• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

一种具有动态属性更新和策略隐藏功能的安全且可扩展的物联网访问控制框架。

A secure and scalable IoT access control framework with dynamic attribute updates and policy hiding.

作者信息

Xu Zhigang, Zhou Wan, Han Hongmu, Dong Xinhua, Zhang Shiguang, Hu Ziping

机构信息

School of Computer Science, Hubei University of Technology, 28 Nanli Road, Wuhan, 430068, China.

Jiangmen Industrial Technology Research Institute of Guangdong Academy of Sciences Ltd, 6 Chaolian Avenue, Guangdong, 529095, China.

出版信息

Sci Rep. 2025 Apr 7;15(1):11913. doi: 10.1038/s41598-024-80307-3.

DOI:10.1038/s41598-024-80307-3
PMID:40195353
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC11976958/
Abstract

With the rapid rise of Internet of Things (IoT) technology, cloud computing and attribute-based encryption (ABE) are often employed to safeguard the privacy and security of IoT data. However, most blockchain based access control methods are one-way, and user access policies are public, which cannot simultaneously meet the needs of dynamic attribute updates, two-way verification of users and data, and secure data transmission. To handle such challenges, we propose an attribute-based encryption scheme that satisfies real-time and secure sharing requirements through attribute updates and policy hiding. First, we designed a new dynamic update and policy hiding bidirectional attribute access control (DUPH-BAAC) scheme. In addition, a strategy hiding technique was adopted. The data owner sends encrypted addresses with hidden access policies to the blockchain network for verification through transactions. Then, the user locally matches attributes, the smart contract verifies user permissions, and generates access transactions for users who meet access policies. Moreover, the cloud server receives user identity keys and matches the user attribute set with the ciphertext attribute set. Besides, blockchain networks replace traditional IoT centralized servers for identity authentication, authorization, key management, and attribute updates, reducing information leakage risk. Finally, we demonstrate that the DUPH-BAAC scheme can resist indistinguishable choice access structures and selective plaintext attacks, achieving IND-sAS-CPA security.

摘要

随着物联网(IoT)技术的迅速崛起,云计算和基于属性的加密(ABE)常被用于保障物联网数据的隐私和安全。然而,大多数基于区块链的访问控制方法都是单向的,且用户访问策略是公开的,无法同时满足动态属性更新、用户与数据的双向验证以及安全数据传输的需求。为应对此类挑战,我们提出一种基于属性的加密方案,该方案通过属性更新和策略隐藏来满足实时且安全的共享需求。首先,我们设计了一种新的动态更新和策略隐藏双向属性访问控制(DUPH-BAAC)方案。此外,采用了一种策略隐藏技术。数据所有者将带有隐藏访问策略的加密地址发送到区块链网络,通过交易进行验证。然后,用户在本地匹配属性,智能合约验证用户权限,并为符合访问策略的用户生成访问交易。此外,云服务器接收用户身份密钥,并将用户属性集与密文属性集进行匹配。另外,区块链网络取代传统的物联网集中式服务器进行身份认证、授权、密钥管理和属性更新,降低信息泄露风险。最后,我们证明DUPH-BAAC方案能够抵御不可区分选择访问结构和选择性明文攻击,实现IND-sAS-CPA安全性。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1437/11976958/0d56b6e7472f/41598_2024_80307_Fig5_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1437/11976958/1d24943fdaed/41598_2024_80307_Fig1_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1437/11976958/8d927ed61121/41598_2024_80307_Fig2_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1437/11976958/d7db36b43039/41598_2024_80307_Fig3_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1437/11976958/7ad301cfc9ee/41598_2024_80307_Fig4_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1437/11976958/0d56b6e7472f/41598_2024_80307_Fig5_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1437/11976958/1d24943fdaed/41598_2024_80307_Fig1_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1437/11976958/8d927ed61121/41598_2024_80307_Fig2_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1437/11976958/d7db36b43039/41598_2024_80307_Fig3_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1437/11976958/7ad301cfc9ee/41598_2024_80307_Fig4_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1437/11976958/0d56b6e7472f/41598_2024_80307_Fig5_HTML.jpg

相似文献

1
A secure and scalable IoT access control framework with dynamic attribute updates and policy hiding.一种具有动态属性更新和策略隐藏功能的安全且可扩展的物联网访问控制框架。
Sci Rep. 2025 Apr 7;15(1):11913. doi: 10.1038/s41598-024-80307-3.
2
Blockchain-enabled data governance for privacy-preserved sharing of confidential data.支持区块链的数据治理,用于在保护隐私的前提下共享机密数据。
PeerJ Comput Sci. 2024 Dec 20;10:e2581. doi: 10.7717/peerj-cs.2581. eCollection 2024.
3
Towards Secure Internet of Things: A Coercion-Resistant Attribute-Based Encryption Scheme with Policy Revocation.迈向安全物联网:一种具有策略撤销功能的抗胁迫属性基加密方案。
Entropy (Basel). 2025 Jan 2;27(1):32. doi: 10.3390/e27010032.
4
Traceable ciphertext-policy attribute-based encryption scheme with attribute level user revocation for cloud storage.可追踪的密文策略属性基加密方案,支持属性级用户撤销,用于云存储。
PLoS One. 2018 Sep 13;13(9):e0203225. doi: 10.1371/journal.pone.0203225. eCollection 2018.
5
A Secured Proxy-Based Data Sharing Module in IoT Environments Using Blockchain.基于区块链的物联网环境中的安全代理数据共享模块。
Sensors (Basel). 2019 Mar 11;19(5):1235. doi: 10.3390/s19051235.
6
Blockchain-Based Data Access Control and Key Agreement System in IoT Environment.基于区块链的物联网环境中的数据访问控制和密钥协商系统。
Sensors (Basel). 2023 May 29;23(11):5173. doi: 10.3390/s23115173.
7
An Access Control Scheme Based on Blockchain and Ciphertext Policy-Attribute Based Encryption.一种基于区块链和基于密文策略属性加密的访问控制方案。
Sensors (Basel). 2023 Sep 23;23(19):8038. doi: 10.3390/s23198038.
8
Blockchain-Enhanced Anonymous Data Sharing Scheme for 6G-Enabled Smart Healthcare With Distributed Key Generation and Policy Hiding.基于分布式密钥生成和策略隐藏的面向6G智能医疗的区块链增强匿名数据共享方案
IEEE J Biomed Health Inform. 2025 Mar 19;PP. doi: 10.1109/JBHI.2025.3550261.
9
A Ring Learning with Errors-Based Ciphertext-Policy Attribute-Based Proxy Re-Encryption Scheme for Secure Big Data Sharing in Cloud Environment.基于错误的环学习密文策略属性基代理重加密方案,用于云环境中的安全大数据共享。
Big Data. 2024 Oct;12(5):357-366. doi: 10.1089/big.2021.0301. Epub 2022 Apr 11.
10
Blockchain-Based Access Control Scheme for Secure Shared Personal Health Records over Decentralised Storage.基于区块链的去中心化存储中安全共享个人健康记录的访问控制方案。
Sensors (Basel). 2021 Apr 2;21(7):2462. doi: 10.3390/s21072462.

本文引用的文献

1
Efficient and accountable anti-leakage attribute-based encryption scheme for cloud storage.用于云存储的高效且可问责的抗泄漏属性基加密方案。
Heliyon. 2024 Jun 7;10(12):e32404. doi: 10.1016/j.heliyon.2024.e32404. eCollection 2024 Jun 30.
2
A Secure and Verifiable Outsourced Access Control Scheme in Fog-Cloud Computing.一种雾计算-云计算环境下的安全可验证外包访问控制方案
Sensors (Basel). 2017 Jul 24;17(7):1695. doi: 10.3390/s17071695.