4.7 Article

DKSM: A Decentralized Kerberos Secure Service-Management Protocol for Internet of Things

Journal

INTERNET OF THINGS
Volume 23, Issue -, Pages -

Publisher

ELSEVIER
DOI: 10.1016/j.iot.2023.100871

Keywords

Internet of Things; Kerberos; Blockchain; Service security

Ask authors/readers for more resources

In this paper, a Decentralized Kerberos Secure Service-Management Protocol (DKSM) based on blockchain technology and Ciphertext-policy Attribute-based Encryption (CP-ABE) schema is proposed. Compared with existing protocols, DKSM fulfills decentralization, fine-grained access control with effective cost, and scalability simultaneously. The security of DKSM is also discussed and the protocol's efficiency and cost-effectiveness are demonstrated through tests on the Ethereum testnet and FISCO consortium platform.
Kerberos is a widely used authentication protocol that protects distributed services on the Internet of Things (IoT) and big data. In a distributed scenario, entities must prove their identity to a trusted third party using shared secrets, such as secret keys. Traditional schemes typically use a trusted central organization, like a Key Distribution Center, for identity authentication. However, Kerberos has some downsides, such as a single point of failure, vulnerability to replay attacks, and potential credential exposure, which can compromise system security. To address these problems, researchers have been working on various solutions, but most have their own drawbacks. In this paper, we propose a Decentralized Kerberos Secure Service-Management Protocol (DKSM) based on blockchain technology and Ciphertext-policy Attribute-based Encryption (CP-ABE) schema. Compared with existing protocols, DKSM fulfills decentralization, fine-grained access control with effective cost, and scalability simultaneously. DKSM uses AES and Fast Attribute-Based Encryption with Optimal Security (FABEO) as its cryptographic basis. We also discuss the security of DKSM and demonstrate how our protocol can defend against attacks. Finally, tests on the Ethereum testnet and FISCO consortium platform have shown that our designed protocol is efficient and cost-effective.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

4.7
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available