A Policy-Hiding Attributed-Based Access Control Scheme for IIoT Device Secure Remote Operation

Authors

  • Linghui Meng Key Lab of Education Blockchain and Intelligent Technology, Ministry of Education, Guangxi Normal University, Guilin, China & Guangxi Key Lab of Multi-Source Information Mining and Security, Guangxi Normal University, Guilin, China
  • Feng Yu Key Lab of Education Blockchain and Intelligent Technology, Ministry of Education, Guangxi Normal University, Guilin, China & Guangxi Key Lab of Multi-Source Information Mining and Security, Guangxi Normal University, Guilin, China & State Key Laboratory of Nuclear Power Safety Monitoring Technology and Equipment, Shenzhen, 518172, China
  • Daicen Jiang Southern Power Grid Supply Chain (Guangxi) Co., Ltd., Nanning, Guangxi, China
  • Jing Xi Key Lab of Education Blockchain and Intelligent Technology, Ministry of Education, Guangxi Normal University, Guilin, China & Guangxi Key Lab of Multi-Source Information Mining and Security, Guangxi Normal University, Guilin, China
  • Shenglin Cao Ningxia Normal University, Guyuan, China
  • Zhihua Zeng State Key Laboratory of Nuclear Power Safety Monitoring Technology and Equipment, Shenzhen, 518172, China

Keywords:

Access control, IIoT device, secure remote operation, policy-controlled signature, policy-hiding

Abstract

IIoT devices are the foundation of the Industrial Internet of Things (IIoT), including functions such as environmental perception, data processing, and remote operation. One core advantage of IIoT devices is their remote operation capability, allowing operators to control them via smart devices from distant locations. While remote operation greatly enhances flexibility, the resulting security issues must not be overlooked. Instructions can be tampered during transmission. Existing devices can verify the sender's identity, but a legitimate sender may still issue non-compliant instructions, impacting safety and efficiency of industrial production. Most existing access control schemes for IIoT devices are unsuitable for secure remote operations. They focus on data exchange between devices, ignoring compliance of data content and sender. This paper proposes a policy-hiding attribute-based access control scheme for secure remote operation of IIoT devices. It provides fine-grained access control while ensuring safe operation by verifying sender compliance and instruction content through a compliance policy. Additionally, policy hiding protects sender privacy. Furthermore, multi-receiver signcryption is employed to prevent unauthorized tampering with the instructions during transmission. The security analysis substantiates the security of our scheme, while the performance analysis demonstrates its applicability in IIoT scenarios.

 

Downloads

Download data is not yet available.

Published

2026-08-31

How to Cite

Meng, L., Yu, F., Jiang, D., Xi, J., Cao, S., & Zeng, Z. (2026). A Policy-Hiding Attributed-Based Access Control Scheme for IIoT Device Secure Remote Operation. Computing and Informatics, 45(4). Retrieved from http://147.213.75.17/ojs/index.php/cai/article/view/7525