USENIX Security2019Top-tier venue
WAVE: A Decentralized Authorization Framework with Transitive Delegation
Michael P. Andersen, Sam Kumar, Moustafa AbdelBaky, Gabe Fierro, John Kolb, Hyung-Sin Kim, David E. Culler, Raluca Ada Popa
Abstract
Most deployed authorization systems rely on a central trusted service whose compromise can lead to the breach of millions of user accounts and permissions. We present WAVE, an authorization framework offering decentralized trust: no central services can modify or see permissions and any participant can delegate a portion of their permissions autonomously. To achieve this goal, WAVE adopts an expressive authorization model, enforces it cryptographically, protects permissions via a novel encryption protocol while enabling discovery of permissions, and stores them in an untrusted scalable storage solution. WAVE provides competitive performance to traditional authorization systems relying on central trust. It is an open-source artifact and has been used for two years for controlling 800 IoT devices.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6fa48ebe-24b2-4942-b6cb-37b06f62c7e9Cited by top-tier papers10
- JEDI: Many-to-Many End-to-End Encryption and Key Delegation for IoTSam Kumar, Yuncong Hu, Michael P. Andersen, Raluca Ada Popa et al.USENIX Security 2019 · 75 citations
- Merkle2: A Low-Latency Transparency Log SystemYuncong Hu, Kian Hooshmand, Harika Kalidhindi, Seung Jin Yang et al.S&P 2021 · 51 citations
- GlassDB: An Efficient Verifiable Ledger Database System Through TransparencyCong Yue, Tien Tuan Anh Dinh, Zhongle Xie, Meihui Zhang et al.VLDB 2023 · 26 citations
- SafetyPin: Encrypted Backups with Human-Memorable SecretsEmma Dauterman, Henry Corrigan-Gibbs, David MazièresOSDI 2020 · 22 citations
- Who's In Control? On Security Risks of Disjointed IoT Device Management ChannelsYan Jia, Bin Yuan, Luyi Xing, Dongfang Zhao et al.CCS 2021 · 22 citations
Builds on2
- JEDI: Many-to-Many End-to-End Encryption and Key Delegation for IoTSam Kumar, Yuncong Hu, Michael P. Andersen, Raluca Ada Popa et al.USENIX Security 2019 · 75 citations
- Decentralized Action Integrity for Trigger-Action IoT PlatformsEarlence Fernandes, Amir Rahmati, Jaeyeon Jung, Atul PrakashNDSS 2018 · 14 citations
Related papers
- 5G-WAVE: A Core Network Framework with Decentralized Authorization for Network SlicesPragya Sharma, Tolga O. Atalay, Hans-Andrew Gibbs, Dragoslav Stojadinovic et al.INFOCOM 2024 · 6 citations
- Droplet: Decentralized Authorization and Access Control for Encrypted Data StreamsHossein Shafagh, Lukas Burkhalter, Sylvia Ratnasamy, Anwar HithnawiUSENIX Security 2020
- Rethinking Trust in Forge-Based Git SecurityAditya Sirish A Yelgundhalli, Patrick Zielinski, Reza Curtmola, Justin CapposNDSS 2025
- DBAC: Directory-Based Access Control for Geographically Distributed IoT SystemsLuoyao Hao, Vibhas Naik, Henning SchulzrinneINFOCOM 2022 · 12 citations
- EnTrust: Regulating Sensor Access by Cooperating Programs via Delegation GraphsGiuseppe Petracca, Yuqiong Sun, Ahmad Atamli-Reineh, Patrick D. McDaniel et al.USENIX Security 2019 · 10 citations
