TY - GEN
T1 - Characterizing Security and Privacy Risks in Smart Home IoT Device Access Sharing
AU - Wan, Yinxin
AU - Xu, Ting
AU - Huynh, Tran Ngoc Bao
AU - Dai, Jun
AU - Sun, Xiaoyan
AU - Xu, Kuai
AU - Xue, Guoliang
N1 - Publisher Copyright:
© 2026 Copyright held by the owner/author(s).
PY - 2026/5/10
Y1 - 2026/5/10
N2 - Smart home IoT systems have become widely deployed in modern households, enabling convenient functionalities such as remote control, automation, and real-time monitoring. A commonly supported and frequently used capability in these ecosystems is device access sharing, which allows a primary device owner to grant other users permission to control or interact with a device. However, despite its security-critical nature, the security and privacy practices involved in the sharing process itself remain largely under-examined. To address this gap, we conduct a systematic study of device access sharing workflows across 56 commercially available smart home IoT devices spanning diverse vendors and product categories. Through comprehensive analysis of real-world sharing mechanisms, we identify 9 recurring classes of security and privacy risks, including coarse device access constraints, coarse sharing constraints, weak or missing sharing credentials, inability to revoke device access, inability to revoke sharing, lack of transparency regarding invitation acceptance, uncontrolled re-sharing, over-privileged access, and unintended privacy exposure. Our findings reveal widespread and systemic weaknesses in the device sharing implementations of current smart home IoT systems, underscoring that insecure sharing workflows can directly expose users to persistent security and privacy threats.
AB - Smart home IoT systems have become widely deployed in modern households, enabling convenient functionalities such as remote control, automation, and real-time monitoring. A commonly supported and frequently used capability in these ecosystems is device access sharing, which allows a primary device owner to grant other users permission to control or interact with a device. However, despite its security-critical nature, the security and privacy practices involved in the sharing process itself remain largely under-examined. To address this gap, we conduct a systematic study of device access sharing workflows across 56 commercially available smart home IoT devices spanning diverse vendors and product categories. Through comprehensive analysis of real-world sharing mechanisms, we identify 9 recurring classes of security and privacy risks, including coarse device access constraints, coarse sharing constraints, weak or missing sharing credentials, inability to revoke device access, inability to revoke sharing, lack of transparency regarding invitation acceptance, uncontrolled re-sharing, over-privileged access, and unintended privacy exposure. Our findings reveal widespread and systemic weaknesses in the device sharing implementations of current smart home IoT systems, underscoring that insecure sharing workflows can directly expose users to persistent security and privacy threats.
KW - device access sharing
KW - IoT security and privacy
KW - sharing workflows
KW - Smart home IoT
KW - smart home security
UR - https://www.scopus.com/pages/publications/105041121431
UR - https://www.scopus.com/pages/publications/105041121431#tab=citedBy
U2 - 10.1145/3774906.3802795
DO - 10.1145/3774906.3802795
M3 - Conference contribution
AN - SCOPUS:105041121431
T3 - SenSys 2026 - Proceedings of the 2026 ACM/IEEE International Conference on Embedded Artificial Intelligence and Sensing Systems, Part of CPS-IoTWeek 2026
SP - 1129
EP - 1136
BT - SenSys 2026 - Proceedings of the 2026 ACM/IEEE International Conference on Embedded Artificial Intelligence and Sensing Systems, Part of CPS-IoTWeek 2026
PB - Association for Computing Machinery, Inc
T2 - International Conference on Embedded Artificial Intelligence and Sensing Systems, SenSys 2026
Y2 - 11 May 2026 through 14 May 2026
ER -