Source-linked AI summary
Towards Secure Blockchain-enabled Internet of Vehicles: Optimizing Consensus Management Using Reputation and Contract Theory
Jiawen Kang, Zehui Xiong, Dusit Niyato, Dongdong Ye, Dong In Kim, Jun Zhao
TL;DR
IoV requires secure data sharing, yet stake-based DPoS miner selection is vulnerable to collusion. The paper addresses this with reputation-based miner selection and contract-incentivized standby-miner verification, reporting improved malicious-miner detection and block-verification security.
Problem
Stake-based DPoS voting is vulnerable to collusion between miner candidates and compromised high-stake stakeholders, threatening secure vehicle data sharing.
Method
The paper combines multi-weight subjective-logic reputation voting with contract theory to select active and standby miners and incentivize standby-miner block verification.
Results
The proposed schemes report improved malicious-miner detection and more secure block verification, including a 100% MWSL detection rate at threshold 0.5.
Takeaways & Limitations
Reputation-based selection and standby-miner auditing strengthen the security of blockchain-enabled IoV data sharing within the evaluated setting.
Abstract
from arXiv · showhide
In Internet of Vehicles (IoV), data sharing among vehicles is essential to improve driving safety and enhance vehicular services. To ensure data sharing security and traceability, highefficiency Delegated Proof-of-Stake consensus scheme as a hard security solution is utilized to establish blockchain-enabled IoV (BIoV). However, as miners are selected from miner candidates by stake-based voting, it is difficult to defend against voting collusion between the candidates and compromised high-stake vehicles, which introduces serious security challenges to the BIoV. To address such challenges, we propose a soft security enhancement solution including two stages: (i) miner selection and (ii) block verification. In the first stage, a reputation-based voting scheme for the blockchain is proposed to ensure secure miner selection. This scheme evaluates candidates' reputation by using both historical interactions and recommended opinions from other vehicles. The candidates with high reputation are selected to be active miners and standby miners. In the second stage, to prevent internal collusion among the active miners, a newly generated block is further verified and audited by the standby miners. To incentivize the standby miners to participate in block verification, we formulate interactions between the active miners and the standby miners by using contract theory, which takes block verification security and delay into consideration. Numerical results based on a real-world dataset indicate that our schemes are secure and efficient for data sharing in BIoV.
I. INTRODUCTION
Blockchain-based IoV addresses vehicle data-sharing challenges with decentralized infrastructure, but DPoS stake-based miner selection remains vulnerable to collusion. The paper proposes two-stage enhancements combining reputation-based miner selection with contract-based block verification.
- Centralized IoV data sharing raises single-point-of-failure and personal-data-manipulation concerns, while decentralized sharing creates unauthorized-access and security-protection challenges.
- Blockchain can provide decentralized, anonymous, and trusted infrastructure for vehicle data sharing, motivating blockchain-enabled IoV.
- Miner voting collusion allows malicious RSUs and compromised high-stake stakeholders to obtain miner roles and continuously damage the system.
- Block verification collusion can let malicious miners generate false verification results, motivating enhanced miner selection and block verification.
- The proposed scheme uses reputation-based voting for miner selection and contract theory to incentivize standby-miner verification against active-miner collusion.
B. Adversary Model for DPoS Consensus Process
The enhanced DPoS process replaces stake-weighted miner selection with reputation-based voting while retaining traditional block generation and adding secure verification. Reputation combines historical interactions with recommended opinions, and standby miners audit active-miner blocks.
- Adversary model: RSUs may be compromised, and stakeholders or miner candidates may be manipulated by plutocrats, creating adversarial conditions for DPoS consensus.
- Consensus workflow: The consensus workflow includes blockchain-data updates, miner-candidate joining, reputation-based voting, and secure block verification using contract theory.
- Miner candidate joining: Candidates submit stakes that the system can confiscate when malicious behavior damages consensus, such as failing to produce a block in the assigned time slot.
- Reputation calculation: Stakeholders calculate candidate reputation from historical interactions and recommended opinions using a subjective-logic model.
- Miner selection: All stakeholders have equal voting power; the top k reputation-ranked candidates become active miners, while y − k candidates become standby miners.
- Block management: Active miners take turns as block managers, generating, broadcasting, verifying, and managing blocks during their assigned time slots.
- Block verification: Standby miners audit newly generated blocks because the limited active-miner set can enable collusive false verification results.
- Compatibility: The enhanced scheme changes miner selection and block verification while leaving block mining and generation compatible with traditional DPoS.
III. EFFICIENT REPUTATION CALCUALTION USING SUBJECTIVE LOGIC MODEL
The paper uses subjective logic to calculate reputation from historical interactions and recommended opinions, while weighting interaction frequency, recency, and effects. The resulting reputation value incorporates uncertainty and supports evaluation of RSUs and miners.
- Local Opinions for Subjective Logic: Subjective logic represents each vehicle’s evaluation of an RSU using positive, negative, and uncertain belief components.The local opinion vector contains belief, distrust, and uncertainty, whose values sum to one.
- Local Opinions for Subjective Logic: Reputation is calculated from historical interactions and recommended opinions to evaluate whether RSUs or miners behave normally.The model reduces the effect of false recommendations when compromised vehicles are limited and most vehicles are reliable.
- Local Opinions for Subjective Logic: The final reputation value combines belief with uncertainty through a parameter γ that controls uncertainty’s effect on reputation.The uncertainty effect parameter satisfies 0 ≤ γ ≤ 1.
- Multi-weight Local Opinions for Subjective Logic: Interaction frequency increases reputation when a vehicle has more prior interactions with an RSU than with other RSUs.Frequency is defined relative to the vehicle’s average interactions with other RSUs during a time window.
- Multi-weight Local Opinions for Subjective Logic: Recent interactions receive greater influence through a recency weight, reflecting that trustfulness and reputation change over time.The recent-interaction period is represented by trecent, while ζ controls the weight assigned to recent interactions.
- Multi-weight Local Opinions for Subjective Logic: Negative interactions receive more weight than positive interactions because they decrease RSU reputation more strongly.The positive and negative interaction weights satisfy θ + τ = 1 and θ < τ.
C. Recommended Opinions for Subjective Logic
Recommended opinions aggregate weighted subjective opinions from vehicles that have interacted with an RSU. Vehicles retain their own local opinions and use final reputation opinions in blockchain storage and reputation-based miner voting.
- Recommended Opinions for Subjective Logic: Recommended opinions combine subjective opinions from multiple recommenders into one opinion according to each opinion’s weight.The recommender set X contains other vehicles that have interacted with the RSU.
- Recommended Opinions for Subjective Logic: A vehicle’s local opinion remains part of the final reputation opinion to reduce opportunities for cheating through recommendations.The final opinion is formed after obtaining ratings of the RSU from other vehicles.
- Recommended Opinions for Subjective Logic: Vehicles upload final reputation opinions as recommended opinions, which stakeholders use to vote for high-reputation miner candidates.These operations occur in the specified reputation-storage and miner-voting steps of the DPoS process.
IV. INCENTIVE MECHANISM FOR SECURE BLOCK VERIFICATION USING CONTRACT THEORY
The contract-theoretic mechanism incentivizes active and standby miners to verify blocks securely while accounting for verification delay. It models verifier reputation as private types and contracts as latency-reward bundles.
- Incentive Mechanism: The mechanism addresses potential block-verification collusion by motivating both active and standby miners to participate in verification.The block manager offers part of the transaction fee as a verifier reward, with faster verification receiving more incentive.
- Incentive Mechanism: The verification market contains a block manager and verifiers that contribute different CPU resources to execute block-verification tasks.The transmitted block and verified-result sizes are modeled as Ik and Ok, respectively.
- Contract Design: Verifier reputation is represented by Q ordered types, with larger θq indicating a higher-reputation verifier.Verifiers are sorted from θ1 to θQ in ascending reputation.
- Contract Design: The block manager offers each verifier type a latency-reward contract bundle containing verification latency and its corresponding incentive.The contract for type q is represented by (Rq, Lq), where Lq is latency and Rq is incentive.
- Latency in Block Verification: Verification latency includes block transmission, local verification, result broadcasting and comparison, and feedback transmission.Transmission rates, CPU resources, block sizes, network scale, and a broadcasting parameter determine the component delays.
- Latency in Block Verification: The latency model assumes fixed verifier locations and uses TDMA with uplink and downlink sharing the same frequency channel.Link rates can be calculated from wireless-channel conditions such as bandwidth, transmission power, channel gain, and noise.
B. Profit of the Block Manager
The block manager’s profit balances verification security benefits against verifier incentives and latency. Its security-latency metric rewards more participating high-reputation verifiers while penalizing excessive delay.
- Profit of the Block Manager: The block manager’s profit equals the security-latency benefit from a verifier type minus a weighted incentive payment.The incentive weight is l, and the benefit is represented by π[φq(Lq)].
- Profit of the Block Manager: More high-reputation verifiers and lower latency increase the block manager’s security-latency benefit.The metric balances network scale against verification time because additional verifiers improve security but can increase communication latency.
- Profit of the Block Manager: The security-latency metric is zero outside the permitted latency range and is bounded by the maximum tolerable verification latency Tmax.The formulation uses coefficients e1 and e2 for network scale and latency, with factors z1 and z2 controlling their effects.
- Profit of the Block Manager: The manager maximizes expected profit over verifier types using their prior probabilities, which sum to one.The type distribution is obtained from observations and statistics of previous verifier behavior.
C. Utility of Block Verifiers
The verifier’s utility increases with incentive valuation and reputation type, while resource consumption from block verification reduces utility. Verifiers therefore seek contracts that maximize utility while minimizing verification resources.
- A type-q verifier’s utility combines incentive valuation, scaled by reputation type, with a deduction for block-verification resource cost.The valuation function η(Rq) increases monotonically with incentive Rq, while l′ denotes unit resource cost.
- Higher-reputation verifier types should receive larger utility in block verification.The paper links higher verifier type to higher reputation and larger utility.
- Verifiers maximize utility by minimizing resource consumption during block verification.
V. OPTIMAL CONTRACT DESIGNING
The contract design enforces individual rationality and incentive compatibility while respecting latency and budget constraints. By exploiting monotonicity, the paper reduces the problem to a tractable convex optimization whose solution determines verifier latency requirements and incentives.
- Contract constraints: Individual rationality requires each verifier to join block verification only when its contract utility is non-negative.
- Contract constraints: Incentive compatibility requires each verifier to obtain maximum utility from choosing the contract designed for its own type.
- Contract constraints: Higher-reputation verifiers receive higher incentives, and incentive-compatible contracts require higher payment when verification latency is lower.
- Contract constraints: Under incentive compatibility, satisfying the type-1 verifier’s individual-rationality constraint ensures individual rationality for the other verifier types.
- Contract constraints: Local downward and upward incentive-compatibility conditions, together with monotonicity, are sufficient to establish the corresponding global constraints.
- Optimization: The reformulated optimization imposes maximum latency and total incentive-budget constraints, including the given transaction-fee limit Rmax.
- Optimization: Defining η(Rq) = Rq enables sequential solution of the relaxed problem, followed by monotonicity verification and adjustment when verifier types are not uniformly distributed.
- Optimization: The resulting problem is convex because the objective sums concave functions and the constraints are affine, allowing optimal latency and incentive values to be obtained with convex optimization tools.
VI. NUMERICAL RESULTS
The numerical evaluation uses real-world mobility traces to assess the proposed reputation scheme and contract-theoretic incentive mechanism. The dataset records one month of driving by 536 taxis, including 200 operating in an urban area.
- The evaluation uses the San Francisco Yellow Cab real-world dataset to assess the MWSL scheme and contract-theoretic incentive mechanism.
- The dataset records mobility traces for 536 taxis driving during one month.
- The study analyzes 200 taxis operating in an urban area bounded by the reported latitude and longitude ranges.The stated ranges are latitude 37.7 to 37.81 and longitude -122.52 to -122.38.
A. Performance of the proposed reputation scheme
The MWSL reputation scheme uses local and recommended opinions, weighted by interaction characteristics, to detect malicious miner candidates more accurately than TSL. It also improves block-verification security when standby miners participate.
- Reputation calculation: MWSL combines local and recommended opinions to calculate miner-candidate reputation, unlike TSL’s linear reputation function.The model incorporates interaction frequency, timeliness, and interaction effects into both opinion sources.
- Malicious-candidate evaluation: MWSL reputation decreases below the trusted-miner threshold faster than TSL when recommended opinions expose malicious behavior.This reduces misleading reputation effects from compromised vehicles and supports more secure miner voting.
- Detection performance: At a successful-detection threshold of 0.5, MWSL detects 100% of malicious miner candidates, 100% higher than TSL.The experiment observes 10 malicious candidates over 60 minutes.
- Block-verification security: Very low detection thresholds can leave active-miner collusion unresolved, motivating standby-miner participation in block verification.The attack involves more than 1/3 of active miners generating a false verification result.
- Block-verification security: At a threshold of 0.2, MWSL with standby miners achieves a 13% higher corrected-block probability than MWSL without standby miners.TSL without standby miners cannot defend against the verification collusion attack.
B. Performance of the incentive mechanism based on contract theory scheme
The contract-theory mechanism assigns contract items to verifiers while accounting for reputation, security, latency, and incentives. Results show incentive compatibility, individual rationality, and higher block-manager profit than the compared Stackelberg models.
- Contract incentives: Verifiers of types 2, 4, 6, and 8 obtain maximum utility from contract items designed for their respective types.This supports the incentive-compatibility constraint.
- Contract incentives: All verifier types choose matching contract items with non-negative utilities, validating the individual-rationality constraint.The contract publisher offers items that verifiers select while meeting latency requirements.
- Block-manager utility: The block manager’s profit increases with the total number of verifier types because more types provide more verifiers and contract choices.The passage links these additional choices to more secure block verification.
- Block-manager utility: The proposed contract model yields better block-manager utility than the compared Stackelberg game models.The proposed model uses limited contract items to extract more benefits from verifiers in the monopoly market.
VII. CONCLUSION
The paper strengthens blockchain-based Internet of Vehicles data sharing with a two-stage soft-security enhancement to Delegated Proof-of-Stake. It combines reputation-based miner selection with contract-based standby-miner verification to improve security and address miner collusion.
- The proposed system uses enhanced Delegated Proof-of-Stake for secure peer-to-peer vehicle data sharing.The scheme provides the hard-security foundation for blockchain-based Internet of Vehicles.
- A reputation-based voting stage selects miners using a multi-weight subjective logic scheme to calculate miner-candidate reputation.This scheme is intended to calculate candidate reputations securely and accurately.
- A contract-theory stage incentivizes standby miners to participate in block verification, helping prevent internal collusion among active miners.The contract-based design accounts for block-verification security and delay.
- Numerical results show advantages over traditional reputation schemes in detecting malicious miner candidates.The evaluation also reports that the proposed contract-based block-verification approach supports the security objective.