计算机科学
访问控制
块链
基于角色的访问控制
计算机安全
数据共享
智能合约
方案(数学)
协议(科学)
数学
医学
数学分析
病理
替代医学
作者
Keke Gai,Yufeng She,Liehuang Zhu,Kim‐Kwang Raymond Choo,Zhiguo Wan
出处
期刊:ACM Transactions on Internet Technology
[Association for Computing Machinery]
日期:2022-07-18
卷期号:23 (3): 1-25
被引量:33
摘要
Multi-organization data sharing is becoming increasingly prevalent due to the interconnectivity of systems and the need for collaboration across organizations (e.g., exchange of data in a supply chain involving multiple upstream and downstream vendors). There are, however, data security concerns due to lack of trust between organizations that may be located in jurisdictions with varying security and privacy legislation and culture (also referred to as a zero trust environment). Hence, in such a zero trust setting, one should introduce strengthened, yet efficient, access control mechanisms to facilitate cross-organizational data access and exchange requests. Contemporary access control schemes generally focus on protecting a single objective rather than multiple parties, due to higher security costs. In this article, we propose a blockchain-based access control scheme, designed to facilitate lightweight data sharing among different organizations. Specifically, our approach utilizes the consortium blockchain to establish a trustworthy environment, in which a Role-Based Access Control (RBAC) model is then deployed using our proposed multi-signature protocol and smart contract methods. Evaluation of our proposed approach is performed on the HyperLedger Fabric consortium blockchain platform using both Caliper and BFT-SMaRT benchmarks, and the findings demonstrate the utility of our approach.
科研通智能强力驱动
Strongly Powered by AbleSci AI