Ali Shahidinejad, Jemal Abawajy, Shamsul Huda
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
449 results Ā· page 5 of 19
Ali Shahidinejad, Jemal Abawajy, Shamsul Huda
No abstract is available for this record.
S. Harihara Gopalan, A. Manikandan, N. P. Dharani, G. Sujatha
Abstract The proposed Blockchain-Based Mitigation of Deauthentication Attacks (BBMDA) Framework aims to enhance the security and trustworthiness of IoT environments by leveraging blockchain technology, the Elliptic Curve Digital Signature Algorithm (ECDSA) for secure authentication, and Multi-Task Transformer (MTT) for efficient traffic classification. This paper presents a novel approach to mitigate de-authentication attacks in IoT ecosystems. The research methodology involves developing and implementing the BBMDA framework, followed by a comprehensive evaluation and comparison with existing techniques. Key findings indicate that the BBMDA framework outperforms traditional methods such as Support Vector Machine (SVM), k-nearest Neighbors (KNN), and Convolutional Neural Network (CNN) in terms of accuracy, false positive rate, false negative rate, precision, recall, and F1-score. These results underscore the effectiveness and efficiency of the proposed framework in enhancing IoT security.
Wenyue Wang, Biwei Yan, Baobao Chai, Ruiyao Shen Ā· 6 authors
In the Internet of Things (IoT), a large number of devices are connected using a variety of communication technologies to ensure that they can communicate both physically and over the network. However, devices face the challenge of a single point of failure, a malicious user may forge device identity to gain access and jeopardize system security. In addition, devices collect and transmit sensitive data, and the data can be accessed or stolen by unauthorized user, leading to privacy breaches, which posed a significant risk to both the confidentiality of user information and the protection of device integrity. Therefore, in order to solve the above problems and realize the secure transmission of data, this paper proposed EBIAS, a secure and efficient blockchain-based identity authentication scheme designed for IoT devices. First, EBIAS combined the Elliptic Curve Cryptography (ECC) algorithm and the SHA-256 algorithm to achieve encrypted communication of the sensitive data. Second, EBIAS integrated blockchain to tackle the single point of failure and ensure the integrity of the sensitive data. Finally, we performed security analysis and conducted sufficient experiment. The analysis and experimental results demonstrate that EBIAS has certain improvements on security and performance compared with the previous schemes, which further proves the feasibility and effectiveness of EBIAS.
Jie Li, Yuanyuan Lin, Yibing Li, Yan Zhuang Ā· 5 authors
The Internet of Vehicles (IoV) connects an isolated individual on the road to share information, which can improve traffic efficiency. However, the promotion of information sharing brings the critical security issues of identity authentication, followed by privacy protection issues in the authentication process in the IoV. In this study, we designed a blockchain-based conditional privacy-preserving authentication scheme for the IoV (BPA). Our scheme implements zero-knowledge proof (ZKP) to verify the identities of vehicles, which moves the authentication process down to the Roadside Units (RSUs) and achieves decentralized authentication at the edge nodes. Moreover, blockchain technology is utilized to synchronize a consistent ledger across all RSUs for recording and disseminating vehicle authentication states, which enhances the overall authentication process efficiency. We provide a theoretical analysis asserting that the BPA ensures enhanced security and effectively protects the privacy of all participating vehicles. Experimental evaluations confirm that our scheme outperforms existing solutions in terms of the computational and communication overhead.
Yuxuan Zhou, Jiaqi Chen, Yibo Wang, Yuzhe Tang Ā· 5 authors
In public blockchains, leaking secret keys can cause the permanent loss of crypto assets. It is imperative to understand the illicit activities on blockchains related to leaked keys. This paper presents the first measurement study that uncovers, quantifies, and characterizes the actual misuses of the leaked keys from top websites on the Internet to withdraw assets on Ethereum. By finding key-leaking web pages and joining them with transactions, the study reveals 7.29*10^6/0.59*10^6 USD worth of assets on Ethereum mainnet/Binance Smart Chain (BSC) are withdrawn from 1421/1514 leaked secret keys. Mitigations are proposed to avoid the financial loss caused by leaked keys.
Sonali Patwe, Sunil B. Mane
The metaverse, which amalgamates physical and virtual realms for diverse social activities, has been the focus of extensive application development by organizations, research institutes, and companies. However, these applications are often isolated, employing distinct authentication methods across platforms. Achieving interoperable authentication is crucial for when avatars traverse different metaverses to mitigate security concerns like impersonation, mutual authentication, replay, and server spoofing. To address these issues, we propose a blockchain-enabled secure and interoperable authentication scheme. This mechanism uniquely identifies users in the physical world as well as avatars, facilitating seamless navigation across verses. Our proposal is substantiated through informal security analyses, employing automated verification of internet security protocols and applications (AVISPA), the real-or-random (ROR) model, and BurrowsāAbadiāNeedham (BAN) logic and showcasing effectiveness against a broad spectrum of security threats. Comparative assessments against similar schemes demonstrate our solutionās superiority in terms of communication costs, computation costs, and security features. Consequently, our blockchain-enabled, interoperable, and secure authentication scheme stands as a robust solution for ensuring security in metaverse environments.
Tanusree Sharma, Vivek Nair, Henry Wang, Yang Wang Ā· 5 authors
Key management has long remained a difficult unsolved problem in the field of usable security. While password-based key derivation functions (PBKDFs) are widely used to solve this problem in centralized applications, their low entropy and lack of a recovery mechanism make them unsuitable for use in decentralized contexts. The multi-factor key derivation function (MFKDF) is a recently proposed cryptographic primitive that aims to address these deficiencies by incorporating commonly used authentication factors into the key derivation process. In this paper, we implement an MFKDF-based Ethereum wallet and perform a user study with 27 participants to directly compare its usability against traditional cryptocurrency wallet architectures. Our results show that MFKDF-based applications outperform conventional key management approaches on both subjective and objective metrics, with a 37% higher average SUS score (p < 0.0001) and 71% faster task completion times (p < 0.0001) for the MFKDF-based wallet.
Jo Vliegen, Md Masoom Rabbani, Wouter Hellemans, Nele Mentens
Over the past decade, an exponential rise in the deployment of Internet-of-Things (IoT) devices engulfed our surroundings. IoT devices have spread into domains like personal smart devices, industrial applications, military applications, and medical applications, to name a few. Brittle security features and large deployment in safety-critical systems make IoT devices an attractive target for cyberattacks. Large collections of data, ranging from personal, and oversensitive to financial data, make it crucial to safeguard IoT applications and data communication from cybercriminals. One key technique to deal with these cyberattacks is Remote Attestation (RA), in which a verifier remotely checks the sanity of an IoT device's firmware. However, implementing RA over large IoT networks can be challenging due to the dynamic nature of the network and the real-time aggregation of attestation results. We propose 'HAGAR: Hashgraph-based Aggregated Communication and Remote Attestation' to address the aforesaid challenges. HAGAR is a distributed ledger based on a hashgraph architecture that not only provides decentralized security guarantees like traditional blockchain technology, but also makes communication fast and thus offers continuous attestation aggregation in large IoT networks. We use the features of Hashgraphs for data aggregation in remote attestation mechanisms for large dynamic IoT networks.
W. Chen
This study investigates the human errors that enable hackers to exploit and carry out social engineering attacks on the non-fungible token (NFT) ecosystem. The aim is to improve the design of decentralized applications that use NFTs to help non-technical users follow security best practices and address remaining user-side vulnerabilities. The study methods included a survey examining participantsā expertise regarding NFTs and cybersecurity, a remote security usability study investigating the pain points and common security best practices and a follow-up interview to examine participantsā experience with a crypto wallet configuration. The results show how human cognitive bias affects usersā decision to be cautious, usersā difficulty with security methods, and improvements to lessen usersā cognitive load. As NFTs expand beyond the cryptocurrency circle, multiple scams and thefts arise due to late adopters not knowing the security best practices. Therefore, increasing the publicās NFT security awareness is key to mitigating potential threats.
S. V. Padmavathi Devi, Mr Alangaram S, Mrs Sangeetha D, S. Jeeva Ā· 5 authors
The healthcare sector has witnessed a rapid digitization of patient records, leading to an exponential increase in the volume and sensitivity of healthcare data.However, ensuring the security and privacy of this data has emerged as a critical challenge due to the evolving landscape of cyber threats.To address this challenge, a novel approach that combines the scalability of cloud computing with the immutability and transparency of blockchain technology to achieve robust security for healthcare data.The proposed hybrid storage framework leverages the advantages of both cloud computing and blockchain to establish a secure and efficient data management system.In this framework, sensitive healthcare data is encrypted and stored on distributed cloud servers to ensure high availability and reliability.Additionally, a blockchain-based distributed ledger is employed to record access logs and maintain a tamper-proof audit trail of data transactions.The integration of blockchain technology enables transparent and accountable data sharing among authorized parties while preserving patient privacy and confidentiality.The results indicate that the hybrid storage model offers superior resilience against various security threats, including unauthorized access, data breaches, and tampering, thus ensuring the confidentiality, integrity, and availability of healthcare data.
Md Jobair Hossain Faruk, Fazlul Alam, Mazharul Islam, Akond Rahman
Abstract As a cornerstone of democratic governance, elections hold unparalleled significance, shaping a nationās trajectory. However, the prevailing ballot-paper based voting systems continue to face trust issues among significant populations. As a result, e-Voting has emerged as an appealing alternative, with numerous countries opting for its implementation globally. While e-Voting systems offer several advantages, they also come with their own set of challenges. Even a minor vulnerability can lead to massive manipulations in voting results. In recent years, there have been efforts to revolutionize the e-Voting paradigm by harnessing the potential of emerging technologies such as biometrics and blockchain. This paper proposes a Internet-based voting that adopts blockchain technology and biometric identification techniques. We use biometric modalities, such as fingerprint and facial recognition, for voter authentication while leveraging Hyperledger Fabric framework as blockchain network and ensuring a secure, transparent, and tamper-evident voting record. We demonstrate the proposed system with 100 participants in a preset environment where we collect the biometrics data. The results indicate that 87% of participants successfully registered with biometrics, while 88% cast their votes with a combination of either voter ID and fingerprint or voter ID with facial recognition. Our findings suggest that the proposed system allows voters to access the system seamlessly and automate identity verification procedures while ensuring a secure, decentralized, and distributed database network that maintains transparency. Future research shall be carried out in collaboration with election officials and voters to improve the system in real-world scenarios.
Ali Shahidinejad, Jemal Abawajy, Shamsul Huda
No abstract is available for this record.
Daiki Ito, Yuta Takata, Keika Mori, Ryoya Furukawa Ā· 6 authors
Web services that use a blockchain and crypto-assets (Web3 services) improve user privacy by anonymous logins using wallet addresses. However, since many users list their account identities (IDs) on social networking service (SNS) profile pages and reuse their account IDs for self-branding and curation purposes, which increases the risk of de-anonymization on Web3 services by linking these accounts. If such high-risk SNS accounts hold large amounts of crypto-assets, they are subject to account hijacking and spoofing attacks for financial gain. In this study, we proposed a method to discover highly relevant SNS accounts from a seed account on Web2 and Web3 SNSs and estimate their account ownership. We applied our method to 480 seed accounts of 9 different SNSs and discovered 1,233 new accounts. We found that SNSs with multiple URL input forms on their profile setting pages linked more accounts and revealed that 207 out of 253 (81.8%) users reused their IDs across different SNSs. We identified 26 accounts linked to personal and crypto-asset information that are at risk of de-anonymization. Our user study using crowdsourcing services showed that as many as 232 (40.8%) out of 568 respondents do not understand the traceability of blockchain transaction histories. We examined the security and privacy risks caused by account listing and ID reuse, and made recommendations for service providers and users based on our findings.
Ahmed R. AlMhanawi, Bashar M. Nema
This review presents a comprehensive analysis of contemporary scholarship pertaining to instant messaging (IM) user behavior and security protocols. Through meticulous selection, the authors highlight critical studies that illuminate optimized message consumption strategies and delve into the evolving landscape of IM security models. Focusing on the past four years, the review meticulously dissects cutting-edge advancements in this domain. A significant insight emerges: achieving optimal communication security necessitates the synergistic convergence of three fundamental techniques: end-to-end encryption for data confidentiality, decentralized authentication for independent user verification, and zero-knowledge proof for identity obscurity. The review postulates that the simultaneous integration of these elements within the application architecture is paramount for robust privacy and heightened security in the realm of IM.
Hojung Yang, Suhyeon Lee, Seungjoo Kim
IOTA is a distributed ledger technology that uses a Directed Acyclic Graph (DAG) structure called the Tangle. It is known for its efficiency and is widely used in the Internet of Things (IoT) environment. Tangle can be configured by utilizing the tip selection process. Due to performance issues with light nodes, full nodes are being asked to perform the tip selections of light nodes. However, in this paper, we demonstrate that tip selection can be exploited to compromise users' privacy. An adversary full node can associate a transaction with the identity of a light node by comparing the light node's request with its ledger. We show that these types of attacks are not only viable in the current IOTA environment but also in IOTA 2.0 and the privacy improvement being studied. We also provide solutions to mitigate these attacks and propose ways to enhance anonymity in the IOTA network while maintaining efficiency and scalability.
Dechao Kong, Xiaoqi Li, Wenkai Li
Non-Fungible Tokens (NFTs) are digital assets recorded on the blockchain, providing cryptographic proof of ownership over digital or physical items. Although Solana has only begun to gain popularity in recent years, its NFT market has seen substantial transaction volumes. In this paper, we conduct the first systematic research on the characteristics of Solana NFTs from two perspectives: longitudinal measurement and wash trading security audit. We gathered 132,736 Solana NFT from Solscan and analyzed the sales data within these collections. Investigating users' economic activity and NFT owner information reveals that the top users in Solana NFT are skewed toward a higher distribution of purchases. Subsequently, we employ the Local Outlier Factor algorithm to conduct a wash trading audit on 2,175 popular Solana NFTs. We discovered that 138 NFT pools are involved in wash trading, with 8 of these NFTs having a wash trading rate exceeding 50%. Fortunately, none of these NFTs have been entirely washed out.
Salman Ali Syed, Selvakumar Manickam, Mueen Uddin, Hamed Alsufyani Ā· 7 authors
Internet of Things (IoT) paves the way for the modern smart industrial applications and cities. Trusted Authority acts as a sole control in monitoring and maintaining the communications between the IoT devices and the infrastructure. The communication between the IoT devices happens from one trusted entity of an area to the other by way of generating security certificates. Establishing trust by way of generating security certificates for the IoT devices in a smart city application can be of high cost and expensive. In order to facilitate this, a secure group authentication scheme that creates trust amongst a group of IoT devices owned by several entities has been proposed. The majority of proposed authentication techniques are made for individual device authentication and are also utilized for group authentication; nevertheless, a unique solution for group authentication is the Dickson polynomial based secure group authentication scheme. The secret keys used in our proposed authentication technique are generated using the Dickson polynomial, which enables the group to authenticate without generating an excessive amount of network traffic overhead. IoT devices' group authentication has made use of the Dickson polynomial. Blockchain technology is employed to enable secure, efficient, and fast data transfer among the unique IoT devices of each group deployed at different places. Also, the proposed secure group authentication scheme developed based on Dickson polynomials is resistant to replay, man-in-the-middle, tampering, side channel and signature forgeries, impersonation, and ephemeral key secret leakage attacks. In order to accomplish this, we have implemented a hardware-based physically unclonable function. Implementation has been carried using python language and deployed and tested on Blockchain using Ethereum Goerli's Testnet framework. Performance analysis has been carried out by choosing various benchmarks and found that the proposed framework outperforms its counterparts through various metrics. Different parameters are also utilized to assess the performance of the proposed blockchain framework and shows that it has better performance in terms of computation, communication, storage and latency.
Cindy Handoko Tantowibowo, WeiāChuen Yau
Abstract Counterfeit artwork presents a significant risk to copyright holders and the economy. Without expertise in art, it is not straightforward to distinguish an artwork counterfeit from a genuine piece. This work designs and implements a reliable solution that enables users with nearāfield communicationāenabled Android smartphones to verify artwork authenticity by accessing its respective certificate of authenticity stored in the Ethereum blockchain. To represent a physical artwork, the artwork image and metadata are stored in an interāplanetary file system and minted as an ERC721 nonāfungible token to a smart contract deployed in Ethereum Rinkeby Testnet. The mobile app ArtProtect was developed to generate certificate of authenticity based on each nonāfungible token fetched through OpenSea Testnet API. Users access this information by scanning an nearāfield communication tag embedded into the artwork. The content of the tag is signed by the respective artwork's artist and responsible agent by using Ethereum signing with their Ethereum wallet accounts. Through testing and analysis, the implemented work is secure, tamperāevident, usable, flexible, and inexpensive to be applied to a realāworld scenario.
Sharon Justine Payattukalanirappel, Panchami V Vamattathil, Mohammed Ziyad C Cheeramthodika
No abstract is available for this record.
Ali Shahidinejad, Jemal Abawajy
Authentication and Session Key Generation Protocols (SKGPs) play an essential role in securing the communication channels of connected Internet of Things (IoT) devices. Recently, through blockchain integration, scholars have tried to enhance the security and applicability of SKGPs. In brief, blockchain is a distributed ledger technology that can provide interesting features such as immutability, transparency, and accountability without any need for the active participation of trusted parties. This survey presents a comprehensive critical review of blockchain-assisted authentication and SKGPs, suggested for different IoT domains, including Internet of Vehicles, Internet of Drones, and Industrial IoT. Our survey categorizes existing schemes based on several criteria, including IoT application domains, security aspects, and blockchain components. By presenting an unbiased critical review and taxonomy of protocols, we aim to clarify the key challenges. Our review will specifically indicate what properties authors gained or lost through the integration of blockchain. To our best knowledge, this survey is the only one that offers all prerequisites for interested readers in blockchain-integrated SKGPs, such as security features and attacks, attack models, verification tools, blockchain types, blockchain platforms, and consensus mechanisms. Further, our survey elaborates existing research gaps in blockchain-assisted SKGPs. In doing so, we aim to guide future research in this field and provide researchers with the essential information they require.
Jay BojiÄ Burgos, Matevž PustiÅ”ek
The rapid expansion of the Internet of Things (IoT) has introduced significant challenges in data authentication, necessitating a balance between scalability and security. Traditional approaches often rely on third parties, while blockchain-based solutions face computational and storage bottlenecks. Our novel framework employs edge aggregating servers and Ethereum Layer 2 rollups, offering a scalable and secure IoT data authentication solution that reduces the need for continuous, direct interaction between IoT devices and the blockchain. We utilize and compare the Nova and Risc0 proving systems for authenticating batches of IoT data by verifying signatures, ensuring data integrity and privacy. Notably, the Nova prover significantly outperforms Risc0 in proving and verification times; for instance, with 10 signatures, Nova takes 3.62 s compared to Risc0's 369 s, with this performance gap widening as the number of signatures in a batch increases. Our framework further enhances data verifiability and trust by recording essential information on L2 rollups, creating an immutable and transparent record of authentication. The use of Layer 2 rollups atop a permissionless blockchain like Ethereum effectively reduces on-chain storage costs by approximately 48 to 57 times compared to direct Ethereum use, addressing cost bottlenecks efficiently.
Surbhi Sharma, Rudresh Dwivedi
Abstract Blockchain technology has become an emerging area in recent years due to its capacity to improve the security, dependability, and resilience of distributed systems. Research based on this technique has impacted several firms, including banking, healthcare, data processing, remote sensing, and many others. The key characteristics of blockchain technology that make it appealing are data immutability, transparency, privacy, decentralization, and distributed ledgers. However, there is a chance of a privacy breach with sensitive biometric data. The purpose of this investigation is to examine blockchainābased biometric applications research. It begins by determining the myriad ways that biometrics and blockchain may work together, including the storage and protection of biometric templates, identity management, and biometric authentication systems. Different biometric applications with respect to blockchain technology are also identified, along with the types of biometric data taken into account, features and capabilities of blockchain technology exploited, and blockchain technology frameworks employed. Finally, the authors seek to investigate blockchain concepts in the biometric domain by evaluating their pros and cons and summarizing the methods developed on blockchain for diverse biometric applications. Additionally, the applications of blockchainābased biometric systems are highlighted before moving on to open research questions and potential future research areas.
Jiawei Li
Blockchain, as one of the emerging technologies in recent years, is essentially a decentralized distributed ledger. By leveraging blockchain, it provides a new approach to identity authentication. This paper provides an overview of the applications of identity authentication based on blockchain. Firstly, the background knowledge of blockchain is introduced. Then, the technical aspects of identity authentication based on blockchain are discussed and classified from the perspectives of identity authentication techniques and cryptographic algorithms. Subsequently, the applications of identity authentication based on blockchain technology are introduced and classified in various fields. Finally, a summary of the entire paper is presented.
Bjorn Oude Roelink, Mohammed ElāHajj, Dipti Kapoor Sarmah
Abstract This systematic literature review examines the implementation and analysis of zkāSNARK, zkāSTARK, and bulletproof nonāinteractive zeroāknowledge proof (NIZKP) protocols in privacyāpreserving applications across diverse sectors. Examining 41 research works obtained through the systematic search queries and filtering criteria published from 2015 to April 2023, we categorized findings into financial, medical, business, general, and other domains. Our analysis highlights significant variations of up to several orders of magnitude in realāworld performance across implementations utilizing NIZKP protocols. However, divergent methodologies in security analyses hindered conclusive comparisons. Addressing research gaps, our future endeavors aim to establish a realāworld benchmark for these protocols.