LegIoT: Ledgered Trust Management Platform for IoT

被引:6
作者
Neureither, Jens [1 ]
Dmitrienko, Alexandra [2 ]
Koisser, David [1 ]
Brasser, Ferdinand [1 ]
Sadeghi, Ahmad-Reza [1 ]
机构
[1] Tech Univ Darmstadt, Darmstadt, Germany
[2] Univ Wurzburg, Wurzburg, Germany
来源
COMPUTER SECURITY - ESORICS 2020, PT I | 2020年 / 12308卷
关键词
Trust management; Blockchain; Remote attestation; SECURITY;
D O I
10.1007/978-3-030-58951-6_19
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
We investigate and address the currently unsolved problem of trust establishment in large-scale Internet of Things (IoT) networks where heterogeneous devices and mutually mistrusting stakeholders are involved. We design, prototype and evaluate LegIoT, a novel, probabilistic trust management system that enables secure, dynamic and flexible (yet inexpensive) trust relationships in large IoT networks. The core component of LegIoT is a novel graph-based scheme that allows network devices (graph nodes) to re-use the already existing trust associations (graph edges) very efficiently; thus, significantly reducing the number of individually conducted trust assessments. Since no central trusted third party exists, LegIoT leverages Distributed Ledger Technology (DLT) to create and manage the trust relation graph in a decentralized manner. The trust assessment among devices can be instantiated by any appropriate assessment technique, for which we focus on remote attestation (integrity verification) in this paper. We prototyped LegIoT for Hyperledger Sawtooth and demonstrated through evaluation that the number of trust assessments in the network can be significantly reduced - e.g., by a factor of 20 for a network of 400 nodes and factor 5 for 1000 nodes.
引用
收藏
页码:377 / 396
页数:20
相关论文
共 53 条
  • [1] Abdul-Rahman A., 1998, New Security Paradigms Workshop. Proceedings, P48
  • [2] Abera T., 2016, ACM DAC
  • [3] DIAT: Data Integrity Attestation for Resilient Collaboration of Autonomous Systems
    Abera, Tigist
    Bahmani, Raad
    Brasser, Ferdinand
    Ibrahim, Ahmad
    Sadeghi, Ahmad-Reza
    Schunter, Matthias
    [J]. 26TH ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2019), 2019,
  • [4] C-FLAT: Control-Flow Attestation for Embedded Systems Software
    Abera, Tigist
    Asokan, N.
    Davi, Lucas
    Ekberg, Jan-Erik
    Nyman, Thomas
    Paverd, Andrew
    Sadeghi, Ahmad-Reza
    Tsudik, Gene
    [J]. CCS'16: PROCEEDINGS OF THE 2016 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2016, : 743 - 754
  • [5] Aberer K., 2001, ACM CIKM
  • [6] Towards Blockchain-Based Collaborative Intrusion Detection Systems
    Alexopoulos, Nikolaos
    Vasilomanolakis, Emmanouil
    Ivanko, Natalia Reka
    Muehlhaeuser, Max
    [J]. CRITICAL INFORMATION INFRASTRUCTURES SECURITY (CRITIS 2017), 2018, 10707 : 107 - 118
  • [7] Beyond the Hype: On Using Blockchains in Trust Management for Authentication
    Alexopoulos, Nikolaos
    Daubert, Joerg
    Muehlhaeuser, Max
    Habib, Sheikh Mahbub
    [J]. 2017 16TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS / 11TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING / 14TH IEEE INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS, 2017, : 546 - 553
  • [8] Alves T., 2004, TRUSTZONE INTEGRATED
  • [9] SANA: Secure and Scalable Aggregate Network Attestation
    Ambrosin, Moreno
    Conti, Mauro
    Ibrahim, Ahmad
    Neven, Gregory
    Sadeghi, Ahmad-Reza
    Schunter, Matthias
    [J]. CCS'16: PROCEEDINGS OF THE 2016 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2016, : 731 - 742
  • [10] Ammar M, 2018, 2018 IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING (DSC), P38