In this thesis, we present a private distributed ledger system, DLedger, designed for wireless meshed Named Data Networking (NDN) protocol network. DLedger utilizes lightweight Proof-Of-Authentication as gating control mechanism combining data openness among the system peers with verifiable identity within the system. The lightweight nature of Proof-Of-Authentication makes it friendly for the ledger systems consisting of even the constrained Internet of Things (IoT) devices unlike "muscle show" approaches like Proof-Of-Work, Proof-Of-Space, etc. which are storage or computation intensive and combines data openness with anonymity (or pseudonymity). Moreover, different from the popular blockchain-based ledger systems, DLedger utilizes a Directed Acyclic Graph as a fundamental data structure so that its operations can tolerate network partitions. Built over NDN, DLedger truly leverages from its data-centric nature to facilitate data dissemination in peer-to-peer heterogenous IoT networks. We conclude the thesis by reasoning our design through simulation results and discussing a real-world use case.
The security issue is one of the greatest challenges in vehicular ad hoc networks (VANETs) attracting a great deal of attention. Malicious onboard units (OBUs) can attack other OBUs with various manners to obtain illegal gains, such as jamming, eavesdropping spoofing and so on. To reduce the potential attackers in the network, we propose an indirect reciprocity security framework with a scalar reputation assigned to each OBU to evaluate their dangerous level to the VANET. A blockchain technique that uses consensus mechanism and encryption algorithms to protect information from being tampered is applied for the transmitter to record the behaviors of other OBUs. We also propose a reinforcement learning based action selection strategy for an OBU in the VANET to choose a reliable relay OBU or determine whether to follow the request of a source OBU or not. A hotbooting technique is applied for the OBUs with prior knowledge to accelerate the learning speed. Simulation results show that the proposed action selection strategy can efficiently increase the packet delivery ratio, the reputation and the utility of the each OBU.
Summary Decentralization, in the form of mesh networking and blockchain, two promising technologies, is coming to the telecommunications industry. Mesh networking allows wider low‐cost Internet access with infrastructures built from routers contributed by diverse owners, whereas blockchain enables transparency and accountability for investments, revenue, or other forms of economic compensations from sharing of network traffic, content, and services. Crowdsourcing network coverage, combined with crowdfunding costs, can create economically sustainable yet decentralized Internet access. This means that every participant can invest in resources and pay or be paid for usage to recover the costs of network devices and maintenance. While mesh networks and mesh routing protocols enable self‐organized networks that expand organically, cryptocurrencies and smart contracts enable the economic coordination among network providers and consumers. We explore and evaluate two existing blockchain software stacks, Hyperledger Fabric (HLF) and Ethereum geth with Proof of Authority (PoA) intended as a local lightweight distributed ledger, deployed in a real city‐wide production mesh network and in laboratory network. We quantify the performance and bottlenecks and identify the current limitations and opportunities for improvement to serve locally the needs of wireless mesh networks, without the privacy and economic cost of relying on public blockchains.
The Internet of Things (IoT) is visioned to connect everything in the world by a common networking technique. In spite that Internet protocol is the most prevailing networking solution, it is difficult to adapt to IoT which is born with scalability, heterogeneity, and dynamics. Thanks to the content-centric communication paradigm, it exerts data-naming strategy to incorporate the heterogeneity and dynamics so as to apply for IoT, composing Named Data Networking (NDN) of Things. However, the paradigm also introduces new types of security attacks. In this paper, the NDN of Things architecture will be illustrated and the security analysis is conducted. Furthermore, the potential security attacks of NDN of Things are categorized and the performance impact caused by security attacks is evaluated. Finally, the solutions for NDN of Things security attacks are discussed and a blockchain solution is illustrated.
Deepak K. Tosh, Sachin Shetty, Peter Foytik, Laurent Njilla · 5 authors
Internet of Things (IoT) technology is emerging to advance the modern defense and warfare applications because the battlefield things, such as combat equipment, warfighters, and vehicles, can sense and disseminate information from the battlefield to enable real-time decision making on military operations and enhance autonomy in the battlefield. Since this Internet-of-Battlefield Things (IoBT) environment is highly heterogeneous in terms of devices, network standards, platforms, connectivity, and so on, it introduces trust, security, and privacy challenges when battlefield entities exchange information with each other. To address these issues, we propose a Blockchain-empowered auditable platform for IoBT and describe its architectural components, such as battlefield-sensing layer, network layer, and consensus and service layer, in depth. In addition to the proposed layered architecture, this paper also presents several open research challenges involved in each layer to realize the Blockchain-enabled IoBT platform.
Enormous research efforts have been investigated in Vehicular Ad Hoc Networking to improve users safety, traffic condition, and provide different reliable services, that are challenging tasks to accomplish in the current Internet model. In-network caching is one of the promising features of Named Data Networking, a new future Internet architecture based on content name instead of the host address. It aims to enhance the network performance, data availability, distribution, and access. The applicability of NDN in VANET introduced several issues, especially in the security and trust relationships. In this paper, we present a reputation-based blockchain mechanism to secure the cache in the vehicular environment and enhance the trust between cache stores and consumer vehicles. The obtained results demonstrate that our scheme outperforms the normal NDN behavior by providing only trust content in the network.
In this work, we propose using edge computing and caching to enhance wireless communications in terms of bandwidth and delay by leveraging concept of mobile 3C systems (communications, computing, and caching). First we argue that without leveraging concepts of edge computing and caching, the huge burden of data transmission and processing necessary for smart city applications and concept is going to exhaust the current wireless infrastructure. Then we demonstrate the need to merge edge computing with caching to enhance wireless communication needed for massive data collection in smart cities. To address the security concerns of using IoT in smart cities, we propose using a blockchain database to secure communication between the smart city and home devices and sensors. This will provide the scalability that is necessary for data transfer between the massive number of nodes in IoT that current security protocols do not provide.
This thesis focuses on aspects related to the functioning of the gossip\nnetworks underlying three relatively popular cryptocurrencies: Ethereum, Nano\nand IOTA.\n We look at topics such as automatic discovery of peers when a new node joins\nthe network, bandwidth usage of a node, message passing protocols and storage\nschemas and optimizations for the shared ledger. We believe this is a topic\nthat is often overlooked in works about blockchains and cryptocurrencies.\nVulnerabilities and inefficiencies attain a higher significance than ones in a\nregular open source project because of the rather direct financial implications\nof these projects. Barring Bitcoin, a network that has been around for nearly\n10 years, no other project has substantial documentation for its operational\ndetails other than scattered and sparse pages in the source code repositories.\nAlmost all of the content described here has been extracted by studying the\nsource code of the reference implementations of these projects.\n We evaluate the use of Invertible Bloom Lookup Tables and the Graphene\nprotocol to decrease block propagation times and bandwidth usage of certain\nmessages. We perform realistic simulations that show significant improvements.\nWe provide a complete implementation of Graphene in Geth, Ethereum's main node\nsoftware and test this implementation against the main Ethereum blockchain.\n We also crawled the chosen cryptocurrency networks for publicly visible nodes\nand provide an Autonomous System-level breakdown of these nodes with the end\ngoal of estimating the ease of performing attacks such as BGP hijacks and their\nimpact.\n Code written for implementing Graphene in Geth, performing various\nsimulations and for other miscellaneous tasks has been uploaded to Github at\nhttps://github.com/sunfinite/masters-thesis.\n
Named Data Networking is built with security which requires each named Data object to be digitally signed by its producer. Thus, the NDN project has proposed a key management model on NDN testbed for verification of the Data packet to be immune to distributing poisoned content. However, in practice, this model poses two challenges for verifying fake content: (1) the centralized architecture easily leads to a single point of failure, especially when the root key fails, its difficult to verify the keys across sites due to the lack of trust between them, and (2) excessive overhead of certificate chain traversal when verifying signature. This paper first proposes a blockchain-based key management scheme in NDN to address the problem of lack of mutual trust between sites without trust anchors. Specifically, all site nodes form a permissioned blockchain for storing public key hashes to ensure the authenticity, and the proxy gateway participates in verifying to reduce excessively frequent communication between the router and the blockchain. In addition, the NDN public key content object and the scheme of their storage, verification, and revocation are redesigned. The result of our analysis and evaluation shows that the proposed scheme is capable of supporting less verification numbers and higher verification efficiency.
The public key infrastructure (PKI) based authentication protocol provides the basic security services for vehicular ad-hoc networks (VANETs). However, trust and privacy are still open issues due to the unique characteristics of vehicles. It is crucial for VANETs to prevent internal vehicles from broadcasting forged messages while simultaneously protecting the privacy of each vehicle against tracking attacks. In this paper, we propose a blockchain-based anonymous reputation system (BARS) to break the linkability between real identities and public keys to preserve privacy. The certificate and revocation transparency is implemented efficiently using two blockchains. We design a trust model to improve the trustworthiness of messages relying on the reputation of the sender based on both direct historical interactions and indirect opinions about the sender. Experiments are conducted to evaluate BARS in terms of security and performance and the results show that BARS is able to establish distributed trust management, while protecting the privacy of vehicles.
One remarkable feature of vehicular ad hoc networks is characterized by an opportunistic communications by means of store-carry-forward message relaying which requires the cooperation of vehicles on the networks. However, we cannot be sure that all vehicles willingly contribute their computing resources to the networks for message forwarding with no rewards for their efforts in real-world scenarios. In addition, unfortunately, there may exist some selfish and greedy node which may not help others but tend to take their own gain. To cope with this challenge, incentive mechanisms are generally considered as the promising solution. In this paper, we design a Bitcoin-based secure and reliable incentive scheme for cooperative vehicular delay tolerant networking services. Bitcoin is the well-known worldwide cryptocurrency and digital payment system whose implementation relies on cryptographic techniques, which makes it possible to develop a practical credit-based incentive scheme on the vehicular networks at a low cost. We also implement Bitcoin transaction scripts to handle our proposed incentive scheme.
Digital identity is the cornerstone of a digital economy. However, proving identity remotely is difficult to do. To complicate things further, identity is usually not a global, absolute construct, but the information shared with different parties differs, based on the relationship to the user. Therefore, a viable solution for digital identity should enable users to have full control over their personal information and share only the information that they wish to share with each service. Blockchain technology can help to realize a self-sovereign identity that puts the user in control of her information, by enabling a decentralized way to handle public key infrastructure. In the current contribution, we present the Sora identity system, which is a mobile app that utilizes blockchain technology to create a secure protocol for storing encrypted personal information, as well as sharing verifiable claims about personal information.
Cash-less payment via a variety of credit, debit or prepaid cards is pervasive in our interconnected society, but not so ubiquitous in remote rural regions where network connectivity is intermittent. We proposed a cash-less payment scheme for remote villages based on blockchains that allow maintaining a record of verifiable transactions in a distributed manner. We overcome the limitations of intermittent network connectivity by solely relying on blockchain mining nodes in the village for transaction processing and verification. The bank joins as a peer and monitors node behaviors, rewards miners and processes currency exchanges whenever the connectivity is available. We take advantage of the Ethereum network to develop our solution and demonstrate the feasibility of the proposed system on off-the-shelf computing devices. We emulate a remote village scenario with intermittent network connectivity and show the robustness and reliability of the proposed system.
Bluetooth Low Energy (BLE) has emerged as one of the most promising technologies to enable the Internet-of-Things (IoT) paradigm. In BLE-based IoT applications, e.g., wearables-oriented service applications, the Bluetooth MAC addresses of devices will be swapped for device pairings. The random address technique is adopted to prevent malicious users from tracking the victim's devices with stationary Bluetooth MAC addresses and accordingly the device privacy can be preserved. However, there exists a tradeoff between privacy and security in the random address technique. That is, when device pairing is launched and one device cannot actually identify another one with addresses, it provides an opportunity for malicious users to break the system security via impersonation attacks. Hence, using random addresses may lead to higher security risks. In this study, we point out the potential risk of using random address technique and then present critical security requirements for BLE-based IoT applications. To fulfill the claimed requirements, we present a privacy-aware mechanism, which is based on elliptic curve cryptography, for secure communication and access-control among BLE-based IoT objects. Moreover, to ensure the security of smartphone application associated with BLE-based IoT objects, we construct a Smart Contract-based Investigation Report Management framework (SCIRM) which enables smartphone application users to obtain security inspection reports of BLE-based applications of interest with smart contracts.
Blockchain provides a new approach for participants to maintain reliable databases in untrusted networks without centralized authorities. However, there are still many serious problems in real blockchain systems in IP network such as the lack of support for multicast and the hierarchies of status. In this paper, we design a bitcoin-like blockchain system named BlockNDN over Named Data Networking and we implement and deploy it on our cluster as well. The resulting design solves those problems in IP network. It provides completely decentralized systems and simplifies system architecture. It also improves the weak-connectivity phenomenon and decreases the broadcast overhead.
The flow of information among people in today's world is essential. People need to exchange data, but they also need to store larger chunks of data for future retrieval. Various business schemes have grown by feeding themselves on these assumptions. Some of them provide the needed infrastructure, such as, cables or wireless base stations in case of GSM/LTE networks, while others provide complementary storage capabilities (cloud storage services). In this paper, we introduce a Fully Distributed GRIDNET protocol (FD-GRIDNET). It facilitates a solution to a problem of motivating users to intercede in a data exchange. MANET/DTN networks were envisioned as a target environment, however we do not restrain our protocol by design only to such. FD-GRIDNET is the first fully distributed data exchange protocol, which rewards intermediaries with a cryptocurrency, one created on behalf of the described communication system itself. It constitutes a communication system with a closed economy cycle, where acting as a router earns cryptocurrency, which in turn can be used for one's own needs, such as, but not limited to - data transmission. Indeed, FD-GRIDNET can be said to facilitate a cryptocurrency of its own. It builds upon a proof-of-work concept, but introduces elements of proof-of-stake as well.
Dimitris Chatzopoulos, Sujit Gujar, Boi Faltings, Pan Hui
The popularity of digital currencies, especially cryptocurrencies, has been continuously growing since the appearance of Bitcoin. Bitcoin is a peer-to-peer (P2P) cryptocurrency protocol enabling transactions between individuals without the need of a trusted authority. Its network is formed from resources contributed by individuals known as miners. Users of Bitcoin currency create transactions that are stored in a specialised data structure called a block chain. Bitcoin's security lies in a proof-of-work scheme, which requires high computational resources at the miners. These miners have to be synchronised with any update in the network, which produces high data traffic rates. Despite advances in mobile technology, no cryptocurrencies have been proposed for mobile devices. This is largely due to the lower processing capabilities of mobile devices when compared with conventional computers and the poorer Internet connectivity to that of the wired networking. In this work, we propose LocalCoin, an alternative cryptocurrency that requires minimal computational resources, produces low data traffic and works with off-the-shelf mobile devices. LocalCoin replaces the computational hardness that is at the root of Bitcoin's security with the social hardness of ensuring that all witnesses to a transaction are colluders. It is based on opportunistic networking rather than relying on infrastructure and incorporates characteristics of mobile networks such as users' locations and their coverage radius in order to employ an alternative proof-of-work scheme. Localcoin features (i) a lightweight proof-of-work scheme and (ii) a distributed block chain.
Mobile Ad hoc network (MANET) is an autonomous system of mobile hosts (nodes) connected by wireless link forming a temporary network without the aid of any established infrastructure or centralized administration. Typical applications of MANETs are: emergency and rescue operations, disaster relief efforts, military operations and exploration mission where cellular infrastructure is unavailable. The main problem of mobile ad hoc networks is to design routing protocols allowing for communication between the hosts. The dynamic nature of ad hoc networks makes this problem especially challenging. Communication in MANET is multi-hop due to limited transmission range; this decentralized operation relies on the cooperative participations of all nodes. MANETs are considered as complex system characterized by high dynamic topology, local interactions, auto-organization and emergence. Modeling and simulation are very important in the design and development of distributed interacting system because of their particular stochastic nature. This article seeks to use agent-based tools for modeling ad hoc network. We focus on Netlogo, an important tool in the modeling and simulation domain of complex system. We have successfully implemented distributed Dijkstra's shortest path algorithm to solve the routing problem. Obtained Results show the quick convergence of Dijkstra's Algorithm to shortest paths relating a source node with all accessible destinations.
Vehicular communication and networking for intelligent transportation systems are emerging concept which allows forwarding of traffic information. Road traffic crashes are one of the largest problems being faced. VANET's are self-organized networks in which vehicles communicate with each other without the presence of any priori infrastructure. The proposed scheme aims to develop applications related to vehicular safety by providing information related to road and traffic. Vehicles share the surrounding information with each other. In this paper we include the development of self-managed VANET's that does not require the deployment of infrastructure with detection and warning about abnormal traffic condition by the secure routing of vehicles. Initially the vehicle registration is done using the public key generated by RSA algorithm. Then the verification of the vehicles is done using Zero Knowledge Proof algorithm and the attackers are also detected and eliminated from the network.
Ubiquitous sensing enabled by Wireless Sensor Network (WSN) technologies cuts\nacross many areas of modern day living. This offers the ability to measure,\ninfer and understand environmental indicators, from delicate ecologies and\nnatural resources to urban environments. The proliferation of these devices in\na communicating-actuating network creates the Internet of Things (IoT),\nwherein, sensors and actuators blend seamlessly with the environment around us,\nand the information is shared across platforms in order to develop a common\noperating picture (COP). Fuelled by the recent adaptation of a variety of\nenabling device technologies such as RFID tags and readers, near field\ncommunication (NFC) devices and embedded sensor and actuator nodes, the IoT has\nstepped out of its infancy and is the the next revolutionary technology in\ntransforming the Internet into a fully integrated Future Internet. As we move\nfrom www (static pages web) to web2 (social networking web) to web3 (ubiquitous\ncomputing web), the need for data-on-demand using sophisticated intuitive\nqueries increases significantly. This paper presents a cloud centric vision for\nworldwide implementation of Internet of Things. The key enabling technologies\nand application domains that are likely to drive IoT research in the near\nfuture are discussed. A cloud implementation using Aneka, which is based on\ninteraction of private and public clouds is presented. We conclude our IoT\nvision by expanding on the need for convergence of WSN, the Internet and\ndistributed computing directed at technological research community.\n