27–29 Oct 2026
Santiago Compostela
Europe/Madrid timezone

Zero Trust IAM for Edge IoT: A Capability-Based Approach with Biscuit on ARM

27 Oct 2026, 17:40
10m
Santiago Compostela

Santiago Compostela

Facultad de Química Santiago de Compostela Aula Magna
Lightning Talk (8' + 2' for questions) Development of innovative software and services Parallel track - I

Speaker

César Cañada Alonso

Description

Identity and Access Management (IAM) remains one of the most persistent challenges in the security of Edge IoT systems. Conventional IAM solutions, originally designed for centralised environments, are increasingly ill-suited to edge deployments: they suffer from high latency, low energy efficiency and high resource consumption; they lack true 'offline-first' operation in scenarios with intermittent connectivity; and they only partially comply with the Zero Trust principles set out in NIST SP 800-207 [7]. Although these problems affect Edge IoT in general, they are significantly exacerbated in devices based on ARM architectures, which dominate the IoT market due to their low energy consumption. These devices have constraints on resources such as CPU, memory and power, but at the same time offer the opportunity to use TrustZone to create secure and isolated execution environments (Trusted Execution Environments). This position paper advocates the integration of Biscuit (a capability-based authorisation model with Datalog- based attenuation) into a distributed Zero Trust architecture optimised for ARM devices with TrustZone. The resulting solution paves the way for the next generation of IAM for critical applications in 5G, the Industrial Internet of Things (IIoT) and connected healthcare.

Author

Co-authors

Prof. Jordi Guijarro (UOC) Dr Josep Jorba (UOC)

Presentation materials

There are no materials yet.