Ao Xiong, Hongkang Tian, Wenchen He, Jie Zhang · 9 authors
This paper proposes a smart grid distributed security architecture based on blockchain technology and SDN cluster structure, referred to as ClusterBlock model, which combines the advantages of two emerging technologies, blockchain and SDN. The blockchain technology allows for distributed peer-to-peer networks, where the network can ensure the trusted interaction of untrusted nodes in the network. At the same time, this article adopts the design of an SDN controller distributed cluster to avoid single point of failure and balance the load between equipment and the controller. A cluster head was selected in each SDN cluster, and it was used as a blockchain node to construct an SDN cluster head blockchain. By combining blockchain technology, the security and privacy of the SDN communication network can be enhanced. At the same time, this paper designs a distributed control strategy and network attack detection algorithm based on blockchain consensus and introduces the Jaccard similarity coefficient to detect the network attacks. Finally, this paper evaluates the ClusterBlock model and the existing model based on the OpenFlow protocol through simulation experiments and compares the security performance. The evaluation results show that the ClusterBlock model has more stable bandwidth and stronger security performance in the face of DDoS attacks of the same scale.
Hai Nam Nguyen, Hai Anh Tran, Scott Fowler, Sami Souihi
Abstract Software‐Defined Networking (SDN) brought a groundbreaking idea to facilitate network system management by decoupling and abstracting the Control plane and Data plane of traditional networks. The centralised control offers network administrators many benefits such as a global view of the network, programmability, dynamic updating of forwarding rules, and software‐based traffic analysis. The SDN architecture has been applied a lot in practice, and especially in Internet of Things (IoT) platforms. With the superiority of SDN, IoT devices can be managed and configured much more easily when combined. However, SDN also raises many challenges in terms of scalability, reliability, and security. Blockchain is another promising solution for secure information storage and transmission technology that operates without a centralised authority. Applying Blockchain technology into SDN can address some of the current issues of SDN by providing decentralised methods to authenticate exchanged network information. This study provides a comprehensive survey on Blockchain technologies applied to SDN in both security and non‐security fields. First, related studies and an overview of SDN and the background of Blockchain technology are presented. Then, the authors review how Blockchain technologies are applied in SDN from two perspectives: non‐security and security‐aware approaches. Finally, challenges and broader perspectives are discussed.
Phan The Duy, Hien Do Hoang, Do Thi Thu Hien, Anh Gia-Tuan Nguyen · 5 authors
Software-Defined Network (SDN) is a new arising terminology of network architecture with outstanding features of orchestration by decoupling the control plane and the data plane in each network element. Even though it brings several benefits, SDN is vulnerable to a diversity of attacks. Abusing the single point of failure in the SDN controller component, hackers can shut down all network operations. More specifics, a malicious OpenFlow application can access to SDN controller to carry out harmful actions without any limitation owing to the lack of the access control mechanism as a standard in the Northbound. The sensitive information about the whole network such as network topology, flow information, and statistics can be gathered and leaked out. Even worse, the entire network can be taken over by the compromised controller. Hence, it is vital to build a scheme of access control for SDN's Northbound. Furthermore, it must also protect the data integrity and availability during data exchange between application and controller. To address such limitations, we introduce B-DAC, a blockchain-based framework for decentralized authentication and fine-grained access control for the Northbound interface to assist administrators in managing and protecting critical resources. With strict policy enforcement, B-DAC can perform decentralized access control for each request to keep network applications under surveillance for preventing over-privileged activities or security policy conflicts. To demonstrate the feasibility of our approach, we also implement a prototype of this framework to evaluate the security impact, effectiveness, and performance through typical use cases.
The 6G wireless network aims to forge a new spectrum, high technical standards of high time and phase synchronization accuracy, and 100% geographic coverage to connect trillions of devices flexibly and efficiently in the future. However, as connectivity increases and applications become novel, it is a challenge to ensure the privacy and security of networks and applications. Blockchain is seen as a promising technology that can improve efficiency, reduce costs, mitigate security, and privacy threats, and establish a trusted data-sharing environment. This article presents a trusted framework based on blockchain technology from the perspective of how to build a trusted software-defined content delivery network. As the peer node of the blockchain, the software-defined network (SDN) controller establishes trust between different regions and a wide range of participants, realizing peer autonomy and flexible business orchestration. The two main purposes of the architecture are to enhance the security of network communications and establish trust relationships between entities in different domains. It includes trusted communication based on routing sandbox, service choreography based on blockchain, proxy server selection strategy based on model predictive control (MPC), and optimization consensus based on practical Byzantine fault tolerance. Some simulation experiments verify the effectiveness of the theoretical method.
Gordon Owusu Boateng, Daniel Ayepah-Mensah, Daniel Mawunyo Doe, Abegaz Mohammed Seid · 6 authors
The advent of radio access network (RAN) slicing is envisioned as a new paradigm for accommodating different virtualized networks on a single infrastructure in 5G and beyond. Consequently, infrastructure providers (InPs) desire virtualized networks to share their subleased resources for effective resource management. Nonetheless, security and privacy challenges in the wireless network deter operators from collaborating with one another for resource trading. Lately, blockchain technology has received overwhelming attention for secure resource trading thanks to its security features. This paper proposes a novel hierarchical framework for blockchain-based resource trading among peer-to-peer (P2P) mobile virtual network operators (MVNOs), for autonomous resource slicing in 5G RAN. Specifically, a consortium blockchain network that supports hyperledger smart contract (SC) is deployed to set up secure resource trading among seller and buyer MVNOs. With the aim of designing a fair incentive mechanism, we model the pricing and demand problem of the seller and buyers as a two-stage Stackelberg game, where the seller MVNO is the leader and buyer MVNOs are followers. To achieve a Stackelberg equilibrium (SE) for the formulated game, a dueling deep Q-network (Dueling DQN) scheme is designed to achieve optimal pricing and demand policies for autonomous resource allocation at negotiation interval. Comprehensive simulation results analysis prove that the proposed scheme reduces double spending attacks by 12% in resource trading settings, and maximizes the utilities of players. The proposed scheme also outperforms deep Q-Network (DQN), Q-learning (QL) and greedy algorithm (GA), in terms of slice and system level satisfaction and resource utilization.
Network Function Virtualization (NFV) is considered to be a hopeful technology for supporting blockchain with many features like flexible networks and intelligent equipment. NFV decreases the expenses incurred on the maintenance and operation of assets that are generated through expenses, in addition to capital expenditures based on the isolate the physical devices from the main tasks executed by that equipment. Blockchain currency transfers or technology is the most powerful security tool that ensures the security of data. The prominent challenges in NFV are the processes of transition, vendor compatibility, network management, rapid growth, and security. The software industry and skills of networking are experiencing fast expansion and deployment of the Network Functions Virtualization (NFV) approach, jointly in blockchain and cloud networks. In this paper, a novel method is offered to virtualize the work of the blockchain based on the NFV with auto work of the smart contract between virtual nodes based on cloud computing. By blending NFV with Blockchain, all of the above-mentioned challenges have been overcome by moving to software environments through creating virtual nodes, as well as smooth interaction among them and managing the transactions between nodes and clients, indicating ideal network management. Through the proposed work, a throughput of up to 20% is obtained by applying NFV compared to not applying NFV to the blockchain. In addition, the costs of the hardware are eliminated and eventually a secure environment is used which distances the system from virtual attacks.
This paper tackles the problem of using and paying a network service with guaranteed quality of service (QoS) at a fine granularity in the future wireless network. We propose the IOTA-based QoS guaranteed Flow system (IQF), where a user and service provider can exchange the IOTA cryptocurrency for the guaranteed network resources, such as latency and bandwidth. First, IQF uses the IOTA Tangle, a lightweight, efficient distributed ledger technology, for its payment and transaction record. Second, IQF adopts Software Defined Networking to realize the guaranteed delay and bandwidth provision. We have implemented the IQF systems using the mininet-wifi emulator, an SDN controller (i.e., POX), and IOTA clients. Moreover, we have evaluated the service provisioning algorithms with a micropayment of IQF with the test Tangle (i.e., comnet). The evaluation results show that IQF has successfully achieved the delay and bandwidth provision with all the transactions stored in comnet.
Operators of networks are striving to provide functional network-based services, while keeping the cost of deploying the service to a minimum. Network Function Virtualization (NFV) is considered to be a promising model to modify such employment by separating network functions from the basic hardware properties, after which they are converted into the style of software. These are eventually referred to as Virtual Network Functions (VNFs). This separation offers numerous benefits, including the decrease of Capital Expenditure (CAPEX) and Operation Expense (OPEX), in addition to the enhanced elasticity of service preparation. Network Functions Virtualization (NFV) is found to cause a remarkable development or even a technological revolution in terms of network-based services, leading to a decrease in deployment costs for network operators. NFV reduces hardware tool costs and energy exhaustion, and it improves its operational performance whereby the network configuration is part of this optimization. Even so, there are a number of possible security problems which are the main focus in NFV. The present study surveys the applications and opportunities of NFV in terms of IoT, SDN, cloud computing and blockchain. A description of the NFV architecture is presented, and several possibilities of NFV security issues and challenges are discussed. Finally, a systematic idea is provided on the design of a Blockchain Network Virtualization System.
Guobiao He, Wei Su, Shuai Gao, Ningchun Liu · 5 authors
Multi-domain networking slice orchestration is an essential technology for the programmable and cloud-native 5G network. However, existing research solutions are either based on the impractical assumption that operators will reveal all the private network information or time-consuming secure multi-party computation which is only applicable to limited computation scenarios. To provide agile and privacy-preserving end-to-end network slice orchestration services, this paper proposes NetChain, a multi-domain network slice orchestration architecture based on blockchain and trusted execution environment. Correspondingly, we design a novel consensus algorithm CoNet to ensure the strong security, scalability, and information consistency of NetChain. In addition, a bilateral evaluation mechanism based on game theory is proposed to guarantee fairness and Quality of Experience by suppressing the malicious behaviors during multi-domain network slice orchestration. Finally, the prototype of NetChain is implemented and evaluated on the Microsoft Azure Cloud with confidential computing. Experiment results show that NetChain has good performance and security under the premise of privacy-preserving.
One of the important characteristics envisioned for 6G is security function virtualization (SFV). Similar to network function virtualization (NFV) in 5G networks, SFV provides new opportunities for improving security while reducing the security overhead. In particular, it provides an attractive way of solving compatibility issues related to security. Malware in Internet of Things (IoT) systems is gaining popularity among cyber-criminals because of the expected number of IoT devices in 5G and 6G networks. To solve this issue, this article proposes a security framework that exploits softwarization of security functions via SFV to improve trust in IoT systems and contain the propagation of malware. IoT devices are categorized into trusted, vulnerable, and compromised levels using remote attestation. To isolate the devices in the three distinct categories, NFV is used to create separate networks for each category, and a distributed ledger is used to store the state of each device. Virtualized remote attestation routines are employed to avoid any compatibility issues among heterogeneous IoT devices and effectively contain malware propagation. The results show that the proposed framework can reduce the number of infected devices by 66 percent in only 10 seconds.
The Internet of Things (IoT) and Blockchain distribution ledger technology as a concept is enchanting facilities and industrial developments with advanced implements in many applications. The IoT and Blockchain market is further expected to develop three times from current development by 2025. Though many IoT applications have major challenges in safest data transaction and scalability issues while increasing the number of IoT devices. Practical Byzantine Fault Tolerance (PBFT) is a widely used form of decentralized consent, however the network node's confidence in PBFT cannot be guaranteed, as well as the mechanism of reaching consensus will consume a large amount of network services. The article suggests the novel consensus process, which is referred to a Hybrid consensus blockchain algorithm and control authentication on Trust. The Internet of Things applications are integrated with a blockchainbased decentralized system that authenticates the IoT devices through distributed control authentication. This hybrid consensus blockchain method provides security for transactions and access to unauthorized devices is restricted. The PBFT algorithm using a decentralized network system using blockchain has no restriction of IoT devices. Even malicious users create the grouping into the network that has been controlled by the distributed control authentication method. Further then malicious users are rejected from the decentralized network. In this paper, we propose the Hybrid consensus blockchain and PBFT algorithm ensure the safest data transaction through blockchain technology and improves the performance of the decentralized network. Finally, we have presented a Hybrid Consensus algorithm to be utilized in the PBFT method which enables the safest data transaction.
IoT group communication allows users to control multiple IoT devices simultaneously. A convenient method for implementing this communication paradigm is by leveraging software-defined networking (SDN) and allowing IoT endpoints to “advertise” the resources that can be accessed through group communication. In this paper, we propose a solution for securing this process by preventing IoT endpoints from advertising “fake” resources. We consider group communication using the constrained application protocol (CoAP), and we leverage Web of Things (WoT) Thing Description (TD) to enable resources’ advertisement. In order to achieve our goal, we are using linked-data proofs. Additionally, we evaluate the application of zero-knowledge proofs (ZKPs) for hiding certain properties of a WoT-TD file.
Marko Šarac, Nikola Pavlović, Nebojša Bačanin, Fadi Al‐Turjman · 5 authors
Internet of Things and Blockchain are considered two major technologies. Lower latency and a higher linked system number provide greater flexibility for remote execution of Internet of Things (IoT) applications. It is no secret that IoT devices often have insufficient computing capacity (both in terms of processing power and storage requirements) to support robust protection and encryption algorithms. The Internet of Things is facing many challenges such as poor interoperability, security vulnerabilities, privacy, and lack of industry standards. Cyber-attacks on IoT devices can have an impact on energy trading privacy and security. This paper suggests a method for introducing a basic interface to an IoT device’s security gateway architecture along with Blockchain to provide decentralization and authentication. It adds much-needed anonymity and versatility to IoT infrastructure, which is currently lacking. The solution enhances the reliability of data sent to remote services by applying compatible cryptographic algorithms to it before sending it. The solution’s benefits include compatibility with all IoT products and the ability to run any cryptographic algorithm on data that can be used for microgrid trading and can be initialized and securely transported over 5G or 6G network infrastructures. As a part of this work, a security procedure has been created that supports every cryptographic algorithm for all IoT devices in the network. In addition, the interface is guarded by the Blockchain technology which eliminates single control authority, records historical transactions performed by the IoT devices and provides a trust between devices.
Botnets are used by hackers to conduct cyber attacks and pose a huge threat to Internet users. The key of botnets is the command and control (C&C) channels. Security researchers can keep track of a botnet by capturing and analyzing the communication traffic between C&C servers and bots. Hence, the botmaster is constantly seeking more covert C&C channels to stealthily control the botnet. This paper designs a new botnet dubbed mp-botnet wherein bots communicate with each other based on the Stratum mining pool protocol. The mp-botnet botnet completes information transmission according to the communication method of the Stratum protocol. The communication traffic in the botnet is disguised as the traffic between the mining pool and the miners in a Bitcoin network, thereby achieving better stealthiness and flexibility.
Insecure and portable devices in the smart city’s Internet of Things (IoT) network are increasing at an incredible rate. Various distributed and centralized platforms against cyber attacks have been implemented in recent years, but these platforms are inefficient due to their constrained levels of storage, high energy consumption, the central point of failure, underutilized resources, high latency, etc. In addition, the current architecture confronts the problems of scalability, flexibility, complexity, monitoring, managing and collecting of IoT data, and defend against cyber threats. To address these issues, the authors present a distributed and decentralized blockchain-software-defined networking (SDN)-based energy-aware architecture for IoT in smart cities. Thus, SDN is continuously observing, controlling, and managing IoT devices activities and detects possible attacks in the network; blockchain provides adequate security and privacy against cyber attacks, and reduces the central point of failure issues; network function virtualization (NFV) is used to saving energy, load balancing, as well as increasing the lifetime of the entire network. Also, we introduce a cluster head selection (CHS) algorithm to reduce the energy consumption in the presented model. Finally, we analyze the performance using various parameters (e.g., throughput, response time, gas consumption, and communication overhead) and demonstrate the result that provides higher throughput, lower response time, and lower gas consumption than existing works for smart cities.
S. Fichera, Andrea Sgambelluri, Francesco Paolucci, A. Giorgetti · 7 authors
Optical network disaggregation is attracting significant consensus to avoid vendor lock-in solutions. However, the presence of network controllers, nodes, and hardware/software components potentially provided by different entities and manufacturers may lead to remarkable responsibility issues in case of service level degradation. We propose the use of the blockchain technology to provide reliable and trusted accountability of events and interactions among disaggregated network elements. Three levels of interactions are specifically considered:i)among SDN controllers,ii)between each SDN controller and the underlying network nodes, andiii)within disaggregated network nodes. The proposed solutions have been implemented and experimentally validated in a disaggregated network testbed. Results show the effectiveness of the method even in case of controversial service level degradation upon failure events. Results also show good scalability performance to retrieve/add/validate blocks recorded in the blockchain even in case of large optical network scenarios.
Healthcare professionals and scholars have emphasized the need for IoT-based remote health monitoring services to track the health of the elderly. Such systems produce a large amount of data, necessitating the security and privacy of that data. On the other hand, Software Defined Networking (SDN) integration could be seen as a good solution to guarantee both flexibility and efficiency of the network which is even more important in the case of healthcare monitoring. Furthermore, Blockchain has recently been proposed as a game-changing tool that can be integrated into the Internet of Things (IoT) to have the optimal level of security and privacy. However, incorporating Blockchain into IoT networks, which rely heavily on patients’ health sensors, is extremely difficult. In this paper, a secure Healthcare Monitoring System (HMS) is proposed with a focus on trust management issues. The architecture seeks to protect multiple healthcare monitoring system components and preserves patient privacy by developing a security interface where separate security modules can be integrated to run side by side to ensure reliable HMS. The security framework architecture we propose takes advantage of the blockchain technology as a secure and timely information back-end. STHM is a proposal that uses Software-Defined Networking (SDN) as the communication medium that allows users to access SDN’s different functional and security technologies and services. Simulation results show that the use of Blockchain for the SDN-based healthcare monitoring can ensure the desired flexibility and security for a very lightweight additional overhead.
Tooba Faisal, Mischa Döhler, Simone Mangiante, Diego López
Infrastructure sharing is a widely discussed and implemented approach and is successfully adopted in telecommunications networks today. In practice, it is implemented through prior negotiated Service Level Agreements (SLAs) between the parties involved. However, it is recognised that these agreements are difficult to negotiate, monitor and enforce. For future 6G networks, resource and infrastructure sharing is expected to play an even greater role. It will be a crucial technique for reducing overall infrastructure costs and increasing operational efficiencies for operators. More efficient SLA mechanisms are thus crucial to the success of future networks. In this work, we present "BEAT", an automated, transparent and accountable end-to-end architecture for network sharing based on blockchain and smart contracts. This work focuses on a particular type of blockchain, Permissioned Distributed Ledger (PDL), due to its permissioned nature allowing for industry-compliant SLAs with stringent governance. Our architecture can be implemented with minimal hardware changes and with minimal overheads.
R. Shashidhara, Nisha Ahuja, M. Lajuvanthi, S. Akhila · 6 authors
Abstract Software‐defined networking (SDN) is a programmable architecture for networking domain in which the security is provided by devising the network policies with the help of the network administrator. This is very cumbersome for the administrator to handle different attacks at various planes in SDN architecture. Blockchain can be used to prevent various attacks in SDN by providing a decentralization authentication environment. In this article, a secure Blockchain‐based privacy‐preserving protocol is proposed to thwart various security vulnerabilities in the SDN architecture. The proposed approach uses Modified‐Delegated Proof of Stake as the consensus protocol to ensure safety and reliability in the network. Besides, a security protocol is designed using cryptographic primitives and analyzed using a detailed security analysis. Initially, the consensus protocols are implemented using solidity smart contracts and deployed to the public Blockchain using Ethereum. Consequently, the proposed approach is simulated on OMNet++ using INET framework. The experimental results show that the proposed SDN‐Chain is secure, efficient, less incentive to centralize, and practically implementable in resource‐limited wireless and mobile environments.
Pol Alemany, Ricard Vilalta, Raül Muñoz, Ramon Casellas · 5 authors
Hierarchical Software Define Networking (SDN) architectures is used to manage the co-existence of multiple domains by having an element on top. A collaborative relation-ship between domains, might solve this issue. Blockchain may become the key element for this change to happen. This paper presents a Blockchain-based architecture to provide SDN actions to configure connectivity services in transport domains. The results presented show that the use of Blockchain is a promising candidate for inter-domain SDN control.
Software-defined wide-area network (SD-WAN) is an emerging and advanced networking platform extending software-defined networking (SDN) across multiple networking domains. Because SD-WAN manages the data plane in the networking domains separated by the public Internet, SDWAN provides a distinct environment and challenges from SDN, including greater risks for the security threats injecting control plane communications from attackers residing outside of the SDN domain. We design and build blockchain-coordinating controllers (BCC) to secure control communications of the SD-WAN controller network formed by the distributed controllers spread across multiple domains. BCC provides resiliency against the security threats in the control plane where an attacker compromises controller communications to manipulate the coordination and the operations of the other controllers. More specifically, BCC provides secure control communications even when up to n controllers’ networking credentials are compromised. BCC is also designed for modularity so that it applies generally across the controller implementations. We prototype BCC using Ethereum and smart contract on CloudLab to validate its effectiveness and efficiency. We experiment on geographically separate nodes on CloudLab and show that BCC achieves the distributed consensus at sub-second level for certificate/key distribution and for network-wide control communication synchronization.
David Breitgand, Alexios Lekidis, Rasoul Behravesh, Avi Weit · 8 authors
Network slicing is an essential 5G innovation whereby the network is partitioned into logical segments, so that Communication Service Providers (CSPs) can offer differentiated services for verticals and use cases. In many 5G use cases, network requirements vary over time and CSPs must dynamically adapt network slices to satisfy the contractual network slice QoS, cooperating and using each others’ resources, e.g. when resources of a single CSP are not sufficient or suitable to maintain all it’s current SLAs. While this need for dynamic cross-CSP cooperation is widely recognized, realization of this need is not yet possible due to gaps both in business processes and in technical capabilities.In this paper, we present a 5GZORRO approach to dynamic cross-CSP slice scaling. Our approach both enables CSPs to collaborate, providing security and trust with smart multi-party contracts, and facilitates thus achieved collaboration to enable resource sharing across multiple administrative domains, either during slice establishment or when already existing slice needs to expand or shrink. Our approach allows automating both business and technical processes involved in dynamic lifecycle management of cross-CSP network slices, following ETSI’s Zero-Touch Network and Service Management (ZSM) closed-loop architecture, and relying on resource-sharing Marketplace, Distributed Ledger (DL), and Operational Data Lake. We show how this approach is realized in truly Cloud Naive way, with Kubernetes as both business and technical cross-domain orchestrator. We then showcase applicability of the proposed solution for dynamic scaling of Content Delivery Network (CDN) service.