Heracles: Scalable, Fine-Grained Access Control for Internet-of-Things in Enterprise Environments

Qian Zhou, Mohammed Elbadry, Fan Ye, Yuanyuan Yang

Research output: Chapters, Conference Papers, Creative and Literary WorksRGC 32 - Refereed conference paper (with host publication)peer-review

23 Citations (Scopus)

Abstract

Scalable, fine-grained access control for Internet-of-Things is needed in enterprise environments, where thousands of subjects need to access possibly one to two orders of magnitude more objects. Existing solutions offer all-or-nothing access, or require all access to go through a cloud backend, greatly impeding access granularity, robustness and scale. In this paper, we propose Heracles, an IoT access control system that achieves robust, fine-grained access control at enterprise scale. Heracles adopts a capability-based approach using secure, unforgeable tokens that describe the authorizations of subjects, to either individual or collections of objects in single or bulk operations. It has a 3-tier architecture to provide centralized policy and distributed execution desired in enterprise environments, and delegated operations for responsiveness of resource-constrained objects. Extensive security analysis and performance evaluation on a testbed prove that Heracles achieves robust, responsive, fine-Qrained access control in large scale enterprise environments. © 2018 IEEE.
Original languageEnglish
Title of host publicationINFOCOM 2018 - IEEE Conference on Computer Communications
PublisherIEEE
Pages1772-1780
Volume2018-April
ISBN (Print)9781538641286
DOIs
Publication statusPublished - 8 Oct 2018
Externally publishedYes
Event2018 IEEE Conference on Computer Communications, INFOCOM 2018 - Honolulu, United States
Duration: 15 Apr 201819 Apr 2018

Publication series

NameProceedings - IEEE INFOCOM
Volume2018-April
ISSN (Print)0743-166X

Conference

Conference2018 IEEE Conference on Computer Communications, INFOCOM 2018
PlaceUnited States
CityHonolulu
Period15/04/1819/04/18

Bibliographical note

Publication details (e.g. title, author(s), publication statuses and dates) are captured on an “AS IS” and “AS AVAILABLE” basis at the time of record harvesting from the data source. Suggestions for further amendments or supplementary information can be sent to [email protected].

Fingerprint

Dive into the research topics of 'Heracles: Scalable, Fine-Grained Access Control for Internet-of-Things in Enterprise Environments'. Together they form a unique fingerprint.

Cite this