Loading [MathJax]/extensions/MathMenu.js
Toward Zero-Trust IoT Networks via Per-Packet Authorization | IEEE Journals & Magazine | IEEE Xplore

Toward Zero-Trust IoT Networks via Per-Packet Authorization


Abstract:

Internet of things (IoT) networks allow cross-device interactions to achieve various intelligent applications, for example, smart homes and smart commercial spaces. Howev...Show More

Abstract:

Internet of things (IoT) networks allow cross-device interactions to achieve various intelligent applications, for example, smart homes and smart commercial spaces. However, cross-device interactions are often protected by inadequate authorization mechanisms, making them susceptible to various attacks, including connection-based attacks, application impersonation attacks, and so on. In this article, we propose a zero-trust IoT network architecture, OUTSIDE, designed to provide fine-grained authorization for IoT applications. It achieves the application-level authorization at the network layer by encoding the capability information of applications into verifiable tokens. Meanwhile, it enables a zero-trust service for per-packet verification, ensuring that every packet is sent by an authorized application with proper access privileges. Particularly, our architecture is versatile and compatible with various IoT protocols. We prototype and deploy OUTSIDE in Raspberry Pis and ESP32 microcontrollers running over the constrained application protocol (CoAP). The experimental results show that our architecture incurs negligible performance degradation.
Published in: IEEE Communications Magazine ( Volume: 62, Issue: 12, December 2024)
Page(s): 90 - 96
Date of Publication: 17 June 2024

ISSN Information:

Funding Agency:


Introduction

The past years have witnessed the rapid growth of the Internet of Things (IoT) systems. In particular, rich IoT applications enabling cross-device interactions (e.g., device-to-device interactions, device-to-cloud interactions) boost the wide-spread adoption of IoT devices. The number of IoT devices has reached more than 10 billion in 2021 and the number is estimated to exceed 25.4 billion in 2030 [1].

Contact IEEE to Subscribe

References

References is not available for this document.