TBAC: A Tokoin-Based Accountable Access Control Scheme for the Internet of Things

被引:2
|
作者
Liu, Chunchi [1 ,2 ]
Xu, Minghui [3 ]
Guo, Hechuan [3 ]
Cheng, Xiuzhen [3 ]
Xiao, Yinhao [4 ]
Yu, Dongxiao [3 ]
Gong, Bei [5 ]
Yerukhimovich, Arkady [1 ]
Wang, Shengling [6 ]
Lyu, Weifeng [7 ]
机构
[1] George Washington Univ, Dept Comp Sci, Washington, DC 20052 USA
[2] Ernst & Young, London SE1 2AF, England
[3] Shandong Univ, Sch Comp Sci & Technol, Jinan 250100, Shandong, Peoples R China
[4] Guangdong Univ Finance & Econ, Sch Informat Sci, Guangzhou 510320, Guangdong Provi, Peoples R China
[5] Beijing Univ Technol, Beijing 100021, Peoples R China
[6] Beijing Normal Univ, Beijing 100875, Peoples R China
[7] Beihang Univ, Beijing 100191, Peoples R China
基金
国家重点研发计划;
关键词
Access control; Program processors; Microcontrollers; Prototypes; User interfaces; Blockchains; Internet of Things; Fine-grained access control; access procedure control; auditability; overprivilege attack; blockchain; trusted execution environment (TEE); IoT; SECURITY;
D O I
10.1109/TMC.2023.3316622
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Overprivilege Attack, a widely reported phenomenon in IoT that accesses unauthorized or excessive resources, is notoriously hard to prevent, trace and mitigate. In this paper, we propose TBAC, a Tokoin-Based Access Control model enabled by blockchain and Trusted Execution Environment (TEE) technologies, to offer fine-grained access control and strong auditability for IoT. TBAC materializes the virtual access power into a definite-amount, secure and accountable cryptographic coin, termed "tokoin" (token+coin), and manages it using atomic and accountable state-transition functions in a blockchain. A tokoin carries a fine-grained policy defined by the resource owner to specify the requirements to be satisfied before an access is granted, and the behavioral constraints that describe the correct procedure to follow during access. The strong-auditability is achieved with blockchain and a TEE-enabled trusted access control object (TACO) to ensure that all access activities are securely monitored and auditable. We prototype TBAC by implementing all its functions with well-studied cryptographic primitives over different blockchain platforms, building a TACO on top of the ARM Cortex-M33 TEE microcontroller, and constructing a user-friendly APP for regular users. A case study is finally presented to demonstrate how TBAC is employed to enable autonomous and secure in-home cargo delivery.
引用
收藏
页码:6133 / 6148
页数:16
相关论文
共 50 条
  • [1] Security Scheme for an RFID Access Control based on Internet of Things
    Isidro Alamillo-Montes, Genaro
    Martinez-Cruz, Alfonso
    Feregrino Uribe, Claudia
    2022 IEEE MEXICAN INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE (ENC), 2022,
  • [2] An Efficient, Accountable, and Privacy-Preserving Access Control Scheme for Internet of Things in a Sharing Economy Environment
    Liu, Yu
    Xue, Kaiping
    He, Peixuan
    Wei, David S. L.
    Guizani, Mohsen
    IEEE INTERNET OF THINGS JOURNAL, 2020, 7 (07): : 6634 - 6646
  • [3] BacS: A blockchain-based access control scheme in distributed internet of things
    Shi, Na
    Tan, Liang
    Yang, Ciaxia
    He, Chen
    Xu, Junli
    Lu, Yang
    Xu, Hao
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2021, 14 (05) : 2585 - 2599
  • [4] An Internet of Things Access Control Scheme Based on Permissioned Blockchain and Edge Computing
    Zhang, Lihua
    Li, Boping
    Fang, Haodong
    Zhang, Ganzhe
    Liu, Chunhui
    APPLIED SCIENCES-BASEL, 2023, 13 (07):
  • [5] BacS: A blockchain-based access control scheme in distributed internet of things
    Na Shi
    Liang Tan
    Ciaxia Yang
    Chen He
    Junli Xu
    Yang Lu
    Hao Xu
    Peer-to-Peer Networking and Applications, 2021, 14 : 2585 - 2599
  • [6] Attribute-based access control scheme for the perceptive layer of the internet of things
    Ren, Fang
    Ma, Jianfeng
    Hao, Xuanwen
    Xi'an Dianzi Keji Daxue Xuebao/Journal of Xidian University, 2012, 39 (02): : 66 - 72
  • [7] Identity driven Capability based Access Control (ICAC) Scheme for the Internet of Things
    Mahalle, Parikshit N.
    Anggorojati, Bayu
    Prasad, Neeli Rashmi
    Prasad, Ramjee
    2012 IEEE INTERNATIONAL CONFERENCE ON ADVANCED NETWORKS AND TELECOMMUNCATIONS SYSTEMS (ANTS), 2012, : 49 - 54
  • [8] LBAC: A lightweight blockchain-based access control scheme for the internet of things
    Qin, Xuanmei
    Huang, Yongfeng
    Yang, Zhen
    Li, Xing
    INFORMATION SCIENCES, 2021, 554 : 222 - 235
  • [9] Capability-Based Access Control for the Internet of Things: An Ethereum Blockchain-Based Scheme
    Nakamura, Yuta
    Zhang, Yuanyu
    Sasabe, Masahiro
    Kasahara, Shoji
    2019 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2019,
  • [10] A Blockchain-Based Access Control Scheme for Reputation Value Attributes of the Internet of Things
    Tian, Hongliang
    Tian, Junyuan
    CMC-COMPUTERS MATERIALS & CONTINUA, 2024, 78 (01): : 1297 - 1310