首页> 外文学位 >Securing the Internet of Things via Locally Centralized, Globally Distributed Authentication and Authorization
【24h】

Securing the Internet of Things via Locally Centralized, Globally Distributed Authentication and Authorization

机译:通过本地集中的,全球分布式的身份验证和授权来保护物联网

获取原文
获取原文并翻译 | 示例

摘要

The Internet of Things (IoT) brings about benefits through interaction with humans and the physical world using a variety of technologies including sensors, actuators, controls, mobile devices and cloud computing. However, these benefits can be hampered by malicious interventions of attackers when the IoT is not protected properly. Hence, authentication and authorization comprise critical parts of basic security processes and are sorely needed in the IoT. Characteristics of the IoT render existing security measures such as SSL/TLS (Secure Socket Layer/Transport Layer Security) and network architectures ineffective against emerging networks and devices. Heterogeneity, scalability, and operation in open environments are serious challenges that need to be addressed to make the IoT secure. Moreover, many existing cloud-based solutions for the security of the IoT rely too much on remote servers over possibly vulnerable Internet connections.;This dissertation presents locally centralized, globally distributed authentication and authorization to address the IoT security challenges. Centralized security solutions make system management simpler and enable agile responses to failures or threats, while having a single point of failure and making it challenging to scale. Solutions based on distributed trust are more resilient and scalable, but they increase each entity's overhead and are more difficult to manage. The proposed approach leverages an emerging network architecture based on edge computers by using them as locally centralized points for authentication and authorization of the IoT. This allows heterogeneity and an agile access control to be handled locally, without having to depend on remote servers. Meanwhile, the proposed approach has a globally distributed architecture throughout the Internet for robustness and scalability.;The proposed approach is realized as SST (Secure Swarm Toolkit), an open-source toolkit for construction and deployment of an authentication and authorization service infrastructure for the IoT, for validation of locally centralized, globally distributed trust management. SST includes a local authorization entity called Auth to be deployed on edge computers which are used as a gateway for authorization as well as for the Internet. Software building blocks provided by SST, called accessors, enable IoT developers to readily integrate their IoT applications with the SST infrastructure, by encapsulating cryptographic operations and key management. In addition to protection against network-based intruders, SST supports a secure migration mechanism for enhancing availability in the case of failures or threats of denial-of-service attacks, based on globally distributed and trusted Auths.;For evaluation, I provide a formal security analysis using an automated verification tool to rigorously show that SST provides necessary security guarantees. I also demonstrate the scalability of the proposed approach with a mathematical analysis, as well as experiments to evaluate security overhead of network entities under different security profiles supported by SST. The effectiveness of the secure migration technique is shown through a case study and simulation based on a concrete IoT application.
机译:物联网(IoT)通过使用包括传感器,执行器,控件,移动设备和云计算在内的多种技术与人类和物理世界进行交互,带来了好处。但是,如果物联网没有得到适当的保护,攻击者的恶意干预可能会阻止这些好处。因此,身份验证和授权是基本安全流程的关键部分,在物联网中非常需要。物联网的特性使现有的安全措施(例如SSL / TLS(安全套接字层/传输层安全性)和网络体系结构)对新兴的网络和设备无效。异构性,可扩展性和开放环境中的操作是严重的挑战,需要确保物联网安全。此外,许多现有的基于云的物联网安全解决方案都过于依赖可能通过易受攻击的Internet连接的远程服务器。本文提出了本地集中,全球分布的身份验证和授权来应对物联网安全挑战。集中式安全解决方案使系统管理更简单,并能够对故障或威胁做出敏捷响应,同时具有单点故障并使其难以扩展。基于分布式信任的解决方案更具弹性和可扩展性,但它们增加了每个实体的开销,并且更难管理。所提出的方法通过将边缘计算机用作物联网的身份验证和授权的本地集中点,来利用基于边缘计算机的新兴网络体系结构。这样就可以在本地处理异构性和敏捷的访问控制,而不必依赖远程服务器。同时,该提议的方法具有遍及Internet的全局分布式体系结构,以实现鲁棒性和可扩展性。该提议的方法实现为SST(安全群工具包),这是一种用于构建和部署用于身份验证和授权服务基础结构的开源工具包。物联网,用于验证本地集中的,全球分布的信任管理。 SST包含一个称为Auth的本地授权实体,该实体将部署在边缘计算机上,这些计算机将用作授权网关以及Internet。 SST提供的称为访问器的软件构建块,通过封装加密操作和密钥管理,使IoT开发人员可以轻松地将其IoT应用程序与SST基础架构集成。除了防范基于网络的入侵者,SST还基于全球分布和受信任的Auth支持安全的迁移机制,以在出现故障或拒绝服务攻击威胁时增强可用性。使用自动验证工具进行的安全分析严格显示SST提供了必要的安全保证。我还将通过数学分析论证所提出方法的可扩展性,以及通过实验来评估SST支持的不同安全配置文件下网络实体的安全开销。通过基于具体物联网应用的案例研究和仿真,可以证明安全迁移技术的有效性。

著录项

  • 作者

    Kim, Hokeun.;

  • 作者单位

    University of California, Berkeley.;

  • 授予单位 University of California, Berkeley.;
  • 学科 Computer science.;Computer engineering.;Electrical engineering.
  • 学位 Ph.D.
  • 年度 2017
  • 页码 117 p.
  • 总页数 117
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号