434
J. Bauer et al.
There are four topics when it comes to IAM, which need to be considered. In
a first step, the user who wants to access the system needs to identify himself
(Identification). This claim needs to be verified (Authentication) by the system.
Subsequently, it is necessary to grant appropriate rights to the user (Authorisation). For many systems and domains, it is mandatory to log different system
events for ensuring auditing, monitoring or tracing (Accountability) [9].
To carry out a target group-oriented authorization, four basic concepts are
considered. The first is identity-based access control (IBAC), which provides an
access control list for each object, which in turn contains all subjects that are
allowed to access the corresponding object [10]. The second concept, role-based
access control (RBAC), provides different read and write permissions (generally: transactions) for different user groups [11]. Attribute-based access control
(ABAC) defines a similar approach to RBAC, except that users are granted
rights based on certain attributes of subjects and objects and environmental
conditions [12]. The last type, capability-based access control (CapBAC) turns
the rights management the other way around and grants rights based on the
token that the user hands over at login [13]. This token then contains an indication of the possibilities a user has on the platform.
openHAB is a smart home middleware, so it is possible to control different
systems in one single graphical user interface (GUI) or app. The software uses
specific components to offer an abstraction layer for all of its subsystems. To
connect to a third-party system like Homematic [14], it is necessary to create
a binding. After activating the binding it is possible to search for accessible
objects, here for the Homematic bridge and all the Homematic devices, e.g. a
switch. The signal of the device and the triggered action from openHAB to the
Homematic device is transported through so-called channels. To create a GUI
a sitemap is needed. In the sitemap file there is a possibility to name items.
An item is a concrete instance of a thing and a channel can be mapped to an
item. For automating event-driven tasks there is the concept of rules, a scriptlike openHAB feature. There are several other smart living middleware systems
or promising approaches besides openHAB, for example, universAAL, HomeKit
and Connected Home over IP.
3 Challenges
To fulfill the idea of our smart living reference architectural model (see Fig. 1)
it is necessary to offer a platform architecture which is able to handle upcoming
requests as flexible as possible. The corresponding IAM needs to be considered in
all systems. This is challenging because existing middleware systems need to be
used to connect to different smart home systems to achieve an adequate market
penetration. Moreover, as mentioned before, security interferes with comfort, so
new concepts need to be evaluated in regard to user acceptance.
openHAB does not yet provide access rights for different user groups and thus
does not offer authentication for end-users, besides developer-addressed possibilities. Therefore, openHAB needs to be extended. In addition, there are three
Précédent

- 438/446

Suivant