首页> 外文期刊>Journal of network and computer applications >BCON: Blockchain based access CONtrol across multiple conflict of interest domains
【24h】

BCON: Blockchain based access CONtrol across multiple conflict of interest domains

机译:BCON:跨多个利益冲突域的基于区块链的访问控制

获取原文
获取原文并翻译 | 示例

摘要

In today's on-demand computing and virtual coalition environment, cross-domain services are acquired and provided. These business domains may belong to either the same or different conflict of interest system. Transitive access" can cause leakage of information between competitors through some other conflict of interest system's member. Therefore, a secure access control mechanism is required to detect and deny "transitive access" efficiently with minimal trust in externalist. Existing access control mechanisms focused on either single or multiple conflict of interest domains but with no "transitive access". In addition, these existing mechanisms are centralized with inherited unfair access control and are a single point of failure. Blockchain (BC) is a shared digital ledger encompassing a list of connected blocks stored on a decentralized distributed network that is secured through cryptography. We propose a BC based access control for conflict of interest domains. We have integrated a BC in our architecture to make access control fair, verifiable and decentralized. Users access histories and "transitive accesses" are stored on BC ledger. We propose a novel mechanism called "Transitive Access Checking and Enforcement (TACE)" i.e., "Algorithm.1". It makes an authorization decision based on BC endorsement that "transitive access" will not occur. "Algorithm.2" verifies and updates users access histories stored at BC before each request approval. Similarly, "Algorithm.3" detects possible future "transitive accesses" and updates Transitive Access Set (TAS) stored at BC after each request approval. The Simple Promela Interpreter (SPIN) model checker is used to verify the proposed mechanisms for "transitive access" detection and prevention. We have identified four conflicting sequences of execution that can cause "transitive access". Results show that the proposed mechanism is safe against "transitive access" by checking all the four possible conflicting sequences of execution.
机译:在当今的按需计算和虚拟联盟环境中,将获取并提供跨域服务。这些业务域可能属于相同或不同的利益冲突系统。 “传递访问”可能会通过其他一些利益冲突系统的成员而导致竞争者之间的信息泄漏。因此,需要一种安全的访问控制机制来有效地检测和拒绝“传递访问”,并且对外部主义者的信任度最低。单个或多个利益冲突域,但没有“传递访问”;此外,这些现有机制集中于继承的不公平访问控制,并且是单点故障;区块链(BC)是一个共享数字分类帐,其中包含连接的列表存储在通过密码术保护的分散式分布式网络中的块。我们提出了一种基于BC的访问控制,以解决利益冲突域。我们将BC集成到我们的体系结构中,以使访问控制公平,可验证和分散。用户访问历史和“可传递的”访问”存储在BC分类帐中。我们提出了一种称为“传递式Acce”的新颖机制ss检查和执行(TACE)”,即“ Algorithm.1”。它根据BC背书做出不会发生“传递访问”的授权决定。在每次请求批准之前,“ Algorithm.2”将验证和更新存储在BC的用户访问历史记录。同样,“ Algorithm.3”会检测到将来可能发生的“传递访问”,并在每次请求批准后更新存储在BC处的传递访问集(TAS)。简单的Promela解释器(SPIN)模型检查器用于验证提出的“传递访问”检测和预防机制。我们确定了四个可能导致“传递访问”的冲突执行顺序。结果表明,通过检查所有四个可能的冲突执行顺序,提出的机制可以安全地防止“传递访问”。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号