Organization-Wide Distributed Access Control for Zero Trust Security Based on a Consortium Blockchain
摘要
The traditional network security model relies on boundary trust, assuming that internal networks are secure while external networks are not secure, which is inadequate in the modern dynamic network environment. To address the limitations of traditional access control mechanisms in dynamic network environments, we combine role-based access control (RBAC) and relationship-based access control (ReBAC) mechanisms and propose a hybrid access control mechanism that relies on consortium blockchains to construct a zero-trust network environment. Leveraging the decentralized nature of the consortium blockchain and the automated execution of smart contracts, our design ensures the security and privacy of cross-organizational resource access. By integrating the ECDH key exchange protocol and Paillier homomorphic encryption technology, it reinforces the encrypted transmission of cross-organizational collaboration information and privacy protection for user resource access. We conduct experiments on the Hyperledger Fabric platform, and our scheme achieves high transaction processing efficiency in both intraorganizational and cross-organizational access control scenarios. Through theoretical analysis and experimental validation, the proposed access control mechanism can effectively resist common network threats such as Sybil attacks, man-in-the-middle attacks, and replay attacks and offers significant advantages in enhancing the granularity, dynamism, and scalability of resource access control in zero-trust environments.