EDDAC: An Efficient and Decentralized Data Access Control Scheme With Attribute Privacy Preservation

EDDAC: An Efficient and Decentralized Data Access Control Scheme With Attribute Privacy Preservation
复制标题

DOI:
10.1109/jiot.2023.3342314
复制
发表时间:
2024-04
影响因子:
10.6
通讯作者:
Lanyan Wang;Wenxiu Ding;Zheng Yan;Su Qiu;Mingjun Wang;Zhiguo Wan
Lanyan Wang;Wenxiu Ding;Zheng Yan;Su Qiu;Mingjun Wang;Zhiguo Wan
中科院分区:
计算机科学1区
文献类型:
--
作者:
Lanyan Wang;Wenxiu Ding;Zheng Yan;Su Qiu;Mingjun Wang;Zhiguo Wan

文献摘要

相似文献

物联网(IoT)的快速发展导致了来自IoT设备的大量数据的产生和感知。这些数据被外包到云端,以实现灵活的共享和深入的分析,这可以显著增强物联网应用。但这引发了物联网设备的隐私问题。采用基于属性的加密技术实现细粒度的访问控制,为数据所有者提供对外包数据的控制能力。然而,集中式基础设施容易受到单点故障问题的影响,并且由于高延迟而可能不适合高度分布式的物联网应用程序。为了克服这个问题,引入区块链技术来实现分布式基础设施并提供强大的数据服务。由于区块链固有的透明特性,与隐私相关的挑战被放大了。因此,本文提出了一种有效的和分散的数据访问控制(EDDAC)方案,保护属性隐私。该方案利用变色龙散列实现属性隐藏,提供抵抗字典攻击。此外,它还包括基于区块链的解密测试,通过应用内积谓词加密来减少客户端的解密开销。此外,我们的方案采用Shamir秘密共享来实现基于区块链的去中心化授权,从而减少了授权节点上的信任建立开销。最后,我们提供的自适应安全性证明所提出的计划,并证明其有效性和优势,通过模拟和与现有文献的比较。
The rapid development of the Internet of Things (IoT) has led to the generation and perception of large amounts of data from IoT devices. These data are outsourced to the cloud for flexible sharing and deep analytics, which can significantly enhance IoT applications. But this raises privacy concerns for IoT devices. Attribute-based encryption is applied to realize fine-grained access control, which offers data owners control capability over their outsourced data. However, the centralized infrastructure is susceptible to the single-point-of-failure problem and may not be suitable for highly distributed IoT applications due to high latency. To overcome this issue, blockchain technology is introduced to realize a distributed infrastructure and provide robust data services. Owing to the innate transparency characteristic of blockchain, challenges associated with privacy are amplified. Therefore, this article presents an efficient and decentralized data access control (EDDAC) scheme that preserves attribute privacy. The scheme utilizes chameleon hash to implement attribute hiding, providing resistance against dictionary attacks. Additionally, it includes blockchain-based decryption tests that reduce the decryption overhead on clients through the application of inner product predicate encryption. Furthermore, our scheme employs Shamir secret sharing to achieve decentralized authorization based on blockchain, thereby reducing the trust-building overhead on authorization nodes. Finally, we provide proof of the adaptive security of the proposed scheme and demonstrate its effectiveness and advantages through simulations and comparisons with existing literature.