• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2015, Vol. 37 ›› Issue (07): 1265-1271.

• 论文 • 上一篇    下一篇

改进的物联网感知层访问控制策略

蔡婷1,陈昌志1,欧阳凯2,周敬利2   

  1. (1.重庆邮电大学移通学院计算机系,重庆 401520;2.华中科技大学计算机学院,湖北 武汉 430074)
  • 收稿日期:2014-10-17 修回日期:2014-11-26 出版日期:2015-07-25 发布日期:2015-07-25
  • 基金资助:

    重庆市本科高校“三特行动计划”特色专业建设项目(渝教高(2013)49号);重庆市教委科学技术研究项目(KJ1402002)

An improved access control strategy for perceptual layer of IoT  

CAI Ting1,CHEN Changzhi1,OUYANG Kai2,ZHOU Jingli2   

  1. (1.Department of Computer,College of Mobile Telecommunications,
    Chongqing University of Posts and Telecommunications,Chongqing 401520;
    2.College of Computer,Huazhong University of Science and Technology,Wuhan 430074,China)
  • Received:2014-10-17 Revised:2014-11-26 Online:2015-07-25 Published:2015-07-25

摘要:

针对当前物联网感知层中海量终端节点访问控制策略可适应性以及运行效率的不足,提出一种高效的访问控制策略。一方面,该策略采用基于属性的访问控制 (ABAC)机制,规范了ABAC形式化定义,给出了物联网感知层下的访问控制策略框架,实现了更加细粒度的授权;另一方面,该策略采用了一种改进的密文策略基于属性加密 (CPABE) 算法,引入了析取范式结构,用DNF树替代传统CPABE算法中AND/OR访问树结构,有效地简化了计算,提高了系统运行效率。通过实验分析,该策略相比传统的访问控制方法减少了系统的时间开销,在物联网环境下更具适应性和优越性。

关键词: 物联网, 感知层, ABAC, 访问控制, CPABE, 策略

Abstract:

Due to the massive terminal nodes in the Internet of Things (IoT),the traditional access control strategies confront challenges in improving adaptability and efficiency.Therefore,we present an efficient access control strategy.Based on ABAC mechanism,we formalize the formal definition of ABAC,and design an access control frame for the perceptual layer of IoT,which achieves a more fine-grained authorization.Moreover,we introduce a disjunctive normal form structure by using an improved CP-ABE algorithm to replace the access tree structure in the traditional CPABE algorithm, which effectively simplifies the calculation and improves the efficiency of the system.Evaluation experiments demonstrate that the proposed access control strategy reduces the time cost of the system, and has better adaptability and superiority in the IoT environment than the traditional strategies.

Key words: Internet of Things (IoT);perceptual layer;ABAC;access control;CPABE;strategy