In recent years block chain technology have gained popularity because of its secure and decentralized architecture. Block chain is a fault-tolerant distributed ledger without administrators. Block chain is originally derived from crypto currency, but it is possible to be applied to other industries. Security is enhanced by the methods of hashing, immutable ledger property, consensus protocol, proof of work (POW) mechanism etc. The design put forward facilitates the conversion of a randomly long input message to a message digest of fixed length and is implemented on FPGA. The use of FPGA provides the added advantage of fast parallel processing and computing, adaptability and real time application. The objective is to optimize the design and efficiently implement the conversion of a randomly long message to a fixed length output using the concepts of block chain.
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Physical Unclonable Functions (PUFs) and Hardware Security
To ensure the proper functioning and performance of Industrial grade Internet of Things devices (IIoT) in Industry 4.0 networks, it is critical to identify the capabilities and malfunctions of their component devices (e.g., sensors, actuators, and controllers) and detect potential misbehavior arising due to cyber-attacks, and misconfiguration. We envision future IoT devices embed behavioral profiles throughSecurity-by-Contract(S×C) that are easy to validate and verify against network security policies; manufacturers to provide manufacturer usage description (MUD) profiles as amanifestfor the devices to signal to the network what sort of access and network functionality they require to properly function. We design authentication in the IoT onboarding process, employ blockchains to a verifiable and immutable repository to store this network manifests, that is signed and verifiable with S×C basedsmart contractsby the device manufacturer, or industry authority. The integrated framework combines blockchains and S×C security contracts, MUD-based behavioral fingerprinting, and software-defined-networking for managing the security of IIoT ecosystems. Finally, the proposed scheme is validated in a simulated IoT environment on various performance parameters.
Blockchain Technology Applications and Security
Physical Unclonable Functions (PUFs) and Hardware Security
Yankai Xie, Chi Zhang, Lingbo Wei, Qingtao Wang · 5 authors
Hardware trusted execution environment (TEE) provided by Intel SGX enclave has been introduced in existing payment channel schemes as a root-of-trust to enforce faithful protocol execution so that participants do not need to monitor Bitcoin blockchain anymore. However, the security of these schemes relies totally on enclaves. Since private keys of all channel funds are kept by both payment channel participants’ enclaves, a malicious participant can steal funds from the counterparty by defeating her own enclave. To solve the above problem, we present a novel TEE-based payment channel scheme that transfers the responsibility of running enclaves from participants to a third party committee, while relieving both participants from monitoring the blockchain at the same time. Furthermore, since committee members can try to steal funds by defeating their own enclaves, we exploit the additive homomorphic property of signature keys in Elliptic Curve Cryptography to design a novel secret sharing scheme to tolerate a subset of committee members to be malicious. By using the above secret sharing scheme, private keys of the channel funds are never constructed in any committee member’s enclave, so that a malicious committee member cannot steal funds by defeating his own enclave. Finally, experiment shows our scheme can ensure payment channel funds security without efficient compromises compared with existing TEE-based payment channel schemes.
Security and Verification in Computing
Blockchain Technology Applications and Security
Physical Unclonable Functions (PUFs) and Hardware Security
In recent years, the number of Internet-of-Things (IoT) devices has grown at an explosive rate. With the dramatic surge of the IoT, security issues have also come to the fore. Consequently, ensuring the security of the IoT communication community environment and trust between entities have become important research topics. In this paper, we design a passwordless IoT authentication mechanism, namely, T-Auth, to address these issues. The identity of a device in T-Auth is based on physical unclonable functions (PUFs), a hardware-based device fingerprint technology, which can greatly improve the security level compared to hardcoded passwords. A smart contract is a program that runs on the blockchain, which provides design flexibility and operational reliability. Our mechanism establishes a new trust architecture that enables devices to exchange information securely and reliably. The main contribution of this paper is to propose a new authentication mechanism that utilizes PUFs and combines them with blockchain to greatly improve the security and reliability of a system. Additionally, by leveraging Ethereum smart contracts, our mechanism supports cross-service group authentication.
Physical Unclonable Functions (PUFs) and Hardware Security
User Authentication and Security Systems
Advanced Steganography and Watermarking Techniques
Christopher M. VanYe, Beatrice Li, Andrew Koch, Mai N. Luu · 12 authors
This paper addresses security and risk management of hardware and embedded systems across several applications. There are three companies involved in the research. First is an energy technology company that aims to leverage electric- vehicle batteries through vehicle to grid (V2G) services in order to provide energy storage for electric grids. Second is a defense contracting company that provides acquisition support for the DOD's conventional prompt global strike program (CPGS). These systems need protections in their production and supply chains, as well as throughout their system life cycles. Third is a company that deals with trust and security in advanced logistics systems generally. The rise of interconnected devices has led to growth in systems security issues such as privacy, authentication, and secure storage of data. A risk analysis via scenario-based preferences is aided by a literature review and industry experts. The analysis is divided into various sections of Criteria, Initiatives, C-I Assessment, Emergent Conditions (EC), Criteria-Scenario (C-S) relevance and EC Grouping. System success criteria, research initiatives, and risks to the system are compiled. In the C-I Assessment, a rating is assigned to signify the degree to which criteria are addressed by initiatives, including research and development, government programs, industry resources, security countermeasures, education and training, etc. To understand risks of emergent conditions, a list of Potential Scenarios is developed across innovations, environments, missions, populations and workforce behaviors, obsolescence, adversaries, etc. The C-S Relevance rates how the scenarios affect the relevance of the success criteria, including cost, schedule, security, return on investment, and cascading effects. The Emergent Condition Grouping (ECG) collates the emergent conditions with the scenarios. The generated results focus on ranking Initiatives based on their ability to negate the effects of Emergent Conditions, as well as producing a disruption score to compare a Potential Scenario's impacts to the ranking of Initiatives. The results presented in this paper are applicable to the testing and evaluation of security and risk for a variety of embedded smart devices and should be of interest to developers, owners, and operators of critical infrastructure systems.
Physical Unclonable Functions (PUFs) and Hardware Security
Javier Arcenegui, Rosario Arjona, Roberto Román, Iluminada Baturone
Non-fungible tokens (NFTs) are widely used in blockchain to represent unique and non-interchangeable assets. Current NFTs allow representing assets by a unique identifier, as a possession of an owner. The novelty introduced in this paper is the proposal of smart NFTs to represent IoT devices, which are physical smart assets. Hence, they are also identified as the utility of a user, they have a blockchain account (BCA) address to participate actively in the blockchain transactions, they can establish secure communication channels with owners and users, and they operate dynamically with several modes associated with their token states. A smart NFT is physically bound to its IoT device thanks to the use of a physical unclonable function (PUF) that allows recovering its private key and, then, its BCA address. The link between tokens and devices is difficult to break and can be traced during their lifetime, because devices execute a secure boot and carry out mutual authentication processes with new owners and users that could add new software. Hence, devices prove their trusted hardware and software. A whole demonstration of the proposal developed with ESP32-based IoT devices and Ethereum blockchain is presented, using the SRAM of the ESP32 microcontroller as the PUF.
Open access
Physical Unclonable Functions (PUFs) and Hardware Security
Miguel A. Prada-Delgado, Gero Dittmann, Ilie Circiumaru, Jens Jelitto
Counterfeiting is a major problem in many industries, causing hundreds of billions of dollars in damages every year. Digital twins further increase a product's value, making it critical to secure the link between the physical and digital world. An entire industry has sprung up to address this problem with a wide variety of product-authentication technologies, or crypto anchors, offering many different trade-offs between supported product surface, security level, price sensitivity, ease of use, etc. Each crypto-anchor vendor provides their own APIs for commissioning, verification and monitoring which makes it hard for application developers to support many of them. This paper introduces a platform that provides a generic model of an object secured by a crypto anchor, supporting any number of product authentication technologies by means of crypto-anchor plugins. Applications programmed against this generic model can immediately interoperate with any of the plugged-in crypto anchors. We present a blockchain architecture for the platform whose decentralization matches the highly differentiated industry structure. We've implemented the system on Hyperledger Fabric.
Physical Unclonable Functions (PUFs) and Hardware Security
Yan Zhang, Bing Li, Bo Liu, Yuanyuan Hu · 5 authors
The combination of the Internet of Things (IoT) and cloud-edge (CE) paradigm promises to be an efficient system to aggregate and further process huge volumes of data from IoT nodes. Physical unclonable functions (PUFs) emerge as a prospective primitive to provide IoT nodes with lightweight physical identities for authentication. However, when integrating PUFs into multiserver authentication protocols to improve security, the following problems occur: 1) the challenge–response pairs (CRPs) of PUFs generated by devices need to be explicitly stored by each edge server. This will cause the privacy leakage of CRPs; 2) the reliability is reduced resulting from the single point failure; and 3) existing PUFs-based authentication protocols would need to put great efforts into synchronizing CRPs, to ensure consistency in multiserver systems. To overcome these problems, in this article, we propose a privacy-aware authentication protocol for the multiserver CE-IoT systems by combining PUFs and the blockchain technique. The real correlations of CRPs are double encoded into mapping correlations (MCs) by a one-time physical identity and the keyed-hash function. The blockchain is leveraged to store MCs, synchronize them efficiently, and incorporate the multireceiver encryption to share the physical identity securely. The security of our protocol is formally proved by a random oracle model, and security features are discussed to show that our protocol resists various attacks. Moreover, a prototype was implemented to prove the efficiency of the protocol, and the comparison results present that our protocol accommodates CE-IoT systems. Finally, the simulation of the smart contract evaluates the scalability of our protocol.
Physical Unclonable Functions (PUFs) and Hardware Security
IoT nodes comprise of sensors and embedded resource-constrained systems. On the other hand, blockchain is regarded as computationally expensive due to the consensus algorithms. Therefore, it is challenging to apply blockchain to an IoT system. This work presents a unique concept that integrates blockchain with lightweight cryptographic solutions targeting resource-constrained IoT sensor nodes. In particular, proof-of-authentication utilizing a lightweight authenticated encryption (AE) scheme to achieve consensus is proposed. At sensor nodes, a tag is generated based on sensor data, which is then broadcast to the network. Upon authentication from the cluster head node (e.g., a gateway), the block is hashed using the lightweight hash function and added to the blockchain. The proposed solution can be implemented in software (e.g., microcontroller) or hardware platform (e.g., FPGA, ASIC). Experimental results show that lightweight authentication can perform 1.34 M authentications per-second with only 6.55 k lookup tables (LUTs) on the Spartan-6 FPGA platform. This high-throughput authentication can speed up the consensus in blockchain, utilizing few resources and making it very suitable for applications in IoT sensor nodes.
Open access
Blockchain Technology Applications and Security
Physical Unclonable Functions (PUFs) and Hardware Security
Blockchain is a promising solution for Industry 4.0; however, it does not guarantee input data integrity. We propose a field-programmable gate array (FPGA)-based private blockchain system for the industrial Internet of Things, where the transaction generation is performed inside the FPGA in an isolated and enclaved manner.
Open access
Blockchain Technology Applications and Security
Physical Unclonable Functions (PUFs) and Hardware Security
This demonstration presents a new trust model for Internet of Things, based on TLS1.3 sessions authenticated by pre-shared key (PSK). According to TLS1.3, security relies on Diffie-Hellman exchanges, optionally authenticated by symmetric secret (PSK) shared by client and server. A major security issue is PSK protection against eavesdropping, in order to avoid device cloning or illegitimate use. We present two secure elements TLS-IM used on client side, and TLS-SE used on server side, which enforce PSK security. TLS-IM is a smartcard associated with TLS1.3 client running in laptop. TLS-SE is a standalone TLS1.3 server running in a secure element, which embeds an application computing signature for blockchain transaction. TLS-SE has a SIM form factor, and is plugged in a hardware module working with a Wi-Fi SoC, providing TCP/IP connectivity.
Physical Unclonable Functions (PUFs) and Hardware Security
In the blockchain, the transaction hashes are implemented through public-key cryptography and hash functions. Hence, there is a possibility for the two users to choose the same private key knowingly or unknowingly. Even the intruders can follow the particular user's bitcoin transaction, and they can masquerade as that user by generating the private and public key pairs of him. If it happens, the user may lose his transaction. Generally, bitcoin technology uses random numbers from 1 to 2256. It is a wide range, but for a greater number of users, there should be one another solution. There is a possibility of digital prototyping which leads to the loss of more accounts. This chapter provides the device-specific fingerprint technology known as physical unclonable function (PUF) to be employed for authentication in a blockchain-based bitcoin environment. The random unique response from PUF ensures correct transaction. In this chapter, a new tetrahedral oscillator PUF has been introduced intrinsically. All the blockchain operations are carried out and verified with PUF response.
Open access
Physical Unclonable Functions (PUFs) and Hardware Security
Hyunyoung Oh, Kevin Nam, Seongil Jeon, Yeongpil Cho · 5 authors
Remote computing has emerged as a trendy computing model that enables users to process an immense number of computations efficiently on the remote server where the necessary data and high-performance computing power are provisioned. Unfortunately, despite such an advantage, this computing model suffers from insider threats that are committed by adversarial administrators of remote servers who attempt to steal or corrupt users' private data. These security threats are somewhat innate to remote computing in that there is no means to control administrators' unlimited data access. In this paper, we present our novel hardware-centric solution, called MeetGo, to address the intrinsic threats to remote computing. MeetGo is a field-programmable gate array (FPGA)-based trusted execution environment (TEE) that aims to operate independently of the host system architecture. To exhibit the ability and effectiveness of MeetGo as a TEE ensuring secure remote computing, we have built two concrete applications: cryptocurrency wallet and GPGPU. MeetGo provides a trust anchor for these applications that enable their users to trade cryptocurrency or to run a GPGPU program server on a remote server while staying safe from threats by insiders. Our experimental results clearly demonstrate that MeetGo incurs only a negligible performance overhead to the applications.
Open access
Security and Verification in Computing
Physical Unclonable Functions (PUFs) and Hardware Security
It has become a truism that the speed of technological progress leaves law and policy scrambling to keep up. But in addition to creating new challenges, technological advances also enable new improvements to issues at the intersection of law and technology. In this thesis, I develop new cryptographic tools for informing and improving our law and policy, including specific technical innovations and analysis of the limits of possible interventions. First, I present a cryptographic analysis of a legal question concerning the limits of the Fifth Amendment: can courts legally compel people to decrypt their devices? Our cryptographic analysis is useful not only for answering this specific question about encrypted devices, but also for analyzing questions about the wider legal doctrine. The second part of this thesis turns to algorithmic fairness. With the rise of automated decision-making, greater attention has been paid to statistical notions of fairness and equity. In this part of the work, I demonstrate technical limits of those notions and examine a relaxation of those notions; these analyses should inform legal or policy interventions. Finally, the third section of this thesis describes several methods for improving zero-knowledge proofs of knowledge, which allow a prover to convince a verifier of some property without revealing anything beyond the fact of the prover's knowledge. The methods in this work yield a concrete proof size reduction of two plausibly post-quantum styles of proof with transparent setup that can be made non-interactive via the Fiat-Shamir transform: "MPC-in-the-head," which is a linear-size proof that is fast, low-memory, and has few assumptions, and "Ligero," a sublinear-size proof achieving a balance between proof size and prover runtime. We will describe areas where zero-knowledge proofs in general can provide new, currently-untapped functionalities for resolving legal disputes, proving adherence to a policy, executing contracts, and enabling the sale of information without giving it away.
Open access
Cryptography and Data Security
Digital and Cyber Forensics
Physical Unclonable Functions (PUFs) and Hardware Security
Alexios Papacharalampopoulos, Harry Bikas, Christos K. Michail, Panagiotis Stavropoulos
Manufacturing process related functionalities, like optimization and control, are in general demanding in terms of data, computational time and efficiency. However, there are no generic certification or validation schemes that can be followed. In particular, only ISO application can verify the suitability of operations up to an extent. The current work utilizes an enhanced version of Blockchain so that functionalities at the process level can be certified as per a particular scheme. The concept of ledger is elaborated to this end, to manipulate knowledge and be able to handle it like an asset that is exchanged. Thus, a specific generic framework is proposed, herein, to reassure that the right kind of information has been exchanged during process control and optimization. Furthermore, expert distributed agents are utilized to turn knowledge into certified procedures. Encryption issues are also regarded, providing safety and security as extra characteristics. The case study of thermal process control is regarded in this sense to prove the complementary character of these concepts and the usability of the framework. Finally, the existence of additional features within this loop is discussed, like the validation of quantifying concepts like resource streams.
Open access
Flexible and Reconfigurable Manufacturing Systems
Digital Transformation in Industry
Physical Unclonable Functions (PUFs) and Hardware Security
Karim Baghery, Cyprien Delpech de Saint Guilhem, Emmanuela Orsini, Nigel P. Smart · 5 authors
This paper introduces M-Circuits, a program representation which generalizes arithmetic and binary circuits. This new representation is motivated by the way modern multi-party computation (MPC) systems based on linear secret sharing schemes actually operate. We then show how this representation also allows one to construct zero knowledge proof (ZKP) systems based on the MPC-in-the-head paradigm. The use of the M-Circuit program abstraction then allows for a number of program-specific optimizations to be applied generically. It also allows to separate complexity and security optimizations for program compilation from those for application protocols (MPC or ZKP).
Fabian Dietrich, Yiwen Ge, Ali Emre Turgut, Louis Louw · 5 authors
Supply chains have become increasingly complex, making it difficult to ensure transparency throughout the whole supply chain. In this context, first approaches came up, adopting the immutable, decentralised, and secure characteristics of the blockchain technology to increase the transparency, security, authenticity, and auditability of assets in supply chains. This paper investigates recent publications combining the blockchain technology and supply chain management and classifies them regarding the complexity to be mapped on the blockchain. As a result, the increase of supply chain transparency is identified as the main objective of recent blockchain projects in supply chain management. Thereby, most of the recent publications deal with simple supply chains and products. The few approaches dealing with complex parts only map sub-areas of supply chains. Currently no example exists which has the aim of increasing the transparency of complex manufacturing supply chains, and which enables the mapping of complex assembly processes, an efficient auditability of all assets, and an implementation of dynamic adjustments.
Open access
Blockchain Technology Applications and Security
Physical Unclonable Functions (PUFs) and Hardware Security
Suat Mercan, Mumin Cebe, Ramazan Aygün, Kemal Akkaya · 6 authors
Abstract A camera footage which is essential for forensic investigations can easily be modified with advanced video tampering techniques. This makes it necessary to employ novel methods to retain and prove the integrity of captured scene in criminal investigations. In this vein, blockchain technology has received a substantial interest in the last decade as it provides trust among users without a trusted third party, which enabled a myriad of applications. To this end, we propose a framework that utilizes blockchain technology to verify integrity of a camera footage recorded by a resource‐constrained wireless Internet of Things (IoT) device. The proposed approach computes the hash of the video data before it leaves the IoT device to ensure the integrity. The hash is then stored on a permissioned blockchain platform that enables detection of tampering in the video. The continuous stream is segmented efficiently to have periodic hash value to minimize the risk of video loss in case of device failure. The system has been implemented on a Raspberry Pi and Hyperledger to validate its efficiency. We are able to process high resolution videos on a resource‐constrained with reasonable amount of delay. The integrity of recorded video is successfully verified by using the digest kept in permissioned blockchain.
Digital Media Forensic Detection
Advanced Steganography and Watermarking Techniques
Physical Unclonable Functions (PUFs) and Hardware Security
A detailed review on the technological aspects of Blockchain and Physical Unclonable Functions (PUFs) is presented in this article. It stipulates an emerging concept of Blockchain that integrates hardware security primitives via PUFs to solve bandwidth, integration, scalability, latency, and energy requirements for the Internet-of-Energy (IoE) systems. This hybrid approach, hereinafter termed as PUFChain, provides device and data provenance which records data origins, history of data generation and processing, and clone-proof device identification and authentication, thus possible to track the sources and reasons of any cyber attack. In addition to this, we review the key areas of design, development, and implementation, which will give us the insight on seamless integration with legacy IoE systems, reliability, cyber resilience, and future research challenges.
Open access
Physical Unclonable Functions (PUFs) and Hardware Security