DBAC: Directory-Based Access Control for Geographically Distributed IoT Systems
Luoyao Hao, Vibhas Naik, Henning Schulzrinne
Abstract
We propose and implement Directory-Based Access Control (DBAC), a flexible and systematic access control approach for geographically distributed multi-administration IoT systems. DBAC designs and relies on a particular module, IoT directory, to store device metadata, manage federated identities, and assist with cross-domain authorization. The directory service decouples IoT access into two phases: discover device information from directories and operate devices through discovered interfaces. DBAC extends attribute-based authorization and retrieves diverse attributes of users, devices, and environments from multi-faceted sources via standard methods, while user privacy is protected. To support resource-constrained devices, DBAC assigns a capability token to each authorized user, and devices only validate tokens to process a request.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on2
- Rethinking Access Control and Authentication for the Home Internet of Things (IoT)Weijia He, Maximilian Golla, Roshni Padhi, Jordan Ofek et al.USENIX Security 2018 · 221 citations
- GOLDIE: Harmonization and Orchestration Towards a Global Directory for IoTLuoyao Hao, Henning SchulzrinneINFOCOM 2021 · 10 citations
Related papers
- Situational Access Control in the Internet of ThingsRoei Schuster, Vitaly Shmatikov, Eran TromerCCS 2018 · 81 citations
- ZKP-CapBAC: Capability-Based Access Control via On-Chain Zero-Knowledge Proofs for Cross-Domain Hiding Delegation TreeYanru Chen, Yuanyuan Zhang, Xin Lin, Tongzhou Xu et al.INFOCOM 2025 · 4 citations
- WAVE: A Decentralized Authorization Framework with Transitive DelegationMichael P. Andersen, Sam Kumar, Moustafa AbdelBaky, Gabe Fierro et al.USENIX Security 2019 · 66 citations
- Droplet: Decentralized Authorization and Access Control for Encrypted Data StreamsHossein Shafagh, Lukas Burkhalter, Sylvia Ratnasamy, Anwar HithnawiUSENIX Security 2020
- P-Verifier: Understanding and Mitigating Security Risks in Cloud-based IoT Access PoliciesZe Jin, Luyi Xing, Yiwei Fang, Yan Jia et al.CCS 2022 · 19 citations
