Internet of Things (IoT) devices pose significant security challenges due to their heterogeneity (i.e., hardware and software) and vulnerability to extensive attack surfaces. Today's conventional perimeter-based systems use credential-based authentication (e.g., username/password, certificates, etc.) to decide whether an actor can access a network. However, the verification process occurs only at the system's perimeter because most IoT devices lack robust security measures due to their limited hardware and software capabilities, making them highly vulnerable. Therefore, this paper proposes a novel approach based on Zero Trust Architecture (ZTA) extended with blockchain to further enhance security. The blockchain component serves as an immutable database for storing users' requests and is used to verify trustworthiness by analyzing and identifying potentially malicious user activities. We discuss the framework, processes of the approach, and the experiments carried out on a testbed to validate its feasibility and applicability in the smart city context. Lastly, the evaluation focuses on non-functional properties such as performance, scalability, and complexity.
翻译:物联网设备因其异构性(即硬件和软件)以及对广泛攻击面的脆弱性,带来了重大的安全挑战。当今传统的基于边界的安全系统采用凭据认证(如用户名/密码、证书等)来判断行为主体能否访问网络。然而,验证过程仅在系统边界进行,因为大多数物联网设备受限于其有限的硬件和软件能力,缺乏稳健的安全措施,极易受到攻击。因此,本文提出了一种基于零信任架构并融合区块链以进一步增强安全性的新方法。区块链组件作为存储用户请求的不可篡改数据库,并用于通过分析和识别潜在的恶意用户活动来验证可信度。我们讨论了该方法的框架、流程以及在测试平台上进行的实验,以验证其在智慧城市背景下的可行性与适用性。最后,评估侧重于性能、可扩展性和复杂性等非功能性属性。