Efficient and revocable attribute-based access control for industrial Internet of Things
Online published: 2025-07-18
Supported by
The National Natural Science Foundation of China (No.62472337, No.62372350, No.62125205)
Copyright
Attribute-based access control, as a key technology to guarantee the compliant use of industrial data, can effectively manage users’ rights to access sensitive data. For the security risks in cloud data management, attribute-based encryption schemes of ciphertext policy effectively address the dual needs of data protection and access control. However, the existing schemes have two limitations: 1) low policy expressiveness and high computational burden; 2) insufficient forward security in user right revocation. Therefore, an efficient and revocable attribute-based access control scheme for industrial Internet of Things was proposed. First, an attribute-based encryption supporting non-monotonic policy constraints and attribute reuse was adopted to improve logical expressiveness, and the offline encryption and outsourced decryption techniques were fused to offload the computational overhead of the client. Second, a two-layer key revocation mechanism was designed to guarantee the forward security through the cooperative control of attribute- and data-layer keys. Finally, the proposed scheme was evaluated and the results showed that it effectively reduced the computational overhead of the client.
XIAO Hao , XU Zihui , JIANG Qi , MA Xindi , YANG Li , YU Zengwen . Efficient and revocable attribute-based access control for industrial Internet of Things[J]. Journal of Cybersecurity, 2025 , 3(2) : 84 -95 . DOI: 10.20172/j.issn.2097-3136.250208
表 1 功能对比Table 1 Function comparison |
| 方案 | 属性重用 | 非单调策略 | 离线加密 | 外包解密 | 快速解密 |
| FAME | ✕ | ✕ | ✕ | ✕ | ✓ |
| ABGW | ✓ | ✕ | ✕ | ✕ | ✕ |
| FABEO | ✓ | ✕ | ✕ | ✕ | ✓ |
| 本方案 | ✓ | ✓ | ✓ | ✓ | ✓ |
表 2 计算开销对比Table 2 Computation cost comparison |
| 方案 | 密钥生成 | 加密 | 解密 |
| FAME | |||
| ABGW | |||
| FABEO | |||
| 本方案 |
表 3 通信开销对比Table 3 Communication cost comparison |
| 方案 | 密钥尺寸 | 密文尺寸 |
| FAME | ||
| ABGW | ||
| FABEO | ||
| 本方案 |
| 1 |
SUN D, HU J, WU H, et al. A comprehensive survey on collaborative data-access enablers in the IIoT[J]. ACM Computing Surveys, 2023, 56 (2): 1- 37.
|
| 2 |
MISHRA N, ISLAM S K H, ZEADALLY S. A survey on security and cryptographic perspective of Industrial-Internet-of-Things[J]. Internet of Things, 2024, 25, 101037.
|
| 3 |
刘奇旭, 靳泽, 陈灿华, 等. 物联网访问控制安全性综述[J]. 计算机研究与发展, 2022, 59 (10): 2190- 2211.
LIU Q X, JIN Z, CHEN C H, et al. Survey on Internet of Things access control security[J]. Journal of Computer Research and Development, 2022, 59 (10): 2190- 2211.
|
| 4 |
房梁, 殷丽华, 郭云川, 等. 基于属性的访问控制关键技术研究综述[J]. 计算机学报, 2017, 40 (7): 1680- 1698.
FANG L, YIN L H, GUO Y C, et al. A survey of key technologies in attribute-based access control scheme[J]. Chinese Journal of Computers, 2017, 40 (7): 1680- 1698.
|
| 5 |
BETHENCOURT J,SAHAI A,WATERS B. Ciphertext-policy attribute-based encryption[C]//2007 IEEE symposium on security and privacy (SP’07). IEEE,2007:321-334.
|
| 6 |
GOYAL V,PANDEY O,SAHAI A,et al. Attribute-based encryption for fine-grained access control of encrypted data[C]//Proceedings of the 13th ACM conference on Computer and communications security. New York:Association for Computing Machinery,2006:89-98.
|
| 7 |
AGHILI S F, SEDAGHAT M, SINGELéE D, et al. MLS-ABAC: Efficient multi-level security attribute-based access control scheme[J]. Future Generation Computer Systems, 2022, 131, 75- 90.
|
| 8 |
ZHU Y, YU R, MA D, et al. Cryptographic attribute-based access control (ABAC) for secure decision making of dynamic policy with multiauthority attribute tokens[J]. IEEE Transactions on Reliability, 2019, 68 (4): 1330- 1346.
|
| 9 |
王生玉, 汪金苗, 董清风, 等. 基于属性加密技术研究综述[J]. 信息网络安全, 2019, 19 (9): 76- 80.
WANG S Y, WANG J M, DONG Q F, et al. A survey of attribute-based encryption technology[J]. Netinfo Security, 2019, 19 (9): 76- 80.
|
| 10 |
RASORI M, LA MANNA M, PERAZZO P, et al. A survey on attribute-based encryption schemes suitable for the internet of things[J]. IEEE Internet of Things Journal, 2022, 9 (11): 8269- 8290.
|
| 11 |
ZHANG Y, DENG R H, XU S, et al. Attribute-based encryption for cloud computing access control: A survey[J]. ACM Computing Surveys (CSUR), 2020, 53 (4): 1- 41.
|
| 12 |
李莉, 朱江文, 杨春艳. 基于属性加密的可撤销机制研究综述[J]. 信息网络安全, 2023, 23 (4): 39- 50.
LI L, ZHU J W, YANG C Y. Overview of research on the revocable mechanism of attribute-based encryption[J]. Netinfo Security, 2023, 23 (4): 39- 50.
|
| 13 |
GARRISON W C,SHULL A,MYERS S,et al. On the practicality of cryptographically enforcing dynamic access control policies in the cloud[C]//2016 IEEE Symposium on Security and Privacy (SP). IEEE,2016:819-838.
|
| 14 |
QI S, ZHENG Y. Crypt-DAC: Cryptographically enforced dynamic access control in the cloud[J]. IEEE Transactions on Dependable and Secure Computing, 2021, 18 (2): 765- 779.
|
| 15 |
MIAO Y, TONG Q, CHOO K K R, et al. Secure online/offline data sharing framework for cloud-assisted industrial Internet of Things[J]. IEEE Internet of Things Journal, 2019, 6 (5): 8681- 8691.
|
| 16 |
LI T, ZHANG J, SHEN Y, et al. Hierarchical and multi-group data sharing for cloud-assisted industrial internet of things[J]. IEEE Transactions on Services Computing, 2023, 16 (5): 3425- 3438.
|
| 17 |
LI Q, ZHANG Q, HUANG H, et al. Secure, efficient, and weighted access control for cloud-assisted industrial IoT[J]. IEEE Internet of Things Journal, 2022, 9 (18): 16917- 16927.
|
| 18 |
RANI S, SRIVASTAVA G. Secure hierarchical fog computing-based architecture for industry 5.0 using an attribute-based encryption scheme[J]. Expert Systems with Applications, 2024, 235, 121180.
|
| 19 |
杜瑞忠, 闫沛文, 刘妍. 雾计算中细粒度属性更新的外包计算访问控制方案[J]. 通信学报, 2021, 42 (3): 160- 170.
DU R Z, YAN P W, LIU Y. Fine-grained attribute update and outsourcing computing access control scheme in fog computing[J]. Journal on Communications, 2021, 42 (3): 160- 170.
|
| 20 |
HOHENBERGER S,WATERS B. Online/offline attribute-based encryption[C]//17th International Conference on Practice and Theory in Public-Key Cryptography. Berlin, Heidelberg:Springer,2014:293-310.
|
| 21 |
GREEN M,HOHENBERGER S,WATERS B. Outsourcing the decryption of ABE ciphertexts[C]//20th USENIX Security Symposium. Berkeley:USENIX Association,2011:34.
|
| 22 |
MA R, ZHANG L, WU Q, et al. BE-TRDSS: Blockchain-enabled secure and efficient traceable-revocable data-sharing scheme in industrial internet of things[J]. IEEE Transactions on Industrial Informatics, 2023, 19 (11): 10821- 10830.
|
| 23 |
WANG Z, FU Y. A unified attribute-based encryption data sharing scheme matching industrial internet framework[J]. IEEE Internet of Things Journal, 2023, 11 (5): 9153- 9170.
|
| 24 |
TIAN T, SHEN Y, GAO H, et al. Attribute-based heterogeneous data privacy sharing in blockchain-assisted industrial IoT[J]. IEEE Internet of Things Journal, 2024, 2 (8): 10404- 10419.
|
| 25 |
张伟航,钟永彦,向元柱,等. 边云辅助下的可撤销属性加密方案[OL]. [2025-03-05]. http://www.ecice06.com/CN/10.19678/j.issn.1000-3428.0069341.
ZHANG W H ,ZHONG Y Y ,XIANG Y Z,et al. Reversible attribute encryption scheme assisted by edge and cloud[OL]. [2025-03-05]. http://www.ecice06.com/CN/10.19678/j.issn.1000-3428.0069341.
|
| 26 |
MYERS,STEVEN,ADAM S. Practical revocation and key rotation[C]//Cryptology–CT-RSA 2018. Springer International Publishing,2018:157-178.
|
| 27 |
RASO E,BRACCIALE L,LORETI P,et al. ABEBox:A data driven access control for securing public cloud storage with efficient key revocation[C]//Proceedings of the 16th International Conference on Availability,Reliability and Security. New York:Association for Computing Machinery,2021:1-7.
|
| 28 |
TOMIDA J, KAWAHARA Y, NISHIMAKI R. Fast, compact, and expressive attribute-based encryption[J]. Designs, Codes and Cryptography, 2021, 89, 2577- 2626.
|
| 29 |
BONEH D,LEWI K,MONTGOMERY H,et al. Key homomorphic PRFs and their applications[C]//Annual Cryptology Conference. Berlin,Heidelberg:Springer,2013:410-428.
|
| 30 |
WATERS B. Ciphertext-policy attribute-based encryption:An expressive,efficient,and provably secure realization[C]//International Workshop on Public Key Cryptography. Berlin,Heidelberg:Springer,2011,6571:53-70.
|
| 31 |
BEIMEL A. Secure schemes for secret sharing and key distribution[D]. Israel:Israel Institute of Technology,1996.
|
| 32 |
KOWALCZYK L, WEE H. Compact adaptively secure ABE for NC 1 from k-Lin[J]. Journal of Cryptology, 2020, 33 (3): 954- 1002.
|
| 33 |
Agrawal S, Chase M. FAME: Fast attribute-based message encryption[C]//Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security. New York: Association for Computing Machinery, 2017: 665-682.
|
| 34 |
Ambrona M, Barthe G, Gay R, et al. Attribute-based encryption in the generic group model: Automated proofs and new constructions[C]//Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security. New York: Association for Computing Machinery, 2017: 647-664.
|
| 35 |
Riepel D, Wee H. FABEO: Fast attribute-based encryption with optimal security[C]//Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security. New York: Association for Computing Machinery, 2022: 2491-2504.
|
| 36 |
LADD W,VERMA T,VENEMA M,et al. Portunus:Re-imagining access control in distributed systems[C]//2023 USENIX Annual Technical Conference. Berkeley:USENIX Association,2023:35-52.
|
/
| 〈 |
|
〉 |