

de Recherche et d’Innovation
en Cybersécurité et Société
Mehrban, A.; Houda, Z. A. El; Moudoud, H.; Brik, B.; Khoukhi, L.
Securing O-RAN Equipment Using Blockchain-Based Supply Chain Verification Article d'actes
Dans: Int. Wirel. Commun. Mob. Comput. Conf., IWCMC, p. 1570–1575, Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 979-833150887-6 (ISBN), (Journal Abbreviation: Int. Wirel. Commun. Mob. Comput. Conf., IWCMC).
Résumé | Liens | BibTeX | Étiquettes: Access network equipment, Authentication, Block-chain, Blockchain, Cryptography, Denial-of-service attack, Firmware, Firmware authentication, Multi-vendor, Network architecture, Network security, O-RAN, Open radio access network, Radio access networks, Security, Security systems, Security vulnerabilities, Supply Chain Verification, Supply chains, Telecommunications networks
@inproceedings{mehrbanSecuringORANEquipment2025,
title = {Securing O-RAN Equipment Using Blockchain-Based Supply Chain Verification},
author = {A. Mehrban and Z. A. El Houda and H. Moudoud and B. Brik and L. Khoukhi},
url = {https://www.scopus.com/pages/publications/105011364438?origin=resultslist},
doi = {10.1109/IWCMC65282.2025.11059692},
isbn = {979-833150887-6 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {Int. Wirel. Commun. Mob. Comput. Conf., IWCMC},
pages = {1570–1575},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {The Open Radio Access Network (O-RAN) architecture has enabled the integration of multi-vendor equipment, yielding a significant enhancement in the flexibility and interoperability of telecommunications networks. However, this openness has also introduced new security vulnerabilities, particularly in supply chain integrity. Malicious actors may exploit weaknesses at various stages of production, distribution, or integration, leading to critical threats such as data tampering, unauthorized access, and denial-of-service (DOS) attacks. To address these challenges, this paper proposes a novel blockchain-based framework designed to secure the O-RAN supply chain. The proposed solution leverages a private permissioned blockchain ledger and cryptographic firmware authentication to ensure the integrity and authenticity of network equipment throughout its lifecycle. Specifically, the framework consists of: (1) a decentralized architecture integrating blockchain network components, equipment node validators, and secure firmware authentication mechanisms; and (2) a consensus-based verification model to enhance trust and transparency within the supply chain. To the best of our knowledge, this is one of the first approaches to use blockchain for O-RAN supply chain security, and also addressing emerging security threats in a scalable and tamper-resistant manner. Experimental validation and security assessments demonstrate the effectiveness of the proposed framework in mitigating supply chain risks, making it a promising solution for ensuring trust and robustness in next-generation O-RAN ecosystems. © 2025 IEEE.},
note = {Journal Abbreviation: Int. Wirel. Commun. Mob. Comput. Conf., IWCMC},
keywords = {Access network equipment, Authentication, Block-chain, Blockchain, Cryptography, Denial-of-service attack, Firmware, Firmware authentication, Multi-vendor, Network architecture, Network security, O-RAN, Open radio access network, Radio access networks, Security, Security systems, Security vulnerabilities, Supply Chain Verification, Supply chains, Telecommunications networks},
pubstate = {published},
tppubtype = {inproceedings}
}
Moudoud, H.; Houda, Z. A. El; Brik, B.
A Blockchain-Based Cross-Domain DDoS Mitigation in Consumer Networks Article de journal
Dans: IEEE Transactions on Consumer Electronics, vol. 71, no 2, p. 7095–7104, 2025, ISSN: 00983063 (ISSN).
Résumé | Liens | BibTeX | Étiquettes: Block-chain, Blockchain, Consumer network, Denial-of-service attack, digital twins, Distributed denial of service, Edge Computing, Fuzzy logic, Fuzzy-Logic, Inter-domain, Internet service providers, Network function virtualization, Network functions, NFV, Platform as a Service (PaaS), Resources sharing, SDN, Software-defined networkings, Virtualizations
@article{moudoudBlockchainBasedCrossDomainDDoS2025,
title = {A Blockchain-Based Cross-Domain DDoS Mitigation in Consumer Networks},
author = {H. Moudoud and Z. A. El Houda and B. Brik},
url = {https://www.scopus.com/pages/publications/105002613162?origin=resultslist},
doi = {10.1109/TCE.2025.3559451},
issn = {00983063 (ISSN)},
year = {2025},
date = {2025-01-01},
journal = {IEEE Transactions on Consumer Electronics},
volume = {71},
number = {2},
pages = {7095–7104},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Distributed Denial of Service (DDoS) attacks pose significant threats to the availability and security of consumer networks and Internet service providers (ISPs). This is a significant concern due to the potential vulnerabilities and security risks associated with the rapid increase in the number of insecure Internet of Things (IoT) devices. Adopting an inter-domain DDoS collaboration strategy is a promising solution to address this issue. However, manual configuration and management of resources across multiple domains can be time-consuming, error-prone, and inefficient. Moreover, the existing inter-domain DDoS mitigation mechanisms (i.e., Cooperative Defense mechanisms) are facing obstacles due to the lack of incentives for cooperation, low flexibility, and high cost. Most importantly, many of them are centralized, which risks single points of failure, hampering collaboration and resource sharing among Autonomous Systems (ASs). The new emerging techniques, such as Digital-Twin (DT) empowered by Network Function Virtualization (NFV), Software-Defined Networking (SDN), and Blockchain introduce new opportunities for efficient and flexible inter-domain DDoS collaboration i.e., resources sharing among multiple SDN-based domains. In this context, we propose SecureShare, a novel digital twin-enabled inter-domain DDoS mitigation framework that allows for an efficient, fair, and secure dynamic resource-sharing among SDN-based domains to deal with large-scale DDoS attacks through resource sharing. The deployment of SecureShare is executed within Ethereum’s test network, Sepolia. Furthermore, we performed extensive experiments employing Microsoft Azure Digital Twins (ADT), a platform-as-a-service tool for generating twin graphs of physical objects. The experimental results show that SecureShare achieves promising results in terms of efficiency, security, and flexibility. © 1975-2011 IEEE.},
keywords = {Block-chain, Blockchain, Consumer network, Denial-of-service attack, digital twins, Distributed denial of service, Edge Computing, Fuzzy logic, Fuzzy-Logic, Inter-domain, Internet service providers, Network function virtualization, Network functions, NFV, Platform as a Service (PaaS), Resources sharing, SDN, Software-defined networkings, Virtualizations},
pubstate = {published},
tppubtype = {article}
}



