With the growing popularity of the Internet of Things (IoT), devices in households and offices are becoming information sharing "smart" devices controlled via network connections. The growth of collection, handling and distribution of data generated by IoT devices presents ethical and privacy issues. Users have no control over what information is kept or revealed, the interpretation of data collected, data ownership and who can access specific information generated by their IoT devices. This paper describes an approach to data ethical/privacy issues related to IoT using a fine-grained access-control framework on Igor, a centralized home and office automation solution. We designed a capability-based access control framework on top of Igor that allows agents, either human or machine, to access and change only the data to which they are authorised. The applicability of this to the European General Data Protection Regulation (GDPR) should be obvious. The implementation, expert evaluation and performance measurement results demonstrate that this is a promising solution for securing access to data generated by IoT devices.

Additional Metadata
Keywords Access control, Authorization, Ethical, Framework, Internet of Things, IoT, Privacy issues
Persistent URL dx.doi.org/10.1016/j.procs.2018.07.194
Conference 15th International Conference on Mobile Systems and Pervasive Computing, MobiSPC 2018
Citation
Wen Shieng, P.S, Jansen, A.J, & Pemberton, S. (2018). Fine-grained access control framework for Igor, a unified access solution to the Internet of Things. In Procedia Computer Science (pp. 385–392). doi:10.1016/j.procs.2018.07.194