授权框架中执行的方法。最后,我们讨论了用例,以说明我们对云辅助连接汽车和车载物联网的愿景中的访问控制要求,并讨论了可能的研究方向。
Internet of Things has become a predominant phenomenon in every sphere of smart life. Connected Cars and Vehicular Internet of Things, which involves communication and data exchange between vehicles, traffic infrastructure or other entities are pivotal to realize the vision of smart city and intelligent transportation. Vehicular Cloud offers a promising architecture wherein storage and processing capabilities of smart objects are utilized to provide on-the-fly fog platform. Researchers have demonstrated vulnerabilities in this emerging vehicular IoT ecosystem, where data has been stolen from critical sensors and smart vehicles controlled remotely. Security and privacy is important in Internet of Vehicles (IoV) where access to electronic control units, applications and data in connected cars should only be authorized to legitimate users, sensors or vehicles. In this paper, we propose an authorization framework to secure this dynamic system where interactions among entities is not pre-defined. We provide an extended access control oriented (E-ACO) architecture relevant to IoV and discuss the need of vehicular clouds in this time and location sensitive environment. We outline approaches to different access control models which can be enforced at various layers of E-ACO architecture and in the authorization framework. Finally, we discuss use cases to illustrate access control requirements in our vision of cloud assisted connected cars and vehicular IoT, and discuss possible research directions.