Secure Data-Centric Access Control for Smart Grid Services Based on Publish/Subscribe Systems

被引:14
|
作者
Duan, Li [1 ,2 ]
Liu, Dongxi [3 ]
Zhang, Yang [1 ]
Chen, Shiping [3 ]
Liu, Ren Ping [4 ]
Cheng, Bo [1 ]
Chen, Junliang [1 ]
机构
[1] Beijing Univ Posts & Telecommun, State Key Lab Networking & Switching Technol, 10 Xi Tu Cheng Rd, Beijing 100876, Peoples R China
[2] CSIRO, Canberra, ACT, Australia
[3] CSIRO, Data 61, Canberra, ACT, Australia
[4] UTS, Sch Comp & Commun, Bldg 11,Level 8,Room 223,81 Broadway,POB 123, Ultimo, NSW 2007, Australia
基金
中国国家自然科学基金;
关键词
Internet of things; access control; full homomorphic encryption; service collaboration; publish/subscribe system; AGGREGATION;
D O I
10.1145/3007190
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The communication systems in existing smart gridsmainly take the request/reply interaction model, in which data access is under the direct control of data producers. This tightly controlled interaction model is not scalable to support complex interactions among smart grid services. On the contrary, the publish/subscribe system features a loose coupling communication infrastructure and allows indirect, anonymous and multi-cast interactions among smart grid services. The publish/subscribe system can thus support scalable and flexible collaboration among smart grid services. However, the access is not under the direct control of data producers, it might not be easy to implement an access control scheme for a publish/subscribe system. In this article, we propose a Data-Centric Access Control Framework (DCACF) to support secure access control in a publish/subscribe model. This framework helps to build scalable smart grid services, while keeping features of service interactions and data confidentiality at the same time. The data published in our DCACF is encrypted with a fully homomorphic encryption scheme, which allows in-grid homomorphic aggregation of the encrypted data. The encrypted data is accompanied by bloom-filter encoded control policies and access credentials to enable indirect access control. We have analyzed the correctness and security of our DCACF and evaluated its performance in a distributed environment.
引用
收藏
页数:17
相关论文
共 50 条
  • [1] Data-centric Access Control with Confidentiality for Collaborating Smart Grid Services based on Publish/Subscribe Paradigm
    Zhang, Yang
    Chen, Jun-Liang
    [J]. 2013 33RD IEEE INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS WORKSHOPS (ICDCSW 2013), 2013, : 45 - 50
  • [2] Data-Centric Publish-Subscribe Approach for Distributed Complex Event Processing Deployment in Smart Grid Internet of Things
    Zu, Xiangrong
    Bai, Yan
    Yao, Xu
    [J]. PROCEEDINGS OF 2016 IEEE 7TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING AND SERVICE SCIENCE (ICSESS 2016), 2016, : 710 - 713
  • [3] A Secure Decentralized Data-Centric Information Infrastructure for Smart Grid
    Kim, Young-Jin
    Thottan, Marina
    Kolesnikov, Vladimir
    Lee, Wonsuck
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2010, 48 (11) : 58 - 65
  • [4] Type-Based Access Control in Data-Centric Systems
    Caires, Luis
    Perez, Jorge A.
    Seco, Joao Costa
    Vieira, Hugo Torres
    Ferrao, Lucio
    [J]. PROGRAMMING LANGUAGES AND SYSTEMS, 2011, 6602 : 136 - +
  • [5] RELOAD extension for data discovery and transfer in data-centric publish-subscribe environments
    Lopez-Vega, Jose M.
    Camarillo, Gonzalo
    Povedano-Molina, Javier
    Lopez-Soler, Juan M.
    [J]. COMPUTER STANDARDS & INTERFACES, 2013, 36 (01) : 110 - 121
  • [6] Safe Distribution and Parallel Execution of Data-centric Workflows over the Publish/Subscribe Abstraction
    Jergler, Matin
    Jacobsen, Hans-Arno
    Sadoghi, Mohammad
    Hull, Richard
    Vaculin, Roman
    [J]. 2016 32ND IEEE INTERNATIONAL CONFERENCE ON DATA ENGINEERING (ICDE), 2016, : 1498 - 1499
  • [7] Safe Distribution and Parallel Execution of Data-Centric Workflows over the Publish/Subscribe Abstraction
    Sadoghi, Mohammad
    Jergler, Martin
    Jacobsen, Hans-Arno
    Hull, Richard
    Vaculin, Roman
    [J]. IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2015, 27 (10) : 2824 - 2838
  • [8] A topic-centric access control model for the publish/subscribe paradigm
    Xie, Rongna
    Shi, Guozhen
    Guo, Yunchuan
    Li, Fenghua
    [J]. CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2020, 32 (09):
  • [9] Access Control on Internet of Things based on Publish/Subscribe using Authentication Server and Secure Protocol
    Wardana, Aulia Arif
    Perdana, Riza Satria
    [J]. PROCEEDINGS OF 2018 THE 10TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY AND ELECTRICAL ENGINEERING (ICITEE), 2018, : 118 - 123
  • [10] Data-Centric Hierarchical Distributed Model Predictive Control for Smart Grid Energy Management
    Saad, Ahmed
    Youssef, Tarek
    Elsayed, Ahmed T.
    Amin, Amr
    Abdalla, Omar Hanafy
    Mohammed, Osama
    [J]. IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2019, 15 (07) : 4086 - 4098