This paper proposes a Non-Fungible Token (NFT) soft pairing framework for Bluetooth service access control. Unlike conventional Bluetooth systems where pairing implicitly grants persistent service access, the proposed approach decouples native Bluetooth pairing from authorization without modifying the underlying protocol stack. The framework introduces a three-layer architecture consisting of a Bluetooth layer for connectivity, a blockchain layer for trusted execution and on-chain state verification, and an application layer where NFT soft pairing defines the authorization logic. In this design, Non-Fungible Bluetooth Tokens (NFBTs) represent user-side access credentials, while Non-Fungible Device Tokens (NFDTs) represent device identities. Their bidirectional on-chain binding forms a revocable and verifiable NFT soft pairing relationship. During access, users prove ownership of valid NFBTs through challenge-response signatures, and devices verify the corresponding on-chain state before granting service access. A prototype implemented with MetaMask and Ethereum demonstrates secure authentication, dynamic revocation, acceptable latency, and gas-efficient credential issuance based on ERC1155.
IoT location services accept client-reported GPS coordinates at face value, yet spoofing is trivial with consumer-grade tools. Existing spoofing detectors output a binary decision, forcing system designers to choose between high false-deny and high false-accept rates. We propose a graduated trust gate that computes a multi-signal integrity score and maps it to three actions: PROCEED, STEP-UP, or DENY, where STEP-UP invokes a stronger verifier such as a zero-knowledge proximity proof. A session-latch mechanism ensures that a single suspicious fix blocks the entire session, preventing post-transition score recovery. Under an idealized step-up oracle on 10,000 synthetic traces, the gate enables strict thresholds (theta_p = 0.9) that a binary gate cannot safely use: at matched false-accept rate (11%), the graduated gate maintains zero false-deny rate versus 0.05% for binary, with 5 microseconds scoring overhead. Real-device traces from an Android smartphone demonstrate the session-latch mechanism and show that a nearby mock location (~550 m) evades theta_p = 0.7 but is routed to step-up at theta_p = 0.9. Signal ablation identifies a minimal two-signal configuration (F1 = 0.84) suitable for resource-constrained scoring layers.
Hari Sai Kaja, Mohamed Firas Aguir, Vincent Duronio, Samah Mansour · 6 authors
This paper presents a Python-based simulation framework for modeling a lightweight authentication architecture in the Internet of Health Things (IoHT). The simulator combines double-hashed biometrics, Physical Unclonable Function (PUF)-based device identification, a simulated zero-knowledge proof (ZKP) abstraction, and blockchain-backed verification through the Proof of Elapsed Work and Luck (PoEWAL) consensus mechanism. Rather than deploying full cryptographic implementations or a distributed blockchain network, the framework focuses on modeling protocol sequencing, component interaction, and timing behavior within a controlled environment. Communication between entities is emulated using the MQTT protocol via a Mosquitto broker to reproduce realistic enrollment and authentication exchanges. Designed for research and educational purposes, the simulator facilitates evaluation of architectural behavior and performance under configurable load conditions. Experimental results demonstrate correct protocol execution, stable simulated response times, and the structural feasibility of integrating PUFs, ZKPs, and blockchain mechanisms for decentralized IoHT authentication workflows..
Reliable voice communication is vital throughout the institutions and organizations, but it is prone to the failures of internet connectivity and cellular network in constrained or isolated settings. Our physical system is a SIM-less intranet calling platform that is going to be implemented on a Raspberry Pi based on the open-source Asterisk PBX platform to provide the Voice over Internet Protocol (VoIP) communication between SIP-based clients. Session Initiation Protocol (SIP) takes care of the registration of the user, call setup, and signalling, whereas Real-Time Transport Protocol (RTP) takes care of a data transfer, providing stable peer-to-peer communication. Softphone applications like Zoiper are used to make the connection to the users and authentication is done with the help of Asterisk configuration files like sip.conf and extensions. conf. The viability of using embedded platforms to power safe and decentralized intranet telephony was confirmed by the result of experimental tests that confirmed good connectivity, low developing latency, and audible performance. A solution suggested can be applied to campuses, laboratories, small businesses, and emergency operation where the constant use of the internal communication network is needed and does not rely on the public network. This work will help to develop autonomous VoIP communication structures which make them more robust, private, and affordable by combining low-cost hardware and open-source software.
Vehicle platoon, an increasingly significant technology in vehicular ad hoc networks (VANETs), effectively reduces energy consumption and environmental pollution, mitigates traffic congestion, and enhances road capacity and traffic safety. Collaborative communication between platoons is available to promote the reliability of data dissemination, ameliorate driving strategies, and further strengthen traffic efficiency. Nevertheless, existing efforts for secure multi-platoon data dissemination still face the following issues: (i) lack of a direct authorization strategy for platoons working on different systems; (ii) no effective mechanism to protect vehicle privacy during platoon communications; (iii) absence of a practical verification approach for cross-system ciphertext transformation. This paper builds a privacy-preserving and verifiable cross-system authorization (PVCA) scheme to mitigate the above issues. Specifically, we first put forth the optimized anonymous identity-based broadcast encryption (IBBE) and policy-hiding attribute-based encryption (ABE) protocols to adapt platoon communications while protecting identity and attribute privacy. After that, the authorized token bridging the proposed protocols is designed to enable ciphertexts of IBBE format to be transformed into new ciphertexts of ABE format, enabling flexible authorization. Furthermore, inspired by the Fujisaki-Okamoto transformation, we devise an efficient zero knowledge proof of knowledge protocol, making our PVCA achieve verifiability and fairness. Rigorous security proof and analysis demonstrate that our PVCA is not only secure against chosen plaintext attacks and collusion attacks, but also satisfies the necessary security requirements. We implement a prototype of PVCA (on a desktop computer and Raspberry Pi) and provide a simulation utilizing NS-2 to validate its feasibility for platoon communications in VANETs. The results indicate that, compared to the state-of-the-art ciphertext transformation solutions, PVCA reduces the running time for original ciphertext generation, transformation, and decryption by at least 91.57%, 49.87%, and 50%, respectively, while compressing the original ciphertext and authorization token sizes by over 78.07% and 15.20%.
Smart contracts, as self-executing code on blockchain platforms, are transforming digital agreements across multiple industries. This paper reviews the technical foundations, applications, security challenges, and emerging directions of smart contract technology through an analysis of recent academic literature and real-world implementations. While smart contracts demonstrate significant potential in decentralized finance, supply chain management, and healthcare, they face critical challenges, including security vulnerabilities, ecosystem centralization risks, and legal uncertainties. Layer-2 scaling solutions, cross-chain interoperability protocols, and AI-assisted security auditing represent promising directions for addressing these challenges. Our analysis reveals that despite technological advances, fundamental issues in security verification and regulatory frameworks require continued research attention.
The adoption of the Internet of Things in critical applications highlights the need to strengthen security in its perception layer, one of the most vulnerable. This article presents a threat model for this layer, identifying replay, denial-of-service, and network traffic capture attacks as the most critical. In order to counteract them, an optimized variant of an authentication protocol based on zero-knowledge proofs is proposed, improving the efficiency and scalability of the original Hecht protocol. The solution introduces elementary matrices to reduce protocol computational complexity and an explicit mechanism for secure secret management. It is experimentally validated in a QR code-based access control system, simulating a real Internet of Things environment. The results show that the proposed variant is lightweight, efficient, and suitable for resource-constrained devices, especially in web environments, offering a high level of security by not revealing information about the secret key during authentication. Furthermore, a design of experiments optimizes the protocol parameters, minimizing execution time without compromising security. The proposed protocol represents a significant improvement in security and efficiency for authentication in the Internet of Things perception layer.
This paper introduces an innovative secure element token, which supports three communication interfaces, USB, WiFi, and Bluetooth. The token is built with a system on chip (SoC) module including FLASH memory, and a secure element (javacard) with a mini SIM form factor. The secure element is managed via ISO7816 five wires interface, thanks to an original library. We present use cases for each communication interface. Serial USB is used to upload software in the SoC, and thereafter to download javacard application in secure element according to Global Platform (GP) protocols. Wi-Fi enables internet access to secure element thanks to TLS1.3 server running within secure element. Bluetooth allows interactions with mobile applications, such as Bluetooth terminal, which use the SoC to build Ethereum transactions signed by secure element.
This demonstration presents an original low cost SIM Ethereum Bluetooth token (SIM_ETH_BLE_TOKEN), used from a mobile application, for the generation of Ethereum transaction. The token is based on open hardware (i.e. Arduino) and open source code. The core security is a secure element (i.e. javacard) with SIM card form factor, protected by PIN code, which stores keys and generates transactions. The token has no keypad or screen; it uses a LED and a button for user interface. The mobile application is available on Google Play. It signs files stored in smartphone, thanks to transactions, inserted in the Ethereum ledger.
Njabulo S. Mtetwa, Paul Tarwireyi, Cecilia Nombuso Sibeko, Adnan M. Abu‐Mahfouz · 5 authors
The Internet of Things (IoT) is changing the way consumers, businesses, and governments interact with the physical and cyber worlds. More often than not, IoT devices are designed for specific functional requirements or use cases without paying too much attention to security. Consequently, attackers usually compromise IoT devices with lax security to retrieve sensitive information such as encryption keys, user passwords, and sensitive URLs. Moreover, expanding IoT use cases and the exponential growth in connected smart devices significantly widen the attack surface. Despite efforts to deal with security problems, the security of IoT devices and the privacy of the data they collect and process are still areas of concern in research. Whenever vulnerabilities are discovered, device manufacturers are expected to release patches or new firmware to fix the vulnerabilities. There is a need to prioritize firmware attacks, because they enable the most high-impact threats that go beyond what is possible with traditional attacks. In IoT, delivering and deploying new firmware securely to affected devices remains a challenge. This study aims to develop a security model that employs Blockchain and the InterPlanentary File System (IPFS) to secure firmware transmission over a low data rate, constrained Long-Range Wide Area Network (LoRaWAN). The proposed security model ensures integrity, confidentiality, availability, and authentication and focuses on resource-constrained low-powered devices. To demonstrate the utility and applicability of the proposed model, a proof of concept was implemented and evaluated using low-powered devices. The experimental results show that the proposed model is feasible for constrained and low-powered LoRaWAN devices.
BACKGROUND: Patient-centered health care information systems (PHSs) enable patients to take control and become knowledgeable about their own health, preferably in a secure environment. Current and emerging PHSs use either a centralized database, peer-to-peer (P2P) technology, or distributed ledger technology for PHS deployment. The evolving COVID-19 decentralized Bluetooth-based tracing systems are examples of disease-centric P2P PHSs. Although using P2P technology for the provision of PHSs can be flexible, scalable, resilient to a single point of failure, and inexpensive for patients, the use of health information on P2P networks poses major security issues as users must manage information security largely by themselves. OBJECTIVE: This study aims to identify the inherent security issues for PHS deployment in P2P networks and how they can be overcome. In addition, this study reviews different P2P architectures and proposes a suitable architecture for P2P PHS deployment. METHODS: A systematic literature review was conducted following PRISMA (Preferred Reporting Items for Systematic Reviews and Meta-Analyses) reporting guidelines. Thematic analysis was used for data analysis. We searched the following databases: IEEE Digital Library, PubMed, Science Direct, ACM Digital Library, Scopus, and Semantic Scholar. The search was conducted on articles published between 2008 and 2020. The Common Vulnerability Scoring System was used as a guide for rating security issues. RESULTS: Our findings are consolidated into 8 key security issues associated with PHS implementation and deployment on P2P networks and 7 factors promoting them. Moreover, we propose a suitable architecture for P2P PHSs and guidelines for the provision of PHSs while maintaining information security. CONCLUSIONS: Despite the clear advantages of P2P PHSs, the absence of centralized controls and inconsistent views of the network on some P2P systems have profound adverse impacts in terms of security. The security issues identified in this study need to be addressed to increase patients' intention to use PHSs on P2P networks by making them safe to use.
The ever-increasing demand for high communication data rate and high-quality multi-media services; over past few decades, has ignited new avenues in radio architectures. Frequency reconfigurable (or frequency agile) communication systems are among the key architectures for efficient and cost-effective utilization of the allotted frequency spectrum. The emerging concept of on-orbit flexible payload (or programmable payload) in satellite communication is another encouraging development on the horizon. In-addition, tunability in filters used for remote radio unit (RRU) is highly preferred by network operators owing to the high cost of installing RRU both in low density remotely accessed locations and in high density expensive urban locations. Such frequency reconfigurable radio architectures typically demand reconfigurability (tunability) of components within the physical layer as well. Hence, tunable filters play a vital role in realization of frequency reconfigurable communication systems. \n \nIn general, any fixed frequency filter can be transformed into a tunable filter by introducing tuning elements dedicated to tuning the resonators and the coupling structures. Thus, a tunable filter of order N would require 2N+1 tuning elements to maintain a constant absolute bandwidth (BW) over the tuning range. This use of large number of tuning elements not only increases size and cost, but also adds to the complexity of the tuning control mechanism, particularly when configured in a closed loop system. Over the past decade, a significant research has been carried out to reduce the number of tuning elements by roughly 50% (i.e. with only N tuning elements). The coupling structures are suitably designed to maintain their performance over the tuning range, eliminating N+1, while only N tuning elements are used for tuning the N resonators. The goal here is to further reduce the number of tuning elements to a ‘single tuning element’. \n \nThe thesis presents several novel configurations for a high-Q tunable band pass filter employing a single tuning element, while maintaining a constant BW, return loss performance and location of the transmission zeros over a wide tuning range. Advanced filter synthesis techniques for both tunable filter and fixed filters are also proposed. \n \nA tunable double-septa waveguide (WG) filter is presented employing a single tuning element. The theory of coupling behavior of single septum and double septa to achieve constant absolute BW is explored. The tuning mechanism of the proposed filter is explained with measurement results presented for a Ku-band tunable WG filter designed at 15 GHz with a 2% fractional BW to achieve 15% tuning range. BW variation is observed to be within ±5% while the center frequency is tuned from 14.65 to 17.15 GHz. The filter promises to be useful in emerging 5G millimeter-wave applications, where the filter size is very small to accommodate multiple mechanical tuning elements. Furthermore, the proposed design methodology is scalable, i.e., the tuning mechanism is independent of the filter order. \n \nA frequency reconfigurable dual-mode WG filter having an elliptic response is presented. The proposed filter maintains a constant absolute BW and a constant rejection BW (i.e. constant frequency spacing between transmission zeros) over the tuning range. Furthermore, the filter can be tuned using a single tuning mechanism. A 4th order prototype filter at 11.5 GHz with 50 MHz bandwidth and 2 symmetric transmission zeros (± 45 MHz) is fabricated and measured. \n \nA novel configuration of a BW reconfigurable WG filter that uses only two tuning elements irrespective of the filter order is proposed. The proposed filter configuration demonstrates that it can achieve a relatively wide BW variations without deviating the center frequency. A 4 pole prototype filter is designed, fabricated and tested at Ku-band. The measured BW tunability of the filter is nearly 35 % from 225 to 320 MHz at 13.375 GHz. To the author’s knowledge, this is the only BW reconfigurable filter that can be tuned with only two tuning elements regardless of the filter order. \n \nThe thesis also demonstrates the feasibility of realizing a high-Q lambda/2 resonator based tunable coaxial filter, which is tuned by a single rotational tuning element irrespective of the filter order. The proposed filter has low variations in the absolute BW and insertion loss (IL) over a relatively wide tuning range. A prototype four-pole filter is developed at 2.5 GHz with a fractional BW of 4% to verify the concept. The measured tuning range of the filter is 20%, within which the BW variation is better than ±10% and IL variation is better than 0.05 dB. The proposed concept is easily expandable to filters with higher order. Furthermore, the concept is adopted to design a tunable diplexer using only a single tuning mechanism while maintaining the frequency performance of each channel and the frequency spacing between the two channels over the tuning range. The proposed high-Q tunable filter is promising for use in the frequency-agile communication architecture at the cellular base-station and aerospace applications. \n \nA novel configuration of a High-Q coaxial tunable filter which employs a single rotational mechanism to tune the filter, while using fixed lambda/4 resonators is also presented. The rotational tuning concept is different from that proposed for the tunable coaxial lambda/2 resonators. A prototype filter is designed for the proof of concept, which has a tuning range of 11.6% from 685 MHz to 770 MHz, over which bandwidth variation is within 10.5±0.7 MHz.. In-addition, the proposed design methodology can be scaled to realize higher order filters. The proposed filter promises to be useful in a wide range of telecommunication applications including flexible payload in aerospace applications.
An Internet of Things (IoT) network can have different components such as servers, gateways, and the end devices. An important source of performance constraint in such an IoT network is found in the limitations of its gateway. The capability of a gateway can dictate the effectiveness of a network and its services. The capacity, power consumption, and security of an IoT gateway are revealed as sources of network bottlenecks and service constraints. Blockchain technology can create a decentralized structure that can offload these strains. To unify these nodes as gateways under the same network, we need an effective means of communication. This paper proposes a setup that makes use of the decentralized capabilities of private blockchain technology partnered with the low-powered and secure connection of Bluetooth Low Energy (BLE). This provides a more secure means of wireless communication and prevents the nodes from being concentrated within an area. The architecture was compared against a standard WiFi network (2.4GHz) to prove its feasibility in effectively carrying out its functionality. In an experiment that used 4 gateway nodes, BLE proved to be more feasible than WiFi by yielding a better verification packet rate of 14 per minute compared to its counterpart that measured 4 per minute. Also, it showed to be more efficient in terms of power consumption with an average of 1095.40 mW, while the WiFi setup was measured to be 1191.83 mW. These results show promise in using BLE paired with blockchain technology to solve the capacity, power and security issues in IoT networks.
The articles in this special section focus on distributed ledger technologies (DLT). DLT, of which blockchain is a popular example, are increasingly becoming a popular means to maintain transactional integrity and achieve consensus among competing parties in many modern distributed data exchanges. Indeed, a Gartner survey estimates that by 2020, DLT and blockchain will support the global movement and tracking of $2 trillion of goods and services annually. Unlike centralized files and databases, distributed ledgers rely on peering nodes to record, share, and synchronize transactions and data in their individually maintained local ledgers. In the case of blockchain, information is organized into blocks that are securely and transparently chained together. These blocks become immutable global knowledge among all peers using consensus algorithms to achieve data synchronization. The “append-only, globally accepted” transactions supported by blockchain technologies have given rise to both opportunities and challenges compared to traditional data storage systems. One of the challenges faced by current information sharing systems, and a key concept that makes DLT appealing is the support for the creation of large scale systems from nodes and components that do not trust each other. Being able to reach consensus and share a commonly verifiable ledger is a very powerful primitive, which is already being considered for data sharing applications in energy, pharmaceuticals, and many other domains.
This demonstration presents an innovative Bluetooth blockchain payment terminal (PBT), built over an Arduino AVR processor, with a touch screen, a smartcard reader socket and a Bluetooth module. The system is bare metal, i.e. firmware's (both BPT and Bluetooth module) can be fully uploaded on-demand. The demo shows an Ethereum blockchain transaction protocol (BTP), performed between a user equipped with a BPT and a merchant using a mobile phone connected to Internet.
Bluetooth Low Energy (BLE) has emerged as one of the most promising technologies to enable the Internet-of-Things (IoT) paradigm. In BLE-based IoT applications, e.g., wearables-oriented service applications, the Bluetooth MAC addresses of devices will be swapped for device pairings. The random address technique is adopted to prevent malicious users from tracking the victim's devices with stationary Bluetooth MAC addresses and accordingly the device privacy can be preserved. However, there exists a tradeoff between privacy and security in the random address technique. That is, when device pairing is launched and one device cannot actually identify another one with addresses, it provides an opportunity for malicious users to break the system security via impersonation attacks. Hence, using random addresses may lead to higher security risks. In this study, we point out the potential risk of using random address technique and then present critical security requirements for BLE-based IoT applications. To fulfill the claimed requirements, we present a privacy-aware mechanism, which is based on elliptic curve cryptography, for secure communication and access-control among BLE-based IoT objects. Moreover, to ensure the security of smartphone application associated with BLE-based IoT objects, we construct a Smart Contract-based Investigation Report Management framework (SCIRM) which enables smartphone application users to obtain security inspection reports of BLE-based applications of interest with smart contracts.
This paper presents a protocol aiming at proving that an encryption system contains structural weaknesses without disclosing any information on those weaknesses. A verifier can check in a polynomial time that a given property of the cipher system output has been effectively realized. This property has been chosen by the prover in such a way that it cannot been achieved by known attacks or exhaustive search but only if the prover indeed knows some undisclosed weaknesses that may effectively endanger the cryptosystem security. This protocol has been denoted zero-knowledge-like proof of cryptanalysis. In this paper, we apply this protocol to the Bluetooth core encryption algorithm E0, used in many mobile environments and thus we suggest that its security can seriously be put into question.