首页> 外文OA文献 >Exploiting Smart Contracts for Capability-Based Access Control in the Internet of Things
【2h】

Exploiting Smart Contracts for Capability-Based Access Control in the Internet of Things

机译:利用基于能力的智能合同,在某物互联网中的基于能力的访问控制

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Due to the rapid penetration of the Internet of Things (IoT) into human life, illegal access to IoT resources (e.g., data and actuators) has greatly threatened our safety. Access control, which specifies who (i.e., subjects) can access what resources (i.e., objects) under what conditions, has been recognized as an effective solution to address this issue. To cope with the distributed and trust-less nature of IoT systems, we propose a decentralized and trustworthy Capability-Based Access Control (CapBAC) scheme by using the Ethereum smart contract technology. In this scheme, a smart contract is created for each object to store and manage the capability tokens (i.e., data structures recording granted access rights) assigned to the related subjects, and also to verify the ownership and validity of the tokens for access control. Different from previous schemes which manage the tokens in units of subjects, i.e., one token per subject, our scheme manages the tokens in units of access rights or actions, i.e., one token per action. Such novel management achieves more fine-grained and flexible capability delegation and also ensures the consistency between the delegation information and the information stored in the tokens. We implemented the proposed CapBAC scheme in a locally constructed Ethereum blockchain network to demonstrate its feasibility. In addition, we measured the monetary cost of our scheme in terms of gas consumption to compare our scheme with the existing Blockchain-Enabled Decentralized Capability-Based Access Control (BlendCAC) scheme proposed by other researchers. The experimental results show that the proposed scheme outperforms the BlendCAC scheme in terms of the flexibility, granularity, and consistency of capability delegation at almost the same monetary cost.
机译:由于事物互联网(物联网)迅速渗透到人类生活中,非法进入物联网资源(例如,数据和执行器)极大地威胁着我们的安全。访问控制,它指定谁(即,主题)可以访问在什么条件下的资源(即,对象)被识别为解决此问题的有效解决方案。为了应对IOT系统的分布式和信任性质,我们通过使用Ethereum Smart合同技术提出了基于分散和可靠的能力的访问控制(CAPBAC)方案。在此方案中,为每个对象创建一个智能合同,以存储和管理分配给相关主题的能力令牌(即,数据结构记录授予的访问权限),也可以验证令牌的访问控制的所有权和有效性。与以前的方案不同,这些方案以受试者为单位管理令牌,即每个主题的一个令牌,我们的方案以访问权限或行动为单位管理令牌,即每次操作一个令牌。此类新颖管理层实现了更细粒度和灵活的能力委派,并确保了委派信息与存储在令牌中的信息之间的一致性。我们在本地建设的Ethereum区间网络中实施了拟议的Capbac计划,以证明其可行性。此外,我们在燃气消耗方面测量了我们方案的货币成本,以将我们的计划与其他研究人员提出的现有基于区块链的分散性的访问控制(Blendcac)计划进行比较。实验结果表明,该方案在几乎同样相同的货币成本方面优于柔韧性,粒度和能力代表团的一致性方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号