Attributes Aware Relationship-based Access Control for Smart IoT Systems

Attributes Aware Relationship-based Access Control for Smart IoT Systems
复制标题

DOI:
10.1109/cic56439.2022.00021
复制
发表时间:
2022-12
期刊:
2022 IEEE 8th International Conference on Collaboration and Internet Computing (CIC)
影响因子:
--
通讯作者:
Lopamudra Praharaj;Safwa Ameer;Maanak Gupta;R. Sandhu
Lopamudra Praharaj;Safwa Ameer;Maanak Gupta;R. Sandhu
中科院分区:
其他
文献类型:
--
作者:
Lopamudra Praharaj;Safwa Ameer;Maanak Gupta;R. Sandhu

文献摘要

相似文献

智能连接设备的普遍性已经侵入了我们的日常生活,并已成为我们世界的固有组成部分。然而,物联网(IoT)在关键应用领域的广泛使用引发了对用户隐私和安全的担忧,以应对日益增长的网络威胁。特别是,物联网设备的网络利用的影响超出了经济损失,可能对人类生命构成风险。大多数部署的智能物联网系统访问控制解决方案不提供策略个性化,即根据个人用户的偏好指定或更改策略的能力。因此,当前部署的系统不太适合在多用户环境中指定访问控制策略,在多用户环境中,用户访问相同的设备以执行不同的操作。当智能生态系统涉及复杂的社会关系时,系统的安全性变得棘手,就像智能家居一样。在线社交网络中广泛使用的基于身份的访问控制(ReBAC)提供了在定义访问控制决策时考虑用户关系的能力,并支持策略个性化。然而,据我们所知,还没有人尝试为智能物联网系统开发正式的ReBAC模型。提出了一种ReBACIoT动态细粒度访问控制模型,该模型将用户之间的社会关系沿着属性一起考虑,为智能物联网系统提供基于属性感知关系的访问控制模型。ReBACIoT是正式定义的,通过不同的用例进行说明,实现和测试。
The pervasive nature of smart connected devices has intruded on our daily lives and has become an intrinsic part of our world. However, the wide use of the Internet of Things (IoT) in critical application domains has raised concerns for user privacy and security against growing cyber threats. In particular, the implications of cyber exploitation for IoT devices are beyond financial losses and could constitute risks to human life. Most deployed access control solutions for smart IoT systems do not offer policy individualization, the ability to specify or change the policy according to the individual user’s preference. As a result, currently deployed systems are not well suited to specify access control policies in a multi-user environment, where users access the same devices to perform different operations. The system’s security gets tricky when the smart ecosystem involves complicated social relationships, much like in a smart home. Relationship-based access control (ReBAC), widely used in online social networks, offers the ability to consider user relationships in defining access control decisions and supports policy individualization. However, to the best of our knowledge, no such attempt has been made to develop a formal ReBAC model for smart IoT systems. This paper proposes a ReBACIoT dynamic and fine-grained access control model which considers the social relationships among users along with the attributes to support an attributes-aware relationship-based access control model for smart IoT systems. ReBACIoT is formally defined, illustrated through different use cases, implemented, and tested.