We present a password‐authenticated (2, 3)‐threshold group key share (PATS) mechanism. Although PATS resembles threshold secret sharing schemes, it has a different structure. The innovative perspective of the PATS mechanism that makes a difference from the standard secret‐sharing schemes is that it involves parties in the generation of the shares. PATS allows parties to communicate securely to establish their shares over insecure channels. Parties (shareholders) construct a secret (key) using shares obtained at the end of the protocol. PATS takes advantage of zero‐knowledge proofs compared to well‐known threshold key exchange schemes and will tolerate the existence of semi‐trusted parties. We present two variants of PATS, centralized and distributed, and then generalize PATS to ( t , n )‐threshold scheme. PATS supports the distributed operation and optionally facilitates group key verification by a trusted third party, which may also partake in group key sharing. In this paper, we present PATS, which employs finite fields and elliptic curves, along with its security and complexity analyses.
Implantable medical devices (IMDs) in medical sciences have provided a quantum leap in network transformation. The communication network with IMDs typically has a wireless radio frequency (RF) telemetry or wired connection. IMDs, being devices, have more computing, communication capabilities and decision-making. Furthermore, these devices are being used to improve patients’ quality of life by medicating various chronic diseases. The captured data is stored in a medical server through a controller node. Our work focuses on wireless communication, so sensitive patient data over a public channel might be tampered with or eavesdropped by unauthorised access. Furthermore, the leakage of health data and malfunctioning of IMDs are vital in constructing cryptographic protocols, particularly in the design of remote user authentication. In this paper, we proposed a novel secure remote user authentication scheme using a lightweight consortium blockchain for the communication network with IMDs.
Xiaoqin Feng, Fuliang Lin, Tao Feng, Jianfeng Ma · 6 authors
Secure and efficient identity authentication is a fundamental requirement in vehicular ad-hoc networks (VANETs); however, it remains challenging due to the highly dynamic network topology, stringent latency constraints, and the need for conditional privacy preservation. Existing authentication schemes either rely on public key infrastructures (PKI) with complex certificate management or introduce partially decentralized designs that still depend on trusted authorities, leading to inefficiencies and single points of failure. In this paper, we propose EBDA, an Ethereum-based fully distributed authentication mechanism for VANETs. The core innovation of EBDA is to replace the traditional PKI certificate system with a blockchain-maintained Graph of Trust (GoT). Through three dedicated smart contracts, EBDA fully decentralizes the management of vehicle identities and pseudonyms. Vehicles use pseudonyms to preserve privacy in Vehicle-to-Vehicle communications, while authentication is achieved certificate-free via transitive trust within the GoT. Importantly, latency-sensitive operations like message verification are executed off-chain through local checks, meeting VANETs’ strict real-time requirements. A prototype implementation and extensive evaluations demonstrate that EBDA significantly reduces authentication latency by at least 22.93% compared with representative blockchain-assisted and PKI-based baselines while maintaining low computational and storage overhead. These results confirm the feasibility of deploying GoT-based decentralized authentication in practical VANET environments.
Radio Frequency Identification (RFID) promotes the fundamental tracking procedure of the Internet of Things (IoT) network due to its autonomous data collection as well as transfer incurring low costs. To overcome the insecure exchange of tracking data and to prevent unauthorized access, parallel dependency RFID grouping-proof protocol is applied by the reader to authenticate tags simultaneously. However, conventional grouping-proof authentication schemes are not sufficient for the memory constraint RFID tags due to the recurrent utilization of a 128-bit PRNG (Pseudo Random Number Generator) function. Alternatively, the existing parallel-dependency grouping-proof schemes are not able to overcome numerous limitations regarding session establishment, efficient key management, and multicast message communication within the specified group. In this research, a lightweight, secure, and efficient communication protocol is proposed to overcome the aforementioned limitations using Elliptic Curve Cryptography (ECC) and Zero-Knowledge property to establish a session key among the participated tags, reader, and remote server. The proposed scheme can work in offline mode. The proposed ECC-based parallel dependency grouping-proof scheme is referred to as ECC-PDGPP which abides by the rules of the EPC class-1 gen-2 (C1 G2) standard of RFID tags. Finally, the proposed protocol is analyzed using a formal random oracle model and simulated using a well-known AVISPA simulation tool that shows the proposed scheme is well protected against all potential security threats.
How to safely and anonymously interact with fog nodes’ charging stations is a big deal for hybrid electric vehicles in fog-based vehicular networks. Although there exist key exchange protocols, which tried to cover this critical concern, most of them are certificate-based. In addition, they do not support key revocation option or cannot totally resist advanced cyber attacks such as key compromise impersonation attack. As a result, this paper, by means of Blockchain, proposes a highly-secure self-certified key exchange protocol with an exceptional level of privacy. By the proper employment of distributed ledger, the suggested protocol can also support the authentication token revocation and immutability. Formal security and performance analyses as well as comparison with top scholarly articles demonstrate the distinct security features and applicability of the proposed protocol.
Ірина Стрелковська, Олексій Онацький, Лариса Григорівна Йона
Background. To ensure the protection of the biometric access control system used in unsecured communication channels, it is necessary to exclude the storage and transfer, transfer of biometric data as well as sequences generated on their basis. The paper proposes a cryptographic protocol of two-factor authentication with the zero-knowledge over the extended field GF(2m) on elliptic curves using biometric data and the private key of the user. Objective. The aim of the article is to develop a cryptographic protocol for zero-knowledge two-factor authentication based on elliptic curves using biometric data and the user’s private key, which allows increasing cryptographic strength and reducing the duration of the authentication process. Methods. The process of implementing zero-knowledge proof protocols is as follows: one user (proofer) can convince another user (verifier) that he has some secret without disclosing the secret itself. Results. A cryptographic protocol for two-factor authentication with zero-knowledge over the extended field GF(2m) of elliptic curves using user biometric data is proposed, which significantly reduces the size of the protocol parameters and increases cryptographic strength (computational complexity of the breaking). There is no leakage of private key information and biometric data of the user during the execution of the zero-knowledge proof protocol. Conclusions. The implementation of a cryptographic protocol with zero-knowledge proof two-factor authentication based on elliptic curves allows significantly reducing the size of protocol parameters and increasing the cryptographic strength (computational complexity of the breaking).
Firas Hamila, Mohammad Hamad, Daniel Costa Salgado, Sebastian Steinhorst
Abstract With the rapid expansion of IoT devices and their applications, there is an increasing demand for efficient and secure authentication mechanisms to protect against unauthorized access. Traditional authentication mechanisms face limitations regarding computational speed, communication costs, and vulnerability to cyber-attacks. Zero-knowledge proof (ZKP) protocols have emerged as an effective solution for achieving secure and efficient authentication in such environments without revealing sensitive information. Among ZKP protocols, $$\Sigma $$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>Σ</mml:mi> </mml:math> -protocols, a class of interactive ZKP protocols, have been employed for their efficiency and security. However, their interactive nature necessitates multiple rounds of communication, which can reduce efficiency and increase communication overhead for resource-constrained devices. Many works have aimed to eliminate the interaction of $$\Sigma $$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>Σ</mml:mi> </mml:math> -protocols by utilizing a transformation called the Fiat–Shamir transformation (FST). However, there is still a concern regarding the soundness of the FST as it can sometimes convert a secure $$\Sigma $$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>Σ</mml:mi> </mml:math> -protocol into an insecure non-interactive zero-knowledge (NIZK) authentication scheme. In this paper, we propose an approach for transforming $$\Sigma $$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>Σ</mml:mi> </mml:math> -protocols into a NIZK protocol based on the FST, yielding significant enhancements in efficiency, communication overhead reduction, and elimination of interaction. Our proposed protocol enables the completion of the authentication process in a single request while also strengthening the soundness of $$\Sigma $$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>Σ</mml:mi> </mml:math> -protocols in comparison with the traditional FST by requiring two authentication factors instead of one. To demonstrate our approach’s robustness, we conducted comprehensive informal and formal security analyses (using the Tamarin-Prover). Our protocol demonstrated completeness, soundness, zero-knowledge properties, and robustness against attacks, including eavesdropping, message modification, replay, and brute force attacks. Additionally, our performance analysis displayed a remarkable 50% improvement in computational cost compared to traditional $$\Sigma $$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>Σ</mml:mi> </mml:math> -protocols, underscoring its efficiency for practical use.
Alexandr Kuznetsov, Emanuele Frontoni, V. A. Katrich, Olena Kobylianska · 5 authors
Existing digital identification systems are often vulnerable to attacks as they are commonly based on authentication methods such as passwords, PIN codes, biometric data, etc., which can be easily forged or compromised. In this letter, we propose a digital identification system based on a unique set of user biometric data processed by Artificial Intelligence (AI) and fuzzy extractors to generate a cryptographically secure password linked to a unique Non-Fungible Token (NFT). Our system provides decentralized identification based on blockchain technology, which eliminates problems associated with centralized identification systems, such as cyber-attacks on central servers and data leaks. Our proposed system offers a higher level of user identification security by linking the user to their data through a unique NFT, generating a cryptographically secure password, and processing large volumes of biometric data using AI and fuzzy extractors. Our system provides a solution to many of these problems, making it important and relevant to many industries, including banking, medical, and financial sectors. The use of decentralized storage of information on the blockchain provides a high level of protection against hacking and reduces the likelihood of data breaches, making our system particularly relevant in the field of financial services and personal data protection.
The ERC721 standard defines a Non-Fungible Token (NFT) as an identifier that uniquely identifies digital data recorded on a blockchain. The NFT currently in use claim to ensure the uniqueness of the contents associated with the NFT by taking advantage of the tamper-resistant characteristics of the blockchain data. Besides, digital signatures based on public-key encryption is a representative technique to prevent digital data from being falsified, and its application to NFT is also discussed. In this study, we first consider an NFT implementation by applying a designated confirmer signature using an interactive verification method without using blockchain technology. We design an NFT issuance protocol that guarantees the uniqueness of data with a designated confirmer signature, and evaluate the security of the protocol. Moreover, we compare it with existing blockchain implementations. By analyzing the both methods, we aim to provide insights into the potential applications and performance in using designated confirmer signatures for NFT. Our findings contribute to the ongoing research on secure and efficient mechanisms for ensuring the integrity and uniqueness of digital assets in decentralized systems.
The Internet of Medical Things (IoMT) is the network of medical devices, software applications, and healthcare information systems used for remote monitoring and delivery of healthcare services. Despite the several advantages of IoMT for today smart healthcare, security issues are growing due to the inadequate computation, limited storage and insufficient self-protection capabilities of IoMT devices. Authentication of IoMT devices is the main requirement to secure IoMT systems. Although, the recent authentication schemes based on tamper-proof decentralized architecture of blockchain technology are robust and enjoy a high level of security, yet they require high computation, more storage, and long authentication time. These issues lead to reduced scalability and time efficiency, which are necessary for large-scale, time-sensitive IoMT systems. To this end, this paper proposes a novel group authentication framework for IoMT Systems. The group authentication scheme is implemented through a four-phase process, including setup, registration, secret construction, and authentication. To enhance both efficiency and scalability, the proposed group authentication framework employs a combination of elliptic curve cryptography (ECC), Shamir’s secret sharing (SSS) algorithm, and blockchain-based fog computing technologies. We simulated the proposed framework through the Ethereum platform and Solidity language and its performance is evaluated using the Hyperledger Caliper tool. The simulation experiments of the proposed framework showed that the average latency of authenticating IoMT devices was 0.5 second and the throughput was 400 transactions per second. Our analysis of the proposed framework’s performance against other cutting-edge blockchain-based authentication techniques showed that it outperformed them in terms of latency and throughput. A security analysis of the proposed framework was conducted using the widely accepted Automated Validation of Internet Security Protocols and Applications (AVISPA) tool. The formal and informal security analysis demonstrated that the proposed framework is secure and resistant to potential authentication-related attacks. We also noted that the average latency of the proposed framework maintains a fairly narrow range when the number of submitted transactions rises, indicating that it supports the scalability of the IoMT system.
Unmanned aerial vehicles (UAVs) have become increasingly popular in recent years and are applied in various fields, from commercial and scientific to military and humanitarian operations. However, their usage presents many challenges, including limited resources, scalability issues, insecure communication, and inefficient solutions. We developed a secure and scalable registration protocol to address these issues using LoRa technology. Our solution involves the usage of the physical unclonable function (PUF) and blockchain technology for key exchange. PUF also ensures security against physical tampering, and blockchain is applied to share the symmetric key among the base stations. After the registration, the later communication messages are encrypted with AES-GCM to provide authentication and confidentiality between the parties. We conducted a security analysis of the registration protocol using the ProVerif tool, and our solution meets the security requirements, including the mutual authentication of entities, key freshness, key secrecy and also key confirmation properties. Besides the Proverif-based analysis, an informal security analysis is also provided that shows that the registration is protected against a variety of well-known active and passive security attacks. As drone resources are limited, we also prepared a proof of concept to test our solution under real-life conditions, focusing on efficiency and lightweight operations.
Open access
User Authentication and Security Systems
Advanced Authentication Protocols Security
Physical Unclonable Functions (PUFs) and Hardware Security
Amit Kumar Mishra, Mohammad Wazid, Devesh Pratap Singh, Ashok Kumar Das · 6 authors
One of the most significant recent advances in technology is the advent of unmanned aerial vehicles (UAVs), i.e., drones. They have widened the scope of possible applications and provided a platform for a wide range of creative responses to a variety of challenges. The Internet of Drones (IoD) is a relatively new concept that has arisen as a consequence of the combination of drones and the Internet. The fifth-generation (5G) and beyond cellular networks (i.e., drones in networks beyond 5G) are promising solutions for achieving safe drone operations and applications. They may have many applications, like surveillance or urban areas, security, surveillance, retaliation, delivering items, smart farming, film production, capturing nature videos, and many more. Due to the fact that it is susceptible to a wide variety of cyber-attacks, there are certain concerns regarding the privacy and security of IoD communications. In this paper, a secure blockchain-enabled authentication key management framework with the big data analytics feature for drones in networks beyond 5G applications is proposed (in short, SBBDA-IoD). The security of SBBDA-IoD against multiple attacks is demonstrated through a detailed security analysis. The Scyther tool is used to perform a formal security verification test on the SBBDA-IoD’s security, confirming the system’s resistance to various potential attacks. A detailed comparative analysis has identified that SBBDA-IoD outperforms the other schemes by a significant margin. Finally, a real-world implementation of SBBDA-IoD is shown to evaluate its effect on several measures of performance.
Aydin Abadi, Dan Ristea, Artem Grigor, Steven J. Murdoch
Time-Lock Puzzles (TLPs) enable a client to lock a message such that a server can unlock it only after a specified time. They have diverse applications, such as scheduled payments, secret sharing, and zero-knowledge proofs. In this work, we present a scalable TLP designed for real-world scenarios involving a large number of puzzles, where clients or servers may lack the computational resources to handle high workloads. Our contributions are both theoretical and practical. From a theoretical standpoint, we formally define the concept of a “Delegated Time-Lock Puzzle (D-TLP)”, establish its fundamental properties, and introduce an upper bound for TLPs, addressing a previously overlooked aspect. From a practical standpoint, we introduce the “Efficient Delegated Time-Lock Puzzle” (ED-TLP) protocol, which implements the D-TLP concept. This protocol enables both the client and server to securely outsource their resource-intensive tasks to third-party helpers. It enables realtime verification of solutions and guarantees their delivery within predefined time limits by integrating an upper bound and a fair payment algorithm. ED-TLP allows combining puzzles from different clients, enabling a solver to process them sequentially, significantly reducing computational resources, especially for a large number of puzzles or clients. ED-TLP is the first protocol of its kind. We have implemented ED-TLP and conducted a comprehensive analysis of its performance for up to 10,000 puzzles. The results highlight its significant efficiency in TLP applications, demonstrating that EDTLP securely delegates 99% of the client’s workload and 100% of the server’s workload with minimal overhead.
Abstract With the increase of IoT devices generating large amounts of user-sensitive data, improper firmware harms users’ security and privacy. Latest home appliances are integrated with features to assure compatibility with smart home IoT. However, applying complex security mechanisms to IoT is limited by device hardware capabilities, making them vulnerable to attacks. Such attacks have recently become frequent. To address this issue, we developed a secure verification mechanism for firmware released by the device’s manufacturer. We proposed an IoT gateway for secure firmware verification and updating for smart home IoT devices utilizing the IOTA MAM (Masked Authenticated Messaging) protocol and a distributed file system with IPFS (Inter-Planetary File System) protocol. These two communication protocols ensure decentralized communication and firmware file distribution between the IoT device vendor and the IoT end device. The proposed scheme securely shares latest firmware content over IOTA and IPFS networks, performs a secure firmware update on IoT end devices and ensures authenticity and integrity of the firmware. Two types of validation methods were proposed for firmware updating and validation. We implemented the proposed scheme using three entities, Vendor, IoT gateway, and IoT end device. Our system yielded promising results in performing secure automated firmware updates on IoT end devices with very low computational power. The system’s functionality was implemented using IOTA’s MAM run on Raspberry Pi as an IoT gateway along with an ESP8266 Wi-Fi microcontroller, demonstrating the effectiveness of our approach. Our proposed methodology can be used for secure firmware distribution on home IoT applications.
A commitment scheme is a cryptographic tool that allows one to commit to a hidden value, with the option to open it later at requested places without revealing the secret itself. Commitment schemes have important applications in zero-knowledge proofs and secure multi-party computation, just to name a few. This survey introduces a few multivariate polynomial commitment schemes that are built from a variety of mathematical structures. We study how Orion is constructed using hash functions; Dory, Bulletproofs, and Vampire using the inner-product argument; Signatures of Correct Computation using polynomial factoring; DARK and Dew using groups of unknown order; and Orion+ using a CP-SNARK. For each protocol, we prove its completeness and state its security assumptions.
Lattice-based cryptography is one of the most promising candidates for designing post-quantum cryptographic algorithms that resist emerging quantum computing attacks. The recent NIST PQC standardization process is nearing its completion, with practical lattice-based algorithms for basic cryptographic functionalities (namely digital signature and public-key encryption) selected for standardization in the near future. However, practical lattice-based solutions for more advanced privacy-preserving protocols, in particular, Zero-Knowledge Proofs (ZKPs), have only emerged recently and are an active area of research. We discuss some recent developments in design and analysis of practical lattice-based post-quantum ZKPs and their applications. In particular, we review some challenges that arise in designing ZKPs in the lattice setting and some recent progress on efficient lattice-based Schnorr-like proofs for important relations, such as binary/range proofs, one-out-of-many proofs and rounding proofs [1, 2, 4]. We discuss applications and optimization of such proof systems as building blocks for practical advanced cryptographic protocols such as ring signatures and balance proofs for privacy-preserving cryptocurrency payment protocols [2, 3]. We also discuss our recent work on succinct designated-verifier ZKPs (DV-ZKSNARKS) for verifying correctness of general delegated computations [5].
Smart healthcare technology is transforming from the traditional healthcare system in every manner conceivably. Smart healthcare provides several advantages over the existing approaches. However, it suffers from healthcare data security and privacy issues. As the Internet attackers may get access to sensitive healthcare data through the use of various types of cyber attacks. In this paper, an architecture of a blockchain-enabled secure smart health monitoring system has been presented (in short, it is called as BSSHM). BSSHM consists of various health data monitoring sensors, i.e., temperature, heartbeat, etc., which monitor the real time health data of the different patients. The healthcare data of the patients can be transmitted to the connected health servers in a secure way, where this data can be stored securely for its various uses. The formal security verification of the proposed BSSHM is also done through the widely-accepted Scyther tool. It has been proved that BSSHM is able to defend various potential attacks.
Awaneesh Kumar Yadav, An Braeken, Mika Ylianttila, Madhusanka Liyanage
The metaverse, which consists of several universes called verses, is predicted to be the Internet of the future. Recently, this idea has received a lot of discussions, but not enough attention has been paid to the security concerns of these virtual worlds. Primarily when the user and platform server communicate with each other and share sensitive information using the public channel, any attacker can capture the message and can perform various types of attacks such as privacy attack, violation of perfect forward secrecy, impersonation attack, ephemeral secret leakage attack and traceability attack. Therefore, there is impelling need to design an authentication protocol for the metaverse environment that can secure the communication between the user and the platform server. Taking this into account, we designed a zero-knowledge proof authentication protocol based on blockchain for the metaverse environment. The security of the designed protocol is verified through the Burrows-Abadi-Needham (BAN) logic, Scyther tool, and Automated Validation of Internet Security Protocols and Applications (AVISPA) tool. The outcome of the security verification demonstrates that the designed metaverse authentication protocol mitigates all the attacks mentioned above. Moreover, we evaluated the performance of the designed metaverse authentication protocol in terms of computational, communication, storage costs, and energy consumption and compared it with existing metaverse authentication protocols, showing good results taking into account the additional security strength.
Xin Liu, Weitong Chen, Naixue Xiong, Dan Luo · 6 authors
Private set intersection (PSI) is a valuable technique with various practical applications, including secure matching of communication packets in the Internet of Things. However, most of the currently available two-party PSI protocols are based on the oblivious transfer (OT) protocol, which is computationally expensive and results in significant communication overhead. In this paper, we propose a new coding method to design a two-party PSI protocol under the semi-honest model. We analyze possible malicious attacks and then develop a PSI protocol under the malicious model using the Paillier cryptosystem, cut-and-choose, zero-knowledge proof, and other cryptographic tools. By adopting the real/ideal model paradigm, we prove the protocol’s security under the malicious model, which is more efficient compared to the existing related schemes.
Smart contracts self-executing code deployed on blockchain platforms have revolutionized the way digital agreements are formed and executed. Despite their decentralized nature and deterministic logic, vulnerabilities in code and execution environments can compromise their security. Cryptography is pivotal in safeguarding the integrity, authenticity, and confidentiality of smart contract operations. This paper explores cryptographic techniques that enhance smart contract trustworthiness, including digital signatures, zero-knowledge proofs, and verifiable computation. We assess how these methods reinforce security, compare frameworks across criteria like scalability and auditability, and present best practices for secure smart contract development
Threshold signatures are a fundamental cryptographic primitive used in many practical applications. As proposed by Boneh and Komlo (CRYPTO'22), TAPS is a threshold signature that is a hybrid of privacy and accountability. It enables a combiner to combine t signature shares while revealing nothing about the threshold t or signing quorum to the public and asks a tracer to track a signature to the quorum that generates it. However, TAPS has three disadvantages: it 1) structures upon a centralized model, 2) assumes that both combiner and tracer are honest, and 3) leaves the tracing unnotarized and static. In this work, we introduce Decentralized, Threshold, dynamically Accountable and Private Signature (DeTAPS) that provides decentralized combining and tracing, enhanced privacy against untrusted combiners (tracers), and notarized and dynamic tracing. Specifically, we adopt Dynamic Threshold Public-Key Encryption (DTPKE) to dynamically notarize the tracing process, design non-interactive zero knowledge proofs to achieve public verifiability of notaries, and utilize the Key-Aggregate Searchable Encryption to bridge TAPS and DTPKE so as to awaken the notaries securely and efficiently. In addition, we formalize the definitions and security requirements for DeTAPS. Then we present a generic construction and formally prove its security and privacy. To evaluate the performance, we build a prototype based on SGX2 and Ethereum.
Sandeep Kumar Arora, Gulshan Kumar, Mustapha Hedabou, El Mehdi Amhoud · 5 authors
Summary A decentralized application runs on the blockchain network without the intervention of a central authority. Transparency in transactions and security in vehicular networks are the issues for central systems. The proposed system uses blockchain‐based smart contracts, which eliminate the requirement for any third‐party verification. Additionally, with signature verification and reduced overhead, smart contracts also help in a fast and secure transaction. This study suggests a trust‐based system paradigm where certificate authority (CA) is employed for vehicle registration. We also propose a blockchain‐based system that provides efficient two‐way authentication and key agreement through encryption and digital signatures. The analysis of the proposed model reveals that it is an efficient way of establishing distributed trust management, which helps in preserving vehicle privacy. The proposed scheme is tested in Automated Validation of Internet Security‐sensitive Protocols (AVISPA), and security parameters verification in Network Simulator 2(NS2) also shows that the proposed scheme is more effective in comparison with existing schemes in terms of authentication cost, storage cost, and overhead.