Akhtar Badshah, Muhammad Waqas, Fazal Muhammad, Ghulam Abbas · 7 authors
The next-generation Internet of vehicles (IoVs) seamlessly connects humans, vehicles, roadside units (RSUs), and service platforms, to improve road safety, enhance transit efficiency, and deliver comfort while conserving the environment. Currently, numerous entities communicate in the IoVs environment via insecure public channels that are susceptible to a variety of security assaults and threats. To address these security challenges, we design an anonymous authenticated key exchange mechanism for the IoVs in smart transportation supported by blockchain, referred to as AAKE-BIVT. AAKE-BIVT securely transmits traffic information to a cluster head, before heading to a nearby RSU utilizing the established secret session keys via mutual authentication and key agreement. A cloud server (CS) then securely aggregates data from related RSUs and generates transactions. The CS combines the transactions into blocks in a peer-to-peer network of CSs, and the blocks are confirmed and added to the blockchain via a voting-based consensus method. By means of rigorous informal security studies and formal security analysis through the random oracle model, we reveal that the proposed AAKE-BIVT is resistant to a broad range of potential security assaults in the IoVs environment. Furthermore, a comparative study reveals that AAKE-BIVT outperforms existing state-of-the-art techniques, in terms of security and functionality while being more efficient in terms of communication and computation. Additionally, the blockchain simulation validates the implementation viability of our proposed AAKE-BIVT.
Identity and Access Management (IAM) systems are crucial for any information system, such as healthcare information systems. Health IoT (HIoT) applications are targeted by attackers due to the high-volume and sensitivity of health data. Thus, IAM systems for HIoT need to be built with high standards and based on reliable frameworks. Blockchain (BC) is an emerging technology widely used for developing decentralized IAM solutions. Although, the integration of BC in HIoT for proposing IAM solutions has gained recent attention, BC is an evolving technology and needs to be studied carefully before using it for IAM solutions in HIoT applications. A systematic literature review was conducted on the BC-based IAM systems in HIoT applications to investigate the security aspect. Twenty-four studies that satisfied the inclusion criteria and passed the quality assessment were included in this review. We studied BC-based solutions in HIoT applications to explore the IAM system architecture, security requirements and threats. We summarized the main components and technologies in typical BC-based IAM systems and the layered architecture of the BC-based IAM system in HIoT. Accordingly, the security threats and requirements were summarized. Our systematic review shows that there is a lack of a comprehensive security framework, risk assessments, and security and functional performance evaluation metrics in BC-based IAM in HIoT applications.
The increasing diversity of Internet-of-Things (IoT) application scenarios and explosive growth of access devices have brought more frequent exchanges of resources between different administrative domains. Cross-domain authentication has become a key to safeguard communication and resource interaction among domains. Traditional centralized authentication schemes present heavy management overhead and trust challenges in cross-domain scenarios. Most of existing studies are incapable of establishing trust relationships between domains deployed with different authentication schemes, rendering such high-cost schemes difficult to be generalized. Further, the cross-domain scenario of IoT also raises additional requirements for device privacy and system overhead. In order to tackle these issues, this paper proposes a complete cross-domain authentication and privacy protection scheme, called CCAP, for the IoT based on consortium blockchain. CCAP achieves cross-domain authentication among the IoT domains which may have different configurations from each other. Further, CCAP can be cost-effectively deployed in resource-limited IoT domains and can offer privacy protection and efficient and secure communication for IoT devices. We demonstrate the effectiveness and efficiency of the scheme through experiments in virtual and physical experiment environments as well as comparing and analyzing CCAP with state-of-the-art work.
With the continuous innovative development and popularization of mobile smart devices , the application of Mobile Crowd Sensing (MCS) continues to be studied extensively. However, existing centralized MCS applications that use servers for task publishing and data collection exhibit common problems, such as single points of failure and security vulnerabilities . Accordingly, we proposed a hybrid blockchain-based identity authentication scheme for MCS called HBIA, which uses blockchain technology to resolve the single-point failure problem. HBIA builds a cluster structure based on factors such as geographical location and balance, and uses it to construct a hybrid blockchain , with the cluster head node and internal cluster node authenticating on the public and private chains, respectively. We also implemented zero-knowledge proof (ZKP) to ensure the privacy of participants’ identities, thus balancing the contradiction between blockchain transparency and security. In addition, HBIA uses the zero-knowledge succinct non-interactive argument of knowledge (zk-SNARK) technology to enable off-chain computing and on-chain verification, further reducing the blockchain’s workload. Finally, HBIA was evaluated based on the pavement crack detection task and tested on the Ethereum public test network known as Ropsten. The test results indicate that the identity authentication scheme proposed in this paper is superior to existing schemes in terms of authentication time.
Internet of Things (IoT) is a system of interconnected devices that have the ability to monitor and transfer data to peers without human intervention. Authentication, Authorization and Audit Logs (AAA) are prime features of Network Security and easily attained in legacy systems, however, remains unachieved in IoT. The IoTs require due security considerations as the conventional security mechanisms are not optimized for such devices due to various aspects such as heterogeneity, resource constrained processing, storage and multiple factors. Additionally, the legacy systems are mostly centralized and thus introduce a single point of failure. In this research, a novel framework, FBASHI is presented that is based on fuzzy logic and blockchain technology to achieve AAA services. The proposed system is developed using Hyperledger that is a blockchain platform providing privacy and fast response capability, therefore, it is best suited for the healthcare IoT environments. This work proposes behavior driven adaptive security mechanism for healthcare IoTs and networks based on blockchain by utilizing fuzzy logic and presents a heuristic approach towards behavior driven adaptive security providing AAA services. FBASHI is implemented to analyze its security and practicality. Furthermore, a comparison is drawn with other blockchain-based solutions.
Usman Khalil, Mueen-Uddin, Owais Ahmed Malik, Saddam Hussain
The mechanisms based on the distributed environment have become an obvious choice for solutions, while they have not been limited only to a specific domain (i.e., crypto-currency). Rather, it has influenced other industries to develop robust privacy and security solutions, such as smart houses, smart electrical grids, smart agriculture, smart health care, smart transportation, etc. These Cyber-Physical Systems heavily depend on IoT-based smart devices that constitute a networked system of devices dependent on each other for the smooth operation of the overall system. Hence, security and privacy have become an integral part of all the architectural frameworks they operate in. The adoption of these architectures, such as the Internet of Things (IoT), Internet of Cyber-Physical Things (IoCPT), Cyber-Physical Systems (CPSs), and Internet of Everything (IoE), has reinforced the need to develop solutions based on a distributed environment. Distributed ledger technology, i.e., Blockchain, has taken the lead and may support the development of solutions with robust privacy and security. We provide an updated review of authentication mechanisms developed on blockchain technology that enforce decentralized architectures. We discuss the security issues regarding the authentication of these IoT-enabled smart devices. We evaluate and analyze the study of the proposed literature schemes that pose authentication challenges in terms of computational costs, communication overheads, and models applied to attain robustness. Hence, lightweight solutions for managing, maintaining, processing, and storing authentication data of IoT-enabled assets are a must. From an integration perspective, cloud computing has provided strong support. In contrast, decentralized ledger technology, i.e., Blockchain, and lightweight cryptosystems are the areas for much more to explore. Finally, we discuss the future research challenges, which present an improvement standpoint to help address the ambiguities.
During the COVID-19 pandemic, engagement in various remote activities such as online education and meetings has increased. However, since the conventional online environments typically provide simple streaming services using cameras and microphones, there have limitations in terms of physical expression and experiencing real-world activities such as cultural and economic activities. Recently, metaverse environments, three-dimensional virtual reality that use avatars, have attracted increasing attention as a means to solve these problems. Thus, many metaverse platforms such as Roblox, Minecraft, and Fortnite have been emerging to provide various services to users. However, such metaverse environments are potentially vulnerable to various security threats because the users and platform servers communicate through public channels. In addition, sensitive user data such as identity, password, and biometric information are managed by each platform server. In this paper, we design a system model that can guarantee secure communication and transparently manage user identification data in metaverse environments using blockchain technology. We also propose a mutual authentication scheme using biometric information and Elliptic Curve Cryptography (ECC) to provide secure communication between users and platform servers and secure avatar interactions between avatars and avatars. To demonstrate the security of the proposed mutual authentication scheme, we perform informal security analysis, Burrows–Abadi–Needham (BAN) logic, Real-or-Random (ROR) model, and Automated Validation of Internet Security Protocols and Applications (AVISPA). In addition, we compare the computation costs, communication costs, and security features of the proposed scheme with existing schemes in similar environments. The results demonstrate that the proposed scheme has lower computation and communication costs and can provide a wider range of security features than existing schemes. Thus, our proposed scheme can be used to provide secure metaverse environments.
Quang Nhat Tran, Benjamin Turnbull, Min Wang, Jiankun Hu
Biometric authentication is, over time, becoming an indispensable complementary component to traditional authentication methods that use passwords and tokens. As a result, the research interest in the protection techniques for the biometric template has also grown considerably. In this paper, we present a light-weight AI-based biometric authentication that operates based on the binary representation of a biometric instance. In details, a binary classifier will be trained using the binary strings that represent the intraclass and interclass biometric subjects. The Support Vector Machine and Multi-layer Perceptron Neural Network are chosen as the classifier to evaluate the fingerprint-based and iris-based authentication capability. Afterward, the authenticated biometric string is fed to a hash function to produce a hash value, which is to be used in a Zero-Knowledge-Proof Protocol for the purpose of privacy preservation. In order to improve the recognition of the classifier, we devise a simple yet efficient strategy to enhance the discriminativeness of the binary strings and name it the Composite Features Retrieval. We evaluated the proposed method with the four publicly available fingerprint datasets FVC2002-DB1, FVC2002-DB2, FVC2002-DB3, and FVC2004-DB2 and the iris dataset UBIRISv1. The promising performance shows this method's capability.
Abstract The information system of healthcare operates through various frameworks, like wireless body area network, telecare medical information system, and mobile or electronic healthcare. All these systems need to maintain the personal health records (PHRs) for various users (ie, patients, doctors, and nurses). In such systems, we need to process and store the health related sensitive data (ie, PHRs). In this article, we aim to provide a robust security mechanism to secure exchange and storage of healthcare data, especially PHRs. We present a generic architecture of blockchain‐enabled secure communication mechanism for Internet of Things‐driven personal health records (BIPHRS). We then discuss various threats and security attacks of healthcare system along with different available security mechanisms. The conducted security analysis and detailed comparative study of the state of art blockchain enabled security schemes for PHR systems show that the proposed BIPHRS provides a better security and more functionality features as compared to other similar existing approaches.
Cryptocurrencies have gained popularity in recent years. However, for many users, keeping ownership of their cryptocurrency is a complex task. News reports frequently bear witness to scams, hacked exchanges, and fortunes beyond retrieval. However, we lack a systematic understanding of user-centered cryptocurrency threats, as causes leading to loss are scattered across publications. To address this gap, we conducted a focus group (n=6) and an expert elicitation study (n=25) following a three-round Delphi process with a heterogeneous group of blockchain and security experts from academia and industry. We contribute the first systematic overview of threats cryptocurrency users are exposed to and propose six overarching categories. Our work is complemented by a discussion on how the human-computer-interaction community can address these threats and how practitioners can use the model to understand situations in which users might find themselves under the pressure of an attack to ultimately engineer more secure systems.
The Internet of Vehicles (IoVs) is a communication environment that consists of various interconnected sensing devices, instruments, and other intelligent vehicles and applications connected. However, since intelligent devices on the IoVs communicate through insecure communication methods, Vehicular Ad-Hoc Network (VANET) may be vulnerable to different types of attacks. Therefore, it is essential to deploy a secure access control solution in the VANET environment, one of the critical security services to protect VANET. In this article, we propose a novel access control scheme for blockchain-based VANET communication. We provide detailed information about the network model and threat model required to design our scheme. The security analysis of the network shows its ability to resist various possible attacks. Furthermore, we introduce other intelligent devices to our network and protect their privacy from prying eyes. We also compared other relevant competing programs and found that our performance is better than these competitive programs. Therefore, our solution is suitable for access control in a blockchain-based VANET environment.
With the increasing complexity of the network environment, the traditional authentication technology has exposed its disadvantages such as low efficiency and power concentration. At the same time, the continuous development of information technology also puts forward higher requirements for authentication technology, for example, to realize authentication anonymization while ensuring authentication efficiency and dishonest users can be held accountable. In this paper, cross-domain authentication of heterogeneous networks is analyzed in detail, and a Blockchain-based Supervised Anonymous Cross-domain Authentication (BSA-CA) scheme is proposed. In this scheme, we retain the original infrastructure of the two trust domains. The trust network of users is established in the Blockchain system, and the trust model of heterogeneous cross-domain authentication is constructed by using zero-knowledge proof method. The BSA-CA scheme uses group signature to design anonymous supervisory properties. System analysis results show that the BSA-CA scheme has a good balance between security and authentication efficiency.
Internet of Vehicles (IoVs) presents promising opportunities for vehicle to everything (V2X) applications, wherein authentication acts as the cornerstone to realize trustworthy vehicular context and to support advanced applications. However, existing authentication schemes mainly depend on centralized servers with both security and privacy issues. In this paper, we propose a CyberTwin (CT) empowered blockchain framework for authentication, namely CyberChain, to reduce both the communication and storage cost while maintaining vehicular privacy. By designing a blockchain system in the cyberspace, we decouple the consensus process from the physical world, so that the operation cost of blockchain can be reduced. A Privacy-Preserving Parallel Pedersen Commitment (P4C) algorithm is designed to protect the privacy of vehicles and accelerate the authentication process. To further enhance the operation efficiency of CyberChain, we propose a Diffused Practical Byzantine Fault Tolerance (DPBFT) mechanism to reach consensus in the cyberspace that can reduce consensus latency. The proposed cyberchain framework and the associated mechanisms are evaluated by qualitative analysis and simulations. The evaluation results demonstrated that the proposed cyberchain based framework significantly improves the authentication performance in terms of authentication latency, privacy, communication overhead and storage cost.
The advent of the data age is impacting the entire world, changing people's lives, work, and thinking. The advent of the big data era has also had a great impact and influence on the management work, and it is a new test of the archives department's archives management ability and level. The new data distributed storage technology-blockchain, provides new methods and ideas for data circulation and sharing through the characteristics of decentralization, timing, distributed ledger, open consensus, openness and transparency, and anti-tampering. Based on big data, this paper studies the construction of a decentralized digital authentication system for cultural archives management.
Dec 1, 2021·2021 IEEE 23rd Int Conf on High Performance Computing & Communications; 7th Int Conf on Data Science & Systems; 19th Int Conf on Smart City; 7th Int Conf on Dependability in Sensor, Cloud & Big Data Systems & Application (HPCC/DSS/SmartCity/DependSys)
With the increasing cross-factory cooperation in manufacturing, the communication between Industrial Internet of Things (IIoT) devices from discrete domains (e.g., indepen-dent factories) has become common. Authentication schemes are widely adopted to secure device-to-device communications. However, most existing schemes directly use the real identities of IIoT devices for communication and even publish them onto a publicly available blockchain. It allows attackers to easily identify devices, relate them with specific factories owned them, and further extract the factories' private information. To address this issue, we propose a privacy-aware cross-domain authentication scheme for IIoT devices based on blockchain. In the proposed scheme, IIoT devices use different pseudonyms for each session instead of their real identities to maintain anonymity and un-linkability. Besides, the proposed certificateless signature scheme can eliminate the reliance on certificates that might expose the ownership of devices. We also proposed an identity management mechanism to realize identity revocation and malicious device tracking. The security analysis and performance evaluation results show that our scheme is feasible and efficient for cross-domain authentication.
The rapid development of the Internet of Things (IoT) has promoted the wide adoption of mobile medical devices, which monitor patients’ body conditions in real-time. The collected health-related data are highly sensitive, requiring careful protection during the accessing and transmission for specialized analysis. Yet, existing efforts either rely on centralized authentication for the numerous end devices or are designed to be partially distributed for a closed institution, both lacking scalability for mobile healthcare scenarios. In this paper, we propose HealthTrust that provides a generalized and flexible authentication scheme for distributed medical devices in the cross-institution context. With blockchain as the building block, HealthTrust jointly exploits smart contracts and secure authentication to attain controlled transmission and secure exchanging of healthcare data between institutions. We have implemented the system functions with a prototype based on Ethereum. Experimental results and safety analysis demonstrate that HealthTrust can well satisfy both the safety and feasibility requirements.
Traditional paper certificates have difficulties in preservation and management, causes tampering and forgery. A secure decentralized-based platform could mitigate the risk with-out any third-party intervention using Ethereum in the core. This work proposed a novel architecture to generate digital certificates using a distributed ledger automatically. Further, it authenticates the same using private keys with trusted certificate authorities. The framework is tested on FU540 (RISC-V) architecture. A detailed mechanism for generating and authenticating certificates is validated on FU540 board with blockchain integration. Mechanism flow starts with the admin. It adds the source organization blocks having the user detail records to the distributed ledger. Verifiers put the request to the source authorizer to perform verifications. This protocol could protect private information and identify the inter mediators who tried to diversify
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Samia Boutalbi, Julio César Pérez García, Abderrahim Benslimane
Currently, the Internet of Things (IoT) is widely used by the emerging of internet-integrated wireless devices in daily life. In order to communicate and exchange data with each other, IoT devices must pass by a gateway that belongs to the same network. But, considering the mobility of such devices and their constraints, it becomes difficult to trust and to connect from a gateway to another. Therefore, this paper introduces a blockchain-based secure handover protocol. It ensures an anonymous mutual authentication solution between a mobile IoT device and a visited gateway by using Zero-Knowledge Proof (ZKP) protocol. To do, simulations have been performed thanks to a discrete events simulator. In addition to a good security level, compared with the most used protocol (DTLS), our simulation results lead to better performance in terms of temporal complexity, energy consumption, and communication cost.
Internet of Vehicles (IoV) has emerged as an advancement over the traditional Vehicular Ad-hoc Networks (VANETs) towards achieving a more efficient intelligent transportation system that is capable of providing various intelligent services and supporting different applications for the drivers and passengers on roads. In order for the IoV and VANETs environments to be able to offer such beneficial road services, huge amounts of data are generated and exchanged among the different communicated entities in these vehicular networks wirelessly via open channels, which could attract the adversaries and threaten the network with several possible types of security attacks. In this survey, we target the authentication part of the security system while highlighting the efficiency of blockchains in the IoV and VANETs environments. First, a detailed background on IoV and blockchain is provided, followed by a wide range of security requirements, challenges, and possible attacks in vehicular networks. Then, a more focused review is provided on the recent blockchain-based authentication schemes in IoV and VANETs with a detailed comparative study in terms of techniques used, network models, evaluation tools, and attacks counteracted. Lastly, some future challenges for IoV security are discussed that are necessary to be addressed in the upcoming research.
Adrián Silveira, Gustavo Betarte, Maximiliano Cristiá, Carlos Luna
Mimblewimble is a privacy-oriented cryptocurrency technology which provides security and scalability properties that distinguish it from other protocols of its kind. In previous work we have proposed an idealized model that captures the main features of the Mimblewimble protocol with a model-driven verification approach. In this work, we present an extension of our model to enable zero-knowledge proofs in order to prove that the transaction amount is in a certain range without revealing the value. Furthermore, we provide some security properties a range proof scheme should satisfy.
The Industrial Internet of Things (IIoT) integrates heterogeneous industrial devices, intelligent sensors, and actuators to provide a new dimension to the industrial systems and environments. As the IIoT expands to various aspects of the Industry, devices from different industrial domains need to collaborate without compromising the privacy and security of the data being exchanged and stored. The biggest challenge IIoT is going to face is security and privacy. Any attack against an industrial environment can adversely affect human life, the quality of products, and permanent damage the machines for an extended period. Authentication is considered the first security control in IIoT system to ensure that the right user accesses the right resources. Blockchain is a distributed public ledger that contains blocks of tamper-proof data. Blockchain-based cybersecurity platforms can protect the connected de-vices in an IIoT platform using digital identities and can be used to authenticate the participating entities. A blockchain enabled IIoT platform has a decentralized infrastructure making it impossible for hackers to attack a network because all participants are immediately notified of any alterations. This work presented a critical review of the existing research works on the authentication solutions based on blockchain based technologies. The current research gaps were analyzed and discussed as well.