Yixiao Gao, Muhammad Saad, Adam Oest, Jean Zhang · 6 authors
Recent years have witnessed the increasing popularity and market value of Non-Fungible Tokens (NFTs), along with the burgeoning of blockchains and metaverse. The media hypes often imply that NFTs are as secure as the underlying blockchains. In this work, we take a first look into the building blocks of NFTs (i.e., ownership certificates stored on-chain and the metadata and digital assets stored on-chain or off-chain), focusing on understanding the new attack surface and safety of these digital assets (rather than the traditional attacks on block-chains). For this purpose, we provide a detailed analysis of the logical structure of the dominant off-chain NFTs, followed by the attack surface analysis. Our study indicates that specific new attacks could be easily mounted on them. To validate our findings, we experiment by minting our own NFTs on Ethereum and demonstrate that we can successfully mount the attacks with trivial or even no cost. The cause of these new attacks is rooted in the current design of NFTs where the digital assets are decoupled from the contracts deployed on the blockchains. We discuss some future research to address these vulnerabilities.
Advanced Steganography and Watermarking Techniques
Zhiqiang Du, W. Jiang, Chenguang Tian, Xiaofeng Rong · 5 authors
Cloud computing is a disruptive technology that has transformed the way people access and utilize computing resources. Due to the diversity of services and complexity of environments, there is widespread interest in how to securely and efficiently authenticate users under the same domain. However, many traditional authentication methods involve untrusted third parties or overly centralized central authorities, which can compromise the security of the system. Therefore, it is crucial to establish secure authentication channels within trusted domains. In this context, we propose a secure and efficient authentication protocol, HIDA (Hyperledger Fabric Identity Authentication), for the cloud computing environment. Specifically, by introducing federated chain technology to securely isolate entities in the trust domain, and combining it with zero-knowledge proof technology, users’ data are further secured. In addition, Subsequent Access Management allows users to prove their identity by revealing only brief credentials, greatly improving the efficiency of access. To ensure the security of the protocol, we performed a formal semantic analysis and proved that it can effectively protect against various attacks. At the same time, we conducted ten simulations to prove that the protocol is efficient and reliable in practical applications. The research results in this paper can provide new ideas and technical support for identity authentication in a cloud environment and provide a useful reference for realizing the authentication problem in cloud computing application scenarios.
Deepika Kamboj, Minakshi Chauhan, Kamal Kumar Gola
At present, there is rapid growth in storing data online. Online data storage enables users to access their information anywhere and anytime. However, this can lead to some security issues, which can be handled today using Blockchain. Numerous researchers have worked on various blockchain application domains, including supply chain management, the medical industry, governance, etc. In addition to these applications, many issues still need research, such as security, privacy, performance, scalability, etc. As part of our research, we are focusing on a blockchain-based medical application field. The concept is based on the Internet of Things (IoT) and Blockchain, where we employ wearable devices to read user data like blood pressure, heartbeat, and temperature. However, anyone can wear this wearable device which comes up with the problem that it is optional that the data we are storing comes from a valid user. Secondly, we need fast access to data stored in Blockchain, but as the block creation takes 10-12 seconds, we suffer from some delay in response time. In our work, we proposed solutions to these two problems by using authentication while storing data and reduction in the Block creation time.
During long-distance flight, unmanned aerial vehicles (UAVs) need to perform cross-domain authentication to prove their identity and receive information from the ground control station (GCS). However, the GCS needs to verify all drones arriving at the area it is responsible for, which leads to the GCS being unable to complete authentication in time when facing cross-domain requests from a large number of drones. Additionally, due to potential threats from attackers, drones and GCSs are likely to be deceived. To improve the efficiency and security of cross-domain authentication, we propose an efficient blockchain-based cross-domain authentication scheme for the Internet of Drones (BCDAIoD). By using a consortium chain with a multi-chain architecture, the proposed method can query and update different types of data efficiently. By mutual authentication before cross-domain authentication, drones can compose drone groups to lighten the authentication workload of domain management nodes. BCDAIoD uses the notification mechanism between domains to enable path planning for drones in advance, which can further improve the efficiency of cross-domain authentication. The performance of BCDAIoD was evaluated through experiments. The results show that the cross-domain authentication time cost and computational overhead of BCDAIoD are significantly lower those of than existing methods when the number of drones is large.
This demonstration presents an original low cost SIM Ethereum Bluetooth token (SIM_ETH_BLE_TOKEN), used from a mobile application, for the generation of Ethereum transaction. The token is based on open hardware (i.e. Arduino) and open source code. The core security is a secure element (i.e. javacard) with SIM card form factor, protected by PIN code, which stores keys and generates transactions. The token has no keypad or screen; it uses a LED and a button for user interface. The mobile application is available on Google Play. It signs files stored in smartphone, thanks to transactions, inserted in the Ethereum ledger.
In the medical era, wearables often manage and find the specific data points to check important data like resting heart rate, ECG voltage, SPO2, sleep patterns like length, interruptions, and intensity, and physical activity like kind, duration, and levels. These digital biomarkers are created mainly through passive data collection from various sensors. The critical issues with this method are time and sensitivity. We reviewed the newest wireless communication trends employed in hospitals using wearable technology and privacy and Block chain to solve this problem. Based on sensors, this wireless technology controls the data gathered from numerous locations. In this study, the wearable sensor contains data from the various departments of the system. The gradient boosting method and the hybrid microwave transmission method have been proposed to find the location and convince people. The patient health decision has been submitted to hybrid microwave transmission using gradient boosting. This will help to trace the mobile phones using the calls from the threatening person, and the data is gathered from the database while tracing. From this concern, the data analysis process is based on decision-making. They adapted the data encountered by the detailed data in the statistical modeling of the system to produce exploratory data analysis for satisfying the data from the database. Complete data is classified with a 97% outcome by removing unwanted data and making it a 98% successful data classification.
Implementation of IoT domain invites tremendous attacking opportunities which demands end to – end security mechanism. Applications related to the domain of IoT varies from critical applications to normal business-oriented applications like Intelligent Transportation Systems, Smart Grid, Video Surveillance, Banking, Logistics, Insurance etc. A special support in terms of security must be required for critical applications as well as normal business applications. Large amount of security mechanisms implemented time to time. Blockchain technology proves to be useful in providing security to several applications based on IoT by following defense – in – depth or castle approach. Blockchain can be defined as a database for storing processed data in a sequential manner. Such data has been shared among participating users. Information can be stored on a public ledger which can’t be updated. Every device in the corresponding network must retain the same ledger. Through the medium of this paper, we try to highlight importance of Blockchain Mechanism in IoT environment and also point out that the concept of Blockchain mechanism is only concerned with security.
In the last few years, blockchain technology and NFTs have been the subject of much research in different sectors ranging from informatics, to medicine, to economics. Although it is most often associated with cryptocurrencies, due to its features of immutability and durability, this technology has found its place in various fields, including GLAM institutions. This article will review the literature from 2017 to 2022 dealing with blockchain and NFTs in the heritage sector. Topics covered, proposed models, and projects will be highlighted. Archives are currently leading the research into the use of blockchain technology and have already developed models such as TrustChain. However, libraries, museums, and galleries are also beginning to show an interest in the new technology and its potential benefits. Therefore, we also approached the GLAM sector as a whole, to emphasize the importance of the joint development on the advancement of shared approaches and protocols in utilizing blockchain technology to enhance the trustworthy management and preservation of digital resources. This is particularly important because GLAM institutions care for a shared heritage and serve a common audience. In the second part of the article we will discuss the proposed uses of the technology and highlight still unexplored topics that should be elaborated in further research. The aim of this paper is to make a synthesis of previous research and bring the potential of blockchain technology and NFTs closer to experts in the heritage field, given that they are still quite unknown.
Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Metaverse is the new virtual world that runs in parallel to the physical world. Multiple verses come together to form a large metaverse where various users, avatars, and devices communicate with one another using various technologies like AR, VR, XR, and MR. The traditional way of implementing these solutions is in a centralized way. Consequently, the authentication mechanisms used in the Metaverse are also centralized. The centralized nature of authentication has many limitations and is prone to authentication security threats. As users and avatars move across various verses in the metaverse, it becomes critical to have a decentralized mechanism for authentication. There are certain decentralized solutions proposed in the literature. But they come with their own limitations. Blockchain is a decentralized ledger technology that can provide an anonymous identity mechanism. In this paper, we propose a Blockchain-enabled architecture for the authentication of Avatars and users. This framework will ensure the decentralized authentication and traceability of the Avatar across the Metaverse. It will help in resolving security issues like impersonation, sever spoofing, identity interoperability, mutual authentication issues, replay, etc.
Despite the widespread use of radio frequency identification and wireless connectivity such as near field communication in electric vehicles, their security and privacy implications in Ad-Hoc networks have not been well explored. This article provides a data protection assessment of radio frequency electronic system in the tire pressure monitoring system (TPMS). It is demonstrated that eavesdropping is completely feasible from a passing car, at an approximate distance up to 50 m. Furthermore, our reverse analysis shows that the staticn-bit signatures and messaging can be eavesdropped from a relatively far distance, raising privacy concerns as a vehicles’ movements can be tracked by using the unique IDs of tire pressure sensors. Unfortunately, current protocols do not use authentication, and automobile technologies hardly follow routine message confirmation so sensor messages may be spoofed remotely. To improve the security of TPMS, we suggest a novel ultralightweight mutual authentication for the TPMS registry process in the automotive network. Our experimental results confirm the effectiveness and security of the proposed method in TPMS.
Paweł Weichbroth, Kacper Wereszko, Helena Anacka, Jolanta Kowal
[Context] The goal of security is to protect digital assets, devices, and services from being disrupted, exploited or stolen by unauthorized users. It is also about having reliable information available at the right time. [Motivation] Since the inception in 2009 of the first cryptocurrency, few studies have been undertaken to analyze and review the state-of-the-art research and current developments with respect to the security of cryptocurrencies. [Purpose] We aim to provide both theoretical and empirical insights into the security landscape, in particular focusing on both technical solutions and human-related facets. [Methodology] We used an integrative review which could help in building science and scholarly research, the basis for conceptual and empirical models. [Results] Successful defense against cyberattacks depends on technical measures on the one hand, as well as on self-education and training with the aim to develop competence, knowledge, skills and social abilities, on the other. [Contribution] Our findings provide a comprehensive review for the major achievements and developments of the recent progress on the security of cryptocurrencies. [Future research] Since there is increasing interest in adoption of the current solutions within the central bank digital currencies, the future research should explore the development and inception of effective measures against social engineering attacks, which still remain the main concern.
In recent years, Internet of Things (IoT) technology has gained a lot of attention. With the development of IoT technology, it comes the need for devices with different trust domains to interact and collaborate. In order to protect the security and reliability of the communication between devices in different trust domains, it raises the concerns about the technology of cross-domain authentication. Traditional cross-domain authentication methods may lead to heavy key management overhead or depend on trusted third parties, while existing blockchain-based cross-domain authentication schemes do not prevent the possibility of mischief by malicious domain managers. In this article, we design an efficient Blockchain and trusted execution environment (TEE)-assisted secure device authentication scheme for cross-domain IoT system, called blockchain and TEE-assisted authentication. Our solution solves the problem that managers are not fully trusted, which in turns protect the security and reliability in the blockchain-based cross-domain communication. Specifically, blockchain is introduced to build trust between different domains, the identity-based signatures are used to verify the identity information of devices and the TEE is introduced to prevent the possibility of mischief by domain managers. Finally, our experiments show that the introduction of TEE has greatly improved system security with a low-efficiency reduction, which proves that our scheme can achieve highly secure distributed IoT authentication.
Controlled drugs are drugs that when used ethically may prove life-saving for patients but these drugs also have the potential for abuse, misuse, and addiction. Controlled drugs are under strict government regulations, but still few people manage to diverge these drugs from the ethical system. Few recent techniques that are considered for administration of controlled drugs are Electronic Health Records (EHR), Machine Learning and Advanced Analytics, IOT, etc. But the techniques mentioned above have some disadvantages such as EHR is centralized, ML requires high computing power and is less scalable, IOT devices are expensive and are vulnerable to cyber-attacks thus compromising sensitive information. The system proposed in this paper uses an Ethereum blockchain for administration of controlled drugs. Blockchain ensures transparency, traceability, immutability, decentralization and security in the system.
Md Ahmad, Gautami Tripathi, Farheen Siddiqui, Mohammad Afshar Alam · 7 authors
The overwhelming popularity of technology-based solutions and innovations to address day-to-day processes has significantly contributed to the emergence of smart cities. where millions of interconnected devices and sensors generate and share huge volumes of data. The easy and high availability of rich personal and public data generated in these digitalized and automated ecosystems renders smart cities vulnerable to intrinsic and extrinsic security breaches. Today, with fast-developing technologies, the classical username and password approaches are no longer adequate to secure valuable data and information from cyberattacks. Multi-factor authentication (MFA) can provide an effective solution to minimize the security challenges associated with legacy single-factor authentication systems (both online and offline). This paper identifies and discusses the role and need of MFA for securing the smart city ecosystem. The paper begins by describing the notion of smart cities and the associated security threats and privacy issues. The paper further provides a detailed description of how MFA can be used for securing various smart city entities and services. A new concept of blockchain-based multi-factor authentication named "BAuth-ZKP" for securing smart city transactions is presented in the paper. The concept focuses on developing smart contracts between the participating entities within the smart city and performing the transactions with zero knowledge proof (ZKP)-based authentication in a secure and privacy-preserved manner. Finally, the future prospects, developments, and scope of using MFA in smart city ecosystem are discussed.
Many classical cryptographic techniques are breakable due to the quantum computing security threats, and it leads to design public key cryptography based on post-quantum cryptography primitives and security protocols. In recent years, Lattice-Based Cryptography (LBC) becomes a prominent post-quantum cryptographic primitive that can be applied in both traditional and emerging security domains, including encryption, key agreement, digital signature and homomorphic encryption. In this article, we first provide a LBC-based security framework using aggregate signature that can be applied in ambient intelligence-assisted blockchain-based Internet of Things (IoT) applications, called LAS-AIBIoT. In LAS-AIBIoT, the wearable/medical devices deployed in the patients' body securely send the sensing secret data (encrypted messages) with their respective lattice-based signatures to their nearby controller nodes (CN), where the CNs forward these secret messages to the attached aggregator node (Aggr). Each Aggr verifies the individual signature of the devices and constructs the aggregate signature on the received secret messages and signatures, and sends the aggregated secret messages with their aggregate signature to the cloud server(s) for block construction in the blockchain center. Through the consensus protocol, the block is then mined and added into the blokchain. We show the robustness of LAS-AIBIoT against various potential attacks including quantum computing security threats through the threat model discussed in this article. Finally, through the blockchain-based simulation study we show that LAS-AIBIoT can be applied for real-time ambient intelligence-assisted IoT applications.
Cryptography and Data Security
User Authentication and Security Systems
Advanced Steganography and Watermarking Techniques
Non Fungible Tokens (NFTs) are among the most promising technologies that have emerged in recent years. NFTs enable the efficient verification and ownership management of digital assets and therefore, offer the means to secure them. NFT is similar to blockchain that was first used by the cryptocurrency and then by numerous other technologies. At first, the NFT concept attracted the attention of the digital art community. However, NFT has the potential to enable a plethora of different applications and sce We present a review of the NFT technology. We describe the basic components of NFTs and how NFTs work. Then, we present and discuss the different applications of the NFTs. Finally, we discuss various challenges that the NFT technology must address in the future.
Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
The Internet of Things (IoT) is ubiquitous in our lives. However, the inherent vulnerability of IoT smart devices can lead to the destruction of networks in untrustworthy environments. Therefore, authentication is a necessary tool to ensure the legitimacy of nodes and protect data security. Naturally, the authentication factors always include various sensitive users’ information, such as passwords, ID cards, even biological information, etc. How to prevent privacy leakage has always been a problem faced by the IoT. Zero-knowledge authentication is a crucial cryptographic technology that uses authenticates nodes on the networks without revealing identity or any other data entered by users. However, zero-knowledge proof (ZKP) requires more complex data exchange protocols and more data transmission compared to traditional cryptography technologies. To understand how zero-knowledge authentication works in IoT, we produce a survey on zero-knowledge authentication in privacy-preserving IoT in the paper. First, we overview the IoT architecture and privacy, including security challenges and open question in different IoT layers. Next, we overview zero-knowledge authentication and provide a comprehensive analysis of designing zero-knowledge authentication protocols in various IoT networks. We summarize the advantages of ZKP-based authentication in IoT. Finally, it summarizes the potential problems and future directions of ZKP in IoT.