شماره ركورد
25955
شماره راهنما
MAT2 729
عنوان
اشتراكگذاري عادلانه، وارسيپذير و امن دادهها در بستر اينترنت اشيا با استفاده از زنجيرهبلوكي
مقطع تحصيلي
كارشناسي ارشد
رشته تحصيلي
علوم كامپيوتر- الگوريتم و نظريه محاسبه
دانشكده
رياضي و آمار
تاريخ دفاع
1405/04/09
صفحه شمار
89ص.
استاد راهنما
مجتبي رفيعي كركوندي , محسن علمبردار ميبدي
كليدواژه فارسي
رايانش مه , اينترنت اشياي صنعتي , محرمانگي , اصالت , انصاف
چكيده فارسي
اينترنت اشيا يكي از زيرساختهاي اصلي سامانههاي هوشمند امروزي است كه با توليد پيوسته داده توسط حسگرها و تجهيزات متصل، نقش مهمي در پايش، تصميمگيري، بهينهسازي فرايندها و افزايش بهرهوري ايفا ميكند. با اين حال، ارزش اقتصادي و عملياتي اين دادهها باعث ميشود كه اشتراكگذاري آنها بدون سازوكارهاي امنيتي مناسب با چالشهاي جدي همراه باشد. در چنين محيطهايي، دادهها معمولاً از طريق موجوديتهاي واسط مانند گرههاي مه، سرويسدهندههاي ابري و زنجيرهبلوكي ميان توليدكنندگان و مشتريان مبادله ميشوند؛ از اينرو، يك طرح مناسب بايد بهطور همزمان ويژگيهايي مانند محرمانگي داده، اصالت داده و انصاف در تبادل را تضمين كند.
در سالهاي اخير، پژوهشهاي متعددي براي تحقق اشتراكگذاري امن و منصفانه داده در بسترهاي غيرمتمركز ارائه شدهاند. در ميان آنها، طرح FairShare بهعنوان يك سازوكار مبتني بر زنجيرهبلوكي براي اشتراكگذاري داده در اينترنت اشياي صنعتي مورد توجه قرار گرفته است. اين طرح تلاش ميكند تا بهصورت همزمان ويژگيهاي محرمانگي، اصالت و انصاف را در فرايند تبادل داده فراهم كند. با اين حال، تحليل امنيتي انجامشده در اين پاياننامه نشان ميدهد كه سازوكار اعتبارسنجي عمومي در FairShare براي تضمين انصاف كافي نيست. بهطور مشخص، يك گره مه بدخواه ميتواند در گام بازيابي داده، فرادادهاي جعلي توليد كند كه آزمون عمومي پروتكل را با موفقيت پشت سر ميگذارد، در حاليكه مشتري پس از رمزگشايي به داده معتبر دست نمييابد و امكان اثبات اين تقلب را نيز ندارد. بنابراين، طرح پايه در برابر حمله جعل توسط مه آسيبپذير است و ادعاي انصاف آن در مدل تهديد مورد نظر برقرار نميماند.
براي رفع اين ضعف، در اين پاياننامه طرحي بهبوديافته با نام FairShare+ ارائه ميشود. طرح پيشنهادي با بازطراحي فرادادههاي رمزنگارانه و افزودن يك مرحله اعتبارسنجي مياني توسط مشتري، امكان تشخيص رفتار مخرب گره مه را پيش از نهايي شدن تبادل فراهم ميكند. افزون بر اين، برخلاف FairShare، طرح FairShare+ بدون استفاده از نگاشتهاي دوخطي طراحي شده و در نتيجه از نظر محاسباتي سبكتر و براي محيطهاي داراي محدوديت منابع مناسبتر است. تحليل امنيتي نشان ميدهد كه طرح پيشنهادي در مدل تهديد مورد نظر، محرمانگي داده، اصالت داده و انصاف در برابر مه و مشتري را تأمين ميكند. همچنين نتايج ارزيابي كارايي نشان ميدهد كه FairShare+ ضمن رفع آسيبپذيري طرح پايه، سربار محاسباتي و ذخيرهسازي را بهترتيب تا حدود 97 و 74 درصد نسبت به FairShare كاهش ميدهد.
كليدواژه لاتين
Fog computing , Industrial Internet of Things , Confidentiality , Authenticity , Fairness
عنوان لاتين
Fair, Auditable and Secure Data Sharing in the Internet of Things Using Blockchain
گروه آموزشي
رياضي كاربردي و علوم كامپيوتر
چكيده لاتين
The Internet of Things (IoT) is one of the main infrastructures of todayʹs smart systems. By continuously generating data through sensors and connected devices, it plays an important role in monitoring, decision-making, process optimization, and improving efficiency. However, the economic and operational value of such data makes their sharing, without appropriate security mechanisms, a serious challenge. In such environments, data are usually exchanged between producers and customers through intermediary entities such as fog nodes, cloud servers, and blockchain. Therefore, a suitable scheme must simultaneously guarantee properties such as data confidentiality, data authenticity, and fairness in exchange.
In recent years, several studies have been proposed to realize secure and fair data sharing in decentralized settings. Among them, FairShare has attracted attention as a blockchain-based mechanism for data sharing in the Industrial Internet of Things. This scheme aims to simultaneously provide confidentiality, authenticity, and fairness during the data-exchange process. However, the security analysis conducted in this thesis shows that the public verification mechanism in FairShare is not sufficient to guarantee fairness. More specifically, a malicious fog node can generate forged metadata during the data-recovery phase that successfully passes the public test of the protocol, while the customer, after decryption, does not obtain valid data and is unable to prove this misbehavior. Therefore, the original scheme is vulnerable to a forgery attack by the fog node, and its fairness claim does not hold in the considered threat model.
To address this weakness, this thesis proposes an improved scheme called FairShare+. The proposed scheme redesigns the cryptographic metadata and adds an intermediate validation phase performed by the customer, enabling the detection of malicious behavior by the fog node before the exchange is finalized. Moreover, unlike FairShare, FairShare+ is designed without using bilinear maps; consequently, it is computationally lighter and more suitable for resource-constrained environments. The security analysis shows that, in the considered threat model, the proposed scheme provides data confidentiality, data authenticity, and fairness against both the fog node and the customer. Furthermore, the performance evaluation results show that FairShare+, while fixing the vulnerability of the original scheme, reduces the computational and storage overheads by approximately 97% and 74%, respectively, compared with FairShare.
تعداد فصل ها
6
فهرست مطالب pdf
161436
نويسنده