Shiqiang Zhang, Dongzhi Cao
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
1,104 results · page 20 of 46
Shiqiang Zhang, Dongzhi Cao
No abstract is available for this record.
Kei Ikebe, Yudai Hata, Toru Nakamura, Takamasa Isohara · 5 authors
The ERC721 standard defines a Non-Fungible Token (NFT) as an identifier that uniquely identifies digital data recorded on a blockchain. The NFT currently in use claim to ensure the uniqueness of the contents associated with the NFT by taking advantage of the tamper-resistant characteristics of the blockchain data. Besides, digital signatures based on public-key encryption is a representative technique to prevent digital data from being falsified, and its application to NFT is also discussed. In this study, we first consider an NFT implementation by applying a designated confirmer signature using an interactive verification method without using blockchain technology. We design an NFT issuance protocol that guarantees the uniqueness of data with a designated confirmer signature, and evaluate the security of the protocol. Moreover, we compare it with existing blockchain implementations. By analyzing the both methods, we aim to provide insights into the potential applications and performance in using designated confirmer signatures for NFT. Our findings contribute to the ongoing research on secure and efficient mechanisms for ensuring the integrity and uniqueness of digital assets in decentralized systems.
Nguyen Van Nghi, Do Quang Trung, Dinh Tien Thanh
The Elliptic Curve Diffie-Hellman (ECDH) protocol is a key exchange protocol that is widely used in information technology systems. However, the ECDH protocol still has inherent weaknesses due to the lack of a user authentication mechanism and is affected by man-in-the-middle attacks. In this paper, we propose two novel variants of the ECDH protocol using Schnorr Zero-Knowledge Proof (ZKP) for Client-Server network model. We aim to integrate the user authentication mechanism into the key exchange process for the Client-Server network model with higher security than applying the original ECDH protocol. To achieve this goal, we compare and analyze the network model utilizing the original ECDH protocol versus the proposed protocols. Therefore, we draw some conclusions about the advantages, disadvantages, and feasibility of the proposed solution.
Sandip Roy, Sourav Nandi, Raj Maheshwari, Sachin Shetty · 6 authors
Recent advances in Internet technology and IoT devices have facilitated researchers to foster a wide range of Intelligent Transportation Systems (ITS) that improve the quality of automated transportation by addressing real-time safety and traffic management issues. The participating ITS agents, such as smart cars and roadside equipment, are required to communicate urgently through an open (unsecured) wireless channel in an unattended setting. To address the security issues, several vehicle-to-vehicle (V2V) and vehicle-to-infrastructure (V2I) authentication and access control protocols have been proposed in recent times. However, fast-moving vehicles need to set up frequent authentication with different roadside units, which induces high computation and communication overheads. Consequently, it becomes a bottleneck for the resource-limited vehicle onboard unit devices. As the blockchain supports decentralized storage with data integrity and transparency, in this article, we design a secure and lightweight Internet of Vehicles (IoV)-enabled blockchain-based access control protocol with a handover authentication facility (we call it BACHP-IoV, in short). The handover authentication mechanism exploits no computation-costly cryptographic primitives. Once the transactions or messages have been securely gathered by a roadside unit (RSU),$RSU_{j}$, residing in a group of vehicles$Vh_{i}$, will form a partial block, which is later forwarded to a cloud server node in the Peer-to-Peer (P2P) cloud servers blockchain network for converting it into a full block. Next, the full blocks are mined using a voting-based consensus algorithm. In addition, the in-charge trusted authority$\mathcal {TA}$uploads information about the registered vehicles, such as randomized masked passwords and random secrets, to the blockchain. Thus, an$RSU_{j}$can check the authenticity of a particular vehicle as well. We prove the security strength of the proposed BACHP-IoV by using the well-known Real-or-Random (ROR)-based random oracle model, the ProVerif 2.03 simulation tool, and informal security analysis. We have implemented the proposed BACHP-IoV through network simulator 3 (NS-3) and blockchain, and the simulation results demonstrate that BACHP-IoV is practical in a real-life scenario. A detailed comparative analysis also shows that BACHP-IoV provides significantly better security and efficiency than the existing competing schemes.
Norah Alsaeed, Farrukh Nadeem, Faisal Albalwy
The Internet of Medical Things (IoMT) is the network of medical devices, software applications, and healthcare information systems used for remote monitoring and delivery of healthcare services. Despite the several advantages of IoMT for today smart healthcare, security issues are growing due to the inadequate computation, limited storage and insufficient self-protection capabilities of IoMT devices. Authentication of IoMT devices is the main requirement to secure IoMT systems. Although, the recent authentication schemes based on tamper-proof decentralized architecture of blockchain technology are robust and enjoy a high level of security, yet they require high computation, more storage, and long authentication time. These issues lead to reduced scalability and time efficiency, which are necessary for large-scale, time-sensitive IoMT systems. To this end, this paper proposes a novel group authentication framework for IoMT Systems. The group authentication scheme is implemented through a four-phase process, including setup, registration, secret construction, and authentication. To enhance both efficiency and scalability, the proposed group authentication framework employs a combination of elliptic curve cryptography (ECC), Shamir’s secret sharing (SSS) algorithm, and blockchain-based fog computing technologies. We simulated the proposed framework through the Ethereum platform and Solidity language and its performance is evaluated using the Hyperledger Caliper tool. The simulation experiments of the proposed framework showed that the average latency of authenticating IoMT devices was 0.5 second and the throughput was 400 transactions per second. Our analysis of the proposed framework’s performance against other cutting-edge blockchain-based authentication techniques showed that it outperformed them in terms of latency and throughput. A security analysis of the proposed framework was conducted using the widely accepted Automated Validation of Internet Security Protocols and Applications (AVISPA) tool. The formal and informal security analysis demonstrated that the proposed framework is secure and resistant to potential authentication-related attacks. We also noted that the average latency of the proposed framework maintains a fairly narrow range when the number of submitted transactions rises, indicating that it supports the scalability of the IoMT system.
Weizheng Wang, Zhaoyang Han, Thippa Reddy Gadekallu, Saleem Raza · 6 authors
With the rapid increase of data from unmanned aerial vehicles (UAVs), the security and privacy of data presents a severe challenge for UAV-based applications. Moreover, UAVs with constrained resources cannot be equipped with strong but complicated cryptographic primitives for authentication protocol design. Although some attempts have been made to deal with security and privacy issues for UAVs, most of the existing studies have been found numerous security vulnerabilities or own extreme communication/computation overheads. This article offers a lightweight and practical mutual authentication protocol solely comprised of bitwise XOR operations and one-way hash functions. Moreover, blockchain technology is utilized to alleviate the centralized trusted party (TA) issue. Then, security of our proposed authentication protocol is proved by widely adopted formal security proof—Real-or-Random model and informal security proof. The experimental results prove that the proposed protocol can achieve better security requirements (e.g., decentralized TA, replay attack defense, and session key security) with less communication cost (i.e., reduced by around 58.7% at most) and computation cost (i.e., reduced by around 98.9% at most) than related UAV authentication schemes.
Sanjeev Kumar Dwivedi, Ruhul Amin, Satyanarayana Vollala, Ashok Kumar Das
The intelligent vehicles collect and distribute the data to other vehicles and Roadside Units (RSU), which ultimately strengthens the vehicular services in the Vehicular Ad-hoc Network (VANET). In order to protect against a variety of potential security threats, the VANET system needs a proper authentication mechanism, which requires more computational overheads and cannot perform better, when a cluster of vehicles sends the messages simultaneously. This paper aims to design a decentralized blockchain-based batch authentication protocol using Elliptic Curve Cryptography, where RSU authenticates the group of vehicles together. Moreover. our protocol also supports the verification of both individual messages (signature) generated by the vehicle and batch signature. We have used the Scyther security tool to verify our protocol and found that the protocol is safe and secure. A detailed comparative analysis reveals that the proposed scheme achieves more functionality and security compared to relevant schemes. The security analysis confirms that the proposed scheme is secure against all applicable attacks. Moreover, the ethereum platform simulates the proposed scheme, showing its effectiveness and confirming that it is feasible to deploy and execute transactions in real networks.
Norbert Oláh, B. Molnár, Andrea Huszti
Unmanned aerial vehicles (UAVs) have become increasingly popular in recent years and are applied in various fields, from commercial and scientific to military and humanitarian operations. However, their usage presents many challenges, including limited resources, scalability issues, insecure communication, and inefficient solutions. We developed a secure and scalable registration protocol to address these issues using LoRa technology. Our solution involves the usage of the physical unclonable function (PUF) and blockchain technology for key exchange. PUF also ensures security against physical tampering, and blockchain is applied to share the symmetric key among the base stations. After the registration, the later communication messages are encrypted with AES-GCM to provide authentication and confidentiality between the parties. We conducted a security analysis of the registration protocol using the ProVerif tool, and our solution meets the security requirements, including the mutual authentication of entities, key freshness, key secrecy and also key confirmation properties. Besides the Proverif-based analysis, an informal security analysis is also provided that shows that the registration is protected against a variety of well-known active and passive security attacks. As drone resources are limited, we also prepared a proof of concept to test our solution under real-life conditions, focusing on efficiency and lightweight operations.
Muhammad Faizan Ayub, Xiong Li, Khalid Mahmood, Salman Shamshad · 6 authors
The development of the industrial Internet of Things and smart grid networks has emphasized the importance of secure smart grid communication for the future of electric power transmission. However, the current deployment of smart meters and wireless communication methods presents several security concerns that must be addressed to ensure sustainable and resilient smart grid networks for Industry 5.0, with a focus on consumer-centric technologies. In this context, we propose a privacy-focused authentication solution for secure consumer-centric demand response management in smart grid networks, incorporating consumer electronics. Our proposed protocol utilizes blockchain-based authentication to enhance resistance against potential attacks and ensure the integrity of demand response data. Additionally, we have incorporated a PUF to prevent physical attacks. We have conducted informal and formal security analyses to verify the effectiveness of our proposed protocol against various threats and to confirm the session key security. Our comparison study has demonstrated that our protocol provides superior security and added functionalities, with lower computation and communication costs compared to similar protocols. Furthermore, we have measured the computational time for implementing the blockchain component of our protocol while considering the impact of varying numbers of block additions and transactions per block.
Mohamed Seifelnasr, Riham AlTawy, Amr Youssef, Essam Ghadafi
The three-tier IoT–Edge–Cloud paradigm enables low-end devices to use the computation capabilities of the more powerful edge nodes to meet efficiency constraints for real-time applications. Many symmetric-key-based schemes rely on an online trusted cloud admin (CA) to establish session keys between IoT devices and edge nodes. In this study, we propose a new provably-secure mutual authentication privacy-preserving protocol with forward secrecy (MAPFS), which eliminates the requirement for an online CA during IoT authentication. To achieve anonymity, our construction utilizes zero-knowledge proofs and randomizes the IoT authentication request. The security of our construction is based on the well-studied discrete logarithm and decisional Diffie–Hellman assumptions in elliptic curve groups. We formally prove that MAPFS ensures mutual authentication and semantic security for session keys. We also evaluate MAPFS performance in terms of the communication overhead, storage requirements, and computation complexity. Finally, we test the performance of MAPFS on a Raspberry Pi 4 and compare it against other certificate-less protocols.
Jie Zhou, Ming Luo, Lixin Song, Jinlin Hu
No abstract is available for this record.
Zhangquan Wang, Jiaxuan Huang, Kelei Miao, Xiaowen Lv · 8 authors
No abstract is available for this record.
Junfeng Miao, Zhaoshun Wang, Zeqing Wu, Xin Ning · 5 authors
No abstract is available for this record.
Amalan Joseph Antony, Kunwar Singh
Abstract Secure exchange of data among the various stake holders of healthcare systems is of prime importance. As the size of the healthcare networks grew, several variants of Public Key Infrastructures (PKIs) were proposed as a means to achieve reliable authentication, confidentiality, non-repudiation, etc. The most prevalent approach to PKI has been the use of Certificate Authorities (CAs). But, events like the breach of the CA DigiNotar, and the ensuing fake certificates for Google, among other noteworthy high-profile domains, has cast doubts on the reliability of a CA, and therefore on PKIs modelled as CAs too. In this paper, we propose a new approach to a healthcare PKI modelled on a blockchain, incorporating Elliptic Curve Cryptographic methods for secure key generations.
Amit Kumar Mishra, Mohammad Wazid, Devesh Pratap Singh, Ashok Kumar Das · 6 authors
One of the most significant recent advances in technology is the advent of unmanned aerial vehicles (UAVs), i.e., drones. They have widened the scope of possible applications and provided a platform for a wide range of creative responses to a variety of challenges. The Internet of Drones (IoD) is a relatively new concept that has arisen as a consequence of the combination of drones and the Internet. The fifth-generation (5G) and beyond cellular networks (i.e., drones in networks beyond 5G) are promising solutions for achieving safe drone operations and applications. They may have many applications, like surveillance or urban areas, security, surveillance, retaliation, delivering items, smart farming, film production, capturing nature videos, and many more. Due to the fact that it is susceptible to a wide variety of cyber-attacks, there are certain concerns regarding the privacy and security of IoD communications. In this paper, a secure blockchain-enabled authentication key management framework with the big data analytics feature for drones in networks beyond 5G applications is proposed (in short, SBBDA-IoD). The security of SBBDA-IoD against multiple attacks is demonstrated through a detailed security analysis. The Scyther tool is used to perform a formal security verification test on the SBBDA-IoD’s security, confirming the system’s resistance to various potential attacks. A detailed comparative analysis has identified that SBBDA-IoD outperforms the other schemes by a significant margin. Finally, a real-world implementation of SBBDA-IoD is shown to evaluate its effect on several measures of performance.
Aydin Abadi, Dan Ristea, Artem Grigor, Steven J. Murdoch
Time-Lock Puzzles (TLPs) enable a client to lock a message such that a server can unlock it only after a specified time. They have diverse applications, such as scheduled payments, secret sharing, and zero-knowledge proofs. In this work, we present a scalable TLP designed for real-world scenarios involving a large number of puzzles, where clients or servers may lack the computational resources to handle high workloads. Our contributions are both theoretical and practical. From a theoretical standpoint, we formally define the concept of a “Delegated Time-Lock Puzzle (D-TLP)”, establish its fundamental properties, and introduce an upper bound for TLPs, addressing a previously overlooked aspect. From a practical standpoint, we introduce the “Efficient Delegated Time-Lock Puzzle” (ED-TLP) protocol, which implements the D-TLP concept. This protocol enables both the client and server to securely outsource their resource-intensive tasks to third-party helpers. It enables realtime verification of solutions and guarantees their delivery within predefined time limits by integrating an upper bound and a fair payment algorithm. ED-TLP allows combining puzzles from different clients, enabling a solver to process them sequentially, significantly reducing computational resources, especially for a large number of puzzles or clients. ED-TLP is the first protocol of its kind. We have implemented ED-TLP and conducted a comprehensive analysis of its performance for up to 10,000 puzzles. The results highlight its significant efficiency in TLP applications, demonstrating that EDTLP securely delegates 99% of the client’s workload and 100% of the server’s workload with minimal overhead.
Mayank Gupta, B. Sathis Kumar
Wireless body area network (WBAN) is a new technology trend that uses wearable sensors linked to the Internet-of-Things (IoT) network to provide remote tracking and data collection for patient healthcare records. IoT technologies have the potential to change our everyday lives, but they also pose significant security concerns. However, in untrusted wireless environments, the majority of WBAN–IoT data is shared between computationally restricted devices. As a result, protecting sensitive data in WBAN–IoT becomes a crucial challenge. The algorithm had to be lightweight due to the limited computing resources in WBAN sensors or IoT devices. However, significant issues in cloud-based IoT systems must be resolved to recognize the authority of communicators during contact sessions over vulnerable networks like the Internet. To eliminate unauthorized access in IoT applications, a safe authentication, confidentiality, and integrity protocol are highly desirable. Under the hard problem assumptions, our protocol is provably reliable and meets all security criteria, including session key security. In addition, our proposed lightweight secure session key protection, mutual authentication, and access control IoT (LSSMAC-IoT) is considerably greater than the fastest ones shown by the performance evaluation, based on an already existing safe, mutual authentication (MA) process based on heavy homomorphic encryptions and zero-knowledge proof.
M. Indushree, Manish Raj
No abstract is available for this record.
Garima Misha, Bramah Hazela, Brijesh Kumar Chaurasia
Internet of Things (IoT) applications, such as e-healthcare departments have grown tremendously where devices gather patient data and instantly transmit it over a distance to servers. Despite its huge advantages, IoT in the healthcare sector has acquired little consideration, largely because of the threats of unauthorized access to private health data made possible by the weak wireless communication channel. The economic complexity of the current security protocols makes them inappropriate, hence new security protocols must be developed for resource-constrained and diverse IoT networks. This work suggests an authenticated key agreement protocol for the Internet of medical things (IoMT) that is based on zero-knowledge proofs (ZKP). The research will include the comparison between computational delays in traditional protocols and ZKP protocol. This paper provides a protocol to obtain privacy of data in IoMT environment on the basis of zero knowledge phenomenon and anonymous communication by ZKP.
Namrata Singh, Ayan Kumar Das
No abstract is available for this record.
Denis Firsov, Dominique Unruh
We formalize security properties of zero-knowledge protocols and their proofs in EasyCrypt. Specifically, we focus on sigma protocols (three-round protocols). Most importantly, we also cover properties whose security proofs require the use of rewinding; prior work has focused on properties that do not need this more advanced technique. On our way we give generic definitions of the main properties associated with sigma protocols, both in the computational and information-theoretical setting. We give generic derivations of soundness, (malicious-verifier) zero-knowledge, and proof of knowledge from simpler assumptions with proofs which rely on rewinding. Also, we address sequential composition of sigma protocols. Finally, we illustrate the applicability of our results on three zero-knowledge protocols: Fiat-Shamir (for quadratic residues), Schnorr (for discrete logarithms), and Blum (for Hamiltonian cycles, NP-complete).
Ashish Tomar, Niraj Gupta, Divya Rani, Sachin Tripathi
No abstract is available for this record.
Qi Xie, Zixuan Ding, Wen Tang, Debiao He · 5 authors
As one of the most valuable vehicle-based Internet of Things (IoT) applications, Vehicular Ad-hoc Networks (VANETs) have received extensive attention since it was proposed. In order to ensure the safety of VANETs and improve the communication efficiency between moving vehicles and different Roadside Units (RSUs), some handover authentication protocols for VANETs have been proposed. However, the existing protocols have some problems such as excessive computation overhead, untraceable malicious messages, and the inability to resist RSU captured attacks. To solve the above problems, we propose a blockchain-based protocol to achieve Vehicle to Infrastructure (V2I) authentication, V2I handover authentication, and Vehicle to Vehicle (V2V) broadcasting authentication. The advantages of our protocol are: (1) It achieves lightweight V2I handover authentication and V2V broadcast authentication, dynamic anonymity strategy and embedding strategy of pseudo-identity and vehicle feature are used to guarantee anonymity and traceability simultaneously; (2) The announcement can be broadcasted verifiably without the help of transportation infrastructure (e.g., RSU) or the Trusted Authority (TA); and (3) The Physically Unclonable Functions (PUF) technology is used to resist RSU captured attacks. We use formal security proof under random oracle model to prove the security of the proposed protocol. Compared with related V2I handover authentication protocols, our protocol can resist RSU captured attacks and other various known attacks. The sum of first and handover authentication efficiency of our protocol is 37.93% higher than the previous most effective protocol, while maintaining the same level of communication and storage costs.
Liu Shenglong, Ge Zhang, Jiawei Jiang, Xin Zhou · 5 authors
With the application of new technologies such as Internet of Things and big data in smart grid industry, new power systems based on new energy sources have emerged in response to the call of “Peak carbon, carbon neutrality.” The power grid enterprise concentrates the data assets and business access to the data external service, which needs to connect a large number of data sources. Ensuring the authenticity of the data without tampering becomes a big challenge. The power system adopts the identity authentication mechanism to resist the security attack and protect the sensitive data. However, in the process of user authentication, the sending of real identity information will lead to the reduction of system privacy, which is easy to cause the leakage of sensitive data. This paper proposes an anonymous authentication mechanism based on zero-knowledge proof for power system, which authenticates the server without revealing the identity. This mechanism uses zero-knowledge proof algorithm to design an anonymous authentication protocol framework, which consists of three stages: registration, mutual authentication and revocation. In this method, anonymous certificate and elliptic curve encryption technology are used to realize the anonymity and authenticity of users. The mechanism effectively protects the user's real identity information and maintains the sensitive data in the power system.