This work formally model AWS IoT Core's components and defines an information flow graph to capture the communication among devices permitted by the access control policies, and builds a finite representation of the graph by leveraging an SMT solver, thus enabling the verification of information flow between devices.
Abstract
Many cloud providers for IoT technologies offer access control mechanisms whose proper configuration is critical for security. However, verifying permissions in isolation is insufficient in a setting where devices have different levels of trust or are compartmentalised in various subsystems. This work analyses IoT access control policies to identify potential security vulnerabilities from unwanted information flow between devices. To this end, we formally model AWS IoT Core's components and define an information flow graph to capture the communication among devices permitted by the access control policies. We build a finite representation of the graph by leveraging an SMT solver, thus enabling the verification of information flow between devices. We implement our approach in a tool called IOT:POKER, and assess it on a realistic scenario and several real-world policies.
Blockchain-enabled Internet of Things (IoT) systems integrate smart contracts with embedded devices to support decentralized device management and access control. Their security therefore depends jointly on the logic of on-chain contracts and off-chain device firmware. Logic flaws in either layer can violate the same s...
Min-Feng Qi, Jia-Lin Li, Tian-Qing Zhu et al.· 0 citations
Internet-of-Things (IoT) devices have become increasingly pervasive across modern society, often performing safety-critical functions. Network attestation – verifying the software state of all devices in a network – is a promising mitigation approach. However, current network attestation schemes suffer from lengthy Tim...
Pavel Frolikov, Youngil Kim, Renascence Tarafder Prapty et al.· GetMobile Mobile Computing a...· 0 citations
FedM, a multi-level formal model designed for context-aware and policy-driven data dissemination in federated IoT environments, is proposed, built upon various access control models and Denning’s research on information flow control, prioritizing the protection and reliability of data flows.
Jakub Sychowiec, Zbigniew Zieliński· Electronics· 0 citations
Health care information systems leverage body area networks (BANs) to provide real-time monitoring and automated medical interventions, significantly enhancing patient care. However, security and privacy concerns present significant barriers to widespread adoption, with broken access control being a considerable risk....
Ramadan Abdunabi, Md Al Amin, Rejina Basnet· International Journal of Inf...· 0 citations
The explosion in number of IoT devices in enterprise network has presented an interesting security problem. The smart cameras, environment monitors, printers, access control units, building controllers, and other devices are commonly placed near corporate devices but are generally less protected by more vulnerable firm...
Zainab Abbass· Al-Noor Journal of Engineeri...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.