Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security

9/5/2018
08:00 PM

7 Ways Blockchain is Being Used for Security

Blockchain is being used as a security tool. If you haven't thought about adopting it, you might want to reconsider your take.
2 of 8

Distributed Identity
Identity on the network comes in two flavors: One is the identity of the user; the other, the identity of the device. In the case of the IoT, where there often is no user in the traditional sense, authenticating the identity of the device itself is critical, and a blockchain has been introduced to establish and maintain those device identities.
IOTA is a 'permissionless blockchain' that seeks to do a number of things around the IoT, including establishing the identity of devices. It does this in the context of providing a micro-payment infrastructure to allow consumers and organizations to pay for IoT services on a per-use basis, but the payments aren't required for the identities to be authenticated.
The basis of the IOTA model is the 'tangle,' which is a combination of Full Nodes (defined as a full peer-to-peer member of the network) and Light Nodes (which must connect to Full Nodes in order to complete transactions). It is a variation on the traditional flat blockchain, but it does allow less powerful IoT devices to be part of the verified chain and remain fully identified and trusted.
(Image: Radu Bercan VIA SHUTTERSTOCK)

Distributed Identity

Identity on the network comes in two flavors: One is the identity of the user; the other, the identity of the device. In the case of the IoT, where there often is no user in the traditional sense, authenticating the identity of the device itself is critical, and a blockchain has been introduced to establish and maintain those device identities.

IOTA is a "permissionless blockchain" that seeks to do a number of things around the IoT, including establishing the identity of devices. It does this in the context of providing a micro-payment infrastructure to allow consumers and organizations to pay for IoT services on a per-use basis, but the payments aren't required for the identities to be authenticated.

The basis of the IOTA model is the "tangle," which is a combination of Full Nodes (defined as a full peer-to-peer member of the network) and Light Nodes (which must connect to Full Nodes in order to complete transactions). It is a variation on the traditional flat blockchain, but it does allow less powerful IoT devices to be part of the verified chain and remain fully identified and trusted.

(Image: Radu Bercan VIA SHUTTERSTOCK)

2 of 8
Comment  | 
Print  | 
Comments
Oldest First  |  Newest First  |  Threaded View
Jesussavesme@1
50%
50%
[email protected],
User Rank: Apprentice
11/6/2018 | 12:16:34 AM
Helpful article
Thanks for your article .really helpms me a lot

https://socialprachar.com/31-10-18-what-is-blockchain-technology/?ref=sudheer
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Our Endpoint Protection system is a little outdated... 
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-16246
PUBLISHED: 2019-12-12
Intesync Solismed 3.3sp1 allows Local File Inclusion (LFI), a different vulnerability than CVE-2019-15931. This leads to unauthenticated code execution.
CVE-2019-17358
PUBLISHED: 2019-12-12
Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and control actions taken by Cacti or potentially cause memory corruption in the PHP ...
CVE-2019-17428
PUBLISHED: 2019-12-12
An issue was discovered in Intesync Solismed 3.3sp1. An flaw in the encryption implementation exists, allowing for all encrypted data stored within the database to be decrypted.
CVE-2019-18345
PUBLISHED: 2019-12-12
A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as well as perform all actions in the name of the user. If the user is an administrat...
CVE-2019-19198
PUBLISHED: 2019-12-12
The Scoutnet Kalender plugin 1.1.0 for WordPress allows XSS.