In the rapidly evolving environment of wireless medical sensor networks (WMSN) and the internet of medical things (IoMT), remote medical support has seen unprecedented advancements. It is essential that the data relayed from the sensors must be trustworthy and unaltered, and that the sensors themselves are genuine. Wireless networks, however, have inherent vulnerabilities. In addition, since WMSN is directly linked to patients’ lives, its continuous availability is crucial. Considerable efforts have been made to maintain the integrity and authenticity of such data. However, many studies have failed to address the problem of a single point of failure (SPOF). This issue has been particularly detrimental to patients who require ongoing management. To address this issue and ensure the protection of the authenticity and integrity of patient data, we suggest the implementation of an authentication scheme based on blockchain technology. In 2022, Yu et al. introduced a blockchain-integrated authentication and key generation scheme for WMSN using Physical Unclonable Functions (PUFs), effectively addressing the SPOF problem by conducting mutual authentication through smart contracts without relying on centralized servers. Our research found that this scheme inadvertently shared critical parameters, including challenge-response pairs and important private keys, with the blockchain network, making it vulnerable to various breaches. We present an enhanced protocol designed to mitigate these security challenges. By limiting the data interaction with smart contracts and ensuring only relevant parties access crucial parameters, our approach reduces the risk of public information disclosure on the blockchain. This not only mitigates the SPOF issue but also efficiently helps in prevention of physical attacks. We prove that our proposed system prevents known security vulnerabilities through informal and formal analysis using the Scyther, Proverif, and BAN logic. Furthermore, the proposed scheme offers 67.37% reduction in computation costs and 3.67% in communication costs, presenting an efficient and secure solution for WMSN in the IoMT landscape.
Zero-knowledge SNARKs have become an extremely studied topic in cryptography due to their recent applications in modern cryptocurrencies. Most of these protocols are created using Polynomial Commitment Schemes such as the KZG protocol by Kate, Zaverucha, and Goldberg (ASIACRYPT 2010). Until recently, the known proofs of ex- tractability of the KZG protocol were either in idealized models or under very strong assumptions. This year, Lipmaa, Parisella, and Siim (EUROCRYPT 2024) proved the KZG protocol to be Special Sound and Black-Box Extractable in the standard model under their new ARSDH assumption. In this thesis, we build upon the work of Lipmaa et al. to prove Special Soundness for the bivariate version of the KZG polynomial commitment. To this end, we generalise their ARSDH assumption and define Special Soundness for the Bivariate KZG polynomial commitment. We then prove that the Bivariate KZG polynomial commitment achieves the Special Soundness under the ARSDH assumption and our generalisation of the AR- SDH assumption. Finally, we give a more refined analysis of the running time of the black-box extractor from Lipmaa et al. 1
We present a password‐authenticated (2, 3)‐threshold group key share (PATS) mechanism. Although PATS resembles threshold secret sharing schemes, it has a different structure. The innovative perspective of the PATS mechanism that makes a difference from the standard secret‐sharing schemes is that it involves parties in the generation of the shares. PATS allows parties to communicate securely to establish their shares over insecure channels. Parties (shareholders) construct a secret (key) using shares obtained at the end of the protocol. PATS takes advantage of zero‐knowledge proofs compared to well‐known threshold key exchange schemes and will tolerate the existence of semi‐trusted parties. We present two variants of PATS, centralized and distributed, and then generalize PATS to ( t , n )‐threshold scheme. PATS supports the distributed operation and optionally facilitates group key verification by a trusted third party, which may also partake in group key sharing. In this paper, we present PATS, which employs finite fields and elliptic curves, along with its security and complexity analyses.
Implantable medical devices (IMDs) in medical sciences have provided a quantum leap in network transformation. The communication network with IMDs typically has a wireless radio frequency (RF) telemetry or wired connection. IMDs, being devices, have more computing, communication capabilities and decision-making. Furthermore, these devices are being used to improve patients’ quality of life by medicating various chronic diseases. The captured data is stored in a medical server through a controller node. Our work focuses on wireless communication, so sensitive patient data over a public channel might be tampered with or eavesdropped by unauthorised access. Furthermore, the leakage of health data and malfunctioning of IMDs are vital in constructing cryptographic protocols, particularly in the design of remote user authentication. In this paper, we proposed a novel secure remote user authentication scheme using a lightweight consortium blockchain for the communication network with IMDs.
Xiaoqin Feng, Fuliang Lin, Tao Feng, Jianfeng Ma · 6 authors
Secure and efficient identity authentication is a fundamental requirement in vehicular ad-hoc networks (VANETs); however, it remains challenging due to the highly dynamic network topology, stringent latency constraints, and the need for conditional privacy preservation. Existing authentication schemes either rely on public key infrastructures (PKI) with complex certificate management or introduce partially decentralized designs that still depend on trusted authorities, leading to inefficiencies and single points of failure. In this paper, we propose EBDA, an Ethereum-based fully distributed authentication mechanism for VANETs. The core innovation of EBDA is to replace the traditional PKI certificate system with a blockchain-maintained Graph of Trust (GoT). Through three dedicated smart contracts, EBDA fully decentralizes the management of vehicle identities and pseudonyms. Vehicles use pseudonyms to preserve privacy in Vehicle-to-Vehicle communications, while authentication is achieved certificate-free via transitive trust within the GoT. Importantly, latency-sensitive operations like message verification are executed off-chain through local checks, meeting VANETs’ strict real-time requirements. A prototype implementation and extensive evaluations demonstrate that EBDA significantly reduces authentication latency by at least 22.93% compared with representative blockchain-assisted and PKI-based baselines while maintaining low computational and storage overhead. These results confirm the feasibility of deploying GoT-based decentralized authentication in practical VANET environments.
Radio Frequency Identification (RFID) promotes the fundamental tracking procedure of the Internet of Things (IoT) network due to its autonomous data collection as well as transfer incurring low costs. To overcome the insecure exchange of tracking data and to prevent unauthorized access, parallel dependency RFID grouping-proof protocol is applied by the reader to authenticate tags simultaneously. However, conventional grouping-proof authentication schemes are not sufficient for the memory constraint RFID tags due to the recurrent utilization of a 128-bit PRNG (Pseudo Random Number Generator) function. Alternatively, the existing parallel-dependency grouping-proof schemes are not able to overcome numerous limitations regarding session establishment, efficient key management, and multicast message communication within the specified group. In this research, a lightweight, secure, and efficient communication protocol is proposed to overcome the aforementioned limitations using Elliptic Curve Cryptography (ECC) and Zero-Knowledge property to establish a session key among the participated tags, reader, and remote server. The proposed scheme can work in offline mode. The proposed ECC-based parallel dependency grouping-proof scheme is referred to as ECC-PDGPP which abides by the rules of the EPC class-1 gen-2 (C1 G2) standard of RFID tags. Finally, the proposed protocol is analyzed using a formal random oracle model and simulated using a well-known AVISPA simulation tool that shows the proposed scheme is well protected against all potential security threats.
How to safely and anonymously interact with fog nodes’ charging stations is a big deal for hybrid electric vehicles in fog-based vehicular networks. Although there exist key exchange protocols, which tried to cover this critical concern, most of them are certificate-based. In addition, they do not support key revocation option or cannot totally resist advanced cyber attacks such as key compromise impersonation attack. As a result, this paper, by means of Blockchain, proposes a highly-secure self-certified key exchange protocol with an exceptional level of privacy. By the proper employment of distributed ledger, the suggested protocol can also support the authentication token revocation and immutability. Formal security and performance analyses as well as comparison with top scholarly articles demonstrate the distinct security features and applicability of the proposed protocol.
Ірина Стрелковська, Олексій Онацький, Лариса Григорівна Йона
Background. To ensure the protection of the biometric access control system used in unsecured communication channels, it is necessary to exclude the storage and transfer, transfer of biometric data as well as sequences generated on their basis. The paper proposes a cryptographic protocol of two-factor authentication with the zero-knowledge over the extended field GF(2m) on elliptic curves using biometric data and the private key of the user. Objective. The aim of the article is to develop a cryptographic protocol for zero-knowledge two-factor authentication based on elliptic curves using biometric data and the user’s private key, which allows increasing cryptographic strength and reducing the duration of the authentication process. Methods. The process of implementing zero-knowledge proof protocols is as follows: one user (proofer) can convince another user (verifier) that he has some secret without disclosing the secret itself. Results. A cryptographic protocol for two-factor authentication with zero-knowledge over the extended field GF(2m) of elliptic curves using user biometric data is proposed, which significantly reduces the size of the protocol parameters and increases cryptographic strength (computational complexity of the breaking). There is no leakage of private key information and biometric data of the user during the execution of the zero-knowledge proof protocol. Conclusions. The implementation of a cryptographic protocol with zero-knowledge proof two-factor authentication based on elliptic curves allows significantly reducing the size of protocol parameters and increasing the cryptographic strength (computational complexity of the breaking).
Abdelrahman Mustafa El-Feky, A. Alavudeen Basha, Karim Mohamed Gomaa, Youssef Ashraf El-Etreby · 6 authors
Authentication is the indispensable key process of identifying a user's identity who's using a service, traditionally using passwords. As the number of services grew, password managers have, since then, been used to manage users' passwords. Traditional centralized password managers have proven their inefficacy in securing a user's password and have failed to keep up with the newer security demands, owing to their centralized architecture and reliance on quantum-vulnerable authentication methods. In this paper, an authentication manager is proposed whose model deploys a zero-trust and zero-knowledge architecture, blockchains, hardware authentication, and quantum-proof algorithms to keep up with the modern security demands. The proposed model has eliminated the single point of failure using decentralization, utilized passkeys, and deployed quantum-proof cryptographic algorithms.
Vehicular Ad-Hoc Networks (VANETs) are a prominent technology in the drive towards establishing smart transportation systems in the Digital Transformation (DX) era. These networks provide users with critical road information for optimal route selection and accident avoidance. However, the openness of VANETs environment makes them susceptible to various cyber threats. Therefore, authenticating the entities that join the network is necessary and crucial for ensuring the security and integrity of VANET communications. Kerberos is one of the authentication protocols that ensure security, as the password and key are never directly sent among the entities. However, ensuring secure and efficient authentication, especially in VANET handovers, remains a challenge. This paper introduces an innovative authentication system for VANETs that leverages the combined power of blockchain and Kerberos. The system stores Kerberos authenticator messages in a distributed ledger within the blockchain, accessible to Trusted Authorities (TAS) and all RSUs. This approach streamlines vehicle handovers and safeguards authenticator messages against adversarial tampering. It exhibits minimal signalling overhead and authentication delay, ensuring swift and secure authentication processes. We verify the proposal’s effectiveness by simulating the VANETs environment with 100 vehicles, 4 RSUs, and 1 TAS using Omnet++ with the Tsushima, Japan area map.
Firas Hamila, Mohammad Hamad, Daniel Costa Salgado, Sebastian Steinhorst
Abstract With the rapid expansion of IoT devices and their applications, there is an increasing demand for efficient and secure authentication mechanisms to protect against unauthorized access. Traditional authentication mechanisms face limitations regarding computational speed, communication costs, and vulnerability to cyber-attacks. Zero-knowledge proof (ZKP) protocols have emerged as an effective solution for achieving secure and efficient authentication in such environments without revealing sensitive information. Among ZKP protocols, $$\Sigma $$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>Σ</mml:mi> </mml:math> -protocols, a class of interactive ZKP protocols, have been employed for their efficiency and security. However, their interactive nature necessitates multiple rounds of communication, which can reduce efficiency and increase communication overhead for resource-constrained devices. Many works have aimed to eliminate the interaction of $$\Sigma $$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>Σ</mml:mi> </mml:math> -protocols by utilizing a transformation called the Fiat–Shamir transformation (FST). However, there is still a concern regarding the soundness of the FST as it can sometimes convert a secure $$\Sigma $$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>Σ</mml:mi> </mml:math> -protocol into an insecure non-interactive zero-knowledge (NIZK) authentication scheme. In this paper, we propose an approach for transforming $$\Sigma $$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>Σ</mml:mi> </mml:math> -protocols into a NIZK protocol based on the FST, yielding significant enhancements in efficiency, communication overhead reduction, and elimination of interaction. Our proposed protocol enables the completion of the authentication process in a single request while also strengthening the soundness of $$\Sigma $$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>Σ</mml:mi> </mml:math> -protocols in comparison with the traditional FST by requiring two authentication factors instead of one. To demonstrate our approach’s robustness, we conducted comprehensive informal and formal security analyses (using the Tamarin-Prover). Our protocol demonstrated completeness, soundness, zero-knowledge properties, and robustness against attacks, including eavesdropping, message modification, replay, and brute force attacks. Additionally, our performance analysis displayed a remarkable 50% improvement in computational cost compared to traditional $$\Sigma $$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>Σ</mml:mi> </mml:math> -protocols, underscoring its efficiency for practical use.
Alexandr Kuznetsov, Emanuele Frontoni, V. A. Katrich, Olena Kobylianska · 5 authors
Existing digital identification systems are often vulnerable to attacks as they are commonly based on authentication methods such as passwords, PIN codes, biometric data, etc., which can be easily forged or compromised. In this letter, we propose a digital identification system based on a unique set of user biometric data processed by Artificial Intelligence (AI) and fuzzy extractors to generate a cryptographically secure password linked to a unique Non-Fungible Token (NFT). Our system provides decentralized identification based on blockchain technology, which eliminates problems associated with centralized identification systems, such as cyber-attacks on central servers and data leaks. Our proposed system offers a higher level of user identification security by linking the user to their data through a unique NFT, generating a cryptographically secure password, and processing large volumes of biometric data using AI and fuzzy extractors. Our system provides a solution to many of these problems, making it important and relevant to many industries, including banking, medical, and financial sectors. The use of decentralized storage of information on the blockchain provides a high level of protection against hacking and reduces the likelihood of data breaches, making our system particularly relevant in the field of financial services and personal data protection.
The article deals with the topic of trust architecture in apparel supply chains in the context of the transition to WEB3 protocols. The authors analyze the possibilities of blockchain technologies and decentralized systems to improve management and interaction processes, increase transparency and traceability of goods, reduce costs and risks. Special attention is given to the creation of a trustworthy environment for all participants in the supply chain through a trust architecture.