论文标题

Tokoin:物联网的基于硬币的负责访问控制计划

Tokoin: A Coin-Based Accountable Access Control Scheme for Internet of Things

论文作者

Liu, Chunchi, Xu, Minghui, Guo, Hechuan, Cheng, Xiuzhen, Xiao, Yinhao, Yu, Dongxiao, Gong, Bei, Yerukhimovich, Arkady, Wang, Shengling, Lv, Weifeng

论文摘要

随着物联网应用程序(IoT)应用程序的普遍性,IoT设备与周围环境紧密相互作用,从而使我们无与伦比的智慧和便利性。但是,安全的物联网解决方案的发展正在落后很长一段路,这使我们接触了常见的未经授权的访问,这可能会给我们的日常生活带来恶意攻击和前所未有的危险。众所周知,访问未经授权或过多资源的物联网中广泛报道的现象过度攻击是很难预防,追踪和减轻的。为了应对这一挑战,我们建议基于Tokoin的访问控制(TBAC),这是一个由区块链和受信任的执行环境(TEE)技术启用的负责任访问控制模型,以提供精致的详细信息,强大的可审核性和IoT的访问程序控制。 TBAC将虚拟访问权力实现为一个确定的宽松和安全的加密硬币,称为“ tokoin”(令牌+硬币),并使用区块链中的原子和负责任的状态转换功能来管理它。我们还通过要求每个Tokoin制定一个细粒度的访问策略来定义谁可以在何时何时完成操作,从而实现访问程序控制。 Tokoin是可以转移的点对点,并且只能在必要时由资源所有者修改。我们完全实施了TBAC,该TBAC具有良好的加密原始图和区块链平台,并为常规用户提供了一个随时可用的应用程序。我们还提出了一项案例研究,以证明如何使用TBAC来实现自主货物交付,同时通过调节交货员的身体行为来保证访问策略合规性和房主的身体安全。

With the prevalence of Internet of Things (IoT) applications, IoT devices interact closely with our surrounding environments, bringing us unparalleled smartness and convenience. However, the development of secure IoT solutions is getting a long way lagged behind, making us exposed to common unauthorized accesses that may bring malicious attacks and unprecedented danger to our daily life. Overprivilege attack, a widely reported phenomenon in IoT that accesses unauthorized or excessive resources, is notoriously hard to prevent, trace and mitigate. To tackle this challenge, we propose Tokoin-Based Access Control (TBAC), an accountable access control model enabled by blockchain and Trusted Execution Environment (TEE) technologies, to offer fine-graininess, strong auditability, and access procedure control for IoT. TBAC materializes the virtual access power into a definite-amount and secure cryptographic coin termed "tokoin" (token+coin), and manages it using atomic and accountable state-transition functions in a blockchain. We also realize access procedure control by mandating every tokoin a fine-grained access policy defining who is allowed to do what at when in where by how. The tokoin is peer-to-peer transferable, and can be modified only by the resource owner when necessary. We fully implement TBAC with well-studied cryptographic primitives and blockchain platforms and present a readily available APP for regular users. We also present a case study to demonstrate how TBAC is employed to enable autonomous in-home cargo delivery while guaranteeing the access policy compliance and home owner's physical security by regulating the physical behaviors of the deliveryman.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源