Publication | Open Access
AuthPrivacyChain: A Blockchain-Based Access Control Framework With Privacy Protection in Cloud
180
Citations
39
References
2020
Year
Blockchain PrivacyAuthentication AuthorizationPrivacy ProtectionEngineeringCloud SecurityIdentity ManagementInformation SecurityCloud ComputingAccess ControlData PrivacyBlockchain ProtocolCloud CryptographyDistributed LedgerCloud Computing SecurityBlockchainData SecurityCryptography
Cloud computing offers ubiquitous on-demand services, yet centralized access control leaves sensitive data vulnerable to tampering or leakage by hackers or internal managers. The study proposes AuthPrivacyChain, a blockchain‑based access control framework that protects privacy in cloud environments. AuthPrivacyChain uses blockchain node addresses as identities, encrypts and stores access permissions on the chain, and implements access control, authorization, and revocation processes. Implementation on EOS demonstrates that AuthPrivacyChain prevents unauthorized access by hackers and administrators while preserving authorized privacy.
Cloud is a computing model that provides sharing and supports ubiquitous on-demand access computing, providing new data processing and services for many industries, significantly reducing user computing and storage costs, and improving ease of use. With the development of cloud-scale and intensification, cloud security has become an essential issue in the field of cloud computing. Access control is one of the critical security technologies for protecting sensitive data stored in the cloud by enterprises and individuals. Since the centralized access control mechanism is adopted in the cloud, the sensitive data in the cloud are easy to be tampered with or leaked by hackers or cloud internal managers. To address this issue, we propose a blockchain-based access control framework with privacy protection called AuthPrivacyChain. Firstly, we use the account address of the node in blockchain as the identity, and at the same time, redefine the access control permission of data for the cloud, which is encrypted and stored in blockchain. After that, we design processes of access control, authorization, and authorization revocation in AuthPrivacyChain. Finally, we implement AuthPrivacyChain based on enterprise operation system (EOS), and the results show that AuthPrivacyChain can not only prevent hackers and administrators from illegally accessing resources, but also protect authorized privacy.
| Year | Citations | |
|---|---|---|
Page 1
Page 1