论文标题

分散应用程序基于动态角色的访问控制

Dynamic Role-Based Access Control for Decentralized Applications

论文作者

Chatterjee, Arnab, Pitroda, Yash, Parmar, Manojkumar

论文摘要

访问控制管理是维护应用程序安全性的组成部分。尽管在云访问控制机制领域已经进行了重要的工作,但是,随着分布式分类帐技术(DLT)的出现,几乎不存在链上访问控制管理框架。现有的访问控制管理机制与业务逻辑紧密相结合,导致治理问题,与现有身份管理解决方案,低安全性和可用性损害相关。我们提出了一个新颖的框架,以实现分散应用程序(DAPP)的基于动态角色的访问控制。该框架允许在DAPP上管理访问控制,该访问控制与业务应用程序完全分离,并与任何DAPP无缝集成。智能合同体系结构允许独立管理业务逻辑和访问控制策略的执行。它还有助于安全,低成本和访问控制管理的高度灵活性。拟议的框架促进了访问控制政策和有效智能合同升级的分散治理。我们还为框架的功效和效率提供定量和定性指标。任何图灵完整的智能合同编程语言都是实施框架的绝佳合适性。我们希望该框架有益于企业和非企业Dapps,并提供更大的访问控制灵活性,并与传统和状态的最先进的身份管理解决方案有效整合。

Access control management is an integral part of maintaining the security of an application. Although there has been significant work in the field of cloud access control mechanisms, however, with the advent of Distributed Ledger Technology (DLT), on-chain access control management frameworks hardly exist. Existing access control management mechanisms are tightly coupled with the business logic, resulting in governance issues, non-coherent with existing Identity Management Solutions, low security, and compromised usability. We propose a novel framework to implement dynamic role-based access control for decentralized applications (dApps). The framework allows for managing access control on a dApp, which is completely decoupled from the business application and integrates seamlessly with any dApps. The smart contract architecture allows for the independent management of business logic and execution of access control policies. It also facilitates secure, low cost, and a high degree of flexibility of access control management. The proposed framework promotes decentralized governance of access control policies and efficient smart contract upgrades. We also provide quantitative and qualitative metrics for the efficacy and efficiency of the framework. Any Turing complete smart contract programming language is an excellent fit to implement the framework. We expect this framework to benefit enterprise and non-enterprise dApps and provide greater access control flexibility and effective integration with traditional and state of the art identity management solutions.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源