top of page
< Back

Extending attribute-based access control model with authentication information for Internet of Things


Date published:





Melike Burakgazi Bilgen, Kemal Bicakci


2020 International Conference on Information Security and Cryptology (ISCTURKEY)



Internet of Things (IoT) brings not only wide range of opportunities but also security and privacy concerns. Consisting of many connected devices used in a highly interactive way, one of the main security concerns in IoT is unauthorized access. Traditional access control models do not support dynamic and fine-grained access control policies. Attribute-Based Access Control (ABAC) model is usually considered the most satisfactory access control model for running IoT applications. In this paper, we propose to take into the user authentication matching score obtained from a biometric authentication system consideration during making access control decisions. We emphasize the need of fine-grained access control and suggest to create access control policies per functionality of the device instead of per device regarding to the least privilege principle of information security. We give full or partial permission to certain …

Download Paper

bottom of page