A Hardware-Software Codesign Approach to Identity, Trust, and Resilience for IoT/CPS at Scale

A Hardware-Software Codesign Approach to Identity, Trust, and Resilience for IoT/CPS at Scale
复制标题

DOI:
10.1109/ithings/greencom/cpscom/smartdata.2019.00191
复制
发表时间:
2019-07
期刊:
2019 International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
影响因子:
--
通讯作者:
Farah I. Kandah;Joseph Cancelleri;D. Reising;Amani Altarawneh;A. Skjellum
Farah I. Kandah;Joseph Cancelleri;D. Reising;Amani Altarawneh;A. Skjellum
中科院分区:
其他
文献类型:
--
作者:
Farah I. Kandah;Joseph Cancelleri;D. Reising;Amani Altarawneh;A. Skjellum

文献摘要

相似文献

通信技术和物联网(IoT)的进步正在推动智慧城市的采用,旨在提高运营效率,改善服务质量和公民福利等潜在利益。必须确保通信的隐私性、可靠性和完整性,以便在收到可采取行动的信息后采取适当、安全、准确和及时的行动。在这项工作中,我们提出了一个多层的方法,包括一个认证和信任建设/分布框架,旨在确保系统中交换的信息的安全性和有效性。区块链协议和射频独特原生属性(RF-DNA)联合收割机结合起来,提供了一个硬件-软件协同设计的系统,用于增强设备身份和整体系统可信度。我们的威胁模型考虑了伪造、突破欺诈和其他实体对一个实体的恶意中伤。实体信任(例如,物联网设备(IoT设备)的安全性取决于参与的质量和水平、消息的质量、系统中给定实体的生命周期以及该实体发送的已知“坏”(非共识)消息的数量。基于这种信任方法,我们能够根据实时和过去的行为向上和向下调整信任,为其他参与者提供信任值,以判断来自给定实体的信息以及与给定实体的交互。从而,这种方法减少了不良或拜占庭行为者操纵物联网系统的可能性。
Advancement in communication technologies and the Internet of Things (IoT) is driving adoption in smart cities that aims to increase operational efficiency and improve the quality of services and citizen welfare, among other potential benefits. The privacy, reliability, and integrity of communications must be ensured so that actions can be appropriate, safe, accurate, and implemented promptly after receiving actionable information. In this work, we present a multi-tier methodology consisting of an authentication and trust-building/distribution framework designed to ensure the safety and validity of the information exchanged in the system. Blockchain protocols and Radio Frequency-Distinct Native Attributes (RF-DNA) combine to provide a hardware-software codesigned system for enhanced device identity and overall system trustworthiness. Our threat model accounts for counterfeiting, breakout fraud, and bad mouthing of one entity by others. Entity trust (e.g., IoT devices) depends on quality and level of participation, quality of messages, lifetime of a given entity in the system, and the number of known "bad" (non-consensus) messages sent by that entity. Based on this approach to trust, we are able to adjust trust upward and downward as a function of real-time and past behavior, providing other participants with a trust value upon which to judge information from and interactions with the given entity. This approach thereby reduces the potential for manipulation of an IoT system by a bad or byzantine actor.