What is it about?
Cloud-based Internet of Things (IoT) systems are increasingly being deployed in cyber-physical environments, where interconnected devices continuously generate and exchange data, creating important challenges for both security and privacy. In this context, we face two related problems: controlling access to devices and regulating the collection, processing, storage, and sharing of the data they produce. This paper proposes a cloud-IoT architecture that integrates device access control and data sharing control within a unified framework so that the same system can determine if an operation on a device is permissible and whether the resulting data can be collected, transformed, stored, or shared. The approach relies on category-based policies to enable fine-grained control over device operations and data streams, allowing users to define permissions in a structured way without having to set up a separate rule for each device, service, or data item. The paper focuses on scenarios where users are not security experts, such as smart homes, therefore, introducing a simple policy template based on category-based policies, users and services are grouped based on trust, devices are grouped by type, while data is governed through sensitivity-based categories and associated transformations. In addition, contextual attributes such as time or location allow the policies to adapt dynamically to changing environmental conditions, giving the framework both flexibility and practical usability.
Featured Image
Photo by Sebastian Scholz (Nuki) on Unsplash
Why is it important?
This work is significant because it addresses a real issue in cloud-IoT systems: how to handle access control and privacy in a secure and practical manner. The category-based approach allows fine-grained management over users, devices, and data while simplifying policy creation for non-security users.
Perspectives
This work is valuable because it balances security and practicality, which is typically difficult in IoT systems. It also could be adapted for other domains in the cyber-physical environments.
Fatmah mashat
King's College London
Read the Original
This page is a summary of: Access Control and Data Sharing in Cloud-IoT Architectures: A Category-Based Approach, June 2026, ACM (Association for Computing Machinery),
DOI: 10.1145/3806008.3811700.
You can read the full text:
Contributors
The following have contributed to this page







