DocumentCode :
3576814
Title :
Federated Identity and Access Management for the Internet of Things
Author :
Fremantle, Paul ; Aziz, Benjamin ; Kopecky, Jacek ; Scott, Philip
Author_Institution :
Sch. of Comput., Univ. of Portsmouth, Portsmouth, UK
fYear :
2014
Firstpage :
10
Lastpage :
17
Abstract :
We examine the use of Federated Identity and Access Management (FIAM) approaches for the Internet of Things (IoT). We look at specific challenges that devices, sensors and actuators have, and look for approaches to address them. OAuth is a widely deployed protocol -- built on top of HTTP -- for applying FIAM to Web systems. We explore the use of OAuth for IoT systems that instead use the lightweight MQTT 3.1 protocol. In order to evaluate this area, we built a prototype that uses OAuth 2.0 to enable access control to information distributed via MQTT. We evaluate the results of this prototyping activity, and assess the strengths and weaknesses of this approach, and the benefits of using the FIAM approaches with IoT and Machine to Machine (M2M) scenarios. Finally we outline areas for further research.
Keywords :
Internet of Things; authorisation; FIAM; Internet of Things; IoT; M2M scenarios; MQTT 3.1 protocol; OAuth 2.0; access control; federated identity and access management; machine to machine scenarios; Authentication; Authorization; Hip; Protocols; Servers;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Secure Internet of Things (SIoT), 2014 International Workshop on
Type :
conf
DOI :
10.1109/SIoT.2014.8
Filename :
7058903
Link To Document :
بازگشت