Computers · 2018 · 173 citations · 28 references
Authentication AuthorizationEngineeringInformation SecurityIot CommunicationIot ProtocolIot SecurityTraditional Access ControlAuthorizationLogical Access ControlAccess Control ListsAccess ControlIot ChallengeSystems EngineeringInternet Of ThingsNetworked Computer SystemsData PrivacyComputer ScienceData SecurityTechnologyBlockchainAuthentication Access ControlAuthorization Policies
IoT is central to Smart Cities but raises privacy and security concerns, especially in access control, where traditional ACL, RBAC, and ABAC approaches lack scalability and centralized servers create bottlenecks. This work introduces BlendCAC, a decentralized, federated capability‑based access control mechanism for large‑scale IoT systems. BlendCAC employs a federated capability‑based delegation model that supports hierarchical, multi‑hop delegation, and uses smart‑contract‑managed identity‑based capability tokens for registration, propagation, and revocation. A proof‑of‑concept prototype running on Raspberry Pi and laptop nodes over a private blockchain demonstrates BlendCAC’s feasibility as a decentralized, scalable, lightweight, and fine‑grained AC solution.
While Internet of Things (IoT) technology has been widely recognized as an essential part of Smart Cities, it also brings new challenges in terms of privacy and security. Access control (AC) is among the top security concerns, which is critical in resource and information protection over IoT devices. Traditional access control approaches, like Access Control Lists (ACL), Role-based Access Control (RBAC) and Attribute-based Access Control (ABAC), are not able to provide a scalable, manageable and efficient mechanism to meet the requirements of IoT systems. Another weakness in today’s AC is the centralized authorization server, which can cause a performance bottleneck or be the single point of failure. Inspired by the smart contract on top of a blockchain protocol, this paper proposes BlendCAC, which is a decentralized, federated capability-based AC mechanism to enable effective protection for devices, services and information in large-scale IoT systems. A federated capability-based delegation model (FCDM) is introduced to support hierarchical and multi-hop delegation. The mechanism for delegate authorization and revocation is explored. A robust identity-based capability token management strategy is proposed, which takes advantage of the smart contract for registration, propagation, and revocation of the access authorization. A proof-of-concept prototype has been implemented on both resources-constrained devices (i.e., Raspberry PI nodes) and more powerful computing devices (i.e., laptops) and tested on a local private blockchain network. The experimental results demonstrate the feasibility of the BlendCAC to offer a decentralized, scalable, lightweight and fine-grained AC solution for IoT systems.
28
Bitcoin: A Peer-to-Peer Electronic Cash System
Spongebob Squarepants · SSRN Electronic Journal · 2008 · 11.2K citations · Full text
Role-based access control models
Ravi Sandhu, Edward J. Coyne, H.L. Feinstein et al. · Computer · 1996 · 5.8K citations
Formalizing and Securing Relationships on Public Networks
Nick Szabo · First Monday · 1997 · 2K citations · Full text