Caciano dos Santos Machado, Renan R. S. dos Santos, Carla Merkle Westphall
Community networks are prone to free-riders, i.e., participants who take advantage of cooperation from others' routers but do not contribute reciprocally. In this paper, we present HARPIA, a system for credit-based incentive mechanisms for data forwarding in community networks aimed to prevent selfish behavior. HARPIA does not require a trusted third-party or tamper-resistant security modules as in other incentive mechanisms. Instead, it uses a distributed accounting scheme (DPIFA) to estimate the balance of data forwarding contribution and consumption of each network router and settle correspondent cryptocurrency debts on an Ethereum smart contract. On-chain settlement transactions are performed every HARPIA cycle (e.g., daily, weekly, monthly) and must be validated by at least m-of-n network routers using a multi-signature scheme (MuSig). We also realized a performance evaluation, security threat assessment, and cryptocurrency costs estimation. Results show that our proposal is suitable for community networks with up to 64 infrastructure routers under specific m-of-n MuSig thresholds.
Andreas Rumsch, Christoph Imboden, Alberto Calatroni, Martin Camenzind · 6 authors
More and more household appliances connect to the Internet and exchange data freely. This is the foundation for true smart buildings. However, there is still no uniform communication technology available, which can connect all appliances from all vendors. Protocols differ between manufacturers making interoperability difficult or even impossible. Manufacturers cannot rely on a reference for the implementation and real estate developers and operators are reluctant to commit to a system until it is clear which one will prevail. A similar situation is evident in smart grids and applies equally to the energy supply industry. This fragmentation ultimately leads to missed opportunities in terms of business models which could connect customers with service providers. We present a first draft of an architecture: SINA - Smart Interoperability Architecture. SINA is based on existing decentralized infrastructure, which avoids creating a dependency of the market participants on an overpowering service provider. The core element of the technical solution is an open-source module integrated in the private clouds of the manufacturers, energy suppliers and service providers. The architecture addresses problems of data ownership, privacy and data security avoiding central administrative structures. It manages data access and transfer in a decentralized and distributed system. SINA uses a blockchain and smart contracts to make sure that the pieces of information about which data are accessed, by whom they are accessed, how they are processed, and which monetary transactions take place are immutably stored and made available. This allows providers to offer services to users in a transparent and trustworthy manner. Finally, SINA includes a matchmaking block which helps service providers find potential customers and vice versa. This set of features makes SINA unique.
With the continuous expansion of Internet of Things (IoT) devices, edge computing mode has emerged in recent years to overcome the shortcomings of traditional cloud computing mode, such as high delay, network congestion, and large resource consumption. Thus, edge-thing systems will replace the classic cloud-thing/cloud-edge-thing systems and become mainstream gradually, where IoT devices can offload their tasks to neighboring edge nodes. A common problem is how to utilize edge computing resources. For the sake of fairness, double auction can be used in the edge-thing system to achieve an effective resource allocation and pricing mechanism. Due to the lack of third-party management agencies and mutual distrust between nodes, in our edge-thing systems, we introduce blockchains to prevent malicious nodes from tampering with transaction records and smart contracts to act as an auctioneer to realize resources auction. Since the auction results stored in this blockchain-based system are transparent, they are threatened with inference attacks. Thus in this paper, we design a differentially private combinatorial double auction mechanism by exploring the exponential mechanism such that maximizing the revenue of edge computing platform, in which each IoT device requests a resource bundle and edge nodes compete with each other to provide resources. It can not only guarantee approximate truthfulness and high revenue, but also ensure privacy security. Through necessary theoretical analysis and numerical simulations, the effectiveness of our proposed mechanisms can be validated.
Marc Jayson Baucas, Petros~Spachos, Konstantinos Plataniotis
The number of embedded devices that connect to a wireless network has been growing for the past decade. This interaction creates a network of Internet of Things (IoT) devices where data travel continuously. With the increase of devices and the need for the network to extend via fog computing, we have fog-based IoT networks. However, with more endpoints introduced to it, the network becomes open to malicious attackers. This work attempts to protect fog-based IoT networks by creating a platform that secures the endpoints through public-key encryption. The servers are allowed to mask the data packets shared within the network. To be able to track all of the encryption processes, we incorporated the use of permissioned blockchains. This technology completes the security layer by providing an immutable and automated data structure to function as a hyper ledger for the network. Each data transaction incorporates a handshake mechanism with the use of a public key pair. This design guarantees that only devices that have proper access through the keys can use the network. Hence, management is made convenient and secure. The implementation of this platform is through a wireless server-client architecture to simulate the data transactions between devices. The conducted qualitative tests provide an in-depth feasibility investigation on the network's levels of security. The results show the validity of the design as a means of fortifying the network against endpoint attacks.
Abstract The number of users approaching the world of cryptocurrencies exploded in the last years, and consequently the daily interactions on their underlying distributed ledgers have intensified. In this paper, we analyze the flow of these digital transactions in a certain period of time, trying to discover important insights on the typical use of these technologies by studying, through complex network theory, the patterns of interactions in four prominent and different Distributed Ledger Technologies (DLTs), namely Bitcoin, DogeCoin, Ethereum, Ripple. In particular, we describe the Distributed Ledger Network Analyzer (DiLeNA), a software tool for the investigation of the transactions network recorded in DLTs. We show that studying the network characteristics and peculiarities is of paramount importance, in order to understand how users interact in the DLT. For instance, our analyses reveal that all transaction graphs exhibit small world properties.
The emergence of Intelligent Connected Vehicles (ICVs) shows great potential for future intelligent traffic systems, enhancing both traffic safety and road efficiency. However, the ICVs relying on data driven perception and driving models face many challenges, including the lack of comprehensive knowledge to deal with complicated driving context. In this paper, we are motivated to investigate cooperative knowledge sharing for ICVs. We propose a secure and efficient directed acyclic graph (DAG) blockchain based knowledge sharing framework, aiming to cater for the micro-transaction based vehicular networks. The framework can realize both local and cross-regional knowledge sharing. Then, the framework is applied to autonomous driving applications, wherein machine learning based models for autonomous driving control can be shared. A lightweight tip selection algorithm (TSA) is proposed for the DAG based knowledge sharing framework to achieve consensus and identity verification for cross-regional vehicles. To enhance model accuracy as well as minimizing bandwidth consumption, an adaptive asynchronous distributed learning (ADL) based scheme is proposed for model uploading and downloading. Experiment results show that the blockchain based knowledge sharing is secure, and it can resist attacks from malicious users. In addition, the proposed adaptive ADL scheme can enhance driving safety related performance compared to several existing algorithms.
With the development in information and communications technology (ICT) and drones such as Internet-of-Things (IoT), edge computing, image processing, and autonomous drones, solutions supporting search and rescue (SAR) missions can be developed with more intelligent capabilities. In most of the drone and unmanned aerial vehicle (UAV) based systems supporting SAR missions, several drones deployed in different areas acquire images and videos that are sent to a ground control station (GCS) for processing and detecting a missing person. Although this offers many advantages, such as easy management and deployment, the approach still has many limitations. For example, when a connection between a drone and a GCS has some problems, the quality of service cannot be maintained. Many drone and UAV-based systems do not support flexibility, transparency, security, and traceability. In this paper, we propose a novel Internet-of-Drones (IoD) architecture using blockchain technology. We implement the proposed architecture with different drones, edge servers, and a Hyperledger blockchain network. The proof-of-concept design demonstrates that the proposed architecture can offer high-level services such as prolonging the operating time of a drone, improving the capability of detecting humans accurately, and a high level of transparency, traceability, and security.
Matthias Grundmann, Max Baumstark, Hannes Hartenstein
A recent spam wave of IP addresses in the Bitcoin P2P network allowed us to estimate the degree distribution of reachable peers in the network. The resulting distribution shows that about every second reachable peer runs with Bitcoin Core's default setting of a maximum of 125 concurrent connections and nearly all connection slots are taken. We validate this result and, in addition, use our observations of the spam wave to group addresses that belong to the same peer. By doing this grouping, we improve on previous measurements and show that simply counting addresses overestimates the number of reachable peers by 13 %.
Abstract Over the past decade, the Bitcoin P2P network protocol has become a reference model for all modern cryptocurrencies. While nodes in this network are known, the connections among them are kept hidden, as it is commonly believed that this helps protect from deanonymization and low-level attacks. However, adversaries can bypass this limitation by inferring connections through side channels. At the same time, the lack of topology information hinders the analysis of the network, which is essential to improve efficiency and security. In this paper, we thoroughly review network-level attacks and empirically show that topology obfuscation is not an effective countermeasure. We then argue that the benefits of an open topology potentially outweigh its risks, and propose a protocol to reliably infer and monitor connections among reachable nodes of the Bitcoin network. We formally analyze our protocol and experimentally evaluate its accuracy in both trusted and untrusted settings. Results show our system has a low impact on the network, and has precision and recall are over 90% with up to 20% of malicious nodes in the network.
Most self-service payment terminals require network connectivity for processing electronic payments. The necessity to maintain network connectivity increases costs, introduces cybersecurity risks, and significantly limits the number of places where the terminals can be installed. Leading payment service providers have proposed offline payment solutions that rely on algorithmically generated payment tokens. Existing payment token solutions, however, require complex mechanisms for authentication, transaction management, and most importantly, security risk management. In this paper, we present VolgaPay, a blockchain-based system that allows merchants to deploy secure offline payment terminal infrastructure that does not require collection and storage of any sensitive data. We design a novel payment protocol which mitigates security threats for all the participants of VolgaPay, such that the maximum loss from gaining full access to any component by an adversary incurs only a limited scope of harm. We achieve significant enhancements in security, operation efficiency, and cost reduction via a combination of polynomial multi-hash chain micropayment channels and blockchain grafting for off-chain channel state transition. We implement the VolgaPay payment system, and with thorough evaluation and security analysis, we demonstrate that VolgaPay is capable of delivering a fast, secure, and cost-efficient solution for offline payment terminals.
Recently, a new generation of P2P systems capable of addressing data integrity and authenticity has emerged for the development of new applications for a "more" decentralized Internet, i.e., Distributed Ledger Technologies (DLT) and Decentralized File Systems (DFS). However, these technologies still have some unanswered issues, mostly related to data lookup and discovery. In this paper, first, we propose a Distributed Hash Table (DHT) system that efficiently manages decentralized keyword-based queries executed on data stored in DFS. Through a hypercube logical layout, queries are efficiently routed among the network, where each node is responsible for a specific keywords set and the related contents. Second, we provide a framework for the governance of the above network, based on a Decentralized Autonomous Organization (DAO) implementation. We show how the use of smart contracts enables organizational decision making and rewards for nodes that have actively contributed to the DHT. Finally, we provide experimental validation of an implementation of our proposal, where the execution of the same protocol for different logical nodes of the hypercube allows us to evaluate the efficiency of communication within the network.
Today, payment paths in Bitcoin's Lightning Network are found by searching for shortest paths on the fee graph. We enhance this approach in two dimensions. Firstly, we take into account the probability of a payment actually being possible due to the unknown balance distributions in the channels. Secondly, we use minimum cost flows as a proper generalization of shortest paths to multi-part payments (MPP). In particular we show that under plausible assumptions about the balance distributions we can find the most likely MPP for any given set of senders, recipients and amounts by solving for a (generalized) integer minimum cost flow with a separable and convex cost function. Polynomial time exact algorithms as well as approximations are known for this optimization problem. We present a round-based algorithm of min-cost flow computations for delivering large payment amounts over the Lightning Network. This algorithm works by updating the probability distributions with the information gained from both successful and unsuccessful paths on prior rounds. In all our experiments a single digit number of rounds sufficed to deliver payments of sizes that were close to the total local balance of the sender. Early experiments indicate that our approach increases the size of payments that can be reliably delivered by several orders of magnitude compared to the current state of the art. We observe that finding the cheapest multi-part payments is an NP-hard problem considering the current fee structure and propose dropping the base fee to make it a linear min-cost flow problem. Finally, we discuss possibilities for maximizing the probability while at the same time minimizing the fees of a flow. While this turns out to be a hard problem in general as well - even in the single path case - it appears to be surprisingly tractable in practice.
Tooba Faisal, Mischa Döhler, Simone Mangiante, Diego López
Infrastructure sharing is a widely discussed and implemented approach and is successfully adopted in telecommunications networks today. In practice, it is implemented through prior negotiated Service Level Agreements (SLAs) between the parties involved. However, it is recognised that these agreements are difficult to negotiate, monitor and enforce. For future 6G networks, resource and infrastructure sharing is expected to play an even greater role. It will be a crucial technique for reducing overall infrastructure costs and increasing operational efficiencies for operators. More efficient SLA mechanisms are thus crucial to the success of future networks. In this work, we present "BEAT", an automated, transparent and accountable end-to-end architecture for network sharing based on blockchain and smart contracts. This work focuses on a particular type of blockchain, Permissioned Distributed Ledger (PDL), due to its permissioned nature allowing for industry-compliant SLAs with stringent governance. Our architecture can be implemented with minimal hardware changes and with minimal overheads.
The innovation provided by network virtualization in 5G, together with standardization and openness boosted by the Open Radio Access Network (O-RAN) Alliance, has paved the way to a collaborative future in cellular systems, driven by flexible network sharing. Such advents are expected to attract new players like content providers and verticals, increasing competitiveness in the telecom market. However, scalability and trust issues are expected to arise, given the criticality of ownership traceability and resource exchanging in a sharing ecosystem. To address that, we propose integrating blockchain technology for enabling mobile operators and other players to exchange radio access network (RAN) resources (e.g., infrastructure) in the form of virtual network functions autonomously and dynamically. Blockchain will provide automation, robustness, trustworthiness, and reliability to mobile networks, thus bringing confidence to open RAN environments. In particular, we define a novel O-RAN-based blockchain-enabled architecture that allows automating RAN sharing procedures through either auction or marketplace-based mechanisms. The potential advantages of the proposed solution are demonstrated through simulation results. The used simulation platform is openly released.
Mohd Anuar Mat Isa, Muzaffar Hamzah, Daimler Benz Alebaba
A variety of mobile devices and applications have spread the usability of blockchain solutions to over 5.27 billion unique mobile phone users. The rising of Bitcoin price up to USD 50,000 in March 2021 has made many blockchain mobile wallets and smart contracts DApps popular for current and future investment of cryptocurrency and digital-asset managements. To understand the trend, this chapter will present the design and implementation of mobile blockchain DApps using Android Studio together with Ethereum smart contract as the digital-asset management tool. Java Android and Ethereum Web3-Java APIs will be demonstrated as a practical deployment of the mobile DApps. The logic and decision-making of the mobile DApps will be demonstrated and coded as a smart contract. The source codes of the mobile DApps and smart-contract were published in Github as open-source codes for those who are interested to build and run the project.
The financial industry is a pioneer in Blockchain technology. One of the most popular platforms in Token-based banking is the flexible Stellar platform. This platform is open-source, and today, its wide range of features makes it possible for many countries and companies to use it in cryptocurrency and Token-based modern banking. This network charges a fee for each transaction. As well, a percentage of the net amount is generated as the inflation rate of the network due to the increased number of tokens. These fees and inflationary amounts are aggregated into a general account and ultimately distributed among members of the network on a collective vote basis. In this mechanism, network users select an account as the destination for which they wish to transfer assets using their user interface, which is generally a wallet. This account could be the account of charities that need this help. It is then determined the target distribution network based on the voting results of all members. One of the challenges in this network is the purposeful and fair distribution of these funds between accounts. In this paper, the first step is a complete infrastructure of a Stellar financial network that will consist of three network-based segments of the core network, off-chain server, and wallet interface. In the second step, a context-aware recommendation system will be explored and implemented as a solution for the purposeful management of payroll account selection. The results of this study concerning the importance of the purposeful division of collective assets and showing a context-aware recommendation system as a solution to improve the process of stellar users' participation in the voting process by effectively helping them in choosing an eligible destination
Xu Wang, Wei Ni, Xuan F. Zha, Guangsheng Yu · 7 authors
As distributed ledgers, blockchains run consensus protocols which trade capacity for consistency, especially in non-ideal networks with incomplete connectivity and erroneous links. Existing studies on the tradeoff between capacity and consistency are only qualitative or rely on specific assumptions. This paper presents discrete-time Markov chain models to quantify the capacity of Proof-of-Work based public blockchains in non-ideal networks. The comprehensive model is collapsed to be ergodic under the eventual consistency of blockchains, achieving tractability and efficient evaluations of blockchain capacity. A closed-form expression for the capacity is derived in the case of two miners. Another important aspect is that we extend the ergodic model to analyze the capacity under strong consistency, evaluating the robustness of blockchains against double-spending attacks. Validated by simulations, the proposed models are accurate and reveal the effect of link quality and the distribution of mining rates on blockchain capacity and the ratio of stale blocks.
The research designs a new integrated system for the security enhancement of a decentralized network by preventing damages from attackers, particularly for the 51 percent attack. The concept of multiple layered design based on Blockchain Governance Games frameworks could handle multiple number of networks analytically. The Multi-Layered Blockchain Governance Game is an innovative analytical model to find the best strategies for executing a safety operation to protect whole multiple layered network systems from attackers. This research fully analyzes a complex network with the compact mathematical forms and theoretically tractable results for predicting the moment of a safety operation execution are fully obtained. Additionally, simulation results are demonstrated to obtain the optimal values of configuring parameters of a blockchain-based security network. The Matlab codes for the simulations are publicly available to help those whom are constructing an enhanced decentralized security network architecture through this proposed integrated theoretical framework.
Matthew K. Luka, Okpo U. Okereke, Elijah E. Omizegba, Ejike C. Anene
Regulatory radio spectrum management is evolving from traditional static frequency allocation and assignment schemes towards dynamic spectrum management and access schemes. This evolution is necessitated by a number of factors including underutilization of licensed spectrum bands, changing market and technological developments and increased demand for spectrum for emerging applications in multimedia communications, internet-of-things and fifth generation (5G) wireless networks. In simple terms dynamic spectrum management involves allowing unlicensed users known as secondary users (SUs) to access the licensed spectrum of a licensed user also known as primary user (PU). This is primarily achieved using spectrum sharing schemes that leverage spectrum database and cognitive radio techniques. However, the use of spectrum database and cognitive radio techniques faces reliability, security and privacy concerns for spectrum sharing. There is also a need to support other requirements of dynamic spectrum management such as secondary spectrum trading market and dynamic spectrum access coordination. In this work, we review the use of blockchains for enabling spectrum sharing and other aspects of dynamic spectrum management. The review covers the use of blockchain to record spectrum management information such as spectrum sensing results and spectrum auction transactions in a secure manner. The article also covers the use of smart contracts to support complex service-levelagreements (SLAs) between network operators which is key to supporting a self-organized secondary spectrum sharing market and enforcement of regulatory policies. A taxonomy of the intersection between blockchain and various concepts of dynamic spectrum management is also provided
Augmenting ground-level communications with flying networks, such as the high-altitude platform system (HAPS), is among the major innovative initiatives of the next generation of wireless systems (6G). Given HAPS quasi-static positioning at the stratosphere, HAPS-to-ground and HAPS-to-air connectivity frameworks are expected to be prolific in terms of data acquisition and computing, especially given the mild weather and quasi-constant wind speed characteristics of the stratospheric layer. This paper explores the opportunities stemming from the realization of cloud-enabled HAPS in the context of telecommunications applications and services. The paper first advocates for the potential physical advantages of deploying HAPS as flying data-centers, also known as super-macro base stations. The paper then describes various cloud services that can be offered from the HAPS and the merits that can be achieved by this integration, such as enhancing the quality, speed, and range of the offered services. The proposed services span a wide range of fields, including satellites, Internet of Things (IoT), ad hoc networks (such as sensor; vehicular; and aerial networks), gaming, and social networks. For each service, the paper illustrates the methods that would be used by cloud providers to offload the service data to the HAPS and enable the cloud customers to consume the service. The paper further sheds light on the challenges that need to be addressed for realizing practical cloud-enabled HAPS, mainly, those related to high energy, processing power, quality of service (QoS), and security considerations. Finally, the paper discusses some open issues on the topic, namely, HAPS mobility and message routing, HAPS security via blockchain and machine learning, artificial intelligence-based resource allocation in cloud-enabled HAPS, and integration with vertical heterogeneous networks.
Recently, blockchain has gained momentum as a novel technology that gives rise to a plethora of new decentralized applications (e.g., Internet of Things (IoT)). However, its integration with the IoT is still facing several problems (e.g., scalability, flexibility). Provisioning resources to enable a large number of connected IoT devices implies having a scalable and flexible blockchain. To address these issues, we propose a scalable and trustworthy blockchain (STB) architecture that is suitable for the IoT; which uses blockchain sharding and oracles to establish trust among unreliable IoT devices in a fully distributed and trustworthy manner. In particular, we design a Peer-To-Peer oracle network that ensures data reliability, scalability, flexibility, and trustworthiness. Furthermore, we introduce a new lightweight consensus algorithm that scales the blockchain dramatically while ensuring the interoperability among participants of the blockchain. The results show that our proposed STB architecture achieves flexibility, efficiency, and scalability making it a promising solution that is suitable for the IoT context.
Blockchain (BC) technology can revolutionize the future of communications by enabling decentralized and open sharing networks. In this paper, we propose the application of BC to facilitate Mobile Network Operators (MNOs) and other players such as Verticals or Over-The-Top (OTT) service providers to exchange Radio Access Network (RAN) resources (e.g., infras-tructure, spectrum) in a secure, flexible and autonomous manner. In particular, we propose a BC-enabled reverse auction mecha-nism for RAN sharing and dynamic users' service provision in Beyond 5G networks, and we analyze its potential advantages with respect to current service provisioning and RAN sharing schemes. Moreover, we study the delay and overheads incurred by the BC in the whole process, when running over both wireless and wired interfaces.
Deployment of optical network infrastructure and network services is growing exponentially for beyond 5G networks. Since the uptake of e-commerce and e-services has seen unprecedented serge in recent months due to the global COVID-19 pandemic era, the security of such transactions in optical communication has gained much importance. Optical fiber communication networks are vulnerable to several types of security threats, such as single point failure, wormhole attacks, and sybil attacks. Therefore, blockchain is a promising solution to protect confidential information against attacks and helps in achieving trusted network architecture by creating a distributed ledger platform. Recently, blockchain has received much attention because of its decentralized and distributed ledger technology. Hence, blockchain has also been employed to protect network against such attacks. However, blockchain technology's security relies on the platform of computational complexity, and because of the evolution of quantum computers, it will become insecure in the near future. Therefore, for enhancing blockchain security, research focus on combining quantum key distribution (QKD) with blockchain. This new technology is known as quantum-secured blockchain. The article describes the attacks in optical networks and provides a solution to protect network against security attacks by employing quantum-secured blockchain in optical networks. It provides a brief overview of blockchain technology with its security loopholes and focuses on QKD, which makes blockchain technology more robust against quantum-attacks. Next, the article provides a broad view of quantum-secured blockchain and presents the network architecture for future research and development of secure and trusted optical communication networks using quantum-secured blockchain.
The 5G wireless networks are potentially revolutionizing future technologies. The 5G technologies are expected to foresee demands of diverse vertical applications with diverse requirements including high traffic volume, massive connectivity, high quality of service, and low latency. To fulfill such requirements in 5G and beyond, new emerging technologies such as SDN, NFV, MEC, and CC are being deployed. However, these technologies raise several issues regarding transparency, decentralization, and reliability. Furthermore, 5G networks are expected to connect many heterogeneous devices and machines which will raise several security concerns regarding users' confidentiality, data privacy, and trustworthiness. To work seamlessly and securely in such scenarios, future 5G networks need to deploy smarter and more efficient security functions. Motivated by the aforementioned issues, blockchain was proposed by researchers to overcome 5G issues because of its capacities to ensure transparency, data reliability, trustworthiness, immutability in a distributed environment. Indeed, blockchain has gained momentum as a novel technology that gives rise to a plethora of new decentralized technologies. In this chapter, we discuss the integration of the blockchain with 5G networks and beyond. We then present how blockchain applications in 5G networks and beyond could facilitate enabling various services at the edge and the core.