A Bi-directional Attribute Synchronization Mechanism for Access Control in IoT Environments

Bruno Cremonezi, Luciano F. da Rocha,Alex B. Vieira,José Nacif, André L. de Oliveira,Edelberto Franco Silva

Mobile Computing, Applications, and Services(2023)

引用 0|浏览1
暂无评分
摘要
The Attribute-Based Access Control (ABAC) model is widely used for IoT due to its capacity to express access policies through attributes, making this method granular and flexible. However, if we assume that attributes are essentially mutable, the irreducible network latency and the architectures proposed to acquire a better communication performance of the IoT expose the point where those policies are evaluated as outdated attributes. Therefore, access policies can be wrongly evaluated, resulting in consistency and security problems. In this paper, we propose a method to reduce this exposure through a bi-directional attribute synchronization capable of mapping all attributes and evaluating their current consistency after a change. If the modified attribute does not affect the access, it will remain valid. Otherwise, a revocation occurs, reducing the risks of unintended accesses. Our modeling allows demonstrating the correctness of our method and its capability to revoke every unintended access that may occur after an attribute change.
更多
查看译文
关键词
access control,bi-directional
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要