Blockchain-Based IoT Access Control System: Towards Security, Lightweight, and Cross-Domain

被引:57
|
作者
Sun, Shuang [1 ,2 ]
Du, Rong [1 ,2 ]
Chen, Shudong [1 ,2 ]
Li, Weiwei [1 ,2 ]
机构
[1] Chinese Acad Sci, Inst Microelect, Beijing 100029, Peoples R China
[2] Univ Chinese Acad Sci, Sch Microelect, Beijing 100049, Peoples R China
关键词
Blockchain; Access control; Peer-to-peer computing; Process control; Real-time systems; Denial-of-service attack; Servers; IoT; blockchain; ABAC; HLF; IBS; PDP selection algorithm; INTERNET;
D O I
10.1109/ACCESS.2021.3059863
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Most IoT devices cannot afford to be a blockchain node due to the high computation and storage loads. Thus, the blockchain is usually deployed on one delegate node, e.g., the edge device or cloud, which may encounters three drawbacks: (1) The delegate node becomes the single failure point when the number of delegate notes are limited. (2) The delegate node replicating the blockchain data can lead to privacy information leak. (3) The delegate node is vulnerable to the Distributed Denial of Service (DDoS) attack. To tackle these drawbacks, we consider to minimize the redundant of blockchain to make the IoT devices as the specialized blockchain nodes. In this paper, we integrate a permissioned blockchain (HLF), an attribute-based access control (ABAC) and an identity-based signature (IBS) to build a security, lightweight, and cross-domain blockchain-based IoT access control system. Specifically, we divided the IoT system into different function domains, named IoT domains. Then, we establish a local blockchain ledger for each IoT domain to enable more IoT devices as blockchain nodes. The local blockchain ledger records the IoT domain entities' attributes, policy files' digests, and access decisions. Meanwhile, we use the channel technology of HLF to realize cross-domain access and use the IBS to filter the legal access requests for each IoT domain to prevent DDoS attacks. We also design a policy decision point (PDP) selection algorithm that select multiple IoT devices (blockchain nodes) to achieve the real-time distributed policy decisions (off-chain). Finally, we implement and evaluate the proposed system to demonstrate its practicality.
引用
收藏
页码:36868 / 36878
页数:11
相关论文
共 50 条
  • [1] A Blockchain-Based IoT Cross-Domain Delegation Access Control Method
    Li, Chao
    Li, Fan
    Yin, Lihua
    Luo, Tianjie
    Wang, Bin
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2021, 2021
  • [2] A Blockchain-Based Cross-Domain Authentication Management System for IoT Devices
    Liu, Yizhong
    Liu, Andi
    Xia, Yu
    Hu, Bin
    Liu, Jianwei
    Wu, Qianhong
    Tiwari, Prayag
    [J]. IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING, 2024, 11 (01): : 115 - 127
  • [3] Blockchain-based cross-domain authentication strategy for trusted access to mobile devices in the IoT
    Dong, Shuai
    Yang, Hui
    Yuan, Jiaqi
    Jiao, Libin
    Yu, Ao
    Zhang, Jie
    [J]. 2020 16TH INTERNATIONAL WIRELESS COMMUNICATIONS & MOBILE COMPUTING CONFERENCE, IWCMC, 2020, : 1610 - 1612
  • [4] A Blockchain-Based Cross-Domain and Autonomous Access Control Scheme for Internet of Things
    Hao, Xiaohan
    Ren, Wei
    Fei, Yangyang
    Zhu, Tianqing
    Choo, Kim-Kwang Raymond
    [J]. IEEE TRANSACTIONS ON SERVICES COMPUTING, 2023, 16 (02) : 773 - 786
  • [5] A Lightweight Authentication Scheme Based on Consortium Blockchain for Cross-Domain IoT
    Zhang, Yujian
    Luo, Yuhao
    Chen, Xing
    Tong, Fei
    Xu, Yuwei
    Tao, Jun
    Cheng, Guang
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [6] Trusted and Efficient Cross-Domain Access Control System Based on Blockchain
    Sun, Shuang
    Chen, Shudong
    Du, Rong
    [J]. SCIENTIFIC PROGRAMMING, 2020, 2020
  • [7] Blockchain-Based Secured Access Control in an IoT System
    Algarni, Sultan
    Eassa, Fathy
    Almarhabi, Khalid
    Almalaise, Abduallah
    Albassam, Emad
    Alsubhi, Khalid
    Yamin, Mohammad
    [J]. APPLIED SCIENCES-BASEL, 2021, 11 (04): : 1 - 16
  • [8] Fabric-iot: A Blockchain-Based Access Control System in IoT
    Liu, Han
    Han, Dezhi
    Li, Dun
    [J]. IEEE ACCESS, 2020, 8 : 18207 - 18218
  • [9] Blockchain-Based Access Control and Behavior Regulation System for IoT
    Song, Haoxiang
    Tu, Zhe
    Qin, Yajuan
    [J]. SENSORS, 2022, 22 (21)
  • [10] BLECA: A Blockchain-Based Lightweight and Efficient Cross-Domain Authentication Scheme for Smart Parks
    Luo, Fengting
    Huang, Ruwei
    Chen, Yuyue
    [J]. CMC-COMPUTERS MATERIALS & CONTINUA, 2023, 77 (02): : 1815 - 1835