Authentication, Authorization, and Selective Disclosure for IoT data sharing using Verifiable Credentials and Zero-Knowledge Proofs

09/01/2022
by   Nikos Fotiou, et al.
0

As IoT becomes omnipresent vast amounts of data are generated, which can be used for building innovative applications. However,interoperability issues and security concerns, prevent harvesting the full potentials of these data. In this paper we consider the use case of data generated by smart buildings. Buildings are becoming ever "smarter" by integrating IoT devices that improve comfort through sensing and automation. However, these devices and their data are usually siloed in specific applications or manufacturers, even though they can be valuable for various interested stakeholders who provide different types of "over the top" services, e.g., energy management. Most data sharing techniques follow an "all or nothing" approach, creating significant security and privacy threats, when even partially revealed, privacy-preserving, data subsets can fuel innovative applications. With these in mind we develop a platform that enables controlled, privacy-preserving sharing of data items. Our system innovates in two directions: Firstly, it provides a framework for allowing discovery and selective disclosure of IoT data without violating their integrity. Secondly, it provides a user-friendly, intuitive mechanisms allowing efficient, fine-grained access control over the shared data. Our solution leverages recent advances in the areas of Self-Sovereign Identities, Verifiable Credentials, and Zero-Knowledge Proofs, and it integrates them in a platform that combines the industry-standard authorization framework OAuth 2.0 and the Web of Things specifications.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/28/2021

Game Theory Based Privacy Preserving Approach for Collaborative Deep Learning in IoT

The exponential growth of Internet of Things (IoT) has become a transcen...
research
12/18/2020

GDPR-inspired IoT Ontology enabling Semantic Interoperability, Federation of Deployments and Privacy-Preserving Applications

Testing and experimentation are crucial for promoting innovation and bui...
research
04/17/2019

I2PA : An Efficient ABC for IoT

Internet of Things (IoT) is very attractive because of its promises. How...
research
11/09/2022

Harpocrates: Privacy-Preserving and Immutable Audit Log for Sensitive Data Operations

The audit log is a crucial component to monitor fine-grained operations ...
research
01/15/2019

Blockchain enabled fog structure to provide data security in IoT applications

IoT provides services by connecting smart devices to the Internet, and e...
research
09/26/2022

Preprint: Privacy-preserving IoT Data Sharing Scheme

Data sharing can be granted using different factors one of which is some...
research
02/23/2020

PrivGen: Preserving Privacy of Sequences Through Data Generation

Sequential data is everywhere, and it can serve as a basis for research ...

Please sign up or login with your details

Forgot password? Click here to reset