The security of Internet of Things (IoT) to achieve identity identification and communication secrecy is the most critical issue to be confronted. To achieve the two security features, authentication of public keys by digital certificate techniques establishes the root of trust. To overcome the deficiencies of Certificate Authority-based Public key Infrastructure (CA-based PKI) on generating certificates and certificating, such as single point failure, non-transparency, and dependency, this paper proposes a decentralized PKI based on blockchain, referred to as FiT-DPKI. FiT-DPKI minimizes the dependency of central components and allows the devices in IoT network to authorize the issuance and revocation of certificates, together to avoid single point failure. For the setting of dynamic security level, it employs threshold signatures so that sufficient number of nodes are required to approve generation of new certificates. For transparency, it combines blockchain so that the nodes can jointly maintain the credential system for IoT networks.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

FiT-DPKI: Decentralized Public Key Infrastructure with Flexibility and Transparency for IoT Networks

  • Ruei-Hau Hsu,
  • Jia-Yin Guo,
  • Bing-Cheng Ke,
  • Chia-Ho Tan

摘要

The security of Internet of Things (IoT) to achieve identity identification and communication secrecy is the most critical issue to be confronted. To achieve the two security features, authentication of public keys by digital certificate techniques establishes the root of trust. To overcome the deficiencies of Certificate Authority-based Public key Infrastructure (CA-based PKI) on generating certificates and certificating, such as single point failure, non-transparency, and dependency, this paper proposes a decentralized PKI based on blockchain, referred to as FiT-DPKI. FiT-DPKI minimizes the dependency of central components and allows the devices in IoT network to authorize the issuance and revocation of certificates, together to avoid single point failure. For the setting of dynamic security level, it employs threshold signatures so that sufficient number of nodes are required to approve generation of new certificates. For transparency, it combines blockchain so that the nodes can jointly maintain the credential system for IoT networks.