Andreas Erwig, Julia Hesse, Maximilian Orlt, Siavash Riahi
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
1,104 results · page 31 of 46
Andreas Erwig, Julia Hesse, Maximilian Orlt, Siavash Riahi
No abstract is available for this record.
Benoît Libert, Alain Passelègue, Hoeteck Wee, David J. Wu
No abstract is available for this record.
Maede Hojjati, Alireza Shafieinejad, Halim Yanıkömeroğlu
Subscriber authentication is a primitive operation in mobile networks required by each operator prior to offering any service to end users. In this paper, we propose a novel blockchain-based Authentication and Key Agreement (AKA) protocol for roaming services in 5G networks. Each Home Network (HN) creates its own smart contract and publishes its address to inform other operators who want to offer roaming services to HN subscribers. All subsequent communication between the HN and Serving Network (SN) is done by calling the function of this smart contract. The proposed protocol eliminates the need for a secure channel between the HN and SN, which is a primary requirement of current 5G AKA protocols. In practice, a secure channel requires the HN and SN to establish a secure session before running the AKA protocol. Further, the proposed protocol leverages the benefits of blockchain, such as auditable log, decentralized architecture, and the prevention of Denial of Service (DoS) attacks. Furthermore, we provide a security proof of the protocol through formal verification using ProVerif. The results show that our scheme tends to preserve user privacy and at the same time provides mutual authentication of the participants. Finally, our evaluation of the Ethereum blockchain shows that the protocol is efficient in terms of both transaction and execution costs.
Nabil Alkeilani Alkadri, Rachid El Bansarkhani, Johannes Buchmann
A canonical identification (CID) scheme is a 3-move protocol consisting of a commitment, challenge, and response. It constitutes the core design of many cryptographic constructions such as zero-knowledge proof systems and various types of signature schemes. Unlike number-theoretic constructions, CID in the lattice setting usually forces provers to abort and repeat the whole authentication process once the distribution of the computed response does not follow a target distribution independent from the secret key. This concept has been realized by means of rejection sampling, which makes sure that the secrets involved in a protocol are concealed after a certain number of repetitions. This however has a negative impact on the efficiency of interactive protocols because it leads to a number of communication rounds that is multiplicative in the number of aborting participants (or rejection sampling procedures). In this work we show how the CID scheme underlying many lattice-based protocols can be designed with smaller number of aborts or even without aborts. Our new technique exploits (unbalanced) binary hash trees and thus significantly reduces the communication complexity. We show how to apply this new method within interactive zero-knowledge proofs. We also present BLAZE \(^{+}\): a further application of our technique to the recently proposed lattice-based blind signature scheme BLAZE (FC’20). We show that BLAZE \(^{+}\) has an improved performance and communication complexity compared to BLAZE while preserving the size of keys and signatures.
Xinyin Xiang, Mingyu Wang, Weiguo Fan
The growth of electronic healthcare (e-health) systems is promoted by the evolution of Internet of Things (IoT) technology, as this new environment provides a variety of alternatives for medical data collection. Traditional authentication models in e-health systems cannot be applied directly to scenarios requiring low-latency, real-time services. Providing a variety of means for data transmission is considered an important method to achieve effective control in e-health systems. However, this new approach also leads to security and privacy concerns as increasingly flexible communication services are introduced. Achieving effective authentication of medical data for different users while providing security guarantees in e-health systems is an interesting problem. In this paper, we present a permissioned blockchain-based identity management and user authentication (PBBIMUA) scheme for the e-health environment. Our scheme satisfies the extensive security requirements of medical data. An evaluation and security analysis show that performance, in terms of lightweight construction and lower network latency with high security standards, is improved in comparison to known methods. The experimental results show that the system has good efficiency.
Seunghwan Son, Joonyoung Lee, Myeonghyun Kim, Sungjin Yu · 6 authors
Telecare medical information system (TMIS) implemented in wireless body area network (WBAN) is convenient and time-saving for patients and doctors. TMIS is realized using wearable devices worn by a patient, and wearable devices generate patient health data and transmit them to a server through a public channel. Unfortunately, a malicious attacker can attempt performing various attacks through such a channel. Therefore, establishing a secure authentication process between a patient and a server is essential. Moreover, wearable devices have limited storage power. Cloud computing can be considered to resolve this problem by providing a storage service in the TMIS environment. In this environment, access control of the patient health data is essential for the quality of healthcare. Furthermore, the database of the cloud server is a major target for an attacker. The attacker can try to modify, forge, or delete the stored data. To resolve these problems, we propose a secure authentication protocol for a cloud-assisted TMIS with access control using blockchain. We employ ciphertext-policy attribute-based encryption (CP-ABE) to establish access control for health data stored in the cloud server, and apply blockchain to guarantee data integrity. To prove robustness of the proposed protocol, we conduct informal analysis and Burrows-Adabi-Needham (BAN) logic analysis, and we formally validate the proposed protocol using automated validation of internet security protocols and applications (AVISPA). Consequently, we show that the proposed protocol provides more security and has better efficiency compared to related protocols. Therefore, the proposed protocol is proper for a practical TMIS environment.
Neha Garg, Mohammad Wazid, Ashok Kumar Das, Devesh Pratap Singh · 6 authors
The Internet of Medical Things (IoMT) is a kind of connected infrastructure of smart medical devices along with software applications, health systems and services. These medical devices and applications are connected to healthcare systems through the Internet. The Wi-Fi enabled devices facilitate machine-to-machine communication and link to the cloud platforms for data storage. IoMT has the ability to make accurate diagnoses, with fewer mistakes and lower costs of care. IoMT with smartphone applications permits the patients to exchange their health related confidential and private information to the healthcare experts (i.e., doctors) for the better control of diseases, and also for tracking and preventing chronic illnesses. Due to insecure communication among the entities involved in IoMT, an attacker can tamper with the confidential and private health related information for example an attacker can not only intercept the messages, but can also modify, delete or insert malicious messages during communication. To deal this sensitive issue, we design a novel blockchain enabled authentication key agreement protocol for IoMT environment, called BAKMP-IoMT. BAKMP-IoMT provides secure key management between implantable medical devices and personal servers and between personal servers and cloud servers. The legitimate users can also access the healthcare data from the cloud servers in a secure way. The entire healthcare data is stored in a blockchain maintained by the cloud servers. A detailed formal security including the security verification of BAKMP-IoMT using the widely-accepted Automated Validation of Internet Security Protocols and Applications (AVISPA) tool is performed to demonstrate its resilience against the different types of possible attack. The comparison of BAKMP-IoMT with relevant existing schemes is conducted which identifies that the proposed system furnishes better security and functionality, and also needs low communication and computational costs as compared to other schemes. Finally, the simulation of BAKMP-IoMT is conducted to demonstrate its impact on the performance parameters.
Yang Tao, Xi Wang, Rui Zhang
No abstract is available for this record.
Rainer Stütz, Peter Gaži, Bernhard Haslhofer, Jacob Illum
In the proof-of-stake (PoS) paradigm for maintaining decentralized, permissionless cryptocurrencies, Sybil attacks are prevented by basing the distribution of roles in the protocol execution on the stake distribution recorded in the ledger itself. However, for various reasons this distribution cannot be completely up-to-date, introducing a gap between the present stake distribution, which determines the parties' current incentives, and the one used by the protocol. In this paper, we investigate this issue, and empirically quantify its effects. We survey existing provably secure PoS proposals to observe that the above time gap between the two stake distributions, which we call stake distribution lag, amounts to several days for each of these protocols. Based on this, we investigate the ledgers of four major cryptocurrencies (Bitcoin, Bitcoin Cash, Litecoin and Zcash) and compute the average stake shift (the statistical distance of the two distributions) for each value of stake distribution lag between 1 and 14 days, as well as related statistics. We also empirically quantify the sublinear growth of stake shift with the length of the considered lag interval. Finally, we turn our attention to unusual stake-shift spikes in these currencies: we observe that hard forks trigger major stake shifts and that single real-world actors, mostly exchanges, account for major stake shifts in established cryptocurrency ecosystems.
Wenzheng Liu, Xiaofeng Wang, Wei Peng
Recently, application scenario of crowdsourcing IoT has covered to e-healthcare service, smart home, smart city, internet of vehicles due to the proliferation of smart devices such as smart mobile devices, smart wearable device, smart medical devices and smart furniture, etc. Patient's data collected by the smart devices send to the various remote medical servers. A group of medical professionals remote access patient data stored at the medical server database. Smart home users want to remote real-time access information of smart devices at home. All these operations need via wireless remote communication, which is suffering from various kinds of threat and attacks. Hence, there are a large number of multi-factor remote authentication and key agreement schemes designed for the application of crowdsourcing IoT. However, in most existing related multi-factor schemes, all factors for identity authentication only act as a parameter for encrypting the local secret key. In this paper, we propose a new secure remote multi-factor authentication scheme that includes three factors: 1) user identity; 2) password; and 3) user biometrics, which are authenticated by the remote server, act as a part of the secret key and participate in the key agreement process. We choose the chaotic map since it has a smaller key size and lower computational overhead, and then achieve remote multi-factor authentication and key agreement by artfully employ it to zero-knowledge technology and the fuzzy extractor technology. Our scheme is more secure and robust since the user revealing nothing sensitive information, and the adversary cannot impersonate any user even if he gets the server's master key. We have done security proof for our proposed scheme using the Random-Or-Real(ROR) model, Burrows-Abadi-Needham (BAN) logic, and ProVerif 2.00 to show that the presented scheme is secure. Also, we give an additional security analysis for other various attacks. Finally, according to the test and simulation result, the proposed scheme is very suitable for the power-constrained smart devices, and in the next generation 5G communication environment, its applicability and usability will be greatly enhanced.
Yi Yang, Debiao He, Huaqun Wang, Lu Zhou
Abstract As an important branch of the Internet of Things (IoT), Vehicular Ad Hoc Networks (VANETs) have attracted wide attention from industrial and academic. Due to an opening wireless channel, the security and efficiency of VANETs have also become serious. To enhance the security and efficiency, various batch verification schemes have been proposed. However, most of those schemes suffer from the complicated certificate management problem or different kinds of attacks. Also,the bilinear pairing which is intractable for lightweight devices in VANETs usually be used inthose schemes. To solve the above problems, we propose an efficient blockchain‐based batch verification scheme for VANETs using the Elliptic Curve Cryptography (ECC). We also provide security analysis to show its ability to resist current known attacks. Besides, we have implemented corresponding blockchain system and the performance analysis shows that it is suitable for VANETs.
Haowen Tan, Ilyong Chung
Nowadays, with rapid advancements of vehicular telematics and communication techniques, proliferation of vehicular ad hoc networks (VANETs) have been witnessed, which facilitates the construction of promising intelligent transportation system (ITS). Due to inherent wireless communicating features in open environment, secure transmission among numerous VANET entities remains crucial issues. Currently, lots of research efforts have been made, while most of which tend to allocate the universal group key to the verified devices for both vehicle-to-vehicle (V2V) and vehicle-to-RSU (V2R) communications. However, in heterogeneous VANET environment with large numbers of devices in same vehicular group, complicated and variable topologies lead to continuous key updating in every moment, causing interference to regular V2R data exchange, which is not reliable and efficient for resource-constrained VANET environment. Moreover, group membership recording and detecting mechanisms are necessary for real time vehicle revocation and participation, which has not been further studied so far. In this paper, we address the above issues by proposing a secure authentication and key management scheme. In our design, novel VANET system model with edge computing infrastructure is adopted so as to offer adequate computing and storing capacity compared to traditional VANET structure. Note that our certificateless authentication scheme applies the independent session key for each vehicle for interference avoidance. Furthermore, consortium blockchain is employed for V2V group key construction. Real time group membership arrangement with efficient group key updating is accordingly provided. Formal security proofs are presented, demonstrating that the proposed scheme can achieve desired security properties. Performance analysis is conducted as well, proving that the proposed scheme is efficient compared with the state-of-the-arts.
Rafael Ansey, James Kempf, Oleg Berzin, Xi Chen · 5 authors
Decentralized Identifiers (DIDs) are a new class of cryptographically secure identifier that does not require a centralized trust anchor for attesting to the validity of keying material. DIDs are based on distributed ledger (blockchain) technology and allow the entity itself to manage its own identifier, hence the name "self-sovereign" which is often applied to them. In this paper, we describe Gnomon, a system that uses DIDs to securely register 5G IoT devices and install firmware/software into the device. Gnomon is designed to avoid the kind of difficulties that plague current technology, which is largely based on Public Key Infrastructure (PKI) and X.509 public key certificates. After a short introduction, we review current practice and briefly describe DIDs and verifiable credentials, a mechanism based on DIDs to securely assert information about the identified entity. We then describe the architecture of Gnomon and a prototype we built, based on the ION DID scheme, for applying DIDs and verifiable credentials to 5G IoT device registration and software installation.
Lavish Saluja, Ashutosh Bhatia
We live in an era of information and it is very important to handle the exchange of information. While sending data to an authorized source, we need to protect it from unauthorized sources, changes, and authentication. ZKP technique can be used in designing secure authentication systems that dont involve any direct exchange of information between the claimant and the verifier thus preventing any possible leak of personal information. We propose a Zero-Knowledge Proof (ZKP) algorithm based on isomorphic graphs. We suggest most of the computations should be carried out on the users' web browser without revealing the password to the server at any point in time. Instead, it will generate random graphs and their permutations based on the login ID and password.
ZHANG Bin, GUANG Hui, CHEN Xi
To improve the security of Wireless Mesh Network(WMN),this paper proposes a Smart Contract-based Security Architecture(SCSA) that integrates blockchain technology.The proposed architecture builds blockchains on routing nodes.Three types of smart contracts are deployed to provide hierarchical management for public keys of nodes,including public key updating,public key cancellation and user access authentication.Also,the Elliptic Curve Diffie-Hellman(ECDH) and symmetric encryption are used to implement secure communication between nodes.Experimental results show that SCSA can efficiently resist node clone attacks or node forgery attacks,key compromise attacks and denial of service attacks,ensuring the security and efficiency of network communication.
Qi Feng, Debiao He, Huaqun Wang, Lu Zhou · 5 authors
When wireless body area network (WBAN) is playing an increasing role in modern medical systems, smart electronic health record (SEHR) system is heralded primarily as an economical and efficient way to optimize personal information or electronic health records (EHR) flowing through the inter-connected hierarchical network. Large scale, diversity and high sensitivity on EHR data collected from the personal intelligent medical sensors intrigue strong security and privacy preservation. As an authentication protocol can effectively identify the legality of the access entities, many authentication approaches for SEHR system have been proposed. However, few of them are suitable for such situation where an authentication message need to be generated by two parties, for example, doctors need to gain authenticaion from patients when accessing to EHRs. A limitation of using secret sharing scheme is the requirement of a trusted third party to recover the original private key. Therefore, we focus on the specific case of two participants (i.e., no trusted majority) and present a collaborative authentication protocol for SEHR system. Our protocol is provable secure under the hard problem assumptions and meets all the security requirements, especially private key protection. Furthermore, contract to an existing secure two-party authentication protocol that relies on heavy homomorphic encryptions and zero-knowledge proofs, our proposed protocol is tremendously faster than the previous ones shown by the performance analysis.
Qi Feng, Debiao He, Sherali Zeadally, Kaitai Liang
If all vehicles are connected together through a wireless communication channel, vehicular ad hoc networks (VANETs) can support a wide range of real-time traffic information services, such as intelligent routing, weather monitoring, emergency call, etc. However, the accuracy and credibility of the transmitted messages among the VANETs are of paramount importance as life may depend on it. In this article we introduce a novel framework called blockchain-assisted privacy-preserving authentication system (BPAS) that provides authentication automatically in VANETs and preserves vehicle privacy at the same time. This design is highly efficient and scalable. It does not require any online registration centre (except for system initialization and vehicle registration), and allows conditional tracing and dynamic revocation of misbehaving vehicles. In this article, we conduct an in-depth security analysis and a comprehensive performance evaluation (which is based on the Hyperledger Fabric platform) for our proposed framework. The results demonstrate that our framework is an efficient solution for the development of a decentralized authentication system in VANETs.
Parthajit Roy
No abstract is available for this record.
Chen Qian
Les primitives lossy trapdoor, preuve à divulgation nulle de connaissance et applications Dans cette thèse, nous étudions deux primitives différentes : les lossy trapdoor functions (LTF) et les systèmes de preuve à divulgation nulle de connaissance. Les LTFs sont des familles de fonctions dans lesquelles les fonctions injectives et les fonctions lossy sont calculatoirement indistinguables. Depuis leur introduction, elles se sont avérées utiles pour la construction de diverses primitives cryptographiques. Nous donnons dans cette thèse des constructions efficaces d’une variante de la LTF : le filtre algébrique lossy. Avec cette variante, nous pouvons améliorer l’efficacité du schéma de chiffrement KDM-CCA et extracteur flous. Dans la deuxième partie de cette thèse, nous étudions les constructions de systèmes de preuve à divulgation nullle de connaissance. Nous donnons la première signature d’anneau de taille logarithmique avec la sécurité étroite en utilisant une variante de Groth-Kolhweiz Σ-protocole dans le modèle de l’oracle aléatoire. Nous proposons également une nouvelle construction d’arguments à divulgation nulle de connaissance non-intéractive et à vérifieur désigné (DVNIZK) sous l’hypothèse de réseaux Euclidiens. En utilisant cette nouvelle construction, nous construisons un système de vote basé sur les réseaux Euclidiens dans le modèle standard.
Mubarak Umar, Xuening Liao, Jiawang Chen
A network of embedded sensors on the human body called Wireless Body Area Network (WBAN) has recently emerged as a healthcare monitoring framework, to provide better medical services. The data collected by these sensors is transmitted via a wireless medium and contains sensitive information of the patients. Therefore, how to provide security schemes for WBAN with resource constraints devices remains a big challenge. Recently, BAN-GZKP, an authentication scheme based on Zero-Knowledge Proof (ZKP) was designed for WBAN as an optimal solution to several attacks suffered by another ZKP based protocol called BANZKP. However, BAN-GZKP is found to be vulnerable to Node Compromise Attack, Node Impersonation, and Denial-of-Service Attacks. To fix the vulnerabilities of BANGZKP, this paper proposes an enhanced BAN-GZKP which exploits a unique physical layer characteristic coming from the surrounding WBAN, i.e., the distinct received signal strength variation among on-body channels and between on-body and off-body channels, to ensure robust authentication. To prove the reliability of our proposal, we conducted real-world experiments on 3 subjects in indoor and outdoor areas. The results showed that our scheme improves the security of the previous scheme with even lesser cost.
Srinivas Jangirala, Ashok Kumar Das, Athanasios V. Vasilakos
Secure real-time data about goods in transit in supply chains needs bandwidth having capacity that is not fulfilled with the current infrastructure. Hence, 5G-enabled Internet of Things (IoT) in mobile edge computing is intended to substantially increase this capacity. To deal with this issue, in this article, we design a new efficient lightweight blockchain-enabled radio frequency identification (RFID)-based authentication protocol for supply chains in 5G mobile edge computing environment, called lightweight blockchain-enabled RFID-based authentication protocol (LBRAPS). LBRAPS is based on bitwise exclusive-or (XOR), one-way cryptographic hash and bitwise rotation operations only. LBRAPS is shown to be secure against various attacks. Moreover, the simulation-based formal security verification using the broadly-accepted Automated Validation of Internet Security Protocols and Applications (AVISPA) tool assures that LBRAPS is secure. Finally, it is shown that LBRAPS has better trade-off among its security and functionality features, communication and computation costs as compared to those for existing protocols.
Zengpeng Li, Ding Wang
Password-based authenticated key exchange($\mathsf {PAKE}$PAKE) protocol, a widely used authentication mechanism to realize secure communication, allows protocol participants to establish a high-entropy session key by pre-sharing a low-entropy password. An open challenge in$\mathsf {PAKE}$PAKEis how to design a quantum-resistant round-optimal$\mathsf {PAKE}$PAKE. To solve this challenge, lattice-based cryptography is a promising candidate for post-quantum cryptography. In addition, Katz and Vaikuntanathan (ASIACRYPT’09) design the firstthree-round$\mathsf {PAKE}$PAKEprotocol by leveraging the smooth projective hash function ($\mathsf {SPHF}$SPHF) over lattices. Subsequently, Zhang and Yu (AISACRYPT’17) optimized Katz-Vaikuntanathan’s approximate$\mathsf {SPHF}$SPHFvia a splittable public key encryption. They then constructed atwo-round$\mathsf {PAKE}$PAKEby using the simulation-sound non-interactive zero-knowledge (NIZK) proofs, but how to construct a lattice-based simulation-sound NIZK remains an open research question. In other words, how to design a one-round$\mathsf {PAKE}$PAKEvia an efficient lattice-based$\mathsf {SPHF}$SPHFstill remains a challenge. In this work, we attempt to fill this gap by proposing a lattice-based$\mathsf {SPHF}$SPHFwith adaptive smoothness. We then obtain aone-round$\mathsf {PAKE}$PAKEprotocol over lattices with rigorous security analysis by integrating the proposed$\mathsf {SPHF}$SPHFinto the one-round framework proposed by Katz and Vaikuntananthan (TCC’11). Furthermore, we explore the possibilities of achieving two-round$\mathsf {PAKE}$PAKEand universal composable (UC) security from our$\mathsf {SPHF}$SPHF, and show the potential application of our$\mathsf {PAKE}$PAKEin Internet of Things (IoTs) where communication cost is the main consideration.
Jonathan Bootle
Zero-knowledge proofs are cryptographic protocols where a prover convinces a verifier that a statement is true, without revealing why it is true or leaking any of the prover’s secret information. Since the introduction of zero-knowledge proofs, researchers have found numerous applications to other cryptographic schemes, such as electronic voting, group signatures, and verifiable computation. Zero-knowledge proofs have also become an integral part of blockchain-based cryptocurrencies. Thus, designing efficient zero-knowledge proofs is an important goal. Recently, the design space has become extremely large. To simplify protocol design, designers have begun to separate the process into modular steps. Information theoretic protocols are designed in idealised communication models and compiled into real protocols secure under cryptographic assumptions. In this thesis, we investigate the Ideal Linear Commitment model, which characterises interactive zero-knowledge protocols where the prover and verifier use homomorphic commitment schemes. We demonstrate the model’s power by exhibiting efficient protocols for useful tasks including NP-Complete problems and other more specialised problems. We demonstrate the model’s versatility by compiling the idealised protocols into real protocols under two completely different cryptographic assumptions; the discrete logarithm assumption, and the existence of collision-resistant hash functions. We show that the Ideal Linear Commitment model is a useful and effective abstraction for producing zero-knowledge protocols. Furthermore, by identifying the limitations of the model and finding protocols outside these constraints, we display special techniques which result in more efficient zero-knowledge proofs than ever. The results are novel and highly efficient protocols. Results include the first ever discrete-logarithm argument for general statements with logarithmic communication cost, the first ever three-move discrete-logarithm argument for arithmetic circuit satisfiability with sub-linear communication costs, and an argument for list membership with sub-logarithmic communication, less than the number of bits required to specify a list index. Every single one of our protocols improves the theoretical state-of-the-art.
Ikram Ali, Gervais Mwitende, Emmanuel Ahene, Fagen Li
No abstract is available for this record.