Skip to content

Checking Information Flow in Cloud-based IoT Access Control Policies (Extended Version)

Jul 2026 · arXiv.org · Vol abs/2607.28088 · 0 citations · 35 references
Computer Science

TL;DR

This work formally model AWS IoT Core's components and defines an information flow graph to capture the communication among devices permitted by the access control policies, and builds a finite representation of the graph by leveraging an SMT solver, thus enabling the verification of information flow between devices.

Abstract

Many cloud providers for IoT technologies offer access control mechanisms whose proper configuration is critical for security. However, verifying permissions in isolation is insufficient in a setting where devices have different levels of trust or are compartmentalised in various subsystems. This work analyses IoT access control policies to identify potential security vulnerabilities from unwanted information flow between devices. To this end, we formally model AWS IoT Core's components and define an information flow graph to capture the communication among devices permitted by the access control policies. We build a finite representation of the graph by leveraging an SMT solver, thus enabling the verification of information flow between devices. We implement our approach in a tool called IOT:POKER, and assess it on a realistic scenario and several real-world policies.

View source

Similar papers

Preprint Sep 2026

Detecting Logic Vulnerabilities Across the Contract and Device Layers of Blockchain-Enabled IoT With Multi-Agent Heterogeneous Graph Attention

Blockchain-enabled Internet of Things (IoT) systems integrate smart contracts with embedded devices to support decentralized device management and access control. Their security therefore depends jointly on the logic of on-chain contracts and off-chain device firmware. Logic flaws in either layer can violate the same s...

Min-Feng Qi, Jia-Lin Li, Tian-Qing Zhu et al. · 0 citations
Jul 2026

Resilient Software Integrity for IoT Networks

Internet-of-Things (IoT) devices have become increasingly pervasive across modern society, often performing safety-critical functions. Network attestation – verifying the software state of all devices in a network – is a promising mitigation approach. However, current network attestation schemes suffer from lengthy Tim...

Pavel Frolikov, Youngil Kim, Renascence Tarafder Prapty et al. · 0 citations
Open access Aug 2026

A Formal Model for Secure and Context-Based Data Dissemination in Federated Special IoT Environments

FedM, a multi-level formal model designed for context-aware and policy-driven data dissemination in federated IoT environments, is proposed, built upon various access control models and Denning’s research on information flow control, prioritizing the protection and reliability of data flows.

Jakub Sychowiec, Zbigniew Zieliński · 0 citations
Open access Jul 2026

Enforcing authorization policy in body area networks: a blockchain and smart contract-based approach for integrity assurance

Health care information systems leverage body area networks (BANs) to provide real-time monitoring and automated medical interventions, significantly enhancing patient care. However, security and privacy concerns present significant barriers to widespread adoption, with broken access control being a considerable risk....

Ramadan Abdunabi, Md Al Amin, Rejina Basnet · 0 citations
Open access Jul 2026

Secure Integration of IoT Devices into Enterprise NetworksUsing VLAN Segmentation and Access Control Policies

The explosion in number of IoT devices in enterprise network has presented an interesting security problem. The smart cameras, environment monitors, printers, access control units, building controllers, and other devices are commonly placed near corporate devices but are generally less protected by more vulnerable firm...

Zainab Abbass · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.