• DocumentCode
    131978
  • Title

    Secure capability-based access control in the M2M local cloud platform

  • Author

    Anggorojati, Bayu ; Prasad, Neeli Rashmi ; Prasad, Ranga

  • Author_Institution
    Center for TeleInFrastruktur (CTIF) Aalborg Univ., Aalborg, Denmark
  • fYear
    2014
  • fDate
    11-14 May 2014
  • Firstpage
    1
  • Lastpage
    5
  • Abstract
    Protection and access control to resources plays a critical role in a distributed computing system like Machine-to-Machine (M2M) and cloud platform. The M2M local cloud platform considered in this paper, consists of multiple distributed M2M gateways that form a local cloud - presenting a unique challenge to the existing access control systems. The most prominent access control systems, such as ACL and RBAC, lack in scalability and flexibility to manage access from users or entity that belong to different authorization domains, and thus unsuitable for the presented platform. The access control approach based on API keys and OAuth that is used by the existing M2M Cloud platform, fails to provide fine grained and flexible access right delegation at the same time when both methods are used together. The proposed approach is built upon capability-based access control that has been specifically designed to provide flexible, yet restricted, access rights delegation. A number of use cases are provided to show the usage of capability creation, delegation, and access provision, particularly in the way application accesses services provided by the platform.
  • Keywords
    application program interfaces; authorisation; cloud computing; computer network security; internetworking; network servers; private key cryptography; API key; M2M local cloud platform; OAuth; application programming interface; authorization domain; distributed computing system; machine-to-machine computing system; multiple distributed M2M gateway; secure capability based access control system; Access control; Buildings; Context; Permission; Privacy; Public key; M2M; access control; capability; cloud; delegation; security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Wireless Communications, Vehicular Technology, Information Theory and Aerospace & Electronic Systems (VITAE), 2014 4th International Conference on
  • Conference_Location
    Aalborg
  • Print_ISBN
    978-1-4799-4626-6
  • Type

    conf

  • DOI
    10.1109/VITAE.2014.6934469
  • Filename
    6934469