首页> 外文会议>IEEE International Smart Cities Conference >Toward Semi-Automated Role Mapping for IoT Systems in Smart Cities
【24h】

Toward Semi-Automated Role Mapping for IoT Systems in Smart Cities

机译:走向智慧城市中物联网系统的半自动角色映射

获取原文

摘要

Some smart city applications may be dynamic and involve IoT devices from multiple domains that are not aware of each other in advance. How to perform access control in such open scenarios is a challenge. Attribute based access control (ABAC) and trust-based access control (TBAC) have been considered in the literature for IoT systems, but they do not consider the potential inconsistency of attributes or trusts across different domains. Cross domain alignment has been considered for role-based access control (RBAC), but they rely on a manual process, which is not feasible when cross domain accesses happen dynamically and the access rights have to be validated dynamically.We introduce a semi-automated role mapping process in smart city settings to enable access control of dynamic accesses. When entities from domain arrive in domain, similarities between the roles in to the roles in are evaluated and the potential role mappings for the entities in are computed. The system then informs the security officers to make approval decisions for these new mappings. In urgent situations, the automatically derived role mappings may be used directly to provide timely access control. Activities based on role mappings without authority approvals are tracked and in case some mappings violate security rules, mitigation actions will be taken. We use a disaster relief scenario as an example to illustrate our approach and show its feasibility.
机译:一些智能城市应用程序可能是动态的,并且涉及来自多个域的IoT设备,这些设备事先并不相互了解。在这样的开放场景中如何执行访问控制是一个挑战。物联网系统的文献中已经考虑了基于属性的访问控制(ABAC)和基于信任的访问控制(TBAC),但它们并未考虑跨不同域的属性或信任的潜在矛盾。基于角色的访问控制(RBAC)已经考虑了跨域对齐,但是它们依赖于手动过程,当跨域访问动态发生且访问权限必须动态验证时这是不可行的。智慧城市设置中的角色映射过程,以实现对动态访问的访问控制。当来自领域的实体到达领域时,将评估角色与角色中的角色之间的相似性,并计算角色中潜在角色的映射。然后,系统通知安全员为这些新映射做出批准决策。在紧急情况下,自动派生的角色映射可以直接用于提供及时的访问控制。跟踪未经授权批准的基于角色映射的活动,并在某些映射违反安全规则的情况下,将采取缓解措施。我们以救灾场景为例来说明我们的方法并显示其可行性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号