Return
STAC-IoT: A secure task-based access control for IoT-edge computing architecture
DOI:10.1016/j.cose.2026.104915.png)
Abstract
En 中文
The explosive growth of the Internet of Things (IoT) has revolutionized many sectors by enabling smart devices to communicate and interact autonomously. Decentralized architectures, such as edge computing, have emerged to enable a seamless management of IoT. However, this technological coupling brings significant security challenges, especially when controlling access to tasks executed by IoT objects. In fact, most existing solutions rely on a centralized trusted node, lack fine-grained access control, and are not adapted to resource-constrained environments. In this paper, we propose STAC-IoT, a new decentralized task-based access control protocol that governs access to actions executed by IoT objects. The proposed approach leverages attribute-based access control model and edge computing to enable a robust, secure and energy efficient task execution. Furthermore, the proposed protocol supports the existence of multiple authorities that independently manage their own users, while being able to adopt cooperative access policies. The treatment of access requests are fast as our protocol eliminates the need to go through a central authority for every access attempt. To demonstrate the applicability of our protocol in a real-world context, we validate it through a realistic smart manufacturing scenario, demonstrating its effectiveness in terms of scalability, security, and energy efficiency. In addition, we provide a formal security analysis showing that STAC-IoT is resilient against common attack vectors such as man-in-the-middle, impersonation, and token forgery.
Keywords:
STAC-IoT
IoT-edge computing
access control
attribute-based access control
decentralized architecture
Journal
C
IF:
5.4
Papers:
179
Citations:
0

