AFaaS: Authorization framework as a service for Internet of Things based on interoperable OAuth

被引:8
作者
Oh, Se-Ra [1 ]
Kim, Young-Gab [1 ]
机构
[1] Sejong Univ, Dept Comp & Informat Secur, Seoul 05006, South Korea
来源
INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS | 2020年 / 16卷 / 02期
关键词
OAuth; authorization; interoperability; interoperable OAuth; Internet of Things;
D O I
10.1177/1550147720906388
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Internet of Things has become a fundamental paradigm in our everyday lives. However, standards and technologies are often designed without considering interoperability, which is a critical issue for Internet of Things. Internet of Things environment requires interoperability to share resources (e.g. data and services) between heterogeneous Internet of Things domains. The open authorization (OAuth) 2.0 framework that is actively used in Internet of Things (as well as in conventional web environments) also did not focus on interoperability. In other words, the systems that implement the same OAuth 2.0 standard cannot interoperate without additional support. For this reason, we propose an authorization framework as a service. Authorization framework as a service provides an additional authorization layer to support standard authorization capabilities as an interoperable secure wrapper between different domains. Besides, authorization framework as a service supports the four extended authorization grant flow types to issue an interoperable access token, which has a global access scope across multiple heterogeneous domains. With the authorization framework as a service, interoperability can be supported for heterogeneous domains, and token management can also be simple because an interoperable access token can represent several existing access tokens that have local access scopes. Furthermore, this article presents a feasible interoperability scenario, implementation, and security considerations for authorization framework as a service, focusing on Internet of Things platforms.
引用
收藏
页数:15
相关论文
共 26 条
[1]   An Identity Framework for Providing Access to MARE OAuth 2.0-Based Services According to the eIDAS European Regulation [J].
Alonso, Alvaro ;
Pozo, Alejandro ;
Choque, Johnny ;
Bueno, Gloria ;
Salvachua, Joaquin ;
Diez, Luis ;
Marin, Jorge ;
Chas Alonso, Pedro Luis .
IEEE ACCESS, 2019, 7 :88435-88449
[2]  
[Anonymous], 6819 IETF RFC
[3]  
[Anonymous], 2017, P GLOBAL INTERNET TH
[4]  
[Anonymous], 6750 IETF RFC
[5]  
[Anonymous], 7009 IETF RFC
[6]  
[Anonymous], 6749 IETF RFC
[7]  
[Anonymous], 2017, 2017 GLOBAL INTERNET, DOI DOI 10.1109/GIOTS.2017.8016233
[8]  
[Anonymous], 7662 IETF RFC
[9]   Enabling IoT Ecosystems through Platform Interoperability [J].
Broring, Arne ;
Schmid, Stefan ;
Schindhelm, Corina-Kim ;
Khelil, Abdelmajid ;
Kabisch, Sebastian ;
Kramer, Denis ;
Danh Le Phuoc ;
Mitic, Jelena ;
Anicic, Darko ;
Teniente, Ernest .
IEEE SOFTWARE, 2017, 34 (01) :54-61
[10]   IoT-OAS: An OAuth-Based Authorization Service Architecture for Secure Services in IoT Scenarios [J].
Cirani, Simone ;
Picone, Marco ;
Gonizzi, Pietro ;
Veltri, Luca ;
Ferrari, Gianluigi .
IEEE SENSORS JOURNAL, 2015, 15 (02) :1224-1234