In a decentralized environment of blockchain, people usually select a random node to perform bookkeeping with the Proof of Stake (PoS) consensus mechanism. To randomly select miners and validators and ensure fair distribution of rewards, the algorithm must incorporate a fair, unbiased random number source. Therefore, in many PoS consensus mechanisms, random numbers are a critical technology. PoS consensus faces the following problems in random number generation: Firstly, in the PoS system, if the number and order of the selected verification nodes are predicted by the attacker, the system will be vulnerable to attacks. Second, if the random number generation algorithm has loopholes or is cracked by an attacker, the attacker may use these loopholes to attack the network, resulting in the insecurity of the PoS system. To address the challenges above, this paper proposes a low-cost, light-weighted, true random number generator designed by a sensors that detects non-deterministic signals. The random numbers generated through this method passed the NIST-STS randomness test. The true random number generator is applied to the commit-reveal service in PoS consensus to randomly elect block producer. Using the random number generated can also enhance IoT security because Photoresistor sensors have applications in IoT systems for smart building. The random number generated by the IoT device can be used as the basis for randomness proof on the blockchain. And the cloud can also use the randomness for identity verification, secure event tracing, data integrity and tamper resistance.
Chaos-based Image/Signal Encryption
Advanced Steganography and Watermarking Techniques
Jo Vliegen, Md Masoom Rabbani, Wouter Hellemans, Nele Mentens
Over the past decade, an exponential rise in the deployment of Internet-of-Things (IoT) devices engulfed our surroundings. IoT devices have spread into domains like personal smart devices, industrial applications, military applications, and medical applications, to name a few. Brittle security features and large deployment in safety-critical systems make IoT devices an attractive target for cyberattacks. Large collections of data, ranging from personal, and oversensitive to financial data, make it crucial to safeguard IoT applications and data communication from cybercriminals. One key technique to deal with these cyberattacks is Remote Attestation (RA), in which a verifier remotely checks the sanity of an IoT device's firmware. However, implementing RA over large IoT networks can be challenging due to the dynamic nature of the network and the real-time aggregation of attestation results. We propose 'HAGAR: Hashgraph-based Aggregated Communication and Remote Attestation' to address the aforesaid challenges. HAGAR is a distributed ledger based on a hashgraph architecture that not only provides decentralized security guarantees like traditional blockchain technology, but also makes communication fast and thus offers continuous attestation aggregation in large IoT networks. We use the features of Hashgraphs for data aggregation in remote attestation mechanisms for large dynamic IoT networks.
This study investigates the human errors that enable hackers to exploit and carry out social engineering attacks on the non-fungible token (NFT) ecosystem. The aim is to improve the design of decentralized applications that use NFTs to help non-technical users follow security best practices and address remaining user-side vulnerabilities. The study methods included a survey examining participants’ expertise regarding NFTs and cybersecurity, a remote security usability study investigating the pain points and common security best practices and a follow-up interview to examine participants’ experience with a crypto wallet configuration. The results show how human cognitive bias affects users’ decision to be cautious, users’ difficulty with security methods, and improvements to lessen users’ cognitive load. As NFTs expand beyond the cryptocurrency circle, multiple scams and thefts arise due to late adopters not knowing the security best practices. Therefore, increasing the public’s NFT security awareness is key to mitigating potential threats.
S. V. Padmavathi Devi, Mr Alangaram S, Mrs Sangeetha D, S. Jeeva · 5 authors
The healthcare sector has witnessed a rapid digitization of patient records, leading to an exponential increase in the volume and sensitivity of healthcare data.However, ensuring the security and privacy of this data has emerged as a critical challenge due to the evolving landscape of cyber threats.To address this challenge, a novel approach that combines the scalability of cloud computing with the immutability and transparency of blockchain technology to achieve robust security for healthcare data.The proposed hybrid storage framework leverages the advantages of both cloud computing and blockchain to establish a secure and efficient data management system.In this framework, sensitive healthcare data is encrypted and stored on distributed cloud servers to ensure high availability and reliability.Additionally, a blockchain-based distributed ledger is employed to record access logs and maintain a tamper-proof audit trail of data transactions.The integration of blockchain technology enables transparent and accountable data sharing among authorized parties while preserving patient privacy and confidentiality.The results indicate that the hybrid storage model offers superior resilience against various security threats, including unauthorized access, data breaches, and tampering, thus ensuring the confidentiality, integrity, and availability of healthcare data.
Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
Advanced Steganography and Watermarking Techniques
Abstract As a cornerstone of democratic governance, elections hold unparalleled significance, shaping a nation’s trajectory. However, the prevailing ballot-paper based voting systems continue to face trust issues among significant populations. As a result, e-Voting has emerged as an appealing alternative, with numerous countries opting for its implementation globally. While e-Voting systems offer several advantages, they also come with their own set of challenges. Even a minor vulnerability can lead to massive manipulations in voting results. In recent years, there have been efforts to revolutionize the e-Voting paradigm by harnessing the potential of emerging technologies such as biometrics and blockchain. This paper proposes a Internet-based voting that adopts blockchain technology and biometric identification techniques. We use biometric modalities, such as fingerprint and facial recognition, for voter authentication while leveraging Hyperledger Fabric framework as blockchain network and ensuring a secure, transparent, and tamper-evident voting record. We demonstrate the proposed system with 100 participants in a preset environment where we collect the biometrics data. The results indicate that 87% of participants successfully registered with biometrics, while 88% cast their votes with a combination of either voter ID and fingerprint or voter ID with facial recognition. Our findings suggest that the proposed system allows voters to access the system seamlessly and automate identity verification procedures while ensuring a secure, decentralized, and distributed database network that maintains transparency. Future research shall be carried out in collaboration with election officials and voters to improve the system in real-world scenarios.
Bangladesh has recently adopted the worldwide trend of digitalization, namely in the area of financial activities. In Bangladesh, the centralized nature of digital payment systems poses notable obstacles, such as lengthy transaction procedures, vulnerability to fraudulent activities, and the potential for financial theft, despite their increasing popularity. In light of these concerns, our study presents an innovative remedy that utilizes the potential of blockchain technology, in conjunction with Near Field Communication (NFC) technology, to transform the field of electronic transactions. Our adoption of the proof-of-stake technique sets us apart from traditional hand-cash systems as well as the current centralized digital payment systems, providing enhanced efficiency and security. This connection facilitates fast, safe, and user-friendly transactions across several platforms, such as online and mobile applications, thereby greatly improving the digital wallet experience. Our decentralized system guarantees the integrity and immutability of every transaction while significantly decreasing transaction and maintenance expenses. This technique functions independently without any external intervention, fostering trust among users and strengthening the system against fraudulent activity. Our system is specifically designed for the high-volume transaction environment of Bangladesh’s digital economy. It has the capability to efficiently handle large transaction volumes while ensuring full security. This article elucidates the revolutionary capacity of our blockchain-powered system to promote a secure, streamlined, and inclusive digital payment ecosystem in Bangladesh, representing a crucial stride towards a technologically progressive financial landscape.
Kexian Liu, Jianfeng Guan, Su Yao, Lili Wang · 5 authors
The widespread adoption of intelligent Internet of Things (IoT) has sparked increased efforts to foster extensive data interaction and collaboration across diverse fields, leading to a trust crisis in cross-domain scenarios. Moreover, cross-domain collaboration increases the complexity of key management, especially in resource-constrained IoT environments where high computational costs are impractical. This situation poses risks of key leakage and inefficient key updates. This paper introduces DKGAuth, a blockchain-based method for distributed key generation and authentication tailored for resource-constrained cross-domain intelligent IoT systems. Initially, we propose a lightweight cross-domain authentication architecture based on blockchain to address the trust crisis effectively among different domains in the intelligent IoT. Secondly, building upon this architecture, we introduce a distributed key generation method that revolutionizes the key infrastructure to address key management concerns. Additionally, we design an algorithm to combine key factors, minimizing costs associated with both key generation and updates. Finally, we establish a simulation environment to assess the computational, storage, and read/write overheads of our approach. In the same configuration, compared to other solutions, the efficiency of key updates improves by 83% when updated 100 times.
User Authentication and Security Systems
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Teng Cheng, Qiang Liu, Qin Shi, Ze Yang · 7 authors
Near-field communication in VANETs can effectively reduce communication overhead compared to peer-to-peer communication. However, there is still plenty of room for improvements to be made to ensure identity authentication privacy protection and to enhance the security and efficiency of key distributions during transmissions. Therefore, this paper proposes an anonymous identity authentication and group key distribution scheme based on quantum random numbers. In the proposed scheme, (1) anonymous credentials for vehicles are generated by a combination of random numbers on the vehicle side and random numbers in the TA, and mutual recognition of vehicles and roadside identity is achieved through the TA in the form of zero-knowledge proof, which achieves privacy protection for the vehicle during authentication. (2) A combined key generation method was devised. The roadside and the TA in this case jointly generate the group key. The TA uses a previously filled quantum key to encrypt the group session key parameter GSPc generated by its quantum random number generator to ensure security, and the roadside obtains the group session key parameter GSPr by calculating the anonymous credentials of all legitimate vehicles to achieve fast updates of the group session key. This scheme achieves forward and backward security while guaranteeing one-at-a-time encryption. The signaling and computation overheads were calculated, and the signaling overhead was reduced by nearly half. In addition, the group key issuance time was significantly reduced compared with other schemes. Through formal security analysis and experimental verification, the security and feasibility of this protocol were proved.
Web services that use a blockchain and crypto-assets (Web3 services) improve user privacy by anonymous logins using wallet addresses. However, since many users list their account identities (IDs) on social networking service (SNS) profile pages and reuse their account IDs for self-branding and curation purposes, which increases the risk of de-anonymization on Web3 services by linking these accounts. If such high-risk SNS accounts hold large amounts of crypto-assets, they are subject to account hijacking and spoofing attacks for financial gain. In this study, we proposed a method to discover highly relevant SNS accounts from a seed account on Web2 and Web3 SNSs and estimate their account ownership. We applied our method to 480 seed accounts of 9 different SNSs and discovered 1,233 new accounts. We found that SNSs with multiple URL input forms on their profile setting pages linked more accounts and revealed that 207 out of 253 (81.8%) users reused their IDs across different SNSs. We identified 26 accounts linked to personal and crypto-asset information that are at risk of de-anonymization. Our user study using crowdsourcing services showed that as many as 232 (40.8%) out of 568 respondents do not understand the traceability of blockchain transaction histories. We examined the security and privacy risks caused by account listing and ID reuse, and made recommendations for service providers and users based on our findings.
Tech innovation experts Dr Rajeev Kumar and Dr Alka Agrawal show how blockchain technology can be integrated with biometric apps in the healthcare sector, to protect highly sensitive patient data from cyber-attacks.
Purpose This study aims to introduce and evaluate the COPULA framework, a construction project monitoring solution based on blockchain designed to address the inherent challenges of construction project monitoring and management. This research aims to enhance efficiency, transparency and trust within the dynamic and collaborative environment of the construction industry by leveraging the decentralized, secure and immutable nature of blockchain technology. Design/methodology/approach This paper employs a comprehensive approach encompassing the formulation of the COPULA model, the development of a digital solution using the ethereum blockchain and extensive testing to assess performance in terms of execution cost, time, integrity, immutability and security. A case analysis is conducted to demonstrate the practical application and benefits of blockchain technology in real-world construction project monitoring scenarios. Findings The findings reveal that the COPULA framework effectively addresses critical issues such as centralization, privacy and security vulnerabilities in construction project management. It facilitates seamless data exchange among stakeholders, ensuring real-time transparency and the creation of a tamper-proof communication channel. The framework demonstrates the potential to significantly enhance project efficiency and foster trust among all parties involved. Research limitations/implications While the study provides promising insights into the application of blockchain technology in construction project monitoring, future research could explore the integration of COPULA with existing project management methodologies to broaden its applicability and impact. Further investigations into the solution’s scalability and adaptation to various construction project types and sizes are also suggested. Originality/value This research offers a comprehensive blockchain solution specifically tailored for the construction industry. Unlike prior studies focusing on theoretical aspects, this paper presents a practical, end-to-end solution encompassing model formulation, digital implementation, proof-of-concept testing and validation analysis. The COPULA framework marks a significant advancement in the digital transformation of construction project monitoring, providing a novel approach to overcoming longstanding industry challenges.
This review presents a comprehensive analysis of contemporary scholarship pertaining to instant messaging (IM) user behavior and security protocols. Through meticulous selection, the authors highlight critical studies that illuminate optimized message consumption strategies and delve into the evolving landscape of IM security models. Focusing on the past four years, the review meticulously dissects cutting-edge advancements in this domain. A significant insight emerges: achieving optimal communication security necessitates the synergistic convergence of three fundamental techniques: end-to-end encryption for data confidentiality, decentralized authentication for independent user verification, and zero-knowledge proof for identity obscurity. The review postulates that the simultaneous integration of these elements within the application architecture is paramount for robust privacy and heightened security in the realm of IM.
The rapid advancement of networking and manufacturing technologies has facilitated the proliferation of Internet of Things (IoT) devices connecting to networks. Just like humans, these devices, spanning various domains worldwide, necessitate interconnection. Therefore, cross domain identity authentication becomes crucial to ensure secure communication and mitigate cyber threats. Blockchain, as an emerging decentralized ledger technology, has garnered widespread attention due to its ability to effectively address the issue of single point of failure in traditional cross-domain identity authentication solutions. However, most cross-domain identity authentication solutions based on blockchain are limited by their reliance on existing single-chain blockchain architectures, which significantly restricts the performance of cross-domain authentication. In this paper, we present a splitchain based efficient authentication mechanism for cross-domain IoT. Specifically, we design an innovative split-chain blockchain structure that enhances the efficiency of authentication through parallelization. Additionally, we have developed a consensus algorithm that guarantees the security and fairness of the authentication system. Extensive experiments have been conducted to demonstrate that our scheme increases throughput by approximately 40% compared to MCCA, one of the most recent existing cross-domain solutions.
IOTA is a distributed ledger technology that uses a Directed Acyclic Graph (DAG) structure called the Tangle. It is known for its efficiency and is widely used in the Internet of Things (IoT) environment. Tangle can be configured by utilizing the tip selection process. Due to performance issues with light nodes, full nodes are being asked to perform the tip selections of light nodes. However, in this paper, we demonstrate that tip selection can be exploited to compromise users' privacy. An adversary full node can associate a transaction with the identity of a light node by comparing the light node's request with its ledger. We show that these types of attacks are not only viable in the current IOTA environment but also in IOTA 2.0 and the privacy improvement being studied. We also provide solutions to mitigate these attacks and propose ways to enhance anonymity in the IOTA network while maintaining efficiency and scalability.
Non-Fungible Tokens (NFTs) are digital assets recorded on the blockchain, providing cryptographic proof of ownership over digital or physical items. Although Solana has only begun to gain popularity in recent years, its NFT market has seen substantial transaction volumes. In this paper, we conduct the first systematic research on the characteristics of Solana NFTs from two perspectives: longitudinal measurement and wash trading security audit. We gathered 132,736 Solana NFT from Solscan and analyzed the sales data within these collections. Investigating users' economic activity and NFT owner information reveals that the top users in Solana NFT are skewed toward a higher distribution of purchases. Subsequently, we employ the Local Outlier Factor algorithm to conduct a wash trading audit on 2,175 popular Solana NFTs. We discovered that 138 NFT pools are involved in wash trading, with 8 of these NFTs having a wash trading rate exceeding 50%. Fortunately, none of these NFTs have been entirely washed out.
Open access
3 source records
Blockchain Technology Applications and Security
User Authentication and Security Systems
Advanced Steganography and Watermarking Techniques
The growing use of IoT in 5G networks has led to new security concerns, particularly related to the lack of authentication mechanisms. This paper proposes a new way to solve this problem by using blockchain-based digital tokens to identify IoT devices and enable secure communication over 5G networks, etc. Our Digital Identity Authentication using Blockchain (DIA-Be) approach proposed in this paper is to create a unique blockchain- based digital identity for each device. The created digital identities are verified using cryptographic protocols and stored in a tamper- proof decentralized ledger. These digital identities can be used to authenticate devices as they connect to a network, preventing unauthorized access, and allowing secure communication channels to be established. We discuss the benefits of this approach, including improved security, reliability, and deployment, and highlight some of the challenges that must be addressed when implementing this approach. Our plan shows our commitment to improving the security of IoT devices in 5G networks, with the ability to create safe and secure IoT devices that can share communications with each other without a network.