...
首页> 外文期刊>Computers & Security >A blockchain based approach for the definition of auditable Access Control systems
【24h】

A blockchain based approach for the definition of auditable Access Control systems

机译:基于区块链接的审计访问控制系统的方法

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

This work proposes to exploit blockchain technology to define Access Control systems that guarantee the auditability of access control policies evaluation. The key idea of our proposal is to codify attribute-based Access Control policies as smart contracts and deploy them on a blockchain, hence transforming the policy evaluation process into a completely distributed smart contract execution. Not only the policies, but also the attributes required for their evaluation are managed by smart contracts deployed on the blockchain. The auditability property derives from the immutability and transparency properties of blockchain technology. This paper not only presents the proposed Access Control system in general, but also its application to the innovative reference scenario where the resources to be protected are themselves smart contracts. To prove the feasibility of our approach, we present a reference implementation exploiting XACML policies and Solidity written smart contracts deployed on the Ethereum blockchain. Finally, we evaluate the system performances through a set of experimental results, and we discuss the advantages and drawbacks of our proposal. (C) 2019 Elsevier Ltd. All rights reserved.
机译:这项工作建议利用区块链技术来定义访问控制系统,以保证访问控制策略评估的审计性。我们建议的核心思想是智能合同编成法典基于属性的访问控制策略,并在blockchain部署它们,因此改造策略评估过程变成一个完全分布式的智能合同执行。不仅是政策,而且还通过部落的智能合约管理所需的评估所需的属性。审计性质源于区块链技术的不变性和透明度。本文不仅提出一般建议门禁系统,也是其应用的创新的参考方案,其中要保护的资源本身是聪明的合同。为了证明我们的方法的可行性,我们提出了一个参考实现利用XACML政策和部署在复仇blockchain密实度的书面智能合同。最后,我们通过一套实验结果评估系统性能,我们讨论了我们提案的优势和缺点。 (c)2019 Elsevier Ltd.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号