Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

486 papersLast indexed Aug 31, 2026
Search papers

Paper index

486 results · page 13 of 21

Clear filters
Sep 28, 2022·Computer Communications
35 cites
A user-centric privacy-preserving authentication protocol for IoT-AmI environments

Mehedi Masud, Gurjot Singh Gaba, Pardeep Kumar, Andrei Gurtov

Ambient Intelligence (AmI) in Internet of Things (IoT) has empowered healthcare professionals to monitor, diagnose, and treat patients remotely. Besides, the AmI-IoT has improved patient engagement and gratification as doctors’ interactions have become more comfortable and efficient. However, the benefits of the AmI-IoT-based healthcare applications are not availed entirely due to the adversarial threats. IoT networks are prone to cyber attacks due to vulnerable wireless mediums and the absentia of lightweight and robust security protocols. This paper introduces computationally-inexpensive privacy-assuring authentication protocol for AmI-IoT healthcare applications. The use of blockchain & fog computing in the protocol guarantees unforgeability, non-repudiation, transparency, low latency, and efficient bandwidth utilization. The protocol uses physically unclonable functions (PUF), biometrics, and Ethereum powered smart contracts to prevent replay, impersonation, and cloning attacks. Results prove the resource efficiency of the protocol as the smart contract incurs very minimal gas and transaction fees. The Scyther results validate the robustness of the proposed protocol against cyber-attacks. The protocol applies lightweight cryptography primitives (Hash, PUF) instead of conventional public-key cryptography and scalar multiplications. Consequently, the proposed protocol is better than centralized infrastructure-based authentication approaches.

Open access
User Authentication and Security Systems
Advanced Authentication Protocols Security
Biometric Identification and Security
Original source
Sep 26, 2022·Annals of Computer Science and Information Systems
5 cites
Secure Onboarding and Key Management in Federated IoT Environments

Krzysztof Kanciak, Konrad Wrona, Michał Jarosz

Many high-impact Internet of Things (IoT) scenarios, such as humanitarian assistance and disaster relief, public safety, and military operations, require the establishment of a secure federated IoT environment. One of the critical challenges in the implementation of federated IoT solutions involves establishing a secure and authenticated key management mechanism. We propose and validate in a laboratory environment a novel federated IoT onboarding and key management solution. Our dl-mOT protocol integrates an efficient identity-based modified Okamoto-Tanaka (mOT) protocol with a distributed ledger in order to establish an anchor of trust between federation members.

Open access
Advanced Authentication Protocols Security
IoT and Edge/Fog Computing
Original source
Sep 20, 2022·Drones
58 cites
An Efficient Authentication Scheme Using Blockchain as a Certificate Authority for the Internet of Drones

Sana Javed, Muhammad Asghar Khan, Ako Muhammad Abdullah, Amjad Alsirhani · 7 authors

The Internet of Drones (IoD) has recently gained popularity in several military, commercial, and civilian applications due to its unique characteristics, such as high mobility, three-dimensional (3D) movement, and ease of deployment. Drones, on the other hand, communicate over an unencrypted wireless link and have little computational capability in a typical IoD environment, making them exposed to a wide range of cyber-attacks. Security vulnerabilities in IoD systems include man-in-the-middle attacks, impersonation, credential leaking, GPS spoofing, and drone hijacking. To avoid the occurrence of such attacks in IoD networks, we need an extremely powerful security protocol. To address these concerns, we propose a blockchain-based authentication scheme employing Hyperelliptic Curve Cryptography (HECC). The concepts of a blockchain as a Certificate Authority (CA) and a transaction as a certificate discussed in this article are meant to facilitate the use of a blockchain without CAs or a Trusted Third Party (TTP). We offer a security analysis of the proposed scheme, which demonstrates its resistance to known and unknown attacks. The proposed scheme resists replay, man-in-the-middle, device impersonation, malicious device deployment, Denial-of-Service (DoS), and De-synchronization attacks, among others. The security and performance of the proposed scheme are compared to relevant existing schemes, and their performance is shown to be better in terms of security attributes as well as computation and communication costs than existing competitive schemes. The total computation cost of the proposed scheme is 40.479 ms, which is 37.49% and 49.79% of the two comparable schemes. This shows that the proposed scheme is better suited to the IoD environment than existing competitive schemes.

Open access
Blockchain Technology Applications and Security
UAV Applications and Optimization
Advanced Authentication Protocols Security
Original source
Aug 31, 2022·IEEE Intelligent Systems
61 cites
Retracted: Deep Learning and Smart Contract-Assisted Secure Data Sharing for IoT-Based Intelligent Agriculture

Randhir Kumar, Prabhat Kumar, Ahamed Aljuhani, A.K.M. Najmul Islam · 6 authors

The recent development of Internet of Things (IoT) and Unmanned Aerial Vehicles has revolutionized traditional agriculture with intelligence and automation. In a typical Intelligent Agriculture (IA) ecosystem, massive and real-time data are generated, analyzed, and sent to the Cloud Server (CS) for the purpose of addressing complex agricultural issues, such as yield prediction, water feed calculation, and so on. This helps farmer and associated stakeholders to take correct decision that improves the yield and quality of agricultural product. However, the distributed nature of IA entities and the usage of insecure wireless communication open various challenges related to data sharing, monitoring, storage, and further makes the entire IA ecosystem vulnerable to various potential attacks. In this article, we exploit deep learning and smart contract to propose a new IoT-enabled IA framework for enabling secure data sharing among its various entities. Specifically, first we develop new authentication and key management scheme to ensure secure data transmission in IoT-enabled IA. The encrypted transactions are then used by the CS to analyze and further detect intrusions by a novel deep learning architecture. In CS, the smart contract (SC)-based consensus mechanism is executed on legitimate transactions that verifies and adds the formed blocks into blockchain by a peer-to-peer CSs network. In comparison to existing competing security solutions, a rigorous comparative research demonstrates that the proposed approach provides greater security and more utility characteristics.

Open access
Blockchain Technology Applications and Security
Advanced Authentication Protocols Security
User Authentication and Security Systems
Original source
Jul 12, 2022·IEEE Transactions on Dependable and Secure Computing
11 cites
Leveraging Smart Contracts for Secure and Asynchronous Group Key Exchange Without Trusted Third Party

Victor Youdom Kemmoe, Yongseok Kwon, Rasheed Hussain, Sunghyun Cho · 5 authors

Group Key Exchange (GKE) is an important tool to develop secure multi-user applications such as group text messages, ad-hoc networks, and so on. Most of the currently deployed GKE schemes are synchronous, i.e., they require all the participants to be online during their execution. However, with more battery-powered devices being used in such applications, the synchronicity requirement is challenging to fulfill. To fill the gaps, asynchronous GKE schemes have been introduced in the literature. Nevertheless, the currently available asynchronous and synchronous GKE schemes rely on Trusted Third Parties (TTPs) for key establishment and management. To this end, reliance on TTPs is a serious shortcoming since TTPs are well known to be the single point of failure. Furthermore, the existing GKE schemes require participants to perform all computations, which can degrade the performance of resource-constrained devices such as Internet of Things (IoT) devices. To solve these problems, in this paper, we propose an asynchronous GKE scheme that uses blockchain and smart contracts to store the security keys-related material and reduce the computational load of the participants. Furthermore, our proposed scheme provides Perfect Forward Secrecy (PFS) and Post-Compromised Security (PCS). Our implementation on Ethereum shows that the proposed scheme can scale to more than 100 participants when combined with a distributed storage system.

Open access
Security in Wireless Sensor Networks
Cryptography and Data Security
Advanced Authentication Protocols Security
Original source
Jun 30, 2022·Zenodo (CERN European Organization for Nuclear Research)
1 cites
Overview of the security and trust mechanisms in the 5GZORRO project

Paulo Chaínho

In the evolution from 5G to beyond 5G networks, new business models are emerging where multi-domain and multistakeholder scenarios will play a paramount role as enablers. In these scenarios, the automated management of the services with minimal human intervention, also known as zero-touch management, is a pivotal requirement to ensure a proper functioning and to enable real-time responses to possible incidents or scalability needs. Nonetheless, these new scenarios and requirements also introduce new security risks that entail a complex threat landscape for beyond 5G networks. Hence, zero-touch management demands new solutions capable of securely controlling network resources into end-to-end scenarios distributed in multiple domains. In this vein, several challenges arise and need to be addressed, such as integrity, non-repudiation, confidentiality, security, and trust. Therefore, the H2020 5GZORRO project proposes new security and trust solutions for multi-domain and multi-stakeholder scenarios in 5G and beyond networks. To deal with the utmost importance security and trust challenges, we introduce different modules to mitigate them, namely, integrity and non-repudiation through Distributed Ledger Technologies, decentralized identity through an Identity and Permission Manager, end-to-end trustworthy relationships via a Trust Management Framework, secure workloads across different tenants and stakeholders via Trusted Execution Environment Security Management, detection and response to internal vulnerabilities and attacks via Network Monitoring, and on-demand secure cross-domain connections via VPN-as-a-Service. Therefore, the built security and trust 5GZORRO mechanisms form a secure environment with zero-touch automation capabilities, minimizing human intervention.

Open access
Advanced Authentication Protocols Security
Opportunistic and Delay-Tolerant Networks
IPv6, Mobility, Handover, Networks, Security
Original source
Jun 15, 2022·Sensors
40 cites
A Secure Blockchain-Based Authentication and Key Agreement Scheme for 3GPP 5G Networks

Man Chun Chow, Maode Ma

The futuristic fifth-generation cellular network (5G) not only supports high-speed internet, but must also connect a multitude of devices simultaneously without compromising network security. To ensure the security of the network, the Third Generation Partnership Project (3GPP) has standardized the 5G Authentication and Key Agreement (AKA) protocol for mutually authenticating user equipment (UE), base stations, and the core network. However, it has been found that 5G-AKA is vulnerable to many attacks, including linkability attacks, denial-of-service (DoS) attacks, and distributed denial-of-service (DDoS) attacks. To address these security issues and improve the robustness of the 5G network, in this paper, we introduce the Secure Blockchain-based Authentication and Key Agreement for 5G Networks (5GSBA). Using blockchain as a distributed database, our 5GSBA decentralizes authentication functions from a centralized server to all base stations. It can prevent single-point-of-failure and increase the difficulty of DDoS attacks. Moreover, to ensure the data in the blockchain cannot be used for device impersonation, our scheme employs the one-time secret hash function as the device secret key. Furthermore, our 5GSBA can protect device anonymity by mandating the encryption of device identities with Subscription Concealed Identifiers (SUCI). Linkability attacks are also prevented by deprecating the sequence number with Elliptic Curve Diffie-Hellman (ECDH). We use Burrows-Abadi-Needham (BAN) logic and the Scyther tool to formally verify our protocol. The security analysis shows that 5GSBA is superior to 5G-AKA in terms of perfect forward secrecy, device anonymity, and mutual Authentication and Key Agreement (AKA). Additionally, it effectively deters linkability attacks, replay attacks, and most importantly, DoS and DDoS attacks. Finally, the performance evaluation shows that 5GSBA is efficient for both UEs and base stations with reasonably low computational costs and energy consumption.

Open access
Advanced Authentication Protocols Security
User Authentication and Security Systems
Internet Traffic Analysis and Secure E-voting
Original source
Jun 14, 2022·Symmetry
33 cites
EBAS: An Efficient Blockchain-Based Authentication Scheme for Secure Communication in Vehicular Ad Hoc Network

Xia Feng, Kaiping Cui, Haobin Jiang, Ze Li

A vehicular ad hoc network (VANET) is essential in building an intelligent transportation system that optimizes traffic conditions and makes traffic information conveniently accessible. However, malicious vehicles may disrupt the traffic order via propagating forged traffic/road information. Therefore, using digital certificates based on cryptography, some existing authentication schemes were proposed to manage vehicles’ identities. At first glance, these schemes can effectively identify malicious vehicles. However, these schemes require more computation and storage resources to maintain certificates. This is because the data storage of the database increases in a near-linear trend as the number of certificates grows. In this paper, we propose an efficient blockchain-based authentication scheme for secure communication in VANET (EBAS) to address the aforementioned issues. In EBAS, the regional trusted authority (RTA) receives traffic messages uploaded by the vehicle, together with transactions constructed via the unspent transaction output (UTXO) model. The verifier checks the legitimacy of the single input contained in the uploaded transaction to verify the legitimacy of the message sender’s identity. In terms of privacy preservation, a asymmetric key encryption technique, elliptic curve cryptography (ECC), is applied for constructing the transaction pseudonym, and users participate in the authentication process anonymously. In addition, our scheme guarantees the scalability of EBAS by proposing a transaction update mechanism, which can keep data storage at a stable level rather than near-linear growth. Under the simulation, the retrieving overhead remains at approximately 0.32 ms while the storage cost is stable at around 32.7 M for the blockchain state database. In terms of authentication efficiency, the average overhead of the proposed scheme is around 0.942 ms, which outperforms the existing schemes.

Open access
Vehicular Ad Hoc Networks (VANETs)
Blockchain Technology Applications and Security
Advanced Authentication Protocols Security
Original source
Jun 8, 2022·arXiv (Cornell University)
0 cites
Intractable Group-theoretic Problems Around Zero-knowledge Proofs

Cansu Betin Onur

While the amount of data produced and accumulated continues to advance at unprecedented rates, protection and concealment of data increase its prominence as a field of scientific study that requires more action. It is essential to protect privacy-sensitive data at every phase; at rest, at run, and while computations are executed on data. The zero-knowledge proof (ZKP) schemes are a cryptographic tool toward this aim. ZKP allows a party to securely ensure the data's authenticity and precision without revealing confidential or privacy-sensitive information during communication or computation. The power of zero-knowledge protocols is based on intractable problems. There is a requirement to design more secure and efficient zero-knowledge proofs. This demand raises the necessity of determining appropriate intractable problems to develop novel ZKP schemes. In this paper, we present a brief outline of ZKP schemes, the connection of these structures to group-theoretic intractable problems, and annotate a list of intractable problems in group theory that can be employed to devise new ZKP schemes.

Open access
2 source records
Cryptography and Data Security
Geometric and Algebraic Topology
Advanced Authentication Protocols Security
Original source
Jun 1, 2022·Vehicular Communications
25 cites
Location privacy in VANETs: Provably secure anonymous key exchange protocol based on self-blindable signatures

Mishri Saleh Al-Marshoud, Ali H. Al‐Bayatti, Mehmet Sabır Kiraz

Security and privacy in vehicular ad hoc networks (VANETs) are challenging in terms of Intelligent Transportation Systems (ITS) features. The distribution and decentralisation of vehicles could threaten location privacy and confidentiality in the absence of trusted third parties (TTP)s or if they are otherwise compromised. If the same digital signatures (or the same certificates) are used for different communications, then adversaries could easily apply linking attacks. Unfortunately, most of the existing schemes for VANETs in the literature do not satisfy the required levels of security, location privacy, and efficiency simultaneously. This paper presents a new and efficient end-to-end anonymous key exchange protocol based on Yang et al. 's self-blindable signatures. In our protocol, vehicles first privately blind their own private certificates for each communication outside the mix-zone and then compute an anonymous shared key based on zero-knowledge proof of knowledge (PoK). The efficiency comes from the fact that once the signatures are verified, the ephemeral values in PoK are also used to compute a shared key through an authenticated Diffie-Hellman key exchange protocol. Therefore, the protocol does not require any further external information to generate a shared key. Our protocol also does not require an interference with the Roadside Units or Certificate Authorities, and hence can be securely run outside the mixed-zones. We demonstrate the security of our protocol in an ideal/real simulation paradigm. Hence, our protocol achieves secure authentication, forward unlinkability, and accountability. Furthermore, the performance analysis shows that our protocol is more efficient in terms of computational and communication overheads compared to existing schemes.

Open access
Vehicular Ad Hoc Networks (VANETs)
Advanced Authentication Protocols Security
Privacy-Preserving Technologies in Data
Original source
May 23, 2022·Future Internet
12 cites
Lightweight Blockchain-Based Scheme to Secure Wireless M2M Area Networks

Karam Eddine Bilami, Pascal Lorenz

Security is a challenging issue for M2M/IoT applications due to the deployment, decentralization and heterogeneity of M2M and IoT devices. Typical security solutions may not be suitable for M2M/IoT systems regarding the difficulties encountered for their implementation on resource-constrained devices. In this paper, we discuss the architectures deployed for M2M communications and the security challenges, as well as the vulnerabilities and solutions to counter possible attacks. We present a lightweight design based on a private blockchain to secure wireless M2M communications at the device domain level. Blockchain integration provides secure storage of data while preserving integrity traceability and availability. Besides, the evaluation and experimentations under NS3 simulator of the proposed scheme show that the authentication mechanism is lightweight, and presents better performances comparatively to other protocols in terms of key parameters as communication and computational overheads, average delay and energy consumption.

Open access
IoT and Edge/Fog Computing
Security in Wireless Sensor Networks
Advanced Authentication Protocols Security
Original source
Mar 21, 2022·2022 IEEE International Conference on Pervasive Computing and Communications Workshops and other Affiliated Events (PerCom Workshops)
1 cites
A New Zero-Trust Aided Smart Key Authentication Scheme in IoV

Yangxu Song, Frank Jiang, Syed Wajid Ali Shah, Robin Doss

With the development of 5G networking technology on the Internet of Vehicle (IoV), there are new opportunities for numerous cyber-attacks, such as in-vehicle attacks like hijacking occurrences and data theft. While numerous attempts have been made to protect against the potential attacks, there are still many unsolved problems such as developing a fine-grained access control system. This is reflected by the granularity of security as well as the related data that are hosted on these platforms. Among the most notable trends is the increased usage of smart devices, IoV, cloud services, emerging technologies aim at accessing, storing and processing data. Most popular authentication protocols rely on knowledge-factor for authentication that is infamously known to be vulnerable to subversions. Recently, the zero-trust framework has drawn huge attention; there is an urgent need to develop further the existing Continuous Authentication (CA) technique to achieve the zero-trustiness framework. In this paper, firstly, we develop the static authentication process and propose a secured protocol to generate the smart key for user to unlock the vehicle. Then, we proposed a novel and secure continuous authentication system for IoVs. We present the proof-of-concept of our CA scheme by building a prototype that leverages the commodity fingerprint sensors, NFC, and smartphone. Our evaluations in real-world settings demonstrate the appropriateness of CA scheme and security analysis of our proposed protocol for digital key suggests its enhanced security against the known attack-vector.

Open access
User Authentication and Security Systems
Advanced Authentication Protocols Security
Biometric Identification and Security
Original source
Mar 14, 2022·Blockchain in Healthcare Today
22 cites
Decentralized Identity Management for E-Health Applications: State-of-the-Art and Guidance for Future Work

Abylay Satybaldy, Anton Hasselgren, Mariusz Nowostawski

Background: The increasing use of various online services requires an efficient digital identity management (DIM) approach. Unfortunately, the original Internet protocols were not designed with built-in identity management, which creates challenges related to privacy, security, and usability. There is an increasing societal concern regarding the management of these sensitive data, access to it, and where it is stored. Blockchain technology can potentially offer a secure solution to address these issues in a decentralized manner without centralized authority. This is important for e-health services where the patient and the healthcare provider often are required to prove their identity. Blockchain technology can be utilized for creating digital identities and making its management easier, thus giving a higher degree of control to the user than what current solutions offer. It can be used to create a digital identity on the blockchain, making it easier for individuals and entities to manage, giving them greater control over who has their personal information and how they handle it. In addition, it might be utilized to create a higher degree of trust and security for e-health applications. Objective: The aim of this research work was to review the state-of-the-art regarding blockchain-based decentralized identity management for healthcare applications. Based on this summary, we provide a viewpoint on how blockchain-based decentralized identity frameworks might be utilized for virtualized healthcare applications. Methods: This research study applied a scoping, semi-systematic review approach to summarize the state-of-the-art. Included identity management systems were evaluated based on seven criteria: autonomy, authority, availability, approval, confidentiality, tenacity, and Interoperability. Results: Seven blockchain-based identity management systems were included and evaluated in this work: these include solutions built with Ethereum, Hyperledger Indy, Hyperledger Fabric, Hedera, and Sovrin blockchains. Conclusions: DIM is crucial for virtual health care. Decentralized identity management for healthcare purposes is currently being explored in both academia and the private sector. More work is needed with the aim of improving the efficiency of current DIM solutions and to fully understand what technical frameworks are best suited for e-health applications.

Open access
Blockchain Technology Applications and Security
Access Control and Trust
Advanced Authentication Protocols Security
Original source
Feb 17, 2022·arXiv (Cornell University)
8 cites
How Do Smart Contracts Benefit Security Protocols?

Rujia Li, Qin Wang, Qi Wang, David Galindo

Smart contracts have recently been adopted by many security protocols. However, existing studies lack satisfactory theoretical support on how contracts benefit security protocols. This paper aims to give a systematic analysis of smart contract (SC)-based security protocols to fulfill the gap of unclear arguments and statements. We firstly investigate \textit{state of the art studies} and establish a formalized model of smart contract protocols with well-defined syntax and assumptions. Then, we apply our formal framework to two concrete instructions to explore corresponding advantages and desirable properties. Through our analysis, we abstract three generic properties (\textit{non-repudiation, non-equivocation, and non-frameability}) and accordingly identify two patterns. (1) a smart contract can be as an autonomous subscriber to assist the trusted third party (TTP); (2) a smart contract can replace traditional TTP. To the best of our knowledge, this is the first study to provide in-depth discussions of SC-based security protocols from a strictly theoretical perspective.

Open access
2 source records
Blockchain Technology Applications and Security
Advanced Authentication Protocols Security
Cryptography and Data Security
Original source
Feb 11, 2022·Security and Communication Networks
18 cites
An Anonymous Blockchain-Based Authentication Scheme for Secure Healthcare Applications

Arun Sekar Rajasekaran, M. Azees

Nowadays, continuous monitoring of a patient’s healthcare data has become a critical factor in human well-being. However, with the rapid advancement of wireless technology, doctors and healthcare professionals can monitor the patient’s healthcare data in real time. But to access the confidential patient’s data which is transferred through the open wireless medium, the secure transmission plays an important role. In this work, the privacy and the anonymity of the end-users (patient/doctor) are preserved using an anonymous blockchain-based authentication scheme. Moreover, in this work initially, mutual authentication is performed between the end-users, followed by encryption and decryption of confidential data. In addition, to avoid reauthentication of the patient again during the movement of a patient from one doctor to another, a transfer authentication protocol is performed between the doctors which enhances performance analysis. The security analysis section illustrates the withstanding capability of the proposed work against various vulnerable attacks. Finally, performance investigation of the proposed work reveals a reduction in computational and communication costs when compared to existing related works.

Open access
User Authentication and Security Systems
Wireless Body Area Networks
Advanced Authentication Protocols Security
Original source
Jan 30, 2022·Algorithms
15 cites
Adaptive Authentication Protocol Based on Zero-Knowledge Proof

Nikita Konstantinovich Chistousov, Igor A. Kalmykov, Daniil Vyacheslavovich Dukhovnyj, М. И. Калмыков · 5 authors

Authentication protocols are expanding their application scope in wireless information systems, among which are low-orbit satellite communication systems (LOSCS) for the OneWeb space Internet, automatic object identification systems using RFID, the Internet of Things, intelligent transportation systems (ITS), Vehicular Ad Hoc Network (VANET). This is due to the fact that authentication protocols effectively resist a number of attacks on wireless data transmission channels in these systems. The main disadvantage of most authentication protocols is the use of symmetric and asymmetric encryption systems to ensure high cryptographic strength. As a result, there is a problem in delivering keys to the sides of the prover and the verifier. At the same time, compromising of keys will lead to a decrease in the level of protection of the transmitted data. Zero-knowledge authentication protocols (ZKAP) are able to eliminate this disadvantage. However, most of these protocols use multiple rounds to authenticate the prover. Therefore, ZKAP, which has minimal time costs, is developed in the article. A scheme for adapting protocol parameters has been developed in this protocol to increase its efficiency. Reductions in the level of confidentiality allow us to reduce the time spent on the execution of the authentication protocol. This increases the volume of information traffic. At the same time, an increase in the confidentiality of the protocol entails an increase in the time needed for authentication of the prover, which reduces the volume of information traffic. The FPGA Artix-7 xc7a12ticsg325-1L was used to estimate the time spent implementing the adaptive ZKAP protocol. Testing was performed for 32- and 64-bit adaptive authentication protocols.

Open access
Vehicular Ad Hoc Networks (VANETs)
Advanced Authentication Protocols Security
Cybersecurity and Information Systems
Original source
Jan 22, 2022·Security and Communication Networks
8 cites
Decentralized, Privacy-Preserving, Single Sign-On

Omid Mir, Michael Roland, René Mayrhofer

In current single sign-on authentication schemes on the web, users are required to interact with identity providers securely to set up authentication data during a registration phase and receive a token (credential) for future access to services and applications. This type of interaction can make authentication schemes challenging in terms of security and availability. From a security perspective, a main threat is theft of authentication reference data stored with identity providers. An adversary could easily abuse such data to mount an offline dictionary attack for obtaining the underlying password or biometric. From a privacy perspective, identity providers are able to track user activity and control sensitive user data. In terms of availability, users rely on trusted third-party servers that need to be available during authentication. We propose a novel decentralized privacy-preserving single sign-on scheme through the Decentralized Anonymous Multi-Factor Authentication (DAMFA), a new authentication scheme where identity providers no longer require sensitive user data and can no longer track individual user activity. Moreover, our protocol eliminates dependence on an always-on identity provider during user authentication, allowing service providers to authenticate users at any time without interacting with the identity provider. Our approach builds on threshold oblivious pseudorandom functions (TOPRF) to improve resistance against offline attacks and uses a distributed transaction ledger to improve availability. We prove the security of DAMFA in the universal composibility (UC) model by defining a UC definition (ideal functionality) for DAMFA and formally proving the security of our scheme via ideal-real simulation. Finally, we demonstrate the practicability of our proposed scheme through a prototype implementation.

Open access
User Authentication and Security Systems
Advanced Authentication Protocols Security
Cryptography and Data Security
Original source
Jan 1, 2022·IEEE Access
33 cites
DDMIA: Distributed Dynamic Mutual Identity Authentication for Referrals in Blockchain-Based Health Care Networks

M.V. Hegde, Rohini R. Rao, B. Nikhil

Patients go to multiple healthcare providers for treatment, and their health data is generally distributed among providers. The distributed health data and the decentralized health care system structure make it ideal for blockchain-based health information systems. The authors consider the referral use case; for instance, a patient goes to his primary health Centre (PHC) for treatment and is referred to a hospital. Authentication is usually done using certificates or key cryptography, which could become cumbersome when multiple parties are involved in a healthcare interaction. The security requirements were defined, and a novel multi-party, mutual patient identity authentication scheme called “Distributed Dynamic Mutual Identity Authentication (DDMIA)” was proposed for the referral use case in a blockchain-based e-health network. The DDMIA enables the PHC to authenticate the patient to the referred hospital. The DDMIA scheme was designed using Elliptic Curve Cryptography. It was proven to be secure by assuming the hardness of the elliptic curve discrete log problem (ECDLP) and Elliptic curve computational Diffie–Hellman problem (ECDH) using CK-Model. The formal security analysis using BAN logic proved that the sessions are secure after authentication. The DDMIA scheme was simulated in the AVISPA tool and proven safe against all active attacks. DDMIA scheme was simulated in the AVISPA tool and proven safe against all active attacks. The scheme allows a patient to be authenticated by multiple parties without registering with all parties. It eliminates the need for multiple registration centers as well as digital certificates. Hence, the DDMIA scheme can be implemented for similar multiparty authentication requirements in blockchain-based networks.

Open access
Advanced Authentication Protocols Security
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Original source
Jan 1, 2022·IEEE Access
30 cites
CKMIB: Construction of Key Agreement Protocol for Cloud Medical Infrastructure Using Blockchain

Samiulla Itoo, Akber Ali Khan, Vinod Kumar, Ahmed Alkhayyat · 6 authors

In the traditional medical healthcare system, each medical facility is responsible for preserving its own records. Sharing such records with another medical establishment is difficult for them. To tackle this challenge, the traditional medical system leverages internet technology to transform into a modern electronic system. In electronic healthcare systems, managing the security and privacy of patient data becomes a major issue. As an alternative, the healthcare sector might use blockchain technology to exchange digitised healthcare data. Blockchain technology is characterised by anonymity, decentralisation, and immutability. It is hard to keep all electronic healthcare data on blockchain due to the expense and volume. Cloud computing is the best solution for storing this type of data and resolving problems like these. To address these concerns, we offer a blockchain-based key agreement protocol for cloud medical network systems that enhances privacy and security. We demonstrate a formal and informal security analysis of the proposed protocol that shows that the proposed protocol is both secure and communicative. We provide security verification of the proposed protocol by using the AVISPA software tool against man in the middle attack and replay attack. Finally, we compute the computation and communication costs of the proposed protocol and other existing protocols, the proposed protocol has less computation and communication costs than other existing protocols in the electronic healthcare system.

Open access
Blockchain Technology Applications and Security
Advanced Authentication Protocols Security
User Authentication and Security Systems
Original source
Jan 1, 2022·IEEE Transactions on Intelligent Transportation Systems
67 cites
AAKE-BIVT: Anonymous Authenticated Key Exchange Scheme for Blockchain-Enabled Internet of Vehicles in Smart Transportation

Akhtar Badshah, Muhammad Waqas, Fazal Muhammad, Ghulam Abbas · 7 authors

The next-generation Internet of vehicles (IoVs) seamlessly connects humans, vehicles, roadside units (RSUs), and service platforms, to improve road safety, enhance transit efficiency, and deliver comfort while conserving the environment. Currently, numerous entities communicate in the IoVs environment via insecure public channels that are susceptible to a variety of security assaults and threats. To address these security challenges, we design an anonymous authenticated key exchange mechanism for the IoVs in smart transportation supported by blockchain, referred to as AAKE-BIVT. AAKE-BIVT securely transmits traffic information to a cluster head, before heading to a nearby RSU utilizing the established secret session keys via mutual authentication and key agreement. A cloud server (CS) then securely aggregates data from related RSUs and generates transactions. The CS combines the transactions into blocks in a peer-to-peer network of CSs, and the blocks are confirmed and added to the blockchain via a voting-based consensus method. By means of rigorous informal security studies and formal security analysis through the random oracle model, we reveal that the proposed AAKE-BIVT is resistant to a broad range of potential security assaults in the IoVs environment. Furthermore, a comparative study reveals that AAKE-BIVT outperforms existing state-of-the-art techniques, in terms of security and functionality while being more efficient in terms of communication and computation. Additionally, the blockchain simulation validates the implementation viability of our proposed AAKE-BIVT.

Open access
Blockchain Technology Applications and Security
Advanced Authentication Protocols Security
User Authentication and Security Systems
Original source
Jan 1, 2022·Computers, materials & continua/Computers, materials & continua (Print)
4 cites
Active Authentication Protocol for IoV Environment with Distributed Servers

Saravanan Manikandan, Mosiur Rahaman, Song Yu-lin

The Internet of Vehicles (IoV) has evolved as an advancement over the conventional Vehicular Ad-hoc Networks (VANETs) in pursuing a more optimal intelligent transportation system that can provide various intelligent solutions and enable a variety of applications for vehicular traffic. Massive volumes of data are produced and communicated wirelessly among the different relayed entities in these vehicular networks, which might entice adversaries and endanger the system with a wide range of security attacks. To ensure the security of such a sensitive network, we proposed a distributed authentication mechanism for IoV based on blockchain technology as a distributed ledger with an ouroboros algorithm. Using timestamp and challenge-response mechanisms, the proposed authentication model can withstand several security attacks such as Man-in-Middle (MiM) attacks, Distributed Denial of Service (DDoS) attacks, server spoofing attacks and more. The proposed method also provides a solution for single-point failure, forward secrecy, revocability, etc. We exhibit the security of our proposed model by using formal (mathematical) analysis and informal analysis. We used Random Oracle Model to perform the mathematical analysis. In addition, we compared the communication cost, computation cost, and security of the proposed model with the related existing studies. We have verified the security of the model by using AVISPA tool simulation. The security analysis and computation analysis show that the proposed protocol is viable.

Open access
Cryptography and Data Security
Advanced Authentication Protocols Security
Vehicular Ad Hoc Networks (VANETs)
Original source
Jan 1, 2022·McGill-DEV
0 cites
Further properties of Practical Relativistic Zero-Knowledge Proofs for NP

Harmanpreet Singh Grover

Les protocoles à connaissance nulle nous donnent une façon par laquelle un prouver(s) peut convaincre un vérificateur(s) qu’un énoncé est vrai sans lui dévoiler quoi que ce soit d’autre. Ces preuves à connaissance nulle nous apportent une solution élégante au problème de s’identifier sans pour autant révéler un quelconque secret. Dans ce travail, notre point de mire porte sur les protocoles multi-prouveurs relativistes à connaissance nulle pour paires distanciées de prouveurs-vérificateurs. Initialement, nous démontrons que le protocole expérimental multi-prouveurs relativiste à connaissance nulle décrit dans le papier récent de \cite{alikhani2020experimental} est sécuritaire face à des prouveurs classiques. Ensuite, nous prouvons que ce même protocole constitue une preuve de connaissance pour le même langage. Enfin, nous démontrons que ce même protocole satisfait une forme plus forte de « à connaissance nulle » en exhibant une paire de simulateurs non-signalant contrairement aux simulateurs habituels qui sont signalants. La sécurité du protocole est obtenue grâce au principe physique de la relativité restreinte

Open access
Cryptography and Data Security
Logic, Reasoning, and Knowledge
Advanced Authentication Protocols Security
Original source