Mohammad Iqbal Saryuddin Assaqty, Ying Gao, Abeer D. Algarni, Siraj Khan · 7 authors
The complexity of the entire process of supply chain management (SCM) is quite cumbersome and traditional way of handling it is devoid of proper authentication and security and very often suffers from human errors in dealing with flaws in quality control process of SCM. While it may have started with shipment tracking, the outcome of using IoT on supply chains has spread to every link in the chain. For instance, manufacturers are employing Internet-enabled sensors in production to find product faults, resulting in higher-quality production runs. Physical Unclonable Function (PUF) is a security mechanism that exploits the unique, unrepeatable physical characteristics of hardware components to generate distinct cryptographic keys or identifiers, typically for a semiconductor device like an Internet of Things (IoT) device. The unique identification of IoT devices along the supply chain is implemented by using PUFs as tamper-resistant IDs. Blockchain, the distributed, immutable ledger, on the other hand is the disruptive technology that provides higher security as compared to traditional centralized systems. The integration of PUF and blockchain proves to be quite interesting while handling the above issues of authentication. A smart contract on the blockchain is a software code that executes spontaneously as and when the conditions of the contract or agreement are satisfied. Hence after authentication process the results are fed to blockchain smart contract for the final validation. This paper presents a novel permissioned blockchain smart contract-based lightweight authentication scheme for SCM using PUF of IoT known as SPUFChain. Informal and formal security analysis (using AVISPA and BAN logic) of the proposed framework show its potential to combat several attack scenarios like man-in-the middle, non-repudiation, impersonation, replay attacks and many other security features as compared to other related schemes. The processing time (~13.8ms) is better than existing lightweight scheme for blockchain-based SCM as well.
Most existing research on decentralized IoT applications tends to address specific vulnerabilities, with relatively few techniques dedicated to managing privacy and trust issues. To mitigate these challenges, blockchain-based solutions are increasingly adopted to enhance the reliability and security of IoT networks. In particular, blockchain-based authentication frameworks offer a decentralized approach to storing and verifying device identities, enabling secure and trustless communication among devices and with external systems. However, current blockchain-based IoT systems often suffer from complexity and storage overhead. To address these limitations, we propose a novel solution tailored for large-scale IoT environments using a permissioned blockchain. Our approach incorporates optimized data storage and a lightweight authentication mechanism, offering improved scalability and reduced storage demands. Furthermore, we introduce, for the first time, the integration of homomorphic encryption to secure IoT data at the user end before uploading it to the cloud. The proposed framework is evaluated through comprehensive simulations and compared with existing benchmark models. This research contributes a trust-aware security model that significantly enhances both the privacy and security of IoT services.
Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Advanced Steganography and Watermarking Techniques
The growth of the Metaverse brings new security problems that traditional perimeter-based defenses can’t manage. This research proposes and tests an integrated Zero-Trust Architecture aimed to solve these weaknesses by merging artificial intelligence (AI)-driven behavioral threat detection, blockchain-based decentralized identification, and post-quantum cryptography. For anomaly detection, the architecture uses a federated ResNet-50 model; for data management that meets regulatory standards, it uses a Hyperledger Fabric-based identification system with Zero-Knowledge Succinct Non-Interactive Argument of Knowledge; and for key exchange that is immune to quantum attacks, it uses the CRYSTALS-Kyber algorithm. Penetration testing, a Delphi study with 20 experts, and user surveys all show that the architecture greatly improves security metrics. This system has a False Acceptance Rate (FAR) of 5.2%, which is 42.7% lower than the 9.1% FAR baseline of rule-based systems, 99.1% protection against Sybil attacks, and strong quantum resilience with a 1.2× latency penalty compared to AES-256. The approach also partially complies with the General Data Protection Regulation by using cryptographic erasure proofs. But these security improvements come at a cost: AI inference now uses 3.1 times more graphics processing unit resources. The results show that the suggested architecture creates a scalable, empirically validated basis for protecting decentralized virtual environments, striking a good balance between security, compliance, and performance trade-offs.
Smart home technologies have revolutionized modern living by enhancing convenience, efficiency, and security. In contrast, many interconnected devices introduce significant security and privacy challenges. This comprehensive review investigates the integration of blockchain technology as a robust solution for secure access control in smart home environments. The decentralized and tamper-resistant nature of blockchain technology effectively solves important problems, including device authentication, data integrity, and access management, through the use of cryptography and distributed ledgers. The study synthesizes findings from 52 research papers, categorizing them into three thematic areas: blockchain in access control systems, its applications in IoT, and specific implementations for smart homes. It highlights the transformative potential of blockchain in mitigating vulnerabilities inherent in centralized systems, fostering trust, and enhancing security frameworks. Despite its promising applications, challenges such as scalability, interoperability, and energy consumption persist, warranting further research. This paper stresses the necessity of collaboration to tackle these limitations and enhance blockchain-based access control solutions for smart homes, setting the stage for more secure and user-focused smart environments.
The rapid growth of the metaverse has led to a scattered ecosystem in which digital assets are deployed on different blockchain platforms. This disintegration creates significant challenges for interoperability, as users need secure, decentralized, and privacy-preserving protocols to enable interoperability between chains. Existing solutions typically depend on centralized exchanges or third-party relays, introducing a single point of failure and potential privacy risks. We propose MAM (Metaverse Asset Management), a novel user-centric protocol utilizing zkSNARK technology (Zero-Knowledge Succinct Non-Interactive Argument of Knowledge) that enables seamless movement of metaverse assets across various blockchain platforms. MAM’s architecture ensures privacy by generating all zkSNARK proofs locally on the user’s machine, ensuring that sensitive data, including private keys and asset metadata, never leave the device. The protocol employs a secure one-time setup to distribute the global circuit-specific proving key, ensuring the permanent destruction of toxic-waste data. Experimental evaluation demonstrates that MAM achieves a constant and minimal proof size (192 bytes), low gas cost (281,107 Gas per verification), and an end-to-end asset transfer latency under 15 seconds, outperforming recent alternatives such as MetaOpera and MAP. Static security analysis confirms the robustness of MAM’s smart contracts against the most significant vulnerability types. This research enhances the state-of-the-art of privacy-preserving and scalable cross-metaverse interoperability, providing a practical approach for fully decentralized digital asset management and transfer across the Metaverse.
Increasing demand in innovative healthcare systems, as well as information management, enforces institutions and private consortiums to enroll in decentralized solutions that preserve patient’s sensitive information, and give capability of revoking and grating access to specific entities that request patient data. With blockchain emerging technology these solutions can be achieved allowing a more user-centric control of their own data. Furthermore, the need to conceal information and disabling data mining algorithm from agglomerating patient’s data and correlate them to their corresponding healthcare providers. This is crucial to maintain several privacy issues introduced by third parties accessing patient data without the patient’s explicit consent and applying those algorithms to perform clinical studies. This paper proposes an architectural approach at solving the problem of privacy preserving data sharing agreements between patients and healthcare providers, using blockchain, smart contracts and zero-knowledge proofs.
Sharad Katkol, Praveen M. Dhulavvagol, Shashikumar G. Totad
Blockchain technology has the potential to transform healthcare data management by enhancing security, transparency, and data integrity. However, scalability, latency, and privacy concerns have limited its application in high-volume, sensitive environments such as healthcare. This paper introduces a blockchain architecture that addresses these challenges through adaptive sharding and rule-based data partitioning. The adaptive sharding algorithm dynamically adjusts shard configurations in response to real-time network demands, optimizing resource allocation and improving scalability. Meanwhile, rule-based data partitioning organizes transactions across shards based on specific attributes, such as transaction type or geographic region, to minimize cross-shard communication and improving processing efficiency. Together, these methods increase transaction throughput by 34% and reduce latency by 9% compared to traditional approaches. Additionally, the system incorporates Byzantine Fault Tolerance (BFT) consensus to strengthen security, along with zero-knowledge proofs and homomorphic encryption to protect sensitive patient data during transaction verification. This architecture provides a comprehensive, scalable, and secure blockchain solution tailored to the unique needs of healthcare data management, addressing critical limitations while maintaining privacy and data integrity.
Faisal Alanazi, Mahdi Zareei, Alberto RodrÃguez Arreola
The rapid growth of the Internet of Things (IoT) demands solutions that can secure massive streams of sensitive data without sacrificing performance. Traditional blockchains struggle in IoT environments, facing significant challenges with transaction speed, scalability, and privacy. This paper introduces PRIVOT, a novel blockchain architecture that integrates a Directed Acyclic Graph (DAG) for high-throughput consensus with lightweight zero-knowledge proofs (ZKPs) for confidential transactions, rateless coded computation for private analytics, and an AI-driven manager that dynamically balances security and efficiency. Our simulations show that PRIVOT significantly outperforms traditional blockchain approaches, achieving high transaction throughput (up to 480 TPS on a 500-device network) with confirmation latencies under 2.1 seconds, even under heavy load. The framework provides robust privacy, limiting data leakage to less than 0.1% against significant node collusion, while keeping computational overhead low enough for resource-constrained IoT devices. By unifying these techniques, PRIVOT offers a scalable and resilient solution ideal for large-scale IoT deployments where both high performance and strong privacy are paramount.
The Internet of Medical Things (IoMT) is transforming healthcare by enabling devices to generate and share critical patient data. However, securely sharing this data across different healthcare entities remains a significant challenge due to concerns over privacy and security. Traditional solutions using Ciphertext Policy Attribute-Based Encryption (CP-ABE), Self-Sovereign Identity (SSI), and Zero-Knowledge Proofs (ZKPs) offer secure and anonymous data access, but they often fall short in scalability and integration, particularly in cross domain environments. To address these limitations, we introduce SSL-XIoMT, an optimized SSI and ZKP authentication framework within a consortium Hyperledger-based environment. This innovative system integrates SSI under advanced Zero-Knowledge Scalable Transparent Argument of Knowledge (ZK-STARK) and Plonk protocols within a consortium Hyperledger framework for privacy-preserving identity verification. We enhance identity privacy by integrating Multi-Party Computation (MPC), ensuring that identity credentials and ZKP proofs are securely shared and reconstructed without exposing sensitive information. Additionally, we optimize CP-ABE by offloading complex computations to fog nodes, which pre-compute attributes and logical operations. This approach significantly reduces computational overhead and enhances both privacy and efficiency. Our extensive analysis shows that SSL-XIoMT dramatically improves the performance of processing time for CP-ABE encryption and decryption compared to current methods. Moreover, our hybrid ZKPs based authentication approach outperforms the existing schemes regarding processing time and flexibility. The throughput test also demonstrates that SSL-XIoMT is practical for large scale cross-domain data sharing implementation.