MATRaCAE: Time-Based Revocable Access Control in the IoT

Clémentine Gritti, Emanuel Regnath, Sebastian Steinhorst

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Internet of Things (IoT) promises a strong connection between digital and physical environments. Nevertheless, this framework comes with security vulnerabilities, due to the heterogeneous nature of devices and the diversity of their provenance. Furthermore, technical constraints (e.g. devices’ limited resources) require to lighten the design of the underlying security protocols. Liu et al. presented a system for data access with time-based control and direct user revocation that are beneficial features in IoT. In this paper, we propose an extension of this system, called MATRaCAE, that involves multiple authorities and considers binary time credentials. Doing so, we mitigate the key escrow problem and comes with a better trade-off between key update frequency and number of revoked users, which limited the applicability of Liu et al.’s scheme in IoT. Our solution can be proved secure under the Decisional Bilinear Diffie-Hellman Exponent assumption. Subsequently, we implement and evaluate MATRaCAE to demonstrate its suitability to IoT frameworks.

Original languageEnglish
Title of host publicationProceedings of the 21st International Conference on Security and Cryptography, SECRYPT 2024
EditorsSabrina De Capitani Di Vimercati, Pierangela Samarati
PublisherScience and Technology Publications, Lda
Pages274-285
Number of pages12
ISBN (Electronic)9789897587092
DOIs
StatePublished - 2024
Event21st International Conference on Security and Cryptography, SECRYPT 2024 - Dijon, France
Duration: 8 Jul 202410 Jul 2024

Publication series

NameProceedings of the International Conference on Security and Cryptography
ISSN (Print)2184-7711

Conference

Conference21st International Conference on Security and Cryptography, SECRYPT 2024
Country/TerritoryFrance
CityDijon
Period8/07/2410/07/24

Keywords

  • Attribute-Based Encryption
  • Direct Revocation
  • Internet of Things
  • Time-Based Access Control

Fingerprint

Dive into the research topics of 'MATRaCAE: Time-Based Revocable Access Control in the IoT'. Together they form a unique fingerprint.

Cite this