In Search of a Scalable Distributed Security Framework for Future IoT Networks
In Search of a Scalable Distributed Security Framework for Future IoT Networks
批准号:
2117948
负责人:
金额:
$0.0万
依托单位:
依托单位国家:
英国
项目类别:
Studentship
财政年份:
2018
资助国家:
英国
项目状态:
已结题
起止时间:
2018 至 --
中文摘要
世界上越来越多的人和设备创造了对我们生活的“系统”的自动化和自我管理的需求。这包括个人系统(例如电子医疗记录、财务、智能家居)、供应和交付系统(例如亚马逊、应急响应、国家电网)、数据收集系统物联网(IoT)是使用互连设备来自动化信息收集,传统系统倾向于具有中央权威“集线器”,其调节其它节点之间的交换以便确保服务质量和安全性,但是集线器的速度和准确性限制了网络的可扩展性。其次,集线器形成单一故障点,这使得网络更容易受到恶意攻击。相比之下,分布式系统允许网络中的节点直接相互通信,并且缺少单个故障点。然而,在没有中央集线器的情况下,分布式网络需要分散的安全协议来促进正确的数据交换。在这个项目中,我们的目标是研究分布式安全框架,以便我们可以确定如何最好地为大规模分布式物联网网络提供可靠性。现有的文献在这个主题提出了各种方法来适应传统的安全协议在分布式网络中使用。然而,这些方法中的大多数仍然依赖于某种最低程度的集中化,因此仍然存在如何以完全分散的方法提供安全性的问题。文献中的一个想法是将区块链(BC)用于资源受限的物联网网络,因为BC是一个完全分散的安全框架。大多数新颖的方法假设网络中存在至少一个可信赖的实体,可以帮助BC处理,数据存储或生根,因为这些任务会给物联网设备带来很大的计算负担。然而,这违背了BC的分布式特性,并在系统中重新引入了单一故障点。作为回应,我们提出了一种新的完全轻量级的方法,其中一个节点集群可以在它们之间随机划分BC存储责任,但每个数据点仍然存储在网络中的多个节点上,从而保留了BC的分布式特性。这给出了有希望的结果,但提出了进一步的问题,当节点本质上不可信时该怎么办,为此我们转向信任推理。一个节点X对另一个节点Y的信任表示下一次X与Y通信时,Y将按照X期望的方式行事的概率。我们的方法来找到一个真正的分布式和可靠的安全框架开始调查广义的分布式网络,这样我们就可以使用统计分析来识别行为模式。这包括物联网设备连接的不稳定性、通信的速率和性质以及通信信道等其他错误因素。这使我们不仅可以准确地建模分布式物联网网络的行为,还可以更准确地预测恶意节点在网络中的行为。通过根据这些行为创建数学模型,我们的目标是设计一种分布式安全协议,该协议适当地考虑这些行为,并通过利用和调整BC和信任推理等分布式网络工具来做出响应。这项工作正在东芝研究欧洲有限公司的资助下完成。和EPSRC。该项目福尔斯属于EPSRC“ICT网络和分布式系统”研究领域的工程类别。
英文摘要
The growing number of people and devices in our world has created a need for automation and self-management of the "systems" by which we live. This includes personal systems (e.g. electronic medical records, finances, smart homes), supply and delivery systems (e.g. Amazon, emergency response, National Grid), the data collection systems (e.g. voting, animal population tracking, sensor networks), and so on. The Internet of Things (IoT) is the use of interconnected devices to automate the information collection, processing and response in each of these systems.Traditional systems tend to have a central authoritative "hub" which regulates exchanges between the other nodes in order to ensure quality of service and security, but the speed and accuracy of the hub limits the scalability of the network. Secondly, the hub forms a single point-of-failure, which makes the network more vulnerable to malicious attacks. In contrast, a distributed system allows nodes in a network to directly communicate with each other and lacks a single point-of-failure. However, in the absence of a central hub, distributed networks require decentralised security protocols to facilitate the exchange of correct data.In this project, we aim to investigate distributed security frameworks such that we may determine how best to provide reliability to large-scale distributed IoT networks. Existing literature on this topic presents various approaches to adapting traditional security protocols for use in distributed networks. However, the majority of these approaches continue to rely on some minimum level of centralisation and thus there still remains a question of how to provide security in a fully decentralised approach.One idea in literature is to adapt blockchain (BC) for use in resource-restricted IoT networks, as BC is a fully decentralised security framework. Most novel approaches assume the existence of at least one trustworthy entity in the network that can aid in BC processing, data storage or rooting as these are tasks which place a large computational burden on IoT devices. However, this goes against the distributed nature of BC and reintroduces a singular point-of-failure in the system. In response, we proposed a novel fully lightweight approach in which a cluster of nodes could divide the BC storage responsibility randomly between themselves but such that each data point is still stored at multiple nodes across the network, thus retaining the distributed nature of BC. This gave promising results but posed further questions regarding what to do when the nodes are not intrinsically trustworthy, for which we turn to trust inference. A node X's trust in another node Y represents the probability that the next time X communicates with Y, Y will behave as X expects it to. Our approach to finding a truly distributed and reliable security framework begins by investigating generalised distributed networks such that we can identify the behavioural patterns using statistical analysis. This includes the intermittency of IoT device connections, rate and nature of communications as well as other error factors such as the communication channel. This allows us to accurately model not only the behaviour of distributed IoT networks but also to make more accurate predictions about how malicious nodes would behave in the network. By creating mathematical models out of these behaviours, we aim to design a distributed security protocol that suitably takes these behaviours into account and responds by utilising and adapting distributed network tools such as BC and trust inference.This work is being completed with funding from Toshiba Research Europe Ltd. and the EPSRC. The project falls within the EPSRC 'ICT Networks & Distributed Systems' research area under the Engineering category.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
国内基金
海外基金
Scalable Learning and Optimization: High-dimensional Models and Online Decision-Making Strategies for Big Data Analysis
-
批准号:--
-
项目类别:合作创新研究团队
-
资助金额:--
-
批准年份:2024
-
负责人:姚韬
-
依托单位: