An Attribute-Based Approach toward a Secured Smart-Home IoT Access Control and a Comparison with a Role-Based Approach

INFORMATION(2022)

引用 13|浏览8
暂无评分
摘要
The area of smart homes is one of the most popular for deploying smart connected devices. One of the most vulnerable aspects of smart homes is access control. Recent advances in IoT have led to several access control models being developed or adapted to IoT from other domains, with few specifically designed to meet the challenges of smart homes. Most of these models use role-based access control (RBAC) or attribute-based access control (ABAC) models. As of now, it is not clear what the advantages and disadvantages of ABAC over RBAC are in general, and in the context of smart-home IoT in particular. In this paper, we introduce HABAC(alpha), an attribute-based access control model for smart-home IoT. We formally define HABAC(alpha) and demonstrate its features through two use-case scenarios and a proof-of-concept implementation. Furthermore, we present an analysis of HABAC(alpha) as compared to the previously published EGRBAC (extended generalized role-based access control) model for smart-home IoT by first describing approaches for constructing HABAC(alpha) specification from EGRBAC and vice versa in order to compare the theoretical expressiveness power of these models, and second, analyzing HABAC(alpha) and EGRBAC models against standard criteria for access control models. Our findings suggest that a hybrid model that combines both HABAC(alpha) and EGRBAC capabilities may be the most suitable for smart-home IoT, and probably more generally.
更多
查看译文
关键词
smart homes, IoT, access control
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要