Cargando…

An Interoperable Access Control Framework for Diverse IoT Platforms Based on OAuth and Role †

Due to the rapid development of Internet of Things (IoT), IoT platforms that can provide common functions for things are becoming increasingly important. However, access control frameworks in diverse IoT platforms have been developed for individual security goals, designs, and technologies. In parti...

Descripción completa

Detalles Bibliográficos
Autores principales: Oh, Se-Ra, Kim, Young-Gab, Cho, Sanghyun
Formato: Online Artículo Texto
Lenguaje:English
Publicado: MDPI 2019
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6514541/
https://www.ncbi.nlm.nih.gov/pubmed/31010030
http://dx.doi.org/10.3390/s19081884
_version_ 1783417892509843456
author Oh, Se-Ra
Kim, Young-Gab
Cho, Sanghyun
author_facet Oh, Se-Ra
Kim, Young-Gab
Cho, Sanghyun
author_sort Oh, Se-Ra
collection PubMed
description Due to the rapid development of Internet of Things (IoT), IoT platforms that can provide common functions for things are becoming increasingly important. However, access control frameworks in diverse IoT platforms have been developed for individual security goals, designs, and technologies. In particular, current OAuth-based access control frameworks that are widely used in IoT research have not been providing interoperability among IoT platforms even though sharing resources and services is a critical issue for IoT platforms. Therefore, we analyze the main requirements for an IoT access control framework to properly design our framework and propose an interoperable access control framework based on OAuth 2.0 and Role. Our approach describes a new extended authorization grant flow to issue an Interoperable Access Token (IAT) that has a global access scope across IoT platforms using multiple pairs of clients’ credentials. With the IAT and proposed framework, we can access client-specific domains in heterogeneous IoT platforms, then valuable resources (e.g., data and services) in the domains can be accessed by validating the roles, which will greatly simplify permission management. Furthermore, IAT supports a simple token management (e.g., token issuance, refreshing, and revocation) by managing only one token for diverse IoT platforms. In addition, we implement our interoperable access control framework on Mobius and FIWARE, which are promising open-source IoT platforms, and test an interoperability scenario to demonstrate our approach with the implementation. Furthermore, the proposed framework is compared with other IoT access control approaches based on the selected requirements in this paper.
format Online
Article
Text
id pubmed-6514541
institution National Center for Biotechnology Information
language English
publishDate 2019
publisher MDPI
record_format MEDLINE/PubMed
spelling pubmed-65145412019-05-30 An Interoperable Access Control Framework for Diverse IoT Platforms Based on OAuth and Role † Oh, Se-Ra Kim, Young-Gab Cho, Sanghyun Sensors (Basel) Article Due to the rapid development of Internet of Things (IoT), IoT platforms that can provide common functions for things are becoming increasingly important. However, access control frameworks in diverse IoT platforms have been developed for individual security goals, designs, and technologies. In particular, current OAuth-based access control frameworks that are widely used in IoT research have not been providing interoperability among IoT platforms even though sharing resources and services is a critical issue for IoT platforms. Therefore, we analyze the main requirements for an IoT access control framework to properly design our framework and propose an interoperable access control framework based on OAuth 2.0 and Role. Our approach describes a new extended authorization grant flow to issue an Interoperable Access Token (IAT) that has a global access scope across IoT platforms using multiple pairs of clients’ credentials. With the IAT and proposed framework, we can access client-specific domains in heterogeneous IoT platforms, then valuable resources (e.g., data and services) in the domains can be accessed by validating the roles, which will greatly simplify permission management. Furthermore, IAT supports a simple token management (e.g., token issuance, refreshing, and revocation) by managing only one token for diverse IoT platforms. In addition, we implement our interoperable access control framework on Mobius and FIWARE, which are promising open-source IoT platforms, and test an interoperability scenario to demonstrate our approach with the implementation. Furthermore, the proposed framework is compared with other IoT access control approaches based on the selected requirements in this paper. MDPI 2019-04-20 /pmc/articles/PMC6514541/ /pubmed/31010030 http://dx.doi.org/10.3390/s19081884 Text en © 2019 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).
spellingShingle Article
Oh, Se-Ra
Kim, Young-Gab
Cho, Sanghyun
An Interoperable Access Control Framework for Diverse IoT Platforms Based on OAuth and Role †
title An Interoperable Access Control Framework for Diverse IoT Platforms Based on OAuth and Role †
title_full An Interoperable Access Control Framework for Diverse IoT Platforms Based on OAuth and Role †
title_fullStr An Interoperable Access Control Framework for Diverse IoT Platforms Based on OAuth and Role †
title_full_unstemmed An Interoperable Access Control Framework for Diverse IoT Platforms Based on OAuth and Role †
title_short An Interoperable Access Control Framework for Diverse IoT Platforms Based on OAuth and Role †
title_sort interoperable access control framework for diverse iot platforms based on oauth and role †
topic Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6514541/
https://www.ncbi.nlm.nih.gov/pubmed/31010030
http://dx.doi.org/10.3390/s19081884
work_keys_str_mv AT ohsera aninteroperableaccesscontrolframeworkfordiverseiotplatformsbasedonoauthandrole
AT kimyounggab aninteroperableaccesscontrolframeworkfordiverseiotplatformsbasedonoauthandrole
AT chosanghyun aninteroperableaccesscontrolframeworkfordiverseiotplatformsbasedonoauthandrole
AT ohsera interoperableaccesscontrolframeworkfordiverseiotplatformsbasedonoauthandrole
AT kimyounggab interoperableaccesscontrolframeworkfordiverseiotplatformsbasedonoauthandrole
AT chosanghyun interoperableaccesscontrolframeworkfordiverseiotplatformsbasedonoauthandrole