论文标题

使用权限的区块链基于分布式属性的访问控制系统

Distributed Attribute-Based Access Control System Using a Permissioned Blockchain

论文作者

Rouhani, Sara, Belchior, Rafael, Cruz, Rui S., Deters, Ralph

论文摘要

通过跟踪所有访问尝试,包括合法和非法访问尝试,审计在计算机系统中提供了必不可少的安全控制。此阶段对于审核的上下文可能很有用,在该上下文中,最终可能会责任责任。区块链技术可以为访问控制系统提供可信赖的可审核性。在本文中,我们提出了一个基于区块链的分布式\ ac {abac}系统,以提供可信赖的访问尝试审核。除了审核性外,我们的系统还提出了透明度,访问请求者和资源所有者都可以从中受益。我们提出了一个基于HyperLeDger织物的实现的系统体系结构,可实现高效率和低计算开销。通过独立数字库的用例来验证所提出的解决方案。考虑到不同的共识机制和数据库,介绍了我们实施的详细绩效分析。实验评估表明,我们提出的系统可以处理5,000个访问控制请求,每秒的发送率为200,延迟为0.3秒。

Auditing provides an essential security control in computer systems, by keeping track of all access attempts, including both legitimate and illegal access attempts. This phase can be useful to the context of audits, where eventual misbehaving parties can be held accountable. Blockchain technology can provide trusted auditability required for access control systems. In this paper, we propose a distributed \ac{ABAC} system based on blockchain to provide trusted auditing of access attempts. Besides auditability, our system presents a level of transparency that both access requestors and resource owners can benefit from it. We present a system architecture with an implementation based on Hyperledger Fabric, achieving high efficiency and low computational overhead. The proposed solution is validated through a use case of independent digital libraries. Detailed performance analysis of our implementation is presented, taking into account different consensus mechanisms and databases. The experimental evaluation shows that our presented system can process 5,000 access control requests with the send rate of 200 per second and a latency of 0.3 seconds.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源