Most popular smart home IoT platforms allow devices to be shared with other users or delegated to other platforms. We find that many IoT platforms have insufficient and vulnerable design of access control in the device sharing and delegation process. Existing literature has revealed non-negligible security and privacy risks caused by flawed access control of IoT platforms and proposed various solutions to enhance the device sharing process. However, they are focusing on securing device sharing within the same IoT platform and leave the access control of cross-platform IoT device sharing an open problem. In this work, we conduct the first systematic study of access control in cross-platform IoT device sharing and identify the issues of entangled associations among devices, users, and IoT platforms. Based on our study, we propose a practical solution named Shadow Connector (ShadowConn), which decouples IoT devices from users and platforms. ShadowConn creates virtual shadow device instances for each specific scenario of device sharing and delegation, synchronizing their states with the real devices. By regulating the state synchronizations between virtual and real devices, fine-grained and flexible access control policies can be enforced. Additionally, we design a Large Language Model (LLM) agent to assist users in specifying accurate and comprehensive access control policies that make use of shadow device instances. We implement the ShadowConn prototype on commercially available smart home platforms and conduct performance evaluations using four access control scenarios. ShadowConn successfully achieves a 100% satisfaction rate in establishing the access control policy based on users’ requests and syncing the status of devices used by multiple users across different platforms.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

ShadowConn: Breaking the Entanglement of Cross-Platform IoT Delegation in Multi-user Environments

  • Huan Bui,
  • Chenglong Fu

摘要

Most popular smart home IoT platforms allow devices to be shared with other users or delegated to other platforms. We find that many IoT platforms have insufficient and vulnerable design of access control in the device sharing and delegation process. Existing literature has revealed non-negligible security and privacy risks caused by flawed access control of IoT platforms and proposed various solutions to enhance the device sharing process. However, they are focusing on securing device sharing within the same IoT platform and leave the access control of cross-platform IoT device sharing an open problem. In this work, we conduct the first systematic study of access control in cross-platform IoT device sharing and identify the issues of entangled associations among devices, users, and IoT platforms. Based on our study, we propose a practical solution named Shadow Connector (ShadowConn), which decouples IoT devices from users and platforms. ShadowConn creates virtual shadow device instances for each specific scenario of device sharing and delegation, synchronizing their states with the real devices. By regulating the state synchronizations between virtual and real devices, fine-grained and flexible access control policies can be enforced. Additionally, we design a Large Language Model (LLM) agent to assist users in specifying accurate and comprehensive access control policies that make use of shadow device instances. We implement the ShadowConn prototype on commercially available smart home platforms and conduct performance evaluations using four access control scenarios. ShadowConn successfully achieves a 100% satisfaction rate in establishing the access control policy based on users’ requests and syncing the status of devices used by multiple users across different platforms.