{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T14:44:30Z","timestamp":1740149070189,"version":"3.37.3"},"reference-count":51,"publisher":"Wiley","license":[{"start":{"date-parts":[[2021,7,19]],"date-time":"2021-07-19T00:00:00Z","timestamp":1626652800000},"content-version":"unspecified","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62002374"],"award-info":[{"award-number":["62002374"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Security and Communication Networks"],"published-print":{"date-parts":[[2021,7,19]]},"abstract":"<jats:p>The Internet lacking accountability suffers from IP address spoofing, prefix hijacking, and DDoS attacks. Global PKI-based accountable network involves harmful centralized authority abuse and complex certificate management. The inherently accountable network with self-certifying addresses is incompatible with the current Internet and faces the difficulty of revoking and updating keys. This study presents DIIA, a blockchain-based decentralized infrastructure to provide accountability for the current Internet. Specifically, DIIA designs a public-permissioned blockchain called TIPchain to act as a decentralized trust anchor, allowing cryptographic authentication of IP addresses without any global trusted authority. DIIA also proposes the revocable trustworthy IP address bound to the cryptographic key, which supports automatic key renewal and efficient key revocation and eliminates complexity certificate management. We present several security mechanisms based on DIIA to show how DIIA can help to enhance network layer security. We also implement a prototype system and experiment with real-world data. The results demonstrate the feasibility and suitability of our work in practice.<\/jats:p>","DOI":"10.1155\/2021\/1974493","type":"journal-article","created":{"date-parts":[[2021,7,19]],"date-time":"2021-07-19T18:50:05Z","timestamp":1626720605000},"page":"1-17","source":"Crossref","is-referenced-by-count":2,"title":["DIIA: Blockchain-Based Decentralized Infrastructure for Internet Accountability"],"prefix":"10.1155","volume":"2021","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3993-8402","authenticated-orcid":true,"given":"Pengkun","family":"Li","sequence":"first","affiliation":[{"name":"College of Computer, National University of Defense Technology, Changsha 410073, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9273-616X","authenticated-orcid":true,"given":"Jinshu","family":"Su","sequence":"additional","affiliation":[{"name":"Science and Technology on Parallel and Distributed Laboratory, National University of Defense Technology, Changsha 410073, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3583-369X","authenticated-orcid":true,"given":"Xiaofeng","family":"Wang","sequence":"additional","affiliation":[{"name":"College of Computer, National University of Defense Technology, Changsha 410073, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8602-9175","authenticated-orcid":true,"given":"Qianqian","family":"Xing","sequence":"additional","affiliation":[{"name":"College of Computer, National University of Defense Technology, Changsha 410073, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"311","reference":[{"key":"1","doi-asserted-by":"publisher","DOI":"10.1109\/access.2018.2817921"},{"article-title":"State of IP spoofing","year":"2021","author":"CAIDA\u2019s Spoofer Project","key":"2"},{"article-title":"Mirai attack on DYN internet infrastructure","year":"2016","author":"S. Day","key":"3"},{"article-title":"Large European routing leak sends traffic through China telecom","year":"2019","author":"D. Madory","key":"4"},{"article-title":"Youtube hijacking: a ripe NCC RIS case study","year":"2008","author":"Ripe Network Coordination Centre","key":"5"},{"article-title":"The resource public key infrastructure (RPKI) to router protocol","year":"2017","author":"R. Bush","key":"6"},{"first-page":"155","article-title":"Bootstrapping accountability in the internet we have","author":"A. Li","key":"7"},{"key":"8","doi-asserted-by":"publisher","DOI":"10.1145\/3065913.3065922"},{"first-page":"51","article-title":"From the consent of the routed: Improving the transparency of the RPKI","author":"E. Heilman","key":"9"},{"key":"10","doi-asserted-by":"publisher","DOI":"10.1145\/2535771.2535787"},{"article-title":"Are we there yet? On RPKI\u2019s deployment and security","author":"Y. Gilad","key":"11","doi-asserted-by":"crossref","DOI":"10.14722\/ndss.2017.23123"},{"key":"12","doi-asserted-by":"publisher","DOI":"10.1145\/3085591"},{"key":"13","doi-asserted-by":"publisher","DOI":"10.1145\/1402946.1402997"},{"key":"14","doi-asserted-by":"publisher","DOI":"10.1145\/2619239.2626306"},{"first-page":"47","article-title":"Identity-based cryptosystems and signature schemes","author":"A. Shamir","key":"15"},{"issue":"2","key":"16","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1109\/CC.2018.8300267","article-title":"T-ip: a self-trustworthy and secure internet protocol","volume":"15","author":"X. Wang","year":"2018","journal-title":"China Communications"},{"first-page":"1632","article-title":"POSTER: IPKI: identity-based private key infrastructure for securing BGP protocol","author":"P. Chen","key":"17"},{"author":"D. K. Smetters","key":"18","article-title":"Domain-based administration of identity-based cryptosystems for secure email and IPSEC"},{"key":"19","doi-asserted-by":"crossref","DOI":"10.17487\/RFC8205","article-title":"BGPsec protocol specification","author":"M. Lepinski","year":"2017"},{"key":"20","doi-asserted-by":"publisher","DOI":"10.1145\/3320269.3384743"},{"key":"21","doi-asserted-by":"publisher","DOI":"10.1109\/icnp.2015.22"},{"first-page":"365","article-title":"Passport: secure and adoptable source authentication","author":"X. Liu","key":"22"},{"article-title":"Security architecture for the internet protocol","year":"2005","author":"K. Seo","key":"23"},{"key":"24","doi-asserted-by":"publisher","DOI":"10.1016\/j.ipm.2020.102468"},{"key":"25","doi-asserted-by":"publisher","DOI":"10.1109\/JAS.2021.1004003"},{"key":"26","doi-asserted-by":"publisher","DOI":"10.1016\/j.jpdc.2021.03.011"},{"key":"27","doi-asserted-by":"publisher","DOI":"10.1109\/tdsc.2020.2983022"},{"key":"28","doi-asserted-by":"publisher","DOI":"10.1109\/sp.2017.57"},{"article-title":"Decentralized public key infrastructure. a white paper from rebooting the web of trust","year":"2015","author":"C. Allen","key":"29"},{"first-page":"181","article-title":"Blockstack: a global naming and storage system secured by blockchains","author":"M. Ali","key":"30"},{"key":"31","first-page":"803","article-title":"A decentralized public key infrastructure with identity retention","volume":"2014","author":"C. Fromknecht","year":"2014","journal-title":"IACR Cryptology ePrint Archive"},{"key":"32","doi-asserted-by":"publisher","DOI":"10.1145\/2656877.2656888"},{"article-title":"Host identity protocol architecture","year":"2019","author":"R. Moskowitz","key":"33"},{"issue":"4","key":"34","doi-asserted-by":"crossref","first-page":"603","DOI":"10.1145\/2829988.2790021","article-title":"Federated end-to-end authentication for the constrained internet of things using IBC and ECC","volume":"45","author":"T. Markmann","year":"2015","journal-title":"ACM SIGCOMM Computer Communication Review"},{"first-page":"128","article-title":"TrueIP: prevention of IP spoofing attacks using identity-based cryptography","author":"C. Schridde","key":"35"},{"key":"36","doi-asserted-by":"publisher","DOI":"10.1109\/jiot.2020.2988126"},{"first-page":"166","article-title":"iTLS\/iDTLS: lightweight end-to-end security protocol for iot through minimal latency","author":"P. Li","key":"37"},{"first-page":"548","article-title":"Hierarchical ID-based cryptography","author":"C. Gentry","key":"38"},{"first-page":"310","article-title":"Efficient identity based signature schemes based on pairings","author":"F. Hess","key":"39"},{"key":"40","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-44647-8_13"},{"first-page":"369","article-title":"A digital signature based on a conventional encryption function","author":"R. C. Merkle","key":"41"},{"key":"42","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-47560-8_13"},{"volume-title":"Scalable and Efficient Data Authentication for Decentralized Systems","year":"2019","author":"S. Ponnapalli","key":"43"},{"article-title":"Ethereum: a secure decentralised generalised transaction ledger","year":"2014","author":"G. Wood","key":"44"},{"key":"45","doi-asserted-by":"publisher","DOI":"10.1109\/comst.2020.2969706"},{"article-title":"Bitcoin: a peer-to-peer electronic cash system","year":"2008","author":"S. Nakamoto","key":"46"},{"first-page":"112","article-title":"The quest for scalable blockchain fabric: proof-of-work vs. BFT replication","author":"M. Vukoli\u0107","key":"47"},{"article-title":"Public-permissioned blockchains as common-pool resources","year":"2020","author":"J. Ruiz","key":"48"},{"key":"49","doi-asserted-by":"publisher","DOI":"10.1109\/icdcs.2013.53"},{"article-title":"TPM 2.0 library specification","year":"2019","author":"Trusted Computing Group","key":"50"},{"key":"51","first-page":"86","article-title":"Intel SGX explained","volume":"2016","author":"V. Costan","year":"2016","journal-title":"IACR Cryptology ePrint Archive"}],"container-title":["Security and Communication Networks"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/downloads.hindawi.com\/journals\/scn\/2021\/1974493.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/downloads.hindawi.com\/journals\/scn\/2021\/1974493.xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/downloads.hindawi.com\/journals\/scn\/2021\/1974493.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,7,19]],"date-time":"2021-07-19T18:50:11Z","timestamp":1626720611000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.hindawi.com\/journals\/scn\/2021\/1974493\/"}},"subtitle":[],"editor":[{"given":"Leandros","family":"Maglaras","sequence":"additional","affiliation":[],"role":[{"role":"editor","vocabulary":"crossref"}]}],"short-title":[],"issued":{"date-parts":[[2021,7,19]]},"references-count":51,"alternative-id":["1974493","1974493"],"URL":"https:\/\/doi.org\/10.1155\/2021\/1974493","relation":{},"ISSN":["1939-0122","1939-0114"],"issn-type":[{"type":"electronic","value":"1939-0122"},{"type":"print","value":"1939-0114"}],"subject":[],"published":{"date-parts":[[2021,7,19]]}}}