Device And Client Authorization Design Apprroach To Address IOT's Security Concerns
Shridhar Mankar, Guruji Ward · 2015
This paper deals with addressing security concerns of IOT by proposing Authorization Server design approach for both IOT devices as well as Client (The user controlling these devices). Authorization Server (AS) is one of the actors described in Open Authorization (OAuth) protocol. AS take care of issuing access tokens to the client after successfully authenticating the resource owner and obtaining authorization. Current version of Authorization Server supports Resource Owner Password Credentials authorization grant type only. The resource owner authentication will be implemented based on Directory Server interactions. Token is represented as a 128-bit immutable universally unique identifier UUID (native java implementation). Generation process described in RFC 4122: A Universally Unique Identifier (UUID) URN Namespace, UUID is generated using a cryptographically strong pseudo random numbers. A cryptographically strong random number minimally complies with the statistical random number generator tests specified in FIPS 140-2, Security Requirements for Cryptographic Modules, An output sequence is cryptographically strong, as described in RFC 1750: Randomness Recommendations for security.