Engin Zeydan, Josep Mangues, Şuayb S. Arslan, Yekta Türk
Self-sovereign identity (SSI) has emerged lately as an identity and access management framework typically implemented based on distributed ledger technology (DLT), allowing device owners to administer and control their own data. In this article, a blockchain (BCN)-based SSI system has been developed as a new identity plane to enable routing device owners in autonomous systems (ASs) to have greater control over inter-domain networks (IDNs), potentially across multiple paths that comply with routing device-defined preferences. The proposed system provides identity management, authentication, and transparent information about routers, attested by ASs, while maintaining the privacy of sensitive network details. Device-level information and preferences are protected by BCN-based SSI. We used a GNS3 network emulation test bed and Hyperledger Indy distributed identity management system to test the proposed solution's AS convergence time and credential operation time, respectively. Experiment results demonstrate that when the proposed routing system was used in combination with the BCN-based SSI credential management platform, the convergence time for the inter-AS and intra-AS systems became longer as the number of routers increased, whereas the credential operations had shorter processing times.
Abstract SDN revolutionises network management by providing a centralised controller that enables flexible and effortless configuration of networks. However, this flexibility also leads to a vulnerability that enables the adversary to trick the security system into allowing the installation of unauthorised flow rules in the switches. Blockchain provides us with a way to protect against malicious tampering with flow rules by storing them in the distributed ledger. In this work, we propose FTISCON, a mechanism to preserve the integrity of the OpenFlow flow table that utilizes blockchain technology. We employ the Ethereum Private Blockchain to implement the proof-of-concept and conduct a comparative analysis of the proposed scheme and existing related schemes, evaluating their performance in terms of delay, computation time, transaction cost, and detection rate. The proposed work is found to perform better in each of these. The study results suggest that the proposed approach offers a practical and efficient remedy to prevent flow modification attacks within SDN networks.
Daniel Ayepah-Mensah, Guolin Sun, Gordon Owusu Boateng, Stephen Anokye · 5 authors
Radio Access Network (RAN) slicing enables resource sharing among multiple tenants and is an essential feature for next-generation mobile networks. Usually, a centralized controller aggregates available resource pools from multiple tenants to increase spectrum availability. In dynamic resource allocation, a tenant could behave strategically by adjusting its preferences based on perceived conditions to maximize its utility. Slice tenants may lie about the resources needed to gain greater utility. Such behavior could lead to poor resource utilization due to excess resources acquired by lying tenants and resource shortages because slice tenants choose not to purchase high-priced resources to save costs. Furthermore, in a scenario with many slice tenants, the centralized controller can become overwhelmed by the number of requests. This, in turn, can lead to slower response times and higher latency, resulting in poor resource utilization and QoS performance of slice tenants. Therefore, this paper proposes a peer-to-peer (P2P) approach to resource trading, where slice tenants communicate directly instead of relying on a centralized orchestrator. This design is motivated by the need for slice tenants to collaborate effectively. We model the interaction between tenants in a Stackelberg multi-leader and multi-follower game and solve the game with multi-agent deep reinforcement learning with an incentive-reward model to achieve the Stackelberg equilibrium. Furthermore, we propose a decentralized resource trading framework by integrating blockchain technology and federated deep reinforcement learning, enabling network tenants to perform inter-slice resource sharing securely. The simulation results show that the proposed mechanism has significant performance improvements over existing implementations.
With fast evolution of computer and networking technologies, more and more systems and applications are based on interconnecting different devices and systems to form the Internet-of-Something: things, vehicles, and even bodies. Many among those systems require permanent, distributed data storage facilities which are being increasingly implemented using replicated, tamper-proof blockchain ledgers. Most, if not all, of those problems are exacerbated, rather than solved, by blockchain technology. In addition, the use of blockchain brings many challenges that include efficient and reliable data distribution; efficient and collusion-proof consensus mechanisms; efficient coverage of wide geographical areas; and a plethora of existing security- and privacy-related constraints on the networks.
Tuğçe Bilen, Müge Erel-Özçevı̇k, Elif Bozkaya, Yusuf Özçevik
Providing Internet access above-the-clouds has made the development of aircraft networks more important than ever. However, new and emerging Internet applications have increased the challenge of providing seamless and real-time connectivity with traditional routing algorithms for aircraft networks in the upcoming 6G due to the highly-dynamic and unstable topology. Moreover, traditional routing mechanisms are prone to routing attacks, which can increase the packet transfer delay. To this end, in this paper, we present Merkle Tree-based secure routing mechanism with the assistance of digital twin. First, we construct a blockchain-based system with decentralized and distributed characteristics for the clustering of aircraft. Then, we propose a novel Merkle-Tree-based secure routing algorithm by combining real-time and historical data with digital twins. A Merkle tree is a data structure that contains gathered data from sender and receiver aircraft. Merkle root in an aircraft cluster forwards the gathered data to a satellite or a ground station in a secure manner. Accordingly, Secure Hash Algorithm (SHA)-256 is used for data integrity and a tree-based structure is built to reduce the number of transactions so that it is aimed to prevent malicious aircraft attacks. Finally, we show through a simulation environment, how blockchain processing time and the number of transactions can be reduced by meeting the strict Quality of Service (QoS) requirements for aircraft networks in 6G. Furthermore, we also use Proof of Stake (PoS) to reduce the computational time for mining a block as well as reducing the packet delivery ratio and packet transfer delay.
To provide customized and high-quality network services under limited network resources, the 5G introduces the network slicing technology that divides physical networks into several logically independent virtual networks, improving the performance of network utilization. The slice management should satisfy the chief concerns of network operators and slice tenants who are the two most important participants, i.e., slice allocation for operators and Service Level Agreement (SLA) guarantee for tenants. However, for slice allocation, traditional centralized schemes cannot well support multi-operator slicing due to the lack of trust. And for SLA guarantee, existing solutions only provide global SLA based on game theory but cannot handle each dispute between operators and tenants. To solve the problems, we propose a blockchain-based network slice management framework consisting of a slice committee and three protocols: slice, audit, and dispute. With the help of the decentralization and reliability of blockchain, the proposed scheme achieves collaborative slice management among multiple operators with SLA guarantee. Through security and performance analysis, we prove that the proposed scheme can defend against possible dishonest behaviors of entities in the system, and is practical in terms of performance.
Yanbo Song, Tao Feng, Chungang Yang, Xinru Mi · 6 authors
Software-defined network (SDN) is characterized by its programmability, flexibility, and the separation of control and data planes. However, SDN still have many challenges, particularly concerning the security of network information synchronization and network element registration. Blockchain and intent-driven networks are recent technologies to establish secure and intelligent SDN. This article investigates the blockchain-based architecture and intent-driven mechanisms to implement intent-driven security software-defined networks (IS2N). Specifically, we propose a novel four-layer architecture of the IS2N with security capabilities. We integrate an intent-driven security management mechanism in the IS2N to achieve automate network security management. Finally, we develop an IS2N platform with blockchain middle-layer to achieve security capabilities and security store network-level snapshots, such as device registration and OpenFlow messages. Our simulations show that IS2N is more flexible than conventional strategies at resolving problems during network operations and has a minimal effect on the SDN.
To address the problems that current studies for enhancing network accountability based on IPv6 addresses do not support cross-Autonomous Systems (AS) or restrict threatener behaviors, a distributed IPv6 Address Traceback and Threatener Restriction Mechanism (ATTRM6) based on smart contract is proposed. Tracing servers of each AS form a blockchain and invoke smart contract functions to store address information of different ASes on the blockchain. When IPv6 address traceback is needed across ASes, the traceback server of a specific AS reads addresses information stored on the blockchain to identify the threatener. Considering the restriction scheme for threatener associated with IPv6 addresses, and proposing a Punishment-Forgiveness Policy (PFP) to dynamically adjust the reputation of threatener, and store restricted threatener and their reputation on the blockchain, thus providing data support to each AS to take restriction measures. Compared with information sharing based on a centralized database, the ATTRM6 mechanism can accomplish more reliable sharing. Experimental results show that the ATTRM6 mechanism has low overhead and can effectively perform IPv6 address traceback and threatener restriction.
The education management model refers to the system and processes that colleges and universities use to manage and oversee their academic programs and operations. However, with the advent of digital technologies, there has been a growing trend towards the Internet+ college education management model, which integrates digital technologies into all aspects of college education management. This model includes the use of online learning platforms and tools, such as learning management systems (LMS), to deliver courses and manage student progress. It also includes the use of digital technologies for administrative tasks such as admissions, enrolment, and financial aid. However, the educational management model is subjected to the challenge of security for educational data management. Hence, this paper constructed a secure framework model of the Ethereum SDN Cloud Architecture (ESDNarc). The ESDNarc model uses the Software-defined Network (SDN) for the decentralized management of the network, secure transactions, and improved efficiency. The ESDNarch model incorporates the SDN with the cryptography scheme the secure the data. The constructed model uses the double-hashing Elliptical Curve Cryptography (DHECC) for the data stored in the Ethereum blockchain. The performance of the constructed model is evaluated with the KDD data set. Simulation analysis stated that ESDNarch significantly increases the data security in the cloud model for the attacks in the network.
Engin Zeydan, Jorge Baranda, Josep Mangues‐Bafalluy, Yekta Türk
In the coming years, blockchain technologies will be used in a variety of industries, including telecommunications. In this article, due to strict governance of telecommunication infrastructure, we propose a blockchain supported architecture, based on a permissioned distributed ledger (PDL) scheme, for a network management and orchestration platform. The main goal is to create a trusted environment for multiple-stakeholders, such as Cloud Service Providers (CSPs), a Mobile Network Operator (MNO), Vertical Service Providers (SPs), Legal and Regulation Authorities, and Responsible Ministry so that the life cycle of automated vertical network services (e.g., instantiation, scaling, termination, and migration/reallocation) can be managed securely and transparently in a multi-cloud and multi-domain environment. The proposed approach is also validated with an experimental Industry 4.0 scenario using the Quorum blockchain network (BCN) to measure various performance metrics (e.g., number of transactions and blocks, and time to write) of various service orchestrator (SO)-related instantiation metrics. At the end of the article, we present the main discussions on the evaluation results and existing standardization efforts for the convergence of BCN, Management and Orchestration (MANO), and network services for a given telecommunication infrastructure.
The Metaverse is gaining attention among academics as maturing technologies empower the promises and envisagements of a multi-purpose, integrated virtual environment. An interactive and immersive socialization experience between people is one of the promises of the Metaverse. In spite of the rapid advancements in current technologies, the computation required for a smooth, seamless and immersive socialization experience in the Metaverse is overbearing, and the accumulated user experience is essential to be considered. The computation burden calls for computation offloading, where the integration of virtual and physical world scenes is offloaded to an edge server. This paper introduces a novel Quality-of-Service (QoS) model for the accumulated experience in multi-user socialization on a multichannel wireless network. This QoS model utilizes deep reinforcement learning approaches to find the near-optimal channel resource allocation. Comprehensive experiments demonstrate that the adoption of the QoS model enhances the overall socialization experience.
Fengyang Guo, Xun Xiao, Artur Hecker, Schahram Dustdar
IOTA is a recent distributed ledger technology that relies on Directed Acyclic Graph (DAG) for its ledger organization. To improve IOTA mechanisms, the state of the art methodology employs graph analysis and, for that, heavily relies on synthetic graph generation. Herein, the most popular generation method simulates IOTA protocol execution. Although this method produces realistic IOTA ledgers, it requires too much memory and time due to repeated random walks on the DAG. In this paper, we propose an alternative Graph Generation and Refinement (GraGR) algorithm designed to generate realistic IOTA ledgers while strongly relaxing memory and timing constraints. The evaluations show that, compared to the state of the art, GraGR can generate a ledger with the same properties with only half of memory and up to 10 times faster.
Network resource sharing needs more flexible and efficient for diversified services with the rapid evolution of 5G network and IoT technology, the current sharing cannot support highly decentralized resource collaboration and sharing. In this paper, we proposed a solution to establish a sharing ecosystem by DLT, and research the relationship and activities of roles in this ecosystem. Based on these, we research the general framwork of network resource sharing based on DLT and give the scenarios and application by using it.
Ronan D. Mendonça, Ericksulino Moura, Glauber Dias Gonçalves, Alex Borges Vieira · 5 authors
Blockchain é uma tecnologia que amplia a segurança nas relações entre organizações via o registro auditável e descentralizado de transações. Notadamente, há uma crescente atenção por aplicações que utilizam essa tecnologia. Entretanto, a eficiência e custo de tais aplicações pode ser influenciada pela rede blockchain utilizada. De fato, a escolha da rede impacta nas qualidades não funcionais das aplicações, em especial desempenho (e.g., em relação a taxa de transações efetivadas) e custo. Este artigo investiga o impacto no desempenho e custo da infraestrutura de rede blockchain para lidar com uma determinada carga de trabalho. Primeiramente, este artigo propõe um modelo de arquitetura de rede comum entre a rede pública Ethereum e permissionada Hyperledger Fabric com base em recursos por nó par da rede blockchain. A seguir, avalia-se o custo por transação para aplicações nessa arquitetura considerando latências e custos mínimos para os pares da rede, em função da carga de trabalho. Os experimentos realizados nas plataformas mais populares para redes blockchain, Ethereum e Hyperledger Fabric, mostram os limites de escalabilidade dessas plataformas e os seus compromissos entre custo e desempenho no projeto de aplicações baseadas em blockchain.
Physical terminals provide network services to upper-layer applications, but their limited memory and processing power make it challenging to perform security updates and patches, leaving them vulnerable to known security threats. Attackers can exploit these weaknesses to control the terminals and attack the network. To restrict unauthorized access to the network and its resources, appropriate access control mechanisms are necessary. In this paper, we propose a fine-grained access control method based on smart contracts (FACSC) for terminals in software-defined networking (SDN). FACSC utilizes the attribute-based access control (ABAC) model to achieve fine-grained control over terminal access networks. To ensure the security and reliability of access control policies and terminal-related attribute information, we utilize smart contract technology to implement the ABAC model. Furthermore, we leverage the programming protocol-independent packet processor (P4) to filter and forward packets in the data plane based on the packet option field, enabling rapid terminal access. Experimental results show that our proposed method achieves fine-grained secure authentication of terminals in SDN networks with a low authentication processing overhead.
The demand for the Internet of Everything has slowed down network routing efficiency. Traditional routing policies rely on manual configuration, which has limitations and adversely affects network performance. In this paper, we propose an Internet of Things (IoT) Intelligent Edge Network Routing (ENIR) architecture. ENIR uses deep reinforcement learning (DRL) to simulate human learning of empirical knowledge and an intelligent routing closed-loop control mechanism for real-time interaction with the network environment. According to the network demand and environmental conditions, the method can dynamically adjust network resources and perform intelligent routing optimization. It uses blockchain technology to share network knowledge and global optimization of network routing. The intelligent routing method uses the deep deterministic policy gradient (DDPG) algorithm. Our simulation results show that ENIR provides significantly better link utilization and transmission delay performance than various routing methods (e.g., open shortest path first, routing based on Q-learning and DRL-based control framework for traffic engineering).
Jaime Fúster de la Fuente, Álvaro Pendás-Recondo, Leon Wong, Paul Harvey
Operation and management of telecommunication networks are increasingly difficult with the demands and behaviors of users exceeding the capacity of network engineers to keep pace. This has led to increased automation of the network, enabled by various forms of intelligent software. One such proposal from the ITU-T Focus Group on Autonomous Networks (standardization group) is an architecture to achieve self-driven automation (i.e. autonomy) of network operation, whereby technology from different operators and third parties is self-assembled and deployed in production networks. This raises questions and challenges regarding transparency, auditability, and trust while maintaining interoperability.This work presents an initial study of a distributed and decentralized marketplace to bring transparent and auditable trust to the proposed architecture without sacrificing interoperable functionality. We demonstrated this by our proof of concept implementation of both the proposed architecture and marketplace based on the combination of Ethereum and IPFS.
Luis Velasco, Marc Ruiz, Pol González, Vincent Lefèbvre · 6 authors
Multi-agent systems (MAS) have been proposed as an alternative to traditional centralized control for near real-time service control. However, MAS also show a distributed attack surface. To overcome their software higher security exposure, we combine a set of scalable techniques fostering enhanced security applied on individual agents and their communications. Specifically, the proposed solution combines: <em>i</em>) binary hardening with secure execution monitoring; <em>ii</em>) distributed ledger technologies for non-real-time MAS management; and <em>iii</em>) VXLAN and encrypted communications for near real-time MAS operation. The solution is designed not only to provide strong security to the MAS, but also to minimize any functional overhead.
In the industrial Internet of things (IIoT), various applications generate a large number of interactions and are vulnerable to various attacks, which are difficult to be monitored in a sophisticated way by traditional network architectures. Therefore, deploying software-defined network (SDN) in IIoT is essential to defend against various attacks. However, SDN has a draw-back: there is a security problem of distributed denial-of-service (DDoS) attacks at the control layer. This paper proposes an effective solution: DDoS detection within the domain using tri-entropy in information theory. The detected attacks are then uploaded to a smart contract in the blockchain, so that the attacks can be quickly cut off even if the same attack occurs in different domains. Experimental validation was conducted under different attack strengths and multiple identical attacks, and the results show that the method has better detection ability under different attack strengths and can quickly block the same attacks.
Farhana Javed, Josep Mangues‐Bafalluy, Engin Zeydan
This poster presents a use case for smart contract-based inter-provider agreements and Service Level Agreement (SLA) monitoring for 6G networks. We use chainlink oracle and InterPlanetary File System (IPFS) to monitor SLA data logs. We also provide experimental evaluations of two approaches: raw data log access in IPFS and chainlink-based log access. To understand the performance and feasibility of the proposed approaches on a public blockchain, the proposed framework is deployed on the Ethereum and Polygon testnets to measure the cost and latency for both approaches. We measure the latency as well as the total cost for comparison purposes. The maximum cost observed for the first approach is ≈ 1.4 USD, and the maximum latency observed with the first approach is ≈4 seconds in the Polygon testnet and 12 ~ 14 seconds in the Ethereum testnet. However, the second approach's latency is 30 ~ 60 seconds.
To mine a blockchain on IP Networks, one must do several tasks related to chain management, rule optimization, verification, and hash generation design. Various consensus model subsets may benefit from the various blockchain mining techniques proposed by researchers. Most of these techniques, however, are rather complicated, which slows down the mining process for large-scale blockchains. Overly simplistic models that include unnecessary redundancies are inefficient and have little practical use. To solve these issues and boost blockchain mining efficiency in large-scale deployments, the authors of this paper propose creating a novel hybrid bioinspired approach. The proposed IP Network model is adaptable to almost all consensus procedures and may be easily combined with dynamic consensus models with few alterations. After collecting performance and context-specific data from the underlying blockchains, the technique uses Genetic Algorithm (GA) that distributes these range sets among miner nodes that support trust, allowing for high-performance mining while maintaining a high degree of trust under actual application situations. The model was tested against Proof-of-Stake (PoS), Proof-of-Work (PoW), Proof-of-Trust (PoT), and Practical Byzantine Fault Tolerance (PBFT) based consensus algorithms to ensure its effectiveness in real-world scenarios. Mining latency, energy consumption, and computational complexity were used as metrics against which this performance was measured. This analysis revealed that the proposed model has the potential to decrease mining latency by 4.5%, energy usage by 3.9%, and compute complexity by 4.1% across a variety of consensus mechanisms, making it suitable for a number of real-time applications.