The Internet of Things (IoT) is a world-wide network of heterogeneous interconnected objects, uniquely addressable, which are based on standard communication protocols and can interact with each other in order to share information based on communication protocol. Moreover, IoT is also one of the technological factors that enable the Internet of Everything (IoE) which includes not only Things, but also People, Data and Processes. Security of IoT and IoE is a major aspect nowadays. The communication protocols that are used on this area lack of mechanisms that enforce policies continuously and control the access to the resources. In addition to the previous, the difference of the communication protocols in terms of architecture and characteristics has the effect that information sharing is difficult to be controlled. Thus, there is the challenge of enhancing the security features of IoT protocols with a single mechanism. For this reason, we present a distributed Usage Control (UCON) model. UCON enhances Attribute Based Access Control (ABAC) models in two novel aspects: continuity of control and mutability of attributes. In order to demonstrate the viability of our approach, we present how UCON can be added on the most common protocols, how we can enhance the interoperability of UCON for IoE services, and finally we present the hierarchical UCON accompanied by policy simplification methods.

Usage Control in the Internet of Everything

RIZOS, ATHANASIOS
2020

Abstract

The Internet of Things (IoT) is a world-wide network of heterogeneous interconnected objects, uniquely addressable, which are based on standard communication protocols and can interact with each other in order to share information based on communication protocol. Moreover, IoT is also one of the technological factors that enable the Internet of Everything (IoE) which includes not only Things, but also People, Data and Processes. Security of IoT and IoE is a major aspect nowadays. The communication protocols that are used on this area lack of mechanisms that enforce policies continuously and control the access to the resources. In addition to the previous, the difference of the communication protocols in terms of architecture and characteristics has the effect that information sharing is difficult to be controlled. Thus, there is the challenge of enhancing the security features of IoT protocols with a single mechanism. For this reason, we present a distributed Usage Control (UCON) model. UCON enhances Attribute Based Access Control (ABAC) models in two novel aspects: continuity of control and mutability of attributes. In order to demonstrate the viability of our approach, we present how UCON can be added on the most common protocols, how we can enhance the interoperability of UCON for IoE services, and finally we present the hierarchical UCON accompanied by policy simplification methods.
25-feb-2020
Italiano
access control
internet of everything
internet of things
protocol security
usage control
Martinelli, Fabio
Saracino, Andrea
File in questo prodotto:
File Dimensione Formato  
Athanasios_Rizos_Description_of_Activities_During_PhD_studies_pr_Version.pdf

accesso aperto

Tipologia: Altro materiale allegato
Licenza: Tutti i diritti riservati
Dimensione 185.22 kB
Formato Adobe PDF
185.22 kB Adobe PDF Visualizza/Apri
Athanasios_Rizos_Thesis_FInal_Version_Revised.pdf

accesso aperto

Tipologia: Altro materiale allegato
Licenza: Tutti i diritti riservati
Dimensione 4.4 MB
Formato Adobe PDF
4.4 MB Adobe PDF Visualizza/Apri

I documenti in UNITESI sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.14242/149857
Il codice NBN di questa tesi è URN:NBN:IT:UNIPI-149857