Blockchain-Based Assurance of Network Device Configuration Integrity
Andrzej Paszkiewicz, Dominik Strzałka, Igor Litwa, Dario AssanteComputer networks constitute a critical component of contemporary digital infrastructure, and their secure and reliable operation is strongly dependent on the correctness, consistency, and accountability of the configurations of the network devices. Although traditional configuration management approaches remain widely adopted, they are primarily based on trust in centralized management systems, repositories, and privileged administrators, which may not fully guarantee tamper resistance or independent verification of configuration change histories. This paper examines the potential of blockchain technology as a mechanism for ensuring the integrity and accountability of configuration changes in network devices. To address this issue, a distributed four-layer architecture is proposed, comprising the network device layer, the configuration layer, the server layer, and the blockchain layer. Within this model, configuration changes are not applied permanently until they have passed a distributed approval procedure involving multi-party authorization, administrator voting, and digital signatures. The approved changes are subsequently recorded on the blockchain as immutable and cryptographically secured audit entries. The proposed concept was validated in a Python-based (version 3.7) simulation environment that reflects distributed management of routers and switches. The results indicate that the blockchain can provide more than a simple event logging mechanism. It can strengthen the security of the configuration approval process, reduce the risk of unauthorized modifications, improve resistance to tampering, and support distributed validation of data integrity. The proposed approach therefore offers a promising foundation for further research on scalable, secure, and auditable configuration management in network infrastructures.