随着物联网的深入发展,其面临的安全威胁也得到广泛关注,访问控制机制能够保证系统资源合法、受控地被使用,可以有效解决安全问题.提出一种基于跨层行为可信的分布式访问控制机制,该机制将信任模型与访问控制相结合,引入跨层设计考察节点在不同网络层次的行为参数,利用引入参数的k-means聚类判断节点行为的信任等级,并生成不同的访问控制策略.该机制实现跨层信息的可靠传递和信任等级划分的离线学习,仿真实验结果表明能够实时监控节点行为,动态变更节点权限,阻断与不可信节点之间的数据分发,保证网络的可靠运行.
With the further development of the Internet of Things,its security problems have also been widely concerned. Network re- sources can be used legally and controlled by effective access control mechanism. In this paper we propose a distributed access control system based on cross-layer design, which study the behaviour of sensors in different network levels, and judge the trust domains to generate different access control strategies by k-means clustring with parameters. This system can deliver cross-layer information relia- bly and save energy by dividing the trust domains offline. Experiments results show it can update permission dynamically in real time, and isolate usage of data with not trust sensors to ensure the reliable operation of the network.