Direkt zum Inhalt

Belchior, Rafael ; Putz, Benedikt ; Pernul, Günther ; Correia, Miguel ; Vasconcelos, André ; Guerreiro, Sérgio

SSIBAC: Self-Sovereign Identity Based Access Control

Belchior, Rafael, Putz, Benedikt , Pernul, Günther, Correia, Miguel, Vasconcelos, André und Guerreiro, Sérgio (2020) SSIBAC: Self-Sovereign Identity Based Access Control. In: The 3rd International Workshop on Blockchain Systems and Applications (BlockchainSys2020), in Conjunction with IEEE TrustCom 2020, December 29, 2020 - January 1, 2021, Guangzhou, China.

Veröffentlichungsdatum dieses Volltextes: 02 Nov 2020 10:20
Konferenz- oder Workshop-Beitrag
DOI zum Zitieren dieses Dokuments: 10.5283/epub.44043


Zusammenfassung

Data breaches combined with ineffective data management practises pose serious issues to consumers and enterprises, such as identity theft and online exposure. Although the general data protection regulation (GDPR) attempts to protect the consumers, often companies cannot avoid data breaches. This leads to negative consequences, e.g., companies loosing credibility and paying fines. In this ...

Data breaches combined with ineffective data management practises pose serious issues to consumers and enterprises, such as identity theft and online exposure. Although the general data protection regulation
(GDPR) attempts to protect the consumers, often companies cannot avoid data breaches. This leads to negative consequences, e.g., companies loosing credibility and paying fines.

In this work, we alleviate the data breach and the user privacy problems by showing how to fit decentralized identities within the context of established enterprise identity and access management technologies. In light of recent endeavours, we explore the usage of decentralized identifiers, verifiable credentials, and blockchains that support self-sovereign identity to foster identity portability, and the decoupling of access control processes with the storage of sensitive data from users.

We propose a simplified access control method that can be applied to cross-organizational identity management, that aims to reduce the impact of data breaches. The Self-Sovereign Identity Access Control (SSIBAC) model leverages blockchain technology to provide decentralized authentication followed by centralized or decentralized authorization. We show that our access control model achieves properties X, Y,Z.

Our preliminary implementation of the model can process one access control request every two seconds, proving to be practical in scenarios not requiring real-time performance.



Beteiligte Einrichtungen


Details

DokumentenartKonferenz- oder Workshop-Beitrag (Nicht ausgewählt)
Verlag:IEEE
Datum29 Dezember 2020
Zusätzliche Informationen (Öffentlich)© 2020 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works.
InstitutionenWirtschaftswissenschaften > Institut für Wirtschaftsinformatik > Lehrstuhl für Wirtschaftsinformatik I - Informationssysteme (Prof. Dr. Günther Pernul)
Informatik und Data Science > Fachbereich Wirtschaftsinformatik > Lehrstuhl für Wirtschaftsinformatik I - Informationssysteme (Prof. Dr. Günther Pernul)
Identifikationsnummer
WertTyp
10.1109/TrustCom50675.2020.00264DOI
Stichwörter / Keywordsdecentralized identity;decentralized authorization;attribute-based authorization
Dewey-Dezimal-Klassifikation000 Informatik, Informationswissenschaft, allgemeine Werke > 004 Informatik
300 Sozialwissenschaften > 330 Wirtschaft
StatusVeröffentlicht
BegutachtetJa, diese Version wurde begutachtet
An der Universität Regensburg entstandenZum Teil
URN der UB Regensburgurn:nbn:de:bvb:355-epub-440430
Dokumenten-ID44043

Bibliographische Daten exportieren

Nur für Besitzer und Autoren: Kontrollseite des Eintrags

nach oben