Efficient and User Friendly Inter-domain Device Authentication/Access Control for Home Networks
Device authentication can reinforce the security of the home network services by ensuring that only specific authorized devices by specific authorized users can access the services. And it is also a mandatory technology for context-aware services in which users do not participate in the service flow. In this paper, we propose a device authentication and access control scheme based on two-layered PKI approach for efficient communication and user convenience. The two layers of our model are Global PKI layer and Localized PKI layer. Global PKI layer uses conventional PKI model. There is only one global root CA, and certificate verification is performed by validating the certificate-chain linked to the root CA. Otherwise, in Localized PKI layer, each home gateway takes a role of root CA which is responsible for issuing device certificates to the devices belong to its domain. We use Global PKI layer for device registration and authentication of inter-home-network, but use Localized PKI layer to authenticate each end-device. Based on this separating, our model provides secure, efficient and user friendly multi-domain device authentication protocols. We also provide a convenient access control scheme using Attribute Mapping Certificate.
KeywordsAccess Control Home Network Access Control Policy Access Control Model Client Device
Unable to display preview. Download preview PDF.
- 3.Device Authentication, http://www.safenet-inc.com
- 4.TrustConnector 2, http://www.phoenix.com
- 5.Bluetooth Core Specification v2.0 (2004), http://www.bluetooth.org/spec/
- 6.ZigBee Specification v1.0 (December 2004), http://www.zigbee.org/en/spec_download/
- 7.OpenCable Security Specification (2004), http://www.opencable.com/specifications/
- 8.Gehrmann, C., Nyberg, K., Mitchell, C.J.: The personal CA - PKI for a personal area network. [Conference Paper] IST Mobile and Wireless Telecommunications Summit 2002, pp. 31–35 (2002)Google Scholar
- 9.Universal Plug and Play Forum, http://www.upnp.org/
- 10.Ellison, C.: UPnP Security Ceremonies Version 1.0. UPnP Forum (2003)Google Scholar
- 11.Hwang, J.-B., Kim, D.-W., Lee, Y.-K., Han, J.-W.: Two Layered PKI Model for Device Authentication in Multi-Domain Home Networks. In: Proc. of 10th International Symposium on Consumer Electronics (ICSE) (June 2006)Google Scholar