{"title":"Bloccess: Towards Fine-Grained Access Control Using Blockchain in a Distributed Untrustworthy Environment","authors":"Yepeng Ding, Hiroyuki Sato","doi":"10.1109/MobileCloud48802.2020.00011","DOIUrl":null,"url":null,"abstract":"Access control plays a crucial role in constructing trust in a system. Particularly, it is imperative to enforce a fine-grained access control mechanism to make the access control framework flexible due to the high complexity of untrustworthy environments such as the Internet of Things (IoT) environments. However, traditional access control techniques can be hardly trusted on account of their centralized enforcements and improper distributed computing mechanisms while facing diverse and intricate threats. Although existing solutions based on public blockchain technology have addressed some issues, new challenges derived from public blockchain technology become noticeable such as low consensus efficiency and delicate incentive mechanism. In this paper, we propose Bloccess, a fine-grained access control framework using permissioned blockchain techniques, which enhances the trust in untrustworthy environments by enforcing a trustworthy access control mechanism. Bloccess provides a unified and user-centric solution for access control in distributed untrustworthy environments and optimizes the decentralized access control management, which significantly ensures the security properties of protected environments in terms of the threat model structured in this paper. We also prove the feasibility and effectiveness of Bloccess by security analysis and the comparison with some related frameworks.","PeriodicalId":241174,"journal":{"name":"2020 8th IEEE International Conference on Mobile Cloud Computing, Services, and Engineering (MobileCloud)","volume":"321 ","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-08-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"9","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 8th IEEE International Conference on Mobile Cloud Computing, Services, and Engineering (MobileCloud)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/MobileCloud48802.2020.00011","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 9
Abstract
Access control plays a crucial role in constructing trust in a system. Particularly, it is imperative to enforce a fine-grained access control mechanism to make the access control framework flexible due to the high complexity of untrustworthy environments such as the Internet of Things (IoT) environments. However, traditional access control techniques can be hardly trusted on account of their centralized enforcements and improper distributed computing mechanisms while facing diverse and intricate threats. Although existing solutions based on public blockchain technology have addressed some issues, new challenges derived from public blockchain technology become noticeable such as low consensus efficiency and delicate incentive mechanism. In this paper, we propose Bloccess, a fine-grained access control framework using permissioned blockchain techniques, which enhances the trust in untrustworthy environments by enforcing a trustworthy access control mechanism. Bloccess provides a unified and user-centric solution for access control in distributed untrustworthy environments and optimizes the decentralized access control management, which significantly ensures the security properties of protected environments in terms of the threat model structured in this paper. We also prove the feasibility and effectiveness of Bloccess by security analysis and the comparison with some related frameworks.