Distributed Ledger for Cybersecurity: Issues and Challenges in Railways
Abstract
:1. Introduction
2. Research Methodology
3. Technical Framework
3.1. Cybersecurity in Railways
3.2. Distributed Ledgers
3.3. Smart Contracts
4. Results
4.1. Properties of Distributed Ledgers
4.2. Taxonomy
- Governance
- Business
- Technology
5. Discussion
6. Conclusions
Author Contributions
Funding
Data Availability Statement
Acknowledgments
Conflicts of Interest
References
- Alexandersson, G.; Hultén, S. The Swedish Railway Deregulation Path. Rev. Netw. Econ. 2009, 7, 18–36. [Google Scholar] [CrossRef]
- Asteris, M. Rail Privatisation: A Platform for Success. Econ. Aff. 1994, 14, 19–23. [Google Scholar] [CrossRef]
- Alexandersson, G.; Hultén, S.; Nilsson, J.-E.; Pyddoke, R. The Liberalization of Railway Passenger Transport in Sweden: Outstanding Regulatory Challenges; Working Papers Transport Economics 2012:5; Centre for Transport Studies Stockholm: Stockholm, Sweden, 2012. [Google Scholar]
- Wellings, R. The Privatisation of the UK Railway Industry: An Experiment in Railway Structure. Econ. Aff. 2014, 34, 255–266. [Google Scholar] [CrossRef]
- Saito, T. Japanese private railway companies and their business diversification. Jpn. Railw. Transp. Rev. 1997, 10, 2–9. [Google Scholar]
- Taylor, Z.; Ciechański, A. Deregulation in Polish rail transport. Transp. Rev. 2006, 26, 305–324. [Google Scholar] [CrossRef]
- Hilmola, O.-P.; Leino, J. Deregulation and privatization process in Finnish railways. In Second Research Meeting Held at Moscow—Strategic Role of Logistics and Supply Chain Management; Research Report Vol. 177; Lappeenranta University of Technology, Department of Industrial Engineering and Management: Lappeenranta, Finland, 2006; pp. 81–96. [Google Scholar]
- Thaduri, A.; Aljumaili, M.; Kour, R.; Karim, R. Cybersecurity for eMaintenance in railway infrastructure: Risks and consequences. Int. J. Syst. Assur. Eng. Manag. 2019, 10, 149–159. [Google Scholar] [CrossRef] [Green Version]
- Kour, R.; Aljumaili, M.; Karim, R.; Tretten, P. eMaintenance in railways: Issues and challenges in cybersecurity. Proc. Inst. Mech. Eng. Part F J. Rail Rapid Transit 2019, 233, 1012–1022. [Google Scholar] [CrossRef]
- Asplund, M. Wayside Condition Monitoring System for Railway Wheel Profiles: Applications and Performance Assessment. Ph.D. Thesis, Luleå University of Technology, Luleå, Sweden, 2016; p. 162. [Google Scholar]
- Wang, H.; Wang, Y.; Cao, Z.; Li, Z.; Xiong, G. An overview of blockchain security analysis. In Communications in Computer and Information Science; Springer: Singapore, 2019; Volume 970, pp. 55–72. [Google Scholar] [CrossRef] [Green Version]
- Sturmanis, A.; Hudenko, J.; Juruss, M. The Application of Blockchain Technologies for Rail Transit Customs Procedures; Springer: Cham, Switzerland, 2020; Volume 117. [Google Scholar] [CrossRef]
- Abbas, Y.; Martinetti, A.; Moerman, J.J.; Hamberg, T.; van Dongen, L.A. Do you have confidence in how your rolling stock has been maintained? A blockchain-led knowledge-sharing platform for building trust between stakeholders. Int. J. Inf. Manag. 2020, 55, 102228. [Google Scholar] [CrossRef]
- Preece, J.D.; Easton, J.M. Blockchain Technology as a Mechanism for Digital Railway Ticketing. In Proceedings of the 2019 IEEE International Conference on Big Data (Big Data), Los Angeles, CA, USA, 9–12 December 2019; IEEE: Piscataway, NJ, USA, 2019; pp. 3599–3606. [Google Scholar] [CrossRef]
- Palo, M.; Galar, D.; Nordmark, T.; Asplund, M.; Larsson, D. Condition monitoring at the wheel/rail interface for decision-making support. Proc. Inst. Mech. Eng. Part F J. Rail Rapid Transit 2014, 228, 705–715. [Google Scholar] [CrossRef]
- Ariyachandra, M.R.M.F.; Brilakis, I. Understanding the challenge of digitally twinning the geometry of existing rail infrastructure. In Proceedings of the 12th FARU International Research Conference, Homagama, Colombo, Sri Lanka, 3–4 December 2019; pp. 25–32. [Google Scholar] [CrossRef]
- Lohr, M.; Hund, J.; Jurjens, J.; Staab, S. Ensuring genuineness for selectively disclosed confidential data using distributed ledgers: Applications to rail wayside monitoring. In Proceedings of the 2019 2nd IEEE International Conference on Blockchain (Blockchain 2019), Atlanta, GA, USA, 14–17 July 2019; pp. 477–482. [Google Scholar] [CrossRef] [Green Version]
- Naser, F. Review: The Potential Use of Blockchain Technology in Railway Applications. In Proceedings of the 2018 IEEE International Conference on Big Data, Seattle, WA, USA, 10–13 December 2018; pp. 4516–4524. [Google Scholar]
- Cohen, E.A.; Hughes, T.P. Rescuing Prometheus; Vintage: New York, NY, USA, 1998; Volume 77. [Google Scholar] [CrossRef]
- Peirone, D. The Governance of Complex Systems: The Case of British Railways. Econ. ePolit. Ind. 2007, 34, 47–70. [Google Scholar]
- Khatri, V.; Brown, C.V. Designing data governance. Commun. ACM 2010, 53, 148–152. [Google Scholar] [CrossRef]
- Commission, E. Roadmap to a Single European Transport Area: Towards a Competitive and Resource Efficient Transport System: White Paper; Publications Office of the European Union: Luxembourg, 2011. [Google Scholar]
- Jägare, V.; Juntti, U.; Karim, R. Governance of digital data sharing in a cross-organisational railway maintenance context. In Proceedings of the 5th International Workshop and Congress on eMaintenance, Stockholm, Sweden, 14–15 May 2019; Luleå University of Technology: Luleå, Sweden, 2019; pp. 1–8. [Google Scholar]
- Juntti, U.; Larsson, L.; Karim, R. Implementation of eMaintenance concept within the Swedish railway. In Proceedings of the COMADEM 2014, Brisbane, Australia, 16–18 September 2014. [Google Scholar]
- Lotfi, Z.; Mukhtar, M.; Sahran, S.; Zadeh, A.T. Information Sharing in Supply Chain Management. Procedia Technol. 2013, 11, 298–304. [Google Scholar] [CrossRef] [Green Version]
- Linton, J. Diffusion of Innovations; Simon and Schuster: New York, NY, USA, 1998; Volume 9. [Google Scholar] [CrossRef]
- ISO. ISO/IEC 27032:2012. Information Technology—Security Techniques—Guidelines for Identification Collection Acquisition and Preservation of Digital Evidence; ISO: Geneva, Switzerland, 2012. [Google Scholar]
- Disterer, G. ISO/IEC 27000, 27001 and 27002 for Information Security Management. J. Inf. Secur. 2013, 4, 92–100. [Google Scholar] [CrossRef] [Green Version]
- Pita, A.M. Real-World Cyber Security Challenges in Rail Systems. Available online: https://railsystemsaustralia.com.au/wp-content/uploads/2020/02/Real-World%20Cyber%20Security%20Challenges%20in%20Rail%20Systems_final.pdf (accessed on 1 November 2020).
- Kour, R.; Karim, R. Cybersecurity workforce in railway: Its maturity and awareness. J. Qual. Maint. Eng. 2020, 27, 453–464. [Google Scholar] [CrossRef]
- Lamport, L.; Shostak, R.; Pease, M. The Byzantine Generals Problem. In ACM Transactions on Programming Languages and Systems (TOPLAS); Association for Computing Machinery: New York, NY, USA, 1982; Volume 4, pp. 382–401. [Google Scholar] [CrossRef] [Green Version]
- Nakamoto, S. Bitcoin: A Peer-to-Peer Electronic Cash System. SSRN Electron. J. 2008. [Google Scholar] [CrossRef]
- Benčić, F.M.; Žarko, I.P. Distributed ledger technology: Blockchain compared to directed acyclic graph. In Proceedings of the 2018 IEEE 38th International Conference on Distributed Computing Systems (ICDCS), Vienna, Austria, 2–6 July 2018; IEEE: Piscataway, NJ, USA, 2018; Volume 2018, pp. 1569–1570. [Google Scholar] [CrossRef] [Green Version]
- Antonopoulos, A.M. Mastering Bitcoin: Unlocking Digital Cryptocurrencies; O’Reilly Media, Inc.: Newton, MA, USA, 2014; ISBN 978-1-449-37404-4. [Google Scholar]
- Monrat, A.A.; Schelén, O.; Andersson, K. A survey of blockchain from the perspectives of applications, challenges, and opportunities. IEEE Access 2019, 7, 117134–117151. [Google Scholar] [CrossRef]
- Monrat, A.A.; Schelen, O.; Andersson, K. Performance Evaluation of Permissioned Blockchain Platforms. In Proceedings of the 2020 IEEE Asia-Pacific Conference on Computer Science and Data Engineering (CSDE), Gold Coast, Australia, 16–18 December 2020. [Google Scholar] [CrossRef]
- Dinh, T.T.A.; Wang, J.; Chen, G.; Liu, R.; Ooi, B.C.; Tan, K.L. BLOCKBENCH: A framework for analyzing private blockchains. In Proceedings of the 2017 ACM International Conference on Management of Data, Chicago, IL, USA, 14–19 May 2017; Part F1277. Association for Computing Machinery: Chicago, IL, USA, 2017; pp. 1085–1100. [Google Scholar] [CrossRef]
- De Angelis, S.; Aniello, L.; Baldoni, R.; Lombardi, F.; Margheri, A.; Sassone, V. PBFT vs proof-of-authority: Applying the CAP theorem to permissioned blockchain. CEUR Workshop Proc. 2018, 2058, 1–11. [Google Scholar]
- Khatoon, A. A blockchain-based smart contract system for healthcare management. Electronics 2020, 9, 94. [Google Scholar] [CrossRef] [Green Version]
- Kuo, T.T.; Kim, H.E.; Ohno-Machado, L. Blockchain distributed ledger technologies for biomedical and health care applications. J. Am. Med. Inform. Assoc. 2017, 24, 1211–1220. [Google Scholar] [CrossRef] [Green Version]
- Bahga, A.; Madisetti, V.K. Blockchain Platform for Industrial Internet of Things. J. Softw. Eng. Appl. 2016, 9, 533–546. [Google Scholar] [CrossRef] [Green Version]
- Brody, P.; Pureswaran, V. Device democracy: Saving the future of the internet of things. IBM Sept. 2014, 1, 15. [Google Scholar]
- Dorri, A.; Steger, M.; Kanhere, S.S.; Jurdak, R. BlockChain: A Distributed Solution to Automotive Security and Privacy. IEEE Commun. Mag. 2017, 55, 119–125. [Google Scholar] [CrossRef] [Green Version]
- Astarita, V.; Giofrè, V.P.; Mirabelli, G.; Solina, V. A Review of Blockchain-Based Systems in Transportation. Information 2020, 11, 21. [Google Scholar] [CrossRef] [Green Version]
- Caro, M.P.; Ali, M.S.; Vecchio, M.; Giaffreda, R. Blockchain-based traceability in Agri-Food supply chain management: A practical implementation. In Proceedings of the 2018 IoT Vertical and Topical Summit on Agriculture—Tuscany (IOT Tuscany), Tuscany, Italy, 8–9 May 2018; IEEE: Piscataway, NJ, USA, 2018; pp. 1–4. [Google Scholar] [CrossRef] [Green Version]
- Francisco, K.; Swanson, D. The Supply Chain Has No Clothes: Technology Adoption of Blockchain for Supply Chain Transparency. Logistics 2018, 2, 2. [Google Scholar] [CrossRef] [Green Version]
- Dobrovnik, M.; Herold, D.; Fürst, E.; Kummer, S. Blockchain for and in Logistics: What to Adopt and Where to Start. Logistics 2018, 2, 18. [Google Scholar] [CrossRef] [Green Version]
- Benbunan-Fich, R.; Castellanos, A. Digitalization of land records: From paper to blockchain. In Proceedings of the International Conference on Information Systems 2018, Libertad City, Ecuador, 10–12 January 2018. [Google Scholar]
- Ølnes, S.; Ubacht, J.; Janssen, M. Blockchain in government: Benefits and implications of distributed ledger technology for information sharing. Gov. Inf. Q. 2017, 34, 355–364. [Google Scholar] [CrossRef] [Green Version]
- Zhang, L.; Huang, Y.; Jiang, T. High-speed railway environmental monitoring data identity authentication scheme based on consortium blockchain. In Proceedings of the 2019 2nd International Conference on Blockchain Technology and Applications, Xi’an China, 9–11 December 2019; Association for Computing Machinery: New York, NY, USA, 2019; pp. 7–13. [Google Scholar] [CrossRef]
- Kuperberg, M.; Kindler, D.; Jeschke, S. Are Smart Contracts and Blockchains Suitable for Decentralized Railway Control? arXiv 2019, 5, 36–61. [Google Scholar] [CrossRef]
- Preece, J.; Easton, J.; Preece, J.D.; Easton, J.M. A Review of Prospective Applications of Blockchain Technology in the Railway Industry. Int. J. Railw. Technol. 2019. preprint. [Google Scholar] [CrossRef]
- Buterin, V. Ethereum White Paper: A Next Generation Smart Contract & Decentralized Application Platform. Etherum, 2014. Available online: https://ethereum.org/en/whitepaper/ (accessed on 1 November 2019).
- Wood, G. Ethereum: A Secure Decentralised Generalised Transaction Ledger. (Yellow Paper). Available online: http://gavwood.com/paper.pdf (accessed on 1 July 2020).
- Androulaki, E.; Barger, A.; Bortnikov, V.; Cachin, C.; Christidis, K.; De Caro, A.; Enyeart, D.; Ferris, C.; Laventman, G.; Manevich, Y.; et al. Hyperledger Fabric: A Distributed Operating System for Permissioned Blockchains. In Proceedings of the Thirteenth EuroSys Conference, Porto, Portugal, 23–26 April 2018; Association for Computing Machinery: New York, NY, USA, 2018; pp. 1–15. [Google Scholar] [CrossRef] [Green Version]
- JP Morgan Chase Quorum Whitepaper; New York JP Morgan Chase. 2016. Available online: https://github.com/ConsenSys/quorum/blob/master/docs/Quorum%20Whitepaper%20v0.2.pdf (accessed on 1 June 2020).
- Hearn, M. Corda: A Distributed Ledger; Whitepaper. 2016. Available online: https://www.r3.com/wp-content/uploads/2017/06/corda_nontechnical_R3.pdf (accessed on 1 July 2020).
- Iansiti, M.; Lakhani, K.R. The truth about blockchain. Harv. Bus. Rev. 2017, 2017, 119–127. [Google Scholar]
- Szabo, N. Smart Contracts: Building Blocks for Digital Markets. EXTROPY J. Transhum. Thought 1996, 18, 50–53. [Google Scholar]
Taxonomy of issues and challenges related to cybersecurity in railways | Governance | Aspects related to overall governance of the system |
Regulation | Defining the rules of operations for data management | |
Democratisation | Brings in equality of rights, opportunities and rules for data access | |
Legislative aspects | Legal contracts defining data access, and interpretation of such contracts | |
Safety | Safety related to data collection, processing, analysis, exchange etc. | |
Confidentiality | Duty of the organization to maintain secrecy of data | |
Privacy | Right of individual to maintain secrecy of personal data | |
Fairness | Fair share of information, risk and returns to all stakeholders | |
Transparency | Assurance of source and openness about collection, use and sharing of data | |
Authentication and authorisation | Open standardized methods of authentication and authorization for cyber and physical systems | |
Ownership | Ownership establishment, lease and transfer with auditable records | |
Integrity | Secure data and metadata, transfer and storage, authenticated source, auditable record and ownership | |
Proprietary systems | Indispensable due to organization requirements, incompatible between stakeholders | |
Organizational requirements | Requirements to fulfil organizations interests and future plans | |
Standards | Essential for interoperability, economics of scale and to add momentum to research | |
Upgradability | Secure, resilient, robust mechanism to perform unsupervised software upgrade | |
Awareness | Awareness of short- and long-term goals, plans and activities | |
Business | Aspects related to business operations | |
Relative advantage | Advantages of new technology as compared to current practices, which may not only be in technical domain | |
Compatibility | Compatibility and improvement from current processes, not just digitalization of the current process | |
Complexity | Complexity in terms of technology adaptation, resource availability, cost of transition | |
Trialability | Evaluate and apply solutions to well understood problems to access usability | |
Observability | Clear and measurable benefits, through adaptation of new technology | |
Awareness | Awareness of core requirements of business operations procedures | |
Technology | Aspects related to technology requirements | |
Cybersecurity | Managing and maintaining secure systems | |
Cost trade-off | Design time decisions can impact in the long run and can be difficult to anticipate | |
Data Volume | Acquiring, transmission, storage and processing issues due to large amount of data | |
Data Silos | Impacts efficiency of decision-making process due to limitations of data availability | |
Backward compatibility | Backward compatibility is required to maintain system access and data exchange | |
Data formats | Incompatible data storage and exchange formats, lock-in with selected data formats | |
Technical constraints | Incompatible technology stacks, data processing models and domain requirements between partners | |
Technical risk | Risk due to lack of understanding of system complexity, limitations of technology | |
Awareness | Awareness of available technology, solved problems and technical issues |
Publisher’s Note: MDPI stays neutral with regard to jurisdictional claims in published maps and institutional affiliations. |
© 2021 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
Share and Cite
Patwardhan, A.; Thaduri, A.; Karim, R. Distributed Ledger for Cybersecurity: Issues and Challenges in Railways. Sustainability 2021, 13, 10176. https://doi.org/10.3390/su131810176
Patwardhan A, Thaduri A, Karim R. Distributed Ledger for Cybersecurity: Issues and Challenges in Railways. Sustainability. 2021; 13(18):10176. https://doi.org/10.3390/su131810176
Chicago/Turabian StylePatwardhan, Amit, Adithya Thaduri, and Ramin Karim. 2021. "Distributed Ledger for Cybersecurity: Issues and Challenges in Railways" Sustainability 13, no. 18: 10176. https://doi.org/10.3390/su131810176
APA StylePatwardhan, A., Thaduri, A., & Karim, R. (2021). Distributed Ledger for Cybersecurity: Issues and Challenges in Railways. Sustainability, 13(18), 10176. https://doi.org/10.3390/su131810176