2018/05/01 by Santiago Aragon, Marco Tiloca, Max Maaß +3
Computer Science · Engineering · Social Sciences · #Access Control and Trust #Access control #Authentication (law) #Cloud computing #Cloud computing security #Computer network #Computer science #Computer security #Cryptographic protocol #Cryptography #IPsec #IPv6, Mobility, Handover, Networks, Security #IoT and Edge/Fog Computing #Network Access Control #Operating system #Provisioning #Security association #The Internet #cs.CR
paper · pdf · doi:10.1109/cns.2018.8433209
published as 2018 IEEE Conference on Communications and Network Security (CNS), Beijing, China, 2018, pp. 1-9
openalex publication_date 2018/05/01 · arxiv created 2018/08/14 · arxiv updated 2018/08/15 · openalex created_date 2025/10/10 · openalex updated_date 2026/08/05
The Authentication and Authorization for Constrained Environments (ACE) framework provides fine-grained access control in the Internet of Things, where devices are resource-constrained and with limited connectivity. The ACE framework defines separate profiles to specify how exactly entities interact and what security and communication protocols to use. This paper presents the novel ACE IPsec profile, which specifies how a client establishes a secure IPsec channel with a resource server, contextually using the ACE framework to enforce authorized access to remote resources. The profile makes it possible to establish IPsec Security Associations, either through their direct provisioning or through the standard IKEv2 protocol. We provide the first Open Source implementation of the ACE IPsec profile for the Contiki OS and test it on the resource-constrained Zolertia Firefly platform. Our experimental performance evaluation confirms that the IPsec profile and its operating modes are affordable and deployable also on constrained IoT platforms.