块链
加密
计算机科学
方案(数学)
计算机安全
GSM演进的增强数据速率
访问控制
物联网
互联网
分散系统
计算机网络
分布式计算
控制(管理)
万维网
电信
数学
人工智能
数学分析
作者
Hanlei Cheng,Sio‐Long Lo,Jing Lu
标识
DOI:10.1016/j.iot.2024.101220
摘要
More edge users opt to use Internet of Things (IoT) devices to collect their data (e.g., health data, social data, e-governance data, etc.), which are stored in central cloud service providers (CSPs). However, this results in a compromise of data privacy, while having issues with collusion attacks. Current ciphertext-policy attribute-based encryption (CP-ABE) schemes with and without blockchain have only partially addressed these issues. Ongoing challenges remain to be resolved, including large-universe attribute management, secret key verification, and malicious attribute authorities (AAs) tracking. Therefore, we propose a decentralized access control scheme (namely BLUMA-CPABE) integrating blockchain with multi-authority ciphertext-policy attribute-based encryption (MA-CP-ABE). The scheme not only supports large-universe, policy hiding, and AAs tracking, but it also utilizes on- and off-chain mechanisms to alleviate the computation burden of the blockchain. In addition, we develop a verifiable key distribution approach in which AAs are configured as blockchain consensus nodes capable of issuing, signing, validating, and disseminating secret keys as transactions on-chain, ensuring the keys' security and reliability. To incentivize authorities to control newly added attributes proactively for large-universe, we enhance the Proof-of-Authority (called PoA+) consensus mechanism in multi-authority scenarios. It allows authorities to take turns proposing and confirming new blocks based on three contribution indicators: attribute management contribution, data decryption contribution, and block validation gain. The proposed scheme is proven statically secure while resisting collusion attacks. The experimental results demonstrate the feasibility and efficiency of our scheme.
科研通智能强力驱动
Strongly Powered by AbleSci AI