The Data Sovereignty paradigm gives users full control of their digital data, allowing them to choose which parts of the data they want to share and to whom. In the case of IoT devices, a secure mechanism is necessary to verify the identity associated with the device, as typically, no trusted third-party authority can verify the identity of the device’s owner. Other important issues in this context concern data provenance, efficient storing and processing while maintaining privacy and security. Physically Unclonable Functions (PUFs) could be helpful in these tasks, as they can generate secure keys or fingerprints inherently and uniquely identify and authenticate physical items or physical objects in which they are embedded. Therefore, to better overcome the above-cited issues, a framework for handling the identities associated with IoT devices, based on the PUF technology to assess their identity and a blockchain network to verify the associated transactions, is proposed in this work. More into detail, our system permits the registration and verification in real-time of the identity associated with an IoT device in a self-sovereign fashion and the traceability of the accesses and processing of the data. Indeed, the identity is checked by using the PUF associated with an IoT device, and the blockchain layer ensures the security and privacy of access to the data in a decentralised way.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Self-Sovereign Identification of IoT Devices by Using Physically Unclonable Functions and Blockchain

  • Gianluigi Folino,
  • Agostino Forestiero,
  • Giuseppe Papuzzo

摘要

The Data Sovereignty paradigm gives users full control of their digital data, allowing them to choose which parts of the data they want to share and to whom. In the case of IoT devices, a secure mechanism is necessary to verify the identity associated with the device, as typically, no trusted third-party authority can verify the identity of the device’s owner. Other important issues in this context concern data provenance, efficient storing and processing while maintaining privacy and security. Physically Unclonable Functions (PUFs) could be helpful in these tasks, as they can generate secure keys or fingerprints inherently and uniquely identify and authenticate physical items or physical objects in which they are embedded. Therefore, to better overcome the above-cited issues, a framework for handling the identities associated with IoT devices, based on the PUF technology to assess their identity and a blockchain network to verify the associated transactions, is proposed in this work. More into detail, our system permits the registration and verification in real-time of the identity associated with an IoT device in a self-sovereign fashion and the traceability of the accesses and processing of the data. Indeed, the identity is checked by using the PUF associated with an IoT device, and the blockchain layer ensures the security and privacy of access to the data in a decentralised way.