BlueSky: Towards Convergence of Zero Trust Principles and Score-Based Authorization for IoT Enabled Smart Systems

BlueSky: Towards Convergence of Zero Trust Principles and Score-Based Authorization for IoT Enabled Smart Systems
复制标题

DOI:
10.1145/3532105.3535020
复制
发表时间:
2022-06
期刊:
Proceedings of the 27th ACM on Symposium on Access Control Models and Technologies
影响因子:
--
通讯作者:
Safwa Ameer;Maanak Gupta;Smriti Bhatt;R. Sandhu
Safwa Ameer;Maanak Gupta;Smriti Bhatt;R. Sandhu
中科院分区:
其他
文献类型:
--
作者:
Safwa Ameer;Maanak Gupta;Smriti Bhatt;R. Sandhu

文献摘要

被引文献

相似文献

零信任 (ZT) 是一组不断发展的网络安全范式的术语,它将防御从静态的、基于网络的边界转移到专注于用户、资产和资源。它假设不会仅根据资产或用户帐户的物理或网络位置授予其隐式信任。物联网生态系统中有数十亿台设备相互连接以实现智能环境,这些设备分散在不同的位置,有时是多个城市甚至多个国家。此外,资源受限设备的部署促进了物联网和云服务的集成。大量技术的采用扩大了攻击面,并使物联网生态系统成为许多潜在安全威胁的目标。这种复杂性已经超过了传统的基于边界的安全方法,因为物联网中的不同用例没有单一的、易于识别的边界。因此,我们认为需要将 ZT 指导原则纳入工作流程、系统设计和操作中,以改善物联网应用程序的安全状况。本文提出了在开发智能物联网系统访问控制模型时实施 ZT 原则的必要性。在设计和实现 ZT 授权系统时,它首先提供 ZT 基本原则和 PEI 框架之间的结构化映射。它提出了 ZT 授权需求框架(ZT-ARF),该框架为 ZT 系统中的授权策略模型提供了结构化方法。此外,它分析了拟议的 ZT-ARF 中物联网访问控制模型的要求,并提出了基于 ZT 分数的授权框架 (ZT-SAF) 的愿景和需求,该框架能够维持 ZT 物联网连接系统的访问控制要求。
Zero trust (ZT) is the term for an evolving set of cybersecurity paradigms that move defenses from static, network-based perimeters to focus on users, assets, and resources. It assumes no implicit trust is granted to assets or user accounts based solely on their physical or network location. We have billions of devices in IoT ecosystems connected to enable smart environments, and these devices are scattered around different locations, sometimes multiple cities or even multiple countries. Moreover, the deployment of resource-constrained devices motivates the integration of IoT and cloud services. This adoption of a plethora of technologies expands the attack surface and positions the IoT ecosystem as a target for many potential security threats. This complexity has outstripped legacy perimeter-based security methods as there is no single, easily identified perimeter for different use cases in IoT. Hence, we believe that the need arises to incorporate ZT guiding principles in workflows, systems design, and operations that can be used to improve the security posture of IoT applications. This paper motivates the need to implement ZT principles when developing access control models for smart IoT systems. It first provides a structured mapping between the ZT basic tenets and the PEI framework when designing and implementing a ZT authorization system. It proposes the ZT authorization requirements framework (ZT-ARF), which provides a structured approach to authorization policy models in ZT systems. Moreover, it analyzes the requirements of access control models in IoT within the proposed ZT-ARF and presents the vision and need for a ZT score-based authorization framework (ZT-SAF) that is capable of maintaining the access control requirements for ZT IoT connected systems.