Advancements in cloud computing have helped Internet of Things (IoT) systems to enable complex and highly scalable IoT solutions in healthcare, which has led to concerns about unauthorized access to the sensitive resources of cloud-enabled IoT (CE-IoT). Traditional access control methods often cannot handle complex resource allocation and permission delegation properly, resulting in inefficiencies in access control and delegation and vulnerabilities in security. To overcome these issues, we have proposed a novel Attribute-Based Access control (ABAC)-based framework for IoT-based healthcare, enabling secure access to resources layered by utilizing a centralized policy repository. Moreover, the framework facilitates the automatic delegation of permissions based on predefined policies and attributes. The proposed framework security has undergone a comprehensive informal security analysis, confirming its effectiveness in achieving the required security. The proposed framework takes significantly less computation and communication costs compared to existing schemes.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

MLADS: Multi-layered Attribute-Based Access Control and Delegation System for Cloud-Enabled IoT Healthcare System

  • Mridul Kailashchandra Mishra,
  • Udai Pratap Rao

摘要

Advancements in cloud computing have helped Internet of Things (IoT) systems to enable complex and highly scalable IoT solutions in healthcare, which has led to concerns about unauthorized access to the sensitive resources of cloud-enabled IoT (CE-IoT). Traditional access control methods often cannot handle complex resource allocation and permission delegation properly, resulting in inefficiencies in access control and delegation and vulnerabilities in security. To overcome these issues, we have proposed a novel Attribute-Based Access control (ABAC)-based framework for IoT-based healthcare, enabling secure access to resources layered by utilizing a centralized policy repository. Moreover, the framework facilitates the automatic delegation of permissions based on predefined policies and attributes. The proposed framework security has undergone a comprehensive informal security analysis, confirming its effectiveness in achieving the required security. The proposed framework takes significantly less computation and communication costs compared to existing schemes.