DAcc:基于分布式账本的企业应用访问控制

Isaac M. Markus, Lei Xu, I. Subhod, N. Nayab
{"title":"DAcc:基于分布式账本的企业应用访问控制","authors":"Isaac M. Markus, Lei Xu, I. Subhod, N. Nayab","doi":"10.1109/BLOC.2019.8751479","DOIUrl":null,"url":null,"abstract":"Access control is one of the fundamental security mechanisms of IT systems. Most existing access control schemes rely on a centralized party to manage and enforce access control policies. As decentralized ledger technologies, especially permissioned networks, find more applicability beyond cryptocurrencies in enterprise solutions is expected that the security requirements will increase. Therefore, it is necessary to develop an access control system that works in a decentralized environment without compromising the unique features of a decentralized ledger. Decentralized ledger based access control schemes have been proposed but have limitations such as lack of capability to protect the access history and detect/tolerate malicious participants. In order to address these concerns, we propose a novel decentralized ledger based access control system that utilizes cryptography. The newly proposed system is flexible and works with various storage system. The proposed system also provides verifiability for end users to detect compromised nodes in the decentralized ledger and high level privacy. We implement the scheme using Hyperledger Fabric and give detailed information of the prototype, and also assess its performance to show that it is practical for real world applications.","PeriodicalId":314490,"journal":{"name":"2019 IEEE International Conference on Blockchain and Cryptocurrency (ICBC)","volume":"41 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-05-14","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"7","resultStr":"{\"title\":\"DAcc: Decentralized Ledger based Access Control for Enterprise Applications\",\"authors\":\"Isaac M. Markus, Lei Xu, I. Subhod, N. Nayab\",\"doi\":\"10.1109/BLOC.2019.8751479\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Access control is one of the fundamental security mechanisms of IT systems. Most existing access control schemes rely on a centralized party to manage and enforce access control policies. As decentralized ledger technologies, especially permissioned networks, find more applicability beyond cryptocurrencies in enterprise solutions is expected that the security requirements will increase. Therefore, it is necessary to develop an access control system that works in a decentralized environment without compromising the unique features of a decentralized ledger. Decentralized ledger based access control schemes have been proposed but have limitations such as lack of capability to protect the access history and detect/tolerate malicious participants. In order to address these concerns, we propose a novel decentralized ledger based access control system that utilizes cryptography. The newly proposed system is flexible and works with various storage system. The proposed system also provides verifiability for end users to detect compromised nodes in the decentralized ledger and high level privacy. We implement the scheme using Hyperledger Fabric and give detailed information of the prototype, and also assess its performance to show that it is practical for real world applications.\",\"PeriodicalId\":314490,\"journal\":{\"name\":\"2019 IEEE International Conference on Blockchain and Cryptocurrency (ICBC)\",\"volume\":\"41 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2019-05-14\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"7\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2019 IEEE International Conference on Blockchain and Cryptocurrency (ICBC)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/BLOC.2019.8751479\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 IEEE International Conference on Blockchain and Cryptocurrency (ICBC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/BLOC.2019.8751479","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 7

摘要

访问控制是IT系统的基本安全机制之一。大多数现有的访问控制方案依赖于集中的一方来管理和执行访问控制策略。随着去中心化分类账技术,特别是许可网络,在企业解决方案中发现加密货币之外的更多适用性,预计安全需求将会增加。因此,有必要开发一种在去中心化环境中工作的访问控制系统,而不会损害去中心化分类账的独特功能。已经提出了基于分布式账本的访问控制方案,但存在诸如缺乏保护访问历史和检测/容忍恶意参与者的能力等局限性。为了解决这些问题,我们提出了一种新的基于分散分类账的访问控制系统,该系统利用密码学。新提出的系统具有灵活性,可与各种存储系统兼容。该系统还为最终用户提供了可验证性,以检测分散分类账中的受损节点和高级隐私。我们使用Hyperledger Fabric实现了该方案,并给出了原型的详细信息,并对其性能进行了评估,以表明它对现实世界的应用是实用的。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
DAcc: Decentralized Ledger based Access Control for Enterprise Applications
Access control is one of the fundamental security mechanisms of IT systems. Most existing access control schemes rely on a centralized party to manage and enforce access control policies. As decentralized ledger technologies, especially permissioned networks, find more applicability beyond cryptocurrencies in enterprise solutions is expected that the security requirements will increase. Therefore, it is necessary to develop an access control system that works in a decentralized environment without compromising the unique features of a decentralized ledger. Decentralized ledger based access control schemes have been proposed but have limitations such as lack of capability to protect the access history and detect/tolerate malicious participants. In order to address these concerns, we propose a novel decentralized ledger based access control system that utilizes cryptography. The newly proposed system is flexible and works with various storage system. The proposed system also provides verifiability for end users to detect compromised nodes in the decentralized ledger and high level privacy. We implement the scheme using Hyperledger Fabric and give detailed information of the prototype, and also assess its performance to show that it is practical for real world applications.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信