Official Gazette Notification Text
Official TranscriptComputerCommunications216(2024)324–345 Contents lists available at ScienceDirect Computer Communications journal homepage: www.elsevier.com/locate/comcom eSIM and blockchain integrated secure zero-touch provisioning for autonomous cellular-IoTs in 5G networks Prabhakar Krishnana, Kurunandan Jaina, Shivananda R. Poojarab,*, Satish Narayana Sriramac, Tulika Pandeyd, Rajkumar Buyyae aCenter for...
ComputerCommunications216(2024)324–345 Contents lists available at ScienceDirect Computer Communications
journal homepage: www.elsevier.com/locate/comcom eSIM and blockchain integrated secure zero-touch provisioning for autonomous cellular-IoTs in 5G networks Prabhakar Krishnana, Kurunandan Jaina, Shivananda R. Poojarab,*, Satish Narayana Sriramac, Tulika Pandeyd, Rajkumar Buyyae aCenter for Cybersecurity Systems and Networks, Amrita Vishwa Vidyapeetham, Amritapuri-campus, India bInstitute of Computer Science, University of Tartu, Tartu, Estonia cSchool of Computer and Information Sciences, The University of Hyderabad, Hyderabad, India dResearch and Development in Cybersecurity, Ministry of Electronics and Information Technology, Government of India, India eCloud Computing and Distributed Systems (CLOUDS) Lab, School of Computing and Information Systems, The University of Melbourne, Australia A R T I C L E I N F O A B S T R A C T
Keywords: The growth of the Internet of Things (IoT) paradigm has resulted in a proliferation of connected devices and their Zero-touch service provisioning (ZTP) applications. Autonomous IoT (AIoT) refers to a network of interconnected devices that operate without human Autonomous IoT (AIoT) intervention, making decisions and performing tasks autonomously. Traditional methods of provisioning IoT Zero-touch networks devices, such as manual configuration and over-the-air updates, are error-prone and insecure. The emergence of Embedded SIM (eSIM) eSIMs (embedded SIMs) provides a viable solution for secure and flexible identity management in IoT devices.
Blockchain This work implements a low-cost, zero-touch remote provisioning system using GSMA standard Over-The-Air Software defined networking (SDN) Remote SIM provisioning (OTA) IoT-SAFE protocol. This research predicts that future IoT devices will be eSIM-enabled, which are sim- ple to configure, provision, validate profiles, and check security policies remotely. IoT onboarding processes are designed where blockchains are used to verify immutable repositories to store this network manifests, verifiable by Ethereum smart contracts. The integrated framework combines blockchain contracts, eSIM-based remote SIM provisioning through IoT-SAFE protocol, and SDN to manage IoT ecosystems’ security. The proposed solution is evaluated using simulations and security analysis, and it demonstrates its feasibility at scale and resilience to attacks even under insecure environments. When compared with the baseline IEEE 802.15.4 protocol, our SDN- based Remote-SIM provisioning system (SIeSIM) reduces overhead to about 240 ms Time-To-Provision (TTP), outperforming manual provisioning by nearly 320 % and 210 % compared to expert provisioning in terms of TTP performances, respectively.
1. Introduction end-users are mapped via protocols [3]. Appropriate users and IoT de- vice authentications must consider service constraints in IoTs, as they In the Internet of Things (IoT) environment, networks of inter- cannot perform complex transactions or processes. User and device connected devices communicate amongst themselves and exchange authentication mechanisms must also be scalable, trustworthy, and data. Networks based on IoTs are expanding rapidly, with more and resistant to threats and assaults. Most authentication methods safeguard more devices connected to the Internet daily. Commonly, devices in IoTs IoT devices but depend on centralized databases or servers. [4], which are equipped with tags or sensors that collect, store, and transmit in- checks users, devices, and communication records in IoTs. The fre- formation via networks where their management is typically achieved quency of cyberattacks on IoT networks and devices has grown, with through centralized architectures [1]. Devices using IoTs have grown devastating results that can result in major risks. Most current security substantially and are expected to cross 25 billion by 2025 from 14.2 solutions in use rely on centralized infrastructure (like PKI), which is billion in 2019 [2]. Servers collect and analyze data in real-time from reliant on third-party service providers being trusted. The drawbacks of these devices. Due to this flaw, anyone may readily access these devices this strategy include a single point of failure (SPOF), many-to-one traffic, and do calculations in accordance with them. On these devices, and restricted scalability. IoT devices frequently lack the same * Corresponding author.
E-mail address: shivananda.poojara@ut.ee (S.R. Poojara).
https://doi.org/10.1016/j.comcom.2023.12.023 Received 5 June 2023; Received in revised form 18 December 2023; Accepted 18 December 2023 Availableonline6January2024 0140-3664/©2024ElsevierB.V.Allrightsreserved.P. Krishnan et al. C o m p u t e r C o m m u n i c a t i o n s 216(2024)324–345 authentication security measures as fully working on a computer node. chips soldered onto the circuit boards of devices. They are non- New IoT authentication methods that integrate with new IoT devices removable SIM cards allowing OTA (over-the-air) activations and must be proposed, are completely suited to satisfy IoT needs, and are management. eSIMs can be programmed with multiple profiles, thus mostly independent of devices and architectures [5]. Secure, trusted allowing them to be used with different carriers or networks. eSIMs can connectivity of IoT nodes shall propel the IoT into the next growth stage. also be remotely provisioned, activated, and managed, eliminating the The growth path for cellular IoT connectivity is now expected that 98 % need for physical SIMs cards and simplified supply chains. eSIM is also of enterprises want an end-to-end security solution that protects data tamper-resistant and provides increased security compared to tradi- integrity and confidentiality from IoT devices, and 72 % of enterprises tional SIM cards. eSIMs can be used in many domains, including pro- consider device-to-cloud security an essential feature when selecting a gramming M2M devices, enabling devices for IoTs independent of solution. Trust frameworks and transparency will need to be woven into tethered smartphones, and changing operator profiles using remote sim all IoT layers for our cities to dispel concerns and ensure these new provisioning. Thus, eSIMs can be applied in IoTs, consumer, and auto- technologies can help our smart cities thrive. The key issue to resolve is motive applications.
providing connectivity and zero-touch provisioning cost-effectively and Technically eSIMs can be used in several areas, including network securely. Identity and provisioning are crucial components of IoT se- authentications (managing connectivity and operator switching), device curity that enable secure communication between devices. The devices attestations (identifying and connecting to clouds), end-to-end encryp- in IoTs rely on secure and reliable communication protocols to transmit tions (data encryptions), and data integrity (ensuring sign-on for future and receive data, where device identifications and provisioning are verifications) as depicted in Fig. 1.
crucial components of security or secure communications between de- SIM cards have mostly stayed the same since the introduction of 2G. vices. Autonomous IoT (AIoT) refers to a network of interconnected Despite several convenience and security improvements, their identity devices that operate without human intervention, making decisions and management has also been static. Numerous IoT applications are performing tasks autonomously. AIoT networks have numerous appli- essentially constrained by the necessity to link them to devices [7]. The cations, including industrial automation, smart cities, and autonomous combination of IoT and eSIM technology has significant engineering and vehicles. Standard application layer protocols for the Internet of Things scientific value since IoT applications need platforms to transfer data have recently undergone advancements, enhancements, and improve- between heterogeneous devices. It intends to do away with the ments. However, due to the dynamic nature of IoT applications, tradi- requirement for Subscriber Identity Module (SIM) cards in the context of tional and upgraded application layer protocols have not yet met their IoT to provide safe communication to IoT devices. The mobile device’s requirements. Autonomously adapting to changing conditions in the circuit board can be configured with SIM profiles that contain identities application, these protocols can become intelligent with the help of and credentials using the more widely used embedded SIM (eSIM) AI/ML [6]. One of the challenges in deploying AIoT networks is the technology [8]. Smartphones and other edge devices on the Internet of secure provisioning of services to the devices. Things (IoT) are becoming more powerful computationally, but there Service provisioning refers to providing access to services, such as are still times when it’s necessary to offload tasks to other devices. This data, applications, and updates, to the devices. Traditional service pro- is especially true for compute-intensive and energy-hungry operations visioning mechanisms require human intervention, which can be time- like encryption/decryption and password/authentication management.
consuming, costly, and error prone. Moreover, human intervention in- Therefore, moving specific processing away from devices with limited creases the risk of attacks and compromises the network’s security. The resources (IoT) and onto more capable devices (cloud, edge servers) is traditional SIM card-based approach for identity and provisioning in IoT necessary.
devices is not suitable for the requirements of the IoT ecosystem. The Because cloud services are delivered over a public network, they emergence of eSIMs provides a viable solution for secure and flexible involve some anonymity and security risk. The authors describe case identity management in IoT devices. ESIMs are small; programmable studies in smart healthcare, safety, and emergency response [9] and the Fig. 1. Applications of eSIM.
325P. Krishnan et al. C o m p u t e r C o m m u n i c a t i o n s 216(2024)324–345 importance of machine learning and task-offloading strategies. eSIMs low-powered processing has opened gateways to provide cognition at can be the safest and most trusted platform for offloading security pro- the extreme edge (E.g., sensors and actuators). It is desirable to enable cessing tasks for IoT and mobile devices. Unlike conventional SIM cards, onboard ML on microcontrollers, turning them from simple data har- eSIMs are powerful embedded microcontroller-based chips with storage vesters to learning-enabled inference generators and on-device analytics capacity and sufficient computation power that are permanent parts of for a variety of sensing modalities (vision, audio, motion, identification, devices. They are smaller than typical nano SIMs, can fit into tiny de- etc.).
vices, and are assets to IoTs. The primary features of eSIMs increase the system’s communication dependability and profile administrations 1.1. Problem statement remotely [10]. They can move network operators’ information to new devices using eSIMs with assistance from Remote SIM Provisioning Security in IoTs is crucial for interactions. Customers must trust that
(RSP) infrastructures [11]. They use Zero-Touch Provisioning, which is their data will be secure against unauthorized users, manipulations, or easy, scalable, and economical [12]. The devices connect immediately to other undesirable device actions. Thus, authentications are critical for the nearest networks and download specific local profiles. This under- IoTs that need customers to manually handle shared keys that guarantee lying feature offers a seamless communication process for heteroge- the device’s functionalities and safe connections. Most authentication neous devices deployed worldwide. The SIM profile contains options on these systems are more user centric. Devices can also security-critical information regarding the user credentials that the authenticate via shared key methods across devices or OAuth2 tech- subscriber can access the mobile networks [13]. niques that are more user-friendly for humans/user authentications.
Therefore, secure transmission of the SIM profile to the mobile de- However, attackers learn shared keys and device IDs for impersonations. vice is paramount. At the same time, unwanted exposure or tampering The developments of solutions based on the Trusted Platform Module with such credentials could lead to eavesdropping, identity theft, billing (TPM), which provides chains of trust, also face challenges. To avoid fraud, and various privacy violations against mobile subscribers [14, impersonation attacks and stop devices from providing data under the 51]. This implies the need for careful designs and analyses of RSP pro- identity of another in the context of smart cities, it is essential to guar- tocols. Zero Touch architecture-based protections should not trust all antee that device identifications are defined and automated. Commu- devices while consistently verifying entities before granting access to nication equipment must be encrypted for secure channel them and avoiding data breaches. The layered architecture of the communications and to ensure that data provided and received is the SDN-IoT ecosystem powered by blockchain is shown in Fig. 2. There is a same, that is, unaltered.
definite need for programmable and reliably enforceable security pro- To automate the bootstrap IoT devices and integrate them into the tocols as significant business networks and critical infrastructure service SIeSIM framework with Zero Touch Provisioning (ZTP) approach, this providers for progressive deployments of IoTs. As seen in Fig. 2, SDN study suggests employing secure tokens, which offer identities, au- controllers manage network services while blockchains offer security thentications, and secure communications. Solutions for provisions and and integrity and data transfers through SDNs. In peer-to-peer (P2P) and authentications of multiple devices can be scaled without having to cloud (WAN) networks, servers, apps, hubs, switches/routers, items, or authenticate each one at a time using device pools. Moreover, devices devices, including sensors, actuators, and hubs, are connected to can be authenticated with one another and authenticate multiple de- improve resource management in networks employing IoTs. vices. This can guarantee safe storage, monitoring, and authentication of Blockchain-enabled SDN-IoT ecosystems’ layered architecture aims to eSIMs; blockchains might offer secure and decentralized solutions for optimize Blockchain-based SDN frameworks. These environments managing eSIMs registered on blockchain networks. Although their comprise sensors and gadgets that sense data in real time and commu- terms are open, digital certificates are frequently used to establish nicate it to the next sub-layers. Higher-energy CHs receive data from identification and authentication. Device provisioning is a laborious forwarding devices (switches, routers, phones, and storage devices). The process involving identity, key provisioning, and device setups. Auto- processes are managed by Access Points (APs), which transfer all mated configuration checks can prevent incorrect forms, a common detected data to SDNs. Data and control planes define Edge Layers in cause of security and privacy problems.
SDN settings. Data from IoT devices is sent through standard gateways Embedded AI on microcontrollers is motivated by applicability, in- (SDN-IoT gateways). Finally, data is received via IoT servers that include dependence from network infrastructure, security and privacy, and low Blockchains. We propose two different Blockchains for the control layer deployment cost.
and the data layer. Blockchain in the control layer contains the distributed flow rules and maintains the consistency of the flow rules of • This brings the advantage that less data needs to be transmitted.
each cluster. In detail, the chain logs all the updates, thus resulting in a Instead of sending raw data, only the results of predictions need to be version control management system in the control layer. On the other sent. This way, data analytics can be performed directly on the IoT hand, Blockchain in the data layer works differently. All the switches device with low latency and power requirements.
dump their flow rules in the chain sequentially and verify if they are • Privacy-centric security systems: closed-loop sensor/actuation sys- maintaining the same rule set. If any of the switches do not dump the tems, single-purpose devices that don’t need connectivity, just some same rules, the record is not updated, and the switch is isolated from the smarts, devices that need a super-fast response time, such as a sensor environment. This isolation helps to identify a fault in the switch and to on a motor detecting a problem and stopping it before it breaks.
contain adversaries if the switch is compromised. • Build devices that use less power and respond ever more quickly.
TinyML is one of the hottest trends in the embedded computing field With actual learning on the chip, each sensor could become right now, with 2.5 billion TinyML-enabled devices estimated to reach personalized to the ways in which the device runs in a particular the market in the next decade and a projected market value exceeding environment.
$70 billion in just five years. Dubbed Tiny Machine Learning (TinyML), • The security benefits of using local machine learning are consider- this upsurging research field proposes to democratize the use of Machine able. After all, if you don’t connect a device to the internet, you have Learning (ML) and Deep Learning (DL) on frugal Microcontroller Units a much smaller attack surface. That benefit goes hand in hand with
(MCUs). Traditionally, sensor data is offloaded onto models running on privacy. mobile devices or cloud servers. This is not suitable for time-critical sense-compute-actuation applications such as autonomous driving, The proposed network architecture can be used by any IoT network robot control, and industrial control systems. TinyML allows offline and deployment in cellular networks (LTE, 4G, 5G, and beyond networks) on-board inference without requiring data offloading or cloud-based irrespective of the protocols and requires minimal procedural changes inference. The rapid miniaturization of Machine Learning (ML) for when adapting to eSIMs. This study suggests adopting the IoT-SAFE 326P. Krishnan et al. C o m p u t e r C o m m u n i c a t i o n s 216(2024)324–345 Fig. 2. Layered architecture of Blockchain-enabled SDN-IoT ecosystem.
327P. Krishnan et al. C o m p u t e r C o m m u n i c a t i o n s 216(2024)324–345 protocol-based eSIM for zero-touch service provisioning in autonomous managed, eliminating the need for physical SIM cards and simplifying IoT to solve the issues with provisioning, secure registration, and supply chains. eSIMs are also tamper-resistant and provide increased authentication. The system is low-cost, zero-touch remote provisioning, security compared to traditional SIM cards. eSIM technology enables making it easier to deploy and operate an IoT solution that is secure, secure identity and large-scale connectivity orchestrations amongst scalable, and manageable over time. It helps solve the challenge of nodes of IoTs. Device platforms in IoTs must also comply with GSMA IoT provisioning millions of IoT devices across an ecosystem by enabling SAFE protocol, allowing the orchestration of secure communication provisioning and credential lifecycle management from a remote IoT channels between devices and servers at distant data centers or in Cloud security service. The proposed approach makes it possible for devices to infrastructures. IoT SAFE applets (applications) on IoT devices embed be supplied safely and automatically without human involvement, eSIMs, and devices are immediately and securely provided with apps as guaranteeing that the network is secure. soon as they are turned on. IoT SAFE Security servers carry out secure provisioning. eSIMs can also be configured to perform various tasks (see Fig. 3). The programmable elements of eSIMs include reading files,
1.2. Major contributions implementing cryptographic procedures (Symmetric and Asymmetric), verifying signatures, generating key pairs, maintaining public/private • We present our systematic study and review of eSIMs and their usage keys, and generating randomized key values.
in blockchains, device provisioning, and implementations of IoT SAFE protocol. • layered hierarchy to deploy a distributed yet efficient Blockchain- 2.2. IoT SAFE protocol enabled SDN-Cellular IoT framework.
• A novel authentication scheme for device provisioning in IoTs using Developed by the mobile industry, IoT SAFE (IoT SIM Applet For eSIMs and blockchains is proposed. Secure End-2-End Communication) enables IoT device manufacturers • Informal and experimental security analysis shows that the proposed and service providers to leverage the SIM as a robust, scalable, stan- scheme can overcome security flaws and vulnerabilities to attacks in dardized hardware Root of Trust to protect IoT data communications.
IoTs. IoT SAFE Framework provides a standard mechanism to secure IoT data • Privacy-centric security systems: closed-loop sensor/actuation sys- communications using a highly trusted SIM and a secure end-to-end tems, single-purpose IoT devices that don’t need connectivity, just solution for IoT device security, including secure provisioning. Fig. 4 some smarts, devices that need a super-fast response time. The se- displays IoT SAFE eSIM architecture and is explained below.
curity benefits of using local machine learning are considerable. In the above figure, key GSMA IoT Security recommendations After all, if you don’t connect a device to the internet, you have a include utilizing ‘Roots of Trust’ in hardware to enable end-to-end, chip- much smaller attack surface. cloud security and services. This necessitates the incorporation of both • Extensive Performance and comprehensive security, scalability provisioning and the usage of security credentials into devices. Because analysis, and comparative experimental results in the state of the art they offer enhanced security and cryptography characteristics and are are presented. completely standardized secure components, eSIMs are ideally suited to operate as Roots of Trust in devices. This enables interoperability be-
The rest of the paper is organized as follows: Section II introduces tween vendors and consistencies of device deployment. IoT SAFE solu- challenges in securing networks of IoTs. Section III presents the litera- tion’s SIM Applet, developed for mobile sectors for Secured End-2-End ture study and a discussion of the related works. Section IV illustrates the Communications, assists IoT device manufacturers and service providers system architecture of the proposed scheme, which is described in detail. to use SIMs as secure, scalable, standardized hardware Roots of Trust
Section V shows the performance evaluation for the security of devices and protect IoT data in exchanges. connected to IoTs. Section VI discusses the limitations and future scope. IoT SAFE provides standard ways to secure data transfers in IoTs
Section VII concludes the paper. using trustworthy SIMs rather than proprietary or less trusted hardware component devices. eSIMs are utilized inside the device as a small
2. Background and motivation ‘crypto-safe’ to securely create a (D)TLS connection with a related application cloud/server that is compatible with eSIMs. The common
2.1. eSIM technology API provides extremely secure eSIM for use as the ‘Root of Trust’ by IoT devices and assistance in deploying millions of IoT devices. IoT devices eSIMs are small and programmable chips soldered onto circuit securely execute mutual (D)TLS authentication to a server using asym- boards of devices. They are non-removable SIMs that allow over-the-air metric or symmetric security algorithms, calculate shared secrets, pro-
(OTA) activations and management. eSIMs can be programmed with tect long-term keys, and allow provisioning and credential lifecycle multiple profiles, enabling them to be used with different carriers or management via remote IoT security services. IoT SAFE’s primary networks. eSIMs can also be remotely provisioned, activated, and characteristics that enable the secure provisioning of IoT devices are as Fig. 3. eSIM Programmable elements.
328P. Krishnan et al. C o m p u t e r C o m m u n i c a t i o n s 216(2024)324–345 Fig. 4. IoT SAFE eSIM architecture
follows: solution in IoT devices. It enables secure, remote provisioning and activating IoT devices, eliminating the need for physical SIM cards. The • Identity and access management: IoT SAFE creates secure commu- eSIM also allows for flexible network selection and management, nication channels between devices and the network, assigning each enabling IoT devices to connect to different networks depending on the IoT device a distinct identity. This ensures that authorized devices location and availability of network coverage. eSIM-based identity and can only access the network and that their exchange data is secure. provisioning can also help address the challenges associated with IoT • Authentication and authorization: IoT SAFE offers robust techniques security. The eSIM enables secure authentication and identity manage- for preventing unauthorized access to IoT networks and devices. ment, which helps prevent unauthorized access and data breaches. The Digital keys, certificates, and other security measures are included to eSIM also allows for secure and encrypted communication between guarantee that only permitted parties may access the network and devices, which helps protect against data tampering and interception.
the data. The lightweight m2m communication protocol developed by Open • OTA provisioning: IoT SAFE allows devices to be remotely set up and Mobile Alliance (OMA) is an open standard for fulfilling the re- updated with security updates and firmware, thanks to OTA provi- quirements of mobile low-power devices with very little processing sioning. This ensures that gadgets constantly use current security power. This protocol is being rapidly accepted for device management standards and are safe from dangers. and service activations amongst telecom carriers.
• Secure boot and firmware update: IoT SAFE provides secure boot and The deployment of TinyML eSIM-based IoT devices in the 5G/6G firmware update mechanisms that only authenticated and autho- networks can have multiple approaches:
rized firmware can be loaded onto devices. This prevents malicious firmware from being installed on devices and compromising their • Over-the-Air (OTA)Approaches. Flashing Over-the-Air (FOTA) up- security. dates are commonplace in resource-abundant situations, and there • Secure storage and processing: IoT SAFE ensures that IoT data is have been attempts to democratize TinyML in an OTA fashion. OTA securely stored and processed. This includes data encryption at rest updates provide the ability to resolve bugs and security vulnerabil- and in transit, secure storage of encryption keys, and secure data ities identified post-deployment or even support completely different processing. functionality • Federated Learning model - the research in TinyML has led to Overall, IoT SAFE provides a comprehensive and robust security breakthroughs in Reformable TinyML, i.e., TinyML solutions that can framework that enables the secure provisioning of IoT devices. By improve themselves via local or OTA updates. The edge devices delivering unique identities, authentication and authorization mecha- update the parameters of a shared model on board, send the local nisms, OTA provisioning, secure boot and firmware update, and secure versions of the updated model to a server, and receive a common and storage and processing, IoT SAFE ensures that IoT devices are protected robust aggregated model without the data ever leaving the edge against a wide range of security threats. devices.
• Task Offloading: On/off-loading of computational tasks can be har- nessed during edge-enabled machine learning scenarios. Such
2.3. eSIM-based secure identity and provisioning for IoT loading strategies should be an add-on to the existing dynamic configuration of edge-aware specifics. By doing so, TinyML can Earlier research has shown that eSIM can provide several benefits for empower the transfer of resource-intensive jobs from the resource- IoT, including reduced complexity and cost of device management, frugal edge devices.
improved security, and greater flexibility. The work in Ref. [1] found that eSIM can reduce the cost of device management by up to 50 % The profiles used on SIMs can be provided in many formats, compared to traditional SIM card provisioning methods. The study also including UXP, ASN.1, and even Excel spreadsheet, where UXP based on found that eSIM can improve security by providing enhanced tamper XML is the most often used format. The language is called SIM Profile resistance and secure data exchange between devices and networks.
Mark-up Language. SM-DP is a platform for storing and delivering dig- eSIM can offer greater flexibility and scalability for IoT deployments, ital eSIM Profiles. The platform protects Profiles using Profile Protection allowing network operators to quickly provision and manage many Keys, which are maintained in a repository and are associated with devices. The eSIM provides a viable, secure identity and provisioning 329P. Krishnan et al. C o m p u t e r C o m m u n i c a t i o n s 216(2024)324–345 Endpoint Identifiers (EID). SM-DP +binds these supported Profiles to executed in stages when the IoT device arrives on-site: (1) Technicians their corresponding EID and securely downloads them to the associated install and turn on the IoT device; Manual configuration and provi- eUICC’s Local Profile Assistant (LPA). SM-DP also executes Remote sioning of devices are done; IT backend accepts IoT device credentials Profile Management activities, such as profile enabled, disabled, or manually and connects to the device management system; IoT device deleted remotely. LPA of eSIMs is a digitalized solution. LPAs are starts working and configures devices for provisioning. Zero Touch helps functional components that offer the LPD (Local Profile Download), LDS reduce human errors and delays during the deployment of Io devices. It (Local Discovery Server), and LUI (Local User Interface) capabilities in also reduces travel costs and workforce requirements and allows field Devices (LPAd) or the eUICC (LPAe). These capabilities are necessary to technicians to focus on other operational tasks like preventive and ensure that the device supports the Discovery server function and the reactive maintenance work.
Profile Download in the eUICC and that the user may manage their eSIM The Zero-Touch feature is attractive because the IoT devices are through the interface on the device. The Device is a user equipment that automatically installed without needing a specialized IoT technician to connects to a mobile network via an eUICC. Remote SIM Provisioning be available in the field. Therefore, Zero Touch can streamline IoT de- can be a smartphone or a handset, but it can also be a companion device vices’ installation and commissioning process. For example, when a new that depends on the capabilities of the primary device. Fig. 5 depicts the IoT device is installed, such as a thermostat, the user switches it on and architecture of the provisioning of eSIMs. connects to the environment. The device network automatically verifies the service pre-loaded into IoT devices. On verification of the service and required authorization, the platform starts measuring dataflows based
2.4. Blockchain integrated secure zero-touch service provisioning on the usage of the IoT device, and the service enabled in the IoT device gets integrated into the e-service provider’s network system. Zero Touch Blockchain-based eSIM management for IoT provisioning is a saves time, effort, and cost, making it a highly desirable solution that decentralized approach to eSIM management that uses blockchain benefits industries that depend on IoT, including the oil and gas sector, technology to provide secure storage, tracking, and authentication of smart buildings, smart factories, smart airports, and smart cities. Zero eSIMs. Each eSIM is registered on a blockchain network, which allows Touch helps reduce human errors and delays during the deployment of for secure and tamper-proof storage and monitoring of the eSIM IoT devices. It also reduces travel costs and workforce requirements and throughout its lifecycle. Blockchain-based eSIM management provides allows field technicians to focus on other operational tasks like pre- several benefits for IoT provisioning. First, it provides a secure and ventive and reactive maintenance. The Zero-Touch feature is attractive decentralized solution for eSIM management, reducing the risk of because the IoT devices are automatically installed without needing a centralized attacks or data breaches. Second, it allows for more efficient specialized IoT technician who has pre-loaded the IoT device during the and secure tracking of eSIMs throughout their lifecycle, reducing the risk manufacturing stage. After verification of the service and required of lost or stolen eSIMs. Finally, it provides a more transparent and authorization, the environment starts measuring dataflows based on the auditable solution for eSIM management, allowing for greater usage of the IoT device, and the service enabled in the IoT device gets accountability and traceability. However, there are also some challenges integrated into the billing system of the service provider’s network.
associated with blockchain-based eSIM management. For example, blockchain networks can be slow and require significant computational resources, which could affect the speed and efficiency of eSIM provi- 2.5. Challenges of using eSIMs for securing IoTs sioning. Additionally, the decentralized nature of blockchain networks can make it challenging to coordinate and manage eSIMs across different eSIMs-based identities and provisioning present opportunities for network operators and service providers. The goal for managing the innovations and growth of ecosystems using IoTs. For example, eSIMs overall IoT device life cycle is to set up each IoT device (short-range and can enable new business models and revenue streams for service pro- long-range) to communicate with its intended destination. The instal- viders like pay-on-use subscriptions and dynamic network selections.
lation and configuration of each IoT device and actuator is a painfully eSIMs also facilitate adopting new applications in IoTs, like connected long experience that requires field specialists’ significant efforts and vehicles and smart homes or cities. A study by ENISA (European Union technical knowledge. The IoT device manual provisioning process is Agency for Cybersecurity) dives deep into eSIM technology’s security Fig. 5. Architecture of eSIM provisioning.
330P. Krishnan et al. C o m p u t e r C o m m u n i c a t i o n s 216(2024)324–345 challenges. The report identified challenges associated with software monitoring synergizes network management with device behavior in- attacks like bloated and locked profile assaults, memory exhaustion and sights. This results in a more efficient, responsive, and adaptable undersized memory exploits, and eSIM swapping. Cybercriminals have network that can handle the dynamic demands of IoT ecosystems, ulti- the potential to disrupt services or obtain confidential data. Even though mately enhancing overall system performance and efficiency.
there have only been a few recorded cybersecurity issues, widespread IoT deployments and the associated growth in the usage of eSIMs might 3. Review of related work cause an increase in cyber events. Significant problems in the provi- sioning and administration of devices, which may be time-consuming Several prior works have proposed solutions to address the chal- and expensive, are the root of IoT implementations. A difficulty to be lenges of secure service provisioning in AIoT networks. Some have considered in security designs is the secure provisioning of services to suggested solutions based on Public Key Infrastructure (PKI), which devices, where service provisioning refers to procedures for granting enables secure authentication and encrypting messages between de- access to services, including data, applications, and updates to devices. vices. However, PKI-based solutions may need to be more scalable and Traditional service provisioning mechanisms require human in- efficient, as they require a centralized authority to manage the keys and terventions, which can be time-consuming, costly, and error prone. certificates. Other studies have proposed solutions based on blockchain Moreover, human intervention increases the risk of attacks and com- technology, which enables decentralized and secure communication and promises the security of networks. eSIMs are considered an alternative storage of data. However, blockchain-based solutions may be too com- to stem these issues. Another critical challenge in the use of eSIMs is a plex and resource-intensive for AIoT networks, as they require signifi- common standard. Lack of standardization in eSIM technology can lead cant computational resources and may introduce latency in the to interoperability issues between different devices and networks. communication between devices. The usage of eSIMs in applications of Securing reliable OTA management requires robust security protocols IoTs is a rapidly developing area of research. eSIMs are generic terms and infrastructures, which can be complex to achieve in remote or used for eSIMs housed on small chips that offer digital storage for mobile challenging environments. subscribers. These SIMs can be used to identify subscribers in various goods, such as wearable technology, PCs, security systems, and mobile
2.6. SDN orchestration and IoT device lifecycle management operator networks. POS (point-of-sale) devices and IoTs. Studies have shown that eSIM can provide several benefits for IoTs, including reduced The integration of Software-Defined Networking (SDN) orchestra- complexity and cost of device management, improved security, and tion and IoT lifecycle monitoring offers several benefits that signifi- greater flexibility. The researchers in Ref. [15] detailed the de- cantly contribute to the overall performance and efficiency of IoT velopments of eSIMs as roles and trust amongst telecom organizations.
systems: The study outlined several gaps in the repartitioning of responsibilities between telecom operators and supply chains. • Dynamic Network Management: SDN allows for centralized An architecture employing eSIM and the advantages of using eSIMs management and control of network resources. By integrating SDN in IoTs were examined in the study [16]. Emergency calling systems with IoT lifecycle monitoring, you gain the ability to dynamically ushered in a new era of connectivity in automobiles. They support a allocate and optimize network resources based on real-time IoT de- wide range of applications, including managing temperatures inside vice demands. This flexibility ensures efficient network utilization, cars, fuel alarms, alternate route navigations, vehicle tracking, security enhancing overall performance. alarms, and driving information. eSIMs-linked automobiles were studied • Traffic Segmentation and Prioritization: SDN enables traffic seg- in Ref. [17]. Although using eSIMs looks simpler for customers, mentation and prioritization. Integrating it with IoT lifecycle moni- increasing their market shares is not guaranteed. The study in Ref. [18] toring allows identifying and prioritizing IoT-related traffic. Critical assessed if consumer eSIM solutions for smart products were feasible.
data from IoT devices can be given higher priority, ensuring Distribution centers might connect intelligent items to private networks smoother and more efficient communication. and get specialized services. The study’s experiments for smart product • Enhanced Security: With SDN, security policies can be centrally switching across IoT networks were successful. The study found that managed and enforced across the network. When combined with IoT local eSIM operations with pre-loaded profiles minimized service out- lifecycle monitoring, detecting anomalies or potential security ages and were favored over regular M2M eSIMs that needed OTA threats in IoT devices becomes easier. This integration allows quicker signaling.
responses to security breaches or policy violations, bolstering overall To increase effectiveness, subscribers’ personal information was system security and efficiency. stored with service providers instead of eSIM. The study in Ref. [19] • Optimized Resource Allocation: IoT lifecycle monitoring provides focused on eSIMs. eSIMs allow consumers to switch carriers without insights into the behavior and performance of IoT devices physically moving, making it beneficial to security systems. Since in- throughout their lifecycle. Integrating this information with SDN formation theft can occur, systems must impose strict evaluations and allows for more informed decisions on resource allocation. For differentiations of IoT and non-IoT devices. The study in Ref. [20] example, resources can be dynamically allocated based on device examined the effects of eSIM on the trust dynamics among telecom behavior patterns to optimize performance and efficiency. sector players. To promote the use of eSIM technology, the research • Scalability and Flexibility: SDN’s agility in reconfiguring networks identified several gaps in repartitioning duties between operators and aligns well with the dynamic nature of IoT ecosystems. The inte- providers based on real-world instances.
gration allows for scalability as IoT device numbers grow or change. Blockchains are distributed, unchangeable ledgers that make it easier This adaptability ensures that network resources can be efficiently to record transactions and monitor assets in commercial networks.
adjusted to accommodate new devices without compromising Intangible assets, such as intellectual property, patents, copyrights, and performance. trademarks, can be as tangible as a house, vehicle, cash, or land. On • Proactive Maintenance: Potential issues or failures can be pre- blockchain networks, almost anything of value may be recorded and dicted by monitoring the IoT device lifecycle. When integrated with sold, lowering risk and increasing efficiency. Businesses depend on the SDN, this data enables proactive maintenance and resource alloca- information, and timely and accurate information retrieval enables tion adjustments to prevent or minimize downtime. It ensures that smarter judgments. Blockchains are the right technologies for delivering the network is continuously optimized for performance. secure information because they offer instant, shareable, and fully transparent data recorded on immutable ledgers that network users can In summary, the integration of SDN orchestration and IoT lifecycle only view with permission. Among other things, a blockchain network 331P. Krishnan et al. C o m p u t e r C o m m u n i c a t i o n s 216(2024)324–345 can monitor orders, payments, accounts, and production. Blockchains between dependability, confidentiality, and efficiency within the sys- can be operated in permission or non-permission modes. IoT devices are tem. In situations when there is heavy traffic, this module works better mere players in blockchains or smart contracts with access via Edge than traditional methods [29]. The study in Ref. [30] designed IoT se- switches. The gateways for devices in IoTs save manifests for devices’ curity, including layers in design, namely, perception, network, and networks which are then used to control blockchain deployments. In application. The study concentrated on current disadvantages in access SDN-enabled Pervasive Edge Computing (PEC) environments, block- control mechanisms which were indicators for IT companies to work on chains are used for authenticating identities of IoT devices [21] and present authentication drawbacks and securing future IoT environ- introduce distributed security platforms with edge clouds and SDN ments. NB-IoT (Narrow Band-Internet of Things) cellular wireless capabilities. network standard, which fulfilled several critical IoT needs, as detailed To track the resource usage of IoT devices, EdgeChains in Ref. [22] in the book [31].
used a “credit-based resource management” architecture underpinned NB-IoT is stimulating the industry to develop new use cases and by static criteria (such as “priority, application type, access pattern related products. The authors described how IoT devices (such as sen- history”). Device-to-device communications were recorded and stored sors) are designed to run anywhere and for more than ten years without on blockchains to protect the Internet of Things. In Ref. [23], a maintenance, using NB-IoT’s enhanced network coverage and excep- blockchain-based IoT device identity authentication system was pro- tional power-saving capabilities. Industrial users may use the book to posed. Blockchains stored information on device identities, and the learn how to leverage NB-IoT capabilities for their IoT projects. Also Blockchain of Things (BCoT) Gateways recommended in the study could included are additional system components (such as IoT cloud services) record authorized transactions. To determine device models, the study and embedded security issues. The author examines NB-IoT in-depth looked at traffic patterns. Existing solutions do not support intelligent from the perspective of application engineering, concentrating on IoT control in IoT settings because they rely on specific controllers or pro- device development. To decrease the computational complexity of se- grams to control IoT devices remotely. curity protocols in many IoT devices, a 5G Authentication and Key A viable alternative is using a single gateway device, like a smart- Agreement (AKA) protocol based on upgraded symmetric keys was phone, to manage many IoT devices. However, it might be challenging presented in Ref. [32]. The improved version of Braekens’ protocol was to ensure security when handling the management of IoT devices. SDN- created to provide forward secrecy by modifying the shared key for enabled gateways [24] provide dynamic network traffic flow manage- low-cost Internet of Things devices. According to the research, the ments that support defense mechanisms against assaults by identifying developed model was immune to the Linkability of Failure Messages and preventing suspicious network traffic flows. A developing IoT (LFM). The protocol was nonetheless susceptible to DoS assaults. Plat- network might be jeopardized by poorly managed devices and flawed form architecture for deploying zero-touch Pervasive Artificial firmware upgrades, and eSIMs combined with other IoT devices are Intelligence-as-a-Service (PAIaaS) in services with blockchain smart becoming increasingly popular. IoT SENTINEL was created in Ref. [25] contracts was proposed in Ref. [33].
to identify various IP-based IoT device types connected to networks. The PAIaaS standardized Pervasive AI at all levels and unified the This study’s device model and software version establish the kind of interfaces to facilitate service deployment across application and infra- device, and passive network traffic monitoring was used to identify the structure domains. FL-as-a-service was used as a use case to evaluate the device type. For feature engineering, a total of 23 packet character- model’s effectiveness. This showed the model’s ability to self-optimize istics—all of which were generated from encrypted data and indepen- and adapt to the 6G network dynamics. However, the smart contract dent of packet content—were used. According to the author, the agents only gradually figured out the best course of action for delivering recommended method can correctly identify devices with little the service. The work in Ref. [34] demonstrated a blockchain-based, overhead. IoT-embedded voting D-App that is safe and anonymous. Privacy was In a smart grid for device management, IoT devices are identified and safeguarded by preserving vote secrets and preventing corrupted au- registered using blockchain [26]. The consensus was also investigated in thorities from forging votes. By achieving privacy and verifiability, the the system. Based on transactions that users upload to blockchains, designed protocol was proven effective. In Ref. [35], a zero-touch hackers may use machine learning techniques to de-anonymize them. management approach for IoT based on Digital Twin (DT) technology Obfuscations anonymize user identities based on transaction histories in was proposed. DT was represented using ontologies and knowledge blockchain-based IoT applications since IoT devices execute trans- graphs, and IoT elements were mapped onto them.
actions in timely patterns, and obfuscations of timestamps are utilized to The DT scheme offered a solution for the device management disrupt these unwanted patterns, resulting in reduced informed and problem under zero-touch management through the example. However, blind assaults [27]. Blockchains created distributed authentication sys- zero-touch management still needs to optimize the networks, which tems in which smart contracts stored users’ wallet addresses and IDs to might pose problems for IoT network provisioning. In the work in enable login to apps following authentications. This process took a bit Ref. [36], a simple IoT device identity privacy method in a 5G network longer than usual because of the volume of transactions on Ethereum. was implemented. The deployed algorithm, HashXor, only needed the According to testing results, the suggested technique was highly effec- IoT device to do two hash and three Xor operations. The examination of tive at preventing attacks like man-in-the-middle, impersonation, execution times showed that HashXor was computationally effective.
replay, and denial-of-service (DoS) [28]. However, IoT devices with insufficient resources were only subjected to To address these security issues and improve the robustness of the 5G light computation. In Ref. [37], a transparent third-party approach network, authors of [47] introduced the Secure Blockchain-based based on proxy-based federated authentications was suggested for Authentication and Key Agreement for 5G Networks (5GSBA); using cloud-edge federations. The transparency in the federated paradigm blockchain [52] as a distributed database, our 5GSBA decentralizes enables the edge and cloud operators to install the built proxy. Ac- authentication functions from a centralized server to all base stations. It cording to experimental findings, federated edge-to-cloud and can prevent single-point-of-failure and increase the difficulty of DDoS cloud-to-edge authentication using a proxy-based concatenation of attacks. In this article [48], the authors present a comprehensive intel- authentication protocols can shorten authentication times. However, the ligence and secure data analytics framework for 5G networks based on third-party authentication made the system vulnerable to insider as- the convergence of Blockchain and AI named “Block5GIntell”. saults. The work in Ref. [38] presented a low-cost client-side encryption For Industrial IoT (IIoT), a private blockchain-based trusted anony- method for secure IoT provisioning.
mous access architecture [53]is recommended, where trusted access is The strategy employed an inexpensive algorithm based on the supplied by three different types of SoftwareDefined Networking (SDN) Advanced Encryption Standard (AES) and ATECC608 tamper-resistant controllers. A particular module is designed to offer a balanced trade-off keys. According to the paper, the IoT device is securely provided to a 332P. Krishnan et al. C o m p u t e r C o m m u n i c a t i o n s 216(2024)324–345 cloud platform. But with the ATECC608, altering any secret keys may end security for IoT devices, including secure provisioning.
lead to further security problems. The SIM Profile Transparency Protocol Table 1 provides a brief overview of the existing works in this field
(SPTP), developed in Ref. [39], aims to detect fraudulent SIM profile and explains the Key findings, limitations, or gaps that the proposed provisioning. The SPTP included the Private Index Calculator (PIC) and framework aims to address.
Transparency Ledger (T) for the authentication process. A security investigation showed subscriber privacy was offered based on IMSI 4. Proposed SIeSIM solution permission. Due to the attestations’ reliance on reliable notaries, the system architecture took time. For IoT devices with firmware, the work The proposed SIeSIM solution is an integrated framework combining in Ref. [40] advocated provisioning, authentication, and secure blockchains, eSIMs, IoT-SAFE protocol, and SDNs to manage the security communication techniques. To address this, the YubiAuthIoT identity of IoT ecosystems. Future IoT devices with eSIM are simple to set up, management and authentication technique was created. The overall validate profiles, and check security policies. Blockchains are utilized in provisioning ran more slowly than usual. The model’s flaw was that the SIeSIM’s IoT onboarding procedures, where Ethereum smart contracts IoT nodes weren’t monitored once provided. may validate an immutable repository used to store network manifests.
In summary, related works of eSIMs in IoT highlight improved se- To control the security of IIoT ecosystems, the integrated framework curity, reduced device complexity/costs, and remote management ca- incorporates Software-Defined Networking (SDN), eSIM-based remote pabilities. Challenges in adopting eSIMs include interoperability and SIM provisioning, and blockchain contracts. Fig. 6 depicts the workflow standardization issues, limited vendor support, and the complexity of of the proposed scheme.
IoTs. Blockchain technology provides several advantages, such as distributed consensus, tamper-proof records, and enhanced security.
However, limitations that need to be addressed include the scalability 4.1. Approach to realizing the solution and interoperability of blockchain-based solutions. In terms of provi-
sioning: eSIMs, blockchains, and secure communication protocols pro- Innovative approaches could lead to more efficient eSIM-based vide m efficient security solutions. However, challenges stem from secure provisioning for IoT devices, and specific examples of the same lightweight and efficient authentication protocols, greater interopera- are detailed below.
bility, and network coordination. IoT SAFE protocol can provide end-to- • Blockchain-based eSIM management: Using blockchain technol- ogy could provide a secure and decentralized solution for eSIM Table 1 management. Each eSIM could be registered on a blockchain A summary of related works.
network, providing secure storage, tracking, and authentication of Publication Key Focus Key Findings the eSIMs. This approach could reduce the need for a centralized Almadhoun Integration of blockchain •Presents IoT SAFE authentication eSIM management platform and provide a more secure and efficient et al. [3] for IoT security protocol using blockchain for IoT solution.
•Decentralized trust and • Machine learning-based access control and Edge Gateway: Ma- transparency benefits chine learning algorithms could be used at the gateway (with heavy Yadav, S. et al. IoT SAFE protocol •Presents the IoT SAFE protocol processing and communication resources) to analyze and learn ac-
[8] architecture and features and its key features •Highlights secure identity cess patterns of IoT devices, which could be used to establish access management and authentication in control policies. The resource-constrained 5G devices can offload the IoT SAFE architecture more compute-intensive operations and security processing to the Ahmed A et al. Security Analysis of the •Provides an in-depth analysis of gateway or edge servers. This approach could provide more efficient
[12] Remote SIM Provisioning IoT security challenges •Explores the application and and accurate access control by detecting and predicting access pat- benefits of the IoT SAFE framework terns, reducing the risk of unauthorized access.
in addressing IoT security concerns • Multi-party computation-based credential sharing: Multi-party Silva et al. IoT SAFE framework for •Proposes an architecture for computation (MPC) could be used to share eSIM credentials
[14] secure IoT device lifecycle secure provisioning and securely among multiple devices. This approach would allow for management management of IoT devices using IoT SAFE more efficient and secure sharing of credentials without exposing the •Addresses secure bootstrapping, credentials to any individual device. This could reduce the risk of authentication, and secure credential theft and provide a more efficient and secure method of communication in the IoT SAFE credential sharing.
framework Thatte et al. Opportunities and •Discusses challenges of eSIM • Artificial Intelligence on the Extreme Edge: With the eSIM-
[16] challenges of eSIM in IoT adoption in IoT empowered SoC on the IoT device, we enable onboard ML on •Privacy concerns and microcontrollers, turning them from simple data harvesters to standardization challenges learning-enabled inference generators and on-device analytics for a Apilo et al. eSIM-Based Mobility •Provides an in-depth analysis of variety of sensing modalities (vision, audio, motion, identification,
[18] Solutions for Advanced Cellular IoT eSIM solutions Smart Products •Explores the application and etc.). The security and privacy benefits of using local machine benefits of the IoT SAFE framework learning are considerable.
in mobile IoT devices • Lightweight cryptography-based eSIM provisioning: Lightweight Gaber et al. Study on eSIM-IoT SAFE- •Presents an experimental cryptography algorithms could be used to reduce the computational
[20] based solution for Smart evaluation of IoT SAFE-based Cities secure provisioning of IoT devices burden of eSIM-based secure provisioning for IoT devices. Using •Assesses the performance and more efficient and lightweight cryptography algorithms could make security aspects of the provisioning the eSIM provisioning process more efficient and faster, reducing the process using IoT SAFE time and resources required for eSIM provisioning.
Gong et al. Blockchain-based IoT •Authentication framework with
[23] Identify management Blockchain for IoT Devices Identity •Benefits of immutability and These potential approaches could lead to more efficient and secure distributed consensus in securing eSIM-based secure provisioning for IoT devices. Further research and Identity and Management (IAM) development in these areas will be necessary to determine their feasi- processes bility and effectiveness.
333P. Krishnan et al. C o m p u t e r C o m m u n i c a t i o n s 216(2024)324–345 Fig. 6. Proposed workflow of SIeSIM Framework
4.2. Architecture Cellular service providers. The registrations and authentications of these devices on service providers are executed using blockchains running on These potential approaches could lead to more efficient and secure SDNs. Controllers of SDNs are responsible for these connections and eSIM-based secure provisioning for IoT devices. Further research and authorizations where corresponding service providers are connected to development in these areas will be necessary to determine their feasi- SDNs. Authorized devices are then registered, and provisioning hap- bility and effectiveness. This work’s proposed architecture of the SIeSIM pens. Once provisioned, these devices are monitored continuously, solution is depicted in Fig. 6 and detailed below. IoT devices have eSIMs where the details are retrievable from blockchains. Unauthorized con- that are IoT SAFE protocol enabled and implemented in their hardware. nections/intrusions are detected and avoided to stop network damage.
A new device connects to IoTs using their primary service provider, like The technological integration is built upon the modular identify service, Fig. 7. Architecture of SIeSIM framework.
334P. Krishnan et al. C o m p u t e r C o m m u n i c a t i o n s 216(2024)324–345 where we made use of the built-in certificate request clients in IETF RFC provides a secure interface for the device manufacturer or IoT 7030 Enrollment over Secure Transport, ISO/IEC 11889 Trusted Plat- service provider to remotely control the eSIMs, including form Module (TPM), and PKCS#11 interface standards. Fig. 7 shows the updating credentials and certificates and managing access architecture of the proposed scalable and secure zero-touch schema, policies.
known as the SIeSIM Framework. 3. Security gateway: The security gateway acts as a secure inter- How does it work? Thanks to the Secure IoT Registry with Block- mediary between the IoT devices and the cloud services. It en- chain, generic IoT devices can safely connect to the appropriate re- forces access policies and provides secure communication sources. The IoT Registry offers zero-touch IoT device registration, between the devices and cloud services. The security gateway activation, deactivation, transfer, and deletion through digital certifi- authenticates the devices using their eSIMs and provides secure cates. A security applet on the eSIM creates and saves the public and end-to-end communication between them and cloud services.
private key pair on the SIM. To manage these certificates, we employ 4. SDNs: SDNs provide backend processing and storage for IoT data asymmetric keys. The private key never leaves the SIM. An IoT device generated by devices. They also provide the necessary APIs for securely registers to the relevant MNO and receives provisioning with devices to communicate with SDNs securely.
the mobile network operator (MNO) profile when powered on for the 5. IoT Device: This component represents the physical IoT device first time. The IoT security applet receives a request to create a public/ that needs to be securely provisioned. The device is equipped private key pair over the air. The MNO receives the public key and with an eSIM and securely communicates with the IoT platform creates a certificate signing request. The ASP registers an IoT device by using the IoT SAFE protocol.
giving the eID, MNO id, and any other pertinent data. A registry payload 6. IoT Platform: This component represents the cloud based IoT is built using this data. platform that manages IoT devices. The platform is responsible The registry payload is safely transferred to the IoT device thanks to for securely provisioning the machines, managing their identities, establishing a trusted relationship with the MNO. The IoT device gen- and providing secure communication channels for data exchange.
erates a fresh public/private key pair. The IoT registry receives the IoT 7. IoT SAFE Services: This component provides the core security device CSR from the MNO for signing. The MNO and the ASP receive the services required for secure IoT device provisioning, including signed cert from the registry. The signed CERT is delivered to the IoT device identity management, authentication and authorization, SIM by the MNO. The activation occurs when the ASP endpoint is OTA provisioning, and secure storage and processing of data.
created, the private/public key pair is generated, and the client certifi- 8. Blockchain: This component represents the distributed ledger cate is sent to the eSIM. technology that provides a tamper-proof record of device iden- In the SIeSIM Framework, eSIMs loaded with necessary profiles also tities and transactions. The blockchain securely stores device have IoT SAFE installed on the attached device. On entering IoTs, they identities and transaction history, ensuring the data cannot be first contact their cellular service providers over the air, where the de- modified or tampered with.
vices pass through an IoT security server with an IoT SAFE module 9. Identity and Access Management (IAM): This component pro- installed. The machines are registered, activated, and provisioned vides an IoT platform’s centralized identity and access manage- through controllers of SDNs, which use blockchains or cloud service ment system. It manages the authentication and authorization of providers based on the networks the device connects to. The security IoT devices, users, and applications and ensures that only controller verifies necessary elements of authorizations like digital cer- authorized entities can access the IoT platform and data.
tificates at the back end before devices can log on and access IoTs. The 10. Security and Compliance: This component provides the necessary
proposed architecture offers several advantages: security and compliance controls to ensure the IoT platform and devices comply with relevant security and privacy regulations.
1. Improved security: ESIMs provide a secure identity and authentica- This includes regular security assessments, vulnerability scan- tion mechanism for IoT devices, reducing the risk of unauthorized ning, and compliance audits.
access and data breaches.
2. Simplified device management: The eSIM management platform al- The security gateway provides a safe intermediary between IoT de- lows for remote provisioning and management of the eSIMs, vices and cloud services. It enables a secure connection between the reducing manual intervention and simplifying device management. devices and cloud services and enforces access controls. The security
3. Scalability: The architecture is highly scalable, allowing for deploy- gateway allows secure end-to-end communication between the devices ing many IoT devices with eSIMs. and cloud services and authenticates the devices using their eSIMs.
4. Standardization: The architecture can be implemented using stan- dardized eSIM technology and protocols, ensuring interoperability 4.4. Authentication and provisioning sequence and compatibility with other systems.
The fluxes between the various components are shown in Fig. 8. To Overall, this architecture provides a comprehensive and robust confirm the endpoints’ legitimacy when an IoT device wishes to connect framework for the secure provisioning of IoT devices using the IoT SAFE with them, the Endpoint device has to be provisioned before any com- protocol and blockchain technology. By providing secure identity munications may be transmitted to Orion. The Endpoint devices (which management, authentication and authorization, OTA provisioning, and may number in the multiples) are provided by the City Manager (root secure storage and processing of data, the architecture ensures that IoT CA). The following device to be supplied is the user/company manager devices are protected against a wide range of security threats. (sub-CA) overseeing and authenticating their subset of IoT devices. The user or enterprise management then provisions the IoT devices.
4.3. Overview of the Components
4.5. Profile activation
1. IoT devices with eSIMs: Each device is equipped with an eSIM, securely provisioned with the necessary credentials and certifi- In eSIM, multiple profiles can be integrated into a single eSIM. By cates. The eSIM provides secure identity and authentication for doing this, the user can switch carriers (i.e., Mobile Network Operators).
the device, enabling it to communicate securely with other de- The activation user profile is mathematically denoted as, vices and cloud services. E user[p 1,p 2,….,p n]orp q,q=123….,n (1)
2. eSIM management platform: The eSIM platform is responsible for securely provisioning and managing the eSIMs on IoT devices. It 335P. Krishnan et al. C o m p u t e r C o m m u n i c a t i o n s 216(2024)324–345 Fig. 8. SIeSIM authentication to provisioning sequence diagram.
Where is the authenticated eSIM user? Field pn depicts the nth profile phase, the eSIM is registered on the blockchain network, which provides activated in the eSIM. a unique identifier and public key for the eSIM. The private key is stored
Key generation: During the activation of the profile in eSIM, a key is securely on the eSIM hardware, while the public key is stored on the generated with the Montgomery Curve Master Key-based Elliptic Curve blockchain network. During the eSIM activation phase, the eSIM is Cryptography (MCMK-ECC). The ECC is selected here due to its activated by the network operator or service provider. The activation enhanced security with higher-speed encryption. But, the ECC has the process involves sending a request to the blockchain network, which vulnerability to exploitation of public parameters. Thus, to avoid this verifies the authenticity of the eSIM using its public key. Once the eSIM problem, the Montgomery Curve and Master Key (MCMK) are intro- is authenticated, it is activated and ready for use. Fig. 9 displays the duced in the ECC algorithm. bootstrapping procedure of devices in the Registration/Provisioning
Basepoint generation: For the key generation in the MCMK-ECC, a Phase. base point is selected from the Montgomery curve. The Montgomery As shown in Fig. 10, the initial bootstrapping of all smart objects (IoT curve [46]over a field I is given as, devices) involves authenticating and attesting each device in the deployment domain using the manufacturer-specific eSIM/IoT device M.u2=v3+v2+v (2) profiles. Attestation protocols must be used to stop leaking secrets, While M,N∈I is a constant parameter, v,u represents the u and v-axes, identities, and data. A new IoT device, system, or equipment gets certified as legitimate when onboarded into the network. It will deter- respectively. From the Montgomery curve equation, a base point b is mine whether this new gadget is suitable. The Blockchain Provisioning selected for the key generation process.
Manager and local domain policy manager produce the SxC contract.
Key generation: Initially, two private keys Field are randomly For instance, to be eligible for participation in a trusted cluster of IoT selected for the key generation. These private keys are prime integers devices, each vendor could need to successfully execute an attestation kept confidential between the subscriber manager and the eSIM user.
exchange and get a licensed/SxC smart contract and profile. The “eSIM- Then, with the base point and the private keys, the sharable public keys signature” is extracted from the profile by the provisioning manager.
are generated on both ends as, To provide authentication to the registered users, blockchain-based P 1=K 1..b (3) security is provided. A hash code is created and stored for authentica- tion in the blockchain, which is connected to the subscription manager.
P 2=K 2..b (4) The hash code is made with the Keccak Parallelism-based Argon 2 The field P1,P2 depicts the public keys generated at the eSIM user (KPA2) to enhance security and avoid brute force attacks. Argon 2 is a password hashing technique that provides better security than simple and subscriber manager side.
hashing algorithms. But, the absence of parallelism may lead to continuous iteration, which increases the hash code generation time.
4.6. Blockchain integrated secure zero-touch eSIM IoT provisioning Thus, to avoid this problem, the Keccak Parallelism is used in the Argon 2 hashing technique.
Blockchain-based eSIM management for IoT provisioning is a Input: Argon2 takes primary and secondary input to produce a decentralized approach to eSIM management that uses blockchain hashcode. The primary inputs are the message field (W)of length t(cid:0) bit technology to provide secure storage, tracking, and authentication of also known as password, which is given as, eSIMs. Each eSIM is registered on a blockchain network, which allows W= for secure and tamper-proof storage and monitoring of the eSIM throughout its lifecycle. The eSIM provisioning process can be divided \langleI,E,RI.b\rangle I,E,RI depicts the IMSI number, enrolment key, into eSIM registration and eSIM activation. During the eSIM registration and registration ID. The secondary input (ζ) contains nonce salt for 336P. Krishnan et al. C o m p u t e r C o m m u n i c a t i o n s 216(2024)324–345 Fig. 9. Bootstrapping procedure of devices in IoTs Fig. 10. eSIM Device Registration in the Blockchain Registry.
password hashing. The primary inputs are given by the user, which can round function. ϑ operates on 128-byte input, which is viewed as 16- have a length of 0 to 232-1 bytes byte registers,
Operation: KPA2 uses an internal compression function (Θ) with ϑ(B 0,B 1,…..B 7)=(F 0,F 1,…..F 7) (7) two 1024-byte inputs, a 1024-byte output, and an internal hash function (ϖˆλ())of BLAKE2 is applied. Where λ depicts the output hash length, Where B,F depicts the input and output of the Blake round function. The KPA2 follows the extract-then-expand concept. First, entropy from the compression function is Θ(E,C). For compression, the registers (Re)of message and nonce are produced by hashing it. The compression func- 16-byte (Re0,....,Re63)are computed with, tion in the KPA2 is applied after the keccak parallelism.
Keccak parallelism: The Keccak function has the initialization, Re=E⊕C (8) absorption, and squeezing stages. In the absorption phase, the t(cid:0) bit input message blocks are XORed with the first t(cid:0) bit of salt value, which The ϑ() is applied row-wise at first and then column-wise to get the compressed output. This process is given as, is given as, KP=W t⊕ξ t (6) Θ(E,C)→ϑRe→ϑv→ϑJ→J⊕Re (9) The resultant KP is interrelated with the function. After the entire Where Re depicts the row-wise resultant of Blake rounding, υ is the input message is processed, the compression takes place. resultant of column-wise Blake rounding. Then, the compressed resul-
Compression: The hash block compression is built on the Blake2 tant is given as Field.
337P. Krishnan et al. C o m p u t e r C o m m u n i c a t i o n s 216(2024)324–345
Resultant hash code: As the Keccak parallelism is introduced, the 5.1. Network setup compression is iterated fewer times than the argon hash. The final hashcode generated is given as, The simulations were conducted using the COOJA simulator, which is a network simulator that enables the evaluation of IoT networks. The ϖ[Bl nn]=J (10) experimental studies were performed using a set of AIoT devices and a Where Blnn signifies the hashcode generated at the nnth block. s Ae zr uv re er ’.
s W Ioe T’v e c lb ou ui dlt sa e rb ve is cp eo s.k e O I uo rT S g Iea Ste Iw Ma sy e t rh va ict e i sn t ie nr ta ec rt as c w t with it hM Aic zr uo rs eo ’f st
Blockchain: This hashcode J is stored in the blockchain as a trans- core application services and ensure policies are followed at the gateway action. Thus, the hashcode is verified whenever the eSIM user initiates level. Fig. 12 shows the lab setup.
the process. Other methods can be performed if the hashcode presented in the blockchain matches the hashcode generated on the user side. If the hashcode is unmatched with the hashcode in the blockchain, the process 5.2. Threat model initiated using the eSIM credentials will be declined. By doing this process, eSIM hijacking will be avoided, as the malicious user cannot get Components need to be evaluated for specific threat types [41,42] the profiles of the registered users. and analyzed using DFDs (“Data Flow Diagrams”) for identifying and mitigating threats. Recent vulnerabilities in Glibc, OpenSSL, and log4j
5. Evaluation logging libraries (popular Java applications) illustrate how components could expose entire systems. Using data flows, processes, and definitions To evaluate the proposed mechanism, we conducted simulations and in DFDs, the proposed SIeSIM solution is analyzed on STRIDE [43] experimental studies. Fig. 11 illustrates the complete end-2-end soft- framework. It also includes specific firewall rules at perimeters of de- ware-to-hardware stack implemented to realize the SIeSIM architecture ployments (to prevent external exploitations) and router rules in SIeSIM described in detail in the previous section. to protect against insider threats, administration errors, and Hardware misconfigurations.
• iSIM, IoT SAFE, Java app integrated SoC in device platform (smart 5.3. Evaluation methodology devices, gateway switches, routers, cellular modems) • eSIM, SoC- Chipset/modules for partners/device vendors/network Given that the duration of the provisioning process (time-to-provi- operators/service providers sion, TTP) is the single most important KPI. We evaluated and compared • 5G, NB- IoT and LTE-M RAN options are packed in a single IP Core/ the efficacy of our advanced SIeSIM provisioning framework with the design. IEEE 802.15.4 baseline [44,49,50] fairly and objectively. ZigBee or ZigBee/IEEE 802.15.4 protocols are wireless networking specifications Software encompassing hardware/software standard designs for wireless sensor networks (WSN), requiring high levels of reliability, lowered costs and • OS - iSIM OS power, scalability, and decreased data rates.
• SIM Management -Remote SIM provisioning solution • IoT Middleware API to support interactions with IoT Safe Applet on a 5.4. Performance analysis SIM. • Applets – IoT SAFE stack, applications This section will present the efficacy metrics of our proposed solu- • SDK/API for implementing/customizing the Applets, tracking, Fil- tion. The function of pre-condition and post-condition policy(ies) ters, Profiles configuration, as defined by the end-user or IoT application/middle- ware, will add some delay in the provisioning process. We ran a series of experiments and test tools to measure the following key performance Fig. 11. SIeSIM solution stack.
338P. Krishnan et al. C o m p u t e r C o m m u n i c a t i o n s 216(2024)324–345 Fig. 12. Laboratory system components. indicators of our solution. They are (1) Provisioning speed or latency, (2) 5.4.2. Throughput network bandwidth/throughput consumed, (3) resource usage (CPU/ Fig. 14 compares throughput with and without the SIeSIM service RAM), (4) Authentication efficacy, (5) eSIM provisioning Workflow operating on the IoT network. We used iPerf to monitor the network’s overhead, (6) runtime monitoring, and (7) anomaly detection (7), throughput while varying the number of postcondition policies (Block- blockchain processing overhead. We connected multiple gateways to the chain contracts). The increase in postcondition policies is mirrored in cloud during each experiment and provisioned Internet of Things (IoT) the bar graph by a corresponding decrease in throughput. As an devices to each gateway. These measurements are highly context- example, the throughput is 480 Mb/s with 400 policies. In contrast, dependent and may vary in other environmental contexts. throughput drops to 960 Mb/s when PCP is disabled.
5.4.1. Latency and device provisioning speed 5.4.3. Resource (CPU/memory) utilization Latency incurred to Device provisioning is the total time required to We will only consider CPU and heap memory usage to describe the autonomously establish connectivity and attest the allowed IoT devices system’s resource utilization by the SIeSIM services on the hardware into IoT edge networks and clouds. The procedures involve authenti- platform. Resource consumption depends most on system configuration cations, linking, and authorizations. There might be modest delays in and execution environment. Thus, this is a prototype system demon- overall device provisioning processes because of the implementation of stration, not a standard representation. We conducted ten experiments precondition policies to improve authentications. Fig. 13 displays la- with average resources. Fig. 15 shows that the number of policies (pre- tency/provisioning times as functions of device counts and necessary and post-condition) affects CPU and heap memory consumption. The policies of authentications. The provisioning time for devices was application used 1250 MB of heap memory and 89 % CPU with 400 measured without SIeSIM, where it was found that it grew linearly with policies. IoT network gateway hubs use 35 % CPU and 127 MB heap device counts. SIeSIM increased provisioning latency logarithmically memory without SIeSIM services.
due to the executions of parallel threads inside its software architecture.
Manual: For 100 devices, it takes 240s and increases to 2650s with 5.4.4. Time-to-provision (manual/zero-touch) 1000 devices. When evaluating automated provisioning systems, we average the
With SIeSIM: Activating the Zero-touch automated provisioning results of 18 evaluation tests to determine TTP performance for the services, the provision time increases slightly due to the processing following situations (see Table 2). Furthermore, the manual provision- check, authentication, and blockchain overhead. With 100 devices, the ing scenario is divided into two cases: i) a single expert makes provision overhead is 120s; for 1000 devices and 400 pre-condition policy entries, across four evaluations, and ii) provisioning is done manually by an the provisioning delay is 1300 s. This result demonstrates that the pro- expert human operator, with each operator doing a single evaluation posed architecture is feasible and can effectively reduce end-to-end test. The second option is desirable since a non-expert can master the delay relative to the baseline. provisioning rules and become an expert by the end of the assessment tests. As a result, we implemented this countermeasure to ensure the validity of the evaluation.
Fig. 13. Device Provisioning Scaling vs. Pre-Condition Policies (PCP). Fig. 14. Throughput vs. PCP scaling.
339P. Krishnan et al. C o m p u t e r C o m m u n i c a t i o n s 216(2024)324–345 Additionally, the suggested technique has a higher efficiency in energy utilization with increasing simulation time despite both algorithms having similar energy-utilization profiles.
Because IoT applications are employed in real-time systems, all processes must be completed as quickly as feasible. Fig 16 b) shows graphs that show the end-to-end delay versus the elapsed simulation time when the IEEE 802.15.4 protocol and the suggested SIeSIM tech- nique are simultaneously executed for 30 s. While the suggested tech- nique consistently exhibits a shorter end-to-end delay than the IEEE
802.15.4 protocol, we can observe that the end-to-end delays of both approaches converge with the simulation time. As a result, our concept offers adequate performance and effective communication between the routing devices.
5.4.6. Authentication and bootstrapping Fig. 17 a) demonstrates the delay for COAP-EAP bootstrapping Fig. 15. Pre/post condition policies vs. Resource usage (CPU, RAM). (authentication/provisioning) per IoT device. The average overall authentication delay for eSIM +Blockchain processing involves getting an eSIM profile from the IT server, translating it to IoT-SAFE policies, Table 2 confirming Blockchain compliance, and enforcing policy under normal Time-to-provision (TTP) evaluation results. and attack scenarios. The defense mechanism must process more when Evaluation Scenarios Manual Provisioning Zero-Touch SIeSIM the attack ratio increases from 0.1 to 0.9. The average provisioning time for a new node is around 1/9 of the open-source traditional IoT provi- Expert Non-Expert sioning strategy. Device authentication takes 4300 ms with the basic Average TTP [sec] 41 143 11 classical IEEE 802.15.4 scheme [44].
Best-Effort TTP [sec] 38 124 9 Worst-Effort TTP [sec] 52 187 14 Our SDN-based remote-SIM provisioning approach at the IoT gateway reduces overhead to 240–2000 ms for an exact number of packet exchanges. Our IoT-SAFE-based scheme can handle complex • Manual Provisioning: The device will be provisioned by one expert network configurations using the Over-The-Air (OTA) GSMA IoT-SAFE familiar with the provisioning procedures and by four non-experts protocol through cellular operators and advanced Cellular-IoT who have no prior knowledge of the provisioning procedures, Gateway hubs. The traditional IoT provisioning scheme (over CoAP/ following the detailed provisioning guide. In addition to the guide- EAP) uses a slower DSA signature generation method. We investigated lines, we provided each non-expert with a few introductory remarks IoT-SAFE and Blockchain-based contract compliance verification over- before beginning the provisioning process.
head with cellular IoT networks and eSIM devices utilizing comparable • Automated SIeSIM: To evaluate the SIeSIM- Zero Touch automated credential/access restrictions. The JSON-based tokens implemented in Provisioning solution with security procedures considered for the SIeSIM authentication protocol reduced metadata size by 25 % in exemplifying interoperability.
Fig. 17 b.
5.3.5. Energy consumption and delay
5.4.7. Workflow overhead Routing devices—generally speaking, networking compo-
IoT Device Enrollment: Cloud-IoT protocols like MQTT and CoAP are nents—consume significant energy during data transmission. In partic- used at the network’s periphery, known as the Edge. The time and effort ular, the device’s energy consumption is directly correlated with the put into the smart contract development and verification procedure did amount of data it transmits (i.e., the more bits it transmits, the more not appear to impact the system’s scalability, as shown inFig. 18 a.
energy it uses). We compare the IEEE 802.15.4 protocol [58] with the
Policy Violation Detection: Policy violation detection in IoT security is suggested SIeSIM in order to assess its energy usage. From Fig 16 a), It is critical for ensuring the integrity and safety of connected devices. When evident that compared to the IEEE 802.15.4 protocol, our suggested policies are violated, it can lead to various risks, including data algorithm uses less energy and can efficiently select the edge server.
breaches, unauthorized access, and potential damage to the IoT Fig. 16. a) Energy Consumption b) End-to-End delay.
340P. Krishnan et al. C o m p u t e r C o m m u n i c a t i o n s 216(2024)324–345 Fig. 17. eSIM-based Provisioning b) Blockchain Contract Registration.
Fig. 18. a) eSIM Enrollment delay b) Blockchain Policy Verification Scalability. ecosystem. sensor data, IoT gateways employ Rule-Based Monitoring. Implement- The impact of policy violation detection on IoT security is ing a rule-based system for monitoring and analyzing incoming data
multifaceted: against predefined policies can efficiently detect violations. However, managing a vast number of rules might impact processing speed. The
1. Risk Mitigation: Detecting policy violations helps mitigate risks by gateway checks real-time sensor data for rule violations. We determined identifying potential security breaches or unauthorized access in the time required for policy verification by altering the number of rules real-time. (beginning with a configuration of 5 rules). Resolution time scales lin-
2. Prevention of Compromise: It assists in preventing the compromise early with policy count (Fig. 18 b). of sensitive data or device functionalities, ensuring the overall integrity of the IoT network. 5.4.8. Blockchain processing overhead
3. Compliance: Maintaining compliance with industry standards and Ethereum’s unit gas represents computational work—Fig. 19 a shows regulations is crucial. Detection of policy violations helps ensure contract/transaction gas consumption. Transactions increase gas use.
adherence to these standards. Our method improved transaction throughput by 30 % and transaction time by 85 %. Gas consumption and processing time are similar (up to The relationship isn’t necessarily linear regarding resolution time 27 s) for transactions under 200. As transactions increase, gas con- scaling with the number of rules. The time required for resolution can sumption increases linearly while processing time remains constant. Our increase with the number of rules due to the complexity of analyzing and system is scalable since an SDN controller’s processing time is lower addressing multiple violations simultaneously. Efficiently managing a than the gas needed for a Blockchain transaction. Thus, our concept larger rule set may require more sophisticated algorithms and compu- combines high safety (Blockchain technology) with efficiency (opti- tational power, potentially leading to increased resolution times. mized SDN-eSIM IoT-SAFE architecture).
To detect rule violations efficiently and accurately in real-time Fig. 19 b shows the performance in terms of overall end-to-end delay Fig. 19. a) Blockchain Energy Consumption b) Delay with Number of Nodes.
341P. Krishnan et al. C o m p u t e r C o m m u n i c a t i o n s 216(2024)324–345 (in seconds). In detail, we compute the overall end-to-end delay in terms Table 3 of workloads and time delay by varying the number of nodes, notably, Overhead in Malicious eSIM Devices Scenario.
with a small number of nodes (i.e., ≤10), the end-to-end delay of our Scheme Computation proposal, and increasing the number of nodes, both end-to-end delays Cost (ms) show a linear increasing trend, with our proposal constantly out- P.G [22] 0.10 performing the baseline method. A.I [28] 0.14 S.J [36] 0.18
5.5. Security analysis SIeSIM [Proposed] 0.04 In the following sections, we’ll review different attack scenarios and discuss the security properties. Finally, we will detail how our proposed SIeSIM safeguards endpoints and the underlying network infrastructure by adapting attack case studies to real-world attack scenarios. Infor- mation security analysis data is also presented.
1) Security Properties, Defense Mechanisms and Attack Studies In this section, we present the results of an empirical evaluation of SIeSIM’s security features. In this article, we described SIeSIM’s security features. We provided case examples that illustrate those features in action. We conducted these case studies in real-time assault scenarios to show how an adversary can easily compromise a device that is either about to be supplied or that has already been provisioned and how the SIeSIM system can protect against such attacks by employing pre- and post-condition criteria.
Fig. 20. Consumption delays vs. Devices. • Case 1—"Device Sending a Single Malicious Packet”: An adversary obtains access to the device via a stolen set of credentials and then and other related techniques. The gist of the strengthening is that even attacks the IoT gateway. An authentication system is required to when the long-term private key is compromised in the future, it does not counter this assault.
allow the attacker to compute any current active session key. Perfect • Case 2—"Device Sending several Malicious Packets”: This simulation forward secrecy is thus achieved. This is done by ensuring that the uses A gadget to overwhelm the Internet of Things gateway with sham compromise of the private key reveals no information on the session key data. The purpose of this assault is to examine the security of the used in the computation of the long-term key. Furthermore, SIeSIM also authentication mechanisms.
achieves leakage resilience because of the structure of the multi- • Case 3—"Compromised Device Injecting Malware”: Only authenticated signature it operates, in that even though the stored secret key leaks and already supplied devices can access the smart network. For out from the signature Si, the attacker cannot obtain any constant non- instance, malware like Mirai infects devices. We will manufacture session-dependent function of the long-term secrets. This is assured due such attacks to put our authorization policies through their rules. to the hardness of the discrete logarithm problem, i.e., given y =Gx mod • Case 4—"State Change of a Device Due to External Manipulation”: The N for some public parameters g and N, it is infeasible to recover the SIeSIM allows device monitoring based on its condition and events.
discrete logarithm x.
This test case aims to validate SDN Security Monitoring during runtime. Here, we’ll conduct assaults against IoT gadgets to induce
5.6. Comparison with related works state transitions in those devices. These transitions in the state are difficult for authorization policies to detect. Our SDN Controller’s There is a paucity of resources to install and manage the expanding event-driven state monitoring services pick up on these shifts as they eSIM-based Autonomous-IoT ecosystem, and its workflow standards still occur.
need to be improved. These issues have received scant attention from
2) Resilience to Malicious eSIM devices academics. Due to these considerations, we introduced a novel and efficient provisioning algorithm and a distributed monitoring technique In an increasingly mobile world, malicious cellular IoT devices can that guarantees network consistency and security within the Blockchain- significantly influence the security and functionality of the communi- enabled software-defined IoT ecosystem. Our framework’s layered cation system. SIeSIM’s capacity to distinguish between legitimate and design supports several SDN domains for mobile carriers to improve IoT malicious devices is paramount. SIeSIM security controller can’t re- ecosystem availability, secrecy, and integrity. Secure device provision- authenticate the device until it receives the entire sequence of mes- ing is our primary goal. Our method differs from others in this field in sages. With our authentication technique, we can significantly minimize four ways. First, eSIM-Blockchain’s granular device and context-specific the calculation and communication requirements for detecting mali- precondition regulations provide security checks to device authentica- cious users/rogue IoT devices in the network. The computing costs of tion during provisioning. Second, SIeSIM precondition policies cross- SIeSIM and the conventional method in the case of an attack scenario check device operation during runtime (authorization). We established due to rogue IoT devices present in the network are compared in Table 3.
a security feature-focused blockchain registry to evaluate provided de- For simplicity’s sake, the vertical axis of Fig. 20 is depicted as a log scale, vice security. Third, SIeSIM evaluates device security during provi- which shows the computational delay.
sioning and runtime. For instance, if the gadget is running malware or has outdated firmware. Finally, the SIeSIM service can prevent rogue
3)Informal Security Analysis devices from entering the network infrastructure and thwart attacks.
At the outset of this part, we demonstrate that our proposed authentication/registration protocol in SIeSIM architecture is resistant to several standard security attack models intrinsic to 3GPP protocols 342P. Krishnan et al. C o m p u t e r C o m m u n i c a t i o n s 216(2024)324–345
5.7. Key findings and result discussions Table 4 Summary of the key findings.
The system’s security was built from the ground up with standard- ASPECTS EVALUATED DISCUSSION ized and trusted components. This study focused on the most pressing Device Provisioning Activating the Zero-touch automated provisioning issues surrounding IoT-based infrastructure security [45], including
Section V.E 1) services, the provision time increases slightly due to provisioning, secure registration of autonomous IoT devices, and attacks the processing check, authentication, and on these systems. Inadequate security configuration, unprotected data blockchain overhead. With 100 devices the transmissions, suspicious behavior, malicious hardware, and security overhead is 120s, for 900 devices, and 450 precondition policies, the provision time is 1300 s.
lapses.
Throughput We assessed SIeSIM’s overall network processing
Section V.E 2) capacity with a specific network traffic load. This • IoT security application, compliant with GSMA IoT SAFE test measures the total provisioning and • Server for credential life cycle management, compliant with GSMA authentication workloads in a fixed time slot. The IoT SAFE. result illustrates a decrease in throughput with • Hardware root of trust through IoT SAFE-based eSIM-enabled secu- increasing postcondition policies. For example, with 450 policies, the throughput is 480 Mb/s. While rity enclave =end-to-end. without the SIeSIM, the throughput is 960 Mb/s. In • IoT SAFE eSIM enabled IoT devices = zero-touch provisioning/re- SIeSIM, multi-threaded processing and network provisioning of credentials. communication are faster than in the IEEE 802.15 • Blockchain-based registration and Identity Management baseline.
Resource Usage The evaluation shows that the CPU and heap • Intelligent field gateway, hub, microcontrollers, SoCs, things Section V.E 3) memory usage increases with the higher number of • IETF Enrolment over Secure Transport (RFC 7030) with Public Key policies (both pre and post-condition). With 450 Infrastructure policies, the CPU usages become 89 %, and the • SDN Orchestration, IoT Life cycle Monitoring, and dynamic provi- software utilized 1250 MB of heap memory. On the other hand, without the SIeSIM services running on sioning System the IoT network hubs, they utilize on average 35 % of the CPU and 127-MB heap memory.
Our research shows a need for improvement in the technology Provisioning Time We evaluate the Time-to-Provision (TTP) components, such as incorporating IoT, Blockchain, eSIM provisioning, Section V.E 4) performance for the various scenarios (automated provisioning with SDN +Blockchain based SIeSIM and SDN management standards into smart and secure autonomous IoT and manual provisioning with IEEE 802.15 baseline.
applications. The TTP evaluation tests are comprehensive and average, New Device Registration With cellular IoT network, with eSIM device, we best-effort (to potentially reveal how much time is required for manual Authentication tested the overhead for the IoT-SAFE and SxC provisioning by an expert with advanced knowledge compared to the Section V.E 5) Blockchain-based contract compliance verification automated ZTP solutions) and worst-effort (to potentially reveal how using similar credential/access policies. Our solution reduced the metadata size by 9 % (24 much time is needed for a non-expert without technical background bytes) with JSON-based token. The total time for the compared to the expert counterpart case and the automated ZTP solu- device authentication process is in the order of tions). Section E exhibits TTP performance. Manual provisioning’s best- 4300 ms. But, with our design, since we deploy the effort TTP (44.83 s) beats all automated provisioning’s worst-effort TPP SDN-based Remote-SIM provisioning protocol at the IoT gateway level, for a similar count of packet (48.80 s) by 9 %. Automated ZTP solutions surpass manual TTP by at exchanges, the overhead is reduced to 240–2000 least 154 %. In summary, our suggested ZTP solution surpassed previous ms.
closely related and comparable ZTP solutions, particularly in the best Blockchain Processing The gas consumption increases with the number of circumstances, where the SIeSIM performs roughly 120 % better TTP Section V.E 7) transactions. Our scheme outperformed current than the [40]. Table 4 below enumerates the summary and salient strategies by up to 30 % in overall transaction throughput and improves the time between findings from the experiments.
transactions by up to 85 %. With a lower number of transactions (i.e. <200), the gas consumption and
6. Limitations and future work processing time assume similar values (up to ≈27 s). Our proposal is able to combine high safety (provided by Blockchain technology) with While the proposed architecture for eSIM-based secure provisioning efficiency (provided by SDN-eSIM IoT-SAFE of IoT devices provides many benefits, there are still open problems. architecture).
While this research has proven the value of integrated approaches by Security Properties We conducted these attack case studies in real-time producing improved outcomes across various performance indicators Section V.F.1 attack scenarios and demonstrate how an adversary can easily compromise an about-to-be-provisioned and security posture, it has its limitations and problems, briefly dis- device or an already-provisioned device. SIeSIM can cussed below.
defend against such attacks using pre/post- condition policies. • Interoperability: Different manufacturers and providers may use Resilience to Malware With our authentication technique, we can different eSIM technologies, which can create interoperability issues. Section V.F.2 significantly minimize the calculation and communication requirements for detecting Standardization efforts should be made to ensure interoperability malicious users/IoT devices.
across different eSIM management platforms and IoT devices. • Scalability: As the number of IoT devices and the volume of data they generate increases, scalability becomes a significant challenge. the technology. Efforts should be made to reduce the cost of eSIMs Efficient provisioning, management, and communication between and associated hardware to make them more accessible to a broader devices and cloud services must be addressed to ensure the archi- range of users.
tecture can handle large-scale deployments. • Regulation: The use of eSIM technology in IoT devices is still rela- • Security: While eSIMs provide an additional layer of security for IoT tively new, and more regulation in this area needs to be done.
devices, they are not entirely immune to attacks. Robust security Governments and regulatory bodies must develop policies and reg- measures should be implemented to prevent unauthorized access, ulations to ensure the security and privacy of data generated by IoT data breaches, and other cybersecurity threats. devices with eSIMs.
• Cost: The cost of implementing eSIM technology in IoT devices can • Cloud service vulnerabilities: Cloud services have intricated pieces be high, which may make it difficult for smaller companies to adopt of software that can have security holes. Current cloud systems must 343P. Krishnan et al. C o m p u t e r C o m m u n i c a t i o n s 216(2024)324–345 correct the assumption that all distributed cloud services can be References trusted. Thus, an unpatched component version or misconfiguration in one cloud service may let adversaries disseminate attacks to other [1] Y. Lu, L. Da Xu, Internet of Things (IoT) cybersecurity research: a review of current cloud services, putting any user’s cloud resources at risk. SIeSIM [2] r Se . s Nea iˇzr ec th i′ ct ,o p Pi .c Sˇs, o lI iE ′cE ,E D I .n Lt .Der .n I.e Gt oT nh zin ´ag les z J -d. e6 , L(2 . 0 P1 a8 tr) o 2 n1 o0 , 3 In–2 te1 r1 n5 e. t of Things (IoT):
protects communications between services, hosts, nodes, and opportunities, issues, and challenges towards a smart and sustainable future, mechanisms. However, a compromised cloud service can still J. Clean. Prod. 274 (2020) 122877.
[3] R. Almadhoun, M. Kadadha, M. Alhemeiri, M. Alshehhi, K. Salah, “A user misbehave or spread attacks. We will examine current defenses authentication scheme of IoT devices using blockchain-enabled fog nodes, in:
carefully and qualitatively against cloud service vulnerabilities and Proceedings of the 2018 IEEE/ACS 15th International Conference on Computer mobile operators’ misconfigurations. Systems and Applications (AICCSA), Aqaba, Jordan, 2018, pp. 1–8. October 2018.
[4] M. Adil, M. AminAlmaiah, A. Omar Alsayed, O. Almomani, An anonymous channel categorization scheme of edge nodes to detect jamming attacks in wireless sensor
7. Conclusions networks, Sensors 20 (8) (2020) 2311.
[5] M.T. Hammi, B. Hammi, P. Bellot, A. Serhrouchni, Bubbles of Trust: a decentralized eSIM-based secure identity and provisioning provide a viable solu- blockchain-based authentication system for IoT, Comput. Secur. 78 (2018) 126–142 [CrossRef].
tion for the requirements of the IoT ecosystem. It enables secure, flex- [6] Praveen Kumar Donta, Satish Narayana Srirama, Tarachand Amgoth, Chandra ible, and remote management of IoT devices, eliminating the need for Sekhara Rao Annavarapu, Survey on recent advances in IoT application layer physical SIM cards and simplifying the supply chain. eSIM-based iden- protocols and machine learning scope for research directions, Digital Communications and Networks 8 (Issue 5) (2022), https://doi.org/10.1016/j.
tity and provisioning can help address the challenges associated with IoT dcan.2021.10.004, 727-744, ISSN 2352-8648. security, such as authentication and data privacy. However, eSIM [7] P. Hosein, G. Sewdhan, A. Jailal, Soft-Churn: Optimal Switching between Prepaid technology faces several challenges, such as standardization and OTA Data Subscriptions on E-SIM Support Smartphones. 2021 IEEE 8th International Conference on Data Science and Advanced Analytics, 2021, https://doi.org/ management. Despite these challenges, eSIM-based identity and provi-
10.1109/DSAA53316.2021.9564163. DSAA 2021. sioning present several opportunities for innovation and growth in the [8] S. Yadav, R. Rishi, Secure and authenticate communication using Softsim for IoT ecosystem. This paper proposed using the GSMA standardized IoT- intelligent transportation systems in smart cities, J. Phys. Conf. 1767 (1) (2021) 1–11, https://doi.org/10.1088/1742-6596/1767/1/012049.
SAFE protocol-based eSIM for secure zero-touch service provisioning
[9] M. Aazam S. u. Islam S. T. Lone and A. Abbas, "Cloud of things (CoT): cloud-fog-IoT in autonomous IoT. The proposed solution enables devices to be provi- task offloading for sustainable internet of things," in IEEE Transactions on sioned securely and automatically without human intervention, Sustainable Computing, vol. 7, no. 1, pp. 87-98, 1 Jan.-March 2022, doi: 10.1109/ TSUSC.2020.3028615..
ensuring the network is protected from vulnerabilities. The solution has
[10] R. Borgaonkar, I. Anne Tøndel, M. ZenebeDegefa, M. Gilje Jaatun, Improving smart been evaluated using simulations and experimental studies, demon- grid security through 5 G-enabled IoT and edge computing, Concurrency Comput.
strating its effectiveness in enabling secure zero-touch service provi- Pract. Ex. 33 (18) (2021) 1–16, https://doi.org/10.1002/cpe.6466. sioning in AIoT networks. In conclusion, eSIM is a rapidly developing [11] K. Oztoprak, Y.K. Tuncel, I. Butun, Technological Transformation of telco operators towards seamless IoT edge-cloud continuum, Sensors 23 (2) (2023) 1–16, https:// area of research in IoT. Future research must focus on creating solutions doi.org/10.3390/s23021004.
to these challenges and exploring new applications for IoT eSIM and [12] A.S. Ahmed, A. Peltonen, M. Sethi, T. Aura, Security Analysis of the Consumer integrated SIM (iSIM) with System-on-Chip in the emerging AI-based Remote SIM Provisioning Protocol, Annals of Telecommunications1, 2022. http:// arxiv.org/abs/2211.1532.
5G/6G and beyond networks.
[13] B. Abazi, 5G new radio evolution towards enhanced features, Thesis 38p (2023).
[14] C. Silva, J.P. Barraca, R. Aguiar, ESIM suitability for 5G and B5G enabled IoT CRediT authorship contribution statement verticals. Proceedings - 2021 International Conference on Future Internet of Things and Cloud, 2021, pp. 210–216, https://doi.org/10.1109/ FiCloud49777.2021.00038. FiCloud.
Prabhakar Krishnan: Writing – review & editing, Writing – original [15] Istabraq Mohammed Alshenaifi, Emad UlHaq Qazi, AbdulrazaqAlmorjan, IoT draft, Visualization, Validation, Software, Resources, Methodology, forensics: machine to machine embedded with SIM card. ITNG 2023 20th International Conference on Information Technology-New Generations, Springer Investigation, Data curation, Conceptualization. Kurunandan Jain:
International Publishing, Cham, 2023.
Writing – review & editing, Writing – original draft, Visualization, [16] Surabhi Thatte, eSIM on IoT: an Innovative Approach towards Connectivity, 2020, Validation, Software, Resources, Methodology, Investigation, Formal https://doi.org/10.17577/IJERTCONV8IS05053.
analysis, Conceptualization. Shivananda R. Poojara: Writing – review [17] R. Kawamura - Future Of eSIM. https://www.soracom.io/blog/the-future-of-esim/. (Accessed 14 August 2019). & editing, Validation, Supervision, Software, Resources, Methodology, [18] Apilo, Olli, PekkaKarhula, Jukka Ma¨kel¨a, eSIM-based inter-operator mobility for Investigation, Formal analysis, Conceptualization. Satish Narayana advanced smart products, IEEE Internet of Things Magazine 5 (2022) 120–126.
Srirama: Writing – review & editing, Visualization, Software, Re- [19] Alex R. Mathew, Threats and protection on E-sim: a prospective study, Novel Perspectives of Engineering Research 8 (2022) 76–81. sources, Methodology, Formal analysis. Tulika Pandey: Writing – re- [20] Chrystel Gaber, Pierrick Kaluza, "eSIM adoption: essential challenges on view & editing, Visualization, Validation, Software, Methodology, responsibilities repartition.". International Conference on 6G Networking (6GNet), Formal analysis. Rajkumar Buyya: Writing – review & editing, Visu- IEEE, 2022, 2022.
[21] Y. Gao et al. "Blockchain-based IIoT data sharing framework for SDN-enabled alization, Validation, Supervision, Software, Formal analysis, pervasive edge computing," in IEEE Trans. Ind. Inf., doi: 10.1109/ Conceptualization. TII.2020.3012508..
[22] Jianli Pan, et al., EdgeChain: an edge-IoT framework and prototype based on blockchain and smart contracts, IEEE Internet Things J. (2018) 4719–4732.
Declaration of competing interest
[23] L. Gong, D.M. Alghazzawi, L. Cheng, BCoT sentry: a blockchain-based identity authentication framework for IoT devices, Information 12 (2021) 203.
The paper entitled, “eSIM/Blockchain Integrated secure Zero-Touch [24] P. Krishnan, et al., SDN Framework for Securing IoT Networks, 218, Springer, Provisioning for Autonomous Cellular-IoTs in 5G Networks” has been Cham, 2018, https://doi.org/10.1007/978-3-319-73423-1_11.
[25] M. Miettinen, S. Marchal, I. Hafeez, N. Asokan, A.R. Sadeghi, S. Tarkoma, IoT
submitted to Special Issue: “Zero-touch Service Provisioning for SENTINEL: automated device-type identification for security enforcement in IoT, Autonomous IoT”. The authors and Co-Authors have no conflicts of in- in: Proceedings of the 2017 IEEE 37th International Conference on Distributed Computing Systems, ICDCS), Atlanta, GA, USA, 5–8 June 2017, pp. 2177–2184.
terest and the paper is not been submitted to any other Journals.
[26] D. Wang, H. Wang, Y. Fu, Blockchain-based IoT device identification and management in 5G smart grid, EURASIP J. Wirel. Commun. Netw. 2021 (2021) Data availability 125.
[27] A. Dorri, C. Roulin, S. Pal, S. Baalbaki, R. Jurdak, S. Kanhere, Device identification in blockchain-based internet of things. Early Access, IEEE Internet Things J, 2022.
No data was used for the research described in the article. [28] B.K. Mohanta, A. Sahoo, S. Patel, S.S. Panda, D. Jena, D. Gountia, DecAuth: decentralized authentication scheme for IoT device using Ethereum blockchain, in:
Proceedings of the TENCON 2019—2019 IEEE Region 10 Conference (TENCON), 2019, pp. 558–563. Kochi, India, 17–20 October.
344P. Krishnan et al. C o m p u t e r C o m m u n i c a t i o n s 216(2024)324–345
[29] H. Yang, B. Bao, C. Li, Q. Yao, A. Yu, J. Zhang, Y. Ji, Blockchain-enabled tripartite 10th Asian Internet Engineering Conference (AINTEC ’14) (2014) 23–30, https:// anonymous identification trusted service provisioning in industrial IoT, IEEE doi.org/10.1145/2684793.2684797. Association for Computing Machinery, New Internet Things J. 9 (2022) 2419–2431. IoT Safe protocol. York, NY, USA.
[30] M. Gowtham, M. Banga, Mallanagouda Patil, Secured authentication systems for [43] Applying a Threat Model to Cloud Computing – OSTI.Gov, 2022. https://www.osti. the internet of things, EAI Endorsed Transactions on Smart Cities 4 (2020) 11. gov/servlets/purl/1594657, 02-01.
[31] Kersten Heins, Kersten Heins, Cellular IoT technology. NB-IoT Use Cases and [44] N. Kushalnagar, G. Montenegro, C. Schumacher, ‘IPv6 over Low-Power Wireless
Devices: Design Guide, 2022, pp. 17–44. Personal Area Networks (6LoWPANs): Overview, Assumptions, Problem
[32] J. Munilla, M. Burmester, R. Barco, An enhanced symmetric-key-based 5G-AKA Statement, and Goals, ’’ Microsoft Corp., New York, NY, USA, 2007. Tech. Rep. protocol, Comput. Network. 198 (2021) 108373, https://doi.org/10.1016/j. 2007A4919.
comnet.2021.108373. [45] H.I. Ahmed, A.A. Nasr, S. Abdel-Mageid, H.K. Aslan, A survey of IoT security
[33] E. Baccour, M.S. Allahham, A. Erbad, A. Mohamed, A.R. Hussein, M. Hamdi, Zero- threats and defenses, Int. J. Adv. Comput. Res. 9 (2019) 325–350. touch realization of pervasive artificial intelligence as a service in 6G networks, [46] C. Costello, B. Smith, Montgomery curves and their arithmetic, J Cryptogr Eng 8 IEEE Commun. Mag. 61 (2) (2023) 110–116, https://doi.org/10.1109/ (2018) 227–240, https://doi.org/10.1007/s13389-017-0157-6.
MCOM.001.2200508. [47] M.C. Chow, M. Ma, A secure blockchain-based authentication and key agreement
[34] C. Toma, M. Popa, C. Boja, C. Ciurea, M. Doinea, Secure and anonymous voting D- scheme for 3GPP 5G networks, Sensors 22 (2022) 4525, https://doi.org/10.3390/ app with IoT embedded device using blockchain technology, Electronics 11 (12) s22124525.
(2022) 1–25, https://doi.org/10.3390/electronics11121895. [48] A.E. Azzaoui, S.K. Singh, Y. Pan, J.H. Park, Block5GIntell: blockchain for AI-
[35] J. Ma, Y. Guo, C. Fang, Q. Zhang, Digital twin-based zero-touch management for enabled 5G networks, IEEE Access 8 (2020) 145918–145935, https://doi.org/ IoT, Electronics 11 (24) (2022) 1–17, https://doi.org/10.3390/ 10.1109/ACCESS.2020.3014356.
electronics11244104. [49] P. Krishnan, A.V. Prabu, S. Loganathan, S. Routray, U. Ghosh, M. AL-Numay,
[36] H. Choudhury, HashXor: a lightweight scheme for identity privacy of IoT devices in Analyzing and managing various energy-related environmental factors for 5G mobile network, Comput. Network. 186 (2021) 107753, https://doi.org/ providing personalized IoT services for smart buildings in smart environment,
10.1016/j.comnet.2020.107753. Sustainability 15 (2023) 6548, https://doi.org/10.3390/su15086548.
[37] Y.D. Lin, D.T. Truong, A. Ali, C.Y. Li, Y.C. Lai, T.M.T. Dinh, Proxy-based federated [50] M. Kasiselvanathan, Teresa V.V. Manikandan Rajagopal, Prabhakar Krishnan,
authentication: a transparent third-party solution for cloud-edge federation, IEEE Performance analysis of alternating minimization based low complexity detection Network 34 (6) (2020) 220–227, https://doi.org/10.1109/MNET.011.2000136. for MIMO communication system, Automatika 64 (4) (2023) 748–755, https://doi.
[38] J. Mamvong, G. Goteng, Y. Gao, Low-cost client-side encryption and secure org/10.1080/00051144.2023.2209416.
Internet of Things (IoT) provisioning, Front. Comput. Sci. 16 (6) (2022) 1–3, [51] A. Balasundaram, S. Routray, A. V. Prabu, P. Krishnan, P. P. Malla and M. Maiti,
https://doi.org/10.1007/s11704-022-1256-9. "Internet of things (IoT) based smart healthcare system for efficient diagnostics of
[39] A.S. Ahmed, M. Thakur, S. Paavolainen, T. Aura, Transparency of SIM profiles for health parameters of patients in emergency care," in IEEE Internet of Things the consumer remote SIM provisioning protocol, Annales Des Journal, doi: 10.1109/JIOT.2023.3246065..
Telecommunications/Annals of Telecommunications 76 (3–4) (2021) 187–202, [52] N. Singh, K. Jain, Data security approach using blockchain mechanism and
https://doi.org/10.1007/s12243-020-00791-2. cryptography algorithms. 2023 11th International Symposium on Digital Forensics
[40] P.R. Sousa, L. Magalha˜es, J.S. Resende, R. Martins, L. Antunes, Provisioning, and Security, ISDFS), USA, 2023, pp. 1–6, https://doi.org/10.1109/ authentication, and secure communications for IoT devices on fiware, Sensors 21 ISDFS58141.2023.10131789. Chattanooga, TN.
(17) (2021) 1–24, https://doi.org/10.3390/s21175898. [53] M. Kataria, K. Jain, N. Subramanian, Exploring advanced encryption and
[41] M. Brandt, et al., Security analysis of software-defined networking protocols steganography techniques for image security, in: 2023 11th International OpenFlow, in: OF-config and OVSDB in IEEE ICCE 2014, 2014. Symposium on Digital Forensics and Security, ISDFS), USA, 2023, pp. 1–6, https://
[42] Markus Tasch, Rahamatullah Khondoker, Ronald Marx, Kpatcha Bayarou, Security doi.org/10.1109/ISDFS58141.2023.10131890. Chattanooga, TN. analysis of security applications for software defined networks, Proceedings of the 345