XACML for Building Access Control Policies in Internet of Things

Hany F. Atlam, Madini O. Alassafi, Ahmed Alenezi, Robert J. Walters, Gary B. Wills
2018 Proceedings of the 3rd International Conference on Internet of Things, Big Data and Security  
Although the Internet of things (IoT) brought unlimited benefits, it also brought many security issues. The access control is one of the main elements to address these issues. It provides the access to system resources only to authorized users and ensures that they behave in an authorized manner during their access sessions. One of the significant components of any access control model is access policies. They are used to build the criteria to permit or deny any access request. Building an
more » ... ient access control model for the IoT require selecting an appropriate access policy language to implement access policies. Therefore, this paper presents an overview of most common access policy languages. It starts with discussing different access control models and features of the access policy. After reviewing different access policy languages, we proposed XACML as the most efficient and appropriate policy language for the IoT as it compatible with different platforms, provides a distributed and flexible approach to work with different access control scenarios of the IoT system. In addition, we proposed an XACML model for an Adaptive Risk-Based Access Control (AdRBAC) for the IoT and showed how the access decision will be made using XACML.
doi:10.5220/0006725102530260 dblp:conf/iotbd/AtlamAAWW18 fatcat:numhemwx6vf4jghud73ueplmyi