About | Contact Us | Register | Login
ProceedingsSeriesJournalsSearchEAI
Security and Privacy in Communication Networks. 18th EAI International Conference, SecureComm 2022, Virtual Event, October 2022, Proceedings

Research Article

Granting Access Privileges Using OpenID Connect in Permissioned Distributed Ledgers

Cite
BibTeX Plain Text
  • @INPROCEEDINGS{10.1007/978-3-031-25538-0_16,
        author={Shohei Kakei and Yoshiaki Shiraishi and Shoichi Saito},
        title={Granting Access Privileges Using OpenID Connect in Permissioned Distributed Ledgers},
        proceedings={Security and Privacy in Communication Networks. 18th EAI International Conference, SecureComm 2022, Virtual Event, October 2022, Proceedings},
        proceedings_a={SECURECOMM},
        year={2023},
        month={2},
        keywords={Distributed ledger technology Smart contract Access control OpenID Connect Hyperledger Fabric},
        doi={10.1007/978-3-031-25538-0_16}
    }
    
  • Shohei Kakei
    Yoshiaki Shiraishi
    Shoichi Saito
    Year: 2023
    Granting Access Privileges Using OpenID Connect in Permissioned Distributed Ledgers
    SECURECOMM
    Springer
    DOI: 10.1007/978-3-031-25538-0_16
Shohei Kakei1,*, Yoshiaki Shiraishi2, Shoichi Saito1
  • 1: Nagoya Institute of Technology
  • 2: Kobe University
*Contact email: kakei.shohei@nitech.ac.jp

Abstract

Permissioned distributed ledger technology (DLT), in which only authenticated entities participate, assumes trust among the participants and implicit consent for data manipulation. In light of international regulations such as the GDPR, it is necessary to clarify the access privileges of user data, even for systems that assume the trust of the participants. In this paper, we propose an access privilege granting method for service providers that need to access user data in permissioned DLT systems. The proposed method separates the access privilege for user data in the distributed ledger from the execution privilege for smart contracts. By requesting a user to grant the access privilege, the participants can manipulate user data using smart contracts. The access privilege is represented by a token issued by OpenID Connect (OIDC). Smart contracts can directly verify the token without the participant’s interference. In this way, all the participants in the DLT network can reach a consensus that data manipulation is based on the user’s consent. We implemented the prototype system with Keycloak, an OIDC-compliant identity provider, and Hyperledger Fabric, a permissioned DLT, and then evaluated its performance. Finally, the overhead of access control is 0.21%, from which we conclude that the load on the system is very small.

Keywords
Distributed ledger technology Smart contract Access control OpenID Connect Hyperledger Fabric
Published
2023-02-04
Appears in
SpringerLink
http://dx.doi.org/10.1007/978-3-031-25538-0_16
Copyright © 2022–2025 ICST
EBSCOProQuestDBLPDOAJPortico
EAI Logo

About EAI

  • Who We Are
  • Leadership
  • Research Areas
  • Partners
  • Media Center

Community

  • Membership
  • Conference
  • Recognition
  • Sponsor Us

Publish with EAI

  • Publishing
  • Journals
  • Proceedings
  • Books
  • EUDL