Towards Fine-Grained Access Control in Enterprise-Scale Internet-of-Things

被引:11
|
作者
Zhou, Qian [1 ]
Elbadry, Mohammed [1 ]
Ye, Fan [1 ]
Yang, Yuanyuan [1 ]
机构
[1] SUNY Stony Brook, Elect & Comp Engn, Stony Brook, NY 11794 USA
基金
美国国家科学基金会;
关键词
Access control; Permission; Mobile computing; Computer architecture; Public key; Robustness; Internet of Things; security; access control;
D O I
10.1109/TMC.2020.2984700
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Scalable, fine-grained access control for Internet-of-Things is needed in enterprise environments, where tens of thousands of users need to access smart objects which have a similar or larger order of magnitude. Existing solutions offer all-or-nothing access, or require all access to go through a cloud backend, greatly impeding access granularity, robustness and scale. In this paper, we propose Heracles, an IoT access control system which achieves robust, fine-grained access control and responsive execution at enterprise scale. Heracles adopts a capability-based approach using secure, unforgeable tokens that describe the authorizations of users, to either individuals or collections of objects in single or bulk operations. It has a 3-tier architecture to provide centralized policy and distributed execution desired in enterprise environments. Extensive analysis and performance evaluation on a testbed prove that Heracles achieves fine-grained access control and responsive execution at enterprise scale. Compared with systems using access control list, Heracles eliminates or reduces by 10x-100x the updating overhead under frequent changes of subject memberships and policies. Besides, Heracles achieves responsive execution: it takes 0.57 second to access 18 objects which are scattered 1-9 hops away, and execution on a 1-hop or 2-hop object needs only 0.07 or 0.13 second respectively.
引用
收藏
页码:2701 / 2714
页数:14
相关论文
共 50 条
  • [31] A Fine-Grained Image Access Control Model
    Al Bouna, Bechara
    Chbeir, Richard
    Gabillon, Alban
    Capolsini, Patrick
    8TH INTERNATIONAL CONFERENCE ON SIGNAL IMAGE TECHNOLOGY & INTERNET BASED SYSTEMS (SITIS 2012), 2012, : 603 - 612
  • [32] Fine-grained access control of PDM and CAPP
    Feng, SH
    Jiang, ZL
    ADVANCES IN MATERIALS MANUFACTURING SCIENCE AND TECHNOLOGY, 2004, 471-472 : 573 - 576
  • [33] Fine-grained access control for cloud computing
    Ye, Xinfeng
    Khoussainov, Bakh
    INTERNATIONAL JOURNAL OF GRID AND UTILITY COMPUTING, 2013, 4 (2-3) : 160 - 168
  • [34] Towards a Flexible Fine-Grained Access Control System for Modern Cloud Applications
    Shiftehfar, Reza
    Mechitov, Kirill
    Agha, Gul
    2014 IEEE 7TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING (CLOUD), 2014, : 966 - 967
  • [35] Towards leakage-resilient fine-grained access control in fog computing
    Yu, Zuoxia
    Au, Man Ho
    Xu, Qiuliang
    Yang, Rupeng
    Han, Jinguang
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2018, 78 : 763 - 777
  • [36] Access policy sheet for access control in fine-grained XML
    Wu, J
    Mu, Y
    Seberry, J
    Ruan, C
    EMBEDDED AND UBIQUITOUS COMPUTING - EUC 2005 WORKSHOPS, PROCEEDINGS, 2005, 3823 : 1273 - 1282
  • [37] Robust fine-grained visual recognition with images based on internet of things
    Cai, Zhenhuang
    Yan, Shuai
    Huang, Dan
    COMPUTATIONAL INTELLIGENCE, 2024, 40 (02)
  • [38] Fine-Grained Support of Security Services for Resource Constrained Internet of Things
    Ban, Hyo Jin
    Choi, Jaeduck
    Kang, Namhi
    INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS, 2016,
  • [39] Towards Fault-Tolerant Fine-Grained Data Access Control for Smart Grid
    Jun Wu
    Mianxiong Dong
    Kaoru Ota
    Zhenyu Zhou
    Bin Duan
    Wireless Personal Communications, 2014, 75 : 1787 - 1808
  • [40] Towards Efficient, Secure, and Fine-Grained Access Control System in MSNs with Flexible Revocations
    Sun, Shi-Feng
    Lyu, Chen
    Gu, Dawu
    Zhang, Yuanyuan
    Ren, Yanli
    INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS, 2015,