Distributed attribute-based access control system using permissioned blockchain

被引:34
|
作者
Rouhani, Sara [1 ]
Belchior, Rafael [2 ]
Cruz, Rui S. [2 ]
Deters, Ralph [1 ]
机构
[1] Univ Saskatchewan, Dept Comp Sci, Saskatoon, SK S7N 5C9, Canada
[2] Univ Lisbon, Inst Super Tecn, Dept Comp Sci & Engn, Lisbon, Portugal
来源
WORLD WIDE WEB-INTERNET AND WEB INFORMATION SYSTEMS | 2021年 / 24卷 / 05期
关键词
Distributed access control; Attribute-based access control; Blockchain; Hyperledger fabric; Performance; MANAGEMENT; FRAMEWORK; SECURITY; INTERNET; IOT;
D O I
10.1007/s11280-021-00874-7
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Auditing provides essential security control in computer systems by keeping track of all access attempts, including both legitimate and illegal access attempts. This phase can be useful in the context of audits, where eventual misbehaving parties can be held accountable. Blockchain technology can provide the trusted auditability required for access control systems. In this paper, we propose a distributed Attribute-Based Access Control (ABAC) system based on blockchain to provide trusted auditing of access attempts. Besides auditability, our system presents a level of transparency that both access requesters and resource owners can benefit from it. We present a system architecture with an implementation based on Hyperledger Fabric, achieving high efficiency and low computational overhead. The proposed solution is validated through a use case of independent digital libraries. Detailed performance analysis of our implementation is presented, taking into account different consensus mechanisms and databases. The experimental evaluation shows that our presented system can effectively handle a transaction throughput of 270 transactions per second, with an average latency of 0.54 seconds per transaction.
引用
收藏
页码:1617 / 1644
页数:28
相关论文
共 50 条
  • [1] Distributed attribute-based access control system using permissioned blockchain
    Sara Rouhani
    Rafael Belchior
    Rui S. Cruz
    Ralph Deters
    World Wide Web, 2021, 24 : 1617 - 1644
  • [2] Utilizing Policy Machine for Attribute-Based Access Control in Permissioned Blockchain
    Lawal, Sherifdeen
    Krishnan, Ram
    2021 IEEE INTERNATIONAL CONFERENCE ON OMNI-LAYER INTELLIGENT SYSTEMS (IEEE COINS 2021), 2021, : 131 - 136
  • [3] Attribute-Based Access Control Policy Review in Permissioned Blockchain
    Lawal, Sherifdeen
    Krishnan, Ram
    SECURE KNOWLEDGE MANAGEMENT IN THE ARTIFICIAL INTELLIGENCE ERA, 2022, 1549 : 97 - 109
  • [4] An Attribute-Based Collaborative Access Control Scheme Using Blockchain for IoT Devices
    Zhang, Yan
    Li, Bing
    Liu, Ben
    Wu, Jiaxin
    Wang, Yazhou
    Yang, Xia
    ELECTRONICS, 2020, 9 (02)
  • [5] An Attribute-Based Distributed Access Control for Blockchain-enabled IoT
    Wang, Peng
    Yue, Yanlin
    Sun, Wen
    Liu, Jiajia
    2019 INTERNATIONAL CONFERENCE ON WIRELESS AND MOBILE COMPUTING, NETWORKING AND COMMUNICATIONS (WIMOB), 2019,
  • [6] An Attribute-Based Access Control for IoT Using Blockchain and Smart Contracts
    Zaidi, Syed Yawar Abbas
    Shah, Munam Ali
    Khattak, Hasan Ali
    Maple, Carsten
    Rauf, Hafiz Tayyab
    El-Sherbeeny, Ahmed M.
    El-Meligy, Mohammed A.
    SUSTAINABILITY, 2021, 13 (19)
  • [7] A Novel Attribute-Based Access Control Scheme Using Blockchain for IoT
    Ding, Sheng
    Cao, Jin
    Li, Chen
    Fan, Kai
    Li, Hui
    IEEE ACCESS, 2019, 7 : 38431 - 38441
  • [8] Attribute-based Access Control Model in Healthcare Systems with Blockchain Technology
    Arora, Prince
    Bhagat, Avinash
    Kumar, Mukesh
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2023, 14 (05) : 793 - 803
  • [9] A Permissioned Blockchain based Access Control System for IOT
    Islam, M. D. Azharul
    Madria, Sanjay K.
    2019 IEEE INTERNATIONAL CONFERENCE ON BLOCKCHAIN (BLOCKCHAIN 2019), 2019, : 469 - 476
  • [10] Towards Supporting Attribute-Based Access Control in Hyperledger Fabric Blockchain
    Pericherla, Amshumaan
    Paul, Proteet
    Sural, Shamik
    Vaidya, Jaideep
    Atluri, Vijay
    ICT SYSTEMS SECURITY AND PRIVACY PROTECTION (SEC 2022), 2022, 648 : 360 - 376