We present models for utilizing blockchain and smart contract technology with the widely used OAuth 2.0 open authorization framework to provide delegated authorization for constrained IoT devices. The models involve different tradeoffs in terms of privacy, delay, and cost, while exploiting key advantages of blockchains and smart contracts. These include linking payments to authorization grants, immutably recording authorization information and policies in smart contracts, and offering resilience through the execution of smart contract code on all blockchain nodes.
@article{arxiv.1905.01665,
title = {OAuth 2.0 meets Blockchain for Authorization in Constrained IoT Environments},
author = {Vasilios A. Siris and Dimitrios Dimopoulos and Nikos Fotiou and Spyros Voulgaris and George C. Polyzos},
journal= {arXiv preprint arXiv:1905.01665},
year = {2019}
}
Comments
Accepted in IEEE 5th World Forum on Internet of Things (WF-IoT), 15-18 April 2019, Limerick, Ireland. arXiv admin note: text overlap with arXiv:1905.01671