Authorization is a crucial security component of many distributed systems handling sensitive data or actions, including IoT systems. We present the design of a fully decentralized authorization system, WAVE, that operates at a global scale providing fine-grained permissions, non-interactive delegation and proofs of permission that can be efficiently verified, while still supporting revocation. Using smart contracts on a public blockchain, it allows rich and complex policies to be expressed and is resistant to DoS attacks without relying on any central trusted parties. We also present a novel mechanism for protecting the secrecy of resources on the public blockchain, without out-of-band channels or interaction between granters, provers or verifiers.
We implemented WAVE, which has now been running for over 500 days. We show that WAVE is efficient enough to support city-scale federation with millions of participants and permission policies.
Title
WAVE: A Decentralized Authorization System for IoT via Blockchain Smart Contracts
Published
2017-12-29
Full Collection Name
Electrical Engineering & Computer Sciences Technical Reports
Other Identifiers
EECS-2017-234
Type
Text
Extent
18 p
Archive
The Engineering Library
Usage Statement
Researchers may make free and open use of the UC Berkeley Library’s digitized public domain materials. However, some materials in our online collections may be protected by U.S. copyright law (Title 17, U.S.C.). Use or reproduction of materials protected by copyright beyond that allowed by fair use (Title 17, U.S.C. § 107) requires permission from the copyright owners. The use or reproduction of some materials may also be restricted by terms of University of California gift or purchase agreements, privacy and publicity rights, or trademark law. Responsibility for determining rights status and permissibility of any use or reproduction rests exclusively with the researcher. To learn more or make inquiries, please see our permissions policies (https://www.lib.berkeley.edu/about/permissions-policies).