期刊文献+

基于区块链和用户信用度的访问控制模型 被引量:14

Access control model based on blockchain and user credit
下载PDF
导出
摘要 针对当前访问控制中用户权限不能随着时间动态变化和访问控制合约中存在的安全性问题,提出了一种以基于角色的访问控制(RBAC)模型为基础,同时基于区块链和用户信用度的访问控制模型。首先,角色发布组织分发角色给相关用户,并把访问控制策略通过智能合约的方式存储在区块链中,该合约设定了访问信用度阈值,合约信息对系统内任何服务提供组织都是可验证、可追溯且不可篡改的。其次,该模型根据用户的当前信用度、历史信用度和推荐信用度评估出最终信用度,并根据最终信用度获得对应角色的访问权限。最后,当用户信用度达到合约设定的信用度阈值时,用户就可以访问相应的服务组织。实验结果表明,该模型在安全访问控制上具有一定的细粒度、动态性和安全性。 Focusing on the problem that user privileges cannot dynamically change with time in the current access control and the security problems in the access control contract,an access control model based on Role-Based Access Control(RBAC)model,blockchain and user credit was proposed.Firstly,the roles were distributed to relevant users by the role publishing organization,and the access control strategy was stored in the blockchain through smart contract method.In the contract,the access credit threshold was set,and the contract information was verifiable,traceable and tamper-proof to any service provider organization in the system.Secondly,the final credit was evaluated by the model according to current credit,historical credit and recommended credit of the user,and the access privileges of the corresponding role was obtained based on the final credit.Finally,when the user credit reached the credit threshold set in the contract,the user can access the corresponding service organization.Experimental results show that the proposed model has certain fine granularity,dynamicity and security in the security access control.
作者 王海勇 潘启青 郭凯璇 WANG Haiyong;PAN Qiqing;GUO Kaixuan(School of Computer Science,Nanjing University of Posts and Telecommunications,Nanjing Jiangsu 210003,China;School of Internet of Things,Nanjing University of Posts and Telecommunications,Nanjing Jiangsu 210003,China)
出处 《计算机应用》 CSCD 北大核心 2020年第6期1674-1679,共6页 journal of Computer Applications
基金 江苏省教育信息化研究资助重点课题(20172105) 江苏省现代教育技术研究2017年度智慧校园专项课题(2017-R-59518) 南京邮电大学教学改革重点项目(JG06717JX66) 南京邮电大学校园信息化创新项目(NYXX217002,NYXX217004) 赛尔网络下一代互联网技术创新项目(NGII20180620)。
关键词 区块链 智能合约 基于角色的访问控制模型 访问控制 用户信用度 blockchain smart contract Role-Based Access Control(RBAC)model access control user credit
  • 相关文献

参考文献6

二级参考文献49

共引文献464

同被引文献129

引证文献14

二级引证文献46

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部