Fariba Ghaffari, Komal Gilani, E. Bertin, Noël Crespi
Summary As the basic building block of any information security system, identity and access management (IAM) solutions play vital role in enterprise's security programmes. Providing centric solutions for IAM is inefficient in terms of having single point of failure, high cost, duplication and complexity to the users. Recently, emerging the distributed ledger technology (DLT) has attracted significant scientific interests in research areas like identity management, authentication and access control processes. In these contexts, Blockchain can offer greater data and rule confidentiality and integrity, as well as increasing the availability of the system by removing the single point of failure in the procedure. In this paper, we provide a comprehensive overview of the IAM solutions based on their basic components including identity management, authentication and access control. In the identity concept, we discuss about self‐sovereign identity which enhances privacy and security of distributed digital identities by providing individual's consolidated digital identity and verified attributes for enabling them to utilize their ownership. To offer a clearer understanding of the state of the art, we propose taxonomy to categorize them based on their features. For the conclusion of the paper, we compare the existing methods based on proposed taxonomy. Also, considering the advantages and disadvantages of existing methods, we discussed about the possible future directions.
Non fungible tokens (NFTs) are used to define the ownership of digital assets. More recently, there has been a surge of platforms to auction digital art as well as other digital assets in form of image, video, and audio content of all sorts. Although NFTs have the potential of revolutionizing the foundations of ownership, they also face various challenges notably in terms of trust and security. This paper starts by identifying the challenges in current NFTs and proposes a solution in order to remedy to their current shortcomings.
Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Abstract In a decentralized network every user makes use of personal identity details at different places for various services and these details are shared with third-parties without their consent and stored at an unknown location. Organizations like government, banks and social platforms are considered to be the weakest point in the current identity management system as they are vulnerable which leads to compromising billions of user identity data. Block chain based User Identity Management is a solution which provides a decentralized environment that manages the user identity data and their related Know-Your-Customer (KYC) documents in a distributed ledger. All the transactions of the network are stored in the block which is a type of a data structure and these blocks are validated using the powerful consensus algorithms and linked to form a block chain. Smart contracts will act as an interface between the client and the block chain network. User’s information cannot be provided to any third party vendors without the explicit consent of the user. This paper proposes a framework for User Identity Management using Block chain technology in a decentralized Network. The proposed framework ensures a high level privacy and security for the personal identity details and the documents. In addition to that the performance analysis of the framework is presented in terms of Transaction, Mining Resource and Difficulty Variation.
Open access
2 source records
Blockchain Technology Applications and Security
Spam and Phishing Detection
Advanced Steganography and Watermarking Techniques
With the recent emergence of the smart healthcare era, and patients relying more on personalized health monitoring based on Internet of Medical Things (IoMT) devices; patients’ lives are becoming highly threatened in case they fall victim to counterfeit devices. Thus, verifying whether these body sensors utilized are authentic and reliable in an unimpeachable, credible, and auditable manner without any centralized management is of crucial importance. Furthermore, manipulating data and hijacking in an IoMT context are also of tremendous criticality. Motivated by the aforementioned challenges, in this article, a smart contract-based scalable authentication scheme dedicated for IoMT devices is proposed. The scheme mitigates the deficiencies of the traditional established systems that are extensively built on centralized approaches, vulnerable to distributed denial of service attacks, by leveraging blockchain’s decentralization and security properties. The scheme ensures confidentiality, anonymity, and privacy as it is built on a consortium blockchain and integrity by offering secure firmware updates and protects patients from counterfeit devices by leveraging the physical unclonable function. The authentication approach was implemented on Ethereum and evaluated with regard to its computation and communication costs to prove its feasibility and effectiveness as well as its security by presenting a formal analysis using ProVerif.
Blockchain Technology Applications and Security
Neuroethics, Human Enhancement, Biomedical Innovations
Victor R. Kebande, Feras M. Awaysheh, Richard A. Ikuesan, Sadi Alawadi · 5 authors
Continuous and emerging advances in Information and Communication Technology (ICT) have enabled IoT-to-Cloud applications to be induced by data pipelines coupled with Edge Intelligence-based architectures. Advanced vehicular networks greatly benefit from these architectures due to the implicit functionalities that are focused on realizing the Internet-of-Vehicle (IoV) vision. However, IoV is susceptible to attacks, where adversaries can easily exploit existing vulnerabilities. Several attacks may succeed due to inadequate or weaker authentication techniques. Hence, there is a timely need for hardening the authentication process through cutting-edge access control mechanisms. This paper proposes a Blockchain-based Multi-Factor authentication model that uses an embedded Digital Signature (MFBC_eDS) for vehicular clouds and Cloud-enabled IoV. Our proposed MFBC_eDS model consists of a scheme that integrates the Security Assertion Mark-up Language (SAML) to the Single Sign-On (SSO) capabilities for a connected Edge-to Cloud ecosystem. MFBC_eDS draws an essential comparison with the baseline authentication scheme suggested by Karla and Sood. Based on the foundations of Karla and Sood’s scheme, an embedded Probabilistic Polynomial-Time Algorithm (ePPTA) and an additional Hash function for the Pi generated during Karla and Sood’s authentication are proposed and discussed. The preliminary analysis of the proposition shows that the approach is more suitable to counter major adversarial attacks in an IoV-centered environment based on Dolev-Yao adversarial model while satisfying aspects of the CIA triad.
We describe a fast three-round mutual authentication protocol for parties A and B belonging to the same coalition group. Parties A and B keep their own independent long-term private keys that are used in the process of authentication and can be used for other purposes. The scheme assumes an initial setup with a trusted third party T. This party initiates another secret information that includes factors of a large RSA modulus. For authentication, both parties must demonstrate each other the knowledge of their private keys without revealing them and the ability to factorize a large RSA modulus. Thus, the protocol based on the suggested scheme provides reciprocal authentication. The scheme possesses all desirable properties of an interactive proof, i.e., completeness, soundness, and zero-knowledge. The security of the protocol relies on assumptions of difficulty of the RSA factorization and existence of a cryptographic hash function.
IoT devices do not possess the potential to protect themselves from risk of the attackers as they are resource-constrained. Blockchain is arising as a decentralized and distributed technology with proficiency in delivering secure management, access control and user authentication for protecting data and services of IoT devices, guaranteeing integrity, confidentiality and availability. IoT-based healthcare applications has many benefits like reduced cost of healthcare, improved quality, remote monitoring of patients etc. Ensuring a robust and secure interactions between patient and healthcare providers is very important to protect sensitive medical data. A distributed and reliable user authentication and access control scheme to be used in IoT based Healthcare is designed and implemented here with the help of local gateways directly interfaced to smart contract based Ethereum Blockchain. The local gateways can manage multiple local IoT devices and improve scalability. This reduces the overhead of performing resource-consuming authentication tasks and blockchain-communication at the IoT devices. To exhibit the working of the framework, a case study is presented with two laptops and a Raspberry Pi.
Badis Hammi, Sherali Zeadally, Yves Christian Elloh Adja, Manlio Del Giudice · 5 authors
Fake check scam is one of the most common attacks used to commit fraud against consumers. This fraud is particularly costly for victims because they generally lose thousands of dollars as well as being exposed to judicial proceedings. Currently, there is no existing solution to authenticate checks and detect fake ones instantly. Instead, banks must wait for a period of more than 48 h to detect the scam. In this context, we propose a blockchain-based scheme to authenticate checks and detect fake check scams. Moreover, our approach allows the revocation of used checks. More precisely, our approach helps the banks to share information about provided checks and used ones, without exposing the banks’ customers’ personal data. We demonstrate a proof of concept of our proposed approach usingNamecoinandHyperledgerblockchain technologies.
Our paper proposes a new device authentication scheme for mobile sensor node called Mobile Data Collector (MDC). Moreover, to validate the data brought by the MDC to the base station (BS), we validate it and then store it. To solve MDC authentication between multiple devices, we proposed blockchain scheme to provide more ease, communication and security between different devices. For this to happen, the last MDC authentication (meaning the first time the information is gathered) is performed by the CH'S first encounter with the classic authentication, and here the protocol accepts or rejects the MDC. Once the CH has authenticated the MDC, CH sends a transaction to the blockchain to verify the legality of the MDC access. Then, when the MDC requests the collected data from another CH in the network, at this point, any CH verifies the trust of the MDC by communicating with the blockchain. Hence, the proposed scheme is as safe as we claim. More specifically, in the proposed protocol for Blockchain Security IoT (Block_MDC) is to provide authentication between the Mobile Data Set (MDC), the head of the group and the member nodes of the WSN. We evaluate the performance of our protocol using simulations using MATLAB. The results confirm that the Block_MDC protocol is robust, efficient, and offers lower power consumption and fast computing time.
Carlos González-Amarillo, Cristian Leonardo Cárdenas-García, Miguel Mendoza-Moreno, Gustavo Ramírez-González · 5 authors
Sensor devices that act in the IoT architecture perception layer are characterized by low data processing and storage capacity. These reduced capabilities make the system ubiquitous and lightweight, but considerably reduce its security. The IoT-based Food Traceability Systems (FTS), aimed at ensuring food safety and quality, serve as a motivating scenario for BIoTS development and deployment; therefore, security challenges and gaps related with data integrity are analyzed from this perspective. This paper proposes the BIoTS hardware design that contains some modules built-in VHDL (SHA-256, PoW, and SD-Memory) and other peripheral electronic devices to provide capabilities to the perception layer by implementing the blockchain architecture's security requirements in an IoT device. The proposed hardware is implemented on FPGA Altera DE0-Nano. BIoTS can participate as a miner in the blockchain network through Smart Contracts and solve security issues related to data integrity and data traceability in an Blockchain-IoT system. Blockchain algorithms implemented in IoT hardware opens a path to IoT devices' security and ensures participation in data validation inside a food certification process.
In the Internet of Vehicles (IoV), numerous potential applications have come up with the use of the Internet of Things (IoT)-empowered smart devices. In IoV, vehicles, roads, street signs and traffic lights can accordingly adjust to changing conditions in order to assist drivers, and also to improve safety, ease congestion and pollution reduction. Since various entities in an IoV environment make communications over public channels, there are potential security threats. To deal with such serious threats, we design a new blockchain-assisted certificateless key agreement protocol for IoV in smart transportation context, called Block-CLAP. In Block-CLAP, through authentication key management, traffic-centric data reach to a cluster head (CH) and then to its nearby road-side unit (RSU) securely using the established secret keys. A cloud server (CS) then securely collects the information from its attached RSUs and create the transactions. Later, the transactions are formed into blocks by the CS in a Peer-to-Peer (P2P) cloud servers network, and the blocks are verified and added through voting-based consensus algorithm in the blockchain. The detailed security analysis through formal, informal and formal security verification, and comparative study show that Block-CLAP provides superior security and has low communication and computational overheads as compared with other existing competing authentication schemes in the IoV environment. Finally, the blockchain-based implementation of Block-CLAP has been performed to measure computational time needed for a varied number of transactions per block and also for a varied number of blocks mined in the blockchain.
The concept of interconnecting smart vehicles and advancements in automotive automation leads to beneficial outcomes, such as a reduction in road fatalities and congestion. However, including a chain of automation in the attack surface will expand the attack surface and expose the security of automobiles to malicious infiltration. The proposed methodology provides access to specific users while restricting the third party requests. Moreover, it also makes use of data exchange that takes place between the roadside units and vehicle to track the vehicle status without compromising the in-vehicle network. To ensure a valid and authentic communication, vehicles with a proper and verifiable record will only be allowed to exchange messages in the blockchain network. Using qualitative arguments, we have identified that the proposed work is resilient to identified attacks. Similarly, quantitative experimentation indicates that this methodology shows a storage size compatibility and suitable response time in realistic scenarios. Simulation results indicate that, the proposed work shows positive results to secure vehicular networks, vehicular forensics and trust management.
Today's era is the smart era where every person is trying to execute the process smartly. Then how the education system will be in a back place. The online conduction of courses either by engaging online classes or by introducing the MOOC courses. This made learning easier but the major concerning issue in the online system is the conduction of online examination. This paper discusses the current treads in an online examination system as well as the new approach introduced for smooth conduction of online examination at any place anywhere at any time. This new approach is based on blockchain technology such as the smart contract. The smart contract will be helpful to the universities, institutes for conduction of online examination at any place at any time. This will keep regress monitoring on the examinee such as posture analysis as well as control panel processes. By using Compare Hash And Password() the authentication of the examinee password will be possible. GoCV package is used to authenticate the examinee through video capturing. dlib toolkit used to monitor the continuous posture of the examinee during the examination.
Over the past few years, there has been an alarming rise in the cyber attacks which are being carried out by Social Engineering Technique. Email is widely used for communication purposes and thus Spam Email Attacks are found to be the most common social engineering technique used by attackers to intrude into the system and perform malicious operations. Almost 85% of the overall email traffic is found to be spam (122.3 billion spam e-mails transmitted per day), which causes severe damage like, data loss, account compromise, ransomware attack, malware infection into the organization/personal systems. Various Artificial Intelligence-based methods (based on reviewing the content of an email) are created to identify spam emails, still, the count of hacks and loss due to spam emails is increasing on daily basis. On the other hand, blockchain being one of the cutting edges and disruptive technology has gained attention in the past few years. In this literature, authors have proposed a blockchain-based system to counter, prevent and identify spam emails. Authors have integrated the wallet-to-wallet transaction in Ethereum, with an existing email system to identify spam and legitimate email. The proposed framework is not based on verifying the content of an email at mailing servers instead the server verifies or check if or not the Cryptocurrency is paid, and thus the proposed framework is supposed to have small workloads and better performance throughput in terms of sending and receiving emails. The authors were able to create a Proof of Concept of the proposed methodology. All the endpoints created to achieve the same were executed in less than 1.5 sec of Elapse Time Average. The proposed framework will act as a Single Source of truth in identifying the Spam E-Mail.
Alexandre Augusto Giron, Jean Everson Martina, Ricardo Felipe Custódio
Steganography is one of the ways to hide data between parties. Its use can be worrisome, e.g., to hide illegal communications. Researchers found that public blockchains can be an attractive place to hide communications; however, there is not much evidence of actual use in blockchains. Besides, previous work showed a lack of steganalysis methods for blockchains. In this context, we present a steganalysis approach for blockchains, evaluating it in Bitcoin and Ethereum, both popular cryptocurrencies. The main objective is to answer if one can find steganography in real case scenarios, focusing on LSB of addresses and nonces. Our sequential analysis included 253 GiB and 107 GiB of bitcoin and ethereum, respectively. We also analyzed up to 98 million bitcoin clusters. We found that bitcoin clusters could carry up to 360 KiB of hidden data if used for such a purpose. We have not found any concrete evidence of hidden data in the blockchains. The sequential analysis may not capture the perspective of the users of the blockchain network. In this case, we recommend clustering analysis, but it depends on the clustering method's accuracy. Steganalysis is an essential aspect of blockchain security.
Open access
Advanced Steganography and Watermarking Techniques
COVID-19 has made eHealth an imperative. The pandemic has been a true catalyst for remote eHealth solutions such as teleHealth. Telehealth facilitates care, diagnoses, and treatment remotely, making them more efficient, accessible, and economical. However, they have a centralized identity management system that restricts the interoperability of patient and healthcare provider identification. Thus, creating silos of users that are unable to authenticate themselves beyond their eHealth application's domain. Furthermore, the consumers of remote eHealth applications are forced to trust their service providers completely. They cannot check whether their eHealth service providers adhere to the regulations to ensure the security and privacy of their identity information. Therefore, we present a blockchain-based decentralized identity management system that allows patients and healthcare providers to identify and authenticate themselves transparently and securely across different eHealth domains. Patients and healthcare providers are uniquely identified by their health identifiers (healthIDs). The identity attributes are attested by a healthcare regulator, indexed on the blockchain, and stored by the identity owner. We implemented smart contracts on an Ethereum consortium blockchain to facilities identification and authentication procedures. We further analyze the performance using different metrics, including transaction gas cost, transaction per second, number of blocks lost, and block propagation time. Parameters including block-time, gas-limit, and sealers are adjusted to achieve the optimal performance of our consortium blockchain.
A blockchain is a database that contains the history of all exchanges made between its users since its creation. A blockchain is a distributed and secure ledger of all transactions made since the start of the distributed system. It is a technology for storing and transmitting information, transparent, secure, and operating without a central control body. Our paper studies a new device authentication for mobile sensor node to prove its authenticity to unknown network manager. To solve the authentication of sensor among multiple networks, our proposal a blockchain scheme where the transaction specifies the authentication of given cluster head CH. As we claim, a blockchain guarantees an integrity and availability of message under assumption that every node has some public and private key pairs. However, it does not provide any authentication mechanism for symmetric key. Hence, the proposed scheme is secure as we claim. More concretely, in the protocol proposed Blockchain Security IoT (BSI) is to provide authentication between the mobile base station (BS), the cluster head and the member nodes for wireless sensor networks (WSN). Our protocol BSI protocol makes it possible to put the necessary keys of the networks at the level of each sensor for the different scenarios carried out, BS mobile node and migration node. We evaluate the performance of our protocol with simulations using MATLAB. The results confirm that the BSI protocol is robust and efficient, provides lower power consumption and fast computing time.
The Fifth Generation (5G) wireless network needs many base stations to provide ultra-high throughput. Thus, the vehicles in Vehicles to Infrastructure (V2I) communication over a 5G wireless network have to perform more frequent mutual authentications than before, which will greatly reduce the efficiency of the entire network. To address this issue, in this paper, we propose a novel handover authentication protocol that incorporates the blockchain based smart contracts to remove redundancy in the traditional handover authentication. Our proposed scheme can achieve the mutual authentication and key agreement between vehicles and base stations in 5G wireless networks, while it can largely reduce the cost for the handover authentication at the same time. The formal verification by Scyther indicates that the proposed protocol can resist various malicious attacks. In addition, the performance evaluation results show that the delay incurred by handover authentication can be significantly reduced indicating that the proposed protocol is feasible and holds potential to be used in the deployment of 5G wireless networks.
In recent years, the number of Internet-of-Things (IoT) devices has grown at an explosive rate. With the dramatic surge of the IoT, security issues have also come to the fore. Consequently, ensuring the security of the IoT communication community environment and trust between entities have become important research topics. In this paper, we design a passwordless IoT authentication mechanism, namely, T-Auth, to address these issues. The identity of a device in T-Auth is based on physical unclonable functions (PUFs), a hardware-based device fingerprint technology, which can greatly improve the security level compared to hardcoded passwords. A smart contract is a program that runs on the blockchain, which provides design flexibility and operational reliability. Our mechanism establishes a new trust architecture that enables devices to exchange information securely and reliably. The main contribution of this paper is to propose a new authentication mechanism that utilizes PUFs and combines them with blockchain to greatly improve the security and reliability of a system. Additionally, by leveraging Ethereum smart contracts, our mechanism supports cross-service group authentication.
Physical Unclonable Functions (PUFs) and Hardware Security
User Authentication and Security Systems
Advanced Steganography and Watermarking Techniques
Tobacco products are an addictive commodity. According to the World Health Organization’s (WHO) latest statistics data, tobacco kills more than eight million people each year. In 2003, the WHO proposed the Framework Convention on Tobacco Control (FCTC) to provide an effective framework for the control of tobacco products to governments around the world. In the field of tobacco products, the hardest problem is how to prevent counterfeit tobacco products and smuggling. To solve the problems, we proposed a blockchain-based traceable and verifiable logistics system for tobacco products with global positioning system (GPS) and radio-frequency identification (RFID) Technologies. In this research, we provide an overview of system architecture, and also define the protocol and the smart contract in every phase that stores data into the blockchain center. We realized a decentralized database and authentication system that uses blockchain and smart contract technology; every protocol in every phase was designed to achieve the integrity of data and non-repudiation of message. Every tobacco product’s shipping record will be completed by scanning the RFID tag and retrieving the GPS with a mobile reader, where the record will be updated and validated in the blockchain center. In the end, the security and costs of the system were analyzed, and a comparison was made with the EU’s (European Commission) method. Our system is more flexible for transportation, more secure in the communication protocol, and more difficult to tamper and forge data. In general, the proposed scheme solved the problem of tobacco products counterfeiting and tracking issues.
Sidra Malik, Naman Gupta, Volkan Dedeoglu, Salil S. Kanhere · 5 authors
Blockchain technology can provide immutability, provenance and traceability in supply chains. To utilize Blockchain's full potential, it is important to link supply chain events to the relevant entities for traceability and accountability purposes. Authorized participation is realised through consortium of various organisations. Transactions are verified by peer nodes pertaining to the consortium. Hence, privacy preservation of trade sensitive information such as trade flows and locations of production, storage and retail sites cannot be ascertained. In this work, we propose a privacy-preservation framework, TradeChain, which decouples the trade events of participants using decentralised identities. TradeChain adopts the Self-Sovereign Identity (SSI) principles and makes the following novel contributions: a) it incorporates two separate ledgers: a public permissioned blockchain for maintaining identities and the permissioned blockchain for recording trade flows, b) it uses Zero Knowledge Proofs (ZKPs) on traders' private credentials to prove multiple identities on trade ledger and c) allows data owners to define dynamic access rules for verifying traceability information from the trade ledger using access tokens and Ciphertext Policy Attribute-Based Encryption (CP-ABE). A proof of concept implementation of TradeChain is presented on Hyperledger Indy and Fabric and an extensive evaluation of execution time, latency and throughput reveals minimal overheads.
Yahye Adam Omar, Saurabh Goyal, Vijayakumar Varadarajan
The world is only beginning to see the value and potential impact of the internet of things (IoT). Until recently, access to the internet was bounded via desktop, tablet, or smartphone. With the (IoT), practically all devices and objects can be connected to the internet and monitored remotely. IoT devices simplify our lives and make organizations more efficient; however, there are still challenges to address, particularly in the security context. As we continue to embed these connected objects and a wider variety of wireless devices, it is mandatory to provide confidence in this vast incoming information source. Blockchain has emerged as a disruptive technology that will transform the way we store, share information, and impose restrictions to know the authentications. The data distribution and robust level of encryption will remove the need for trust among the involved parties and add another security layer for IoT data. IoT devices generate too much data using sensors and stored, processed, accessed the same using cloud computing and achieve security some extend using big-data. Big-data security mechanism is not sufficient to meet the security requirements of IoT devices. We have proposed the Blockchain encryption mechanism using different layers architecture for the IoT devices to achieve the desired security level. In this paper, we have focused on how Blockchain could possibly improve IoT security. We also survey the most relevant work to investigate challenges associate with IoT Blockchain convergence. This proposed mechanism will achieve the security mechanism in IoT devices some extend.