• شماره ركورد
    25955
  • شماره راهنما
    MAT2 729
  • عنوان

    اشتراك‌گذاري عادلانه، وارسي‌پذير و امن داده‌ها در بستر اينترنت اشيا با استفاده از زنجيره‌بلوكي

  • مقطع تحصيلي
    كارشناسي ارشد
  • رشته تحصيلي
    علوم كامپيوتر- الگوريتم و نظريه محاسبه
  • دانشكده
    رياضي و آمار
  • تاريخ دفاع
    1405/04/09
  • صفحه شمار
    89ص.
  • استاد راهنما
    مجتبي رفيعي كركوندي , محسن علمبردار ميبدي
  • كليدواژه فارسي
    رايانش مه , اينترنت اشياي صنعتي , محرمانگي , اصالت , انصاف
  • چكيده فارسي
    اينترنت اشيا يكي از زيرساخت‌هاي اصلي سامانه‌هاي هوشمند امروزي است كه با توليد پيوسته داده توسط حسگرها و تجهيزات متصل، نقش مهمي در پايش، تصميم‌گيري، بهينه‌سازي فرايندها و افزايش بهره‌وري ايفا مي‌كند. با اين حال، ارزش اقتصادي و عملياتي اين داده‌ها باعث مي‌شود كه اشتراك‌گذاري آن‌ها بدون سازوكارهاي امنيتي مناسب با چالش‌هاي جدي همراه باشد. در چنين محيط‌هايي، داده‌ها معمولاً از طريق موجوديت‌هاي واسط مانند گره‌هاي مه، سرويس‌دهنده‌هاي ابري و زنجيره‌بلوكي ميان توليدكنندگان و مشتريان مبادله مي‌شوند؛ از اين‌رو، يك طرح مناسب بايد به‌طور هم‌زمان ويژگي‌هايي مانند محرمانگي داده، اصالت داده و انصاف در تبادل را تضمين كند. در سال‌هاي اخير، پژوهش‌هاي متعددي براي تحقق اشتراك‌گذاري امن و منصفانه داده در بسترهاي غيرمتمركز ارائه شده‌اند. در ميان آن‌ها، طرح FairShare به‌عنوان يك سازوكار مبتني بر زنجيره‌بلوكي براي اشتراك‌گذاري داده در اينترنت اشياي صنعتي مورد توجه قرار گرفته است. اين طرح تلاش مي‌كند تا به‌صورت هم‌زمان ويژگي‌هاي محرمانگي، اصالت و انصاف را در فرايند تبادل داده فراهم كند. با اين حال، تحليل امنيتي انجام‌شده در اين پايان‌نامه نشان مي‌دهد كه سازوكار اعتبارسنجي عمومي در FairShare براي تضمين انصاف كافي نيست. به‌طور مشخص، يك گره مه بدخواه مي‌تواند در گام بازيابي داده، فراداده‌اي جعلي توليد كند كه آزمون عمومي پروتكل را با موفقيت پشت سر مي‌گذارد، در حالي‌كه مشتري پس از رمزگشايي به داده معتبر دست نمي‌يابد و امكان اثبات اين تقلب را نيز ندارد. بنابراين، طرح پايه در برابر حمله جعل توسط مه آسيب‌پذير است و ادعاي انصاف آن در مدل تهديد مورد نظر برقرار نمي‌ماند. براي رفع اين ضعف، در اين پايان‌نامه طرحي بهبوديافته با نام FairShare+ ارائه مي‌شود. طرح پيشنهادي با بازطراحي فراداده‌هاي رمزنگارانه و افزودن يك مرحله اعتبارسنجي مياني توسط مشتري، امكان تشخيص رفتار مخرب گره مه را پيش از نهايي شدن تبادل فراهم مي‌كند. افزون بر اين، برخلاف FairShare، طرح FairShare+ بدون استفاده از نگاشت‌هاي دوخطي طراحي شده و در نتيجه از نظر محاسباتي سبك‌تر و براي محيط‌هاي داراي محدوديت منابع مناسب‌تر است. تحليل امنيتي نشان مي‌دهد كه طرح پيشنهادي در مدل تهديد مورد نظر، محرمانگي داده، اصالت داده و انصاف در برابر مه و مشتري را تأمين مي‌كند. همچنين نتايج ارزيابي كارايي نشان مي‌دهد كه FairShare+ ضمن رفع آسيب‌پذيري طرح پايه، سربار محاسباتي و ذخيره‌سازي را به‌ترتيب تا حدود 97 و 74 درصد نسبت به FairShare كاهش مي‌دهد.
  • كليدواژه لاتين
    Fog computing , Industrial Internet of Things , Confidentiality , Authenticity , Fairness
  • عنوان لاتين
    Fair, Auditable an‎d Secure Data Sharing in the Internet of Things Using Blockchain
  • گروه آموزشي
    رياضي كاربردي و علوم كامپيوتر
  • چكيده لاتين
    The Internet of Things (IoT) is one of the main infrastructures of todayʹs smart systems. By continuously generating data through sensors an‎d connected devices, it plays an important role in monitoring, decision-making, process optimization, an‎d improving efficiency. However, the economic an‎d operational value of such data makes their sharing, without appropriate security mechanisms, a serious challenge. In such environments, data are usually exchanged between producers an‎d customers through intermediary entities such as fog nodes, cloud servers, an‎d blockchain. Therefore, a suitable scheme must simultaneously guarantee properties such as data confidentiality, data authenticity, an‎d fairness in exchange. In recent years, several studies have been proposed to realize secure an‎d fair data sharing in decentralized settings. Among them, FairShare has attracted attention as a blockchain-based mechanism for data sharing in the Industrial Internet of Things. This scheme aims to simultaneously provide confidentiality, authenticity, an‎d fairness during the data-exchange process. However, the security analysis conducted in this thesis shows that the public verification mechanism in FairShare is not sufficient to guarantee fairness. More specifically, a malicious fog node can generate forged metadata during the data-recovery phase that successfully passes the public test of the protocol, while the customer, after decryption, does not obtain valid data an‎d is unable to prove this misbehavior. Therefore, the original scheme is vulnerable to a forgery attack by the fog node, an‎d its fairness claim does not hold in the considered threat model. To address this weakness, this thesis proposes an improved scheme called FairShare+. The proposed scheme redesigns the cryptographic metadata an‎d adds an intermediate validation phase performed by the customer, enabling the detection of malicious behavior by the fog node before the exchange is finalized. Moreover, unlike FairShare, FairShare+ is designed without using bilinear maps; consequently, it is computationally lighter an‎d more suitable for resource-constrained environments. The security analysis shows that, in the considered threat model, the proposed scheme provides data confidentiality, data authenticity, an‎d fairness against both the fog node an‎d the customer. Furthermore, the performance eva‎luation results show that FairShare+, while fixing the vulnerability of the original scheme, reduces the computational an‎d storage overheads by approximately 97% an‎d 74%, respectively, compared with FairShare.
  • تعداد فصل ها
    6
  • فهرست مطالب pdf
    161436
  • نويسنده

    ابري، مهدي