In Internet of Things (IoT)-based e-Health Systems (IoTEHS), medical devices form a large network that continuously sense and share the healthcare data with the nearby edge devices or cloud servers. The health data is subsequently made available to various IoTEHS stakeholders (such as doctors, nurses and patients) to track and monitor patients under observation. However, the entire IoTEHS stakeholders communicate with each other over a wireless unsecured public communication channel. This is a major security and privacy loophole wherein the attacker can exploit the vulnerability of the system and can launch various attacks on the ongoing communication. Motivated by the aforementioned challenges, a secure data dissemination scheme using AI and blockchain is proposed. In this scheme, the transaction collected through healthcare sensors installed around the patients premises act as data sets that is forwarded to the nearby edge devices. The collected data is first filtered using AI-based intrusion detection system located at the edge of the network. Second, a secure health monitoring network is designed using blockchain. Specifically, the filtered or normal transactions are transmitted to centralized cloud servers where the smart contact-enabled consensus mechanism is used to validate the transactions. Once the transaction gets validated, it is stored on distributed InterPlanetary File System (IPFS) of cloud and returned transaction hash is stored on the blockchain ledger located at edge devices making data exchange faster. The detailed experimental investigation demonstrates that the proposed schemes are efficient (in terms of computing and processing time) as well as its resistance to a variety of security attacks.
Rashidah Funke Olanrewaju, Burhan Ul Islam Khan, Miss Laiha Mat Kiah, Nor Aniza Abdullah · 5 authors
The inclusion of mobility-based Internet-of-Things (IoT) devices accelerates the data transmission process, thereby catering to IoT users’ demands; however, securing the data transmission in mobility-based IoT is one complex and challenging concern. The adoption of unified security architecture has been identified to prevent side-channel attacks in the IoT, which has been discussed extensively in developing security solutions. Despite blockchain’s apparent superiority in withstanding a wide range of security threats, a careful examination of the relevant literature reveals that some common pitfalls are associated with these methods. Therefore, the proposed scheme introduces a novel computational security framework wherein a branched and decentralized blockchain network is formulated to facilitate coverage from different variants of side-channel IoT attacks that are yet to be adequately reported. A unique blockchain-based authentication approach is designed to secure communication among mobile IoT devices using multiple stages of security implementation with Smart Agreement and physically unclonable functions. Analytical modeling with lightweight finite field encryption is used to create this framework in Python. The study’s benchmark results show that the proposed scheme offers 4% less processing time, 5% less computational overhead, 1% more throughput, 12% less latency, and 30% less energy consumption compared to existing blockchain methods.
Dec 1, 2022·2022 IEEE 24th Int Conf on High Performance Computing & Communications; 8th Int Conf on Data Science & Systems; 20th Int Conf on Smart City; 8th Int Conf on Dependability in Sensor, Cloud & Big Data Systems & Application (HPCC/DSS/SmartCity/DependSys)
Digital technologies, such as wireless body area networks (WBANs) for mobile health (mHealth) applications, are expected to enhance the quality of the public health care system. Although mHealth can improve patients' quality of health by offering outpatient real-time health monitoring systems instead of being stuck in the hospital all the time to monitor chronic diseases. The major challenge in adopting mHealth is data security and privacy. The health data routed on the internet from the patient monitoring device to the health center for remote monitoring is vulnerable to confidentiality attacks. To handle this issue, we present an authentication scheme based on non-interactive zero-knowledge proof (NIZKP), which issues certificates and authenticates monitoring devices each time performing transactions without revealing sensitive information. Our authentication scheme provides a high level of security with a low computational cost, which is lightweight for WBANs.
Muhammad Bilal Akram Dastagir, Omer Tariq, Dongsoo Han
The adaption of the NFT to the mainstream web3 marketplace has led to the rise of challenges like authenticity and verification. On the other hand, privacy-preserving is one of the important research topics in the data-driven metaverse due to its anonymity while maintaining transparency and security. As the traditional method does not preserve privacy, there is a dire need for a novel privacy-preserving method for NFT authentication while preserving anonymity, transparency, and security. This paper proposes a smart card-based approach for privacy preservation authentication of Non-Fungible Tokens using Non-Interactive Zero Knowledge Proof (NIZKP). The paper presents a Novel NIZKP response with the integration of challenge and proof with the encapsulation of a time-based one-time password (TOTP) solution to address the most critical problem of the proof of the source of the NFT and its rightful owner. The proposed solution is a lightweight mechanism for preventing unauthorized and hostile agents from the accessibility of the system while maintaining privacy and anonymity along with the verification and authenticity of the NFT. We have implemented our approach and compared the communication overhead and functional security features with related work and its precedence over them. The results show that the proposed approach has less communication overhead than the existing work and fulfills all the functional security and privacy-preserving features. It indicates that the proposed method can be an ideal solution for NFT authentication and transaction among users.
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Jaewon Noh, Yongseok Kwon, Junggab Son, Sunghyun Cho
One significant security challenge in vehicular networks is defending against malicious members’ attacks, including insiders and compromised authorities. Insiders are legitimate vehicles who have passed the registration process. Since they can exploit all the information related to the network and other members’ communication, it is easier to perform various attacks with a high impact. In addition, an authority takes charge of registering and managing legitimate vehicles. Thus, if the authority is compromised, it will cause significant damage to the system, including the leaking of private information, such as identity, location, and membership. Many authentication schemes have been proposed to protect vehicular communication from these security issues. However, most existing schemes still face the vulnerability of malicious members. Furthermore, most conventional schemes require additional interactions between the vehicles and infrastructure for authentication, which can cause communication overheads. To overcome these issues, we propose a novel blockchain-based one-time authentication scheme to protect vehicular communication against malicious members. One-time authentication provides higher security and efficiency as every message is authenticated with different proof at a time. We use publicly verifiable secret sharing with blockchain for this property, which brings two benefits. First, it prevents even an authority from obtaining members’ identities by distributing encrypted shares instead of their real identities. Second, it enables robust vehicular communication against insiders’ attacks by allowing a vehicle to send unique proof generated from its private information with messages. Receivers can authenticate the messages by comparing attached values to the information through the blockchain in a noninteractive manner. Security analysis shows that our scheme assures secure vehicle-to-everything communication against insider attacks, and efficiency analysis shows how both authentication and consensus delay change.
Jie Cui, Nan Liu, Qingyang Zhang, Debiao He · 6 authors
The rapid development of the Industrial Internet of Things (IIoT) has realized the intelligence of industrial manufacturing and improved production efficiency. For improved collaboration, devices from different management domains (e.g., factories) connected through various communication technologies exchange information and share resources. However, they face security and privacy issues when cross-domain communication requires authentication. The limitations of existing schemes include the risk of a single point of failure in a trusted center, leakage of device privacy, high certificate management costs, and low authentication efficiency. Because blockchain with features such as decentralization and tamper-proof can effectively solve some of these problems, we design an efficient and anonymous cross-domain authentication scheme based on blockchain to achieve reliable communication between cross-domain IIoT devices. Specifically, our scheme improves authentication efficiency while enabling device anonymity to ensure that identities are not linkable, and combines blockchain and dynamic accumulator technology to achieve fast authentication. Security analysis demonstrates that our scheme can resist common attacks, and a performance evaluation proves its feasibility and efficiency.
Ali Zouaghi Yousra, Mahamdioua Meriama, Atidel Lahoulou
Biometric authentication methods generally rely on centralized authority such as centralized database servers to store biometric templates and manage authentication. These methods suffer from different points of attack. If the central entity is compromised, the system becomes vulnerable and unable to ensure integrity of stored templates. This paper proposes a distributed scheme of biometric authentification, eliminating the need for a central entity. The proposal is based on the Ethereum blockchain, which offers decentralized and irreversible properties for the storage and management of biometric templates. For each user, the fingerprint template is encrypted using homomorphic encryption and stored on the smart card. The hashed encrypted vector is then stored on the blockchain to ensure its confidentiality. Our proposed scheme, allows authentication of users using a smart contract, while the distance calculation is performed on the encrypted domain that achieves the integrity of the calculation results. By using hashed vectors, the proposal is efficient and cost-effective. These improvements provide solutions to many problems in biometric systems such as template modification, channel interception, and override comparator.
Biometric Identification and Security
Advanced Steganography and Watermarking Techniques
Advancement in the Internet of Things (IoT) and cloud computing has escalated the number of connected edge devices in a smart city environment. Having billions more devices has contributed to security concerns, and an attack-proof authentication mechanism is the need of the hour to sustain the IoT environment. Securing all devices could be a huge task and require lots of computational power, and can be a bottleneck for devices with fewer computational resources. To improve the authentication mechanism, many researchers have proposed decentralized applications such as blockchain technology for securing fog and IoT environments. Ethereum is considered a popular blockchain platform and is used by researchers to implement the authentication mechanism due to its programable smart contract. In this research, we proposed a secure authentication mechanism with improved performance. Neo blockchain is a platform that has properties that can provide improved security and faster execution. The research utilizes the intrinsic properties of Neo blockchain to develop a secure authentication mechanism. The proposed authentication mechanism is compared with the existing algorithms and shows that the proposed mechanism is 20 to 90 per cent faster in execution time and has over 30 to 70 per cent decrease in registration and authentication when compared to existing methods.
Blockchain technology has a significant application in smart farming due to its immutability, decentralization and transparency properties. Data exchanged in an Internet of Things (IoT)-based smart agriculture can be used to remotely monitor the fields and regulate the crop needs for optimal productivity. However, such data is sensitive to several attacks, such as man-in-the-middle attack, replay attack, ephemeral secret leakage attack, impersonation attack and denial of service (DoS) attack. The existing solutions to counter these attacks are either costly or lack significant security features. To mitigate these issues, we design a novel lightweight blockchain based authentication scheme based on a fully decentralized and distributed architecture. The designed scheme is subjected to a rigorous security analysis and also a formal security verification using the widely-used Automated Validation of Internet Security Protocols and Applications (AVISPA) tool, and it is shown that the scheme is robust and secure against various passive and active attacks. A detailed comparative analysis shows that the proposed scheme has the low communication cost and significantly lower computation cost while satisfying all the security and functionality features as compared to those for other existing relevant schemes.
The Biometric system can be understood as a system that deals with an automated recognition of individual based on their physiological aspects (face, fingerprints, iris, retina) and behavioral patterns (signature, posture etc.). Biometric system works on feature extraction and feature matching. The feature is extracted in the form of fingerprints, iris and retina and then it is matched by the information stored by measuring the same patterns of particular individual, this process is feature matching. Between the two, works template database which is a central point from where every time the feature extracted is matched for confirming the identity of a person.. If the database is breached by the hacker, then the data could be used for falsifying the identity of the person. The paper focuses to implement blockchain technology in a biometric system in a manner that every record of individual is maintained using a blockchain so that it can’t be hampered by the hacker. Blockchain works as adecentralized repository of data which we assume to be the most suitable approach to hold the credentials of individuals and thus avoiding an unauthorized access to the systems. Making changes to blockchain is a complex and time-consuming task for any unwanted user. Many researchers contributed their work highlighting the security issues of the biometric system when applied practically. They noted that the fingerprint of an individual remains the same over life and once applied can’t be modified when compares with non-biometric systems which makes use of passwords and if forgotten or breached could be changed. Some of them conveyed that the biometric system is safe when only considering its physical implementation but the database created is still under threat.
Biometric Identification and Security
User Authentication and Security Systems
Advanced Steganography and Watermarking Techniques
Cooperative perception is an essential and widely discussed application of connected automated vehicles. However, the authenticity of perception data is not ensured, because the vehicles cannot independently verify the event they did not see. Many methods, including trust-based (i.e., statistical) approaches and plausibility-based methods, have been proposed to determine data authenticity. However, these methods cannot verify data without a priori knowledge. In this study, a novel approach of constructing a self-proving data from the number plate of target vehicles was proposed. By regarding the pseudonym and number plate as a shared secret and letting multiple vehicles prove they know it independently, the data authenticity problem can be transformed to a cryptography problem that can be solved without trust or plausibility evaluations. Our work can be adapted to the existing works including ETSI/ISO ITS standards while maintaining backward compatibility. Analyses of common attacks and attacks specific to the proposed method reveal that most attacks can be prevented, whereas preventing some other attacks, such as collusion attacks, can be mitigated. Experiments based on realistic data set show that the rate of successful verification can achieve 70\% to 80\% at rush hours.
Blockchain-based traceability systems are a promising approach because they are decentralized, transparent, and tamper proof; however, if all traceability data are uploaded to a blockchain platform, it may affect the efficiency or even lead to data explosion. Additionally, it is difficult to guarantee the reliability of the original data source of massive Internet of Things (IoT) devices. Furthermore, when different enterprise nodes adopt different data storage structures, the costs that are associated with data sharing will increase. In this paper, we have proposed a trustworthy product traceability system that is based on hyperledger fabric and Electronic Product Code Information Service (EPCIS), which is not only capable of making products traceable, but it can also authenticate and authorize the IoT devices that are used for data collection. First, we adopted the on-chain and off-chain collaborative management mechanism in order to alleviate data explosion on the chain. Second, we proposed a scheme to authenticate and authorize devices based on blockchain. Third, we complied with EPCIS and Core Business Vocabulary (CBV) standards and provided the EPCIS location discovery service in order to improve the interactivity. Finally, we implemented and tested the proposed traceability system and compared it with the existing research. The proposed solution provides product information traceability, data tamper proofing, data confidentiality, and data source reliability.
Constant advancements in technology have a significant impact on our everyday lives and the ecosystem in which we live. The growing popularity of cryptocurrencies (e.g., Bitcoin and Ethereum), along with Non-Fungible Tokens (NFTs), which are founded on blockchain technology, has opened the way for these blockchain projects to be integrated into a wide range of other kinds of applications (apps). Today, cryptocurrencies are used as a popular method of payment online; however, their popularity on the dark Web is also increasing. For example, they can be used to buy and perform various illegal activities among criminals due to their anonymity. Web3 cryptocurrency wallets, used to store cryptocurrencies, have not been studied as thoroughly as many other apps from a digital forensic perspective on mobile devices, given the increasing number of these services and apps today for many platforms, including the leading mobile operating systems (i.e., iOS and Android). Therefore, the purpose of this research is to guide investigators to unlock the full potential of popular cryptocurrency Web3 wallets, Trust Wallet and Metamask, to understand what can be recovered, and to look at areas where there are knowledge gaps. We digitally analyzed and forensically examined two mobile wallets that do not require any personal identifiers to register and are widely used for Web3 cryptocurrencies on Android and iOS devices. We review the digital evidence we have collected and discuss the implications of the forensic tools we have used. Finally, we propose a proof of concept extension to the iOS Logs, Events, And Plists Parser (iLEAPP) tool to automatically recover artifacts.
Regulating illegal activities in cyberspace to balance user privacy and cyberspace governance has been a non-trivial challenge when designing anonymous authentication solutions. For example, while several existing anonymous authentication protocols support accountability, they either risk leaking users' private keys or incur significant overhead for accountability in each ongoing authentication, including in cloud service-based authentication schemes. Seeking to address these limitations, this paper proposes an auditable anonymous user authentication (A2UA) protocol based on blockchain for cloud services. The A2UA protocol mainly employs bilinear pairing, partial authentication factors, dynamic credits and fake-public keys (FPKs) to achieve anonymous mutual authentication between users and cloud service providers, and applies ring signature and blockchain to accomplish two-level accountability while maintaining user privacy. Our analysis results show that the A2UA protocol outperforms several other existing schemes in terms of security, computation and communication costs as well as security and privacy features. Additionally, it has good feasibility in terms of the Ethereum Gas cost as demonstrated in our evaluation.
Wireless Sensor Networks (WSNs) are becoming more popular for many applications due to their convenient services. However, sensor nodes may suffer from significant security flaws, leading researchers to propose authentication schemes to protect WSNs. Although these authentication protocols significantly fulfill the required protection, security enhancement with less energy consumption is essential to preserve the availability of resources and secure better performance. In 2020, Youssef et al. suggested a scheme called Enhanced Probabilistic Cluster Head Selection (LEACH-PRO) to extend the sensors' lifetime in WSNs. This paper introduces a new variant of the LEACH-PRO protocol by adopting the blockchain security technique to protect WSNs. The proposed protocol (SLEACH-PRO) performs a decentralized authentication mechanism by applying a blockchain to multiple base stations to avoid system and performance degradation in the event of a station failure. The security analysis of the SLEACH-PRO is performed using Burrows-Abadi-Needham (BAN) logic and Automated Validation of Internet Security Protocols and Applications (AVISPA) tool. Moreover, the SLEACH-PRO is evaluated and compared to related protocols in terms of computational cost and security level based on its resistance against several attacks. The comparison results showed that the SLEACH-PRO protocol is more secure and requires less computational cost compared to other related protocols.
The Internet of Medical Things (IoMTs) are critical components in wearable healthcare applications such as bio-systems, rehabilitation robots, activity identification, to name a few. Traditional security measures are unable to protect data from harmful attackers. Patients' privacy may be endangered as a result of eavesdropping, and the diagnosis of life-threatening diseases may be delayed as a result of IoMT device malfunction caused by attacks such as Denial of Service (DoS) attacks. Blockchain has emerged as a possible answer to these problems. The benefits of adopting blockchain based into the healthcare ecosystem include decentralisation, dependability, efficiency, security, and privacy, to name a few. Biometric systems have been rapidly gaining traction in a variety of industries in recent years, and they continue to provide enhanced security for access control systems. In comparison to traditional procedures, security methods based on biometric features give more trustworthiness while requiring less processing. As a result, biometric traits are used in current healthcare systems to implement security in healthcare. This research work proposes a secure blockchain based architecture for IoMT based healthcare applications that can provide decentralized and secure communication while taking into account the constraints listed above. Bio-keys, in combination with biometric authentication are also offered as a way to further enhance the security.
The Nakamoto longest chain protocol is remarkably simple and has been proven to provide security against any adversary with less than 50% of the total hashing power. Proof-of-stake (PoS) protocols are an energy efficient alternative; however existing protocols adopting Nakamoto's longest chain design achieve provable security only by allowing long-term predictability, subjecting the system to serious bribery attacks. In this paper, we prove that a natural longest chain PoS protocol with similar predictability as Nakamoto's PoW protocol can achieve security against any adversary with less than 1/(1+e) fraction of the total stake. Moreover we propose a new family of longest chain PoS protocols with a formal proof of their security against a 50% adversary, while only requiring short-term predictability.
The Internet of Vehicles (IoV) can significantly improve transportation efficiency and ensure traffic safety. Authentication is regarded as the fundamental defense line against attacks in IoV. However, the state-of-the-art approaches suffer from several drawbacks, including bottlenecks of the single cloud server model, high computational overhead of operations, excessive trust in cloud servers and roadside units (RSUs), and leakage of vehicle trajectory privacy. In this paper, BEPHAP, a Blockchain-based Efficient Privacy-preserving Handover Authentication Protocol with key agreement for internet of vehicles, is introduced to address these problems. BEPHAP achieves anonymous cross-domain mutual handover authentication with key agreement based on the tamper-proof blockchain, symmetric cryptography, and the chameleon hash function under a security model that cloud servers and RSUs may launch attacks. BEPHAP is particularly well suited for IoV since it allows vehicles only need to perform lightweight cryptographic operations during the authentication phase. BEPHAP also achieves data confidentiality, unlinkability, traceability, non-repudiation, non-frameability, and key escrow freeness. Formal verification based on ProVerif and formal security proofs based on the BAN logic indicates that BEPHAP is resistant to various typical attacks, such as man-in-the-middle attacks, impersonation attacks, and replay attacks. Performance analysis demonstrates that BEPHAP surpasses existing works in both computation and communication efficiencies. And the message loss rate remains 0 at 5000 requests per second, which meets the requirement of IoV.
Summary Since inception, blockchain has earned significant attention due to its exclusive characteristics and advantages. It has changed the way the transactions are conducted by eradicating the role of third parties and promises to ensure trust among the participants. This technology is emerging as a potential solution to several issues but not without certain security vulnerabilities. In particular, protection of sensitive data is a more critical issue in the absence of a third party. This paper is aimed to report and share the state of the art of sensitive data protection in blockchain applications. The covered aspects include identification of sensitive data, existing techniques to protect sensitive data and to know how real time data compromised by security risks, attacks, threats and vulnerabilities concerning blockchain applications. This paper analysis the tools and techniques used in the past for protecting sensitive data and categorized them. On the basis of research and intuitive findings, methods and techniques are elaborated which can contribute in future in the designing a framework for protection of sensitive data in blockchain applications.
Sensitive data have to be communicated via secure channels generally set up by using cryptography. This needs an authentic key exchange, which in turn requires an authentication process. However, the Internet of Things (IoT) includes its own challenges and security requirements. This paper introduces a novel signature algorithm and handshake protocol combining a zero-knowledge proof method being based on the graph isomorphism problem with an identity-based scheme to provide authentication with integrated key exchange while meeting the IoT challenges and security requirements. Our approach applies a way to parallelly perform multiple rounds usually needed by zero-knowledge proofs while retaining the same security level. Moreover, we present a graph compression algorithm providing a compression ratio of up to ca. 7:1. Our handshake protocol is resistant to active man in the middle attacks and does not require any public data pre-distribution or secret pre-sharing. Additionally, no third party has to hold any device-specific authentication data. Furthermore, our approach is application-independent and does not require any additional components or procedures. This paper also evaluates the high performance of our approach with regard to multiple affecting factors.
While 5G can provide high-speed Internet connectivity and over-the-horizon control for Unmanned Aerial Vehicles (UAVs), authentication becomes a key security component in 5G-enabled UAVs. This is due to fact that the communicating entities in the network mostly uses unsecured communication channel to exchange critical surveillance data. Authentication thus plays a crucial role in the 5G-enabled UAV network, providing a range of security services such as credential privacy, Session-Key (SK) security, and secure mutual authentication. However, transparency, anonymity, traceability and centralized control are few major security requirements that cannot be fulfilled by the traditional authentication schemes. One of the upcoming technologies that can provide a solution for present centralized 5G-enabled UAV network is blockchain-based authentication scheme. Motivated from aforementioned discussion, this paper presents a Permissioned Blockchain empowered Secure Authentication and Key Agreement framework in 5G-enabled UAVs. In this framework, first an authentication phase between UAV-to-UAV, UAV-to-Edge Server (ES) and Edge-to-Cloud Server (CS) supporting mutual authentication and key agreement is proposed. The authenticated surveillance data collected from UAV is used by the peer-to-peer CS for transaction verification, block creation and addition using smart contract-based consensus mechanism. The practical implementation of framework shows the effectiveness of the proposed approach.
The integration of the Internet of Things (IoT) with traditional healthcare systems has improved quality of healthcare services. However, the wearable devices and sensors used in Healthcare System (HS) continuously monitor and transmit data to the nearby devices or servers using an unsecured open channel. This connectivity between IoT devices and servers improves operational efficiency, but it also gives a lot of room for attackers to launch various cyber-attacks that can put patients under critical surveillance in jeopardy. In this article, a Blockchain-orchestrated Deep learning approach for Secure Data Transmission in IoT-enabled healthcare system hereafter referred to as “BDSDT” is designed. Specifically, first a novel scalable blockchain architecture is proposed to ensure data integrity and secure data transmission by leveraging Zero Knowledge Proof (ZKP) mechanism. Then, BDSDT integrates with the off-chain storage InterPlanetary File System (IPFS) to address difficulties with data storage costs and with an Ethereum smart contract to address data security issues. The authenticated data is further used to design a deep learning architecture to detect intrusion in HS network. The latter combines Deep Sparse AutoEncoder (DSAE) with Bidirectional Long Short-Term Memory (BiLSTM) to design an effective intrusion detection system. Experiments on two public data sources (CICIDS-2017 and ToN-IoT) reveal that the proposed BDSDT outperformed state-of-the-arts in both non-blockchain and blockchain settings and have obtained accuracy close to 99% using both datasets.