Identity authentication is a very important aspect of information security theory. Usually, the problem that identity authentication is prone to is that the user name and password are transmitted in the network in plaintext. The security is not enough, and it is very vulnerable to replay attacks and dictionary attacks. Dynamic passwords Although authentication is more secure, if there is a problem with the time synchronization between the server and the client, the user will not be able to login for a long time. Moreover, the password of the dynamic password is the same within a period of time, and it is also vulnerable to replay attacks. Therefore, a decentralized dynamic identity authentication system based on blockchain isn’t proposed. By using a public key + nonce (integer number that increases from 0) to sign in, It only solves the problem of over-centralized identity authentication, but also solves the replay attack. Improved the security of the identity authentication process.
Abstract In this paper, we propose a novel cryptographic primitive named reusable group fuzzy extractor (RGFE) allowing any member of a group to extract and reproduce random strings from a fuzzy and non-uniform source of high entropy (called fingerprint). Any group member can anonymously generate a random string for the group using his fingerprint and can be traced when needed, whereas other members can reproduce the string using their own fingerprints. Moreover, a fingerprint can be repeatedly used to generate multiple random strings. Basing on RGFE, we present group-shared Bitcoin wallet, which can be used by a group of users to receive or spend coins via biometrics in a traceable way.
User Authentication and Security Systems
Advanced Steganography and Watermarking Techniques
Distributed business advertising has proliferated in related vehicles, to advance their goods through vehicle communications or frameworks. Despite the possibility of spreading promotions in the vehicle network, but facing difficulties in the organization, especially on security and protection. In particular, vehicles may be sneaky to trick sponsors into getting rewards without spreading advertisements, which can cause “free driving” problems in this exercise. In addition, concerns about possible spill protection may disinterest the vehicle during the time spent on ad implementation. In addition, outside DDoS attacks and interior disappointment purposes can also affect administrative accessibility. To solve this problem, we investigated the ability of blockchain innovations to develop plausible and unknown plans for publication on the vehicle network. We first present a review of a blockchain based advertising deployment system.
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Security and forensics represent two key components for network management, especially to guarantee the trusted operation of massive access networks such as the Internet of Things (IoT). As a core technology to provide low latency and high communication for IoT, Mobile Edge Computing (MEC) pulls computing resources from remote cloud centers to devices. The process of MEC service involves three types of entities: devices, data generated by devices and digital evidence generated after the data interaction. These entities are fully distributed and difficult to protect through traditional, highly centralized security and authentication mechanisms. As a decentralized shared ledger and database, the emerging blockchain is considered to provide cooperative trust and collaborative action among multiple subjects while ensuring the integrity and confidentiality of data. Because of its anonymity, non-tampering and traceability, the blockchain arouses research on the combination of blockchain and edge computing for device security, data security and forensics in IoT. This survey analyzes the application of blockchain in MEC-IoT systems and mainly focuses on approaches and technologies to manage the security and forensics issues for IoT. Finally, we present open issues and prospects for future work and research directions.
Passwords are currently the king in online authentication. But passwords come with a lot of baggage - how to use them, store them, hide them, and obfuscate them. Every year, there are plenty of cyber-attacks which involves passwords being stolen. These passwords are stored and transmitted over networks and hence, many mistakes can be made while doing so. In this paper, a relatively new form of authentication is explored - one based on the concept of Zero-Knowledge Proof (ZKP). It further explores how ZKP can provide additional security to the authentication mechanism by taking the transmission of passwords out of the picture. This paper also discusses the Replay attack vulnerability present in the non-interactive implementation of ZKP and proposes a two-fold mitigation strategy against the vulnerability.
Mwrwan Abubakar, Zakwan Jaroucheh, Ahmed Al Dubai, Bill Buchanan
The Session Initiation Protocol (SIP) is the principal signalling protocol in Voice over IP (VoIP) systems, responsible for initialising, terminating, and maintaining sessions amongst call parties. However, the problem with the SIP protocol is that it was not designed to be secure by nature as the HTTP digest authentication used in SIP is insecure, making it vulnerable to a variety of attacks. The current solutions rely on several standardised encryption protocols, such as TLS and IPsec, to protect SIP registration messages. However, the current centralised solutions do not scale well and cause algorithm overload when encoding and decoding SIP messages. In trying to rectify this issue, we propose in this paper a blockchain-based lightweight authentication mechanism, which involves a decentralised identity model to authenticate the SIP client to the SIP server. Our mechanism uses a smart contract on the Ethereum blockchain to ensure trust, accountability and preserves user privacy. We provided a proof-of-concept implementation to demonstrate our work. Further analysis of this approach's usability, mainly CPU and memory usage, was conducted comparing to IPsec and TLS. Then we discussed our system's security and presented a security analysis. Our analysis proves that our approach satisfies the SIP protocol security requirements.
Mustafa Kara, Muhammed Ali Aydın, Hasan H. Balık
Peer-to-peer VoIP applications are exposed to threats in the Internet environment as they carry out conversations over the Internet, which is an electronic communication line, and its security has always been largely a matter of concern. Authentication of the caller is the first line of defense among the security principles and is an important principle to provide security in VoIP application. Authentication methods in VoIP applications are usually based on trusted third parties or through centralized architecture. This situation creates problems in terms of single point of failure and privacy in call security over IP based communications. However, blockchain technology with a distributed architecture offers an innovative solution to multimedia communication authentication model. In this paper, a blockchain-based mutual authentication scheme for VoIP applications is proposed. In addition, the model's having a comprehensive security structure against various threats is explained via security and communication cost analysis. The proposed schema shows better performance than the methods that make a verification through the centralized architecture in the literature. The proposed model has been formally verified using the AVISPA tool, and it has been proven that the model is safe against potential threats.
Due to the emergence of heterogeneous Internet of Medical Things (IoMT) (e.g., wearable health devices, smartwatch monitoring, and automated insulin delivery systems), large volumes of patient data are dispatched to central cloud servers for disease analysis and diagnosis. Although this direct mode brings a lot of convenience for both patients and medical professionals (MPs), the open communication channel between them also incurs several security and privacy issues, such as man-in-the-middle attacks, eavesdropping attacks, and tracking attacks. Based on the unsolved challenges in wireless medical sensor networks (WMSNs), several researchers have proposed various authentication and key agreement (AKA) protocols for this type of healthcare system recently. However, most of these protocols do not perceive physical-layer security and over-centralized server problem in WMSN. In this article, to address these two open problems, we propose a lightweight and reliable authentication protocol for WMSN, which is composed of cutting-edge blockchain technology and physically unclonable functions (PUFs). In addition, a fuzzy extractor scheme is introduced to deal with biometric information. Subsequently, two security evaluation methods are used to prove the high reliability of our proposed scheme. Finally, performance evaluation experiments illustrate that the proposed mutual authentication protocol requires the least computation and communication cost among the compared schemes.
K. S. Arikumar, Deepak Kumar A, GowthamC, Sahaya Beni Prathiba
The most shocking events were was the recent discovery of the fraudulent activities in the Punjab National Bank. This is due to frequent systemic failures that detect human errors. Blockchain technology is the greatest solution for this issue. It is surprisingly common for the information settlement mechanism like SWIFT to be on a isolated ledger from the payment settlement mechanism. If the banks uses a ledger that stores information settlement distributed across all the participants, then the fraudulent user may reflect on all the available participants in the transactions, auditors and regulators. Our Paper is a Decentralised Loan Management Web Application (DApp) built on Ethereum blockchain which targets on preventing such fraudulent attacks on Loans sanctions by decentralising the processes. The security features authentication of the user identity, authentication of bank officials and multiple levels of verification of details are implemented using Public Key Infrastructure (PKI).
Open access
User Authentication and Security Systems
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Paul Black, Iqbal Gondal, Richard R. Brooks, Lu Yu
News media often contain reports that raise doubt related to policing operations. We examine the question of how to improve policing integrity during the execution of search warrants and provide an outline for law enforcement search warrants and digital forensic analysis procedures. Existing techniques for improving the integrity of search warrants are reviewed, limitations are noted, and we propose an Advanced Forensic Evidence System (AFES) to address these limitations.AFES provides an immutable record and biometric authentication of the officers present during the execution of a search warrant, time and location, video recording, seizure record, contemporaneous notes, and photographs. AFES records digital evidence items, imaging details, evidence hashes, provides an access control system, and an immutable record of access to all stored items. AFES uses a permissioned distributed ledger prototype, called Scrybe, developed under NSF aegis, to ensure evidence seizure integrity. Scrybe is run as multiple blockchain instances at law enforcement, prosecution, judicial, and defence organisations to ensure that an immutable record is maintained.
Single Secret Leader Elections have recently been proposed as an improved leader election mechanism for proof-of-stake (PoS) blockchains. However, the security gain they provide has not been quantified. In this work, we present a comparison of PoS longest-chain protocols that are based on Single Secret Leader Elections (SSLE) - that elect exactly one leader per round - versus those based on Probabilistic Leader Elections (PLE) - where one leader is elected on expectation. Our analysis shows that when considering the private attack - the worst attack on longest-chain protocols [14] - the security gained from using SSLE is substantial: the settlement time is decreased by ~ 25% for a 33% or 25% adversary. Furthermore, when considering grinding attacks, we find that the security threshold is increased by 10% (from 0.26 in the PLE case to 0.36 in the SSLE case) and the settlement time is decreased by roughly 70% for a 20% adversary in the SSLE case.
The vast majority of communication on the Internet and private networks heavily relies on Public-key infrastructure (PKI). One possible solution, to avoid complexities around PKI, is to use Password Authenticated Key-Exchange (PAKE) protocols. PAKE protocols enable a secure communication link between the two parties who only share a low-entropy secret (password). PAKEs were introduced in the 1990s, and with the introduction of the first security models and security proofs in the early 2000s, it was clear that PAKEs have a potential for wide deployment - filling the gap where PKI falls short. PAKEs' PKI-free nature, resistance to phishing attacks and forward secrecy are just some of the properties that make them interesting and important to study. This dissertation includes three works on various aspects of PAKEs: an attack on an existing PAKE proposal, an application of PAKEs in login (for password leak detection) and authentication protocols (HoneyPAKEs), and a security analysis of the J-PAKE protocol, that is used in practice, and its variants. In our first work, we provide an empirical analysis of the zkPAKE protocol proposed in 2015. Our findings show that zkPAKE is not safe against offline dictionary attacks, which is one of the basic security requirements of the PAKE protocols. Further, we demonstrate an implementation of an efficient offline dictionary attack, which emphasizes that, it is necessary to provide a rigorous security proof when proposing a new protocol. In our second contribution, we propose a combined security mechanism called HoneyPAKE. The HoneyPAKE construction aims to detect the loss of password files and ensures that PAKE intrinsically protects that password. This makes the PAKE part of the HoneyPAKE more resilient to server-compromise and pre-computation attacks which are a serious security threat in a client-server communication. Our third contribution facilitates the wider adoption of PAKEs. In this work, we revisit J-PAKE and simplify it by removing a non-interactive zero knowledge proof from the last round of the protocol and derive a lighter and more efficient version called sJ-PAKE. Furthermore, we prove sJ-PAKE secure in the indistinguishability game-based model, the so-called Real-or-Random, also satisfying the notion of perfect forward secrecy.
Victor R. Kebande, Feras M. Awaysheh, Richard A. Ikuesan, Sadi Alawadi · 5 authors
Continuous and emerging advances in Information and Communication Technology (ICT) have enabled Internet-of-Things (IoT)-to-Cloud applications to be induced by data pipelines and Edge Intelligence-based architectures. Advanced vehicular networks greatly benefit from these architectures due to the implicit functionalities that are focused on realizing the Internet of Vehicle (IoV) vision. However, IoV is susceptible to attacks, where adversaries can easily exploit existing vulnerabilities. Several attacks may succeed due to inadequate or ineffective authentication techniques. Hence, there is a timely need for hardening the authentication process through cutting-edge access control mechanisms. This paper proposes a Blockchain-based Multi-Factor authentication model that uses an embedded Digital Signature (MFBC_eDS) for vehicular clouds and Cloud-enabled IoV. Our proposed MFBC_eDS model consists of a scheme that integrates the Security Assertion Mark-up Language (SAML) to the Single Sign-On (SSO) capabilities for a connected edge to cloud ecosystem. MFBC_eDS draws an essential comparison with the baseline authentication scheme suggested by Karla and Sood. Based on the foundations of Karla and Sood's scheme, an embedded Probabilistic Polynomial-Time Algorithm (ePPTA) and an additional Hash function for the Pi generated during Karla and Sood's authentication were proposed and discussed. The preliminary analysis of the proposition shows that the approach is more suitable to counter major adversarial attacks in an IoV-centered environment based on the Dolev-Yao adversarial model while satisfying aspects of the Confidentiality, Integrity, and Availability (CIA) triad.
Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
Advanced Steganography and Watermarking Techniques
Hardware wallets are designed to withstand malware attacks by isolating their private keys from the cyberspace, but they are vulnerable to the attacks that fake an address stored in a clipboard. To prevent such attacks, a hardware wallet asks the user to verify the recipient address shown on the wallet display. Since crypto addresses are long sequences of random symbols, their manual verification becomes a difficult task. Consequently, many users of hardware wallets elect to verify only a few symbols in the address, and this can be exploited by an attacker. In this work, we introduce EthClipper, an attack that targets owners of hardware wallets on the Ethereum platform. EthClipper malware queries a distributed database of pre-mined accounts in order to select the address with maximum visual similarity to the original one. We design and implement a EthClipper malware, which we test on Trezor, Ledger, and KeepKey wallets. To deliver computation and storage resources for the attack, we implement a distributed service, ClipperCloud, and test it on different deployment environments. Our evaluation shows that with off-the-shelf PCs and NAS storage, an attacker would be able to mine a database capable of matching 25% of the digits in an address to achieve a 50% chance of finding a fitting fake address. For responsible disclosure, we have contacted the manufactures of the hardware wallets used in the attack evaluation, and they all confirm the danger of EthClipper.
Ying Chen, Tianhui Zhou, Jun Zhou, Zhenfu Cao · 6 authors
Self-organizing vehicular social networks underpin many location-based services (LBS) such as those that collect and share environmental information (e.g., traffic and weather conditions) among vehicular users and the infrastructure. There are, however, security and privacy considerations in the sharing of such information, and one popular approach is to design lightweight authentication solutions for LBS. Existing approaches may suffer from limitations such as significant computational and/or storage overheads, latency and time delays, and consequently impractical for resource-constrained on-board units. In this paper, we propose an efficient privacy-preserving LBS bundle authentication scheme (hereafter referred to as SAVE) through secure redundancy filtering in self-organizing vehicular social networks. Firstly, an enhanced self-healing key distribution protocol with distributed revocation is proposed to reduce communication cost for retransmitting lost key material and resist free-riding attacks to enhance the authentication efficiency. Then, based on it, a generalized version of online/offline aggregate signature is proposed to achieve batch LBS bundle verification based on arbitrary one-way function holding the property of multiplicative homomorphism. Finally, an efficient zero-knowledge range proof based on lightweight one-way hash chain is designed to decide the redundancy of LBS bundles without disclosing vehicular users’ location privacy. Formal security proof and extensive simulation results demonstrate that our proposed SAVE achieves identity privacy, two levels of location privacy and the practicability in reality.
Zero- Knowledge Proof is a cryptographic protocol exercised to render privacy and data security by securing the identity of users and using services anonymously. It finds numerous applications; authentication is one of them. A Zero-Knowledge Proof-based authentication system is discussed in this paper. Advanced Encryption Standard (AES) and Secure Remote Password (SRP) protocol have been used to design and build the ZKP based authentication system. SRP is a broadly used Password Authenticated Key Exchange (PAKE) protocol. The proposed method overcomes several drawbacks of traditional and commonly used authentication systems such as a simple username and plaintext password-based system, multi-factor authentication system and others.
E-learning has been carried out all over the world and then online examinations have become an important means to check learning effect during the outbreak of COVID-19. Participant authenticity, data integrity, and access control are the assurance to online examination. The existing online examination schemes cannot provide the protection of biometric features and fine-grained access control. Particularly, they did not discuss how to resolve some disputes among students, teachers, and a platform in a fair and reasonable way. We propose a novel biometric authentication and blockchain-based online examination scheme. The examination data are encrypted to store in a distributed system, which can be obtained only if the user satisfies decryption policy. And the pieces of evidence are recorded in a blockchain network which is jointly established by some credible institutions. Unlike other examination authentication systems, face templates in our scheme are protected using a fuzzy vault and a cryptographic method. Furthermore, educational administrative department can determine who the real initiator of malicious behavior is when a dispute arises using a dispute determination protocol. Analysis shows that no central authority is required in our scheme; the collusion of multiple users cannot obtain more data; even if the authorities compromise, biometric features of each user will not be leaked. Therefore, in terms of privacy-preserving biometric templates, fine-grained access, and dispute resolution, it is superior to the existing schemes.
Open access
Biometric Identification and Security
Advanced Steganography and Watermarking Techniques
Vehicular ad-hoc network enhances driving safety and enables various intelligent transportation applications by adopting the revolutionary vehicular wireless communication technology. This has attracted a lot of attentions from both academia and industry in recent years. Given the sophistication of vehicular manufacturing and the heterogeneity of intelligent transport terminals, performing vehicular authentication is of great importance. The existing schemes have largely considered vehicle security and authentication within a single administrative domain, which lacks supervision of the authority and entity in the intelligent transportation system. In this article, we propose a multidomain vehicular authentication architecture by introducing blockchain technique to build distributed trust and share cross-domain information among multiple administrative domains. To guarantee the anonymity and traceability, a pseudonym-based privacy-preserving authentication method is proposed. Specifically, considering the supervision of authority and the resilience to key escrow, we design a two-phase pseudonym distribution mechanism with the assistance of a roadside unit (RSU) proxy. We conduct in-depth security analysis by comparing with existing works and deploy experiments to show the efficiency and feasibility of the proposed scheme in the multidomain scenario.
Biometric authentication systems have major security weaknesses: risk of biometric information leakage, unreliability of authentication modules, and non-transparency of biometric information management. This paper presents BDAS, a new biometric authentication system using blockchain, which provides a decentralized and distributed mechanism for processing biometric authentication and an auditable mechanism for managing biometric information. BDAS’s evaluation demonstrates that it provides reliable and secure authentication compared to existing methods while introducing negligible performance overhead in real-world scenarios.
Over the past decade, the Internet of Things (IoT) is widely adopted in various domains, including education, commerce, government, and healthcare. There are also many IoT-based applications drawn significant attentions in recent years. With the increasing numbers of the connected devices in the IoT system, one of the challenging tasks is to ensure devices’ authenticity, which allows users to have a high confidence in the decision. In addition, due to the heterogeneity of the IoT system and the resource-constrained devices, how to efficiently manage such system and guarantee the security and privacy for devices is concerned. In this article, we proposed a new blockchain-based authentication scheme to meet the challenges. Our proposed framework combines the blockchain technique and the modular square root algorithm to achieve an effective authentication process. Besides, we demonstrate the security and utility of the proposed scheme by providing the security analysis and the detailed experiment.