首页> 外文会议>International Workshop on Secure Internet of Things >Securing Complex IoT Platforms with Token Based Access Control and Authenticated Key Establishment
【24h】

Securing Complex IoT Platforms with Token Based Access Control and Authenticated Key Establishment

机译:通过基于令牌的访问控制和经过身份验证的密钥建立来保护复杂的物联网平台

获取原文

摘要

In this paper we propose a new authorization and authentication framework for the IoT that combines the security model of OAuth 1.0a with the lightweight building blocks of ACE. By designing self-securing tokens the security of the framework no longer depends on the security of the network stack. We use basic PKI functionalities to bootstrap a chain-of-trust between the devices which simplifies future token exchanges. Finally, we propose an alternate key establishment scheme for use cases where devices cannot directly communicate. We test our proposal by implementing the critical aspects on a STM32L4 microcontroller. The results indicate that our framework guarantees a strong level of security for IoT devices with basic asymmetric cryptography capabilities.
机译:在本文中,我们为IoT提出了一个新的授权和认证框架,该框架将OAuth 1.0a的安全模型与ACE的轻量级构建块相结合。通过设计自保护令牌,框架的安全性不再取决于网络堆栈的安全性。我们使用基本的PKI功能来引导设备之间的信任链,从而简化了以后的令牌交换。最后,针对设备无法直接通信的用例,我们提出了另一种密钥建立方案。我们通过在STM32L4微控制器上实现关键方面来测试我们的建议。结果表明,我们的框架通过基本的非对称加密功能为物联网设备保证了高度的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号