Delegated Anonymous Credentials with Revocation Capability for IoT Service Chains

Abstract

—This article deals with providing privacy-preserving access control in Internet of Things (IoT) systems. Here, a user/IoT device requests access to services rovided by other IoT devices and multiple requests are combined to a requestspecific service chain. An anonymous delegated credential-based system architecture is proposed, here the requester’s identity is not exposed to the services. The article presents the proposed architecture’s various components including the security aspects. Various options for implementing the architecture on resourcefull and resource-constrained services are presented. A prototype of the proposed architecture is then implemented using Linuxbased containers to emulate the services. Two representative systems, namely, a small-scale home automation system using a short service chain and a large-scale industrial automation system using a long service chain are considered. Timing measurements from the implementation are presented to demonstrate that the architecture is feasible and can be adapted for practical use in large-scale IoT systems.

Publication
IEEE Internet of Things Journal
Click the Cite button above to demo the feature to enable visitors to import publication metadata into their reference management software.
Create your slides in Markdown - click the Slides button to check out the example.

Add the publication’s full text or supplementary notes here. You can use rich formatting such as including code, math, and images.

Sandeep Kiran Pinjala
Sandeep Kiran Pinjala
PhD candidate

I like building secure systems using cryptographic protocols to solve real-world problems. My current research involves building practical plausibly deniable systems that are truly private and censorship-resilient.