Attribute-Based Access Control for AWS Internet of Things and Secure Industries of the Future

Attribute-Based Access Control for AWS Internet of Things and Secure Industries of the Future
复制标题

DOI:
10.1109/access.2021.3101218
复制
发表时间:
2021-01-01
期刊:
影响因子:
3.9
通讯作者:
Sandhu, Ravi
Sandhu, Ravi
中科院分区:
计算机科学3区
文献类型:
--
作者:
Bhatt, Smriti;Pham, Thanh Kim;Sandhu, Ravi

文献摘要

被引文献

相似文献

物联网(IoT)正在各个方面彻底改变和提高人类生活的质量。随着物联网设备和应用程序的中断,攻击者正在利用这些物联网设备和应用程序上的弱身份验证和访问控制机制,以获得对用户设备和数据的未经授权的访问,并对其造成伤害。访问控制是保护物联网生态系统的关键安全机制,物联网生态系统包括云计算和边缘计算服务以及智能设备沿着。如今,包括Amazon Web Services(AWS)、Google Cloud Platform(GCP)和Azure在内的主要云和物联网服务提供商都使用了一些自定义形式的基于角色的访问控制(RBAC)模型,沿着使用了由基于策略的访问控制模型启用的特定授权策略。为了实现细粒度的访问控制并克服现有访问控制模型的局限性,迫切需要开发一种灵活和动态的访问控制模型,以保护支持云的物联网架构中的智能设备,数据和资源。在本文中,我们通过构建和扩展先前为AWS IoT开发的访问控制模型(称为AWS-IoTAC模型),为AWS IoT开发了一个正式的基于属性的访问控制(ABAC)模型。我们通过工业物联网用例及其在AWS物联网平台中的实施来证明我们提出的模型的适用性。我们为AWS IoT提出的细粒度模型结合了其现有功能,并为IoT实体引入了新的属性和基于属性的策略,以便在AWS IoT中实现表达性访问控制。我们还评估了我们的模型在AWS云和物联网平台上的性能,以及未来智能行业的用例,以描述我们的模型在现实世界平台上的可行性。
Internet of Things (IoT) is revolutionizing and enhancing the quality of human lives in every aspect. With a disruption of IoT devices and applications, attackers are leveraging weak authentication and access control mechanisms on these IoT devices and applications to gain unauthorized access on user devices and data and cause them harm. Access control is a critical security mechanism to secure the IoT ecosystem which comprises cloud computing and edge computing services along with smart devices. Today major cloud and IoT service providers including Amazon Web Services (AWS), Google Cloud Platform (GCP), and Azure utilize some customized forms of Role-Based Access Control (RBAC) model along with specific authorization policies enabled by policy-based access control models. To enable fine-grained access control and overcome limitations of existing access control models, there is an imminent need to develop a flexible and dynamic access control model for securing smart devices, data and resources in the cloud-enabled IoT architecture. In this paper, we develop a formal attribute-based access control (ABAC) model for AWS IoT by building upon and extending previously developed access control model for AWS IoT, known as AWS-IoTAC model. We demonstrate the applicability of our proposed model through an industrial IoT use case and its implementation in the AWS IoT platform. Our proposed fine grained model for AWS IoT incorporates its existing capabilities and introduces new attributes for IoT entities and attribute-based policies for enabling expressive access control in AWS IoT. We also evaluate the performance of our model on the AWS cloud and IoT platform with the future smart industries use-case to depict the feasibility of our model in a real-world platform.