Counterfeit copycat devices have become one of the most important problems in IoT ecosystem. The number of IoT devices manufactured has grown exponentially through last years. In order to be competitive in terms of production cost, they usually need to assemble devices by using ready components built by other manufacturers. This scheme results in a high risk that produced IoT devices do not function properly due to malfunctioning components. This can either be related to component manufacturers trying to minimize costs or even to malicious practices for violating privacy or security of end users of such devices. In this paper a novel approach for preventing such counterfeit copycat practices is presented. The proposed methodology is based on identifying each one of the used components through the use of PUF responses and employing blockchain technology, in order to set-up a platform for tracking the supply chain of both component and IoT devices, without requiring the existence of any central authority.
Physical Unclonable Functions (PUFs) and Hardware Security
Globalization of IC supply chain has increased the risk of counterfeit, tampered, and re-packaged chips in the market. Counterfeit electronics poses a security risk in safety critical applications like avionics, SCADA systems, and defense. It also affects the reputation of legitimate suppliers and causes financial losses. Hence, it becomes necessary to develop traceability solutions to ensure the integrity of supply chain, from the time of fabrication to the end of product-life, which allows a customer to verify the provenance of a device or a system. In this article, we present an IC traceability solution based on blockchain. A blockchain is a public immutable database that maintains a continuously growing list of data records secured from tampering and revision. Over the lifetime of an IC, all ownership transfer information is recorded and archived in a blockchain. This safe, verifiable method prevents any party from altering or challenging the legitimacy of the information being exchanged. However, a chain of sales record is not enough to ensure provenance of an IC. There is a need for clone-proof method for securely binding the identity of an IC to the blockchain information. In this article, we propose a method of IC supply chain traceability via blockchain pegged to embedded physically unclonable function (PUF). The blockchain provides ownership transfer record, while the PUF provides unique identification for an IC allowing it to be linked uniquely to a blockchain. Our proposed solution automates hardware and software protocols using blockchain-powered Smart Contract that allows supply chain participants to authenticate, track, trace, analyze, and provision chips throughout their entire life cycle.
Open access
Physical Unclonable Functions (PUFs) and Hardware Security
Integrated Circuits and Semiconductor Failure Analysis
This paper concentrates on the Design of Parameterizable Implementation of SHA-256 algorithm in FPGA imparting Blockchain Concepts. SHA-256 is the key principle utilized in Blockchain architecture to impart security and privacy into a system. This one way hash function generates unique output for a given input ensuring data authenticity and non- repudiation. Blockchain technology is gaining popularity in the Internet world due to its property of decentralization. Through this implementation, main goal is to introduce this new technology into VLSI domain for securing hardware digital system designs and SOC's(System On Chip). The proposed methodology enables any bit length input message to get converted to fixed length message digest known as Hash. The design for the proposed architecture was simulated in Modelsim and synthesized in Xilinx Vivado Design Suite using Artix 7 FPGA.
Blockchain Technology Applications and Security
Physical Unclonable Functions (PUFs) and Hardware Security
Counterfeiting constitutes a major challenge in current supply chains leading to millions of dollars of lost revenue for the involved parties every year. Hardware-based authentication solutions built upon Physically Unclonable Functions (PUF) and RFID tags prevent counterfeiting in a multiparty supply chain context. Unfortunately, these solutions cannot prevent counterfeiting and duplication attacks by supply chain parties themselves, as they can simply equivocate by duplicating products in their local and unique activity ledger. In this work, we study the benefits and challenges of using distributed ledger technology (or blockchain) to prevent counterfeiting even in the presence of malicious supply chain parties. In particular, we show that the provision of a distributed and append-only ledger jointly governed by supply chain parties themselves, by means of a distributed consensus algorithm, makes permissioned blockchains such as Hyperledger Fabric a promising approach towards mitigating counterfeiting. At the same time, the distributed nature of the ledger also possesses a privacy challenge as competing supply chain parties strive to protect their businesses from the prying eyes of competitors. Additionally, we show our efforts to build a blockchain-based counterfeiting prevention system for automotive supply chains, albeit the lessons learned are seamlessly applied to other supply chains. From our experience, we highlight two lessons: (i) the requirement of adding identities other than supply chain entities themselves to facilitate the tracking of goods; and (ii) the challenges derived from privacy enforcement in such a permissioned scenario. We thus finalize this work with a set of challenges that need to be overcome to achieve the best of both worlds: a solution to the counterfeiting problem using distributed ledger technology while providing the privacy notions of interest for supply chain parties.
Blockchain Technology Applications and Security
Physical Unclonable Functions (PUFs) and Hardware Security
Nicholas Kolokotronis, Konstantinos Limniotis, Stavros Shiaeles, Romain Griffiths
Blockchain is a disruptive technology that has been characterised to be the next big thing and has already gained a broad recognition by experts in diverse fields. In this paper, we consider possible use cases and applications of the blockchain for the consumer electronics (CE) industry and its interplay with the Internet of things. Instead of discussing how the blockchain can revolutionise the supply chain, we focus on how it could be employed for enhancing the security of networked CE devices. This work is motivated by the large number of recent attacks that use easily hackable devices as a weaponry. Towards this direction, privacy and data protection aspects of blockchain solutions are also presented and are linked to regulatory framework provisions. Information on existing blockchain solutions is also provided.
Open access
2 source records
cs.CR
Blockchain Technology Applications and Security
Physical Unclonable Functions (PUFs) and Hardware Security
The widespread computer network has been changing drastically and substantially since blockchain and IoT entered the stage. Blockchain is good at protecting data transactions between logical nodes with a desirable guaranty. Internet of Things (IoT), on the other hand, by providing ultimate convenience to consumers, is expected to give rise to many various merits in a broad business scene. The security of IoT is still an open problem and if blockchain can reinforce IoT security, as many authors have hoped in recent papers, these newcomers appear to make a good collaboration to reinforce IoT security. However, software copes with logical nodes and IoT involves a vast number of physical nodes (IoT devices). Enabling blockchain to protect IoT cannot be brought to reality without respectively identifying logical and physical nodes. This is identical to the Proof-of-Trust problem. In this article, we propose a conceptual solution—Blockchained IoT—and show that this concept is able to be realized on-chip level using mass-produced dynamical random access memory (DRAM). We have completed the first test of longevity and temperature dependence (−40 °C to 105 °C) to confirm the necessary characteristics for the 5G base stations that are known to have an issue of self-heating. Furthermore, we have coarsely evaluated the probability of two DRAM IC chips being associated with an identical cyber-physical chip identification accidentally. Then, such a probability is minimal.
Open access
Physical Unclonable Functions (PUFs) and Hardware Security
Venkatachalapathy S. K. Balagurusamy, Christian James Cabral, S. Coomaraswamy, Emmanuel Delamarche · 22 authors
Blockchain technology can increase visibility in supply-chain transactions and lead to more accurate tracing of goods as well as provide evidence of whether a product is authentic or not. A shared, distributed ledger or blockchain alone, however, does not guarantee correct and trustworthy supply-chain traceability. We argue that blockchain technology (and any other digital traceability solution) must be enhanced with methods to “anchor” physical objects into information technology, Internet-of-Things and blockchain systems. Only when trust from the digital domain is extended to the physical domain can the movement of goods be accurately traced (e.g., for callbacks and provenance) and product authenticity determined. In this paper, we introduce the concept of crypto anchors, propose a classification and system architecture, and give implementation examples for different use cases and industries.
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Physical Unclonable Functions (PUFs) and Hardware Security
Sabah Suhail, Rasheed Hussain, Abid Khan, Choong Seon Hong
"Trustworthy data" is the fuel for ensuring transparent traceability, precise decision-making, and cogent coordination in the supply chain (SC) space. However, the disparate data silos act as a trade barrier in orchestrating the provenance of product story starting from the transformation of raw materials into the circuit board to the assembling of electronic components into end products available on the store shelf for customers. Therefore, to bridge the fragmented siloed information across global supply chain partners, the diffusion of blockchain (BC) as one of the advanced distributed ledger technology (DLT) takeover the on-premise legacy systems. Nevertheless, the challenging constraints of blockchain including scalability, accessing off-line data, fee-less microtransactions and many more lead to the third wave of blockchain called IOTA. In this paper, we propose a framework for supporting provenance in the electronic supply chain (ECS) by using permissioned IOTA ledger. Realizing the crucial requirement of trustworthy data, we use Masked Authenticated Messaging (MAM) channel provided by IOTA that allows the SC players to procure distributed information while keeping confidential trade flows, tamper-proof data, and fine-grained accessibility rights. To identify operational disruption, we devise a transparent product ledger through transaction data and consignment information to keep track of the complete product journey at each intermediary step during SC processes. Furthermore, we evaluate the secure provenance data construction time for varying payload size.
An enormous amount of energy is wasted in Proofof-Work (PoW) mechanisms adopted by popular blockchain applications (e.g., PoW-based cryptocurrencies), because miners must conduct a large amount of computation. Owing to this, one serious rising concern is that the energy waste not only dilutes the value of the blockchain but also hinders its further application. In this paper, we propose a novel blockchain design that fully recycles the energy required for facilitating and maintaining it, which is re-invested to the computation of deep learning. We realize this by proposing Proof-of-Deep-Learning (PoDL) such that a valid proof for a new block can be generated if and only if a proper deep learning model is produced. We present a proof-of-concept design of PoDL that is compatible with the majority of the cryptocurrencies that are based on hash-based PoW mechanisms. Our benchmark and simulation results show that the proposed design is feasible for various popular cryptocurrencies such as Bitcoin, Bitcoin Cash, and Litecoin.
Md. Mehedi Hassan Onik, Chul‐Soo Kim, Jinhong Yang
Fourth industrial revolution (Industry 4.0) promises a connected and smart manufacturing system where internet, machine (physical system) and humans lumped together. Unlike other industrial revolutions, this industrial revolution deals more with information. Device to device (D2D) and Machine to Machine (M2M) communications often generate, preserve and share private information. Personal data has already turned out to be a new commodity and currently identified as a ‘new oil’ or ‘new domain of warfare’. The more information gets generated and accumulated, the more extensive and risky the personal information becomes. Although privacy and security are often bundled together, they are different. This study investigates the privacy attack surfaces of key Industry 4.0 components (i.e. Cyber-Physical System, Artificial Intelligence, additive manufacturing, autonomous vehicle, big data, cloud computing, internet of things, distributed ledger etc). Multi-dimensional privacy challenges, data breaching incidents, regulations and need of a contextual privacy awareness is discussed in this study. Finally, this work elaborates the risk of Personally Identifiable Information (PII) leaking in the era of industry 4.0.
Open access
Blockchain Technology Applications and Security
Digital Transformation in Industry
Physical Unclonable Functions (PUFs) and Hardware Security
Trusted Execution Environments (TEEs), such as Intel SGX enclaves, use hardware to ensure the confidentiality and integrity of operations on sensitive data. While the technology is available on many processors, the complexity of its programming model and its performance overhead have limited adoption. TEEs provide a new and valuable hardware functionality that has no obvious analogue in programming languages, which means that developers must manually partition their application into trusted and untrusted components. This paper describes an approach that fully integrates trusted execution into a language. We extend the Go language to allow a programmer to execute a goroutine within an enclave, to use low-overhead channels to communicate between the trusted and untrusted environments, and to rely on a compiler to automatically extract the secure code and data. Our prototype compiler and runtime, GOTEE, is a backward-compatible fork of the Go compiler. The evaluation shows that our compiler-driven code and data partitioning efficiently executes both microbenchmarks and applications. On the former, GOTEE achieves a 5.2×throughput and a 2.3× latency improvement over the Intel SGX SDK. Our case studies, a Go ssh server, the Go tls package, and a secured keystore inspired by the go-ethereum project, demonstrate that minor source-code modifications suffice to provide confidentiality and integrity guarantees with only moderate performance overheads.
Open access
Security and Verification in Computing
Advanced Malware Detection Techniques
Physical Unclonable Functions (PUFs) and Hardware Security
The protection of smart meters (SMs) from cyberattacks is of utmost importance because SMs in advanced metering infrastructure (AMI) are physically unprotected and produce a large amount of sensitive data. Due to scalability, the SMs are small-sized and low-cost devices having low computational capabilities. The algorithms that are designed to complete the security requirements of SMs should be lightweight. To address this issue, this paper proposes a lightweight security solution to address the man-in-the-middle attack, data tempering, and blockchain-based data provenance. Received signal strength indicator (RSSI) is used to generate link fingerprints, which are used along with pseudo-random nonce to secure AMI. The proposed algorithm detects the involvement of adversarial node or meter tempering by computing other values along with 0 and 1 as the average of consecutive RSSI and difference between the RSSI of connected static SMs. Pearson correlation coefficient (ρ) of 0.9102 is achieved when no adversarial node is present in between the connected SMs having mobility in one or both SMs. Negative or approximately equal to zero values of ρ are computed when the adversary is present in the AMI or any of the SM in the AMI is forged. For blockchain-based data provenance, all the hash values of the packet header are 100% matched with the hash functions present at the data concentrator unit (DCU), which shows no adversary's involvement in AMI. For cases when the adversary is in the AMI, hash functions show no match with the hash values present at the DCU.
Open access
Electricity Theft Detection Techniques
Smart Grid Security and Resilience
Physical Unclonable Functions (PUFs) and Hardware Security
Pinchen Cui, Julie Dixon, Ujjwal Guin, Daniel DiMase
The complexity of the electronics supply chain has grown significantly due to the expansion of globalization in the 21st century. Electronic parts are now manufactured, distributed, and sold globally. Ensuring the security and integrity of the supply chain has become extremely challenging due to the widespread infiltration of untrusted hardware, specifically, counterfeit and cloned parts. Especially, the provenance of microelectronics and commercial off-the-shelf (COTS) parts becomes prohibitively difficult to track and calls for immediate solutions. In this paper, we present a non-destructive way of ensuring the traceability of electronic parts in the supply chain. We have implemented a blockchain-based framework, which helps to track and trace every chip while they are circulating in the supply chain. The proposed framework is built upon a permissioned blockchain. Hyperledger is used for implementing this framework. A detailed analysis is carried out to present the feasibility of our proposed approach.
Open access
Physical Unclonable Functions (PUFs) and Hardware Security
Establishing a root-of-trust is a key early step in establishing trust throughout the lifecycle of a device, notably by attesting the running software. A key technique is to use hardware security in the form of specialised modules or hardware functions such as TPMs. However, even if a device supports such features, other steps exist that can compromise the overall trust model between devices being manufactured until decommissioning. In this paper, we discuss how blockchains, and smart contracts in particular, can be used to harden the overall security management both in the case of existing hardware-enhanced security or when only software attestation is possible.
Security and Verification in Computing
Physical Unclonable Functions (PUFs) and Hardware Security
Data provenance and data integrity are among the key concerns in IoT based environments such as smart cities, smart grids, and vehicular networks etc. Many IoT devices suffer from both impersonation and data tampering attacks due to their architectural and computational limitations, which are unable to provide adequate level of security. This paper aims to provide and enforce data provenance and data integrity in IoT environments by using Physical Unclonable Functions (PUFs) and Ethereum, a blockchain variant with smart contracts. PUFs provide unique hardware fingerprints to establish data provenance while Ethereum provides a decentralized digital ledger which is able to withstand data tampering attacks.
Physical Unclonable Functions (PUFs) and Hardware Security
Oct 1, 2018·2018 IEEE SmartWorld, Ubiquitous Intelligence & Computing, Advanced & Trusted Computing, Scalable Computing & Communications, Cloud & Big Data Computing, Internet of People and Smart City Innovation (SmartWorld/SCALCOM/UIC/ATC/CBDCom/IOP/SCI)
Protection of IPs through watermarking techniques is prevalent to prevent IP infringement. In previous researches, authentication of watermark in IPs easily disclosures sensitive information of real embedded watermarks, where the evidence of identifying IP ownership may be attacked by illegal verifiers. Despite several watermark detection techniques can address the disclosure of sensitive information in detection procedure, the efficiency for such a detection remains relatively low. Besides, it may yield to large communication overhead on multiple authentication rounds. Motivated by the needs of robustness and efficiency, it is proposed in this work a leakage-resilient protocol to authenticate ownership of Field Programmable Gate Array (FPGA) bitfile design using zero-knowledge proof. The prover can convince the verifier that he knows a secret in the suspected bitfile design via only one interaction. Real locations of watermarks are concealed through location anonymity. With the received authentication package from the prover, the verifier cannot obtain other useful information about watermarks. From experiments, we show that the proposed authentication technique achieves high efficiency and robustness on watermark detection.
Physical Unclonable Functions (PUFs) and Hardware Security
Advanced Steganography and Watermarking Techniques
Big data technology has brought innovation and convenience to many areas, such as medical diagnosis, financial investment and smart travel. However, one of the most urgent challenges is how to collect massive private data from end customers effectively without invasion of privacy. In this paper, a framework, called Trusted Big Data Collection and Trade (TBDCT) system, is proposed to provide a fair and trusted platform for every participant in big data world. Firstly, by adopting technology of Physical Unclonable Function (PUF), data is binded with the 'fingerprint' of the sensor to identify the authenticity of source. Secondly, private network attached storage embedded with Trusted Security Module (TSM) is used to guarantee the trustability of collecting process. Lastly, blockchain is implemented in this system to provide uncentralized accounting and trading platform. With this framework, private data can be traded and the conflict between private data shortage and invasion of privacy can be mitigated. The experiment demonstrates the feasibility of the proposed TBDCT.
Blockchain Technology Applications and Security
Physical Unclonable Functions (PUFs) and Hardware Security
Advanced Steganography and Watermarking Techniques
With ubiquitous adoption of connected sensors, actuators and smart devices are finding inroads into daily life. Internet of Things (IoT) authentication is rapidly transforming from classical cryptographic user-centric knowledge based approaches to device signature based automated methodologies to corroborate identity between claimant and a verifier. Physical Unclonable Function (PUF) based IoT authentication mechanisms are gaining widespread interest as users are required to access IoT devices in real time while also expecting execution of sensitive (even physical) IoT actions immediately. This paper, delineates combination of BlockChain and Sensor based PUF authentication mechanism for solving real-time but non-repudiable access to IoT devices in a Smart Home by utilizing a mining less consensus mechanism for the provision of immutable assurance to users' and IoT devices' transactions i.e. commands, status alerts, actions etc.
Physical Unclonable Functions (PUFs) and Hardware Security
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
Blockchain technology has brought a huge paradigm shift in multiple industries, by integrating distributed ledger, smart contracts and consensus protocol under the same roof. Notable applications of blockchain include cryptocurrencies and large-scale multi-party transaction management systems. The latter fits very well into the domain of manufacturing and supply chain management for Integrated Circuits (IC), which, despite several advanced technologies, is vulnerable to malicious practices, such as overproduction, IP piracy and deleterious design modification to gain unfair advantages. To combat these threats, researchers have proposed several ideas like hardware metering, design obfuscation, split manufacturing and watermarking. In this paper, we show, how these issues can be complementarily dealt with using blockchain technology coupled with identity-based encryption and physical unclonable functions, for improved resilience against certain adversarial motives. As part of our proposed blockchain protocol, titled `BLIC', we propose an authentication mechanism to secure both active and passive IC transactions, and a composite consensus protocol designed for IC supply chains. We also present studies on the security, scalability, privacy and anonymity of the BLIC protocol.
Physical Unclonable Functions (PUFs) and Hardware Security
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
Imposter devices pose serious threats. The majority of low-cost edge devices can easily be counterfeited or cloned; the supply chain is insufficiently secure. Reliability of deployed devices can be called into question simply because they might be counterfeit or cloned. It is a must to identify edge devices' sourcing uniquely and verify their validity periodically at runtime. We integrate blockchain technology to authenticate resource-constrained, low-cost edge devices. We use SRAM-based physically unclonable functions (PUFs)to generate unique “digital fingerprints” (device IDs). Registered manufacturers upload a cryptographic hash of each device ID to a “globally accessible” blockchain instance (key-value store or smart contract). While registering/designating a device locally, the end-user verifies whether the hash is present in that blockchain. We utilize a “locally permissioned” blockchain infrastructure (which is still a globally managed blockchain or, in future, a sidechain)to authenticate edge devices for a defense-in-depth approach. Devices can authenticated periodically to prevent device cloning. Target environments can be large and have varied trust among users and lack a specific perimeter; this “local” blockchain methodology is thus pertinent, especially since blockchains gain security over time. Our approach reduces the potential for classes of information leakage and types of sabotage in a critical infrastructure or large-scale deployment (such as a smart city)arising from imposter devices. This methodology protects against such imposters in mobile settings within an IoT infrastructure too.
Physical Unclonable Functions (PUFs) and Hardware Security
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
Current blockchains often are designed with one use case in mind, such as currency transfer in Bitcoin or record storage in Namecoin. While application-specific blockchains are powerful tools for fulfilling their niche use cases, there are blockchains like Ethereum that have a set of use cases comprising a superset of the use cases of many blockchains. These generalized blockchains are powerful tools for extending decentralization to new use cases without designing entirely new blockchains. This paper considers tradeoffs in the design and implementation of blockchain systems that intend to deliver general functionality and examines various current and Merged-mining, fragmentation, the network effect, scalability, and generalized blockchain approaches are all considered and put into context. Bitcoin, Ethereum, Cardano, and Rootstock are considered in various aspects of the current limitations, and potential future solutions to problems noted. This paper weighs the chances of success of various generalized blockchain paradigms, including the network effect scalability and potential client-side use. We conclude that the network effect likely favors a Bitcoin/sidechain solution while scalability favors a direct Ethereum solution. The likelihood of success of mainstream adoption of any single decentralized application appears to favor an Ethereum solution.
Blockchain Technology Applications and Security
Physical Unclonable Functions (PUFs) and Hardware Security
In this vision paper, we present an approach that makes it possible to protect developed ideas and early concepts even during their systematical development. We take the Design Thinking process as an example, in which interfaces are used for individual stages (understand, observe, define, ideate, prototype, test) to digitally record verbal, written or sketched, and even modeled or constructed outcome. This outcome is recorded and linked to the originating person. To guarantee both proof-of-existence and proof-of-origin, a unique hash is generated from each digital artifact stored and embedded into the Bitcoin Blockchain by the OriginStamp decentralized trusted timestamping service. Once this unique fingerprint is embedded in a transaction in the underlying Blockchain network, it can be proven where particular contributions originated due to the characteristics of Blockchain architecture. By setting up a decentralized tamper-proof means of record keeping, the entire innovation chain from the first ideation to the beginning of production is verifiably stored. By providing a clear proof-of-origin, all innovators (even competitors) could continue to work on existing problem-solving process and add their contribution proportionately, depending on the state of innovation development. This concept enables an Open Innovation ecosystem, which has the potential to increase the innovation potential of companies immensely. Additionally, inventions that are not patentable because they do not comply with the strict regulations of patent law can still be published and protected because the information about the origin of the respective contribution is guaranteed.
Open access
Computability, Logic, AI Algorithms
Physical Unclonable Functions (PUFs) and Hardware Security