Skip to content
Open access

BTR-SDN: A Blockchain-Enabled Trusted Routing Scheme for SDN Interdomain

Jul 2026 · Journal of Network and Systems Management · Vol 34 · 0 citations · 39 references

TL;DR

A blockchain-enabled trusted routing scheme for SDN inter-domain communication, denoted as BTR-SDN, which achieves a 20.5% higher malicious node detection rate and improves bandwidth utilization by 10.7% compared to benchmark schemes, maintaining high throughput even under dynamic adversarial conditions.

Abstract

With the evolution of Software-Defined Networking (SDN) toward distribution and servitization, multi-controller architectures have been widely adopted to enhance scalability. However, such architectures face challenges in inter-domain trust and scalability. To address these issues, this paper proposes a blockchain-enabled trusted routing scheme for SDN inter-domain communication, denoted as BTR-SDN. First, a multi-dimensional model based on the Fuzzy Analytic Hierarchy Process (FAHP) is designed to quantify node trust values, and a sliding-window trust recovery mechanism with a time-decay factor is introduced to enable penalized nodes to regain trust through compliant behaviors gradually. Second, a trust-aware hierarchical topology reconstruction and route-pruning mechanism is introduced to adaptively adjust the network view and path selection strategy based on trust evaluation results. Third, to address scalability bottlenecks, we construct a layered “on-chain anchoring + off-chain storage” architecture. Critical trust proofs are anchored on-chain for attestation, while voluminous routing data is stored off-chain. Experimental results demonstrate that BTR-SDN achieves a 20.5% higher malicious node detection rate and improves bandwidth utilization by 10.7% compared to benchmark schemes, maintaining high throughput even under dynamic adversarial conditions.

Read PDF

Similar papers

Open access Jul 2026

H-PBFT: A Hierarchical and Credit-Aware PBFT Consensus Mechanism for Blockchain-Based Intelligent Transportation Systems

Simulation results show that compared with standard PBFT, Q-PBFT, and APBFT, H-PBFT exhibits significant advantages in consensus latency, throughput, and view switching recovery time, and maintains high system robustness even in complex network environments with malicious nodes.

Zhen-Hua Wang, Jiangang Hu, Xinmeng Wang et al. · 0 citations
Conference Aug 2026

D2S-BFT: A General Performance Evaluation Framework for Sharded Blockchain Networks

Blockchain technology enables decentralized trust, yet traditional blockchain networks face critical scalability limitations under large-scale deployments. Sharding improves throughput through parallel processing, but existing sharded BFT architectures still suffer from severe hierarchical coupling between shards and the verification committee. Moreover, the complex asynchronous competition and backoff/retransmission dynamics in sharded blockchain services remain largely unmodeled, leaving the network-level steady-state behavior of sharded blockchains poorly understood. To address these challenges, we propose D2S-BFT, a novel Decoupled Double-Star Byzantine Fault-Tolerant architecture, which physically decouples local intra-shard consensus from global verification. For rigorous performance evaluation, we establish a randomized-service double-star service system and cast the cross-shard competition mechanism as a finite-source Markov chain. We derive the state transition probability matrix under general load conditions, compute the extended sojourn time, and construct an end-to-end transaction on-chain latency equation that explicitly incorporates encryption overhead, network delay, and queuing delay. The resulting D2S queuing model, expressed in the non-classical Kendall notation L/G/n=2/inf/L-RSS, provides strict theoretical boundary constraints on system performance. It demonstrates that D2S-BFT can effectively alleviate transaction congestion and ensure robust operation, while also laying a rigorous analytical foundation for model-driven configuration optimization in large-scale dynamic blockchain environments.

Ji-Qiang Liu, Lijun Sun, Xiao Chen et al. · 0 citations
Open access Aug 2026

iTZBEI: ІНТЕГРАЛЬНА МЕТРИКА БЕЗПЕКИ ДЛЯ SDN-АРХІТЕКТУР З ІНТЕГРАЦІЄЮ ZERO TRUST ТА BLOCKCHAIN

The subject matter of the article is the iTZBEI (Integrated Trust–ZTA–Blockchain SDN Efficiency Index) – a novel composite metric for quantitative security assessment of software-defined networks (SDN) integrating Zero Trust Architecture (ZTA) and Blockchain technologies. The relevance of the research is determined by the fact that the centralized SDN control model generates critical vulnerabilities, including DDoS attacks, unauthorized routing manipulation, and insider threats – for which no unified quantitative evaluation framework currently exists. The study introduced a formalized aggregated security metric that enables continuous monitoring and comparative assessment across all components of the SDN–ZTA–Blockchain architecture. The tasks to be solved include: (1) identification of principal SDN attack vectors; (2) formalization of a transaction-processing algorithm covering the full access lifecycle; (3) definition of nine local security indicators; and (4) construction of the iTZBEI index with justified weighting coefficients. The methods used combine mathematical formalization of access control processes, cryptographic transaction verification, and experimental emulation of attack scenarios in a Mininet–OpenDaylight–Hyperledger Fabric environment. Conclusions. The obtained results of the article consist in the development of a functional algorithm that performs dynamic verification of user requests, makes adaptive authorization decisions according to the principles of least privilege, and records these decisions in an immutable distributed ledger. A metrics system is proposed, including local indicators such as the Continuous Authorisation Integrity Score (CAIS), the Blockchain Audit Integrity Score (BAIS), and the Local Policy Integrity (LPI). On this basis, the generalized Integrated Trust and Zero-Trust Blockchain Evaluation Index (iTZBEI) is described as an aggregated metric for comparative evaluation and continuous monitoring of the network’s security state. Scientific novelty. This study introduces a unified SDN + ZTA + Blockchain framework for network security, formalizes a transaction-level algorithm that directly links access decisions with distributed audit procedures, and proposes the iTZBEI metric as the first integral indicator for evaluating the integration’s effectiveness in dynamic network environments.

Oleksandr Pidpalyi, Oleksandr Romanov, L. Globa et al. · 0 citations
Open access Aug 2026

A behavior-based trust-gating framework for securing permissioned IoT blockchains using proof of authority

This work demonstrates that a dynamic, reputation-based security layer can provide near-total protection against the modeled threats at negligible performance cost, offering a viable, highly effective solution for securing resource-constrained IoT deployments.

Natraj N. A., A. T, B. M. · 0 citations
Open access Aug 2026

Quantum-resistant blockchain-based trust management for IoT networks

The rapid development of the Internet of Things (IoT) has placed considerable pressure on both security and stability in heterogeneous, resource-constrained networks. In such dynamic environments, trust management is a central issue to determine which service providers can be trusted and to combat malicious activity. Although blockchain-based solutions have offered a means for decentralized, tamper-resistant trust management, most rely on classical cryptographic primitives, which are vulnerable to future quantum computing attacks. This study proposes a Quantum-Resistant Blockchain-Based Trust Management (QR-BCTM) framework in which Post-Quantum Cryptographic mechanisms, Permissioned Blockchain Platform, and Fog-assisted Trust Management architecture are combined and utilized in IoT networks. The framework introduces a quantum-aware trust computation model that combines behavioral trust, indirect recommendations, and a cryptographic assurance score quantifying each participant’s compliance with security requirements. Trust evidence is compressed to reduce blockchain storage and communication overhead, while the hierarchical fog-blockchain architecture offloads computationally intensive operations from resource-constrained IoT devices. The performance of the framework has been simulated in the presence of an adversary, including bad-mouthing, ballot-stuffing, on-off behavior, and identity attacks using a Sybil-type mechanism. Trust accuracy, false trust acceptance, communication overhead, and computation cost were measured, and a sensitivity analysis on the trust-weight parameters was performed. The simulation results suggest that QR-BCTM can enhance the accuracy of trust evaluation, mitigate the impact of malicious nodes, and remain scalable and efficient despite the existing cryptographic overhead. Post-quantum digital signatures and formal security analysis provide protection against quantum-era threats and attacks, while classical threats are mitigated through behavioral trust aggregation and recommendation filtering. In summary, QR-BCTM provides a scalable, simulation-validated and quantum-aware framework for trustworthy IoT network operation, offering practical guidelines for future deployment and prototyping.

M. A. Al-Khasawneh, D. Alsekait, K. Alkayid et al. · 0 citations
Conference Aug 2026

A Trust-Aware ICN–Block Chain Framework for Secure VANETS Enabled by PBFT

The vehicular ad-hoc network (VANET) provides a way for drivers or vehicles to communicate with each other in a more effective manner, however, there are still many issues with respect to different aspects of security, trust management, and delivering information reliably between two nodes. This study presents a way to facilitate Security in a VANET through a Trust-Aware, Block chain-Supported Information-Centric Networking (ICN) Framework. This Framework allows for more efficient dissemination of secure information in VANETs, making use of the requested/forwarding of Content In-Networks by Caching, which ideally would provide fast access to content and maintain availability and reduced latency for users within the network. A Trust Evaluation Module is employed to determine Node Behavior via the Packet-Forwarding Ratio of Nodes as well as the Validity of Packet-Content being forwarded. Blockchain Technology is used to hold Trust Records using PBFT Consensus, where records of malicious nodes identified. Lastly, Adaptive Trust Thresholds, Probabilistic Caching, and Malicious Content Filtering are utilized for Trust-Aware Forwarding and Caching mechanisms based upon calculated Trust Values with the intent to ensure the delivery of verified Data and to improve Network Performance. Simulation results show that the proposed method achieves a PDR of 98%, higher throughput, reduced delay, and lower packet loss compared to existing approaches, confirming its effectiveness in providing secure and reliable VANET communication under attack conditions.

Jinsha Lawrence, S. Pradeepa, R. T. Kumar et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.