Blockchain-based Zero Trust Cybersecurity in the Internet of Things
Shancang Li, Surya Nepal, Theo Tryfonas, Hongwei Li · ACM Transactions on Internet Technology · 2023
Blockchain-based Zero Trust Cybersecurity in the Internet of Things 1 INTRODUCTIONThe Internet of Things (IoT) connects a massive number of smart devices to the Internet, in which all data, applications, devices, and users require connectivity, security, and trust.Traditional security approaches assume that all participants within the network perimeter are trustworthy.However, in IoT environment data, applications, devices, and users are gradually moving outside the traditional trusted defence perimeter and have become a source of security risks.Unlike traditional security approaches, which are initially designed for the optimum protection and only act if a process is malicious, the zero-trust security framework upholds the "verify and never trust" principle.Zero trust-based approaches assume that everything within the system is untrustworthy and needs to be verified to prevent threats.Meanwhile, the blockchain technology shows promises on cyber security and several blockchain security mechanisms have been developed, including access management, user authentication, and transaction security.Due to its prowess in enhancing cyber security, blockchain can provide zero trust security framework with highly accessible and transparent security mechanisms via a visible blockchain, in which all transactions are visible to restricted operators.Zero-trust models can be secured further by a blockchain due to its sheer immutable nature and blockchain technology is expected to recognise them, authenticate their trust, and allow them access.Blockchain-enabled zero trust security can detect suspicious online transaction, isolate connection, and restrict access to the user.This special issue received in total 37 high-quality submissions.Per journal policy, it was ensured that handling editors did not have any potential conflict of interest with authors of submitted papers.All submitted papers were reviewed by at least three independent potential referees.The papers were evaluated for their rigor and quality, and also for their relevance to the theme of our special issue.After evaluating the overall scores, seven papers were selected by the guest editors and approved by the Editor-in-Chief for inclusion in this special issue.We will now briefly introduce the accepted papers. THE PAPERSThe paper entitled "Three-tier storage framework based on TBchain and IPFS for protecting IoT security and privacy" by authors Li et al. proposed to use a three-tier blockchain to split