ZT&T: Secure blockchain-based tokens for service session management in Zero Trust Networks

  • Javier Jose Diaz Rivera
  • , Talha Ahmed Khan
  • , Waleed Akbar
  • , Afaq Muhammad

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

8 Scopus citations

Abstract

In the current digitalized world, the number of interconnected entities is constantly growing. Users and devices are no longer confined to the same physical or geographical region when participating in network connections. Due to this, the line that delimits the network perimeter can no longer be identified. Traditional castle-And-moat security approaches cannot accommodate the latent threats that may occur in these borderless network deployments. Zero Trust Networking, alongside Software Defined Perimeter (SDP) concepts, aims to extend the perimeter of trust to every entity connected to the network regardless of their physical location. Authentication, access control, and verification methods must constantly be applied for all the participants in the network, as everything is considered untrustworthy. The requirement of complex security mechanisms alongside constant trust assurance for every interaction may challenge the realization of the Zero Trust vision. Blockchain is an emergent technology that can be integrated into Zero Trust to leverage these requirements. The data decentralization, anonymity, cryptography, and immutable record of transactions can provide the required security for Zero Trust. In this work, we propose a mechanism for assuring secure service session management with the use of blockchain capabilities. Non-Fungible-Tokens (NFT) are applied to access and provider tokens representing a policy agreement for service consumption. The tokens are mapped to the public addresses of entities registered in the blockchain. The access and provider tokens are encoded with metadata defining the service sessions' expiration. The proposal is realized through the use of an emerging open source Zero Trust platform (OpenZiti), a private Ethereum blockchain (Hyperledger Besu), and a session manager decentralized application (ZT&T) for handling the creation of policies and blockchain interaction.

Original languageEnglish
Title of host publication2022 6th Cyber Security in Networking Conference, CSNet 2022
EditorsLuis Henrique M. K. Costa, Igor Monteiro Moraes, Aruna Seneviratne, Diogo M. F. Mattos, Marc Oliver Pahl, Carol Fung, Marcelo G. Rubinstein
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9798350397222
DOIs
StatePublished - 2022
Externally publishedYes
Event6th Cyber Security in Networking Conference, CSNet 2022 - Rio de Janeiro, Brazil
Duration: 24 Oct 202226 Oct 2022

Publication series

Name2022 6th Cyber Security in Networking Conference, CSNet 2022

Conference

Conference6th Cyber Security in Networking Conference, CSNet 2022
Country/TerritoryBrazil
CityRio de Janeiro
Period24/10/2226/10/22

Bibliographical note

Publisher Copyright:
© 2022 IEEE.

Keywords

  • NFT
  • Software Defined Perimeter
  • Zero Trust
  • access control
  • blockchain

ASJC Scopus subject areas

  • Computer Networks and Communications
  • Hardware and Architecture
  • Information Systems and Management
  • Safety, Risk, Reliability and Quality

Fingerprint

Dive into the research topics of 'ZT&T: Secure blockchain-based tokens for service session management in Zero Trust Networks'. Together they form a unique fingerprint.

Cite this