Mahmoud A. Shawky, Muhammad Usman, David Flynn, Muhammad Ali Imran Ā· 7 authors
Intelligent transportation systems are an emerging technology that facilitates real-time vehicle-to-everything communication. Hence, securing and authenticating data packets for intra- and inter-vehicle communication are fundamental security services in vehicular ad-hoc networks (VANETs). However, public-key cryptography (PKC) is commonly used in signature-based authentication, which consumes significant computation resources and communication bandwidth for signatures generation and verification, and key distribution. Therefore, physical layer-based secret key extraction has emerged as an effective candidate for key agreement, exploiting the randomness and reciprocity features of wireless channels. However, the imperfect channel reciprocity generates discrepancies in the extracted key, and existing reconciliation algorithms suffer from significant communication costs and security issues. In this paper, PKC-based authentication is used for initial legitimacy detection and exchanging authenticated probing packets. Accordingly, we propose a blockchain-based reconciliation technique that allows the trusted third party (TTP) to publish the correction sequence of the mismatched bits through a transaction using a smart contract. The smart contract functions enable the TTP to map the transaction address to vehicle-related information and allow vehicles to obtain the transaction contents securely. The obtained shared key is then used for symmetric key cryptography (SKC)-based authentication for subsequent transmissions, saving significant computation and communication costs. The correctness and security robustness of the scheme are proved using BurrowsāAbadiāNeedham (BAN)-logic and Automated Validation of Internet Security Protocols and Applications (AVISPA) simulator. We also discussed the schemeās resistance to typical attacks. The schemeās performance in terms of packet delay and loss ratio is evaluated using the network simulator (OMNeT++). Finally, the computation analysis shows that the scheme saves ā¼99% of the time required to verify 1000 messages compared to existing PKC-based schemes.
Open access
Vehicular Ad Hoc Networks (VANETs)
Advanced Authentication Protocols Security
Advanced Steganography and Watermarking Techniques
Yan Zhuang, ChiāRen Shyu, Shenda Hong, Pengfei Li Ā· 5 authors
BACKGROUND: Patient tokenization is a novel approach that allows anonymous patient-level linkage across healthcare facilities, minimizing the risk of breaching protected health information in health information exchange (HIE). Most patient tokenization is the centralized approach that is unable to address data security concerns fundamentally. Non-Fungible Tokens (NFT), which are non-transferable cryptographic assets on the blockchain, have the potential to provide secure, decentralized, and trustworthy patient tokenization. Self-Sovereign Identity (SSI) is a user-centric approach to verify the ownership of NFTs in a decentralized manner. METHODS: We have developed a blockchain architecture that contains four modules: (1) Creation module for NFTs creation, (2) Linkage module to link the local patients' accounts to their NFTs, (3) Authentication module that allows patients to permit healthcare providers to access their token, and (4) Exchange module, which involves the HIE process and the validation of the legitimacy of the token through SSI. RESULTS: A case study has been conducted on the proposed architecture. Over 3 million transactions have been completed successfully with a blockchain validation and written time of 1.17 s on average. A stability test has also been conducted with a higher throughput of 200 transactions per second running for an hour with an average transaction processing time of 1.42 s. CONCLUSIONS: This study proposed a blockchain architecture that achieves SSI-enabled NFT-based patient tokenization. Our architecture design, implementation, and case studies have demonstrated the feasibility and potential of NFT with SSI to establish a secure, transparent, and patient-centric identity management and HIE.
Keunok Kim, Jihyeon Ryu, Hakjun Lee, Youngsook Lee Ā· 5 authors
Federated authentication, such as Google ID, enables users to conveniently access multiple websites using a single login credential. Despite this convenience, securing federated authentication services requires addressing a single point of failure, which can result from using a centralized authentication server. In addition, because the same login credentials are used, anonymity and protection against user impersonation attacks must be ensured. Recently, researchers introduced distributed authentication schemes based on blockchains and smart contracts (SCs) for systems that require high availability and reliability. Data on a blockchain are immutable, and deployed SCs cannot be changed or tampered with. Nonetheless, updates may be necessary to fix programming bugs or modify business logic. Recently, methods for updating SCs to address these issues have been investigated. Therefore, this study proposes a distributed and federated authentication scheme that uses SCs to overcome a single point of failure. Additionally, an updatable SC is designed to fix programming bugs, add to the function of an SC, or modify business logic. ProVerif, which is a widely known cryptographic protocol verification tool, confirms that the proposed scheme can provide protection against various security threats, such as single point of failure, user impersonation attacks, and user anonymity, which is vital in federated authentication services. In addition, the proposed scheme exhibits a performance improvement of 71% compared with other related schemes.
The Internet of Things (IoT) is ubiquitous in our lives. However, the inherent vulnerability of IoT smart devices can lead to the destruction of networks in untrustworthy environments. Therefore, authentication is a necessary tool to ensure the legitimacy of nodes and protect data security. Naturally, the authentication factors always include various sensitive usersā information, such as passwords, ID cards, even biological information, etc. How to prevent privacy leakage has always been a problem faced by the IoT. Zero-knowledge authentication is a crucial cryptographic technology that uses authenticates nodes on the networks without revealing identity or any other data entered by users. However, zero-knowledge proof (ZKP) requires more complex data exchange protocols and more data transmission compared to traditional cryptography technologies. To understand how zero-knowledge authentication works in IoT, we produce a survey on zero-knowledge authentication in privacy-preserving IoT in the paper. First, we overview the IoT architecture and privacy, including security challenges and open question in different IoT layers. Next, we overview zero-knowledge authentication and provide a comprehensive analysis of designing zero-knowledge authentication protocols in various IoT networks. We summarize the advantages of ZKP-based authentication in IoT. Finally, it summarizes the potential problems and future directions of ZKP in IoT.
Perubahan teknologi semakin lama semakin pesat diberbagai bidang, termasuk teknologi digital yang merupakan revolusi dari teknologi analog dan elektronik. Dekade ini semua serba bermetamorfosis menjadi digital, termasuk akhirnya muncul uang digital, yaitu cryptocurrency. Cryptocurrency sebagai bentuk digital cash beroperasi dengan bantuan teknik yang disebut kriptografi. Kriptografi sendiri adalah proses yang menerjemahkan semua informasi yang dapat dibaca menjasi kode yang tidak dapat dipecah sama sekali. Cryptocurrency menggunakan blockchain sebagai buku utama, yang semua sistemnya dikelola oleh yang disebut penambang. Mata uang crypto memiliki sistem yang sedikit rumit yang tidak dengan mudah dapat dipahami, jadi pengetahuan tentang cryptocurrency mau tidak mau harus dipelajari, dipahami agar dalam implementasi tidak mengalami dampak yang merugikan. Jenis jenis cryptocurrency, serta kekurangan dan kelebihannya akan dikupas sekilas dalam artikel ini.
Zhe Tu, Huachun Zhou, Kun Li, Haoxiang Song Ā· 5 authors
Abstract It is well known that the Sixth Generation (6G) communication system integrating multiple access networks promotes the internet of everything world-widely. However, due to the differentiated underlying network protocols, it is difficult to find a general authentication solution to support various authentication methods in different access networks. Blockchain is a new technology that supports network heterogeneity, which provides a potential solution for differentiated authentication. In this paper, we propose a blockchain-based differentiated authentication mechanism for 6G Heterogeneous Networks (HetNets), which can efficiently authenticate user identities through scheduling different authentication methods. Particularly, we analyze the authentication architecture of 6G HetNets and put forward a blockchain-based differentiated authentication framework. Besides, to improve the scalability of user authentication, it is the first time to use various blockchain authentication contracts to represent different authentication methods. Meanwhile, a differentiated authentication management contract is proposed to uniformly manage different authentication contracts to realize differentiated identity authentication. Based on the evaluation of the prototype system, the proposed mechanism can dynamically provide differentiated authentication services (e.g. EAP-MD5, 5G-AKA) with low additional time (milliseconds levels) cost.
Mahmoud A. Shawky, Abdul Jabbar, Muhammad Usman, Muhammad Ali Imran Ā· 7 authors
This letter proposes a group key distribution scheme using smart contract-based blockchain technology. The smart contractās functions allow for securely distributing the group session key, following the initial legitimacy detection using public key infrastructure-based authentication. For message authentication, we propose a lightweight symmetric key cryptography-based group signature method, supporting the security and privacy requirements of vehicular ad hoc networks (VANETs). Our discussion examined the schemeās robustness against typical adversarial attacks. To evaluate the gas costs associated with smart contracts functions, we implemented it on the Ethereum main network. Finally, comprehensive analyses of computation and communication costs demonstrate the schemeās effectiveness.
Internet of Medical Things (IoMT) plays an essential role in collecting and managing personal medical data. In recent years, blockchain technology has put power in traditional IoMT systems for data sharing between different medical institutions and improved the utilization of medical data. However, some problems in the information transfer process between wireless medical devices and mobile medical apps, such as information leakage and privacy disclosure. This paper first designs a cross-device key agreement model for blockchain-enabled IoMT. This model can establish a key agreement mechanism for secure medical data sharing. Meanwhile, a certificateless authenticated key agreement (KA) protocol has been proposed to strengthen the information transfer security in the cross-device key agreement model. The proposed KA protocol only requires one exchange of messages between the two parties, which can improve the protocol execution efficiency. Then, any unauthorized tampering of the transmitted signed message sent by the sender can be detected by the receiver, so this can guarantee the success of the establishment of a session key between the strange entities. The blockchain ledger can ensure that the medical data cannot be tampered with, and the certificateless mechanism can weaken the key escrow problem. Moreover, the security proof and performance analysis are given, which show that the proposed model and KA protocol are more secure and efficient than other schemes in similar literature.
Siddhant Thapliyal, Mohammad Wazid, Devesh Pratap Singh, Ashok Kumar Das Ā· 6 authors
The healthcare sector is a very crucial and important sector of any society, and with the evolution of the various deployed technologies, like the Internet of Things (IoT), machine learning and blockchain it has numerous advantages. However, in this section, the data is much more vulnerable than others, because the data is strictly private and confidential, and it requires a highly secured framework for the transmission of data between entities. In this article, we aim to design a blockchain-envisioned authentication and key management mechanism for the IoMT-based smart healthcare applications (in short, we call it SBAKM-HS). We compare the various attributes of the proposed SBAKM-HS and other existing schemes to demonstrate that SBAKM-HS outperforms other existing schemes. The conducted security analysis and formal security verification via Scyther automated validation tool prove the security of the proposed SBAKM-HS against various possible potential attacks. Next, a real-tested implementation of SBAKM-HS is provided to observe its impact on the performance of the system.
Recently, the Digital Twin (DT) technology has procured a lot of attention because of its applicability in the manufacturing and space industries. The DT environment involves the formation of a clone of the tangible object to perform simulations in the virtual space. The combination of conceptual development, predictive maintenance, real-time monitoring, and simulation characteristics of DT has increased the utilization of DT in different scenarios, such as medical environments, healthcare, manufacturing industries, aerospace, etc. However, these utilizations have also brought serious security pitfalls in DT deployment. Towards this, several authentication protocols with different security and privacy features for DT environments have been proposed. In this article, we first review a recently proposed two-factor authentication protocol for DT environments that utilizes the blockchain technology. However, the analyzed scheme is unable to offer the desirable security and cannot withstand various security attacks like offline password-guessing attack, smart card stolen attack, anonymity property, and known session-specific temporary information attack. We also demonstrate that an attacker can impersonate the analyzed protocolās legal user, owner, and cloud server. To mitigate these security loopholes, we devise an effective three-factor privacy-preserving authentication scheme for DT environments. The proposed work is demonstrated to be secure by performing the informal security analysis, the formal security analysis using the widely recognized Burrows-Abadi-Needham (BAN) logic, and the Real-or-Random (ROR) model. A detailed comparative study with the existing competing schemes including the analyzed scheme demonstrates that the devised framework furnishes better security features while also having lower computation costs and comparable communication costs than the existing schemes.
OpenID Connect (OIDC) is one of the most widely used delegated authentication protocols in web and mobile applications providing a single sign-on experience. It allows third-party applications, called Relying Parties (RP), to securely request and receive information about authenticated sessions and end-users from an identity provider. The OIDC specification defines several parameters, including the client_id, client_secret, authorization code, access token, id token, state, and redirect_uri, as keys to the protocol operation, with significant security and privacy implications. Therefore, securing these parameters is critical to prevent attackers from impersonating legitimate entities, gaining unauthorized access, having complete control over usersā accounts, and/or violating their privacy. To enhance OIDC security and preserve its usersā privacy, we propose a novel model for OIDC based on the Ethereum Blockchain and the non-fungible token (ERC721) standard. To prove the robustness and safety of the proposed system, we perform a detailed security analysis formally using the most widely accepted protocols security verification tools, AVISPA and Scyther, and informally by discussing various attacks. The analysis results show that the proposed system is resilient against well-known attacks. Furthermore, we evaluate the cost and performance of the proposed solution, confirming its affordability and assuring that our approach does not impact the user experience and performance of existing OIDC-based systems. Finally, we conduct a security and privacy comparative analysis with similar existing systems, proving the superiority and efficiency of our proposed Blockchain-based OIDC system.
Adnan Shahid Khan, Mohd Izzat Bin Yahya, Kartinah Zen, Johari Abdullah Ā· 8 authors
Cell-Free mMIMO is a part of technology that will be integrated with future 6G ultra-dense cellular networks to ensure unlimited wireless connectivity and ubiquitous latency-sensitive services. Cell-Free gained researchersā interest as it offers ubiquitous communication with large bandwidth, high throughput, high data transmission, and greater signal gain. Cell-Free eliminates the idea of cell boundary in cellular communication that reduces frequent handover and inter-cell interference issues. However, the effectiveness of the current authentication protocol could become a serious issue due to the dynamic nature of Cell-Free in densely distributed, high number of users, high mobility, and frequent data exchange. Secondly, secure communication may be achieved in such a dynamic environment at the expense of high authentication overhead, high communication and computational costs. To address the above security challenges, we proposed a lightweight multifactor mutual authentication protocol for Cell-Free communication using ECC-based Deffie Hellman (ECDH). This scheme utilizes timestamping, one-way hash function, Blind-Fold Challenge scheme with public key infrastructure. The proposed cryptosystem integrates with blockchain technology using proof of staked (POS) as a consensus mechanism to ensure integrity, non-repudiation and traceability. The proposed scheme can enforce the mitigation of several major security attacks on communication links such as spoofing attacks, eavesdropping, user location privacy issues, replay attacks, denial of service attacks, and man-in-the-middle (MITM) attacks, which is one of the significant features of the scheme. Furthermore, this scheme contributes to reducing authentication, communication, and computational overheads with an average of 32.8%, 52.4% and 53.2% better performance respectively as compared baseline authentication protocols.
We study a mechanism design problem in the blockchain proof-of-stake (PoS) protocol. Our main objective is to extend the transaction fee mechanism (TFM) recently proposed in Chung and Shi (SODA, p.3856-3899, 2023), so as to incorporate a long-run utility model for the miner into the burning second-price auction mechanism $\texttt{BSP}(γ)$ proposed in Chung and Shi (where $γ$ is a key parameter in the strict $γ$-utility model that is applied to both miners and users). First, we derive an explicit functional form for the long-run utility of the miner using a martingale approach, and reveal a critical discontinuity of the utility function, namely a small deviation from being truthful will yield a discrete jump (up or down) in the miner's utility. We show that because of this discontinuity the $\texttt{BSP}(γ)$ mechanism will fail a key desired property in TFM, $c$-side contract proofness ($c$-SCP). As a remedy, we introduce another parameter $θ$, and propose a new $\texttt{BSP}(θ)$ mechanism, and prove that it satisfies all three desired properties of TFM: user- and miner-incentive compatibility (UIC and MIC) as well as $c$-SCP, provided the parameter $θ$ falls into a specific range, along with a proper tick size imposed on user bids.
Zengpeng Li, Mei Wang, Vishal Sharma, Prosanta Gope
Vehicle authentication is an essential component validating the vehicleās identity and ensuring the integrity of transformed data for intelligent transport vehicles (ITS) in the vehicular ad hoc network (VANET). Easy to deploy and operate privacy-enhancing vehicle authentication mechanisms are the mainstay for the widespread ITS in the VANET. Very recently, VANET security architectures are constituting by IEEE 1609.2 group, NoW project, the SeVeCom project. However, these approaches heavily depend on the consuming public key infrastructure (PKI) and certification authorities (CA). In this work, walking along the research line, we attempt to design authentication protocols with two diverse factors for Vehicle-to-Vehicle (V2V) and Vehicle-to-Infrastructure (V2I) networks, respectively, without depending on the stumbling block PKI/CA. In addition, a smooth projective hash function (SPHF) (a.k.a., a special case of the designated-verifier zero-knowledge proof system) guarantees any recipient can confirm the authenticity and integrity of the received messages without knowing the authentication factors. Thus, to optimize the communication round, SPHF is used to design a (group) two-factor authenticated key exchange (AKE) with low-interactive communication rounds. The proof-of-concept implementation indicates that the computation and communication overheads introduced by our solution are acceptable in real-world deployments. The security of the proposed approach is validated using Bellare-Pointcheval-Rogaway (BPR) model along with the experimental evaluation and the theoretical analysis.
Arun Sekar Rajasekaran, Azees Maria, R. Maheswar, Josip Lƶrincz
The Internet of Health Things (IoHT) has emerged as an attractive networking paradigm in wireless communications, integrated devices and embedded system technologies. In the IoHT, real-time health data are collected through smart healthcare sensors and, in recent years, the IoHT has started to have an important role in the Internet of Things technology. Although the IoHT provides comfort in health monitoring, it also imposes security challenges in maintaining patient data confidentiality and privacy. To overcome such security issues, in this paper, a novel blockchain-based privacy-preserving authentication scheme is proposed as an approach for achieving efficient authentication of the patient without the involvement of a trusted entity. Moreover, a secure handover authentication mechanism that ensures avoiding the patient re-authentication in multi-doctor communication scenarios and revoking the possible malicious misbehavior of medical professionals in the IoHT communication with the patient is developed. The performance of the proposed authentication and handover scheme is analyzed concerning the existing state-of-the-art authentication schemes. The results of the performance analyses reveal that the proposed authentication scheme is resistant to different types of security attacks. Moreover, the results of analyses show that the proposed authentication scheme outperforms similar state-of-the-art authentication schemes in terms of having lower computational, communication and storage costs. Therefore, the novel authentication and handover scheme has proven practical applicability and represents a valuable contribution to improving the security of communication in IoHT networks.
Mina Namazi, Ross Duncan, Xiaojie Zhu, Erman Ayday
Individuals are encouraged to prove their eligibility to access specific services regularly. However, providing various organizations with personal data spreads sensitive information and endangers people's privacy. Hence, privacy-preserving identification systems that enable individuals to prove they are permitted to use specific services are required to fill the gap. Cryptographic techniques are deployed to construct identity proofs across the internet; nonetheless, they do not offer complete control over personal data or prevent users from forging and submitting fake data. In this paper, we design a privacy-preserving identity protocol called "zkFaith." A new approach to obtain a verified zero-knowledge identity unique to each individual. The protocol verifies the integrity of the documents provided by the individuals and issues a zero-knowledge-based id without revealing any information to the authenticator or verifier. The zkFaith leverages an aggregated version of the Camenisch-Lysyanskaya (CL) signature scheme to sign the user's commitment to the verified personal data. Then the users with a zero-knowledge proof system can prove that they own the required attributes of the access criterion of the requested service providers. Vector commitment and their position binding property enables us to, later on, update the commitments based on the modification of the personal data; hence update the issued zkFaith id with no requirement of initiating the protocol from scratch. We show that the design and implementation of the zkFaith with the generated proofs in real-world scenarios are scalable and comparable with the state-of-the-art schemes.
Sana Hafeez, Mahmoud A. Shawky, Mohammad Al-Quraan, Lina Mohjazi Ā· 6 authors
Unmanned aerial vehicles (UAV), an emerging architecture that embodies flying ad-hoc networks, face critical privacy and security challenges, mainly when engaged in data-sensitive missions. Therefore, message authentication is a crucial security feature for drone communication. This paper presents a Blockchain-based Efficient, and Trusted Authentication scheme for UAV communication BETA-UAV, which exploits the inherent properties of blockchain technology concerning memorability and immutable to record communication sessions via transaction using a smart contract. The smart contract in BETA-UAV allows participants to publish and call transactions from the blockchain network. Furthermore, the transaction addresses are proof of freshness and trustworthiness for subsequent transmissions. Furthermore, we investigate the ability to resist active attacks, e.g., impersonation, replaying, and modification. In addition, we evaluate the gas costs associated with the smart contract's functions by implementing BETA-UAV on the Ethereum public blockchain. Comparing computation and communication over-heads shows that the proposed approach can save significant costs over traditional techniques.
Mohamed A. El-Zawawy, Alessandro Brighente, Mauro Conti
The inclusion of drones in Internet of Vehicles (IoV) is a current trend that presents significant trade-offs. On the one hand, Unmanned Aerial Vehicles (UAVs) provide advantages such as enabling ground communications also when physical obstacles limit the connectivity. On the other hand, they increase the attack surface. For instance, physical attacks on drones provide the attacker with credentials that can be used to inject bogus information into the IoV network, thus jeopardizing not only security but also usersā safety. In this scenario, authentication plays a fundamental role to guarantee security. It is however fundamental to develop authentication protocols that can, at the same time, protect ground usersā data and prevent attacks to drones. However, currently available authentication schemes cannot guarantee security in case of attacks to drones. In this paper, we propose a Blockchain-supported authentication protocol for Drone-assisted IoV using Elliptic curve cryptography (BDIVE). Compared to existing authentication protocols, we extend the threat model from an honest-but-curious drone to active attacks against drones.BDIVEprovides both energy-efficiency, traceability, and accountability thanks to the use of blockchain at the Trusted Authority (TA). Using Burrow-AbadiāNeedham (BAN) logic, we analyze and prove the security of mutual authentication inBDIVE. We also prove the security ofBDIVEagainst several attacks by implementing it in AVISPA. To assess its scalability and energy efficiency, we implementBDIVEusing Omnetpp with its Castalia simulator. The comparison ofBDIVEwith currently existing authentication protocols, shows that it reduces the energy consumption up to 70% and the computational cost up to 68%, while providing resistance to previously unconsidered attack vectors.
Wireless Sensor Networks (WSNs) are becoming more popular for many applications due to their convenient services. However, sensor nodes may suffer from significant security flaws, leading researchers to propose authentication schemes to protect WSNs. Although these authentication protocols significantly fulfill the required protection, security enhancement with less energy consumption is essential to preserve the availability of resources and secure better performance. In 2020, Youssef et al. suggested a scheme called Enhanced Probabilistic Cluster Head Selection (LEACH-PRO) to extend the sensors' lifetime in WSNs. This paper introduces a new variant of the LEACH-PRO protocol by adopting the blockchain security technique to protect WSNs. The proposed protocol (SLEACH-PRO) performs a decentralized authentication mechanism by applying a blockchain to multiple base stations to avoid system and performance degradation in the event of a station failure. The security analysis of the SLEACH-PRO is performed using Burrows-Abadi-Needham (BAN) logic and Automated Validation of Internet Security Protocols and Applications (AVISPA) tool. Moreover, the SLEACH-PRO is evaluated and compared to related protocols in terms of computational cost and security level based on its resistance against several attacks. The comparison results showed that the SLEACH-PRO protocol is more secure and requires less computational cost compared to other related protocols.
The Internet of Vehicles (IoV) can significantly improve transportation efficiency and ensure traffic safety. Authentication is regarded as the fundamental defense line against attacks in IoV. However, the state-of-the-art approaches suffer from several drawbacks, including bottlenecks of the single cloud server model, high computational overhead of operations, excessive trust in cloud servers and roadside units (RSUs), and leakage of vehicle trajectory privacy. In this paper, BEPHAP, a Blockchain-based Efficient Privacy-preserving Handover Authentication Protocol with key agreement for internet of vehicles, is introduced to address these problems. BEPHAP achieves anonymous cross-domain mutual handover authentication with key agreement based on the tamper-proof blockchain, symmetric cryptography, and the chameleon hash function under a security model that cloud servers and RSUs may launch attacks. BEPHAP is particularly well suited for IoV since it allows vehicles only need to perform lightweight cryptographic operations during the authentication phase. BEPHAP also achieves data confidentiality, unlinkability, traceability, non-repudiation, non-frameability, and key escrow freeness. Formal verification based on ProVerif and formal security proofs based on the BAN logic indicates that BEPHAP is resistant to various typical attacks, such as man-in-the-middle attacks, impersonation attacks, and replay attacks. Performance analysis demonstrates that BEPHAP surpasses existing works in both computation and communication efficiencies. And the message loss rate remains 0 at 5000 requests per second, which meets the requirement of IoV.
While 5G can provide high-speed Internet connectivity and over-the-horizon control for Unmanned Aerial Vehicles (UAVs), authentication becomes a key security component in 5G-enabled UAVs. This is due to fact that the communicating entities in the network mostly uses unsecured communication channel to exchange critical surveillance data. Authentication thus plays a crucial role in the 5G-enabled UAV network, providing a range of security services such as credential privacy, Session-Key (SK) security, and secure mutual authentication. However, transparency, anonymity, traceability and centralized control are few major security requirements that cannot be fulfilled by the traditional authentication schemes. One of the upcoming technologies that can provide a solution for present centralized 5G-enabled UAV network is blockchain-based authentication scheme. Motivated from aforementioned discussion, this paper presents a Permissioned Blockchain empowered Secure Authentication and Key Agreement framework in 5G-enabled UAVs. In this framework, first an authentication phase between UAV-to-UAV, UAV-to-Edge Server (ES) and Edge-to-Cloud Server (CS) supporting mutual authentication and key agreement is proposed. The authenticated surveillance data collected from UAV is used by the peer-to-peer CS for transaction verification, block creation and addition using smart contract-based consensus mechanism. The practical implementation of framework shows the effectiveness of the proposed approach.