Authentication-enabled attribute-based access control for smart homes

被引:1
|
作者
Burakgazi Bilgen, Melike [1 ]
Abul, Osman [1 ]
Bicakci, Kemal [2 ]
机构
[1] TOBB Univ Econ & Technol, Dept Comp Engn, Ankara, Turkey
[2] Istanbul Tech Univ, Informat Inst, Istanbul, Turkey
基金
欧盟地平线“2020”;
关键词
Access control; Attribute-based access control; Internet of Things; False matching rate; Smart home security; INTERNET; THINGS;
D O I
10.1007/s10207-022-00639-x
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Smart home technologies constantly bring significant convenience to our daily lives. Unfortunately, increased security risks accompany this convenience. There can be severe consequences when unauthorized or malicious users gain access to smart home devices. Therefore, dependable and comprehensive access control models are needed to address the security concerns. To this end, the attribute-based access control (ABAC) model is usually considered the most satisfactory access control model for running IoT applications. However, the uncertainty left with the authentication stage should be carried to the authorization policy specification. In this work, we extend the ABAC model by carrying the assurance level of user authentication obtained from biometric authentication systems for authorization. The extended ABAC model quantifies how far the authentication matching score is from the predefined threshold. This quantification serves as a regular attribute like others to define authorization policies. The novelty in this quantification is that it consults false matching rate and hence can easily normalize across wide range of biometric authentication devices and algorithms. As a result, the resulting access control policies are concise and easy to comprehend. Moreover, our model is fine-grained in that different access policies can be specified for each smart device functionality. This work also shows, through case studies, that the extended ABAC model is feasible and implementable in XACML language.
引用
收藏
页码:479 / 495
页数:17
相关论文
共 50 条
  • [1] Authentication-enabled attribute-based access control for smart homes
    Melike Burakgazi Bilgen
    Osman Abul
    Kemal Bicakci
    International Journal of Information Security, 2023, 22 : 479 - 495
  • [2] An Attribute-Based Access Control for Cloud Enabled Industrial Smart Vehicles
    Gupta, Maanak
    Awaysheh, Feras M.
    Benson, James
    Alazab, Mamoun
    Patwa, Farhan
    Sandhu, Ravi
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2021, 17 (06) : 4288 - 4297
  • [3] Firewall for Attribute-Based Access Control in Smart Grids
    Ruland, Christoph
    Sassmannshausen, Jochen
    2018 THE 6TH IEEE INTERNATIONAL CONFERENCE ON SMART ENERGY GRID ENGINEERING (SEGE 2018), 2018, : 336 - 341
  • [4] Attribute-Based Access Control using Combined Authentication Technologies
    Park, Hyun-A
    Lee, Dong Hoon
    Zhan, Justin
    2008 IEEE INTERNATIONAL CONFERENCE ON GRANULAR COMPUTING, VOLS 1 AND 2, 2008, : 518 - +
  • [5] Blockchain-Enabled decentralized Attribute-Based access control with policy hiding for smart healthcare
    Zhang, Yinghui
    Wei, Xuanni
    Cao, Jin
    Ning, Jianting
    Ying, Zuobin
    Zheng, Dong
    JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2022, 34 (10) : 8350 - 8361
  • [6] BEAAS: Blockchain Enabled Attribute-Based Access Control as a Service
    Kumar, Ritik
    Palanisamy, Balaji
    Sural, Shamik
    2021 IEEE INTERNATIONAL CONFERENCE ON BLOCKCHAIN AND CRYPTOCURRENCY (ICBC), 2021,
  • [7] An Efficient and Secure Revocation-Enabled Attribute-Based Access Control for eHealth in Smart Society
    Khan, Shahzad
    Iqbal, Waseem
    Waheed, Abdul
    Mehmood, Gulzar
    Khan, Shawal
    Zareei, Mahdi
    Biswal, Rajesh Roshan
    SENSORS, 2022, 22 (01)
  • [8] Efficient Blockchain Enabled Attribute-based Access Control as a Service
    Kumar, Ritik
    Palanisamy, Balaji
    Sural, Shamik
    2022 IEEE 4TH INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS, AND APPLICATIONS, TPS-ISA, 2022, : 87 - 96
  • [9] Attribute-based access control and authentication mechanism using smart cards for cloud-based IoT applications
    Gupta, B. B.
    Quamara, Megha
    INTERNATIONAL JOURNAL OF EMBEDDED SYSTEMS, 2020, 13 (01) : 40 - 49
  • [10] AACS: Attribute-Based Access Control Mechanism for Smart Locks
    Xin, Zhenghao
    Liu, Liang
    Hancke, Gerhard
    SYMMETRY-BASEL, 2020, 12 (06):