[Submitted on 30 Jul 2026]
Abstract:Many cloud providers for IoT technologies offer access control mechanisms whose proper configuration is critical for security. However, verifying permissions in isolation is insufficient in a setting where devices have different levels of trust or are compartmentalised in various subsystems. This work analyses IoT access control policies to identify potential security vulnerabilities from unwanted information flow between devices. To this end, we formally model AWS IoT Core's components and define an information flow graph to capture the communication among devices permitted by the access control policies. We build a finite representation of the graph by leveraging an SMT solver, thus enabling the verification of information flow between devices. We implement our approach in a tool called IOT:POKER, and assess it on a realistic scenario and several real-world policies.
Submission history
From: Lorenzo Ceragioli [view email]
[v1]
Thu, 30 Jul 2026 11:54:36 UTC (333 KB)
0 Comments
Log in to join the conversation.No comments yet. Be the first to share your thoughts.