首页> 外文期刊>Applied System Innovation >Design and Implementation of a Contextual-Based Continuous Authentication Framework for Smart Homes
【24h】

Design and Implementation of a Contextual-Based Continuous Authentication Framework for Smart Homes

机译:基于上下文的智能家居连续认证框架的设计与实现

获取原文
           

摘要

There has been a rapid increase in the number of Internet of Things (IoT) devices in the lastfew years, providing a wide range of services such as camera feeds, light controls, and door locksfor remote access. Access to IoT devices, whether within the same environment or remotely via theInternet, requires proper security mechanisms in order to avoid disclosing any secure information oraccess privileges. Authentication, on which other security classes are built, is the most important partof IoT security. Without ensuring that the authorized party is who it claims to be, other security factorswould be useless. Additionally, with the increased mobility of IoT devices, traditional authenticationmechanisms, such as a username and password, are less effective. Numerous security challenges inthe IoT domain have resulted in the proposal of many different approaches to authentication. Manyof these methods require either carrying an authentication token, such as a smartcard, or restrictingaccess to a particular physical location. Considering that most IoT devices contain a wide arrayof sensors, a large amount of contextual information can be provided. Thus, real-time securitymechanisms can protect user access by, for example, utilizing contextual information to validaterequests. A variety of contextual information can be retrieved to strengthen the authenticationprocess, both at the time of access request and throughout the entire access session, without requiringuser interaction, which avoids the risk of being discovered by attackers of these features. In this paper,we introduce a continuous authentication framework that integrates contextual information for userauthentication in smart homes. The implementation and evaluation show that the framework canprotect smart devices against unauthorized access from both anonymous and known users, either,locally or remotely, in a flexible manner and without requiring additional user intervention.
机译:在过去的几年中,物联网(IoT)设备的数量迅速增加,提供了广泛的服务,例如摄像头馈送,灯光控制和用于远程访问的门锁。无论是在同一环境中还是通过Internet远程访问IoT设备,都需要适当的安全机制,以避免泄露任何安全信息或访问权限。建立其他安全性类别的身份验证是物联网安全性的最重要部分。如果不确保授权方是其声称的身份,其他安全因素将毫无用处。另外,随着物联网设备移动性的提高,传统的身份验证机制(例如用户名和密码)的有效性降低。 IoT域中的众多安全挑战导致提出了许多不同的身份验证方法。这些方法中的许多方法都需要携带身份验证令牌(例如智能卡)或限制对特定物理位置的访问。考虑到大多数物联网设备包含各种各样的传感器,因此可以提供大量的上下文信息。因此,实时安全机制可以通过例如利用上下文信息来验证请求来保护用户访问。可以在访问请求时以及在整个访问会话期间检索各种上下文信息以增强身份验证过程,而无需用户交互,从而避免了被这些功能的攻击者发现的风险。在本文中,我们介绍了一个连续的身份验证框架,该框架集成了上下文信息以用于智能家居中的用户身份验证。该实施和评估表明,该框架可以灵活地保护智能设备,使其免受本地和远程匿名和已知用户的未经授权的访问,而无需其他用户干预。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号