Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

449 papersLast indexed Aug 31, 2026
Search papers

Paper index

449 results · page 6 of 19

Clear filters
Jan 22, 2024·arXiv (Cornell University)
33 cites
zkLogin: Privacy-Preserving Blockchain Authentication with Existing Credentials

Foteini Baldimtsi, Konstantinos Kryptos Chalkias, Yan Ji, Jonas Lindstrøm · 9 authors

For many users, a private key based wallet serves as the primary entry point to blockchains. Commonly recommended wallet authentication methods, such as mnemonics or hardware wallets, can be cumbersome. This difficulty in user onboarding has significantly hindered the adoption of blockchain-based applications. We develop zkLogin, a novel technique that leverages identity tokens issued by popular platforms (any OpenID Connect enabled platform e.g., Google, Facebook, etc.) to authenticate transactions. At the heart of zkLogin lies a signature scheme allowing the signer to sign using their existing OpenID accounts and nothing else. This improves the user experience significantly as users do not need to remember a new secret and can reuse their existing accounts. zkLogin provides strong security and privacy guarantees. Unlike prior works, zkLogin's security relies solely on the underlying platform's authentication mechanism without the need for any additional trusted parties (e.g., trusted hardware or oracles). As the name suggests, zkLogin leverages zero-knowledge proofs (ZKP) to ensure that the sensitive link between a user's off-chain and on-chain identities is hidden, even from the platform itself. zkLogin enables a number of important applications outside blockchains. It allows billions of users to produce \textit{verifiable digital content leveraging their existing digital identities}, e.g., email address. For example, a journalist can use zkLogin to sign a news article with their email address, allowing verification of the article's authorship by any party. We have implemented and deployed zkLogin on the Sui blockchain as an additional alternative to traditional digital signature-based addresses.

Open access
3 source records
cs.CR
Cryptography and Data Security
Blockchain Technology Applications and Security
Original source
Jan 17, 2024·Multimedia Tools and Applications
24 cites
Enabling secure health information sharing among healthcare organizations by public blockchain

Gianluca Lax, Roberto Nardone, Antonia Russo

Abstract The facilitation of sharing and exchanging patients’ health records is a paramount opportunity in e-health, enabling healthcare providers to garner a comprehensive and clear perspective of patients’ medical histories without necessitating direct inquiries. Besides this great advantage, it introduces substantial issues on security and privacy, mainly related to unauthorized access to e-health records when different healthcare service providers maintain records. In this paper, we deal with this problem and propose using the blockchain technology (1) to obfuscate the linkage between patients’ identities and their e-health records and (2) to grant access to e-health records exclusively to entities authorized by patients themselves. Key outcomes include using a digital identity based on the Electronic Identification, Authentication, and Trust Services Regulation (eIDAS) to control access to these records, and a concrete implementation by adopting the Ethereum blockchain. Our solution relies on using a public blockchain, which is an improvement for the state of the art, in which only private or consortium blockchains have been proposed. The resulting solution has been analyzed, and the effectiveness and affordability of the proposal have been shown.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
Privacy, Security, and Data Protection
Original source
Jan 12, 2024·IEEE Transactions on Consumer Electronics, 2024
17 cites
Secure Targeted Message Dissemination in IoT Using Blockchain Enabled Edge Computing

Muhammad Baqer Mollah, Md Abul Kalam Azad, Yinghui Zhang

Smart devices are considered as an integral part of Internet of Things (IoT), have an aim to make a dynamic network to exchange information, collect data, analysis, and make optimal decisions in an autonomous way to achieve more efficient, automatic, and economical services. Message dissemination among these smart devices allows adding new features, sending updated instructions, alerts or safety messages, informing the pricing information or billing amount, incentives, and installing security patches. On one hand, such message disseminations are directly beneficial to the all parties involved in the IoT system. On the other hand, due to remote procedure, smart devices, vendors, and other involved authorities might have to meet a number of security, privacy, and performance related concerns while disseminating messages among targeted devices. To this end, in this paper, we design STarEdgeChain, a security and privacy aware targeted message dissemination in IoT to show how blockchain along with advanced cryptographic techniques are devoted to address such concerns. In fact, the STarEdgeChain employs a permissioned blockchain assisted edge computing in order to expedite a single signcrypted message dissemination among targeted groups of devices, at the same time avoiding the dependency of utilizing multiple unicasting approaches. Finally, we develop a software prototype of STarEdgeChain and show it's practicability for smart devices. The codes are publicly available at https://github.com/mbaqer/Blockchain-IoT

Open access
2 source records
cs.CR
cs.NI
Blockchain Technology Applications and Security
Original source
Jan 11, 2024·Heritage Science
6 cites
Salsal: blockchain for vetting cultural object collections

Adel Khelifi, Mark Altaweel, Mohammad Hashir, Tasoula Hadjitofi · 5 authors

Abstract Many modern cultural object collections suffer from the problem of being obtained in unethical and illegal circumstances. Additionally, information about collections, including their status, object descriptions, and other data need up-to-date information presented to users. We propose a novel blockchain tool called Salsal that enables the vetting of objects, individually or as part of more extensive collections, to meet required ethical and legal guidelines while informing users about relevant information regarding collections. Blockchain provides a better and more rapid way for users to know about collections using a decentralized and immutable ledger technology. Blockchain can be used to incentivize or even pressure collections to vet their objects for ethical and legal guidelines that can benefit the public who use object collections. The prototype software we have made is presented and compared to other blockchains, with code and demonstration provided. We present how our blockchain can enable benefit, providing a useful vetting process for cultural objects, and allowing a user community to contribute to collections in a transparent and secure manner.

Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
User Authentication and Security Systems
Original source
Jan 1, 2024·IEEE Access
14 cites
Space Authentication in the Metaverse: A Blockchain-Based User-Centric Approach

Jungwon Seo, Hankyeong Ko, Sooyong Park

As the metaverse gains traction, the importance of metaverse security research becomes increasingly evident. While there has been research on authenticating users in the metaverse, there is a notable gap in research concerning the authentication of specific spaces within the metaverse. This paper addresses this gap by proposing a novel user-centric blockchain-based authentication approach that incorporates space authentication. The proposed approach leverages blockchain smart contracts to authenticate users using cosine similarity metrics. A significant advantage of this approach its ability to establish user-centric authentication by seamlessly integrating metaverse and blockchain technologies, all without the need for a centralized authority. In this paper, we not only evaluate the security of our proposed approach but also conduct experiments to determine the cosine similarity threshold and assess its feasibility within a metaverse environment.

Open access
User Authentication and Security Systems
Face recognition and analysis
Privacy, Security, and Data Protection
Original source
Jan 1, 2024·IEEE Open Journal of the Computer Society
24 cites
Generic Quantum Blockchain-Envisioned Security Framework for IoT Environment: Architecture, Security Benefits and Future Research

Mohammad Wazid, Ashok Kumar Das, Youngho Park

Quantum cryptography has the potential to secure the infrastructures that are vulnerable to various attacks, like classical attacks, including quantum-related attacks. Therefore, quantum cryptography seems to be a promising technology for the future secure online infrastructures and applications, like blockchain-based frameworks. In this paper, we propose a generic quantum blockchain-envisioned security framework for an Internet of Things (IoT) environment. We then discuss some potential applications of the proposed framework. We also highlight the security advantages of quantum cryptography-based systems. We explain the working of blockchain, applications of blockchain, types of blockchain, the structure of blockchain, the structure of blockchain in a classical blockchain, and the structure of a block in a quantum blockchain context. Next, the adverse effects of quantum computing on the security of blockchain-based frameworks are highlighted. Furthermore, the comparisons of quantum cryptography-based security schemes, like quantum key distribution, quantum digital signature, and quantum hashing schemes, are provided. Finally, some future research directions related to the designed generic quantum blockchain-envisioned security framework for IoT are provided.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
User Authentication and Security Systems
Original source
Jan 1, 2024·IEEE Access
22 cites
Enhanced Lightweight Medical Sensor Networks Authentication Scheme Based on Blockchain

Tae-Woong Kang, N.S. Woo, Jihyeon Ryu

In the rapidly evolving environment of wireless medical sensor networks (WMSN) and the internet of medical things (IoMT), remote medical support has seen unprecedented advancements. It is essential that the data relayed from the sensors must be trustworthy and unaltered, and that the sensors themselves are genuine. Wireless networks, however, have inherent vulnerabilities. In addition, since WMSN is directly linked to patients’ lives, its continuous availability is crucial. Considerable efforts have been made to maintain the integrity and authenticity of such data. However, many studies have failed to address the problem of a single point of failure (SPOF). This issue has been particularly detrimental to patients who require ongoing management. To address this issue and ensure the protection of the authenticity and integrity of patient data, we suggest the implementation of an authentication scheme based on blockchain technology. In 2022, Yu et al. introduced a blockchain-integrated authentication and key generation scheme for WMSN using Physical Unclonable Functions (PUFs), effectively addressing the SPOF problem by conducting mutual authentication through smart contracts without relying on centralized servers. Our research found that this scheme inadvertently shared critical parameters, including challenge-response pairs and important private keys, with the blockchain network, making it vulnerable to various breaches. We present an enhanced protocol designed to mitigate these security challenges. By limiting the data interaction with smart contracts and ensuring only relevant parties access crucial parameters, our approach reduces the risk of public information disclosure on the blockchain. This not only mitigates the SPOF issue but also efficiently helps in prevention of physical attacks. We prove that our proposed system prevents known security vulnerabilities through informal and formal analysis using the Scyther, Proverif, and BAN logic. Furthermore, the proposed scheme offers 67.37% reduction in computation costs and 3.67% in communication costs, presenting an efficient and secure solution for WMSN in the IoMT landscape.

Open access
User Authentication and Security Systems
Advanced Authentication Protocols Security
Biometric Identification and Security
Original source
Jan 1, 2024·AIP conference proceedings
2 cites
Application of blockchain technology in securing mobile applications

Nima Modrek Alsaiary, Shakeel Ahmed

The present era is witnessing rapid development in the smartphone revolution, where mobile users can access many required services through mobile applications. These services include healthcare, finance, learning, insurance, and the Internet of Things. Android has become the most popular smartphone operating system, and this rapidly increasing adoption of Android has led to a significant increase in the number of malware compared to previous years, resulting in issues related to the insecurity of mobile applications and the violation of their users' privacy. A large role in this mobile phone revolution has been played by the emergence of blockchain technology (BCT), which represents an effective way to develop applications, improve their security, and protect the privacy of their users. The aim of this paper is to design a system architecture for the software and provide a prototype that uses BCT at its core for the purpose of storing and sharing malicious data while also integrating a malicious detection technique. We employed the design science research approach to guide our project. Through this approach, we successfully integrated a malware detection technique with BCT in an Android application, resulting in a decentralized feature that enables peers to add and share malware data. Furthermore, we have developed an easy-to-use interface that allows users to interact with the blockchain in the Android application. This interface displays the results of the malware signature detection algorithm and enables users to take appropriate action if malware is detected. We have employed a design science methodology to develop a software framework, and open-source code meeting the tool's requirements has been provided. Finally, the proposed methodology has been evaluated against the existing methodologies and compared with the other techniques to demonstrate the effectiveness of the blockchain-based detection tools.

Open access
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
User Authentication and Security Systems
Original source
Jan 1, 2024·International Journal of Global Innovations and Solutions (IJGIS)
1 cites
Empowering Users: Towards User-Centric Consent Mechanisms in Single Sign-On Systems

Saurav Bhattacharya, Madhavi Najana, Harsh Gupta, Anoop Gupta

This article explores the importance of putting users at the center of consent processes, in Single Sign On (SSO) systems to tackle privacy issues and empower user independence. It dives into the world of SSO systems shedding light on their privacy weaknesses and the need for users to have control over how their data is shared. By looking at privacy focused SSO solutions and their drawbacks the article suggests a plan to give users control over their data sharing preferences during authentication. The main elements of this plan include a user consent management interface, consent choices, educational materials, preference persistence and tracking logs. Additionally it talks about the obstacles in implementing consent driven SSO systems like creating consent APIs and incorporating privacy boosting technologies such as zero knowledge proofs and decentralized identity frameworks. By tackling these hurdles and promoting designs that prioritize users the article aims to help create authentication solutions that prioritize privacy in line, with changing regulations and user desires.

Open access
2 source records
Privacy, Security, and Data Protection
User Authentication and Security Systems
Personal Information Management and User Behavior
Original source
Jan 1, 2024·IEEE Access
4 cites
LA-IMDCN: A Lightweight Authentication Scheme With Smart Contract in Implantable Medical Device Communication Networks

Jayaprakash Kar, Xiaoguang Liu, Fagen Li

Implantable medical devices (IMDs) in medical sciences have provided a quantum leap in network transformation. The communication network with IMDs typically has a wireless radio frequency (RF) telemetry or wired connection. IMDs, being devices, have more computing, communication capabilities and decision-making. Furthermore, these devices are being used to improve patients’ quality of life by medicating various chronic diseases. The captured data is stored in a medical server through a controller node. Our work focuses on wireless communication, so sensitive patient data over a public channel might be tampered with or eavesdropped by unauthorised access. Furthermore, the leakage of health data and malfunctioning of IMDs are vital in constructing cryptographic protocols, particularly in the design of remote user authentication. In this paper, we proposed a novel secure remote user authentication scheme using a lightweight consortium blockchain for the communication network with IMDs.

Open access
Wireless Body Area Networks
Advanced Authentication Protocols Security
User Authentication and Security Systems
Original source
Jan 1, 2024·Internet of Things
2 cites
SHIELD: Secure holistic IoT environment with ledger-based defense

Samson Kahsay Gebresilassie, Joseph Rafferty, Mamun Abu-Tair, Aftab Ali · 6 authors

The Internet of Things (IoT) is a technology paradigm that has transformed several domains including manufacturing, agriculture, healthcare, power grids, travel, and retail. Despite the enormous advantages that IoT offers to organizations and transforming individuals’ everyday lives in a wide range of domains, it comes with potential cyber risks that can negatively impact, harm, or damage them. Security is the most challenging issue in IoT systems due to insecure devices, inadequate IDMS, lack of data security and privacy, lack of trust, lack of risk analysis on network traffic, various vulnerabilities and attacks, lack of physical security, and many other risk factors. Although several security architectures have been developed, they fail to properly and fully address these IoT security challenges and an urgent demand awaits for a robust IoT security architecture. Thus, this work investigates state-of-the-art solutions and proposes a holistic novel IoT security architecture called SHIELD: Secure Holistic IoT Environment with Ledger-based Defense with core security capabilities of decentralized Identity Management System (IDMS), Network Traffic Monitoring, Analysis, and dataset generation, deep learning-based Intrusion Detection System (IDS), and Distributed Ledger Technology (DLT)-based Trust Management System (TMS). The proposed architecture is qualitatively compared with existing solutions using key features like a single point of failure, risk/attack-aware, trust, real-time traffic behavior monitoring, up-to-date dataset, cross-platform functionality, and availability among others. As a result of this comparison, SHIELD architecture provides a holistic and robust solution with multiple core security features to overcome some of the key security challenges IoT environment.

Open access
2 source records
IoT and Edge/Fog Computing
Advanced Malware Detection Techniques
Network Security and Intrusion Detection
Original source
Jan 1, 2024·IEEE Access
33 cites
Blockchain-Enhanced Zero Knowledge Proof-Based Privacy-Preserving Mutual Authentication for IoT Networks

Aditya Pathak, Irfan Al‐Anbagi, Howard J. Hamilton

Authentication in low-latency Internet of Things (IoT) networks must satisfy three requirements, namely, high security and privacy preservation, high scalability, and low authentication time. These requirements arise because devices in IoT networks must operate in a secure and scalable manner despite being limited in computational resources. Existing authentication mechanisms focus on the security and privacy of IoT networks but neglect the importance of scalability and authentication time. Therefore, existing authentication mechanisms are unscalable and unsuited to low-latency IoT networks. With a focus on increasing scalability and reducing the authentication time while providing high security and privacy preservation in low-latency IoT networks, we propose a mutual authentication mechanism called Zero-Knowledge Proof-based Privacy-Preserving Mutual Authentication (Z-PMA) for IoT networks. The Z-PMA mechanism utilizes a combination of a zero-knowledge proof, an incentive mechanism, and a permissioned blockchain to provide secure, privacy-preserving, scalable, low-latency authentication for IoT networks. We develop a new approach to address the trade-off between the three requirements for authentication mechanisms for low-latency IoT networks that has the potential to improve the overall performance of these networks. A permissioned blockchain is incorporated in the approach to provide secure and immutable data storage using its distributed and unforgeable ledger. Our experimental results show that the Z-PMA mechanism reduces authentication time than existing state-of-the-art authentication mechanisms, while providing high security and privacy preservation as well as high scalability.

Open access
2 source records
Blockchain Technology Applications and Security
User Authentication and Security Systems
Cryptography and Data Security
Original source
Dec 27, 2023·IEEE Transactions on Network Science and Engineering
35 cites
Anonymous Blockchain-Assisted Authentication Protocols for Secure Cross-Domain IoD Communications

Ali Shahidinejad, Jemal Abawajy

Due to its diverse and promising use cases, including civilian, military, and commercial, the Internet of Drones (IoD) has quickly become a hot issue in academic and industry circles. Concerns about drone privacy and security are also growing at the same rate. Drones from different flying zones frequently work together in the IoD to accomplish the same mission, necessitating the development of trust among untrusted domains. Recently, some researchers have used blockchain in their authentication scheme to establish trust across different domains. However, the integration led to significant communication, computation and storage overheads and the loss of crucial security features like anonymity or unlinkability. To address these concerns, we develop a cost-effective key exchange protocol for cross-domain IoD communications through the judicious use of the blockchain. Specifically, we employ Chebyshev's chaotic map as the crypto-system, and the ledger keeps only the public keys of the drones, resulting in a significant decrease in storage and computation overheads. The proposed protocol not only complies with the stringent Canetti and Krawczyk adversary model but also satisfies the essential security requirements for IoD, such as anonymity and unlinkability. Using informal justification, formal proof, and automated security reasoning in addition to a comparative performance evaluation, this research substantiates its claims.

Open access
Blockchain Technology Applications and Security
UAV Applications and Optimization
User Authentication and Security Systems
Original source
Dec 26, 2023·Sensors
6 cites
Sensing Data Concealment in NFTs: A Steganographic Model for Confidential Cross-Border Information Exchange

Ghassan Al-Sumaidaee, Željko Žilić

In an era dominated by rapid digitalization of sensed data, the secure exchange of sensitive information poses a critical challenge across various sectors. Established techniques, particularly in emerging technologies like the Internet of Things (IoT), grapple with inherent risks in ensuring data confidentiality, integrity, and vulnerabilities to evolving cyber threats. Blockchain technology, known for its decentralized and tamper-resistant characteristics, stands as a reliable solution for secure data exchange. However, the persistent challenge lies in protecting sensitive information amidst evolving digital landscapes. Among the burgeoning applications of blockchain technology, non-fungible tokens (NFTs) have emerged as digital certificates of ownership, securely recording various types of data on a distributed ledger. Unlike traditional data storage methods, NFTs offer several advantages for secure information exchange. Firstly, their tamperproof nature guarantees the authenticity and integrity of the data. Secondly, NFTs can hold both immutable and mutable data within the same token, simplifying management and access control. Moving beyond their conventional association with art and collectibles, this paper presents a novel approach that utilizes NFTs as dynamic carriers for sensitive information. Our solution leverages the immutable NFT data to serve as a secure data pointer, while the mutable NFT data holds sensitive information protected by steganography. Steganography embeds the data within the NFT, making them invisible to unauthorized eyes, while facilitating portability. This dual approach ensures both data integrity and authorized access, even in the face of evolving digital threats. A performance analysis confirms the approach's effectiveness, demonstrating its reliability, robustness, and resilience against attacks on hidden data. This paves the way for secure data transmission across diverse industries.

Open access
2 source records
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Advanced Steganography and Watermarking Techniques
Original source
Dec 13, 2023·Measurement Sensors
18 cites
Deep learning enabled blockchain based electronic heathcare data attack detection for smart health systems

S. Chidambaranathan, R. Geetha

The idea of networked personal medical devices is a component of contemporary Smart Health Systems (SHS). These gadgets offer remote observing and the exchange of wellbeing information, which enormously further develop the patient's personal satisfaction while at the same time reducing treatment expenses for both the patient and the medical care suppliers (telemedicine). For individuals' wellbeing, a cutting edge individual wellbeing record framework is fundamental. Here, there are still difficulties with information mix from different EHRs, information interoperability, and guaranteeing that admittance to information is totally under the power of the patient. Some security issues are caused by the Network. To settle these issues, we propose a novel profound learning-based framework that circuits state of the art decentralized innovations like IPFS and blockchain with wellbeing information interoperability principles and advances like FHIR's APIs. In this review, we show that correspondence between private clinical gadgets is as a matter of fact powerless to different cyber attacks. We show how an outer assailant could involve man-in-the-center, replay, bogus information infusion, and refusal of-administration assaults to block delicate wellbeing information stream by capturing the correspondence of the individual clinical gadget. We likewise suggest an Interruption Recognition Framework (IDS), GAN, to additional screen traffic on private clinical gear and spot attacks against them. Our extensive investigation shows that GAN, with an F1-score of 98 % and an accuracy of 98.7 %, can successfully and accurately recognise numerous assaults on personal medical equipment.

Open access
Blockchain Technology Applications and Security
Digital Mental Health Interventions
User Authentication and Security Systems
Original source
Dec 7, 2023·Scientific Journal of Metaverse and Blockchain Technologies
30 cites
Integration of IoT and Blockchain for user Authentication

Mandeep Gupta

The proliferation of Internet of Things (IoT) devices has ushered in a new era of connectivity, necessitating robust solutions for user authentication to address security and trust challenges. This paper explores an innovative approach to user authentication in IoT environments by leveraging the unique capabilities of Non-Fungible Tokens (NFTs) and 9NM (9NFTMANIA) tokens, with a specific focus on utilizing contract addresses. The proposed system involves the tokenization of user identities through the creation of contract addresses on blockchain networks. Each user is assigned a unique digital identity represented by an NFT or 9NM token, providing a tamper-proof association between the user and their cryptographic keys. Blockchain smart contracts are employed to manage authentication processes, dictating access control policies based on the user's contract address. The research underscores the importance of industry-wide collaboration to develop common standards for user authentication in IoT environments. By offering a comprehensive exploration of user authentication in IoT using contract address-based NFTs and 9NM tokens that are developed on Satoshi core based blockchain, this paper contributes to the advancement of secure and user-centric practices in the rapidly evolving landscape of IoT technology. The proposed framework not only enhances the overall security posture of IoT networks but also lays the foundation for a more transparent and interoperable authentication ecosystem. This paper has discussed the mechanism where web 3.0 based programming is made using Javascript, Python, ASP.NET and PHP for user authentication considering presence of smart contracts in user wallet.

Open access
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
User Authentication and Security Systems
Original source
Nov 25, 2023·International Journal of Information Security
8 cites
Enhancing security in Fiat–Shamir transformation-based non-interactive zero-knowledge protocols for IoT authentication

Firas Hamila, Mohammad Hamad, Daniel Costa Salgado, Sebastian Steinhorst

Abstract With the rapid expansion of IoT devices and their applications, there is an increasing demand for efficient and secure authentication mechanisms to protect against unauthorized access. Traditional authentication mechanisms face limitations regarding computational speed, communication costs, and vulnerability to cyber-attacks. Zero-knowledge proof (ZKP) protocols have emerged as an effective solution for achieving secure and efficient authentication in such environments without revealing sensitive information. Among ZKP protocols, $$\Sigma $$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>Σ</mml:mi> </mml:math> -protocols, a class of interactive ZKP protocols, have been employed for their efficiency and security. However, their interactive nature necessitates multiple rounds of communication, which can reduce efficiency and increase communication overhead for resource-constrained devices. Many works have aimed to eliminate the interaction of $$\Sigma $$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>Σ</mml:mi> </mml:math> -protocols by utilizing a transformation called the Fiat–Shamir transformation (FST). However, there is still a concern regarding the soundness of the FST as it can sometimes convert a secure $$\Sigma $$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>Σ</mml:mi> </mml:math> -protocol into an insecure non-interactive zero-knowledge (NIZK) authentication scheme. In this paper, we propose an approach for transforming $$\Sigma $$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>Σ</mml:mi> </mml:math> -protocols into a NIZK protocol based on the FST, yielding significant enhancements in efficiency, communication overhead reduction, and elimination of interaction. Our proposed protocol enables the completion of the authentication process in a single request while also strengthening the soundness of $$\Sigma $$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>Σ</mml:mi> </mml:math> -protocols in comparison with the traditional FST by requiring two authentication factors instead of one. To demonstrate our approach’s robustness, we conducted comprehensive informal and formal security analyses (using the Tamarin-Prover). Our protocol demonstrated completeness, soundness, zero-knowledge properties, and robustness against attacks, including eavesdropping, message modification, replay, and brute force attacks. Additionally, our performance analysis displayed a remarkable 50% improvement in computational cost compared to traditional $$\Sigma $$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>Σ</mml:mi> </mml:math> -protocols, underscoring its efficiency for practical use.

Open access
Advanced Authentication Protocols Security
Cryptography and Data Security
User Authentication and Security Systems
Original source
Nov 24, 2023·Scientific Reports
20 cites
Towards reliable IoT communication and robust security: investigating trusted schemes in the internet of medical things using blockchain

Geetanjali Rathee, R. Maheswar, Sountharrajan Sehar, Durga Prasad Bavirisetti

The Internet of Things (IoT) is evolving in various sectors such as industries, healthcare, smart homes, and societies. Billions and trillions of IoT devices are used in e-health systems, known as the Internet of Medical Things (IoMT), to improve communication processes in the network. Scientists and researchers have proposed various methods and schemes to ensure automatic monitoring, communication, diagnosis, and even operating on patients at a distance. Several researchers have proposed security schemes and approaches to identify the legitimacy of intelligent systems involved in maintaining records in the network. However, existing schemes have their own performance issues, including delay, storage efficiency, costs, and others. This paper proposes trusted schemes that combine mean and subjective logic aggregation methods to compute the trust of each communicating device in the network. Additionally, the network maintains a blockchain of legitimate devices to oversee the trusted devices in the network. The proposed mechanism is further verified and analyzed using various security metrics, such as reliability, trust, delay, beliefs, and disbeliefs, in comparison to existing schemes.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
User Authentication and Security Systems
Original source
Nov 23, 2023·ACM Transactions on Internet Technology
15 cites
EtherShield: Time-interval Analysis for Detection of Malicious Behavior on Ethereum

Bofeng Pan, Natalia Stakhanova, Zhongwen Zhu

Advances in blockchain technology have attracted significant attention across the world. The practical blockchain applications emerging in various domains, ranging from finance, healthcare, and entertainment, have quickly become attractive targets for adversaries. The novelty of the technology coupled with the high degree of anonymity it provides made malicious activities even less visible in the blockchain environment. This made their robust detection challenging. This article presents EtherShield, a novel approach for identifying malicious activity on the Ethereum blockchain. By combining temporal transaction information and contract code characteristics, EtherShield can detect various types of threats and provide insight into the behavior of contracts. The time-interval-based analysis used by EtherShield enables expedited detection, achieving comparable accuracy to other approaches with significantly less data. Our validation analysis, which involved over 15,000 Ethereum accounts, demonstrated that EtherShield can significantly expedite the detection of malicious activity while maintaining high accuracy levels (86.52% accuracy with 1 hour of transaction history data and 91.33% accuracy with 1 year of transaction history data).

Open access
User Authentication and Security Systems
Advanced Malware Detection Techniques
Network Security and Intrusion Detection
Original source
Nov 16, 2023·CEUR Workshop Proceedings, Vol-3550: Proceedings of the Cybersecurity Providing in Information and Telecommunication Systems II
0 cites
A Comprehensive Decentralized Digital Identity System: Blockchain, Artificial Intelligence, Fuzzy Extractors, and NFTs for Secure Identity Management

Alexandr Kuznetsov, Emanuele Frontoni, V. A. Katrich, Olena Kobylianska · 5 authors

Existing digital identification systems are often vulnerable to attacks as they are commonly based on authentication methods such as passwords, PIN codes, biometric data, etc., which can be easily forged or compromised. In this letter, we propose a digital identification system based on a unique set of user biometric data processed by Artificial Intelligence (AI) and fuzzy extractors to generate a cryptographically secure password linked to a unique Non-Fungible Token (NFT). Our system provides decentralized identification based on blockchain technology, which eliminates problems associated with centralized identification systems, such as cyber-attacks on central servers and data leaks. Our proposed system offers a higher level of user identification security by linking the user to their data through a unique NFT, generating a cryptographically secure password, and processing large volumes of biometric data using AI and fuzzy extractors. Our system provides a solution to many of these problems, making it important and relevant to many industries, including banking, medical, and financial sectors. The use of decentralized storage of information on the blockchain provides a high level of protection against hacking and reduces the likelihood of data breaches, making our system particularly relevant in the field of financial services and personal data protection.

Open access
User Authentication and Security Systems
Blockchain Technology Applications and Security
Advanced Authentication Protocols Security
Original source
Nov 13, 2023·Journal of Systems Architecture
17 cites
A distributed message authentication scheme with reputation mechanism for Internet of Vehicles

Xia Feng, XiaoFeng Wang, Kaiping Cui, Qingqing Xie · 5 authors

Real-time and interactive traffic information sharing systems are crucial in the Internet of Vehicles (IoV) as they enable vehicles to make informed decisions, thereby improving the efficiency of intelligent transportation systems (ITS). Message authentication ensures the accuracy, integrity, and tamper-resistance of information in IoV. Existing schemes aim to achieve time-critical message authentication . However, these schemes are time-consuming and cannot meet the real-time requirements of IoV. Additionally, there are issues with latency in data synchronization and data redundancy when vehicles traverse different domains. We propose an efficient, distributed, and resistant-to-malicious-attacks authentication scheme based on the reputation mechanism. Our scheme supports batch verification, enabling fast authentication. By leveraging the decentralized and ledger-synchronized features of blockchain , our distributed scheme reduces data redundancy. We also employ a reputation mechanism to ensure reliable reports in IoVs. We experimentally confirm that our scheme outperforms EADA (59.73%), RCoM (76.35%), MLGSDT (63.36%), and TRAJ (82.08%). This approach provides a secure and reliable solution for report authentication.

Open access
Vehicular Ad Hoc Networks (VANETs)
User Authentication and Security Systems
Blockchain Technology Applications and Security
Original source
Nov 13, 2023·Proceedings of the ACM on Human-Computer Interaction
22 cites
"Centralized or Decentralized?": Concerns and Value Judgments of Stakeholders in the Non-Fungible Tokens (NFTs) Market

Yunpeng Xiao, B. Deng, Siqi Chen, Zhixuan Zhou · 7 authors

Non-fungible tokens (NFTs) are decentralized digital tokens to represent the unique ownership of items. Recently, NFTs have been gaining popularity and at the same time bringing up issues, such as scams, racism, and sexism. Decentralization, a key attribute of NFT, contributes to some of the issues that are easier to regulate under centralized schemes, which are intentionally left out of the NFT marketplace. In this work, we delved into this centralization-decentralization dilemma in the NFT space through mixed quantitative and qualitative methods. Centralization-decentralization dilemma is the dilemma caused by the conflict between the slogan of decentralization and the interests of stakeholders. We first analyzed over 30,000 NFT-related tweets to obtain a high-level understanding of stakeholders' concerns in the NFT space. We then interviewed 15 NFT stakeholders (both creators and collectors) to obtain their in-depth insights into these concerns and potential solutions. Our findings identify concerning issues among users: financial scams, counterfeit NFTs, hacking, and unethical NFTs. We further reflected on the centralization-decentralization dilemma drawing upon the perspectives of the stakeholders in the interviews. Finally, we gave some inferences to solve the centralization-decentralization dilemma in the NFT market and thought about the future of NFT and decentralization.

Open access
3 source records
Blockchain Technology Applications and Security
Market Dynamics and Volatility
Art History and Market Analysis
Original source