Object Capability model for IoT

Tim Coote <[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <[email protected]>
Hullo

Is there any prior work on how to design a capability based security model for the internet of things? I’m trying to build a composable model for IoT devices so that I can suck intelligence out of the end devices as these seem to suffer from poor software quality and hence are unreliable (in all senses of the word). POLA seems to me to be the right principle to approach delegation of control/visibility of information.

I like what I read about Waterken/Clusterken, but I’m not clear how complete/live they are.

The aspect that I’m struggling most with is how to ensure that capabilities don’t just become strings as, afaict, they need to be passed outside the nice controlled world of a single programming language/operating system. I presume that there’s some mechanism to get individual capabilities tied to individual instances of objects and make delegation an explicit extension of the trust chain.

Sorry if this is too broad a question and/or not well worded - I only had a brief intro to capabilites by Maurice Wilkes, so you can guess how long ago that was.

Thanks for any pointers.

TC
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.