电子科技 ›› 2019, Vol. 32 ›› Issue (9): 55-59.doi: 10.16180/j.cnki.issn1007-7820.2019.09.012

• • 上一篇    下一篇

基于属性的物联网感知层访问控制方案

刘琛,马驷俊,倪雪莉   

  1. 江苏警官学院 计算机信息与网络安全系,江苏 南京 210031
  • 收稿日期:2018-09-28 出版日期:2019-09-15 发布日期:2019-09-19
  • 作者简介:刘琛(1990-),男,博士,讲师。研究方向:物联网技术与应用。
  • 基金资助:
    江苏省高等学校自然科学研究面上项目(18KJD140002);江苏警官学院高层次人才引进项目(JSPI17GKZL201);江苏警官学院科研创新团队(2018SJYTD15);江苏警官学院院级项目(2017SJYZY01);江苏警官学院院级项目(2017SJYZY02);江苏警官学院院级项目(2017SJYZC05)

Attribute-Based Access Control for the Perception Layer of The Internet of Things

LIU Chen,MA Sijun,NI Xueli   

  1. Department of Computer Information and Cyber Security,Jiangsu Police Institute,Nanjing 210031,China
  • Received:2018-09-28 Online:2019-09-15 Published:2019-09-19
  • Supported by:
    Natural Science Foundation of the Jiangsu Higher Education Institutions of China(18KJD140002);High-level Introduction of Talent Scientific Research Start-up Fund of Jiangsu Police Institute(JSPI17GKZL201);Research and Innovation Team of Jiangsu Police Institute(2018SJYTD15);Research Project of Jiangsu Police Institute(2017SJYZY01);Research Project of Jiangsu Police Institute(2017SJYZY02);Research Project of Jiangsu Police Institute(2017SJYZC05)

摘要:

物联网感知层包含大量环境数据与个人信息。因此,对这些数据的访问做出严格界定对于物联网信息安全与隐私保护至关重要。文中在传统访问控制模型的基础上,引入属性概念,提出了一种基于属性的访问控制方案。在这一方案中,通过对用户的主体属性、被访问资源的客体属性、访问请求的权限属性以及该请求发生时的环境属性进行判定,决定是否给与主体访问权限。基于属性的访问控制方案具有灵活性强、控制相对简单、拓展性强等特点,能够满足动态的大规模环境,有利于解决物联网感知层访问控制问题。

关键词: 物联网, 感知层, 访问控制, 基于属性, 信息安全, 隐私保护

Abstract:

The perception layer of the IOT contained large sum of environmental data and personal information. Therefore, a strict definition of data access was of great importance for information security and privacy protection of the IOT. Based on the traditional access control model, the concept of attribute was introduced and a proposal of attribute-based access control was proposed. In this proposal, the principal access authority was determined according to the attribute of subject, object, the permission and the environment. The attributed-based access control was superior for its characteristics of strong flexibility, relatively simple control and strong expansibility. It was suitable to the dynamic and large-scale environment and was conducive to solving the problems of access control for the perception layer of the IOT.

Key words: the Internet of things, perception layer, access control, attribute-based, information security, privacy protection

中图分类号: 

  • TP393