Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Application-scoped Access Control for the Construction Industry
Luleå University of Technology, Department of Computer Science, Electrical and Space Engineering, Embedded Internet Systems Lab.ORCID iD: 0000-0001-5408-0008
Luleå University of Technology, Department of Computer Science, Electrical and Space Engineering.
Luleå University of Technology, Department of Computer Science, Electrical and Space Engineering, Embedded Internet Systems Lab.ORCID iD: 0000-0002-2654-2292
Luleå University of Technology, Department of Computer Science, Electrical and Space Engineering.
Show others and affiliations
2021 (English)In: 2021 26th IEEE International Conference on Emerging Technologies and Factory Automation (ETFA), IEEE, 2021, p. 1-8Conference paper, Published paper (Refereed)
Abstract [en]

The construction industry is characterized by its extensive and dynamic collaborations between contractors providing various services and expertise. In such eco-systems, the secure sharing of information, data and equipment challenges the access control needs to be application agnostic. Furthermore, it needs fine-grained access policies including means for abstraction to ease administration, and support for delegated authorization in Service-Oriented Architecture (SOA) based systems. In this paper, we explore the use of delegated access using OAuth 2.0 with Attribute-Based Access Control (ABAC) for the collaborative sharing of equipment at construction sites. In particular, we investigate the use of contextual attributes to capture the dynamic aspects, such as location and urgency, in the booking of construction lifts. Through this study, we propose a solution based on the IoT Application-scoped Access Control as a Service (IAACaaS) architecture model combined with NIST Next Generation Access Control (NGAC). We present an architecture for a general Identity and Access Management (IAM) system for the construction industry, and provide a design and guide for implementation of this architecture in terms how key functionalities should be captured as reusable micro-services. Moreover, we describe how these micro-services can be combined to make the system a general and reusable solution providing access control for collaborative sharing of data, information and equipment at construction sites.

Place, publisher, year, edition, pages
IEEE, 2021. p. 1-8
Keywords [en]
Access control, Conferences, Collaboration, NIST, Service-oriented architecture, Stakeholders, Next generation networking, identity and access management, IAM, localization, prioritization, ABAC, NGAC
National Category
Computer Sciences
Research subject
Cyber-Physical Systems; Pervasive Mobile Computing
Identifiers
URN: urn:nbn:se:ltu:diva-88443DOI: 10.1109/ETFA45728.2021.9613645ISI: 000766992600221Scopus ID: 2-s2.0-85122954034OAI: oai:DiVA.org:ltu-88443DiVA, id: diva2:1620697
Conference
26th IEEE International Conference on Emerging Technologies and Factory Automation (ETFA 2021), Västerås, Sweden, September 7-10, 2021
Note

ISBN för värdpublikation: 978-1-7281-2989-1, 978-1-7281-2990-7

Available from: 2021-12-16 Created: 2021-12-16 Last updated: 2023-11-17Bibliographically approved
In thesis
1. Attribute-based Approaches for Secure Data Sharing in Industry
Open this publication in new window or tab >>Attribute-based Approaches for Secure Data Sharing in Industry
2022 (English)Licentiate thesis, comprehensive summary (Other academic)
Abstract [en]

The Industry 4.0 revolution relies heavily on data to generate value, innovation, new services, and optimize current processes [1]. Technologies such as Internet of Things (IoT), machine learning, digital twins, and much more depend directly on data to bring value and innovation to both discrete manufacturing and process industries. The origin of data may vary from sensor data to financial statements and even strictly confidential user or business data. In data-driven ecosystems, collaboration between different actors is often needed to provide services such as analytics, logistics, predictive maintenance, process improvement, and more. Data therefore cannot be considered a corporate internal asset only. Hence, data needs to be shared among organizations in a data-driven ecosystem for it to be used as a strategic resource for creating desired values, innovations, or process improvements [2]. When sharing business critical and sensitive data, the access to the data needs to be accurately controlled to prevent leakage to authorized users and organizations. 

Access control is a mechanism to control actions of users over objects, e.g., to read, write, and delete files, accessing data, writing over registers, and so on. This thesis studies one of the latest access control mechanisms in Attribute Based Access Control (ABAC) for industrial data sharing. ABAC emerges as an evolution of the commonly industry-wide used Role-based Access Control. ABAC presents the idea of attributes to create access policies, rather than manually assigned roles or ownerships, enabling for expressive fine-granular access control policies. Furthermore, this thesis presents approaches to implement ABAC into industrial IoT data sharing applications, with special focus on the manageability and granularity of the attributes and policies.  The thesis also studies the implications of outsourced data storage on third party cloud servers over access control for data sharing and explores how to integrate cryptographic techniques and paradigms into data access control. In particular, the combination of ABAC and Attribute-Based Encryption (ABE) is investigated to protect privacy over not-fully trusted domains. In this, important research gaps are identified. 

Place, publisher, year, edition, pages
Luleå University of Technology, 2022
Series
Licentiate thesis / Luleå University of Technology, ISSN 1402-1757
Keywords
Access Control, NGAC, Fine-grained, IoT, Industry 4.0, Encryption, flexible
National Category
Computer Systems
Research subject
Cyber-Physical Systems
Identifiers
urn:nbn:se:ltu:diva-90432 (URN)978-91-8048-092-5 (ISBN)978-91-8048-093-2 (ISBN)
Presentation
2022-06-15, A117, Luleå University of technology 971 87, Luleå, 09:00 (English)
Opponent
Supervisors
Projects
Arrowhead Tools
Available from: 2022-04-26 Created: 2022-04-26 Last updated: 2023-09-05Bibliographically approved
2. Attribute-based Approaches for Secure Data Sharing in the Industry
Open this publication in new window or tab >>Attribute-based Approaches for Secure Data Sharing in the Industry
2023 (English)Doctoral thesis, comprehensive summary (Other academic)
Abstract [en]

In the Industry 4.0 era, secure and efficient data sharing is vital for innovation and operational enhancement. Industry 4.0 envisions a highly connected ecosystem where machines, devices, and stakeholders collaborate in real time to optimize processes, enhance productivity, and create new value propositions. However, this surge in data-driven collaboration brings forth a critical challenge, ensuring the secure and controlled sharing of sensitive information. As organizations embrace the potential of Industry 4.0, the need for robust mechanisms to achieve key data security properties of data integrity, confidentiality, and availability, while enabling efficient data exchange becomes paramount. However, while the promise of Industry 4.0 presents promising opportunities, it also introduces a set of challenges intrinsic to data security solutions. These solutions, while promising in providing fine-grained data security, introduce complexities such as administrative overhead and substantial management efforts for the users. Striking a balance between robust security and operational ease is critical for enabling seamless data exchange within the evolving landscape of Industry 4.0.

This thesis explores the realm of Attribute-based approaches to achieve the desired secure data sharing, pivotal in the digitized Industry 4.0 environment.  An overarching objective is to achieve compatibility of these data-securing mechanisms with the Industry 4.0 paradigms through the usage of attribute-based approaches. This includes the exploration of the existing solutions within the state-of-the-art and its analysis in the context of usability and practicality for industrial adoption. 

Access control entails the establishment of policies and mechanisms to regulate who can access specific resources or information, under what conditions, and to what extent. The study will delve into various access control models and their applicability, with a particular emphasis on Attribute-Based Access Control. Moreover, through the creation of proofs-of-concepts implementations, we explore the usability of Attribute-based Access Control (ABAC) models and policy languages, applied to different aspects of the data-sharing process.  Manageability, user-friendliness, and fine-granularity of the access control were identified as key properties for the usability of data securing technologies in industry. Hence, discovering and addressing challenges for such properties is of special focus for this thesis. 

In addition, this thesis explores attribute-based encryption techniques, seeking to augment data security while minimizing additional operational complexities. Moreover, this thesis also explores the implications of third-party cloud services, popular in Industry 4.0 environments, as well as third-party stakeholder data sharing to motivate the need to ensure both in-transit and at-rest data security.

This thesis makes significant contributions in the domain of secure data sharing in Industry 4.0. First, it contextualizes access control within the broader data security landscape and explores state-of-the-art Attribute-Based Access Control policy languages. The research designs, evaluates, and automates ABAC models to address fine-granularity and manageability gaps, with a focus on user-friendliness for industrial adoption. Furthermore, it proposes and implements an automated management solution for integrating new data sources in Service-Oriented Architecture (SOA) industrial data-sharing applications, within the Eclipse Arrowhead Framework. This includes the innovative proposal of contractual automation of access control policies to enhance efficiency and security. 

Moreover, the research delves into the realm of attribute-based encryption approaches, conducting a state-of-the-art exploration and gap analysis, with a special focus on uncovering the adoption barriers associated with this technology.  Lastly, the thesis designs, implements, and evaluates an ABAC-Enabled ABE solution architecture, covering the discovered gaps, and offering an expressive and user-friendly approach to secure data sharing. These contributions collectively advance the field of data security and access control in the context of Industry 4.0 and similar evolving industrial landscapes

The research indicated that Attribute-based approaches hold promise for practical data protection at rest through access control mechanisms, especially within fine-grained policies. The study explores ABAC in a graph-based policy language, Next-generation Access Control (NGAC), showcasing its potential for reducing administrative workload related to policy management. Simplified policy creation and expression enhance the ease of model implementation. These insights extend to ABE, highlighting the value of delegating attribute management for reduced administrative complexity and improved expressiveness within ABE schemes. This approach allows for automation techniques developed for ABAC policy management to be translated into ABE schemes. 

Place, publisher, year, edition, pages
Luleå: Luleå University of Technology, 2023
Series
Doctoral thesis / Luleå University of Technology 1 jan 1997 → …, ISSN 1402-1544
Keywords
Data security, secure data sharing, Attribute-based Access Control, Attribute-based Encryption, industry 4.0, cyber-physical systems, cyber security
National Category
Computer Systems
Research subject
Cyber-Physical Systems
Identifiers
urn:nbn:se:ltu:diva-101858 (URN)978-91-8048-422-0 (ISBN)978-91-8048-423-7 (ISBN)
Public defence
2023-12-14, A 117, Luleå tekniska universitet, Luleå, 10:00 (English)
Opponent
Supervisors
Available from: 2023-10-31 Created: 2023-10-30 Last updated: 2023-12-01Bibliographically approved

Open Access in DiVA

No full text in DiVA

Other links

Publisher's full textScopus

Authority records

Bodin, UlfChiquito, AlexSynnes, Kåre

Search in DiVA

By author/editor
Bodin, UlfChristofferson, AndréChiquito, AlexRodahl, JohanSynnes, Kåre
By organisation
Embedded Internet Systems LabDepartment of Computer Science, Electrical and Space EngineeringComputer Science
Computer Sciences

Search outside of DiVA

GoogleGoogle Scholar

doi
urn-nbn

Altmetric score

doi
urn-nbn
Total: 246 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf