Identity Authentication and Capability Based Access Control (IACAC) for the Internet of Things


  • Parikshit N. Mahalle Center for TeleInFrastruktur, Aalborg University, Aalborg, Denmark
  • Bayu Anggorojati Center for TeleInFrastruktur, Aalborg University, Aalborg, Denmark
  • Neeli R. Prasad Center for TeleInFrastruktur, Aalborg University, Aalborg, Denmark
  • Ramjee Prasad Center for TeleInFrastruktur, Aalborg University, Aalborg, Denmark



access control, authentication, capability, Internet of Things


In the last few years the Internet of Things (IoT) has seen widespreadapplication and can be found in each field. Authentication and accesscontrol are important and critical functionalities in the context of IoTto enable secure communication between devices. Mobility, dynamicnetwork topology and weak physical security of low power devices in IoTnetworks are possible sources for security vulnerabilities. It ispromising to make an authentication and access control attack resistant andlightweight in a resource constrained and distributed IoT environment.This paper presents the Identity Authentication and Capability basedAccess Control (IACAC) model with protocol evaluation and performanceanalysis. To protect IoT from man-in-the-middle, replay and denial ofservice (Dos) attacks, the concept of capability for access control isintroduced. The novelty of this model is that, it presents an integratedapproach of authentication and access control for IoT devices. Theresults of other related study have also been analyzed to validate andsupport our findings. Finally, the proposed protocol is evaluated byusing security protocol verification tool and verification results showsthat IACAC is secure against aforementioned attacks. This paper alsodiscusses performance analysis of the protocol in terms of computationaltime compared to other existing solutions. Furthermore, this paper addresseschallenges in IoT and security attacks are modelled with the use casesto give an actual view of IoT networks.


Author Biographies

Parikshit N. Mahalle, Center for TeleInFrastruktur, Aalborg University, Aalborg, Denmark

Parikshit N. Mahalle is IEEE member, ACM member, Life member ISTE and graduated in Computer Engineering from Amravati University,Maharashtra, India in 2000 and received Master in Computer Engineering from Pune University in 2007. From 2000 to 2005, he was working as lecturer in Vishwakarma Institute of technology, Pune, India. From August 2005, he was working as an Assistant Professor in Department of Computer Engineering, STES’s Smt. Kashibai Navale College of Engineering, and Pune, India. Currently he is pursuing his Ph.D. in wireless communication at Center for TeleInFrastruktur (CTIF), Aalborg University, Denmark. He has published 25 papers at national and international level. He has authored five books on subjects like Data Structures, Theory of Computations and Programming Languages. He is also the recipient of “Best Faculty Award” by STES and Cognizant Technologies Solutions. His research interests are Algorithms, IoT, Identity Management and Security.

Bayu Anggorojati, Center for TeleInFrastruktur, Aalborg University, Aalborg, Denmark

Bayu Anggorojati is currently pursuing his PhD at Center for TeleIn-Frastruktur (CTIF), Aalborg University. His main research interest is in access control for RFID system and IoT. During the period of his PhD work, he has been involved in several projects, especially the EC projects, such as ASPIRE, ISISEMD, LIFE2.0, and BETaaS.

Neeli R. Prasad, Center for TeleInFrastruktur, Aalborg University, Aalborg, Denmark

Neeli Rashmi Prasad, Ph.D., IEEE Senior Member, Director, Center For TeleInfrastructure USA (CTIF-USA), Princeton, USA. She is also Head of Research and Coordinator of Themantic area Network without Borders, Center for TeleInfrastruktur (CTIF) head office, Aalborg University, Aalborg, Denmark.
She is leading IoT Testbed at Easy Life Lab (IoT/M2M and eHealth) and Secure Cognitive radio network testbed at S-Cogito Lab (Network Manage-ment, Security, Planning , etc.). She received her Ph.D. from University of Rome “Tor Vergata”, Rome, Italy, in the field of “adaptive security for wireless heterogeneous networks” in 2004 and M.Sc. (Ir.) degree in Electrical Engineering from Delft University of Technology, the Netherlands, in the field of “Indoor Wireless Communications using Slotted ISMA Protocols” in 1997.
She has over 15 years of management and research experience both inindustry and academia. She has gained a large and strong experience into the administrative and project coordination of EU-funded and Industrial research projects. She joined Libertel (now Vodafone NL), The Netherlands in 1997. Until May 2001, she worked at Wireless LANs in Wireless Communications and Networking Division of Lucent Technologie, the Netherlands. From June2001 to July 2003, she was with T-Mobile Netherlands, the Netherlands.Subsequently, from July 2003 to April 2004, at PCOM:I3, Aalborg, Denmark. She has been involved in a number of EU-funded R&D projects, including FP7 CP Betaas for M2M & Cloud, FP7 IP ISISEMD ICt for Demetia, FP7 IP ASPIRE RFID and Middleware, FP7 IP FUTON Wired-Wireless Convergence, FP6 IP eSENSE WSNs, FP6 NoE CRUISE WSNs, FP6 IPMAGNET and FP6 IP Magnet Beyond Secure Personal Networks/Future Internet as the latest ones. She is currently the project coordinator of the FP7CIP-PSP LIFE 2.0 and IST IP ASPIRE and was project coordinator of FP6NoE CRUISE. She was also the leader of EC Cluster for Mesh and Sensor Networks and is Counselor of IEEE Student Branch, Aalborg. Her current research interests are in the area of IoT & M2M, Cloud, identity management,mobility and network management; practical radio resource management; security, privacy and trust. Experience in other fields includes physical layer techniques, policy based management, short-range communications. She has published over 160 publications ranging from top journals, international conferences and chapters in books. She is and has been in the organization and TPC member of several international conferences. She is the co-editoris chief ofJournal for Cyber Security and Mobilityby River Publishers andassociate editor of Social Media and Social Networkingby Springer.

Ramjee Prasad, Center for TeleInFrastruktur, Aalborg University, Aalborg, Denmark

Ramjee Prasad (R) is currently the Director of the Center for TeleIn-frastruktur (CTIF) at Aalborg University (AAU), Denmark and Professor, Wireless Information Multimedia Communication Chair. He is the Founding Chairman of the Global ICT Standardisation Forum for India ( established in 2009. GISFI has the purpose of increasing the collaboration between European, Indian, Japanese, North-American, andother worldwide standardization activities in the area of Information and Communication Technology (ICT) and related application areas. He was the Founding Chairman of the HERMES Partnership – a network of leading independent European research centres established in 1997, of which he is now the Honorary Chair.
Ramjee Prasad is the founding editor-in-chief of the Springer International Journal on Wireless Personal Communications.He is a member of the editorial board of several other renowned international journals, including those of River Publishers. He is a member of the Steering, Advisory, and Technical Program committees of many renowned annual international conferences, including Wireless Personal Multimedia Communications Sym-posium (WPMC) and Wireless VITAE. He is a Fellow of the Institute of Electrical and Electronic Engineers (IEEE), USA, the Institution of Electronics and Telecommunications Engineers (IETE), India, the Institution of Engineering and Technology (IET), UK, and a member of the Netherlands Electronics and Radio Society (NERG) and the Danish Engineering Society(IDA). He is also a Knight (“Ridder”) of the Order of Dannebrog (2010), a distinguishment awarded by the Queen of Denmark.


