On Design of A Fine-Grained Access Control Architecture for Securing IoT-Enabled Smart Healthcare Systems

被引:12
|
作者
Pal, Shantanu [1 ]
Hitchens, Michael [1 ]
Varadharajan, Vijay [2 ]
Rabehaja, Tahiry [1 ]
机构
[1] Macquarie Univ, Dept Comp, Sydney, NSW 2109, Australia
[2] Univ Newcastle, Adv Cyber Secur Engn Res Ctr, Newcastle, NSW 2308, Australia
关键词
Internet of things; healthcare systems; access control; policy management; security; INTERNET; THINGS; PRIVACY; TRUST;
D O I
10.1145/3144457.3144485
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Internet of Things (IoT) is facilitating the development of novel and cost-effective applications that promise to deliver efficient and improved medical facilities to patients and health organisations. This includes the use of smart 'things' as medical sensors attached to patients to deliver real-time data. However, the security of patient data is an ever-present concern in the healthcare arena. In the wider deployment of IoT-enabled smart healthcare systems one particular issue is the need to protect smart 'things' from unauthorised access. Commonly used access control approaches e.g. Attribute Based Access Control (ABAC), Role Based Access Control (RBAC) and capability based access control do not, in isolation, provide a complete solution for securing access to IoT-enabled smart healthcare devices. They may, for example, require an overly-centralised solution or an unmanageably large policy base. To address these issues we propose a novel access control architecture which improves policy management by reducing the required number of authentication policies in a large-scale healthcare system while providing fine-grained access control. We devise a hybrid access control model employing attributes, roles and capabilities. We apply attributes for role-membership assignment and in permission evaluation. Membership of roles grants capabilities. The capabilities which are issued may be parameterised based on further attributes of the user and are then used to access specific services provided by IoT 'things'. We also provide a formal specification of the model and a description of its implementation and demonstrate its application through different use-case scenarios. Evaluation results of core functionality of our architecture are provided.
引用
收藏
页码:432 / 441
页数:10
相关论文
共 50 条
  • [21] Lightweight and Privacy-Aware Fine-Grained Access Control for IoT-Oriented Smart Health
    Sun, Jianfei
    Xiong, Hu
    Liu, Ximeng
    Zhang, Yinghui
    Nie, Xuyun
    Deng, Robert H.
    IEEE INTERNET OF THINGS JOURNAL, 2020, 7 (07) : 6566 - 6575
  • [22] A SDN-based IoT Fine-grained Access Control Method
    Wei, Min
    Liang, Erxiong
    Nie, Zichuang
    2020 34TH INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING (ICOIN 2020), 2020, : 637 - 642
  • [23] Secure Cyber Engineering for IoT-Enabled Smart Healthcare System
    Pandey A.K.
    Das A.K.
    Kumar R.
    Rodrigues J.J.P.C.
    IEEE Internet of Things Magazine, 2024, 7 (02): : 70 - 77
  • [24] Smart teledentistry healthcare architecture for medical big data analysis using IoT-enabled environment
    Babar, Muhammad
    Tariq, Muhammad Usman
    Alshehri, Mohammad Dahman
    Ullah, Fasee
    Uddin, M. Irfan
    Sustainable Computing: Informatics and Systems, 2022, 35
  • [25] Smart teledentistry healthcare architecture for medical big data analysis using IoT-enabled environment
    Babar, Muhammad
    Tariq, Muhammad Usman
    Alshehri, Mohammad Dahman
    Ullah, Fasee
    Uddin, M. Irfan
    SUSTAINABLE COMPUTING-INFORMATICS & SYSTEMS, 2022, 35
  • [26] Fine-Grained Access Control to Medical Records in Digital Healthcare Enterprises
    Khan, M. Fahim Ferdous
    Sakamura, Ken
    2015 INTERNATIONAL SYMPOSIUM ON NETWORKS, COMPUTERS AND COMMUNICATIONS (ISNCC 2015), 2015,
  • [27] A Data Aggregation Scheme with Fine-grained Access Control for the Smart Grid
    Wen, Mi
    Zhang, Xu
    Li, Hongwei
    Li, Jinguo
    2017 IEEE 86TH VEHICULAR TECHNOLOGY CONFERENCE (VTC-FALL), 2017,
  • [28] Fine-grained Context-aware Access Control for Smart Devices
    Baresi, Luciano
    Sadeghi, Mersedeh
    2018 8TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND INFORMATION TECHNOLOGY (CSIT), 2018, : 55 - 61
  • [29] A Reference Architecture for IoT-Enabled Dynamic Planning in Smart Logistics
    Koot, Martijn
    Iacob, Maria-Eugenia
    Mes, Martijn R. K.
    ADVANCED INFORMATION SYSTEMS ENGINEERING (CAISE 2021), 2021, 12751 : 551 - 565
  • [30] IoT-enabled Smart Child Safety Digital System Architecture
    Madhuri, Madhuri
    Gill, Asif Qumer
    Khan, Habib Ullah
    2020 IEEE 14TH INTERNATIONAL CONFERENCE ON SEMANTIC COMPUTING (ICSC 2020), 2020, : 166 - 169