Attribute-Based Access Control for AWS Internet of Things and Secure Industries of the Future

Internet of Things (IoT) is revolutionizing and enhancing the quality of human lives in every aspect. With a disruption of IoT devices and applications, attackers are leveraging weak authentication and access control mechanisms on these IoT devices and applications to gain unauthorized access on use...

Full description

Bibliographic Details
Main Authors: Smriti Bhatt, Thanh Kim Pham, Maanak Gupta, James Benson, Jaehong Park, Ravi Sandhu
Format: Article
Language:English
Published: IEEE 2021-01-01
Series:IEEE Access
Subjects:
Online Access:https://ieeexplore.ieee.org/document/9502070/
_version_ 1818624182259286016
author Smriti Bhatt
Thanh Kim Pham
Maanak Gupta
James Benson
Jaehong Park
Ravi Sandhu
author_facet Smriti Bhatt
Thanh Kim Pham
Maanak Gupta
James Benson
Jaehong Park
Ravi Sandhu
author_sort Smriti Bhatt
collection DOAJ
description Internet of Things (IoT) is revolutionizing and enhancing the quality of human lives in every aspect. With a disruption of IoT devices and applications, attackers are leveraging weak authentication and access control mechanisms on these IoT devices and applications to gain unauthorized access on user devices and data and cause them harm. Access control is a critical security mechanism to secure the IoT ecosystem which comprises cloud computing and edge computing services along with smart devices. Today major cloud and IoT service providers including Amazon Web Services (AWS), Google Cloud Platform (GCP), and Azure utilize some customized forms of Role-Based Access Control (RBAC) model along with specific authorization policies enabled by policy-based access control models. To enable fine-grained access control and overcome limitations of existing access control models, there is an imminent need to develop a flexible and dynamic access control model for securing smart devices, data and resources in the cloud-enabled IoT architecture. In this paper, we develop a formal attribute-based access control (ABAC) model for AWS IoT by building upon and extending previously developed access control model for AWS IoT, known as AWS-IoTAC model. We demonstrate the applicability of our proposed model through an industrial IoT use case and its implementation in the AWS IoT platform. Our proposed fine grained model for AWS IoT incorporates its existing capabilities and introduces new attributes for IoT entities and attribute-based policies for enabling expressive access control in AWS IoT. We also evaluate the performance of our model on the AWS cloud and IoT platform with the future smart industries use-case to depict the feasibility of our model in a real-world platform.
first_indexed 2024-12-16T18:52:53Z
format Article
id doaj.art-ff9fa128bd304d30b59c5def6380117e
institution Directory Open Access Journal
issn 2169-3536
language English
last_indexed 2024-12-16T18:52:53Z
publishDate 2021-01-01
publisher IEEE
record_format Article
series IEEE Access
spelling doaj.art-ff9fa128bd304d30b59c5def6380117e2022-12-21T22:20:39ZengIEEEIEEE Access2169-35362021-01-01910720010722310.1109/ACCESS.2021.31012189502070Attribute-Based Access Control for AWS Internet of Things and Secure Industries of the FutureSmriti Bhatt0Thanh Kim Pham1https://orcid.org/0000-0002-8948-3074Maanak Gupta2https://orcid.org/0000-0001-9189-2478James Benson3Jaehong Park4https://orcid.org/0000-0002-1612-5137Ravi Sandhu5Department of Computer and Information Technology, Purdue University, West Lafayette, IN, USADepartment of Computer Science, Tennessee Technological University, Cookeville, TN, USADepartment of Computer Science, Tennessee Technological University, Cookeville, TN, USADepartment of Computer Science, Institute for Cyber Security, The University of Texas at San Antonio, San Antonio, TX, USADepartment of Management, Marketing and Information Systems, The University of Alabama in Huntsville, Huntsville, AL, USADepartment of Computer Science, Institute for Cyber Security, The University of Texas at San Antonio, San Antonio, TX, USAInternet of Things (IoT) is revolutionizing and enhancing the quality of human lives in every aspect. With a disruption of IoT devices and applications, attackers are leveraging weak authentication and access control mechanisms on these IoT devices and applications to gain unauthorized access on user devices and data and cause them harm. Access control is a critical security mechanism to secure the IoT ecosystem which comprises cloud computing and edge computing services along with smart devices. Today major cloud and IoT service providers including Amazon Web Services (AWS), Google Cloud Platform (GCP), and Azure utilize some customized forms of Role-Based Access Control (RBAC) model along with specific authorization policies enabled by policy-based access control models. To enable fine-grained access control and overcome limitations of existing access control models, there is an imminent need to develop a flexible and dynamic access control model for securing smart devices, data and resources in the cloud-enabled IoT architecture. In this paper, we develop a formal attribute-based access control (ABAC) model for AWS IoT by building upon and extending previously developed access control model for AWS IoT, known as AWS-IoTAC model. We demonstrate the applicability of our proposed model through an industrial IoT use case and its implementation in the AWS IoT platform. Our proposed fine grained model for AWS IoT incorporates its existing capabilities and introduces new attributes for IoT entities and attribute-based policies for enabling expressive access control in AWS IoT. We also evaluate the performance of our model on the AWS cloud and IoT platform with the future smart industries use-case to depict the feasibility of our model in a real-world platform.https://ieeexplore.ieee.org/document/9502070/Internet of Thingssmart industriesfuture manufacturingaccess controlsecurityprivacy
spellingShingle Smriti Bhatt
Thanh Kim Pham
Maanak Gupta
James Benson
Jaehong Park
Ravi Sandhu
Attribute-Based Access Control for AWS Internet of Things and Secure Industries of the Future
IEEE Access
Internet of Things
smart industries
future manufacturing
access control
security
privacy
title Attribute-Based Access Control for AWS Internet of Things and Secure Industries of the Future
title_full Attribute-Based Access Control for AWS Internet of Things and Secure Industries of the Future
title_fullStr Attribute-Based Access Control for AWS Internet of Things and Secure Industries of the Future
title_full_unstemmed Attribute-Based Access Control for AWS Internet of Things and Secure Industries of the Future
title_short Attribute-Based Access Control for AWS Internet of Things and Secure Industries of the Future
title_sort attribute based access control for aws internet of things and secure industries of the future
topic Internet of Things
smart industries
future manufacturing
access control
security
privacy
url https://ieeexplore.ieee.org/document/9502070/
work_keys_str_mv AT smritibhatt attributebasedaccesscontrolforawsinternetofthingsandsecureindustriesofthefuture
AT thanhkimpham attributebasedaccesscontrolforawsinternetofthingsandsecureindustriesofthefuture
AT maanakgupta attributebasedaccesscontrolforawsinternetofthingsandsecureindustriesofthefuture
AT jamesbenson attributebasedaccesscontrolforawsinternetofthingsandsecureindustriesofthefuture
AT jaehongpark attributebasedaccesscontrolforawsinternetofthingsandsecureindustriesofthefuture
AT ravisandhu attributebasedaccesscontrolforawsinternetofthingsandsecureindustriesofthefuture