物联网环境下的情景感知碎玻璃访问控制系统

Dries Van Bael, Shirin Kalantari, A. Put, B. Decker
{"title":"物联网环境下的情景感知碎玻璃访问控制系统","authors":"Dries Van Bael, Shirin Kalantari, A. Put, B. Decker","doi":"10.1109/IOTSMS52051.2020.9340209","DOIUrl":null,"url":null,"abstract":"In Internet of Things (IoT) environments, sensors measure and quantify properties of physical locations, objects and even people. Context-aware access control systems include this data in the decision making process to improve their accuracy and precision. However, access control systems can fail when unexpected situations occur for which no access rules have been defined. One solution implemented by access control systems for critical infrastructure (e.g. a hospital, factory production line), is to break the glass in case of emergency to temporarily obtain the necessary privileges. During this process, sufficient non-repudiation evidence must be collected, which is audited at a later stage to verify whether the emergency access was justified. Shortcomings of existing Break Glass models are twofold: firstly, Break Glass is mostly considered as a static process for which the activation requirements and granted privileges are not adapted to the context of the emergency situation; secondly, a closed environment such as a hospital with authenticated caregivers is generally assumed, which is not realistic for open environments.In this paper, we present a context-aware Break Glass system architecture, which uses contextual information to detect ongoing emergencies, and allows the activation requirements and temporary privileges to be be adapted to the current situation or emergency. Furthermore, the system includes a fail-safe operation to disable the Break Glass activation if the emergency was wrongly detected. Our prototype shows the soundness of the design and its practical feasibility to be used in time-critical scenarios.","PeriodicalId":147136,"journal":{"name":"2020 7th International Conference on Internet of Things: Systems, Management and Security (IOTSMS)","volume":"85 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":"{\"title\":\"A Context-Aware Break Glass Access Control System for IoT Environments\",\"authors\":\"Dries Van Bael, Shirin Kalantari, A. Put, B. Decker\",\"doi\":\"10.1109/IOTSMS52051.2020.9340209\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"In Internet of Things (IoT) environments, sensors measure and quantify properties of physical locations, objects and even people. Context-aware access control systems include this data in the decision making process to improve their accuracy and precision. However, access control systems can fail when unexpected situations occur for which no access rules have been defined. One solution implemented by access control systems for critical infrastructure (e.g. a hospital, factory production line), is to break the glass in case of emergency to temporarily obtain the necessary privileges. During this process, sufficient non-repudiation evidence must be collected, which is audited at a later stage to verify whether the emergency access was justified. Shortcomings of existing Break Glass models are twofold: firstly, Break Glass is mostly considered as a static process for which the activation requirements and granted privileges are not adapted to the context of the emergency situation; secondly, a closed environment such as a hospital with authenticated caregivers is generally assumed, which is not realistic for open environments.In this paper, we present a context-aware Break Glass system architecture, which uses contextual information to detect ongoing emergencies, and allows the activation requirements and temporary privileges to be be adapted to the current situation or emergency. Furthermore, the system includes a fail-safe operation to disable the Break Glass activation if the emergency was wrongly detected. Our prototype shows the soundness of the design and its practical feasibility to be used in time-critical scenarios.\",\"PeriodicalId\":147136,\"journal\":{\"name\":\"2020 7th International Conference on Internet of Things: Systems, Management and Security (IOTSMS)\",\"volume\":\"85 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2020-10-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"3\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2020 7th International Conference on Internet of Things: Systems, Management and Security (IOTSMS)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/IOTSMS52051.2020.9340209\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 7th International Conference on Internet of Things: Systems, Management and Security (IOTSMS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/IOTSMS52051.2020.9340209","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

摘要

在物联网(IoT)环境中,传感器测量和量化物理位置、物体甚至人的属性。上下文感知访问控制系统将这些数据纳入决策过程,以提高其准确性和精度。但是,当没有定义访问规则的意外情况发生时,访问控制系统可能会失效。关键基础设施(如医院、工厂生产线)的访问控制系统实施的一种解决方案是,在紧急情况下打破玻璃,以暂时获得必要的特权。在这一过程中,必须收集足够的不可否认证据,并在稍后阶段审计这些证据,以核实紧急访问是否合理。现有的破玻璃模型存在两个缺点:首先,破玻璃模型大多被认为是一个静态过程,其激活要求和授予的特权不适应紧急情况的背景;其次,通常假设一个封闭的环境,例如拥有经过身份验证的护理人员的医院,这对于开放环境来说是不现实的。在本文中,我们提出了一个上下文感知的破碎玻璃系统架构,它使用上下文信息来检测正在进行的紧急情况,并允许激活需求和临时特权适应当前的情况或紧急情况。此外,该系统还包括一个故障安全操作,可以在错误检测到紧急情况时禁用“破碎玻璃”激活。我们的原型显示了设计的合理性和在时间紧迫的情况下使用的实际可行性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
A Context-Aware Break Glass Access Control System for IoT Environments
In Internet of Things (IoT) environments, sensors measure and quantify properties of physical locations, objects and even people. Context-aware access control systems include this data in the decision making process to improve their accuracy and precision. However, access control systems can fail when unexpected situations occur for which no access rules have been defined. One solution implemented by access control systems for critical infrastructure (e.g. a hospital, factory production line), is to break the glass in case of emergency to temporarily obtain the necessary privileges. During this process, sufficient non-repudiation evidence must be collected, which is audited at a later stage to verify whether the emergency access was justified. Shortcomings of existing Break Glass models are twofold: firstly, Break Glass is mostly considered as a static process for which the activation requirements and granted privileges are not adapted to the context of the emergency situation; secondly, a closed environment such as a hospital with authenticated caregivers is generally assumed, which is not realistic for open environments.In this paper, we present a context-aware Break Glass system architecture, which uses contextual information to detect ongoing emergencies, and allows the activation requirements and temporary privileges to be be adapted to the current situation or emergency. Furthermore, the system includes a fail-safe operation to disable the Break Glass activation if the emergency was wrongly detected. Our prototype shows the soundness of the design and its practical feasibility to be used in time-critical scenarios.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信