Abstract Vehicular Ad Hoc Networks (VANETs) are characterized by high mobility of nodes and volatility, which make privacy, trust management, and security challenging issues in VANETs' design. In such networks, data can be exposed to a variety of attacks, the most dangerous is false information dissemination, which threatens the safety and efficiency of transportation systems. False emergency messages can be injected by inside attackers to announce fake incidents such as traffic accidents, resulting in a false information attack. As the data in VANET is based on events, any trust mechanism must first identify the true events. To address these security challenges, a blockchain‐based authentication scheme and trust management model are proposed for VANETs. Using the authentication scheme, vehicles are enabled to send messages anonymously to the roadside units (RSUs) and the identity privacy of vehicles is protected. Besides, the proposed trust management model is designed to detect and deal with false information by evaluating the trustworthiness of vehicles and data. Using the trust model, when vehicles report an incident to the nearest RSU, the RSU is able to verify whether or not the incident took place. This mechanism ensures that RSUs send only verified event notifications. Finally, RSUs participate in updating the trust values of vehicles and store these values in the blockchain. The efficiency of the proposed authentication scheme is validated through analysis while the trust model is validated through simulations. The results obtained show that the proposed authentication scheme and the trust model provide better performance than other state‐of‐the‐art models where malicious vehicles can be identified efficiently and RSUs are enabled to broadcast only legitimate events.
B. D. Deebak, Fida Hussain Memon, Sunder Ali Khowaja, Kapal Dev · 7 authors
Internet of Things (IoT) has led to significant advancements in communication technologies, specifically, concerning IoT-based sustainable information systems. Lately, industry-academic communities have made great strides for the development of security in IoT-based applications, such as traffic management, industrial automation systems, military surveillance systems, transportation, parking, etc. The sustainable IoT converges AI and blockchain technologies for enhancing quality of individual’s life. As a result, emerging IoT applications operate a distributed ledger technology to provide robust-level of encryption and execution for contractual agreement that resolves interoperability and security issues. Thus, this article proposes a blockchain-based remote mutual authentication (B-RMA) that considers smart devices and cloud networks to offer security and privacy. The proposed B-RMA can coexist with the IoT-based smart environment to decentralize the processing of user authentication requests. The prominence of the proposed strategies including security efficiency and privacy protection, is evaluated using informal security analysis. Moreover, a runtime platform “Node.js” was used to analyze the communication metrics, such as execution time, throughput, and overhead ratio, over the concurrent requests. The investigation results prove that the B-RMA achieves a scalable environment, accordingly.
Nowadays, continuous monitoring of a patient’s healthcare data has become a critical factor in human well-being. However, with the rapid advancement of wireless technology, doctors and healthcare professionals can monitor the patient’s healthcare data in real time. But to access the confidential patient’s data which is transferred through the open wireless medium, the secure transmission plays an important role. In this work, the privacy and the anonymity of the end-users (patient/doctor) are preserved using an anonymous blockchain-based authentication scheme. Moreover, in this work initially, mutual authentication is performed between the end-users, followed by encryption and decryption of confidential data. In addition, to avoid reauthentication of the patient again during the movement of a patient from one doctor to another, a transfer authentication protocol is performed between the doctors which enhances performance analysis. The security analysis section illustrates the withstanding capability of the proposed work against various vulnerable attacks. Finally, performance investigation of the proposed work reveals a reduction in computational and communication costs when compared to existing related works.
Abstract The Internet of Things (IoT) has become a significant technology on the internet with its widespread adoption in almost every place we could think of, like homes, hospitals, industries, companies, and so on. This adoption in virtually every device had made them smart, thereby reducing the human intervention to handle them. These devices become smart by gathering the sensed information and communicating with other devices or servers to take the appropriate decisions based on acquired data. However, these devices are deployed in batches with default usernames and passwords, making them vulnerable to attacks as seen in recent pasts like the Mirai botnet attack. Most of the attacks could have been avoided if these devices were equipped with a decent lightweight secure authentication scheme. One of the most common authentication procedures is using traditional public key infrastructure (PKI), which suffers from a single point of failure. Moreover, the complex procedures of PKI make them unfit for low‐powered IoT devices. Identity‐based cryptography (IBC), a lightweight cryptosystem, could be a good fit for these devices. But, even IBC suffers from a single point of failure and key escrow problem because of the private key generator (PKG). Blockchain has proved its mettle in eliminating a single point of failure with its robust distributed ledger technology. This article presents a novel authentication scheme for IoT devices based on identity‐based cryptography using a blockchain network. Blockchain is used as a distributed PKG, eliminating a single point of failure and key escrow problem of PKGs. Further, the proposed work is implemented in Hyperledger Fabric, which is an open‐source blockchain platform that efficiently performs the addition, updating, and deletions operation for effective authentication and communication of IoT devices.
Regional medical consortium systems facilitates medical information sharing. However, many security issues exposed by the dominant centralized architectures, such as single points of failure, unauthorized operations and illegal access, are increasingly apparent constraints on the security and efficiency of data sharing across domains. Even more, any malicious operation detected, effective measures should be executed promptly for identity tracing. In this paper, we propose a secure and efficient cross-domain authentication scheme based on two cooperative blockchains (BCs) for medical consortium systems. Specifically, an intra-domain BC records any legal users’ registration and authentication information while an inter-domain BC is responsible for writing users’ cross-domain authentication information. In each domain, the general hospital acts as a trusted third service provider to achieve cross-chain interactions. For the entire cross-domain authentication procedure, anonymity mechanism is utilized to enhance security, and to trace malicious users, the improved chameleon hash is used in the intra-domain BC to redact the state of the user, and blacklist merkle tree is extended in the inter-domain BC to protect different domains’ services from illegal accessing. In addition, security analysis and performance evaluation are completely given to prove the superior security features and performance compared with other schemes.
Daya Gupta, Arijit Karati, Walid Saad, Daniel Benevides da Costa
The so-called Internet of Vehicle (IoV) systems will interconnect numerous vehicles to communicate significant information through an Internet of Things (IoT) enabled network. It has emerged as a promising system wherein various data authentication techniques have been introduced using clumsy certificate management and Diffie-Hellman (DH) assumption. However, in the presence of quantum cryptanalysis, DH-type problems could be solved in polynomial-time. In this paper, a novel certificateless data authentication protocol is designed, enabling security features in open wireless communication in the IoV. The proposed protocol resists a quantum attack using lattice cryptography. Further, a reliable blockchain mechanism is shown to provide vehicles’ trustworthiness in batch data verification. Rigorous formal analysis shows the ability of the proposed algorithm to resist existential unforgeability against the chosen-message attack. Nonetheless, the developed protocol supports other essential security functionalities, including unlikability, conditional-traceability, anti-replay, and data authenticity. Performance analysis exhibits the simulation orchestration and shows the way the proposed protocol outperforms other related techniques in energy consumption, data computation, communication, and cryptographic key storage overheads.
In current single sign-on authentication schemes on the web, users are required to interact with identity providers securely to set up authentication data during a registration phase and receive a token (credential) for future access to services and applications. This type of interaction can make authentication schemes challenging in terms of security and availability. From a security perspective, a main threat is theft of authentication reference data stored with identity providers. An adversary could easily abuse such data to mount an offline dictionary attack for obtaining the underlying password or biometric. From a privacy perspective, identity providers are able to track user activity and control sensitive user data. In terms of availability, users rely on trusted third-party servers that need to be available during authentication. We propose a novel decentralized privacy-preserving single sign-on scheme through the Decentralized Anonymous Multi-Factor Authentication (DAMFA), a new authentication scheme where identity providers no longer require sensitive user data and can no longer track individual user activity. Moreover, our protocol eliminates dependence on an always-on identity provider during user authentication, allowing service providers to authenticate users at any time without interacting with the identity provider. Our approach builds on threshold oblivious pseudorandom functions (TOPRF) to improve resistance against offline attacks and uses a distributed transaction ledger to improve availability. We prove the security of DAMFA in the universal composibility (UC) model by defining a UC definition (ideal functionality) for DAMFA and formally proving the security of our scheme via ideal-real simulation. Finally, we demonstrate the practicability of our proposed scheme through a prototype implementation.
Sidrah Abdullah, Junaid Arshad, Muhammad Mubashir Khan, Mamoun Alazab · 5 authors
Abstract Healthcare has evolved significantly in recent years primarily due to the advancements in and increasing adoption of technology in healthcare processes such as data collection, storage, diagnostics, and treatment. The emergence of the industrial internet of things (IIoT) has further evolved e-Health by facilitating the development of connected healthcare systems which can significantly improve data connectivity, visibility, and interoperability leading to improved quality of service delivered to patients. However, such technological advancements come with their perils—there are growing concerns with regards to the security and privacy of healthcare data especially when collected, shared, and processed using cutting-edge connected sensor devices affecting the adoption of next-generation e-healthcare systems. In particular, during the front-end and back-end data transfer in health information exchange (HIE) there exist a security risk in term of confidentiality, integrity, authentication and access control of the data due to the limited capabilities of IoT devices involved. In this paper, we investigate the use of distributed ledger technologies (DLT) to address such security concerns for emerging healthcare systems. In particular, we use masked authenticated messaging (MAM) over the Tangle to achieve secure data sharing within a healthcare system and provide a proof-of-concept of applying the proposed approach for securing healthcare data in a connected IIoT environment. Further, we have performed the evaluation and analysis of data communication against the metrics of encryption and efficiency in transaction time.
Authentication is essential for the prevention of various types of attacks in fog/edge computing. Therefore, a novel mode-based hash chain for secure mutual authentication is necessary to address the Internet of Things (IoT) devices' vulnerability, as there have been several years of growing concerns regarding their security. Therefore, a novel model is designed that is stronger and effective against any kind of unauthorized attack, as IoT devices' vulnerability is on the rise due to the mass production of IoT devices (embedded processors, camera, sensors, etc.), which ignore the basic security requirements (passwords, secure communication), making them vulnerable and easily accessible. Furthermore, crackable passwords indicate that the security measures taken are insufficient. As per the recent studies, several applications regarding its requirements are the IoT distributed denial of service attack (IDDOS), micro-cloud, secure university, Secure Industry 4.0, secure government, secure country, etc. The problem statement is formulated as the "design and implementation of dynamically interconnecting fog servers and edge devices using the mode-based hash chain for secure mutual authentication protocol", which is stated to be an NP-complete problem. The hash-chain fog/edge implementation using timestamps, mode-based hash chaining, the zero-knowledge proof property, a distributed database/blockchain, and cryptography techniques can be utilized to establish the connection of smart devices in large numbers securely. The hash-chain fog/edge uses blockchain for identity management only, which is used to store the public keys in distributed ledger form, and all these keys are immutable. In addition, it has no overhead and is highly secure as it performs fewer calculations and requires minimum infrastructure. Therefore, we designed the hash-chain fog/edge (HCFE) protocol, which provides a novel mutual authentication scheme for effective session key agreement (using ZKP properties) with secure protocol communications. The experiment outcomes proved that the hash-chain fog/edge is more efficient at interconnecting various devices and competed favorably in the benchmark comparison.
Seunghwan Son, Joonyoung Lee, Yohan Park, Youngho Park · 5 authors
Connected vehicle means providing different services, such as advanced driver-assistance systems (ADAS) from vehicles connected to the network. Vehicular ad-hoc networks (VANETs) can support vehicle-to-vehicle (V2V) and vehicle-to-infrastructure (V2I) communications to realize connected vehicle. In VANETs, secure communication must be ensured, as otherwise it can lead to traffic accidents and human injuries. Recently, many studies on V2I authentication have been conducted to guarantee the security of V2I communications. However, recent V2I authentication protocols do not consider the handover situation, and it causes unnecessary computations. As vehicles have limited computing resources, unnecessary computation can lead to overload to the vehicles. In recent years, blockchain-based VANET is an active field of research because it can provide decentralization, data integrity and transparency. Using the strength of the blockchain technology, we design a blockchain-based handover authentication protocol for VANETs. In the proposed protocol, vehicles only perform lightweight computations in handover situations for efficiency of the network. We also conduct the formal analysis such as Burrows–Abadi–Needham (BAN) logic, Real-Or-Random (ROR) oracle model, and Automated Validation of Internet Security Protocols and Applications (AVISPA) simulation to the proposed protocol. We simulate the proposed protocol using network simulator 3 (NS-3) to verify that the proposed protocol is practical. Finally, we compare the computational cost and security features of the proposed protocol with existing protocols to show that the proposed protocol is more secure and efficient.
The industrial Internet of Things (IIoT) is a fast-growing network of Internet-connected sensing and actuating devices aimed to enhance manufacturing and industrial operations. This interconnection generates a high volume of data over the IIoT network and raises serious security (e.g., the rapid evolution of hacking techniques), privacy (e.g., adversaries performing data poisoning and inference attacks), and scalability issues. To mitigate the aforementioned challenges, this article presents, a new privacy-preserved threat intelligence framework (P2TIF) to protect confidential information and to identify cyber-threats in IIoT environments. There are two major elements in the proposed P2TIF framework. First, a scalable blockchain module that enables secure communication of IIoT data and prevents data poisoning attacks. Second, a deep learning module that transforms actual data into a new format and protects data from inference attacks using a deep variational autoencoder (DVAE) technique. The encoded data are then employed by a threat detection system using attention-based deep gated recurrent neural network (A-DGRNN) to recognize malicious patterns in IIoT environments. The proposed framework is validated using two different network data sources, i.e., ToN-IoT and IoT-Botnet. Security analysis and experimental results revealed the high efficiency and scalability of the proposed P2TIF framework.
Munkenyi Mukhandi, Francisco Damião, Jorge Granjal, João P. Vilela
To decrease the IoT attack surface and provide protection against security threats such as introduction of fake IoT nodes and identity theft, IoT requires scalable device identity and authentication management. This work proposes a blockchain-based identity management approach with consensus authentication as a scalable solution for IoT device authentication management. The proposed approach relies on having a blockchain secure tamper proof ledger and a novel lightweight consensus-based identity authentication. The results show that the proposed decentralised authentication system is scalable as we increase number of nodes.
Internet of Things (IoT) has been ubiquitous in both industrial and living areas, but also known for its weak security. Being as the first defense line against various cyberattacks, authentication is even more critical to IoT applications. Moreover, there has been a growing demand for cross-domain collaboration, leading to an increasing need for cross-domain authentication. Recently, certificate-based authentication schemes have been extensively studied. However, many of these schemes are not efficient in computation, storage, and communication, which are highly required in IoT. In this paper, we propose a lightweight authentication scheme based on consortium blockchain and design a cryptocurrency-like digital token to build trust. Furthermore, trust lifecycle management is performed by manipulating the amount of tokens. The comprehensive analysis and evaluation demonstrate that the proposed scheme is resistant to various common attacks and more efficient than competitor schemes in terms of storage, communication, and authentication cost.
Bangyao Du, Debiao He, Min Luo, Cong Peng · 5 authors
Covert communication is designed for hiding the subliminal communication which takes place between both of the speakers and their relationship. The traditional covert communication utilizes the centralized channel and the third‐party central node or authority to distribute messages which leads to a lack of undetectability, antitraceability, and robustness. In recent years, there have been attempts to apply the blockchain to covert communication solutions, for the characteristics of blockchain such as decentralization, openness, and trustworthiness. In this paper, based on the analysis of the literature and the classification according to the hiding position, we identify four kinds of covert communication: Address Channel, Value Channel, DSA (Digital Signature Algorithm) Channel, and Script Channel, which will help inform future research agenda.
Open access
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Blockchain is current demanding technology in the field of data and information security. In this paper, we present a model of the data integrity assurance by the use of blockchain. Our proposed method, the message authentication code is stored under the block of blockchain with hash value, timestamp, and nonce. The existing message authentication code, SHA-256 is used to generate the hash value to store into the blockchain after encrypting by asymmetric key cryptography with recipient public key. We also compared the strength of our blockchain based data integrity assurance method with others existing method of integrity assurance and management. We have applied penetration testing by using five different tools to test the strength and robustness of proposed method of integrity assurance. It is found that blockchain based integrity assurance method is more robust than other methods of integrity assurance.
Samiulla Itoo, Akber Ali Khan, Vinod Kumar, Ahmed Alkhayyat · 6 authors
In the traditional medical healthcare system, each medical facility is responsible for preserving its own records. Sharing such records with another medical establishment is difficult for them. To tackle this challenge, the traditional medical system leverages internet technology to transform into a modern electronic system. In electronic healthcare systems, managing the security and privacy of patient data becomes a major issue. As an alternative, the healthcare sector might use blockchain technology to exchange digitised healthcare data. Blockchain technology is characterised by anonymity, decentralisation, and immutability. It is hard to keep all electronic healthcare data on blockchain due to the expense and volume. Cloud computing is the best solution for storing this type of data and resolving problems like these. To address these concerns, we offer a blockchain-based key agreement protocol for cloud medical network systems that enhances privacy and security. We demonstrate a formal and informal security analysis of the proposed protocol that shows that the proposed protocol is both secure and communicative. We provide security verification of the proposed protocol by using the AVISPA software tool against man in the middle attack and replay attack. Finally, we compute the computation and communication costs of the proposed protocol and other existing protocols, the proposed protocol has less computation and communication costs than other existing protocols in the electronic healthcare system.
Talha Ahsan, Farrukh Zeeshan Khan, Zeshan Iqbal, Muneer Ahmed · 8 authors
Advancement in technology has led to innovation in equipment, and the number of devices is increasing every day. Industries are introducing new devices every day and predicting 50 billion connected devices by 2022. These devices are deployed through the Internet, called the Internet of Things (IoT). Applications of IoT devices are weather prediction, monitoring surgery in hospitals, identification of animals using biochips, providing tracking connectivity in automobiles, smart home appliances, etc. IoT devices have limitations related to security at both the software and hardware ends. Secure user interfaces can overcome software‐level limitations like front‐end‐user interfaces are accessed easily through public and private networks. The front‐end interfaces are connected to the localized storage to contain data produced by the IoT devices. Localized storage deployed in a closed environment connected to IoT devices is more efficient than online servers from a security perspective. Blockchain has emerged as a technology or technique with capabilities to achieve secure administrational authentication and accessibility to IoT devices and their computationally produced data in a decentralized way with high reliability, interrogation, and resilience. In this paper, we propose device, end‐user, and transactional authentication techniques using blockchain‐embedded algorithms. The localized server interacts with the user interface to authenticate IoT devices, end‐users, and their access to IoT devices. The localized server provides efficiency by reducing the load on the IoT devices by carrying out end‐user heavy computational data, including end‐user, IoT device authentication, and communicational transactions. Authentication data are placed on the public ledger in block form, distributed over the system nodes through blockchain algorithms.
Paras Jain, Sunita Dwivedi, Adel R. Alharbi, R. Sureshbabu · 7 authors
Through the use of blockchain technology, sensitive information may be securely communicated without the need to replicate it, which can assist in decreasing medical record mistakes and saving time by eliminating the need to duplicate information. Furthermore, the information is timestamped, which further enhances the security of the data even further. The deployment of blockchain technology in a range of healthcare situations may enhance the security and efficiency of payment transactions. In this way, only those who have been allowed access to patient medical information can see or modify such information. It is proposed in this study that blockchain technology be used to provide an accessible data storage and retrieval mechanism for patients and healthcare professionals in a healthcare system that is both safe and efficient. As of 1970, a variety of traditional knowledge‐based approaches such as Personal Identification Recognition Number (PIRN), passwords, and other similar methods have been made available; however, many token‐based approaches such as drivers’ licenses, passports, credit cards, bank accounts, ID cards, and keys have also been made available; however, they have all failed to establish a secure and reliable transaction channel. Because they are easily misplaced, stolen, or lost, they are usually unable to protect secrecy or authenticate the identity of a legitimate claimant. Aside from that, personally identifiable information such as passwords and PINs is very prone to fraud since they are easily forgotten or guessed by an imposter. Biometric identification and authentication (commonly known as biometrics) are attracting a great deal of attention these days, particularly in the realm of information security systems, due to its inherent potential and advantages over other conventional ways for identifying and authenticating. As a result of the device’s unique biological characteristics, which include features such as fingerprints, facepalms, hand geometry (including the iris), and the device’s iris, it can be used in a variety of contexts, such as consumer banking kiosks, airport security systems, international ports of entry, universities, office buildings, and forensics, to name a few. It is also used in several other contexts, including forensics and law enforcement. Consequently, every layer of the system—sensed data, computation, and processing of data, as well as the storage and administration of data—is susceptible to a broad variety of threats and weaknesses (cloud). There does not seem to be any suitable methods for dealing with the large volumes of data created by the fog computing architecture when normal data storage and security technologies are used. Because of this, the major objective of this research is to design security countermeasures against medical data mining vulnerabilities that originate from the sensing layer and data storage in the Internet of Things’ cloud database, both of which are discussed in more depth further down. A key allows for the creation of a distributed ledger database and provides an immutable security solution, transaction transparency, and the prohibition of tampering with patient information. This mechanism is particularly useful in healthcare settings, where patient information must be kept confidential. When used in a hospital environment, this method is extremely beneficial. As a result of incorporating blockchain technology into the fog paradigm, it is possible to alleviate some of the current concerns associated with latency, centralization, and scalability.
In the Internet of Battlefield Things (IoBT), users and sensor-equipped entities send multiple messages to the Command Control Center (CCC) over the network. The authentication and integrity of these messages are crucial because if an adversary or malicious node transmits, alters, or replays these messages, the consequences will be disasters. Current centralized authentication systems are not suitable for the distributed environment because such schemes are prone to a single point of failure, privacy, and scalability issues. Moreover, the high communication overhead caused by centralization increases energy consumption. In this work, we propose a technique called Blockchain-based Autonomous Authentication and Integrity for the Internet of Battlefield Things (BIoBT) for the C3I system. The proposed technique does not require an explicit authentication channel for the authentication of entities because it is performed on the blockchain side when receiving the data. In addition, it provides data integrity and non-repudiation. BIoBT prototype is created, deployed, and tested on the Ethereum test network. The results prove that BIoBT is efficient, cost-effective, and satisfies the security requirements of a distributed environment for IoBT. BIoBT also outperforms contemporary mechanisms in terms of the number of messages required to establish a secure channel, thereby reducing communication overhead and resource consumption.
We constructed a cryptographic interaction method museum art exchange protocol (MAXP) for museum digital collections on the basis of blockchain technology. Using our method, we build a digital collection exchange system on Ethereum to realize the digital collection’s online exchange between two museums. Compared with the traditional centralized collection digital resource database method, MAXP can avoid the security risks caused by subjective factors and force majeure factors in the exchange process of digital collections, such as hackers and network viruses. In our exchange system we have built, the expression of content covered by digital collections is more convenient, and copyright disputes can be quickly resolved. Concurrently, given the decentralization and anonymity of the blockchain, a regulatory mechanism has been added to MAXP to avoid fraud, illegal fundraising, money laundering and smuggling. The regulatory mechanism we constructed is a dual receiver public key encryption scheme based on the Diffie-Hellman algorithm and the SM2 elliptic curve public key encryption algorithm. The sender encrypts the collection data, and both receivers can decrypt the messages using their respective private keys. One of the receivers is the museum that obtained the collection information, and the other receiver is the regulator. These two receivers can decrypt simultaneously, and the regulator can regulate the information exchange on the blockchain. The Beijing Planetarium and the Beijing Museum of Natural History have completed the exchange of collections through the system we have built. The analysis results show that the regulatory scheme based on the exchange blockchain system of the museum’s digital collections proves to be feasible, with security and expansibility. Our new encrypted exchange management method of digital collections in museums can effectively promote the exchange of collections between museums, and is of great significance to the promotion of cultural heritage and the dissemination of scientific knowledge.
Open access
2 source records
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques