{"title":"A Sovereign PKI for IoT Devices Based on the Blockchain Technology","authors":"I. Obiri, Jingcong Yang, Qi Xia, Jianbin Gao","doi":"10.1109/ICCWAMTIP53232.2021.9674095","DOIUrl":null,"url":null,"abstract":"In the Internet of Things (IoT) environment, public key distribution and device authentication remain the most significant security challenges. To validate the authenticity of the identity of IoT devices, existing solutions depend on Public Key Infrastructure (PKI) backed by Certificate Authorities (CA). CA-based PKI has flaws in terms of a single point of failure and certificate transparency. While some blockchain-based PKI solutions exist, they either have a high storage overhead or require a lot of cryptographic computations in the smart contract, which can exceed the transaction size limit on the blockchain network. Hence, we propose a sovereign PKI for IoT devices based on blockchain technology, in which individual controls and maintains the public and private keys for the IoT devices he or she owns. Public keys are kept in a decentralized key store database (DKSB). The blockchain serves as the ground proof for authenticating identities (public keys) on the DKSB. Cryptographic operations like identity authentication are done off-chain without incurring transaction fees.","PeriodicalId":358772,"journal":{"name":"2021 18th International Computer Conference on Wavelet Active Media Technology and Information Processing (ICCWAMTIP)","volume":"3 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-12-17","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 18th International Computer Conference on Wavelet Active Media Technology and Information Processing (ICCWAMTIP)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICCWAMTIP53232.2021.9674095","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4
Abstract
In the Internet of Things (IoT) environment, public key distribution and device authentication remain the most significant security challenges. To validate the authenticity of the identity of IoT devices, existing solutions depend on Public Key Infrastructure (PKI) backed by Certificate Authorities (CA). CA-based PKI has flaws in terms of a single point of failure and certificate transparency. While some blockchain-based PKI solutions exist, they either have a high storage overhead or require a lot of cryptographic computations in the smart contract, which can exceed the transaction size limit on the blockchain network. Hence, we propose a sovereign PKI for IoT devices based on blockchain technology, in which individual controls and maintains the public and private keys for the IoT devices he or she owns. Public keys are kept in a decentralized key store database (DKSB). The blockchain serves as the ground proof for authenticating identities (public keys) on the DKSB. Cryptographic operations like identity authentication are done off-chain without incurring transaction fees.