Sourav Saha, Durbadal Chattaraj, Basudeb Bera, Ashok Kumar Das
Abstract This article introduces a new consortium blockchaināenabled access control scheme in edge computing based generic Internet of Things environment (called CBACSāEIoT), where the mutual authentication among the IoT smart devices and the gateway node(s), and also among the gateway node(s) and respective edge server(s) occur. In addition, key management phase is executed among the edge server(s) and associated cloud server(s). Using the established secret keys, the entities in the network communicate securely. The data gathered securely by the gateway nodes are then used to form various types of blocks (private, public, or consortium) at the edge server(s) based on application types in the generic IoT environment. The created blocks are mined by the edge servers in order to add them in the blockchain center. A detailed security analysis including the formal security has revealed that the proposed CBACSāEIoT is robust against various potential attacks needed in the IoT environment. To further strengthen the security, the simulationābased formal security verification on CBACSāEIoT has been carried out to exhibit that CBACSāEIoT is secure against passive and active attacks. Finally, a meticulous comparative performance analysis shows that CBACSāEIoT offers superior security and supports more functionality features, and also provides less communication and computational overheads compared with existing relevant schemes.
Access control is one of the important security services that is essential for an Internet of Things (IoT)-enabled authorized user using his/her smart mobile device to authenticate with the trusted Hospital Authority (HA) in a hospital. After mutual authentication, a secret key is established among the user and HA for secure data transmission. The secure data (transactions) gathered by the HA from the users in the hospital is encrypted using a shared key among various trusted hospital authorities involved in the private blockchain network of hospitals. The HA of each hospital is responsible for constructing the blocks in the blockchain using the encrypted transactions because the data in healthcare application is treated as confidential and private. To deal with this important problem, we design a novel access control scheme using private blockchain technology. The proposed scheme is shown to be secure against various well-known attacks. Moreover, the proposed scheme provides better security and functionality features, and also requires low communication and computational costs as compared to relevant approaches.
In 2009, Gradwohl, Naor, Pinkas, and Rothblum proposed physical zero-knowledge proof protocols for Sudoku. That is, for a puzzle instance of Sudoku, their excellent protocols allow a prover to convince a verifier that there is a solution to the Sudoku puzzle and the prover knows it, without revealing any information about the solution. The possible drawback is that the existing protocols have an extractability error with a non-zero probability, or need special cards (such as scratch-off cards). Thus, in this study, we propose new protocols to perform zero-knowledge proof of knowledge for Sudoku using a normal deck of playing cards with no extractability error. Our protocols can be easily implemented by humans with a reasonable number of playing cards.
Myeonghyun Kim, Sungjin Yu, Joonyoung Lee, Yohan Park Ā· 5 authors
In the traditional electronic health record (EHR) management system, each medical service center manages their own health records, respectively, which are difficult to share on the different medical platforms. Recently, blockchain technology is one of the popular alternatives to enable medical service centers based on different platforms to share EHRs. However, it is hard to store whole EHR data in blockchain because of the size and the price of blockchain. To resolve this problem, cloud computing is considered as a promising solution. Cloud computing offers advantageous properties such as storage availability and scalability. Unfortunately, the EHR system with cloud computing can be vulnerable to various attacks because the sensitive data is sent over a public channel. We propose the secure protocol for cloud-assisted EHR system using blockchain. In the proposed scheme, blockchain technology is used to provide data integrity and access control using log transactions and the cloud server stores and manages the patient's EHRs to provide secure storage resources. We use an elliptic curve cryptosystems (ECC) to provide secure health data sharing with cloud computing. We demonstrate that the proposed EHR system can prevent various attacks by using informal security analysis and automated validation of internet security protocols and applications (AVISPA) simulation. Furthermore, we prove that the proposed EHR system provides secure mutual authentication using BAN logic analysis. We then compare the computation overhead, communication overhead, and security properties with existing schemes. Consequently, the proposed EHR system is suitable for the practical healthcare system considering security and efficiency.
<div class="section abstract"><div class="htmlview paragraph">The automotive industry is set for a rapid transformation in the next few years in terms of communication. The kind of growth the automotive industry is poised for in fields of connected cars is both fascinating and alarming at the same time. The communication devices equipped to the cars and the data exchanges done between vehicles to vehicles are prone to a lot of cyber-related attacks. The signals that are sent using Vehicular Adhoc Network (VANET) between vehicles can be eavesdropped by the attackers and it may be used for various attacks such as the man in the middle attack, DOS attack, Sybil attack, etc. These attacks can be prevented using the Blockchain technology, where each transaction is logged in a decentralized immutable Blockchain ledger. This provides authenticity and integrity to the signals. But the use of Blockchain Platforms such as Ethereum has various drawbacks like scalability which makes it infeasible for connected car system. Here, we propose a solution to address various drawbacks of VANET such as privacy issues and, security using a more scalable decentralized platform called IOTA incorporated with a Public Key Infrastructure.</div></div>
Jie Xu, Kaiping Xue, Hangyu Tian, Jianan Hong Ā· 6 authors
More and more users are eager to obtain more comprehensive network services without revealing their private information. Traditionally, in order to access a network, a user is authorized with an identity and corresponding keys, which are generated and managed by the network operator. All users' personally identifying information are centralized stored by the network operator. However, this approach makes users lose the control of their personally identifying information. Users are concerned about who can access these sensitive data and whether they have been compromised. In this paper, we propose a blockchain-based identity management and authentication scheme for mobile networks, where users' identifying information are controlled by the users themselves. Our scheme let users generate their self-sovereign identities (SSIs) and corresponding public keys and private keys. The private key used to authenticate the user's identifying information is only known to the user. We use blockchain to record SSIs and public keys of legitimate user, and adopt chameleon hash to delete illegal users' information on the blockchain, while keeping the block head unchanged. Furthermore, other service providers can obtain the user's SSI and public key and authenticate users by querying the blockchain. Experimental results confirm that our scheme can greatly reduce the revocation overhead and communication overhead.
Alexander Frolov, Alexander Vinnikov, S.D. Polyakova
We present the IT solutions for educational modeling of non-interactive zero knowledge (NIZK) cryptographic public keys certification protocols. Certified public keys can then be used in a variety of non-interactive protocols, for example, in protocols using technique designated verifier proofs. The solution is based on algebraic means provided by MPEI algebraic processor. The IT solution supports the following educational purposes: obtaining practical skills of remote implementation of multiple non-interactive oblivious transfer and of non-interactive zero-knowledge proof protocol, mastering the methods of a remote automatic modeling of cryptographic protocols and of non-interactive public keys certification, and the technique designated verifier proofs.
A key communication technology in smart cities and smart buildings for automation is RFID. Proving the simultaneous presence of a group of RFID-tagged objects is a practical need in many application areas within this domain. Some examples of this include vehicle fleets, smart parking, safety in public places (smart cities), security and access control (smart buildings), and asset location (supply chain system, health care industry). Security, privacy, and efficiency are central issues when designing such a grouping-proof protocol. This work is motivated by Sundaresan et al.'s grouping-proof protocol, which applies zero-knowledge techniques. In this paper, we propose a lightweight, offline, serial-dependency grouping-proof protocol. Compared to existing grouping-proof protocols, our scheme improves on efficiency, scalability, security, and communication cost. It resists well-known attacks on grouping-proofs including tag/reader impersonation, tracking, replay, desynchronization, and message integrity.
Secret sharing has been study for many years and has had a number of real-word applications. There are several methods to construct the secret-sharing schemes. One of them is based on coding theory. In this work, we construct a secret-sharing scheme that realizes an access structure by using linear codes, in which any element of the access structure can reconstruct the secret key. We prove that our scheme is a multiprover zero-knowledge proof system in the random oracle model, which shows that a passive adversary gains no information about the secret key. Our scheme is also a leakage-resilient secret-sharing scheme (LRSS) in the bounded-leakage model, which remain provably secure even if the adversary learns a bounded amount of leakage information about their secret key. As an application, we propose a new group identification protocol (GID-scheme) from our LRSS. We prove that our GID-scheme is a leakage-resilient scheme. In our leakage-resilient GID-scheme, the verifier believes the validity of qualified group members and tolerates l bits of adversarial leakage in the distribution protocol, whereas for unqualified group members, the verifier cannot believe their valid identifications in the proof protocol.
Battery-powered mobile devices are convenient to use anywhere and anytime. Nowadays maximum people using the mobile device, such as Smartphone, Tablet computers to use mobile services anytime and anywhere. Moreover, most of the Smartphone having wireless communication like Wi-Fi and 4G. For some applications, the requirement of computing power may be very high, but the actual configuration of mobile devices are very limited, such as CPU, memory, storage, and battery. Among these computational resources, bandwidth and battery are the most significant problems for Smartphone. Efficient Computational Offloading is the best solution for extending the usage of Smartphone by executing the resource-intensive task to offload from mobile to the remote cloud servers can extend processing capability and support for multiple categories of application. However, this technique is having difficulty in offloading the process to a remote cloud server without the proven security of entity verification. To deal with these challenges, here we are proposing new security protocol to authenticate mobile and cloud server with zero knowledge proof of authentication to verify the communication entities and recommends to offload the service. The proposed protocol will get verify by the University of Oxford developed verification tool Scyther.
Blockchain technology has emerged as a revolutionary innovation with potential applications in various sectors, including finance, supply chain, healthcare, and more. However, the widespread adoption of blockchain technology has brought to light numerous security challenges. This article provides a comprehensive analysis of blockchain security protocols, focusing on the strengths and weaknesses of consensus algorithms, cryptographic techniques, and privacy mechanisms. By examining key protocols such as Proof of Work (PoW), Proof of Stake (PoS), and hybrid systems, this paper aims to provide a thorough understanding of the security measures that underlie blockchain systems and the potential vulnerabilities that could compromise their integrity. The article also discusses the future directions for enhancing blockchain security and the role of emerging technologies such as quantum computing in shaping the future of blockchain protocols.
Advanced wireless technology in Internet of Things (IoT) devices is increasing and facing various security threats. The authentication of IoT devices is the first line of defense for the wireless network. Especially in a Wi-Fi network, the existing authentication methods mainly use a password or digital certificate, these methods are inconvenient to manage due to certificate issuance or prone to be attacked because passwords are easily cracked. In this paper, we propose a location-aware authentication scheme using smart contracts to ensure that IoT devices can securely perform Wi-Fi network authentication. The scheme adopts the concept of secondary authentication and consists of two phases: the registration phase, which is mainly designed to complete the generation of the public and private keys, and to link the device information with its related device information; the authentication phase, which is mainly designed to determine whether the requesting device is within a legal location range. We use the smart contract to ensure the credibility and irreparability of the authentication process. Analysis of the attack model and the attacks at different stages proves that this certification scheme is assured, and the simulation results show that the overhead introduced by this scheme is acceptable, this scheme can provide greater security for the Wi-Fi authentication of IoT devices.
Zhuo Ma, Junwei Zhang, Yongzhen Guo, Yang Liu Ā· 6 authors
The vehicular ad hoc network (VANET) has been considered as one of the most prominent technologies for improving the efficiency and safety of modern transportation systems. However, VANET will present a unique range of challenges and opportunities for security. In particular, key management, as the footstone to build a practical security framework in VANET, becomes a research hotspot. In this paper, we investigate key management based on blockchain for VANET. We first propose an efficient decentralized key management mechanism for VANET with blockchain (DB-KMM) to automatically realize the registration, update and revocation of user's public key. At the same time, we present a lightweight mutual authentication and key agreement protocol based on the bivariate polynomial. Then, we analyze the security of DB-KMM in the universally composable framework and show that the mechanism can prevent the typical attacks including internal attacks, DoS attacks, public key tampering attacks and collusion attacks. Finally, we analyze the performance of the proposed scheme through experiments and simulation. Experiment results show that DB-KMM has better performance than the existing schemes in terms of communication, storage, computation overhead and latency.
Zaher Haddad, Mostafa M. Fouda, Mohamed Mahmoud, Mohamed Abdallah
Fifth generation (5G) cellular network, is a promising network that provides user promising quality of services in various applications such as health, banking, education, etc. Security consideration is the most critical element facing the reliance upon this technology. Registration, authentication and key agreement protocols are considered the most important protocols in any cellular network, since the subscriber and the network trust each other and share a symmetric key. Third Generation Partnership Project (3GPP) developed security specifications for the user authentication with the provider. However, many researchers targeted these protocols and concluded that there are still some security issues and proposed authentication and key agreement protocols. On the other hand, blockchain is considered one of the emerging technologies that will have a great impact on our life in the coming days. Blockchain grants its security properties such as authenticity and integrity to various applications such as bitcoin, smart contracts, etc. Therefore, in this paper, we introduce a novel, efficient and secure authentication and key agreement protocol for 5G networks using blockchain. Our security analysis illustrates that the proposed scheme is secure and withstands the known attacks; denial of service, distributed denial of service, man in the middle, hijacking and compromising attacks. Furthermore, our performance evaluation shows that the proposed scheme is more efficient than the current scheme and also other schemes since it preserves the small battery properties of the user equipment and also preserves the bandwidth of the network.
In this thesis, we present novel methods for verifying, implementing and specifying protocols. In particular, we focus properties modeling data protection and the protection of privacy. In the first part of the thesis, the author introduces protocol verification and presents a model for verification that encompasses so-called Zero-Knowledge (ZK) proofs. These ZK proofs are a cryptographic primitive that is particularly suited for hiding information and hence serves the protection of privacy. The here presented model gives a list of criteria which allows the transfer of verification results from the model to the implementation if the criteria are met by the implementation. In particular, the criteria are less demanding than the ones of previous work regarding ZK proofs. The second part of the thesis contributes to the area of protocol implementations. Hereby, ZK proofs are used in order to improve multi-party computations. The third and last part of the thesis explains a novel approach for specifying data protection policies. Instead of relying on policies, this approach relies on actual legislation. The advantage of relying on legislation is that often a fair balancing is introduced which is typically not contained in regulations or policies.
Identity is a tool that identifies a person or group and ensures that they are recognized by others. Personalidentification cards issued by the states to people contain specific information about the person given.Identity systems used for centuries are now digitalized, ID cards with chips and passports with chipshave entered our lives. In the past, only information such as name, surname and place of birth wereincluded in ID cards with chips and passports. But today, in addition to our personal information, itincludes our biometric information such as fingerprints, iris, digital signatures. Blockchain technology,which has entered our lives with the financial sector, offers application areas in different sectors andsubjects. Some of these are IoT (internet of things), security and reliability systems, copyrights, publicand health sectors. In this study, it has been mentioned about the advantages and the features obtainedby using blockchain technology in identity management. The purpose of this study; It is to ensure thesafe use of identity information thanks to the features provided by the block chain such as distributeddatabase called DLT (distributed ledger technology), peer-to-peer transmission, transparency andirreversible records. Also in this study, a software that can simulate blockchain technology was createdand an Android application that reads data with NFC (Near Field Communication) technology wasdeveloped. Thus, the process of adding the data in the ID card or passport to the block chain by readingthe data from NFC with the Android application can be performed.
We study adaptive security of delayed-input Sigma protocols and non-interactive zero-knowledge (NIZK) proof systems in the common reference string (CRS) model. Our contributions are threefold:
We exhibit a generic compiler taking any delayed-input Sigma protocol and returning a delayed-input Sigma protocol satisfying adaptive-input special honest-verifier zero knowledge (SHVZK). In case the initial Sigma protocol also satisfies adaptive-input special soundness, our compiler preserves this property.
We revisit the recent paradigm by Canetti et al. (STOC 2019) for obtaining NIZK proof systems in the CRS model via the Fiat-Shamir transform applied to so-called trapdoor Sigma protocols, in the context of adaptive security. In particular, assuming correlation-intractable hash functions for all sparse relations, we prove that Fiat-Shamir NIZKs satisfy either:
(i)
Adaptive soundness (and non-adaptive zero knowledge), so long as the challenge is obtained by hashing both the proverās first round and the instance being proven;
(ii)
Adaptive zero knowledge (and non-adaptive soundness), so long as the challenge is obtained by hashing only the proverās first round, and further assuming that the initial trapdoor Sigma protocol satisfies adaptive-input SHVZK.
We exhibit a generic compiler taking any Sigma protocol and returning a trapdoor Sigma protocol. Unfortunately, this transform does not preserve the delayed-input property of the initial Sigma protocol (if any). To complement this result, we also give yet another compiler taking any delayed-input trapdoor Sigma protocol and returning a delayed-input trapdoor Sigma protocol with adaptive-input SHVZK.