Document Title

FLUID-IoT: Flexible and Granular Access Control in Shared IoT Environments via UI-Level Control Distribution

Document Information

  • Subject Area: Access Control in Shared IoT Environments
  • Keywords: IoT Security, Access Control, Multi-User IoT, UI Distribution, Smart Home, Permission Settings, Shared Device Management

Research Background and Problem Statement

  • Identified Challenges: The increasing demand for shared IoT devices has exposed limitations in existing access control mechanisms (e.g., Google Home, Amazon Alexa), which predominantly operate on an "all-or-nothing" model. This model can result in:

    • Security Risks: Unnecessary access to sensitive devices (e.g., cameras).
    • User Experience Issues: Hindering the adoption of shared device ecosystems.
  • Significance:

    • To fully realize the potential of IoT in multi-user environments, it is essential to address privacy concerns and the lack of flexibility in device sharing.
    • Granular access control methods can enhance user experience and ensure secure sharing.
  • Research Motivation and Related Work:

    • Existing studies attempt to enhance access control by modifying IoT applications or building new systems, but these approaches often require significant infrastructure changes and are challenging to deploy on proprietary platforms.
    • "Device-level access control" is insufficient to meet user demands for fine-grained management of individual device functionalities (e.g., adjusting the temperature or fan speed of an air conditioner).

Solution

  • Proposed Approach: The FLUID-IoT framework introduces multi-user UI distribution technology, transforming existing IoT applications into centralized control hubs capable of selectively distributing device UI components based on user permissions.

  • Innovations:

    • Granular UI-Based Permissions: Enables functionality-level control based on UI elements (e.g., channel switch or volume control buttons on a smart TV).
    • No Core Device Logic Modification: The framework enforces access control via UI distribution rather than altering the core logic of device connections.
    • Support for Existing IoT Platforms: Can be seamlessly integrated into mainstream proprietary platforms (e.g., Google Home, Amazon Alexa) without extensive source code modifications.
  • Implementation Steps and Key Technologies:

    • Multi-Activity Mode Operation: Supports multiple UI interfaces of IoT applications running simultaneously in the foreground, allowing parallel control by users.
    • UI Extraction and Independent Rendering: Displays each UI element in an independent rendering buffer to ensure flexibility in UI distribution and prevent UI element overlap.
    • Dynamic UI Stream Switching: Configures user permissions to selectively distribute target UI elements via network channels.
    • Compatibility with Multiple Platforms and Existing IoT Applications: The system-level framework directly supports unmodified IoT applications.

Research Outcomes

  • Specific Achievements:

    • FLUID-IoT was successfully integrated into six mainstream IoT applications (e.g., Google Home, Amazon Alexa), covering approximately 90% of the IoT ecosystem.
    • Provided three access control mechanisms:
      1. Differentiated Access Control: Role-based UI functionality allocation.
      2. Time-Based Access Control: Time-slot-based authorization.
      3. Supervised Access Control: Ensures device usage safety through monitoring and authorization.
  • Experiments and Evaluation Results:

    • Coverage Testing: The FLUID-IoT framework supports six mainstream IoT platforms, demonstrating high compatibility.
    • Performance Evaluation:
      • Response Time: Averaging 128.6ms, close to the user-perceived "instantaneous reaction" threshold (100ms).
      • Reduced Synchronization Delays in Multi-User Environments: From an average of 5 seconds on native Google Home to 165ms.
      • Low Memory Consumption: Occupies only 0.297% of the average memory of modern smartphones.
    • User Study:
      • 17 participants conducted field tests of FLUID-IoT, achieving a total score of 79.08 on the SUS scale, categorized as a "good user experience."
      • Most users recognized the significant advantages of differentiated permission settings in daily scenarios.
  • Limitations and Future Directions:

    • Limitations:
      • Currently does not support IoT applications based on third-party UI engines (e.g., Flutter).
      • Relies on a single primary device, posing a single point of failure risk.
      • Does not yet address scenarios involving remote access or physical button bypasses.
    • Future Directions:
      • Support additional access control mechanisms (e.g., location-based or operation rate-limiting controls).
      • Improve scalability to support large-scale user or device scenarios.
      • Develop unified interface solutions across multiple IoT platforms to reduce fragmented experiences between applications.

In summary, FLUID-IoT is a novel framework with broad applicability and high flexibility, offering an innovative solution for fine-grained secure access control in shared IoT environments. It also outlines clear directions for future research.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/147714/2024

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3613904.3641991
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2024
emoji_events
Award
No award tagged
group
Authors
7 authors
sell
Subtopics
Context-Aware Computing, Smart Home Interaction Design, Smart Home Privacy & Security
work
Professions
—
article
Content Status
Full text indexed
hub
Related Papers
9 related papers