Visible to the public Trust Aware Continuous Authorization for Zero Trust in Consumer Internet of Things

TitleTrust Aware Continuous Authorization for Zero Trust in Consumer Internet of Things
Publication TypeConference Paper
Year of Publication2020
AuthorsDimitrakos, T., Dilshener, T., Kravtsov, A., Marra, A. La, Martinelli, F., Rizos, A., Rosetti, A., Saracino, A.
Conference Name2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom)
Date Publisheddec
KeywordsABAC, Authorization, Computer architecture, human factors, Internet of Things, IoT, Monitoring, policy-based governance, privacy, Prototypes, pubcrawl, resilience, Resiliency, Scalability, Smart homes, Trust, usage control, zero trust
AbstractThis work describes the architecture and prototype implementation of a novel trust-aware continuous authorization technology that targets consumer Internet of Things (IoT), e.g., Smart Home. Our approach extends previous authorization models in three complementary ways: (1) By incorporating trust-level evaluation formulae as conditions inside authorization rules and policies, while supporting the evaluation of such policies through the fusion of an Attribute-Based Access Control (ABAC) authorization policy engine with a Trust-Level-Evaluation-Engine (TLEE). (2) By introducing contextualized, continuous monitoring and re-evaluation of policies throughout the authorization life-cycle. That is, mutable attributes about subjects, resources and environment as well as trust levels that are continuously monitored while obtaining an authorization, throughout the duration of or after revoking an existing authorization. Whenever change is detected, the corresponding authorization rules, including both access control rules and trust level expressions, are re-evaluated.(3) By minimizing the computational and memory footprint and maximizing concurrency and modular evaluation to improve performance while preserving the continuity of monitoring. Finally we introduce an application of such model in Zero Trust Architecture (ZTA) for consumer IoT.
DOI10.1109/TrustCom50675.2020.00247
Citation Keydimitrakos_trust_2020