Capability-based IoT access control using blockchain

被引:24
|
作者
Liu, Yue [1 ,2 ]
Lu, Qinghua [1 ,2 ]
Chen, Shiping [1 ,2 ]
Qu, Qiang [3 ]
O'Connor, Hugo [2 ]
Choo, Kim-Kwang Raymond [4 ]
Zhang, He [5 ]
机构
[1] Univ New South Wales, Sch Comp Sci & Engn, Sydney, NSW, Australia
[2] CSIRO, Data61, Canberra, ACT, Australia
[3] Chinese Acad Sci, Shenzhen Inst Adv Technol, Shenzhen, Guangdong, Peoples R China
[4] Univ Texas San Antonio, Dept Informat Syst & Cyber Secur, San Antonio, TX USA
[5] Nanjing Univ, Software Inst, Nanjing, Jiangsu, Peoples R China
关键词
Blockchain; Internet of things; Capability-based access control; Identity management; Architecture design;
D O I
10.1016/j.dcan.2020.10.004
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Internet of Things (IoT) devices facilitate intelligent service delivery in a broad range of settings, such as smart offices, homes and cities. However, the existing IoT access control solutions are mainly based on conventional identity management schemes and use centralized architectures. There are known security and privacy limitations with such schemes and architectures, such as the single-point failure or surveillance (e.g., device tracking). Hence, in this paper, we present an architecture for capability-based IoT access control utilizing the blockchain and decentralized identifiers to manage the identity and access control for IoT devices. Then, we propose a protocol to provide a systematic view of system interactions, to improve security. We also implement a proof-of-concept prototype of the proposed approach and evaluate the prototype using a real-world use case. Our evaluation results show that the proposed solution is feasible, secure, and scalable.
引用
收藏
页码:463 / 469
页数:7
相关论文
共 50 条
  • [1] Capability-based IoT access control using blockchain
    Yue Liu
    Qinghua Lu
    Shiping Chen
    Qiang Qu
    Hugo OConnor
    KimKwang Raymond Choo
    He Zhang
    [J]. Digital Communications and Networks, 2021, 7 (04) - 469
  • [2] Blockchain-based Scheme for Authentication and Capability-based Access Control in IoT Environment
    Sivaselvan, N.
    Bhat, Vivekananda K.
    Rajarajan, Muttukrishnan
    [J]. 2020 11TH IEEE ANNUAL UBIQUITOUS COMPUTING, ELECTRONICS & MOBILE COMMUNICATION CONFERENCE (UEMCON), 2020, : 323 - 330
  • [3] A Traceable Capability-based Access Control for IoT
    Li, Chao
    Li, Fan
    Huang, Cheng
    Yin, Lihua
    Luo, Tianjie
    Wang, Bin
    [J]. CMC-COMPUTERS MATERIALS & CONTINUA, 2022, 72 (03): : 4967 - 4982
  • [4] CAPLets: Resource Aware, Capability-Based Access Control for IoT
    Bakir, Fatih
    Krintz, Chandra
    Wolski, Rich
    [J]. 2021 ACM/IEEE 6TH SYMPOSIUM ON EDGE COMPUTING (SEC 2021), 2021, : 106 - 120
  • [5] CoAP Option for Capability-Based Access Control for IoT-Applications
    Chen, Borting
    Guenes, Mesut
    Huang, Yu-Lun
    [J]. IOTBD: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON INTERNET OF THINGS AND BIG DATA, 2016, : 266 - 274
  • [6] Information Flow Control Based on the CapBAC (Capability-Based Access Control) Model in the IoT
    Nakamura, Shigenari
    Enokido, Tomoya
    Takizawa, Makoto
    [J]. INTERNATIONAL JOURNAL OF MOBILE COMPUTING AND MULTIMEDIA COMMUNICATIONS, 2019, 10 (04) : 13 - 25
  • [7] Authentication and Capability-based Access Control: An Integrated Approach for IoT Environment
    Sivaselvan, N.
    Asif, Waqar
    Bhat, Vivekananda K.
    Rajarajan, Muttukrishnan
    [J]. 2020 12TH INTERNATIONAL CONFERENCE ON COMMUNICATION SOFTWARE AND NETWORKS (ICCSN 2020), 2020, : 110 - 117
  • [8] Capability-Based Access Control for the Internet of Things: An Ethereum Blockchain-Based Scheme
    Nakamura, Yuta
    Zhang, Yuanyu
    Sasabe, Masahiro
    Kasahara, Shoji
    [J]. 2019 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2019,
  • [9] BlendCAC: A BLockchain-ENabled Decentralized Capability-based Access Control for IoTs
    Xu, Ronghua
    Chen, Yu
    Blasch, Erik
    Chen, Genshe
    [J]. IEEE 2018 INTERNATIONAL CONGRESS ON CYBERMATICS / 2018 IEEE CONFERENCES ON INTERNET OF THINGS, GREEN COMPUTING AND COMMUNICATIONS, CYBER, PHYSICAL AND SOCIAL COMPUTING, SMART DATA, BLOCKCHAIN, COMPUTER AND INFORMATION TECHNOLOGY, 2018, : 1027 - 1034
  • [10] Capability-Based Information Flow Control Model in the IoT
    Nakamura, Shigenari
    Enokido, Tomoya
    Barolli, Leonard
    Takizawa, Makoto
    [J]. INNOVATIVE MOBILE AND INTERNET SERVICES IN UBIQUITOUS COMPUTING, IMIS-2019, 2020, 994 : 63 - 71