Software-Defined Networking (SDN) has revolutionized network management by providing unprecedented flexibility, control, and efficiency. However, its centralized architecture introduces critical security vulnerabilities. This paper introduces a novel approach to securing SDN environments using IOTA 2.0 smart contracts. The proposed system utilizes the IOTA Tangle, a directed acyclic graph (DAG) structure, to improve scalability and efficiency while eliminating transaction fees and reducing energy consumption. We introduce three smart contracts: Authority, Access Control, and DoS Detector, to ensure trusted and secure network operations, prevent unauthorized access, maintain the integrity of control data, and mitigate denial-of-service attacks. Through comprehensive simulations using Mininet and the ShimmerEVM IOTA Test Network, we demonstrate the efficacy of our approach in enhancing SDN security. Our findings highlight the potential of IOTA 2.0 smart contracts to provide a robust, decentralized solution for securing SDN environments, paving the way for the further integration of blockchain technologies in network management.
Ethereum is rapidly expanding through cross-chain linkages with its layer 2 and EVM-compatible blockchains. As it is already the largest ecosystem in terms of the number of users, applications, and economic value, it is of a great importance to study the speed, network activity and power consumption of its protocols. Furthermore, understanding the correlation between network activity and power consumption is important to gain insight into those protocols' scalability. An examination of Ethereum, Ethereum Layer 2 (Arbitrum and Optimism), and EVM-compatible (Avalanche, BSC, and Harmony) blockchain protocols revealed that emerging Ethereum Layer 2 and EVM-compatible blockchains are faster than Ethereum. Pearson analysis between power consumption and network activity showed weak correlations. Furthermore, there is no evidence of Granger causality between the power consumption and the network activity in either direction for any blockchain protocol. This finding suggests that power consumption is independent of network activity, indicating that protocols that consume less power do not do so because of their low network activity, but rather because of protocol-specific optimization. This also shows that these protocols can potentially scale with user growth. This study, therefore, serves as a valuable insight for those planning to implement blockchain protocols tailored to their industry requirements.
Blockchain transactions can be made more scalable using Payment Channel Networks (PCNs), which do not require significant modifications to the distributed ledger algorithm. On the other hand, an onion protocol for anonymity and a locking mechanism to prevent race conditions are needed when routing a payment via several channels in a PCN. This method can be abused by adversaries to launch wormhole attacks. Prior research concentrated on source routing, which is unlikely to continue to be an effective routing strategy as these networks expand. We investigate the impact of attacks in PCNs that employ local knowledge-based routing algorithms. In these scenarios, malicious nodes can steal the benefits of interacting nodes by exchanging confidential information among themselves. We have analyzed the impact of wormhole attacks in the Swift algorithm, Speedy Murmurs, and Silent Whispers. Our experiments introduced an attack that uses a depth measure to arrange malicious nodes in various locations. We used attack gain, attack cost, and attack transaction ratio metrics to assess the attack's impact on routing algorithms. Our simulation-driven analysis demonstrates that placing a malicious node subsequent to a landmark node will raise the likelihood of an attack but at a higher cost. With high transaction volume, attack gain in Silent Whisper will decrease compared to Speedy Murmurs and Swift due to congestion. With 9.6% malicious nodes located at different locations, the average attack transaction ratio for all distributive routing algorithms is 41 %.
As a result of the Internet of Things, high-speed data transmission and ultra-low latency are achieved in various applications. Data tampering in IoT networks can be caused by malicious or accidental interference, however. By combining blockchain technology with software-defined networking (SDN), we can mitigate these problems. IoT devices and SDN controllers will be able to communicate peer-to-peer by using public and private blockchains. For devices with limited resources, it is an ideal solution since it eliminates Proof-of-Work (PoW) and incorporates distributed trust. In this paper, we present a new Proof-of-Authority (PoA) consensus algorithm that is designed to improve the consistency and reliability of edge devices within the IoT ecosystem, as well as to ensure a high level of trust across IoT ecosystems. During experiments, the integration of SDN and blockchain outperformed existing models in terms of throughput, delay, response time, and CPU utilization, including Blockchain Fundamentals (BCF), AS Cooperative Interdomain Reputation (ASCIR), and Blockchain-based SDN-enabled Secure Routing (BSDNSR).
Yi Gong, Boyuan Yu, Lei Yang, Fanke Meng · 7 authors
With the evolution of next-generation communication networks, ensuring robust Core Network (CN) architecture and data security has become paramount. This paper addresses critical vulnerabilities in the architecture of CN and data security by proposing a novel framework based on blockchain technology that is specifically designed for communication networks. Traditional centralized network architectures are vulnerable to Distributed Denial of Service (DDoS) attacks, particularly in roaming scenarios where there is also a risk of private data leakage, which imposes significant operational demands. To address these issues, we introduce the Blockchain-Enhanced Core Network Architecture (BECNA) and the Secure Decentralized Identity Authentication Scheme (SDIDAS). The BECNA utilizes blockchain technology to decentralize data storage, enhancing network security, stability, and reliability by mitigating Single Points of Failure (SPoF). The SDIDAS utilizes Decentralized Identity (DID) technology to secure user identity data and streamline authentication in roaming scenarios, significantly reducing the risk of data breaches during cross-network transmissions. Our framework employs Ethereum, free5GC, Wireshark, and UERANSIM tools to create a robust, tamper-evident system model. A comprehensive security analysis confirms substantial improvements in user privacy and network security. Simulation results indicate that our approach enhances communication CNs security and reliability, while also ensuring data security.
Software-Defined Networking (SDN) has revolutionized network management by providing unprecedented flexibility, control, and efficiency. However, its centralized architecture introduces critical security vulnerabilities. This paper presents an innovative approach to securing SDN environments using IOTA 2.0 smart contracts. The proposed system leverages the IOTA Tangle, a directed acyclic graph (DAG) structure, to enhance scalability and efficiency while eliminating transaction fees and reducing energy consumption. We introduce three smart contracts—Authority, Access Control, and DoS Detector—to ensure secure network operations, prevent unauthorized access, and mitigate denial-of-service attacks. Through comprehensive simulations using Mininet and the ShimmerEVM IOTA Test Network, we demonstrate the efficacy of our approach in enhancing SDN security. Our findings highlight the potential of IOTA 2.0 smart contracts to provide a robust, decentralized solution for securing SDN environments, paving the way for further integration of blockchain technologies in network management.
Kouros Zanbouri, Mehdi Darbandi, Mohammad Nassr, Arash Heidari · 6 authors
Summary The latest developments in the industrial Internet of things (IIoT) have opened up a collection of possibilities for many industries. To solve the massive IIoT data security and efficiency problems, a potential approach is considered to satisfy the main needs of IIoT, such as high throughput, high security, and high efficiency, which is named blockchain. The blockchain mechanism is considered a significant approach to boosting data protection and performance. In the quest to amplify the capabilities of blockchain‐based IIoT, a pivotal role is accorded to the Glowworm Swarm Optimization (GSO) algorithm. Inspired by the collaborative brilliance of glowworms in nature, the GSO algorithm offers a unique approach to harmonizing these conflicting aims. This paper proposes a new approach to improve the performance optimization of blockchain‐based IIoT using the GSO algorithm due to the blockchain's contradictory objectives. The proposed blockchain‐based IIoT system using the GSO algorithm addresses scalability challenges typically associated with blockchain technology by efficiently managing interactions among nodes and dynamically adapting to network demands. The GSO algorithm optimizes the allocation of resources and decision‐making, reducing inefficiencies and bottlenecks. The method demonstrates considerable performance improvements through extensive simulations compared to traditional algorithms, offering a more scalable and efficient solution for industrial applications in the context of the IIoT. The extensive simulation and computational study have shown that the proposed method using GSO considerably improves the objective function and blockchain‐based IIoT systems' performance compared to traditional algorithms. It provides more efficient and secure systems for industries and corporations.
Recent advancements in Vehicle-to-Grid (V2G) lead to efficient service provisions, such as eco-friendly environment, demand response management, charging, and discharging to the end-users. However, security and privacy preservation for the aforementioned services are key challenges keeping in view of the dependency on the existing centralized security architectures which are not resilient to fault tolerance due to a single point of failure. Hence, there is a need to design new efficient security solutions for the current V2G network, so as to provide seamless services to the end-users. Motivated by these, in this work, we proposed a bloom filter-enabled smart contract-based scheme for access control in V2G environment. In comparison to complex signature-based cryptographic techniques, we propose bloom filter-based authentication for the registered nodes for efficient storage and searching of stored data on the blockchain network. We also designed the Proof-of-Authority (PoA) consensus mechanism, which selects authority nodes dynamically to verify various transactions on the blockchain network. To validate the proposal, we implemented it on the Ethereum network on benchmark datasets using various evaluation parameters such as- latency, throughput, false positive probability, and gas cost.
Juncal Uriol, Álvaro Camacho, Pablo Angueira, Jon Montalbán · 6 authors
The arrival of 5 G networks has introduced an era of unprecedented connectivity characterised by high speeds and low latency. The need for efficient resource utilisation and sharing becomes paramount within this landscape. The resource sharing within $\mathbf{5 G}$ networks and beyond explores the feasibility of establishing a Distributed Ledger Technology (DLT)-enabled Marketplace. This paper comprehensively analyses three prominent DLTs facilitating a robust Marketplace tailored for efficient resource sharing within the high-speed and dynamic environment of 5 G networks. As the foundational technologies underlying various decentralised systems, these DLTs have gained substantial attention for their potential to revolutionise industries and reshape how data and transactions are managed. The comprehensive analysis delves into multiple facets: scalability, security, decentralisation, transaction throughput, consensus mechanisms and energy efficiency. Evaluating the strengths and limitations of each technology in these domains facilitates a deeper understanding of their suitability for diverse use cases.
A mempool is a security-critical subsystem in a public blockchain. Recent mempool attacks, notably asymmetric DoS, have shown their ability to severely damage the Ethereum network. This paper tackles the open research problem of designing principled and non-intrusive defenses against asymmetric mempool DoSes with provable security. It presents the first mempool economic-security definitions based on mempool-observable conditions. It then presents SAFERAD, a framework of secure mempool designs with provable security against asymmetric DoSes. To defend against dual attacks by evicting and locking a victim mempool, SAFERAD adopts a non-trivial design of enforcing an upper bound of the attack damage under the locking attacks and a lower bound of the attack cost under the eviction attacks. With a prototype implementation on Geth and evaluation under real transaction traces, the results show SAFERAD has low overhead in latency and block revenue, implying non-intrusiveness and practicality.
S. Vijayalakshmi, Rohan Yellamilli, R Shobikaa, V Subasree · 6 authors
Network Intrusion Detection Systems are critical in bolstering an organization's security infrastructure. The goal of our paper is to design and build a specialized intrusion detection system for simulated military scenarios. The solution classifies network accesses using machine learning techniques and seamlessly integrates the Ethereum blockchain for secure anomalous access record-keeping and auditing. The machine learning component classifies the records as normal or anomalous using the ensemble learning technique, which is the random forest classifier. Feature selection techniques like Variance Threshold, Spearman's correlation coefficient, Pearson's correlation coefficient, Mutual Information and Chi square tests were used to improve the accuracy of the model and reduce dimensionality. The final accuracy of the model was brought to 96.69%. It then sends the records to the blockchain environment for storage. To ensure data integrity and transparency, anomalous access events will be time-stamped, hashed using IPFS, and published to the blockchain. By providing a hash value and a unique id as input, the user will be able to add new anomalous entries. Furthermore, the user will be able to examine the hashed anomalous data for each csv file using the proper id.
Establishing strong security protocols is crucial in the quickly changing internet of things (IoT) environment to reduce potential risks and weaknesses. It is possible to manage security risks more effectively, but there are also challenges because of the interconnected nature of IoT devices, the introduction of 6G networks, and the incorporation of distributed ledger technology (DLT). The focus of this note is on proactive methods of protecting infrastructure and sensitive data. It explores different management strategies that are intended to mitigate threats in IoT environments. Using a security-by-design methodology is a fundamental tactic for threat mitigation in internet of things settings. Every phase of the lifecycle of an IoT device, from design and development to deployment and operation, must incorporate security measures.
Abstract Decentralized autonomous organization (DAO)-based applications can revolutionize traditional centralized decision-making procedures and services by enabling scalable, decentralized, autonomous, and democratized decision-making processes. Unlike traditional applications, DAO-based decentralized applications use Ethereum blockchain-based smart contract programs to execute policies or make automated decisions. To that end, 6 G technologies can improve the latency and reliability of many existing blockchain-based DAOs. Previous research did not investigate the execution of DAO and non-DAO-based applications, as well as an adaptive resource choreography scheme, while accounting for various 6 G technologies, blockchain, and mobile-edge cloud (MEC). To prevail over the previous shortcomings, this article supplies a street smart multi-platform coordination, application scheduling, and low-latency-aware resource choreography scheme for both DAO and non-DAO-based application execution over blockchain and MEC-enabled 6 G networks by taking heterogenous DAO and non-DAO application count, application requirements, physical worker, virtual worker, and communication resource status into account. The results verified that the proposed kaizen scheme delivers at least 11.26% app work completion delay gain, 7.2% user energy overhead gain, 6.55% user economic charge gain, and 21% service provider profit than the compared schemes.
A Multi-Controller Software-Defined Network (MC-SDN) is a revolutionary concept comprising multiple controllers and switches separated using programmable features, enhancing network availability, management, scalability, and performance. The MC-SDN is a potential choice for managing large, heterogeneous, complex industrial networks. Despite the rich operational flexibility of MC-SDN, it is imperative to protect the network deployment with proper protection against potential vulnerabilities that lead to misuse and malicious activities on the MC-SDN structure. The security holes in the MC-SDN structure significantly impact network survivability and performance efficiency. Hence, detecting MC-SDN security attacks is crucial to improving network performance. Accordingly, this work intended to design blockchain-based controller security (BCS) that exploits the advantages of immutable and distributed ledger technology among multiple controllers and securely manages the controller communications against various attacks. Thereby, it enables the controllers to maintain consistent network view and accurate flow tables among themselves and also neglects the controller failure issues. Finally, the experimental results of the proposed BCS approach demonstrated superior performance under various scenarios, such as attack detection, number of attackers, number of controllers, and number of compromised controllers, by applying different performance metrics.
The surge in blockchain-based cryptocurrencies has created a pressing need for Cross-Chain Transaction (CCTx) solutions. Existing solutions either lack sufficient security, like centralized exchanges, or suffer from poor efficiency and scalability, such as atomic swaps. Inspired by the success of the Lightning Network in accelerating Bitcoin transactions, we propose CrossChannel that establishes cross-and-off-chain micropayment channels to achieve efficient and scalable CCTx. Specifically, we analyze the challenges of extending one-chain channels to cross-chain scenarios caused by the separation of blockchains. To overcome these challenges, we employ the chain relay mechanism to synchronize channel-related information across blockchains and construct the channel management protocol on this basis, ensuring the same security level as one-chain channels in cross-chain settings. We prototype CrossChannel between two Ethereum testnets, comparing its transaction efficiency and costs with a typical HTLC-swap scheme. Results demonstrate the significant advancements in efficiency and scalability offered by CrossChannel. Even with channels closing after just 20 transactions, CrossChannel exhibits a fivefold capacity increase for handling CCTxs compared to HTLC swaps.
Payment Channel Networks (PCNs) have been proposed as a second-layer solution to the scalability issue of blockchain-based cryptocurrencies, most developed systems still lack effective strategies for further scalability solutions. Virtual payment channel (VPC) has been proposed as an off-chain technique that avoids the involvement of intermediaries for payments in a PCN. However, there is no research on how to efficiently construct VPCs while considering the characteristics of the underlying PCN. To fill this void, this paper focuses on the VPC construction in a PCN. More specifically, we propose a metric, Capacity to the Number of Intermediaries Ratio (CNIR), to consider both the capacity of the constructed VPC and the collateral locked by the involved users. We first study the VPC construction problem for a single pair of users and design an efficient algorithm that achieves the optimal CNIR. Based on this, we propose Thor, a protocol that constructs a virtual payment channel network (VPCN) for multiple pairs. Evaluation results show that Thor can efficiently construct a VPCN and outperform baseline algorithms in terms of the CNIR.
Distributed ledger technology, with its multitude of advantages including immutability, transparency, decentralization, and security, has excellent potential to promote and even revolutionize future 6G mobile networks. Large-scale distributed ledger deployment within or for mobile networks relies on distributed ledger-focused standards to facilitate and ensure interoperability. The European Telecommunications Standards (ETSI) Industry Specification Group (ISG) on Permissioned Distributed Ledger (PDL) develops PDL-related standards, targeting various application verticals, especially within the Information and Communications Technology (ICT) domain. This article aims to give an overview of ETSI ISG PDL and describes selected PDL standards, which have synergies with future 6G mobile networks.
Cooperation among telecom carriers and datacenter (DC) providers (DCPs) is essential to ensure resiliency of network-cloud ecosystems. To enable efficient cooperative recovery in case of resource crunch, e.g., due to traffic congestion or network failures, we previously studied several frameworks for cooperative recovery among different stakeholders (e.g., telecom carriers and DCPs). Now, we introduce a novel Multi-entity Cooperation Platform (MCP) for implementing cooperative recovery planning, to achieve efficient use of carriers' valuable optical-network resources during recovery. We adopt a Distributed Ledger Technology (DLT) that ensures decentralized and tamper-proof information exchange among stakeholders to achieve open and fair cooperation. To support diverse types of cooperation, we develop a state machine representing the MCP operation and define state transitions associated to stakeholders' cooperation within the state machine. Moreover, we propose a signaling system in MCP to ensure simple and reliable state transitions for stakeholders during the cooperative recovery planning in large ecosystems. We experimentally demonstrate a proof-of-concept DLT-based MCP on a testbed. We showcase a DCP-carrier cooperative planning process, showing the flexibility of the proposed MCP to support diverse types of cooperation.
Cryptographic primitives have finite security lifespans, yet many modern systems—particularly blockchain and zero-knowledge infrastructures—are structurally resistant to change. Existing guidance on cryptographic agility assumes mutable environments and does not account for immutability, governance overhead, or proof system constraints. This work introduces a framework for evaluating cryptographic agility in deployed systems. We propose the Cryptographic Agility Score (CAS), a nine-dimensional evaluation model that characterizes how and where cryptographic dependencies are embedded, and how these constraints affect migration feasibility. Applying the framework to TLS and ZK rollup systems reveals a structural distinction: systems that anchor cryptographic primitives at negotiation layers achieve agility, while those that anchor them at execution layers face fundamental constraints. In ZK systems, these constraints are not only architectural but mathematical, arising from the algebraic structure of proof systems. This preprint presents the framework and its application across case studies. It is intended as a diagnostic and design tool for engineers building systems that must remain resilient under cryptographic change.
Yankai Xie, Ruian Li, Yan Huang, Chi Zhang · 6 authors
The Bitcoin blockchain enables users to conduct transactions securely, but its performance is restricted by the need for global consensus. Payment channels, as a promising solution to this issue, overcome this limitation through off-chain transactions. Instead of conducting each transaction on-chain, they only settle the final payment balances with the underlying blockchain. However, the most prominent scheme, the Lightning Network payment channel, requires participants to regularly monitor blockchain; otherwise, there is a potential risk of fund loss. Moreover, this scheme also fails to support participants in settling the final payment balances in real time, compromising the efficiency of fund utilization. Existing payment channel enhancing technologies are unable to overcome the above issues without compromising payment privacy. To solve the above issues, we apply the Intel Software Guard Extensions (SGX), which provides trusted execution environments with confidentiality and integrity guarantees, to design a novel Bitcoin payment channel scheme. The scheme can support real-time settlement yet guarantee the participants' fund security without monitoring the blockchain. Through a combination of the additive homomorphic property of keys, the secret sharing scheme, and customized punishments, our scheme can still guarantee fund security and off-chain transaction privacy, even if the confidentiality of SGX is compromised by side-channel attacks. Finally, security and performance analysis demonstrate that our scheme allows participants to construct a secure yet efficient payment channel to transfer value.
Anichur Rahman, Md. Saikat Islam Khan, Antonio Montieri, Md. Jahidul Islam · 9 authors
Abstract The fifth generation (5G) of mobile communications is the most exciting emerging technology for researchers and scientists to get the full benefit of a network system. However, 5G networks confront massive threats and vulnerabilities including protection, privacy, and secrecy. To face these challenges in the increasingly interconnected Internet of Things (IoT) scenario, we aim to leverage state‐of‐the‐art technologies as software defined networking (SDN) in conjunction with network function virtualization (NFV), blockchain, and machine learning (ML). Indeed, these technologies convey a robust and secure setting in the networking platform enabling to manage several criticalities related to security, privacy, flexibility, and performance. In light of these considerations, in this article, we propose the “BlockSD‐5GNet” architecture to efficiently improve the security of a 5G network and to exploit the combined advantages of Blockchain, SDN, NFV, and ML. In the proposed architecture, the SDN helps to manage the network by dividing it into data plane and control plane, while the Blockchain guarantees improved security and confidentiality. Therefore, the “BlockSD‐5GNet” architecture can both secure sensitive data and attain reliable data transfer within and between the 5G network‐infrastructure planes. Additionally, an ML module is integrated into the SDN controller to estimate network bandwidth and assist the administrator in taking effective decisions and satisfying high‐bandwidth demand. We assess the performance of the “BlockSD‐5GNet” architecture via an experimental evaluation performed in a simulation environment, and show the effectiveness of the proposed solution in comparison with baseline schemes. Finally, we also demonstrate the capability of different ML models in bandwidth prediction.
In the realm of network management, the integration of Software-Defined Networking (SDN) with blockchain-based smart contracts is an emerging frontier with significant potential to enhance inter-domain communications. This paper presents an in-depth analysis of the application of smart contracts within SDN, particularly focusing on the automation and security of inter-domain interactions. Smart contracts, characterized by their immutable and autonomous nature, offer a novel approach to enforcing network policies and agreements across different SDN domains seamlessly. We explore the inherent benefits of this integration, including enhanced security through the tamper-proof nature of blockchain, and the efficiency gains achieved by automating network policy enforcement. The paper also addresses critical challenges such as scalability, interoperability, and the complexity of smart contract development within the SDN context. Through a combination of theoretical analysis and practical case studies, this research illuminates the transformative potential of smart contracts in SDN, paving the way for more secure, efficient, and self-regulating network environments. The findings and discussions in this paper aim to contribute to the ongoing evolution of SDN, particularly in scenarios where multiple administrative domains necessitate robust, automated, and secure communication frameworks.