Abstract
Cybersecurity and trustworthiness of IoT devices are becoming more and more vital. Device attestation is one approach to increase trust through measured evidence of a device’s software integrity. However, the lack of integration to different services still limits the adoption of device attestation in the IoT world. This paper describes integration of Device Identity Composition Engine (DICE) -based device attestation with delegated identity and access management. We present device attestation extensions to two existing authorization flows of the widely used OAuth 2.0 framework. These extensions do not alter the original flows, but they do include attestation evidence and result within the original message content, simplifying integration to existing systems. In addition, we describe our prototype implementation of the solution and present early performance results measured using a physical IoT device. Furthermore, we discuss the benefits and challenges of the approach. The goal of this work is to ease the adoption of device attestation by simplifying integration to existing IoT systems.
| Original language | English |
|---|---|
| Title of host publication | 2021 8th International Conference on Internet of Things |
| Subtitle of host publication | Systems, Management and Security, IOTSMS 2021 |
| Editors | Jaime Mauri Lauret, Mohamed Abdel-Maguid, Yaser Jararweh, Elhadj Benkhelifa |
| Publisher | IEEE Institute of Electrical and Electronic Engineers |
| Pages | 1-8 |
| Number of pages | 8 |
| ISBN (Electronic) | 9781665458689 |
| ISBN (Print) | 978-1-6654-5869-6 |
| DOIs | |
| Publication status | Published - 2021 |
| MoE publication type | A4 Article in a conference publication |
| Event | 8th International Conference on Internet of Things: Systems, Management and Security, IOTSMS: Online - Virtual, Gandia, Spain Duration: 6 Dec 2021 → 9 Dec 2021 |
Conference
| Conference | 8th International Conference on Internet of Things: Systems, Management and Security, IOTSMS |
|---|---|
| Country/Territory | Spain |
| City | Gandia |
| Period | 6/12/21 → 9/12/21 |
Keywords
- Access Control
- Cybersecurity
- Identity Management
- IoT
- OAuth 2.0.
- Remote Attestation
Fingerprint
Dive into the research topics of 'Delegated Device Attestation for IoT'. Together they form a unique fingerprint.Research output
- 6 Citations
- 1 Article
-
Security-Driven Prioritization for Tactical Mobile Networks
Suomalainen, J., Julku, J., Heikkinen, A., Rantala, S. J. & Yastrebova, A., Jun 2022, In: Journal of Information Security and Applications. 67, 103198.Research output: Contribution to journal › Article › Scientific › peer-review
Open AccessFile6 Link opens in a new tab Citations (Scopus)231 Downloads (Pure)
Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver