Secure Ownership Management and Transfer of Consumer Internet of Things Devices with Self-sovereign Identity

Nazmus Sakib, Md Yeasin Ali, Nuran Mubashshira Momo, Marzia Islam Mumu, Masum Al Nahid, Fairuz Rahaman Chowdhury, Md Sadek Ferdous
{"title":"Secure Ownership Management and Transfer of Consumer Internet of Things Devices with Self-sovereign Identity","authors":"Nazmus Sakib, Md Yeasin Ali, Nuran Mubashshira Momo, Marzia Islam Mumu, Masum Al Nahid, Fairuz Rahaman Chowdhury, Md Sadek Ferdous","doi":"arxiv-2408.17184","DOIUrl":null,"url":null,"abstract":"The popularity of the Internet of Things (IoT) has driven its usage in our\nhomes and industries over the past 10-12 years. However, there have been some\nmajor issues related to identity management and ownership transfer involving\nIoT devices, particularly for consumer IoT devices, e. g. smart appliances such\nas smart TVs, smart refrigerators, and so on. There have been a few attempts to\naddress this issue; however, user-centric and effective ownership and identity\nmanagement of IoT devices have not been very successful so far. Recently,\nblockchain technology has been used to address these issues with limited\nsuccess. This article presents a Self-sovereign Identity (SSI) based system\nthat facilitates a secure and user-centric ownership management and transfer of\nconsumer IoT devices. The system leverages a number of emerging technologies,\nsuch as blockchain and decentralized identifiers (DID), verifiable credentials\n(VC), under the umbrella of SSI. We present the architecture of the system\nbased on a threat model and requirement analysis, discuss the implementation of\na Proof-of-Concept based on the proposed system and illustrate a number of\nuse-cases with their detailed protocol flows. Furthermore, we analyse its\nsecurity using ProVerif, a state-of-the art protocol verification tool and\nexamine its performance.","PeriodicalId":501168,"journal":{"name":"arXiv - CS - Emerging Technologies","volume":"3 1","pages":""},"PeriodicalIF":0.0000,"publicationDate":"2024-08-30","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"arXiv - CS - Emerging Technologies","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/arxiv-2408.17184","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

The popularity of the Internet of Things (IoT) has driven its usage in our homes and industries over the past 10-12 years. However, there have been some major issues related to identity management and ownership transfer involving IoT devices, particularly for consumer IoT devices, e. g. smart appliances such as smart TVs, smart refrigerators, and so on. There have been a few attempts to address this issue; however, user-centric and effective ownership and identity management of IoT devices have not been very successful so far. Recently, blockchain technology has been used to address these issues with limited success. This article presents a Self-sovereign Identity (SSI) based system that facilitates a secure and user-centric ownership management and transfer of consumer IoT devices. The system leverages a number of emerging technologies, such as blockchain and decentralized identifiers (DID), verifiable credentials (VC), under the umbrella of SSI. We present the architecture of the system based on a threat model and requirement analysis, discuss the implementation of a Proof-of-Concept based on the proposed system and illustrate a number of use-cases with their detailed protocol flows. Furthermore, we analyse its security using ProVerif, a state-of-the art protocol verification tool and examine its performance.
利用自我主权身份确保消费物联网设备所有权的安全管理和转让
过去 10-12 年间,物联网(IoT)的普及推动了其在家庭和工业领域的应用。然而,在涉及物联网设备的身份管理和所有权转移方面一直存在一些重大问题,特别是对于消费类物联网设备,如智能电视、智能冰箱等智能电器。已经有一些尝试来解决这个问题,但迄今为止,以用户为中心、有效的物联网设备所有权和身份管理还不是很成功。最近,区块链技术被用来解决这些问题,但成效有限。本文介绍了一种基于自我主权身份(SSI)的系统,该系统有助于以用户为中心对消费者物联网设备进行安全的所有权管理和转让。该系统利用了一系列新兴技术,如区块链、去中心化标识符(DID)、可验证凭证(VC)等。我们在威胁模型和需求分析的基础上介绍了该系统的架构,讨论了基于拟议系统的概念验证的实施情况,并举例说明了一些使用案例及其详细的协议流。此外,我们还使用最先进的协议验证工具 ProVerif 分析了系统的安全性,并检验了其性能。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信