Network slicing in a 6G environment is an important research area in the current years. However, satisfying the demands of network slice requests is a challenging task. Energy-efficient, secure, and Quality of Service (QoS) aware network slicing is important since network slices must share fewer amounts of resources. Further, implementing secure network slicing for software-defined networks (SDNs)/network function virtualization (NFV) is crucial. In this article, we tackle the issues, such as security, QoS, and resource consumption issues through network slicing and load balancing mechanisms in SDN/NFV assisted 6G environments. First, deep network slicing is implemented using generative adversarial network (GAN) for network slicing and management. Based on the slice capacity, slice priority, and QoS demands of network slices, GAN predicts the appropriate slice and links for data transmission. For each slice, the directed acyclic graph (DAG)-based blockchain technology is used in which traditional consensus is replaced by the Proof of Space (PoS) algorithm. A limitation of scalability and high resource consumption in the traditional blockchain is addressed in DAG-blockchain. To improve security, context-based authentication, and secure handover schemes are presented using the Markov decision making (MDM) and weighted product model, respectively. Then, higher load faced at the SDN controllers and switches are addressed by intruder packets classification and packets migration through hybrid neural decision tree (HyDNT) and Hybrid Political optimizer with a Heap-based Optimizer (HPoHO), respectively. To predict the load accurately, environment learning is implemented using the soft actor-critic (SAC) algorithm. Finally, the performance of the proposed SliceBlock model is evaluated.
Sultan Algarni, Fathy Eassa, Khalid Ali Almarhabi, Abdullah Algarni · 5 authors
Software-defined networking (SDN) has emerged as a flexible and programmable network architecture that takes advantage of the benefits of global visibility and centralized control over a network. One of the main properties of the SDN architecture is the ability to offer a northbound interface (NBI), which enables network applications to access the SDN controller resources. However, the NBI can be compromised by a malicious application due to the lack of standardization and security aspects in the most current NBI designs. Therefore, in this paper, we propose a novel comprehensive security solution for securing the applicationâcontroller interface, named BCNBI. We propose a controller-independent lightweight blockchain architecture and exploit the security features of blockchain while limiting the blockchainâs computational overhead. BCNBI automatically verifies application and SDN controller credentials through token-based authentication. The proposed solution enforces fine-grained access control for each applicationâs API request and classifies the permission set into strict and normal policies, in order to add an extra level of security. In addition, the trustworthiness of applications is evaluated in order to prevent malicious activities. We implemented our blockchain-based solution to analyze its security, based on the confidentialityâintegrityâavailability model criteria, and evaluated the introduced overhead in terms of processing time and packet overhead. The experimental results demonstrate that the BCNBI can effectively secure the NBI, based on the fundamental security goals, while introducing insignificant overhead.
Blockchain was always associated with Bitcoin, cryptocurrencies, and digital asset trading. However, its benefits are far beyond that. It supports technologies like the Internet-of-Things (IoT) to pave the way for futuristic smart environments, like smart homes, smart transportation, smart energy trading, smart industries, smart supply chains, and more. To enable these environments, IoT devices, machines, appliances, and vehicles, need to intercommunicate without the need for centralized trusted parties. Blockchain replaces these trusted parties in such trustless environments. It provides security enforcement, privacy assurance, authentication, and other key features to IoT ecosystems. Besides IoT-Blockchain integration, other technologies add more benefits that attract the research community. Software-Defined Networking (SDN), Fog, Edge, and Cloud Computing technologies, for example, play a key role in enabling realistic IoT applications. Moreover, the integration of Artificial Intelligence (AI) provides smart, dynamic, and autonomous decision-making capabilities for IoT devices in smart environments. To push the research further in this domain, we provide in this paper a comprehensive survey that includes state-of-the-art technological integration, challenges, and solutions for smart environments, and the role of these technologies as the building blocks of such smart environments. We also demonstrate how the level of integration between these technologies has increased over the years, which brings us closer to the futuristic view of smart environments. We further discuss the current need to provide general-purpose Blockchain platforms that can adapt to unique design requirements of different applications and solutions. Finally, we provide a simplified architecture of futuristic smart environments that integrate these technologies, showing the advantage of such integration.
HongâNing Dai, Yulei Wu, Muhammad Imran, Nidal Nasser
Space-air-ground-sea integrated networks (SAGSINs) are promising to offer ubiquitous Internet services across the globe while confronting research challenges such as security vulnerabilities, privacy leakage concerns, and difficulty in resource sharing. On one hand, emerging network slicing and network softwarization technologies can fulfill diverse requirements with the provision of various services on top of heterogeneous SAGSIN hardware and software resources. On the other hand, blockchain and smart contracts can compensate for network slicing and softwarization to offer secure and automatic network services. This article presents an investigation on the convergence of blockchains with network slicing and network softwarization technologies for SAGSINs from the perspectives of network management and brokerage services of SAGSINs. In contrast to existing studies, this article is the first to incorporate blockchains into network slicing and network softwarization dedicated for SAGSINs. This article starts with a summary of key characteristics and challenges of SAGSINs. Then a review of network slicing and network softwarization is given in the context of SAGSINs. This article next presents an integrated framework of network slicing, network softwarization, and blockchain for SAGSINs. Moreover, this article outlines a set of open issues and research challenges that would be useful to guide future research in this area.
The Internet of Things (IoT) aims to create a digital world where any information system can expose, discover, understand and consume data and services for analysis, diagnosis, decision support and task automation in various domains such as healthcare, transportation, energy, industry, agriculture, etc. Faced with this diversity of applications and rapid evolution, infrastructures must be able to achieve high levels of security and confidentiality while being open, sustainable, and agile to adapt to the multiple requirements of applications. To meet these needs, new paradigms are emerging. These include the Software Defined Networks (SDN) paradigm, which offers the ability to dynamically program different applications and devices to provide end-to-end service chains. In parallel, the Blockchain paradigm is increasingly used in the Internet of Things, making distributed transactions between connected objects such as financial transactions or "smart contracts" possible. Although the combination of these two paradigms (Blockchain/SDN) is a major issue for the success of the Internet of Things, paving the way for new business models and management/control of communication networks, there is not yet a specified/formalized architecture allowing the use of the "Blockchain" in SDN. In this research, a new architecture for a system combining blockchain and SDN for IoT security is proposed
Vehicular Ad-hoc networks (VANETs) during the communication process, nodes are always varying and the process is always under security threats like Sybil attacks, masquerading attacks, etc. In order to reduce the probability of these attacks and to regulate traffic flow in the network, a software-defined network (SDN) is used. The SDN is used for implementing protocols like OpenFlow and reducing the routing load in the network, but it doesnât provide a high level of security to the network, hence protocols like encryption, hashing, etc. are applied to the VANET. In the paper, SDN based blockchain-inspired algorithm is implemented, which coordinates network traffic and improves the overall security of the network. Security analysis of the proposed algorithm shows that the combination of blockchain with encrypted SDN is removing more than 95% of the network attacks as compared to its non-blockchain counterparts.
Networked control systems (NCSs) are widely used in practical applications because of their flexibility in deployment. However, due to the dependence on the communication network, NCSs could be vulnerable to malicious cyberattacks. To address this problem, a novel blockchain technology-assisted networked predictive secure control approach is presented for the first time in this article. First, the introduction of blockchain technology brings a significant boost to the inherent resilience of the NCS in an active manner without relying on any prior knowledge of the system or potential attacks. However, blockchain technology would induce time delays unfavorable to the NCS, which could result in the low real-time performance of the control system. Subsequently, a networked Kalman filter-based predictive control is specially designed to compensate for the low real-time property of blockchain technology. A detailed analysis of the security and stability of the closed-loop NCS with the developed networked predictive secure controller is also presented, while sufficient conditions for the closed-loop system to be simultaneously stable and safe in a probabilistic sense are given. Finally, to verify the performance of the proposed approach in terms of practicality, an experimental prototype of a photovoltaic (PV)-based power generation system subjected to random cyber-attacks is built for voltage regulation.
Deploying multi-domain network services is becoming a need for operators. However, achieving that in a real operational environment is not easy and requires the use of federation. Federation is a multi-domain concept that enables the use and orchestration of network services/resources to/from external administrative domains. In this article, we first characterize the federation concept and involved procedures, and then dive into the challenges that emerge when federation is performed in dynamic environments. To tackle these challenges, we propose the application of blockchain technology, identifying some associated high-level benefits. Last, we validate our proposed approach by conducting a small experimental scenario using Tendermint, an application-based blockchain.
Wenjuan Li, Yu Wang, Weizhi Meng, Jin Li · 5 authors
To safeguard critical services and assets in a distributed environment, collaborative intrusion detection systems (CIDSs) are usually adopted to share necessary data and information among various nodes, and enhance the detection capability. For simplifying the network management, software defined networking (SDN) is an emerging platform that decouples the controller plane from the data plane. Intuitively, SDN can help lighten the management complexity in CIDSs, and a CIDS can protect the security of SDN. In practical implementation, trust management is an important approach to help identify insider attacks (or malicious nodes) in CIDSs, but the challenge is how to ensure the data integrity when evaluating the reputation of a node. Motivated by the recent development of blockchain technology, in this work, we design BlockCSDN â a framework of blockchain-based collaborative intrusion detection in SDN, and take the challenge-based CIDS as a study. The experimental results under both external and internal attacks indicate that using blockchain technology can benefit the robustness and security of CIDSs and SDN.
Pol Alemany, Ricard Vilalta, RaĂŒl Muñoz, Ramon Casellas · 5 authors
Data center (DC) interconnection allows us to have optical transmissions between DCs directly connected to optical networks, avoiding the use of a packet-based infrastructure. Thanks to the use of next-generation pluggable coherent optics, it is possible to create connectivity services (CSs) across multiple optical transport domains. In this multi-domain CS scenario, cloud operators and transport operators have to work together in the most dynamic way possible. To do so, they need a common place (i.e., a market) where the transport operators may expose their available optical resources and the cloud operators request (e.g., rent) them to be used in order to create end-to-end (E2E) CSs between DCs. Having multiple transport operators exposing their resource information in a common place requires a set of common rules (i.e., how much of the topology to show) to create E2E CSs requested between cloud operators. This paper makes use of the blockchain technology to present a blockchain-based extension for the software-defined network (SDN) architecture to allow each optical transport operator domain to become a peer in a blockchain network. In there, each peer follows the same rules and shares the same exact level of topology information by using a specific abstraction model to map the optical domain resources. This paper uses a set of three different abstraction models to validate their behavior on a blockchain system when managing multiple domain resources and the deployment of CSs across these domains. To do so, an experimental comparison on how the different abstraction models affect the performance of the blockchain system is presented.
Compared with the classical structure with only one controller in software-defined networking (SDN), multi-controller topology structure in SDN provides a new type of cross-domain forwarding network architecture with multiple centralized controllers and distributed forwarding devices. However, when the network includes multiple domains, lack of trust among the controllers remains a challenge how to verify the correctness of cross-domain forwarding behaviors in different domains. In this paper, we propose a novel secure multi-controller rule enforcement verification (BlockREV) mechanism in SDN to guarantee the correctness of cross-domain forwarding. We first adopt blockchain technology to provide the immutability and privacy protection for forwarding behaviors. Furthermore, we present an address-based aggregate signature scheme with appropriate cryptographic primitives, which is provably secure in the random oracle model. Moreover, we design a verification algorithm based on hash values of forwarding paths to check the consistency of forwarding order. Finally, experimental results demonstrate that the proposed BlockREV mechanism is effective and suitable for multi-controller scenarios in SDN.
The decoupling of the data plane and the control plane in the Software- Defined Network (SDN) can increase the flexibility of network management and operation. And it can reduce the network limitations caused by the hardware. However, the centralized scheme in SDN also can introduce some other security issues such as the single point of failure, the data consistency in multiple-controller environment and the spoofing attack initiated by a malicious device in the data plane. To solve these problems, a security framework for SDN based on Blockchain (BCSDN) is proposed in this paper. BCSDN adopts a physically distributed and logically centralized multi-controller architecture. LLDP protocol is periodically used to obtain the link state information of the network, and a Merkle tree is establised according to the collected link information and the signature is generate based on KSI for each link that submitted by a switch by the main controller selected by using the PoW mechanism. Such, the dynamic change of network topology is recorded on Blockchian and the consistency of the topology information among multiple controllers can be guaranteed. The main controller issues the signature to the corresponding switch and a controller checks the legitimate of a switch by verifying the signature when it requests the flow rule table from the controller later. The signature verification ensures the authenticated communication between a controller and a switch. Finally, the simulation of the new scheme is implemented in Mininet platform that is a network emulation platform and experiments are done to verify our novel solution in our simulation tool. And we also informally analysis the security attributes that provided by our BCSDN.
Telecom operators are deploying the fifth generation (5G) networks around the world which promises high information transmission rate, wide network coverage, low communication delay, and easy access to a large number of devices. However, during the construction and operation of 5G, telecom operators face many challenges, such as insufficient frequency resources, low efficiency of network management, information opacity, risks of data interoperability, and network privacy vulnerabilities. As 5G is generally deployed in heterogeneous networks with massive ubiquitous devices, it is quite necessary to provide secure and decentralized solutions. Blockchain is a distributed system maintained by multiple parties with inherit features including decentralization, traceability and tamperproof. These features collectively contribute to a new application ecosystem where transactions are secure and trustworthy. Therefore, blockchain is expected to integrate with 5G networks to build safer and more reliable mobile network infrastructures. This paper firstly discusses the merits of blockchain technology and the benefits of integrating it with 5G networks. Then a variety of applications of blockchain technology in telecom network operation are reviewed, including spectrum sharing, international roaming settlement, network operation management, number selection management and supply chain management. In the end, we show our recently advance in integrating blockchain in 5G by introducing a multi framework based blockchain service network architecture deployed in real environment.
With the rapid development of the IoT (Internet-of-Things), additional smart gadgets may be associated with the Internet, significantly enhancing data transfer and communication. Software-Defined Networking (SDN) is known as a new model that separates the control plane and the data plane, and is anticipated as a favorable solution for implementing Blockchain, to offer the scalability and adaptability required for IoT. The scalability of the network rises in direct proportion to the usersâ enhanced privacy on the network. Blockchain and SDN are two top innovations utilized to create secure network architectures and provide trustworthy data transmission. They offer a strong and trustworthy platform to deal with dangers and problems, including security, privacy, adaptability, scalability, and secrecy. Unfortunately, the attackers can still inject traffic to disrupt a blockchain nodeâs regular functions. This study provides an optimized Blockchain-based SD IoT architecture for smart networks that is safe and energy-efficient. In this work, it is concentrated on blockchain-based SDN and creates an SDN-Blockchain Classifier. This IDS-based security tool provides a trust-based classifier by handling and reducing harmful traffic through traffic fusion and aggregation. Finally, it is concluded by evaluating the proposed framework SDN-Blockchain Classifier performance against MAC flooding attack in a simulation setting and demonstrating that it can attain optimized average throughput, response time, packet loss of crossing domain path, energy efficiency, end-to-end delay, file transfer operation, energy consumption, and CPU utilization compared to the baselines taken into consideration, thereby achieving efficacy and also security in the proposed smart network.
Yustus Eko Oktian, Thi-Thu-Huong Le, Uk Jo, Howon Kim
Bandwidth trading procedures can be made to incentivize users to sell their needless traffic and indirectly reduce the probability of traffic congestion. However, implementation of bandwidth trading is opex-heavy from Internet Service Provider (ISP) perspective, while on the other hand, users also do not trust network executions from the ISP due to its heavily centralized control. These issues hinder the applicability of bandwidth trading and become our motivation to propose this paper. Our bandwidth-trading framework utilize software-defined networking (SDN) and blockchain. SDN automates the bandwidth trading executions from the ISP side and reduces the opex. Meanwhile, the smart contract is a trusted platform for building a trading marketplace where buyers, sellers, and SDN controllers can negotiate the trading terms. Once the trading is executed, SDN controllers generate proof of trading that must be submitted to the smart contract as proof of provisioning. We implement our works using Ethereum and POX SDN controllers, and the results prove that it can provide a seamless bandwidth trading experience with reasonable overhead. Furthermore, by committing to our framework, bandwidth trading can be executed fairly and securely because all previous provisioning can be cross-checked through the provided proof-of-trading.
The development of fifthâgeneration (5G) mobile communication technology has become a major driver to the growth of Internet of Things (IoT) applications. As a promising networking paradigm, softwareâdefined networking (SDN) makes IoT more flexible and agile by decoupling control plane from data plane. With a large number of heterogeneous devices accessing to the network, we need to divide the network into several domains and each domain is managed by an SDN controller. Controllers share topologies with each other to form global view of the entire network, which is used for crossingâdomain path routing. However, crossingâdomain routing requires global trust between multiple controllers. The reason is that if the malicious controller shares misleading topologies, the rest of controllers may calculate mistaken crossingâdomain paths. As a result, packets are forwarded to the domain that is managed by the malicious controller and dropped deliberately, which is known as the blackâhole attack. To this end, we present a blockchainâbased architecture to ensure secure routing among multiple domains in SDNâenabled IoT networks. All SDN controllers are equipped with blockchains, and they upload abstract topologies to the blockchain via the smart contract. Thus, the genuine view of the entire network can be gained from the blockchain due to its consensus and immutability. In addition, we use the concept of reputation that consists of the local reputation and the global reputation to further protect routing reliability, and the global reputation is reserved in the blockchain. Compared with benchmark architectures, the emulation results show that our proposed method can effectively build trust between multiple controllers and ensure secure routing among multiple domains.
Network slicing is one of the fundamental tenets of Fifth Generation (5G)/Sixth Generation (6G) networks. Deploying slices requires end-to-end (E2E) control of services and the underlying resources in a network substrate featuring an increasing number of stakeholders. Beyond the technical difficulties this entails, there is a long list of administrative negotiations among parties that do not necessarily trust each other, which often requires costly manual processes, including the legal construction of neutral entities. In this context, Blockchain comes to the rescue by bringing its decentralized yet immutable and auditable lemdger, which has a high potential in the telco arena. In this sense, it may help to automate some of the above costly processes. There have been some proposals in this direction that are applied to various problems among different stakeholders. This paper aims at structuring this field of knowledge by, first, providing introductions to network slicing and blockchain technologies. Then, state-of-the-art is presented through a global architecture that aggregates the various proposals into a coherent whole while showing the motivation behind applying Blockchain and smart contracts to network slicing. And finally, some limitations of current work, future challenges and research directions are also presented.
Tooba Faisal, Mischa Döhler, Simone Mangiante, Diego López
It is widely expected that future networks of 6G and beyond will deliver on the unachieved goals set by 5G. Technologies such as Internet of Skills and Industry 4.0 will become stable and viable, as a direct consequence of networks that offer sustained and reliable mobile performance levels. The primary challenges for future technologies are not just low-latency and high-bandwidth. The more critical problem Mobile Service Providers (MSPs) will face will be in balancing the inflated demands of network connections and customers' trust in the network service, that is, being able to interconnect billions of unique devices while adhering to the agreed terms of Service Level Agreements (SLAs). To meet these targets, it is self-evident that MSPs cannot operate in a solitary environment. They must enable cooperation among themselves in a manner that ensures trust, both between themselves as well as with customers. In this study, we present the BEAT (Blockchain-Enabled Accountable and Transparent) Infrastructure Sharing architecture. BEAT exploits the inherent properties of permissioned type of distributed ledger technology (i.e., permissioned distributed ledgers) to deliver on accountability and transparency metrics whenever infrastructure needs to be shared between providers. We also propose a lightweight method that enables device-level accountability. BEAT has been designed to be deployable directly as only minor software upgrades to network devices such as routers. Our simulations on a resource-limited device show that BEAT adds only a few seconds of overhead processing time -- with the latest state-of-the-art network devices, we can reasonably anticipate much lower overheads.
Along with the high demand for network connectivity from both end-users and service providers, networks have become highly complex; and so has become their lifecycle management. Recent advances in automation, data analysis, artificial intelligence, distributed ledger technologies (e.g., Blockchain), and data plane programming techniques have sparked the hope of the researchersâ community in exploring and leveraging these techniques towards realizing the much-needed vision of trustworthy self-driving networks (SelfDNs). In this vein, this article proposes a novel framework to empower fully distributed trustworthy SelfDNs across multiple domains. The framework vision is achieved by exploiting (i) the capabilities of programmable data planes to enable real-time in-network telemetry collection; (ii) the potential of P4 â as an important example of data plane programming languages â and AI to (re)write the source code of network components in a fashion that the network becomes capable of automatically translating a policy intent into executable actions that can be enforced on the network components; and (iii) the potential of blockchain and federated learning to enable decentralized, secure and trustable knowledge sharing between domains. A relevant use case is introduced and discussed to demonstrate the feasibility of the intended vision. Encouraging results are obtained and discussed.
Yunhua He, Zhang Cui, Bin Wu, Yigang Yang · 6 authors
As a key technology for the development of 5G networks, network slicing is developing rapidly. Although network slicing can realize the flexible division of 5G network resources and quickly customize virtual networks that meet the differentiated needs of customers, it is still difficult to determine the optimal service quality parameters in application scenarios. To solve the problem, this article designs a multichain 5G network slicing service quality computing model to calculate the service quality parameters of the network slicing. The calculated service quality parameters can be used as an adjustment basis in the negotiation of the SLA between the customer and the network operator. However, the traditional method of calculating information across chains will cause frequent information interactions and affect efficiency. Therefore, in this scheme, we deploy a smart contract on each blockchain to calculate the information, which can reduce the frequency of information transmission and improve efficiency. In addition, in order to make the calculation between smart contracts more fluent and the requirements more relevant, this article proposes to coordinate the development of smart contracts through multiple blockchains. Besides, to ensure the cross-chain security calculation, the signature by Cosi protocol and multisigncryption algorithms are used in the transmission of nonprivate information and private information in the cross-chain process, respectively. Security analysis and experimental results prove that the multichain 5G network slicing service quality computing model is feasible and efficient in practice.
Blockchain is a popular topic of research in recent years. For worthwhile research into the use Blockchains, they often must be deployed into environments that are as close to real-world scenarios as possible. Real-world networks are large and complex and therefore the Blockchains used to research them should be large and complex. Creating large Blockchains like this may seem out-of-reach for the humble researcher. The tool introduced in this paper - Containerchain - seeks to make it much easier to spin up a large Blockchain system with little-or-no setup. The ultimate goal being to allow researchers to spend more time on actual research, rather than on setting up the network. Containerchain allows the user to deploy a real Blockchain system (not simulated) with several configurable parameters at their disposal. The user can control the number of nodes in the system, the consensus mechanism used and can observe and analyze the network traffic in the Blockchain - which is recorded out-of-the-box.
Damir Dautov, Rinat Khayretdinov, Alexey Vulfin, Konstantin Mironov
Software-defined networks are becoming more popular as the number of devices in large enterprise networks continues to grow. However, this technology has vulnerabilities that can be very dangerous for company. An algorithm of implementation of the distributed ledgers in software-defined networks for security purposes is proposed in this paper.