4.7 Article

DKSM: A Decentralized Kerberos Secure Service-Management Protocol for Internet of Things

期刊

INTERNET OF THINGS
卷 23, 期 -, 页码 -

出版社

ELSEVIER
DOI: 10.1016/j.iot.2023.100871

关键词

Internet of Things; Kerberos; Blockchain; Service security

向作者/读者索取更多资源

In this paper, a Decentralized Kerberos Secure Service-Management Protocol (DKSM) based on blockchain technology and Ciphertext-policy Attribute-based Encryption (CP-ABE) schema is proposed. Compared with existing protocols, DKSM fulfills decentralization, fine-grained access control with effective cost, and scalability simultaneously. The security of DKSM is also discussed and the protocol's efficiency and cost-effectiveness are demonstrated through tests on the Ethereum testnet and FISCO consortium platform.
Kerberos is a widely used authentication protocol that protects distributed services on the Internet of Things (IoT) and big data. In a distributed scenario, entities must prove their identity to a trusted third party using shared secrets, such as secret keys. Traditional schemes typically use a trusted central organization, like a Key Distribution Center, for identity authentication. However, Kerberos has some downsides, such as a single point of failure, vulnerability to replay attacks, and potential credential exposure, which can compromise system security. To address these problems, researchers have been working on various solutions, but most have their own drawbacks. In this paper, we propose a Decentralized Kerberos Secure Service-Management Protocol (DKSM) based on blockchain technology and Ciphertext-policy Attribute-based Encryption (CP-ABE) schema. Compared with existing protocols, DKSM fulfills decentralization, fine-grained access control with effective cost, and scalability simultaneously. DKSM uses AES and Fast Attribute-Based Encryption with Optimal Security (FABEO) as its cryptographic basis. We also discuss the security of DKSM and demonstrate how our protocol can defend against attacks. Finally, tests on the Ethereum testnet and FISCO consortium platform have shown that our designed protocol is efficient and cost-effective.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.7
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据