AccessChain: A scalable and privacy-preserving access control scheme for blockchain-based IoT
摘要
Access control is a significant technique to ensure data security in the Internet of Things (IoT). To overcome the challenges posed by uncontrollable access policies in existing cloud-based access control schemes, blockchain-based access control schemes have emerged. However, most of these schemes still face challenges such as huge resource consumption and privacy leakage, which would not be suitable for large-scale IoT applications. In this paper, we propose a scalable and privacy-preserving access control scheme, named AccessChain, which combines blockchain, edge computing, and IPFS to guarantee secure and trustworthy access control while making it more applicable for resource-constrained devices in IoT. Considering privacy threats of attributes and access policies caused by the transparency of blockchain, we propose an attribute and policy hiding encryption (PP-ABE) to protect device privacy. By using smart contracts with the process, we can heighten the level of self-government. Finally, our theoretical analysis and experimental results demonstrate that our AccessChain is effective and can be applied to large-scale IoT applications.