高级检索

    物联网中基于区块链与雾计算的轻量级访问控制机制

    A Lightweight Access Control Mechanism Based on Blockchain and Fog Computing for the Internet of Things

    • 摘要: 针对大规模物联网环境中终端资源受限、跨域信任分散和访问策略动态变化等问题,提出一种区块链与雾计算协同的轻量级访问控制机制。该机制采用“链上可信状态维护、雾侧实时授权计算、端侧轻量身份响应”的分层架构,将属性基加密中的密钥生成、策略匹配与加解密等高复杂度操作迁移至雾节点,终端仅执行物理不可克隆函数响应生成和SHA-256哈希计算。为实现细粒度授权与跨域可信访问,构建CP-ABE与KP-ABE 协同的混合授权框架,分别表达资源级访问策略和用户级资源权限;同时将设备身份哈希、策略状态和撤销事件写入Hyperledger Fabric联盟链,形成PUF物理唯一性与链上状态一致性结合的可信身份链。进一步设计短期跨域访问令牌和基于挑战哈希的外包解密验证方法,以支持跨域认证和轻量级结果校验。安全分析表明,该机制满足身份认证、会话建立、数据机密性、抗共谋、抗重放和跨域凭证不可伪造等安全目标。原型实验表明,在5个属性条件下,CP-ABE加密和解密时间分别约为13.3 ms和5.5 ms,数据访问路径延迟约为18 ms。结果表明,所提机制能够支持资源受限物联网场景下的细粒度、可审计和跨域访问控制。

       

      Abstract: To address resource constraints of terminal devices, distributed cross-domain trust, and dynamic access policies in large-scale Internet of things (IoT) environments, we propose a lightweight access control mechanism based on blockchain and fog computing. The mechanism adopts a layered architecture of on-chain trusted state maintenance, fog-side real-time authorization, and terminal-side lightweight identity response. High-complexity operations in attribute-based encryption (ABE), including key generation, policy matching, encryption, and decryption, are offloaded to fog nodes, while terminals only perform physical unclonable function (PUF) response generation and SHA-256 hashing. To support fine-grained and trusted cross-domain access, a hybrid authorization framework combining ciphertext-policy ABE (CP-ABE) and key-policy ABE (KP-ABE) is designed, where CP-ABE expresses resource-level access policies and KP-ABE supplements user-level resource permissions. Device identity hashes, policy states, and revocation events are recorded on a Hyperledger Fabric consortium blockchain, forming a trusted identity chain that combines PUF-based physical uniqueness with on-chain state consistency. In addition, a short-lived cross-domain access token and a challenge-hash-based verification method are introduced for cross-domain authentication and lightweight outsourced decryption verification. Security analysis shows that the mechanism satisfies identity authentication, session establishment, data confidentiality, collusion resistance, replay resistance, and unforgeability of cross-domain credentials. Prototype experiments show that, with five attributes, CP-ABE encryption and decryption take approximately 13.3 ms and 5.5 ms, respectively, and the data access path latency is approximately 18 ms. The results demonstrate that the proposed mechanism can support fine-grained, auditable, and cross-domain access control for resource-constrained IoT scenarios.

       

    /

    返回文章
    返回