Extending Attribute-Based Access Control Model with Authentication Information for Internet of Things

Melike Burakgazi Bilgen, Kemal Bicakci

Araştırma sonucu: ???type-name???Konferans katkısıbilirkişi

4 Atıf (Scopus)

Özet

Internet of Things (IoT) brings not only wide range of opportunities but also security and privacy concerns. Consisting of many connected devices used in a highly interactive way, one of the main security concerns in IoT is unauthorized access. Traditional access control models do not support dynamic and fine-grained access control policies. Attribute-Based Access Control (ABAC) model is usually considered the most satisfactory access control model for running IoT applications. In this paper, we propose to take into the user authentication matching score obtained from a biometric authentication system consideration during making access control decisions. We emphasize the need of fine-grained access control and suggest to create access control policies per functionality of the device instead of per device regarding to the least privilege principle of information security. We give full or partial permission to certain functionalities of the IoT devices based on the user's authentication matching score thus provide more fine-grained and powerful access control mechanism. We present an extended Attribute-Based Access Control model that includes the assurance level of user authentication in access control policies and partially or fully permit the request accordingly.

Orijinal dilİngilizce
Ana bilgisayar yayını başlığı2020 International Conference on Information Security and Cryptology, ISCTURKEY 2020 - Proceedings
EditörlerSeref Sagiroglu, Sedat Akleylek, Ferruh Ozbudak, Yavuz Canbay
YayınlayanInstitute of Electrical and Electronics Engineers Inc.
Sayfalar48-55
Sayfa sayısı8
ISBN (Elektronik)9781665418638
DOI'lar
Yayın durumuYayınlandı - 3 Ara 2020
Harici olarak yayınlandıEvet
Etkinlik13th International Conference on Information Security and Cryptology, ISCTURKEY 2020 - Virtual, Ankara, Turkey
Süre: 3 Ara 20204 Ara 2020

Yayın serisi

Adı2020 International Conference on Information Security and Cryptology, ISCTURKEY 2020 - Proceedings

???event.eventtypes.event.conference???

???event.eventtypes.event.conference???13th International Conference on Information Security and Cryptology, ISCTURKEY 2020
Ülke/BölgeTurkey
ŞehirVirtual, Ankara
Periyot3/12/204/12/20

Bibliyografik not

Publisher Copyright:
© 2020 IEEE.

Parmak izi

Extending Attribute-Based Access Control Model with Authentication Information for Internet of Things' araştırma başlıklarına git. Birlikte benzersiz bir parmak izi oluştururlar.

Alıntı Yap