Identity and Access Management for the Computing Continuum

📅 2025-03-30
🏛️ MECC@EuroSys
📈 Citations: 0
Influential: 0
📄 PDF

career value

209K/year
🤖 AI Summary
To address access control challenges arising from the dynamicity, distribution, and heterogeneity of computing continua, this paper proposes a zero-trust-oriented cross-domain access control framework. The framework deeply integrates decentralized identifiers (DIDs) and verifiable credentials (VCs) to enable fine-grained, cryptographically verifiable identity management. It introduces, for the first time, a synergistic modeling approach that unifies relationship-based access control (ReBAC) with DID/VC primitives, thereby supporting evolving multi-party trust relationships and adaptive policy updates. Evaluated via a prototype implementation, the framework demonstrates significantly enhanced policy expressiveness compared to conventional RBAC and ABAC models; it reduces average authorization latency by 32% and improves security, controllability, and trust verifiability in decentralized environments.

Technology Category

Application Category

📝 Abstract
The computing continuum introduces new challenges for access control due to its dynamic, distributed, and heterogeneous nature. In this paper, we propose a Zero-Trust (ZT) access control solution that leverages decentralized identification and authentication mechanisms based on Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs). Additionally, we employ Relationship-Based Access Control (ReBAC) to define policies that capture the evolving trust relationships inherent in the continuum. Through a proof-of-concept implementation, we demonstrate the feasibility and efficiency of our solution, highlighting its potential to enhance security and trust in decentralized environments.
Problem

Research questions and friction points this paper is trying to address.

Address access control challenges in dynamic computing continuum
Propose Zero-Trust solution using decentralized identification mechanisms
Enhance security with Relationship-Based Access Control policies
Innovation

Methods, ideas, or system contributions that make the work stand out.

Zero-Trust access control solution
Decentralized Identifiers and Verifiable Credentials
Relationship-Based Access Control policies
🔎 Similar Papers
2024-02-04IEEE Communications Surveys & TutorialsCitations: 11
C
C. D. N. Kyriakidou
Athens Univ. of Economics & Business, ExcID P.C., Athens, Greece
A
A. M. Papathanasiou
Athens Univ. of Economics & Business, ExcID P.C., Athens, Greece
V
V. Siris
Athens Univ. of Economics & Business, ExcID P.C., Athens, Greece
N
N. Fotiou
ExcID P.C., Athens, Greece
G
G.C. Polyzos
ExcID P.C., Athens, Greece
E
Eduardo Cánovas Martínez
Universidad de Murcia, Murcia, Spain
A
Antonio Skármeta
Universidad de Murcia, Murcia, Spain