IoT Access Control Issues: A Capability Based Approach
- 1 July 2012
- conference paper
- Published by Institute of Electrical and Electronics Engineers (IEEE)
- p. 787-792
- https://doi.org/10.1109/imis.2012.38
Abstract
Resource and information protection plays a relevant role in distributed systems. Most of the currently proposed authorization frameworks do not provide scalable, manageable, effective, and efficient mechanisms to support distributed systems with many interacting services. The advent of IoT will further increase the need for scalable and manageable solutions able to face the potentially unbound number of sensors, actuators and related resources, services and subjects. This is even more relevant if we take into account that IoT environments can envisage not only a greater number of resources to manage, but also a substantial increase of the interaction dynamics. This paper presents a capability based access control system that enterprises, or even individuals, can use to manage their own access control processes to services and information. The proposed mechanism supports rights delegation and a more sophisticated access control customization. The proposed approach is being developed within the European FP7 IoT@Work project to manage access control for some of the project's services deployed in the shop floor.Keywords
This publication has 8 references indexed in Scilit:
- Architecting the Internet of ThingsPublished by Springer Nature ,2011
- Adding Attributes to Role-Based Access ControlComputer, 2010
- Solving the Transitive Access Problem for the Services Oriented ArchitecturePublished by Institute of Electrical and Electronics Engineers (IEEE) ,2010
- Taming subsystemsPublished by Association for Computing Machinery (ACM) ,2009
- Access control for the services oriented architecturePublished by Association for Computing Machinery (ACM) ,2007
- Authorization-Based Access Control for the Services Oriented ArchitecturePublished by Institute of Electrical and Electronics Engineers (IEEE) ,2006
- Attributed based access control (ABAC) for Web servicesPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2005
- The Confused DeputyACM SIGOPS Operating Systems Review, 1988