On Design of A Fine-Grained Access Control Architecture for Securing IoT-Enabled Smart Healthcare Systems

被引:12
|
作者
Pal, Shantanu [1 ]
Hitchens, Michael [1 ]
Varadharajan, Vijay [2 ]
Rabehaja, Tahiry [1 ]
机构
[1] Macquarie Univ, Dept Comp, Sydney, NSW 2109, Australia
[2] Univ Newcastle, Adv Cyber Secur Engn Res Ctr, Newcastle, NSW 2308, Australia
关键词
Internet of things; healthcare systems; access control; policy management; security; INTERNET; THINGS; PRIVACY; TRUST;
D O I
10.1145/3144457.3144485
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Internet of Things (IoT) is facilitating the development of novel and cost-effective applications that promise to deliver efficient and improved medical facilities to patients and health organisations. This includes the use of smart 'things' as medical sensors attached to patients to deliver real-time data. However, the security of patient data is an ever-present concern in the healthcare arena. In the wider deployment of IoT-enabled smart healthcare systems one particular issue is the need to protect smart 'things' from unauthorised access. Commonly used access control approaches e.g. Attribute Based Access Control (ABAC), Role Based Access Control (RBAC) and capability based access control do not, in isolation, provide a complete solution for securing access to IoT-enabled smart healthcare devices. They may, for example, require an overly-centralised solution or an unmanageably large policy base. To address these issues we propose a novel access control architecture which improves policy management by reducing the required number of authentication policies in a large-scale healthcare system while providing fine-grained access control. We devise a hybrid access control model employing attributes, roles and capabilities. We apply attributes for role-membership assignment and in permission evaluation. Membership of roles grants capabilities. The capabilities which are issued may be parameterised based on further attributes of the user and are then used to access specific services provided by IoT 'things'. We also provide a formal specification of the model and a description of its implementation and demonstrate its application through different use-case scenarios. Evaluation results of core functionality of our architecture are provided.
引用
收藏
页码:432 / 441
页数:10
相关论文
共 50 条
  • [1] Fine-grained multi-authority access control in IoT-enabled mHealth
    Qi Li
    Hongbo Zhu
    Jinbo Xiong
    Ruo Mo
    Zuobin Ying
    Huaqun Wang
    Annals of Telecommunications, 2019, 74 : 389 - 400
  • [2] Fine-grained multi-authority access control in IoT-enabled mHealth
    Li, Qi
    Zhu, Hongbo
    Xiong, Jinbo
    Mo, Ruo
    Ying, Zuobin
    Wang, Huaqun
    ANNALS OF TELECOMMUNICATIONS, 2019, 74 (7-8) : 389 - 400
  • [3] Fine-Grained Access Control for Smart Healthcare Systems in the Internet of Things
    Pal, Shantanu
    Hitchens, Michael
    Varadharajan, Vijay
    Rabehaja, Tahiry
    EAI Endorsed Transactions on Industrial Networks and Intelligent Systems, 2017, 4 (13):
  • [4] Securing Operating Systems Through Fine-Grained Kernel Access Limitation for IoT Systems
    Zhan, Dongyang
    Yu, Zhaofeng
    Yu, Xiangzhan
    Zhang, Hongli
    Ye, Lin
    Liu, Likun
    IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (06) : 5378 - 5392
  • [5] Privacy-Preserving Bilateral Fine-Grained Access Control for Cloud-Enabled Industrial IoT Healthcare
    Sun, Jianfei
    Yuan, Yu
    Tang, MingJian
    Cheng, Xiaochun
    Nie, Xuyun
    Aftab, Muhammad Umar
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2022, 18 (09) : 6483 - 6493
  • [6] On the Design of Blockchain-Based Access Control Protocol for IoT-Enabled Healthcare Applications
    Saha, Sourav
    Sutrala, Anil Kumar
    Das, Ashok Kumar
    Kumar, Neeraj
    Rodrigues, Joel J. P. C.
    ICC 2020 - 2020 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2020,
  • [7] A Reference Architecture for IoT-Enabled Smart Buildings
    Bashir M.R.
    Gill A.Q.
    Beydoun G.
    SN Computer Science, 3 (6)
  • [8] A Fine-Grained Access Control Model for Smart Grid
    Wang, Chen
    Ai, Hong
    Wu, Lie
    Yang, Yun
    APPLIED SCIENCE, MATERIALS SCIENCE AND INFORMATION TECHNOLOGIES IN INDUSTRY, 2014, 513-517 : 772 - 776
  • [9] Design and Evaluation of Large-Scale IoT-Enabled Healthcare Architecture
    Said, Omar
    Tolba, Amr
    APPLIED SCIENCES-BASEL, 2021, 11 (08):
  • [10] FINE-GRAINED TRUSTED CONTROL METHODS FOR IOT BOUNDARY ACCESS
    Wang, Jie
    Liu, Chang
    Zhu, Guowei
    Liu, Xiaojun
    Xiao, Bibo
    SCALABLE COMPUTING-PRACTICE AND EXPERIENCE, 2025, 26 (01): : 180 - 190