Trust-Aware Authentication and Authorization for IoT: A Federated Machine Learning Approach
作者:Kazi Istiaque Ahmed, Mohammad Tahir, Sian Lun Lau, Mohamed Hadi Habaebi, Abdul Ahad, Amna Mughees · 发表于:IEEE Internet of Things Journal · 年份:2024 · DOI:10.1109/jiot.2024.3512657 · 被引用次数:14 · 研究领域:Privacy-Preserving Technologies in Data、Blockchain Technology Applications and Security、Cloud Data Security Solutions
The need for strong authentication and authorization (AA) security measures is growing with the proliferation of the Internet of Things (IoT). This article presents an advanced trust-aware AA system for IoT environments. Using real-world data collected from Zigbee Zolertia Z1 devices, a federated machine learning model was developed that utilizes physical layer properties, such as received signal strength indicator (RSSI), link quality indicator (LQI), device internal temperature, device battery level, and device media access control address. The proposed solution for AA IoT utilizes a trust calculation algorithm based on federated learning (FL), which is suitable for IoT environments and enables data privacy and scalability. Incorporating device-specific information, such as internal temperature and battery level, helps a more nuanced evaluation of the device’s status, improving the precision of trust calculations. The proposed architecture performs particularly well for unauthorized intrusion attempts modeled using spoofing, replay and Sybil attacks. Specifically, the proposed methodology can detect malicious AA activities classified as Writing + Reading attempts with 100% accuracy, demonstrating its effectiveness in protecting IoT devices from attacks. Furthermore, the model achieves 99.18% accuracy in reading access permissions and 99.99% accuracy in identifying Write + Read + Execute permissions, highlighting its reliability in implementing access control restrictions fo...