SlideShare une entreprise Scribd logo
1  sur  21
©	2016	– The	symbIoTe Consortium
Attribute-based	Access	Control	scheme	in	
federated	IoT	platforms
symbIoTe
Savio	Sciancalepore,	 Michal	Pilc,	Svenja	Schröder,	Giuseppe	Bianchi,	Gennaro	Boggia,	
Marek	Pawlowski,	Giuseppe	Piro,	Marcin	Plóciennik	and	Hannes	Weisgrab
2nd Workshop	on	Interoperability	and	Open-Source	Solutions	for	the	IoT,	07/11/2016,	
Stuttgart
©	2016	– The	symbIoTe Consortium2
• SymbIoTe	scenario	and	Requirements
• Related	work
• Baseline	Architecture	&	Components
• Scenarios	
• Technical	solutions
• Conclusions	&	Next	Steps
Outline
©	2016	– The	symbIoTe Consortium3
• SymbIoTe	scenario	and	Requirements
• Related	work
• Baseline Architecture	&	Components
• Scenarios	
• Technical	solutions
• Conclusions	&	Next	Steps
©	2016	– The	symbIoTe Consortium4
• symbIoTe H2020	EU	project:	symbiosis	of	smart	
objects	across	IoT environments
• interoperability	and	mediation framework	for	the	
collaboration	of	vertical	IoT	platforms
SymbIoTe	scenario
©	2016	– The	symbIoTe Consortium5
• authentication and	authorization
– decoupling	logic
– offline	platforms
• flexible security	policies
• revocation	and	expiration	of	access	rights
• delegation	of	access	rights
• user	privacy,	data	anonymization
• OWASP	secure	coding	rules
Security	requirements
©	2016	– The	symbIoTe Consortium6
• SymbIoTe	scenario	and	Requirements
• Related	work
• Baseline	Architecture	&	Components
• Scenarios	
• Technical	solutions
• Conclusions	&	Next	Steps
©	2016	– The	symbIoTe Consortium7
Related	work
©	2016	– The	symbIoTe Consortium8
• SymbIoTe	scenario	and	Requirements
• Related	work
• Baseline	Architecture	&	Components
• Scenarios
• Technical	solutions
• Conclusions	&	Next	Steps
©	2016	– The	symbIoTe Consortium9
Baseline	System	Architecture
©	2016	– The	symbIoTe Consortium10
Core	AAM
• Authentication of	components/	and	
applications	registered	in	the	mediator
• Release	of	(authenticated/trusted)	core tokens
storing	attributes	at	the	mediator	side
• Management	of	asynchronous	
core	token	revocation
• Core	Tokens	cryptography	validation	through	
challenge-response
• Attributes	mapping	function
©	2016	– The	symbIoTe Consortium11
Platform	AAM
• Authentication of	components/	and	
applications	registered	in	the	IoT	platform
• Release	of	(authenticated/trusted)	home
tokens storing	attributes	in	the	IoT	platform
• Management	of	asynchronous	
home	token	revocation
• Home	Tokens	cryptography	validation	through	
challenge-response
• Attributes	mapping	function
©	2016	– The	symbIoTe Consortium12
• SymbIoTe	scenario	and	Requirements
• Related	work
• Baseline	Architecture	&	Components
• Scenarios
• Technical	solutions
• Conclusions	&	Next	Steps
©	2016	– The	symbIoTe Consortium13
Scenarios
• Scenario #1: application is registered with an
IoT platform and would access to resources
exposed by the same IoT platform
• Scenario #2: application is registered with
symbIoTe and wants to access to resources
exposed by a federated platform
• Scenario #3: application is registered with one
or more federated platforms and would access
to resources exposed elsewhere (multi-
domain access rights composition)
©	2016	– The	symbIoTe Consortium14
Scenario	#1
©	2016	– The	symbIoTe Consortium15
Scenario	#2
©	2016	– The	symbIoTe Consortium16
Scenario	#3
©	2016	– The	symbIoTe Consortium17
• SymbIoTe	scenario	and	Requirements
• Related	work
• Baseline	Architecture	&	Components
• Scenarios
• Technical	solutions
• Conclusions	&	Next	Steps
©	2016	– The	symbIoTe Consortium18
Macaroons	&	JWTs
• Macaroons: distributed	authorization	in	the	
cloud
• JSON	Web	Tokens(JWTs):	online	purchasing
©	2016	– The	symbIoTe Consortium19
• SymbIoTe	scenario	and	Requirements
• Related	work
• Baseline	Architecture	&	Components
• Scenarios
• Technical	solutions
• Conclusions	&	Next	Steps
©	2016	– The	symbIoTe Consortium20
• Implementation of	security	components	in	the	
symbIoTe	ecosystem
• Technical	solutions	for
– Token	format	(JWT,	Macaroons,	etc.)
– Challenge-response	procedure
– Check	revocation	procedure
– Policy	and	ABAC
• Anomaly	detection
– monitoring	suspicious	behavior		
– mitigating	security	threats		
– detection	of	malicious	sensors/	apps/	platforms
Conclusions	&	Next	Steps
©	2016	– The	symbIoTe Consortium
Thank	you!
Questions?
savio.sciancalepore@poliba.it

Contenu connexe

Tendances

FreeGIS.net presentation at the Geospatial World Forum in Rotterdam 2013
FreeGIS.net presentation at the Geospatial World Forum in Rotterdam 2013FreeGIS.net presentation at the Geospatial World Forum in Rotterdam 2013
FreeGIS.net presentation at the Geospatial World Forum in Rotterdam 2013
Paolo Viskanic
 
Support.services.4.sg.developers
Support.services.4.sg.developersSupport.services.4.sg.developers
Support.services.4.sg.developers
Nuno Ferreira
 

Tendances (20)

FIWARE Global Summit - Pixel: A Port IoT Solution for Environmental Leverage
FIWARE Global Summit - Pixel: A Port IoT Solution for Environmental LeverageFIWARE Global Summit - Pixel: A Port IoT Solution for Environmental Leverage
FIWARE Global Summit - Pixel: A Port IoT Solution for Environmental Leverage
 
FreeGIS.net presentation at the Geospatial World Forum in Rotterdam 2013
FreeGIS.net presentation at the Geospatial World Forum in Rotterdam 2013FreeGIS.net presentation at the Geospatial World Forum in Rotterdam 2013
FreeGIS.net presentation at the Geospatial World Forum in Rotterdam 2013
 
FIWARE Global Summit - What Are We Doing in FIWARE Brazil?
FIWARE Global Summit - What Are We Doing in FIWARE Brazil?FIWARE Global Summit - What Are We Doing in FIWARE Brazil?
FIWARE Global Summit - What Are We Doing in FIWARE Brazil?
 
Widgetsintro 28 Jan09
Widgetsintro 28 Jan09Widgetsintro 28 Jan09
Widgetsintro 28 Jan09
 
AGILE: Building the Open Gateway for IoT
AGILE: Building the Open Gateway for IoTAGILE: Building the Open Gateway for IoT
AGILE: Building the Open Gateway for IoT
 
OSS in Bigciites
OSS in BigciitesOSS in Bigciites
OSS in Bigciites
 
SC7 Workshop 3: Big Data Europe Project
SC7 Workshop 3: Big Data Europe ProjectSC7 Workshop 3: Big Data Europe Project
SC7 Workshop 3: Big Data Europe Project
 
IoT Reference Architectures
IoT Reference ArchitecturesIoT Reference Architectures
IoT Reference Architectures
 
IoT Meets Exhibition Areas: a Modular Architecture to Improve Proximity Inter...
IoT Meets Exhibition Areas: a Modular Architecture to Improve Proximity Inter...IoT Meets Exhibition Areas: a Modular Architecture to Improve Proximity Inter...
IoT Meets Exhibition Areas: a Modular Architecture to Improve Proximity Inter...
 
CloudTeams Presentation for the SE4SA Cluster in NetFutures2016
CloudTeams Presentation for the SE4SA Cluster in NetFutures2016CloudTeams Presentation for the SE4SA Cluster in NetFutures2016
CloudTeams Presentation for the SE4SA Cluster in NetFutures2016
 
Webinar on 2nd Open Call - Platforms - slideset
Webinar on 2nd Open Call - Platforms - slidesetWebinar on 2nd Open Call - Platforms - slideset
Webinar on 2nd Open Call - Platforms - slideset
 
scalable Smart aNalytic APplication builder for sentient Cities Overview -- S...
scalable Smart aNalytic APplication builder for sentient Cities Overview -- S...scalable Smart aNalytic APplication builder for sentient Cities Overview -- S...
scalable Smart aNalytic APplication builder for sentient Cities Overview -- S...
 
Webinar on 2nd Open Call - Applications and Trials - slideset
Webinar on 2nd Open Call - Applications and Trials - slidesetWebinar on 2nd Open Call - Applications and Trials - slideset
Webinar on 2nd Open Call - Applications and Trials - slideset
 
Jacques Magen (FIRESTATION): Testbeds for Service Deployment. FIRESTATION’s v...
Jacques Magen (FIRESTATION): Testbeds for Service Deployment. FIRESTATION’s v...Jacques Magen (FIRESTATION): Testbeds for Service Deployment. FIRESTATION’s v...
Jacques Magen (FIRESTATION): Testbeds for Service Deployment. FIRESTATION’s v...
 
Secure Cloud - Secure Big Data Processing in Untrusted Clouds
Secure Cloud - Secure Big Data Processing in Untrusted CloudsSecure Cloud - Secure Big Data Processing in Untrusted Clouds
Secure Cloud - Secure Big Data Processing in Untrusted Clouds
 
Support.services.4.sg.developers
Support.services.4.sg.developersSupport.services.4.sg.developers
Support.services.4.sg.developers
 
Iot & digital services platform in skiing station cwin18_toulouse
Iot & digital services platform in skiing station cwin18_toulouseIot & digital services platform in skiing station cwin18_toulouse
Iot & digital services platform in skiing station cwin18_toulouse
 
CloudTeams - Boosting Collaboration of Developers and End Users Together for ...
CloudTeams - Boosting Collaboration of Developers and End Users Together for ...CloudTeams - Boosting Collaboration of Developers and End Users Together for ...
CloudTeams - Boosting Collaboration of Developers and End Users Together for ...
 
MEASURE H2020 project presented at OW2con'19, June 12-13, 2019, Paris.
 MEASURE H2020 project presented at OW2con'19, June 12-13, 2019, Paris.  MEASURE H2020 project presented at OW2con'19, June 12-13, 2019, Paris.
MEASURE H2020 project presented at OW2con'19, June 12-13, 2019, Paris.
 
Data Ownership & Trust in the IoT
Data Ownership & Trust in the IoTData Ownership & Trust in the IoT
Data Ownership & Trust in the IoT
 

En vedette

En vedette (9)

Conceptos Técnicos de Mobile para QA
Conceptos Técnicos de Mobile para QAConceptos Técnicos de Mobile para QA
Conceptos Técnicos de Mobile para QA
 
5º MeetUP ARQconf 2016 - IoT: What is it really and how does it work?
5º MeetUP ARQconf 2016 - IoT: What is it really and how does it work?5º MeetUP ARQconf 2016 - IoT: What is it really and how does it work?
5º MeetUP ARQconf 2016 - IoT: What is it really and how does it work?
 
Internet of Things (IoT) is a King, Big data is a Queen and Cloud is a Palace
Internet of Things (IoT) is a King, Big data is a Queen and Cloud is a PalaceInternet of Things (IoT) is a King, Big data is a Queen and Cloud is a Palace
Internet of Things (IoT) is a King, Big data is a Queen and Cloud is a Palace
 
Big Data, Cloud Computing, Internet of Things & Co. Technologien von heute - ...
Big Data, Cloud Computing, Internet of Things & Co. Technologien von heute - ...Big Data, Cloud Computing, Internet of Things & Co. Technologien von heute - ...
Big Data, Cloud Computing, Internet of Things & Co. Technologien von heute - ...
 
Is your MQTT broker IoT ready?
Is your MQTT broker IoT ready?Is your MQTT broker IoT ready?
Is your MQTT broker IoT ready?
 
MQTT, Eclipse Paho and Java - Messaging for the Internet of Things
MQTT, Eclipse Paho and Java - Messaging for the Internet of ThingsMQTT, Eclipse Paho and Java - Messaging for the Internet of Things
MQTT, Eclipse Paho and Java - Messaging for the Internet of Things
 
Attribute Based Access Control
Attribute Based Access ControlAttribute Based Access Control
Attribute Based Access Control
 
Reference architecture for Internet of Things
Reference architecture for Internet of ThingsReference architecture for Internet of Things
Reference architecture for Internet of Things
 
Open Source IoT Project Flogo - Introduction, Overview and Architecture
Open Source IoT Project Flogo - Introduction, Overview and ArchitectureOpen Source IoT Project Flogo - Introduction, Overview and Architecture
Open Source IoT Project Flogo - Introduction, Overview and Architecture
 

Similaire à Attribute-based Access Control scheme in federated IoT platforms

OSGi IoT Demo - OSGi Community Event 2014
OSGi IoT Demo - OSGi Community Event 2014OSGi IoT Demo - OSGi Community Event 2014
OSGi IoT Demo - OSGi Community Event 2014
mfrancis
 
Netflix for the_360_billion_professional_development_market
Netflix for the_360_billion_professional_development_marketNetflix for the_360_billion_professional_development_market
Netflix for the_360_billion_professional_development_market
KristineMejia2
 

Similaire à Attribute-based Access Control scheme in federated IoT platforms (20)

Distributed Development of IoT Middleware with Microservices
Distributed Development of IoT Middleware with MicroservicesDistributed Development of IoT Middleware with Microservices
Distributed Development of IoT Middleware with Microservices
 
OSGi IoT Demo @ CeBIT 2016
OSGi IoT Demo @ CeBIT 2016OSGi IoT Demo @ CeBIT 2016
OSGi IoT Demo @ CeBIT 2016
 
Javantura v6 - Building IoT Middleware with Microservices - Mario Kusek
Javantura v6 - Building IoT Middleware with Microservices - Mario KusekJavantura v6 - Building IoT Middleware with Microservices - Mario Kusek
Javantura v6 - Building IoT Middleware with Microservices - Mario Kusek
 
Building IoT Middleware with Microservices
Building IoT Middleware with MicroservicesBuilding IoT Middleware with Microservices
Building IoT Middleware with Microservices
 
C. Santoro, Labour Market Areas Web application based on Istat SDP framework
C. Santoro, Labour Market Areas Web application based on Istat SDP frameworkC. Santoro, Labour Market Areas Web application based on Istat SDP framework
C. Santoro, Labour Market Areas Web application based on Istat SDP framework
 
Smartweek 2014 London: EU FP7 SocIoTal project overview - Michele Nati - Univ...
Smartweek 2014 London: EU FP7 SocIoTal project overview - Michele Nati - Univ...Smartweek 2014 London: EU FP7 SocIoTal project overview - Michele Nati - Univ...
Smartweek 2014 London: EU FP7 SocIoTal project overview - Michele Nati - Univ...
 
Genesi di una tecnologia, dalla ricerca all'industria...
Genesi di una tecnologia, dalla ricerca all'industria...Genesi di una tecnologia, dalla ricerca all'industria...
Genesi di una tecnologia, dalla ricerca all'industria...
 
TPAC2016 - From Linked Building Data to Building Data on the Web
TPAC2016 - From Linked Building Data to Building Data on the WebTPAC2016 - From Linked Building Data to Building Data on the Web
TPAC2016 - From Linked Building Data to Building Data on the Web
 
SocIoTal project-overview - ICT30 Community Day London
SocIoTal project-overview - ICT30 Community Day LondonSocIoTal project-overview - ICT30 Community Day London
SocIoTal project-overview - ICT30 Community Day London
 
OSGi IoT Demo - OSGi Community Event 2014
OSGi IoT Demo - OSGi Community Event 2014OSGi IoT Demo - OSGi Community Event 2014
OSGi IoT Demo - OSGi Community Event 2014
 
Collaboration Mechanisms for IoT Platform Federations Fostering Organizationa...
Collaboration Mechanisms for IoT Platform Federations Fostering Organizationa...Collaboration Mechanisms for IoT Platform Federations Fostering Organizationa...
Collaboration Mechanisms for IoT Platform Federations Fostering Organizationa...
 
Network Automation e-Academy
Network Automation e-AcademyNetwork Automation e-Academy
Network Automation e-Academy
 
A Framework for Cognitive Internet of Things based on Blockchain
A Framework for Cognitive Internet of Things based on BlockchainA Framework for Cognitive Internet of Things based on Blockchain
A Framework for Cognitive Internet of Things based on Blockchain
 
The Automation Continuum
The Automation ContinuumThe Automation Continuum
The Automation Continuum
 
Snap4City November 2019 Course: Smart City IOT platform installation, deploy,...
Snap4City November 2019 Course: Smart City IOT platform installation, deploy,...Snap4City November 2019 Course: Smart City IOT platform installation, deploy,...
Snap4City November 2019 Course: Smart City IOT platform installation, deploy,...
 
LEDU Education Ecosystem Whitepaper
LEDU Education Ecosystem WhitepaperLEDU Education Ecosystem Whitepaper
LEDU Education Ecosystem Whitepaper
 
LEDU Education Ecosystem Whitepaper
LEDU Education Ecosystem WhitepaperLEDU Education Ecosystem Whitepaper
LEDU Education Ecosystem Whitepaper
 
Netflix for the_360_billion_professional_development_market
Netflix for the_360_billion_professional_development_marketNetflix for the_360_billion_professional_development_market
Netflix for the_360_billion_professional_development_market
 
2017 GeoBusiness
2017 GeoBusiness 2017 GeoBusiness
2017 GeoBusiness
 
Geospatial innovation along four dimensions
Geospatial innovation along four dimensionsGeospatial innovation along four dimensions
Geospatial innovation along four dimensions
 

Dernier

Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
amilabibi1
 
If this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New NigeriaIf this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New Nigeria
Kayode Fayemi
 
Uncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac FolorunsoUncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac Folorunso
Kayode Fayemi
 
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptx
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptxChiulli_Aurora_Oman_Raffaele_Beowulf.pptx
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptx
raffaeleoman
 

Dernier (18)

Report Writing Webinar Training
Report Writing Webinar TrainingReport Writing Webinar Training
Report Writing Webinar Training
 
Thirunelveli call girls Tamil escorts 7877702510
Thirunelveli call girls Tamil escorts 7877702510Thirunelveli call girls Tamil escorts 7877702510
Thirunelveli call girls Tamil escorts 7877702510
 
ICT role in 21st century education and it's challenges.pdf
ICT role in 21st century education and it's challenges.pdfICT role in 21st century education and it's challenges.pdf
ICT role in 21st century education and it's challenges.pdf
 
Digital collaboration with Microsoft 365 as extension of Drupal
Digital collaboration with Microsoft 365 as extension of DrupalDigital collaboration with Microsoft 365 as extension of Drupal
Digital collaboration with Microsoft 365 as extension of Drupal
 
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdfAWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
 
Dreaming Music Video Treatment _ Project & Portfolio III
Dreaming Music Video Treatment _ Project & Portfolio IIIDreaming Music Video Treatment _ Project & Portfolio III
Dreaming Music Video Treatment _ Project & Portfolio III
 
The workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdf
The workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdfThe workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdf
The workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdf
 
Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...
Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...
Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...
 
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
 
If this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New NigeriaIf this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New Nigeria
 
lONG QUESTION ANSWER PAKISTAN STUDIES10.
lONG QUESTION ANSWER PAKISTAN STUDIES10.lONG QUESTION ANSWER PAKISTAN STUDIES10.
lONG QUESTION ANSWER PAKISTAN STUDIES10.
 
Uncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac FolorunsoUncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac Folorunso
 
My Presentation "In Your Hands" by Halle Bailey
My Presentation "In Your Hands" by Halle BaileyMy Presentation "In Your Hands" by Halle Bailey
My Presentation "In Your Hands" by Halle Bailey
 
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptx
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptxChiulli_Aurora_Oman_Raffaele_Beowulf.pptx
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptx
 
Sector 62, Noida Call girls :8448380779 Noida Escorts | 100% verified
Sector 62, Noida Call girls :8448380779 Noida Escorts | 100% verifiedSector 62, Noida Call girls :8448380779 Noida Escorts | 100% verified
Sector 62, Noida Call girls :8448380779 Noida Escorts | 100% verified
 
Causes of poverty in France presentation.pptx
Causes of poverty in France presentation.pptxCauses of poverty in France presentation.pptx
Causes of poverty in France presentation.pptx
 
Dreaming Marissa Sánchez Music Video Treatment
Dreaming Marissa Sánchez Music Video TreatmentDreaming Marissa Sánchez Music Video Treatment
Dreaming Marissa Sánchez Music Video Treatment
 
Aesthetic Colaba Mumbai Cst Call girls 📞 7738631006 Grant road Call Girls ❤️-...
Aesthetic Colaba Mumbai Cst Call girls 📞 7738631006 Grant road Call Girls ❤️-...Aesthetic Colaba Mumbai Cst Call girls 📞 7738631006 Grant road Call Girls ❤️-...
Aesthetic Colaba Mumbai Cst Call girls 📞 7738631006 Grant road Call Girls ❤️-...
 

Attribute-based Access Control scheme in federated IoT platforms