A Policy-Hiding Attributed-Based Access Control Scheme for IIoT Device Secure Remote Operation
Keywords:
Access control, IIoT device, secure remote operation, policy-controlled signature, policy-hidingAbstract
IIoT devices are the foundation of the Industrial Internet of Things (IIoT), including functions such as environmental perception, data processing, and remote operation. One core advantage of IIoT devices is their remote operation capability, allowing operators to control them via smart devices from distant locations. While remote operation greatly enhances flexibility, the resulting security issues must not be overlooked. Instructions can be tampered during transmission. Existing devices can verify the sender's identity, but a legitimate sender may still issue non-compliant instructions, impacting safety and efficiency of industrial production. Most existing access control schemes for IIoT devices are unsuitable for secure remote operations. They focus on data exchange between devices, ignoring compliance of data content and sender. This paper proposes a policy-hiding attribute-based access control scheme for secure remote operation of IIoT devices. It provides fine-grained access control while ensuring safe operation by verifying sender compliance and instruction content through a compliance policy. Additionally, policy hiding protects sender privacy. Furthermore, multi-receiver signcryption is employed to prevent unauthorized tampering with the instructions during transmission. The security analysis substantiates the security of our scheme, while the performance analysis demonstrates its applicability in IIoT scenarios.