Cargando…
Rechained: Sybil-Resistant Distributed Identities for the Internet of Things and Mobile Ad Hoc Networks
Today, increasing Internet of Things devices are deployed, and the field of applications for decentralized, self-organizing networks keeps growing. The growth also makes these systems more attractive to attackers. Sybil attacks are a common issue, especially in decentralized networks and networks th...
Autores principales: | , |
---|---|
Formato: | Online Artículo Texto |
Lenguaje: | English |
Publicado: |
MDPI
2021
|
Materias: | |
Acceso en línea: | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8125832/ https://www.ncbi.nlm.nih.gov/pubmed/34066711 http://dx.doi.org/10.3390/s21093257 |
_version_ | 1783693617331699712 |
---|---|
author | Bochem, Arne Leiding, Benjamin |
author_facet | Bochem, Arne Leiding, Benjamin |
author_sort | Bochem, Arne |
collection | PubMed |
description | Today, increasing Internet of Things devices are deployed, and the field of applications for decentralized, self-organizing networks keeps growing. The growth also makes these systems more attractive to attackers. Sybil attacks are a common issue, especially in decentralized networks and networks that are deployed in scenarios with irregular or unreliable Internet connectivity. The lack of a central authority that can be contacted at any time allows attackers to introduce arbitrary amounts of nodes into the network and manipulate its behavior according to the attacker’s goals, by posing as a majority participant. Depending on the structure of the network, employing Sybil node detection schemes may be difficult, and low powered Internet of Things devices are usually unable to perform impactful amounts of work for proof-of-work based schemes. In this paper, we present Rechained, a scheme that monetarily disincentivizes the creation of Sybil identities for networks that can operate with intermittent or no Internet connectivity. We introduce a new revocation mechanism for identities, tie them into the concepts of self-sovereign identities, and decentralized identifiers. Case-studies are used to discuss upper- and lower-bounds for the costs of Sybil identities and, therefore, the provided security level. Furthermore, we formalize the protocol using Colored Petri Nets to analyze its correctness and suitability. Proof-of-concept implementations are used to evaluate the performance of our scheme on low powered hardware as it might be found in Internet of Things applications. |
format | Online Article Text |
id | pubmed-8125832 |
institution | National Center for Biotechnology Information |
language | English |
publishDate | 2021 |
publisher | MDPI |
record_format | MEDLINE/PubMed |
spelling | pubmed-81258322021-05-17 Rechained: Sybil-Resistant Distributed Identities for the Internet of Things and Mobile Ad Hoc Networks Bochem, Arne Leiding, Benjamin Sensors (Basel) Article Today, increasing Internet of Things devices are deployed, and the field of applications for decentralized, self-organizing networks keeps growing. The growth also makes these systems more attractive to attackers. Sybil attacks are a common issue, especially in decentralized networks and networks that are deployed in scenarios with irregular or unreliable Internet connectivity. The lack of a central authority that can be contacted at any time allows attackers to introduce arbitrary amounts of nodes into the network and manipulate its behavior according to the attacker’s goals, by posing as a majority participant. Depending on the structure of the network, employing Sybil node detection schemes may be difficult, and low powered Internet of Things devices are usually unable to perform impactful amounts of work for proof-of-work based schemes. In this paper, we present Rechained, a scheme that monetarily disincentivizes the creation of Sybil identities for networks that can operate with intermittent or no Internet connectivity. We introduce a new revocation mechanism for identities, tie them into the concepts of self-sovereign identities, and decentralized identifiers. Case-studies are used to discuss upper- and lower-bounds for the costs of Sybil identities and, therefore, the provided security level. Furthermore, we formalize the protocol using Colored Petri Nets to analyze its correctness and suitability. Proof-of-concept implementations are used to evaluate the performance of our scheme on low powered hardware as it might be found in Internet of Things applications. MDPI 2021-05-08 /pmc/articles/PMC8125832/ /pubmed/34066711 http://dx.doi.org/10.3390/s21093257 Text en © 2021 by the authors. https://creativecommons.org/licenses/by/4.0/Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/). |
spellingShingle | Article Bochem, Arne Leiding, Benjamin Rechained: Sybil-Resistant Distributed Identities for the Internet of Things and Mobile Ad Hoc Networks |
title | Rechained: Sybil-Resistant Distributed Identities for the Internet of Things and Mobile Ad Hoc Networks |
title_full | Rechained: Sybil-Resistant Distributed Identities for the Internet of Things and Mobile Ad Hoc Networks |
title_fullStr | Rechained: Sybil-Resistant Distributed Identities for the Internet of Things and Mobile Ad Hoc Networks |
title_full_unstemmed | Rechained: Sybil-Resistant Distributed Identities for the Internet of Things and Mobile Ad Hoc Networks |
title_short | Rechained: Sybil-Resistant Distributed Identities for the Internet of Things and Mobile Ad Hoc Networks |
title_sort | rechained: sybil-resistant distributed identities for the internet of things and mobile ad hoc networks |
topic | Article |
url | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8125832/ https://www.ncbi.nlm.nih.gov/pubmed/34066711 http://dx.doi.org/10.3390/s21093257 |
work_keys_str_mv | AT bochemarne rechainedsybilresistantdistributedidentitiesfortheinternetofthingsandmobileadhocnetworks AT leidingbenjamin rechainedsybilresistantdistributedidentitiesfortheinternetofthingsandmobileadhocnetworks |