Authentication-enabled attribute-based access control for smart homes

被引:2
作者
Burakgazi Bilgen, Melike [1 ]
Abul, Osman [1 ]
Bicakci, Kemal [2 ]
机构
[1] TOBB Univ Econ & Technol, Dept Comp Engn, Ankara, Turkey
[2] Istanbul Tech Univ, Informat Inst, Istanbul, Turkey
基金
欧盟地平线“2020”;
关键词
Access control; Attribute-based access control; Internet of Things; False matching rate; Smart home security; INTERNET; THINGS;
D O I
10.1007/s10207-022-00639-x
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Smart home technologies constantly bring significant convenience to our daily lives. Unfortunately, increased security risks accompany this convenience. There can be severe consequences when unauthorized or malicious users gain access to smart home devices. Therefore, dependable and comprehensive access control models are needed to address the security concerns. To this end, the attribute-based access control (ABAC) model is usually considered the most satisfactory access control model for running IoT applications. However, the uncertainty left with the authentication stage should be carried to the authorization policy specification. In this work, we extend the ABAC model by carrying the assurance level of user authentication obtained from biometric authentication systems for authorization. The extended ABAC model quantifies how far the authentication matching score is from the predefined threshold. This quantification serves as a regular attribute like others to define authorization policies. The novelty in this quantification is that it consults false matching rate and hence can easily normalize across wide range of biometric authentication devices and algorithms. As a result, the resulting access control policies are concise and easy to comprehend. Moreover, our model is fine-grained in that different access policies can be specified for each smart device functionality. This work also shows, through case studies, that the extended ABAC model is feasible and implementable in XACML language.
引用
收藏
页码:479 / 495
页数:17
相关论文
共 36 条
  • [1] Toward an Access Control Model for IOTCollab
    Adda, Mehdi
    Abdelaziz, Jabril
    Mcheick, Hamid
    Saad, Rabeb
    [J]. 6TH INTERNATIONAL CONFERENCE ON AMBIENT SYSTEMS, NETWORKS AND TECHNOLOGIES (ANT-2015), THE 5TH INTERNATIONAL CONFERENCE ON SUSTAINABLE ENERGY INFORMATION TECHNOLOGY (SEIT-2015), 2015, 52 : 428 - 435
  • [2] MLS-ABAC: Efficient Multi-Level Security Attribute-Based Access Control scheme
    Aghili, Seyed Farhad
    Sedaghat, Mahdi
    Singelee, Dave
    Gupta, Maanak
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2022, 131 : 75 - 90
  • [3] The HABAC Model for Smart Home IoT and Comparison to EGRBAC
    Ameer, Safwa
    Sandhu, Ravi
    [J]. SAT-CPS'21: PROCEEDINGS OF THE 2021 ACM WORKSHOP ON SECURE AND TRUSTWORTHY CYBER-PHYSICAL SYSTEMS, 2021, : 39 - 48
  • [4] [Anonymous], 2022, FVC NGOING
  • [5] [Anonymous], 2013, OASIS STANDARD, V154
  • [6] [Anonymous], BIOMETRICS WILL HAVE
  • [7] Securing Home IoT Environments with Attribute-Based Access Control
    Bezawada, Bruhadeshwar
    Haefner, Kyle
    Ray, Indrakshi
    [J]. PROCEEDINGS OF THE THIRD ACM WORKSHOP ON ATTRIBUTE-BASED ACCESS CONTROL (ABAC'18), 2018, : 43 - 53
  • [8] Bilgen MB, 2020, 2020 INTERNATIONAL CONFERENCE ON INFORMATION SECURITY AND CRYPTOLOGY (ISCTURKEY 2020), P48, DOI [10.1109/ISCTURKEY51113.2020.9307964, 10.1109/iscturkey51113.2020.9307964]
  • [9] Borse Y., 2018, INT J COMPUT TRENDS, V59, P81, DOI [10.14445/22312803/ijctt-v59p113, DOI 10.14445/22312803/IJCTT-V59P113]
  • [10] Edge Centric Secure Data Sharing with Digital Twins in Smart Ecosystems
    Cathey, Glen
    Benson, James
    Gupta, Maanak
    Sandhu, Ravi
    [J]. 2021 THIRD IEEE INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS AND APPLICATIONS (TPS-ISA 2021), 2021, : 70 - 79