TY - JOUR
T1 - Extending access control in AWS IoT through event-driven functions
T2 - an experimental evaluation using a smart lock system
AU - Ahmad, Tahir
AU - Morelli, Umberto
AU - Ranise, Silvio
AU - Zannone, Nicola
N1 - Publisher Copyright:
© 2021, The Author(s), under exclusive licence to Springer-Verlag GmbH, DE.
PY - 2022/4
Y1 - 2022/4
N2 - In recent years, the design of effective authorization mechanisms for IoT and, in particular, for smart home applications has gained increasing attention from researchers and practitioners. However, very little attention is given to the performance evaluation of those authorization mechanisms. To fill this gap, this paper presents a thorough experimental evaluation of cloud- and edge-based access control mechanisms for smart home applications. We discuss the main architectural choices, namely (a) where the access control logic is deployed (in the cloud or the edge) and (b) how the attributes needed for policy evaluation are provided to the policy evaluation point and identify possible deployment models for cloud- and edge-based access control mechanisms. To study the impact of these choices on the performance of smart homes, we realized the identified deployment models within the IoT platforms offered by Amazon Web Services (AWS), namely AWS IoT and Greengrass, and empirically evaluate them using a smart lock system. Based on our experimental evaluation, we provide recommendations to both researchers and practitioners.
AB - In recent years, the design of effective authorization mechanisms for IoT and, in particular, for smart home applications has gained increasing attention from researchers and practitioners. However, very little attention is given to the performance evaluation of those authorization mechanisms. To fill this gap, this paper presents a thorough experimental evaluation of cloud- and edge-based access control mechanisms for smart home applications. We discuss the main architectural choices, namely (a) where the access control logic is deployed (in the cloud or the edge) and (b) how the attributes needed for policy evaluation are provided to the policy evaluation point and identify possible deployment models for cloud- and edge-based access control mechanisms. To study the impact of these choices on the performance of smart homes, we realized the identified deployment models within the IoT platforms offered by Amazon Web Services (AWS), namely AWS IoT and Greengrass, and empirically evaluate them using a smart lock system. Based on our experimental evaluation, we provide recommendations to both researchers and practitioners.
KW - Access control
KW - Amazon web services
KW - Internet of things
UR - http://www.scopus.com/inward/record.url?scp=85109308039&partnerID=8YFLogxK
U2 - 10.1007/s10207-021-00558-3
DO - 10.1007/s10207-021-00558-3
M3 - Article
AN - SCOPUS:85109308039
SN - 1615-5262
VL - 21
SP - 379
EP - 408
JO - International Journal of Information Security
JF - International Journal of Information Security
IS - 2
ER -