Enterprise IT systems deployed in the public cloud are subjected to various attacks, including inside and outside enterprise attacks. Context-aware access control techniques are available only for mobile devices with built-in sensors. A common case is when the user may access the IT system through multiple stable workstations deployed in different enterprise locations, i.e., “The user is mobile, but the workstations are stable.” Since location sensing devices are not integrated into stable workstations, context-aware solutions were not proposed for stable workstations. Because of the security perspective of the IT System, users may assigned different roles in different zones. Therefore, we propose a context-aware access control solution, LOC-MAC-HASH, for stable workstations using IoT devices, sensors, edge computing, and IoT cloud services. The LOC-MAC-HASH requires UID, PWD, PC_token, and Biometric during login to ensure an appropriate location-based role is assigned to the user. To generate location-based PC_tokens for a stable workstation, a unique Zone_token is required which is generated on an edge device with AWS IoT Greengrass core by sensing zone-specific environmental parameters like sound, temperature, image, location, etc. The PC_token is created by hashing the PC-specific Zone_token and MAC Address. The workstation PC_token and their zone-id are updated in the IT system through AWS IoT cloud services and edge devices. Since the Zone_token is generated periodically with short time intervals on an edge device, a unique PC_token for each workstation may be considered dynamic to increase security at the next level.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

LOC-MAC-HASH: A Novel Approach to Generate Environmental Tokens for IT System Security

  • Nitesh Kumar Jangid,
  • Pankaj Dadheech,
  • Mukesh Kumar Gupta

摘要

Enterprise IT systems deployed in the public cloud are subjected to various attacks, including inside and outside enterprise attacks. Context-aware access control techniques are available only for mobile devices with built-in sensors. A common case is when the user may access the IT system through multiple stable workstations deployed in different enterprise locations, i.e., “The user is mobile, but the workstations are stable.” Since location sensing devices are not integrated into stable workstations, context-aware solutions were not proposed for stable workstations. Because of the security perspective of the IT System, users may assigned different roles in different zones. Therefore, we propose a context-aware access control solution, LOC-MAC-HASH, for stable workstations using IoT devices, sensors, edge computing, and IoT cloud services. The LOC-MAC-HASH requires UID, PWD, PC_token, and Biometric during login to ensure an appropriate location-based role is assigned to the user. To generate location-based PC_tokens for a stable workstation, a unique Zone_token is required which is generated on an edge device with AWS IoT Greengrass core by sensing zone-specific environmental parameters like sound, temperature, image, location, etc. The PC_token is created by hashing the PC-specific Zone_token and MAC Address. The workstation PC_token and their zone-id are updated in the IT system through AWS IoT cloud services and edge devices. Since the Zone_token is generated periodically with short time intervals on an edge device, a unique PC_token for each workstation may be considered dynamic to increase security at the next level.