Fine-Grained Access Control for Smart Healthcare Systems in the Internet of Things

被引:0
|
作者
Pal, Shantanu [1 ]
Hitchens, Michael [1 ]
Varadharajan, Vijay [2 ]
Rabehaja, Tahiry [1 ]
机构
[1] Department of Computing, Macquarie University, Sydney,NSW,2019, Australia
[2] Advanced Cyber Security Engineering Research Centre, University of Newcastle, NSW,2308, Australia
关键词
D O I
10.4108/eai.20-3-2018.154370
中图分类号
学科分类号
摘要
There has been tremendous growth in the application of the Internet of Things (IoT) in our daily lives. Yet with this growth has come numerous security concerns and privacy challenges for both the users and the systems. Smart devices have many uses in a healthcare system, e.g. collecting and reporting patient data and controlling the administration of treatment. In this paper, we address the specific security issue of access control for smart healthcare systems and the protection of smart things from unauthorised access in such large scale systems. Commonly used access control approaches e.g. Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC) and Capability-Based Access Control (CapBAC) do not, in isolation, provide a complete solution for securing access to IoT-enabled smart healthcare devices. They may, for example, require an overly-centralised solution or an unmanageably large policy base. We propose a novel access control architecture which improves policy management by reducing the required number of authentication policies in a large-scale healthcare system while providing fine-grained access control. The devised access control model employs attributes, roles and capabilities. We apply attributes for role membership assignment and in permission evaluation. Membership of roles grants capabilities. The capabilities which are issued may be parameterised based on attributes of the user and are then used to access specific services provided by things. We also provide a formal specification of the model and a description of its implementation and demonstrate its application through different use-case scenarios. The evaluation results of core functionality of our architecture are provided with the practical testbed experiments. © 2018. Shantanu Pal et al.
引用
收藏
相关论文
共 50 条
  • [1] Lightweight and Expressive Fine-Grained Access Control for Healthcare Internet-of-Things
    Xu, Shengmin
    Li, Yingjiu
    Deng, Robert H.
    Zhang, Yinghui
    Luo, Xiangyang
    Liu, Ximeng
    IEEE TRANSACTIONS ON CLOUD COMPUTING, 2022, 10 (01) : 474 - 490
  • [2] SFAC:A Smart Contract-Based Fine-Grained Access Control for Internet of Things
    Chai, Baobao
    Yan, Biwei
    Dong, Anming
    Yu, Jiguo
    2020 INTERNATIONAL CONFERENCE ON IDENTIFICATION, INFORMATION AND KNOWLEDGE IN THE INTERNET OF THINGS (IIKI2020), 2021, 187 : 335 - 340
  • [3] Distributed Fine-Grained Secure Control of Smart Actuators in Internet of Things
    Kouicem, Djamel Eddine
    Bouabdallah, Abdelmadjid
    Lakhlef, Hicham
    2017 15TH IEEE INTERNATIONAL SYMPOSIUM ON PARALLEL AND DISTRIBUTED PROCESSING WITH APPLICATIONS AND 2017 16TH IEEE INTERNATIONAL CONFERENCE ON UBIQUITOUS COMPUTING AND COMMUNICATIONS (ISPA/IUCC 2017), 2017, : 653 - 660
  • [4] Adaptive Fine-grained Access Control Method in Social Internet of Things
    Zhang, Hongbin
    Ma, Pengcheng
    Liu, Bin
    International Journal of Network Security, 2021, 23 (01) : 42 - 48
  • [5] Fine-grained Access Control Framework for Igor, a Unified Access Solution to The Internet of Things
    Shieng, Pauline Sia Wen
    Jansen, Jack
    Pemberton, Steven
    15TH INTERNATIONAL CONFERENCE ON MOBILE SYSTEMS AND PERVASIVE COMPUTING (MOBISPC 2018) / THE 13TH INTERNATIONAL CONFERENCE ON FUTURE NETWORKS AND COMMUNICATIONS (FNC-2018) / AFFILIATED WORKSHOPS, 2018, 134 : 385 - 392
  • [6] Fine-grained Device and Data Access Control of Community Medical Internet of Things
    Huang, Cheng
    Zhang, Ziyang
    Huang, Jing
    Chen, Fulong
    2020 16TH INTERNATIONAL CONFERENCE ON MOBILITY, SENSING AND NETWORKING (MSN 2020), 2020, : 236 - 243
  • [7] On Design of A Fine-Grained Access Control Architecture for Securing IoT-Enabled Smart Healthcare Systems
    Pal, Shantanu
    Hitchens, Michael
    Varadharajan, Vijay
    Rabehaja, Tahiry
    PROCEEDINGS OF THE 14TH EAI INTERNATIONAL CONFERENCE ON MOBILE AND UBIQUITOUS SYSTEMS: COMPUTING, NETWORKING AND SERVICES (MOBIQUITOUS 2017), 2017, : 432 - 441
  • [8] Heracles: Scalable, Fine-Grained Access Control for Internet-of-Things in Enterprise Environments
    Zhou, Qian
    Elbadry, Mohammed
    Ye, Fan
    Yang, Yuanyuan
    IEEE CONFERENCE ON COMPUTER COMMUNICATIONS (IEEE INFOCOM 2018), 2018, : 1781 - 1789
  • [9] Fine-grained Access Control Mechanism of Industrial Internet of Things Based on DAG Blockchain
    Tang, Fei
    Ye, Zhangtao
    Dong, Kung
    Huang, Dong
    International Journal of Network Security, 2022, 24 (05): : 872 - 886
  • [10] Towards Fine-Grained Access Control in Enterprise-Scale Internet-of-Things
    Zhou, Qian
    Elbadry, Mohammed
    Ye, Fan
    Yang, Yuanyuan
    IEEE TRANSACTIONS ON MOBILE COMPUTING, 2021, 20 (08) : 2701 - 2714