User-trust centric lightweight access control for smart IoT crowd sensing applications in healthcare systems

Q1 Social Sciences
Zahid Mahmood, Zeeshan Ashraf, Muddesar Iqbal, Beenish Farooq
{"title":"User-trust centric lightweight access control for smart IoT crowd sensing applications in healthcare systems","authors":"Zahid Mahmood, Zeeshan Ashraf, Muddesar Iqbal, Beenish Farooq","doi":"10.1007/s00779-024-01803-x","DOIUrl":null,"url":null,"abstract":"<p>The Internet of Things (IoT) enables healthcare systems to handle emergencies, where multiple authorities interact to perform tasks. Prevention of unauthorized access and defining access domains for legitimate users are crucial. Attribute-Based Access Control System (ABACS) techniques play a vital role in defining boundaries in a multi-agent environment. However, adopting traditional ABAC in IoT-based resource-constrained networks is not feasible. This research analyzes the effects of attributes as key performance metrics, including execution time, memory overhead, and computational complexities. To address these challenges, this research proposes a Physical-Social Attributes Access Control Policy (PS-ABACS) framework that secures Multiparty Computation (SMC), symmetric encryption, and randomization-based access control methods. PS-ABASC introduces a lightweight two-party set intersection technique to generate an access policy. The analysis shows that the proposed technique is efficient in computing access policy and session key generation, and less number of attributes based on randomness characteristics is appropriate for resource-constrained networks. Moreover, it demonstrates advancements by reducing memory usage up to 0.048 KB for 60 attributes. The framework generates session keys proficiently, encrypts data, and minimizes computational expenses through a randomized attribute vector. In terms of communication overhead, the framework surpasses expectations by supporting up to 100 attributes, resulting in a reduction of transmission costs to 1120 bits. Overall, this framework improves security, reduces resource consumption, and enhances data exchange efficiency in IoT ecosystems.</p>","PeriodicalId":54628,"journal":{"name":"Personal and Ubiquitous Computing","volume":"19 1","pages":""},"PeriodicalIF":0.0000,"publicationDate":"2024-05-06","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Personal and Ubiquitous Computing","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1007/s00779-024-01803-x","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"Social Sciences","Score":null,"Total":0}
引用次数: 0

Abstract

The Internet of Things (IoT) enables healthcare systems to handle emergencies, where multiple authorities interact to perform tasks. Prevention of unauthorized access and defining access domains for legitimate users are crucial. Attribute-Based Access Control System (ABACS) techniques play a vital role in defining boundaries in a multi-agent environment. However, adopting traditional ABAC in IoT-based resource-constrained networks is not feasible. This research analyzes the effects of attributes as key performance metrics, including execution time, memory overhead, and computational complexities. To address these challenges, this research proposes a Physical-Social Attributes Access Control Policy (PS-ABACS) framework that secures Multiparty Computation (SMC), symmetric encryption, and randomization-based access control methods. PS-ABASC introduces a lightweight two-party set intersection technique to generate an access policy. The analysis shows that the proposed technique is efficient in computing access policy and session key generation, and less number of attributes based on randomness characteristics is appropriate for resource-constrained networks. Moreover, it demonstrates advancements by reducing memory usage up to 0.048 KB for 60 attributes. The framework generates session keys proficiently, encrypts data, and minimizes computational expenses through a randomized attribute vector. In terms of communication overhead, the framework surpasses expectations by supporting up to 100 attributes, resulting in a reduction of transmission costs to 1120 bits. Overall, this framework improves security, reduces resource consumption, and enhances data exchange efficiency in IoT ecosystems.

Abstract Image

为医疗保健系统中的智能物联网人群感知应用提供以用户信任为中心的轻量级访问控制
物联网(IoT)使医疗保健系统能够处理紧急事件,在这种情况下,多个机构交互执行任务。防止未经授权的访问和为合法用户定义访问域至关重要。基于属性的访问控制系统(ABACS)技术在多代理环境中定义边界方面发挥着重要作用。然而,在基于物联网的资源受限网络中采用传统 ABAC 并不可行。本研究分析了作为关键性能指标的属性的影响,包括执行时间、内存开销和计算复杂性。为应对这些挑战,本研究提出了一种物理-社会属性访问控制策略(PS-ABACS)框架,可确保多方计算(SMC)、对称加密和基于随机化的访问控制方法的安全。PS-ABASC 引入了一种轻量级的双方集合交集技术来生成访问策略。分析表明,所提出的技术在计算访问策略和生成会话密钥方面是高效的,而且基于随机性特征的属性数量较少,适用于资源受限的网络。此外,60 个属性的内存使用量最多可减少到 0.048 KB,这也证明了该技术的先进性。该框架能熟练地生成会话密钥、加密数据,并通过随机属性向量最大限度地减少计算开销。在通信开销方面,该框架支持多达 100 个属性,从而将传输成本降至 1120 位,超出了预期。总体而言,该框架提高了安全性,减少了资源消耗,并提高了物联网生态系统中的数据交换效率。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
Personal and Ubiquitous Computing
Personal and Ubiquitous Computing 工程技术-电信学
CiteScore
6.60
自引率
0.00%
发文量
35
审稿时长
6-12 weeks
期刊介绍: Personal and Ubiquitous Computing publishes peer-reviewed multidisciplinary research on personal and ubiquitous technologies and services. The journal provides a global perspective on new developments in research in areas including user experience for advanced digital technologies, the Internet of Things, big data, social technologies and mobile and wearable devices.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信