5G networks are expected to provide cost-efficient, reliable, and flexible services for industrial productions and applications potentially, by introducing emerging network technologies like blockchain and network functions virtualization (NFV), which virtualizes network functions and runs them on standard infrastructure rather than customized hardware. However, how to deal with the emerging security challenges and fulfil the requirement of ultra-reliable and low-latency communications (URLLC) has not been fully resolved. In this article, we present an NFV-enabled 5G paradigm for the industry with the guarantee of URLLC through service chain acceleration and dynamic blockchain-based spectrum resource sharing among a variety of industry applications running in NVF-based equipment. First, we elaborate the benefits and shortcomings of NFV for industry, by executing an industry application experiment in virtualized and nonvirtualized data center networks. Then, we illustrate an NFV-enabled 5G paradigm for URLLC in detail, with a special focus on the service chain acceleration and spectrum sharing built on NFV, blockchain, software-defined networking, and mobile edge computing. Finally, we establish a mathematical model to study the worst-cast transmission latency of NFV-enabled 5G with the input of the bursty traffic. The proposed model can be exploited to support the plan, management, and optimization of NFV-enabled 5G URLLC systems for industry.
Qiwei Hu, Wei Wang, Xiang Bai, Shi Jin · 5 authors
Recent years have witnessed a blooming of new applications that demand different network services. Network slicing is advocated by the research community to simultaneously support multiple services on a common physical infrastructure. Federated network slicing, which involves multiple operators, further generalizes the concept to cover a broader range. Existing federated slicing systems advocate the master-slave architecture among untrusted operators, which brings some centralization concern, making operators hesitate to join the system. Recently, blockchain shows great power to build trust in decentralized environments. Besides, artificial intelligence (Ai), especially reinforcement learning, is envisioned with the potential to develop more efficient optimization algorithms. Motivated by innovations in blockchain, smart contract, and Ai, this article proposes a decentralized federated slicing architecture that is trustful and efficient. We systematically discuss the design principles and key challenges in realizing the blockchain-enabled architecture. With these principles and challenges in mind, we develop a general architecture for multiple operators and cloud providers, with a new proof of business consensus protocol to ensure incentive and fairness. To further enhance its efficiency, we utilize reinforcement learning to accelerate optimizations in the resource allocation. Benefits of the Ai accelerated optimizer are demonstrated in simulations.
Mohammed Amine Togou, Ting Bi, Kapal Dev, Kevin McDonnell · 7 authors
5G technology is expected to enable many innovative applications in different verticals. These applications have heterogeneous performance requirements (e.g., high data rate, low latency, high reliability, and high availability). In order to meet these requirements, 5G networks endorse network flexibility through the deployment of new emerging technologies, mainly network slicing and mobile edge computing. This article introduces a distributed blockchain-enabled network slicing (DBNS) framework that enables service and resource providers to dynamically lease resources to ensure high performance for their end-to-end services. The key component of our framework is the global service provisioning (GSP), which provides admission control for incoming service requests along with dynamic resource assignment by means of a blockchain-based bidding system. The goal is to improve users' experience with diverse services and reduce providers' capital and operational expenditures.
Bitcoin's throughput is far lower than those of centralized systems such as Visa and PayPal. To handle a comparable number of transactions, Bitcoin's throughput must be improved, which will require a reduction in the block propagation time. Relay networks have attracted attention as a method to improve throughput. However, the nature and strength of the effects of relay networks are not yet clear. In particular, the effects on individual nodes have received little attention. Thus, this study aims to investigate the effects of relay networks on the Bitcoin network and its nodes under the current network state in approximately 2019. We simulate a relay network under the current network state because simulation is virtually the only way to obtain data for all nodes. A major contribution of this study is that it is the first to investigate the relay network effect on the 90th percentile of block propagation time. Moreover, this study shows that relay networks benefit not only the system but also the nodes utilizing them. The utilizing nodes' blocks were more than six times more likely to be approved as valid blocks when nonutilizing and utilizing nodes generated blocks simultaneously. This finding can motivate the use of nodes in relay networks.
2 source records
Blockchain Technology Applications and Security
Caching and Content Delivery
Advanced Steganography and Watermarking Techniques
The most recent development of the Internet of Things brings massive timely sensitive and bursty data flows. Also, joint optimization on storage, computation, and communication is in need for multiaccess edge computing frameworks. The adaptive network control has been explored using deep reinforcement learning (RL), but it is not sufficient for bursty network traffic flows, especially when the network traffic pattern may change over time. We formulate the routing control in an environment with time-variant link delays as a Lyapunov optimization problem. We identify that there is a tradeoff between optimization performance and modeling accuracy when the propagation delays are included. We propose a novel deep RL (DRL)-based adaptive network routing method to tackle the issues mentioned above. A Lyapunov optimization technique is used to reduce the upper bound of the Lyapunov drift, improving queuing stability in networked systems. By modeling the network traffic pattern using the Markovian arrival process, we show that network routing problems can be modeled as Markov decision processes and value-iteration-based RL methods can be used to solve them. We design a blockchain-based protocol using proof of elapsed time consensus mechanism to ensure a trustworthy network statistics information exchange for the routing framework. Experiment results show that the proposed method can learn a routing policy and adapt to the changing environment. The proposed method outperforms the baseline backpressure method in multiple settings and converges faster than existing methods. Moreover, the DRL module can effectively learn a better estimation of the long-term Lyapunov drift and penalty functions, providing superior results in terms of the backlog size, end-to-end latency, age of information, and throughput. Furthermore, the blockchain-based network statistics exchange can provide the routing framework against malicious nodes. In addition, the proposed model performs well under various topologies, and thus can be used in general cases.
Andrea Ceccarelli, Marcello Cinque, Christian Esposito, Luca Foschini · 6 authors
The industrial Internet of Things (IIoT) is currently foreseen as a foundation to implement the Industry 4.0 vision. However, device heterogeneity and the need of integration and configuration exposes the industrial infrastructure to potential threats, such as black-hole, man-in-the-middle, and malicious configuration attacks. In this article, we investigate how to manage distributed trust information and to enable trusted configuration actions in the IIoT, by opportunistically intermingling blockchain with the software defined networking and container orchestration technologies. In particular, we focus on how the joint and coordinated adoption of such technologies can make technicians’ interventions on industrial equipment both easier and more trusted. To this purpose, we present the design of a software architecture to simplify the management, configuration, and assessment of IIoT systems, and we discuss our experiences with the application of the proposed architecture in a railways use case.
Open access
Physical Unclonable Functions (PUFs) and Hardware Security
Virtual Network Functions allow the effective separation between hardware and network functionality, a strong paradigm shift from previously tightly integrated monolithic, vendor, and technology dependent deployments. In this virtualized paradigm, all aspects of network operations can be made to deploy on demand, dynamically scale, as well as be shared and interworked in ways that mirror behaviors of general cloud computing. To date, although seeing rising demand, distributed ledger technology remains largely incompatible in such elastic deployments, by its nature as functioning as an immutable record store. This work focuses on the structural incompatibility of current blockchain designs and proposes a novel, temporal blockchain design built atop federated byzantine agreement, which has the ability to dynamically scale and be packaged as a Virtual Network Function (VNF) for the 5G Core.
The Internet of Things (IoT) is evolving from a stovepipe architecture to a collaborative and shared converged architecture. In the future, it will become a network development trend to construct a network-based virtual operating platform by virtualizing the IoT infrastructure to support different IoT services. The trust issues encountered during resource aggregation in heterogeneous networks and state measurements limit the applicability of the virtual network operating platform. In this article, we propose a framework for an endogenous trusted network to support virtual network operation, provide shared services externally, allocate resources internally, and implement artificial-intelligence-driven customization services for trusted virtual resources for the IoT. We use the consortium blockchain to establish the endogenous trusted framework for heterogeneous networks through software-defined networking and network function virtualization. In this framework, we design a mechanism for on-chain and off-chain collaborative resource allocation. The framework integrates time prediction algorithms and resource allocation algorithms to predict resource demand and allocate resources to achieve customization and dynamic adjustment. The application of this framework in specific scenarios is described using application examples.
Pol Alemany, Ricard Vilalta, Raül Muñoz, Ramon Casellas · 5 authors
This paper presents a non-hierarchical architecture to deploy End-to-End Network Slices in a multi-domain network using an Ethereum-based Blockchain to manage the Network Slicing requests across domains. The use of Blockchain aims to look towards a collaboration vision to deploy Networks Slices using the resources to deploy them as if they would be placed under the domain of the Network Slice requester. The authors describe a possible instantiation procedure and they present results showing how much the use of Blockchain might increase the deployment time of an End-to-End Network Slice.
The promise of disparate features envisioned by the 3GPP for 5G, such as offering enhanced Mobile Broadband connectivity while providing massive Machine Type Communications likely with very low data rates and maintaining Ultra Reliable Low Latency Communications requirements, create a very challenging environment for protecting the 5G networks themselves and associated assets. To overcome such complexity, future 5G networks must employ a very high degree of network and service management automation, which is a security challenge by itself as well as an opportunity for smarter and more efficient security functions. In this paper, we present the smart, trustworthy and liable 5G security platform being designed and developed in the INSPIRE-5Gplus1 project. This platform takes advantage of new techniques such as Machine Learning (ML), Artificial Intelligence (AI), Distributed Ledger Technologies (DLT), network softwarization and Trusted Execution Environment (TEE) for closed-loop and end-to-end security management following a zero-touch model in 5G and Beyond 5G networks. To this end, we specifically elaborate on two key aspects of our platform, namely security management with Security Service Level Agreements (SSLAs) and liability management, in addition to the description of the overall architecture.
Pervasive edge computing (PEC) is an emerging paradigm for the industrial Internet of Things (IIoT), and software-defined networks (SDN) offer lower latency services, and massive intelligent devices connectivity for the IIoT. However, the PEC has some issues with data security, and privacy while PEC devices sharing data among edges. What's more, the centralized SDN suffers from single point of attacks such as distributed denial of service (DDoS) from IIoT devices, and has the challenge of data leakage. In this article, we use blockchain, and proxy reencryption (PRE) technologies to tackle these challenges. The blockchain authorizes all devices in the network to improve their credibility, and authenticity. In addition, a blockchain-based data sharing framework that combines a PRE scheme is introduced for secure device-to-device communication in PEC environments. A series of smart contracts are designed for flexible operations of searching, and updating records on the blockchain. The experiments reveal that our design is highly efficient, and has high performance.
Jovan Nikolić, Nursultan Jubatyrov, Evangelos Pournaras
Large-scale decentralized systems of autonomous agents interacting via\nasynchronous communication often experience the following self-healing dilemma:\nfault detection inherits network uncertainties making a remote faulty process\nindistinguishable from a slow process. In the case of a slow process without\nfault, fault correction is undesirable as it can trigger new faults that could\nbe prevented with fault tolerance that is a more proactive system maintenance.\nBut in the case of an actual faulty process, fault tolerance alone without\neventually correcting persistent faults can make systems underperforming.\nMeasuring, understanding and resolving such self-healing dilemmas is a timely\nchallenge and critical requirement given the rise of distributed ledgers, edge\ncomputing, the Internet of Things in several energy, transport and health\napplications. This paper contributes a novel and general-purpose modeling of\nfault scenarios during system runtime. They are used to accurately measure and\npredict inconsistencies generated by the undesirable outcomes of fault\ncorrection and fault tolerance as the means to improve self-healing of\nlarge-scale decentralized systems at the design phase. A rigorous experimental\nmethodology is designed that evaluates 696 experimental settings of different\nfault scales, fault profiles and fault detection thresholds in a prototyped\ndecentralized network of 3000 nodes. Almost 9 million measurements of\ninconsistencies were collected in a network, where each node monitors the\nhealth status of another node, while both can defect. The prediction\nperformance of the modeled fault scenarios is validated in a challenging\napplication scenario of decentralized and dynamic in-network data aggregation\nusing real-world data from a Smart Grid pilot project. Findings confirm the\norigin of inconsistencies at design phase.\n
Software Defined Networking (SDN) is a promising platform to secure and manage large-scale Internet of Things (IoT) due to its separated control and data plane functionality as well as programmability in the network. The original design of SDN faces single point of failure, and therefore several decentralized SDN architectures for IoT were proposed. However, practical SDN may be deployed by various networking operators, which incurs the conflict between data security of different networking operators and cooperative network management among them. Existing schemes cannot well support the cooperative network management among multiple controllers and meanwhile guarantee data security. To tackle this problem, we propose a blockchain based SDN framework for IoT called BS-IoT. BS-IoT introduces blockchain into SDN to support secure and cooperative network management. Besides, we leverage blockchain sharding for better efficiency and improve it with secure multi-party computation (SMPC) to make it suitable for decentralized SDN management with data security. The security analysis illustrate the security and effectiveness of our scheme.
In this paper, we propose a Blockchain-based solution for the recovery of an SDN controller back to a previously known state upon sudden failure. A lightweight minimal Blockchain ledger containing metadata details about each controller event is maintained by the switches. The set of all instructions given by the controller to the switches denotes the state of the controller at that instant. Whenever a new event occurs, the meta-information about it gets stored in the Blockchain which is updated in the switches after regular epochs. Upon sudden failure and subsequently coming back online again, the controller downloads all the tables and information from the respective switches. It checks and compares the metadata contained in the Blockchain with those data received from the switches. In addition to the existing security services provided by Blockchain, the proposed scheme can further solve the controller failure problem. The performance of the proposed solution is measured through simulation. The proposed scheme with the metadata-based solution saves about 75% of space and a controller can securely recover with a duration of 50 Sec.
Software defined networking (SDN) is the promising technology for the future network with the advantage of isolating the control plane form the data plane. Through SDN, physical network resources can be softwarized and virtualized easily. In future network scenarios, end users usually have customized resource demands, modeled as virtual network requests (VNRs). Hence, these VNRs need to be allocated and implemented efficiently, called as virtual network embedding (VNE). As one of the key issues in SDN, secure softwarized and virtualized resource allocation, especially in certain network scenarios with high security requirements, calls for significant attention in the literature. In this paper, we research the virtual network embedding for secure SDN, using the blockchain technology. VNE problem model for secure SDN is firstly presented. Then, it is the security model for SDN. Next, we propose our blockchain-based VNE algorithm for secure SDN. Aiming at validating our blockchain-based algorithm efficiency, we execute the experiment evaluation. Experiment results show that our blockchain-based algorithm performs better than its counterpart without blockchain technology, in terms of fault tolerant performance.
Sudip Misra, Pallav Kumar Deb, Nidhi Pathak, Anandarup Mukherjee
Software-Defined Network (SDN) is vital in simplifying the dynamic network characteristics and device management. However, the centralized architecture of SDN opens the scope for malicious attacks on the controllers. To mitigate such attacks in real-time, we propose an SDN architecture for resource-constrained devices in a fog-enabled IoT environment using a private blockchain (pBC) network. We exploit the decentralized nature of pBC for enabling resource-constrained SDN controllers towards transparently setting flow rules for fog nodes and other devices in the network. In case the miners identify faulty flow rules, pBC allows the SDN devices/fog nodes to retract back to an earlier flow rule while raising a flag against the alleged controller. Additionally, since data in pBC are accessible by all the candidates having the same genesis file, they are readily available to malicious users. Towards this, we further propose encrypting the data before inserting them into the blocks, which helps in securing the data from undesired users. Through the extensive deployment of our proposed fusion, we observe CPU usage of 30% among the devices and latencies in the range of milliseconds, which presents the feasibility of our system with minimum delay. We also observe a reduction in energy consumption by more than 90%, compared to traditional SDN.
The basic idea of Software Defined Networks (SDNs) is to centralize the control plane and make it programmable using generic APIs. In SDNs, the network intelligence resides within the controller which is considered as the heart of the entire network. The network principles are programmed as controller applications by the administrator using the generic APIs at the North Bound. Though SDNs improve the programmability of the network, the centralized control and flexibility are offered at the cost of security vulnerabilities at various surfaces in the SDN stack. Fortunately, the programmable control plane allows enforcing a sophisticated security policy that can be easily customized for securing the network. Many research studies reveal that the major threat in SDNs is the single point of failure. Any failure in the controller will impact the overall functionality of the network due to which compromising the controller has become the primary target of attackers. Hence, the security of the controller plays a crucial role in the success of SDNs. Besides securing the controller, the overall security of the network is equally important. In this paper, the authors proposed a security model based on Blockchain technology for ensuring consistency among instances of the SDN controller with enhanced security. The said security model is proposed considering the operational flow of the OpenDaylight (ODL) controller as a case study, but can be implemented with any SDN controller.
Durbadal Chattaraj, Sourav Saha, Basudeb Bera, Ashok Kumar Das
Software Defined Networking (SDN) becomes a de facto standard for the future Internet. SDN decouples the control plane from the data plane of a proprietary network asset to ensure better programmability and security for designing more innovative future network applications. Presently, the SDN framework does not have proper access control mechanism among different entities, namely SDN applications, SDN controllers and switches. To achieve this goal, this paper proposes a blockchain-based access control scheme for the SDN framework. The proposed scheme has the capability to resist various well-known attacks and alleviate the existing single point of controller failure issue in SDN.
With the increase of IOT devices worldwide, Software-Defined Networking (SDN) has emerged as a critical tool to optimize and manage congested IP networks. The challenges faced with such networks are achieving optimal resource allocation and traceability. Network operators face network security attacks (eg. MITM) causing a breach in Service-Level Agreements (SLA). Traditional solutions have aimed to improve this using algorithms and additional hardware. This paper presents DecOp, a new methodology in operating a network based on peers instead of a centralized algorithm using Blockchain (BC). BC is a growing technology that is used primarily in the financial industry (eg. BITCON and ETHEREUM) because of its ability to bring dependable consensus amongst several users using distributed ledgers. DecOp makes use of the existing platforms infrastructure to process and store network configurations. This allows for a modular solution that can be implemented and verified with varying platforms. We designed a new method to allocate resources by integrating SDN and BC using the designed Secure Service Contract (SSC) chaincode, Secure Network Operator (SNO) chaincode, and modular communication middleware. This provides a dependable traceability by storing changes to the network state in an immutable ledger. A prototype is developed and tested with Hyperledger Fabric as the BC platform and OpenDaylight as the SDN Controller. Evaluation results focus on system performance versus the BC Network size, from 12 to 40 peers.
The advent of 5G has sparked interest in Wi-Fi offloading techniques that enable efficient resource sharing and congestion management of wireless communication spectrum. However, offloading data between multiple networks (i.e. service providers) requires costly inter-provider communication which has a substantial overhead as well as high offloading latency. Moreover, involvement of the profit-oriented decision making of service providers has an inherent weakness of unfair scheduling among users and networks. To overcome those problems, this research work proposes a holistic framework similar to an online data market place where existing infrastructure can be used to set up Wi-Fi zones that everyone can use from their own data plan irrespective of the network operators they belong to. First, our proposed architecture improves the efficacy of offloading by using decentralized nature of the emerging Software-Defined Networking (SDN) to set up an operator-assisted data offloading platform, resulting in efficient inter-provider communication. Second, our proposal strengthens the fair scheduling of offloading resources by using blockchain technology to initiate unbiased and independent decision making. The resulting service is a rating system for the sellers to make reliable transactions for payments.
Mohammed Amine Togou, Ting Bi, Kapal Dev, Kevin McDonnell · 7 authors
5G technology is expected to enable a plethora of new applications with distinct requirements. Provisioning resources to accommodate such applications implies having a flexible network infrastructure that can be tailored to the specific needs of each application. This can be achieved through network slicing. Still, several applications might request network slices, but their request may not be fulfilled due to lack of resources or lack of coverage and provisioning such resources is a cumbersome task. This paper describes an architecture that facilitates the dynamic leasing of resources among network operators to support cross-domain services. The cornerstone of this architecture is a brokering layer, called DBB, that relies on a blockchain-based bidding system to request resources and evaluate resource provisioning offers. The paper also presents a simulation-based use case scenario that illustrates the need for DBB and which was used to evaluate the performance of the proposed architecture.
Zakaria Abou El Houda, Abdelhakim Hafid, Lyes Khoukhi
Nowadays, blockchain technology is seen as one of the main technological innovations to emerge since the advent of the internet. Many applications can benefit from blockchain to protect their exchanges. Nonetheless, applications with more restricted interests cannot use public blockchains. Permissioned blockchains promise to combine effectiveness of blockchains with stricter permissions to join blockchain's network. In permissioned blockchain, the number of participating entities is limited compared to public blockchain. However, by targeting the peers of the blockchain, the attackers can easily take control of consensus process and halt the blockchain operations. In this paper, we propose BrainChain, a scalable and efficient scheme to protect permissioned blockchain nodes from the largest ever Distributed Denial of Service (DDoS) attack (i.e., Domain Name System (DNS) amplification attack) in the context of software defined networks (SDN). BrainChain consists of 4 schemes: (1) Flow statistics collection scheme (FS) to gather the features of flows in an efficient way using sFlow; (2) Entropy based scheme (ES) to measure disorder of network features; (3) Bayes Network based Filtering scheme (BF) to classify, based on entropy values, illegitimate DNS requests; and (4) DNS Mitigation (DM) scheme to mitigate in an effective way the illegitimate flows (i.e., illegitimate DNS requests). Experimental results show that BrainChain can quickly and effectively detect and mitigate the attacks (i.e., DNS amplification attacks) with a high accuracy and a small false positive rate making it a promising scheme to protect blockchain applications from DNS Amplification attacks.