Blockchain-assisted Undisclosed IIoT Vulnerabilities Trusted Sharing Protection with Dynamic Token
Wenbo Zhang, Jing Zhang, Yifei Shi, Jingyu Feng

TL;DR
This paper introduces a blockchain-assisted scheme with dynamic tokens to securely share undisclosed IIoT vulnerabilities, preventing leaks by dishonest participants and ensuring tamper-proof logging.
Contribution
It proposes a novel dynamic token-based trust mechanism combined with blockchain for secure, tamper-proof sharing of undisclosed IIoT vulnerabilities.
Findings
Resilient against dishonest sharing workers
Effective in preventing vulnerability leaks
Ensures tamper-proof log storage
Abstract
With the large-scale deployment of industrial internet of things (IIoT) devices, the number of vulnerabilities that threaten IIoT security is also growing dramatically, including a mass of undisclosed IIoT vulnerabilities that lack mitigation measures. Coordination Vulnerabilities Disclosure (CVD) is one of the most popular vulnerabilities sharing solutions, in which some security workers (SWs) can develop undisclosed vulnerabilities patches together. However, CVD assumes that sharing participants (SWs) are all honest, and thus offering chances for dishonest SWs to leak undisclosed IIoT vulnerabilities. To combat such threats, we propose an Undisclosed IIoT Vulnerabilities Trusted Sharing Protection (UIV-TSP) scheme with dynamic token. In this article, a dynamic token is an implicit access credential for an SW to acquire an undisclosed vulnerability information, which is only held by…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsBlockchain Technology Applications and Security · Cloud Data Security Solutions · IoT and Edge/Fog Computing
