Title | Access Control Audit and Traceability Forensics Technology Based on Blockchain |
Publication Type | Conference Paper |
Year of Publication | 2022 |
Authors | Shang, Siyuan, Zhou, Aoyang, Tan, Ming, Wang, Xiaohan, Liu, Aodi |
Conference Name | 2022 4th International Conference on Frontiers Technology of Information and Computer (ICFTIC) |
Date Published | dec |
Keywords | Access Control, Authorization, Big Data, blockchain, blockchains, computer security, Forensics, Human Behavior, human factors, information forensics, maintenance engineering, metadata, Metrics, pubcrawl, resilience, Resiliency, Scalability, Secure storage, security audit |
Abstract | Access control includes authorization of security administrators and access of users. Aiming at the problems of log information storage difficulty and easy tampering faced by auditing and traceability forensics of authorization and access in cross-domain scenarios, we propose an access control auditing and traceability forensics method based on Blockchain, whose core is Ethereum Blockchain and IPFS interstellar mail system, and its main function is to store access control log information and trace forensics. Due to the technical characteristics of blockchain, such as openness, transparency and collective maintenance, the log information metadata storage based on Blockchain meets the requirements of distribution and trustworthiness, and the exit of any node will not affect the operation of the whole system. At the same time, by storing log information in the blockchain structure and using mapping, it is easy to locate suspicious authorization or judgment that lead to permission leakage, so that security administrators can quickly grasp the causes of permission leakage. Using this distributed storage structure for security audit has stronger anti-attack and anti-risk. |
DOI | 10.1109/ICFTIC57696.2022.10075123 |
Citation Key | shang_access_2022 |