Decentralized data access control over consortium blockchains

被引:16
|
作者
Chen, Yaoliang [1 ]
Chen, Shi [1 ]
Liang, Jiao [1 ]
Feagan, Lance Warren [2 ]
Han, Weili [1 ]
Huang, Sheng [2 ]
Wang, X. Sean [1 ]
机构
[1] Fudan Univ, Shanghai, Peoples R China
[2] Gezhi Tech Co Ltd, Shanghai, Peoples R China
基金
国家重点研发计划;
关键词
Blockchain; Consortium blockchain; Data security; Access control;
D O I
10.1016/j.is.2020.101590
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Blockchain is an emerging data management technology that enables people in a collaborative network to establish trusted connections with the other participants. Recently consortium blockchains have raised interest in a broader blockchain technology discussion. Instead of a fully public, autonomous network, consortium blockchain supports a network where participants can be limited to a subset of users and data access strictly controlled. Access control policies should be defined by the respective data owner and applied throughout the network without requiring a centralized data administrator. As a result, decentralized data access control (DDAC) emerges as a fundamental challenge for such systems. However, we show from a trust model for consortium collaborative networks that current consortium blockchain systems provide limited support for DDAC. Further, the distributed, replicated nature of blockchain makes it even more challenging to control data access, especially read access, compared with traditional DBMSes. We investigate possible strategies to protect data from being read by unauthorized users in consortium blockchain systems using combinations of ledger partitioning and encryption strategies. A general framework is proposed to help inexperienced users determine appropriate strategies under different application scenarios. The framework was implemented on top of Hyperledger Fabric to evaluate feasibility. Experimental results along with a real-world case study contrasted the performance of different strategies under various conditions and the practicality of the proposed framework. (C) 2020 Elsevier Ltd. All rights reserved.
引用
收藏
页数:15
相关论文
共 50 条
  • [1] Building Private Blockchains over Public Blockchains (PoP): An Attribute-Based Access Control Approach
    Huang, Dijiang
    Chung, Chun-Jen
    Dong, Qiuxiang
    Luo, Jim
    Kang, Myong
    SAC '19: PROCEEDINGS OF THE 34TH ACM/SIGAPP SYMPOSIUM ON APPLIED COMPUTING, 2019, : 355 - 363
  • [2] Ontology Modeling for Data Reliability Assessment in Consortium Blockchains
    Shi, Yani
    Shi, Dongying
    Ying, Jiji
    Yan, Jiaqi
    JOURNAL OF GLOBAL INFORMATION MANAGEMENT, 2023, 31 (07)
  • [3] Are Smart Contracts and Blockchains Suitable for Decentralized Railway Control?
    Kuperberg, Michael
    Kindler, Daniel
    Jeschke, Sabina
    LEDGER, 2020, 5 : 36 - 61
  • [4] Decentralized Netting Protocol over Consortium Blockchain
    Naganuma, Ken
    Yoshino, Masayuki
    Sato, Hisayoshi
    Yamada, Nishio
    Suzuki, Takayuki
    Kunihiro, Noboru
    PROCEEDINGS OF 2018 INTERNATIONAL SYMPOSIUM ON INFORMATION THEORY AND ITS APPLICATIONS (ISITA2018), 2018, : 174 - 177
  • [5] Access Control over Uncertain Data
    Rastogi, Vibhor
    Suciu, Dan
    Welbourne, Evan
    PROCEEDINGS OF THE VLDB ENDOWMENT, 2008, 1 (01): : 821 - 832
  • [6] Revocable, dynamic and decentralized data access control in cloud storage
    Wang, Chong
    Jin, Hao
    Wei, Ronglei
    Zhou, Ke
    JOURNAL OF SUPERCOMPUTING, 2022, 78 (07): : 10063 - 10087
  • [7] Revocable, dynamic and decentralized data access control in cloud storage
    Chong Wang
    Hao Jin
    Ronglei Wei
    Ke Zhou
    The Journal of Supercomputing, 2022, 78 : 10063 - 10087
  • [8] Decentralized Access Control with Anonymous Authentication of Data Stored in Clouds
    Ruj, Sushmita
    Stojmenovic, Milos
    Nayak, Amiya
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2014, 25 (02) : 384 - 394
  • [9] Droplet: Decentralized Authorization and Access Control for Encrypted Data Streams
    Shafagh, Hossein
    Burkhalter, Lukas
    Ratnasamy, Sylvia
    Hithnawi, Anwar
    PROCEEDINGS OF THE 29TH USENIX SECURITY SYMPOSIUM, 2020, : 2469 - 2486
  • [10] Decentralized Access Control Infrastructure Using Blockchain for Big Data
    Mounnan, Oussama
    Abou El Kalam, Anas
    El Haourani, Lamia
    2019 IEEE/ACS 16TH INTERNATIONAL CONFERENCE ON COMPUTER SYSTEMS AND APPLICATIONS (AICCSA 2019), 2019,