Tamperproof Data Transmission to Offline IoT Devices in a Zero-Trust Environment
Richard Vogel, Robert Manthey, Matthias Baumgart, Christian Roschke, Marc Ritter, Matthias Vodel · 2024
This paper presents a holistic approach for transmitting arbitrary data to local Internet-of-Things (IoT) devices using only public services in a zero-trust environment. The approach features a variety of benefits, namely (i) eliminates the need for service providers to deploy their own costly infrastructure, (ii) enables the receiving device to operate without an active network connection, (iii) ensures that the data can be proven untampered on the IoT device itself, (iv) verifies both the validity and recency of the information, (v) requires low administrative and technical efforts, (vi) allows for wireless data updates, including the timeliness of current information, by any participant due to the zero-trust assumption. The described methodology utilizes distinct features of Proof-of-Work (PoW)-based programmable blockchain systems. This work will focus on the usage of Ethereum Classic (ETC) as base layer for trust, the validity and recency of the information. The proposed approach has wide-ranging practical applications, including programmable, rule-based locking systems such as smart locks used in corporate and institutional buildings, cars, and hotels. It also facilitates other forms of access control, such as ticket systems, health certificates, and proof-of-possession for resources or achievements. Due to the zero-trust assumption, data updates as well their recency can be updated by any participant of the system.