TY - JOUR
T1 - A CP-ABE and IOTA-Based Lightweight Sensitive Data Access Control Scheme for IoT
AU - Yao, Xuanxia
AU - Zhou, Jinyuan
AU - Du, Xiaojiang
AU - Zhang, Shurong
N1 - Publisher Copyright:
© 2014 IEEE.
PY - 2024
Y1 - 2024
N2 - Nowadays, we are living in an open network environment with varieties of smart devices, which makes individual privacy face unprecedented threats. For one thing, a plenty of sensitive information may be gathered without the owner's knowledge. For the other, the Internet of Things (IoT)-based services and various intelligent applications require a large amount of perceptual data. And in practice, these data are usually encrypted and stored in storage providers like cloud for security and cost saving. To fully harness the productivity value of data and protect privacy, ciphertext-policy attribute-based encryption (CP-ABE) is widely used. Nevertheless, most existing CP-ABE schemes cannot work well for IoT because of the heavy overhead and the open and distributed environment. To lower the cost, a lightweight CP-ABE scheme without pairing is proposed and proved in the set-selective mode. Both the theoretical analysis and experiments show its advantages in computation, communication, and storage overhead. For flexible access control in IoT, we attempt to employ the masked authenticated message (MAM) mechanism of the IOTA to manage authorization for our CP-ABE scheme. Comparisons with similar schemes show that it can overcome the low throughput and monetary cost in other distributed ledger-based access control schemes.
AB - Nowadays, we are living in an open network environment with varieties of smart devices, which makes individual privacy face unprecedented threats. For one thing, a plenty of sensitive information may be gathered without the owner's knowledge. For the other, the Internet of Things (IoT)-based services and various intelligent applications require a large amount of perceptual data. And in practice, these data are usually encrypted and stored in storage providers like cloud for security and cost saving. To fully harness the productivity value of data and protect privacy, ciphertext-policy attribute-based encryption (CP-ABE) is widely used. Nevertheless, most existing CP-ABE schemes cannot work well for IoT because of the heavy overhead and the open and distributed environment. To lower the cost, a lightweight CP-ABE scheme without pairing is proposed and proved in the set-selective mode. Both the theoretical analysis and experiments show its advantages in computation, communication, and storage overhead. For flexible access control in IoT, we attempt to employ the masked authenticated message (MAM) mechanism of the IOTA to manage authorization for our CP-ABE scheme. Comparisons with similar schemes show that it can overcome the low throughput and monetary cost in other distributed ledger-based access control schemes.
KW - Access control
KW - ciphertext-policy attribute-based encryption (CP-ABE)
KW - IOTA
KW - privacy preserving
UR - http://www.scopus.com/inward/record.url?scp=85203555384&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=85203555384&partnerID=8YFLogxK
U2 - 10.1109/JIOT.2024.3456553
DO - 10.1109/JIOT.2024.3456553
M3 - Article
AN - SCOPUS:85203555384
VL - 11
SP - 40831
EP - 40844
JO - IEEE Internet of Things Journal
JF - IEEE Internet of Things Journal
IS - 24
ER -