Varun Deshpande, Taniya Das, Hakim Badis, Laurent George
In the context of the Internet of Things (IoT), the issue of holistic data security is complex as data has to be secured at 3 critical points i.e., 1. Point of generation (IoT sensors), 2. Point of storage, 3. Point of usage (IoT actuators). Point 2 can be adequately addressed by Blockchain that offers remarkable immutability by storing data securely and transparently in a distributed setting, making it tamper-proof while in storage. However, blockchain alone cannot root out all the data security impediments in an IoT network as Points 1 and 3 still needs to be resolved. In this paper, we propose a novel Secure Element and Blockchain based stratagem called SEBS to effectively secure all 3 Points at once, thereby realizing light, holistic, efficient IoT data security in true sense. Further, we elaborate on SEBS implementation in a generic IoT network scenario and show how it improves the performance of critical security operations by as much as 31 times. Next, we address a niche problem by proposing a novel SEOVA or SE based offline verification algorithm to verify if the data received through intermediary really belongs to the blockchain.
Due to existing issues (e.g., complexity/ invisibility on share data for multiple parties, patient's privacy's leak) in the pharmaceutical supply in health-care systems, we proposed the architecture for a prescription drug supply using blockchain. This architecture could provide an efficient authentication among un-trusted parties to prevent an illegal agent from knowing sensitive drug transactions. Besides, dynamic identity is employed to protect users' anonymity and privacy. What's more, secure drug transactions are designed to guarantee share data to be confidentiality, integrity, and non-repudiation by using blockchain. Security analysis shows that our protocol successfully mutually authenticates in addition to being resistant to user impersonation attacks, smart card loss attacks, denial of attacks, database compromised attacks. Furthermore, our protocol can provide reliable service as well as protecting patient's privacy. Performance analysis illustrates our scheme to be competitive in comparison to existing schemes relative to the added security benefits it provides.
In an internet of things (IoT) based smart healthcare system, personal health data can be produced by means of various wearable devices connected through a wireless body area network (WBAN). Since they contain sensitive information, whole collected data should be stored in a platform that guarantee both data confidentiality and integrity. In this sense, permissioned blockchain i.e. Hyperledger can be seen as an auspicious candidate for providing a secure yet scalable storage platform thanks to its data integrity and peers decentralization features. Considering that both IoT and blockchain network have different working mechanism, therefore, a software platform is required to provide an integration layer between the IoT and blockchain network. In this paper, we propose the design of IoT-to-Blockchain platform for integrating internet of things based smart healthcare system and blockchain network. The proposed system consists of five components including blcokchain-to-device interface, chain code execution interface, membership service provider (MSP), peers node and ordering node. The proposed system consists of five components including HTTP-based API gateway as device-to-blockchain interface, membership service provider (MSP), peers node and orderer. At first, the API gateway receives sensing data from IoT gateway device. Upon reception, the API gateway acting as client invokes chain code installed in each blockchain peer by emitting a transaction proposal to peers. Peers then simulate the execution and send back the endorsed data to the client i.e. API gateway. Collected endorsement from various peers are sent to orderer which then build a block containing an ordered transactions received from all clients and then broadcast that block to all peers. Each peer the performs a final verification before committing all ordered transactions on that block into its own local ledger. By using this mechanism, every peer in network can receive similar transaction orders which lead to identical ledger state changes.
This paper presents the vision of establishing a global service for Global IoT Device Discovery and Integration (GIDDI). The establishment of a GIDDI will: (1) make IoT application development more efficient and cost-effective via enabling sharing and reuse of existing IoT devices owned and maintained by different providers, and (2) promote deployment of new IoT devices supported by a revenue generation scheme for their providers. More specifically, this paper proposes a distributed IoT blockchain ledger that is specifically designed for managing the metadata needed to describe IoT devices and the data they produce. This GIDDI Blockchain is Internet-owned (i.e., it is not controlled by any individual or organization) and is Internet-scaled (i.e., it can support the discovery and reuse billions of IoT devices). The paper also proposes a GIDDI Marketplace that provides the functionality needed for IoT device registration, query, integration, payment and security via the proposed GIDDI Blockchain. We outline the GIDDI Blockchain and Marketplace implementation. We also discuss ongoing research for automatically mining the IoT Device metadata needed for IoT Device query and integration from the data produce. This significantly reduces the need for IoT device providers to supply the metadata descriptions the devices and the data they produce during the registration of IoT Devices in the GIDDI Blockchain.
Internet of Things (IoT) gained a great focus in recent years due to its importance in humans' everyday life. IoT applications appear in several domains for human welfare. The need for a powerful and scalable security framework is the main focus for the current research. Blockchain (BC) is a distributed write-only ledger that eliminates the need for third parity to secure and verify transactions between peers. Though BC is considered the most powerful technique for securing transactions between IoT devices, these devices, unfortunately, cannot act as peers in BC because of its limited processing and storage. In this work, Blockchain is utilized in deploying a security framework for IoT monitoring applications. The proposed framework comprises clients (who query IoT devices), device gateways, and an administrator. IoT devices access BC through gateways. These gateways are assumed to be resource-rich and can perform mining tasks. To that end, Ethereum Blockchain is utilized in addition to Ethereum Smart contracts for enforcing a set of rules defined by the system administrator.
The Internet of things (IoT), as an extension of the Internet, has become a trend of network development nowadays. In order to protect the integrity and authenticity of the information in the IoT, an identity authentication protocol applied to the networked devices is designed in this paper, using the physical unclonable function (PUF) to extract the uniqueness and tamper resistance of the randomness in the manufacturing process of the physical device. We propose the protocol including the database, accessed devices, access devices and users in the specific network environment. Relying on the unique identification information generated by the PUF embedded in devices and passwords set by users, devices and users identities could be verified through zero-knowledge proofs. The performance analysis and the experiment at the end of this work show that our protocol provides users with a strong security guarantee for IoT devices.
Physical Unclonable Functions (PUFs) and Hardware Security
Bitcoin and other cryptocurrencies have become popular and motivate more hackers to steal digital funds. Users protect their private keys using crypto wallets to keep their funds safe from hackers. While the most secure option is hardware wallet, it suffers from lack of a secure and convenient backup and recovery process. Almost all existing wallets use mnemonics to back up the private keys, and a user must write down these words on a piece of paper. This approach is not only inconvenient but also problematic since the paper could be lost or stolen, resulting in a hacker recovering the keys. In this paper, we propose a new digital scheme to securely back up a hardware wallet relying on the side-channel human visual verification enabled by display screen on a hardware wallet. Using this method, we transfer the root of private keys from one hardware wallet to another wallet securely even via an untrusted terminal, such as a smartphone. At the end of this process, the user has two hardware wallets with the same private keys while she may use one of them as the main wallet and another one as a backup wallet.
2 source records
Advanced Steganography and Watermarking Techniques
Yusuf Muhammad Tukur, Dhavalkumar Thakker, Irfan‐Ullah Awan
The Internet of Things (IoT) has allured so much interest since inception thanks to the amazing capabilities it offers. Consequently, it has found tremendous applications and has been employed to meet increasing automation and computerization demands of public and private organizations where it handles enormous critical information. However, the major issue surrounding the IoT is, it is exposed to various physical and cyber threats including the significantly harmful insider threat. In this work, we approach the insider threat problem to IoT from the viewpoint of examining the influence of tampering with state of the sensing environment on the overall IoT system. Our aim is to investigate how altering the environment state in perception layer of the IoT affects the integrity of the data read by sensors; and provide mechanism to preserve the integrity of the system data to ensure accurate analytics and processing. We focused on threat models where insiders compromise physical properties about which data are collected and transmitted, deceiving the sensors into reading inaccurate data. As initial solution to the problem, we developed a framework that integrates Ethereum blockchain with edge computing to perform checks and preserve integrity of incoming sensor data before being analyzed, processed and stored.
We live in an era of information and it is very important to handle the exchange of information. While sending data to an authorized source, we need to protect it from unauthorized sources, changes, and authentication. ZKP technique can be used in designing secure authentication systems that dont involve any direct exchange of information between the claimant and the verifier thus preventing any possible leak of personal information. We propose a Zero-Knowledge Proof (ZKP) algorithm based on isomorphic graphs. We suggest most of the computations should be carried out on the users' web browser without revealing the password to the server at any point in time. Instead, it will generate random graphs and their permutations based on the login ID and password.
Abstract Recent studies show that 20.4% of the internet traffic originates from automated agents. To identify and block such ill-intentioned traffic, mechanisms that verify the humanness of the user are widely deployed, with CAPTCHAs being the most popular. Traditional CAPTCHAs require extra user effort (e.g., solving mathematical puzzles), which can severely downgrade the end-user’s experience, especially on mobile, and provide sporadic humanness verification of questionable accuracy. More recent solutions like Google’s reCAPTCHA v3, leverage user data, thus raising significant privacy concerns. To address these issues, we present zkSENSE: the first zero-knowledge proof-based humanness attestation system for mobile devices. zkSENSE moves the human attestation to the edge: onto the user’s very own device, where humanness of the user is assessed in a privacy-preserving and seamless manner. zkSENSE achieves this by classifying motion sensor outputs of the mobile device, based on a model trained by using both publicly available sensor data and data collected from a small group of volunteers. To ensure the integrity of the process, the classification result is enclosed in a zero-knowledge proof of humanness that can be safely shared with a remote server. We implement zkSENSE as an Android service to demonstrate its effectiveness and practicality. In our evaluation, we show that zkSENSE successfully verifies the humanness of a user across a variety of attacking scenarios and demonstrate 92% accuracy. On a two years old Samsung S9, zkSENSE’s attestation takes around 3 seconds (when visual CAPTCHAs need 9.8 seconds) and consumes a negligible amount of battery.
Recent studies show that 20.4% of the internet traffic originates from automated agents. To identify and block such ill-intentioned traffic, mechanisms that verify the humanness of the user are widely deployed across the internet. CAPTCHA is the most popular among such mechanisms. Original CAPTCHAs require extra user effort (e.g., solving mathematical or image-based puzzles), which severely harms user's experience, especially on mobile, and provide only sporadic verification of their humanness. More recent solutions like Google's reCAPTCHA v3 leverage attestation data (e.g., user behavioral data, device fingerprints) shared with a remote server, thus raising significant privacy concerns. To address all of the above, we present ZKSENSE: the first zero knowledge proof-based humanness attestation system designed for mobile devices. Contrary to state-of-the-art systems, ZKSENSE assesses humanness continuously on the background in a privacy preserving way. ZKSENSE achieves that by classifying the motion sensor outputs of the mobile device based on a model trained by using both publicly available sensor data and data collected from a small group of volunteers. The classification result is enclosed in a zero knowledge proof of humanness that can be safely shared with an attestation service such as Privacy Pass. We implement ZKSENSE as an Android service to demonstrate its effectiveness and practicability. In our evaluation, we show that ZKSENSE verifies the humanness of the users asynchronously, on the background, without degrading their experience or jeopardizing user privacy, while it achieves 91% accuracy across a variety of attack scenarios. On a two years old Samsung S9, each attestation takes around 3 seconds in total (when visual CAPTCHAs need 9.8 seconds) and consumes a negligible amount of battery.
Besides confidentiality and privacy, trust is an important factor for any IoT system. When a sensor send data that is signed with its private key, the receiving nodes verify it using the public key of the sensor. Hence, it is understood that authenticating the public key of the system is part of creating trust within the system. Traditionally, trust is maintained using Public Key Infrastructure (PKI) where a centralized Certificate Authority (CA) is used for authenticating the public keys. However, a centralized system can result in single point of failure where CA can be compromised or can act maliciously. Decentralizing this system using blockchain and by automating the process of certificate authentication without the need for a central third party can overcome the abovementioned limitations. We identify the challenges in creating such a system and propose a generic framework for PKI in IoT infrastructure using blockchain that can provide the functions of a CA.
When wireless body area network (WBAN) is playing an increasing role in modern medical systems, smart electronic health record (SEHR) system is heralded primarily as an economical and efficient way to optimize personal information or electronic health records (EHR) flowing through the inter-connected hierarchical network. Large scale, diversity and high sensitivity on EHR data collected from the personal intelligent medical sensors intrigue strong security and privacy preservation. As an authentication protocol can effectively identify the legality of the access entities, many authentication approaches for SEHR system have been proposed. However, few of them are suitable for such situation where an authentication message need to be generated by two parties, for example, doctors need to gain authenticaion from patients when accessing to EHRs. A limitation of using secret sharing scheme is the requirement of a trusted third party to recover the original private key. Therefore, we focus on the specific case of two participants (i.e., no trusted majority) and present a collaborative authentication protocol for SEHR system. Our protocol is provable secure under the hard problem assumptions and meets all the security requirements, especially private key protection. Furthermore, contract to an existing secure two-party authentication protocol that relies on heavy homomorphic encryptions and zero-knowledge proofs, our proposed protocol is tremendously faster than the previous ones shown by the performance analysis.
If all vehicles are connected together through a wireless communication channel, vehicular ad hoc networks (VANETs) can support a wide range of real-time traffic information services, such as intelligent routing, weather monitoring, emergency call, etc. However, the accuracy and credibility of the transmitted messages among the VANETs are of paramount importance as life may depend on it. In this article we introduce a novel framework called blockchain-assisted privacy-preserving authentication system (BPAS) that provides authentication automatically in VANETs and preserves vehicle privacy at the same time. This design is highly efficient and scalable. It does not require any online registration centre (except for system initialization and vehicle registration), and allows conditional tracing and dynamic revocation of misbehaving vehicles. In this article, we conduct an in-depth security analysis and a comprehensive performance evaluation (which is based on the Hyperledger Fabric platform) for our proposed framework. The results demonstrate that our framework is an efficient solution for the development of a decentralized authentication system in VANETs.
The Nakamoto longest chain protocol has served Bitcoin well in its decade long existence. It is remarkably simple and uses only basic cryptographic primitives, but its proof-of-work framework is energy wasting. Proof-of-stake (PoS) protocols are an energy efficient alternative; however they are significantly complicated and promise weaker security guarantees. An effort to mimic the Nakamoto protocol directly in the PoS setting is made in [10, 11] with security shown only for a class of purely private attacks. In this paper we demonstrate a new, and fatal, attack on the protocol of [10, 11]. This attack motivates the design of a new family of Nakamoto-style longest chain PoS protocols, with a formal proof of their security against all possible attacks in a general security model.
The Session Initiation Protocol (SIP) is an application-layer control protocol for creating, modifying, and terminating Voice/Video over IP sessions. While deployed globally to facilitate multimedia communications, SIP is subject to various attacks. The defense against SIP attacks, however, often lack expertise due to the limited resources within the organization. When there is a large footprint of SIP systems, scaling and keeping up SIP defense becomes crucial in safeguarding these systems. This paper proposes SIPchain, a distributed SIP defense cluster system that leverages Blockchain technology as a distributed, highly-available, and permanent ledger of Indicator of Compromise (IOC). Each node in this cluster is a sensor and shares attack intelligence with other nodes via Blockchain. Each node reads information from the Blockchain and implements the appropriate firewall rule based on this information. This approach scales the defense because each node can leverage the actionable intelligence provided by other nodes and does not have to perform detection on their own. Experiments have been performed using a cluster of three SIP nodes in three different countries (US, UK, and Singapore) and the Ethereum Blockchain network. The result shows that when a node detected an attack, it produced and stored the IOC information at the Ethererum. Fellow SIP nodes retrieved this information, implemented firewall rule based on this information, and were proactively prepared when the same attack was launched against them. This SIPchain approach scales the SIP defense effort by utilizing Blockchain technology to secure the ever-growing footprint of SIP systems within the organization.
Achraf Fayad, Badis Hammi, Rida Khatoun, Ahmed Serhrouchni
Internet of Things (IoT) systems are almost a part of our daily lives. The security of this new paradigm had always faced many challenge in order to insure user privacy and authentication. These security issues are still far from being solved by the classical centralized architectures which reaches their limits in terms of scalability especially when thousands or tens of thousands of IoT devices are connected in the same network. To remedy this architectural issue, we rely on blockchains in order to propose a simple and lightweight blockchain-based authentication solution for IoT systems. We provided a real implementation of our proposed scheme relying on Ethereum blockchain and using different devices in order to confirm its feasibility and evaluate its initial performances. The results obtained confirm its suitability to such environments.
Blockchain is a specific type of distributed ledger with the features of high transparency and publicly verifiable which may threaten users' data privacy. Due to this concern, we propose a blockchain-based privacy protection identity authentication scheme in this paper. On the one hand, we take advantage of the decentralized feature of blockchain to safely store the hash value of users' identity information in the block of the blockchain, so that these information cannot be tampered and can be verified by the verifier. On the other hand, we introduce a set of key derivation algorithms into the scheme to provide anonymity and unlinkability. The scheme is applicable to scenarios with unified authentication and information privacy protection requirements.
A network of embedded sensors on the human body called Wireless Body Area Network (WBAN) has recently emerged as a healthcare monitoring framework, to provide better medical services. The data collected by these sensors is transmitted via a wireless medium and contains sensitive information of the patients. Therefore, how to provide security schemes for WBAN with resource constraints devices remains a big challenge. Recently, BAN-GZKP, an authentication scheme based on Zero-Knowledge Proof (ZKP) was designed for WBAN as an optimal solution to several attacks suffered by another ZKP based protocol called BANZKP. However, BAN-GZKP is found to be vulnerable to Node Compromise Attack, Node Impersonation, and Denial-of-Service Attacks. To fix the vulnerabilities of BANGZKP, this paper proposes an enhanced BAN-GZKP which exploits a unique physical layer characteristic coming from the surrounding WBAN, i.e., the distinct received signal strength variation among on-body channels and between on-body and off-body channels, to ensure robust authentication. To prove the reliability of our proposal, we conducted real-world experiments on 3 subjects in indoor and outdoor areas. The results showed that our scheme improves the security of the previous scheme with even lesser cost.
Increasingly, governments around the world, particularly in technologically advanced countries, are exploring or implementing smart homes, or the related smart facilities for the benefits of the society. The capability to remotely access and control Internet of Things (IoT) devices (e.g., capturing of images, audios, and other information) is convenient but risky, as vulnerable devices can be exploited to conduct surveillance or perform other nefarious activities on the users and organizations. This highlights the necessity of designing a secure and efficient remote user authentication solution. Most of the existing solutions for this problem are generally based on a single-server architecture, which has limitations in terms of privacy and anonymity (leading to users' daily activities being predicted), and integrity and confidentiality (resulting in an unreliable behavior auditing). While blockchain-based solutions may mitigate these issues, they still face some critical challenges (e.g., providing regulation of behaviors and privacy protection of access policy). Motivated by these facts, in this article, we construct a novel secure mutual authentication system, which can be applied in smart homes and other applications. Specifically, the proposed approach integrates blockchain, group signature, and message authentication code to provide reliable auditing of users' access history, anonymously authenticate group members, and efficiently authenticate home gateway, respectively. We also prove the security and privacy requirements, including anonymity, traceability, and confidentiality, that the proposed system satisfies, with an implementation and evaluation to demonstrate its practicality.
Mohammad El-Hajj, Ahmad Fadlallah, Maroun Chamoun, Ahmed Serhrouchni
Enterprises are no doubt interested in reaching data collected from billions of Internet of Things (IoT) devices which opens a huge potential business. The main concern remains the security challenges from the distribution of key while using public key cryptography. To ensure that IOT connected devices can be trusted to be what they are supposed to be, robust IoT device authentication is mandated. Each IoT device therefore requires a unique identity which can be verified when the device tries to link to an intermediate device. One of the early solutions used to secure data transmission among parties in public networks is the Public Key Infrastructure (PKI) which is used to distribute and manage public keys (digital certificates) among different parties and these certificates are generated upon request by Certificate Authorities (CA). Nevertheless, for billions of devices connected to IoT and mobile phones, the distribution management of certificates for each client proved to be inefficient. In this research, we propose a decentralized authentication platform based on PKI and Ethereum Blockchain. The public key certificates are stored in a decentralized fashion and the private keys are stored inside the devices themselves. It also includes a protocol for Pre-Shared Keys (PSK) distribution. PSK keys are then used by PSK-based security protocols for securing the communication channel between two devices. This platform includes a client-side module, a server-side Wallet Management Function, and a smart contract deployed on the Ethereum Blockchain network. This platform can be used by applications for end devices and/or intermediate devices authentication and a secure Machine-to-Machine (M2M) communication. The proposed platform is validated by the implementation of a Secure Session Establishment between IoT devices. Results show that the solution implementation has minimal impact on the existing networks, and the secure session setup time between two devices is negligible compared to the existing security methods. Eventually, this scheme can help removing the trust requirement placed on clients by the current PKI/CAs infrastructure.
Bhabendu Kumar Mohanta, Anisha Sahoo, Shibasis Patel, Soumyashree S. Panda · 6 authors
Internet of Things (IoT) has lots of attention in the last decade. The connected IoT devices are more than the total world population. Due to its low cost, easy to deploy, and simple to implement, application areas are large like smart city, smart home, smart transportation, environment monitoring, agriculture and many more. There exists some security and privacy challenges in IoT system. The device identification is one of the challenges in any IoT application. Authentication is one of the processes to identify the device. Though some work has been done on this problem, most of these are using a centralized system. In this paper, we have proposed a distributed authentication system using the Blockchain technology The implementation of the proposed authentication is done on Ethereum platform for its better results in order to justify it as a superior scheme.
The importance of the Internet of Things is constantly growing, together with the proliferation of IoT devices which are changing our daily life and empowering industrial processes. However, the most IoT devices and protocols were not designed with security in mind, and economic and energyconsumption constraints make the implementation of security measures a non-trivial problem. One of the most used messaging protocol in IoT, which is MQTT (Message Queuing Telemetry Transport), leaves to developers the task to implement security, as native security services provided by the protocol are very weak. This paper focuses on MQTT authentication, which is definitely insecure in the protocol, even though the implementations can combine MQTT with other mechanisms to obtain a suitable level of security. The aim of the present work is to propose an innovative OTP-authentication scheme for MQTT which uses Ethereum to implement an independent logic channel for the second-factor authentication. The implementation of the proposed scheme relies on the trusted behavior of smart contracts and adopts suitable strategies to preserve the privacy of users.