Security interoperability in heterogeneous IoT platforms

Se-Ra Oh, Jahoon Koo, Young‐Gab Kim · Proceedings of the 37th ACM/SIGAPP Symposium on Applied Computing · 2022

The Internet of Things (IoT) has strong potential to improve the accessibility and usability of our daily lives and industries, and various related technologies are being developed. In particular, IoT platforms are the role of middleware in IoT environments and are software that connects multiple devices such as various sensors, access points, and data networks. In addition, the open authorization (OAuth) 2.0 is an authorization framework standard for delegating authority to a third party and is widely used to protect APIs in IoT platforms and the existing web environments. However, interoperability and security are barriers that hinder the potential. Technologies have often been developed without adequate considerations for interoperability and security, such as the OAuth 2.0 framework widely used in IoT domains. Furthermore, most studies did not consider interoperability, even though interoperability among heterogeneous domains is critical for the IoT to share resources. No study addressed the limitation of the conventional OAuth 2.0 framework to support interoperability, and the studies did not comprehensively discuss the security of the OAuth 2.0 framework. Therefore, based on the well-known threats of the conventional OAuth 2.0 framework, we identify possible threats and proper countermeasures for the interoperable OAuth 2.0 framework (IOAF) to achieve security interoperability. In addition, we propose a new authorization code for multiple domains (ACMD) grant flow using a proof key for code exchange (PKCE), which is more secure than the current ACMD flow.

Read the paper · More papers on PaperTik