A privacy-aware authentication and usage-controlled access protocol for IIoT decentralized data marketplace

被引:0
作者
Dixit, Akanksha [1 ]
Zarpelao, Bruno Bogaz [2 ]
Smith-Creasey, Max [3 ]
Rajarajan, Muttukrishnan [1 ]
机构
[1] Univ London, Sch Sci & Technol, London, England
[2] State Univ Londrina UEL, Comp Sci Dept, Londrina, Brazil
[3] IEEE UK & Ireland Cyber Secur Grp, London, England
关键词
Data marketplace; Authentication; Usage control; Decentralized Identifiers (DID); Verifiable Credentials (VC); Privacy; User-revocation; BLOCKCHAIN; INTERNET;
D O I
10.1016/j.cose.2024.104050
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Data is ubiquitous, powerful and valuable today. With vast instalments of Industrial Internet-of-Things (IIoT) infrastructure, data is in abundance albeit sitting in organizational silos. Data Marketplaces have emerged to allow monetization of data by trading it with interested buyers. While centralized marketplaces are common, they are controlled by few and are non-transparent. Decentralized data marketplaces allow the democratization of rates, trading terms and fine control to participants. However, in such a marketplace, ensuring privacy and security is crucial. Existing data exchange schemes depend on a trusted third party for key management during authentication and rely on a 'one-time-off' approach to authorization. This paper proposes a user-empowered, privacy-aware, authentication and usage-controlled access protocol for IIoT data marketplace. The proposed protocol leverages the concept of Self-Sovereign Identity (SSI) and is based on the standards of Decentralized Identifier (DID) and Verifiable Credential (VC). DIDs empower buyers and give them complete control over their identities. The buyers authenticate and prove claims to access data securely using VC. The proposed protocol also implements a dynamic user-revocation policy. Usage-controlled based access provides secure ongoing authorization during data exchange. A detailed performance and security analysis is provided to show its feasibility.
引用
收藏
页数:13
相关论文
共 43 条
  • [1] Blockchain Technology in Healthcare: A Systematic Review
    Agbo, Cornelius C.
    Mahmoud, Qusay H.
    Eklund, J. Mikael
    [J]. HEALTHCARE, 2019, 7 (02)
  • [2] Reliable, Fair and Decentralized Marketplace for Content Sharing Using Blockchain
    Banerjee, Prabal
    Govindarajan, Chander
    Jayachandran, Praveen
    Ruj, Sushmita
    [J]. 2020 IEEE INTERNATIONAL CONFERENCE ON BLOCKCHAIN (BLOCKCHAIN 2020), 2020, : 365 - 370
  • [3] On Using Obligations for Usage Control in Joining of Datasets
    Bargh, Mortaza S.
    Vink, Marco
    Choenni, Sunil
    [J]. INFORMATION SYSTEMS SECURITY AND PRIVACY, 2018, 867 : 173 - 196
  • [4] Zerocash: Decentralized Anonymous Payments from Bitcoin
    Ben-Sasson, Eli
    Chiesa, Alessandro
    Garmant, Christina
    Green, Matthew
    Miers, Ian
    Tromer, Eran
    Virza, Madars
    [J]. 2014 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP 2014), 2014, : 459 - 474
  • [5] Camenisch J, 2002, LECT NOTES COMPUT SC, V2442, P61
  • [6] Cremers CJF, 2008, LECT NOTES COMPUT SC, V5123, P414
  • [7] Blockchain Enabled Data Transmission for Energy Imbalance Market
    Cui, Jingshi
    Gu, Nan
    Wu, Chenye
    [J]. IEEE TRANSACTIONS ON SUSTAINABLE ENERGY, 2022, 13 (02) : 1254 - 1266
  • [8] Enabling Identity for the IoT-as-a-Service Business Model
    de Diego, Santiago
    Regueiro, Cristina
    Macia-Fernandez, Gabriel
    [J]. IEEE ACCESS, 2021, 9 : 159965 - 159975
  • [9] Dixit A., 2022, Supply chain
  • [10] FAST DATA: A Fair, Secure, and Trusted Decentralized IIoT Data Marketplace Enabled by Blockchain
    Dixit, Akanksha
    Singh, Arjun
    Rahulamathavan, Yogachandran
    Rajarajan, Muttukrishnan
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (04) : 2934 - 2944