论文标题
启用混合区块链的安全微服务面料,用于分散的多域航空电子系统
Hybrid Blockchain-Enabled Secure Microservices Fabric for Decentralized Multi-Domain Avionics Systems
论文作者
论文摘要
人工智能(AI)和机器学习(ML),动态数据驱动应用系统(DDDAS)和层次结构云雾化计算范式的进步为增强多域系统性能提供了机会。作为代表多域情景的一个示例,“飞行”系统利用DDDAS框架来支持自主操作并提高可操作性,安全性和燃油效率。 DDDA“飞行”航空电子系统可以增强多域协调,以支持特定领域的操作。但是,传统的启用技术依靠集中式的方式来进行数据聚合,共享和安全策略执行,并且会遇到与绩效,数据出处和一致性瓶颈有关的关键问题。受到集装箱的微服务和区块链技术的启发,本文引入了Blem,Blem是一种启用混合区块链的安全微服务织物,以支持分散,安全有效的数据融合以及航空电子系统的多域操作。利用微服务体系结构的细粒度和松散耦合特征,多域操作和安全功能被解耦到多个容器化的微服务。提出了基于两级委员会共识协议的混合区块链结构,以实现分散的安全体系结构,并支持现有多域航空电子系统的数据可靠性的不可超然性,可审核性和可追溯性。我们的评估结果表明,拟议的BLEM机制支持分散的安全服务并确保对跨域边界的数据可行性的不变性,可审核性和可追溯性的可行性。
Advancement in artificial intelligence (AI) and machine learning (ML), dynamic data driven application systems (DDDAS), and hierarchical cloud-fog-edge computing paradigm provide opportunities for enhancing multi-domain systems performance. As one example that represents multi-domain scenario, a "fly-by-feel" system utilizes DDDAS framework to support autonomous operations and improve maneuverability, safety and fuel efficiency. The DDDAS "fly-by-feel" avionics system can enhance multi-domain coordination to support domain specific operations. However, conventional enabling technologies rely on a centralized manner for data aggregation, sharing and security policy enforcement, and it incurs critical issues related to bottleneck of performance, data provenance and consistency. Inspired by the containerized microservices and blockchain technology, this paper introduces BLEM, a hybrid BLockchain-Enabled secure Microservices fabric to support decentralized, secure and efficient data fusion and multi-domain operations for avionics systems. Leveraging the fine-granularity and loose-coupling features of the microservices architecture, multidomain operations and security functionalities are decoupled into multiple containerized microservices. A hybrid blockchain fabric based on two-level committee consensus protocols is proposed to enable decentralized security architecture and support immutability, auditability and traceability for data provenience in existing multi-domain avionics system. Our evaluation results show the feasibility of the proposed BLEM mechanism to support decentralized security service and guarantee immutability, auditability and traceability for data provenience across domain boundaries.