Distributed Access Control and Authorization (DACA) for Internet of Things

Parikshit N. Mahalle, Sandesh Mahamure, Poonam N. Railkar, Pankaj R. Chandre

Abstract


In the 21st century, devices surrounding us are
increasing at faster rate and these devices are providing
contextual and adaptive services to all the stake holders. This
paradigm of communication computing which is distributed in
nature is referred as Internet of Things (IoT). Equally, time is
also the crucial factor for any business use cases. To run a
successful business the resource and time need to be
efficiently managed. Now the atomization in all the fields of
engineering helps to save time as well as money. IoT
communication helps to reduce time but now we reach one
step ahead of this traditional communication. This IoT needs
to be intelligent and can be viewed as an intelligent device to
device communication network in which devices are
connected via the Internet. Security in IoT in terms of access
control and authorization is very important. Controlling access
to information is usually done by defining access control
model, which decides who is allowed and who is not. In the
sequel, this paper presents proposed Distributed Access
Control and Authorization (DACA) model for IoT. This paper
also gives idea about challenges and issues faced for
implementation of DACA. Relational calculus based
mathematical model for DACA is also presented and
discussed in the next part of this paper. Implementation of
DACA shows that the local device access time and remote
device access time requires nearly same amount of time which
significant contribution of this paper. This finding proves that
the proposed DACA model is most suited for the IoT.


Full Text:

PDF

References


Bag, G., Mukhtar, H., Shams, S.M.S., Ki Hyung Kim and SeungwhaYoo,

"Inter-PAN Mobility Support for 6LoWPAN", Convergence

and Hybrid Information Technology, 2008. ICCIT '08, Volume 1, 11-

Nov. 2008, pp. 787-792.

Bag, G., Raza, M.T., Mukhtar, H., Akbar, A.H., Shams, S.M.S., Kim,

K-H., Seung-wha Y. and Donghwa K., "Energy-aware and bandwidthefficient

mobility architecture for 6LoWPAN",Military

Communications Conference 2008, pp.1-7

Bag, G., Shams, S.M.S., Akbar, A.H., Raza, H.M.M.T., Ki-Hyung Kim

and Seung-WhaYoo, "Network Assisted Mobility Support for

LoWPAN", Consumer Communications and Networking Conference,

pp. 1-5.

Camilo, T., Pinto, P., Rodrigues, A., Sa Silva, J. and Boavida, F.,

"Mobility management in IP-based Wireless Sensor Networks", World

of Wireless, Mobile and Multimedia Networks, 2008.WoWMoM 2008,

-26 June 2008, pp. 1-8

The DAIDALOS (Designing Advanced network Interfaces for the

Delivery and Administration of Location independent, Optimised

personal Services) Project

The DAMe (Deploying Authorization Mechanisms for Federated

Services in the eduroam Architecture) Project, 2008.

A. Dey, and G. Abowd, "Towards a Better Understanding of Context

and Context-Awareness, ” College of Computing, Georgia Institute of

Technology, Tech. Report GIT-GVU-99-22, 1999.

Granjal, J., Silva, R., Sa Silva, J., and E. Monteiro, "Why is IPSec a

viable option for wireless sensor networks", Wireless and Sensor

Networks Security , 2008.

R. Moskowitz, P. Nikander, P. Jokela, T. Henderson, "Host Identity

Protocol”, RFC 5201, April 2008.

G. López, O. Cánovas, and A. F. Gomez-Skarmeta - "Use of XACML

policies for a network access control service”in Proceedings 4th

International Workshop for Applied PKI, IWAP 05. IOS Press, 2005

D. Johnson, C. Perkins, J. Arkko, Support in IPv6”, RFC 3775, June

Mukhtar, H., Kim Kang-Myo, Chaudhry, S.A., Akbar, A.H., Kim Ki-

Hyung and Seung-WhaYoo, "LNMP-Management architecture for

IPv6 based low-power wireless Personal Area Networks (6LoWPAN)",

Network Operations and Management Symposium, 2008. NOMS 2008,

-11 April 2008, pp. 417-424.

Mayer, C., "Security and Privacy Challenges in the IoT”,WowKivs,

Electronic Communications of the EASST, Volume 17, 2009, Germany

J. Rosenberg, H. Schulzrinne, G. Camarillo, A. Johnston, J. Peterson, R.

Sparks, M. Handley, E. Schooler, "SIP:Session Initiation Protocol”,

RFC 3261, June 2002.

E. Wedlund, H. Schulzrinne, "Mobility support using SIP”, Second

ACM/IEEE International Conference on Wireless and Mobile

Multimedia, 1999.

M.Weiser, "The Computer for the Twenty-First Century,”Scientific

American, pp. 94-104, 19 [Wss07] Web Services Security

Specifications Index Page on

MSDN.http://msdn.microsoft.com/enus/library/ms951273.aspx

OASIS.eXtensible Access Control Markup Language (XACML)

Version 3.0, February 2009. Working Draft 8.

P. Saint Andre (editor), "Extensible Messaging and Presence Protocol

(XMPP): Core", RFC 3920, IETF, October, 2004

OASIS Extensible Resource Identifier (XRI) TC,

N. Zhang. E-Infrastructure Security: An Investigation of Authentication

Levels of Assurance (LoAs), Open Grid Forum, 2007.


Refbacks

  • There are currently no refbacks.


Copyright © IJETT, International Journal on Emerging Trends in Technology