Skip to main navigation Skip to search Skip to main content

Security Implications of Permission Models in Smart-Home Application Frameworks

  • Earlence Fernandes
  • , Amir Rahmati
  • , Jaeyeon Jung
  • , Atul Prakash
  • University of Michigan, Ann Arbor
  • Samsung's Cloud Platform Group

Research output: Contribution to journalArticlepeer-review

60 Scopus citations

Abstract

Several competing smart-home programming frameworks that support third-party app development have emerged. Such frameworks' permission models represent the dividing line between malicious apps that compromise user security and useful apps that provide user benefits. The authors survey the permission models of four popular frameworks: IoTivity, HomeKit, AllJoyn, and SmartThings, then report on their recent deep empirical analysis of SmartThings. A key finding is that SmartThings apps are automatically overprivileged, which can leave users vulnerable to various remote attacks.

Original languageEnglish
Article number7891524
Pages (from-to)24-30
Number of pages7
JournalIEEE Security and Privacy
Volume15
Issue number2
DOIs
StatePublished - 2017

Keywords

  • Internet of Things
  • IoT
  • apps
  • overprivilege
  • permission model
  • privacy
  • security
  • smart home
  • smart technology
  • smart-home programming

Fingerprint

Dive into the research topics of 'Security Implications of Permission Models in Smart-Home Application Frameworks'. Together they form a unique fingerprint.

Cite this