首页> 外文会议>IEEE Security and Privacy Workshops >Never Ending Story: Authentication and Access Control Design Flaws in Shared IoT Devices
【24h】

Never Ending Story: Authentication and Access Control Design Flaws in Shared IoT Devices

机译:永无止境的故事:共享物联网设备的身份验证和访问控制设计缺陷

获取原文

摘要

Internet-of-Things (IoT) devices implement weak authentication and access control schemes. The on-demand nature of IoT devices requires a responsive communications channel, which is often at odds with thorough authentication and access control. This paper seeks to better understand IoT device security by examining the design of authentication and access control schemes. In this work, we explore the challenge of propagating credential revocation and access control list modifications in a shared IoT ecosystem. We evaluate the vulnerability of 19 popular security cameras and doorbells against a straightforward user-interface bound adversary attack. Our results demonstrate that 16 of 19 surveyed devices suffer from flaws that enable unauthorized access after credential modification or revocation. We conclude by discussing these findings and propose a means for balancing authentication and access control schemes while still offering responsive communications channels.
机译:Internet-of-Mistor(IoT)设备实现弱认证和访问控制方案。物联网设备的按需性质需要响应通信信道,该信道通常具有彻底认证和访问控制的赔率。本文旨在通过检查认证和访问控制方案的设计更好地了解IoT设备安全性。在这项工作中,我们探讨了共享物联网生态系统中传播凭证撤销和访问控制列表修改的挑战。我们评估19个受欢迎的安全摄像头和门铃的脆弱性,以防止直接的用户界面绑定的对手攻击。我们的结果表明,19个受访设备中有16个受到缺陷,可在凭证修改或撤销后未经授权的访问。我们通过讨论这些调查结果来结论,并提出用于平衡认证和访问控制方案的手段,同时仍提供响应通信信道。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号