An Interoperable Access Control Framework for Diverse IoT Platforms Based on OAuth and Role

被引:23
作者
Oh, Se-Ra [1 ]
Kim, Young-Gab [1 ]
Cho, Sanghyun [2 ]
机构
[1] Sejong Univ, Dept Comp & Informat Secur, Seoul 05006, South Korea
[2] Naver Corp, Secur Team, Bundang 13561, South Korea
关键词
IoT platform; access control; interoperability; OAuth; 2; 0; role; security requirements;
D O I
10.3390/s19081884
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
Due to the rapid development of Internet of Things (IoT), IoT platforms that can provide common functions for things are becoming increasingly important. However, access control frameworks in diverse IoT platforms have been developed for individual security goals, designs, and technologies. In particular, current OAuth-based access control frameworks that are widely used in IoT research have not been providing interoperability among IoT platforms even though sharing resources and services is a critical issue for IoT platforms. Therefore, we analyze the main requirements for an IoT access control framework to properly design our framework and propose an interoperable access control framework based on OAuth 2.0 and Role. Our approach describes a new extended authorization grant flow to issue an Interoperable Access Token (IAT) that has a global access scope across IoT platforms using multiple pairs of clients' credentials. With the IAT and proposed framework, we can access client-specific domains in heterogeneous IoT platforms, then valuable resources (e.g., data and services) in the domains can be accessed by validating the roles, which will greatly simplify permission management. Furthermore, IAT supports a simple token management (e.g., token issuance, refreshing, and revocation) by managing only one token for diverse IoT platforms. In addition, we implement our interoperable access control framework on Mobius and FIWARE, which are promising open-source IoT platforms, and test an interoperability scenario to demonstrate our approach with the implementation. Furthermore, the proposed framework is compared with other IoT access control approaches based on the selected requirements in this paper.
引用
收藏
页数:17
相关论文
共 50 条
  • [11] Ontology-Based Access Control Framework for Smart Building IoT Devices
    Takizaki, Nao
    Kido, Yoshiyuki
    Masuda, Yoshiyuki
    Toshima, Yoshihisa
    Yamamoto, Matsuki
    Shimojo, Shinji
    2023 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS, ICCE, 2023,
  • [12] DACIoT: Dynamic Access Control Framework for IoT Deployments
    Alkhresheh, Ashraf
    Elgazzar, Khalid
    Hassanein, Hossam S.
    IEEE INTERNET OF THINGS JOURNAL, 2020, 7 (12): : 11401 - 11419
  • [13] A Blockchain based access control for IoT
    Riabi, Imen
    Dhif, Yosr
    Ben Ayed, Hella Kaffel
    Zaatouri, Khaled
    2019 15TH INTERNATIONAL WIRELESS COMMUNICATIONS & MOBILE COMPUTING CONFERENCE (IWCMC), 2019, : 2086 - 2091
  • [14] A Framework for Risk-Aware Role Based Access Control
    Bijon, Khalid Zaman
    Krishnan, Ram
    Sandhu, Ravi
    2013 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2013, : 462 - 469
  • [15] An Event-based Access Control for IoT
    Zulkipli, Nurul Huda Nik
    Wills, Gary B.
    PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON INTERNET OF THINGS, DATA AND CLOUD COMPUTING (ICC 2017), 2017,
  • [16] A Novel Role-Based-Access-Control(RBAC) Framework and Application
    Zhou, Yanjie
    Wen, Min
    PROCEEDINGS OF THE 2015 INTERNATIONAL CONFERENCE ON EDUCATION, MANAGEMENT AND COMPUTING TECHNOLOGY, 2015, 30 : 207 - 210
  • [17] A blockchain based lightweight and secure access control framework for IoT-enabled supply chain
    Raj, Rashmi
    Ghosh, Mohona
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2024, 17 (03) : 1610 - 1630
  • [18] Embedded role based access control unit for the web document access control
    Shim, WB
    Park, S
    6TH WORLD MULTICONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL V, PROCEEDINGS: COMPUTER SCI I, 2002, : 247 - 252
  • [19] Big Data Source Location Privacy and Access Control in the Framework of IoT
    Zebboudj, Sofia
    Brahami, Rabah
    Mouzaia, Chahinas
    Abbas, Celia
    Boussaid, Nabil
    Omar, Mawloud
    2017 5TH INTERNATIONAL CONFERENCE ON ELECTRICAL ENGINEERING - BOUMERDES (ICEE-B), 2017,
  • [20] Asset-Oriented Access Control: Towards a New IoT Framework
    Cattermole, Thomas
    Docherty, Simon
    Pym, David
    Sasse, Angela
    PROCEEDINGS OF THE 9TH INTERNATIONAL CONFERENCE ON THE INTERNET OF THINGS ( IOT 2019), 2019,