On Design of A Fine-Grained Access Control Architecture for Securing IoT-Enabled Smart Healthcare Systems

被引:12
|
作者
Pal, Shantanu [1 ]
Hitchens, Michael [1 ]
Varadharajan, Vijay [2 ]
Rabehaja, Tahiry [1 ]
机构
[1] Macquarie Univ, Dept Comp, Sydney, NSW 2109, Australia
[2] Univ Newcastle, Adv Cyber Secur Engn Res Ctr, Newcastle, NSW 2308, Australia
关键词
Internet of things; healthcare systems; access control; policy management; security; INTERNET; THINGS; PRIVACY; TRUST;
D O I
10.1145/3144457.3144485
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Internet of Things (IoT) is facilitating the development of novel and cost-effective applications that promise to deliver efficient and improved medical facilities to patients and health organisations. This includes the use of smart 'things' as medical sensors attached to patients to deliver real-time data. However, the security of patient data is an ever-present concern in the healthcare arena. In the wider deployment of IoT-enabled smart healthcare systems one particular issue is the need to protect smart 'things' from unauthorised access. Commonly used access control approaches e.g. Attribute Based Access Control (ABAC), Role Based Access Control (RBAC) and capability based access control do not, in isolation, provide a complete solution for securing access to IoT-enabled smart healthcare devices. They may, for example, require an overly-centralised solution or an unmanageably large policy base. To address these issues we propose a novel access control architecture which improves policy management by reducing the required number of authentication policies in a large-scale healthcare system while providing fine-grained access control. We devise a hybrid access control model employing attributes, roles and capabilities. We apply attributes for role-membership assignment and in permission evaluation. Membership of roles grants capabilities. The capabilities which are issued may be parameterised based on further attributes of the user and are then used to access specific services provided by IoT 'things'. We also provide a formal specification of the model and a description of its implementation and demonstrate its application through different use-case scenarios. Evaluation results of core functionality of our architecture are provided.
引用
收藏
页码:432 / 441
页数:10
相关论文
共 50 条
  • [31] Securing the IoT-enabled smart healthcare system: A PUF-based resource-efficient authentication mechanism
    Alruwaili, Omar
    Tanveer, Muhammad
    Alotaibi, Faisal Mohammed
    Abdelfattah, Waleed
    Armghan, Ammar
    Alserhani, Faeiz M.
    HELIYON, 2024, 10 (18)
  • [32] Fine-Grained Access Control for Microservices
    Nehme, Antonio
    Jesus, Vitor
    Mahbub, Khaled
    Abdallah, Ali
    FOUNDATIONS AND PRACTICE OF SECURITY, FPS 2018, 2019, 11358 : 285 - 300
  • [33] IoT-enabled Smart Healthcare System for Accessing Healthcare Services Anywhere and Anytime
    Chand, Repu Daman
    Rajnish, Ranjana
    Chandra, Hem
    Proceedings of the 17th INDIACom; 2023 10th International Conference on Computing for Sustainable Global Development, INDIACom 2023, 2023, : 688 - 693
  • [34] Forward Privacy Preservation in IoT-Enabled Healthcare Systems
    Wang, Ke
    Chen, Chien-Ming
    Tie, Zhuoyu
    Shojafar, Mohammad
    Kumar, Sachin
    Kumari, Saru
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2022, 18 (03) : 1991 - 1999
  • [35] Design of a Telepresence Robot to Avoid Obstacles in IoT-Enabled Sustainable Healthcare Systems
    Altalbe, Ali A.
    Khan, Muhammad Nasir
    Tahir, Muhammad
    SUSTAINABILITY, 2023, 15 (07)
  • [36] Fine-Grained Access Control for Electronic Health Record Systems
    Pham Thi Bach Hue
    Wohlgemuth, Sven
    Echizen, Isao
    Dong Thi Bich Thuy
    Nguyen Dinh Thu
    U- AND E-SERVICE, SCIENCE AND TECHNOLOGY, 2010, 124 : 31 - +
  • [37] Fine-Grained Access Control-Enabled Logging Method on ARM TrustZone
    Lee, Seungho
    Jo, Hyo Jin
    Choi, Wonsuk
    Kim, Hyoseung
    Park, Jong Hwan
    Lee, Dong Hoon
    IEEE ACCESS, 2020, 8 (08): : 81348 - 81364
  • [38] Fine-grained access control policy in blockchain-enabled edge computing
    He, Guangxuan
    Li, Chunlin
    Shu, Yong
    Luo, Youlong
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2024, 221
  • [39] Secure IoT Data Outsourcing With Aggregate Statistics and Fine-Grained Access Control
    Liu, Ling
    Wang, He
    Zhang, Yuqing
    IEEE ACCESS, 2020, 8 : 95057 - 95067
  • [40] A Fine-Grained Access Control Scheme in Fog-IoT Based Environment
    Derki, Mohamed Saddek
    Taboudjemat-Nouali, Nadia
    Nouali, Omar
    ADVANCED INTELLIGENT SYSTEMS FOR SUSTAINABLE DEVELOPMENT (AI2SD'2020), VOL 2, 2022, 1418 : 465 - 474