Torsten Jacobi
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
65 results · page 2 of 3
Torsten Jacobi
No abstract is available for this record.
Syed Badruddoja, Sasi Kanduri, Ram Dantu
No abstract is available for this record.
Mingwei Zeng, Jie Cui, Qingyang Zhang, Hong Zhong · 5 authors
The rapid evolution of the Industrial Internet of Things (IIoT) has necessitated increased device interactions across various management domains. This entails devices from different domains collaborating on the same production task. This poses significant challenges for the dynamics of cross-domain authentication schemes. Traditional cross-domain authentication schemes struggle to support seamless switching between domains and face difficulties when accommodating devices that join and leave the same domain. Moreover, these schemes suffer from intricate interactions and suboptimal efficiency. To address these issues, we propose a dynamic group signature scheme based on a dynamic accumulator and a non-interactive zero-knowledge proof. We integrated this scheme with blockchain technology to construct an efficient revocation cross-domain authentication scheme. The proposed scheme enables cross-domain anonymous authentication with simple interactions and provides an efficient revocation function for illegal devices. This approach ensures conditional privacy-preserving and enables efficient member joining and exiting through a dynamic accumulator. It effectively addresses the dynamic requirements of devices involved in IIoT production and manufacturing processes. We prove the security of the proposed scheme using a random Oracle model and conduct thorough analyses to verify its resistance against various attacks. Furthermore, the experimental results demonstrate that the proposed scheme achieves better performance in terms of computational and communication costs.
Stanisław Barański, Ben Biedermann, Joshua Ellul
Voting is a cornerstone of collective participatory decision-making in contexts ranging from political elections to decentralized autonomous organizations (DAOs). Despite the proliferation of internet voting protocols promising enhanced accessibility and efficiency, their evaluation and comparison are complicated by a lack of standardized criteria and unified definitions of security and maturity. Furthermore, socio-technical requirements by decision makers are not structurally taken into consideration when comparing internet voting systems. This paper addresses this gap by introducing a trust-centric maturity scoring framework to quantify the security and maturity of seventeen internet voting systems. A comprehensive trust model analysis is conducted for selected internet voting protocols, examining their security properties, trust assumptions, technical complexity, and practical usability. In this paper we propose the Internet Voting Maturity Framework (IVMF) which supports nuanced assessment that reflects real-world deployment concerns and aids decision-makers in selecting appropriate systems tailored to their specific use-case requirements. The framework is general enough to be applied to other systems, where the aspects of decentralization, trust, and security are crucial, such as digital identity, Ethereum layer-two scaling solutions, and federated data infrastructures. Its objective is to provide an extendable toolkit for policy makers and technology experts alike that normalizes technical and non-technical requirements on a univariate scale.
Shengyu Chen, Shenghao Jin, Yigang Wei, Hui Zhang
This study mainly focus on Sybil attacks with the Identity-Augmented Proof-of-Stake (IdAPoS) protocol under different network topologies, including random, scale-free, and hierarchical networks. The study finds that scale-free networks are more resistant to Sybil attacks, delaying their effects. Furthermore, the research improves the IdAPoS protocol by introducing active strategies for honest nodes, which improves the behaviours of this protocol, and by enabling them to dynamically assess and update their trusted and suspicious authority lists based on on-ledger data, which improves the completeness of this protocol.
Winnie Owoko
The rapid evolution of next-generation networks (NGNs), characterized by advancements such as 5G, 6G, edge computing, and the Internet of Things (IoT), has introduced unprecedented opportunities for connectivity and innovation. However, this progress has also expanded the attack surface, leading to new and complex security challenges. This paper provides a comprehensive review of state-of-the-art security schemes tailored for NGNs, emphasizing the interplay of confidentiality, integrity, availability, and privacy. Key areas explored include authentication mechanisms, end-to-end encryption, intrusion detection systems, and distributed ledger technologies. Furthermore, the role of artificial intelligence and machine learning in predicting and mitigating threats is analyzed. The paper also investigates emerging paradigms such as zero-trust architectures, quantum-resistant cryptographic algorithms, and secure network slicing. Through a critical assessment of existing frameworks and their limitations, this work proposes a unified approach that integrates adaptive security policies, decentralized trust models, and real-time threat intelligence. By addressing both technical and operational perspectives, this study aims to guide the development of resilient and secure NGNs, ensuring a sustainable digital future.
Sonali Kothari, Tejas Ulbhaje, Vishant Kalwani, Yash Mangale · 5 authors
In this research paper, we introduce a Kotlin application that assesses different security features on the Android SDK and executes them. The objectives are:1.Improving security of mobile phones—The most commonly used for m-payments; High-value targets, because they store substantial amount of personal information (especially financial details);2.Some of the available features include data obfuscation and anti-screenshot which is meant to be obedient with security guidelines set by RBI for financial apps.3.Zero-Knowledge Proof — enables the parties to verify facts about each other without sharing personal data and removes risks associated with unauthorized access or data breaches, significantly enhancing security for end-users.It is important to have this kind of initiative for any financial application that you develop, otherwise how can an app user trust your code and be sure it met all possible regulations?!
Kjell‐Erik Marstein, Paulina Davita, Luke Riley
The distributed ledger technology (DLT) landscape comprises a wide range of independent networks with little to none built-in interoperability. To be applied in traditional enterprises, these DLT systems must also interact with legacy systems with no support for the processes of a DLT. An important topic in DLT research is, therefore, to establish standardised protocols for cross-network transfer and exchange of data and assets. Ideally, these protocols should be general-purpose so that they can be applied on top of many different types of ledger systems. One such protocol, supporting asset transfer, is the Secure Asset Transfer Protocol (SATP or 'SAT protocol') in development by the Internet Engineering Task Force (IETF). The SATP Core protocol draft by Hargreaves et al. (2024) describes an interoperability protocol that can facilitate asset transfer between two DLT systems, as well as between a DLT system and a non-DLT system. In either case, the SAT protocol imposes no restrictions on the underlying system implementations. Building on this work, in this paper, we present an adaptation of SATP that facilitates cross-network asset exchanges. This asset exchange protocol, named the Secure Asset Exchange Protocol, inherits the key advantages of SATP but enables asset exchanges instead of asset transfers.
Usha Divakarla, K Chandrasekaran
Cache poisoning and DDoS attacks are just two of the many ways that the Domain Name System (DNS), an essential part of the Internet infrastructure, can be attacked. Countermeasures have been suggested, although they are not without restrictions. This article introduces D-DNS, a domain name system built on blockchain technology that can offer effective and safe DNS services. D-DNS solves two issues with current blockchain-based DNS systems: the inefficient query handling and the computationally demanding Proof-of-Work (PoW) protocol. D-DNS accomplishes this by putting in place a domain index and a Proof-of-Stake (PoS) consensus mechanism. To evaluate the security of D-DNS versus legacy DNS in terms of attack success rate, attack cost, and attack surface, a new quantitative comparison is presented.. According to experimental results, the attack surface of D-DNS is substantially less than that of legacy DNS, the attack cost is a million times higher, and the chance of a successful attack on D-DNS is 1% of a successful attack on legacy DNS. When D-DNS query performance is compared to the most advanced commercial DNS implementations, it is demonstrated to achieve equivalent or even reduced query latency.
Pascal Urien
This paper introduces an innovative secure element token, which supports three communication interfaces, USB, WiFi, and Bluetooth. The token is built with a system on chip (SoC) module including FLASH memory, and a secure element (javacard) with a mini SIM form factor. The secure element is managed via ISO7816 five wires interface, thanks to an original library. We present use cases for each communication interface. Serial USB is used to upload software in the SoC, and thereafter to download javacard application in secure element according to Global Platform (GP) protocols. Wi-Fi enables internet access to secure element thanks to TLS1.3 server running within secure element. Bluetooth allows interactions with mobile applications, such as Bluetooth terminal, which use the SoC to build Ethereum transactions signed by secure element.
Mikel Cortes Goicoechea
(English) The advent of the internet, marked by pivotal developments such as the launch of Arpanet and the standardization of HTTP, has irrevocably changed the fabric of modern society. Centralized platforms like Microsoft, Google, Apple, and Amazon have dominated this digital landscape, offering many services ranging from cloud computing to online storage. However, the centralized nature of these services has raised significant concerns regarding user privacy, data integrity, and the potential for censorship. In response to these issues, the open-source community has explored peer-to-peer alternatives, notably in the realm of distributed file systems, ledgers, and blockchain technology. Blockchains, popularized by the emergence of Bitcoin, promote a democratized service model that challenges the centralized status quo. Yet, they are not without their own challenges, including decentralization, security, privacy, and performance. This thesis delves into the nuances of blockchain technology, focusing on Ethereum's transition from Proof of Work (PoW) to Proof of Stake (PoS) and its implications on network hardware requirements, topology, and overall performance. The development of Ethereum serves as a small-scale reflection of the broader ambitions and challenges in transitioning to Decentralized Finance (DeFi) platforms. Despite significant theoretical advancements in consensus mechanisms and scalability solutions, real-world implementations and experimental validations remain sparse. This work aims to bridge this gap by comprehensively analysing Ethereum's PoS transition by examining the interlaced relationships between software logic, hardware configurations, and network dynamics. Through novel measurement models and tools, this thesis contributes to a deeper understanding of how Ethereum's architectural changes impact its ecosystem and its participants' behaviours. Lastly, the research presented in this thesis illustrates the technical and operational challenges facing Ethereum and similar blockchain platforms and proposes a series of contributions that advance the field. This work empirically analyses the future enhancements in blockchain technology by exploring the implications of the network and its topology, to the viability of decentralized validation processes, and the potential for scaling solutions like Data Availability Sampling. The open-source tools and methodologies developed within the thesis scope represent the commitment to transparency and collaboration, which follows the spirit of the decentralized communities it seeks to serve. Through a mix of theoretical exploration and empirical research, this thesis aims to provide a deeper and more detailed understanding of Ethereum PoS' design choices, its capabilities and the limitations this one represents in future steps and upgrades, leading the way for more resilient, scalable, and decentralized digital infrastructures. (Català) L'arribada d'Internet, marcada per avenços fonamentals com el llançament d'Arpanet i l'estandardització de HTTP, ha canviat irrevocablement el teixit de la societat moderna. Les plataformes centralitzades com Microsoft, Google, Apple i Amazon han dominat aquest panorama digital, oferint serveis que van des de la computació al núvol fins a l'emmagatzematge en línia. No obstant això, la naturalesa centralitzada d'aquests serveis ha generat importants preocupacions pel que fa a la privacitat de l'usuari, la integritat de les dades i la possibilitat de censura. En resposta a aquests problemes, la comunitat de codi obert ha explorat alternatives d'igual a igual, especialment en l'àmbit dels sistemes d'arxius distribuïts i la tecnologia blockchain. Les blockchains, popularitzades pel sorgiment de Bitcoin, han proposat fins i tot un model de servei democratitzat que desafia l'statu quo centralitzat. No obstant això, no estan exemptes de desafiaments, incloent la descentralització, la seguretat, la privacitat i el rendiment. Aquesta tesi aprofundeix en les dinàmiques de la tecnologia blockchain, centrant-se en la transició d'Ethereum de Proof of Work (PoW) a Proof of Stake (PoS) i les seves implicacions en els requisits, la topologia de la xarxa i el rendiment general del maquinari. El desenvolupament d'Ethereum serveix com un reflex a petita escala de les ambicions i els desafiaments més amplis en la transició a plataformes de finances descentralitzades (DeFi). Malgrat els importants avenços teòrics en els mecanismes de consens i les solucions d'escalabilitat, les implementacions al món real i les validacions experimentals segueixen sent escasses. Aquesta tesi té com a objectiu tancar aquesta bretxa analitzant exhaustivament la transició PoS d'Ethereum mitjançant l'examen de les relacions entrellaçades entre la lògica del programari, les configuracions de maquinari i la dinàmica de la xarxa. A través de nous models i eines de mesura, aquesta tesi contribueix a una comprensió més profunda de com els canvis arquitectònics d'Ethereum impacten en el seu ecosistema i els comportaments dels seus participants. Per últim, la investigació presentada en aquesta tesi il·lustra els desafiaments tècnics i operatius que enfronten Ethereum i plataformes blockchain similars, i proposa una sèrie de contribucions que esperem serveixin per fer avançar el mon de les blockchains. La tesi analitza empíricament les millores futures en la tecnologia blockchain explorant les implicacions de la xarxa i la seva topologia, la viabilitat dels processos de validació descentralitzats i el potencial per escalar solucions com el mostreig de disponibilitat de dades. Les eines i metodologies de codi obert desenvolupades dins de l'abast de la tesi representen el compromís amb la transparència i la col·laboració, que segueix l'esperit de les comunitats descentralitzades a les que busquem servir. A través d'una combinació d'exploració teòrica i investigació empírica, aquesta tesi té com a objectiu proporcionar una comprensió més profunda i detallada de les opcions de disseny d'Ethereum PoS, les seves capacitats i les limitacions que això representa en futurs passos i actualitzacions, obrint el camí cap a una solució més resilient i escalable per a infraestructures digitals descentralitzades. (Español) La llegada de Internet, marcada por avances fundamentales como el lanzamiento de Arpanet y la estandarización de HTTP, ha cambiado irrevocablemente el tejido de la sociedad moderna. Plataformas centralizadas como Microsoft, Google, Apple y Amazon han dominado este panorama digital, ofreciendo servicios que van desde computación en la nube hasta almacenamiento en línea. Sin embargo, la naturaleza centralizada de estos servicios ha generado importantes preocupaciones con respecto a la privacidad del usuario, la integridad de los datos y la posibilidad de censura. En respuesta a estos problemas, la comunidad de código abierto ha explorado alternativas de igual a igual, especialmente en el ámbito de los sistemas de archivos distribuidos, los libros de contabilidad y la tecnología blockchain. Las blockchains, popularizadas por el surgimiento de Bitcoin, promueven un modelo de servicio democratizado que desafía el status quo centralizado. Sin embargo, no están exentos de desafíos, incluida la descentralización, la seguridad, la privacidad y el rendimiento. Esta tesis profundiza en los matices de la tecnología blockchain, centrándose en la transición de Ethereum de Proof of Work (PoW) a Proof of Stake (PoS) y sus implicaciones en los requisitos, la topología de la red y el rendimiento general del hardware. El desarrollo de Ethereum sirve como un reflejo a pequeña escala de las ambiciones y desafíos más amplios en la transición a plataformas de finanzas descentralizadas (DeFi). A pesar de los importantes avances teóricos en los mecanismos de consenso y las soluciones de escalabilidad, las implementaciones en el mundo real y las validaciones experimentales siguen siendo escasas. Esta tesis tiene como objetivo cerrar esta brecha analizando exhaustivamente la transición PoS de Ethereum mediante el examen de las relaciones entrelazadas entre la lógica del software, las configuraciones de hardware y la dinámica de la red. A través de novedosos modelos y herramientas de medición, esta tesis contribuye a una comprensión más profunda de cómo los cambios arquitectónicos de Ethereum impactan su ecosistema y los comportamientos de sus participantes. Por último, la investigación presentada en esta tesis ilustra los desafíos técnicos y operativos que enfrentan Ethereum y plataformas blockchain similares y propone una serie de contribuciones que hacen avanzar el campo. La tesis analiza empíricamente las mejoras futuras en la tecnología blockchain explorando las implicaciones de la red y su topología, la viabilidad de los procesos de validación descentralizados y el potencial para escalar soluciones como el muestreo de disponibilidad de datos. Las herramientas y metodologías de código abierto desarrolladas dentro del alcance de la tesis representan el compromiso con la transparencia y la colaboración, que sigue el espíritu de las comunidades descentralizadas a las que busca servir. A través de una combinación de exploración teórica e investigación empírica, esta tesis tiene como objetivo proporcionar una comprensión más profunda y detallada de las opciones de diseño de Ethereum PoS, sus capacidades y las limitaciones que esto representa en futuros pasos y actualizaciones, abriendo el camino hacia una solución más resiliente y escalable. e infraestructuras digitales descentralizadas.
Lyhour Hak, Somchart Fugkeaw, Hiroyuki Satō
The Internet of Medical Things (IoMT) has emerged substantial growth within the healthcare sector, spurred by advancements in smart devices that generate and process critical healthcare data. Sharing this data among trusted healthcare entities is vital for efficient patient care but raises substantial security and privacy concerns. Existing solutions have focused on authentication techniques employing Self-Sovereign Identity (SSI) and Zero-Knowledge Proofs (ZKPs), aiming to ensure secure, auditable, and anonymous authentication. These solutions often prioritize either lightweight authentication or robust security, yet a flexible approach that integrates both characteristics is essential for adaptive cross-domain authentication in the IoMT landscape. Furthermore, the importance of lightweight authentication combined with adaptive verification, pivotal for scaling access control in cross-domain environments, has been underexplored in existing frameworks. Addressing this gap, we proposed a scheme called LSAC which is a lightweight, scalable, and anonymous authentication for SSI-based cross-domain authentication for IoMT setting. Our proposed LSAC scheme not only facilitates rapid and robust identity verification across multiple IoMT domains within a consortium blockchain network but also incorporates the advanced ZK-STARK and Plonk ZKP protocols to enable efficient and secure verification processes. By leveraging Hyperledger for generating smart contracts and managing user interactions across domains, our system represents a significant step forward in cross-domain authentication. Our comprehensive functionality and performance analysis confirms the effectiveness of our solution in providing scalable and secure access to IoMT resources, supporting the ongoing evolution of healthcare services.
Guoli Zheng, Li Cao, Yuanshuai Li, Honglei Men
Secure and efficient communication between vehicles is a prerequisite for providing intelligent services in the Internet of Vehicles (IoV). The openness and high mobility of the IoV communication environment impose stringent requirements on privacy and efficiency. Hence, we propose an efficient hybrid anonymous message authentication scheme for the IoV environment. The scheme is based on utilizing discrete logarithm zero-knowledge proofs and combines global pseudo identity for communication between network entities and local pseudo identity for communication within a domain, aiming to achieve efficient and authenticated secure communication among vehicles with conditional privacy protection. Additionally, through the design of a verification tuple, the message receiver can authenticate the sender's identity upon receiving the message, addressing security vulnerabilities arising from the inability of traditional schemes to promptly revoke malicious vehicles. The performance analysis indicates that the scheme, in comparison to other similar solutions, successfully mitigates the drawback of high time expenditure in traditional message authentication schemes, demonstrating its efficiency and applicability, meeting the security and efficiency requirements of communication in the IoV environment. The feasibility analysis reveals that the total delay introduced by the scheme is significantly lower than the communication duration, meeting the requirements of high-speed dynamic scenarios in the Io V.
Lakshmi Rama Kiran Pasumarthy, Hisham Ali, William J. Buchanan, Jawad Ahmad · 7 authors
There is an increasing need to share threat information for the prevention of widespread cyber-attacks. While threat-related information sharing can be conducted through traditional information exchange methods, such as email communications etc., these methods are often weak in terms of their trustworthiness and privacy. Additionally, the absence of a trust infrastructure between different information-sharing domains also poses significant challenges. These challenges include redactment of information, the Right-to-be-forgotten, and access control to the information-sharing elements. These access issues could be related to time bounds, the trusted deletion of data, and the location of accesses. This paper presents an abstraction of a trusted information-sharing process which integrates Attribute-Based Encryption (ABE), Homomorphic Encryption (HE) and Zero Knowledge Proof (ZKP) integrated into a permissioned ledger, specifically Hyperledger Fabric (HLF). It then provides a protocol exchange between two threat-sharing agents that share encrypted messages through a trusted channel. This trusted channel can only be accessed by those trusted in the sharing and could be enabled for each data-sharing element or set up for long-term sharing.
Maede Hojjati, Arian Arabnouri, Alireza Shafieinejad, Halim Yanıkömeroğlu
Universal Subscriber Identity Module (USIM) is an essential part of the mobile network mainly for providing identification and authentication of the subscriber. The activation and deactivation of USIMs are the two most critical services that must be supported by Mobile Network Operators (MNOs). The current solutions suffer from several limitations such as the lack of round-the-clock services and the presence of a single point of failure. In this paper, we propose a blockchain-based scheme for USIM management. Each MNO creates its own smart contract and publishes its address to subscribers. Subscribers can then directly submit their requests by registering a transaction that invokes a specific function of the smart contract. The proposed scheme provides an anytime-anywhere service while at the same time it leverages the benefits of blockchain technology, such as a decentralized architecture that prevents Denial-of-Service (DoS) attacks, as well as a secure auditable log and payment using cryptocurrency. Moreover, we provide a security proof for the scheme through formal verification. Our results demonstrate that our scheme ensures subscriber privacy while providing mutual authentication among participants. Finally, our evaluation on the Ethereum blockchain confirms the efficiency of the scheme in terms of both transaction and execution costs.
Shuaib Ahmed, Yichiet Aun, Miao Xuan Ng
No abstract is available for this record.
Authors unavailable
WPA2 is the most used wireless communication protocol in the world (2023). It first appeared in 2006, and now several vulnerabilities have been identified. To use WPA2-EAP or WPA3 (2018), which were released to compensate for the vulnerabilities of WPA2, additional equipment upgrades are required for STA (station) and AP (access point, router), which are connecting devices. We are currently living in the Web3 era. In the future society, people will have more than one NFT each. It is possible to improve the security of WPA2 by using this as an authentication means. In this paper, see the principles of WPA2 crack tools that are currently used today and suggest a way to defend against them using NFT. An experiment was carried out on the security of WPA2, which is widely used in SOHO environments, using only SBC (Single Board Computer) and NFT without expensive routers or additional authentication means. Hacking time, Internet connection delay time, download speed, etc. were compared on various PCs. In conclusion, this proposal demonstrated that representative WPA2 cracking tools can be defended without performance degradation compared to existing WPA2.
Didin Kusmayadi Imas Nurhayati
Perubahan teknologi semakin lama semakin pesat diberbagai bidang, termasuk teknologi digital yang merupakan revolusi dari teknologi analog dan elektronik. Dekade ini semua serba bermetamorfosis menjadi digital, termasuk akhirnya muncul uang digital, yaitu cryptocurrency. Cryptocurrency sebagai bentuk digital cash beroperasi dengan bantuan teknik yang disebut kriptografi. Kriptografi sendiri adalah proses yang menerjemahkan semua informasi yang dapat dibaca menjasi kode yang tidak dapat dipecah sama sekali. Cryptocurrency menggunakan blockchain sebagai buku utama, yang semua sistemnya dikelola oleh yang disebut penambang. Mata uang crypto memiliki sistem yang sedikit rumit yang tidak dengan mudah dapat dipahami, jadi pengetahuan tentang cryptocurrency mau tidak mau harus dipelajari, dipahami agar dalam implementasi tidak mengalami dampak yang merugikan. Jenis jenis cryptocurrency, serta kekurangan dan kelebihannya akan dikupas sekilas dalam artikel ini.
Wenpin Tang, David Yao
We study a mechanism design problem in the blockchain proof-of-stake (PoS) protocol. Our main objective is to extend the transaction fee mechanism (TFM) recently proposed in Chung and Shi (SODA, p.3856-3899, 2023), so as to incorporate a long-run utility model for the miner into the burning second-price auction mechanism $\texttt{BSP}(γ)$ proposed in Chung and Shi (where $γ$ is a key parameter in the strict $γ$-utility model that is applied to both miners and users). First, we derive an explicit functional form for the long-run utility of the miner using a martingale approach, and reveal a critical discontinuity of the utility function, namely a small deviation from being truthful will yield a discrete jump (up or down) in the miner's utility. We show that because of this discontinuity the $\texttt{BSP}(γ)$ mechanism will fail a key desired property in TFM, $c$-side contract proofness ($c$-SCP). As a remedy, we introduce another parameter $θ$, and propose a new $\texttt{BSP}(θ)$ mechanism, and prove that it satisfies all three desired properties of TFM: user- and miner-incentive compatibility (UIC and MIC) as well as $c$-SCP, provided the parameter $θ$ falls into a specific range, along with a proper tick size imposed on user bids.
Paulo Chaínho
In the evolution from 5G to beyond 5G networks, new business models are emerging where multi-domain and multistakeholder scenarios will play a paramount role as enablers. In these scenarios, the automated management of the services with minimal human intervention, also known as zero-touch management, is a pivotal requirement to ensure a proper functioning and to enable real-time responses to possible incidents or scalability needs. Nonetheless, these new scenarios and requirements also introduce new security risks that entail a complex threat landscape for beyond 5G networks. Hence, zero-touch management demands new solutions capable of securely controlling network resources into end-to-end scenarios distributed in multiple domains. In this vein, several challenges arise and need to be addressed, such as integrity, non-repudiation, confidentiality, security, and trust. Therefore, the H2020 5GZORRO project proposes new security and trust solutions for multi-domain and multi-stakeholder scenarios in 5G and beyond networks. To deal with the utmost importance security and trust challenges, we introduce different modules to mitigate them, namely, integrity and non-repudiation through Distributed Ledger Technologies, decentralized identity through an Identity and Permission Manager, end-to-end trustworthy relationships via a Trust Management Framework, secure workloads across different tenants and stakeholders via Trusted Execution Environment Security Management, detection and response to internal vulnerabilities and attacks via Network Monitoring, and on-demand secure cross-domain connections via VPN-as-a-Service. Therefore, the built security and trust 5GZORRO mechanisms form a secure environment with zero-touch automation capabilities, minimizing human intervention.
Lyuye Zhang, Maode Ma, Yue Qiu
No abstract is available for this record.
Andrea Tesei, Domenico Lattuca, Alexandr Tardo, Luca Di Mauro · 8 authors
Major maritime carriers are globally demanding improvements in the efficiency of port operations. Cargo carried by ships must be loaded and unloaded quickly with minimal stopover time in the port. This requirement mandates seaports to deploy cutting-edge technology to the port area so that logistic processes are increasingly efficient and reliable. In this scenario, the attack surface of such critical infrastructure is growing very rapidly and advanced security techniques must be deployed to enforce a high attack resilience. A Distributed Ledger-based Credential Management System exploiting a Distributed Ledger Technology (DLT) to enable transparent and real-time tracking of logistic vehicles and cargos within a terminal is presented in this paper. Based on a customization of Vehicular Ad-Hoc Network (VANET) security standards, the proposed scheme provides authentication, authorization, and revocation capabilities to promptly exclude misbehaving logistic vehicles from the system, while maintaining an immutable record of all the logistic vehicles' activity. The laboratory validation demonstrates that the delay of the devised scheme is not dependent on the quay area capacity, thus being applicable in seaports of any size. Furthermore, the effectiveness of the solution is demonstrated with the field trial results obtained with the EU Horizon 2020 COREALIS project testbed deployed in the Port of Livorno.
Jan Kotráš
Tato diplomová práce se zabývá technologii blockchain se zaměřením na konsenzus protokoly, zvláště protokoly typu proof-of-stake. V této práci naleznete popis těchto protokolů následovaný popisem konsenzu v technologii blockchain. Prvotní kapitoly detailněji popisují a porovnávají jednotlivé proof-of-stake protokoly na základě teoretických znalostí. Druhá část práce se zaobírá návrhem a implementací testbedu, který je následně použitý pro praktické porovnání proof-of-stake protokolů. V závěrečné částí práce je diskutováno nad zjištěnými výsledky pozorováním testbedu a zjištěnými vlatnostmi protokolů. Na tomto základě práce ve svém konci naznačuje další směřování consesus protokolů, ba jejich případné zlepšení, a zvláště proof-of-stake typu protokolů.
Wenfeng Liu, Yu Zhang, Lu Liu, Shuyan Liu · 6 authors
The domain name system (DNS) is the infrastructure of many services and applications, thus the availability and consistency of the domain name resolution process are crucial but have long troubled DNS. The availability problem is caused by a denial-of-service (DoS) attack or a single point of failure (SPOF). The consistency problem originates from the lack of a forced data synchronization mechanism between authoritative server replicas or between parent/child authoritative servers. We proposed a novel blockchain-based domain name resolution and management architecture named FI-DNS to solve the above problems fundamentally. FI-DNS solves availability and consistency problems in the name resolution process from the mechanism level and guarantees the authenticity and integrity of name resolution results by using public-key cryptography. FIDNS also supports root zone collaborative management based on smart contracts, which is compatible with the current governance model led by Internet Corporation for Assigned Names and Numbers (ICANN). We implemented the prototype system to prove the feasibility and effectiveness of the FI-DNS architecture. We built an experimental environment with real domain name data, evaluated the name resolution performance and stability of the FI-DNS prototype system, and compared the prototype system with DNS.