Shiva Kazemi Taskou, Mehdi Rasti, Pedro H. J. Nardelli
Many of the key enabling technologies of the fifth-generation (5G), such as network slicing, spectrum sharing, and federated learning, rely on a centralized authority. This may lead to pitfalls in terms of security or single point of failure. Distributed ledger technology, specifically blockchain, is currently employed by different applications related to the Internet of Things (IoT) and 5G to address the drawbacks of centralized systems. For this reason, mobile blockchain networks (MBNs) have recently attracted a great deal of attention. To add a transaction to the blockchain in MBNs, mobile or IoT users must perform various tasks like encryption, decryption, and mining. These tasks require energy and processing power, which impose limitations on mobile and IoT users' performance because they are usually battery powered and have a low processing power. One possible solution is to perform the tasks virtually on commodity servers provided by mobile edge computing (MEC) or cloud computing. To do so, all tasks needed to add a transaction to the blockchain can be treated as virtual blockchain functions that can be executed on commodity servers. We introduce a blockchain virtualization framework called blockchain function virtualization (BFV), through which all blockchain functions can be performed virtually by MEC or cloud computing. Furthermore, we describe applications of the BFV framework and resource allocation challenges brought by the BFV framework in mobile networks. In addition, to illustrate the advantages of BFV, we define an optimization problem to simultaneously minimize the energy consumption cost and maximize miners' rewards. Finally, simulation results show the performance of the proposed framework in terms of total energy consumption, transaction confirmation rate, and miners' average profit.
The novel concept of factory-as-a-service (FaaS) allows the agility of adapting the manufacturing process by identifying the industryâs supply chain and user requirements. To cater to FaaS, flexibility in networking and cloud services is a must. 5G network slice broker (NSB) is a third-party mediator that caters to networking resource demand from clients to the service providers. Thus, this article introduces a secure blockchain-based NSB to facilitate FaaS. The proposed secure NSB (SNSB) provides secure, cognitive, and distributed network services for resource allocation and security service level agreement (SSLA) formation with coordination of slice managers and SSLA managers. In SNSB, we introduce a federated slice selection algorithm with Stackelberg game model and reinforcement learning algorithm to compute the real time and the optimal unit price and demand level. We provide an extensive implementation and performance evaluation of SNSB using the slice manager and a custom SSLA manager.
Space-air-ground integrated network is capable of providing seamless and ubiquitous services to cater for the increasing wireless communication demands of emerging applications. However, how to efficiently manage the heterogeneous resources and protect the privacy of connected devices is a very challenging issue, especially under the highly dynamic network topology and multiple trustless network operators. In this paper, we investigate blockchain-empowered dynamic spectrum management by reaping the advantages of blockchain and software defined network (SDN), where operators are incentive to share their resources in a common resourced pool. We first propose a blockchain enabled spectrum management framework for space-air-ground integrated network, with inter-slice spectrum sharing and intra-slice spectrum allocation. Specifically, the inter-slice spectrum sharing is realized through a consortium blockchain formed by the upper-tier SDN controllers, and then a graph coloring based channel assignment algorithm is proposed to manage the intra-slice spectrum assignment. A bilateral confirmation protocol and a consensus mechanism are also proposed for the consortium blockchain. The simulation results prove that our proposed consensus algorithm takes less time than practical Byzantine fault tolerance algorithm to reach a consensus, and the proposed channel assignment algorithm significantly improves the spectrum utilization and outperforms the baseline algorithm in both simulation and real-world scenarios.
Software-Defined Networking (SDN) enhances the flexibility and programmability of networks by separating control plane and data plane. The logically centralized control mechanism makes the control plane vulnerable in both single and multiple controller scenarios. Malicious third parties can exploit vulnerabilities of reactive forwarding mode to launch distributed denial-of-service (DDoS) attacks against SDN controllers. Unfortunately, existing DoS/DDoS solutions under single controller can not afford effective performance under multiple controllers due to the absence of cooperative detection and mitigation. To solve the above problem, we propose a blockchain-based SDN-targeted DDoS defense framework (BSD-Guard) that can provide cooperative detection and mitigation mechanism to protect SDN controllers. BSD-Guard introduces a blockchain-based secure middle plane between control plane and data plane. The secure middle plane calculates the suspect rate of new flows based on the collected packetsâ information and reports suspect lists to blockchain for immutably storing and sharing. Besides, the smart contract deployed on blockchain in advance constitutes collaborative defense strategies based on the suspect lists reported from multiple SDN domains. When receiving defense strategies, the secure middle plane converts them to specific flow table actions and installs actions into relevant switches. The experimental results indicate that BSD-Guard can efficiently detect DoS/DDoS attacks in multiple controllers scenario and issue precise defensive strategies near the source of attack by identifying the attack path.
This document presents the final design of the 5GZORRO high-level architecture, which targets the achievement and implementation of the innovative 5G networks and services vision described above. More specifically, this deliverable is intended as a self-contained document, which merges the original content of deliverables D2.2 and D2.3 (that present the initial and the updated 5GZORRO high-level architecture respectively) and further improves them to align the 5GZORRO architecture functionalities with the feedback from the platform implementation undergoing in WP3 and WP4. With this document, the goal is to have a single source of information for the 5GZORRO high-level architecture, which includes the whole set of services offered, functionalities supported, and operational workflows implemented.<br> In practice, in alignment with the original approach proposed and described in D2.2 and D2.3, the architecture follows a principle of service-based architecture, similar to the 5G Service-based architecture defined in 3GPP and in the ETSI Zero touch network and Service Management. Integrating SDN/NFV and Cloud native orchestration technologies with a Permissioned Distributed Ledger infrastructure, the 5GZORRO architecture offers services for:<br> ⢠cross-domain network slicing,<br> ⢠resource and service offering via marketplaces,<br> ⢠discovery, intelligent selection and trading of resources and Services via Smart Contracts<br> ⢠zero-touch network slice and service lifecycle management<br> ⢠cross-stakeholder e-license management<br> ⢠SLA monitoring & breach prediction<br> ⢠security and trust across multiple domains.<br> The realization of these services is made possible through the interaction of various functions for slice orchestration, network intelligence and analytics, security and trust, management of virtualized resources, all executed for multi-domain and single domain scopes. Moreover, 5GZORRO leverages many state-of-the-art technologies and standards for virtualization, NFV, Cloud Native platforms and services, zero touch, SDN, distributed ledgers, data lakes, which have been extensively reviewed to summarise the specific positioning of the 5GZORRO innovative proposition.
Tooba Faisal, JosÊ Antonio Ordóùez Lucena, Diego López, Chonggang Wang ¡ 5 authors
With the growing demand for network connectivity and diversity of network applications, one primary challenge that network service providers are facing is managing the commitments for Service Level Agreements (SLAs). Service providers typically monitor SLAs for management tasks such as improving their service quality, customer billing and future network planning. Network service customers, on their side, monitor services provided to them, to optimize their network usage and apply, when required, penalties related to service failures. In future 6G networks, critical network applications such as remote surgery and connected vehicles will require these SLAs to be more dynamic, flexible, and automated to match their diverse requirements on network services. Moreover, these SLAs should be transparent to all stakeholders to address the trustworthiness on network services and service providers required by critical applications. Currently, there is no standardized method to immutably record and audit SLAs, leading to challenges in aspects such as SLA enforcement and accountability - traits essential for future network applications. This work explores new requirements for future service contracts, that is, on the evolution of SLAs. Based on those new requirements, we propose an end to end layered SLA architecture leveraging Distributed Ledger Technology (DLT) and smart contracts. Our architecture is inheritable by an existing telco-application layered architectural frameworks to support future SLAs. We also discuss some limitations of DLT and smart contracts and provide several directions of future studies.
Emilio C. Piesciorovsky, Raymond Borges Hink, Aaron Werth, Gary Hahn ¡ 7 authors
The electrical substation-grid testbed was created to integrate the GOOSE and/or DNP (Distributed Network Protocol) messages with time synchronized sources and Distributed Ledger Technology (DLT). The objective was to study the impact of faults and cyber-events at an electrical substation with inside (protective relays) and outside (power meters) substation devices. The electrical substation-grid testbed was based on the design of a 34.5/ 12.47 kV electrical substation (sectionalized bus configuration) with two power transformers, connected to radial power lines and load feeders. The electrical substation-grid testbed was installed at 252 lab space (Advanced Power System Protection), Grid Research Integration and Deployment Center (GRID-C), Oak Ridge National Laboratory. This testbed was created for Task 5, DarkNet project.The electrical substation-grid testbed was created to simulate fault and/or cyber events that could potentially result in damage to the electrical infrastructure. In addition, tests were run that are usually not allowed to be performed in an operational electrical power grid, because these test scenarios could trip breakers and/or generate fault situations that could potentially damage equipment. The number of tests performed in the electrical substation-grid testbed were executed in a better way than in a real electrical substation and/or power grid, because multiple tests could be run in a short period of time, and complex permits, and safety/ schedule restrictions like in a real electrical substation environment were not needed.The electrical substation-grid testbed was created using real measurement, communication, and protection devices that are used by electrical utilities, to have same conditions that we could observe in a real power grid or electrical substation. The electrical substation-grid testbed was based on using a real time simulator and expansion box with amplifiers that were wired to electrical substation-grid devices. This hardware-in-the-loop (HIL) was provided by protective relays, power meters, ethernet switches, remote terminal units, synchronized timing network clock, DLT devices, workstations, and servers.This report includes the design, installation, and assessment of the electrical substation-grid testbed that was similar to an operational electrical substation, integrating the power system protection, communication, and control systems. The results for the electrical substation-grid testbed were based on:⢠verifying the analog signals for protective relays and power meters, ⢠observing the synchronized time source frame at devices, ⢠authenticating the GOOSE (IEC 61850) and DNP messages from power meters and protective relays, and ⢠verifying the trip conditions of protective relays at fault tests with the power system fault event detection, using DLT devices.For future work, the electrical substation-grid testbed with protective relays and power meters, using DLT and synchronized time source from DarkNet, will be used to study the impact of cyber-events at inside and outside substation devices. Advanced algorithms for detecting cyber-events produced by non-desired protective relay settings will be studied, to improve the detection and reliability of protection, control, and communication systems at power grids.
Sultan Algarni, Fathy Eassa, Khalid Ali Almarhabi, Abdullah Algarni ¡ 5 authors
Software-defined networking (SDN) has emerged as a flexible and programmable network architecture that takes advantage of the benefits of global visibility and centralized control over a network. One of the main properties of the SDN architecture is the ability to offer a northbound interface (NBI), which enables network applications to access the SDN controller resources. However, the NBI can be compromised by a malicious application due to the lack of standardization and security aspects in the most current NBI designs. Therefore, in this paper, we propose a novel comprehensive security solution for securing the applicationâcontroller interface, named BCNBI. We propose a controller-independent lightweight blockchain architecture and exploit the security features of blockchain while limiting the blockchainâs computational overhead. BCNBI automatically verifies application and SDN controller credentials through token-based authentication. The proposed solution enforces fine-grained access control for each applicationâs API request and classifies the permission set into strict and normal policies, in order to add an extra level of security. In addition, the trustworthiness of applications is evaluated in order to prevent malicious activities. We implemented our blockchain-based solution to analyze its security, based on the confidentialityâintegrityâavailability model criteria, and evaluated the introduced overhead in terms of processing time and packet overhead. The experimental results demonstrate that the BCNBI can effectively secure the NBI, based on the fundamental security goals, while introducing insignificant overhead.
Blockchain was always associated with Bitcoin, cryptocurrencies, and digital asset trading. However, its benefits are far beyond that. It supports technologies like the Internet-of-Things (IoT) to pave the way for futuristic smart environments, like smart homes, smart transportation, smart energy trading, smart industries, smart supply chains, and more. To enable these environments, IoT devices, machines, appliances, and vehicles, need to intercommunicate without the need for centralized trusted parties. Blockchain replaces these trusted parties in such trustless environments. It provides security enforcement, privacy assurance, authentication, and other key features to IoT ecosystems. Besides IoT-Blockchain integration, other technologies add more benefits that attract the research community. Software-Defined Networking (SDN), Fog, Edge, and Cloud Computing technologies, for example, play a key role in enabling realistic IoT applications. Moreover, the integration of Artificial Intelligence (AI) provides smart, dynamic, and autonomous decision-making capabilities for IoT devices in smart environments. To push the research further in this domain, we provide in this paper a comprehensive survey that includes state-of-the-art technological integration, challenges, and solutions for smart environments, and the role of these technologies as the building blocks of such smart environments. We also demonstrate how the level of integration between these technologies has increased over the years, which brings us closer to the futuristic view of smart environments. We further discuss the current need to provide general-purpose Blockchain platforms that can adapt to unique design requirements of different applications and solutions. Finally, we provide a simplified architecture of futuristic smart environments that integrate these technologies, showing the advantage of such integration.
The Internet of Things (IoT) aims to create a digital world where any information system can expose, discover, understand and consume data and services for analysis, diagnosis, decision support and task automation in various domains such as healthcare, transportation, energy, industry, agriculture, etc. Faced with this diversity of applications and rapid evolution, infrastructures must be able to achieve high levels of security and confidentiality while being open, sustainable, and agile to adapt to the multiple requirements of applications. To meet these needs, new paradigms are emerging. These include the Software Defined Networks (SDN) paradigm, which offers the ability to dynamically program different applications and devices to provide end-to-end service chains. In parallel, the Blockchain paradigm is increasingly used in the Internet of Things, making distributed transactions between connected objects such as financial transactions or "smart contracts" possible. Although the combination of these two paradigms (Blockchain/SDN) is a major issue for the success of the Internet of Things, paving the way for new business models and management/control of communication networks, there is not yet a specified/formalized architecture allowing the use of the "Blockchain" in SDN. In this research, a new architecture for a system combining blockchain and SDN for IoT security is proposed
Vehicular Ad-hoc networks (VANETs) during the communication process, nodes are always varying and the process is always under security threats like Sybil attacks, masquerading attacks, etc. In order to reduce the probability of these attacks and to regulate traffic flow in the network, a software-defined network (SDN) is used. The SDN is used for implementing protocols like OpenFlow and reducing the routing load in the network, but it doesnât provide a high level of security to the network, hence protocols like encryption, hashing, etc. are applied to the VANET. In the paper, SDN based blockchain-inspired algorithm is implemented, which coordinates network traffic and improves the overall security of the network. Security analysis of the proposed algorithm shows that the combination of blockchain with encrypted SDN is removing more than 95% of the network attacks as compared to its non-blockchain counterparts.
Deploying multi-domain network services is becoming a need for operators. However, achieving that in a real operational environment is not easy and requires the use of federation. Federation is a multi-domain concept that enables the use and orchestration of network services/resources to/from external administrative domains. In this article, we first characterize the federation concept and involved procedures, and then dive into the challenges that emerge when federation is performed in dynamic environments. To tackle these challenges, we propose the application of blockchain technology, identifying some associated high-level benefits. Last, we validate our proposed approach by conducting a small experimental scenario using Tendermint, an application-based blockchain.
Wenjuan Li, Yu Wang, Weizhi Meng, Jin Li ¡ 5 authors
To safeguard critical services and assets in a distributed environment, collaborative intrusion detection systems (CIDSs) are usually adopted to share necessary data and information among various nodes, and enhance the detection capability. For simplifying the network management, software defined networking (SDN) is an emerging platform that decouples the controller plane from the data plane. Intuitively, SDN can help lighten the management complexity in CIDSs, and a CIDS can protect the security of SDN. In practical implementation, trust management is an important approach to help identify insider attacks (or malicious nodes) in CIDSs, but the challenge is how to ensure the data integrity when evaluating the reputation of a node. Motivated by the recent development of blockchain technology, in this work, we design BlockCSDN â a framework of blockchain-based collaborative intrusion detection in SDN, and take the challenge-based CIDS as a study. The experimental results under both external and internal attacks indicate that using blockchain technology can benefit the robustness and security of CIDSs and SDN.
Pol Alemany, Ricard Vilalta, Raßl Muùoz, Ramon Casellas ¡ 5 authors
Data center (DC) interconnection allows us to have optical transmissions between DCs directly connected to optical networks, avoiding the use of a packet-based infrastructure. Thanks to the use of next-generation pluggable coherent optics, it is possible to create connectivity services (CSs) across multiple optical transport domains. In this multi-domain CS scenario, cloud operators and transport operators have to work together in the most dynamic way possible. To do so, they need a common place (i.e., a market) where the transport operators may expose their available optical resources and the cloud operators request (e.g., rent) them to be used in order to create end-to-end (E2E) CSs between DCs. Having multiple transport operators exposing their resource information in a common place requires a set of common rules (i.e., how much of the topology to show) to create E2E CSs requested between cloud operators. This paper makes use of the blockchain technology to present a blockchain-based extension for the software-defined network (SDN) architecture to allow each optical transport operator domain to become a peer in a blockchain network. In there, each peer follows the same rules and shares the same exact level of topology information by using a specific abstraction model to map the optical domain resources. This paper uses a set of three different abstraction models to validate their behavior on a blockchain system when managing multiple domain resources and the deployment of CSs across these domains. To do so, an experimental comparison on how the different abstraction models affect the performance of the blockchain system is presented.
Compared with the classical structure with only one controller in software-defined networking (SDN), multi-controller topology structure in SDN provides a new type of cross-domain forwarding network architecture with multiple centralized controllers and distributed forwarding devices. However, when the network includes multiple domains, lack of trust among the controllers remains a challenge how to verify the correctness of cross-domain forwarding behaviors in different domains. In this paper, we propose a novel secure multi-controller rule enforcement verification (BlockREV) mechanism in SDN to guarantee the correctness of cross-domain forwarding. We first adopt blockchain technology to provide the immutability and privacy protection for forwarding behaviors. Furthermore, we present an address-based aggregate signature scheme with appropriate cryptographic primitives, which is provably secure in the random oracle model. Moreover, we design a verification algorithm based on hash values of forwarding paths to check the consistency of forwarding order. Finally, experimental results demonstrate that the proposed BlockREV mechanism is effective and suitable for multi-controller scenarios in SDN.
The decoupling of the data plane and the control plane in the Software- Defined Network (SDN) can increase the flexibility of network management and operation. And it can reduce the network limitations caused by the hardware. However, the centralized scheme in SDN also can introduce some other security issues such as the single point of failure, the data consistency in multiple-controller environment and the spoofing attack initiated by a malicious device in the data plane. To solve these problems, a security framework for SDN based on Blockchain (BCSDN) is proposed in this paper. BCSDN adopts a physically distributed and logically centralized multi-controller architecture. LLDP protocol is periodically used to obtain the link state information of the network, and a Merkle tree is establised according to the collected link information and the signature is generate based on KSI for each link that submitted by a switch by the main controller selected by using the PoW mechanism. Such, the dynamic change of network topology is recorded on Blockchian and the consistency of the topology information among multiple controllers can be guaranteed. The main controller issues the signature to the corresponding switch and a controller checks the legitimate of a switch by verifying the signature when it requests the flow rule table from the controller later. The signature verification ensures the authenticated communication between a controller and a switch. Finally, the simulation of the new scheme is implemented in Mininet platform that is a network emulation platform and experiments are done to verify our novel solution in our simulation tool. And we also informally analysis the security attributes that provided by our BCSDN.
With the rapid development of the IoT (Internet-of-Things), additional smart gadgets may be associated with the Internet, significantly enhancing data transfer and communication. Software-Defined Networking (SDN) is known as a new model that separates the control plane and the data plane, and is anticipated as a favorable solution for implementing Blockchain, to offer the scalability and adaptability required for IoT. The scalability of the network rises in direct proportion to the usersâ enhanced privacy on the network. Blockchain and SDN are two top innovations utilized to create secure network architectures and provide trustworthy data transmission. They offer a strong and trustworthy platform to deal with dangers and problems, including security, privacy, adaptability, scalability, and secrecy. Unfortunately, the attackers can still inject traffic to disrupt a blockchain nodeâs regular functions. This study provides an optimized Blockchain-based SD IoT architecture for smart networks that is safe and energy-efficient. In this work, it is concentrated on blockchain-based SDN and creates an SDN-Blockchain Classifier. This IDS-based security tool provides a trust-based classifier by handling and reducing harmful traffic through traffic fusion and aggregation. Finally, it is concluded by evaluating the proposed framework SDN-Blockchain Classifier performance against MAC flooding attack in a simulation setting and demonstrating that it can attain optimized average throughput, response time, packet loss of crossing domain path, energy efficiency, end-to-end delay, file transfer operation, energy consumption, and CPU utilization compared to the baselines taken into consideration, thereby achieving efficacy and also security in the proposed smart network.
Yustus Eko Oktian, Thi-Thu-Huong Le, Uk Jo, Howon Kim
Bandwidth trading procedures can be made to incentivize users to sell their needless traffic and indirectly reduce the probability of traffic congestion. However, implementation of bandwidth trading is opex-heavy from Internet Service Provider (ISP) perspective, while on the other hand, users also do not trust network executions from the ISP due to its heavily centralized control. These issues hinder the applicability of bandwidth trading and become our motivation to propose this paper. Our bandwidth-trading framework utilize software-defined networking (SDN) and blockchain. SDN automates the bandwidth trading executions from the ISP side and reduces the opex. Meanwhile, the smart contract is a trusted platform for building a trading marketplace where buyers, sellers, and SDN controllers can negotiate the trading terms. Once the trading is executed, SDN controllers generate proof of trading that must be submitted to the smart contract as proof of provisioning. We implement our works using Ethereum and POX SDN controllers, and the results prove that it can provide a seamless bandwidth trading experience with reasonable overhead. Furthermore, by committing to our framework, bandwidth trading can be executed fairly and securely because all previous provisioning can be cross-checked through the provided proof-of-trading.
The development of fifthâgeneration (5G) mobile communication technology has become a major driver to the growth of Internet of Things (IoT) applications. As a promising networking paradigm, softwareâdefined networking (SDN) makes IoT more flexible and agile by decoupling control plane from data plane. With a large number of heterogeneous devices accessing to the network, we need to divide the network into several domains and each domain is managed by an SDN controller. Controllers share topologies with each other to form global view of the entire network, which is used for crossingâdomain path routing. However, crossingâdomain routing requires global trust between multiple controllers. The reason is that if the malicious controller shares misleading topologies, the rest of controllers may calculate mistaken crossingâdomain paths. As a result, packets are forwarded to the domain that is managed by the malicious controller and dropped deliberately, which is known as the blackâhole attack. To this end, we present a blockchainâbased architecture to ensure secure routing among multiple domains in SDNâenabled IoT networks. All SDN controllers are equipped with blockchains, and they upload abstract topologies to the blockchain via the smart contract. Thus, the genuine view of the entire network can be gained from the blockchain due to its consensus and immutability. In addition, we use the concept of reputation that consists of the local reputation and the global reputation to further protect routing reliability, and the global reputation is reserved in the blockchain. Compared with benchmark architectures, the emulation results show that our proposed method can effectively build trust between multiple controllers and ensure secure routing among multiple domains.
Network slicing is one of the fundamental tenets of Fifth Generation (5G)/Sixth Generation (6G) networks. Deploying slices requires end-to-end (E2E) control of services and the underlying resources in a network substrate featuring an increasing number of stakeholders. Beyond the technical difficulties this entails, there is a long list of administrative negotiations among parties that do not necessarily trust each other, which often requires costly manual processes, including the legal construction of neutral entities. In this context, Blockchain comes to the rescue by bringing its decentralized yet immutable and auditable lemdger, which has a high potential in the telco arena. In this sense, it may help to automate some of the above costly processes. There have been some proposals in this direction that are applied to various problems among different stakeholders. This paper aims at structuring this field of knowledge by, first, providing introductions to network slicing and blockchain technologies. Then, state-of-the-art is presented through a global architecture that aggregates the various proposals into a coherent whole while showing the motivation behind applying Blockchain and smart contracts to network slicing. And finally, some limitations of current work, future challenges and research directions are also presented.
Tooba Faisal, Mischa DĂśhler, Simone Mangiante, Diego LĂłpez
It is widely expected that future networks of 6G and beyond will deliver on the unachieved goals set by 5G. Technologies such as Internet of Skills and Industry 4.0 will become stable and viable, as a direct consequence of networks that offer sustained and reliable mobile performance levels. The primary challenges for future technologies are not just low-latency and high-bandwidth. The more critical problem Mobile Service Providers (MSPs) will face will be in balancing the inflated demands of network connections and customers' trust in the network service, that is, being able to interconnect billions of unique devices while adhering to the agreed terms of Service Level Agreements (SLAs). To meet these targets, it is self-evident that MSPs cannot operate in a solitary environment. They must enable cooperation among themselves in a manner that ensures trust, both between themselves as well as with customers. In this study, we present the BEAT (Blockchain-Enabled Accountable and Transparent) Infrastructure Sharing architecture. BEAT exploits the inherent properties of permissioned type of distributed ledger technology (i.e., permissioned distributed ledgers) to deliver on accountability and transparency metrics whenever infrastructure needs to be shared between providers. We also propose a lightweight method that enables device-level accountability. BEAT has been designed to be deployable directly as only minor software upgrades to network devices such as routers. Our simulations on a resource-limited device show that BEAT adds only a few seconds of overhead processing time -- with the latest state-of-the-art network devices, we can reasonably anticipate much lower overheads.
Along with the high demand for network connectivity from both end-users and service providers, networks have become highly complex; and so has become their lifecycle management. Recent advances in automation, data analysis, artificial intelligence, distributed ledger technologies (e.g., Blockchain), and data plane programming techniques have sparked the hope of the researchersâ community in exploring and leveraging these techniques towards realizing the much-needed vision of trustworthy self-driving networks (SelfDNs). In this vein, this article proposes a novel framework to empower fully distributed trustworthy SelfDNs across multiple domains. The framework vision is achieved by exploiting (i) the capabilities of programmable data planes to enable real-time in-network telemetry collection; (ii) the potential of P4 â as an important example of data plane programming languages â and AI to (re)write the source code of network components in a fashion that the network becomes capable of automatically translating a policy intent into executable actions that can be enforced on the network components; and (iii) the potential of blockchain and federated learning to enable decentralized, secure and trustable knowledge sharing between domains. A relevant use case is introduced and discussed to demonstrate the feasibility of the intended vision. Encouraging results are obtained and discussed.
Ao Xiong, Hongkang Tian, Wenchen He, Jie Zhang ¡ 9 authors
This paper proposes a smart grid distributed security architecture based on blockchain technology and SDN cluster structure, referred to as ClusterBlock model, which combines the advantages of two emerging technologies, blockchain and SDN. The blockchain technology allows for distributed peer-to-peer networks, where the network can ensure the trusted interaction of untrusted nodes in the network. At the same time, this article adopts the design of an SDN controller distributed cluster to avoid single point of failure and balance the load between equipment and the controller. A cluster head was selected in each SDN cluster, and it was used as a blockchain node to construct an SDN cluster head blockchain. By combining blockchain technology, the security and privacy of the SDN communication network can be enhanced. At the same time, this paper designs a distributed control strategy and network attack detection algorithm based on blockchain consensus and introduces the Jaccard similarity coefficient to detect the network attacks. Finally, this paper evaluates the ClusterBlock model and the existing model based on the OpenFlow protocol through simulation experiments and compares the security performance. The evaluation results show that the ClusterBlock model has more stable bandwidth and stronger security performance in the face of DDoS attacks of the same scale.