FOTB: a secure blockchain-based firmware update framework for IoT environment

被引:0
作者
Alexander Yohan
Nai-Wei Lo
机构
[1] National Taiwan University of Science and Technology,Department of Information Management
来源
International Journal of Information Security | 2020年 / 19卷
关键词
Internet of Things; Firmware update; Blockchain; Smart contract; ECDH;
D O I
暂无
中图分类号
学科分类号
摘要
Recently, numerous exploitations and attacks in IoT environment occurred all over the world. One of the major attacking channels is utilizing the firmware of IoT devices as the access interface to compromise the targeted IoT devices. Therefore, it is important for IoT device manufacturers to support secure and efficient firmware update functionality for sold or deployed IoT devices. In this paper, a secure and verifiable blockchain-based firmware update framework for IoT environment is proposed. The aims of the proposed framework are providing secure peer-to-peer verification mechanism on each new version of firmware released by corresponding device manufacturer and providing a reliable way to distribute the updated firmware to IoT devices in timely manner. Furthermore, the utilization of blockchain technology in the proposed framework ensures the integrity of firmware during its distribution through Internet. The proposed firmware update framework consists of four processes: creation of firmware update contract, creation of third-party firmware update contract, PUSH update mechanism and PULL update mechanism. Six corresponding protocols are derived to support the four processes. The evaluation on performance and security strength of the proposed firmware update framework is conducted. Based on the proofs of formal security analysis, the proposed framework supports mutual authentication and defends against major cyber attacks: firmware modification attack, impersonation attack, man-in-the-middle attack and replay attack.
引用
收藏
页码:257 / 278
页数:21
相关论文
共 50 条
[41]   Blockchain-Based Community Safety Security System with IoT Secure Devices [J].
Chen, Chin-Ling ;
Lim, Zi-Yi ;
Liao, Hsien-Chou .
SUSTAINABILITY, 2021, 13 (24)
[42]   Customized blockchain-based architecture for secure smart home for lightweight IoT [J].
Ammi, Meryem ;
Alarabi, Shatha ;
Benkhelifa, Elhadj .
INFORMATION PROCESSING & MANAGEMENT, 2021, 58 (03)
[43]   A Blockchain-based secure PHR data storage and sharing framework [J].
Ghani, Ayoub ;
Zinedine, Ahmed ;
El Mohajir, Mohammed .
2020 6TH IEEE CONGRESS ON INFORMATION SCIENCE AND TECHNOLOGY (IEEE CIST'20), 2020, :162-166
[44]   A Secure and Verifiable Blockchain-Based Framework for Personal Data Validation [J].
Yu, Junyan ;
Li, Ximing ;
Guo, Yubin .
COMPUTERS, 2024, 13 (09)
[45]   A Blockchain-Based Trustable Framework for IoT Data Storage and Access [J].
Li, Jiangfeng ;
Hu, Shili ;
Shi, Yang ;
Zhang, Chenxi .
BLOCKCHAIN AND TRUSTWORTHY SYSTEMS, BLOCKSYS 2019, 2020, 1156 :336-349
[46]   Blockchain-based IoT: An Overview [J].
Raza, Muhammad Raheel ;
Varol, Asaf ;
Hussain, Walayat .
9TH INTERNATIONAL SYMPOSIUM ON DIGITAL FORENSICS AND SECURITY (ISDFS'21), 2021,
[47]   Decentralized Blockchain-Based IoT Data Marketplaces [J].
Christidis, John ;
Karkazis, Panagiotis A. ;
Papadopoulos, Pericles ;
Leligou, Helen C. .
JOURNAL OF SENSOR AND ACTUATOR NETWORKS, 2022, 11 (03)
[48]   Schloss: Blockchain-Based System Architecture for Secure Industrial IoT [J].
Ghajar, Fatemeh Ghovanlooy ;
Sikora, Axel ;
Welte, Dominik .
ELECTRONICS, 2022, 11 (10)
[49]   BlockDeepNet: A Blockchain-Based Secure Deep Learning for IoT Network [J].
Rathore, Shailendra ;
Pan, Yi ;
Park, Jong Hyuk .
SUSTAINABILITY, 2019, 11 (14)
[50]   Blockchain-Based Secure Storage Management with Edge Computing for IoT [J].
Nyamtiga, Baraka William ;
Sicato, Jose Costa Sapalo ;
Rathore, Shailendra ;
Sung, Yunsick ;
Park, Jong Hyuk .
ELECTRONICS, 2019, 8 (08)