Extending access control in AWS IoT through event-driven functions: an experimental evaluation using a smart lock system

Tahir Ahmad (Corresponding author), Umberto Morelli, Silvio Ranise, Nicola Zannone

Research output: Contribution to journalArticleAcademicpeer-review

12 Citations (Scopus)
175 Downloads (Pure)

Abstract

In recent years, the design of effective authorization mechanisms for IoT and, in particular, for smart home applications has gained increasing attention from researchers and practitioners. However, very little attention is given to the performance evaluation of those authorization mechanisms. To fill this gap, this paper presents a thorough experimental evaluation of cloud- and edge-based access control mechanisms for smart home applications. We discuss the main architectural choices, namely (a) where the access control logic is deployed (in the cloud or the edge) and (b) how the attributes needed for policy evaluation are provided to the policy evaluation point and identify possible deployment models for cloud- and edge-based access control mechanisms. To study the impact of these choices on the performance of smart homes, we realized the identified deployment models within the IoT platforms offered by Amazon Web Services (AWS), namely AWS IoT and Greengrass, and empirically evaluate them using a smart lock system. Based on our experimental evaluation, we provide recommendations to both researchers and practitioners.

Original languageEnglish
Pages (from-to)379-408
Number of pages30
JournalInternational Journal of Information Security
Volume21
Issue number2
Early online date2 Jul 2021
DOIs
Publication statusPublished - Apr 2022

Keywords

  • Access control
  • Amazon web services
  • Internet of things

Fingerprint

Dive into the research topics of 'Extending access control in AWS IoT through event-driven functions: an experimental evaluation using a smart lock system'. Together they form a unique fingerprint.

Cite this