Decentralized access control for secure microservices cooperation with blockchain

被引:2
作者
Xi, Ning [1 ]
Liu, Jin [1 ]
Li, Yajie [1 ]
Qin, Bojun [1 ]
机构
[1] Xidian Univ, Sch Cyber Engn, Taibai Rd 2, Xian 710071, Peoples R China
基金
中国国家自然科学基金;
关键词
Microservices; Service cooperation; Access control; Permission management; Blockchain; MANAGEMENT; INTERNET; SCHEME; THINGS;
D O I
10.1016/j.isatra.2023.07.018
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the rapid advancement of cloud-native computing, the microservice with high concurrency and low coupling has ushered in an unprecedented period of vigorous development. However, due to the mutability and complexity of cooperation procedures, it is difficult to realize high-efficient security management on these microservices. Traditional centralized access control has the defects of relying on a centralized cloud manager and a single point of failure. Meanwhile, decentralized mechanisms are defective by inconsistent policies defined by different participants. This paper first proposes a blockchain-based distributed access control policies and scheme, especially for microservices coopera-tion with dynamic access policies. We store the authorized security policies on the blockchain to solve the inconsistent policy problem while enabling individual management of personalized access policies by the providers rather than a central authority. Then we propose a graph-based decision-making scheme to achieve an efficient access control for microservices cooperation. Through the evaluations and experiments, it shows that our solution can realize effective distributed access control at an affordable cost.(c) 2023 ISA. Published by Elsevier Ltd. All rights reserved.
引用
收藏
页码:44 / 51
页数:8
相关论文
共 39 条
[21]  
Pahl M., 2018, NOMS 2018 2018 IEEE, P1
[22]   A New Centralized Access Control Scheme for D2D-Enabled mmWave Networks [J].
Panno, Daniela ;
Riolo, Salvatore .
IEEE ACCESS, 2019, 7 :80697-80716
[23]   Towards multi-party policy-based access control in federations of cloud and edge microservices [J].
Preuveneers, Davy ;
Joosen, Wouter .
2019 4TH IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (EUROS&PW), 2019, :29-38
[24]   Access control with delegated authorization policy evaluation for data-driven microserviceworkflows [J].
Preuveneers, Davy ;
Joosen, Wouter .
Future Internet, 2017, 9 (04)
[25]   DSMAC: Privacy-Aware Decentralized Self-Management of Data Access Control Based on Blockchain for Health Data [J].
Saidi, Hafida ;
Labraoui, Nabila ;
Ari, Ado Adamou Abba ;
Maglaras, Leandros A. ;
Emati, Joel Herve Mboussam .
IEEE ACCESS, 2022, 10 :101011-101028
[26]   What we do - and don't - know about the Smart Home: An analysis of the Smart Home literature [J].
Solaimani, Sam ;
Keijzer-Broers, Wally ;
Bouwman, Harry .
INDOOR AND BUILT ENVIRONMENT, 2015, 24 (03) :370-383
[27]   Blockchain-Based Access Control Model to Preserve Privacy for Personal Health Record Systems [J].
Thwin, Thein Than ;
Vasupongayya, Sangsuree .
SECURITY AND COMMUNICATION NETWORKS, 2019, 2019
[28]  
Tian Y, 2017, PROCEEDINGS OF THE 26TH USENIX SECURITY SYMPOSIUM (USENIX SECURITY '17), P361
[29]  
Vince T, 2019, PROCEEDINGS OF THE 2019 IEEE INTERNATIONAL CONFERENCE ON MODERN ELECTRICAL AND ENERGY SYSTEMS (MEES'2019), P474, DOI 10.1109/MEES.2019.8896686
[30]   A Blockchain-Based Framework for Data Sharing With Fine-Grained Access Control in Decentralized Storage Systems [J].
Wang, Shangping ;
Zhang, Yinglong ;
Zhang, Yaling .
IEEE ACCESS, 2018, 6 :38437-38450