Situational Access Control in the Internet of Things
Roei Schuster, Vitaly Shmatikov, Eran Tromer
Abstract
Access control in the Internet of Things (IoT) often depends on a situation-for example, "the user is at home"-that can only be tracked using multiple devices. In contrast to the (well-studied) smartphone frameworks, enforcement of situational constraints in the IoT poses new challenges because access control is fundamentally decentralized. It takes place in multiple independent frameworks, subjects are often external to the enforcement system, and situation tracking requires cross-framework interaction and permissioning. Existing IoT frameworks entangle access-control enforcement and situation tracking. This results in overprivileged, redundant, inconsistent, and inflexible implementations. We design and implement a new approach to IoT access control. Our key innovation is to introduce "environmental situation oracles" (ESOs) as first-class objects in the IoT ecosystem. An ESO encapsulates the implementation of how a situation is sensed, inferred, or actuated. IoT access-control frameworks can use ESOs to enforce situational constraints, but ESOs and frameworks remain oblivious to each other's implementation details. A single ESO can be used by multiple access-control frameworks across the ecosystem. This reduces inefficiency, supports consistent enforcement of common policies, and-because ESOs encapsulate sensitive device-access rights-reduces overprivileging. ESOs can be deployed at any layer of the IoT software stack where access control is applied. We implemented prototype ESOs for the IoT resource layer, based on the IoTivity framework, and for the IoT Web services, based on the Passport middleware.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers8
- Charting the Attack Surface of Trigger-Action IoT PlatformsQi Wang, Pubali Datta, Wei Yang, Si Liu et al.CCS 2019 · 162 citations
- Identifying privacy weaknesses from multi-party trigger-action integration platformsKulani Mahadewa, Yanjun Zhang, Guangdong Bai, Lei Bu et al.ISSTA 2021 · 25 citations
- Who's In Control? On Security Risks of Disjointed IoT Device Management ChannelsYan Jia, Bin Yuan, Luyi Xing, Dongfang Zhao et al.CCS 2021 · 22 citations
- Ruledger: Ensuring Execution Integrity in Trigger-Action IoT PlatformsJingwen Fan, Yi He, Bo Tang, Qi Li et al.INFOCOM 2021 · 17 citations
- An Intent-Based Automation Framework for Securing Dynamic Consumer IoT InfrastructuresVasudevan Nagendra, Arani Bhattacharya, Vinod Yegneswaran, Amir Rahmati et al.WWW 2020 · 17 citations
Builds on7
- Security Analysis of Emerging Smart Home ApplicationsEarlence Fernandes, Jaeyeon Jung, Atul PrakashS&P 2016 · 684 citations
- FlowFence: Practical Data Protection for Emerging IoT Application FrameworksEarlence Fernandes, Justin Paupore, Amir Rahmati, Daniel Simionato et al.USENIX Security 2016 · 296 citations
- Sensitive Information Tracking in Commodity IoTZ. Berkay Celik, Leonardo Babun, Amit Kumar Sikder, Hidayet Aksu et al.USENIX Security 2018 · 236 citations
- SmartAuth: User-Centered Authorization for the Internet of ThingsYuan Tian, Nan Zhang, Yue-Hsun Lin, XiaoFeng Wang et al.USENIX Security 2017 · 231 citations
- Fear and Logging in the Internet of ThingsQi Wang, Wajih Ul Hassan, Adam Bates, Carl A. GunterNDSS 2018 · 205 citations
Related papers
- DBAC: Directory-Based Access Control for Geographically Distributed IoT SystemsLuoyao Hao, Vibhas Naik, Henning SchulzrinneINFOCOM 2022 · 12 citations
- ContexloT: Towards Providing Contextual Integrity to Appified IoT PlatformsYunhan Jack Jia, Qi Alfred Chen, Shiqi Wang, Amir Rahmati et al.NDSS 2017 · 325 citations
- FLUID-IoT : Flexible and Fine-Grained Access Control in Shared IoT Environments via Multi-user UI DistributionSunjae Lee, Minwoo Jeong, Daye Song, Junyoung Choi et al.CHI 2024 · 2 citations
- P-Verifier: Understanding and Mitigating Security Risks in Cloud-based IoT Access PoliciesZe Jin, Luyi Xing, Yiwei Fang, Yan Jia et al.CCS 2022 · 19 citations
- Rethinking Access Control and Authentication for the Home Internet of Things (IoT)Weijia He, Maximilian Golla, Roshni Padhi, Jordan Ofek et al.USENIX Security 2018 · 221 citations
