Pravin Mundhe, Pooja Phad, R. Yuvaraj, Shekhar Verma · 5 authors
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
1,104 results · page 23 of 46
Pravin Mundhe, Pooja Phad, R. Yuvaraj, Shekhar Verma · 5 authors
No abstract is available for this record.
Anusha Vangala, Ashok Kumar Das, Ankush Mitra, Sajal K. Das · 5 authors
Precision farming has a positive potential in the agricultural industry regarding water conservation, increased productivity, better development of rural areas, and increased income. Blockchain technology is a better alternative for storing and sharing farm data as it is reliable, transparent, immutable, and decentralized. Remote monitoring of an agricultural field requires security systems to ensure that any sensitive information is exchanged only among authenticated entities in the network. To this end, we design an efficient blockchain-enabled authenticated key agreement scheme for mobile vehicles-assisted precision agricultural Internet of Things (IoT) networks called$AgroMobiBlock$. The limited existing work on authentication in agricultural networks shows passive usage of blockchains with very high costs.$AgroMobiBlock$proposes a novel idea using the elliptic curve operations on an active hybrid blockchain over mobile farming vehicles with low computation and communication costs. Formal and informal security analysis along with the formal security verification using the Automated Validation of Internet Security Protocols and Applications (AVISPA) software tool have shown the robustness of$AgroMobiBlock$against man-in-the-middle, impersonation, replay, physical capture, and ephemeral secret leakage attacks among other potential attacks. The blockchain-based simulation on large-scale nodes shows the computational time for an increase in the network and block sizes. Moreover, the real-time testbed experiments have been performed to show the practical usefulness of the proposed scheme.
Mustafa Kara, Hisham Raad Jafer Merzeh, Muhammed Ali Aydın, Hasan H. Balık
No abstract is available for this record.
Edward Mensah Acheampong, Shijie Zhou, Yongjian Liao, Emmanuel Antwi‐Boasiako · 5 authors
Digital technologies, such as wireless body area networks (WBANs) for mobile health (mHealth) applications, are expected to enhance the quality of the public health care system. Although mHealth can improve patients' quality of health by offering outpatient real-time health monitoring systems instead of being stuck in the hospital all the time to monitor chronic diseases. The major challenge in adopting mHealth is data security and privacy. The health data routed on the internet from the patient monitoring device to the health center for remote monitoring is vulnerable to confidentiality attacks. To handle this issue, we present an authentication scheme based on non-interactive zero-knowledge proof (NIZKP), which issues certificates and authenticates monitoring devices each time performing transactions without revealing sensitive information. Our authentication scheme provides a high level of security with a low computational cost, which is lightweight for WBANs.
Anusha Vangala, Sandip Roy, Ashok Kumar Das
Blockchain technology has a significant application in smart farming due to its immutability, decentralization and transparency properties. Data exchanged in an Internet of Things (IoT)-based smart agriculture can be used to remotely monitor the fields and regulate the crop needs for optimal productivity. However, such data is sensitive to several attacks, such as man-in-the-middle attack, replay attack, ephemeral secret leakage attack, impersonation attack and denial of service (DoS) attack. The existing solutions to counter these attacks are either costly or lack significant security features. To mitigate these issues, we design a novel lightweight blockchain based authentication scheme based on a fully decentralized and distributed architecture. The designed scheme is subjected to a rigorous security analysis and also a formal security verification using the widely-used Automated Validation of Internet Security Protocols and Applications (AVISPA) tool, and it is shown that the scheme is robust and secure against various passive and active attacks. A detailed comparative analysis shows that the proposed scheme has the low communication cost and significantly lower computation cost while satisfying all the security and functionality features as compared to those for other existing relevant schemes.
Sana Hafeez, Mahmoud A. Shawky, Mohammad Al-Quraan, Lina Mohjazi · 6 authors
Unmanned aerial vehicles (UAV), an emerging architecture that embodies flying ad-hoc networks, face critical privacy and security challenges, mainly when engaged in data-sensitive missions. Therefore, message authentication is a crucial security feature for drone communication. This paper presents a Blockchain-based Efficient, and Trusted Authentication scheme for UAV communication BETA-UAV, which exploits the inherent properties of blockchain technology concerning memorability and immutable to record communication sessions via transaction using a smart contract. The smart contract in BETA-UAV allows participants to publish and call transactions from the blockchain network. Furthermore, the transaction addresses are proof of freshness and trustworthiness for subsequent transmissions. Furthermore, we investigate the ability to resist active attacks, e.g., impersonation, replaying, and modification. In addition, we evaluate the gas costs associated with the smart contract's functions by implementing BETA-UAV on the Ethereum public blockchain. Comparing computation and communication over-heads shows that the proposed approach can save significant costs over traditional techniques.
Mohamed A. El-Zawawy, Alessandro Brighente, Mauro Conti
The inclusion of drones in Internet of Vehicles (IoV) is a current trend that presents significant trade-offs. On the one hand, Unmanned Aerial Vehicles (UAVs) provide advantages such as enabling ground communications also when physical obstacles limit the connectivity. On the other hand, they increase the attack surface. For instance, physical attacks on drones provide the attacker with credentials that can be used to inject bogus information into the IoV network, thus jeopardizing not only security but also users’ safety. In this scenario, authentication plays a fundamental role to guarantee security. It is however fundamental to develop authentication protocols that can, at the same time, protect ground users’ data and prevent attacks to drones. However, currently available authentication schemes cannot guarantee security in case of attacks to drones. In this paper, we propose a Blockchain-supported authentication protocol for Drone-assisted IoV using Elliptic curve cryptography (BDIVE). Compared to existing authentication protocols, we extend the threat model from an honest-but-curious drone to active attacks against drones.BDIVEprovides both energy-efficiency, traceability, and accountability thanks to the use of blockchain at the Trusted Authority (TA). Using Burrow-Abadi–Needham (BAN) logic, we analyze and prove the security of mutual authentication inBDIVE. We also prove the security ofBDIVEagainst several attacks by implementing it in AVISPA. To assess its scalability and energy efficiency, we implementBDIVEusing Omnetpp with its Castalia simulator. The comparison ofBDIVEwith currently existing authentication protocols, shows that it reduces the energy consumption up to 70% and the computational cost up to 68%, while providing resistance to previously unconsidered attack vectors.
Ghada Sultan Aljumaie, Wajdi Alhakami
Wireless Sensor Networks (WSNs) are becoming more popular for many applications due to their convenient services. However, sensor nodes may suffer from significant security flaws, leading researchers to propose authentication schemes to protect WSNs. Although these authentication protocols significantly fulfill the required protection, security enhancement with less energy consumption is essential to preserve the availability of resources and secure better performance. In 2020, Youssef et al. suggested a scheme called Enhanced Probabilistic Cluster Head Selection (LEACH-PRO) to extend the sensors' lifetime in WSNs. This paper introduces a new variant of the LEACH-PRO protocol by adopting the blockchain security technique to protect WSNs. The proposed protocol (SLEACH-PRO) performs a decentralized authentication mechanism by applying a blockchain to multiple base stations to avoid system and performance degradation in the event of a station failure. The security analysis of the SLEACH-PRO is performed using Burrows-Abadi-Needham (BAN) logic and Automated Validation of Internet Security Protocols and Applications (AVISPA) tool. Moreover, the SLEACH-PRO is evaluated and compared to related protocols in terms of computational cost and security level based on its resistance against several attacks. The comparison results showed that the SLEACH-PRO protocol is more secure and requires less computational cost compared to other related protocols.
Xianwang Xie, Bin Wu, Botao Hou
The Internet of Vehicles (IoV) can significantly improve transportation efficiency and ensure traffic safety. Authentication is regarded as the fundamental defense line against attacks in IoV. However, the state-of-the-art approaches suffer from several drawbacks, including bottlenecks of the single cloud server model, high computational overhead of operations, excessive trust in cloud servers and roadside units (RSUs), and leakage of vehicle trajectory privacy. In this paper, BEPHAP, a Blockchain-based Efficient Privacy-preserving Handover Authentication Protocol with key agreement for internet of vehicles, is introduced to address these problems. BEPHAP achieves anonymous cross-domain mutual handover authentication with key agreement based on the tamper-proof blockchain, symmetric cryptography, and the chameleon hash function under a security model that cloud servers and RSUs may launch attacks. BEPHAP is particularly well suited for IoV since it allows vehicles only need to perform lightweight cryptographic operations during the authentication phase. BEPHAP also achieves data confidentiality, unlinkability, traceability, non-repudiation, non-frameability, and key escrow freeness. Formal verification based on ProVerif and formal security proofs based on the BAN logic indicates that BEPHAP is resistant to various typical attacks, such as man-in-the-middle attacks, impersonation attacks, and replay attacks. Performance analysis demonstrates that BEPHAP surpasses existing works in both computation and communication efficiencies. And the message loss rate remains 0 at 5000 requests per second, which meets the requirement of IoV.
Irfan Simsek
Sensitive data have to be communicated via secure channels generally set up by using cryptography. This needs an authentic key exchange, which in turn requires an authentication process. However, the Internet of Things (IoT) includes its own challenges and security requirements. This paper introduces a novel signature algorithm and handshake protocol combining a zero-knowledge proof method being based on the graph isomorphism problem with an identity-based scheme to provide authentication with integrated key exchange while meeting the IoT challenges and security requirements. Our approach applies a way to parallelly perform multiple rounds usually needed by zero-knowledge proofs while retaining the same security level. Moreover, we present a graph compression algorithm providing a compression ratio of up to ca. 7:1. Our handshake protocol is resistant to active man in the middle attacks and does not require any public data pre-distribution or secret pre-sharing. Additionally, no third party has to hold any device-specific authentication data. Furthermore, our approach is application-independent and does not require any additional components or procedures. This paper also evaluates the high performance of our approach with regard to multiple affecting factors.
Zhengtao Jiang, Ye Chen, Huiqiang Li, Ting Yu
As the basic problem that introduces the idea of secure multi-party computation (SMC), millionaires’ problem (MP) is one of the research highlights in the field of SMC. However, most of current protocols for MP are only secure in semi-honest model, which using public key cryptography schemes, and there are few secure schemes in malicious model exist security defects. Therefore, this paper analyzes the Li et al.’s protocol for MP that secure in malicious model. Firstly, we point out several behaviours that can be successfully implemented in Li et al.’s protocol. Secondly, by using the zero-knowledge proof (ZKP) for the equality of discrete logarithm (DL), cut-and-choose method etc. We propose the improved protocol and show how to detect malicious behaviours. Finally, we analyze the correctness and security against malicious behaviours of the improved protocol.
Randhir Kumar, Ahamed Aljuhani, Prabhat Kumar, Abhinav Kumar · 6 authors
While 5G can provide high-speed Internet connectivity and over-the-horizon control for Unmanned Aerial Vehicles (UAVs), authentication becomes a key security component in 5G-enabled UAVs. This is due to fact that the communicating entities in the network mostly uses unsecured communication channel to exchange critical surveillance data. Authentication thus plays a crucial role in the 5G-enabled UAV network, providing a range of security services such as credential privacy, Session-Key (SK) security, and secure mutual authentication. However, transparency, anonymity, traceability and centralized control are few major security requirements that cannot be fulfilled by the traditional authentication schemes. One of the upcoming technologies that can provide a solution for present centralized 5G-enabled UAV network is blockchain-based authentication scheme. Motivated from aforementioned discussion, this paper presents a Permissioned Blockchain empowered Secure Authentication and Key Agreement framework in 5G-enabled UAVs. In this framework, first an authentication phase between UAV-to-UAV, UAV-to-Edge Server (ES) and Edge-to-Cloud Server (CS) supporting mutual authentication and key agreement is proposed. The authenticated surveillance data collected from UAV is used by the peer-to-peer CS for transaction verification, block creation and addition using smart contract-based consensus mechanism. The practical implementation of framework shows the effectiveness of the proposed approach.
Xin Liu, Miao Wang, Tanyang Wang, Ruisheng Zhang
No abstract is available for this record.
Mehedi Masud, Gurjot Singh Gaba, Pardeep Kumar, Andrei Gurtov
Ambient Intelligence (AmI) in Internet of Things (IoT) has empowered healthcare professionals to monitor, diagnose, and treat patients remotely. Besides, the AmI-IoT has improved patient engagement and gratification as doctors’ interactions have become more comfortable and efficient. However, the benefits of the AmI-IoT-based healthcare applications are not availed entirely due to the adversarial threats. IoT networks are prone to cyber attacks due to vulnerable wireless mediums and the absentia of lightweight and robust security protocols. This paper introduces computationally-inexpensive privacy-assuring authentication protocol for AmI-IoT healthcare applications. The use of blockchain & fog computing in the protocol guarantees unforgeability, non-repudiation, transparency, low latency, and efficient bandwidth utilization. The protocol uses physically unclonable functions (PUF), biometrics, and Ethereum powered smart contracts to prevent replay, impersonation, and cloning attacks. Results prove the resource efficiency of the protocol as the smart contract incurs very minimal gas and transaction fees. The Scyther results validate the robustness of the proposed protocol against cyber-attacks. The protocol applies lightweight cryptography primitives (Hash, PUF) instead of conventional public-key cryptography and scalar multiplications. Consequently, the proposed protocol is better than centralized infrastructure-based authentication approaches.
Krzysztof Kanciak, Konrad Wrona, Michał Jarosz
Many high-impact Internet of Things (IoT) scenarios, such as humanitarian assistance and disaster relief, public safety, and military operations, require the establishment of a secure federated IoT environment. One of the critical challenges in the implementation of federated IoT solutions involves establishing a secure and authenticated key management mechanism. We propose and validate in a laboratory environment a novel federated IoT onboarding and key management solution. Our dl-mOT protocol integrates an efficient identity-based modified Okamoto-Tanaka (mOT) protocol with a distributed ledger in order to establish an anchor of trust between federation members.
Sana Javed, Muhammad Asghar Khan, Ako Muhammad Abdullah, Amjad Alsirhani · 7 authors
The Internet of Drones (IoD) has recently gained popularity in several military, commercial, and civilian applications due to its unique characteristics, such as high mobility, three-dimensional (3D) movement, and ease of deployment. Drones, on the other hand, communicate over an unencrypted wireless link and have little computational capability in a typical IoD environment, making them exposed to a wide range of cyber-attacks. Security vulnerabilities in IoD systems include man-in-the-middle attacks, impersonation, credential leaking, GPS spoofing, and drone hijacking. To avoid the occurrence of such attacks in IoD networks, we need an extremely powerful security protocol. To address these concerns, we propose a blockchain-based authentication scheme employing Hyperelliptic Curve Cryptography (HECC). The concepts of a blockchain as a Certificate Authority (CA) and a transaction as a certificate discussed in this article are meant to facilitate the use of a blockchain without CAs or a Trusted Third Party (TTP). We offer a security analysis of the proposed scheme, which demonstrates its resistance to known and unknown attacks. The proposed scheme resists replay, man-in-the-middle, device impersonation, malicious device deployment, Denial-of-Service (DoS), and De-synchronization attacks, among others. The security and performance of the proposed scheme are compared to relevant existing schemes, and their performance is shown to be better in terms of security attributes as well as computation and communication costs than existing competitive schemes. The total computation cost of the proposed scheme is 40.479 ms, which is 37.49% and 49.79% of the two comparable schemes. This shows that the proposed scheme is better suited to the IoD environment than existing competitive schemes.
Xinyin Xiang, Jin Cao, Weiguo Fan
No abstract is available for this record.
Wei Liu, Jian Weng, Bingsheng Zhang, Kai He · 5 authors
No abstract is available for this record.
Xiaotong Zhou, Debiao He, Muhammad Khurram Khan, Wei Wu · 5 authors
Vehicular Ad-hoc Networks (VANETs) have potential applications in improving the efficiency and safety for intelligent transportation systems. The openness of VANETs, however, also introduces privacy and security implications. Despite a number of conditional privacy-preserving authentication (CPPA) schemes with anonymity and conditional traceability have been designed for VANETs, a majority of these schemes cannot be directly applied to a real-world setting (e.g., due to the need for a certificate manager for issuing keys in PKI-based solutions, or the inherent key escrow problem in ID-based solutions). There have also been attempts to design blockchain-based CPPA schemes, but these schemes may not support key revocation or are inefficient (e.g., due to on-chain operations). This paper proposes an efficient blockchain-based CPPA (EBCPPA) scheme, which is designed to mitigate the above limitations. Our proposal consists of two key building blocks, namely: signature of knowledge and smart contract. To evaluate the feasibility, we present the security and performance analyses of EBCPPA. Specifically, the performance evaluations show that EBCPPA is more efficient than other existing state-of-the-art solutions, in terms of signing (improving at least 49.71%), the verification (improving at least 32.84%) and bandwidth requirement (reducing at least 27.59%).
Randhir Kumar, Prabhat Kumar, Ahamed Aljuhani, A.K.M. Najmul Islam · 6 authors
The recent development of Internet of Things (IoT) and Unmanned Aerial Vehicles has revolutionized traditional agriculture with intelligence and automation. In a typical Intelligent Agriculture (IA) ecosystem, massive and real-time data are generated, analyzed, and sent to the Cloud Server (CS) for the purpose of addressing complex agricultural issues, such as yield prediction, water feed calculation, and so on. This helps farmer and associated stakeholders to take correct decision that improves the yield and quality of agricultural product. However, the distributed nature of IA entities and the usage of insecure wireless communication open various challenges related to data sharing, monitoring, storage, and further makes the entire IA ecosystem vulnerable to various potential attacks. In this article, we exploit deep learning and smart contract to propose a new IoT-enabled IA framework for enabling secure data sharing among its various entities. Specifically, first we develop new authentication and key management scheme to ensure secure data transmission in IoT-enabled IA. The encrypted transactions are then used by the CS to analyze and further detect intrusions by a novel deep learning architecture. In CS, the smart contract (SC)-based consensus mechanism is executed on legitimate transactions that verifies and adds the formed blocks into blockchain by a peer-to-peer CSs network. In comparison to existing competing security solutions, a rigorous comparative research demonstrates that the proposed approach provides greater security and more utility characteristics.
Lei Yan, Maode Ma, Dandan Li, Xiaohong Huang · 6 authors
No abstract is available for this record.
Victor Youdom Kemmoe, Yongseok Kwon, Rasheed Hussain, Sunghyun Cho · 5 authors
Group Key Exchange (GKE) is an important tool to develop secure multi-user applications such as group text messages, ad-hoc networks, and so on. Most of the currently deployed GKE schemes are synchronous, i.e., they require all the participants to be online during their execution. However, with more battery-powered devices being used in such applications, the synchronicity requirement is challenging to fulfill. To fill the gaps, asynchronous GKE schemes have been introduced in the literature. Nevertheless, the currently available asynchronous and synchronous GKE schemes rely on Trusted Third Parties (TTPs) for key establishment and management. To this end, reliance on TTPs is a serious shortcoming since TTPs are well known to be the single point of failure. Furthermore, the existing GKE schemes require participants to perform all computations, which can degrade the performance of resource-constrained devices such as Internet of Things (IoT) devices. To solve these problems, in this paper, we propose an asynchronous GKE scheme that uses blockchain and smart contracts to store the security keys-related material and reduce the computational load of the participants. Furthermore, our proposed scheme provides Perfect Forward Secrecy (PFS) and Post-Compromised Security (PCS). Our implementation on Ethereum shows that the proposed scheme can scale to more than 100 participants when combined with a distributed storage system.
Ivan Futivić
Pametni ugovori su programi koji se na deterministički način izvršavaju na kriptografskom lancu blokova pomoću virtualnog stroja i zajedničkog mehanizma konsenzusa. Ti programi mogu implementirati vlastitu logiku te raspolagati kriptovalutama. Stoga je od iznimne važnosti osigurati da su pametni ugovori otporni na napade i zlouporabu. U prvom dijelu rada predstavljeni su osnovni termini i potrebne tehnologije za korištenje pametnih ugovora te je ukratko prikazana njihova povijest. U drugom dijelu prikazane su neke od najčešćih ranjivosti koje su prisutne u pametnim ugovora i načini na koji mogu biti iskorištene od strane napadača. Objašnjeni su načini kako se mogu preventirati spomenute ranjivosti te su navedeni neki primjeri napada koji su se zaista dogodili. Konačno, predstavljena je potencijalna Front Running ranjivost u ERC-918 pametnim ugovorima te je implementiran jednostavni primjer pomoću kojeg je simuliran napad. Također, predložen je jedan od potencijalnih načina zaštite od takvoga napada.
Paulo Chaínho
In the evolution from 5G to beyond 5G networks, new business models are emerging where multi-domain and multistakeholder scenarios will play a paramount role as enablers. In these scenarios, the automated management of the services with minimal human intervention, also known as zero-touch management, is a pivotal requirement to ensure a proper functioning and to enable real-time responses to possible incidents or scalability needs. Nonetheless, these new scenarios and requirements also introduce new security risks that entail a complex threat landscape for beyond 5G networks. Hence, zero-touch management demands new solutions capable of securely controlling network resources into end-to-end scenarios distributed in multiple domains. In this vein, several challenges arise and need to be addressed, such as integrity, non-repudiation, confidentiality, security, and trust. Therefore, the H2020 5GZORRO project proposes new security and trust solutions for multi-domain and multi-stakeholder scenarios in 5G and beyond networks. To deal with the utmost importance security and trust challenges, we introduce different modules to mitigate them, namely, integrity and non-repudiation through Distributed Ledger Technologies, decentralized identity through an Identity and Permission Manager, end-to-end trustworthy relationships via a Trust Management Framework, secure workloads across different tenants and stakeholders via Trusted Execution Environment Security Management, detection and response to internal vulnerabilities and attacks via Network Monitoring, and on-demand secure cross-domain connections via VPN-as-a-Service. Therefore, the built security and trust 5GZORRO mechanisms form a secure environment with zero-touch automation capabilities, minimizing human intervention.