Perils and Mitigation of Security Risks of Cooperation in Mobile-as-a-Gateway IoT


연구 분야: Infrastructure



학회: CCS '22: Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security


초록

Mobile-as-a-Gateway (MaaG) is a popular feature using mobile devices as gateways to connect IoT devices to cloud services for management. MaaG IoT access control systems support remote access sharing/revocation while allowing "offline availability'' for better usability. Realizing these functionalities requires secure cooperation among the cloud service, the companion app, and the IoT device. For practical considerations, we find that almost all cloud services perform access model translation (AMT) to translate expressive cloud-side access policies to simple device-side policies. During the process, ad-hoc protocols are developed to support the access policy synchronization. Unfortunately, current MaaG IoT systems fail to recognize the security risks in the process of access model translation and synchronization. We analyze ten top-of-the-line MaaG IoT devices and find that all of them have serious vulnerabilities, e.g., allowing irrevocable and permanent access for temporary users. We further propose a secure protocol design that defends against all identified attacks.


Author Profile
Xin'an Zhou

University of California Riverside Riverside CA USA

Canada
Author Profile
Jiale Guan

Indiana University Bloomington Bloomington IN USA

India
Author Profile
Luyi Xing

Indiana University Bloomington Bloomington IN USA

India

📄 논문 정보

발행 연도 2022년
인용수 7
출판 국가 India, Canada
사이트 ACM
좋아요 수 0

연관 논문 목록 (298건)