Zain Ul Islam Adil, Majid Iqbal Khan, Kahkishan Sanam, Saif Ur Rehman Malik · 6 authors
ABSTRACT Counterfeit medical devices pose a threat to patient safety, necessitating a secure device authentication system for medical applications. Resource‐constrained sensory nodes are vulnerable to hacking, prompting the need for robust security measures. Token‐based authentication schemes, such as one‐time passwords (OTPs), smart cards, key fobs, and mobile authentication apps, along with certificate‐based authentication methods, such as client and code‐signing, employ cryptographic frameworks like elliptical curve cryptography (ECC) and physical unclonable functions (PUF). However, these methods face challenges, including block sequence issues and susceptibility to side‐channel attacks. To address these issues, we propose a framework for mutual authentication using private Ethereum. This framework integrates private Ethereum and cryptographic techniques for encrypting and decrypting data using mathematical algorithms to overcome block sequence issues and side‐channel attacks. Similarly, fog nodes are utilised to enhance local computing, storage, and networking capabilities for sensors. The framework is evaluated using metrics such as communication costs, execution costs, and computation costs based on Ethereum gas consumption. The performance of the LightAuth framework is compared with that of the Smart Contracts Against Counterfeit IoMT (SCACIoMT) framework, designed for Internet of Medical Things (IoMT) devices. The effectiveness of LightAuth is verified through formal security analysis using BAN logic.
Gopal Singh Rawat, Karan Singh, Mohd Shariq, Ashok Kumar Das · 6 authors
Intelligent Transportation Systems (ITS) dwell on Vehicular Ad-hoc NETworks (VANETs) for message dissemination to achieve the goal of traffic safety and efficiency. VANETs achieve communication among vehicles and roadside units via wireless communication. Hence, security and privacy are significant concerns to be addressed for an effective application of secure VANETs in any ITS. Researchers have addressed these issues with trust management-based schemes or cryptography-based schemes. While these schemes can secure VANETs, they have various limitations presenting hindrances in their deployment. In this context, we have proposed a Blockchain-assisted Trust Computation with a Conditional Privacy-preserving Authentication (BTC2PA) scheme for connected vehicles. The BTC2PA scheme uses a blockchain (Ethereum) assisted PKI infrastructure with digital signatures to achieve authentication for secure communication. Furthermore, it integrates a trust score computation scheme based on a reward and punishment mechanism to provide resistance against internal attacks. The feasibility and validity of the proposed BTC2PA scheme have been studied by implementation work in Rinkeby (Ethereum test network) and extensive simulations using NS-3. The results obtained show that the proposed BTC2PA scheme meets the security and privacy requirements while significantly improving the performance metrics such as communication, storage, computation cost, and end-to-end delay when compared to existing schemes.
Michael Prummer, Emanuel Regnath, Saurabh Singh, Harald Kosch
The increasing digitalization in manufacturing and trends like the Industrial Metaverse drive the need for secure decentralized asset exchanges and industrial asset intellectual property (IP) rights protection. Utilizing distributed ledgers and non-fungible tokens (NFTs) linked by a hash enables the management and authentication of assets. However, challenges arise in authenticating the same asset’s different versions and file formats using a single hash.In this work, we propose a new NFT structure that allows binding multiple files existing in different file formats, representing the same digital asset by combining a Merkle Tree (MT) with a calculated Average Perceptual Hash (APH). While the MT proves bitwise integrity, the APH verifies functional integrity for asset authentication. We evaluate our approach for exchanging Printed Circuit Board (PCB) designs in a decentralized ecosystem by calculating unique PCB fingerprints and the APH. Our results show a robust identification and integrity verification of PCB designs depending on the manipulation type. Our approach for asset authentication is generalizable to all asset classes with an appropriate perceptual hash.
Advanced Steganography and Watermarking Techniques
With the advancement of cutting-edge technologies, the Internet of Medical Things (IoMT) has assisted the healthcare sector by facilitating interaction between healthcare service providers and patients in remote areas. In IoMT, wearable or implantable sensors collect the patient’s record and share the information through a public network. Health-related information about the patient must be protected from a variety of attacks by the adversary since it is sensitive and extremely vulnerable to attacks. The sensor equipment that is implanted in the patient is also resource-constrained and has a low power capacity. The entities involved in the communication must be authenticated with one another in order to protect patients’ health information, anonymity, and reliability. While several authenticated key agreement protocols have been proposed, many suffer from high computational costs and storage cost, making them unsuitable for lightweight applications. This paper proposes a secure three-factor robust Elliptic Curve Cryptography (ECC) based mutually authenticated and key agreement protocol known as RELAKA for the IoMT environment, utilizing the benefits of one-way hash function. In proposed scheme, all entities, including the healthcare service providers and wearable sensors, are authenticated by the medical server. Subsequently, a secret key is established for each communication session and shared between all the entities. Additionally, mechanism for appropriate user revocation and re-registration is integrated to provide additional security in cases where a user’s QR code is tampered with by the attacker. The privacy of the proposed protocol is investigated by the potential use of zero knowledge proof. Furthermore, the efficacy of the authentication is examined by challenge and response mechanism. The informal security analysis demonstrates its resistance to threats such as DoS, impersonation, message modification, password guessing, and so on. The performance evaluation of RELAKA protocol indicates that the execution, communication, and storage costs is reduced by 87.59%, 43% and 60.71% respectively. Moreover, the outcomes of the AVISPA simulation illustrate that the RELAKA successfully evades both active and passive attacks. In addition, real-world testbed environment is developed with Raspberry pi 4 model B and the experimental results verifies the robustness of the proposed protocol. According to theoretical analysis and experimental evaluation, the RELAKA scheme is more secure and efficient than the existing protocols.
In the rapidly expanding field of the Internet of Things, ensuring secure and efficient communication between IoT devices and servers is crucial. This paper henceforth designs a lightweight authentication system under the Zero Knowledge Proof (ZKP) protocol, utilizing the HMAC hashing algorithm for the improvement of security measures put in place. This system is designed to enable the authentication of IoT devices without sending their actual password, thus avoiding risks due to password interception at the point of authentication. For instance, if using the phrase "God is great" as the password, one can get it hashed into HMAC with this method and still be assured that it is secure even if proof is intercepted. Simulations in the simulator shall evaluate the system’s effectiveness and performance. Performance metrics include accuracy, response time, memory consumption, latency, and throughput. The presented results intend to serve lightweight device authentication mechanisms for IoT devices such that the trustworthiness of IoT devices is achieved without hampering their performance. The presented results are also shown to outperform conventional methods.
User Authentication and Security Systems
Advanced Malware Detection Techniques
Advanced Steganography and Watermarking Techniques
Oct 23, 2024·Advances in knowledge acquisition, transfer, and management book series/Advances in knowledge acquisition, transfer and management book series
Mageshkumar Naarayanasamy Varadarajan, N. Rajkumar, C. Viji, A. Mohanraj · 6 authors
User Authentication and Privacy explores the application of blockchain technology in enhancing user authentication and protecting user privacy within library systems. The decentralized and immutable nature of blockchain provides a robust alternative to traditional centralized authentication methods, which are often vulnerable to breaches and unauthorized access. By utilizing blockchain, libraries can implement a secure and transparent system for verifying user identities, significantly reducing the risk of data tampering and unauthorized access. This study delves into the specifics of how blockchain can safeguard user data, ensuring confidentiality and integrity. Additionally, the use of blockchain for identity management in libraries is examined, demonstrating its potential to offer a streamlined, tamper-proof, and trustless environment for identity verification. Blockchain's ability to enhance data security and protect user privacy makes it an ideal solution for modernizing library management systems.
This article proposes a novel method for managing usage counters within an anonymous credential system, addressing the limitation of traditional anonymous credentials in tracking repeated use. The method takes advantage of blockchain technology through Smart Contracts deployed on the Ethereum network to enforce a predetermined maximum number of uses for a given credential. Users retain control over increments by providing zero-knowledge proofs (ZKPs) demonstrating private key possession and agreement on the increment value. This approach prevents replay attacks and ensures transparency and security. A prototype implementation on a private Ethereum blockchain demonstrates the feasibility and efficiency of the proposed method, paving the way for its potential deployment in real-world applications requiring both anonymity and usage tracking.
Current authentication schemes based on zero-knowledge proof (ZKP) still face issues such as high computation costs, low efficiency, and security assurance difficulty. Therefore, we propose a secure and efficient authentication scheme (SEAS) for large-scale IoT devices based on ZKP. In the initialization phase, the trusted authority creates prerequisites for device traceability and system security. Then, we propose a new registration method to ensure device anonymity. In the identity tracing and revocation phase, we revoke the real identity of abnormal devices by decrypting and updating group public keys, avoiding their access and reducing revocation costs. In the authentication phase, we check the arithmetic relationship between blind certificates, proofs, and other random data. We propose a new anonymous batch authentication method to effectively reduce computation costs, enhance authentication efficiency, and guarantee device authentication security. Security analysis and experimental results show that an SEAS can ensure security and effectively reduce verification time and energy costs. Its security and performance exceed existing schemes.
Open access
User Authentication and Security Systems
Advanced Steganography and Watermarking Techniques
IT has made significant progress in various fields over the past few years, with many industries transitioning from paper-based to electronic media. However, sharing electronic medical records remains a long-term challenge, particularly when patients are in emergency situations, making it difficult to access and control their medical information. Previous studies have proposed permissioned blockchains with limited participants or mechanisms that allow emergency medical information sharing to pre-designated participants. However, permissioned blockchains require prior participation by medical institutions, and limiting sharing entities restricts the number of potential partners. This means that sharing medical information with local emergency doctors becomes impossible if a patient is unconscious and far away from home, such as when traveling abroad. To tackle this challenge, we propose an emergency access control system for a global electronic medical information system that can be shared using a public blockchain, allowing anyone to participate. Our proposed system assumes that the patient wears a pendant with tamper-proof and biometric authentication capabilities. In the event of unconsciousness, emergency doctors can perform biometrics on behalf of the patient, allowing the family doctor to share health records with the emergency doctor through a secure channel that uses the Diffie-Hellman (DH) key exchange protocol. The pendant's biometric authentication function prevents unauthorized use if it is stolen, and we have tested the blockchain's fee for using the public blockchain, demonstrating that the proposed system is practical.
Abstract Non-Fungible Tokens (NFTs) are becoming increasingly popular as a way to represent and own digital property. However, the usage of NFTs also prompts questions about privacy. In this work, we show that it is possible to use NFTs to retrieve enough information to fingerprint users. By doing so, we can uniquely associate users with blockchain accounts. This would allow linking several blockchain accounts to the same user. This work focuses on the vulnerabilities presented by some popular NFT marketplaces. Since NFTs may have HTML files embedded, they allow the use of fingerprinting techniques if not handled carefully. Finally, we provide recommendations and countermeasures for the different actors in this ecosystem to avoid these kinds of tracking methods and, in doing so, safeguard user privacy.
Open access
Advanced Steganography and Watermarking Techniques
The increased use of artificial intelligence generated content (AIGC) among vast user populations has heightened the risk of private data leaks. Effective auditing and regulation remain challenging, further compounding the risks associated with the leaks involving model parameters and user data. Blockchain technology, renowned for its decentralized consensus mechanism and tamper-resistant properties, is emerging as an ideal tool for documenting, auditing, and analyzing the behaviors of all stakeholders in machine learning as a service (MLaaS). This study centers on biometric recognition systems, addressing pressing privacy and security concerns through innovative endeavors. We conducted experiments to analyze six distinct deep neural networks, leveraging a dataset quality metric grounded in the query output space to quantify the value of the transfer datasets. This analysis revealed the impact of imbalanced datasets on training accuracy, thereby bolstering the system's capacity to detect model data thefts. Furthermore, we designed and implemented a novel Bio-Rollup scheme, seamlessly integrating technologies such as certificate authority, blockchain layer two scaling, and zero-knowledge proofs. This innovative scheme facilitates lightweight auditing through Merkle proofs, enhancing efficiency while minimizing blockchain storage requirements. Compared to the baseline approach, Bio-Rollup restores the integrity of the biometric system and simplifies deployment procedures. It effectively prevents unauthorized use through certificate authorization and zero-knowledge proofs, thus safeguarding user privacy and offering a passive defense against model stealing attacks.
Charlotte McCabe, Althaff Irfan Cader Mohideen, Raman Singh
Passwords are the first line of defence against preventing unauthorised access to systems and potential leakage of sensitive data. However, the traditional reliance on username and password combinations is not enough protection and has prompted the implementation of technologies such as two-factor authentication (2FA). While 2FA enhances security by adding a layer of verification, these techniques are not impervious to threats. Even with the implementation of 2FA, the relentless efforts of cybercriminals present formidable obstacles in securing digital spaces. The objective of this work is to implement blockchain technology as a form of 2FA. The findings of this work suggest that blockchain-based 2FA methods could strengthen digital security compared to conventional 2FA methods.
Ehsanul Islam Zafir, Afifa Akter, Muhammad Najam-ul-Islam, Shahid A. Hasib · 7 authors
The Internet of Robotic Things (IoRT) integrates robots and autonomous devices, transforming industries such as manufacturing, healthcare, and transportation. However, security vulnerabilities in IoRT systems pose significant challenges to data privacy and system integrity. To address these issues, encryption is essential for protecting sensitive data transmitted between devices. By converting data into ciphertext, encryption ensures confidentiality and integrity, reducing the risk of unauthorized access and data breaches. Blockchain technology also enhances IoRT security by offering decentralized, tamper-proof data storage solutions. By offering comprehensive insights, practical recommendations, and future directions, this paper aims to contribute to the advancement of knowledge and practice in securing interconnected robotic systems, thereby ensuring the integrity and confidentiality of data exchanged within IoRT ecosystems. Through a thorough examination of encryption requisites, scopes, and current implementations in IoRT, this paper provides valuable insights for researchers, engineers, and policymakers involved in IoRT security efforts. By integrating encryption and blockchain technologies into IoRT systems, stakeholders can foster a secure and dependable environment, effectively manage risks, bolster user confidence, and expedite the widespread adoption of IoRT across diverse sectors. The findings of this study underscore the critical role of encryption and blockchain technology in IoRT security enhancement and highlight potential avenues for further exploration and innovation. Furthermore, this paper suggests future research areas, such as threat intelligence and analytics, security by design, multi-factor authentication, and AI for threat detection. These recommendations support ongoing innovation in securing the evolving IoRT landscape.
Biagio Boi, Franco Cirillo, Marco De Santis, Christian Esposito
Context: The digitalization of the healthcare sector faces significant challenges due to the diverse representation of data and their distribution across various hospitals. Moreover, security is a key concern as healthcare-related data are subject to the legal obligations of General Data Protection Regulation (GDPR) and similar data protection legislation. Standardization efforts like Health Level Seven (HL7) have been implemented to enhance data interoperability. However, authentication still remains a critical issue with significant challenges. Aim: This research aims to improve and strengthen the authentication process by introducing a novel architecture for decentralized authentication. Additionally, it proposes a new approach to decentralized data management, which is crucial for handling sensitive medical data efficiently. Methodology: The proposed architecture adopts a user-centric approach, utilizing Self-Sovereign Identity (SSI). It introduced a new non-fungible token (NFT) type called soulbound token (SBT) in the medical context, which will facilitate user authentication across different hospitals, effectively creating a federation of interconnected institutions. Results: The implementation of the proposed architecture demonstrated a significant reduction in authentication time across multiple hospitals. The use of SBT ensured secure and seamless user authentication, enhancing overall system interoperability and data security. The decentralized approach also mitigated the risks associated with centralized authentication servers. Conclusion: This study successfully presents a novel decentralized authentication architecture for the healthcare domain, leveraging SSI and SBTs. This approach accelerates the authentication process and enhances data security and interoperability among hospitals. Future research should explore the scalability of this architecture and its application in other sectors requiring stringent data security measures.
This paper presents an innovative Web 3.0 authentication technique, designed for a user-centric internet environment. Addressing the rising demand for authentication techniques suitable for Web 3.0, it defines the essential features of such systems and introduces a new approach using smart contracts. This approach utilizes mother and child tokens in conjunction with the lock smart contract to ensure secure authentication. The approach is thoroughly tested against various security threats, including man-in-the-middle, replay, and brute-force attacks, and its practicality is evaluated on Ethereum-based networks.
Hussein Zangoti, Alex Pissinou Makki, Wazir Zada Khan, Niki Pissinou
The rapidly evolving mobile IoT landscape, driven by mobile financial applications, self-driving cars, wearables, and health monitoring devices, confronts substantial blockchain storage challenges due to decentralized networks, limited band-width, and high storage overhead. To tackle these issues, we propose the Collective Signing-Based Blockchain Storage Optimization (CSBSO) algorithm. CSBSO mitigates storage over-head by leveraging the Collective Signing (CoSi) protocol and employing a multidimensional blockchain structure for efficient block management and retrieval. It focuses on identifying and pruning irrelevant blocks and implementing streamlined data management. Evaluations with Ethereum Classic Blockchain and Facebook Users datasets show CSBSO achieves up to 92% storage optimization, surpassing current models. These results underscore the effectiveness of CoSi-based strategies in reducing blockchain storage overhead in resource-constrained environments.
Samuel Hand, Alexander Koch, Pascal Lafourcade, Daiki Miyahara · 5 authors
Abstract A zero-knowledge proof (ZKP) allows a prover to prove to a verifier that it knows some secret, such as a solution to a difficult puzzle, without revealing any information about it. In recent years, ZKP protocols using only a deck of playing cards for solutions to various pencil puzzles have been proposed. The previous work of Lafourcade et al. deals with a famous puzzle called Slitherlink. Their proposed protocol can verify that a solution forms a single loop without revealing anything about the solution, except this fact. Their protocol guarantees that the solution satisfies the single-loop condition, by interactively constructing a solution starting from a state that holds a simple single loop, and proceeding via steps that preserve the invariant of encoding a single loop, until the proper solution is reached. A drawback of their protocol is that it requires additional verifications to guarantee a single loop. In this study, we propose a more efficient ZKP protocol for such a puzzle with fewer additional verifications. For this, we employ the previous work of Robert et al., which addressed the connectivity property in a puzzle. That is, we verify that a solution is connected but not split, to be a single loop. Applying our proposal, we construct a card-based ZKP protocol for Moon-or-Sun, which has its specific rule of alternating pattern in addition to the single-loop condition.
Open access
Advanced Steganography and Watermarking Techniques