Flexible Fine-grained Data Access Management for Hyperledger Fabric

被引:0
|
作者
Parente, Joao [1 ]
Alonso, Ana Nunes [1 ]
Coelho, Fabio [1 ]
Vinagre, Joao [1 ]
Bastos, Paulo [2 ]
机构
[1] INESC TEC & U Minho, Braga, Portugal
[2] NAU 21, Porto, Portugal
关键词
access control; blockchain; privacy; confidentiality;
D O I
10.1109/BCCA55292.2022.9921837
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As blockchains go beyond cryptocurrencies into applications in multiple industries such as Insurance, Healthcare and Banking, handling personal or sensitive data, data access control becomes increasingly relevant. Access control mechanisms proposed so far are mostly based on requester identity, particularly for permissioned blockchain platforms, and are limited to binary, all-or-nothing access decisions. This is the case with Hyperledger Fabric's native access control mechanisms and, as permission updates require consensus, these fall short regarding the flexibility required to address GDPR-derived policies and client consent management. We propose SDAM, a novel access control mechanism for Fabric that enables fine-grained and dynamic control policies, using both contextual and resource attributes for decisions. Instead of binary results, decisions may also include mandatory data transformations as to conform with the expressed policy, all without modifications to Fabric. Results show that SDAM's overhead w.r.t baseline Fabric is acceptable. The scalability of the approach w.r.t to the number of concurrent clients is also evaluated and found to follow Fabric's.
引用
收藏
页码:76 / 84
页数:9
相关论文
共 50 条
  • [1] A Privacy-Protection Data Separation Approach for Fine-Grained Data Access Management
    Dai, Wenyun
    Chen, Longbin
    Qiu, Meikang
    Wu, Ana
    Chen, Bin
    [J]. 2017 IEEE INTERNATIONAL CONFERENCE ON SMART CLOUD (SMARTCLOUD), 2017, : 84 - 89
  • [2] Fine-grained access control for database management systems
    Zhu, Hong
    Lue, Kevin
    [J]. DATA MANAGEMENT: DATA, DATA EVERYWHERE, PROCEEDINGS, 2007, 4587 : 215 - +
  • [3] Fine-Grained Access Management in Reconfigurable Scan Networks
    Baranowski, Rafal
    Kochte, Michael A.
    Wunderlich, Hans-Joachim
    [J]. IEEE TRANSACTIONS ON COMPUTER-AIDED DESIGN OF INTEGRATED CIRCUITS AND SYSTEMS, 2015, 34 (06) : 937 - 946
  • [4] The Fine-Grained Security Access Control of Spatial Data
    Ma, Fuguang
    Gao, Yong
    Yan, Menglong
    Xu, Fuchun
    Liu, Ding
    [J]. 2010 18TH INTERNATIONAL CONFERENCE ON GEOINFORMATICS, 2010,
  • [5] On the facilitation of fine-grained access to distributed healthcare data
    Slaymaker, Mark
    Power, David
    Russell, Douglas
    Simpson, Andrew
    [J]. SECURE DATA MANAGEMENT, PROCEEDINGS, 2008, 5159 : 169 - 184
  • [6] Realizing Fine-Grained and Flexible Access Control to Outsourced Data with Attribute-Based Cryptosystems
    Zhao, Fangming
    Nishide, Takashi
    Sakurai, Kouichi
    [J]. INFORMATION SECURITY PRACTICE AND EXPERIENCE, 2011, 6672 : 83 - 97
  • [7] A License Management and Fine-Grained Verifiable Data Access Control System for Online Catering
    Ni, Xiaoze
    Feng, Jian
    Jiang, Renkai
    He, Yajie
    Liu, Tao
    Chen, Ting
    Qiu, Sen
    [J]. IEEE TRANSACTIONS ON COMPUTATIONAL SOCIAL SYSTEMS, 2023, 10 (06) : 3586 - 3601
  • [8] Fine-grained Data Usage Analysis by Access Sampling Seeing The Data That is Not There
    Zhang, Zhizhou
    Ye, Chencheng
    Lavaee, Rahman
    Gu, Ning
    Ding, Chen
    [J]. PROCEEDINGS OF THE INTERNATIONAL SYMPOSIUM ON MEMORY SYSTEMS (MEMSYS 2018), 2018, : 221 - 231
  • [9] SMGuard: A Flexible and Fine-Grained Resource Management Framework for GPUs
    Yu, Chao
    Bai, Yuebin
    Yang, Hailong
    Cheng, Kun
    Gu, Yuhao
    Luan, Zhongzhi
    Qian, Depei
    [J]. IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2018, 29 (12) : 2849 - 2862
  • [10] Fine-grained Access Control and Revocation for Sharing Data on Clouds
    Tu, Shan-shan
    Niu, Shao-zhang
    Li, Hui
    Yun Xiao-ming
    Li, Meng-jiao
    [J]. 2012 IEEE 26TH INTERNATIONAL PARALLEL AND DISTRIBUTED PROCESSING SYMPOSIUM WORKSHOPS & PHD FORUM (IPDPSW), 2012, : 2146 - 2155