Tyche: Risk-Based Permissions for Smart Home Platforms

01/14/2018
by   Amir Rahmati, et al.
0

Emerging smart home platforms, which interface with a variety of physical devices and support third-party application development, currently use permission models inspired by smartphone operating systems-they group functionally similar device operations into separate units, and require users to grant apps access to devices at that granularity. Unfortunately, this leads to two issues: (1) apps that do not require access to all of the granted device operations have overprivileged access to them, (2) apps might pose a higher risk to users than needed because physical device operations are fundamentally risk- asymmetric-"door.unlock" provides access to burglars, and "door.lock" can potentially lead to getting locked out. Overprivileged apps with access to mixed-risk operations only increase the potential for damage. We present Tyche, a system that leverages the risk-asymmetry in physical device operations to limit the risk that apps pose to smart home users, without increasing the user's decision overhead. Tyche introduces the notion of risk-based permissions. When using risk-based permissions, device operations are grouped into units of similar risk, and users grant apps access to devices at that risk-based granularity. Starting from a set of permissions derived from the popular Samsung SmartThings platform, we conduct a user study involving domain-experts and Mechanical Turk users to compute a relative ranking of risks associated with device operations. We find that user assessment of risk closely matches that of domain experts. Using this ranking, we define risk-based groupings of device operations, and apply it to existing SmartThings apps, showing that risk-based permissions indeed limit risk if apps are malicious or exploitable.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
12/04/2018

A Study of Data Store-based Home Automation

Home automation platforms provide a new level of convenience by enabling...
research
10/09/2019

Aegis: A Context-aware Security Framework for Smart Home Systems

Our everyday lives are expanding fast with the introduction of new Smart...
research
04/07/2016

Aware: Controlling App Access to I/O Devices on Mobile Platforms

Smartphones' cameras, microphones, and device displays enable users to c...
research
11/22/2019

Multi-User Multi-Device-Aware Access Control System for Smart Home

In a smart home system, multiple users have access to multiple devices, ...
research
12/23/2020

If This Context Then That Concern: Exploring users' concerns with IFTTT applets

End users are increasingly using trigger-action platforms like, If-This-...
research
09/02/2018

A study on users' privacy perception with smart devices

Nowadays, privacy has become a very serious issue with smart and mobile ...
research
03/23/2021

Risk Analysis and Policy Enforcement of Function Interactions in Robot Apps

Robot apps are becoming more automated, complex and diverse. An app usua...

Please sign up or login with your details

Forgot password? Click here to reset