Perils and Mitigation of Security Risks of Cooperation in Mobile-as-a-Gateway IoT
Xin'an Zhou, Jiale Guan, Luyi Xing, Zhiyun Qian
Abstract
Mobile-as-a-Gateway (MaaG) is a popular feature using mobile devices as gateways to connect IoT devices to cloud services for management. MaaG IoT access control systems support remote access sharing/revocation while allowing "offline availability" for better usability. Realizing these functionalities requires secure cooperation among the cloud service, the companion app, and the IoT device. For practical considerations, we find that almost all cloud services perform access model translation (AMT) to translate expressive cloud-side access policies to simple device-side policies. During the process, ad-hoc protocols are developed to support the access policy synchronization. Unfortunately, current MaaG IoT systems fail to recognize the security risks in the process of access model translation and synchronization. We analyze ten topof-the-line MaaG IoT devices and find that all of them have serious vulnerabilities, e.g., allowing irrevocable and permanent access for temporary users. We further propose a secure protocol design that defends against all identified attacks. CCS CONCEPTS • Security and privacy → Embedded systems security; Software reverse engineering; • Networks → Network architectures.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- P-Verifier: Understanding and Mitigating Security Risks in Cloud-based IoT Access PoliciesZe Jin, Luyi Xing, Yiwei Fang, Yan Jia et al.CCS 2022 · 19 citations
- Demystifying the Security Implications in IoT Device Rental ServicesYi He, Yunchao Guan, Ruoyu Lun, Shangru Song et al.USENIX Security 2024 · 2 citations
- Hidden and Lost Control: on Security Design Risks in IoT User-Facing Matter ControllerHaoqiang Wang, Yiwei Fang, Yichen Liu, Ze Jin et al.NDSS 2025
Builds on28
- Security Analysis of Emerging Smart Home ApplicationsEarlence Fernandes, Jaeyeon Jung, Atul PrakashS&P 2016 · 684 citations
- ContexloT: Towards Providing Contextual Integrity to Appified IoT PlatformsYunhan Jack Jia, Qi Alfred Chen, Shiqi Wang, Amir Rahmati et al.NDSS 2017 · 325 citations
- IoTGuard: Dynamic Enforcement of Security and Safety Policy in Commodity IoTZ. Berkay Celik, Gang Tan, Patrick D. McDanielNDSS 2019 · 254 citations
- SmartAuth: User-Centered Authorization for the Internet of ThingsYuan Tian, Nan Zhang, Yue-Hsun Lin, XiaoFeng Wang et al.USENIX Security 2017 · 231 citations
- Rethinking Access Control and Authentication for the Home Internet of Things (IoT)Weijia He, Maximilian Golla, Roshni Padhi, Jordan Ofek et al.USENIX Security 2018 · 221 citations
Related papers
- Burglars' IoT Paradise: Understanding and Mitigating Security Risks of General Messaging Protocols on IoT CloudsYan Jia, Luyi Xing, Yuhang Mao, Dongfang Zhao et al.S&P 2020 · 64 citations
- Shattered Chain of Trust: Understanding Security Risks in Cross-Cloud IoT Access DelegationBin Yuan, Yan Jia, Luyi Xing, Dongfang Zhao et al.USENIX Security 2020
- IoTFlow: Inferring IoT Device Behavior at Scale through Static Mobile Companion App AnalysisDavid Schmidt, Carlotta Tagliaro, Kevin Borgolte, Martina LindorferCCS 2023 · 13 citations
- Who's In Control? On Security Risks of Disjointed IoT Device Management ChannelsYan Jia, Bin Yuan, Luyi Xing, Dongfang Zhao et al.CCS 2021 · 22 citations
- Insecurity of operational cellular IoT service: new vulnerabilities, attacks, and countermeasuresSihan Wang, Guan-Hua Tu, Xinyu Lei, Tian Xie et al.MobiCom 2021 · 12 citations
