Efficient Revocation of Capability Tokens
At a glance
- Citations
- 0
- References
- 7
- Comments
- 0
Öz
In this paper we propose L2Cap, an approach to efficiently store and distribute revocation data of LCap capability tokens. By using a probabilistic data structure, L2Cap is able to operate with a small and fixed size memory, even when no upper bound for the number of revoked capability tokens can be given. The problem of a high false positive rate of a saturated Bloom filter is mitigated by guaranteeing that renewed capability tokens are correctly detected as valid until at least the next revocation data update. This ensures normal quality of service operation can be resumed swiftly after a mass revocation event.We have shown that the computational overhead of L2Cap and its impact on response time compared to plain LCap are negligible. The use L2Cap is shown to be safe in regard to the attacker model analyzed in this paper. L2Cap allows the use of Capability Based Access Control (CBAC) for Class 0 IoT devices with only sporadic internet connectivity, while issuing capability tokens with a validity that is longer than the use of stale tokens can be tolerated.
Publication details
- DOI
- 10.1109/noms54207.2022.9789833
- OpenAlex
- W4281658560
- Document type
- conference-paper
- Language
- EN
- Source
- NOMS 2022-2022 IEEE/IFIP Network Operations and Management Symposium
- Last metadata update
Comments
Oturum Açın to join the discussion.