首页> 外文OA文献 >BlendCAC: A Smart Contract Enabled Decentralized Capability-Based Access Control Mechanism for the IoT
【2h】

BlendCAC: A Smart Contract Enabled Decentralized Capability-Based Access Control Mechanism for the IoT

机译:Blendcac:智能合同使IOT的基于分散的基于能力的访问控制机制使能

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

While Internet of Things (IoT) technology has been widely recognized as an essential part of Smart Cities, it also brings new challenges in terms of privacy and security. Access control (AC) is among the top security concerns, which is critical in resource and information protection over IoT devices. Traditional access control approaches, like Access Control Lists (ACL), Role-based Access Control (RBAC) and Attribute-based Access Control (ABAC), are not able to provide a scalable, manageable and efficient mechanism to meet the requirements of IoT systems. Another weakness in today’s AC is the centralized authorization server, which can cause a performance bottleneck or be the single point of failure. Inspired by the smart contract on top of a blockchain protocol, this paper proposes BlendCAC, which is a decentralized, federated capability-based AC mechanism to enable effective protection for devices, services and information in large-scale IoT systems. A federated capability-based delegation model (FCDM) is introduced to support hierarchical and multi-hop delegation. The mechanism for delegate authorization and revocation is explored. A robust identity-based capability token management strategy is proposed, which takes advantage of the smart contract for registration, propagation, and revocation of the access authorization. A proof-of-concept prototype has been implemented on both resources-constrained devices (i.e., Raspberry PI nodes) and more powerful computing devices (i.e., laptops) and tested on a local private blockchain network. The experimental results demonstrate the feasibility of the BlendCAC to offer a decentralized, scalable, lightweight and fine-grained AC solution for IoT systems.
机译:虽然事物互联网(IOT)技术被广泛认为是智能城市的重要组成部分,但它在隐私和安全方面也带来了新的挑战。访问控制(AC)是最重要的安全问题,这在资源和信息保护上都是IOT设备的关键。传统的访问控制方法,如访问控制列表(ACL),基于角色的访问控制(RBAC)和基于属性的访问控制(ABAC),不能提供可扩展,可管理和有效的机制,以满足IOT系统的要求。今天的AC中的另一个弱点是集中式授权服务器,这可能导致性能瓶颈或单点故障。本文提出了智能合约的智能合约,提出了Blendcac,它是一种分散的联合能力的交流机制,以便在大型物联网系统中有效保护设备,服务和信息。引入了基于联合能力的委派模型(FCDM)来支持分层和多跳委派。探讨了代表授权和撤销的机制。提出了一种强大的基于身份的能力令牌管理策略,它利用了访问授权的登记,传播和撤销的智能合同。在资源受限的设备(即,Raspberry PI节点)和更强大的计算设备(即,笔记本电脑)上并在本地私有区块网络上进行了测试,并在本地私有区块链网络上实现了概念验证原型。实验结果表明,Blendcac为IoT系统提供分散,可扩展,轻质和细粒度的AC解决方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号