Mariam Bisma, F. Azam, Yawar Rasheed, Muhammad Waseem Anwar
{"title":"A Model-Driven Framework for Ensuring Role Based Access Control in IoT Devices","authors":"Mariam Bisma, F. Azam, Yawar Rasheed, Muhammad Waseem Anwar","doi":"10.1145/3404555.3404582","DOIUrl":null,"url":null,"abstract":"Ensuring security and privacy of IOT devices and the associated/ dependent complex and critical systems is certainly a major concern, especially after proliferation of IoT devices in variety of domains in current era. A considerable level of security can be achieved in these systems using the techniques of Role Based Access Control (RBAC). In contrast to Discretionary Access Control (DAC) where personal identity of the owner/ user matters, RBAC grants access permissions on the basis of roles of the user. Due to the inherent complexity associated with ensuring security in IoT devices and related systems/ services, a level of abstraction is required in the development process, in order to better understand and develop the system accordingly by integrating all the security aspects. This level of abstraction can be achieved by developing the system as per the concepts of Model Driven Development (MDD). In this paper, techniques of Model Driven Architecture (MDA)/ MDD has been used to propose such a Framework/ Meta-Model, which ensures RBAC in order to access the services associated with IoT devices. The proposed Meta-Model can be further extended for the model-based development and automation of such a system that ensure RBAC for IoT devices. Validity of proposed Meta-Model has been proved by creating an M1 level Instance Model of a real-world case study. Results prove, that the proposed Meta-Model is capable to be transformed into a reliable system that ensures RBAC in IoT devices.","PeriodicalId":220526,"journal":{"name":"Proceedings of the 2020 6th International Conference on Computing and Artificial Intelligence","volume":"18 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-04-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 2020 6th International Conference on Computing and Artificial Intelligence","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3404555.3404582","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1
Abstract
Ensuring security and privacy of IOT devices and the associated/ dependent complex and critical systems is certainly a major concern, especially after proliferation of IoT devices in variety of domains in current era. A considerable level of security can be achieved in these systems using the techniques of Role Based Access Control (RBAC). In contrast to Discretionary Access Control (DAC) where personal identity of the owner/ user matters, RBAC grants access permissions on the basis of roles of the user. Due to the inherent complexity associated with ensuring security in IoT devices and related systems/ services, a level of abstraction is required in the development process, in order to better understand and develop the system accordingly by integrating all the security aspects. This level of abstraction can be achieved by developing the system as per the concepts of Model Driven Development (MDD). In this paper, techniques of Model Driven Architecture (MDA)/ MDD has been used to propose such a Framework/ Meta-Model, which ensures RBAC in order to access the services associated with IoT devices. The proposed Meta-Model can be further extended for the model-based development and automation of such a system that ensure RBAC for IoT devices. Validity of proposed Meta-Model has been proved by creating an M1 level Instance Model of a real-world case study. Results prove, that the proposed Meta-Model is capable to be transformed into a reliable system that ensures RBAC in IoT devices.