Skip to main navigation Skip to search Skip to main content

PICO: Privacy-Preserving Access Control in IoT Scenarios through Incomplete Information

Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

42 Downloads (Pure)

Abstract

Internet of Things (IoT) platforms typically require IoT devices and users to provide fine-grained information to determine whether access to resources and services can be granted. However, this information can be sensitive for users and its disclosure can lead to severe privacy threats, forcing users to decide between receiving a service or protecting their privacy. To close this gap, this work proposes PICO, a framework for privacy-preserving access control in IoT scenarios through incomplete information. PICO allows IoT devices to evaluate the privacy risks of disclosing the information needed to access a service and determine at which level of granularity such information can be disclosed. At the same time, PICO empowers IoT platforms to evaluate access control policies even when incomplete information is provided and possibly grant access to services based on a customized service-dependent risk factor. Through simulations using data from real IoT devices, we show the existence of a trade-off between privacy and energy consumption on IoT devices running PICO, and that more privacy can be achieved for such devices only by sacrificing a consistent portion of the overall energy capacity.

Original languageEnglish
Title of host publicationSAC '22
Subtitle of host publicationProceedings of the 37th ACM/SIGAPP Symposium on Applied Computing
Place of PublicationNew York
PublisherAssociation for Computing Machinery, Inc.
Pages147-156
Number of pages10
ISBN (Electronic)978-1-4503-8713-2
DOIs
Publication statusPublished - 6 May 2022
Event37th ACM/SIGAPP Symposium on Applied Computing, SAC 2022 - Virtual, Online
Duration: 25 Apr 202229 Apr 2022

Conference

Conference37th ACM/SIGAPP Symposium on Applied Computing, SAC 2022
CityVirtual, Online
Period25/04/2229/04/22

Funding

This work has been partially supported by the INTERSCT project, Grant No. NWA.1162.18.301, funded by Netherlands Organisation for Scientific Research (NWO). The findings reported herein are solely responsibility of the authors.

UN SDGs

This output contributes to the following UN Sustainable Development Goals (SDGs)

  1. SDG 7 - Affordable and Clean Energy
    SDG 7 Affordable and Clean Energy

Keywords

  • client privacy
  • disclosure risk
  • energy-privacy trade-off
  • IoT security
  • privacy-preserving access control

Fingerprint

Dive into the research topics of 'PICO: Privacy-Preserving Access Control in IoT Scenarios through Incomplete Information'. Together they form a unique fingerprint.

Cite this