An Interoperable Access Control Framework for Diverse IoT Platforms Based on OAuth and Role

被引:23
|
作者
Oh, Se-Ra [1 ]
Kim, Young-Gab [1 ]
Cho, Sanghyun [2 ]
机构
[1] Sejong Univ, Dept Comp & Informat Secur, Seoul 05006, South Korea
[2] Naver Corp, Secur Team, Bundang 13561, South Korea
关键词
IoT platform; access control; interoperability; OAuth; 2; 0; role; security requirements;
D O I
10.3390/s19081884
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
Due to the rapid development of Internet of Things (IoT), IoT platforms that can provide common functions for things are becoming increasingly important. However, access control frameworks in diverse IoT platforms have been developed for individual security goals, designs, and technologies. In particular, current OAuth-based access control frameworks that are widely used in IoT research have not been providing interoperability among IoT platforms even though sharing resources and services is a critical issue for IoT platforms. Therefore, we analyze the main requirements for an IoT access control framework to properly design our framework and propose an interoperable access control framework based on OAuth 2.0 and Role. Our approach describes a new extended authorization grant flow to issue an Interoperable Access Token (IAT) that has a global access scope across IoT platforms using multiple pairs of clients' credentials. With the IAT and proposed framework, we can access client-specific domains in heterogeneous IoT platforms, then valuable resources (e.g., data and services) in the domains can be accessed by validating the roles, which will greatly simplify permission management. Furthermore, IAT supports a simple token management (e.g., token issuance, refreshing, and revocation) by managing only one token for diverse IoT platforms. In addition, we implement our interoperable access control framework on Mobius and FIWARE, which are promising open-source IoT platforms, and test an interoperability scenario to demonstrate our approach with the implementation. Furthermore, the proposed framework is compared with other IoT access control approaches based on the selected requirements in this paper.
引用
收藏
页数:17
相关论文
共 50 条
  • [1] Interoperable Access Control Framework for Services Demanding High Level Security among Heterogeneous IoT Platforms
    Koo, Jahoon
    Kang, Giluk
    Kim, Young-Gab
    38TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, SAC 2023, 2023, : 737 - 740
  • [2] Security Interoperability in Heterogeneous IoT Platforms: Threat Model of the Interoperable OAuth 2.0 Framework
    Oh, Se-Ra
    Koo, Jahoon
    Kim, Young-Gab
    37TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, 2022, : 22 - 31
  • [3] Advancing Interoperable IoT-Based Access Control Systems: A Unified Security Approach in Diverse Environments
    Penica, Mihai
    Bhattacharya, Mangolika
    O'Brien, William
    Mcgrath, Sean
    Hayes, Martin
    O'Connell, Eoin
    IEEE ACCESS, 2025, 13 : 27767 - 27782
  • [4] AFaaS: Authorization framework as a service for Internet of Things based on interoperable OAuth
    Oh, Se-Ra
    Kim, Young-Gab
    INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS, 2020, 16 (02):
  • [5] An OAuth-Based Authorization Framework for Access Control in Remote Collaboration Systems
    Jonnada, Srikanth
    Dantu, Ram
    Shrestha, Pradhumna
    Ranasinghe, Ishan
    Widick, Logan
    2018 NATIONAL CYBER SUMMIT: RESEARCH TRACK (NCS 2018), 2018, : 38 - 44
  • [6] RRAC: Role based reputed access control method for mitigating malicious impact in intelligent IoT platforms
    Amoon, Mohammed
    Altameem, Torki
    Altameem, Ayman
    COMPUTER COMMUNICATIONS, 2020, 151 (151) : 238 - 246
  • [7] IoT Framework for Effective and Fine-Grain Access Control
    Houhamdi, Zina
    Athamena, Belkacem
    2021 EIGHTH INTERNATIONAL CONFERENCE ON INTERNET OF THINGS, SYSTEMS, MANAGEMENT AND SECURITY (IOTSMS), 2021, : 23 - 28
  • [8] EnC-IoT: An Efficient Encryption and Access Control Framework based on IPFS for Decentralized IoT
    Song, Mansub
    Lee, Minji
    Kim, Sunggon
    Eom, Hyeonsang
    Son, Yongseok
    2024 IEEE 24TH INTERNATIONAL SYMPOSIUM ON CLUSTER, CLOUD AND INTERNET COMPUTING, CCGRID 2024, 2024, : 425 - 434
  • [9] Ontology-Based Access Control Framework for Smart Building IoT Devices
    Takizaki, Nao
    Kido, Yoshiyuki
    Masuda, Yoshiyuki
    Toshima, Yoshihisa
    Yamamoto, Matsuki
    Shimojo, Shinji
    2023 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS, ICCE, 2023,
  • [10] Scaling the Blockchain-based Access Control Framework for IoT via Sharding
    Li, Mengya
    Qin, Yang
    IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC 2021), 2021,