The 5th generation mobile network (5G) is designed with a new core architecture that makes it quite extensible. The components of the 5G core architecture are no longer physical standalone devices, but rather software processes run on commercial off-the-shelf (COTS) servers. The backbone of 5G is software-defined networking (SDN) and network function virtualization (NFV), and they both bring unprecedented flexibility to network and resource management. In this context, 5G logical networks can be created by partitioning a shared physical infrastructure, and each network can be customized and optimized for specific entity. This concept is known as 5G network slicing. Despite the tremendous benefits of network slicing, it also brings many unprecedented security challenges because of the dynamism and diversity of slice's structure. Therefore, establishing trust in the 5G ecosystem is a cornerstone for global adaptation and tackling security and privacy risks. In this paper, we focus on the trust aspect between the network slice stakeholders (i.e slice owners, users, slice resource providers, and service providers), and we propose a blockchain-based zero trust model that addresses threat models that are based on the lack of trust between the entities in a network slice. Our approach for zero trust modeling and quantification is based on direct evidence and indirect evidence and the use of smart contracts with blockchain to maintain the required trust values at runtime. We provide details on how to model and quantify the trust of all the stakeholders of a given network slice and how the blockchain smart contract can enforce the zero-trust requirements for all network slice stakeholders.
Network slicing has gained popularity as a result of the advances in the fifth generation (5G) mobile network. Network slicing facilitates the support of different service types with varying requirements, which brings into light the slicing-aware next generation mobile network architecture. While allowing resource sharing among multiple stakeholders, there is a long list of administrative negotiations among parties that have not established mutual trust. Distributed ledger technology may be a solution to mitigate the above issues by taking its decentralized yet immutable and auditable ledger, which may help to ease administrative negotiations and build mutual trust among multi-stakeholders. There have been many research interests in this direction which focus on handling various problems in network slicing. This paper aims at constructing this area of knowledge by introducing network slice from a standardization point of view to start with, and presenting security, privacy, and trust challenges of network slicing in 5G and beyond networks. Furthermore, this paper covers distributed ledger technologies basics and related approaches that tackle security, privacy, and trust threats in network slicing for 5G and beyond networks. The various proposals proposed in the literature are compared and presented. Lastly, limitations of current work and open challenges are illustrated as well.
Jing Song, Ya Kang, Qingyang Song, Lei Guo · 5 authors
Virtual reality-embedded digital twin (VR-DT) service integrates digital twin with virtual reality to visualize the digital representation of real-world production, boosting the digital transformation of manufacturing industry in the Industrial Internet of Things (IIoT). Balanced against the advantages of the VR-DT service, its data-driven, computing-intensive, and security-sensitive features bring challenges to the current IIoT. Therefore, we propose a blockchain-based distributed resource allocation scheme to improve the average Quality of Service (QoS) of the VR-DT services with regard to service delay and transaction throughput. We formulate the joint optimization of channel assignment, subframe configuration, computing capacity allocation, and block size adjustment as a mixed-integer nonlinear programming problem. A fully decentralized multiagent compound-action actor–critic algorithm is developed to solve the QoS optimization problem. Simulation results demonstrate that our proposed scheme can efficiently improve the average QoS of the VR-DT services in a realizable way as compared to existing schemes.
Eranga Bandara, Sachin Shetty, Ravi Mukkamala, Abdul Rahman · 7 authors
5G network slicing enables IoT networks to connect billions of heterogeneous objects providing high quality of service, high network capacity, and enhanced system throughput. It opens a new marketplace opportunity for cloud providers and network operators to sell portions of their networks to address specific customer needs in 5G applications. However, there are numerous open challenges to providing end-to-end slices due to complex business and engineering requirements from service and resource providers. To address these challenges, in this paper, we propose “Kaputa”, a blockchain-enabled network slice broker and NFT-enabled network slice marketplace. Here, different stakeholders such as cloud providers, network operators, RAN providers, and transport network providers can collaborate to rent their resources. Kaputa orchestrates the network slices with the help of blockchain smart contracts. The orchestrated network slices will be encoded as NFT tokens and published in the Kaputa NFT marketplace. Customers can purchase the network slices from the marketplace based on their 5G application requirements via paying crypto/fiat currency. The revenue will be distributed among different providers. The data provenance information of the network slices is encoded into Model Cards and stored in the blockchain ledger. A prototype of Kaputa has been implemented with FreedomFi and OpenAirInterface 5G core. To the best of our knowledge, this is the very first research that tries to represent 5G/6G network slices as NFTs. This design methodology provides enhanced transparency and auditability to the network slice orchestration process while providing an open platform to share and trade network slices in the marketplace.
Alexey Finogeev, Michael Deev, Данила Парыгин, Антон Финогеев
The article deals with the creation of an intelligent architecture of the Internet of Things transport environment based on software-defined network (SDN) and blockchain for detecting threats and attacks. The transport environment is created for the monitoring system of critical events in the road transport infrastructure. Blockchain technology is used to authenticate network nodes, store sensor data in a distributed ledger. The network packet clustering method based on a fuzzy neural network is used to detect packets with possible malicious content. The intelligent SDN architecture is a hierarchy of four layers with six levels and includes: a) edge computing layer (sensor nodes and routers level, SDN switches data level), b) fog computing layer (zone server level, control level in SDN controllers), c) a cloud computing layer with data center servers, d) a layer for presenting monitoring results on user devices and applications. Detection of threats and attacks is implemented by validating network nodes and analyzing header fields of IP packets and TCP segments. The intrusion detection system includes a parser and analyzer of data packets, a module for filtering traffic by type, port numbers and other characteristics of packets, a module for synthesizing digital signatures of trusted nodes and their validation, a module for analyzing and clustering packets based on fuzzy logic and a neural network, modules for logging procedures. The probability function of packets belonging to clusters is tuned through deep learning of a five-layer neural network. The conclusion about belonging and degree of similarity with malicious packages is formed using the fuzzy logic apparatus. To train the neural network, the previously synthesized rules of the flow tables and the identified signs of atypical data packets are used. The functionality and effectiveness of the SDN architecture with an intrusion detection system is validated by simulating procedures in the NS3 Simulator system, evaluating authenticity, latency, throughput, response time, and accuracy in detecting atypical data packets.
Presently, trillions of Internet of Things (IoT) devices are in use, with many more projected to join IoT networks in the future. These IoT devices create a massive volume of data, which cannot be transmitted over the network without proper security and privacy. Furthermore, as the amount of information and variety of interconnected devices grows, problems, including excessive response time, bandwidth constraints, and scalability, emerge in proper network design. To solve the constraints of today’s smart cities for next-generation networks, an effective, secure, and scalable distributed framework must be designed bringing computing and storage resources nearer to endpoints. In this article, combining the strengths of software-defined networks (SDNs) and blockchain technology, an innovative adaptable network infrastructure for smart cities is developed. The network is divided into different domains in which SDN will detect potential attacks and transmit the secured data to the blockchain. Our in-depth experimental analysis on performance evaluation show that the proposed framework achieves 12.75% improvement over baseline methodologies.
Mizna Khalid, Sufian Hameed, Abdul Qadir, Syed Attique Shah · 5 authors
Access control is essential for the IoT environment to ensure that only approved and trusted parties are able to configure devices, access sensor information, and command actuators to execute activities. The IoT ecosystem is subject to various access control complications due to the limited latency between IoT devices and the Internet, low energy requirements of IoT devices, the distributed framework, ad-hoc networks, and an exceptionally large number of heterogeneous IoT devices that need to be managed. The motivation for this proposed work is to resolve the incurring challenges of IoT associated with management and access control security. Each IoT domain implementation has particular features and needs separate access control policies to be considered in order to design a secure solution. This research work aims to resolve the intricacy of policies management, forged policies, dissemination, tracking of access control policies, automation, and central management of IoT nodes and provides a trackable and auditable access control policy management system that prevents forged policy dissemination by applying Software Defined Network (SDN) and blockchain technology in an IoT environment. Integration of SDN and blockchain provides a robust solution for IoT environment security. Recently, smart contracts have become one of blockchain technology’s most promising applications. The integration of smart contracts with blockchain technology provides the capability of designing tamper-proof and independently verifiable policies. In this paper, we propose a novel, scalable solution for implementing immutable, verifiable, adaptive, and automated access control policies for IoT devices together with a successful proof of concept that demonstrates the scalability of the proposed solution. The performance of the proposed solution is evaluated in terms of throughput and resource access delay between the blockchain component and the controller as well as from node to node. The number of nodes in the IoT network and the number of resource access requests were independently and systematically increased during the evaluations. The results illustrate that the resource access delay and throughput were affected neither linearly nor exponentially; hence, the proposed solution shows no significant degradation in performance with an increase in the number of nodes and/or requests.
This paper presents an inter-domain transport net-work slice management with Service Level Agreements (SLA) using the ETSI TeraFlowSDN (TFS) controller. Different instances of the TFS controller are deployed for each involved domain. The communication between the TFS instances is supported by a Distributed Ledger Technology (DLT)-based database. The different TFS instances upload the abstracted view of their topologies and retrieve that from remote peers. When the end- to-end SLA of the transport network slice is violated, the slice is reconfigured avoiding the domain that originated the violation.
In current IPv6 networks, the increasing number of network devices also boosts the widespread DDoS attacks. Meanwhile, Intrusion Detection System (IDS) is evolved from the individual defense pattern to a distributed and collaborative mode, and Cooperative IDS (CIDS) becomes the mainstream technique. How to improve the overall defense capability through the coordination of information becomes worth studying. In this paper, we propose a DDoS blacklist mechanism with smart contract for IPv6-SAVI (Source Address Validation Improvements) network. In SAVI environment, DDoS source information detected by IDS is considered to be credible. Based on this observation, we design a dynamic update strategy for the reputation of trusted addresses based on the detection results and form a blacklist. Furthermore, we combine CIDS deployment with blockchain to design a blacklist sharing strategy based on smart contract, so that the individual IDS distributed on the chain can realize safe and reliable sharing and updating of the blacklist. Finally, extensive experiments evaluate the performance of our mechanism in terms of latency, overhead, reputation change accuracy, etc., which demonstrates that the blacklist can provide DDoS traffic filtering reference to improve the DDoS mitigation capability.
DC microgrids with distributed architectures inevitably encounter the threats of communication constraints and cyber attacks, and there is little research to address these two communication irregularities simultaneously. To provide DC microgrids with maximum resistance to communication constraints and cyber attacks, a distributed predictive secure control method based on blockchain protocol is proposed in this paper. The proposed control approach is the first attempt to address cyber attacks with a hybrid of data and models, improving the resilience and robustness of DC microgrids. With the help of practical Byzantine ideas, the proposed strategy preserves the resilience strengths of the blockchain against corruption and discards its shortcomings of low real-time performance, significantly enhancing the security without compromising the dynamic performance of the system by active intervention. Subsequently, a bound on the communication delay induced by the blockchain network under the expected security index is given based on the theoretical analysis. Unlike the existing practice of passively tolerating communication delays and packet dropouts, the predictive control method proposed in this paper actively compensates for them experienced by DC microgrids. Then, an analytical model of the closed-loop DC microgrid system is developed, and stability analysis is presented accordingly. Finally, several experimental tests performed on a PV-based DC microgrid hardware system are presented to demonstrate the effectiveness of the proposed control strategy.
Digitization in the power industry enables wide connectivity among multiple new entrants such as DERs, prosumers, and P2P counterparts within or outside the Distributed Ledger Technology (DLT). The use of DLT to improve resilience in the power grid has growing support, but new technology provides new opportunities for adversaries to cause harm. This work completed by the Cybersecurity focused task force of IEEE SA P2418.5 evaluates the potential risks by applying the MITRE ATT&CK ICS matrix to the DLT Engineering and Cybersecurity Stack designed for power systems applications.
The high energy consumption of proof of work-based distributed ledgers has become an important environmental concern. Bitcoin, for example, consumes as much energy in a year as a developed country. Alternative consensus mechanisms, such as proof of stake, have been shown to use drastically less energy than proof of work-based DLTs. For example, the IOTA DLT, built upon a directed acyclic graph (DAG) architecture, uses an alternative consensus mechanism that requires significantly less energy than other DLTs. Because the (DLT) space is constantly and rapidly evolving, the question of how much energy DLTs actually consume demands to be continuously studied and answered. Previous research into the energy consumption of the IOTA network has shown that an optimization in the overall protocol correlates to an optimization in energy consumption. The planned IOTA 2.0 update, built upon the GoShimmer research prototype, promises to further optimize the protocol by removing the network's centralized Coordinator. This report presents the results of measuring the energy consumption of a private GoShimmer network while comparing these findings to previous research into the current mainnet, which is called Chrysalis. The main findings of this report are that the IOTA 2.0 research prototype shows both improvements and increase in the energy consumption metrics compared to the Chrysalis network. Additionally, this report defines a model to estimate the total annual energy consumption of an IOTA network. This model should be significant for future research as it enables a way to estimate the total cost of running the IOTA network as well as its carbon emissions. Moreover, having an annual power consumption metric allows for better objective comparisons to different DLTs.
Javier José Díaz Rivera, Talha Ahmed Khan, Waleed Akbar, Muhammad Afaq · 5 authors
In the current digitalized world, the number of interconnected entities is constantly growing. Users and devices are no longer confined to the same physical or geographical region when participating in network connections. Due to this, the line that delimits the network perimeter can no longer be identified. Traditional castle-and-moat security approaches cannot accommodate the latent threats that may occur in these borderless network deployments. Zero Trust Networking, alongside Software Defined Perimeter (SDP) concepts, aims to extend the perimeter of trust to every entity connected to the network regardless of their physical location. Authentication, access control, and verification methods must constantly be applied for all the participants in the network, as everything is considered untrustworthy. The requirement of complex security mechanisms alongside constant trust assurance for every interaction may challenge the realization of the Zero Trust vision. Blockchain is an emergent technology that can be integrated into Zero Trust to leverage these requirements. The data decentralization, anonymity, cryptography, and immutable record of transactions can provide the required security for Zero Trust. In this work, we propose a mechanism for assuring secure service session management with the use of blockchain capabilities. Non-Fungible-Tokens (NFT) are applied to access and provider tokens representing a policy agreement for service consumption. The tokens are mapped to the public addresses of entities registered in the blockchain. The access and provider tokens are encoded with metadata defining the service sessions' expiration. The proposal is realized through the use of an emerging open source Zero Trust platform (OpenZiti), a private Ethereum blockchain (Hyperledger Besu), and a session manager decentralized application (ZT&T) for handling the creation of policies and blockchain interaction.
Sasikumar Asaithambi, Logesh Ravi, Hossam Kotb, Ahmad H. Milyani · 8 authors
The number of unsecured and portable Internet of Things (IoT) devices in the smart industry is growing exponentially. A diversity of centralized and distributed platforms have been implemented to defend against security attacks; however, these platforms are insecure because of their low storage capacities, high power utilization, single node failure, underutilized resources, and high end-to-end delay. Blockchain and Software-Defined Networking (SDN) are growing technologies to create a secure system and to ensure safe network connectivity. Blockchain technology offers a strong and trustworthy foundation to deal with threats and problems, including safety, privacy, adaptability, scalability, and security. However, the integration of blockchain with SDN is still in the implementation phase, which provides an efficient resource allocation and reduced latency that can overcome the issues of industrial IoT networks. We propose an energy-efficient blockchain-integrated software-defined networking architecture for Industrial IoT (IIoT) to overcome these challenges. We present a framework for implementing decentralized blockchain integrated with SDN for IIoT applications to achieve efficient energy utilization and cluster-head selection. Additionally, the blockchain-enabled distributed ledger ensures data consistency throughout the SDN controller network and keeps a record of the nodes enforced in the controller. The simulation result shows that the proposed model provides the best energy consumption, end-to-end latency, and overall throughput compared to the existing works.
Zhenni Li, Wensheng Su, Minrui Xu, Rong Yu · 6 authors
Dynamic off-chain routing in payment channel network (PCN)-based Internet of Things (IoT) is attracting increasing research attention. However, there are two major issues in dynamic routing in PCN-based IoT with resource-limited devices. The first issue is how to achieve high long-term transaction efficiency in PCN with dynamic channel capacities. The second issue is how to achieve a lightweight routing algorithm deployed on IoT devices while achieving high transaction efficiency, i.e., successful payment amount and success ratio. Therefore, in this paper, we propose a compact deep reinforcement learning (DRL) algorithm to learn the joint dynamic and lightweight routing policy for maximizing long-term transaction efficiency. To obtain optimal performance in dynamic routing problems for off-chain systems, a proximal policy optimization algorithm is employed to create an actor–critic learning structure for training the teacher DRL model. To obtain a compact and efficient student DRL model, an adaptive pruning technique is utilized for pruning unnecessary parameters of networks in the teacher model adaptively without affecting its learning ability. Furthermore, knowledge distillation is leveraged to improve the performance of the student network. Thus, a compact and efficient student DRL model can be developed and implemented to maximize the long-term transaction efficiency in off-chain systems on resource-limited IoT devices. The simulation results demonstrate that the proposed DRL algorithm outperforms the other baseline algorithms in PCN transaction efficiency while requiring only 10% of the computation and storage resources compared with that of the original teacher model.
Georgios Fragkos, Jay Johnson, Eirini Eleni Tsiropoulou
A global transition to power grids with high penetrations of renewable energy generation is being driven in part by rapid installations of distributed energy resources (DER). New DER equipment includes standardized IEEE 1547-2018 communication interfaces and proprietary communications capabilities. Interoperable DER provides new monitoring and control capabilities. The existence of multiple entities with different roles and responsibilities within the DER ecosystem makes the Access Control (AC) mechanism necessary. In this paper, we introduce and compare two novel architectures, which provide a Role-Based Access Control (RBAC) service to the DER ecosystem’s entities. Selecting an appropriate RBAC technology is important for the RBAC administrator and users who request DER access authorization. The first architecture is centralized, based on the OpenLDAP, an open source implementation of the Lightweight Directory Access Protocol (LDAP). The second approach is decentralized, based on a private Ethereum blockchain test network, where the RBAC model is stored and efficiently retrieved via the utilization of a single Smart Contract. We have implemented two end-to-end Proofs-of-Concept (PoC), respectively, to offer the RBAC service to the DER entities as web applications. Finally, an evaluation of the two approaches is presented, highlighting the key speed, cost, usability, and security features.
Eder J. Scheid, Muriel Figueredo Franco, Fabian Kuffer, Niels Kubler · 6 authors
Network Functions Virtualization (NFV) has been a key part of evolving communication systems in the last few years. However, the life-cycle management of Virtual Network Functions (VNF) is still a not trivial task. Blockchains (BC), due to their decentralization and immutability characteristics, together with the automation provided by Smart Contracts (SC), can be employed to enable such automated and trustworthy VNF management.Thus, this paper proposes VeNiCE to automate the deployment and life-cycle management of VNFs using events emitted on SCs. VeNiCE provides automation and auditability by relying on a BC to provide a decentralized approach for VNF management, which performs management actions, such as VNF deployment and deletion, and based on events and communicates with an SC to provide immutable logging of the VNF life-cycle. VeNiCE provides (i) a frontend for user interaction, (ii) a backend implementing the communication with the NFV framework, and (iii) an SC that emits events, stores VNF allocations, and authenticates users. A prototype of VeNiCE was developed and deployed in the Ethereum BC using OpenStack Tacker as an NFV platform. Experiments were conducted in a real-world deployment of such a prototype to analyze the economic costs of using SCs and the time required to process requests by each component of VeNiCE and the BC. Those results obtained show VeNiCE’s feasibility, highlight its benefits achieved with the automation and provide insights on reducing costs by exploring additional BC platforms and different deployment types, which introduce centralization and management concerns.
Saurabh Singh, C. Rajesh Babu, Kadiyala Ramana, In-Ho Ra · 5 authors
Fifth-generation (5G) technology is anticipated to allow a slew of novel applications across a variety of industries. The wireless communication of the 5G and Beyond-5G (B5G) networks will accommodate a wide variety of services and user expectations, including intense end-user connectivity, sub-1 ms delay, and a transmission rate of 100 Gbps. Network slicing is envisioned as an appropriate technique that can meet these disparate requirements. The intrinsic qualities of a blockchain, which has lately acquired prominence, mean that it is critical for the 5G network and B5G networks. In particular, the incorporation of blockchain technology into B5G enables the network to effectively monitor and control resource utilization and sharing. Using blockchain technology, a network-slicing architecture referred to as the Blockchain Consensus Framework is introduced that allows resource providers to dynamically contract resources, especially the radio access network (RAN) schedule, to guarantee that their end-to-end services are effortlessly executed. The core of our methodology is comprehensive service procurement, which offers the fine-grained adaptive allocation of resources through a blockchain-based consensus mechanism. Our objective is to have Primary User-Secondary User (PU-SU) interactions with a variety of services, while minimizing the operation and maintenance costs of the 5G service providers. A Blockchain-Enabled Network Slicing Model (BENS), which is a learning-based algorithm, is incorporated to handle the spectrum resource allocation in a sophisticate manner. The performance and inferences of the proposed work are analyzed in detail.
James Lembke, Srivatsan Ravi, Pierre-Louis Roman, Patrick Eugster
Software-defined wide area networking (SD-WAN) enables dynamic network policy control over a large distributed network via network updates . To be practical, network updates must be consistent (i.e., free of transient errors caused by updates to multiple switches), secure (i.e., only be executed when sent from valid controllers), and reliable (i.e., function despite the presence of faulty or malicious members in the control plane), while imposing only minimal overhead on controllers and switches. We present SERENE: a protocol for se cure and re liable ne twork updates for SD-WAN environments. In short: Consistency is provided through the combination of an update scheduler and a distributed transactional protocol. Security is preserved by authenticating network events and updates, the latter with an adaptive threshold cryptographic scheme. Reliability is provided by replicating the control plane and making it resilient to a dynamic adversary by using a distributed ledger as a controller failure detector. We ensure practicality by providing a mechanism for scalability through the definition of independent network domains and exploiting the parallelism of network updates both within and across domains. We formally define SERENE’s protocol and prove its safety with regards to event-linearizability. Extensive experiments show that SERENE imposes minimal switch burden and scales to large networks running multiple network applications all requiring concurrent network updates, imposing at worst a 16% overhead on short-lived flow completion and negligible overhead on anticipated normal workloads.