ACE of Spades in the IoT Security Game: A Flexible IPsec Security Profile for Access Control

08/14/2018
by   Santiago Aragon, et al.
0

The Authentication and Authorization for Constrained Environments (ACE) framework provides fine-grained access control in the Internet of Things, where devices are resource-constrained and with limited connectivity. The ACE framework defines separate profiles to specify how exactly entities interact and what security and communication protocols to use. This paper presents the novel ACE IPsec profile, which specifies how a client establishes a secure IPsec channel with a resource server, contextually using the ACE framework to enforce authorized access to remote resources. The profile makes it possible to establish IPsec Security Associations, either through their direct provisioning or through the standard IKEv2 protocol. We provide the first Open Source implementation of the ACE IPsec profile for the Contiki OS and test it on the resource-constrained Zolertia Firefly platform. Our experimental performance evaluation confirms that the IPsec profile and its operating modes are affordable and deployable also on constrained IoT platforms.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/07/2022

Secure and Authorized Client-to-Client Communication for LwM2M

Constrained devices on the Internet of Things (IoT) continuously produce...
research
05/01/2018

A Federated Capability-based Access Control Mechanism for Internet of Things (IoTs)

The prevalence of Internet of Things (IoTs) allows heterogeneous embedde...
research
08/30/2019

IoT based Smart Access Controlled Secure Smart City Architecture Using Blockchain

Standard security protocols like SSL, TLS, IPSec etc. have high memory a...
research
11/10/2020

Tokoin: A Coin-Based Accountable Access Control Scheme for Internet of Things

With the prevalence of Internet of Things (IoT) applications, IoT device...
research
03/11/2021

Robofleet: Secure Open Source Communication and Management for Fleets of Autonomous Robots

Safe long-term deployment of a fleet of mobile robots requires reliable ...
research
02/19/2019

Zest: REST over ZeroMQ

In this paper, we introduce Zest (REST over ZeroMQ), a middleware techno...
research
08/11/2020

Planimation

Planimation is a modular and extensible open source framework to visuali...

Please sign up or login with your details

Forgot password? Click here to reset