Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

1,104 papersLast indexed Aug 31, 2026
Search papers

Paper index

1,104 results · page 26 of 46

Clear filters
Dec 14, 2021·Mathematics
15 cites
BCmECC: A Lightweight Blockchain-Based Authentication and Key Agreement Protocol for Internet of Things

Jan Lánský, Amir Masoud Rahmani, Saqib Ali, Nasour Bagheri · 7 authors

In this paper, targeting efficient authentication and key agreement in an IoT environment, we propose an Elliptic Curve Cryptography-(ECC) based lightweight authentication protocol called BCmECC which relies on a public blockchain to validate the users’ public key to provide desired security. We evaluate the security of the proposed protocol heuristically and validate it formally, which demonstratse the high level of the security. For the formal verification we used the widely accepted formal methods, i.e., BAN logic and the Scyther tool. In this paper we also analyse the security of recently proposed blockchain-based authentication protocols and show that this protocol does not provide the desired security against known session-specific temporary information attacks in which the adversary has access to the session’s ephemeral values and aims to retrieve the shared session key. In addition, the protocol lacks forward secrecy, in which an adversary with access to the server’s long-term secret key can retrieve the previous session keys, assuming that the adversary has already eavesdropped the transferred messages over a public channel in the target session. The proposed attacks are very efficient and their success probability is ‘1’, while the time complexity of each attack could be negligible. Besides, we show that BCmECC is secure against such attacks.

Open access
Advanced Authentication Protocols Security
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Dec 10, 2021·2021 7th International Conference on Computer and Communications (ICCC)
8 cites
Secure Authentication Scheme for VANET Based on Blockchain

Yuyang Cheng, Shiyuan Xu, Miao Zang, Shuo Jiang · 5 authors

The Internet of Vehicles (IoVs) is a communication environment that consists of various interconnected sensing devices, instruments, and other intelligent vehicles and applications connected. However, since intelligent devices on the IoVs communicate through insecure communication methods, Vehicular Ad-Hoc Network (VANET) may be vulnerable to different types of attacks. Therefore, it is essential to deploy a secure access control solution in the VANET environment, one of the critical security services to protect VANET. In this article, we propose a novel access control scheme for blockchain-based VANET communication. We provide detailed information about the network model and threat model required to design our scheme. The security analysis of the network shows its ability to resist various possible attacks. Furthermore, we introduce other intelligent devices to our network and protect their privacy from prying eyes. We also compared other relevant competing programs and found that our performance is better than these competitive programs. Therefore, our solution is suitable for access control in a blockchain-based VANET environment.

Vehicular Ad Hoc Networks (VANETs)
User Authentication and Security Systems
Advanced Authentication Protocols Security
Original source
Dec 10, 2021·2021 7th International Conference on Computer and Communications (ICCC)
0 cites
Blockchain-based Supervised Anonymous Cross-domain Authentication Scheme

Liquan Chen, Wenyi Wu, Guiyu Kou, Linyue Zhang

With the increasing complexity of the network environment, the traditional authentication technology has exposed its disadvantages such as low efficiency and power concentration. At the same time, the continuous development of information technology also puts forward higher requirements for authentication technology, for example, to realize authentication anonymization while ensuring authentication efficiency and dishonest users can be held accountable. In this paper, cross-domain authentication of heterogeneous networks is analyzed in detail, and a Blockchain-based Supervised Anonymous Cross-domain Authentication (BSA-CA) scheme is proposed. In this scheme, we retain the original infrastructure of the two trust domains. The trust network of users is established in the Blockchain system, and the trust model of heterogeneous cross-domain authentication is constructed by using zero-knowledge proof method. The BSA-CA scheme uses group signature to design anonymous supervisory properties. System analysis results show that the BSA-CA scheme has a good balance between security and authentication efficiency.

Blockchain Technology Applications and Security
User Authentication and Security Systems
Advanced Authentication Protocols Security
Original source
Dec 3, 2021·2021 the 11th International Conference on Communication and Network Security
1 cites
Strengthening the Security of Deniable Authentication Scheme Using Zero-Knowledge Proof

Asep Rizal Nurjaman, Ari Moesriami Barmawi

In an electronic voting system, authentication is used to ensure that the voter is legitimate without knowing his/her identity, while the vote collectors verify the data is received from a legitimate user without knowing the identity of the voter. One of the authentication schemes that fulfilled this requirement is called a deniable authentication scheme, where the receiver can prove the source of the message while another party cannot identify the source of the message. In 2013, Li-Takagi et al. proposed a deniable authentication scheme. However, Li-Takagi's scheme has weaknesses if the receiver fully cooperates with the third party. In this case, the third party can identify the source of a given message. In the proposed method, zero-knowledge proof is introduced to preserve the anonymity of the deniable authentication scheme when the receiver fully cooperates with the third party. Based on the analysis, the proposed scheme fulfills the requirement of the deniable authentication scheme when the receiver fully cooperates with the third party. However, the proposed scheme has additional computation costs for securing the shared secret key. Two attack schemes that are carried out on both Li-Takagi and the proposed scheme are the MITM attack and the impersonation attack. The probability of breaking the proposed scheme using an MITM attack is lower than when using Li-Takagi's scheme, but the probability of breaking the proposed scheme using an impersonation attack is the same as Li-Takagi's scheme.

Cryptography and Data Security
Advanced Authentication Protocols Security
Internet Traffic Analysis and Secure E-voting
Original source
Dec 1, 2021·2021 IEEE Globecom Workshops (GC Wkshps)
2 cites
Lightweight RFID Ownership Transfer Protocol Based on Blockchain

Dong Qingkaun, Gao Wenxin, Li Li, Ren Xiaolong · 5 authors

With regard to current RFID tags, as their owners change during the circulation process, the ownership of the tags is transferred, and the data containing the tag information is also transferred. Data is stored in the blockchain, which is a distributed ledger system maintained by a decentralized collective. A complete ownership transfer requires a download, decryption, and encrypted upload of the label content information from the blockchain server. This mode will bring tedious and repetitive data processing problems when carrying out multiple consecutive ownership transfers. Seriously affect the efficiency of the entire process, and will bring safety issues. For this reason, this paper proposes a lightweight RFID ownership transfer protocol that uses a proxy re-encryption algorithm to process tag content information. That is, the blockchain server uses proxy re-encryption to perform ciphertext conversion of the encrypted information, so that the ciphertext encrypted by the user Alice's public key is converted into the ciphertext encrypted with the user Bob's public key, and the user Bob can directly decrypt it with his private key. This paper uses a lightweight hash function calculation to ensure the security of ownership transfer. The experimental security analysis of the protocol show that the proposed protocol meets the security requirements and improves the efficiency of ownership transfer.

Cryptography and Data Security
RFID technology advancements
Advanced Authentication Protocols Security
Original source
Nov 15, 2021·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Secure Authentication Protocols in Cryptographic Systems

Amira Khalid Hassan, Fatima N. M. Al-Hashimi

—Algebra is one of the important fields of mathematics. It concerns with the study and manipulation of mathematical symbols. It also concerns with the study of abstractions such as groups, rings, and fields. Due to the development of these abstractions, it is extended to consider other structures, such as vectors, matrices, and polynomials, which are non-numerical objects. Computer algebra is the implementation of algebraic methods as algorithms and computer programs. Recently, many algebraic cryptosystem protocols are based on non-commutative algebraic structures, such as authentication, key exchange, and encryptiondecryption processes are adopted. Cryptography is the science that aimed at sending the information through public channels in such a way that only an authorized recipient can read it. Ring theory is the most attractive category of algebra in the area of cryptography. In this paper, we employ the algebraic structure called skew -Armendariz rings to design a neoteric algorithm for zero knowledge proof. The proposed protocol is established and illustrated through numerical example, and its soundness and completeness are proved

Open access
6 source records
Cryptography and Data Security
Polynomial and algebraic computation
Advanced Authentication Protocols Security
Original source
Oct 19, 2021·IEEE Transactions on Network and Service Management
31 cites
Decentralized On-Chain Data Access via Smart Contracts in Ethereum Blockchain

R. Sivasankari, R. Akila, S. Revathi, J. Brindha Merin

Smart contracts in Ethereum blockchain network are self-executable scripts used for managing tokenized assets and access rights between different entities on the blockchain network. They are significant addition to blockchain technology for achieving data transparency and reliability in maintaining the digital relationship between two or more entities. However, the smart contract is in its nascent stage and suffers from various limitations, including immutability and code secrecy. In this paper, we address the inability of smart contracts to access the on-chain data. The smart contract currently fetches the on-chain data by taking external oracle assistance, which can be compromised to influence the customers. To address the issue, we propose a decentralized mechanism for accessing the blockchain data directly from the smart contracts by indexing single or multiple parameters of a transaction in each block using the Merkle-Patricia Trie (MPT). The idea is to increase the data transparency of blockchain applications. The paper provides a sequential search methodology that can retrieve transactions from${N}$blocks, satisfying specific conditions, in${O}$(${N}$). The complexity is further reduced to${O}$(N/k) by partitioning the blockchain data into${k}$disjoint subsets to achieve parallelism in the search procedure. We experimentally verify the effectiveness of the proposed methodology with a case study on the Ethereum blockchain data.

2 source records
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Advanced Steganography and Watermarking Techniques
Original source
Oct 10, 2021·Intelligent Automation & Soft Computing
9 cites
Bcvop2p: Decentralized Blockchain-Based Authentication Scheme for Secure Voice Communication

Mustafa Kara, Muhammed Ali Aydın, Hasan H. Balık

Peer-to-peer VoIP applications are exposed to threats in the Internet environment as they carry out conversations over the Internet, which is an electronic communication line, and its security has always been largely a matter of concern. Authentication of the caller is the first line of defense among the security principles and is an important principle to provide security in VoIP application. Authentication methods in VoIP applications are usually based on trusted third parties or through centralized architecture. This situation creates problems in terms of single point of failure and privacy in call security over IP based communications. However, blockchain technology with a distributed architecture offers an innovative solution to multimedia communication authentication model. In this paper, a blockchain-based mutual authentication scheme for VoIP applications is proposed. In addition, the model's having a comprehensive security structure against various threats is explained via security and communication cost analysis. The proposed schema shows better performance than the methods that make a verification through the centralized architecture in the literature. The proposed model has been formally verified using the AVISPA tool, and it has been proven that the model is safe against potential threats.

Open access
Advanced Authentication Protocols Security
User Authentication and Security Systems
Internet Traffic Analysis and Secure E-voting
Original source
Oct 6, 2021·IEEE Internet of Things Journal
263 cites
Blockchain and PUF-Based Lightweight Authentication Protocol for Wireless Medical Sensor Networks

Weizheng Wang, Chen Qiu, Zhimeng Yin, Gautam Srivastava · 7 authors

Due to the emergence of heterogeneous Internet of Medical Things (IoMT) (e.g., wearable health devices, smartwatch monitoring, and automated insulin delivery systems), large volumes of patient data are dispatched to central cloud servers for disease analysis and diagnosis. Although this direct mode brings a lot of convenience for both patients and medical professionals (MPs), the open communication channel between them also incurs several security and privacy issues, such as man-in-the-middle attacks, eavesdropping attacks, and tracking attacks. Based on the unsolved challenges in wireless medical sensor networks (WMSNs), several researchers have proposed various authentication and key agreement (AKA) protocols for this type of healthcare system recently. However, most of these protocols do not perceive physical-layer security and over-centralized server problem in WMSN. In this article, to address these two open problems, we propose a lightweight and reliable authentication protocol for WMSN, which is composed of cutting-edge blockchain technology and physically unclonable functions (PUFs). In addition, a fuzzy extractor scheme is introduced to deal with biometric information. Subsequently, two security evaluation methods are used to prove the high reliability of our proposed scheme. Finally, performance evaluation experiments illustrate that the proposed mutual authentication protocol requires the least computation and communication cost among the compared schemes.

Advanced Authentication Protocols Security
User Authentication and Security Systems
Biometric Identification and Security
Original source
Oct 1, 2021·2021 IEEE 4th 5G World Forum (5GWF)
8 cites
EAP-ZKP: A Zero-Knowledge Proof based Authentication Protocol to Prevent DDoS Attacks at the Edge in Beyond 5G

Gholamreza Ramezan, Amr Abdelnasser, Bingyang Liu, Weiyu Jiang · 5 authors

5G has Introduced the primary and secondary authentication procedures to authenticate the user equipment requesting access to mobile network operators (MNOs) and service providers (SPs) data networks, respectively. However, the possibility of running distributed denial of service (DDoS) attacks on the MNO 5G core network (CN) and the SPs data networks still remains. In this paper, we introduce a zero- knowledge proof (ZKP) authentication algorithm called Partial- ID ZKP that authenticates users without revealing their service credentials. We show that Partial-ID ZKP has completeness and soundness properties. Based on Partial-ID ZKP, we then propose an extensible authentication protocol called EAP-ZKP that can be used in primary and secondary authentications to mitigate DDoS attacks at the CN edge. Finally, as a proof of concept, we implement EAP-ZKP in the 5G authentication procedure. Using the 5G simulators free5GC and gnbsim, we show that EAP-ZKP significantly reduces the authentication time for fake authentication attempts during DDoS attacks. Results also demonstrate that EAP-ZKP is able to recognize DDoS attack authentication attempts in about 10 msec. Interestingly, for the legitimate authentication attempts, the average authentication time slightly increases from 3.05 sec in current 5G authentication protocols to 3.06 sec in EAP-ZKP. This indicates that EAP-ZKP is promising for Beyond 5G.

Advanced Authentication Protocols Security
Cryptographic Implementations and Security
Network Security and Intrusion Detection
Original source
Sep 16, 2021·IEEE Journal of Biomedical and Health Informatics
137 cites
On the Design of Blockchain-Based ECDSA With Fault-Tolerant Batch Verification Protocol for Blockchain-Enabled IoMT

Hu Xiong, Chuanjie Jin, Mamoun Alazab, Kuo‐Hui Yeh · 8 authors

The blockchain-enabled internet of medical things (IoMT) is an emerging paradigm that could provide strong trust establishment and ensure the traceability of data sharing in the IoMT networks. One of the fundamental building blocks for Blockchain is Elliptic Curve Digital Signature Algorithm (ECDSA). Nevertheless, when processing a large number of transactions, the verification of multiple signatures will incur cumbersome overhead to the nodes in Blockchain. Although batch verification is able to provide a promising approach that verifies multiple signatures simultaneously and efficiently, the upper bound of batch size is limited to small-scale and the efficiency will drop rapidly as the batch size grows in the state-of-the-art ECDSA batch schemes. Meanwhile, most of the existing researches only focus on improving the efficiency of batch verification algorithms in various cryptosystem while ignoring the identification of invalid signatures, which could cause severe performance degradation when the batch verification fails. Motivated by these observations, this paper proposes an efficient and large-scale batch verification scheme with group testing technology based on ECDSA. The application of the presented protocols in Bitcoin and Hyperledger Fabric has been analyzed as supportive and effective. When the batch verification returns a false result, we utilize group testing technology to improve the efficiency of identifying invalid signatures. Comprehensive simulation results demonstrate that our protocol outperforms the related ECDSA batch verification schemes.

Cryptography and Data Security
Advanced Authentication Protocols Security
Security in Wireless Sensor Networks
Original source
Sep 15, 2021·HAL (Le Centre pour la Communication Scientifique Directe)
0 cites
Attaques et preuves de sécurité des protocoles d'échange de clés authentifiés

Petra Šala

The vast majority of communication on the Internet and private networks heavily relies on Public-key infrastructure (PKI). One possible solution, to avoid complexities around PKI, is to use Password Authenticated Key-Exchange (PAKE) protocols. PAKE protocols enable a secure communication link between the two parties who only share a low-entropy secret (password). PAKEs were introduced in the 1990s, and with the introduction of the first security models and security proofs in the early 2000s, it was clear that PAKEs have a potential for wide deployment - filling the gap where PKI falls short. PAKEs’ PKI-free nature, resistance to phishing attacks and forward secrecy are just some of the properties that make them interesting and important to study. This dissertation includes three works on various aspects of PAKEs: an attack on an existing PAKE proposal, an application of PAKEs in login (for password leak detection) and authentication protocols (HoneyPAKEs), and a security analysis of the J-PAKE protocol, that is used in practice, and its variants. In our first work, we provide an empirical analysis of the zkPAKE protocol proposed in 2015. Our findings show that zkPAKE is not safe against offline dictionary attacks, which is one of the basic security requirements of the PAKE protocols. Further, we demonstrate an implementation of an efficient offline dictionary attack, which emphasizes that, it is necessary to provide a rigorous security proof when proposing a new protocol. In our second contribution, we propose a combined security mechanism called HoneyPAKE. The HoneyPAKE construction aims to detect the loss of password files and ensures that PAKE intrinsically protects that password. This makes the PAKE part of the HoneyPAKE more resilient to server-compromise and pre-computation attacks which are a serious security threat in a client-server communication. Our third contribution facilitates the wider adoption of PAKEs. In this work, we revisit J-PAKE and simplify it by removing a non-interactive zero knowledge proof from the last round of the protocol and derive a lighter and more efficient version called sJ-PAKE. Furthermore, we prove sJ-PAKE secure in the indistinguishability game-based model, the so-called Real-or-Random, also satisfying the notion of perfect forward secrecy.

Open access
Advanced Authentication Protocols Security
Cryptography and Data Security
Original source
Sep 15, 2021·Open Repository and Bibliography (University of Luxembourg)
0 cites
Attacks and Security Proofs of Password Authenticated Key-Exchange Protocols

SALA, Petra

The vast majority of communication on the Internet and private networks heavily relies on Public-key infrastructure (PKI). One possible solution, to avoid complexities around PKI, is to use Password Authenticated Key-Exchange (PAKE) protocols. PAKE protocols enable a secure communication link between the two parties who only share a low-entropy secret (password). PAKEs were introduced in the 1990s, and with the introduction of the first security models and security proofs in the early 2000s, it was clear that PAKEs have a potential for wide deployment - filling the gap where PKI falls short. PAKEs' PKI-free nature, resistance to phishing attacks and forward secrecy are just some of the properties that make them interesting and important to study. This dissertation includes three works on various aspects of PAKEs: an attack on an existing PAKE proposal, an application of PAKEs in login (for password leak detection) and authentication protocols (HoneyPAKEs), and a security analysis of the J-PAKE protocol, that is used in practice, and its variants. In our first work, we provide an empirical analysis of the zkPAKE protocol proposed in 2015. Our findings show that zkPAKE is not safe against offline dictionary attacks, which is one of the basic security requirements of the PAKE protocols. Further, we demonstrate an implementation of an efficient offline dictionary attack, which emphasizes that, it is necessary to provide a rigorous security proof when proposing a new protocol. In our second contribution, we propose a combined security mechanism called HoneyPAKE. The HoneyPAKE construction aims to detect the loss of password files and ensures that PAKE intrinsically protects that password. This makes the PAKE part of the HoneyPAKE more resilient to server-compromise and pre-computation attacks which are a serious security threat in a client-server communication. Our third contribution facilitates the wider adoption of PAKEs. In this work, we revisit J-PAKE and simplify it by removing a non-interactive zero knowledge proof from the last round of the protocol and derive a lighter and more efficient version called sJ-PAKE. Furthermore, we prove sJ-PAKE secure in the indistinguishability game-based model, the so-called Real-or-Random, also satisfying the notion of perfect forward secrecy.

Open access
Advanced Authentication Protocols Security
User Authentication and Security Systems
Cryptography and Data Security
Original source
Sep 13, 2021·arXiv (Cornell University)
2 cites
Zero-Knowledge Authentication

Jakob Jakob Povšič, Andrej Brodnik

Zero-Knowledge proofs (ZKPs) enable proving of mathematical statements, revealing nothing but their validity. We design an authentication sys-tem with a ZKP as a password verification mech-anism within the Extensible Authentication Pro-tocol (EAP) framework. Designing a secure pass-word authentication system requires us to adopt security practices for protecting ourselves against the vulnerabilities of passwords. Integrating said practices is not trivial because of the tight cou-pling with the password verification method.

Open access
3 source records
Cryptography and Data Security
Cloud Data Security Solutions
Cryptography and Residue Arithmetic
Original source
Sep 10, 2021·IEEE Internet of Things Journal
13 cites
Identity-Based Key Agreement for Blockchain-Powered Intelligent Edge

Jie Zhang, Futai Zhang

In the new paradigm of blockchain-powered intelligent edge, the key agreement is a significant problem that has not been extensively studied so far. Existing key agreement protocols in the traditional public-key setting are usually too complicated and heavy for edge and end devices. Besides, most protocols in use do not have effective measures to resist side-channel attacks, which are increasingly threatening cloud servers, edge devices, and end devices. Identity (ID)-based protocols can be conveniently implemented in the blockchain-powered intelligent edge. Several leakage-resilient ID-based protocols, which can resist side-channel attacks, have been proposed. However, they all involve time-consuming pairing computations. Besides, none of them address side-channel attacks to the key generation center (KGC). This article designs and realizes two novel ID-based key agreement protocols for the blockchain-powered intelligent edge, including an extended Canetti-Krawczyk (eCK) secure ID-based authenticated key agreement (AKA) protocol and a continuous after-the-fact leakage-resilient eCK (CAFL-eCK) secure ID-based AKA protocol. Both protocols do not involve any heavy pairing computation. Besides, the second one can resist side-channel attacks to the KGC and the communicating parties. A hybrid implementation of the two protocols can achieve high efficiency and strong security at the same time in blockchain-powered intelligent edge environments. This is demonstrated via a use case of a blockchain-powered smart home.

Cryptography and Data Security
Advanced Authentication Protocols Security
Cryptographic Implementations and Security
Original source
Sep 7, 2021·Security and Communication Networks
14 cites
Threshold Key Management Scheme for Blockchain-Based Intelligent Transportation Systems

Tianqi Zhou, Jian Shen, Yongjun Ren, Sai Ji

Intelligent transportation systems (ITS) have always been an important application of Internet of Things (IoT). Today, big data and cloud computing have further promoted the construction and development of ITS. At the same time, the development of blockchain has also brought new features and convenience to ITS. However, due to the endless emergence of increasingly advanced types of attacks, the security of blockchain-based ITS needs more attention from industry and academia. In this paper, we focus on exploring the primitives in cryptography to guarantee the security of blockchain-based ITS. In particular, the authentication, encryption, and key management schemes in cryptography are discussed. Furthermore, we propose two methods for achieving the threshold key management in blockchain-based ITS. The proposed threshold key management scheme (with threshold t ) enables various stakeholders to recover a secret if the number of participated stakeholders is at least t . It should be noted that the proposed threshold key management scheme is efficient and secure for multiple users in blockchain-based ITS, especially for the data-sharing scenario.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Advanced Authentication Protocols Security
Original source
Sep 1, 2021·IEEE Internet of Things Journal
40 cites
AI-Envisioned Blockchain-Enabled Signature-Based Key Management Scheme for Industrial Cyber–Physical Systems

Ashok Kumar Das, Basudeb Bera, Sourav Saha, Neeraj Kumar · 6 authors

This article proposes a new blockchain-envisioned key management protocol for artificial intelligence (AI)-enabled industrial cyber–physical systems (ICPSs). The designed key management protocol enables key establishment among the Internet of Things (IoT)-enabled smart devices and their respective gateway nodes. The blocks partially constructed with secure data from smart devices by fog servers are provided to cloud servers that are responsible for completing blocks, and then mining those blocks for verification and addition in the blockchain. The most important application of the private blockchain construction is to apply AI algorithms for accurate predictions in Big data analytics. A detailed security analysis along with formal security verification show that the proposed scheme resists various potential attacks in an ICPS environment. Moreover, practical testbed experiments have been conducted using the multiprecision integer and rational arithmetic cryptographic library (MIRACL). Furthermore, a detailed comparative analysis shows superiority of the proposed scheme over recent relevant schemes. In addition, the practical implementation using the blockchain for the proposed scheme demonstrates the total computational costs when the number of transactions per block and also the number of blocks mined in the blockchain are varied.

Blockchain Technology Applications and Security
Cryptography and Data Security
Advanced Authentication Protocols Security
Original source
Aug 27, 2021·2021 Asian Conference on Innovation in Technology (ASIANCON)
26 cites
Secure Authentication using Zero Knowledge Proof

Adwait Pathak, Tejas Patil, Shubham Pawar, Piyush Raut · 5 authors

Zero- Knowledge Proof is a cryptographic protocol exercised to render privacy and data security by securing the identity of users and using services anonymously. It finds numerous applications; authentication is one of them. A Zero-Knowledge Proof-based authentication system is discussed in this paper. Advanced Encryption Standard (AES) and Secure Remote Password (SRP) protocol have been used to design and build the ZKP based authentication system. SRP is a broadly used Password Authenticated Key Exchange (PAKE) protocol. The proposed method overcomes several drawbacks of traditional and commonly used authentication systems such as a simple username and plaintext password-based system, multi-factor authentication system and others.

Advanced Authentication Protocols Security
User Authentication and Security Systems
Cryptography and Data Security
Original source
Aug 24, 2021·IEEE Journal of Biomedical and Health Informatics
122 cites
CP-BDHCA: Blockchain-Based Confidentiality-Privacy Preserving Big Data Scheme for Healthcare Clouds and Applications

Hemant Ghayvat, Sharnil Pandya, Pronaya Bhattacharya, Mohd Zuhair · 7 authors

Healthcare big data (HBD) allows medical stakeholders to analyze, access, retrieve personal and electronic health records (EHR) of patients. Mostly, the records are stored on healthcare cloud and application (HCA) servers, and thus, are subjected to end-user latency, extensive computations, single-point failures, and security and privacy risks. A joint solution is required to address the issues of responsive analytics, coupled with high data ingestion in HBD and secure EHR access. Motivated from the research gaps, the paper proposes a scheme, that integrates blockchain (BC)-based confidentiality-privacy (CP) preserving scheme, CP-BDHCA, that operates in two phases. In the first phase, elliptic curve cryptographic (ECC)-based digital signature framework, HCA-ECC is proposed to establish a session key for secure communication among different healthcare entities. Then, in the second phase, a two-step authentication framework is proposed that integrates Rivest-Shamir-Adleman (RSA) and advanced encryption standard (AES), named as HCA-RSAE that safeguards the ecosystem against possible attack vectors. CP-BDAHCA is compared against existing HCA cloud applications in terms of parameters like response time, average delay, transaction and signing costs, signing and verifying of mined blocks, and resistance to DoS and DDoS attacks. We consider 10 BC nodes and create a real-world customized dataset to be used with SEER dataset. The dataset has 30,000 patient profiles, with 1000 clinical accounts. Based on the combined dataset the proposed scheme outperforms traditional schemes like AI4SAFE, TEE, Secret, and IIoTEED, with a lower response time. For example, the scheme has a very less response time of 300 ms in DDoS. The average signing cost of mined BC transactions is 3,34 seconds, and for 205 transactions, has a signing delay of 1405 ms, with improved accuracy of ≈ 12% than conventional state-of-the-art approaches.

Blockchain Technology Applications and Security
Cryptography and Data Security
Advanced Authentication Protocols Security
Original source