Authentication-enabled attribute-based access control for smart homes

Melike Burakgazi Bilgen*, Osman Abul, Kemal Bicakci

*Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

3 Citations (Scopus)

Abstract

Smart home technologies constantly bring significant convenience to our daily lives. Unfortunately, increased security risks accompany this convenience. There can be severe consequences when unauthorized or malicious users gain access to smart home devices. Therefore, dependable and comprehensive access control models are needed to address the security concerns. To this end, the attribute-based access control (ABAC) model is usually considered the most satisfactory access control model for running IoT applications. However, the uncertainty left with the authentication stage should be carried to the authorization policy specification. In this work, we extend the ABAC model by carrying the assurance level of user authentication obtained from biometric authentication systems for authorization. The extended ABAC model quantifies how far the authentication matching score is from the predefined threshold. This quantification serves as a regular attribute like others to define authorization policies. The novelty in this quantification is that it consults false matching rate and hence can easily normalize across wide range of biometric authentication devices and algorithms. As a result, the resulting access control policies are concise and easy to comprehend. Moreover, our model is fine-grained in that different access policies can be specified for each smart device functionality. This work also shows, through case studies, that the extended ABAC model is feasible and implementable in XACML language.

Original languageEnglish
Pages (from-to)479-495
Number of pages17
JournalInternational Journal of Information Security
Volume22
Issue number2
DOIs
Publication statusPublished - Apr 2023

Bibliographical note

Publisher Copyright:
© 2022, The Author(s), under exclusive licence to Springer-Verlag GmbH, DE.

Funding

Open access funding provided by Uppsala University. TM is supported by the Gunvor och Josef Anérs stiftelse and by Uppsala University (Ingegerd Bergh and Kungl Vetenskapssamh Stipends). HS and MW are supported by the Swedish Research Council; the Swedish Brain Research Foundation; the Swedish Research Council for Environment, Agricultural Sciences and Spatial Planning; the Novo Nordisk Foundation; and the FAT4BRAIN project funding from the European Union’s Horizon 2020 research and innovation programme (Grant No: 857394). The funders had no role in the design of the study or in the writing of the manuscript.

FundersFunder number
Swedish Brain Research Foundation
Horizon 2020 Framework Programme857394
Gunvor och Josef Anérs Siftelse
Svenska Forskningsrådet Formas
Vetenskapsrådet
Uppsala Universitet
Novo Nordisk Fonden

    Keywords

    • Access control
    • Attribute-based access control
    • False matching rate
    • Internet of Things
    • Smart home security

    Fingerprint

    Dive into the research topics of 'Authentication-enabled attribute-based access control for smart homes'. Together they form a unique fingerprint.

    Cite this