SAAC: Secure Access Control Management Framework for Multi-User Smart Home Systems

被引:0
|
作者
Hashmi, Iram Fatima [1 ]
Iqbal, Zafar [1 ]
Munir, Eman [1 ]
Kryvinska, Natalia [2 ]
Ivanochko, Iryna [2 ]
Sampedro, Gabriel Avelino [3 ]
机构
[1] Air Univ, Dept Cyber Secur, Islamabad 44000, Pakistan
[2] Comenius Univ, Fac Management, Bratislava 82005, Slovakia
[3] De La Salle Coll St Benilde, Sch Management & Informat Technol, Manila 1004, Philippines
来源
IEEE ACCESS | 2024年 / 12卷
关键词
Access control; Smart homes; Smart devices; Internet of Things; Environmental factors; Servers; Dynamic scheduling; Smart home; access control; authorization; multi-user; attribute-based access control; role-based access control; IOT; SDN; SCHEME;
D O I
10.1109/ACCESS.2024.3446180
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In a smart home environment, multiple users can access a single smart device simultaneously. Moreover, these multiple users may have conflicting demands at a time; that is, one user's demands differ from another for the same device based on the role of users and environmental factors. Therefore, existing single-user access control systems cannot handle such conflicting and dynamically changing demands, considering both roles and environmental factors in the multi-user smart home environment. Considering this issue, we proposed a Smart Access Control and Authorization framework (SAAC). It is a multi-user access control solution that has four modules, namely, a user interaction module, a backend server module, a policy manager module, and a policy execution module. The user interaction module collects user data and resource policies, which are processed by the backend server and forwarded to the policy manager. The policy manager resolves conflicts and generates final policies, which are stored in the backend server for enforcement by the policy execution module. The finalized policies are shared with the backend server module and saved there till needed for execution by the policy execution module to enforce the access control decision. We have implemented a proof of concept of the proposed framework on VS Code using the Casbin library. The performance evaluation results show our framework's effectiveness and efficiency with lower computational complexity requirements than existing methods. Finally, we performed a security analysis of the proposed model based on the STRIDE model that confirms its robustness against access control attacks.
引用
收藏
页码:133339 / 133355
页数:17
相关论文
共 50 条
  • [21] SM9-based Traceable and Accountable Access Control for Secure Multi-user Cloud Storage
    Ren, Ke
    Jiang, Peng
    Gai, Keke
    Zhu, Liehuang
    Huang, Jingjing
    2021 IEEE 6TH INTERNATIONAL CONFERENCE ON SMART CLOUD (SMARTCLOUD 2021), 2021, : 13 - 18
  • [22] Fine-Grained Access Control Aware Multi-User Data Sharing with Secure Keyword Search
    Zhao, Fangming
    Nishide, Takashi
    Sakurai, Kouichi
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2014, E97D (07): : 1790 - 1803
  • [23] A Secure Access Control Framework for Cloud Management
    Jiawei Zhang
    Ning Lu
    Jianfeng Ma
    Ruixiao Wang
    Wenbo Shi
    Mobile Networks and Applications, 2022, 27 : 404 - 416
  • [24] Blockchain-Based Access Control for Secure Smart Industry Management Systems
    Kalapaaking, Aditya Pribadi
    Khalil, Ibrahim
    Rahman, Mohammad Saidur
    Bouras, Abdelaziz
    NETWORK AND SYSTEM SECURITY, NSS 2022, 2022, 13787 : 615 - 630
  • [25] A Secure Access Control Framework for Cloud Management
    Zhang, Jiawei
    Lu, Ning
    Ma, Jianfeng
    Wang, Ruixiao
    Shi, Wenbo
    MOBILE NETWORKS & APPLICATIONS, 2022, 27 (01): : 404 - 416
  • [26] A Multi Perspective Access Control in a Smart Home
    Kanchi, Shravya
    Karlapalem, Kamalakar
    PROCEEDINGS OF THE ELEVENTH ACM CONFERENCE ON DATA AND APPLICATION SECURITY AND PRIVACY (CODASPY '21), 2021, : 321 - 323
  • [27] Privacy-preserving Secure Media Streaming for Multi-user Smart Environments
    Carpentieri, Bruno
    Castiglione, Arcangelo
    de Santis, Alfredo
    Palmieri, Francesco
    Pizzolante, Raffaele
    ACM TRANSACTIONS ON INTERNET TECHNOLOGY, 2022, 22 (02)
  • [28] Secure Data Transmission with Access Control for Smart Home Devices
    Chen, Biwen
    Yang, Lei
    Xiang, Tao
    Li, Xiaoguo
    2021 IEEE 20TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2021), 2021, : 258 - 265
  • [29] Personalization and multi-user management in smart homes for disabled people
    Kadouche, Rachid
    Abdulrazak, Bessam
    Mokhtari, Mounir
    Giroux, Sylvain
    Pigot, Héléne
    International Journal of Smart Home, 2009, 3 (01): : 39 - 48
  • [30] Secure Beamforming in Multi-User Multi-IRS Millimeter Wave Systems
    Rafieifar, Anahid
    Ahmadinejad, Hosein
    Razavizadeh, S. Mohammad
    He, Jiguang
    IEEE TRANSACTIONS ON WIRELESS COMMUNICATIONS, 2023, 22 (09) : 6140 - 6156