Authentication-enabled attribute-based access control for smart homes

被引:1
|
作者
Burakgazi Bilgen, Melike [1 ]
Abul, Osman [1 ]
Bicakci, Kemal [2 ]
机构
[1] TOBB Univ Econ & Technol, Dept Comp Engn, Ankara, Turkey
[2] Istanbul Tech Univ, Informat Inst, Istanbul, Turkey
基金
欧盟地平线“2020”;
关键词
Access control; Attribute-based access control; Internet of Things; False matching rate; Smart home security; INTERNET; THINGS;
D O I
10.1007/s10207-022-00639-x
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Smart home technologies constantly bring significant convenience to our daily lives. Unfortunately, increased security risks accompany this convenience. There can be severe consequences when unauthorized or malicious users gain access to smart home devices. Therefore, dependable and comprehensive access control models are needed to address the security concerns. To this end, the attribute-based access control (ABAC) model is usually considered the most satisfactory access control model for running IoT applications. However, the uncertainty left with the authentication stage should be carried to the authorization policy specification. In this work, we extend the ABAC model by carrying the assurance level of user authentication obtained from biometric authentication systems for authorization. The extended ABAC model quantifies how far the authentication matching score is from the predefined threshold. This quantification serves as a regular attribute like others to define authorization policies. The novelty in this quantification is that it consults false matching rate and hence can easily normalize across wide range of biometric authentication devices and algorithms. As a result, the resulting access control policies are concise and easy to comprehend. Moreover, our model is fine-grained in that different access policies can be specified for each smart device functionality. This work also shows, through case studies, that the extended ABAC model is feasible and implementable in XACML language.
引用
收藏
页码:479 / 495
页数:17
相关论文
共 50 条
  • [41] Attribute-Based Access Control for NoSQL Databases
    Gupta, Eeshan
    Sural, Shamik
    Vaidya, Jaideep
    Atluri, Vijayalakshmi
    PROCEEDINGS OF THE ELEVENTH ACM CONFERENCE ON DATA AND APPLICATION SECURITY AND PRIVACY (CODASPY '21), 2021, : 317 - 319
  • [42] ANALYSIS OF THE METHODS FOR ATTRIBUTE-BASED ACCESS CONTROL
    Kalimoldayev, M. N.
    Biyashev, R. G.
    Rog, O. A.
    PRIKLADNAYA DISKRETNAYA MATEMATIKA, 2019, (44): : 43 - 57
  • [43] Attribute Expressions, Policy Tables and Attribute-Based Access Control
    Crampton, Jason
    Williams, Conrad
    PROCEEDINGS OF THE 22ND ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES (SACMAT'17), 2017, : 79 - 90
  • [44] Accountable attribute-based authentication with fine-grained access control and its application to crowdsourcing
    Li, Peng
    Lai, Junzuo
    Wu, Yongdong
    FRONTIERS OF COMPUTER SCIENCE, 2023, 17 (01)
  • [45] Accountable multi-authority attribute-based data access control in smart grids
    Zhang, Leyou
    Yang, Guang
    Song, Chao
    Wu, Qing
    JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2023, 35 (07)
  • [46] Dynamic Groups and Attribute-Based Access Control for Next-Generation Smart Cars
    Gupta, Maanak
    Benson, James
    Patwa, Farhan
    Sandhu, Ravi
    PROCEEDINGS OF THE NINTH ACM CONFERENCE ON DATA AND APPLICATION SECURITY AND PRIVACY (CODASPY '19), 2019, : 61 - 72
  • [47] Accountable attribute-based authentication with fine-grained access control and its application to crowdsourcing
    Peng LI
    Junzuo LAI
    Yongdong WU
    Frontiers of Computer Science, 2023, 17 (01) : 203 - 216
  • [48] Attribute-Based Collaborative Access Control Scheme with Constant Ciphertext Length for Smart Grid
    Ge, Jiangyan
    Wen, Mi
    Wang, Liangliang
    Xie, Rong
    IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC 2022), 2022, : 540 - 546
  • [49] Accountable attribute-based authentication with fine-grained access control and its application to crowdsourcing
    Peng Li
    Junzuo Lai
    Yongdong Wu
    Frontiers of Computer Science, 2023, 17
  • [50] A user-friendly attribute-based data access control scheme for smart grids
    Mu, Tianshi
    Lai, Yuyang
    Feng, Guocong
    Lyu, Huahui
    Yang, Hang
    Deng, Jianfeng
    ALEXANDRIA ENGINEERING JOURNAL, 2023, 67 : 209 - 217