Javascript must be enabled to continue!
Towards Decentralized IoT Access Control Scheme with Gateway-Level Cache and Blockchain-Based Trust Infrastructure
View through CrossRef
Abstract
The deployment of Internet of Things (IoT) systems in multiple administrative domains brings high demands on access control mechanisms that are scalable, auditable and interoperable. Existing centralized solutions cannot support cross-domain flexibility, while blockchain-based access control schemes that run authorization logic on-chain are plagued with high transaction latency, low throughput, and high operational cost, ruling them out of the high frequency IoT access scenario. This paper presents DGAC-IoT, a decentralized and gateway-assisted access control framework, which unambiguously separates the trust management, policy evaluation and enforcement functionality among the edge and blockchain layers. Access decisions are made fine-grained off-chain at domain gateways incorporating attribute-based access control (ABAC) policies while a permissioned blockchain network using Hyperledger Fabric is used as a distributed trust anchor. Smart contracts (chain-code) are only used to register cryptographically signed authorization commitments, policy updates and revocation events. Gateways have a local authorization cache that is indexed on subject-object-policy tuples and is bounded by explicit validity intervals so that repeated access requests can be resolved without having to interact with the blockchain. The communication is secure and cannot be denied (rejected) using public key infrastructure (PKI), digital signatures, and cryptographic hash functions. The framework is carried out with the use of containerized gateway services orchestrated via Docker and Fabric peers that are deployed across multiple domains. Performance is tested under conditions of rising access request rates, different cache hit ratios and dynamic revocation situations. Results reveal that DGAC-IoT has significant gains for end-to-end access latency, maintains close to linear throughput with scaling of the request load, and limits the scale up of blockchain transactions to a small set of access events. Sensitivity analysis is further used to quantify the effect of the policy expiration time and revocation frequency, as the effect of adaptive cached management and policy management directly affects the system responsiveness and blockchain overhead. These results show that by ensuring that blockchain is only used for immutable authorization commitment and revocation while policy evaluation and enforcement are done off-chain at gateways, a scalable and deployable access control solution for cross-domain IoT environments with heterogeneous trust and performance requirements can be achieved.
Springer Science and Business Media LLC
Title: Towards Decentralized IoT Access Control Scheme with Gateway-Level Cache and Blockchain-Based Trust Infrastructure
Description:
Abstract
The deployment of Internet of Things (IoT) systems in multiple administrative domains brings high demands on access control mechanisms that are scalable, auditable and interoperable.
Existing centralized solutions cannot support cross-domain flexibility, while blockchain-based access control schemes that run authorization logic on-chain are plagued with high transaction latency, low throughput, and high operational cost, ruling them out of the high frequency IoT access scenario.
This paper presents DGAC-IoT, a decentralized and gateway-assisted access control framework, which unambiguously separates the trust management, policy evaluation and enforcement functionality among the edge and blockchain layers.
Access decisions are made fine-grained off-chain at domain gateways incorporating attribute-based access control (ABAC) policies while a permissioned blockchain network using Hyperledger Fabric is used as a distributed trust anchor.
Smart contracts (chain-code) are only used to register cryptographically signed authorization commitments, policy updates and revocation events.
Gateways have a local authorization cache that is indexed on subject-object-policy tuples and is bounded by explicit validity intervals so that repeated access requests can be resolved without having to interact with the blockchain.
The communication is secure and cannot be denied (rejected) using public key infrastructure (PKI), digital signatures, and cryptographic hash functions.
The framework is carried out with the use of containerized gateway services orchestrated via Docker and Fabric peers that are deployed across multiple domains.
Performance is tested under conditions of rising access request rates, different cache hit ratios and dynamic revocation situations.
Results reveal that DGAC-IoT has significant gains for end-to-end access latency, maintains close to linear throughput with scaling of the request load, and limits the scale up of blockchain transactions to a small set of access events.
Sensitivity analysis is further used to quantify the effect of the policy expiration time and revocation frequency, as the effect of adaptive cached management and policy management directly affects the system responsiveness and blockchain overhead.
These results show that by ensuring that blockchain is only used for immutable authorization commitment and revocation while policy evaluation and enforcement are done off-chain at gateways, a scalable and deployable access control solution for cross-domain IoT environments with heterogeneous trust and performance requirements can be achieved.
Related Results
Access mechanisms for massive Internet of Things in 5G and beyond networks
Access mechanisms for massive Internet of Things in 5G and beyond networks
(English) The Massive Internet of Things (MIoT) characterizes a communication scenario where a massive number of battery-operated devices perform infrequent, primarily uplink-orien...
Optimized content caching strategies for multi-access edge computing (MEC)-assisted future cellular networks
Optimized content caching strategies for multi-access edge computing (MEC)-assisted future cellular networks
(English) Handling the tsunami of multimedia content is a big challenge for heterogeneous cellular networks.
Serving large volumes of content from the central system to end-users,...
An Efficient Software-Managed Cache Based on Cell Broadband Engine Architecture
An Efficient Software-Managed Cache Based on Cell Broadband Engine Architecture
While the CBEA (Cell Broadband Engine Architecture) offers substantial computational power, its explicit multilevel memory hierarchy poses significant challenges to traditional pro...
Centaurs transitioning to JFCs: thermal and dynamical evolution
Centaurs transitioning to JFCs: thermal and dynamical evolution
<p>1- Context</p>
<p>Jupiter-family Comets are continuously replenished from their outer solar system reservoirs. Before they enter the in...
Potable Water Sources, Household Hygiene, and Sanitation Practices in Ikpoba Okha LGA, Edo State: Implications for Public Health and Sustainable Water Management
Omoregie, Andrew Edosa.1 Omoregie Abieyuwa Peace2 Okoro, Enyinnaya Okoro.3
1 College of Medi
Potable Water Sources, Household Hygiene, and Sanitation Practices in Ikpoba Okha LGA, Edo State: Implications for Public Health and Sustainable Water Management
Omoregie, Andrew Edosa.1 Omoregie Abieyuwa Peace2 Okoro, Enyinnaya Okoro.3
1 College of Medi
BACKGROUND
Access to potable drinking water and sufficient sanitation continues to be an urgent global concern, particularly in developing regions where con...
Investigating the influence of organizational factors on blockchain adoption
Investigating the influence of organizational factors on blockchain adoption
Purpose
Blockchain possesses the potential to disrupt and reshape a plethora of industries in the next decade. However, blockchain adoption rates in technology ...
A Hierarchical Cache Architecture-Oriented Cache Management Scheme for Information-Centric Networking
A Hierarchical Cache Architecture-Oriented Cache Management Scheme for Information-Centric Networking
Information-Centric Networking (ICN) typically utilizes DRAM (Dynamic Random Access Memory) to build in-network cache components due to its high data transfer rate and low latency....
Connectivity sharing for wireless mesh networks
Connectivity sharing for wireless mesh networks
Internet access is still unavailable to one-third of the world population due to the lack of infrastructure, high cost, and the digital divide. Many access-limited communities opt ...

