https://www.iotworldtoday.com/wp-content/themes/ioti_child/assets/images/logo/footer-logo.png
  • Home
  • News
    • Back
    • IoT World 2020 News
  • Strategy
  • Special Reports
  • Galleries
  • Business Resources
    • Back
    • Webinars
    • White Papers
    • Industry Perspectives
    • Featured Vendors
  • Other Content
    • Back
    • IoT World 2020 News
    • Q&As
    • Case Studies
    • Features
    • How-to
    • Opinion
    • Video / Podcasts
  • More
    • Back
    • About Us
    • Contact
    • Advertise
    • Strategic Partners
  • IOT World Events
    • Back
    • Internet of Things World: San Jose
    • IoT World 2020 News
Iot World Today
  • NEWSLETTER
  • Home
  • News
    • Back
    • IoT World 2020 News
  • Strategy
  • Special Reports
  • Galleries
  • Business Resources
    • Back
    • Webinars
    • White Papers
    • Industry Perspectives
    • Featured Vendors
  • Other Content
    • Back
    • IoT World 2020 News
    • Q&As
    • Case Studies
    • Features
    • How-to
    • Opinion
    • Video / Podcasts
  • More
    • Back
    • About Us
    • Contact
    • Advertise
    • Strategic Partners
  • IOT World Events
    • Back
    • Internet of Things World: San Jose
    • IoT World 2020 News
  • newsletter
  • IIoT
  • Cities
  • Energy
  • Homes/Buildings
  • Transportation/Logistics
  • Connected Health Care
  • Retail
  • AI
  • Architecture
  • Engineering/Development
  • Security
ioti.com

Security


Can Blockchain Security Safeguard IoT? Maybe, Maybe Not

Several trade press articles suggest blockchain security can protect IoT deployments from cyberthreats. Not all cybersecurity professionals, however, are convinced.
  • Written by Brian Buntz
  • 17th September 2018

According to a well-known cyber slogan, complexity is the enemy of security. So why is it that a good number of blockchain enthusiasts hail distributed ledger technology as a sort of panacea for IoT security? One of the prime reasons IoT security is challenging is its complexity and ever-growing scale. Meanwhile, blockchain, thanks to its distributed architecture, is inherently more involved than a traditional database. “Blockchain is still a new technology. It’s experimental. At this stage, if you are using it for IoT security, you are adding more complexity and probably making your deployment less secure,” said Cesar Cerrudo, chief technology officer of IOActive Labs.

While opinions vary regarding the potential of blockchain security, RSA’s Chief Technology Officer Zulfikar Ramzan also has a skeptical take: “People’s optimism around blockchain is often inversely proportional to their understanding of how it actually works,” he said. “People who understand the details, see the limitations.” Ramzan also added that it is difficult to evaluate a new technology early in the adoption cycle, observing that the those who helped develop public key infrastructure in the 1970s could have scarcely imagined its role in helping create e-commerce decades later.

Frank Hißen, the owner of an independent IT security software development and consulting business in Germany, has a similar opinion. Blockchain is “a good technology,” but it’s not a “holy grail,” Hißen said. “Moreover, its implementation has drawbacks,” which limits its potential applications for cybersecurity.

[IoT Blockchain Summit is the event that’s exploring the intersection of blockchain and IoT across industry and enterprise. Get your ticket now.]

According to Peter Tran, vice president and head of global cyber defense for Worldpay, those evaluating blockchain for IoT deployments should avoid binary conclusions when it comes to evaluating its benefits. “It’s not a matter of whether it’s a perfect fit for cybersecurity, but whether it is more of a complementary asset,” Tran said. “The ability for blockchain to orchestrate across billions of data transactions/inputs with checks and balances shouldn’t be dismissed so easily for IoT infrastructures.”

To date, some of the most mature blockchain applications are also the closest to its original purpose: removing intermediaries when transacting digital assets. A significant effort, however, is underway to extend blockchain to the physical world through asset tokenization, but at present, mature blockchain use cases involving the physical realm are far and few between.

Because blockchain uses public key cryptography — also known as asymmetric cryptography — key management becomes an important theme. Because each endpoint requires a private key, it requires a secure strategy for keeping those keys safe from prying eyes. In this way, blockchain security applied to the Internet of Things could look similar to IoT deployments using public key cryptography. “You’ll have to put a key on each device and will have to manage them in some way in order to be able to use blockchain in IoT,” Cerrudo said. One of the most secure strategies for managing private keys is the use of hardware security modules for each endpoint.  This strategy can be expensive and would require ongoing key management, as it does for IoT projects using PKI encryption.

One of blockchain’s chief selling points is the immutability of its data (although Accenture has patented an editable version of the technology). This characteristic will likely sway some companies with IoT deployments to consider using blockchain to store a trail of transactional data. “For some companies, that could be a good solution,” Cerrudo said, “but then for others, they could store that data on a database.” It is relatively simple to find database experts who can meet a given organization’s needs, but “few people know how to set up a blockchain deployment.”

The difficulties of deploying blockchain for an IoT application are compounded in an existing environment that wasn’t initially designed for the technology. “You would modify firmware and applications on top of key management,” Cerrudo said. “I see a very difficult challenge in trying to integrate blockchain with older technology.”

While the full potential of blockchain may not be apparent in this early stage of adoption, organizations grappling with the intricacies of an IoT deployment should be aware of the potential added difficulty and cost of adding blockchain into the mix. It’s understandable that organizations would want to provide “a secure solution to solve a new [cybersecurity] problem,” Cerrudo said. But there are few experts in both blockchain and cybersecurity to help deploy the technologies in tandem — especially when it involves retrofitting. “If you’re going to develop something from scratch, then you might consider blockchain for some specific solutions,” Cerrudo said. “But if you have already invested in technology and have decided: “OK, let’s put blockchain on it, I don’t think it will be easy and you’ll probably be wasting your time.”

Tags: Security Features

Related


  • Image shows welding robotics and a digital manufacturing operation.
    IoT Supply Chain Vulnerability Poses Threat to IIoT Security
    The supply chain provides building blocks for IoT but also vulnerabilities. IT pros need to ward against malicious attacks that exploit supply chain security gaps.
  • IoT Security Needs Pen Testing Approach
    IoT pen testing is a no-brainer, say experts. But don’t test everything.
  • Image shows a digital background depicting innovative technologies in security systems,
    Securing IoT Devices With Zero Trust Requires Mindset Shift
    Zero-trust approaches require a shift in mindset to ensure IoT devices have rigorous security policies applied — and the work is never done, say IT pros.
  • An Integrated Approach to IoT Security
    This e-book provides a comprehensive framework to help organizations reduce risk in IoT products and environments.

Leave a comment Cancel reply

-or-

Log in with your IoT World Today account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Related Content

  • Common Internet of Things Security Pitfalls 
  • Can Privacy-Preserving Machine Learning Overcome Data-Sharing Worries?
  • Developing a Critical Infrastructure Cybersecurity Strategy
  • Addressing IoT Security Challenges From the Cloud to the Edge 

News

View all

Webex Collaboration Banks on Hybrid Workplace Model at Cisco Live 2021

2nd April 2021

Cisco Enlists Networking Automation, CX Cloud in COVID-19 Response

31st March 2021

White Papers

View all

Telehealth and COVID Infographic

30th March 2021

Medical Supply Chain Management with Smart Devices and Sensors

30th March 2021

Special Reports

View all

Cybersecurity Protection Increasingly Depends on Machine Learning

28th October 2020

Webinars

View all

Weber’s Journey: How a Top Grill Maker Serves Up Connected Cooking

25th February 2021

From Insights to Action: Best Practices for Implementing Connected Device Security

15th December 2020

Galleries

View all

Top IoT Trends to Watch in 2020

26th January 2020

Five of the Most Promising Digital Health Technologies

14th January 2020

Industry Perspectives

View all

IoT Spending Holds Firm — Tempered by Dose of ‘IoT Pragmatism’

1st December 2020

The Great IoT Connectivity Lockdown

11th May 2020

Events

View all

Embedded IoT World 2021

28th April 2021 - 29th April 2021

The Virtual Industrial AI Summit

29th June 2021 - 30th June 2021

IoT World 2021

2nd November 2021 - 4th November 2021

Twitter

IoTWorldToday, IoTWorldSeries

🥳Happy #IoTDay! How are you celebrating? We're giving $50 off All Access Passes to join our upcoming virtual event,… twitter.com/i/web/status/1…

9th April 2021
IoTWorldToday, IoTWorldSeries

🎉 Announcing #EIOTWORLD sponsor, @InnoPhaseinc — a fabless wireless semiconductor platform company specializing in… twitter.com/i/web/status/1…

8th April 2021
IoTWorldToday, IoTWorldSeries

Digital Health Infrastructure Benefits From Cloud-to-Edge Architecture dlvr.it/RxBwQ4 https://t.co/AILVdUVWDA

7th April 2021
IoTWorldToday, IoTWorldSeries

Meet the #EIOTWORLD keynote lineup: Google, Facebook, Linux Foundation, STMicroelectronics, Antmicro, OpenHW Group,… twitter.com/i/web/status/1…

6th April 2021
IoTWorldToday, IoTWorldSeries

Network Data Analytics Supports Back-to-Work Health and Safety dlvr.it/Rx5xlL https://t.co/VvxxpdUMJ3

6th April 2021
IoTWorldToday, IoTWorldSeries

IoT Cybersecurity Act Places Security Onus on Device Makers dlvr.it/Rx2jHK https://t.co/fyd3nQ1r1Z

5th April 2021

Newsletter

Sign up for IoT World Today newsletters: vertical industry coverage on Tuesdays and horizontal tech coverage on Thursdays.

Special Reports

Our Special Reports take an in-depth look at key topics within the IoT space. Download our latest reports.

Business Resources

Find the latest white papers and other resources from selected vendors.

Media Kit and Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • IoT World Series
  • Channel Futures
  • RISC-V
  • Dark Reading
  • ITPro Today
  • Web Hosting Talk

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Login/Register

FOLLOW IoT World Today ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookies Policy
  • Terms
Copyright © 2021 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X