###
Journal of Software:2019.30(9):2636-2654

基于区块链的大数据访问控制机制
刘敖迪,杜学绘,王娜,李少卓
(信息工程大学, 河南 郑州 450001;河南省信息安全重点实验室, 河南 郑州 450001)
Blockchain-based Access Control Mechanism for Big Data
LIU Ao-Di,DU Xue-Hui,WANG Na,LI Shao-Zhuo
(Information Engineering University, Zhengzhou 450001, China;Henan Provincial Key Laboratory of Information Security, Zhengzhou 450001, China)
Abstract
Chart / table
Reference
Similar Articles
Article :Browse 973   Download 762
Received:June 09, 2018    Revised:August 28, 2018
> 中文摘要: 针对大数据资源来源广泛、动态性强且呈现出分布式管理的特点,当前主流集中式访问控制机制存在权限管理效率低、灵活性不足、扩展性差等不足.基于此,以ABAC模型为基础,提出一种基于区块链的大数据访问控制机制:首先,对区块链技术的基本原理进行描述,并对基于属性的访问控制模型进行形式化的定义;然后提出基于区块链技术的大数据访问控制架构,并对访问控制的基本框架与流程进行了详细的阐述与分析;同时,对基于区块链事务的访问控制策略及实体属性信息管理方法进行了说明,以此保证访问控制信息的不可篡改性、可审计性和可验证性;随后,采用基于智能合约的访问控制方法实现对大数据资源由用户驱动、全程透明、动态、自动化的访问控制;最后,通过仿真实验验证了该机制的有效性,并对该研究内容进行总结与展望.
Abstract:In terms of the wide source, large dynamics, and distributed management characteristics of big data resources, the current mainstream centralized access control mechanisms have shortcomings, such as low efficiency, insufficient flexibility, and poor scalability. Therefore, this study proposes a blockchain-based big data access control mechanism based on the ABAC model. First, in this paper, the fundamental principle of blockchain technology is described and the attribute-based access control model is formalized. Then, big data access control architecture is presented based on blockchain technology, and the basic framework and flow of access control are analyzed. At the same time, to ensure the access control information is tamper-resistant, auditability, and verifiability, the transaction-based access control policy and entity attribute information management methods are also described in detail. In addition, a smart contract-based access control method is used to implement user-driven, transparent, dynamic, and automated access control for big data resources. Finally, simulation experiments validate the effectiveness of this mechanism, and then the views presented in this paper are summarized and prospected.
文章编号:     中图分类号:    文献标志码:
基金项目:国家重点研发计划(2018YFB0803603,2016YFB0501901);国家自然科学基金(61802436);河南省自然科学基金(162300410334) 国家重点研发计划(2018YFB0803603,2016YFB0501901);国家自然科学基金(61802436);河南省自然科学基金(162300410334)
Foundation items:National Key Research and Development Program of China (2018YFB0803603, 2016YFB0501901); National Natural Science Foundation of China (61802436); Natural Science Foundation of He'nan Province of China (162300410334)
Reference text:

刘敖迪,杜学绘,王娜,李少卓.基于区块链的大数据访问控制机制.软件学报,2019,30(9):2636-2654

LIU Ao-Di,DU Xue-Hui,WANG Na,LI Shao-Zhuo.Blockchain-based Access Control Mechanism for Big Data.Journal of Software,2019,30(9):2636-2654