节点文献

基于区块链的工业控制系统角色委派访问控制机制

Blockchain-based Role-Delegation Access Control for Industrial Control System

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 郭显王雨悦冯涛曹来成蒋泳波张迪

【Author】 GUO Xian;WANG Yu-yue;FENG Tao;CAO Lai-cheng;JIANG Yong-bo;ZHANG Di;School of Computer and Communication,Lanzhou University of Technology;

【通讯作者】 郭显;

【机构】 兰州理工大学计算机与通信学院

【摘要】 IT和OT的融合模糊了工业控制系统"网络边界"的概念,细粒度的访问控制策略是保障工业企业网络安全的基石。基于角色委派的访问控制机制可把域中用户对网络资源的访问权限委派给其他域的用户或企业合作伙伴,这样为企业员工或企业合作伙伴远程访问企业网络资源提供了便利。然而,这种便利可能增加工业控制系统的攻击面。区块链技术固有的去中心化、防篡改、可审计等特征可以成为基于角色委派访问控制管理的基础架构,因而提出了基于区块链技术的角色委派访问控制方案(Delegatable Role-Based Access Control, DRBAC)。DRBAC包括用户角色管理及委派、访问控制、监控机制等几个重要组件,并基于智能合约实现该方案,DRBAC的目的是保证每个网络连接必须受到细粒度访问控制策略的保护。最后,通过搭建本地私有区块链网络测试分析了DRBAC的正确性、可行性和开销。

【Abstract】 The concept of “network perimeter” in industrial control system is becoming vague due to the integration of IT and OT technology.The fine-grained access control strategy that intends to protect each network connection can ensure the network security of industrial control system.The role-delegation-based access control scheme can delegate an access right of user in a domain to a user in another domain or a company partner so that these users can remotely access the network resources of the industrial enterprise.However, these benefits resulted from the delegation may increase the attack surface for industrial control system.The blockchain technology with decentralization, tamper-proof, auditable and other characteristics can be considered as a basic framework of the role-delegation access control for network resources in industrial control system.This paper proposes a role-delegation access control scheme DRBAC based on blockchain.DRBAC includes several important components: user role management and delegation, access control, monitoring mechanism, etc.The DRBAC solution is implemented based on smart contract.The DRBAC ensures that each network connection must be protected by fine-grained access control strategies.Finally, the correctness, feasibility and overhead of DRBAC are tested and analyzed in a private blockchain network.

【基金】 国家自然科学基金(61461027);甘肃省自然科学基金(20JR5RA467)~~
  • 【文献出处】 计算机科学 ,Computer Science , 编辑部邮箱 ,2021年09期
  • 【分类号】TP393.08;TP273
  • 【被引频次】3
  • 【下载频次】521
节点文献中: 

本文链接的文献网络图示:

本文的引文网络