Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

1,050 papersLast indexed Aug 31, 2026
Search papers

Paper index

1,050 results · page 8 of 44

Clear filters
Aug 2, 2024·Computer Networks
4 cites
Priv-Share: A privacy-preserving framework for differential and trustless delegation of cyber threat intelligence using blockchain

Kealan Dunnett, Shantanu Pal, Zahra Jadidi, Volkan Dedeoglu · 5 authors

The emergence of the Internet of Things (IoT), Industry 5.0 applications and associated services have caused a powerful transition in the cyber threat landscape. As a result, organisations require new ways to proactively manage the risks associated with their infrastructure. In response, a significant amount of research has focused on developing efficient Cyber Threat Intelligence (CTI) sharing. However, in many cases, CTI contains sensitive information that has the potential to leak valuable information or cause reputational damage to the sharing organisation. While a number of existing CTI sharing approaches have utilised blockchain to facilitate privacy, it can be highlighted that a comprehensive approach that enables dynamic trust-based decision-making, facilitates decentralised trust evaluation and provides CTI producers with highly granular sharing of CTI is lacking. Subsequently, in this paper, we propose a blockchain-based CTI sharing framework, called Priv-Share, as a promising solution towards this challenge. In particular, we highlight that the integration of differential sharing, trustless delegation, democratic group managers and incentives as part of Priv-Share ensures that it can satisfy these criteria. The results of an analytical evaluation of the proposed framework using both queuing and game theory demonstrate its ability to provide scalable CTI sharing in a trustless manner. Moreover, a quantitative evaluation of an Ethereum proof-of-concept prototype demonstrates that applying the proposed framework within real-world contexts is feasible.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
Advanced Malware Detection Techniques
Original source
Aug 2, 2024·Engineering Technology & Applied Science Research
12 cites
Blockchain-Inspired Lightweight Dynamic Encryption Schemes for a Secure Health Care Information Exchange System

E. R. Aruna, Arun Sahayadhas

The telemedicine sector has entered a new phase marked by the integration of Internet of Things (IoT) devices to identify and then send patient health data to medical terminals for additional diagnostic and therapeutic procedures. Today, patients can receive prompt and expert medical care at home in comfortable settings. Due to the unique nature of these services, it is essential to verify patient healthcare data, as it contains a greater amount of personal information that is vulnerable to privacy violations and data breaches. Blockchain technology has attracted interest in addressing security concerns due to its decentralized, immutable, shared, and distributed characteristics. This study proposes lightweight dynamic blockchain-enabled encryption schemes to secure physiological data during authentication and exchange processes. The proposed scheme introduces the logistic Advanced Encryption Scheme (AES) that combines chaotic logistic maps to secure the data in the blockchain network and mitigate different attacks. The model was deployed on the Ethereum blockchain and performance metrics, such as computation and transaction time, were calculated and compared with other current blockchain-inspired encryption models. Furthermore, the NIST test was conducted to prove the strength of the proposed scheme. The proposed model exhibits high security and a shorter transaction time (0.964 s) than other existing schemes. Finally, the proposed model generates high-dynamic keys that are suitable for defending against unpredictable attacks on blockchain.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
User Authentication and Security Systems
Original source
Jul 14, 2024·Computers & Security
9 cites
A novel biometric authentication scheme with privacy protection based on SVM and ZKP

Chunjie Guo, Lin You, Xingyu Li, Gengran Hu · 6 authors

Biometric authentication is a very convenient and user-friendly method. The popularity of this method requires strong privacy-preserving technology to prevent the disclosure of template information. Most of the existing privacy protection technologies rely on classic encryption techniques, such as homomorphic encryption, which incur huge system overhead and cannot be popularized. To address these issues, we propose a novel biometric authentication scheme with privacy protection based on support vector machine and zero knowledge proof (BioAu–SVM+ZKP). BioAu–SVM+ZKP allows users to authenticate themselves to different service providers without disclosing any biometric template information. The evidence is generated through the zero-knowledge proof utilizing polynomial commitments. Our approach for generating a unique and repeatable biometric identifier from the user’s fingerprint image leverages the multi-classification property of SVM. Notably, our scheme not only reduces the communication overhead but also provides the privacy protection features. Besides, the communication overhead of BioAu–SVM+ZKP is constant. We have simulated the authentication scheme on the common dataset NIST, analyzed the performance and proved the security.

Open access
Biometric Identification and Security
User Authentication and Security Systems
Advanced Steganography and Watermarking Techniques
Original source
Jul 10, 2024·2024 2nd International Conference on Sustainable Computing and Smart Systems (ICSCSS)
1 cites
A Secured Multiple Party Key Agreement Protocol Design Over Cloud Computing Platform by Using Statistical Data Analysis Logic

Allam Balaram, Sajja Suneel, P. Kavitha, Achinta Saikia · 6 authors

In the field of cloud computing, ensuring secure and efficient key agreement among multiple parties has emerged as a paramount challenge. Traditional key agreement protocols often rely on central authorities or trusted third parties, posing significant security and privacy concerns. To address these challenges, this paper introduces a novel key agreement protocol designed specifically for cloud computing platforms, emphasizing security, efficiency, and resilience without depending on a trusted third party. The proposed protocol innovatively combines Distributed Key Generation (DKG) with a Dynamic Consensus Mechanism, Zero-Knowledge Proof (ZKP) based authentication, and a Multi-Cloud Redundancy approach, offering a comprehensive solution to secure multi-party communication in distributed cloud environments. The DKG protocol facilitates the collaborative generation of a shared secret among participants, significantly enhancing security by eliminating single points of failure. The proposed Dynamic Consensus Mechanism ensures the integrity and finality of key agreement transactions on a blockchain-based ledger, adapting to network conditions and participant trust levels to optimize performance without compromising security. ZKP-based authentication allows participants to verify their identities without revealing sensitive information, preserving privacy and thwarting impersonation attacks. Lastly, the Multi-Cloud Redundancy strategy enhances the protocol's resilience to cloud-specific vulnerabilities and service outages, ensuring high availability and robustness.

Advanced Authentication Protocols Security
User Authentication and Security Systems
Security in Wireless Sensor Networks
Original source
Jul 1, 2024·Chinese Journal of Electronics
14 cites
Blockchain Meets Generative Behavior Steganography: A Novel Covert Communication Framework for Secure IoT Edge Computing

Yuanlong Cao, Junjie Li, Kailin Chao, Jianmao Xiao · 5 authors

The rapid development of Internet of things (IoT) and edge computing technologies has brought forth numerous possibilities for the intelligent and digital future. The frequent communication and interaction between devices inevitably generate a large amount of sensitive information. Deploying a blockchain network to store sensitive data is crucial for ensuring privacy and security. The openness and synchronicity of blockchain networks give rise to challenges such as transaction privacy and storage capacity issues, significantly impeding their development in the context of edge computing and IoT. This paper proposes a reliable fog computing service solution based on a blockchain fog architecture. This paper stores data files in the inter planetary file system (IPFS) and encrypts the file hash values used for retrieving data files with stream cipher encryption. It employs a steganographic transmission technique leveraging AlphaZero's Gomoku algorithm to discretely transmit the stream cipher key across the blockchain network without a carrier, thus achieving dual encryption. This approach aims to mitigate the storage burden on the blockchain network while ensuring the security of transaction data. Experimental results demonstrate that the model enhances the transmission capacity of confidential information from kilobytes (KB) to megabytes (MB) and exhibits high levels of covert and security features.

Advanced Steganography and Watermarking Techniques
User Authentication and Security Systems
Blockchain Technology Applications and Security
Original source
Jun 22, 2024·arXiv (Cornell University)
0 cites
I Experienced More than 10 DeFi Scams: On DeFi Users' Perception of Security Breaches and Countermeasures

Mingyi Liu, Jun Ho Huh, HyungSeok Han, Jaehyuk Lee · 8 authors

Decentralized Finance (DeFi) offers a whole new investment experience and has quickly emerged as an enticing alternative to Centralized Finance (CeFi). Rapidly growing market size and active users, however, have also made DeFi a lucrative target for scams and hacks, with 1.95 billion USD lost in 2023. Unfortunately, no prior research thoroughly investigates DeFi users' security risk awareness levels and the adequacy of their risk mitigation strategies. Based on a semi-structured interview study (N = 14) and a follow-up survey (N = 493), this paper investigates DeFi users' security perceptions and commonly adopted practices, and how those affected by previous scams or hacks (DeFi victims) respond and try to recover their losses. Our analysis shows that users often prefer DeFi over CeFi due to their decentralized nature and strong profitability. Despite being aware that DeFi, compared to CeFi, is prone to more severe attacks, users are willing to take those risks to explore new investment opportunities. Worryingly, most victims do not learn from previous experiences; unlike victims studied through traditional systems, DeFi victims tend to find new services, without revising their security practices, to recover their losses quickly. The abundance of various DeFi services and opportunities allows victims to continuously explore new financial opportunities, and this reality seems to cloud their security priorities. Indeed, our results indicate that DeFi users' strong financial motivations outweigh their security concerns - much like those who are addicted to gambling. Our observations about victims' post-incident behaviors suggest that stronger control in the form of industry regulations would be necessary to protect DeFi users from future breaches.

Open access
2 source records
cs.CR
Information and Cyber Security
User Authentication and Security Systems
Original source
Jun 21, 2024·Electronics
10 cites
A Security Analysis of Cryptocurrency Wallets against Password Brute-Force Attacks

H S Byun, Jueun Kim, Yun-Seok Jeong, Byoungjin Seok · 6 authors

Currently, the monetary value of cryptocurrencies is extremely high, leading to frequent theft attempts. Cyberattacks targeting cryptocurrency wallets and the scale of these attacks are also increasing annually. However, many studies focus on large-scale exchanges, leading to a lack of research on cryptocurrency wallet security. Nevertheless, the threat to individual wallets is real and can lead to severe consequences for individuals. In this paper, we analyze the security of the open-source cryptocurrency wallets Sparrow, Etherwall, and Bither against brute-force attacks, a fundamental threat in password-based systems. As cryptocurrency wallets use passwords to manage users’ private keys, we analyzed the private key management mechanism and implemented a password verification oracle. We used this oracle for brute-force attacks. We identified the private key management mechanism by conducting a code-level investigation and evaluated the three wallets’ security through practical experimentation. The experiment results revealed that the wallets’ security, which depends on passwords, could be diminished due to the password input space and the configuration of password length settings. We propose a general methodology for analyzing the security of desktop cryptocurrency wallets against brute-force attacks and provide practical guidelines for designing secure wallets. By using the analysis methods suggested in this paper, one can evaluate the security of wallets.

Open access
Advanced Malware Detection Techniques
User Authentication and Security Systems
Network Security and Intrusion Detection
Original source
Jun 19, 2024·IEEE Transactions on Network and Service Management
16 cites
Blockchain-Based Secure Authentication and Authorization Framework for Robust 5G Network Slicing

Shalitha Wijethilaka, Awaneesh Kumar Yadav, An Braeken, Madhusanka Liyanage

The rapid evolution of heterogeneous applications signifies the requirement for network slicing to cater to diverse network requirements. Network Functions (NFs), which are the essential elements of network slices, are required to communicate with each other securely to facilitate network services. Certificates are the established method to authenticate each other. However, dynamic certificate management while allowing NFs to communicate in a multi-operator environment is arduous. Also, sharing NFs between network slices originates authorization-related security challenges such as unauthorized service utilization, deceptive Denial of Service attacks, and data leakages from network slices. In this paper, we develop a novel framework to address the security challenges related to authentication and authorization in 5G network slicing systems. A blockchain-based multi-party distributed certificate management framework with secure communication protocols is developed using elliptic curve cryptography to facilitate certificate services for multi-operator environments. Also, we propose a blockchain-based NF authorization framework to mitigate the security vulnerabilities in NF sharing between network slices. We implement the proposed framework using Hyperledger Fabric blockchain with Java chain codes and perform comprehensive experiments to show the significance of our framework.The Ability to mitigate the single point of failure with respect to state-of-the-art, including traditional certificate authorities and blockchain-based certificate authorities, time analysis for certificate generation, and the potential to eliminate the mentioned authorization attacks are some of the experiments conducted.Also, we have shown that our framework is secure using informal and formal (using Real-Or-Random (ROR) logic and Scyther Validation tool) security verification mechanisms.

Open access
Advanced Authentication Protocols Security
Cryptography and Data Security
User Authentication and Security Systems
Original source
Jun 7, 2024·2024 International Conference on Innovations and Challenges in Emerging Technologies (ICICET)
3 cites
Efficient Multiple authentication scheme for IOTA using ZK-SNARK

Danish Meraj, Arun Mishra

In IoT(Internet of Things) Traditional authentication methods, such as passwords or public-key cryptography, often encounter challenges related to security, efficiency, and scalability. In response, Present work proposed a streamlined alternative utilizing Zero-knowledge proofs(ZKPs), allowing users to prove their identity with minimal exposure to sensitive information. Emphasizing the need for optimization in computational resources, this approach becomes particularly valuable in the context of Internet of Things application(IOTA). Current work introduces a novel method for authentication that combines the concept of isomorphic graphs from multi-graph ZKP with ZeroKnowledge Succinct Non-Interactive Argument of Knowledge (Zk-SNARKs), along with multi-threading in the IOTA ecosystem. This advancement represents a significant step forward in scalability and provides a solution to the increasing need for secure and effective authentication methods.

Chaos-based Image/Signal Encryption
Advanced Authentication Protocols Security
User Authentication and Security Systems
Original source
Jun 1, 2024·Sensors
17 cites
Two-Layered Multi-Factor Authentication Using Decentralized Blockchain in an IoT Environment

Saeed Bamashmos, Naveen Chilamkurti, Ahmad Salehi Shahraki

Internet of Things (IoT) technology is evolving over the peak of smart infrastructure with the participation of IoT devices in a wide range of applications. Traditional IoT authentication methods are vulnerable to threats due to wireless data transmission. However, IoT devices are resource- and energy-constrained, so building lightweight security that provides stronger authentication is essential. This paper proposes a novel, two-layered multi-factor authentication (2L-MFA) framework using blockchain to enhance IoT devices and user security. The first level of authentication is for IoT devices, one that considers secret keys, geographical location, and physically unclonable function (PUF). Proof-of-authentication (PoAh) and elliptic curve Diffie-Hellman are followed for lightweight and low latency support. Second-level authentication for IoT users, which are sub-categorized into four levels, each defined by specific factors such as identity, password, and biometrics. The first level involves a matrix-based password; the second level utilizes the elliptic curve digital signature algorithm (ECDSA); and levels 3 and 4 are secured with iris and finger vein, providing comprehensive and robust authentication. We deployed fuzzy logic to validate the authentication and make the system more robust. The 2L-MFA model significantly improves performance, reducing registration, login, and authentication times by up to 25%, 50%, and 25%, respectively, facilitating quicker cloud access post-authentication and enhancing overall efficiency.

Open access
User Authentication and Security Systems
Biometric Identification and Security
Advanced Steganography and Watermarking Techniques
Original source
Jun 1, 2024·arXiv (Cornell University)
7 cites
Stealing Trust: Unraveling Blind Message Attacks in Web3 Authentication

Kailun Yan, Xiaokuan Zhang, Wenrui Diao

As the field of Web3 continues its rapid expansion, the security of Web3 authentication, often the gateway to various Web3 applications, becomes increasingly crucial. Despite its widespread use as a login method by numerous Web3 applications, the security risks of Web3 authentication have not received much attention. This paper investigates the vulnerabilities in the Web3 authentication process and proposes a new type of attack, dubbed blind message attacks. In blind message attacks, attackers trick users into blindly signing messages from target applications by exploiting users' inability to verify the source of messages, thereby achieving unauthorized access to the target application. We have developed Web3AuthChecker, a dynamic detection tool that interacts with Web3 authentication-related APIs to identify vulnerabilities. Our evaluation of real-world Web3 applications shows that a staggering 75.8% (22/29) of Web3 authentication deployments are at risk of blind message attacks. In response to this alarming situation, we implemented Web3AuthGuard on the open-source wallet MetaMask to alert users of potential attacks. Our evaluation results show that Web3AuthGuard can successfully raise alerts in 80% of the tested Web3 authentications. We have responsibly reported our findings to vulnerable websites and have been assigned two CVE IDs.

Open access
3 source records
Spam and Phishing Detection
Web Application Security Vulnerabilities
Advanced Malware Detection Techniques
Original source
May 28, 2024·˜The œInternational journal of networked and distributed computing
33 cites
Enhancing IoT Security: A Blockchain-Based Mitigation Framework for Deauthentication Attacks

S. Harihara Gopalan, A. Manikandan, N. P. Dharani, G. Sujatha

Abstract The proposed Blockchain-Based Mitigation of Deauthentication Attacks (BBMDA) Framework aims to enhance the security and trustworthiness of IoT environments by leveraging blockchain technology, the Elliptic Curve Digital Signature Algorithm (ECDSA) for secure authentication, and Multi-Task Transformer (MTT) for efficient traffic classification. This paper presents a novel approach to mitigate de-authentication attacks in IoT ecosystems. The research methodology involves developing and implementing the BBMDA framework, followed by a comprehensive evaluation and comparison with existing techniques. Key findings indicate that the BBMDA framework outperforms traditional methods such as Support Vector Machine (SVM), k-nearest Neighbors (KNN), and Convolutional Neural Network (CNN) in terms of accuracy, false positive rate, false negative rate, precision, recall, and F1-score. These results underscore the effectiveness and efficiency of the proposed framework in enhancing IoT security.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
Cybercrime and Law Enforcement Studies
Original source
May 27, 2024·IEEE Transactions on Intelligent Transportation Systems
38 cites
PBAG: A Privacy-Preserving Blockchain-Based Authentication Protocol With Global-Updated Commitment in IoVs

Xia Feng, Kaiping Cui, Liangmin Wang, Zhiquan Liu · 5 authors

Internet of Vehicles (IoVs) is increasingly used as a medium to propagate critical information via establishing connections between entities such as vehicles and infrastructures. During message transmission, privacy-preserving authentication is considered the first line of defence against attackers and malicious information. To achieve a more secure and stable communication environment, ever-increasing numbers of blockchain-based authentication schemes are proposed. At first glance, existing approaches provide robust architectures and achieve transparent authentication. However, in these schemes, verifiers need to conduct real-time operations in the blockchain (e.g., querying certificates). To remedy this limit, we propose a privacy-preserving blockchain-based authentication protocol with global-updated commitment (PBAG). In PBAG, based on the issued certificates, a public global commitment is computed, and a unique evaluation proof is generated for each authorized vehicle. Instead of querying the blockchain in real-time, verifiers can independently authenticate vehicles using the global commitment that is pre-updated with the assistance of the blockchain. Moreover, our scheme proposes a dynamic update mechanism to ensure the freshness of the global commitment and evaluation proofs. Benefiting from the update mechanism, there will be an authentication failure for vehicles holding invalid certificates when using the latest global commitment, thus avoiding the time-consuming of checking the Certificate Revocation List (CRL). In terms of privacy protection, our scheme provides privacy properties such as anonymity and unlinkability. It allows anonymous authentication based on evaluation proofs and achieves traceability of identity in the event of a dispute. The simulation demonstrates that the average computation cost of verifying per message is 0.36ms under the batch-enabled mechanism, reducing by more than 63.7% compared with existing schemes.

Blockchain Technology Applications and Security
User Authentication and Security Systems
Advanced Authentication Protocols Security
Original source
May 19, 2024·High-Confidence Computing
17 cites
EBIAS: ECC-enabled blockchain-based identity authentication scheme for IoT device

Wenyue Wang, Biwei Yan, Baobao Chai, Ruiyao Shen · 6 authors

In the Internet of Things (IoT), a large number of devices are connected using a variety of communication technologies to ensure that they can communicate both physically and over the network. However, devices face the challenge of a single point of failure, a malicious user may forge device identity to gain access and jeopardize system security. In addition, devices collect and transmit sensitive data, and the data can be accessed or stolen by unauthorized user, leading to privacy breaches, which posed a significant risk to both the confidentiality of user information and the protection of device integrity. Therefore, in order to solve the above problems and realize the secure transmission of data, this paper proposed EBIAS, a secure and efficient blockchain-based identity authentication scheme designed for IoT devices. First, EBIAS combined the Elliptic Curve Cryptography (ECC) algorithm and the SHA-256 algorithm to achieve encrypted communication of the sensitive data. Second, EBIAS integrated blockchain to tackle the single point of failure and ensure the integrity of the sensitive data. Finally, we performed security analysis and conducted sufficient experiment. The analysis and experimental results demonstrate that EBIAS has certain improvements on security and performance compared with the previous schemes, which further proves the feasibility and effectiveness of EBIAS.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
Advanced Steganography and Watermarking Techniques
Original source
May 13, 2024·IEEE Internet of Things Journal
47 cites
Blockchain-Based Mutual Authentication Protocol for IoT-Enabled Decentralized Healthcare Environment

Chien‐Ming Chen, Zhaoting Chen, Saru Kumari, Mohammad S. Obaidat · 6 authors

In the ever-evolving landscape of technology, healthcare continuously harnesses its benefits, propelling advancements in medical practices. Within intelligent healthcare, medical robots play a pivotal role, providing integral support to healthcare professionals, streamlining processes, and delivering efficient services. These robots securely transmit patient treatment plans, transferring them to cloud storage and subsequently storing them in blockchain systems. This innovative approach ensures the integrity and accessibility of patient data, introducing novel avenues for seamless interaction with medical information for hospitals and patients’ families. Despite these advantages, the looming privacy risks associated with sensitive patient data transmission pose a compelling challenge, demanding a comprehensive solution. In response to this challenge, we propose a mutual authentication and key agreement protocol designed to optimize healthcare services while prioritizing data security and patient privacy. To validate the robustness of our authentication protocol, we conduct thorough analyses based on both formal and informal models, establishing a foundational framework for evaluating the protocol’s security. Additionally, we perform a comprehensive comparative analysis, assessing the proposed protocol against existing counterparts across various dimensions. This comparative scrutiny reveals the superiority of our protocol in terms of security, as well as its efficiency in communication cost and computational overhead. These findings affirm the efficacy of our proposed solution in navigating the intricate interplay between medical robotics, blockchain, and data security.

Advanced Authentication Protocols Security
User Authentication and Security Systems
Blockchain Technology Applications and Security
Original source
May 13, 2024·Electronics
3 cites
BPA: A Novel Blockchain-Based Privacy-Preserving Authentication Scheme for the Internet of Vehicles

Jie Li, Yuanyuan Lin, Yibing Li, Yan Zhuang · 5 authors

The Internet of Vehicles (IoV) connects an isolated individual on the road to share information, which can improve traffic efficiency. However, the promotion of information sharing brings the critical security issues of identity authentication, followed by privacy protection issues in the authentication process in the IoV. In this study, we designed a blockchain-based conditional privacy-preserving authentication scheme for the IoV (BPA). Our scheme implements zero-knowledge proof (ZKP) to verify the identities of vehicles, which moves the authentication process down to the Roadside Units (RSUs) and achieves decentralized authentication at the edge nodes. Moreover, blockchain technology is utilized to synchronize a consistent ledger across all RSUs for recording and disseminating vehicle authentication states, which enhances the overall authentication process efficiency. We provide a theoretical analysis asserting that the BPA ensures enhanced security and effectively protects the privacy of all participating vehicles. Experimental evaluations confirm that our scheme outperforms existing solutions in terms of the computational and communication overhead.

Open access
Vehicular Ad Hoc Networks (VANETs)
User Authentication and Security Systems
Blockchain Technology Applications and Security
Original source
May 12, 2024·Companion Proceedings of the ACM Web Conference 2024
1 cites
Towards Understanding Crypto-Asset Risks on Ethereum Caused by Key Leakage on the Internet

Yuxuan Zhou, Jiaqi Chen, Yibo Wang, Yuzhe Tang · 5 authors

In public blockchains, leaking secret keys can cause the permanent loss of crypto assets. It is imperative to understand the illicit activities on blockchains related to leaked keys. This paper presents the first measurement study that uncovers, quantifies, and characterizes the actual misuses of the leaked keys from top websites on the Internet to withdraw assets on Ethereum. By finding key-leaking web pages and joining them with transactions, the study reveals 7.29*10^6/0.59*10^6 USD worth of assets on Ethereum mainnet/Binance Smart Chain (BSC) are withdrawn from 1421/1514 leaked secret keys. Mitigations are proposed to avoid the financial loss caused by leaked keys.

Open access
User Authentication and Security Systems
Advanced Malware Detection Techniques
Advanced Steganography and Watermarking Techniques
Original source
May 11, 2024·Future Internet
17 cites
Blockchain-Enabled Secure and Interoperable Authentication Scheme for Metaverse Environments

Sonali Patwe, Sunil B. Mane

The metaverse, which amalgamates physical and virtual realms for diverse social activities, has been the focus of extensive application development by organizations, research institutes, and companies. However, these applications are often isolated, employing distinct authentication methods across platforms. Achieving interoperable authentication is crucial for when avatars traverse different metaverses to mitigate security concerns like impersonation, mutual authentication, replay, and server spoofing. To address these issues, we propose a blockchain-enabled secure and interoperable authentication scheme. This mechanism uniquely identifies users in the physical world as well as avatars, facilitating seamless navigation across verses. Our proposal is substantiated through informal security analyses, employing automated verification of internet security protocols and applications (AVISPA), the real-or-random (ROR) model, and Burrows–Abadi–Needham (BAN) logic and showcasing effectiveness against a broad spectrum of security threats. Comparative assessments against similar schemes demonstrate our solution’s superiority in terms of communication costs, computation costs, and security features. Consequently, our blockchain-enabled, interoperable, and secure authentication scheme stands as a robust solution for ensuring security in metaverse environments.

Open access
User Authentication and Security Systems
Cloud Data Security Solutions
Blockchain Technology Applications and Security
Original source
May 11, 2024·Proceedings of the CHI Conference on Human Factors in Computing Systems
5 cites
“I Can’t Believe It’s Not Custodial!”: Usable Trustless Decentralized Key Management

Tanusree Sharma, Vivek Nair, Henry Wang, Yang Wang · 5 authors

Key management has long remained a difficult unsolved problem in the field of usable security. While password-based key derivation functions (PBKDFs) are widely used to solve this problem in centralized applications, their low entropy and lack of a recovery mechanism make them unsuitable for use in decentralized contexts. The multi-factor key derivation function (MFKDF) is a recently proposed cryptographic primitive that aims to address these deficiencies by incorporating commonly used authentication factors into the key derivation process. In this paper, we implement an MFKDF-based Ethereum wallet and perform a user study with 27 participants to directly compare its usability against traditional cryptocurrency wallet architectures. Our results show that MFKDF-based applications outperform conventional key management approaches on both subjective and objective metrics, with a 37% higher average SUS score (p < 0.0001) and 71% faster task completion times (p < 0.0001) for the MFKDF-based wallet.

Open access
User Authentication and Security Systems
Privacy, Security, and Data Protection
Advanced Malware Detection Techniques
Original source