Password-based authentication systems remain the most widely used method for user verification despite being highly susceptible to offline dictionary attacks. To mitigate such attacks, server-aided password-based authentication schemes utilize an independent server, which helps to harden the credentials to be stored on the website database. Existing server-aided password-based authentication schemes rely on number-theoretic assumptions that are vulnerable to quantum-enabled adversaries and incorporate complex computations such as bilinear pairings, exponentiation, and Zero-Knowledge Proofs. In this work, we introduce a novel post-quantum secure server-aided password-based authentication scheme based on the Module Learning With Errors (M-LWE) problem. A defining feature of our protocol is its complete operational transparency as it integrates with existing web interfaces without requiring users to modify their login behaviour or perform additional computation. To ensure long-term resilience, our scheme includes a transparent key rotation mechanism that allows service providers to update the entire credential database with a fresh secret key without user intervention. We provide a formal security analysis in the Real-or-Random (RoR) framework. This analysis demonstrates that our protocol's resistance to offline dictionary attacks reduces to the underlying hardness of the M-LWE problem, and the system achieves forward secrecy through a key rotation mechanism. Through an optimized Number Theoretic Transformation (NTT)-based implementation for faster polynomial multiplications, our empirical analysis demonstrates high computational efficiency, with average registration and authentication latencies of 0.88 ms and 0.96 ms, respectively.
In a metaverse ecosystem composed of various sub-metaverses, each offering unique functionalities and use cases, secure cross-domain communication becomes an essential requirement. Traditional authenticated key establishment (AKE) methods typically rely on centralized servers for identity verification, thus introducing single points of failure and significant latency. While some blockchain-based approaches mitigate these issues, they remain vulnerable to malicious key uploads. This paper proposes a blockchain-assisted identity (ID)-based hierarchical key management system and illustrates a cross-sub-metaverse AKE protocol with provable security to solve single points of failure and the risk of malicious key uploads. The hierarchical structure is designed to manage and categorize usersâ identities. Moreover, smart contracts are used to pre-verify uploaded user identities and public keys on the blockchain, eliminating the need to fully trust identity issuers and preventing erroneous submissions. We implemented a prototype of our proposed blockchain-assisted cross-domain key management scheme, achieving an average execution time of approximately 0.1 seconds per user operation. We also deployed our contract on the Ethereum test network, incurring 1,802k gas for registration and 1,625k gas for key additions/updates. Furthermore, we formally prove the protocolâs security under the extended Canetti-Krawczyk (eCK) model, highlighting its suitability for next-generation metaverse ecosystems.
Decentralized finance (DeFi) has emerged as a transformative paradigm, leveraging programmable blockchains to innovate upon traditional financial services without centralized intermediaries. However, DeFi introduces a unique and highly adversarial security landscape characterized by immutable transactions, complex protocol composability, and transparent execution environments. This survey provides a comprehensive systematization of DeFi security, categorizing vulnerabilities across three distinct layers: technical and code layer, economic and protocol layer, and infrastructure and cross-chain layer. Furthermore, we structure the defense mechanisms according to the protocol lifecycle, including pre-deployment prevention strategies, runtime mitigation techniques, and post-incident response and recovery mechanisms. We also delve into specific phenomena such as maximal extractable value, analyzing its dual role as both a market efficiency tool and a security vector. By synthesizing existing literature and incident reports, this survey establishes a holistic framework for understanding the interplay between code and finance. Finally, we identify critical open challenges and propose future research directions aimed at maturing the discipline of DeFi security and mitigating systemic risks.
Open access
Infrastructure Resilience and Vulnerability Analysis
Shaoyu Li, Hexuan Yu, Shanghao Shi, Md Mohaimin Al Barat · 7 authors
With the growing demand for wireless spectrum, dynamic spectrum sharing (DSS) frameworks such as the Citizens Broadband Radio Service (CBRS) have emerged as practical solutions to improve utilization while protecting incumbent users (IUs) such as military radars. However, current incumbent protection mechanisms face critical limitations. The Environmental Sensing Capability (ESC) requires costly sensor deployments and remains vulnerable to interference and security risks. Alternatively, the Incumbent Informing Capability (IIC) requires IUs to disclose their identities and operational parameters to the Spectrum Coordination System (SCS), creating linkable records that compromise operational privacy and mission secrecy. We propose IU-GUARD, a privacy-preserving spectrum sharing framework that enables IUs to access spectrum without revealing their identities. Leveraging verifiable credentials (VCs) and zero-knowledge proofs (ZKPs), IU-GUARD allows IUs to prove their authorization to the SCS while disclosing only essential operational parameters. This decouples IU identity from spectrum access, prevents cross-request linkage, and mitigates the risk of centralized SCS data leakage. We implement a prototype, and our evaluation shows that IU-GUARD achieves strong privacy guarantees with practical computation and communication overhead, making it suitable for real-time DSS deployment.
We present a comprehensive cryptographic framework for distributed ledger-based authentication that achieves perfect zero-knowledge privacy preservation through homomorphic pairwise verification based on Elliptic Curve ElGamal encryption. Our construction extends the theoretical foundations of homomorphic authentication to practical distributed systems by introducing novel public zero-detection protocols based on bilinear pairings over elliptic curves and threshold secret sharing mechanisms. The system guarantees that authentication succeeds if and only if encrypted credential differences equal the point at infinity, while maintaining computational indistinguishability of authentication transcripts from random distributions. We provide rigorous security proofs demonstrating the system's resistance to adaptive chosen-message attacks, replay attacks, and node compromise scenarios under standard cryptographic assumptions including the Elliptic Curve Discrete Logarithm Problem and the Bilinear Diffie-Hellman assumption. Our performance analysis shows sub-100 millisecond authentication latency with linear scalability properties, making the system suitable for enterprise-grade deployment. The construction enables perfect forward secrecy, unlinkable authentication sessions, and cryptographically verifiable audit trails without compromising user privacy.
Vinod Kumar Joshi, Rajendra Kachhava, Kriti Kamal Gupta, Dixit Dutt Bohra
The quantum-secure CBIR scheme which is presented in this research is a fence against unauthorized users and adversarial attacks on cloud environment remote sensor images. The proposed solution is characterized by Quantum Key Distribution, zero-knowledge proof authentication, QCrypt encryption, adversarial trained deep hashing, and robust watermarking. The model was developed with the help of the MLRSNet dataset, where proposed model recorded a remarkable mean average precision of 94.77% that is 10% improvement from the previous deep-hash results while the watermark-extraction accuracy of over 95% was maintained at 35 dB PSNR. The model has been able provide good result with adversarial, replay, and JPEG compression. Even though the computing engine provides military-grade security and forensic accountability, the current compute overhead is the major reason it has limited use in real-time scenarios.
Ziyang Ji, Jie Zhang, Yuji Dong, Ka Lok Man · 6 authors
Effective management of private keys is crucial to ensure the security and ownership of usersâ data and digital assets in the Web3 environment. However, existing solutions often fail to adequately address private key management from the userâs perspective. Private key leakage and loss incidents occur frequently, resulting in significant losses of digital assets. Moreover, the conventional approach of revoking both the private and public keys after a leakage or loss accident is inconvenient in Web3, where the public key serves as the userâs wallet address or digital identity. To tackle the issue of user-side private key management in Web3, this paper presents KeyShield which is a leakage-and-loss-resilient private key protection scheme. KeyShield divides the userâs private key into three shares, securely stored across a primary device and a secondary device owned by the user, and a third storage module owned by the user or a semi-trusted service provider. For daily use of the private key, the user only needs to connect the primary and secondary devices. In the event of a leakage or loss, such as device theft or attack, an update process will be triggered to update the three shares, immediately invalidating the leaked or lost share while causing no changes to the public key. As a demonstration of KeyShield, we developed KeyShieldECC accessible on both Android and iOS platforms for managing Elliptic Curve Cryptography (ECC) private keys. The testing results show that for a 256-bit ECC private key, the daily use only needs 0.05 seconds and update needs 0.25 to 0.3 seconds on an ordinary smart phone.
The Address Resolution Protocol (ARP) plays a critical role in the data link layer by mapping network addresses to physical hardware addresses. However, its lack of authentication mechanisms exposes it to spoofing attacks, enabling adversaries to intercept, modify, or disrupt communication within a local network. This paper proposes B-ARP (Blockchain-Secured ARP), a secure and decentralized approach to ARP leveraging blockchain technology. By treating MAC-IP bindings as verifiable transactions stored on a distributed ledger, the system ensures immutability, transparency, and resistance to tampering. A consensus-based validation mechanism prevents the propagation of forged ARP responses and enhances trust among network nodes. The proposed method not only mitigates common spoofing attacks but also introduces a scalable framework for integrating decentralized trust into foundational network protocols. Analytical evaluation demonstrates that this approach maintains strong security guarantees with minimal performance degradation, offering a viable path toward resilient and tamperproof address resolution in modern network architectures.
The advent of next-generation networks, epitomized by Sixth-Generation (6G) wireless systems, signifies a paradigm shift from the simplistic goal of connectivity to a complex ecosystem defined by the convergence of the physical, digital, and biological worlds. This transition, characterized by hyper-density, extreme heterogeneity, and the integration of novel paradigms like terahertz (THz) communications, reconfigurable intelligent surfaces (RIS), and non-terrestrial networks (NTN), fundamentally invalidates many of the security assumptions of previous generations. The very characteristics that enable unprecedented data rates, ultra-low latency, and massive machine-type communicationsâsuch as massive Multiple-Input Multiple-Output (MIMO), distributed ledger technologies, and artificial intelligence (AI)-driven network slicingâalso expand the attack surface, introducing novel vulnerabilities ranging from intelligent jamming and eavesdropping in the physical layer to sophisticated adversarial attacks on AI-based network management functions. This article provides a comprehensive exploration of secure transmission techniques designed for this nascent landscape. It moves beyond the traditional paradigm of cryptography-as-an-overlay to advocate for a holistic, interdisciplinary approach where security is embedded as a foundational property across all protocol layers. The discussion commences with a critical re-evaluation of the evolving threat landscape, identifying key vulnerabilities unique to next-generation architectures. Subsequently, it delves into advanced physical layer security (PLS) techniques, demonstrating how the intrinsic randomness of the wireless channel can be leveraged for secret key generation and covert communications, particularly in the context of massive MIMO and THz bands. The narrative then transitions to the cryptographic layer, examining the imperative shift towards post-quantum cryptography (PQC) to counter the looming threat of quantum decryption, alongside the role of blockchain and distributed ledgers in establishing decentralized trust in a network devoid of fixed infrastructure. A significant portion of the article is dedicated to AI-native security, exploring both the potential of AI to create autonomous, self-healing security mechanisms and the critical vulnerabilities introduced by adversarial machine learning. The analysis culminates in an examination of securing the networkâs foundational pillars, including the integrity of network slicing, the resilience of the Radio Access Network (RAN), and the security of non-terrestrial components. This article concludes that the security of next-generation networks is not merely a technical challenge but a foundational requirement for the socio-economic viability of a hyper-connected future, necessitating a continuous, adaptive, and unified security architecture that evolves in lockstep with the network itself.
Mohammad Badhesha, Arun Sekar Rajasekaran, Ashok Kumar Das, Azees Maria · 6 authors
Authenticated key exchange and secure handover between vehicles and roadside units (RSUs) are essential for the reliability of vehicular networks. However, many existing approaches incur high computational and communication overhead or rely on re-authentication, which limits scalability under high mobility. Moreover, conventional schemes based on classical cryptography cannot withstand quantum adversaries, while lattice-based solutions overlook the need for efficient handover and strong privacy protection. To address these limitations, a lattice-based authentication and key agreement protocol that integrates non-interactive zero-knowledge (NIZK) proofs to enable seamless and post-quantum secure handover in both intra-domain and cross-domain vehicular networks (LAKAS-N) is proposed in this work. The scheme establishes mutual key exchange between vehicles and RSUs, eliminates re-authentication within a single domain, and preserves anonymity when transitioning across domains. Security is rigorously validated through informal and formal analyses, including Scyther-based verification, which confirms resistance against classical and quantum attacks. Lastly, a comprehensive evaluation shows that LAKAS-N achieves stronger security with substantially lower computational, communication, storage, and energy costs compared to state-of-the-art protocols, demonstrating its practicality for real-world vehicular networks.
Junhee LEE, Yixi Cai Lili lei Lei Li, Gweonho Jeong, Jihye Kim · 6 authors
Forward-secure digital signatures protect the integrity of past signatures, even if the current signing key is compromised. Among forward-secure signature schemes, the method introduced by Lee et al. [1], based on zero-knowledge succinct non-interactive arguments of knowledge (zk-SNARKs), is particularly notable for achieving constant complexity across all metrics without requiring a predefined maximum time period. However, a naive approach to recursive proof composition results in an excessive amount of redundant computation being repeated for each signing process, which our method reduces significantly. In this paper, we advance a zk-SNARK-based forward-secure signature scheme by significantly improving the efficiency of its signing algorithm. By incorporating commit-and-prove SNARKs, we replace the inner verification process with commit verification within the signing circuit. Furthermore, we employ efficient recursive zk-SNARKs with accumulation and folding schemes to improve the setup and update algorithms. Our implementation demonstrates the practicality of our approach: the signing procedure completes in 0.18 seconds, achieving a 75-fold speedup over the previous scheme, setup time is reduced to 0.71 seconds - over 61 times faster, and public parameters are reduced to 25 MB, more than 16 times smaller.
Communication protocol is a fundamental component of modern networking. With proliferation of networking and communication, users have become more concerned about privacy. This leads to development of end-to-end encrypted messaging systems which provides confidential communication. Besides confidentiality, there is an increasing demand for additional security properties such as unforgeability, anonymity, off-the-record (OTR), and consistency. However, efficiently achieving these properties simultaneously, especially on resource-constrained mobile devices, remains a significant challenge. In this paper, we propose MERIT, a novel multi-designated receiver authenticated broadcast encryption scheme that satisfies all the above security guarantees in a highly efficient manner. MERIT ensures the following key properties: (i) unforgeability prevents unauthorized parties from generating valid messages; (ii) privacy safeguards the messages and identities of the sender and receivers from non-designated parties; (iii) OTR ensures that receivers cannot later prove the origin of the messages even with their secret keys; and (iv) consistency ensures that all designated receivers obtain identical decrypted messages and identities. The core building block of MERIT is a practical multi-designated verifier signature (PMDVS), which might be of independent interest. We employed a novel batched cut-and-choose technology to prove that the ciphertext is well-formed. This results in an order-of-magnitude efficiency improvement in our scheme compared to its counterparts that rely on general-purpose zero-knowledge proofs. We then show how MERIT leverages PMDVS to provide unforgeability, privacy, OTR, and consistency in the scenario of group messaging. We provide security analysis to demonstrate that MERIT satisfies these security guarantees. We also conduct a thorough performance implementation, and the experimental results demonstrate that MERIT is highly efficient for deployment on mobile devices.
Attribute-Based Encryption (ABE) enables fine-grained access control over outsourced data, but its key generation process typically requires users to disclose their complete attribute sets, introducing significant privacy risks. Existing privacy-preserving approachesâsuch as those based on zero-knowledge proofs or tightly coupled interactive protocolsâsuffer from limited scalability, high communication costs, and insufficient support for selective attribute disclosure. To address these limitations, we propose a privacy-enhancing key generation protocol guided by the principle ofMinimal Disclosure, which ensures that users disclose only the minimally necessary subset of attributes required for authorization. Our protocol decouples attribute verification from key issuance: users first obtain cryptographically verifiable attribute tokens, and later issue blinded key requests over selectively chosen attributes. This design enables selective disclosure, supports reusable attribute credentials, and enhances user autonomy. To improve scalability, we introduce a lightweight batch verification mechanism that reduces computation and communication overhead for the attribute authority. We prove that our protocol achieves thebindingandhidingproperties under standard cryptographic assumptions, and we formally verify these guarantees in the symbolic model using the ProVerif tool. In addition, we propose two privacy metricsâAttributeInference Gain (AIG) andPrivacy Gain (PG)âalongside an entropy-based analysis to quantify resistance against attribute inference attacks. Experimental results show that our scheme effectively mitigates inference leakage while offering substantial efficiency gains compared to existing schemes.
In decentralized finance (DeFi), accidental cryptocurrency transfers to incorrect wallet addresses are a large usability and security issue, frequently causing permanent loss of funds. We present CryptoSafeSend, a smart contract-based safety protocol for transactions featuring a cryptographically secure passcode verification scheme supporting conditional transfers. This work addresses higher-level security issues by introducing a PBKDF2-based key derivation function, which generates strong encryption keys based on Firebaseâs Firebase UID. Secret passcodes are encrypted in AES-GCM functions deployed underneath the Web Crypto API, and Initialization Vector and ciphertext are Base64 encoded for off-chain reliable storage and Firebase Firestore-based messaging. The protocol prevents unauthorized exploitation by safely binding off-chain passcode transmission to a matching on-chain verification, reinforcing user trust without undermining decentralization. Testing on an Ethereum testnet confirms negligible gas overhead, immunity against double claims, and strong security guarantees, qualifying CryptoSafeSend as a valuable constituent in next-generation secure digital asset protocols.
C. Selvan, M. A. Gunavathie, Sini Anna Alex, Shaik Jaffar Hussain
ABSTRACT Appropriate routing strategies are necessary for mobile ad hoc networks (MANETs) in order to facilitate effective data transfer. In order to counter the prevailing problems, the correct routing schemes will need to be selected as the default configurations are used. In this paper, a special optimal link state routing (OLSR) protocol is proposed to incorporate a deep learning methodology to facilitate efficient video streaming in MANETs. This study presents a new improved variant of the OLSR protocol, which is specially tailored to achieve efficient video streaming in MANETs. It is a radical approach that combines a deepâlearning model with blockchain technology to overcome security and reliability issues. It starts with the gathering of video content that is available publicly. In order to detect blackâhole nodes, a special twinâattentionâbased Elman spiking neural network model is applied. The reliability of the neighboring nodes is then measured by means of trust values. The pufferfish optimization algorithm, or the accuracyâaware energyâefficient multipath routing algorithm (AEMRAP), which takes into account nodeâ and linkâstability degrees, is used in making routing decisions. Interplanetary file system (IPFS) technology is used to store the data on blockchain and increase its security. The authentication of the blockchain architecture is conducted via the delegated proofâofâstake (DPoS) method that also delivers an extra protection of MANETs against unauthorized access. The study demonstrates superior performance in securing and optimizing video transmission, confirming that the extended OLSR protocol is highly effective for MANET video streaming applications. The proposed model exceeds the current approaches with a throughput of 2100 Kbps, an average end latency of 20.2 s, and a packetâdelivery ratio of 92.3%.
Yi-Jing Liu, L. Zhang, Xiaoqian Li, Hongyang Du · 8 authors
Integrated Sensing and Communication (ISAC) is driving the evolution of edge intelligence. In ISAC-enabled wireless edge networks, federated learning (FL) is crucial for realizing edge intelligence by supporting the networks with privacy protection, efficient data management, and dynamic adaptability. Specifically, FL allows distributed computing nodes (e.g., sensor devices) to first train local models by using data collected or sensed via ISAC and subsequently send them to one or multiple aggregation nodes for global model collaboration. However, traditional FL frameworks face significant challenges in the ISAC scenarios. For example, the privacy sensitivity of heterogeneous sensor data and the lack of transparency in model parameter exchange make it difficult to ensure the credibility of local and global models. Sharding distributed ledger technology (DLT), which divides the ledger into smaller and manageable shards, offers a potential solution to address these challenges by utilizing multi-node trust capabilities to facilitate distributed consensus during FL training. In this paper, we propose a trusted FL framework that incorporates sharding DLT within ISAC-enabled wireless edge networks to enhance both model training and consensus performance. Specifically, we develop a theoretical model to examine the interactions between model training performance and network capacities of sensing nodes (e.g., storage, computing, and communication capabilities) based on ISACâs real-time channel state information. Based on this theoretical model, we design a trusted clustering scheme for aggregating local models. Numerical results demonstrate that in ISAC-enabled wireless edge networks, our proposed scheme significantly increases network throughput for model transmission while ensuring optimal model learning performance compared to some classical baselines.
While decentralized authentication mechanisms have gained significant attention for enabling user-centric identity management without centralized authorities, the critical counterpart - authenticated key exchange (AKE) in decentralized settings - remains understudied. Although it forms the basis for secure communication in decentralized scenarios, shifting existing AKE protocols to decentralized settings is impractical: the trust assumption is different, and the insufficient support for dynamic identity attributes, etc. To address these challenges, we present a novel decentralized AKE protocol that innovatively integrates attribute authentication with key exchange through multi-party secure computation. Building upon MPCAuth's foundational framework (S&P 23), our protocol goes further to provide key exchange based on authentication of real-world attributes such as a digital passport and email address, etc. Our protocol establishes a new paradigm for decentralized AKE without complex credential operations and heavy zero-knowledge proof. The core of our protocol is a distributed way to securely reconstruct the attributes and establish a session key. We further evaluate its performance across multiple servers. Experimental results on servers under 5 demonstrate that it can finish the full AKE procedure in an acceptable time, enabling efficient and scalable multi-party key AKE in distributed environments.