• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

基于发布/订阅中间件实现物联网服务的策略隐私。

Realizing IoT service's policy privacy over publish/subscribe-based middleware.

作者信息

Duan Li, Zhang Yang, Chen Shiping, Wang Shiyao, Cheng Bo, Chen Junliang

机构信息

State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications, Beijing, 100876 China ; Data61, CSIRO, Marsfield, NSW 2122 Australia.

State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications, Beijing, 100876 China.

出版信息

Springerplus. 2016 Sep 20;5(1):1615. doi: 10.1186/s40064-016-3250-x. eCollection 2016.

DOI:10.1186/s40064-016-3250-x
PMID:27652188
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC5028380/
Abstract

The publish/subscribe paradigm makes IoT service collaborations more scalable and flexible, due to the space, time and control decoupling of event producers and consumers. Thus, the paradigm can be used to establish large-scale IoT service communication infrastructures such as Supervisory Control and Data Acquisition systems. However, preserving IoT service's policy privacy is difficult in this paradigm, because a classical publisher has little control of its own event after being published; and a subscriber has to accept all the events from the subscribed event type with no choice. Few existing publish/subscribe middleware have built-in mechanisms to address the above issues. In this paper, we present a novel access control framework, which is capable of preserving IoT service's policy privacy. In particular, we adopt the publish/subscribe paradigm as the IoT service communication infrastructure to facilitate the protection of IoT services policy privacy. The key idea in our policy-privacy solution is using a two-layer cooperating method to match bi-directional privacy control requirements: (a) data layer for protecting IoT events; and (b) application layer for preserving the privacy of service policy. Furthermore, the anonymous-set-based principle is adopted to realize the functionalities of the framework, including policy embedding and policy encoding as well as policy matching. Our security analysis shows that the policy privacy framework is Chosen-Plaintext Attack secure. We extend the open source Apache ActiveMQ broker by building into a policy-based authorization mechanism to enforce the privacy policy. The performance evaluation results indicate that our approach is scalable with reasonable overheads.

摘要

发布/订阅范式使物联网服务协作更具可扩展性和灵活性,这得益于事件生产者和消费者在空间、时间及控制方面的解耦。因此,该范式可用于建立大规模的物联网服务通信基础设施,如监控与数据采集系统。然而,在这种范式下保护物联网服务的策略隐私很困难,因为传统发布者在发布自身事件后对其几乎没有控制权;而订阅者必须毫无选择地接受来自所订阅事件类型的所有事件。现有的发布/订阅中间件很少有内置机制来解决上述问题。在本文中,我们提出了一种新颖的访问控制框架,它能够保护物联网服务的策略隐私。具体而言,我们采用发布/订阅范式作为物联网服务通信基础设施,以促进对物联网服务策略隐私的保护。我们的策略隐私解决方案的关键思想是使用一种两层协作方法来匹配双向隐私控制要求:(a)数据层用于保护物联网事件;(b)应用层用于保护服务策略的隐私。此外,采用基于匿名集的原则来实现框架的功能,包括策略嵌入、策略编码以及策略匹配。我们的安全分析表明,该策略隐私框架在选择明文攻击下是安全的。我们通过在开源的Apache ActiveMQ代理中构建基于策略的授权机制来实施隐私策略,对其进行了扩展。性能评估结果表明,我们的方法具有可扩展性且开销合理。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ebc1/5028380/1334afaa999c/40064_2016_3250_Fig12_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ebc1/5028380/9afdb15c59c6/40064_2016_3250_Fig1_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ebc1/5028380/a1ed7b441189/40064_2016_3250_Fig2_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ebc1/5028380/863887011035/40064_2016_3250_Fig3_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ebc1/5028380/d3a4bd47d61c/40064_2016_3250_Fig4_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ebc1/5028380/3314a6acd211/40064_2016_3250_Fig5_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ebc1/5028380/4cc547cdcd41/40064_2016_3250_Fig6_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ebc1/5028380/ecf27a4f075e/40064_2016_3250_Fig7_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ebc1/5028380/fb268dc097b2/40064_2016_3250_Fig8_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ebc1/5028380/00b2fcafb27c/40064_2016_3250_Fig9_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ebc1/5028380/599e41ea198e/40064_2016_3250_Fig10_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ebc1/5028380/f06389e46975/40064_2016_3250_Fig11_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ebc1/5028380/1334afaa999c/40064_2016_3250_Fig12_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ebc1/5028380/9afdb15c59c6/40064_2016_3250_Fig1_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ebc1/5028380/a1ed7b441189/40064_2016_3250_Fig2_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ebc1/5028380/863887011035/40064_2016_3250_Fig3_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ebc1/5028380/d3a4bd47d61c/40064_2016_3250_Fig4_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ebc1/5028380/3314a6acd211/40064_2016_3250_Fig5_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ebc1/5028380/4cc547cdcd41/40064_2016_3250_Fig6_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ebc1/5028380/ecf27a4f075e/40064_2016_3250_Fig7_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ebc1/5028380/fb268dc097b2/40064_2016_3250_Fig8_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ebc1/5028380/00b2fcafb27c/40064_2016_3250_Fig9_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ebc1/5028380/599e41ea198e/40064_2016_3250_Fig10_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ebc1/5028380/f06389e46975/40064_2016_3250_Fig11_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ebc1/5028380/1334afaa999c/40064_2016_3250_Fig12_HTML.jpg

相似文献

1
Realizing IoT service's policy privacy over publish/subscribe-based middleware.基于发布/订阅中间件实现物联网服务的策略隐私。
Springerplus. 2016 Sep 20;5(1):1615. doi: 10.1186/s40064-016-3250-x. eCollection 2016.
2
Evaluation of an IoT Application-Scoped Access Control Model over a Publish/Subscribe Architecture Based on FIWARE.基于 FIWARE 的物联网应用范围访问控制模型在发布/订阅架构上的评估。
Sensors (Basel). 2020 Aug 4;20(15):4341. doi: 10.3390/s20154341.
3
Using Machine Learning to Provide Reliable Differentiated Services for IoT in SDN-Like Publish/Subscribe Middleware.使用机器学习为 SDN 式发布/订阅中间件中的物联网提供可靠的差异化服务。
Sensors (Basel). 2019 Mar 25;19(6):1449. doi: 10.3390/s19061449.
4
Performance evaluation of publish-subscribe systems in IoT using energy-efficient and context-aware secure messages.使用节能且情境感知的安全消息对物联网中的发布-订阅系统进行性能评估。
J Cloud Comput (Heidelb). 2022;11(1):6. doi: 10.1186/s13677-022-00278-6. Epub 2022 Jan 31.
5
Enabling Large-Scale IoT-Based Services through Elastic Publish/Subscribe.通过弹性发布/订阅实现基于物联网的大规模服务。
Sensors (Basel). 2017 Sep 19;17(9):2148. doi: 10.3390/s17092148.
6
Secret Forwarding of Events over Distributed Publish/Subscribe Overlay Network.分布式发布/订阅覆盖网络上事件的秘密转发
PLoS One. 2016 Jul 1;11(7):e0158516. doi: 10.1371/journal.pone.0158516. eCollection 2016.
7
MQT-TZ: Secure MQTT Broker for Biomedical Signal Processing on the Edge.MQT-TZ:用于边缘生物医学信号处理的安全MQTT代理服务器。
Stud Health Technol Inform. 2020 Jun 16;270:332-336. doi: 10.3233/SHTI200177.
8
Efficient Solution for Large-Scale IoT Applications with Proactive Edge-Cloud Publish/Subscribe Brokers Clustering.基于主动式边缘云发布/订阅代理集群的大规模物联网应用高效解决方案。
Sensors (Basel). 2021 Dec 9;21(24):8232. doi: 10.3390/s21248232.
9
Do CHANGE platform: A service-based architecture for secure aggregation and distribution of health and wellbeing data.Do CHANGE 平台:一种用于安全聚合和分发健康和幸福数据的基于服务的架构。
Int J Med Inform. 2018 Sep;117:103-111. doi: 10.1016/j.ijmedinf.2018.06.004. Epub 2018 Jun 18.
10
MultiFuzz: A Coverage-Based Multiparty-Protocol Fuzzer for IoT Publish/Subscribe Protocols.MultiFuzz:一种用于物联网发布/订阅协议的基于覆盖的多方协议模糊测试器。
Sensors (Basel). 2020 Sep 11;20(18):5194. doi: 10.3390/s20185194.