A Verifiable and Flexible Data Sharing mechanism for Information-Centric IoT

A Verifiable and Flexible Data Sharing mechanism for Information-Centric IoT
复制标题

DOI:
10.1109/icc.2017.7996804
复制
发表时间:
2017-05
期刊:
2017 IEEE International Conference on Communications (ICC)
影响因子:
--
通讯作者:
Ruidong Li;H. Asaeda;Jie Li;Xiaoming Fu
Ruidong Li;H. Asaeda;Jie Li;Xiaoming Fu
中科院分区:
其他
文献类型:
--
作者:
Ruidong Li;H. Asaeda;Jie Li;Xiaoming Fu

文献摘要

被引文献

相似文献

在用于大数据共享的以信息为中心的物联网(ICIoT)环境中,物联网数据可以在整个网络中缓存。这种分布式数据缓存对灵活的授权和身份验证提出了挑战。对于细粒度的分布式数据访问授权,基于属性的密文策略加密(CP-ABE)已被确定为一个有前途的方法。然而,在现有的基于CP-ABE的方案中,每个发布者将需要从集中式服务器检索属性以用于加密数据,从而导致高通信开销。此外,有效授权期和分布式认证仍然没有解决和无缝地结合。在本文中,我们提出了一个可验证的和灵活的数据共享(VFDS)的ICIoT机制,它利用CP-ABE授权和基于身份的签名(IBS)的身份的分布式验证。在VFDS中,发布者从附近的缓存持有者检索属性。此外,属性清单(AM)和自动属性更新(AAU)实现高效的属性更新内的分布式缓存,以实现有效的授权期限。同时,VFDS提供了IBS在本地域的公共参数,这使得有效的身份验证。我们的系统评估表明,VFDS可以实现较低的带宽成本相比,现有的方案的认证和灵活的授权。
In an Information-Centric Internet of Things (ICIoT) environment for big data sharing, IoT data can be cached throughout the network. Such distributed data caching poses a challenge on flexible authorization and identity verification. For fine-grained data access authorization in a distributed manner, Ciphertext-Policy Attribute-Based Encryption (CP-ABE) has been identified as a promising approach. However in the existing CP-ABE based scheme, each publisher would need to retrieve the attributes from the centralized server for encrypting data, resulting in high communication overhead. Moreover, valid authorization period and distributed authentication are still not addressed and seamlessly incorporated. In this paper, we propose a Verifiable and Flexible Data Sharing (VFDS) mechanism for ICIoT, which exploits CP-ABE for authorization and Identity-Based Signature (IBS) for the distributed verification of the identities. In VFDS, publishers retrieve the attributes from the nearby cache holders. In addition, the Attribute Manifest (AM) and the Automatic Attribute Update (AAU) realize efficient attribute updates within the distributed caches to achieve valid authorization period. Meanwhile, VFDS provides the public parameters of IBS in local domain, which enables the efficient identity verifications. Our system evaluations show that the VFDS can achieve lower bandwidth cost compared to the existing schemes for both authentication and flexible authorization.