Garima Misra, Bramah Hazela, Brijesh Kumar Chaurasia
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
1,046 results · page 5 of 44
Garima Misra, Bramah Hazela, Brijesh Kumar Chaurasia
No abstract is available for this record.
Riaz Ahmed Khan, Saba Mushtaq, Sajaad Ahmed Lone, Rajesh Gupta · 5 authors
No abstract is available for this record.
S Sudhip, Pratyush Sthapit, S. Maheshwari, Samarjit Sahu · 5 authors
Abstract: In today's fast-paced world, tracking personnel has become a necessity for various organizations, especially in industries such as Police Department, and security. The use of Near Field Communication (NFC) devices has emerged as a promising technology for tracking personnel. This paper presents a study on the feasibility and benefits of tracking personnel using NFC devices. Our study is based on NFC (Near Field Communication) which is A wireless communication technology that allows two devices to Exchange data when they are brought into proximity. NFC when used in reader/writer mode NFC device can read From NFC transponders or NFC writer. NFC when used in peerTo-peer mode NFC can be used to exchange information Between two NFC enabled devices and in card emulation mode NFC device can be used with Contactless Card for various Purposes like paying money or exchanging information Security of NFC device can be ensured by various means of Encryption and now we have new web3 technology.
Xingyu Liang, Sen Wang, Ling Xiong, Zhicai Liu · 5 authors
No abstract is available for this record.
Qiuli Wang, Zhiyu Ren, Cao Yajun
The advancement of Industrial Internet of Things (IIoT) has enabled cross-domain collaboration among enterprises, facilitating data exchange and coordinated operations for complex manufacturing tasks. As the primary security mechanism, cross-domain continuous authentication periodically verifies external devices to prevent unauthorized access and session hijacking, thereby mitigating system vulnerabilities. However, existing solutions face limitations: some rely on device-specific features incompatible with heterogeneous environments, while others neglect cross-domain scenarios, offering insufficient privacy protection and irreversible identity management. To address these gaps, we propose a cross-domain authentication framework leveraging zero-knowledge proofs and blockchain technology. Devices are assigned anonymous identities, with revocation managed via a distributed ledger. Initial authentication employs zero-knowledge proofs to generate valid tokens, while continuous authentication refreshes these tokens periodically. Security analysis confirms robustness against common threats, and performance evaluations demonstrate that periodic token renewal reduces computational and communication costs compared to repeated initial authentication processes.
Abdullah Alabdulatif
The advancement of e-health systems has resulted in substantial enhancements in healthcare delivery via effective data management and accessibility. The use of digital health solutions presents dangers to sensitive health information, including unauthorised access, privacy violations, and security weaknesses. This research presents a blockchain-based paradigm for privacy-preserving authentication and access control specifically designed for e-health systems. The architecture utilises the Ethereum blockchain, smart contracts, blind signatures, Proof of Authority (PoA) consensus, and one-way hash functions to improve data integrity, security, and privacy in a decentralised framework. The proposed methodology addresses computational efficiency and scalability issues via the implementation of lightweight cryptographic techniques, achieving an average authentication delay of 0.059 milliseconds, which represents a 4000-fold improvement compared to current approaches. The model exhibits a significant decrease in memory use, requiring just 0.0198 MB in contrast to the 96.98 MB required by benchmark models, and attains an average signature verification duration of 0.00092 milliseconds. The findings demonstrate the model’s capability for safe, efficient, and scalable applications in e-health, which guarantees privacy and adherence to regulatory norms.
Bertrand Cambou, Mahafujul Alam
Crypto wallets store and protect the private keys needed to sign transactions for crypto currencies; they are secured by multi-factor authentication schemes. However, the loss of a wallet, or a dysfunctional factor of authentication, can be catastrophic, as the keys are then lost as well as the crypto currencies. Such difficult tradeoffs between the protection of the private keys and factors of authentication that are easy to use are also present in public key infrastructures, banking cards, smartphones and smartcards. In this paper, we present protocols based on novel challenge–response pair mechanisms that protect private keys, while using factors of authentication that can be lost or misplaced without negative consequences. Examples of factors that are analyzed include passwords, tokens, wearable devices, biometry, and blockchain-based non-fungible tokens. In normal operations, the terminal device uses all factors of authentication to retrieve an ephemeral key, decrypt the private key, and finally sign a transaction. With our solution, users can download the software stack into multiple terminal devices, turning all of them into backups. We present a zero-knowledge multi-factor authentication scheme allowing the secure recovery of private keys when one of the factors is lost, such as the token. The challenge–response pair mechanisms also enable a novel key pair generation protocol in which private keys can be kept secret by the user, while a Keystore can securely authenticate the user and transmit the public key to a distributed network. The standardized LWE post-quantum cryptographic CRYSTALS Dilithium protocol was selected in the experimental section.
Ramadan Abdunabi, Md Al Amin, Rejina Basnet
Body area networks (BANs) frequently generate sensitive healthcare data from sensors and other devices. Security and privacy breaches in BAN systems can compromise information affecting patients’ physical health, emotional state, and financial well-being. The lack of well-defined security perimeters and qualified personnel to administer security in such dynamic environments requires an authorization framework for protecting patient data, where access depends on the users’ credentials, location, and time. Toward this end, this work aims to define a secure system architecture to incorporate fine-grained information access management. It also leverages a spatiotemporal attribute-based access control (STABAC) model to make it possible to enforce location and time factors with BAN policies and required attributes to make access decisions. The BAN policies have various dynamic constraints that may conflict with each other or introduce inconsistencies. Therefore, this work proposes a formal verification framework using timed colored Petri nets to ensure such errors are not introduced. The blockchain network is utilized to maintain policy integrity, where STABAC verifies policy integrity from the network through smart contract services before making access decisions. Finally, the policy and attribute management framework ensures that STABAC maintains a verified set of policies and attributes for authorizing uninterrupted care and services.
Chao Geng, Yang Zhang, Xin Xu, Yingbiao Yao · 6 authors
No abstract is available for this record.
Ahod Alghuried, Mohammed Alkinoon, Manar Mohaisen, An Wang · 6 authors
Blockchain technology has heralded a new era in digital innovation, revolutionizing our approach to designing and building distributed applications in the digital sphere. Blockchain technology operates as an immutable digital ledger, where each entry representing a digital transaction is indelible and cannot be altered once established. Initially designed as the fundamental framework for cryptocurrencies, blockchain has outgrown its original purpose, demonstrating significant potential in various industries and offering a variety of security and privacy features. Our study provides a thorough and current survey of blockchain applications, security, privacy concepts, primitives, and threat models. It stands out by concentrating on how blockchain technology intersects with emerging fields like IoT, EVs, FinTech, and healthcare systems in a single framework. To provide security and privacy features, blockchain systems employ different foundational notions and primitives while tackling diverse adversarial scenarios with various capabilities and goals. This study presents a fresh examination of the current state of applications, security and privacy notions and primitives, and threat models in blockchain systems. Additionally, this work highlights existing gaps in knowledge and outlines open questions, aiming to stimulate interest in further advancements in the field.
M. Natarajan, A. Bharathi, C. Sai Varun, Shitharth Selvarajan
Nowadays, most of the medical records are maintained in a digital format known as Electronic Health Records Sharing (EHRS) framework. Patients have individual login credentials for accessing these medical records. In the BCT, the information about the owner of the block and its dependency over other blocks is maintained in itself. Moreover, each block is linked with its nearby blocks, leading to a network controlled by patients responsible for storing and sharing the information. In healthcare, BCT can help with mobile health apps, monitoring equipment, sharing and keeping of clinical trial data, electronic medical records, and insurance information storage. This study proposes a secure Patient Login Credential System (PLCS) for EHRS. The proposed scheme has been included for block encryption with the symmetric and asymmetric cryptography algorithms with respect to the hospital server and patients. Additionally, the Quantum Secure Trust Protocol (QSTP) is integrated to enhance trust and security between the patient-side and hospital-side, maintaining data integrity and confidentiality. Similarly, the Tune Swarm Optimization (TSO) algorithm is utilized to optimize performance metrics. The security analysis for the proposed scheme has been evaluated with basic security assumptions for information systems like, availability, access control, maintaining forward secrecy, and maintaining data integrity. The proposed scheme demonstrated enhanced security and performance, with IDEA achieving encryption in 58 ms and decryption in 278 ms for a 512-bit block, offering the best performance in terms of encryption speed.
Zhexuan Yang, Xiao Qu, Zeng Chen, Guozi Sun
No abstract is available for this record.
Attaullah Buriro
This paper presents a comprehensive review of the technological advancements, practical applications, inherent challenges, and emerging trends shaping the field of mobile biometrics. Over the past decade, the domain has evolved from basic fingerprint sensors to sophisticated multimodal systems leveraging AI-driven physiological and behavioral biometrics. The analysis examines the vast opportunities in finance, health-care, and digital identity management, while emphasizing the critical need to address privacy, security, regulatory, and ethical concerns. Furthermore, the study underscores the importance of collaborative efforts, highlighting promising future directions such as decentralized biometric storage and blockchain integration to enable secure and user-centric mobile experiences.
Kalash, Bishakh Chandra Ghosh, Sourav Kanti Addya
No abstract is available for this record.
航 车
随着信息技术的快速发展,数据安全和用户的隐私越发受到重视。本文提出了一种匿名认证密钥交换(Anonymous Key Exchange, AKE)协议,旨在为医疗场景下的医疗数据共享和患者身份隐私提供安全和隐私的保护。该方案通过使用累加器、零知识证明和关联数据加密等技术,实现用户匿名的认证和安全的会话密钥协商,有效防止敌手对于用户和医用物联网设备的攻击,还能抵御诚实且好奇的医疗机构对患者身份的猜测。相较于现有的方案提供了更强的隐私安全保护,并且很好地平衡了性能和安全性,具有重要的理论价值和意义。With the rapid development of information technology, data security and user privacy have been paid more and more attention. This paper proposes an Anonymous authenticated Key Exchange (AKE) protocol to provide security and privacy protection for medical data sharing and patient identity privacy in medical scenarios. By using accumulator, zero-knowledge proof and associated data encryption technology, the scheme realizes anonymous user authentication and secure session key agreement, which effectively prevents adversaries from attacking users and medical IoT devices, and can resist honest and curious medical institutions from guessing the patient’s identity. Compared with the existing schemes, it provides stronger privacy security protection, and a good balance between performance and security, which has important theoretical value and significance.
Zibin Lin, Taotao Wang, Junhao Lai, Shengli Zhang · 6 authors
No abstract is available for this record.
Talha Abdullah Punjabi, Ahmad Qadeib Alban, Mahmoud Barhamgi
No abstract is available for this record.
Gaurav Kumawat, Tapan Kant, Vivek Bhardwaj, Mukesh Kumar · 6 authors
Password-based authentication systems are vulnerable to a variety of security risks, such as phishing, credential theft, and user fatigue due to complex password requirements. This paper introduces a novel passwordless authentication framework that leverages advanced cryptographic techniques, including Zero-Knowledge Proofs (ZKP), Secure Multi-Party Computation (SMPC), and Homomorphic Encryption to enhance security, privacy, and user experience. The proposed system eliminates the need for traditional passwords by utilizing biometric data to generate cryptographic keys, ensuring that sensitive information remains secure. The architecture is composed of three primary components: the client device, the authentication server, and the key management system (KMS). The client device captures biometric data and transforms it into cryptographic keys using SMPC, while the server verifies the authentication using ZKP and establishes secure communication channels via Diffie-Hellman key exchange. The KMS handles key generation, storage, and rotation to ensure secure communication. Evaluation results show that the system is highly resistant to common attack vectors such as replay and man-in-the-middle attacks, with a 0% attack success rate. Performance analysis reveals an average authentication time of 180 ms, which is 10% faster than WebAuthn.
浩然 司
现有区块链交易通常使用加密货币作为抵押物并进行链上交易,但由于加密货币的波动性,面临清算风险。本文旨在区块链与链下资产的融合,降低区块链交易风险,并提出一种基于零知识证明的密码学方案,将链下资产绑定到链上交易作为抵押物。该方案在支持区块链交易的同时,确保数据隐私性、数据源认证和低Gas消耗。在性能方面,我们对所提方案进行了功能分析和实验评估,研究了不同实体在各个阶段产生的计算成本。实验结果表明,该方案在功能上可行,并且计算效率较高。综上,该方案为区块链交易提供了一种安全且高效的基于零知识证明的解决方案。Existing blockchain transactions typically use cryptocurrencies as collateral for on-chain trading. However, the volatility of cryptocurrencies exposes these transactions to significant liquidation risks. This paper aims to integrate blockchain with off-chain assets to mitigate such risks and proposes a cryptographic scheme based on zero-knowledge proofs that links off-chain assets to on-chain transactions as collateral. The proposed scheme enables secure blockchain transactions while ensuring data privacy, authentication of data sources, and low gas cost. From a performance perspective, this paper conducts a functional analysis and experimental evaluation, assessing the computational costs incurred by different entities at various stages. Experimental results demonstrate that the scheme is both functionally viable and computationally efficient. In conclusion, this work presents a secure and efficient zero-knowledge-proof-based solution for blockchain transactions.
Zhangliang Li, Zhengyuan Yue, Zhongli Qiao, Keqing Wang · 7 authors
No abstract is available for this record.
Murat Koca
No abstract is available for this record.
Mohammad Iqbal Saryuddin Assaqty, Ying Gao, Abeer D. Algarni, Siraj Khan · 7 authors
The complexity of the entire process of supply chain management (SCM) is quite cumbersome and traditional way of handling it is devoid of proper authentication and security and very often suffers from human errors in dealing with flaws in quality control process of SCM. While it may have started with shipment tracking, the outcome of using IoT on supply chains has spread to every link in the chain. For instance, manufacturers are employing Internet-enabled sensors in production to find product faults, resulting in higher-quality production runs. Physical Unclonable Function (PUF) is a security mechanism that exploits the unique, unrepeatable physical characteristics of hardware components to generate distinct cryptographic keys or identifiers, typically for a semiconductor device like an Internet of Things (IoT) device. The unique identification of IoT devices along the supply chain is implemented by using PUFs as tamper-resistant IDs. Blockchain, the distributed, immutable ledger, on the other hand is the disruptive technology that provides higher security as compared to traditional centralized systems. The integration of PUF and blockchain proves to be quite interesting while handling the above issues of authentication. A smart contract on the blockchain is a software code that executes spontaneously as and when the conditions of the contract or agreement are satisfied. Hence after authentication process the results are fed to blockchain smart contract for the final validation. This paper presents a novel permissioned blockchain smart contract-based lightweight authentication scheme for SCM using PUF of IoT known as SPUFChain. Informal and formal security analysis (using AVISPA and BAN logic) of the proposed framework show its potential to combat several attack scenarios like man-in-the middle, non-repudiation, impersonation, replay attacks and many other security features as compared to other related schemes. The processing time (~13.8ms) is better than existing lightweight scheme for blockchain-based SCM as well.
Aditya Kapoor
No abstract is available for this record.
Reem Alsolami, Muhammad Mostafa Monowar, Afraa Attiah, Asma Cherif
No abstract is available for this record.