Fine-Grained Data Access Control for Collaborative Process Execution on Blockchain

被引:6
|
作者
Marangone, Edoardo [1 ]
Di Ciccio, Claudio [1 ]
Weber, Ingo [2 ]
机构
[1] Sapienza Univ Rome, Rome, Italy
[2] Tech Univ Berlin, Software & Business Engn, Berlin, Germany
关键词
Attribute Based Encryption; Blockchain; Business process management; IPFS;
D O I
10.1007/978-3-031-16168-1_4
中图分类号
F [经济];
学科分类号
02 ;
摘要
Multi-party business processes are based on the cooperation of different actors in a distributed setting. Blockchains can provide support for the automation of such processes, even in conditions of partial trust among the participants. On-chain data are stored in all replicas of the ledger and therefore accessible to all nodes that are in the network. Although this fosters traceability, integrity, and persistence, it undermines the adoption of public blockchains for process automation since it conflicts with typical confidentiality requirements in enterprise settings. In this paper, we propose a novel approach and software architecture that allow for fine-grained access control over process data on the level of parts of messages. In our approach, encrypted data are stored in a distributed space linked to the blockchain system backing the process execution; data owners specify access policies to control which users can read which parts of the information. To achieve the desired properties, we utilise AttributeBased Encryption for the storage of data, and smart contracts for access control, integrity, and linking to process data. We implemented the approach in a proof-of-concept and conduct a case study in supply-chainmanagement. From the experiments, we find our architecture to be robustwhile still keeping execution costs reasonably low.
引用
收藏
页码:51 / 67
页数:17
相关论文
共 50 条
  • [41] Fine-grained Access Control to Web Databases
    Roichman, Alex
    Gudes, Ehud
    [J]. SACMAT'07: PROCEEDINGS OF THE 12TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2007, : 31 - 40
  • [42] A Fine-Grained Image Access Control Model
    Al Bouna, Bechara
    Chbeir, Richard
    Gabillon, Alban
    Capolsini, Patrick
    [J]. 8TH INTERNATIONAL CONFERENCE ON SIGNAL IMAGE TECHNOLOGY & INTERNET BASED SYSTEMS (SITIS 2012), 2012, : 603 - 612
  • [43] Fine-grained access control of PDM and CAPP
    Feng, SH
    Jiang, ZL
    [J]. ADVANCES IN MATERIALS MANUFACTURING SCIENCE AND TECHNOLOGY, 2004, 471-472 : 573 - 576
  • [44] Fine-grained access control for cloud computing
    Ye, Xinfeng
    Khoussainov, Bakh
    [J]. INTERNATIONAL JOURNAL OF GRID AND UTILITY COMPUTING, 2013, 4 (2-3) : 160 - 168
  • [45] BDSS: Blockchain-based Data Sharing Scheme With Fine-grained Access Control And Permission Revocation In Medical Environment
    Zhang, Lejun
    Zou, Yanfei
    Yousuf, Muhammad Hassam
    Wang, Weizheng
    Jin, Zilong
    Su, Yansen
    Seokhoon, Kim
    [J]. KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2022, 16 (05): : 1634 - 1652
  • [46] A blockchain-based framework for electronic medical records sharing with fine-grained access control
    Sun, Jin
    Ren, Lili
    Wang, Shangping
    Yao, Xiaomin
    [J]. PLOS ONE, 2020, 15 (10):
  • [47] Designing Fine-Grained Access Control for Software-Defined Networks Using Private Blockchain
    Chattaraj, Durbadal
    Bera, Basudeb
    Das, Ashok Kumar
    Rodrigues, Joel J. P. C.
    Park, Youngho
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (02) : 1542 - 1559
  • [48] Blockchain Based Multi-Authority Fine-Grained Access Control System With Flexible Revocation
    Xiao, Meiyan
    Huang, Qiong
    Miao, Ying
    Li, Shunpeng
    Susilo, Willy
    [J]. IEEE TRANSACTIONS ON SERVICES COMPUTING, 2022, 15 (06) : 3143 - 3155
  • [49] A Blockchain-based Secure Cloud Files Sharing Scheme with Fine-Grained Access Control
    Liu, Yuke
    Zhang, Junwei
    Gao, Qi
    [J]. 2018 INTERNATIONAL CONFERENCE ON NETWORKING AND NETWORK APPLICATIONS (NANA), 2018, : 277 - 283
  • [50] Access policy sheet for access control in fine-grained XML
    Wu, J
    Mu, Y
    Seberry, J
    Ruan, C
    [J]. EMBEDDED AND UBIQUITOUS COMPUTING - EUC 2005 WORKSHOPS, PROCEEDINGS, 2005, 3823 : 1273 - 1282