Evaluation of an IoT Application-Scoped Access Control Model over a Publish/Subscribe Architecture Based on FIWARE

被引:7
|
作者
Pozo, Alejandro [1 ]
Alonso, Alvaro [1 ]
Salvachua, Joaquin [1 ]
机构
[1] Univ Politecn Madrid, Dept Ingn Sistemas Telemat, Escuela Tecn Super Ingn Telecomunicac, Madrid 28040, Spain
关键词
IoT; security; identity management; access control; OAuth; 2; 0; CoAP; publish & subscribe; IAACaaS; INTERNET;
D O I
10.3390/s20154341
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
The Internet of Things (IoT) brings plenty of opportunities to enhance society's activities, from improving a factory's production chain to facilitating people's household tasks. However, it has also brought new security breaches, compromising privacy and authenticity. IoT devices are vulnerable to being accessed from the Internet; they lack sufficient resources to face cyber-attack threats. Keeping a balance between access control and the devices' resource consumption has become one of the highest priorities of IoT research. In this paper, we evaluate an access control architecture based on the IAACaaS (IoT application-Scoped Access Control as a Service) model with the aim of protecting IoT devices that communicate using the Publish/Subscribe pattern. IAACaaS is based on the OAuth 2.0 authorization framework, which externalizes the identity and access control infrastructure of applications. In our evaluation, we implement the model using FIWARE Generic Enablers and deploy them for a smart buildings use case with a wireless communication. Then, we compare the performance of two different approaches in the data-sharing between sensors and the Publish/Subscribe broker, using Constrained Application Protocol (CoAP) and Hypertext Transfer Protocol (HTTP) protocols. We conclude that the integration of Publish/Subscribe IoT deployments with IAACaaS adds an extra layer of security and access control without compromising the system's performance.
引用
收藏
页码:1 / 19
页数:20
相关论文
共 48 条
  • [1] A topic-centric access control model for the publish/subscribe paradigm
    Xie, Rongna
    Shi, Guozhen
    Guo, Yunchuan
    Li, Fenghua
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2020, 32 (09):
  • [2] An IOT-Oriented Privacy-Preserving Publish/Subscribe Model Over Blockchains
    Lv, Pin
    Wang, Licheng
    Zhu, Huijun
    Deng, Wenbo
    Gu, Lize
    IEEE ACCESS, 2019, 7 : 41309 - 41314
  • [3] A Topic-Based Publish/Subscribe System in a Fog Computing Model for the IoT
    Saito, Takumi
    Nakamura, Shigenari
    Enokido, Tomoya
    Takizawa, Makoto
    COMPLEX, INTELLIGENT AND SOFTWARE INTENSIVE SYSTEMS, 2021, 1194 : 12 - 21
  • [4] A Distributed Fog-based Access Control Architecture for IoT
    Alnefaie, Seham
    Cherif, Asma
    Alshehri, Suhair
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2021, 15 (12): : 4545 - 4566
  • [5] Cross-layer access control in publish/subscribe middleware over software-defined networks
    Zhang, Yang
    Zhou, Huiyu
    Chen, Jun-liang
    COMPUTER COMMUNICATIONS, 2019, 134 : 1 - 13
  • [6] Lightweight and secure authentication scheme for IoT network based on publish-subscribe fog computing model
    Amanlou, Sanaz
    Hasan, Mohammad Kamrul
    Abu Bakar, Khairul Azmi
    COMPUTER NETWORKS, 2021, 199
  • [7] MPaS: A Micro-services based Publish/Subscribe Middleware System Model for IoT
    Ahmed, Noor
    2022 5TH CONFERENCE ON CLOUD AND INTERNET OF THINGS, CIOT, 2022, : 220 - 225
  • [8] Realizing IoT service's policy privacy over publish/subscribe-based middleware
    Duan, Li
    Zhang, Yang
    Chen, Shiping
    Wang, Shiyao
    Cheng, Bo
    Chen, Junliang
    SPRINGERPLUS, 2016, 5
  • [9] Safety in Discretionary Access Control for Logic-based Publish-Subscribe Systems
    Minami, Kazuhiro
    Borisov, Nikita
    Gunter, Carl A.
    SACMAT'09: PROCEEDINGS OF THE 14TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2009, : 3 - 12
  • [10] Distributed Access Control on IoT Ledger-based Architecture
    Lunardi, Roben Castagna
    Michelin, Regio Antonio
    Neu, Charles Varlei
    Zorzo, Avelino Francisco
    NOMS 2018 - 2018 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, 2018,