首页> 外文会议>Annual IEEE International Conference on Sensing, Communication, and Networking >Delegation-based authentication and authorization for the IP-based Internet of Things
【24h】

Delegation-based authentication and authorization for the IP-based Internet of Things

机译:基于委托的身份验证和基于IP的物联网授权

获取原文

摘要

IP technology for resource-constrained devices enables transparent end-to-end connections between a vast variety of devices and services in the Internet of Things (IoT). To protect these connections, several variants of traditional IP security protocols have recently been proposed for standardization, most notably the DTLS protocol. In this paper, we identify significant resource requirements for the DTLS handshake when employing public-key cryptography for peer authentication and key agreement purposes. These overheads particularly hamper secure communication for memory-constrained devices. To alleviate these limitations, we propose a delegation architecture that offloads the expensive DTLS connection establishment to a delegation server. By handing over the established security context to the constrained device, our delegation architecture significantly reduces the resource requirements of DTLS-protected communication for constrained devices. Additionally, our delegation architecture naturally provides authorization functionality when leveraging the central role of the delegation server in the initial connection establishment. Hence, in this paper, we present a comprehensive, yet compact solution for authentication, authorization, and secure data transmission in the IP-based IoT. The evaluation results show that compared to a public-key-based DTLS handshake our delegation architecture reduces the memory overhead by 64 %, computations by 97 %, network transmissions by 68 %.
机译:资源受限设备的IP技术可在物联网(IoT)中的各种设备和服务之间实现透明的端到端连接。为了保护这些连接,最近已经提出了几种传统IP安全协议的变体进行标准化,其中最引人注目的是DTLS协议。在本文中,当使用公共密钥加密进行对等身份验证和密钥协商时,我们确定了DTLS握手的大量资源需求。这些开销特别妨碍了内存受限设备的安全通信。为了减轻这些限制,我们提出了一种委托体系结构,该体系结构将昂贵的DTLS连接建立卸载到了委托服务器上。通过将已建立的安全上下文移交给受约束的设备,我们的委托体系结构显着降低了受约束设备受DTLS保护的通信的资源需求。此外,当在初始连接建立中利用委派服务器的中心角色时,我们的委派架构自然会提供授权功能。因此,在本文中,我们提出了一个全面而紧凑的解决方案,用于基于IP的IoT中的身份验证,授权和安全数据传输。评估结果表明,与基于公钥的DTLS握手相比,我们的委派体系结构将内存开销减少了64%,计算量减少了97%,网络传输量减少了68%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号