Sensors, Vol. 21, Pages 5053: Combining IOTA and Attribute-Based Encryption for Access Control in the Internet of Things

Sensors, Vol. 21, Pages 5053: Combining IOTA and Attribute-Based Encryption for Access Control in the Internet of Things Sensors doi: 10.3390/s21155053 Authors: Yuanyu Zhang Ruka Nakanishi Masahiro Sasabe Shoji Kasahara Unauthorized resource access represents a typical security threat in the Internet of things (IoT), while distributed ledger technologies (e.g., blockchain and IOTA) hold great promise to address this threat. Although blockchain-based IoT access control schemes have been the most popular ones, they suffer from several significant limitations, such as high monetary cost and low throughput of processing access requests. To overcome these limitations, this paper proposes a novel IoT access control scheme by combining the fee-less IOTA technology and the Ciphertext-Policy Attribute-Based Encryption (CP-ABE) technology. To control the access to a resource, a token, which records access permissions to this resource, is encrypted by the CP-ABE technology and uploaded to the IOTA Tangle (i.e., the underlying database of IOTA). Any user can fetch the encrypted token from the Tangle, while only those who can decrypt this token are authorized to access the resource. In this way, the proposed scheme enables not only distributed, fee-less and scalable access control thanks to the IOTA but also fine-grained attribute-based access control thanks to the CP-ABE. We show the feasibility of our scheme by implementing a proof-of-concept prototype system using smart p...
Source: Sensors - Category: Biotechnology Authors: Tags: Article Source Type: research