首页> 外文会议>2018 IEEE Industrial Cyber-Physical Systems >An AAA solution for securing industrial IoT devices using next generation access control
【24h】

An AAA solution for securing industrial IoT devices using next generation access control

机译:使用下一代访问控制保护工业物联网设备的AAA解决方案

获取原文
获取原文并翻译 | 示例

摘要

Industry 4.0 is advancing the use of Internet of Things (IoT) devices in industrial applications, which enables efficient device-to-device (D2D) communication. However, these devices are often heterogeneous in nature, i.e. from different manufacturers, use different protocols, etc. and adds requirements such as security, interoperability, etc. To address these requirements, the Service-Oriented Architecture-Based (SOA) Arrowhead Framework was previously proposed using the concept of local clouds. These local clouds provide a set of mandatory and support core systems to enable industrial automation applications. One of these mandatory core systems is an Authentication, Authorisation and Accounting (AAA) system, which is used to authenticate and provide access control to the devices in a local cloud. In an industrial context, with multiple stakeholders, the AAA must support fine-grain access control. For example, in a distributed control loop, a controller should only have read access to its sensor such as a flow meter and write access to its actuator, such as a valve. The controller should not have access to any other information besides what is needed to implement the desired functionality. In this work, an NGAC-based AAA solution to achieve fine-grain service level access control between IoT devices has been proposed and implemented. The solution is presented using a district heating use case.
机译:工业4.0促进了工业应用中物联网(IoT)设备的使用,从而实现了有效的设备到设备(D2D)通信。但是,这些设备通常本质上是异构的,即来自不同的制造商,使用不同的协议等,并增加了诸如安全性,互操作性等要求。为了满足这些要求,基于服务的基于架构(SOA)的箭头框架是先前提出使用局部云的概念。这些本地云提供了一组强制性和支持性的核心系统,以支持工业自动化应用程序。这些强制性核心系统之一是身份验证,授权和计费(AAA)系统,用于对本地云中的设备进行身份验证并提供访问控制。在工业环境中,具有多个利益相关者的AAA必须支持细粒度访问控制。例如,在分布式控制回路中,控制器只能对其传感器(例如流量计)进行读取访问,而对其执行器(如阀门)进行写访问。除了实现所需功能所需的信息外,控制器不应访问任何其他信息。在这项工作中,已经提出并实施了基于NGAC的AAA解决方案,以实现物联网设备之间的细粒度服务级别访问控制。该解决方案使用区域供热用例进行介绍。

著录项

  • 来源
  • 会议地点 St. Petersburg(RU)
  • 作者单位

    Dept. of Computer Science, Electrical and Space Engineering, Luleå University of Technology, Luleå, Sweden 97187;

    Dept. of Computer Science, Electrical and Space Engineering, Luleå University of Technology, Luleå, Sweden 97187;

    Dept. of Computer Science, Electrical and Space Engineering, Luleå University of Technology, Luleå, Sweden 97187;

    Dept. of Computer Science, Electrical and Space Engineering, Luleå University of Technology, Luleå, Sweden 97187;

    Dept. of Computer Science, Electrical and Space Engineering, Luleå University of Technology, Luleå, Sweden 97187;

    The Open Group, Apex Plaza, Forbury Road, Reading, Berkshire RG1 1AX, UK;

  • 会议组织
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Authentication; Authorization; Protocols; Cloud computing; Standards;

    机译:身份验证;授权;协议;云计算;标准;;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号