Scalability Evaluation of a Per-User Access Control Framework

Scalability Evaluation of a Per-User Access Control Framework
复制标题

DOI:
10.1109/csci54926.2021.00291
复制
发表时间:
2021-12
期刊:
2021 International Conference on Computational Science and Computational Intelligence (CSCI)
影响因子:
--
通讯作者:
Arata Endo;Chun-Jae Lee;S. Date
Arata Endo;Chun-Jae Lee;S. Date
中科院分区:
其他
文献类型:
--
作者:
Arata Endo;Chun-Jae Lee;S. Date

文献摘要

相似文献

当今的物联网(IoT)设备具有各种安全要求和策略。虽然访问控制被应用于这样的设备以满足各种各样的要求和策略,但是访问控制很少用于网络资源。针对这种情况,我们提出了一种基于用户的访问控制框架,该框架利用软件定义网络实现了对网络链路和带宽资源的访问控制。所提出的框架使网络管理员能够简单地通过将管理员的策略作为所提出的框架的输入来对网络资源应用访问控制。然而,人们仍然担心,当物联网设备的数量增加时,所提出的框架可能会导致数据传输的显着开销。在本文中,我们通过考虑使用大量物联网设备的实际和实际情况,研究了所提出的框架作为基础设施的可扩展性。我们的评估结果表明,所提出的方法产生的开销可以忽略不计,特别是在物联网设备传输大规模数据的情况下。此外,评估结果表明,所提出的框架减少了物联网设备对第三方的暴露时间。
Today’s Internet of Things (IoT) devices have a variety of security requirements and policies. While an access control is applied to such devices to meet the varieties of requirements and policies, the access control has rarely been used for network resources. Due to this situation, we have proposed a per-user access control framework, which realizes the access control for network links and bandwidth as network resources by using Software-Defined Networking, in our previous work. The proposed framework enables a network administrator to apply access control to network resources simply by giving the administrator’s policy as input to the proposed framework. However, there remains the concern that the proposed framework may cause a significant overhead for the data transfers when the number of IoT devices is increased. In this paper, we investigate how scalable the proposed framework is as infrastructure, by considering the actual and practical situation where lots of IoT devices are used. Our evaluation results imply that the overhead incurred by the proposed method is negligible, especially in the case where IoT devices transfer large-sized data. Also, the evaluation results show that the proposed framework reduces the exposure time of the IoT devices to a third party.