Mehmet Ali Aygül, Hakan Ali Çırpan, Hüseyin Arslan
This paper proposes a novel multi-party key generation method that jointly utilizes channel state information (CSI) and blockchain technology to enhance security in distributed systems. The proposed method starts by extracting CSI from wireless channels, leveraging the channels’ inherent randomness and reciprocity to generate secure key fragments shared among legitimate parties. Then, the key generation process involves several stages, including quantization, reconciliation, and privacy amplification, ensuring that the resulting keys are secure and synchronized across participants. Blockchain technology is then leveraged to securely commit these keys, ensuring that the key agreements are recorded in a decentralized, tamper-resistant ledger. The proposed method effectively combines the physical-layer properties of CSI with the decentralized nature of blockchain, providing robust protection against eavesdropping and tampering attacks. Theoretical analyses and simulation results demonstrate the effectiveness of the proposed method in terms of key mismatch probability and secrecy capacity. Additionally, the randomness of the generated keys by the proposed method is validated using the National Institute of Standards and Technology randomness tests.
Yenlik Begimbayeva, Temirlan Zhaxalykov, Amir Akhtanov, Ruslan Pashkevich · 6 authors
This research focuses on enhancing the security of decentralized quantum key distribution (QKD) networks, where the absence of a central authority creates significant challenges such as malicious node infiltration, undetected key leakage, and unauthorized re-entry of revoked participants. Traditional authentication and trust models are insufficient for fully distributed QKD topologies, which remain highly vulnerable to insider threats and persistent compromise. To address these risks, let’s propose a layered security framework composed of three integrated components: Challenge-Response Authentication (CRA), Dynamic Trust Scoring (DTS), and Blockchain-Based Access Control (BBAC). CRA verifies node legitimacy through randomized quantum-state interactions, significantly reducing impersonation and quantum replay attacks. DTS implements real-time trust evaluation using anomaly detection to dynamically downgrade compromised nodes based on their behavioral deviations. BBAC maintains an immutable and tamper-proof trust ledger to block revoked nodes from re-entering under falsified identities and resists Sybil attacks using post-quantum cryptographic primitives. Simulation results confirm that the system improves detection rates of covert threats, ensures authentication latency under 10 ms, and reduces re-entry success to zero. The proposed architecture ensures long-term scalability and resilience, making it applicable to critical domains such as finance, national infrastructure, and military communication. This work contributes a novel, verifiable, and scalable solution to one of the most pressing open problems in distributed quantum networks
W. Jiang, Zhiqiang Du, Xiaofeng Rong, Yanfang Fu · 6 authors
With the rapid development of 5 G communication technology, small military UAV swarms are increasingly used in reconnaissance, surveillance, and remote sensing fields. Authentication has become a critical factor in ensuring the safe and efficient operation of UAV swarms. Due to their complexity and limitations, traditional methods cannot meet the dynamic deployment and command authority switching requirements of UAV swarms in special wartime environments. Therefore, this study proposes a secure and efficient authentication scheme for UAV swarms based on the CVMerkle tree structure. The scheme integrates distributed digital ledger technology to optimize the authentication process between UAVs and the Airborne Command Center(ACC). This significantly reduces the communication and computational load while improving the security and reliability of authentication. Additionally, the scheme introduces the innovative concept of dynamic authorization in the ACC, which effectively eliminates security threats arising from internal corruption within the core organization. The results of the simulation experiment demonstrate that the scheme offers significant advantages in terms of security, efficiency, and storage requirements. Future research will focus on developing more efficient key management mechanisms and swarm-switching strategies to adapt to the complex and dynamic combat environment, further enhancing the combat effectiveness of UAV swarms.
A MANET (Mobile Ad Hoc Network) is a decentralised, infrastructure-less system inherently vulnerable to a variety of security threats due to its dynamic topology and limited resources. In such networks, traditional trust management approaches, which are typically centralised and resource-intensive, do not meet the security requirements. A hybrid Proof-of- Work (Po W)/Proof-of-Stake (PoS) trust framework that takes advantage of elliptic curve cryptography (ECC) is presented for MANETs. Three factors are considered in calculating the dynamic trust score: node behaviour, energy efficiency, and communication efficiency. As a result of the proposed model, trust evaluation accuracy and transaction validation are enhanced while the computational overhead and latency are minimised. The results show that the system has strong potential for securing and scaling MANET deployments by reducing detection times, controlling overhead, and mitigating the impact of network attacks.
The Internet of Vehicles (IoV), as a core component of intelligent transportation systems, significantly enhances the intelligence level of traffic management by enabling efficient vehicle-to-vehicle (V2V) and vehicle-to-infrastructure information sharing. However, the highly dynamic and open nature of the IoV poses severe security challenges in cross-domain scenarios, mainly due to the lack of trust relationships between different domains, making it difficult to achieve efficient and secure cross-domain authentication(CDA). Existing CDA mechanisms in the IoT context often suffer from high computational complexity, excessive communication overhead, and poor scalability for large-scale deployments. This paper proposes a Batch CDA Protocol based on Dynamic Group Signatures (BCDAP-DGS) to address these issues. The proposed protocol incorporates non-interactive zero-knowledge (NIZK) proofs to achieve secure identity verification without requiring additional data exchange. By leveraging dynamic group signature techniques, BCDAP-DGS supports real-time updates of vehicle membership status and provides conditional anonymity. In addition, an online/offline authentication framework is designed by incorporating vehicle location information to precompute related parameters, thereby significantly improving CDA efficiency. A formal security analysis is conducted under the random oracle model, demonstrating that the proposed protocol satisfies essential security properties, including anonymity, non-frameability, unforgeability, and traceability. Experimental results and performance comparisons show that the proposed protocol outperforms existing schemes in terms of both security and efficiency, making it well-suited for large-scale and highly dynamic IoV CDA scenarios.
Santiago Germino, Martín N. Menéndez, Ariel Lutenberg
Essential infrastructure and services depend on critical systems. To ensure that critical systems function properly, regular testing and monitoring are necessary. Establishing direct, dedicated data connections for remote testing can be expensive, while using public cellular, satellite, or fiber Internet connections can introduce privacy and security risks. Securing the medium often requires placing trust in third parties. The novel proposal introduced in this work suggests using zero-knowledge proofs, a modern cryptographic technique, to conduct secure remote testing and monitoring of critical systems over affordable public networks, which can include email or instant messaging apps. This approach guarantees both the integrity and confidentiality of the transmitted data, as well as the integrity of the processes involved in preparing the data for transmission. We will present this approach and demonstrate its implementation through a real-world use case: the remote testing of an electronic railway interlocking system.
The evolution of future network and control technologies has enabled unmanned aerial vehicles (UAVs) to collaborate across diverse geographical areas and task domains, enhancing task execution efficiency through data and resource sharing. In response to the increasing demand for cross-domain task allocation and operations for UAVs, establishing robust authentication mechanisms within trusted domains has become a critical foundation for ensuring secure cross-domain access. Despite significant progress in UAV identity authentication and cross-domain access, challenges persist, such as cumbersome and inefficient processes, UAV resource limitations, and establishing trust relationships across different domains. To address these challenges, this paper introduces a dual blockchain-assisted trusted authentication scheme for UAVs' cross-domain access. Our approach utilizes a certificateless signcryption algorithm for lightweight UAV authentication, thereby eliminating the need for certificate management. Then, an efficient credit-based trust model is designed to measure the trustworthiness of data-in-transit and cross-domain entities. Furthermore, blockchain technology is introduced to store the relevant information of UAVs and credibility to assist cross-domain authentication. Theoretical security analysis and extensive simulations have been conducted, demonstrating the effectiveness and efficiency of our proposed scheme.
Bhupinder Kaur, Deepak Prashar, Leo Mršić, Ahmad Almogren · 7 authors
Wireless sensor networks (WSNs) are subject to distributed denial-of-service (DDoS) attacks that impact data dependability, mobility of nodes, and energy drain. The remedy to these challenges in this work is a solution based on deep learning integrated with a blockchain-aided distance-vector hop (DV-HOP) localization algorithm for reliable and secure node localization. Incorporating a blockchain ledger makes the network more trustworthy as it verifies usual and unusual system activities, whereas the DV-HOP algorithm mitigates localization inaccuracies and enhances node placement. The system is evaluated according to different performance measures like localization error, accuracy ratio, average localization error (ALE), probability of location, false positive rate (FPR), false negative rate (FNR), energy utilization, network stability, node failure rate, node recovery rate, and malicious node detection rate. Experimental results reveal improved security, accuracy, and efficiency with 17% FPR and 15% FNR, outperforming the conventional methods. This model enhances WSN performance in different environments via precise data transmission from the source to the destination. The results confirm that integrating deep learning with blockchain and DV-HOP increases network robustness, thus making WSNs more secure against security attacks while reducing energy consumption and localization accuracy. The proposed model presents a strong solution for real-world applications in wireless network environments.
Threshold multi-party fully homomorphic encryption (TMFHE) schemes enable efficient computation to be performed on sensitive data while maintaining privacy. These schemes allow a subset of parties to perform threshold decryption of evaluation results via a distributed protocol without the need for a trusted dealer, and provide a degree of fault tolerance against a set of corrupted parties. However, existing TMFHE schemes can only provide correctness and security against honest-but-curious parties. We construct a compact TMFHE scheme based on the Learning with Errors (LWE) problem. The scheme applies Shamir secret sharing and share resharing to support an arbitrary t-out-of-N threshold access structure, and enables non-interactive reconstruction of secret key shares using additive shares derived from the current set of online participants. Furthermore, the scheme implements commitment and non-interactive zero-knowledge (NIZK) proof techniques to verify the TMFHE operations. Finally, our experiments demonstrate that the proposed scheme achieves active security against malicious adversaries. It overcomes the limitation of existing TMFHE schemes that can only guarantee correct computation under passive semi-honest adversaries.
C. Aparna, S. Radha, C. Aarthi, K. M. Karthick Raghunath
ABSTRACT Mobile Ad hoc networks (MANETs) are key for applications in which flexibility and organization are paramount, but the security of such networks entails threats that can exploit the vulnerability of their open architecture, resulting in various attacks. To address such issues, a novel architectural framework is always required. One such framework is introduced, namely, the HoneyFed Secure Architecture (HFSA), which provides the combination of an advanced honey encryption system with federated learning‐based decentralized security to improve the security of MANET. Honey encryption, on the other hand, employs adaptive deception techniques to generate plausible decoy data on decryption failure, employs dynamic key management for tamper resistance, and provides perfect authentication through multi‐factor methods and zero‐knowledge proofs. We found that federated learning offers decentralized model training, where nodes jointly train local models while exchanging progress updates without exposing raw data, enabling 81.4% more detections of emerging threats while preserving data privacy. Using the proposed HFSA approach achieves a 78% protection improvement against attacks and a 71% reduction in unauthorized access. HFSA offers a robust and scalable framework of security that uses continuous learning and adaptation to the vulnerabilities of the MANETs to enhance network resilience.
Crypto wallets store and protect the private keys needed to sign transactions for crypto currencies; they are secured by multi-factor authentication schemes. However, the loss of a wallet, or a dysfunctional factor of authentication, can be catastrophic, as the keys are then lost as well as the crypto currencies. Such difficult tradeoffs between the protection of the private keys and factors of authentication that are easy to use are also present in public key infrastructures, banking cards, smartphones and smartcards. In this paper, we present protocols based on novel challenge–response pair mechanisms that protect private keys, while using factors of authentication that can be lost or misplaced without negative consequences. Examples of factors that are analyzed include passwords, tokens, wearable devices, biometry, and blockchain-based non-fungible tokens. In normal operations, the terminal device uses all factors of authentication to retrieve an ephemeral key, decrypt the private key, and finally sign a transaction. With our solution, users can download the software stack into multiple terminal devices, turning all of them into backups. We present a zero-knowledge multi-factor authentication scheme allowing the secure recovery of private keys when one of the factors is lost, such as the token. The challenge–response pair mechanisms also enable a novel key pair generation protocol in which private keys can be kept secret by the user, while a Keystore can securely authenticate the user and transmit the public key to a distributed network. The standardized LWE post-quantum cryptographic CRYSTALS Dilithium protocol was selected in the experimental section.
Open access
Physical Unclonable Functions (PUFs) and Hardware Security
Mobile ad hoc networks (MANETs) facilitate data communication across multiple nodes and hop stations, characterized by their dynamic topology. This inherent flexibility, however, makes MANETs vulnerable to various security threats, notably blackhole and wormhole attacks, where malicious nodes can intercept and manipulate data. This study investigates the security vulnerabilities of MANETs, particularly against blackhole, Sybil, and wormhole attacks, and introduces the Advanced Blockchain Dynamic Source Routing (ABCD) algorithm to address these challenges. Motivated by the need for robust and decentralized security solutions in MANETs, the proposed algorithm integrates blockchain technology and homomorphic encryption to secure data communication without intermediate decryption. The ABCD algorithm leverages Dijkstra’s algorithm for optimal routing and employs a tamper-proof, decentralized data storage approach. Comparative analysis under attack scenarios reveals that the ABCD algorithm outperforms the standard DSR protocol across multiple quality of service metrics, demonstrating a significant improvement in MANET security over equivalent studies. The packet delivery rate is also improved from 81 to 92% using the modified ABCD algorithm.
Abstract Authentication and access control for Cyber-Physical Systems (CPSs) are pivotal for protecting systems and their users from problems related to harmful actions and the malicious use of retrieved data. In some situations, making access decisions requires using user information, thereby challenging their privacy. Attribute-based access control (ABAC) supports dynamic and context-aware access decisions that are attractive in cyber-physical system environments. However, privacy preservation for access decisions is an open issue for authorization and is not supported by existing ABAC models. For example, if access decisions need to be made based on private attribute values such as health data, the corresponding access control policies need to be revealed. This paper reviews the ABAC, homomorphic encryption (HE), and zero-knowledge proof (ZKP) approaches, confirming the gap in privacy preservation in ABAC. Based on this observation, we further present the application of a new ZKP-based protocol in which ABAC allows for the privacy-preserving evaluation of attributes. This protocol is implemented and evaluated in terms of its performance and security. The evaluation demonstrates that there is a possibility for privacy-preserving ABAC, which may benefit the use of CPS, e.g., in underground and open-pit mines.
With the rise of the internet of things (IoT), ensuring operational efficiency and security for resource-constrained nodes has become crucial. This paper proposes two certificate-less key agreement protocols based on confidential message entanglement, addressing limitations of traditional key management such as certificate reliance and high computational costs. A smart contract-driven, dynamically switchable distributed key management framework is also introduced to enhance adaptability under varying attack frequencies. Simulation results indicate reduced communication and computational overhead. Protocols 1 and 2 show computational losses of 5.53 and 6.47, respectively, while smart contract-based scenarios range from 4.28 to 4.39. In smart agriculture applications, dynamic switching reduced overhead from 6.47 to 4.28, optimising performance by 33.84%. The research supports the development of lightweight, secure, and adaptable communication frameworks for IoT applications in smart cities, industrial monitoring, and telemedicine, offering strong theoretical and practical value.
Михайленко, Олександр Ігорович, Гороховський, Кирило Семенович, Гороховський, Семен Самуїлович
The paper explores the possibility of expanding the use of end-to-end encryption protocols based on the Double Ratchet algorithm in applications with low trust in the server, particularly in turn-based games and strategic interactions. The relevance of the research is due to the growing need for secure communication in cyberattacks, especially during military operations. The field of end-to-end encryption requires the study of additional applications beyond the usual ones, such as encrypted communication in text messengers. The developed implementation of the protocol can be safely used in any applications that aim to implement end-to-end encryption and satisfy the criterion of session ephemerality (in cases where secrets are stored outside a secure environment). The implemented server supports ephemeral sessions, which guarantee minimal risks of information compromise, and uses digital signatures (EdDSA) for user authentication. Logical routing of requests ensures efficient message transmission in secure scenarios. The choice of the classic game of checkers as an example allowed the authors to effectively demonstrate the advantages of end-to-end encryption and the capabilities of the implemented protocol. All cryptographic operations, including key generation, encryption and decryption of messages, are successfully performed on client devices. It is important to improve error handling mechanisms and optimize the operation of WebAssembly. An interesting area of further research is the creation of zero-knowledge proof mechanisms to prevent Man-In-The-Middle attacks during the creation of a shared secret, optimizing integration with cryptographic hardware security modules (HSM), and exploring the scalability of the solution. The proposed approach can be used to solve real-world information security problems where trust in the data transmission channel is critically important. Thus, the work has created a comprehensive solution that includes a cryptographic protocol, a backend, and a web client, which demonstrates the viability of end-to-end encryption in browser environments and multiplayer games. The work can be used as a basis for further research and development in the field of security of communication systems and privacy in multiplayer games.
Distributed key generation (DKG) is a cryptographic primitive that produces one public key and shares of a corresponding secret key among a group of distributed parties. As the basis of threshold cryptography, the classical DKG protocols are resurging due to their widespread applications in blockchain, such as MEV protection, checkpointing into Bitcoin, and more. Those applications raise a challenge of deploying DKG on a very large scale. While efforts have been made to improve DKG communication, practical large-scale deployments are yet to come due to various issues. On the other hand, theoretical challenges arise when we aim to optimise the latency while achieving near-optimal communication costs. This thesis focus on solving scalable DKG on both practical and theoretical landscape. We first investigate how to build a practical, scalable and adaptively secure DKG protocol to enable all-hands checkpointing in blockchains with weighted validators. Our Any-Trust DKG achieves (quasi-)linear computation and broadcast overhead per-node cost with the help of a common coin, against weak adaptive adversaries. The key to our improvements lies in delegating the most costly operations to an Any-Trust group together with a set of techniques for adaptive security. Our Any-Trust DKG leads to a fully practical instantiation of Filecoin's checkpointing mechanism, in which all validators of a Proof-of-Stake (PoS) blockchain periodically run DKG and threshold signing to create checkpoints on Bitcoin, to enhance the security of the PoS chain. Then, on the theoretical side, we purpose Circular Dragon, the first construction of adaptively secure DKG protocol that (i) realises optimal n/2 resilience in the synchronous network, and (ii) attains near-optimal asymptotic complexities, i.e., O(n^2 log n) communication and O(k log n) rounds. In addition, the proposed DKG protocol also produces field-element secrets to support the standard discrete-logarithm based threshold cryptosystem.