Trustworthy Configuration Management for Networked Devices using\n Distributed Ledgers
Abstract
Numerous IoT applications, like building automation or process control of\nindustrial sites, exist today. These applications inherently have a strong\nconnection to the physical world. Hence, IT security threats cannot only cause\nproblems like data leaks but also safety issues which might harm people.\nAttacks on IT systems are not only performed by outside attackers but also\ninsiders like administrators. For this reason, we present ongoing work on a\nconfiguration management system (CMS) that provides control over\nadministrators, restrains their rights, and enforces separation of concerns. We\nreach this goal by conducting a configuration management process that requires\nmulti-party authorization for critical configurations to achieve Byzantine\nfault tolerance against attacks and faults by administrators. Only after a\nconfiguration has been authorized by multiple experts, it is applied to the\ntargeted devices. For the whole configuration management process, our CMS\nguarantees accountability and traceability. Lastly, our system is\ntamper-resistant as we leverage Hyperledger Fabric, which provides a\ndistributed execution environment for our CMS and a blockchain-based\ndistributed ledger that we use to store the configurations. A beneficial side\neffect of this approach is that our CMS is also suitable to manage\nconfigurations for infrastructure shared across different organizations that do\nnot need to trust each other.\n
Community
0 commentsNo discussion yet
Be the first to share a question or observation.