Towards Fine-Grained Access Control in Enterprise-Scale Internet-of-Things

被引:11
|
作者
Zhou, Qian [1 ]
Elbadry, Mohammed [1 ]
Ye, Fan [1 ]
Yang, Yuanyuan [1 ]
机构
[1] SUNY Stony Brook, Elect & Comp Engn, Stony Brook, NY 11794 USA
基金
美国国家科学基金会;
关键词
Access control; Permission; Mobile computing; Computer architecture; Public key; Robustness; Internet of Things; security; access control;
D O I
10.1109/TMC.2020.2984700
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Scalable, fine-grained access control for Internet-of-Things is needed in enterprise environments, where tens of thousands of users need to access smart objects which have a similar or larger order of magnitude. Existing solutions offer all-or-nothing access, or require all access to go through a cloud backend, greatly impeding access granularity, robustness and scale. In this paper, we propose Heracles, an IoT access control system which achieves robust, fine-grained access control and responsive execution at enterprise scale. Heracles adopts a capability-based approach using secure, unforgeable tokens that describe the authorizations of users, to either individuals or collections of objects in single or bulk operations. It has a 3-tier architecture to provide centralized policy and distributed execution desired in enterprise environments. Extensive analysis and performance evaluation on a testbed prove that Heracles achieves fine-grained access control and responsive execution at enterprise scale. Compared with systems using access control list, Heracles eliminates or reduces by 10x-100x the updating overhead under frequent changes of subject memberships and policies. Besides, Heracles achieves responsive execution: it takes 0.57 second to access 18 objects which are scattered 1-9 hops away, and execution on a 1-hop or 2-hop object needs only 0.07 or 0.13 second respectively.
引用
收藏
页码:2701 / 2714
页数:14
相关论文
共 50 条
  • [1] Heracles: Scalable, Fine-Grained Access Control for Internet-of-Things in Enterprise Environments
    Zhou, Qian
    Elbadry, Mohammed
    Ye, Fan
    Yang, Yuanyuan
    IEEE CONFERENCE ON COMPUTER COMMUNICATIONS (IEEE INFOCOM 2018), 2018, : 1781 - 1789
  • [2] Lightweight and Expressive Fine-Grained Access Control for Healthcare Internet-of-Things
    Xu, Shengmin
    Li, Yingjiu
    Deng, Robert H.
    Zhang, Yinghui
    Luo, Xiangyang
    Liu, Ximeng
    IEEE TRANSACTIONS ON CLOUD COMPUTING, 2022, 10 (01) : 474 - 490
  • [3] Adaptive Fine-grained Access Control Method in Social Internet of Things
    Zhang, Hongbin
    Ma, Pengcheng
    Liu, Bin
    International Journal of Network Security, 2021, 23 (01) : 42 - 48
  • [4] Fine-Grained Access Control for Smart Healthcare Systems in the Internet of Things
    Pal, Shantanu
    Hitchens, Michael
    Varadharajan, Vijay
    Rabehaja, Tahiry
    EAI Endorsed Transactions on Industrial Networks and Intelligent Systems, 2017, 4 (13):
  • [5] Fine-grained Access Control Framework for Igor, a Unified Access Solution to The Internet of Things
    Shieng, Pauline Sia Wen
    Jansen, Jack
    Pemberton, Steven
    15TH INTERNATIONAL CONFERENCE ON MOBILE SYSTEMS AND PERVASIVE COMPUTING (MOBISPC 2018) / THE 13TH INTERNATIONAL CONFERENCE ON FUTURE NETWORKS AND COMMUNICATIONS (FNC-2018) / AFFILIATED WORKSHOPS, 2018, 134 : 385 - 392
  • [6] Fine-grained Device and Data Access Control of Community Medical Internet of Things
    Huang, Cheng
    Zhang, Ziyang
    Huang, Jing
    Chen, Fulong
    2020 16TH INTERNATIONAL CONFERENCE ON MOBILITY, SENSING AND NETWORKING (MSN 2020), 2020, : 236 - 243
  • [7] Towards a fine-grained access control for Cloud
    Msahli, Mounira
    Chen, Xiuzhen
    Serhrouchni, Ahmed
    2014 IEEE 11TH INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING (ICEBE), 2014, : 286 - 291
  • [8] SFAC:A Smart Contract-Based Fine-Grained Access Control for Internet of Things
    Chai, Baobao
    Yan, Biwei
    Dong, Anming
    Yu, Jiguo
    2020 INTERNATIONAL CONFERENCE ON IDENTIFICATION, INFORMATION AND KNOWLEDGE IN THE INTERNET OF THINGS (IIKI2020), 2021, 187 : 335 - 340
  • [9] Fine-grained Access Control Mechanism of Industrial Internet of Things Based on DAG Blockchain
    Tang, Fei
    Ye, Zhangtao
    Dong, Kung
    Huang, Dong
    International Journal of Network Security, 2022, 24 (05): : 872 - 886
  • [10] A Fine-Grained Cross-Domain Access Control Mechanism for Social Internet of Things
    Wu, Jun
    Dong, Mianxiong
    Ota, Kaoru
    Li, Jianhua
    Pei, Bei
    2014 IEEE 11TH INTL CONF ON UBIQUITOUS INTELLIGENCE AND COMPUTING AND 2014 IEEE 11TH INTL CONF ON AUTONOMIC AND TRUSTED COMPUTING AND 2014 IEEE 14TH INTL CONF ON SCALABLE COMPUTING AND COMMUNICATIONS AND ITS ASSOCIATED WORKSHOPS, 2014, : 666 - 671