Nespoli Pantaleone, Zago Mattia, Huertas Celdrán Alberto, Gil Pérez Manuel, Gómez Mármol Félix, García Clemente Félix J
Department of Information and Communications Engineering, University of Murcia, 30100 Murcia, Spain.
Telecommunication Software & Systems Group, Waterford Institute of Technology, X91 K0EK Waterford, Ireland.
Sensors (Basel). 2019 Jun 25;19(12):2832. doi: 10.3390/s19122832.
Continuous authentication was introduced to propose novel mechanisms to validate users' identity and address the problems and limitations exposed by traditional techniques. However, this methodology poses several challenges that remain unsolved. In this paper, we present a novel framework, PALOT, that leverages IoT to provide context-aware, continuous and non-intrusive authentication and authorization services. To this end, we propose a formal information system model based on ontologies, representing the main source of knowledge of our framework. Furthermore, to recognize users' behavioral patterns within the IoT ecosystem, we introduced a new module called "confidence manager". The module is then integrated into an extended version of our early framework architecture, IoTCAF, which is consequently adapted to include the above-mentioned component. Exhaustive experiments demonstrated the efficacy, feasibility and scalability of the proposed solution.
引入持续认证是为了提出新颖的机制来验证用户身份,并解决传统技术所暴露的问题和局限性。然而,这种方法带来了一些尚未解决的挑战。在本文中,我们提出了一个新颖的框架PALOT,它利用物联网来提供上下文感知、持续且非侵入式的认证和授权服务。为此,我们提出了一个基于本体的形式化信息系统模型,它代表了我们框架的主要知识来源。此外,为了识别物联网生态系统内用户的行为模式,我们引入了一个名为“置信度管理器”的新模块。然后将该模块集成到我们早期框架架构IoTCAF的扩展版本中,从而使其经过调整以包含上述组件。详尽的实验证明了所提出解决方案的有效性、可行性和可扩展性。