Cargando…

Evaluation of an IoT Application-Scoped Access Control Model over a Publish/Subscribe Architecture Based on FIWARE

The Internet of Things (IoT) brings plenty of opportunities to enhance society’s activities, from improving a factory’s production chain to facilitating people’s household tasks. However, it has also brought new security breaches, compromising privacy and authenticity. IoT devices are vulnerable to...

Descripción completa

Detalles Bibliográficos
Autores principales: Pozo, Alejandro, Alonso, Álvaro, Salvachúa, Joaquín
Formato: Online Artículo Texto
Lenguaje:English
Publicado: MDPI 2020
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7435769/
https://www.ncbi.nlm.nih.gov/pubmed/32759687
http://dx.doi.org/10.3390/s20154341
_version_ 1783572399275376640
author Pozo, Alejandro
Alonso, Álvaro
Salvachúa, Joaquín
author_facet Pozo, Alejandro
Alonso, Álvaro
Salvachúa, Joaquín
author_sort Pozo, Alejandro
collection PubMed
description The Internet of Things (IoT) brings plenty of opportunities to enhance society’s activities, from improving a factory’s production chain to facilitating people’s household tasks. However, it has also brought new security breaches, compromising privacy and authenticity. IoT devices are vulnerable to being accessed from the Internet; they lack sufficient resources to face cyber-attack threats. Keeping a balance between access control and the devices’ resource consumption has become one of the highest priorities of IoT research. In this paper, we evaluate an access control architecture based on the IAACaaS (IoT application-Scoped Access Control as a Service) model with the aim of protecting IoT devices that communicate using the Publish/Subscribe pattern. IAACaaS is based on the OAuth 2.0 authorization framework, which externalizes the identity and access control infrastructure of applications. In our evaluation, we implement the model using FIWARE Generic Enablers and deploy them for a smart buildings use case with a wireless communication. Then, we compare the performance of two different approaches in the data-sharing between sensors and the Publish/Subscribe broker, using Constrained Application Protocol (CoAP) and Hypertext Transfer Protocol (HTTP) protocols. We conclude that the integration of Publish/Subscribe IoT deployments with IAACaaS adds an extra layer of security and access control without compromising the system’s performance.
format Online
Article
Text
id pubmed-7435769
institution National Center for Biotechnology Information
language English
publishDate 2020
publisher MDPI
record_format MEDLINE/PubMed
spelling pubmed-74357692020-08-25 Evaluation of an IoT Application-Scoped Access Control Model over a Publish/Subscribe Architecture Based on FIWARE Pozo, Alejandro Alonso, Álvaro Salvachúa, Joaquín Sensors (Basel) Article The Internet of Things (IoT) brings plenty of opportunities to enhance society’s activities, from improving a factory’s production chain to facilitating people’s household tasks. However, it has also brought new security breaches, compromising privacy and authenticity. IoT devices are vulnerable to being accessed from the Internet; they lack sufficient resources to face cyber-attack threats. Keeping a balance between access control and the devices’ resource consumption has become one of the highest priorities of IoT research. In this paper, we evaluate an access control architecture based on the IAACaaS (IoT application-Scoped Access Control as a Service) model with the aim of protecting IoT devices that communicate using the Publish/Subscribe pattern. IAACaaS is based on the OAuth 2.0 authorization framework, which externalizes the identity and access control infrastructure of applications. In our evaluation, we implement the model using FIWARE Generic Enablers and deploy them for a smart buildings use case with a wireless communication. Then, we compare the performance of two different approaches in the data-sharing between sensors and the Publish/Subscribe broker, using Constrained Application Protocol (CoAP) and Hypertext Transfer Protocol (HTTP) protocols. We conclude that the integration of Publish/Subscribe IoT deployments with IAACaaS adds an extra layer of security and access control without compromising the system’s performance. MDPI 2020-08-04 /pmc/articles/PMC7435769/ /pubmed/32759687 http://dx.doi.org/10.3390/s20154341 Text en © 2020 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).
spellingShingle Article
Pozo, Alejandro
Alonso, Álvaro
Salvachúa, Joaquín
Evaluation of an IoT Application-Scoped Access Control Model over a Publish/Subscribe Architecture Based on FIWARE
title Evaluation of an IoT Application-Scoped Access Control Model over a Publish/Subscribe Architecture Based on FIWARE
title_full Evaluation of an IoT Application-Scoped Access Control Model over a Publish/Subscribe Architecture Based on FIWARE
title_fullStr Evaluation of an IoT Application-Scoped Access Control Model over a Publish/Subscribe Architecture Based on FIWARE
title_full_unstemmed Evaluation of an IoT Application-Scoped Access Control Model over a Publish/Subscribe Architecture Based on FIWARE
title_short Evaluation of an IoT Application-Scoped Access Control Model over a Publish/Subscribe Architecture Based on FIWARE
title_sort evaluation of an iot application-scoped access control model over a publish/subscribe architecture based on fiware
topic Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7435769/
https://www.ncbi.nlm.nih.gov/pubmed/32759687
http://dx.doi.org/10.3390/s20154341
work_keys_str_mv AT pozoalejandro evaluationofaniotapplicationscopedaccesscontrolmodeloverapublishsubscribearchitecturebasedonfiware
AT alonsoalvaro evaluationofaniotapplicationscopedaccesscontrolmodeloverapublishsubscribearchitecturebasedonfiware
AT salvachuajoaquin evaluationofaniotapplicationscopedaccesscontrolmodeloverapublishsubscribearchitecturebasedonfiware