Distributed Access Control with Blockchain

01/11/2019
by   Jordi Paillisse, et al.
0

The specification and enforcement of network-wide policies in a single administrative domain is common in today's networks and considered as already resolved. However, this is not the case for multi-administrative domains, e.g. among different enterprises. In such situation, new problems arise that challenge classical solutions such as PKIs, which suffer from scalability and granularity concerns. In this paper, we present an extension to Group-Based Policy -- a widely used network policy language -- for the aforementioned scenario. To do so, we take advantage of a permissioned blockchain implementation (Hyperledger Fabric) to distribute access control policies in a secure and auditable manner, preserving at the same time the independence of each organization. Network administrators specify polices that are rendered into blockchain transactions. A LISP control plane (RFC 6830) allows routers performing the access control to query the blockchain for authorizations. We have implemented an end-to-end experimental prototype and evaluated it in terms of scalability and network latency.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
05/31/2018

Blockchain for Access Control in e-Health Scenarios

Access control is a crucial part of a system's security, restricting wha...
research
05/02/2022

A Secure File Sharing System Based on IPFS and Blockchain

There is a great interest in many approaches towards blockchain in provi...
research
01/28/2019

Physical Access Control Management System Based on Permissioned Blockchain

Using blockchain as a decentralized backend infrastructure has grabbed t...
research
10/10/2018

Blockchain access control Ecosystem for Big Data security

In recent years, the advancement in modern technologies has experienced ...
research
10/04/2021

Controlling Resource Allocation using Blockchain-Based Delegation

Allocation of resources and their control over multiple organisations is...
research
07/17/2019

Effcient logging and querying for Blockchain-based cross-site genomic dataset access audit

Background: Genomic data have been collected by different institutions a...
research
06/22/2023

XACML Extension for Graphs: Flexible Authorization Policy Specification and Datastore-independent Enforcement

The increasing use of graph-structured data for business- and privacy-cr...

Please sign up or login with your details

Forgot password? Click here to reset