Mandrita Banerjee, Junghee Lee, Qian Chen, Kim‐Kwang Raymond Choo
Internet-of-Things (IoT) is increasingly becoming the norm in both civilian and military settings. In this paper, we present a comprehensive security abstraction layer for IoT systems based on blockchain, which provides us a logical view of a system that comprises trusted devices. The goal of the proposed layer is to detect and isolate untrusted devices. The proposed abstraction layer provides three services, namely: authorization, authentication, and auditing by using blockchain and smart contract-based approaches. We adopt a hardware based approach, where dedicated hardware modules are used to monitor the behavior of the firmware without incurring excessive performance overhead.
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
The financial industry is faced with attractive business opportunities to adopt blockchain. To make such an investment, decision makers need answers to a number of questions including: what existing business problems will be solved, will blockchain solve them, and what long term benefits and new business opportunities blockchain can create. In this paper we analyze security aspects of these questions, focusing on the protection of integrity of data and financial transactions. We start from the analysis of an essential security architecture of financial systems which is based on the perimeter protection and traditional business process safeguards such as maker-checker. Subsequently, we look at the options on how to improve such an architecture to provide protection against malicious internal users and malware implanted inside the system; the vulnerabilities that have been exploited by organized criminal teams of attackers in the attacks seen lately. We show that the improvements based on the preventive safeguards, inherent to blockchain security architecture, provide strong protection against those attacks. Finally, we argue that in comparison with typically used detective measures (e.g. monitoring), security architecture based on the blockchain model provides superior protection against attacks using attack scenarios never seen before.
Frank Yeong‐Sung Lin, Chiu‐Han Hsiao, Yean‐Fu Wen, Yang-Che Su
Transactions and blocks must be synchronized among the blockchain miners on the Internet. Software-defined networking and network function virtualization techniques support dynamically assigning computing resources into servers of the core and edge clouds. In this paper, an adaptive broadcast algorithm is proposed for blockchain authentication, authorization, and accounting (AAA) services. The cryptography is propagated throughout the Internet by using a broadcast mechanism. The broadcast message may incur a propagation delay and duplicate transmissions. The total propagation delay is assumed to be a combination of transmission time and computational time for data verification. A mathematical programming model is formulated to address the secure broadcast problem as a minimum spanning tree problem. The objective is to minimize the processing and transmission delay through reduced duplicate transmissions. Computational experiments demonstrate proof of concept to adopt blockchain techniques. The dynamic AAA architecture and path selection enable the blockchain operator to efficiently make decisions and achieve more secure services.
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
Kai Fan, Yanhui Ren, Zheng Yan, Shangyang Wang · 6 authors
The era of information has arrived. As an important part of new generation of information technology., Internet of Things (IoT)., which is developing rapidly., requires higher and higher time accuracy. However, the malicious nodes located in network can influence the time synchronization. The security issue of time transfer and consistency is critical and challenging. In this paper, we propose a secure scheme based on blockchain to solve the problem of time announcement in IoT. In this distributed network, a closed blockchian to record and broadcast time is utilized, which minimize attacks from external environments. Moreover, this scheme has the advantage of adapting the changes of network topology. By employing POS consensus mechanism, time synchronization can be implemented efficiently. At last, the analysis results show that this secure scheme can be achieved with high efficiency and less communication cost.
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
With the development of Internet of Things (IoT) and blockchain technologies, people find more and more blockchain applications in the IoT domain. While it is reasonable that IoT systems use hierarchical network structures, their sheer large scales may lead to hundreds or even thousands of non-leaf nodes, which may serve as full nodes when participating in IoT blockchains. From IoT blockchain design perspective, it is important to understand the scalability of the energy consumption feature of IoT blockchains. In our research we have collected real-world data that reflect the energy consumption features of several consensus algorithms of blockchain. In this work-in-progress paper, we report our results based on linear regression models. These models provide reference estimations of the energy consumption impact in designing blockchains for IoT systems.
In recent times, data has become an inevitable factor in cloud computing. The word data eventually seeks its issue on privacy and security. With the rise of new technologies, the need for data storage has increased. Massive increase in the datasets has led to the evolution of cloud storage. The benefits of cloud computing are immense, but on the contrary there is an increasing risk to the security of the data stored in the cloud. This paper deals with a survey on the security issues which highlights the effectiveness of security that has been implied in the forms of cloud computing and blockchain technologies. The survey also includes a deep understanding of a PoW-based blockchain model using the blockchain technology. The idea behind this work is to provide a detailed survey about the blockchain technology which is growing tremendously.
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Advanced Steganography and Watermarking Techniques
The Plug-and-Produce concept requires that after connecting a new module to a system, the exchange of the configuration data takes place. As further operation of the system depends on this initialization procedure, it is necessary to ensure that the data presented by the system and the newly attached component is authentic. Therefore, we propose a new concept for secure Plug-and-Produce functionality, which exploits the combination of the Asset Administration Shell (AAS) and Blockchain technology. On the one hand, the AAS shall be responsible for presenting uniform and standardized configuration data as well as for storing and managing Blockchain. On the other, Blockchain shall ensure authenticity and integrity of the configuration data.
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
Despite that the cloud computing is considered as the panacea of processing and analyzing IoT data, it shows drawbacks in many other aspects like latency, bandwidth, and mobility when transferring data from connected devices to the cloud. The fog computing paradigm extends the cloud and refers to a geographically distributed computing paradigm at the edge of loT networks. However, realizing fog computing still has a long way to go, especially when it comes to security in the context of loT unconventional characteristics such as scalability, heterogeneity, mobility and limited resources. In addition, applying social network principles to the loT seems to be appealing to build the Internet of Things as a network of peer-to-peer networks. In this paper, we introduce a hybrid architecture for the Internet of things, combing fog computing to ensure security in the trustless loT environment. By enabling our fog computing architecture with blockchain-based social networks, users could easily manage smart objects via establishing tamper-proof digital identities in a trustless environment and build a new class of authentication and authorization mechanisms for the loT. We also demonstrate and analyze the feasibility of our architecture with a prototype.
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
Marcello Cinque, Christian Esposito, Stefano Russo
Trust management is extremely important for sensor networks, and the emerging vision of the Internet of Things (IoT) does not represent an exception. In fact, it allows to realize a dynamic access control needed to cope with internal attacks conducted by compromised nodes, which are likely to occur in real world. However, trust management implies a considerable consumption of energy, due to the amount of messages exchanged to collect reputation scores. Consumption is further exacerbated by the means needed to protect from attacks the trust management entities themselves. This work proposes a suitable trust management for the IoT by exploiting the eventual consistency and security guarantees of blockchain. The design of a solution based on such a technology is described, and a qualitative assessment of its protection degree is provided.
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
The popularity of the Internet of Things (IoT) and its various applications are growing rapidly. Trust in most IoT networks is presumed implicitly. This implicit assumption of trust can be abused by adversaries to disrupt the network and manipulate reputations of trusted devices. Spoofing devices' identities or forging new identities allows adversaries to masquerade and act as legitimate devices. Devices with forged identities are known as Sybils. In this paper, we propose an IoT trust model that uses permissioned blockchains that utilize Smart Contracts (executable policies) to evaluate trustworthiness of IoT devices by recording and validating IoT devices' identities to prevent Sybil attacks. Additionally, to show effectiveness of our model, we provide a proof-of-concept prototype of our model's key features.
Seunghyun Yoo, Seungbae Kim, Joshua Joy, Mário Gerla
A proof-of-work blockchain adopts an incentive-driven design to encourage people to participate in the network. Miners provide computing resources and services in exchange for incentives such as static block rewards and transaction fees collected from blockchain users. However, our findings suggest that the current reward scheme may not encourage miners to process user transactions. A non-cooperative strategy that submits a block with no transaction can be more rewarded than a cooperative strategy. As a consequence, the non-cooperative strategy can prevail over the cooperative strategy, decrease the system throughput, and distort credit distribution. We particularly choose Ethereum project as a subject since it is a general-purpose smart contract platform. By investigating the past two years of its ledger history, we find network propagation and block processing delays are the most significant factors that cause miners to choose the non-cooperative strategy. From this finding, we develop a more accurate statistical model for a block discovery time, as well as a reward matrix. We then derive the condition that either strategy has no additional gain, which also helps to estimate whether the transaction fee is underpriced or not. Simulation results show that the non-cooperative strategy is no longer dominant under the revised reward scheme.
Juan Carlos Farah, Andrii Vozniuk, María Jesús Rodríguez‐Triana, Denis Gillet
The need to ensure privacy and data protection in educational contexts is driving a shift towards new ways of securing and managing learning records. Although there are platforms available to store educational activity traces outside of a central repository, no solution currently guarantees that these traces are authentic when they are retrieved for review. This paper presents a blueprint for an architecture that employs blockchain technology to sign and validate learning traces, allowing them to be stored in a distributed network of repositories without diminishing their authenticity. Our proposal puts participants in online learning activities at the center of the design process, granting them the option to store learning traces in a location of their choice. Using smart contracts, stakeholders can retrieve the data, securely share it with third parties and ensure it has not been tampered with, providing a more transparent and reliable source for learning analytics. Nonetheless, a preliminary evaluation found that only 56% of teachers surveyed considered tamper-evident storage a useful feature of a learning trace repository. These results motivate further examination with other end users, such as learning analytics researchers, who may have stricter expectations of authenticity for data used in their practice.
This paper presents a new trade-clearing framework with a Super-Large Ledger (SLL) that can be shared with exchanges, banks, and regulators. Furthermore, this SLL runs on top of a permissioned BC with significant redundancy, and can be efficiently processed at high speed with scalability. In other words, when the workload increases, the SLL will be split and allocated to different processors to speed up the operation. The framework has been implemented and evaluated at a clearinghouse and processed 3.3B historical and real-time transactions.
BITCONCH chain proposed an innovative POR (Proof Of Reputation) reputation consensus algorithm, which solved the pain point that the blockchain is difficult to maintain both high throughput and decentralization. Based on social graphs, BITCONCH Chain mathematically models social, time, and contribution activities to build a decentralized reputation system. Each user has the opportunity to establish a high reputation value. The higher the user's reputation, the lower the transaction cost (or even free). The more opportunities that are selected as trust nodes to participate in the consensus, the greater the benefits. High-reputation users are defined as “mutual trust nodes”, and small micro-transactions will start “payment channels” for high-speed offline transactions. The reputation system and system incentive system will effectively promote the continued enthusiasm of business developers and ordinary users, and contribute to the construction of the business ecosystem. Business developers with traffic are more likely to get high reputation values, and the chances of being elected to a trusted full node are higher. Ordinary users can increase reputation by actively engaging in social interactions and actively using business applications in the ecosystem, increasing the chances of being selected as trusted light nodes. The Bitconch chain uses a DAG directed acyclic graph data structure to maintain the system's positive scalability. Support smartphone light node client to resist the decentralization of the system and maintain dispersion. Zero-knowledge verification, latticed data storage, quantum-level encryption algorithms, and improved BVM virtual machines make Bitconch chain more reliable and provide a friendly DApp and sidechain development environment to meet certain applications. Technical requirements for large file storage, low transaction costs, user information protection, sidechain and smart contract iterations, and bug fixes. BITCONCH chain is a decentralized distributed network with no block and no chain, which solves two difficulties in the application of blockchain: scalability and decentralization. Bitconch chain, which can be applied to the commercial application needs of users above 10 million, is the most feasible blockchain ecosystem for high-frequency small micro-transactions and social applications.
Blockchain is one of the most hyped technologies of recent years. It promises to restructure the way applications are developed and to replace the widely client-server model used today. While the technology is promising the ecosystem of tools and development methodologies are still in their early stages. In this paper a proof of concept blockchain application is developed, regarding the exchange of data between different universities in different countries, with respect to the Erasmus program. A decentralized application has been designed from ground up and is proposed to be installed in multiple nodes located in all participating universities. Ethereum platform has been chosen and the required smart contracts have been implemented. Additionally an easy to use web interface have been developed in order to be usable for end users. We have evaluated both the development process and the efficiency of the resulting implementation.
Rawia Bdiwi, Cyril de Runz, Sami Faïz, Arab Ali Chérif
Internet of Things (IoT) and Blockchain (BC) is an innovative paradigm that is gaining ground in smart environments. In intelligent classrooms, IoT makes our exchange easier with the prominent advent of smart devices, connected objects and sensors. However, the important research direction in this kind of IoT-Based Ubiquitous Learning Environment (ULE) is security and privacy that remaining essential challenges. Previously, we exposed the initial architecture of ULE based on BC technology and the educational services that can be delivered via this platform. In this paper, we investigate deeper and we highlight the main component of our ULE known as integrated IoT-ubiquitous platform using BC. The collection of data exchanged across devices is determined by the miner that preserves security using transactions that trace communications. Finally, in this study we demonstrate our preliminary experimental results that show the effectiveness of the proposed decentralized platform which is more secure by analyzing confidentiality, integrity, and availability.
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
Blockchain technology is a ledger system that is popularly known as the backbone of the Bitcoin cryptocur-rency. Since its conception, the potential beneficial applications of blockchain in other digital sectors have been lauded in the literature, and related challenges have been disputed. In this study, the literature is reviewed for frameworks and use cases that fully realize the applicability of blockchain beyond financial applications and cryptocurrencies. A network analysis of the literature was performed to identify the most popularly documented digital sectors in this context, which include the Internet of Things (IoT), healthcare, supply chain management, and government sectors. For each sector, this review documents use cases in which an attempt is made to implement blockchain solutions. The main purpose of this paper is to probe each sector for the growing maturity of blockchain technology and to document the unique benefits and challenges arising from the use of this technology. The findings show that despite the growing reputation of blockchain technology, its implementation within these four sectors remains in infancy because the use cases lack concrete evaluations of its effectiveness and plausibility. Nevertheless, the categorization of current blockchain use cases demonstrates current applications and sector-specific concerns that suggest future directions for further research.
Thomas K. Dasaklis, Fran Casino, Constantinos Patsakis
Blockchain technology is rapidly gaining traction in healthcare industry as one of the most exciting technological developments. In particular, blockchain technology presents numerous opportunities for healthcare industry such as reduced transaction costs, increased transparency for regulatory reporting, efficient healthcare data management and healthcare records universality. In the context of smart health, blockchain may provide distinct benefits, particularly from a context-aware perspective where efficient and personalised solutions may be provided to citizens and the society in general. In this article, we portray the symbiotic relationship between blockchain and smart health. Among others, we identify and analyse three individual streams of possible synergies. In addition, we discuss several challenges for actually implementing blockchain-based applications in the healthcare industry along with several opportunities for future research directions.
Research related to electric vehicles (EVs) is mainly focused on hardware such as battery charging method, and there is still a lack of software (service oriented) research such as billing system that needs to be developed realistically. The result of the charge measured in the charging EV can be different from the charge amount claimed to be charged in the charging station. This is because the charge is measured separately from each other using its smart meters. And if mechanical measurements are assumed to be accurate, it is possible to lie in one of the EV or charging station. Also, billing information can be manipulated. To prevent those problems, this paper proposes the blockchain based billing system. The EV and the charging station store the billing information in the blockchain after mutual authentication and prevent the modification. A blockchain is the system in which all nodes have the same ledger, therefore cannot be tampered with. This prevents a user from modifying the record after charging.
Unmanned Aerial Vehicles - UAVs, or drones - are now being operated by several military forces and currently, to a more limited extent, by civilian organizations. These latter operations, however, may eventually expand to exceed, in number and diversity, those of the military. Further expected development in battery capacity, construction materials and software, especially regarding machine learning algorithms and drone integration, will definitely increase UAVs' autonomous. Unique risks associated with UAVs like risk of hackers' attacks to intercept the control are also increasing. More incidents likely will occur once regulations are finalized that encourage more use that is widespread. Such incidents could result in multi-million dollar claims against businesses, operators and manufacturers. Blockchain is the basis technology for cryptocurrencies. However, Blockchain can have far larger applications in the field of UAVs, because Blockchain is highly distributed and publically viewable system of sequentially linked cryptographically. This paper presents a concept of application, where each UAV in the UAVNet is a Blockchain node, has on-board functionality for creating and reading transactions from the block, as well as communication tools for exchanging transactions with other UAVs.
Internet of Things (IoTs) offers a plethora of opportunities for remote monitoring and communication of everyday objects known as things with applications in numerous domains. The advent of blockchains can be a significant enabler for IoTs towards conducting and verifying transactions in a secure manner. However, applying blockchains to IoTs is challenging due to the resource constrained nature of the embedded devices coupled with significant delay incurred in processing and verifying transactions in the blockchain. Thus there exists a need for profiling the energy consumption of blockchains for securing IoTs and analyzing energy-performance trade-offs. Towards this goal, we profile the impact of workloads based on Smart Contracts and further quantify the power consumed by different operations performed by the devices on the Ethereum platform. In contrast to existing approaches that are focused on performance, we characterize performance and energy consumption for real workloads and analyse energy-performance trade-offs. Our proposed methodology is generic in that it can be applied to other platforms. The insights obtained from the study can be used to develop secure protocols for IoTs using blockchains.
Yiming Jiang, Chenxu Wang, Ye Huang, Siyu Long · 5 authors
At present, the Internet of Things (IoT) is rapidly setting off a huge wave of digitalization in traditional industries. In the era of the Internet of Everything, massive data is generated by IoT devices. Recently, Blockchain has attracted more and more attentions in the field of IoT due to its decentralization, traceability, security and so on. Many IoT-oriented data services are built based on distributed ledger technology like blockchains. However, due to the lack of scalability and high transaction costs of the public blockchain, it is hard to directly apply the blockchain technology to IoT scenarios. The recent transaction directed acyclic graph (TDAG) technology, especially Tangle, is suitable for low-latency M2M (Machine to Machine) micropayment transactions in the ever-growing scale of the edge-centric IoT. In this paper, we propose a framework to integrate Tangle into IoT blockchains and build a cross-chain interactive decentralized access model in the context of data management. We employ a consortium blockchain as the control station, and Tangle runs as the backbone of all IoT devices. It is equivalent to opening the off-chain channel of the DAG Tangle structure on the consortium blockchain. Transactions in these channels form the sub-Tangle and then merge sub-Tangle into the main Tangle for confirmation through the notary mechanism. Finally, we implement a prototype of the proposed model and conduct extensive experiments to evaluate its performance. The results clearly demonstrate the effectiveness and efficiency of our framework.
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
The Internet of Things aims at connecting everything ranging from individuals, organizations, companies to things in the physical and virtual world. The digital identity has always been considered as the keystone for all online services and the foundation for building security mechanisms such as authentication and authorization. However, current literature still lacks of a comprehensive research on the digital identity management for the Internet of Things (IoT). In this paper, we identify digital identity challenges and solutions for the Internet in general. We then focus on how existing solutions cope with IoT requirements such as scalability, interoperability, mobility, security and privacy. We also investigate recent surging blockchain sovereign identity solutions and enumerate some projects and startups which are focusing on IoT identity problems. Furthermore, we elaborate challenges of building identity management systems for the IoT, including access control, privacy preserving, trust and performance respectively. At last, we conclude with the promising future research trends in building IoT identity management systems.
Thomas Kobzan, Alexander Biendarra, Sebastian Schriegel, Thomáš Herbst · 6 authors
The fourth Industrial Revolution is finding its way into modern manufacturing sites. Assets with a certain degree of implemented communication technology will be enabled to interconnect and cooperate with practically every other entity via the Industrial Internet. An extreme amount of data and information will be exchanged all the time. Machines will be empowered to make crucial decisions autonomously influencing whole production processes. Erroneous, illegitimate or tampered data will lead to incorrect decisions and will be posing a huge threat to future strong cross-linked added value networks. An approach to tackle this issue comes from a technology called distributed ledger technology with its most known variant the “blockchain”. Certain properties of blockchain technology are showing promising enhancements for industrial networks primarily in order to guarantee digital trust. In this paper, issues like the ability to scale and the adaption onto the requirements of industrial networks are investigated. It turns out that simulation approaches must be taken into consideration, and a first step for an implementation is presented.