A Blockchain-based Distributed Access Control for IoT Erez Waisbard Joint work with Roberto Di Pietro, Xavier Salleras and Matteo Signorini SACMAT 2018
PKI is not suited for IoT Security Model The IoT model No central Trusted Authority Need Mutual authentication Multiple device vendors Multiple service providers Multiple Protocols Low power unprotected devices (no crypto processing, no secure storage, no patches) PKI is not suited for IoT
Trust in IoT Building reputation using Blockchain
Motivating use case
Trust in IoT Requirements Without requiring explicit bilateral agreements Without a central root of trust Support flexible business models i.e. not simply pre-paid
Bridging Island of Trust
Offering services Publishing the Terms of Use
Distributed Reputation System The service provider makes the decision
Bitcoin & Blockchain [October 2008]
A Secure Distributed Ledger Blockchain A Secure Distributed Ledger Blockchain transaction Sender Receiver Message Block
Trust between edge devices Backends utilizes Blockchain information
Obligation Chain
Bridging Trust