Attribute-Based Access Control for AWS Internet of Things and Secure Industries of the Future
Internet of Things (IoT) is revolutionizing and enhancing the quality of human lives in every aspect. With a disruption of IoT devices and applications, attackers are leveraging weak authentication and access control mechanisms on these IoT devices and applications to gain unauthorized access on use...
Main Authors: | , , , , , |
---|---|
Format: | Article |
Language: | English |
Published: |
IEEE
2021-01-01
|
Series: | IEEE Access |
Subjects: | |
Online Access: | https://ieeexplore.ieee.org/document/9502070/ |
_version_ | 1818624182259286016 |
---|---|
author | Smriti Bhatt Thanh Kim Pham Maanak Gupta James Benson Jaehong Park Ravi Sandhu |
author_facet | Smriti Bhatt Thanh Kim Pham Maanak Gupta James Benson Jaehong Park Ravi Sandhu |
author_sort | Smriti Bhatt |
collection | DOAJ |
description | Internet of Things (IoT) is revolutionizing and enhancing the quality of human lives in every aspect. With a disruption of IoT devices and applications, attackers are leveraging weak authentication and access control mechanisms on these IoT devices and applications to gain unauthorized access on user devices and data and cause them harm. Access control is a critical security mechanism to secure the IoT ecosystem which comprises cloud computing and edge computing services along with smart devices. Today major cloud and IoT service providers including Amazon Web Services (AWS), Google Cloud Platform (GCP), and Azure utilize some customized forms of Role-Based Access Control (RBAC) model along with specific authorization policies enabled by policy-based access control models. To enable fine-grained access control and overcome limitations of existing access control models, there is an imminent need to develop a flexible and dynamic access control model for securing smart devices, data and resources in the cloud-enabled IoT architecture. In this paper, we develop a formal attribute-based access control (ABAC) model for AWS IoT by building upon and extending previously developed access control model for AWS IoT, known as AWS-IoTAC model. We demonstrate the applicability of our proposed model through an industrial IoT use case and its implementation in the AWS IoT platform. Our proposed fine grained model for AWS IoT incorporates its existing capabilities and introduces new attributes for IoT entities and attribute-based policies for enabling expressive access control in AWS IoT. We also evaluate the performance of our model on the AWS cloud and IoT platform with the future smart industries use-case to depict the feasibility of our model in a real-world platform. |
first_indexed | 2024-12-16T18:52:53Z |
format | Article |
id | doaj.art-ff9fa128bd304d30b59c5def6380117e |
institution | Directory Open Access Journal |
issn | 2169-3536 |
language | English |
last_indexed | 2024-12-16T18:52:53Z |
publishDate | 2021-01-01 |
publisher | IEEE |
record_format | Article |
series | IEEE Access |
spelling | doaj.art-ff9fa128bd304d30b59c5def6380117e2022-12-21T22:20:39ZengIEEEIEEE Access2169-35362021-01-01910720010722310.1109/ACCESS.2021.31012189502070Attribute-Based Access Control for AWS Internet of Things and Secure Industries of the FutureSmriti Bhatt0Thanh Kim Pham1https://orcid.org/0000-0002-8948-3074Maanak Gupta2https://orcid.org/0000-0001-9189-2478James Benson3Jaehong Park4https://orcid.org/0000-0002-1612-5137Ravi Sandhu5Department of Computer and Information Technology, Purdue University, West Lafayette, IN, USADepartment of Computer Science, Tennessee Technological University, Cookeville, TN, USADepartment of Computer Science, Tennessee Technological University, Cookeville, TN, USADepartment of Computer Science, Institute for Cyber Security, The University of Texas at San Antonio, San Antonio, TX, USADepartment of Management, Marketing and Information Systems, The University of Alabama in Huntsville, Huntsville, AL, USADepartment of Computer Science, Institute for Cyber Security, The University of Texas at San Antonio, San Antonio, TX, USAInternet of Things (IoT) is revolutionizing and enhancing the quality of human lives in every aspect. With a disruption of IoT devices and applications, attackers are leveraging weak authentication and access control mechanisms on these IoT devices and applications to gain unauthorized access on user devices and data and cause them harm. Access control is a critical security mechanism to secure the IoT ecosystem which comprises cloud computing and edge computing services along with smart devices. Today major cloud and IoT service providers including Amazon Web Services (AWS), Google Cloud Platform (GCP), and Azure utilize some customized forms of Role-Based Access Control (RBAC) model along with specific authorization policies enabled by policy-based access control models. To enable fine-grained access control and overcome limitations of existing access control models, there is an imminent need to develop a flexible and dynamic access control model for securing smart devices, data and resources in the cloud-enabled IoT architecture. In this paper, we develop a formal attribute-based access control (ABAC) model for AWS IoT by building upon and extending previously developed access control model for AWS IoT, known as AWS-IoTAC model. We demonstrate the applicability of our proposed model through an industrial IoT use case and its implementation in the AWS IoT platform. Our proposed fine grained model for AWS IoT incorporates its existing capabilities and introduces new attributes for IoT entities and attribute-based policies for enabling expressive access control in AWS IoT. We also evaluate the performance of our model on the AWS cloud and IoT platform with the future smart industries use-case to depict the feasibility of our model in a real-world platform.https://ieeexplore.ieee.org/document/9502070/Internet of Thingssmart industriesfuture manufacturingaccess controlsecurityprivacy |
spellingShingle | Smriti Bhatt Thanh Kim Pham Maanak Gupta James Benson Jaehong Park Ravi Sandhu Attribute-Based Access Control for AWS Internet of Things and Secure Industries of the Future IEEE Access Internet of Things smart industries future manufacturing access control security privacy |
title | Attribute-Based Access Control for AWS Internet of Things and Secure Industries of the Future |
title_full | Attribute-Based Access Control for AWS Internet of Things and Secure Industries of the Future |
title_fullStr | Attribute-Based Access Control for AWS Internet of Things and Secure Industries of the Future |
title_full_unstemmed | Attribute-Based Access Control for AWS Internet of Things and Secure Industries of the Future |
title_short | Attribute-Based Access Control for AWS Internet of Things and Secure Industries of the Future |
title_sort | attribute based access control for aws internet of things and secure industries of the future |
topic | Internet of Things smart industries future manufacturing access control security privacy |
url | https://ieeexplore.ieee.org/document/9502070/ |
work_keys_str_mv | AT smritibhatt attributebasedaccesscontrolforawsinternetofthingsandsecureindustriesofthefuture AT thanhkimpham attributebasedaccesscontrolforawsinternetofthingsandsecureindustriesofthefuture AT maanakgupta attributebasedaccesscontrolforawsinternetofthingsandsecureindustriesofthefuture AT jamesbenson attributebasedaccesscontrolforawsinternetofthingsandsecureindustriesofthefuture AT jaehongpark attributebasedaccesscontrolforawsinternetofthingsandsecureindustriesofthefuture AT ravisandhu attributebasedaccesscontrolforawsinternetofthingsandsecureindustriesofthefuture |