论文标题

使用羽毛灯链基础架构保护物联网传感器数据和固件的完整性

Protecting the Integrity of IoT Sensor Data and Firmware With A Feather-Light Blockchain Infrastructure

论文作者

Reijsbergen, Daniel, Maw, Aung, Venugopalan, Sarad, Yang, Dianshi, Dinh, Tien Tuan Anh, Zhou, Jianying

论文摘要

智能城市部署了大量传感器并从中收集大量数据。例如,高级计量基础架构(AMIS)由收集有关公用事业(例如电力和水)的用法数据组成,是智能城市中的重要组成部分。在典型的传感器网络中,测量设备通过计算机网络连接,从而使它们暴露于网络攻击。此外,数据在操作员的服务器中进行了集中管理,使其容易受到内幕威胁的影响。 我们的目标是保护大规模传感器网络收集的数据的完整性以及测量设备中的固件免受网络攻击和内部威胁。为此,我们首先开发了针对数据和固件完整性的攻击的全面威胁模型,该模型可以针对传感器网络操作中的任何利益相关者。接下来,我们使用威胁模型来分析现有的防御机制,包括签名检查,远程固件证明,异常检测和基于区块链的安全日志。但是,受信任的计算基础的大尺寸和缺乏可扩展性限制了这些现有机制的适用性。我们提出了羽毛光链基础设施(FLBI)框架来解决这些局限性。我们的框架利用了两层体系结构和加密阈值签名链来支持大容量设备的大型网络,例如仪表和数据聚合器。我们已经在HyperLeDger结构和私人以太坊区块链平台上完全实现了FLBI的端到端功能。我们的实验表明,FLBI能够支持数百万端设备。

Smart cities deploy large numbers of sensors and collect a tremendous amount of data from them. For example, Advanced Metering Infrastructures (AMIs), which consist of physical meters that collect usage data about public utilities such as power and water, are an important building block in a smart city. In a typical sensor network, the measurement devices are connected through a computer network, which exposes them to cyber attacks. Furthermore, the data is centrally managed at the operator's servers, making it vulnerable to insider threats. Our goal is to protect the integrity of data collected by large-scale sensor networks and the firmware in measurement devices from cyber attacks and insider threats. To this end, we first develop a comprehensive threat model for attacks against data and firmware integrity, which can target any of the stakeholders in the operation of the sensor network. Next, we use our threat model to analyze existing defense mechanisms, including signature checks, remote firmware attestation, anomaly detection, and blockchain-based secure logs. However, the large size of the Trusted Computing Base and a lack of scalability limit the applicability of these existing mechanisms. We propose the Feather-Light Blockchain Infrastructure (FLBI) framework to address these limitations. Our framework leverages a two-layer architecture and cryptographic threshold signature chains to support large networks of low-capacity devices such as meters and data aggregators. We have fully implemented the FLBI's end-to-end functionality on the Hyperledger Fabric and private Ethereum blockchain platforms. Our experiments show that the FLBI is able to support millions of end devices.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源