<p>Access control is a significant technique to ensure data security in the Internet of Things (IoT). To overcome the challenges posed by uncontrollable access policies in existing cloud-based access control schemes, blockchain-based access control schemes have emerged. However, most of these schemes still face challenges such as huge resource consumption and privacy leakage, which would not be suitable for large-scale IoT applications. In this paper, we propose a scalable and privacy-preserving access control scheme, named AccessChain, which combines blockchain, edge computing, and IPFS to guarantee secure and trustworthy access control while making it more applicable for resource-constrained devices in IoT. Considering privacy threats of attributes and access policies caused by the transparency of blockchain, we propose an attribute and policy hiding encryption (PP-ABE) to protect device privacy. By using smart contracts with the process, we can heighten the level of self-government. Finally, our theoretical analysis and experimental results demonstrate that our AccessChain is effective and can be applied to large-scale IoT applications.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

AccessChain: A scalable and privacy-preserving access control scheme for blockchain-based IoT

  • Guirong Piao,
  • Jianming Zhu

摘要

Access control is a significant technique to ensure data security in the Internet of Things (IoT). To overcome the challenges posed by uncontrollable access policies in existing cloud-based access control schemes, blockchain-based access control schemes have emerged. However, most of these schemes still face challenges such as huge resource consumption and privacy leakage, which would not be suitable for large-scale IoT applications. In this paper, we propose a scalable and privacy-preserving access control scheme, named AccessChain, which combines blockchain, edge computing, and IPFS to guarantee secure and trustworthy access control while making it more applicable for resource-constrained devices in IoT. Considering privacy threats of attributes and access policies caused by the transparency of blockchain, we propose an attribute and policy hiding encryption (PP-ABE) to protect device privacy. By using smart contracts with the process, we can heighten the level of self-government. Finally, our theoretical analysis and experimental results demonstrate that our AccessChain is effective and can be applied to large-scale IoT applications.