Security-Aware Multi-User Architecture for IoT
2021 (English)In: 2021 IEEE 21ST INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY AND SECURITY (QRS 2021), Institute of Electrical and Electronics Engineers Inc. , 2021, p. 102-113Conference paper, Published paper (Refereed)
Abstract [en]
IoT systems, such as in smart cities or hospitals, generate data that may be subject to different security classifications, privacy regulations, and access rights. However, popular IoT platforms do not consider data classification and security-aware data analysis. In this paper, we present a novel architecture based on open-source solutions that handles the issue of collecting and classifying data at the source and presents the data analysis to users at different authorization levels. Our architecture consists of three layers: a layer for exposing collected and classified data to a middleware, the middleware to handle storage and analysis of the data and expose it to a dashboard, and the dashboard responsible for authenticating users and visualizing data according to the users' classification level. Our solution distinguishes itself by focusing on data classification rather than data collection, supporting fine-grained access control and declassification. Our implementation, using the Web of Things API, Node-RED and Grafana, demonstrates the security benefits of our design on use cases in the smart city and healthcare domains.
Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers Inc. , 2021. p. 102-113
Series
IEEE International Conference on Software Quality Reliability and Security, ISSN 2693-9185
Keywords [en]
secure IoT architecture, user-centric data classification, decentralized label model, fine-grained access control, multi-user IoT platform, data-centric architecture
National Category
Computer Systems
Identifiers
URN: urn:nbn:se:kth:diva-305259DOI: 10.1109/QRS54544.2021.00021ISI: 000814747000011Scopus ID: 2-s2.0-85146199452OAI: oai:DiVA.org:kth-305259DiVA, id: diva2:1614041
Conference
21st IEEE International Conference on Software Quality, Reliability and Security (QRS), DEC 06-10, 2021, Hainan, CHINA
Projects
CDISDigital FuturesTrustfull
Note
Part of proceedings: ISBN 978-1-6654-5813-9
QC 20211129
QC 20220708
2021-11-242021-11-242023-06-08Bibliographically approved