Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

486 papersLast indexed Aug 31, 2026
Search papers

Paper index

486 results · page 10 of 21

Clear filters
Nov 13, 2024·Expert Systems
8 cites
LightAuth : A Lightweight Sensor Nodes Authentication Framework for Smart Health System

Zain Ul Islam Adil, Majid Iqbal Khan, Kahkishan Sanam, Saif Ur Rehman Malik · 6 authors

ABSTRACT Counterfeit medical devices pose a threat to patient safety, necessitating a secure device authentication system for medical applications. Resource‐constrained sensory nodes are vulnerable to hacking, prompting the need for robust security measures. Token‐based authentication schemes, such as one‐time passwords (OTPs), smart cards, key fobs, and mobile authentication apps, along with certificate‐based authentication methods, such as client and code‐signing, employ cryptographic frameworks like elliptical curve cryptography (ECC) and physical unclonable functions (PUF). However, these methods face challenges, including block sequence issues and susceptibility to side‐channel attacks. To address these issues, we propose a framework for mutual authentication using private Ethereum. This framework integrates private Ethereum and cryptographic techniques for encrypting and decrypting data using mathematical algorithms to overcome block sequence issues and side‐channel attacks. Similarly, fog nodes are utilised to enhance local computing, storage, and networking capabilities for sensors. The framework is evaluated using metrics such as communication costs, execution costs, and computation costs based on Ethereum gas consumption. The performance of the LightAuth framework is compared with that of the Smart Contracts Against Counterfeit IoMT (SCACIoMT) framework, designed for Internet of Medical Things (IoMT) devices. The effectiveness of LightAuth is verified through formal security analysis using BAN logic.

Open access
User Authentication and Security Systems
Advanced Authentication Protocols Security
Cloud Data Security Solutions
Original source
Nov 1, 2024·Engineering Science and Technology an International Journal
6 cites
RELAKA: Robust ECC based Privacy Preserving Lightweight Authenticated Key Agreement protocol for healthcare applications

R. Kousalya, Gulshan Kumar

With the advancement of cutting-edge technologies, the Internet of Medical Things (IoMT) has assisted the healthcare sector by facilitating interaction between healthcare service providers and patients in remote areas. In IoMT, wearable or implantable sensors collect the patient’s record and share the information through a public network. Health-related information about the patient must be protected from a variety of attacks by the adversary since it is sensitive and extremely vulnerable to attacks. The sensor equipment that is implanted in the patient is also resource-constrained and has a low power capacity. The entities involved in the communication must be authenticated with one another in order to protect patients’ health information, anonymity, and reliability. While several authenticated key agreement protocols have been proposed, many suffer from high computational costs and storage cost, making them unsuitable for lightweight applications. This paper proposes a secure three-factor robust Elliptic Curve Cryptography (ECC) based mutually authenticated and key agreement protocol known as RELAKA for the IoMT environment, utilizing the benefits of one-way hash function. In proposed scheme, all entities, including the healthcare service providers and wearable sensors, are authenticated by the medical server. Subsequently, a secret key is established for each communication session and shared between all the entities. Additionally, mechanism for appropriate user revocation and re-registration is integrated to provide additional security in cases where a user’s QR code is tampered with by the attacker. The privacy of the proposed protocol is investigated by the potential use of zero knowledge proof. Furthermore, the efficacy of the authentication is examined by challenge and response mechanism. The informal security analysis demonstrates its resistance to threats such as DoS, impersonation, message modification, password guessing, and so on. The performance evaluation of RELAKA protocol indicates that the execution, communication, and storage costs is reduced by 87.59%, 43% and 60.71% respectively. Moreover, the outcomes of the AVISPA simulation illustrate that the RELAKA successfully evades both active and passive attacks. In addition, real-world testbed environment is developed with Raspberry pi 4 model B and the experimental results verifies the robustness of the proposed protocol. According to theoretical analysis and experimental evaluation, the RELAKA scheme is more secure and efficient than the existing protocols.

Open access
Advanced Authentication Protocols Security
Cryptography and Data Security
User Authentication and Security Systems
Original source
Aug 31, 2024·Blockchain in Healthcare Today
5 cites
Soulbound Tokens: Enabler for Privacy-Aware and Decentralized Authentication Mechanism in Medical Data Storage

Biagio Boi, Franco Cirillo, Marco De Santis, Christian Esposito

Context: The digitalization of the healthcare sector faces significant challenges due to the diverse representation of data and their distribution across various hospitals. Moreover, security is a key concern as healthcare-related data are subject to the legal obligations of General Data Protection Regulation (GDPR) and similar data protection legislation. Standardization efforts like Health Level Seven (HL7) have been implemented to enhance data interoperability. However, authentication still remains a critical issue with significant challenges. Aim: This research aims to improve and strengthen the authentication process by introducing a novel architecture for decentralized authentication. Additionally, it proposes a new approach to decentralized data management, which is crucial for handling sensitive medical data efficiently. Methodology: The proposed architecture adopts a user-centric approach, utilizing Self-Sovereign Identity (SSI). It introduced a new non-fungible token (NFT) type called soulbound token (SBT) in the medical context, which will facilitate user authentication across different hospitals, effectively creating a federation of interconnected institutions. Results: The implementation of the proposed architecture demonstrated a significant reduction in authentication time across multiple hospitals. The use of SBT ensured secure and seamless user authentication, enhancing overall system interoperability and data security. The decentralized approach also mitigated the risks associated with centralized authentication servers. Conclusion: This study successfully presents a novel decentralized authentication architecture for the healthcare domain, leveraging SSI and SBTs. This approach accelerates the authentication process and enhances data security and interoperability among hospitals. Future research should explore the scalability of this architecture and its application in other sectors requiring stringent data security measures.

Open access
Advanced Authentication Protocols Security
User Authentication and Security Systems
Digital Rights Management and Security
Original source
Jul 15, 2024·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Zero-knowledge proofs for scalability and privacy in a supply-chain

SEBASTIAN GEORGE MOIAN

In this thesis, the aim is to understand the possibilities and limitations of Zero Knowledge Proofs (ZKP) in blockchain technology. The first chapters focus on the presentation of distributed ledger systems and the tools that will be used, with particular reference to Remix, the IDE of choice for programming smart contracts in Solidity, and Sepolia, the Ethereum Testnet where the smart contracts were deployed. Subsequently, zero knowledge proofs are defined, their characteristics are explained, and the difference between interactive and non-interactive proofs is discussed; the latter will be emphasized as they are the most interesting in this context. The thesis then moves on to possible theoretical application contexts, with a particular focus on verifiable computation. Zokrates, a framework used to implement the non-interactive ZKP protocol, will be presented, explaining its language, features, functioning, and differences compared to other programming languages. A focal point for explaining how to implement verifiable computation will be introducing the various representations of an arithmetic circuit, fundamentally of textual and matrix types. Through various tests, the limitations of Zokrates and, to some extent, the entire arithmetic circuits sector for ZKP were highlighted. The thesis concludes with a possible implementation on the subject and an attack that this technology may be able to avoid.

Open access
2 source records
Cryptography and Data Security
Blockchain Technology Applications and Security
Advanced Authentication Protocols Security
Original source
Jul 8, 2024·2024 IEEE 9th European Symposium on Security and Privacy (EuroS&P)
6 cites
Share with Care: Breaking E2EE in Nextcloud

M. Albrecht, Matilda Backendal, Daniele Coppola, Kenneth G. Paterson

Nextcloud is a leading cloud storage platform with more than 20 million users. Nextcloud offers an end-to-end encryption (E2EE) feature that is claimed to be able “to keep extremely sensitive data fully secure even in case of a full server breach”. They also claim that the Nextcloud server “has Zero Knowledge, that is, never has access to any of the data or keys in unencrypted form”. This is achieved by having encryption and decryption operations that are done using file keys that are only available to Nextcloud clients, with those file keys being protected by a key hierarchy that ultimately relies on long passphrases known exclusively to the users. We provide the first detailed documentation and security analysis of Nextcloud's E2EE feature. Nextcloud's strong security claims motivate conducting the analysis in the setting where the server itself is considered malicious. We present three distinct attacks against the E2EE security guarantees in this setting. Each one enables the confidentiality and integrity of all user files to be compromised. All three attacks are fully practical and we have built proof-of-concept implementations for each. The vulnerabilities make it trivial for a malicious Nextcloud server to access and manipulate users' data. We have responsibly disclosed the three vulnerabilities to N extcloud. The second and third vulnerabilities have been remediated. The first was addressed by temporarily disabling file sharing from the E2EE feature until a redesign of the feature can be made. We reflect on broader lessons that can be learned for designers of E2EE systems.

Open access
Advanced Authentication Protocols Security
Digital Rights Management and Security
Privacy, Security, and Data Protection
Original source
Jun 19, 2024·IEEE Transactions on Network and Service Management
16 cites
Blockchain-Based Secure Authentication and Authorization Framework for Robust 5G Network Slicing

Shalitha Wijethilaka, Awaneesh Kumar Yadav, An Braeken, Madhusanka Liyanage

The rapid evolution of heterogeneous applications signifies the requirement for network slicing to cater to diverse network requirements. Network Functions (NFs), which are the essential elements of network slices, are required to communicate with each other securely to facilitate network services. Certificates are the established method to authenticate each other. However, dynamic certificate management while allowing NFs to communicate in a multi-operator environment is arduous. Also, sharing NFs between network slices originates authorization-related security challenges such as unauthorized service utilization, deceptive Denial of Service attacks, and data leakages from network slices. In this paper, we develop a novel framework to address the security challenges related to authentication and authorization in 5G network slicing systems. A blockchain-based multi-party distributed certificate management framework with secure communication protocols is developed using elliptic curve cryptography to facilitate certificate services for multi-operator environments. Also, we propose a blockchain-based NF authorization framework to mitigate the security vulnerabilities in NF sharing between network slices. We implement the proposed framework using Hyperledger Fabric blockchain with Java chain codes and perform comprehensive experiments to show the significance of our framework.The Ability to mitigate the single point of failure with respect to state-of-the-art, including traditional certificate authorities and blockchain-based certificate authorities, time analysis for certificate generation, and the potential to eliminate the mentioned authorization attacks are some of the experiments conducted.Also, we have shown that our framework is secure using informal and formal (using Real-Or-Random (ROR) logic and Scyther Validation tool) security verification mechanisms.

Open access
Advanced Authentication Protocols Security
Cryptography and Data Security
User Authentication and Security Systems
Original source
May 7, 2024·Proceedings of the 21st ACM International Conference on Computing Frontiers: Workshops and Special Sessions
2 cites
HAGAR: Hashgraph-based Aggregated Communication and Remote Attestation

Jo Vliegen, Md Masoom Rabbani, Wouter Hellemans, Nele Mentens

Over the past decade, an exponential rise in the deployment of Internet-of-Things (IoT) devices engulfed our surroundings. IoT devices have spread into domains like personal smart devices, industrial applications, military applications, and medical applications, to name a few. Brittle security features and large deployment in safety-critical systems make IoT devices an attractive target for cyberattacks. Large collections of data, ranging from personal, and oversensitive to financial data, make it crucial to safeguard IoT applications and data communication from cybercriminals. One key technique to deal with these cyberattacks is Remote Attestation (RA), in which a verifier remotely checks the sanity of an IoT device's firmware. However, implementing RA over large IoT networks can be challenging due to the dynamic nature of the network and the real-time aggregation of attestation results. We propose 'HAGAR: Hashgraph-based Aggregated Communication and Remote Attestation' to address the aforesaid challenges. HAGAR is a distributed ledger based on a hashgraph architecture that not only provides decentralized security guarantees like traditional blockchain technology, but also makes communication fast and thus offers continuous attestation aggregation in large IoT networks. We use the features of Hashgraphs for data aggregation in remote attestation mechanisms for large dynamic IoT networks.

Open access
User Authentication and Security Systems
Cryptography and Data Security
Advanced Authentication Protocols Security
Original source
Apr 10, 2024·ACM Computing Surveys
118 cites
Security, Privacy, and Decentralized Trust Management in VANETs: A Review of Current Research and Future Directions

Mishri Saleh Al-Marshoud, Mehmet Sabır Kiraz, Ali H. Al-Bayati

Vehicular Ad Hoc Networks (VANETs) are powerful platforms for vehicular data services and applications. The increasing number of vehicles has made the vehicular network diverse, dynamic, and large-scale, making it difficult to meet the 5G network’s demanding requirements. Decentralized systems are interesting and provide attractive services because they are publicly available (transparency), have an append-only ledger (robust integrity protection), remove single points of failure, and enable distributed key management and communication in a peer-to-peer network. Researchers dedicated substantial efforts to advancing vehicle communications, however conventional cryptographic mechanisms are insufficient which enabled us to look at decentralized technologies. Therefore, we revisit decentralized approaches with VANETs. Endpoint devices hold a wallet which may incorporate threshold key management methods like MPC wallets, HD Wallets, or multi-party threshold ECDSA/EdDSA/BLS. We also discuss trust management approaches and demonstrate how decentralization can improve integrity, security, privacy, and resilience to single points of failure. We also conduct a comprehensive review, comparing them with current requirements, and the latest authentication and secure communication architectures, which require the involvement of trusted but non-transparent authorities in certificate issuance/revocation. We highlight the limitations of these schemes from PKI deployment and recommend future research, particularly in the realm of quantum cryptography.

Open access
Vehicular Ad Hoc Networks (VANETs)
Privacy-Preserving Technologies in Data
Advanced Authentication Protocols Security
Original source
Apr 9, 2024·High Performance Privacy Preserving AI
0 cites
Blockchain and Zero Knowledge Proofs

Authors unavailable

Blockchain and zero-knowledge (ZK) proof techniques have advanced greatly in recent years, largely spurred by cryptocurrency development. They enable decentralized coordination of, and proofs of computational integrity in, the execution of privacy-preserving protocols.

Open access
Cryptography and Data Security
Advanced Authentication Protocols Security
Cloud Data Security Solutions
Original source
Apr 1, 2024·Journal of Physics Conference Series
2 cites
An efficient authentication protocol with privacy-preserving for virtual power plant

Shuang Yao, Yayun Zhu, Xiaojuan Zhang, Dahua Zhang · 7 authors

Abstract As an important manifestation of the current development and transformation of the world’s power and energy industries, the virtual power plant is an important foundation for optimizing the layout of energy resources. However, since there are many open channels in the virtual power plant, adversaries can implement eavesdropping, replay, impersonation, forgery, and other attacks to access the virtual power plant, and even publish false data in the virtual power plant to disrupt the operation of the virtual power plant. In addition, it is easy for an adversary to deduce key information such as the layout of virtual power plant equipment through the identity of the device. In this context, to ensure the security and privacy of devices when accessing the platform, in this paper, we propose an efficient authentication protocol based on the elliptic curve cryptography and zero-knowledge proof, which requires only two information exchanges. Security analysis shows that the proposed protocol can meet security features such as mutual authentication, key agreement, perfect forward secrecy, and device anonymity. Performance analysis indicates that the proposed protocol achieves a reasonable balance between computational and signaling overhead, and it is more suitable for achieving efficient device authentication and privacy protection in virtual power plants.

Open access
Smart Grid Security and Resilience
Advanced Authentication Protocols Security
Security in Wireless Sensor Networks
Original source
Mar 30, 2024·Journal of Al-Qadisiyah for Computer Science and Mathematics
0 cites
¬¬¬Instant Messaging Security: A Comprehensive Review of Behavior Patterns, Methodologies, and Security Protocols

Ahmed R. AlMhanawi, Bashar M. Nema

This review presents a comprehensive analysis of contemporary scholarship pertaining to instant messaging (IM) user behavior and security protocols. Through meticulous selection, the authors highlight critical studies that illuminate optimized message consumption strategies and delve into the evolving landscape of IM security models. Focusing on the past four years, the review meticulously dissects cutting-edge advancements in this domain. A significant insight emerges: achieving optimal communication security necessitates the synergistic convergence of three fundamental techniques: end-to-end encryption for data confidentiality, decentralized authentication for independent user verification, and zero-knowledge proof for identity obscurity. The review postulates that the simultaneous integration of these elements within the application architecture is paramount for robust privacy and heightened security in the realm of IM.

Open access
User Authentication and Security Systems
Advanced Authentication Protocols Security
Network Security and Intrusion Detection
Original source
Mar 11, 2024·Journal of Sensor and Actuator Networks
24 cites
An Optimized Link State Routing Protocol with a Blockchain Framework for Efficient Video-Packet Transmission and Security over Mobile Ad-Hoc Networks

Huda A. Ahmed, Hamid Alasadi

A mobile ad-hoc network (MANET) necessitates appropriate routing techniques to enable optimal data transfer. The selection of appropriate routing protocols while utilizing the default settings is required to solve the existing problems. To enable effective video streaming in MANETs, this study proposes a novel optimized link state routing (OLSR) protocol that incorporates a deep-learning model. Initially, the input videos are collected from the Kaggle dataset. Then, the black-hole node is detected using a novel twin-attention-based dense convolutional bidirectional gated network (SA_ DCBiGNet) model. Next, the neighboring nodes are analyzed using trust values, and routing is performed using the extended osprey-aided optimized link state routing protocol (EO_OLSRP) technique. Similarly, the extended osprey optimization algorithm (EOOA) selects the optimal feature based on parameters such as node stability and link stability. Finally, blockchain storage is included to improve the security of MANET data using interplanetary file system (IPFS) technology. Additionally, the proposed blockchain system is validated utilizing a consensus technique based on delegated proof-of-stake (DPoS). The proposed method utilizes Python and it is evaluated using data acquired from various mobile simulator models accompanied by the NS3 simulator. The proposed model performs better with a packet-delivery ratio (PDR) of 91.6%, average end delay (AED) of 23.6 s, and throughput of 2110 bytes when compared with the existing methods which have a PDR of 89.1%, AED of 22 s, and throughput of 1780 bytes, respectively.

Open access
Mobile Ad Hoc Networks
Advanced Authentication Protocols Security
Security in Wireless Sensor Networks
Original source
Mar 1, 2024·Journal of Education and Health Promotion
17 cites
Securing patient data in the healthcare industry: A blockchain-driven protocol with advanced encryption

Sourav Kunal, Parth Gandhi, Digvijaysinh Rathod, Ruhul Amin · 5 authors

BACKGROUND: Ensuring the security and privacy of patient data is a critical concern in the healthcare industry. The growing utilization of electronic data transmission and storage in medical records has amplified apprehensions about data security. However, due to varying stakeholder interests, not all data can be freely shared, necessitating the development of secure protocols. MATERIALS AND METHODS: This study presents a highly secure protocol that integrates blockchain technology, patient biometric information, and robust cryptographic algorithms (elliptic curve cryptography (ECC) and advanced encryption algorithm (AEC)) to facilitate data encryption and decryption. The protocol encompasses secure login, secure key sharing, and data sharing mechanisms among miners, offering comprehensive security measures. To validate the effectiveness of the proposed protocol, both informal and formal security analyses are conducted. The security protocol description language in Scyther is utilized to evaluate the protocol's resilience against attacks. RESULTS: The culmination of this research is a secure protocol that leverages blockchain technology and ECC for the secure storage and sharing of medical records. The protocol covers all stages, including system setup, user registration, login mechanisms, key exchange between users and blockchain, communication between blockchains, and interaction with other miners, with a steadfast emphasis on security. Furthermore, the protocol's communication and computation costs are assessed, with a comparison to existing blockchain-based schemes. Informal proofs establish the protocol's security against common attacks faced by medical institutions. Formal simulation of the protocol using the Scyther tool provides definitive evidence of its resistance to attacks. CONCLUSIONS: As a result, this protocol presents a viable real-time implementation solution for safeguarding patient data within the healthcare domain, representing a significant contribution to data security.

Open access
Blockchain Technology Applications and Security
Advanced Authentication Protocols Security
Cryptography and Data Security
Original source
Feb 28, 2024·Scientific Reports
6 cites
Dickson polynomial-based secure group authentication scheme for Internet of Things

Salman Ali Syed, Selvakumar Manickam, Mueen Uddin, Hamed Alsufyani · 7 authors

Internet of Things (IoT) paves the way for the modern smart industrial applications and cities. Trusted Authority acts as a sole control in monitoring and maintaining the communications between the IoT devices and the infrastructure. The communication between the IoT devices happens from one trusted entity of an area to the other by way of generating security certificates. Establishing trust by way of generating security certificates for the IoT devices in a smart city application can be of high cost and expensive. In order to facilitate this, a secure group authentication scheme that creates trust amongst a group of IoT devices owned by several entities has been proposed. The majority of proposed authentication techniques are made for individual device authentication and are also utilized for group authentication; nevertheless, a unique solution for group authentication is the Dickson polynomial based secure group authentication scheme. The secret keys used in our proposed authentication technique are generated using the Dickson polynomial, which enables the group to authenticate without generating an excessive amount of network traffic overhead. IoT devices' group authentication has made use of the Dickson polynomial. Blockchain technology is employed to enable secure, efficient, and fast data transfer among the unique IoT devices of each group deployed at different places. Also, the proposed secure group authentication scheme developed based on Dickson polynomials is resistant to replay, man-in-the-middle, tampering, side channel and signature forgeries, impersonation, and ephemeral key secret leakage attacks. In order to accomplish this, we have implemented a hardware-based physically unclonable function. Implementation has been carried using python language and deployed and tested on Blockchain using Ethereum Goerli's Testnet framework. Performance analysis has been carried out by choosing various benchmarks and found that the proposed framework outperforms its counterparts through various metrics. Different parameters are also utilized to assess the performance of the proposed blockchain framework and shows that it has better performance in terms of computation, communication, storage and latency.

Open access
User Authentication and Security Systems
Advanced Authentication Protocols Security
Security in Wireless Sensor Networks
Original source
Feb 10, 2024·ACM Computing Surveys
107 cites
An All-Inclusive Taxonomy and Critical Review of Blockchain-Assisted Authentication and Session Key Generation Protocols for IoT

Ali Shahidinejad, Jemal Abawajy

Authentication and Session Key Generation Protocols (SKGPs) play an essential role in securing the communication channels of connected Internet of Things (IoT) devices. Recently, through blockchain integration, scholars have tried to enhance the security and applicability of SKGPs. In brief, blockchain is a distributed ledger technology that can provide interesting features such as immutability, transparency, and accountability without any need for the active participation of trusted parties. This survey presents a comprehensive critical review of blockchain-assisted authentication and SKGPs, suggested for different IoT domains, including Internet of Vehicles, Internet of Drones, and Industrial IoT. Our survey categorizes existing schemes based on several criteria, including IoT application domains, security aspects, and blockchain components. By presenting an unbiased critical review and taxonomy of protocols, we aim to clarify the key challenges. Our review will specifically indicate what properties authors gained or lost through the integration of blockchain. To our best knowledge, this survey is the only one that offers all prerequisites for interested readers in blockchain-integrated SKGPs, such as security features and attacks, attack models, verification tools, blockchain types, blockchain platforms, and consensus mechanisms. Further, our survey elaborates existing research gaps in blockchain-assisted SKGPs. In doing so, we aim to guide future research in this field and provide researchers with the essential information they require.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
Advanced Authentication Protocols Security
Original source
Feb 1, 2024·Journal of King Saud University - Computer and Information Sciences
15 cites
Hybrid blockchain-based many-to-many cross-domain authentication scheme for smart agriculture IoT networks

Fengting Luo, Ruwei Huang, Yuqi Xie

With the development of smart agricultural Internet of Things (IoT) projects, the need for extensive collaboration among agricultural devices from different domains has surged, necessitating the authentication of device identities for secure communication. Existing centralized architecture-dependent authentication mechanisms encounter issues like a sole point of failure and inefficiencies. Most authentication schemes are unable to support plentiful devices synchronously connecting to numerous data servers in other domains. To address these problems, we propose a many-to-many cross-domain authentication scheme based on the hybrid blockchain architecture for smart agriculture IoT networks. The scheme enables multiple devices simultaneously executing mutual authentication with several data service providers from other agricultural systems. This paper designs a groupable batch verification (GBV) algorithm that dynamically adjusts the batch size by performing group verification for a list of requests, enhancing the flexibility of cross-domain batch authentication. Furthermore, the proposed scheme provides a pseudonym update mechanism to protect the privacy of devices and guards services of different domains from illegal access by tracking malicious devices. The security analysis and performance evaluation demonstrate that the proposed scheme has superior security features and performance.

Open access
Blockchain Technology Applications and Security
Advanced Authentication Protocols Security
Cryptography and Data Security
Original source
Jan 1, 2024·IEEE Access
16 cites
Blockchain-Based Caller-ID Authentication (BBCA): A Novel Solution to Prevent Spoofing Attacks in VoIP/SIP Networks

Ismail Melih Tas, Selçuk Baktır

Voice over Internet Protocol (VoIP) networks are vulnerable to caller-ID (caller-identification) spoofing attacks due to the open nature of Session Initiation Protocol (SIP) signaling. Caller-ID spoofing is a critical security threat in modern telecommunication systems, allowing attackers to impersonate legitimate callers and gain access to sensitive information. While these attacks pose a significant threat to the telecom and financial industries, the existing solutions are limited to only closed-circuit options for subscribers of the same service provider. In this paper, we present a novel blockchain-based solution to effectively prevent caller-ID spoofing attacks in real time. Our approach employs a low-latency consensus algorithm to manage and verify end-to-end the caller-ID information of Internet Service Providers (ISPs) and institutions. We propose a two-step verification process, in which the accuracy and integrity of Automatic Number Identification (ANI) information is verified at different stages of the call. The proposed solution initiates a renewal of the ISP registration on every caller-ID change, making it unaffected by unusual situations such as roaming, the use of an IP-PBX (Internet Protocol Private Branch Exchange), or the use of a VPN (Virtual Private Network). We also discuss the proposed solution’s feasibility and potential deployment issues, including its integration into existing RFC (Request for Comments) efforts and the necessary regulations for service providers to demonstrate compliance. Furthermore, we address future research directions, such as handling complex call scenarios such as call forwarding and teleconference calls. Our approach not only improves the security of telecommunication systems but also provides an efficient and scalable solution to prevent caller-ID spoofing attacks.

Open access
Cryptography and Data Security
Internet Traffic Analysis and Secure E-voting
Advanced Authentication Protocols Security
Original source
Jan 1, 2024·IEEE Transactions on Information Forensics and Security
20 cites
Highly-Secure Yet Efficient Blockchain-Based CRL-Free Key Management Protocol for IoT-Enabled Smart Grid Environments

Ali Shahidinejad, Jemal Abawajy, Shamsul Huda

The Internet of Things (IoT) has advanced smart grid (SG) infrastructure by providing smart meters (SMs) with enhanced capabilities such as the ability to leverage the Internet platform for bidirectional information exchange. Cryptographic keys are necessary for securely exchanging sensitive information between SMs and energy providers. To manage these keys, a secure key management protocol (KMP) with little overhead and influence on the SG’s overall performance is necessary. Although various KMPs are available for IoT-enabled SG environments, exiting solutions have several flaws in terms of certificate revocation, security requirements, and overall SG performance. To address these challenges, this paper proposes a blockchain-based computationally-efficient and highly-secure KMP for IoT-enabled SG environments. We show that, compared to existing solutions, the proposed KMP has better SM side efficiency with improved security and more properties such as perfect forward secrecy, conditional anonymity, and simple SM revocation.

Open access
Smart Grid Security and Resilience
Blockchain Technology Applications and Security
Advanced Authentication Protocols Security
Original source
Jan 1, 2024·IEEE Access
22 cites
Enhanced Lightweight Medical Sensor Networks Authentication Scheme Based on Blockchain

Tae-Woong Kang, N.S. Woo, Jihyeon Ryu

In the rapidly evolving environment of wireless medical sensor networks (WMSN) and the internet of medical things (IoMT), remote medical support has seen unprecedented advancements. It is essential that the data relayed from the sensors must be trustworthy and unaltered, and that the sensors themselves are genuine. Wireless networks, however, have inherent vulnerabilities. In addition, since WMSN is directly linked to patients’ lives, its continuous availability is crucial. Considerable efforts have been made to maintain the integrity and authenticity of such data. However, many studies have failed to address the problem of a single point of failure (SPOF). This issue has been particularly detrimental to patients who require ongoing management. To address this issue and ensure the protection of the authenticity and integrity of patient data, we suggest the implementation of an authentication scheme based on blockchain technology. In 2022, Yu et al. introduced a blockchain-integrated authentication and key generation scheme for WMSN using Physical Unclonable Functions (PUFs), effectively addressing the SPOF problem by conducting mutual authentication through smart contracts without relying on centralized servers. Our research found that this scheme inadvertently shared critical parameters, including challenge-response pairs and important private keys, with the blockchain network, making it vulnerable to various breaches. We present an enhanced protocol designed to mitigate these security challenges. By limiting the data interaction with smart contracts and ensuring only relevant parties access crucial parameters, our approach reduces the risk of public information disclosure on the blockchain. This not only mitigates the SPOF issue but also efficiently helps in prevention of physical attacks. We prove that our proposed system prevents known security vulnerabilities through informal and formal analysis using the Scyther, Proverif, and BAN logic. Furthermore, the proposed scheme offers 67.37% reduction in computation costs and 3.67% in communication costs, presenting an efficient and secure solution for WMSN in the IoMT landscape.

Open access
User Authentication and Security Systems
Advanced Authentication Protocols Security
Biometric Identification and Security
Original source