Hai Nam Nguyen, Hai Anh Tran, Scott Fowler, Sami Souihi
Abstract SoftwareâDefined Networking (SDN) brought a groundbreaking idea to facilitate network system management by decoupling and abstracting the Control plane and Data plane of traditional networks. The centralised control offers network administrators many benefits such as a global view of the network, programmability, dynamic updating of forwarding rules, and softwareâbased traffic analysis. The SDN architecture has been applied a lot in practice, and especially in Internet of Things (IoT) platforms. With the superiority of SDN, IoT devices can be managed and configured much more easily when combined. However, SDN also raises many challenges in terms of scalability, reliability, and security. Blockchain is another promising solution for secure information storage and transmission technology that operates without a centralised authority. Applying Blockchain technology into SDN can address some of the current issues of SDN by providing decentralised methods to authenticate exchanged network information. This study provides a comprehensive survey on Blockchain technologies applied to SDN in both security and nonâsecurity fields. First, related studies and an overview of SDN and the background of Blockchain technology are presented. Then, the authors review how Blockchain technologies are applied in SDN from two perspectives: nonâsecurity and securityâaware approaches. Finally, challenges and broader perspectives are discussed.
Phan The Duy, Hien Do Hoang, Do Thi Thu Hien, Anh Gia-Tuan Nguyen ¡ 5 authors
Software-Defined Network (SDN) is a new arising terminology of network architecture with outstanding features of orchestration by decoupling the control plane and the data plane in each network element. Even though it brings several benefits, SDN is vulnerable to a diversity of attacks. Abusing the single point of failure in the SDN controller component, hackers can shut down all network operations. More specifics, a malicious OpenFlow application can access to SDN controller to carry out harmful actions without any limitation owing to the lack of the access control mechanism as a standard in the Northbound. The sensitive information about the whole network such as network topology, flow information, and statistics can be gathered and leaked out. Even worse, the entire network can be taken over by the compromised controller. Hence, it is vital to build a scheme of access control for SDN's Northbound. Furthermore, it must also protect the data integrity and availability during data exchange between application and controller. To address such limitations, we introduce B-DAC, a blockchain-based framework for decentralized authentication and fine-grained access control for the Northbound interface to assist administrators in managing and protecting critical resources. With strict policy enforcement, B-DAC can perform decentralized access control for each request to keep network applications under surveillance for preventing over-privileged activities or security policy conflicts. To demonstrate the feasibility of our approach, we also implement a prototype of this framework to evaluate the security impact, effectiveness, and performance through typical use cases.
Network Function Virtualization (NFV) is considered to be a hopeful technology for supporting blockchain with many features like flexible networks and intelligent equipment. NFV decreases the expenses incurred on the maintenance and operation of assets that are generated through expenses, in addition to capital expenditures based on the isolate the physical devices from the main tasks executed by that equipment. Blockchain currency transfers or technology is the most powerful security tool that ensures the security of data. The prominent challenges in NFV are the processes of transition, vendor compatibility, network management, rapid growth, and security. The software industry and skills of networking are experiencing fast expansion and deployment of the Network Functions Virtualization (NFV) approach, jointly in blockchain and cloud networks. In this paper, a novel method is offered to virtualize the work of the blockchain based on the NFV with auto work of the smart contract between virtual nodes based on cloud computing. By blending NFV with Blockchain, all of the above-mentioned challenges have been overcome by moving to software environments through creating virtual nodes, as well as smooth interaction among them and managing the transactions between nodes and clients, indicating ideal network management. Through the proposed work, a throughput of up to 20% is obtained by applying NFV compared to not applying NFV to the blockchain. In addition, the costs of the hardware are eliminated and eventually a secure environment is used which distances the system from virtual attacks.
Operators of networks are striving to provide functional network-based services, while keeping the cost of deploying the service to a minimum. Network Function Virtualization (NFV) is considered to be a promising model to modify such employment by separating network functions from the basic hardware properties, after which they are converted into the style of software. These are eventually referred to as Virtual Network Functions (VNFs). This separation offers numerous benefits, including the decrease of Capital Expenditure (CAPEX) and Operation Expense (OPEX), in addition to the enhanced elasticity of service preparation. Network Functions Virtualization (NFV) is found to cause a remarkable development or even a technological revolution in terms of network-based services, leading to a decrease in deployment costs for network operators. NFV reduces hardware tool costs and energy exhaustion, and it improves its operational performance whereby the network configuration is part of this optimization. Even so, there are a number of possible security problems which are the main focus in NFV. The present study surveys the applications and opportunities of NFV in terms of IoT, SDN, cloud computing and blockchain. A description of the NFV architecture is presented, and several possibilities of NFV security issues and challenges are discussed. Finally, a systematic idea is provided on the design of a Blockchain Network Virtualization System.
The Internet of Things (IoT) and Blockchain distribution ledger technology as a concept is enchanting facilities and industrial developments with advanced implements in many applications. The IoT and Blockchain market is further expected to develop three times from current development by 2025. Though many IoT applications have major challenges in safest data transaction and scalability issues while increasing the number of IoT devices. Practical Byzantine Fault Tolerance (PBFT) is a widely used form of decentralized consent, however the network node's confidence in PBFT cannot be guaranteed, as well as the mechanism of reaching consensus will consume a large amount of network services. The article suggests the novel consensus process, which is referred to a Hybrid consensus blockchain algorithm and control authentication on Trust. The Internet of Things applications are integrated with a blockchainbased decentralized system that authenticates the IoT devices through distributed control authentication. This hybrid consensus blockchain method provides security for transactions and access to unauthorized devices is restricted. The PBFT algorithm using a decentralized network system using blockchain has no restriction of IoT devices. Even malicious users create the grouping into the network that has been controlled by the distributed control authentication method. Further then malicious users are rejected from the decentralized network. In this paper, we propose the Hybrid consensus blockchain and PBFT algorithm ensure the safest data transaction through blockchain technology and improves the performance of the decentralized network. Finally, we have presented a Hybrid Consensus algorithm to be utilized in the PBFT method which enables the safest data transaction.
IoT group communication allows users to control multiple IoT devices simultaneously. A convenient method for implementing this communication paradigm is by leveraging software-defined networking (SDN) and allowing IoT endpoints to âadvertiseâ the resources that can be accessed through group communication. In this paper, we propose a solution for securing this process by preventing IoT endpoints from advertising âfakeâ resources. We consider group communication using the constrained application protocol (CoAP), and we leverage Web of Things (WoT) Thing Description (TD) to enable resourcesâ advertisement. In order to achieve our goal, we are using linked-data proofs. Additionally, we evaluate the application of zero-knowledge proofs (ZKPs) for hiding certain properties of a WoT-TD file.
Marko Ĺ arac, Nikola PavloviÄ, NebojĹĄa BaÄanin, Fadi AlâTurjman ¡ 5 authors
Internet of Things and Blockchain are considered two major technologies. Lower latency and a higher linked system number provide greater flexibility for remote execution of Internet of Things (IoT) applications. It is no secret that IoT devices often have insufficient computing capacity (both in terms of processing power and storage requirements) to support robust protection and encryption algorithms. The Internet of Things is facing many challenges such as poor interoperability, security vulnerabilities, privacy, and lack of industry standards. Cyber-attacks on IoT devices can have an impact on energy trading privacy and security. This paper suggests a method for introducing a basic interface to an IoT deviceâs security gateway architecture along with Blockchain to provide decentralization and authentication. It adds much-needed anonymity and versatility to IoT infrastructure, which is currently lacking. The solution enhances the reliability of data sent to remote services by applying compatible cryptographic algorithms to it before sending it. The solutionâs benefits include compatibility with all IoT products and the ability to run any cryptographic algorithm on data that can be used for microgrid trading and can be initialized and securely transported over 5G or 6G network infrastructures. As a part of this work, a security procedure has been created that supports every cryptographic algorithm for all IoT devices in the network. In addition, the interface is guarded by the Blockchain technology which eliminates single control authority, records historical transactions performed by the IoT devices and provides a trust between devices.
Healthcare professionals and scholars have emphasized the need for IoT-based remote health monitoring services to track the health of the elderly. Such systems produce a large amount of data, necessitating the security and privacy of that data. On the other hand, Software Defined Networking (SDN) integration could be seen as a good solution to guarantee both flexibility and efficiency of the network which is even more important in the case of healthcare monitoring. Furthermore, Blockchain has recently been proposed as a game-changing tool that can be integrated into the Internet of Things (IoT) to have the optimal level of security and privacy. However, incorporating Blockchain into IoT networks, which rely heavily on patientsâ health sensors, is extremely difficult. In this paper, a secure Healthcare Monitoring System (HMS) is proposed with a focus on trust management issues. The architecture seeks to protect multiple healthcare monitoring system components and preserves patient privacy by developing a security interface where separate security modules can be integrated to run side by side to ensure reliable HMS. The security framework architecture we propose takes advantage of the blockchain technology as a secure and timely information back-end. STHM is a proposal that uses Software-Defined Networking (SDN) as the communication medium that allows users to access SDNâs different functional and security technologies and services. Simulation results show that the use of Blockchain for the SDN-based healthcare monitoring can ensure the desired flexibility and security for a very lightweight additional overhead.
Tooba Faisal, Mischa DĂśhler, Simone Mangiante, Diego LĂłpez
Infrastructure sharing is a widely discussed and implemented approach and is successfully adopted in telecommunications networks today. In practice, it is implemented through prior negotiated Service Level Agreements (SLAs) between the parties involved. However, it is recognised that these agreements are difficult to negotiate, monitor and enforce. For future 6G networks, resource and infrastructure sharing is expected to play an even greater role. It will be a crucial technique for reducing overall infrastructure costs and increasing operational efficiencies for operators. More efficient SLA mechanisms are thus crucial to the success of future networks. In this work, we present "BEAT", an automated, transparent and accountable end-to-end architecture for network sharing based on blockchain and smart contracts. This work focuses on a particular type of blockchain, Permissioned Distributed Ledger (PDL), due to its permissioned nature allowing for industry-compliant SLAs with stringent governance. Our architecture can be implemented with minimal hardware changes and with minimal overheads.
Adriana FernĂĄndezâFernĂĄndez, Michael De Angelis, Pietro G. Giardina, James C. Taylor ¡ 10 authors
To fully cope with the requirements of innovative 5G use cases, evolving business models and flexible networking scenarios spanning multiple administrative domains are envisioned. In this context, transparent and trusted frameworks that enable network service providers and infrastructure providers to advertise, negotiate and acquire, in real time, 5G resources and services, distributed over various geographical areas, are extremely valuable. To address this goal, emerging Distributed Ledger Technologies (DLTs) arise as well-suited solutions to ensure distributed security and trust, as well as effective and agile transaction management across the various parties involved in the 5G service chain implementation. Following this vision, this paper presents the design of a DLT-enabled Marketplace aimed to foster the secure trading of heterogeneous resources in dynamic 5G ecosystems. The performance of an initial implementation as proof-of-concept is also analyzed. The results of this proof-of-concept validate the feasibility of a decentralized marketplace implementation in the context of 5G resource trading.
TeraFlow proposes a new type of secure, cloud-native Software Defined Networking (SDN) controller that will radically advance the state-of-the-art in beyond 5G networks by introducing novel micro-services architecture, and provide revolutionary features for both flow management (service layer) and optical/microwave network equipment integration (infras-tructure layer) by adapting new data models. TeraFlow will also incorporate security using Machine Learning (ML) and forensic evidence for multi-tenancy based on Distributed Ledgers. Finally, this new SDN controller shall be able to integrate with the current Network Function Virtualization (NFV) and Multi-access Edge Computing (MEC) frameworks as well as to other networks. The target pool of TeraFlow stakeholders expands beyond the traditional telecom operators towards edge and hyperscale cloud providers.
With the advent of 5G verticals and the Internet of Things paradigm, Edge Computing has emerged as the most dominant service delivery architecture, placing augmented computing resources in the proximity of end users. The resource orchestration of edge clouds relies on the concept of network slicing, which provides logically isolated computing and network resources. However, though there is significant progress on the automation of the resource orchestration within a single cloud or edge cloud datacenter, the orchestration of multi-domain infrastructure or multi-administrative domain is still an open challenge. Towards exploiting the network service marketplace at its full capacity, while being aligned with ETSI Network Function Virtualization architecture, this article proposes a novel Blockchain-based service orchestrator that leverages the automation capabilities of smart contracts to establish cross-service communication between network slices of different tenants. In particular, we introduce a multi-tier architecture of a Blockchain-based network marketplace, and design the lifecycle of the cross-service orchestration. For the evaluation of the proposed approach, we set up cross-service communication in an edge cloud and we demonstrate that the orchestration overhead is less than other cross-service solutions.
Some Internet of Things (IoT) platforms use blockchain to transport data. The value proposition of IoT is the connection to the Internet of a myriad of devices that provide and exchange data to improve peopleâs lives and add value to industries. The blockchain technology transfers data and value in an immutable and decentralised fashion. Security, composed of both non-intentional and intentional risk management, is a fundamental design requirement for both IoT and blockchain. We study how blockchain answers some of the IoT security requirements with a focus on intentional risk. The review of a sample of security incidents impacting public blockchains confirm that identity and access management (IAM) is a key security requirement to build resilience against intentional risk. This fact is also applicable to IoT solutions built on a blockchain. We compare the two IoT platforms based on public permissionless distributed ledgers with the highest market capitalisation: IOTA, run on an alternative to a blockchain, which is a directed acyclic graph (DAG); and IoTeX, its contender, built on a blockchain. Our objective is to discover how we can create IAM resilience against intentional risk in these IoT platforms. For that, we turn to complex network theory: a tool to describe and compare systems with many participants. We conclude that IoTeX and possibly IOTA transaction networks are scale-free. As both platforms are vulnerable to attacks, they require resilience against intentional risk. In the case of IoTeX, DIoTA provides a resilient IAM solution. Furthermore, we suggest that resilience against intentional risk requires an IAM concept that transcends a single blockchain. Only with the interplay of edge and global ledgers can we obtain data integrity in a multi-vendor and multi-purpose IoT network.
As the next-generation network architecture, software-defined networking (SDN) has great potential. But how to forward data packets safely is a big challenge today. In SDN, packets are transferred according to flow rules which are made and delivered by the controller. Once flow rules are modified, the packets might be redirected or dropped. According to related research, we believe that the key to forward data flows safely is keeping the consistency of flow rules. However, existing solutions place little emphasis on the safety of flow rules. After summarizing the shortcomings of the existing solutions, we propose FRChain to ensure the security of SDN data forwarding. FRChain is a novel scheme that uses blockchain to secure flow rules in SDN and to detect compromised nodes in the network when the proportion of malicious nodes is less than one-third. The scheme places the flow strategies into blockchain in form of transactions. Once an unmatched flow rule is detected, the system will issue the problem by initiating a vote and possible attacks will be deduced based on the results. To simulate the scheme, we utilize BigchainDB, which has good performance in data processing, to handle transactions. The experimental results show that the scheme is feasible, and the additional overhead for network performance and system performance is less than similar solutions. Overall, FRChain can detect suspicious behaviors and deduce malicious nodes to keep the consistency of flow rules in SDN.
Shiva Kazemi Taskou, Mehdi Rasti, Pedro H. J. Nardelli
Network function virtualization (NFV) is a promising technology to make 5G networks flexible and agile. NFV decreases operatorsâ OPEX and CAPEX by decoupling the physical hardware from the functions they perform. In NFV, usersâ service request can be viewed as a service function chain (SFC) consisting of several virtual network functions (VNFs) which are connected through virtual links. Resource allocation in NFV is done through a centralized authority called NFV Orchestrator (NFVO). This centralized authority suffers from some drawbacks such as single point of failure and security. Blockchain (BC) technology is able to address these problems by decentralizing resource allocation. The drawbacks of NFVO in NFV architecture and the exceptional BC characteristics to address these problems motivate us to focus on NFV resource allocation to usersâ SFCs without the need for an NFVO. To this end, we assume there are two types of users: users who send SFC requests (SFC requesting users) and users who perform mining process (miner users). For SFC requesting users, we formulate NFV resource allocation (NFV-RA) problem as a multi-objective problem to minimize the energy consumption and utilized resource cost, simultaneously. To address this problem, we propose an Approximation-based Resource Allocation algorithm (ARA) using Majorization-Minimization approximation method to convexify NFV-RA problem. Furthermore, due to the high complexity of ARA algorithm, we propose a low complexity Hungarian-based Resource Allocation (HuRA) algorithm using Hungarian algorithm for server allocation. Through the simulation results, we show that our proposed ARA and HuRA algorithms achieve near-optimal performance with lower computational complexity. Also, ARA algorithm outperforms the existing algorithms in terms of number of active servers, energy consumption, and average latency. Moreover, the mining process is the foundation of BC technology. In wireless networks, mining is performed by resource-limited mobile users. Since the mining process requires high computational complexity, miner users cannot perform it alone. So, in this article, we assume that miner users can perform mining process with participating of other users. For mining process, the problem of minimizing the energy consumption and cost of usersâ processing resources is formulated as a linear programming problem that can be optimally solved in polynomial time.
As the most fundamental infrastructure in the current Internet, the Border Gateway Protocol (BGP) supports the inter-connectivity of different Autonomous Systems (ASs) and then the reachability can be achieved from any network in the Internet. However, due to the lack of security consideration during its original design, the BGP suffers from multiple security threats. Another challenge is that it cannot support the future sophisticated applications with deterministic routing. In this article, we propose a novel BGP management architecture, namely BGPChain, which is based on the blockchain in order to establish a secure, smart, and agile routing infrastructure for the future Internet.
Domain Name System (DNS) is a widely used infrastructure for remote control and batch management of IoT devices. As a critical Internet infrastructure, DNS is structured as a treeâlike hierarchy with single root zone authority at the top, which puts the operation of DNS at risk from single point of failure. The current root zone management is lack of transparency and accountability, since only the root zone file is published as the final outcome of operations inside the root zone authority. Towards distributed root zone operation in DNS, this paper presents a blockchainâbased root operation architectureâRootChain, composed of multiple root servers. On the basis of maintaining the single root authority for topâlevel domain (TLD), RootChain decentralizes TLD data publication by empowering delegated TLD authorities to publish authenticated data directly. The transparency and accountability of root zone operation are attained by smartâcontracting the whole life cycle of TLD operation and logging all operations on the chain. RootChain is transparent to recursive/stub resolver and DNS/DNSSECâcompatible. A proofâofâconcept prototype of RootChain has been implemented with Hyperledger Fabric and evaluated by experiments.
Abstract With assistance from Software Defined Networking (SDN) and Blockchain, networks have become more creative to build and maintain over the last few years. The inflexibility of modern network architecture is presenting researchers with a tough achievement. SDN replaces existing inescapable and complicated networks with a creative way of separating the control plane from the data plane and fixing those constraints, namely configurations done manually, monitoring, protection, usability, and functionality. This paper provides an overview of blockchain and SDN in healthcare. Various existing projects of their integration have been studied the benefits of the Blockchain provides security, privacy, integrity to the health care data has been discussed. The decentralization feature of blockchain provides access to data within and across the nation. Different use cases are discussed in the paper that provides the acceptability of blockchain and SDN in healthcare. This paper provides the overview and results that integration of blockchain and SDN in healthcare is a good research area and various initiatives have been taken to explore its integration.
In satellite communication systems, satellite power and processing capacities are limited, which means that storage and security are also constrained. Satellite communication channels are extremely vulnerable to hackers and external interference signals. Protecting satellite networks from illegal information access and use can be extremely challenging. In this paper, an architecture composed of satellite and ground equipment is developed that integrates communication network authentication and privacy protection structures. In the proposed scheme, the communication, registration, authentication, and revocation of information are achieved through stages to improve communication security. The satellite forwards the collected information to a ground base station, which has a strong data processing capacity. The ground base station records all the key parameters in the distributed blockchain, and all malicious node certificates are removed from the system. To further enhance data transmission security, the key is transferred using an asymmetric encryption algorithm. To measure the robustness of using the proposed network architecture, under the same attack condition, an invulnerability analysis is performed. After conducting simulation experiments, the results show that the proposed scheme greatly improves communication security and protection.
Multicontroller softwareâdefined networks have been widely adopted to enable management of largeâscale networks. However, they are vulnerable to several attacks including false data injection, which creates topology inconsistency among controllers. To deal with this issue, we propose BMCâSDN, a security architecture that integrates blockchain and multicontroller SDN and divides the network into several domains. Each SDN domain is managed by one master controller that communicates through blockchain with the masters of the other domains. The master controller creates blocks of network flow updates, and its redundant controllers validate the new block based on a proposed reputation mechanism. The reputation mechanism rates the controllers, i.e., block creator and voters, after each voting operation using constant and combined adaptive fading reputation strategies. The evaluation results demonstrate a fast and optimal detection of fraudulent flow rule injection.
Shahid Abbas, Nadeem Javaid, Ahmad Almogren, Sardar Muhammad Gulfam ¡ 6 authors
Internet of Things (IoT) is an emerging domain in which different devices communicate with each other through minimum human intervention. IoT devices are usually operated in hostile and unattended environments. Moreover, routing in current IoT architecture becomes inefficient due to malicious and unauthenticated nodesâ existence, minimum network lifetime, insecure routing, etc. This paper proposes a lightweight blockchain based authentication mechanism where ordinary sensorsâ credentials are stored. As IoT nodes have a short lifespan due to energy depletion, few credentials are stored in the blockchain to achieve lightweight authentication. Moreover, the route calculation is performed by a genetic algorithm enabled software defined network controller, which is also used for on-demand routing to optimize the energy consumption of the nodes in the IoT network. Furthermore, a route correctness mechanism is proposed to check the existence of malicious nodes in the calculated route. Moreover, a detection mechanism is proposed to restrict the malicious nodesâ activities, while a malicious nodeâs list is maintained in the blockchain, which is used in the route correctness mechanism. The proposed model is evaluated by performing intensive simulations. The effectiveness of the proposed model is depicted in terms of gas consumption, which shows the optimized utilization of resources. The residual energy of the network shows optimized route calculation, while the malicious node detection method shows the number of packets dropped.
Due to the simultaneous development of DC-microgrids (DC-MGs) and the use of intelligent control, monitoring and operation methods, as well as their structure, these networks can be threatened by various cyber-attacks. Overall, a typical smart DC-MG includes battery, supercapacitors and power electronic devices, fuel cell, solar Photovoltaic (PV) systems, and loads such as smart homes, plug-in hybrid electrical vehicle (PHEV), smart sensors and network communication like fiber cable or wireless to send and receive data. Given these issues, cyber-attack detection and securing data exchanged in smart DC-MGs like CPS has been considered by experts as a significant subject in recent years. In this study, in order to detect false data injection attacks (FDIAs) in a MG system, Hilbert-Huang transform methodology along with blockchain-based ledger technology is used for enhancing the security in the smart DC-MGs with analyzing the voltage and current signals in smart sensors and controllers by extracting the signal details. Results of simulation on the different cases are considered with the objective of verifying the efficacy of the proposed model. The results offer that the suggested model can provide a more precise and robust detection mechanism against FDIA and improve the security of data exchanging in a smart DC-MG.
Anichur Rahman, Md. Jahidul Islam, Antonio Montieri, Mostofa Kamal Nasir ¡ 10 authors
Software-Defined Networking (SDN) and Blockchain are leading technologies used worldwide to establish safe network communication as well as build secure network infrastructures. They provide a robust and reliable platform to address threats and face challenges such as security, privacy, flexibility, scalability, and confidentiality. Driven by these assumptions, this paper presents an optimized energy-efficient and secure Blockchain-based software-defined IoT framework for smart networks. Indeed, SDN and Blockchain technologies have proven to be able to suitably manage resource utilization and to develop secure network communication across the IoT ecosystem. However, there is a lack of research works that present a comprehensive definition of such a framework that can meet the requirements of the IoT ecosystem (i.e. efficient energy utilization and reduced end-to-end delay). Therefore, in this research, we present a layered hierarchical architecture for the deployment of a distributed yet efficient Blockchain-enabled SDN-IoT framework that ensures efficient cluster-head selection and secure network communication via the identification and isolation of rouge switches. Besides, the Blockchain-enabled flow-rules record keeps track of the rules enforced in the switches and maintains the consistency within the controller cluster. Finally, we assess the performance of the proposed framework in a simulation environment and show that it can achieve optimized energy-utilization, end-to-end delay, and throughput compared to considered baselines, thus being able to achieve efficiency and security in the smart network.