Security in resource-constrained IoT deployments remains a persistent challenge: devices used in industrial control, smart healthcare, and transportation must authenticate quickly, consume minimal energy, and resist physical attacks — yet existing protocols rarely address all three requirements at once. To the best of current knowledge, no prior protocol jointly optimises security, energy, and latency within a single formally verified framework. This paper presents OPAQUE-IoT, an Optimization-driven PUF-Blockchain AKA Protocol for constrained IoT networks. The framework integrates PUF-based hardware identity verification, a permissioned blockchain for decentralized trust management, and the Adaptive Security-Energy Trade-off Optimizer (ASETO), which jointly minimizes authentication latency and energy consumption under formal security constraints. Convergence of ASETO is proven under Lipschitz-continuous objective functions. Formal security analysis under the Real-or-Random (RoR) model with explicit Random Oracle and ECDH hardness assumptions demonstrates resistance to replay, impersonation, man-in-the-middle, PUF modeling, insider, and side-channel attacks, with a security advantage bound of approximately 2^(-68). Simulation results across heterogeneous IoT topologies ( N = 50 to 5000 devices) show 31.8% lower energy consumption, 30.2% reduced authentication latency, and 41.1% higher throughput compared to the best-performing blockchain-capable baseline, with O(log N) Merkle-indexed blockchain query complexity and O(T_max·N·P) per-epoch optimiser complexity.
W. C. Yang, J. F. Qiao, J. F. Hu, Jie Wang · 5 authors
This study presents a multi-level verification system for secure communication protocols in energy billing infrastructures. The proposed framework integrates device attestation, network integrity verification, privacy-preserving aggregation, billing validation, and immutable auditing to address security vulnerabilities across Advanced Metering Infrastructure (AMI) communication chains. A Hybrid Secure-Efficient Protocol (HSEP) combining elliptic curve cryptography, homomorphic encryption, and zero-knowledge proofs is developed to provide secure authentication, privacy protection, and verifiable data integrity while maintaining low computational overhead. Experimental evaluation using a large-scale AMI testbed demonstrates that the proposed system significantly improves tampering detection capability, achieving an intrusion detection AUC of 0.94 while maintaining an average energy consumption of 1.55 J per transaction and acceptable communication latency for large-scale deployment. The architecture exhibits strong scalability, robustness, and rapid dispute-resolution performance under multiple attack scenarios. The proposed framework is particularly applicable to wireless smart metering networks and antenna-enabled AMI communication infrastructures, where reliable data transmission, secure protocol verification, and resilience against communication-layer attacks are essential for trustworthy energy billing and grid operation. This work provides an effective engineering solution for secure, privacy-preserving, and verifiable communication in modern intelligent energy systems.
The use of a wireless sensor network is increasingly supporting e-governance functions such as municipal utility monitoring, environmental monitoring, grievance-based field reporting, and smart public service delivery. Most wireless sensor network architectures rely on a gateway or database. However, this introduces vulnerabilities to data integrity, node accountability, and auditability. This study examines transparency through a blockchain-enabled WSN architecture for e-governance. The study applies a reproducible Python-based Monte Carlo simulation with a fixed random seed, five node densities, three architectural scenarios, and 450 observations. The scenarios that are compared in this work are a normal WSN, a centralized secure WSN, and a permissioned blockchain-enabled WSN with smart-contract-based identity registration, hash-linked data records, trust scoring, and tamper verification. Descriptive statistics, one-way ANOVA, Welch t-tests, Pearson correlation, and multiple linear regression analysis. The blockchain-assisted WSN, as evidenced by the simulation findings of our project, produced the highest mean data integrity score, tampering detection rate, trust score, malicious node detection rate, and packet delivery ratio. The architecture also improved the composite service efficiency index relative to the conventional baseline, even though it introduced higher latency, transaction confirmation time, and energy consumption. The research indicates that the permissioned blockchain can enhance public-sector WSN transparency with edge aggregation and lightweight cryptographic operations along with carefully tuned endorsement rules. The methods presented in this study allow for scrutiny of secure WSN designs tailored for e-governance.
Over the past few years, Wireless Sensor Networks (WSNs) have been increasingly deployed for numerous sensing and monitoring purposes in environmental monitoring, industrial automation, health monitoring, military surveillance, smart agriculture and disaster management among others. The inherent limitations in terms of processing power, memory, communication bandwidth and energy of sensor nodes make WSNs highly susceptible to malware attacks. A wide variety of malware such as sensor network worms, Trojans, viruses, botnets and ransomware can easily propagate in a network through inter node communication. Such malware can cause serious damage to communication, compromise sensitive data, consume energy of the infected nodes thereby reducing the lifetime of network among others. In the last decade, numerous approaches have been proposed for the detection of malware infecting sensor nodes. These approaches range from traditional signature-based detection and behavior-based detection to more advanced approaches such as machine learning (ML)-based, deep learning (DL) -based, blockchain-based, trust management-based and federated learning-based detection. Most of the existing approaches for malware detection in WSNs have been designed to work on WSNs and have not been tested on real scenarios. Most of the approaches have their own strengths and weaknesses and the most suitable approach for a given application depends on various factors. In this paper, we present a comprehensive review of approaches for the detection of malware infecting sensor nodes in WSNs. We present a taxonomy of reviewed approaches for detection of malware. We also present a discussion on approaches for modeling malware propagation in a WSN as well as review on various categories of malware that have been designed to attack sensor nodes in WSNs along with detection frameworks for different categories of malware. We also present a comparative study of approaches used for the detection of malware in WSNs on the basis of various parameters such as detection accuracy, computational complexity, energy efficiency, scalability, detection latency and deployability. The review and taxonomy presented in this paper will be highly beneficial for researchers and practitioners designing approaches and systems for the detection of malware in WSNs. Various open research challenges in this area have also been discussed in this paper including detection of zero-day malware, designing of intelligent models to be light enough to be deployed on sensor nodes, use of explainable artificial intelligence for detection of malware in WSNs, designing approaches for privacy-preserving collaborative learning in WSNs and designing adaptive security approaches for WSNs.
Ahmed A. Jasim, Noor Riyadh Issa, Hisham A. Shehadeh, Fadhil Mukhlif · 6 authors
Abstract The Wireless Sensor Networks (WSNs), which are deployed in harsh environments, are extremely susceptible to localized battery exhaustion as well as intelligent inside routing threats, especially sinkhole and data falsification attacks. In this paper, we present ECHVM (Enhanced Cluster Head selection by Voting and an ECC-based Blockchain Mechanism), a novel, secure, and energy-efficient routing framework to achieve an optimal trade-off between network security and hardware resource efficiency. We present the ECHVM protocol that combines Elliptic Curve Cryptography (ECC) with a lightweight, local distributed ledger to mitigate risks of centralized authority by transferring the verification of crucial network events from a single, highly vulnerable centralized alert sink node to a decentralized, voting-based consensus among neighboring nodes. In this study, a weighted voting algorithm based on node and distance proximity metrics is applied to cluster head selection, where a 51% neighbor consensus rule is leveraged to validate local ledger transactions against malicious acts. Moreover, a local energy density and topological communication geometry-oriented energy-efficient cluster head (CH) selection algorithm is crafted to ensure balanced CH distribution in the high-density areas of the network structure so as to avoid the premature energy hole problem. Using the standard first-order radio energy model, quantitative simulations performed in MATLAB show that ECHVM achieves a malicious node detection rate of 98.2% and extends the network lifetime by 30% compared to state-of-the-art protocols (e.g., ELSO and SEC-HDT) because of proactive topology defense and rapid node sleeping. The results of statistical validation using the Wilcoxon Signed-Rank test confirm that both the reduction in energy consumption and network longevity offered by ECHVM are highly significant ( p = 0.019), justifying ECHVM as a mathematically sound, permanent, scalable security framework suitable for resource-constrained, dense Internet of Things (IoT) and smart sensing applications for next-generation communication systems.
P. Thanalakshmi, V. G. Kiruthika, J. C. Gokul Abinash, P. Saravanan · 6 authors
Wireless Sensor Networks (WSNs) are vulnerable to malicious nodes and sensor node failures, which compromise data integrity and network reliability. These threats result in incorrect decisions and reduce system trust. To address this, machine learning algorithms enable anomaly detection by identifying abnormal sensor nodes, while blockchain ensures secure and tamper-proof data storage. However, reliable consensus is essential before data validation in the blockchain. A hybrid framework combining ML, blockchain, and a modified HotStuff consensus algorithm with post-quantum cryptographic systems provides secure, fault-tolerant, and quantum-resistant consensus, ensuring trustworthy and resilient WSN operations.
Blockchain interoperability remains a major challenge because heterogeneous blockchain networks cannot securely and efficiently exchange cross-chain data and transactions. Existing interoperability solutions often rely on central relays or trusted intermediaries, creating security vulnerabilities, limited fault tolerance, and a single point of failure. To address these limitations, this paper proposes VeriMesh, a decentralised mesh-based interoperability framework that combines trust-adaptive routing, multi-path relay verification, and Zero-Knowledge Proof (ZKP)-based validation for secure cross-chain communication. VeriMesh models relay nodes as a trust-weighted graph in which routing decisions dynamically adapt based on node behaviour and delivery reliability. Multi-path routing improves resilience against adversarial relay nodes, while transport-layer ZKP verification enables privacy-preserving validation without exposing sensitive information. The framework was implemented using Python relay nodes, Solidity smart contracts, and an Ethereum (Ganache) environment. Experimental evaluation using structured event-driven workloads demonstrated stable latency below 34 ms and delivery success rates above 85% up to 40% malicious node presence. Comparative evaluation against single-path and random multi-path relay baselines showed improved fault tolerance and routing reliability. The results demonstrate favourable scalability and robustness within the evaluated network range ( N = 10–30), while larger-scale evaluation remains future work. All experiments were conducted in a controlled local Ganache blockchain environment rather than on a public Ethereum testnet or mainnet, so the reported latency, gas, and delivery figures characterise protocol-layer behaviour under controlled conditions and should not yet be interpreted as representative of performance under public-network conditions such as real gas markets, block propagation delays, or network congestion.
The Wireless Sensor Networks (WSN) and the Internet of Things (IoT) have revolutionized various application areas such as smart cities, health, industrial automation, environment, agriculture, and intelligent transportation systems. Despite the successful widespread use of WSNs-IoT, they still have several security issues including resource constrained sensor nodes, decentralized design, and the combination of heterogeneous communication protocols and insecure wireless communication channels. Most traditional security solutions including cryptographic methods, intrusion detection systems are rule-based, which is not enough to protect against the advanced, evolving and zero-day attacks. Therefore, the paradigm of artificial intelligence (AI) has become an exciting approach to creating intelligent, adaptive and autonomous cyber security solutions. This paper is a systematic literature review of the security solutions based on artificial intelligence (AI) applied to WSNs (WSNs) in the context of IoT. Structured review methodology is followed in the study, which critically analyzes recent machine learning, deep learning, reinforcement learning, federated learning, blockchain and edge intelligence advancements in the field of intrusion detection, anomaly detection, threat prediction, authentication, privacy preservation, and secure communication. These approaches are compared on the basis of their accuracy to detect the target, computational complexity, energy efficiency, scalability, and privacy and feasibility for deployment in resource constrained environments. Moreover, it classifies the already known security threats, examines layer-wise defense measures and analyzes upcoming hybrid AI frameworks, which combine several intelligent technologies. The review reveals several gaps in the research, such as the lack of explainability of models, use of benchmark datasets, susceptibility to adversarial and model-poisoning attacks, blockchain scalability issues, and the absence of standardized, secure system architectures that can offer reliable, privacy-preserving, and energy-efficient protection. The paper then proposes future research directions that highlight the need of combining Explainable Artificial Intelligence (XAI), Federated Learning, Blockchain, and Edge AI for the construction of strong and adaptive cybersecurity frameworks. This review is a comprehensive reference for researchers and practitioners who are interested in designing secure, intelligent and sustainable WSN-IoT systems for next-generation cyber-physical ecosystems.
Due to the fast development of digital communication technologies and the creation of distributed computing architecture, it is crucial to ensure the security of communication through effective and safe authentication schemes that can protect data privacy within cybersecurity frameworks. The most efficient cryptographic method for such purposes is zero knowledge proof since it provides ultimate security by proving the authenticity without disclosing any sensitive data to the verifying party. It is fascinating to look into the zero-knowledge proof protocol based on graph isomorphism because of its mathematical nature. A detailed discussion on the graph isomorphism based zero-knowledge authentication techniques along with their significance in the current cryptography is presented in this paper. Working principles and concepts behind graph theoretic based authentication techniques and the concept of graph isomorphism and zero-knowledge proofs have been discussed in this paper. Besides, emerging application areas of these protocols in disciplines like cybersecurity, block-chain. Internet of Things security, cloud computing and post-quantum cryptography have also been highlighted in this paper. In addition to that, this paper provides an analysis of major advantages, drawbacks and future research directions for the graph theoretic zero-knowledge authentication schemes
Wireless Sensor Networks (WSNs) are widely used in critical applications such as environmental monitoring, healthcare, industrial automation, and military surveillance; however, their resource constraints, wireless communication, and unattended deployment make them highly vulnerable to node capture attacks.In such attacks, adversaries physically compromise sensor nodes to extract cryptographic keys and sensitive information, leading to key leakage, node impersonation, communication disruption, and large-scale network compromise.Existing key management schemes often rely on static key structures, they lack forward secrecy, and fail to identify structurally vulnerable nodes, resulting in weak resilience against progressive node capture attacks.To address these limitations, this paper proposes a threshold-based ECDHE-TSSS key management framework to detect vulnerable nodes and mitigate node capture attacks in WSNs.The proposed scheme introduces an attack matrix based on graph-theoretic metrics to identify high-risk nodes and provide adaptive protection through decentralized masking of secret shares.The Proposed Scheme integrates Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) with Threshold Shamir Secret Sharing (TSSS) to achieve forward secrecy and strong resistance against node compromise while maintaining lightweight operations suitable for resource-constrained environments.A layered security architecture incorporating Schnorr-based Non-Interactive Zero-Knowledge Proof (NIZKP) authentication and distributed key revocation further enhances network resilience and secure communication.Simulation results demonstrate that the proposed scheme significantly reduces key compromise probability and improves overall network robustness compared with existing approaches.
Sepideh Avizheh, Reihaneh Safavi-Naini, Shiwei Sun
Group signatures are privacy preserving signature schemes in which a group member can anonymously sign messages on behalf of the group, while providing accountability, by allowing the signature of a misbehaving group member be ``opened'' and the identity of the signer be revealed. In group signature members are admitted to the group by a (trusted) group manager. We motivate the need for a flexible mechanism in applications, such as privacy preserving access in smart environments, and propose a two-level member-join group signature that we call SPonsored Group Signature (SPGS) where group members of level 1 can ``sponsor'' new members, in level 2, to join the group. This relaxation of user join comes with additional accountability mechanisms: we require that the signature of a sponsored member can be opened to the identity of the sponsor (that is sponsor is responsible for the sponsored member), and while all signatures are anonymous, for the sponsored members, the signatures are linkable. This allows a sponsor to efficiently identify an undesirable sponsored member. We formalize SPGS scheme, define its security using a game-based approach, and give a generic construction of SPGS that uses a (dynamic) group signature scheme, a commitment scheme, and a knowledge-sound non-interactive zero knowledge proof of knowledge, and prove its security. We also give an instantiation of our construction. To show applicability of SPGS in practice, we consider the problem of providing guest access in a smart building, and introduce Anonymous Guest Access Token (AGAT) that allows a temporary guest to anonymously access (a subset of) the building resources. We show how SPGS can be used (together with an IND-CPA secure public key encryption scheme) to give a direct construction for AGAT, and show the efficiency of our guest access protocol when it is instantiated with existing schemes.
Sancaktar Pelin, Necla Kırcalı Gürsoy, Arif Gürsoy
Modern authentication architectures contain structural vulnerabilities against automated credential stuffing and server-side data breaches. Traditional solutions rely on the transmission of raw or hashed passwords over the network; for bot defense, they position third-party Completely Automated Public Turing test to tell Computers and Humans Apart (CAPTCHA) services, which may violate user privacy and create institutional dependencies, as an illusion of two-factor authentication (2FA). This situation raises a critical research question in cybersecurity: How can an integrated cryptographic shield be constructed that is independent of user-privacy-invasive mechanisms and external data authorities, while preventing autonomous bots from targeting the identity and human-verification layers separately?In response to this question, this paper presents a zero-dependency, original, and hybrid protocol that integrates a Zero-Knowledge Proof (ZKP) based on the Schnorr authentication scheme with a local Human Interaction Proof (HIP) mechanism. The main advantage of the proposed architecture is that it mathematically seals the user’s secret credential together with a dynamically generated one-time CAPTCHA token on the client side using the SHA-256 function, thereby transforming the verification process into an indivisible atomic “Hybrid Secret.” In this way, the transmission of password hashes over the network is completely eliminated, and the server evaluates only the mathematical validity of the proof under the Discrete Logarithm Problem (DLP) assumption.Experimental results obtained through Selenium-based automated brute-force attack simulation engines demonstrate that the system provides complete blocking against automated threat vectors. Dynamic one-time nonce mutation immediately invalidates the derived client response, even in extreme scenarios where an attacking bot obtains the correct password string and solves the CAPTCHA image, thereby mathematically defeating brute-force and replay attacks. Furthermore, the autonomous structure of the proposed protocol, with no dependency on third-party analytics services, opens the way for a highly secure and local authentication architecture for internet-isolated critical infrastructures.In this study, the theoretical and mathematical foundations of the proposed protocol are presented, the stages constituting its life cycle are methodologically explained, and Selenium-based experimental simulation results together with telemetry log analyses are detailed.
Despite the growing adoption of blockchains, their isolated architectures hinder seamless cross-chain communication, challenging applications that rely on integrated blockchain infrastructures, notably Blockchain-based Information Systems (BISs). Achieving interoperability while preserving privacy and regulatory compliance remains a core challenge, particularly when separate organizations operate different blockchain platforms and tokenized value must move across them without exposing transaction links that may reveal business relationships or payment behavior. Existing interoperability solutions often incur high computational overhead and rely on protocol-specific assumptions, limiting their applicability across heterogeneous blockchains. We introduce zkPACT, a privacy-preserving framework for compliant cross-chain token transfers across heterogeneous blockchains. Our framework combines Zero-Knowledge Proofs (ZKPs), oracle networks, and off-chain batching to support scalable transfers. It employs a coordinated oracle model in which validators process cross-chain burn events, while a rotating aggregator updates the shared off-chain Merkle tree after reaching consensus, enabling private and efficient token claims. To improve scalability and reduce gas costs, zkPACT batches claim requests off-chain and then submits a single succinct proof to the smart contract. To ensure validator accountability, the framework enforces an incentive mechanism and dynamic slashing. We also integrate a Know Your Customer (KYC) mechanism that enables users to demonstrate compliance without revealing sensitive data, preserving privacy and accountability in the event of abuse. We present a proof-of-concept implementation of zkPACT that achieves up to 95% lower gas costs and up to 94% lower off-chain memory usage than a non-batching approach, demonstrating its suitability for private, scalable cross-chain token transfers.
Este Trabajo Fin de Grado presenta un análisis criptográfico y matemático de la arquitectura de Monero, una criptomoneda diseñada con la privacidad como propiedad fundamental de su protocolo. El estudio comienza con la formalización de los fundamentos algebraicos que conforman el sistema, como las curvas de Edwards retorcidas y la completitud de su ley de grupo, característica que contribuye a mitigar vulnerabilidades asociadas a ataques de canal lateral. Sobre esta base se estudia el protocolo Ring Confidential Transactions (RingCT), núcleo de los mecanismos de privacidad de la red. En particular, se analizan las direcciones sigilosas (stealth addresses), que garantizan la no vinculabilidad de los receptores mediante intercambios Diffie–Hellman sobre curvas elípticas; las firmas de anillo CLSAG y las imágenes de clave, que proporcionan anonimato al emisor y previenen el doble gasto; y los compromisos de Pedersen, utilizados para ocultar las cantidades transferidas. Asimismo, se estudian las pruebas de rango Bulletproofs+, destacando su función en la reducción del tamaño de las transacciones mediante argumentos de producto interno. Finalmente, se examinan diversas vulnerabilidades históricas y técnicas de análisis de trazabilidad aplicadas a Monero, evaluando el grado de resistencia que ofrece el protocolo frente a distintos ataques. Los resultados ponen de manifiesto cómo la integración de herramientas avanzadas de criptografía de clave pública, pruebas de conocimiento cero y estructuras algebraicas sobre curvas elípticas permite construir un sistema financiero con garantías de privacidad, seguridad y fungibilidad. ABSTRACT This Bachelor’s Thesis presents a cryptographic and mathematical analysis of the architecture of Monero, a cryptocurrency designed with privacy as a fundamental property of its protocol. The study begins with the formalization of the algebraic foundations underlying the system, including twisted Edwards curves and the completeness of their group law, a feature that helps mitigate vulnerabilities associated with side-channel attacks. Building upon this mathematical framework, the Ring Confidential Transactions (RingCT) protocol, which forms the core of Monero’s privacy mechanisms, is examined. In particular, the thesis analyzes stealth addresses, which ensure receiver unlinkability through Diffie–Hellman key exchanges over elliptic curves; CLSAG ring signatures and key images, which provide sender anonymity and prevent double-spending; and Pedersen commitments, which are used to conceal transferred amounts. Furthermore, Bulletproofs+ range proofs are studied, highlighting their role in reducing transaction size through efficient inner-product arguments. Finally, several historical vulnerabilities and traceability analysis techniques applied to Monero are reviewed in order to evaluate the protocol’s resistance against different types of attacks. The results demonstrate how the integration of advanced public-key cryptography, zero-knowledge proofs, and algebraic structures based on elliptic curves makes it possible to build a financial system with strong guarantees of privacy, security, and fungibility.
Wireless sensor networks (WSNs) integrated with the internet of things (IoT) are hybrid technologies of interconnected systems. The IoT connects various devices, from sensors to smart gadget networks, and leverages a framework to provide secure solutions. This paper presents a lightweight adaptive proof-of-stake (APoS) blockchain framework design specifically for IoT-WSN. It focuses on efficient energy, scalability, and robust security. The proposed model integrates a hybrid APoS-delegated PoS (DPoS) consensus mechanism, trust-based routing, and a random forest (RF)-driven intrusion detection system (IDS). Extensive simulations of 100 to 10,000 nodes display energy usage of 0.018–0.019 mJ/node, breach of privacy rates of 0.02%, and throughput up to 9.92 tx/round for 1,000 nodes and 3.40 tx/round for GreenOrbs validation. The IDS achieves 94.21% accuracy for 1,000 nodes and 88.89% for GreenOrbs against distributed denial-of-service (DDoS), Sybil, and Jamming attacks. Validated using the GreenOrbs dataset, the framework ensures real-world applicability in resource-constrained WSNs. Future research has validated and verified the use of APoS and PoS hybrid models for broader decentralised IoT–WSN deployments.
This chapter proposes a novel multi-factor authentication (MFA) with six schemes, namely password salting/hashing, non-interactive zero-knowledge (NIZK) proofs, GPS-based validation, time-based one-time passwords (TOTP), DNA cryptography, and lightweight SPECK ciphers. Taken together, these elements address the deficiencies in prior authentication and achieve a tradeoff between security and computational efficiency. The system is verified by theoretical and experimental methods. Furthermore, it is theoretically examined under the Real-or-Random model (RoR) with generative/explainable Artificial Intelligence (AI)-driven cybersecurity and provides strong security guarantees in terms of unpredictability (even if reduced in certain security parameters) and defends against replay, insider misuse, brute-force key search attacks, as well as spoofing ones. The solution is developed in Java, and the system is empirically evaluated by performing 100 runs to examine essential performance features: randomness, determinism, stability, and scalability.
The proliferation of sensor networks in critical infrastructure, healthcare monitoring, and smart city applications demands robust privacy-preserving mechanisms for data verification. Zero-knowledge succinct non-interactive arguments of knowledge (zk-SNARKs) offer a promising cryptographic primitive that enables data integrity verification without revealing sensitive sensor readings. However, the practical feasibility of deploying zk-SNARKs in resource-constrained sensor network environments remains insufficiently characterized. This paper presents a systematic benchmarking study of the Groth16 zk-SNARK protocol across eight representative circuit types spanning six orders of magnitude in computational complexity, from basic arithmetic operations (1 constraint) to ECDSA signature verification (1,510,185 constraints). Using an automated open-source benchmarking framework built on the Circom-snarkjs toolchain, we conducted 160 statistically controlled measurements (20 iterations per circuit) with cold/warm separation, collecting proof generation time, verification time, proof size, memory consumption, and witness generation overhead. Our results demonstrate that Groth16 proofs maintain a constant size of 804.7±1.7 bytes and near-constant verification time of 0.662±0.032 s regardless of circuit complexity, with coefficients of variation below 5% across all circuit types. Proof generation time exhibits sub-linear scaling (α=0.256, R2=0.608), with statistically significant differences between circuit categories confirmed by one-way ANOVA (F=355.0, p<10-79, η2=0.94). We identify three operational deployment tiers for sensor network architectures and estimate energy budgets for battery-powered devices. These findings provide actionable guidance for the design of privacy-preserving data verification systems in next-generation sensor networks.
Open access
Security in Wireless Sensor Networks
Cryptographic Implementations and Security
Physical Unclonable Functions (PUFs) and Hardware Security
This paper analyses MicroMix, a noncustodial Ethereum mixer that unlinks deposits from withdrawals using browser-side zkSNARKs, a centralised relayer, and on-chain enforcement via Semaphore and Mixer contracts. The study formalises core acceptance conditions—value conservation, nullifier uniqueness, external‑nullifier scoping, and signal binding—and evaluates risks that persist despite sound cryptography, including timing correlation in small anonymity sets, Sybil pool distortion, single‑relayer censorship, ETH payout liveness under gas‑stipend limits, ERC‑20 heterogeneity, circuit–verifier input/order mismatches, and cross‑chain replay. The work proposes concrete mitigations: randomised scheduling and probabilistic batching, multi‑denomination support, decentralised relayer participation with user-paid fallbacks, guarded call patterns with reentrancy protection, SafeERC20 enforcement and token whitelisting, strict public‑input ordering and signal‑to‑field mapping, a fixed mixer-scoped external nullifier, and chain-bound proofs. With these measures, MicroMix can preserve unlinkability while improving liveness and correctness in adversarial environments, advancing practical, privacy‑preserving withdrawals on Ethereum.
Margherita Cozzolino, Stephan Krenn, Thomas Lorünser
While QKD ensures information-theoretic security at the link level, real-world deployments depend on trusted repeaters, creating potential vulnerabilities. In this paper, we thus introduce a topology-hiding connectivity assurance protocol to enhance trust in quantum key distribution (QKD) network infrastructures. Our protocol allows network providers to jointly prove the existence of a secure connection between endpoints without revealing internal topology details. By extending graph-signature techniques to support multi-graphs and hidden endpoints, we enable zero-knowledge proofs of connectivity that ensure both soundness and topology hiding. We further discuss how our approach can certify, e.g., multiple disjoint paths, supporting multi-path QKD scenarios. This work bridges cryptographic assurance methods with the operational requirements of QKD networks, promoting verifiable and privacy-preserving inter-network connectivity.
Tamara S. Alakbarova, Parvin A. Abbasova, Samira B. Baratzade
In the study, cryptographic authentication approaches for ensuring secure automated access in Cyber-Physical Systems were modeled and examined. The proposed research analyzed the efficiency of three cryptographic models based on Public Key Infrastructure, Zero-Knowledge Proof, and Elliptic Curve Cryptography with the challenge-response mechanism. It was investigated how each model performs under varying latency, computational, and scalability conditions in smart grids, autonomous vehicle systems, and industrial Internet of Things environments. It was identified that the Elliptic Curve Cryptography model provides the best performance in real-time and resource-constrained scenarios. It was studied that the Zero-Knowledge Proof approach ensures higher privacy protection and stronger attack resistance compared to other models. It was defined that the Public Key Infrastructure model remains effective in structured networks but exhibits higher latency. It was established that simulation tools such as Matrix Laboratory and Network Simulator 3 confirm the reliability and reproducibility of results. It was developed a comparative framework that allows researchers to select optimal authentication methods for specific operational contexts. It was justified that hybrid approaches combining multiple cryptographic mechanisms can enhance both efficiency and resilience in Cyber-Physical Systems.
Wireless medical sensor networks (WMSNs) enable continuous patient monitoring by transmitting sensitive physiological data over open wireless links. Given the resource-constrained nature and large-scale deployment of such networks, authentication mechanisms must be both lightweight and privacy-preserving. Moreover, due to the frequent turnover of patients and devices in hospital environments, timely member revocation is crucial to prevent discharged or compromised entities from injecting forged reports that could mislead medical diagnosis. Although existing pairing-free certificateless aggregate authentication schemes are efficient, they often suffer from critical security and privacy vulnerabilities. Recently, an efficient certificateless authentication scheme with revocation has been proposed. However, our analysis reveals that the scheme presents the following security vulnerabilities: (i) member witnesses can be recovered from public information, (ii) revocation checks can be bypassed via identity grafting attack, and (iii) user identities can be linked due to the long-term use of static pseudonyms. To address these issues, we propose a security-enhanced certificateless aggregate authentication protocol with revocation for WMSNs. Our design enforces strong identity-membership binding to resist grafting attacks, employs a non-interactive zero-knowledge membership proof to preserve witness secrecy, and adopts dynamic pseudonym rotation to achieve unlinkability. We provide formal security proofs and comprehensive performance comparisons. The results indicate that, at the same security level, our protocol achieves more efficient signature verification while maintaining communication overhead comparable to existing schemes. In addition, the overhead introduced by our revocation mechanism remains constant, making it well suited for large-scale WMSNs deployments with frequent membership changes.