During long-distance flight, unmanned aerial vehicles (UAVs) need to perform cross-domain authentication to prove their identity and receive information from the ground control station (GCS). However, the GCS needs to verify all drones arriving at the area it is responsible for, which leads to the GCS being unable to complete authentication in time when facing cross-domain requests from a large number of drones. Additionally, due to potential threats from attackers, drones and GCSs are likely to be deceived. To improve the efficiency and security of cross-domain authentication, we propose an efficient blockchain-based cross-domain authentication scheme for the Internet of Drones (BCDAIoD). By using a consortium chain with a multi-chain architecture, the proposed method can query and update different types of data efficiently. By mutual authentication before cross-domain authentication, drones can compose drone groups to lighten the authentication workload of domain management nodes. BCDAIoD uses the notification mechanism between domains to enable path planning for drones in advance, which can further improve the efficiency of cross-domain authentication. The performance of BCDAIoD was evaluated through experiments. The results show that the cross-domain authentication time cost and computational overhead of BCDAIoD are significantly lower those of than existing methods when the number of drones is large.
In the medical era, wearables often manage and find the specific data points to check important data like resting heart rate, ECG voltage, SPO2, sleep patterns like length, interruptions, and intensity, and physical activity like kind, duration, and levels. These digital biomarkers are created mainly through passive data collection from various sensors. The critical issues with this method are time and sensitivity. We reviewed the newest wireless communication trends employed in hospitals using wearable technology and privacy and Block chain to solve this problem. Based on sensors, this wireless technology controls the data gathered from numerous locations. In this study, the wearable sensor contains data from the various departments of the system. The gradient boosting method and the hybrid microwave transmission method have been proposed to find the location and convince people. The patient health decision has been submitted to hybrid microwave transmission using gradient boosting. This will help to trace the mobile phones using the calls from the threatening person, and the data is gathered from the database while tracing. From this concern, the data analysis process is based on decision-making. They adapted the data encountered by the detailed data in the statistical modeling of the system to produce exploratory data analysis for satisfying the data from the database. Complete data is classified with a 97% outcome by removing unwanted data and making it a 98% successful data classification.
In the last few years, blockchain technology and NFTs have been the subject of much research in different sectors ranging from informatics, to medicine, to economics. Although it is most often associated with cryptocurrencies, due to its features of immutability and durability, this technology has found its place in various fields, including GLAM institutions. This article will review the literature from 2017 to 2022 dealing with blockchain and NFTs in the heritage sector. Topics covered, proposed models, and projects will be highlighted. Archives are currently leading the research into the use of blockchain technology and have already developed models such as TrustChain. However, libraries, museums, and galleries are also beginning to show an interest in the new technology and its potential benefits. Therefore, we also approached the GLAM sector as a whole, to emphasize the importance of the joint development on the advancement of shared approaches and protocols in utilizing blockchain technology to enhance the trustworthy management and preservation of digital resources. This is particularly important because GLAM institutions care for a shared heritage and serve a common audience. In the second part of the article we will discuss the proposed uses of the technology and highlight still unexplored topics that should be elaborated in further research. The aim of this paper is to make a synthesis of previous research and bring the potential of blockchain technology and NFTs closer to experts in the heritage field, given that they are still quite unknown.
Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Despite the widespread use of radio frequency identification and wireless connectivity such as near field communication in electric vehicles, their security and privacy implications in Ad-Hoc networks have not been well explored. This article provides a data protection assessment of radio frequency electronic system in the tire pressure monitoring system (TPMS). It is demonstrated that eavesdropping is completely feasible from a passing car, at an approximate distance up to 50 m. Furthermore, our reverse analysis shows that the staticn-bit signatures and messaging can be eavesdropped from a relatively far distance, raising privacy concerns as a vehicles’ movements can be tracked by using the unique IDs of tire pressure sensors. Unfortunately, current protocols do not use authentication, and automobile technologies hardly follow routine message confirmation so sensor messages may be spoofed remotely. To improve the security of TPMS, we suggest a novel ultralightweight mutual authentication for the TPMS registry process in the automotive network. Our experimental results confirm the effectiveness and security of the proposed method in TPMS.
Paweł Weichbroth, Kacper Wereszko, Helena Anacka, Jolanta Kowal
[Context] The goal of security is to protect digital assets, devices, and services from being disrupted, exploited or stolen by unauthorized users. It is also about having reliable information available at the right time. [Motivation] Since the inception in 2009 of the first cryptocurrency, few studies have been undertaken to analyze and review the state-of-the-art research and current developments with respect to the security of cryptocurrencies. [Purpose] We aim to provide both theoretical and empirical insights into the security landscape, in particular focusing on both technical solutions and human-related facets. [Methodology] We used an integrative review which could help in building science and scholarly research, the basis for conceptual and empirical models. [Results] Successful defense against cyberattacks depends on technical measures on the one hand, as well as on self-education and training with the aim to develop competence, knowledge, skills and social abilities, on the other. [Contribution] Our findings provide a comprehensive review for the major achievements and developments of the recent progress on the security of cryptocurrencies. [Future research] Since there is increasing interest in adoption of the current solutions within the central bank digital currencies, the future research should explore the development and inception of effective measures against social engineering attacks, which still remain the main concern.
Md Ahmad, Gautami Tripathi, Farheen Siddiqui, Mohammad Afshar Alam · 7 authors
The overwhelming popularity of technology-based solutions and innovations to address day-to-day processes has significantly contributed to the emergence of smart cities. where millions of interconnected devices and sensors generate and share huge volumes of data. The easy and high availability of rich personal and public data generated in these digitalized and automated ecosystems renders smart cities vulnerable to intrinsic and extrinsic security breaches. Today, with fast-developing technologies, the classical username and password approaches are no longer adequate to secure valuable data and information from cyberattacks. Multi-factor authentication (MFA) can provide an effective solution to minimize the security challenges associated with legacy single-factor authentication systems (both online and offline). This paper identifies and discusses the role and need of MFA for securing the smart city ecosystem. The paper begins by describing the notion of smart cities and the associated security threats and privacy issues. The paper further provides a detailed description of how MFA can be used for securing various smart city entities and services. A new concept of blockchain-based multi-factor authentication named "BAuth-ZKP" for securing smart city transactions is presented in the paper. The concept focuses on developing smart contracts between the participating entities within the smart city and performing the transactions with zero knowledge proof (ZKP)-based authentication in a secure and privacy-preserved manner. Finally, the future prospects, developments, and scope of using MFA in smart city ecosystem are discussed.
Non Fungible Tokens (NFTs) are among the most promising technologies that have emerged in recent years. NFTs enable the efficient verification and ownership management of digital assets and therefore, offer the means to secure them. NFT is similar to blockchain that was first used by the cryptocurrency and then by numerous other technologies. At first, the NFT concept attracted the attention of the digital art community. However, NFT has the potential to enable a plethora of different applications and sce We present a review of the NFT technology. We describe the basic components of NFTs and how NFTs work. Then, we present and discuss the different applications of the NFTs. Finally, we discuss various challenges that the NFT technology must address in the future.
Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
The Internet of Things (IoT) is ubiquitous in our lives. However, the inherent vulnerability of IoT smart devices can lead to the destruction of networks in untrustworthy environments. Therefore, authentication is a necessary tool to ensure the legitimacy of nodes and protect data security. Naturally, the authentication factors always include various sensitive users’ information, such as passwords, ID cards, even biological information, etc. How to prevent privacy leakage has always been a problem faced by the IoT. Zero-knowledge authentication is a crucial cryptographic technology that uses authenticates nodes on the networks without revealing identity or any other data entered by users. However, zero-knowledge proof (ZKP) requires more complex data exchange protocols and more data transmission compared to traditional cryptography technologies. To understand how zero-knowledge authentication works in IoT, we produce a survey on zero-knowledge authentication in privacy-preserving IoT in the paper. First, we overview the IoT architecture and privacy, including security challenges and open question in different IoT layers. Next, we overview zero-knowledge authentication and provide a comprehensive analysis of designing zero-knowledge authentication protocols in various IoT networks. We summarize the advantages of ZKP-based authentication in IoT. Finally, it summarizes the potential problems and future directions of ZKP in IoT.
Mahmoud Tayseer Al Ahmed, Fazirulhisyam Hashim, Shaiful Jahari Hashim, Azizol Abdullah
Internet of Things networks (IoT) are becoming very important in industrial, medical, and commercial applications. The security aspect of IoT networks is critical, especially the authentication of the devices in the network. The current security model in IoT networks uses centralized key exchange servers that present a security weak point. IoT networks need decentralized management for network security. Blockchain, with its decentralized model of authentication, can provide a solution for decentralized authentication in IoT networks. However, blockchain authentication models are known to be computationally demanding because they require complex mathematical calculations. In this paper, we present an Authentication-Chains protocol which is a lightweight decentralized protocol for IoT authentication based on blockchain distributed ledger. The proposed protocol arranges the nodes in clusters and creates an authentication blockchain for each cluster. These cluster chains are connected by another blockchain. A new consensus algorithm based on proof of identity authentication is adapted to the limited computational capabilities of IoT devices. The proposed protocol security performance is analyzed using cryptographic protocols verifier software and tested. Additionally, a test bed consisting of a Raspberry Pi network is presented to analyze the performance of the proposed protocol.
In this paper, we explore Blockchain technology can be used to build a reliable decentralised authentication system. High security for the bioacoustics signal authentication mechanism is guaranteed by using an optimised number of secured features from the bioacoustics signal rather than conventional biometric features for authentication, and by utilising a blockchain model to improve the robustness of multiple checks on the data. It allows for trustworthy authentication and the tracking of terminal activity. Then, light weighted cryptography (LWC) is developed to offer protection at each edge node and terminal. Finally, the belief propagation (BP) algorithm for retraining the features of the bioacoustics signal serves as the foundation for the catching method. It improves hit ratio while decreasing delay time. The experimental setup uses the bioacoustics signals for authentication instead of conventional biometric features, and the use of a blockchain model for data transparency improves the efficiency of multiple checks. When this happens, privacy and safety are both boosted.
Digital transformation has increased its proportion in the last few years and the Internet-on-Things (IoT) domain is not an exception, with more and more devices or sensors being connected to the Internet and transmitting different types of data. Usually, being part of more complex IT systems, it must be ensured that the IoT devices transmitting the data are authenticated components of the system before sending the data to a storage server. However, usually, IoT devices have limited computing power, therefore all of the work that they are doing should not be too expensive in terms of computations. This is the case for the authentication mechanism, too. Having this context, in this paper, we propose an authentication mechanism for IoT devices based on elliptic curves, which are known as having a low computational cost compared to other techniques used in cryptography that provide the same level of security. The proposed system includes a blockchain network that will verify the identity of the device which tries to connect within the system to send the data to the storage server, a process that will be made together with the storage server. Once the identity is valid, the blockchain records the transaction and the storage server initiates the data transmission process. Besides including a lightweight authentication mechanism, the proposed method has several other important properties due to it using the blockchain network. Compared to the related work that we analyzed, we show that the proposed authentication mechanism is secure against common attacks designed for IoT devices. The performance analysis shows that the authentication query made by the IoT device takes place in less than a second on both a MSP430F1611 microcontroller and a MICAz sensor.
Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Wireless Sensor Networks—WSNs, an important part of IoT—consist of sensor nodes with limited processing, memory capacities, and energy. Wireless Sensor Networks face many dangers as they are often distributed into untrusted regions. The accuracy of the data obtained in a WSN, where security threats cannot be prevented, is also questioned. In WSNs, the authentication of the resources and the data can be verified with the authentication mechanism. Authentication in WSNs allows the node to verify whether data have been sent from authorized sources and protects the original data from changes. However, there are some deficiencies in terms of security in existing authentication protocols such as ID spoofing attacks. In addition, blockchain, one of the emerging technologies, gives significant successful results in security applications. Cryptographically secured, immutable, non-repudiable, irrevocable, auditable, and verifiable can be given as security-related characteristics of the blockchain. This study aims to use these features of the blockchain in WSNs. In this study, a new blockchain-based authentication protocol was developed for WSNs. Based on the study’s system model, sensor nodes, cluster nodes, base station, and blockchain networks were created using a private blockchain, and users. A detailed security analysis was carried out for the study. At the same time, efficiency analysis was performed by implementing the proposed model on the WiSeN sensor node.
Raman Singh, Sean Sturley, Bhisham Sharma, Imed Ben Dhaou
The Internet of Things (IoT) is the network of multiple devices known as “things” which includes sensors, security cameras, smart lights, smart TV, traffic lights etc. in the smart home or industrial environment. In many applications, these IoT devices are installed in open areas for example traffic lights/ security cameras in a smart city. Strong authentication and authorisation for these devices need to be deployed to ensure trust among IoT networks. IoT devices produce and forward security-sensitive data and hence confidentiality, authentication and proper authorisation should be the primary priority of an IoT system. Implementing Certificate Authority-based digital certificate solutions is costly because of the number of devices involved in IoT networks. Blockchain is a decentralized ledger-based technology which can help to provide seamless yet cost-effective solutions for confidentiality, authentication, and authorisation for IoT environments. A blockchain-based system for device registration, authentication, authorisation, and data confidentiality is proposed. The paper shows the methodological and procedural details of the proposed security scheme.
With the rapid increase in the number of Internet of Things (IoT) devices in recent years, massive amounts of sensitive IoT data are being generated and transmitted over the Internet. Despite its growing adoption in various fields, IoT security remains a major challenge requiring further research. IoT authentication is an essential security mechanism for building trust in IoT systems. However, conventional authentication approaches use expensive cryptographic primitives that do not align with the resource-constrained nature of IoT devices. Furthermore, centralized authentication schemes have proven to be inapplicable for cross-domain authentication and do not limit the scalability of IoT networks. Recently, blockchain technology has been applied to building decentralized authentication between IoT devices. Nevertheless, most existing blockchain-based authentication approaches incur high overhead in IoT computation, storage, and energy consumption. Authentication time is another critical issue in real-time IoT systems. When numerous IoT authentication requests are transferred to the blockchain, an additional time delay is imposed, in addition to the high computational cost of the blockchain caused by the consensus mechanism. This study proposes a hybrid centralized and blockchain-based authentication architecture for IoT systems. Edge servers are deployed to provide centralized authentication for associated IoT devices. A blockchain network of centralized edge servers is then established to ensure decentralized authentication and verification of IoT devices that belong to different and heterogeneous IoT systems. Lightweight cryptographic methods are implemented to achieve efficient authentication, in which limiting the consumption of IoT resources is required. The architecture is demonstrated using a local Ethereum blockchain network. The results indicate that the proposed method achieves significant improvements in terms of computation cost, execution time, and power consumption for IoT compared with centralized and blockchain-based authentication schemes. A security analysis proves the ability of our architecture to mitigate attacks and satisfy the IoT security requirements.
Sarra Namane, Marwa Ahmim, Aron Kondoro, Imed Ben Dhaou
In the era of the Fourth Industrial Revolution, cybercriminals are targeting critical infrastructures such as traffic light systems and smart grids. A major concern is the security of such systems, which can be broken down into a number of categories, such as the authentication of data collection devices, secure data transmission, and use of the data by authorized and authenticated parties. The majority of research studies in the literature have largely focused on data integrity and user authentication. So far, no published work has addressed the security of a traffic light system from data collection to data access. Furthermore, it is evident that the conventional cloud computing architecture is incapable of analyzing and managing the massive amount of generated data. As a result, the fog computing paradigm combined with blockchain technology may be the best way to ensure data privacy in a decentralized manner while reducing overheads, latency, and maintaining security. This paper presents a blockchain-based authentication scheme named VDAS using the fog computing paradigm. The formal and informal verifications of the proposed solution are presented. The evaluation of the proposed scheme VDAS showed that it has low communication and computation costs compared to existing lightweight authentication techniques.
Zhe Tu, Huachun Zhou, Kun Li, Haoxiang Song · 5 authors
Abstract It is well known that the Sixth Generation (6G) communication system integrating multiple access networks promotes the internet of everything world-widely. However, due to the differentiated underlying network protocols, it is difficult to find a general authentication solution to support various authentication methods in different access networks. Blockchain is a new technology that supports network heterogeneity, which provides a potential solution for differentiated authentication. In this paper, we propose a blockchain-based differentiated authentication mechanism for 6G Heterogeneous Networks (HetNets), which can efficiently authenticate user identities through scheduling different authentication methods. Particularly, we analyze the authentication architecture of 6G HetNets and put forward a blockchain-based differentiated authentication framework. Besides, to improve the scalability of user authentication, it is the first time to use various blockchain authentication contracts to represent different authentication methods. Meanwhile, a differentiated authentication management contract is proposed to uniformly manage different authentication contracts to realize differentiated identity authentication. Based on the evaluation of the prototype system, the proposed mechanism can dynamically provide differentiated authentication services (e.g. EAP-MD5, 5G-AKA) with low additional time (milliseconds levels) cost.
The Industrial Internet of Things (IIoT) is able to connect machines, analytics and people with IoT smart devices, gateway nodes and edge devices to create powerful intuitivenesses to drive smarter, faster and effective business agreements. IIoT having interconnected machines along with devices can monitor, gather, exchange, and analyze information. Since the communication among the entities in IIoT environment takes place insecurely (for instance, wireless communications and Internet), an intruder can easily tamper with the data. Moreover, physical theft of IoT smart devices provides an intruder to mount impersonation and other attacks. To handle such critical issues, in this work, we design a new private blockchain-envisioned access control scheme for Pervasive Edge Computing (PEC) in IIoT environment, called PBACS-PECIIoT. We consider the private blockchain consisting of the transactions and registration credentials of the entities related to IIoT, because the information is strictly confidential and private. The security of PBACS-PECIIoT is significantly improved due to usage of blockchain as immutability, transparency and decentralization along with protection of various potential attacks. A meticulous comparative analysis exhibits that PBACS-PECIIoT achieves greater security and more functionality features, and requires low costs for communication and computational as compared to other pertinent schemes.
With the increasing number of vehicles connected to the Internet of Vehicles (IoV), to accommodate the evolving needs and patterns of new vehicles, passengers, and drivers, traditional single Trusted Authority (TA) authentication model may no longer be suitable for the IoV scenario, it is crucial to develop secure, lightweight, efficient, and cross-TA identity authentication and key agreement algorithms. In 2021, Xu et al. proposed a blockchain-based Roadside Unit (RSU)-assisted authentication and key agreement protocol for IoV. However, we describe that their protocol is vulnerable to identity guessing attacks, vehicle forgery attacks, and lacks of session key security and known session key secrecy, and propose a novel blockchain and elliptic curve cryptography-based cross-TA authentication and key agreement protocol for IoV. Our protocol uses Physical Unclonable Functions (PUF) and biometric keys to resist RSU capture attacks and Onboard Unit (OBU) intrusion attacks. Formal security proof and comparative analysis indicate that the proposed protocol can resist various known attacks and maintains lower computational complexity.
Jihyeon Oh, Myeonghyun Kim, Yohan Park, Youngho Park
In a rapidly evolving metaverse, where the physical and virtual realms naturally merge, users are actively participating in interactive experiences, content creation, and content trading, transcending spatial and temporal constraints. However, with the spread of the metaverse, security concerns have been raised about privacy and the integrity of digital transactions. Several studies have thus focused on enhancing the security and privacy in metaverse. However, there is still a lack of security research on content trading between metaverse platforms. Therefore, this paper proposes a secure content trading system for cross-platform interactions within the metaverse. Leveraging the blockchain technology, the proposed system delivers an ecosystem that ensures secure content management, data integrity, and verifiable transactions. We use smart contracts that enable reliable and automated purchase methods, empowering users and building their trust. In addition, we incorporate searchable encryption to further enhance the user experience within the metaverse by allowing avatars to seamlessly search for and obtain the desired content across different metaverse platforms. The security of the proposed scheme is comprehensively assessed via vulnerability analyses, including BAN logic and Scyther, to identify potential threats and vulnerabilities in various content trading scenarios. The security and performance of the proposed system are compared with those of the related schemes. Result reveals that the proposed scheme is robust and can be applied to content trading systems in dynamic and ever-expanding metaverse environments.
Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
T. T. Tram Ngo, The Anh Dang, V. Vuong Huynh, Tam Le
Although blockchain is an emerging technology, it has been applied in a lot of domains by leveraging its features. Traditional identity management systems have many issues regarding security and privacy of personal data. Blockchain has the potential to mitigate and avoid such issues by creating trust among the parties involved in the system while reducing reliance on third-party authorities. The first blockchain-based identity management solutions were launched in 2016. Since then, due to high demand, numerous primary and experimental studies and intatives have been carried out to provide solutions to this research topic. Along with that, there are also a lot of secondary studies to overview the current state of research on this topic. However, the number of systematic research articles is still limited and each research has it limitation. Through this study, we provide a novel systematic literature including categorization of studies into predefined categories (domain, research type, place of publication), analysis of publication frequency, co-authorship, number of papers citing each paper of all studied papers. Comparing to other systematic literature mapping studies, our paper provides a more comprehensive view of the studied articles. In particular, we analyze the number of citations, which no study has ever done. In this research, we studied 361 papers published from January 2009 to April 2022 in four big databases (IEEE Explore, ACM Digital Library, ScienceDirect, Springer Link), the largest number of articles studied compared to previous researches. The obtained results show that most of the articles under validation research type (providing solution and implementing that solution but not in real-world scenarios) propose solutions/systems, models/schemes and architectures to address general problems. We also find that the majority of authors works alone or collaborate in a separate group and co-work in only one paper. This shows that there is no long term collaboration in blockchain-based IdM identity management, and thus subsequent publications presenting real-world blockchain-based identity management products do not exist.
Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Siddhant Thapliyal, Mohammad Wazid, Devesh Pratap Singh, Ashok Kumar Das · 6 authors
The healthcare sector is a very crucial and important sector of any society, and with the evolution of the various deployed technologies, like the Internet of Things (IoT), machine learning and blockchain it has numerous advantages. However, in this section, the data is much more vulnerable than others, because the data is strictly private and confidential, and it requires a highly secured framework for the transmission of data between entities. In this article, we aim to design a blockchain-envisioned authentication and key management mechanism for the IoMT-based smart healthcare applications (in short, we call it SBAKM-HS). We compare the various attributes of the proposed SBAKM-HS and other existing schemes to demonstrate that SBAKM-HS outperforms other existing schemes. The conducted security analysis and formal security verification via Scyther automated validation tool prove the security of the proposed SBAKM-HS against various possible potential attacks. Next, a real-tested implementation of SBAKM-HS is provided to observe its impact on the performance of the system.
Senay A. Gebreab, Khaled Salah, Raja Jayaraman, Mohamed Jamal Zemerly
Medical devices play a crucial role in the global healthcare system, but their high cost has led to the increasing adoption of refurbished medical devices as a sustainable alternative for hospitals and patients around the world. The repositioning of refurbished devices into the market, however, is accompanied by a number of challenges, including concerns about quality and safety, as well as the risk of fraudulent activities such as counterfeiting. To address these challenges, we propose an NFT-based solution for managing refurbished medical devices that creates a secure, transparent, and verifiable record of the refurbishment process to ensure the safety and quality of these devices. The proposed solution utilizes dynamic composable NFTs as digital representations of medical devices, with replacement parts and certificate documents embedded in a parent-child NFT hierarchy, and reprocessing steps captured and reflected through the evolution of the dynamic tokens. This serves to authenticate and track the movement of refurbished devices while also providing a trustworthy means of managing individual devices and their ownership. Furthermore, the integration of non-transferable NFTs as certificates of refurbishment acts as an effective mechanism for detecting suspect medical devices and instances of fraudulent labeling, thereby increasing buyer confidence and promoting user safety. We leverage the Interplanetary File System to store and keep track of the metadata of the tokenized components of the system. We present the system architecture and implementation details with tested algorithms. We develop a front-end decentralized application (DApp) to interact with the designed smart contracts and showcase their functionalities. We also conduct security analysis to demonstrate our system is resistant to common vulnerabilities and exploits. The smart contract code is made available on GitHub.
Sulaiman M. Karim, Adib Habbal, Shehzad Ashraf Chaudhry, Azeem Irshad
The Internet of Vehicles (IoV) is a network that connects vehicles and their environment: in-built devices, pedestrians, and infrastructure through the Internet using heterogeneous access technologies. During communication between vehicles, roadside units, and control rooms, data confidentiality and privacy are critical issues that require effective measures. Several works have been proposed for securing IoV environments based on vehicles-to-infrastructure authentication; However, some schemes have security vulnerabilities, while others have shown efficiency issues. Due to its decentralization, stability, and transaction tracking capabilities, Blockchain as an emerging technology presents a potential solution for IoV security. This article provides an in-depth examination of the benefits of blockchain for a 5G-based IoV environment. In particular, we propose and evaluate a novel blockchain-based secure data exchange (BSDCE-IoV) scheme based on Elliptic Curve Cryptography algorithm. Our solution is designed to eliminate several potential attacks that pose a threat to the IoV environment. Deep examination using the Real-or-Random oracle model and Scyther tool, in addition to the informal security analysis, validates the scheme regarding security and privacy. The Multi-precision Integer and Rational Arithmetic Cryptographic Library (MIRACL) assesses the computational and communication overhead. Computational and communicative overheads were also evaluated using the Multi-precision Integer and Rational Arithmetic Cryptographic Library (MIRACL). BSDCE-IoV shows higher performance in terms of security, functionality, and time delay than a number of recent selective work in IoV security.
Egor Ermolaev, Iván Abellán Álvarez, Johannes Sedlmeir, Gilbert Fridgen
E-commerce has grown rapidly over the past years, with prevailing e-commerce platforms aggregating large amounts of customer data. This practice has several undesirable side effects, such as facilitating profiling that may lead to price discrimination and data feedback loops that can hamper competition. Moreover, data hoarding carries security risks through data breaches and undermines customers’ privacy expectations. On the other hand, convenience aspects and compliance regulation demand the processing and storage of user-related data. To address this tension field, we aim to conceptualize and iteratively refine a data-minimizinig e-commerce platform. Following a design science research approach, we identify design objectives and propose and implement a solution in which stakeholders receive only customer data that is indispensable for their part of the process. Our solution leverages digital identity wallets and general-purpose zero-knowledge proofs (zk-SNARKs). We aim to perform a criteria-based evaluation to assess our artifact’s feasibility and fitness from an interdisciplinary perspective. With our results, we hope to illustrate that combining state-of-the-art cryptographic techniques and an emerging digital identity paradigm allows reaching the user experience of incumbent e-commerce platforms while mitigating the undesirable socio-economic side effects of avoidable data disclosure.