首页 | 本学科首页   官方微博 | 高级检索  
     

多域物联网中基于区块链和权能的访问控制机制
引用本文:王思源,邹仕洪. 多域物联网中基于区块链和权能的访问控制机制[J]. 应用科学学报, 2021, 39(1): 55-69. DOI: 10.3969/j.issn.0255-8297.2021.01.005
作者姓名:王思源  邹仕洪
作者单位:北京邮电大学 网络空间安全学院, 北京 100876
基金项目:国家重点研发计划基金(No.2018YFB0803602)资助
摘    要:物联网中的数据通常包含大量的隐私信息,为了防止设备协同过程中因越权访问造成隐私数据泄露的问题,针对多域物联网设备协同场景提出了一套访问控制机制.将分布式的基于权能的访问控制(capability-based access control,CapAC)与区块链技术相结合,设计了存储于区块链的权能令牌以及基于智能合约实现的...

关 键 词:区块链  访问控制  物联网  智能合约
收稿时间:2020-11-15

Blockchain and Capability Based Access Control Mechanism in Multi-domain IoT
WANG Siyuan,ZOU Shihong. Blockchain and Capability Based Access Control Mechanism in Multi-domain IoT[J]. Journal of Applied Sciences, 2021, 39(1): 55-69. DOI: 10.3969/j.issn.0255-8297.2021.01.005
Authors:WANG Siyuan  ZOU Shihong
Affiliation:School of Cyberspace Security, Beijing University of Posts and Telecommunications, Beijing 100876, China
Abstract:Data in Internet of things (IoT) usually contains a large amount of personal privacy information, In order to prevent privacy data leakage due to unauthorized access during device collaboration, this article proposes a set of access control mechanisms for multi-domain IoT device collaboration scenarios. By combining distributed capabilitybased access control (CapAC) with blockchain technology, this article designs a capability token stored in the blockchain and a token management contract based on smart contracts. According to CapACs access decision-making method, a blockchain-based token verification method is designed. The blockchain lightweight node is optimized for the characteristics of IoT. Finally, a blockchain system is built to implement the mechanism proposed in the article. Experimental test results show that compared to centralized access control mechanisms, this solution can safely and accurately execute access decisions in large-scale IoT scenarios and has more stable processing performance. Lightweight design can greatly reduce node storage burden.
Keywords:blockchain  access control  Internet of things (IoT)  smart contract  
本文献已被 CNKI 等数据库收录!
点击此处可从《应用科学学报》浏览原始摘要信息
点击此处可从《应用科学学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号