Distributed attribute-based access control system using permissioned blockchain

被引:31
|
作者
Rouhani, Sara [1 ]
Belchior, Rafael [2 ]
Cruz, Rui S. [2 ]
Deters, Ralph [1 ]
机构
[1] Univ Saskatchewan, Dept Comp Sci, Saskatoon, SK S7N 5C9, Canada
[2] Univ Lisbon, Inst Super Tecn, Dept Comp Sci & Engn, Lisbon, Portugal
关键词
Distributed access control; Attribute-based access control; Blockchain; Hyperledger fabric; Performance; MANAGEMENT; FRAMEWORK; SECURITY; INTERNET; IOT;
D O I
10.1007/s11280-021-00874-7
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Auditing provides essential security control in computer systems by keeping track of all access attempts, including both legitimate and illegal access attempts. This phase can be useful in the context of audits, where eventual misbehaving parties can be held accountable. Blockchain technology can provide the trusted auditability required for access control systems. In this paper, we propose a distributed Attribute-Based Access Control (ABAC) system based on blockchain to provide trusted auditing of access attempts. Besides auditability, our system presents a level of transparency that both access requesters and resource owners can benefit from it. We present a system architecture with an implementation based on Hyperledger Fabric, achieving high efficiency and low computational overhead. The proposed solution is validated through a use case of independent digital libraries. Detailed performance analysis of our implementation is presented, taking into account different consensus mechanisms and databases. The experimental evaluation shows that our presented system can effectively handle a transaction throughput of 270 transactions per second, with an average latency of 0.54 seconds per transaction.
引用
收藏
页码:1617 / 1644
页数:28
相关论文
共 50 条
  • [41] HetDAPAC: Distributed Attribute-Based Private Access Control with Heterogeneous Attributes
    Department of Electrical and Computer Engineering University of Maryland, College Park
    MD
    20742, United States
    arXiv, 1600,
  • [42] Blockchain Access Control Scheme Based on Multi-authority Attribute-Based Encryption
    Li, Yang
    Qi, Baoyue
    Wang, Mengmeng
    Zhu, Jianming
    Wang, Xiuli
    DATA SCIENCE (ICPCSEE 2022), PT II, 2022, 1629 : 105 - 124
  • [43] Cloud Storage Data Access Control Scheme Based on Blockchain and Attribute-Based Encryption
    Yang, Xiaodong
    Chen, Aijia
    Wang, Zhisong
    Li, Shudong
    SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [44] Fast Distributed Evaluation of Stateful Attribute-Based Access Control Policies
    Thang Bui
    Stoller, Scott D.
    Sharma, Shikhar
    DATA AND APPLICATIONS SECURITY AND PRIVACY XXXI, DBSEC 2017, 2017, 10359 : 101 - 119
  • [45] Attribute-Based Oblivious Access Control
    Han, Jinguang
    Susilo, Willy
    Mu, Yi
    Yan, Jun
    COMPUTER JOURNAL, 2012, 55 (10): : 1202 - 1215
  • [46] A privacy-enhanced attribute-based access control system
    Kolter, Jan
    Schillinger, Rolf
    Pernul, Guenther
    DATA AND APPLICATIONS SECURITY XXI, PROCEEDINGS, 2007, 4602 : 129 - +
  • [47] Distributed Framework of SWIFT System Based on Permissioned Blockchain
    Zhu J.-M.
    Ding Q.-Y.
    Gao S.
    Ruan Jian Xue Bao/Journal of Software, 2019, 30 (06): : 1594 - 1613
  • [48] Cooperative attribute-based access control for enterprise computing system
    Li, Mengting
    Huang, Xinyi
    Liu, Joseph K.
    Xu, Li
    Wu, Wei
    INTERNATIONAL JOURNAL OF EMBEDDED SYSTEMS, 2015, 7 (3-4) : 191 - 202
  • [49] Secure Federated Cloud Storage Protection Strategy Using Hybrid Heuristic Attribute-Based Encryption With Permissioned Blockchain
    Kathole, Atul B.
    Vhatkar, Kapil Netaji
    Goyal, Ankur
    Kaushik, Shivkant
    Mirge, Amita Sanjiv
    Jain, Prince
    Soliman, Mohamed S.
    Islam, Mohammad Tariqul
    IEEE ACCESS, 2024, 12 : 117154 - 117169
  • [50] An Attribute-Based Access Control using chaincode in RFID systems
    Figueroa, Santiago
    Anorga, Javier
    Arrizabalaga, Saioa
    Irigoyen, Inigo
    Monterde, Mario
    2019 10TH IFIP INTERNATIONAL CONFERENCE ON NEW TECHNOLOGIES, MOBILITY AND SECURITY (NTMS), 2019,