Dato Kavazi, Victor Smirnov, Sasha Shilina, Jonathan Shomroni · 7 authors
We present a novel 1 Human = 1 Node blockchain protocol which aims to overcome problems arising from plutocratic principles upon which Proof-of-Work (PoW) and Proof-of-Stake (PoS) heavily rely on. The advent of blockchain technology has led to a massive wave of different decentralized ledger technology (DLT) solutions. Projects such as Bitcoin and Ethereum managed to shift the paradigm of how to transact value in a decentralized manner, yet their core technologies give rise to a significant early adopters’ control bias and have led to financial systems flawed by massive inequality and centralization of power. In this paper we propose an alternative to modern decentralized financial networks by introducing the Humanode network. Humanode is a network safeguarded by cryptographically secure bio-authorized nodes on which users are able to deploy nodes by staking their encrypted biometric data. This approach can potentially lead to the creation of a truly public, permissionless financial network, based on consensus between equal human nodes with algorithmic emission mechanisms targeting real value growth and contribution-based wealth distribution.
Cloud computing is a cost-effective way for organizations to access and use IT resources. However, it also exposes data to security threats. Authentication and authorization are crucial components of access control that prevent unauthorized access to cloud services. Organizations are turning to identity management solutions to help IT administrators face and mitigate security concerns. Identity management (IDM) has been recognized as a more robust solution for validating and maintaining digital identities. Identity management (IDM) is a key security mechanism for cloud computing that helps to ensure that only authorized users have access to data and resources. Traditional IDM solutions are centralized and rely on a single authority to manage user identities, which makes them vulnerable to attack. However, existing identity management solutions need to be more secure and trustworthy. Blockchain technology can create a more secure and trustworthy cloud transaction environment. Purpose: This paper investigates the security and trustworthiness of existing identity management solutions in cloud computing. Comparative results: We compared 14 traditional IDM schemes in cloud systems to explore contributions and limitations. This paper also compared 17 centralized, decentralized, and federated IDM models to explain their functions, roles, performance, contribution, primary metrics, and target attacks. About 17 IDM models have also been compared to explore their efficiency, overhead consumption, effectiveness to malicious users, trustworthiness, throughput, and privacy. Major conclusions: Blockchain technology has the potential to make cloud transactions more secure and reliable. It featured strong authentication and authorization mechanisms based on smart contracts on the Ethereum platform. As a result, it is still regarded as a reliable and immutable solution for protecting data sharing between entities in peer-to-peer networks. However, there is still a large gap between the theoretical method and its practical application. This paper also helps other scholars in the field discover issues and solutions and make suggestions for future research.
With the rapid development of information and communication technology, vehicular AD hoc networks (VANETs) has attracted more and more attention. In order to provide traffic safety services, vehicles frequently share information related to road traffic, such as vehicle motion data and traffic flow data. Reliable key generation is the basis of VANET security system construction. Presently, most key generation schemes rely on a trusted third party, so there are security risks. Traditional key agreement protocols have high overhead, and is not suitable for the latency-sensitive requirements of VANET. The physical layer security technology extracts the fingerprint of the wireless channel and the identity of the device, and generates the key quickly and in real time without the third party distribution. A physical layer key generation scheme based on received signal strength (RSS) is proposed to realize Vehicle-to-Vehicle (V2V) secure communications. First, a network model based on long short-term memory (LSTM) network and the Kalman filtering is proposed to effectively enhance the reciprocity of physical layer information in dynamic environment. Second, a lossless quantization scheme is proposed, which achieves a lower bit disagreement rate and a higher bit generation rate. Third, the inconsistent bits are corrected by fuzzy extractor, the confidentiality of the key exchange process is enhanced by zero knowledge proof, and the security of the key is improved by using hash function for privacy amplification. Finally, the experimental results show that the proposed scheme has great improvements in data correlation, bit disagreement rate, bit generation rate and bit distribution randomness.
With the advent of the era of big data, privacy computing analyzes and calculates data on the premise of protecting data privacy, to achieve data 'available and invisible'. As an important branch of secure multi-party computation, the geometric problem can solve practical problems in the military, national defense, finance, life, and other fields, and has important research significance. In this paper, we study the similarity problem of geometric graphics. First, this paper proposes the adjacency matrix vector coding method of isomorphic graphics, and use the Paillier variant encryption cryptography to solve the problem of isomorphic graphics confidentiality under the semi-honest model. Using cryptography tools such as elliptic curve cryptosystem, zero-knowledge proof, and cut-choose method, this paper designs a graphic similarity security decision protocol that can resist malicious adversary attacks. The analysis shows that the protocol has high computational efficiency and has wide application value in terrain matching, mechanical parts, biomolecules, face recognition, and other fields.
Open access
Biometric Identification and Security
Advanced Steganography and Watermarking Techniques
With the growing popularity of smartphone photography in recent years, web photos play an increasingly important role in all walks of life. Source camera identification of web photos aims to establish a reliable linkage from the captured images to their source cameras, and has a broad range of applications, such as image copyright protection, user authentication, investigated evidence verification, etc. This paper presents an innovative and practical source identification framework that employs neural-network enhanced sensor pattern noise to trace back web photos efficiently while ensuring security. Our proposed framework consists of three main stages: initial device fingerprint registration, fingerprint extraction and cryptographic connection establishment while taking photos, and connection verification between photos and source devices. By incorporating metric learning and frequency consistency into the deep network design, our proposed fingerprint extraction algorithm achieves state-of-the-art performance on modern smartphone photos for reliable source identification. Meanwhile, we also propose several optimization sub-modules to prevent fingerprint leakage and improve accuracy and efficiency. Finally for practical system design, two cryptographic schemes are introduced to reliably identify the correlation between registered fingerprint and verified photo fingerprint, i.e. fuzzy extractor and zero-knowledge proof (ZKP). The codes for fingerprint extraction network and benchmark dataset with modern smartphone cameras photos are all publicly available at https://github.com/PhotoNecf/PhotoNecf 1.
Open access
3 source records
cs.CV
Digital Media Forensic Detection
Advanced Steganography and Watermarking Techniques
In this paper, we explore Blockchain technology can be used to build a reliable decentralised authentication system. High security for the bioacoustics signal authentication mechanism is guaranteed by using an optimised number of secured features from the bioacoustics signal rather than conventional biometric features for authentication, and by utilising a blockchain model to improve the robustness of multiple checks on the data. It allows for trustworthy authentication and the tracking of terminal activity. Then, light weighted cryptography (LWC) is developed to offer protection at each edge node and terminal. Finally, the belief propagation (BP) algorithm for retraining the features of the bioacoustics signal serves as the foundation for the catching method. It improves hit ratio while decreasing delay time. The experimental setup uses the bioacoustics signals for authentication instead of conventional biometric features, and the use of a blockchain model for data transparency improves the efficiency of multiple checks. When this happens, privacy and safety are both boosted.
Unlike general passwords, user authentication technology using biometric data cannot be lost or forgotten, and it has the advantage of being impossible to forge or falsify by attackers. Since this biometric data contains sensitive information, a safe storage method is needed. However, if biometric data is managed on a central server, it is limited by being vulnerable to integrity infringement attacks by system attackers and persistent infringement attacks on the authentication service. To solve this problem, a model using blockchain-based information security technology is proposed in this paper. The aim is to safely manage the user biometric data by dispersing the storage of the biometric data feature information for user authentication in smart contracts and IPFS using Ethereum. We have verified that it takes an average of 1,472.733 ms and 217.829 ms, to register and authenticate a user in the proposed model and we expect that it will provide a reliable authentication service to the users compared to the existing authentication method in which the biometric data is managed by a single server.
Zengpeng Li, Mei Wang, Vishal Sharma, Prosanta Gope
Vehicle authentication is an essential component validating the vehicle’s identity and ensuring the integrity of transformed data for intelligent transport vehicles (ITS) in the vehicular ad hoc network (VANET). Easy to deploy and operate privacy-enhancing vehicle authentication mechanisms are the mainstay for the widespread ITS in the VANET. Very recently, VANET security architectures are constituting by IEEE 1609.2 group, NoW project, the SeVeCom project. However, these approaches heavily depend on the consuming public key infrastructure (PKI) and certification authorities (CA). In this work, walking along the research line, we attempt to design authentication protocols with two diverse factors for Vehicle-to-Vehicle (V2V) and Vehicle-to-Infrastructure (V2I) networks, respectively, without depending on the stumbling block PKI/CA. In addition, a smooth projective hash function (SPHF) (a.k.a., a special case of the designated-verifier zero-knowledge proof system) guarantees any recipient can confirm the authenticity and integrity of the received messages without knowing the authentication factors. Thus, to optimize the communication round, SPHF is used to design a (group) two-factor authenticated key exchange (AKE) with low-interactive communication rounds. The proof-of-concept implementation indicates that the computation and communication overheads introduced by our solution are acceptable in real-world deployments. The security of the proposed approach is validated using Bellare-Pointcheval-Rogaway (BPR) model along with the experimental evaluation and the theoretical analysis.
Ali Zouaghi Yousra, Mahamdioua Meriama, Atidel Lahoulou
Biometric authentication methods generally rely on centralized authority such as centralized database servers to store biometric templates and manage authentication. These methods suffer from different points of attack. If the central entity is compromised, the system becomes vulnerable and unable to ensure integrity of stored templates. This paper proposes a distributed scheme of biometric authentification, eliminating the need for a central entity. The proposal is based on the Ethereum blockchain, which offers decentralized and irreversible properties for the storage and management of biometric templates. For each user, the fingerprint template is encrypted using homomorphic encryption and stored on the smart card. The hashed encrypted vector is then stored on the blockchain to ensure its confidentiality. Our proposed scheme, allows authentication of users using a smart contract, while the distance calculation is performed on the encrypted domain that achieves the integrity of the calculation results. By using hashed vectors, the proposal is efficient and cost-effective. These improvements provide solutions to many problems in biometric systems such as template modification, channel interception, and override comparator.
Biometric Identification and Security
Advanced Steganography and Watermarking Techniques
The Biometric system can be understood as a system that deals with an automated recognition of individual based on their physiological aspects (face, fingerprints, iris, retina) and behavioral patterns (signature, posture etc.). Biometric system works on feature extraction and feature matching. The feature is extracted in the form of fingerprints, iris and retina and then it is matched by the information stored by measuring the same patterns of particular individual, this process is feature matching. Between the two, works template database which is a central point from where every time the feature extracted is matched for confirming the identity of a person.. If the database is breached by the hacker, then the data could be used for falsifying the identity of the person. The paper focuses to implement blockchain technology in a biometric system in a manner that every record of individual is maintained using a blockchain so that it can’t be hampered by the hacker. Blockchain works as adecentralized repository of data which we assume to be the most suitable approach to hold the credentials of individuals and thus avoiding an unauthorized access to the systems. Making changes to blockchain is a complex and time-consuming task for any unwanted user. Many researchers contributed their work highlighting the security issues of the biometric system when applied practically. They noted that the fingerprint of an individual remains the same over life and once applied can’t be modified when compares with non-biometric systems which makes use of passwords and if forgotten or breached could be changed. Some of them conveyed that the biometric system is safe when only considering its physical implementation but the database created is still under threat.
Biometric Identification and Security
User Authentication and Security Systems
Advanced Steganography and Watermarking Techniques
We propose a method to protect ownership of specified areas on image data using blockchain. Different values are assigned corresponding to the object's importance in the region and the ownership of the area is managed and given to the required user. The detected areas are individually encrypted by XOR cipher, and a corresponding key image is created to decrypt to protect ownership of selected object regions detected by the object recognition algorithm. We use non-fungible tokens(NFTs) to secure key images by managing ownership of each object on image data. Key images to decrypt are registered as NFTs. Ownership NFTs are also created to access and retrieve the key image NFTs. Each key image NFT is generated by key holders and ownership NFTs are obtained by users requiring them. In addition, there is a judging function that clarifies if ownership and key NFTs match. Key NFTs appear on the screen only when they are matched.
Advanced Steganography and Watermarking Techniques
The integration of the Internet of Things (IoT) with traditional healthcare systems has improved quality of healthcare services. However, the wearable devices and sensors used in Healthcare System (HS) continuously monitor and transmit data to the nearby devices or servers using an unsecured open channel. This connectivity between IoT devices and servers improves operational efficiency, but it also gives a lot of room for attackers to launch various cyber-attacks that can put patients under critical surveillance in jeopardy. In this article, a Blockchain-orchestrated Deep learning approach for Secure Data Transmission in IoT-enabled healthcare system hereafter referred to as “BDSDT” is designed. Specifically, first a novel scalable blockchain architecture is proposed to ensure data integrity and secure data transmission by leveraging Zero Knowledge Proof (ZKP) mechanism. Then, BDSDT integrates with the off-chain storage InterPlanetary File System (IPFS) to address difficulties with data storage costs and with an Ethereum smart contract to address data security issues. The authenticated data is further used to design a deep learning architecture to detect intrusion in HS network. The latter combines Deep Sparse AutoEncoder (DSAE) with Bidirectional Long Short-Term Memory (BiLSTM) to design an effective intrusion detection system. Experiments on two public data sources (CICIDS-2017 and ToN-IoT) reveal that the proposed BDSDT outperformed state-of-the-arts in both non-blockchain and blockchain settings and have obtained accuracy close to 99% using both datasets.
Abstract With the the advent era of big data, the secure computation calculates data on the premise of protecting data privacy, to realize the availability and invisibility of data. Secure multi-party computation, as one of three major technical tools of privacy computing, can still securely carry out data collaborative computation without a trusted third party. As an important branch of secure multi-party computation, the secure computing geometric problem can solve practical problems in the military, national defense, finance, life, and other fields, which has important research significance. In this paper, the graphic similarity problem is studied. Firstly, this paper proposes the adjacency matrix vector coding method of isomorphic graphics and uses the Paillier variant cryptosystem to securely solve the graphic similarity judgment under the semi-honest model. By using an elliptic curve cryptosystem and zero-knowledge proof to solve the possible malicious attacks under the semi-honest model, a graphic similarity judgment protocol under the malicious model is designed. The protocol can resist malicious attacks, has high computational efficiency, and has wide application value.
Non-fungible tokens (NFTs) are becoming very popular in a large number of applications ranging from copyright protection to monetization of both physical and digital assets. It is however a fact that NFTs suffer from a large number of security issues that create a lack of trust in solutions based on them. In this paper, we provide an overview of some of the most critical security challenges in media assets in form of visual content and then propose a specific solution for one among them, namely, secure person identification used in the context of KnowYour-Customer (KYC) with emphasis on liveness detection. The solution includes an authentication procedure that matches a selfie photo to a photograph of an identity document (ID). The system runs through a series of steps. First, detection is applied to extract faces from the selfie and the ID. Then a face comparison is performed to assess if they belong to the same person. While these two procedures are standard in KYC, a liveness check is also included so as to increase the security. The latter ensures that the user undergoing identity verification is in front of the camera and not a fraudster attempting to impersonate another individual. The system instructs the user to perform gestures such as waving hands or tilting head in front of the camera. The algorithmic detection of these actions during the live feed will reveal whether or not the user is carrying out the instructed activities. Performance of the proposed solution is then assessed under varying conditions.
Mehedi Masud, Gurjot Singh Gaba, Pardeep Kumar, Andrei Gurtov
Ambient Intelligence (AmI) in Internet of Things (IoT) has empowered healthcare professionals to monitor, diagnose, and treat patients remotely. Besides, the AmI-IoT has improved patient engagement and gratification as doctors’ interactions have become more comfortable and efficient. However, the benefits of the AmI-IoT-based healthcare applications are not availed entirely due to the adversarial threats. IoT networks are prone to cyber attacks due to vulnerable wireless mediums and the absentia of lightweight and robust security protocols. This paper introduces computationally-inexpensive privacy-assuring authentication protocol for AmI-IoT healthcare applications. The use of blockchain & fog computing in the protocol guarantees unforgeability, non-repudiation, transparency, low latency, and efficient bandwidth utilization. The protocol uses physically unclonable functions (PUF), biometrics, and Ethereum powered smart contracts to prevent replay, impersonation, and cloning attacks. Results prove the resource efficiency of the protocol as the smart contract incurs very minimal gas and transaction fees. The Scyther results validate the robustness of the proposed protocol against cyber-attacks. The protocol applies lightweight cryptography primitives (Hash, PUF) instead of conventional public-key cryptography and scalar multiplications. Consequently, the proposed protocol is better than centralized infrastructure-based authentication approaches.
Biometric identification is a convenient and reliable method in identity authentication. The widespread adoption of biometric identification requires strong privacy protection against possible theft or loss of biometric data. Existing techniques for privacy-preserving biometric identification mainly rely on traditional cryptographic technology such as oblivious transfer and homomorphic encryption, which will incur huge expenses to the system and cannot be applied to large-scale practical applications. For these issues, we propose a biometric identification scheme by constructing zero-knowledge succinct noninteractive argument of knowledge (zk-SNARK). Our scheme not only reduces the communication overhead, which only needs to send 8 constants to the verifier but also can protect the fingerprint template from disclosure. The time complexity of proof generation and proof verification are about O(C) and <a:math xmlns:a="http://www.w3.org/1998/Math/MathML" id="M1"> <a:mi>O</a:mi> <a:mfenced open="(" close=")" separators="|"> <a:mrow> <a:mi>x</a:mi> </a:mrow> </a:mfenced> <a:mo>+</a:mo> <a:mi mathvariant="normal">log</a:mi> <a:mtext> </a:mtext> <a:mtext> </a:mtext> <a:mi>C</a:mi> </a:math> , respectively, and the size of the proof is only 8 constants, where C and x represent the size of the circuit and the public input, respectively. We have implemented the proposed authentication solution on a public data set of fingerprint images and evaluated the performance and security.
Integration of healthcare and Internet of Things (IoT) has a potential to revolutionize the medical treatments, diagnosis and predict medical issues thereby enabling patients, families, doctors and medical insurers stay connected for a proactive delivery of services. However, IoT devices operate in infrastructure-less environments, and hence data security and privacy is always a concern. Counterfeit IoT devices create huge menace in sensitive applications. Moreover, conventional healthcare systems are not patient-centric in the sense that they do not include patient’s emotions during treatments. EI helps the clinicians better understand and mange medical procedures. This paper presents a human-centered approach in healthcare domain by the integration of emotional intelligence (EI) and sensor network built around IoT devices. A Raspberry Pi connected with sensors and a camera acts as an IoT device. These sensors collect body vital parameters and Facial expression recognition (FER) based EI. The system is hosted on an Ethereum permissioned blockchain for reliability, security and tamper-proof data sharing and storage. Devices in the network are authenticated using physical unclonable functions (PUFs). Comparative analysis confirms that the PUF-based authentication is 330% faster than conventional methods. The system offers latency of as low as 20 ms. Using smart contracts, the proposed model provides role-based access control and helps in building scalable and harmonious digital healthcare platforms.
User authentication is a measurement challenge for handheld devices and online accounts such as bank accounts, social media accounts etc. because illegal access results in money loss and user privacy. Individual devices, online financial services, and intelligent spaces are three significant areas of concern for customer authentication procedures. Three ways have been identified for authentication factors: i) knowledge-factor, ii) Inherence factor, and iii) possession-factor. This study investigates two-way user authentication through image processing. CNN, RCNN, and Deepface are deep learning algorithms used for image recognition. We used imagechain for image storage and Blockchain for personal information storage (mobile number) to secure the database. The database is stored on an Ethereum-based blockchain. After determining whether the image is fake or real, match the webcam image with the imagechain; if both images match, the one-time password is given to the user’s cellphone number for login access. For image processing, Opencv is employed, and the Python library is used to execute machine and deep learning algorithms for user authentication. Test the proposed model on the 10 to 100 users for authentication. Accuracy of this experiment is 75.35, 76.33, 98.18 and cosine similarities of images are much better between images, but in case of fake image identification it achieved 97.35 % accuracy.
User Authentication and Security Systems
Biometric Identification and Security
Advanced Steganography and Watermarking Techniques
We propose an efficient identity authentication protocol based on cancelable biometric and Physical Uncloable Function (PUF) namely BioP-TAP, which realizes the two-way authentication between the user and the server. Specially, the concept of biometric template protection is added to the proposed protocol to better protect user privacy. We use the properties of PUF to generate the cancelable biometric and adds it to the authentication protocol. Then, we design a complete authentication protocol combining the elliptic curve Pedersen commitment and Zero-knowledge proof. Finally, we adopt the method of combining formalization and non-formalization to carry out scientific evaluation from multiple perspectives. And the performance analysis and comparison with existing schemes are employed to evaluate the proposed scheme, so as to ensure the effectiveness and security. The results show that the proposed method is more effective for security than existing methods, and more suitable for the user biometric authentication in a multi-server environment.
Biometric Identification and Security
Physical Unclonable Functions (PUFs) and Hardware Security
In the modern processed world, it becomes more necessary to certify humans in a very secure way. There are modern square measure applications such as online banking or online search usage techniques that are depended on passwords, keys or individual identification card. These technologies and processes carry the danger that information may be forgotten, lost, or perhaps stolen. Therefore, the forms of identification promise a singular thanks to being ready to certify humans. A secure and confidential identification technique is the use of fingerprints. We proposed here IoT and Blockchain Based Intelligence Security System for Human Detection using an Improved ACO and Heap Algorithm. We proposed IoT and Blockchain Based Technology for ensuring the security of our system.