论文标题

使用可验证的凭据和零知识证明,对物联网数据共享的身份验证,授权和选择性披露

Authentication, Authorization, and Selective Disclosure for IoT data sharing using Verifiable Credentials and Zero-Knowledge Proofs

论文作者

Fotiou, Nikos, Pittaras, Iakovos, Chadoulos, Spiros, Siris, Vasilios A., Polyzos, George C., Ipiotis, Nikolaos, Keranidis, Stratos

论文摘要

随着物联网成为无所不在的大量数据,可用于构建创新应用。但是,互操作性问题和安全问题,防止收获这些数据的全部潜力。在本文中,我们考虑智能建筑物生成的数据的用例。通过整合通过感知和自动化来改善舒适性的物联网设备,建筑物变得“更聪明”。但是,这些设备及其数据通常在特定的应用程序或制造商中孤立,即使它们对于提供不同类型的“顶级”服务(例如能源管理)的各种类型的利益相关者可能很有价值。大多数数据共享技术都遵循“全部或全无”的方法,从而在部分揭示,隐私保护的数据子集可能会推动创新的应用程序中,从而造成了重大的安全性和隐私威胁。考虑到这些,我们开发了一个平台,该平台能够对数据项进行受控,隐私共享。我们的系统在两个方向上进行了创新:首先,它提供了一个框架,可以在不违反其完整性的情况下发现和选择性披露物联网数据。其次,它提供了一种用户友好,直观的机制,可以对共享数据有效,细粒度的访问控制。我们的解决方案利用了自我主张身份,可验证的凭据和零知识证明领域的最新进展,并将它们集成到结合行业标准授权框架OAuth 2.0和事物规范的平台中。

As IoT becomes omnipresent vast amounts of data are generated, which can be used for building innovative applications. However,interoperability issues and security concerns, prevent harvesting the full potentials of these data. In this paper we consider the use case of data generated by smart buildings. Buildings are becoming ever "smarter" by integrating IoT devices that improve comfort through sensing and automation. However, these devices and their data are usually siloed in specific applications or manufacturers, even though they can be valuable for various interested stakeholders who provide different types of "over the top" services, e.g., energy management. Most data sharing techniques follow an "all or nothing" approach, creating significant security and privacy threats, when even partially revealed, privacy-preserving, data subsets can fuel innovative applications. With these in mind we develop a platform that enables controlled, privacy-preserving sharing of data items. Our system innovates in two directions: Firstly, it provides a framework for allowing discovery and selective disclosure of IoT data without violating their integrity. Secondly, it provides a user-friendly, intuitive mechanisms allowing efficient, fine-grained access control over the shared data. Our solution leverages recent advances in the areas of Self-Sovereign Identities, Verifiable Credentials, and Zero-Knowledge Proofs, and it integrates them in a platform that combines the industry-standard authorization framework OAuth 2.0 and the Web of Things specifications.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源