...
首页> 外文期刊>Procedia Computer Science >Attribute-Based Access Control Using Smart Contracts for the Internet of Things
【24h】

Attribute-Based Access Control Using Smart Contracts for the Internet of Things

机译:基于智能合同的基于属性的访问控制

获取原文
   

获取外文期刊封面封底 >>

       

摘要

Access control is one of the most important security concerns, which is critical in resource and information protection over IoT devices. This paper proposes a new scheme that combines attribute-based access control (ABAC) model with blockchain technology and uses smart contracts for access control judgment. This scheme can realize dynamic, distributed and reliable access control in the open IoT environment. The IoT access control system based on this scheme consists of five functional modules. The information registration point registers information for each device that joins the system. Policy enforcement point (PEP) is responsible for managing agent-devices in the system and processing original access requests from access subjects. Policy decision point (PDP) makes access control right decision through smart contracts. Policy administration point (PAP) is used to manage smart contract information. Policy information point (PIP) is used to manage key attribute information of devices used for access control judgment. The scheme also includes three types of smart contracts, one management contract (MC) is used to manage other contracts in the system, one policy decision contract (PDC) is responsible for obtaining attribute information from PIP and making final access control right decision, and a large number of policy contracts (PCs) which composed of a public policy contract (PPC) and a large number of exclusive policy contracts (EPCs). These PCs are used to implement specific attribute-based access control policies. To demonstrate the application of the scheme, we simulated a scenario of access control in a home IoT environment and verified the feasibility of access control decisions using our proposed scheme through three experiments.
机译:访问控制是最重要的安全问题之一,这在资源和信息保护上都是IOT设备的关键。本文提出了一种新的方案,将基于属性的访问控制(ABAC)模型与区块链技术结合起来,并使用智能合同进行访问控制判断。该方案可以在开放式IOT环境中实现动态,分布式和可靠的访问控制。基于该方案的IOT访问控制系统由五个功能模块组成。信息注册点注册加入系统的每个设备的信息。策略实施点(PEP)负责管理系统中的代理设备,并从访问主题处理原始访问请求。政策决策点(PDP)通过智能合同使访问控制权决定。策略管理点(PAP)用于管理智能合同信息。策略信息点(PIP)用于管理用于访问控制判断的设备的密钥属性信息。该方案还包括三种类型的智能合同,一个管理合同(MC)用于管理系统中的其他合同,一个策略决定合同(PDC)负责从PIP获取属性信息并进行最终访问控制权决定,以及由公共政策合同(PPC)组成的大量政策合同(PC)以及大量独家政策合同(EPC)。这些PC用于实现基于特定的基于属性的访问控制策略。为了展示该方案的应用,我们模拟了在家IOT环境中的访问控制场景,并通过三个实验验证了使用我们提出的方案的访问控制决策的可行性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号