A Formal Model for Secure and Context-Based Data Dissemination in Federated Special IoT Environments
Jakub Sychowiec, Zbigniew ZielińskiAn increasing number of special Internet of Things (IoT) applications are being deployed within federated and zero-trust (ZT) environments. These ad-hoc networks consist of heterogeneous, resource-constrained devices from various administrative domains, all of which are susceptible to compromise. The dynamic nature of these environments necessitates near-real-time Situational Awareness (SA), where processed data varies with its sensitivity and reliability, without dependence on a central authority. Examples include NATO and non-NATO coalitions engaged in hybrid military operations or humanitarian aid scenarios. To address the challenges of security, reliability, and context-aware data dissemination, we propose FedM, a multi-level formal model designed for context-aware and policy-driven data dissemination in federated IoT environments. This model is built upon various access control models and Denning’s research on information flow control (IFC), prioritizing the protection and reliability of data flows. A crucial element of this model is the distributed ledger, which facilitates the dynamic modification of label expressiveness, enhances resilience against disruption attacks, and separates policy logic from application functionality to mitigate risks associated with the benevolent developer. Additionally, we delineate a deterministic and history- and precedence-aware policy enforcement procedure to resolve conflicting actions and introduce processing primitives for the ongoing Data Quality Assessment (DQA) process. Our model also aligns with the concepts of Ubiquitous and Continuum Computing. Furthermore, in our paper we illustrate a policy-based dissemination pipeline, incorporating a bounded trustworthiness dimension. Additionally, we present a refined multi-layered framework that proposes the deployment of Information Flow Control (IFC) components, such as the Open Policy Agent decision engine, to facilitate policy-driven contextual data dissemination. We provide preliminary benchmarks for resource-constrained platforms, along with a formal threat model that addresses implicit flows, the benevolent developer problem, and the behavior of a distributed ledger under degraded network conditions. Finally, we conduct a formal verification of our model using the P framework.