Role and attribute-based access control scheme for decentralized medicine supply chain

被引:0
|
作者
Hathaliya, Jigna J. [1 ]
Tanwar, Sudeep [1 ]
机构
[1] Nirma Univ, Inst Technol, Dept Comp Sci & Engn, Ahmadabad 382481, Gujarat, India
关键词
InterPlanetary file system; Hyperledger Fabric; Medicine supply chain; Hyperledger Calliper; Role based access control; Attribute based access control; Blockchain; TRACEABILITY;
D O I
10.1016/j.jisa.2024.103851
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The medicine supply chain (MSC) is an intricate structure that extends across multiple organizations and geographic locations and is an important basis for essential daily services. It involves manufacturing, distributing, and delivering medicine to patients. The intermediaries in the MSC include manufacturers, warehouses, distributors, transporters, retailers, consumers, and patients, in which each intermediary plays a vital role and responsibility in an MSC. MSC poses different challenges, such as medicine counterfeiting, data temperament, and cold chain shipping, leading to various security and privacy issues. To overcome the aforementioned issues, public blockchain (BC) provides transparency, traceability, and data security to some extent but often fails to protect MSC's data privacy. To address the aforementioned, we adopted the Hyperledger Fabric consortium BC, which preserves the data security and privacy of the proposed scheme. Hyperledger Fabric uses a role-based access control (RBAC) policy for all writers and readers, where each reader and writer accesses all the smart contract information based on their static roles (reader and writer). This RBAC scheme limits the dynamicity and granularity of the access control. With this concern, we adopt the combination of RBAC and attribute-based access control (ABAC) schemes to provide fine-grained access to the smart contract functions. Additionally, we use a distributed interplanetary file system (IPFS) to enhance the scalability of the proposed scheme. Before saving data, IPFS does not use any encryption algorithm. We embraced the advanced encryption standard (AES) algorithm to encrypt MSC data. Next, we integrated RBAC and fine-grained ABAC through smart contracts to prevent unauthorized access in an MSC environment. Further, the proposed scheme is evaluated using various performance parameters, such as scalability for different number of clients, average latency (0.12 s), minimum execution time is around (115 s) for 100 transactions execution, and throughput of (72.5) transactions per second (TPS) of invoke-based smart contract functions while 618.7 (TPS) for query-based smart contract functions.
引用
收藏
页数:17
相关论文
共 50 条
  • [21] Attribute-Based Access Control Scheme with Efficient Revocation in Cloud Computing
    Zhihua Xia
    Liangao Zhang
    Dandan Liu
    [J]. China Communications, 2016, 13 (07) : 92 - 99
  • [22] Attribute-Based Oblivious Access Control
    Han, Jinguang
    Susilo, Willy
    Mu, Yi
    Yan, Jun
    [J]. COMPUTER JOURNAL, 2012, 55 (10): : 1202 - 1215
  • [23] AARBAC: Attribute-Based Administration of Role-Based Access Control
    Ninglekhu, Jiwan L.
    Krishnan, Ram
    [J]. 2017 IEEE 3RD INTERNATIONAL CONFERENCE ON COLLABORATION AND INTERNET COMPUTING (CIC), 2017, : 126 - 135
  • [24] An efficient attribute-based hierarchical data access control scheme in cloud computing
    He, Heng
    Zheng, Liang-han
    Li, Peng
    Deng, Li
    Huang, Li
    Chen, Xiang
    [J]. HUMAN-CENTRIC COMPUTING AND INFORMATION SCIENCES, 2020, 10 (01)
  • [25] Attribute-Based Data and Privilege Hybrid Access Control Scheme in Cloud Computing
    Liu, Qin
    Li, Pengju
    Yu, Chunwu
    [J]. Computer Engineering and Applications, 2024, 60 (13) : 276 - 286
  • [26] An Attribute-Based Collaborative Access Control Scheme Using Blockchain for IoT Devices
    Zhang, Yan
    Li, Bing
    Liu, Ben
    Wu, Jiaxin
    Wang, Yazhou
    Yang, Xia
    [J]. ELECTRONICS, 2020, 9 (02)
  • [27] A Non-Interactive Attribute-Based Access Control Scheme by Blockchain for IoT
    Yang, Qiliang
    Zhang, Mingrui
    Zhou, Yanwei
    Wang, Tao
    Xia, Zhe
    Yang, Bo
    [J]. ELECTRONICS, 2021, 10 (15)
  • [28] Access control scheme based on blockchain and attribute-based searchable encryption in cloud environment
    Liang Yan
    Lina Ge
    Zhe Wang
    Guifen Zhang
    Jingya Xu
    Zheng Hu
    [J]. Journal of Cloud Computing, 12
  • [29] Access control scheme based on blockchain and attribute-based searchable encryption in cloud environment
    Yan, Liang
    Ge, Lina
    Wang, Zhe
    Zhang, Guifen
    Xu, Jingya
    Hu, Zheng
    [J]. JOURNAL OF CLOUD COMPUTING-ADVANCES SYSTEMS AND APPLICATIONS, 2023, 12 (01):
  • [30] An Attribute-Based Controlled Collaborative Access Control Scheme for Public Cloud Storage
    Xue, Yingjie
    Xue, Kaiping
    Gai, Na
    Hong, Jianan
    Wei, David S. L.
    Hong, Peilin
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2019, 14 (11) : 2927 - 2942