With the rapid growth of hyperconnected devices and decentralized data architectures, safeguarding Internet of Things (IoT) transactions is becoming increasingly challenging. Blockchain presents a promising solution, yet its effectiveness depends on the underlying consensus algorithm. Conventional mechanisms, such as Proof of Work and Proof of Stake, are often impractical for resource-constrained IoT environments. To address these limitations, this work introduces a fair and lightweight hybrid consensus algorithm tailored for IoT. The proposed approach minimizes resource demands on the nodes while providing a fair and secure agreement process. Specifically, it utilizes a distributed lottery mechanism to ensure fair block proposals without requiring dedicated hardware. In addition, to enhance trust and establish finality, a reputation-based voting mechanism is incorporated. Finally, we experimentally validated the key features of the proposed consensus algorithm.
Nowadays IoT devices have a significant role in our daily lives, from smart home appliances to smart healthcare and the industry, aiming to provide novel services. IoT networks, however, are characterized by the heterogeneity of the devices, which brings new challenges, such as managing devices' identities. Moreover, this heterogeneity leaves open space for attackers to act, compromising the security of IoT networks. In this work we present a verifiable data registry solution for the decentralized identity management in IoT environments, employing Blockchain and gRPC technologies. The proposed solution focuses on providing both security and scalability, enhancing its applicability to the IoT context.
In today's interconnected IoT ecosystems, blockchain technology acts as a facilitator for decentralization. Hyperledger Fabric (HLF) is a renounced permissioned blockchain platform designed for enterprise use. Currently, HLF supports two primary consensus algorithms: Raft and smartBFT. Despite HLF's modular nature, integrating new consensus algorithms remains a challenging and intricate process that lacks sufficient guidelines. In this work, we bridge this gap by providing a novel, comprehensive, yet practical guide to simplify the integration of consensus algorithms into HLF. Furthermore, we demonstrate our approach by integrating a new hybrid algorithm into HLF, specifically tailored for the IoT ecosystem. Compared to the current algorithms, experiments indicate promising performance and reliability.
Introduction to the ERATOSTHENES project, a collaborative research initiative dedicated to developing innovative solutions for securing the IoT. It provides a roadmap for the book, Preface xv inviting readers to explore the intricacies of IoT security, the technical architecture of the ERATOSTHENES framework, and the collaborative efforts driving advancements in this field.
Efficiency and interoperability are essential for the evolution of secure and scalable e-governance systems. This paper presents a novel framework for interoperable smart contract generation that integrates semantic technologies, and Layer-2 blockchain scaling solutions to enhance interoperability, security, and efficiency in e-governance applications. Using zero-knowledge proofs for privacy-preserving transactions and self-sovereign identity mechanisms for decentralized authentication, the proposed architecture ensures trust and compliance with international standards. Initially applied to e-voting, this framework is adaptable to broader public services, fostering a transparent, cost-effective, and sustainable digital governance ecosystem.
Logistics plays a crucial role in modern society, particularly in densely populated urban areas, facilitating the transportation of goods. Last-mile e-commerce deliveries are emissions-intensive, contributing significantly to CO2 levels and traffic congestion. Addressing this challenge requires systemic changes in last-mile delivery ecosystems. Based on this observation, in alignment with the EU decarbonisation goals, the URBANE project (GA101069782) aims to promote the adoption of sustainable and environmentally friendly last-mile delivery solutions by introducing a collaborative layered “Platform as a Service” (PaaS) paradigm. The initiative focuses on establishing Physical Internet (PI) inspired interventions combined with the implementation of innovative tools, such as agent-based and AI models, employing a Digital Twin platform addressing the operational and strategic planning challenges of city logistics networks. A multi-factorial impact assessment radar further enhances the evaluation of the PI interventions’ effectiveness. The platform fosters collaboration among urban logistics stakeholders governed through “green” smart contracts, addressing security and privacy concerns by using a blockchain infrastructure and digital IDs, creating a trustworthy system for collaboration. The paper showcases the applicability of the URBANE Innovation Transferability Platform in designing, measuring, testing, and validating targeted logistics interventions in Lighthouse Living Labs. Cities and logistic operators receive suggestions for informed data-driven decision-making coupled with integrated and transferable applications that can be standardised and structured, aligned with the targets set in a citie’s Sustainable Urban Logistics Plan (SULP).
Delving into the design and implementation of a verifiable data registry (VDR) for decentralized identity and trust management in IoT environments. The authors utilize HyperLedger Fabric as the underlying blockchain infrastructure and xvi Preface introduce a novel hybrid consensus algorithm tailored for IoT networks. The chapter also details the creation of an efficient and secure VDR using gRPC services, emphasizing both security and scalability for IoT applications.
The goals of the European Union towards the energy transition imply profound changes in the energy field, so as to promote sustainable energy development while fostering economic growth. To achieve these changes, the incorporation of sustainable technologies supporting decentralisation, energy efficiency, renewable energy production, and demand flexibility is of vital importance. Blockchain has the potential to change energy services towards this direction. To optimally exploit blockchain, innovative business models need to be designed, identifying the opportunities emerging from unmet needs, while also considering potential risks so as to take action to overcome them. In this context, the scope of this paper is to examine the opportunities and the risks that emerge from the adoption of blockchain in four innovative business models, while also identifying mitigation strategies to support and accelerate the energy transition, thus proposing optimal approaches of exploitation of blockchain in energy services. The business models concern Energy Performance Contracting with P4P guarantees, improved self-consumption in energy cooperatives, energy efficiency and flexibility services for natural gas boilers, and smart energy management for EV chargers and HVAC appliances. Firstly, the value proposition of the business models is analysed and results in a comprehensive SWOT analysis. Based on the findings of the analysis and consultations with relevant market actors, in combination with the examination of the relevant literature, risks are identified and evaluated through a qualitative assessment approach. Subsequently, specific mitigation strategies are proposed to address the detected risks. This research demonstrates that blockchain integration into these business models can significantly improve energy efficiency, reduce operational costs, enhance security, and support a more decentralised energy system, providing actionable insights for stakeholders to implement blockchain solutions effectively. Furthermore, according to the results, technological and legal risks are the most significant, followed by political, economic, and social risks, while environmental risks of blockchain integration are not as important. Strategies to address risks relevant to blockchain exploitation include ensuring policy alignment, emphasising economic feasibility, facilitating social inclusion, prioritising security and interoperability, consulting with legal experts, and using consensus algorithms with low energy consumption. The findings offer clear guidance for energy service providers, policymakers, and technology developers, assisting in the design, deployment, and risk mitigation of blockchain-enabled business models to accelerate sustainable energy development.
E-voting systems often face risks such as data breaches, vote manipulation, and lack of voter confidence. Balancing security and anonymity has posed significant obstacles that obscured the immense potential of electronic voting systems. This paper addresses critical challenges in e-voting, including security vulnerabilities, lack of transparency, scalability and user accessibility issues. We propose a privacy-preserving framework to tackle these challenges, enhancing the security, transparency and scalability of e-voting systems. Our framework leverages blockchain to provide a tamper-evident ledger, zero-knowledge proofs to ensure ballot secrecy and data integrity and Merkle Trees to facilitate data storage in a scalable manner. Furthermore, we present findings of the framework's performance that was conducted under an e-voting use case, while we suggest improvements towards an even more secure and transparent framework.
The governance of blockchain networks presents unique challenges in ensuring privacy and accountability in operational processes. This work examines current obstacles within existing governance structures and proposes directions towards the privacy-preserving governance of blockchain networks. We explore the complexities of data protection, smart contract accountability, and operational governance, highlighting the discrepancies between traditional governance models and the decentralized nature of blockchain ecosystems. To this end, we propose integrating legally binding smart contracts and Ricardian contracts, along with practical guidelines for blockchain administrators aiming to enable enhanced privacy, regulatory compliance, and efficient dispute resolution mechanisms.
Shared travel offers an important way to increase the accessibility of rail services. However, providing an integrated shared travel capability for rail travel is both a conceptual and technical challenge. This paper presents an overview of Ride2Rail, enabling ‘Easy use for all’ of rail through ridesharing as part of a multimodal journey. Ride2Rail has the overall objective of developing intelligent multimodal mobility, by facilitating the efficient combination of flexible and crowdsourced transport services, such as ridesharing, with scheduled transport. A requirements activity has set out the travel behaviour and system requirements for Ride2Rail. Development activities have covered the technical implementation of Ride2Rail, involving both development of the Ride2Rail functionalities and the Ride2Rail Driver Companion application, integrated within the wider Shift2Rail ecosystem. Demonstration activities have involved the preparation, implementation, execution and monitoring of Ride2Rail at four demonstration sites. This paper outlines the overall approach and findings of the Ride2Rail. This demonstrates the technical feasibility of integrating shared travel, including the architecture for a shared ride capability that can be readily integrated into pre-existing Mobility as a Service (MaaS) platform. Additionally, the paper reports positive user attitudes to this kind of shared travel, within the context of multimodal trips.
The Internet of Things (IoT) and Cyber-Physical Systems (CPS) are the backbones of Industry 4.0, where data quality is crucial for decision support. Data quality in these systems can deteriorate due to sensor failures or uncertain operating environments. Our objective is to summarize and assess the research efforts that address data quality in data-centric CPS/IoT industrial applications. We systematically review the state-of-the-art data quality techniques for CPS and IoT in Industry 4.0 through a systematic literature review (SLR) study. We pose three research questions, define selection and exclusion criteria for primary studies, and extract and synthesize data from these studies to answer our research questions. Our most significant results are (i) the list of data quality issues, their sources, and application domains, (ii) the best practices and metrics for managing data quality, (iii) the software engineering solutions employed to manage data quality, and (iv) the state of the data quality techniques (data repair, cleaning, and monitoring) in the application domains. The results of our SLR can help researchers obtain an overview of existing data quality issues, techniques, metrics, and best practices. We suggest research directions that require attention from the research community for follow-up work.
: One of the greatest challenges of the European last mile logistics sector is the requirement to decouple its economic growth from resource use and air pollutants emissions from transport operations. This requirement, alongside the rise of e-commerce and the phenomenon of urbanization, creates an urgent need for European Union's member states to identify and rapidly upscale innovative last-mile solutions that will ensure the green and digital transformation of European urban environments. To achieve such a goal, innovative frameworks such as the Physical Internet (PI) are required, which can lead to low-emission logistics services that remain competitive compared to the latest industry trends such as same-or next-day-delivery, real-time parcel tracking, and omni-channel distribution. The URBANE project introduces an Innovation Transferability Platform with Digital Twinning capabilities, under the Platform-as-a-service (PaaS) paradigm, which enables the project's Living Labs to assess the impact of the PI-inspired interventions before or during their implementation in the real-world context. In that regard, in the current article, a presentation of initial project results is given, including platform micro-services and Use Cases (UCs) that aim at supporting the transition to the PI.
There is a current wave of a new generation of digital solutions based on intelligent systems, hybrid digital twins and AI-driven optimization tools to assure quality in smart factories. Such digital solutions heavily depend on quality-related information within the supply chain business ecosystem to drive zero-waste value chains. To empower zero-waste value chain strategies with meaningful, reliable, and trustful data, there must be a solution for end-to-end industrial data traceability, trust, and security across multiple process chains or even inter-organizational supply chains. In this paper, we first present Product, Process, and Data quality services to drive zero-waste value chain strategies. Following this, we present the Trusted Framework (TF), which is a key enabler for the secure and effective sharing of quality-related information within the supply chain business ecosystem, and thus for quality optimization actions towards zero-defect manufacturing. The TF specification includes the data model and format of the Process/Product/Data (PPD) Quality Hallmark, the OpenAPI exposed to factory system and a comprehensive Identity Management layer, for secure horizontal- and vertical quality data integration. The PPD hallmark and the TF already address some of the industrial needs to have a trusted approach to share quality data between the different stakeholders of the production chain to empower zero-waste value chain strategies.
The ERATOSTHENES project is driven by recent security challenges of IoT networks being today embedded into our day to day lives. The high increase of connected devices, their inhomogeneous nature, high penetration, as well as different manufacturing and vendor characteristics have created a vast attack surface that is prone to increase in the next years. This has already created challenges such as: confidentiality access control, privacy for users and things, devices’ trustworthiness and compliance that require lifecycle considerations of IoT devices and networks. ERATOSTHENES will devise a novel distributed, automated, auditable, yet privacy-respectful, Trust and Identity Management Framework intended to dynamically and holistically manage the lifecycle of IoT devices, strengthening trust, identities, and resilience in the entire IoT ecosystem, supporting the enforcement of the NIS directive, GDPR and Cybersecurity Act. This publication positions the project into the internet of things and applications and describes the project concept, requirements, first architectural decisions and outcomes.
ERATOSTHENES is an EC, co-funded, research project strongly considering modern security challenges in the domain of Internet of Things in mind of their huge penetration into our day to day lives. There are a series of recent challenges that recently have been converted into obstacles or risk points that could block the secure operation of IoT networks in all day to day activities, from home to office, to leisure and security. These include examples such as the highly increased number of connected devices (at all network levels) that are on top forming inhomogeneous networks and systems of systems. Different vendor characteristics further increase the attack surface that is expected to further rise in the upcoming years. Such, highly critical, characteristics, dramatically increase the needs for confidentiality access control, user and things’ privacy, devices’ trustworthiness and compliance that require lifecycle considerations. The ERATOSTHENES project orchestrates a novel distributed, automated, auditable, yet privacy-respectful, Trust and Identity Management Framework and Reference Architecture with the ultimate scope to dynamically and holistically manage IoT devices in a lifecycle approach, strengthening trust, identities, and resilience in the entire IoT ecosystem while supporting the enforcement of the NIS directive, GDPR and Cybersecurity Act. This publication describes the ERATOSTHENES technical concept and reference architecture as well as design considerations, architecture characteristics, connectivity and interoperability.
Transport and Logistics stakeholders utilise Blockchain to interact within their networks in a transparent and secure manner. This creates islands of disconnected communities which prohibits visibility across the entire supply chain. This paper introduces a framework, which aims at unifying multiple proprietary Blockchain systems, offering an opportunity to empower stakeholders across the entire supply chain to collaborate and exchange information seamlessly. The Blockchain Interoperability framework employs smart contracts, which aspire to automate previously cumbersome processes and bring value to the Physical Internet (PI) paradigm. Smart contracts guarantee a trustworthy and distributed process of contract negotiation and execution that significantly reduces time, administrative overheads, and costs which are currently typically spent on manual inter-organisational processes.
Data protection and privacy is a major concern in the Internet of Things (IoT) ecosystem, and the excessive use of IoT devices may risk the security of the network. Blockchain solutions are used to enhance the trustworthiness and eliminate the need for trusted third parties by providing mechanisms to reach consensus in a network of trustless participants. The consensus algorithms employed by blockchain architectures ensure the integrity of the data stored in the blockchain, the resiliency of the network and manage the security of devices. However, current solutions are compute intensive affecting the performance of the network and consuming much energy. In this work, we introduce a consensus algorithm for offering secure distributed consensus among IoT devices without affecting the performance of the network. The algorithm is inspired by existing solutions, employs decentralised identities, verifiable credentials and a decentralised trust management mechanism to guarantee security, privacy and trustworthiness of transactions. Finally, our algorithm combines technologies for operating in a distributed manner which favors the scalability and allow the effective integration in large scale networks.
Big amount of data produced, exchanged and stored during a building's lifetime, along with the increasing adoption of IoT technologies, provide a huge potential for the development of data-driven services that can facilitate processes such as predictive maintenance or monitoring of KPIs that are required for demonstrating climate policy compliance. On the other hand, storing and sharing information among interested stakeholders, can generate critical privacy and trust issues. In this paper, we present a blueprint architecture based on a combination of state-of-the-art and disruptive technologies, introducing the concept of a modular Trusted Digital Building Logbook (DBL) that will act as a dynamic record at facility level and will segregate monitored data and other building related information, in a way that guarantees both the privacy of confidential data and the transparency to authorities and city stakeholders that wish to have a real-time overview of buildings' performance at a local or regional level. The Trusted DBL is based on Blockchain and Digital Twin (DT) technologies and can be used to report progress on emission reductions, the impact of a given energy efficiency measure or to recommend precautionary measures ahead of critical events such as heatwaves. Designed to be interoperable, the Trusted DBL architecture revolutionises the buildings performance evaluation process by securely connecting different buildings clusters to capture critical information at national, organizational and/or facility level, help understand a region's emissions profile and report it in the form of a trusted emissions inventory.