With the increasing connectivity and intelligence of Internet-of-Things(IoT)devices,which interface with numerous aspects of our daily lives,security remains a major concern for IoT devices deployed in e-healthcare sy...With the increasing connectivity and intelligence of Internet-of-Things(IoT)devices,which interface with numerous aspects of our daily lives,security remains a major concern for IoT devices deployed in e-healthcare systems.The existing solutions demonstrate that authentication of IoT devices across all domains,especially in healthcare,poses significant vulnerabilities,including side-channel,insider,and replay attacks.Alternatively,it is not feasible for resource-constrained IoT devices due to the computational,communicational,and space overheads of modular exponentiation or bilinear pairing,or because it requires four to five round-trips for authentication.The rapid growth of IoT in the e-healthcare sector is expected to cross“50 billion”or more by 2030,highlighting desynchronization,man-in-the-middle(MITM)attacks,and unavailability flaws in e-healthcare.If the aforementioned security concerns are not adequately addressed,they will,in turn,escalate and lead to severe consequences.Therefore,this article introduces a security protocol for an e-healthcare system to ensure secure communication for the voluminous data collected by IoT devices and to transfer it to the cloud safely.The proof of correctness and robustness of the proposed protocol was conducted using BAN(Burrows-Abadi-Needham)logic,the Real-Or-Random(ROR)model,the ProVerif verification toolkit,and pragmatic discussions.The performance analysis section was addressed by measuring several key metrics,including communication,computation,space,and energy consumption,along with scalability.The results obtained demonstrate that the communication cost may be reduced by up to 76%,the computation cost by up to 92%,and the energy consumption by up to 31%.展开更多
Unmanned aerial vehicles(UAVs)are also increasingly becoming more often in the transportation infrastructure of smart cities,so that they can successfully achieve real-time observation of traffic,emergency coordinatio...Unmanned aerial vehicles(UAVs)are also increasingly becoming more often in the transportation infrastructure of smart cities,so that they can successfully achieve real-time observation of traffic,emergency coordination,and two-way communication relaying.However,the security and privacy risks arising in open,highly mobile intelligent transportation systems(ITS)enabled by UAVs are critical,as they pose threats of impersonation,replay,Sybil,and tracking attacks.Secondly,standard static authentication mechanisms are unable to support dynamic risk environments and excessive resource consumption on UAV platforms with limited capacity.To address these challenges,this study introduces a Generative-AI-assisted Risk-Adaptive Authentication(GRAA)system that modulates the intensity of the authentication process based on risk levels identified by mobility,contextual awareness,and the environment.The framework contains unlinkable pseudonymous credentials and,unlike the accumulator-based revocation scheme and AI-based trust evaluation,it is impossible to correlate sessions.The coherence with the majority of attacks is demonstrated under the formal analysis model,which is also based on the real-or-random(ROR)session key,alongside the justifications of forward secrecy and unlinkability.The performance analysis shows that GRAA can achieve up to 87.9%reduction in computation cost and 56.7%reduction in communication overhead compared to pairing-and-group signature schemes,while lowering the latency and energy consumption of the UAVs in a congested urban setting.Generally,the suggested architecture provides a scalable,convenient,and privacy-friendly authentication system for next-generation smart transportation systems that use UAVs.展开更多
In the expanding Internet of Things(IoT)ecosystem,billions of interconnected devices exchange sensitive data,making secure and usable authentication critical.IoT devices in public or shared environments are vulnerable...In the expanding Internet of Things(IoT)ecosystem,billions of interconnected devices exchange sensitive data,making secure and usable authentication critical.IoT devices in public or shared environments are vulnerable to shoulder-surfing and video recorded observation attacks.Traditional passwords and static graphical schemes remain susceptible due to predictable patterns and direct credential entry.This study presents a novel recognition-based graphical authentication scheme that combines pass-image selection with compass direction substitution and rotation logic to resist observation-based attacks.A prototype was evaluated with 58 participants over three days.Usability metrics included registration time,login time,success rate,and error rate.Memorability and resistance to shoulder-surfing were also assessed.Results showed that login times decreased from 43.62 to 37.78 s,while success rates increased from 40%to 53%,indicating rapid adaptation.Memorability scores improved from 2.05 to 2.19 on a 3-point scale,with perfect recall for five-image passwords by Day 3.Shoulder-surfing tests recorded a 0%attacker success rate.The preliminary results suggest that the scheme offers a useful balance of usability,memorability,and resistance to single session observation attacks.Future work will explore adaptive complexity and accessibility features to further enhance secure authentication.展开更多
Meat adulteration is a significant global food safety challenge,creating a pressing need for rapid and on-site detection technologies.Herein,we present an intelligent one-pot biosensing platform termed one-pot TLAMP-P...Meat adulteration is a significant global food safety challenge,creating a pressing need for rapid and on-site detection technologies.Herein,we present an intelligent one-pot biosensing platform termed one-pot TLAMP-PfAgo assay(OTPA)that integrates the rapid amplification of turn-back loop primer-accelerated loop-mediated isothermal amplification(LAMP)(TLAMP)with the sequence-specific detection of Pyrococcus furiosus Argonaute(PfAgo).This system features a clever heat-activatable design using microcrystalline wax to spatially separate reactions within a single tube,enabling contamination-free and streamlined operation.The OTPA assay achieves sensitive and specific detection,with limits of detection as low as 3×10-4 ng/μL for pork DNA and 2×10-4 ng/μL for beef DNA within 30 min.It successfully enables duplex target identification and has been validated with commercial meat products,showing perfect concordance with standard polymerase chain reaction(PCR)-based qualitative detection.Notably,the result can be directly visualized under blue light,underscoring the substantial potential of this costeffective and simple platform for point-of-care testing(POCT)and intelligent biosensing in food safety surveillance.展开更多
The satellite-based augmentation system(SBAS)provides differential and integrity augmentation services for life safety fields of aviation and navigation.However,the signal structure of SBAS is public,which incurs a ri...The satellite-based augmentation system(SBAS)provides differential and integrity augmentation services for life safety fields of aviation and navigation.However,the signal structure of SBAS is public,which incurs a risk of spoofing attacks.To improve the anti-spoofing capability of the SBAS,European Union and the United States conduct research on navigation message authentication,and promote the standardization of SBAS message authentication.For the development of Beidou satellite-based augmentation system(BDSBAS),this paper proposes navigation message authentication based on the Chinese commercial cryptographic standards.Firstly,this paper expounds the architecture and principles of the SBAS message authentication,and then carries out the design of timed efficient streaming losstolerant authentication scheme(TESLA)and elliptic curve digital signature algorithm(ECDSA)authentication schemes based on Chinese commercial cryptographic standards,message arrangement and the design of over-the-air rekeying(OTAR)message.Finally,this paper conducts a theoretical analysis of the time between authentications(TBA)and maximum authentication latency(MAL)for L5 TESLA-I and L5 ECDSA-Q,and further simulates the reception time of OTAR message,TBA and MAL from the aspects of OTAR message weight and demodulation error rate.The simulation results can provide theoretical supports for the standardization of BDSBAS message authentication.展开更多
Driven by globalization and digitization,the Mobile Industrial Supply Chain Internet of Things(IoT)has gradually developed,utilizing mobile devices and IoT technologies to enable real-time monitoring and efficient res...Driven by globalization and digitization,the Mobile Industrial Supply Chain Internet of Things(IoT)has gradually developed,utilizing mobile devices and IoT technologies to enable real-time monitoring and efficient responses across various stages.However,with the growing demand for high-frequency data exchange,the Mobile Industrial Supply Chain IoT faces significant challenges in data security,authentication,and privacy protection.This paper proposes a security authentication scheme based on blockchain and group key management,leveraging the decentralized and tamper-resistant features of blockchain,the privacy-preserving authentication method of Zero-Knowledge Proofs(ZKP),and a hierarchical key management mechanism based on binary key trees.This approach aims to enhance the security and scalability of Mobile Industrial Supply Chain IoT.The experimental section simulates scenarios such as dynamic node addition and key updates,evaluating the performance in terms of encryption,decryption,and key management efficiency,thus demonstrating its superiority in multi-party collaborative environments.展开更多
This paper exploits multi-modal Physical(PHY)-layer features in terms of artificial fingerprint,In-phase/Quadrature(IQ)imbalance and Angle of Arrival(AoA)to propose a novel PHY-layer authentication framework for a Mil...This paper exploits multi-modal Physical(PHY)-layer features in terms of artificial fingerprint,In-phase/Quadrature(IQ)imbalance and Angle of Arrival(AoA)to propose a novel PHY-layer authentication framework for a Millimeter Wave(mmWave)Multiple-Input Multiple-Output(MIMO)Unmanned Aerial Vehicle(UAV)-enabled communication system.First,we resort to the AoA-based spatial fingerprint to effectively address the challenge of channel fingerprint instability induced by high-speed UAV mobility.To further enhance the low discriminability of hardware fingerprints caused by refined manufacturing techniques,artificial Gaussian noise is injected into the transmission signals to assist the receiver in better distinguishing between legitimate and illegitimate UAVs.Then,we jointly combine with inherent IQ imbalance and AoA features to design a hybrid authentication scheme and thus construct a multi-dimensional fingerprint space for a comprehensive characterization of UAV identities.To theoretically evaluate the effectiveness of the proposed authentication framework,the analytical closed-form expressions of performance metrics like false alarm and detection probabilities are also exactly derived based on the statistical signal processing technology and composite hypothesis testing.Finally,we provide large simulation results to validate the correctness and feasibility of the proposed theoretical models,and also discuss the relation between system security and communication service quality under different artificial fingerprint level.展开更多
With the growing deployment of unmanned aerial vehicles(UAVs)swarms in national defense,military operations,and emergency response,secure and reliable intra-swarm identity authentication has become critical for ensuri...With the growing deployment of unmanned aerial vehicles(UAVs)swarms in national defense,military operations,and emergency response,secure and reliable intra-swarm identity authentication has become critical for ensuring coordinated action and mission reliability.To address the drawbacks of public key infrastructure(PKI)based authentication in UAV swarms,namely,complex certificate management,strong dependence on centralized authorities,and authentication latency.We propose a certificateless identity authentication scheme for UAV swarms built on blockchain sharding.The scheme leverages sharding to execute authentication in parallel across multiple shards,significantly improving efficiency.Each UAV locally generates its public/private key pair and then adopts a registration-based encryption(RBE)mechanism:A registration algorithm binds the device identity to its key on the blockchain,ensuring public verifiability and immutability of identity mapping.On this basis,an authentication algorithm runs in which the initiator produces an authentication signature using a common reference string(CRS),on-chain public-key registration information,and its local private key,and the verifier rapidly validates the authentication message using the on-chain registration data and the identity of the initiator.The experimental results demonstrate that the proposed scheme achieves low-latency and high-throughput identity authentication in large-scale UAV swarm environments,providing a solid technical foundation and broad application prospects for trustworthy UAV swarm identity authentication.展开更多
Unmanned Aerial Vehicles(UAVs)in Flying Ad-Hoc Networks(FANETs)are widely used in both civilian and military fields,but they face severe security,trust,and privacy vulnerabilities due to their high mobility,dynamic to...Unmanned Aerial Vehicles(UAVs)in Flying Ad-Hoc Networks(FANETs)are widely used in both civilian and military fields,but they face severe security,trust,and privacy vulnerabilities due to their high mobility,dynamic topology,and open wireless channels.Existing security protocols for Mobile Ad-Hoc Networks(MANETs)cannot be directly applied to FANETs,as FANETs require lightweight,high real-time performance,and strong anonymity.The current FANETs security protocol cannot simultaneously meet the requirements of strong anonymity,high security,and low overhead in high dynamic and resource-constrained scenarios.To address these challenges,this paper proposes an Anonymous Authentication and Key Exchange Protocol(AAKE-OWA)for UAVs in FANETs based on OneWay Accumulators(OWA).During the UAV registration phase,the Key Management Center(KMC)generates an identity ticket for each UAV using OWA and transmits it securely to the UAV’s on-board tamper-proof module.In the key exchange phase,UAVs generate temporary authentication tickets with random numbers and compute the same session key leveraging the quasi-commutativity of OWA.For mutual anonymous authentication,UAVs encrypt random numbers with the session key and verify identities by comparing computed values with authentication values.Formal analysis using the Scyther tool confirms that the protocol resists identity spoofing,man-in-the-middle,and replay attacks.Through Burrows Abadi Needham(BAN)logic proof,it achieves mutual anonymity,prevents simulation and physical capture attacks,and ensures secure connectivity of 1.Experimental comparisons with existing protocols prove that the AAKE-OWA protocol has lower computational overhead,communication overhead,and storage overhead,making it more suitable for resource-constrained FANET scenarios.Performance comparison experiments show that,compared with other schemes,this scheme only requires 8 one-way accumulator operations and 4 symmetric encryption/decryption operations,with a total computational overhead as low as 2.3504 ms,a communication overhead of merely 1216 bits,and a storage overhead of 768 bits.We have achieved a reduction in computational costs from 6.3%to 90.3%,communication costs from 5.0%to 69.1%,and overall storage costs from 33%to 68%compared to existing solutions.It can meet the performance requirements of lightweight,real-time,and anonymity for unmanned aerial vehicles(UAVs)networks.展开更多
Cyber-criminals target smart connected devices for spyware distribution and security breaches,but existing Internet of Things(IoT)security standards are insufficient.Major IoT industry players prioritize market share ...Cyber-criminals target smart connected devices for spyware distribution and security breaches,but existing Internet of Things(IoT)security standards are insufficient.Major IoT industry players prioritize market share over security,leading to insecure smart products.Traditional host-based protection solutions are less effective due to limited resources.Overcoming these challenges and enhancing the security of IoT Devices requires a security design at the network level that uses lightweight cryptographic parameters.In order to handle control,administration,and security concerns in traditional networking,the Gateway Node offers a contemporary networking architecture.By managing all network-level computations and complexity,the Gateway Node relieves IoT devices of these responsibilities.In this study,we introduce a novel privacy-preserving security architecture for gateway-node smart homes.Subsequently,we develop Smart Homes,An Efficient,Anonymous,and Robust Authentication Scheme(EARAS)based on the foundational principles of this security architecture.Furthermore,we formally examine the security characteristics of our suggested protocol that makes use of methodology such as ProVerif,supplemented by an informal analysis of security.Lastly,we conduct performance evaluations and comparative analyses to assess the efficacy of our scheme.Performance analysis shows that EARAS achieves up to 30%to 54%more efficient than most protocols and lower computation cost compared to Banerjee et al.’s scheme,and significantly reduces communication overhead compared to other recent protocols,while ensuring comprehensive security.Our objective is to provide robust security measures for smart homes while addressing resource constraints and preserving user privacy.展开更多
With the widespread adoption of web applications and cloud services,the OAuth 2.0-based OpenID Connect(OIDC)Single Sign-on(SSO)protocol has become the core of modern digital identity authentication.Although the OIDC p...With the widespread adoption of web applications and cloud services,the OAuth 2.0-based OpenID Connect(OIDC)Single Sign-on(SSO)protocol has become the core of modern digital identity authentication.Although the OIDC protocol itself has strict security specifications,its implementation in real-world web frameworks can introduce critical vulnerabilities,particularly the improper omission of the state parameter,which leads to severe authentication forgery risks.Existing research often overlooks these implementation-level flaws,especially from a formal analysis perspective.This paper addresses this gap by formally analyzing the authentication forgery attack resulting from the missing state parameter.We construct a high-fidelity web framework model and,using the Tamarin formal analysis tool,systematically analyze the flawed OIDC implementation.Specifically,we demonstrate an attack path where cross-site request forgery is leveraged as a vector to deceive the relying party,ultimately achieving identity binding forgery—linking the attacker’s identity to the victim’s session.In response to this forgery vulnerability,this article proposes and formally verifies corresponding patches to successfully defend against such attacks.Finally,this paper provides concrete guidance for developers.This research,through formal methods,characterizes a replicable authentication forgery pattern within modern web architectures,providing a robust theoretical and practical foundation for hardening SSO systems against such advanced forgery threats.展开更多
The ubiquitous adoption of mobile devices as essential platforms for sensitive data transmission has heightened the demand for secure client-server communication.Although various authentication and key agreement proto...The ubiquitous adoption of mobile devices as essential platforms for sensitive data transmission has heightened the demand for secure client-server communication.Although various authentication and key agreement protocols have been developed,current approaches are constrained by homogeneous cryptosystem frameworks,namely public key infrastructure(PKI),identity-based cryptography(IBC),or certificateless cryptography(CLC),each presenting limitations in client-server architectures.Specifically,PKI incurs certificate management overhead,IBC introduces key escrow risks,and CLC encounters cross-system interoperability challenges.To overcome these shortcomings,this study introduces a heterogeneous signcryption-based authentication and key agreement protocol that synergistically integrates IBC for client operations(eliminating PKI’s certificate dependency)with CLC for server implementation(mitigating IBC’s key escrow issue while preserving efficiency).Rigorous security analysis under the mBR(modified Bellare-Rogaway)model confirms the protocol’s resistance to adaptive chosen-ciphertext attacks.Quantitative comparisons demonstrate that the proposed protocol achieves 10.08%–71.34%lower communication overhead than existing schemes across multiple security levels(80-,112-,and 128-bit)compared to existing protocols.展开更多
Quantum Key Distribution(QKD)ensures secure key establishment through the principles of quantum mechanics;however,its effectiveness in practice hinges on dependable identity verification via classical channels during ...Quantum Key Distribution(QKD)ensures secure key establishment through the principles of quantum mechanics;however,its effectiveness in practice hinges on dependable identity verification via classical channels during the post-processing phase.Current QKD implementations typically depend on pre-existing symmetric-key authentication,which suffers from limited scalability and complicated key management in extensive networks.Authentication methods utilizing post-quantum cryptography(PQC)signatures,based on complex mathematical assumptions,introduce extra and uncertain security dependencies,potentially compromising the security model integrity that QKD aims to maintain.This paper explores the application of hash-based signatures(HBS)for identity verification in the post-processing of QKD.HBS methods derive their security from cryptographic hash functions,which are integral to QKD protocols,allowing for scalable public-key-style authentication without the need for new computational assumptions.A detailed authentication framework is proposed,incorporating HBS-based verification into all essential phases of QKD post-processing,such as mutual certificate validation,basis sifting,parameter estimation,error correction verification,and privacy amplification.Security assessments indicate that the suggested framework maintains the security model integrity of QKD by relying cryptographically solely on the collision resistance of hash functions—without introducing new computational assumptions.At the system deployment level,it adheres to standard PKI trust assumptions which are necessary for public-key-style authentication and consistent with practical QKD network operations.Additionally,system-level evaluations affirm the scalability and practical applicability of HBS-based authentication,while also addressing the operational trade-offs among various HBS approaches in realistic QKD deployment contexts.展开更多
With the rapid development of the Internet of Things(IoT),the widespread adoption of applications such as smart homes and industrial IoT has raised the demand for secure authentication and key agreement among resource...With the rapid development of the Internet of Things(IoT),the widespread adoption of applications such as smart homes and industrial IoT has raised the demand for secure authentication and key agreement among resource-constrained devices over open communication channels.Traditional authentication protocols often rely on centralized servers for key distribution,which results in high communication overhead and exposes systems to single-point-of-failure risks.Moreover,IoT devices are typically constrained in computational resources and are vulnerable to hardware cloning.These limitations necessitate lightweight yet robust security mechanisms.To address these challenges,we propose a lightweight peer-to-peer authentication protocol based on Physically Unclonable Function(PUF)and Multiple Reference Fuzzy Extractor(MRFE).The proposed protocol enables direct mutual authentication and key agreement between IoT devices without the participation of a trusted third-party server.Formal security analysis,along with evaluations of computation and communication costs,demonstrates that the protocol achieves strong security guarantees while maintaining high efficiency.Therefore,the proposed protocol is well-suited for lightweight peer-to-peer authentication scenarios in IoT environments.展开更多
This work evaluates an architecture for decentralized authentication of Internet of Things(IoT)devices in Low Earth Orbit(LEO)satellite networks using IOTA Identity technology.To the best of our knowledge,it is the fi...This work evaluates an architecture for decentralized authentication of Internet of Things(IoT)devices in Low Earth Orbit(LEO)satellite networks using IOTA Identity technology.To the best of our knowledge,it is the first proposal to integrate IOTA’s Directed Acyclic Graph(DAG)-based identity framework into satellite IoT environments,enabling lightweight and distributed authentication under intermittent connectivity.The system leverages Decentralized Identifiers(DIDs)and Verifiable Credentials(VCs)over the Tangle,eliminating the need for mining and sequential blocks.An identity management workflow is implemented that supports the creation,validation,deactivation,and reactivation of IoT devices,and is experimentally validated on the Shimmer Testnet.Three metrics are defined and measured:resolution time,deactivation time,and reactivation time.To improve robustness,an algorithmic optimization is introduced that minimizes communication overhead and reduces latency during deactivation.The experimental results are compared with orbital simulations of satellite revisit times to assess operational feasibility.Unlike blockchain-based approaches,which typically suffer from high confirmation delays and scalability constraints,the proposed DAG architecture provides fast,cost-free operations suitable for resource-constrained IoT devices.The results show that authentication can be efficiently performed within satellite connectivity windows,positioning IOTA Identity as a viable solution for secure and scalable IoT authentication in LEO satellite networks.展开更多
Food fraud is an increasingly prevalent deliberate act of deception for profit.Hence,it is highly necessary to develop robust analytical methods to assess the authenticity of foods.In recent years,the geographical ori...Food fraud is an increasingly prevalent deliberate act of deception for profit.Hence,it is highly necessary to develop robust analytical methods to assess the authenticity of foods.In recent years,the geographical origin authenticity of fruits has attracted considerable public concern.The geographical origin of fruit is generally determined based on specific indicators such as elements,stable isotopes,and metabolites.Many studies have demonstrated that mineral elements and stable isotope ratios are effective indicators for geographical origin authentication as they are directly related to the geographical environment.Other techniques,such as spectroscopy and chromatography,also exhibit promising potential for fruit origin discrimination and authenticity assessment.Omics technologies have emerged as a key approach for authenticating the geographical origin of fruit.The integration of instrumental analysis techniques with machine learning enables highprecision discrimination of fruit geographical origin,and the growing trend toward combining multiple analytical techniques further enhances identification accuracy.Commonly used methods for geographical origin authentication include linear techniques such as PCA,PLS-DA,and LDA.Machine learning algorithms,including SVM,RF,and ANN,have also been applied to identify fruit origin with high accuracy.Future developments in this field should prioritize the consideration of agricultural practices to ensure reliable and practical authentication.展开更多
To ensure the access security of 6G,physical-layer authentication(PLA)leverages the randomness and space-time-frequency uniqueness of the channel to provide unique identity signatures for transmitters.Furthermore,the ...To ensure the access security of 6G,physical-layer authentication(PLA)leverages the randomness and space-time-frequency uniqueness of the channel to provide unique identity signatures for transmitters.Furthermore,the introduction of artificial intelligence(AI)facilitates the learning of the distribution characteristics of channel fingerprints,effectively addressing the uncertainties and unknown dynamic challenges in wireless link modeling.This paper reviews representative AI-enabled PLA schemes and proposes a graph neural network(GNN)-based PLA approach in response to the challenges existing methods face in identifying mobile users.Simulation results demonstrate that the proposed method outperforms six baseline schemes in terms of authentication accuracy.Furthermore,this paper outlines the future development directions of PLA.展开更多
Pre-Authentication and Post-Connection(PAPC)plays a crucial role in realizing the Zero Trust security model by ensuring that access to network resources is granted only after successful authentication.While earlier ap...Pre-Authentication and Post-Connection(PAPC)plays a crucial role in realizing the Zero Trust security model by ensuring that access to network resources is granted only after successful authentication.While earlier approaches such as Port Knocking(PK)and Single Packet Authorization(SPA)introduced pre-authentication concepts,they suffer from limitations including plaintext communication,protocol dependency,reliance on dedicated clients,and inefficiency under modern network conditions.These constraints hinder their applicability in emerging distributed and resource-constrained environments such as AIoT and browser-based systems.To address these challenges,this study proposes a novel port-sequence-based PAPC scheme structured as a modular model comprising a client,server,and ephemeral Key Management System(KMS).The system employs the Advanced Encryption Standard(AES-128)to protect message confidentiality and uses a Hash-Based Message Authentication Code(HMAC-SHA256)to ensure integrity.Authentication messages are securely fragmented and mapped to destination port numbers using a signature-based avoidance algorithm,which prevents collisions with unsafe or reserved port ranges.The server observes incoming port sequences,retrieves the necessary keys from the KMS,reconstructs and verifies the encrypted data,and conditionally updates firewall policies.Unlike SPA,which requires decrypting all incoming payloads and imposes server-side overhead,the proposed system verifies only port-derived fragments,significantly reducing computational burden.Furthermore,it eliminates the need for raw socket access or custom clients,supporting browser-based operation and enabling protocol-independent deployment.Through a functional web-based prototype and emulated testing,the system achieved an F1-score exceeding 95%in detecting unauthorized access while maintaining low resource overhead.Although port sequence generation introduces some client-side cost,it remains lightweight and scalable.By tightly integrating lightweight cryptographic algorithms with a transport-layer communication model,this work presents a conceptually validated architecture that contributes a novel direction for interoperable and scalable Zero Trust enforcement in future network ecosystems.展开更多
Machine-to-machine (M2M) communication networks consist of resource-constrained autonomous devices, also known as autonomous Internet of things (IoTs) or machine-type communication devices (MTCDs) which act as a backb...Machine-to-machine (M2M) communication networks consist of resource-constrained autonomous devices, also known as autonomous Internet of things (IoTs) or machine-type communication devices (MTCDs) which act as a backbone for Industrial IoT, smart cities, and other autonomous systems. Due to the limited computing and memory capacity, these devices cannot maintain strong security if conventional security methods are applied such as heavy encryption. This article proposed a novel lightweight mutual authentication scheme including elliptic curve cryptography (ECC) driven end-to-end encryption through curve25519 such as (i): efficient end-to-end encrypted communication with pre-calculation strategy using curve25519;and (ii): elliptic curve Diffie-Hellman (ECDH) based mutual authentication technique through a novel lightweight hash function. The proposed scheme attempts to efficiently counter all known perception layer security threats. Moreover, the pre-calculated key generation strategy resulted in cost-effective encryption with 192-bit curve security. It showed comparative efficiency in key strength, and curve strength compared with similar authentication schemes in terms of computational and memory cost, communication performance and encryption robustness.展开更多
The Internet of Healthcare Things(IoHT)marks a significant breakthrough in modern medicine by enabling a new era of healthcare services.IoHT supports real-time,continuous,and personalized monitoring of patients’healt...The Internet of Healthcare Things(IoHT)marks a significant breakthrough in modern medicine by enabling a new era of healthcare services.IoHT supports real-time,continuous,and personalized monitoring of patients’health conditions.However,the security of sensitive data exchanged within IoHT remains a major concern,as the widespread connectivity and wireless nature of these systems expose them to various vulnerabilities.Potential threats include unauthorized access,device compromise,data breaches,and data alteration,all of which may compromise the confidentiality and integrity of patient information.In this paper,we provide an in-depth security analysis of LAP-IoHT,an authentication scheme designed to ensure secure communication in Internet of Healthcare Things environments.This analysis reveals several vulnerabilities in the LAP-IoHT protocol,namely its inability to resist various attacks,including user impersonation and privileged insider threats.To address these issues,we introduce LSAP-IoHT,a secure and lightweight authentication protocol for the Internet of Healthcare Things(IoHT).This protocol leverages Elliptic Curve Cryptography(ECC),Physical Unclonable Functions(PUFs),and Three-Factor Authentication(3FA).Its security is validated through both informal analysis and formal verification using the Scyther tool and the Real-Or-Random(ROR)model.The results demonstrate strong resistance against man-in-the-middle(MITM)attacks,replay attacks,identity spoofing,stolen smart device attacks,and insider threats,while maintaining low computational and communication costs.展开更多
摘要With the increasing connectivity and intelligence of Internet-of-Things(IoT)devices,which interface with numerous aspects of our daily lives,security remains a major concern for IoT devices deployed in e-healthcare systems.The existing solutions demonstrate that authentication of IoT devices across all domains,especially in healthcare,poses significant vulnerabilities,including side-channel,insider,and replay attacks.Alternatively,it is not feasible for resource-constrained IoT devices due to the computational,communicational,and space overheads of modular exponentiation or bilinear pairing,or because it requires four to five round-trips for authentication.The rapid growth of IoT in the e-healthcare sector is expected to cross“50 billion”or more by 2030,highlighting desynchronization,man-in-the-middle(MITM)attacks,and unavailability flaws in e-healthcare.If the aforementioned security concerns are not adequately addressed,they will,in turn,escalate and lead to severe consequences.Therefore,this article introduces a security protocol for an e-healthcare system to ensure secure communication for the voluminous data collected by IoT devices and to transfer it to the cloud safely.The proof of correctness and robustness of the proposed protocol was conducted using BAN(Burrows-Abadi-Needham)logic,the Real-Or-Random(ROR)model,the ProVerif verification toolkit,and pragmatic discussions.The performance analysis section was addressed by measuring several key metrics,including communication,computation,space,and energy consumption,along with scalability.The results obtained demonstrate that the communication cost may be reduced by up to 76%,the computation cost by up to 92%,and the energy consumption by up to 31%.
基金supported by the Ministry of Trade,Industry and Energy and implemented by the Korea Institute forAdvancement of Technology.The project includes(Development of an International Standardization and Sustainability Integration Framework for AI Industry Internalization and Global Competitiveness Enhancement(RS-2025-07372968)).
摘要Unmanned aerial vehicles(UAVs)are also increasingly becoming more often in the transportation infrastructure of smart cities,so that they can successfully achieve real-time observation of traffic,emergency coordination,and two-way communication relaying.However,the security and privacy risks arising in open,highly mobile intelligent transportation systems(ITS)enabled by UAVs are critical,as they pose threats of impersonation,replay,Sybil,and tracking attacks.Secondly,standard static authentication mechanisms are unable to support dynamic risk environments and excessive resource consumption on UAV platforms with limited capacity.To address these challenges,this study introduces a Generative-AI-assisted Risk-Adaptive Authentication(GRAA)system that modulates the intensity of the authentication process based on risk levels identified by mobility,contextual awareness,and the environment.The framework contains unlinkable pseudonymous credentials and,unlike the accumulator-based revocation scheme and AI-based trust evaluation,it is impossible to correlate sessions.The coherence with the majority of attacks is demonstrated under the formal analysis model,which is also based on the real-or-random(ROR)session key,alongside the justifications of forward secrecy and unlinkability.The performance analysis shows that GRAA can achieve up to 87.9%reduction in computation cost and 56.7%reduction in communication overhead compared to pairing-and-group signature schemes,while lowering the latency and energy consumption of the UAVs in a congested urban setting.Generally,the suggested architecture provides a scalable,convenient,and privacy-friendly authentication system for next-generation smart transportation systems that use UAVs.
基金supported by the Ministry of Higher Education(MoHE),Malaysia through the Fundamental Research Grant Scheme(FRGS/1/2023/ICT03/UTAR/02/1)。
摘要In the expanding Internet of Things(IoT)ecosystem,billions of interconnected devices exchange sensitive data,making secure and usable authentication critical.IoT devices in public or shared environments are vulnerable to shoulder-surfing and video recorded observation attacks.Traditional passwords and static graphical schemes remain susceptible due to predictable patterns and direct credential entry.This study presents a novel recognition-based graphical authentication scheme that combines pass-image selection with compass direction substitution and rotation logic to resist observation-based attacks.A prototype was evaluated with 58 participants over three days.Usability metrics included registration time,login time,success rate,and error rate.Memorability and resistance to shoulder-surfing were also assessed.Results showed that login times decreased from 43.62 to 37.78 s,while success rates increased from 40%to 53%,indicating rapid adaptation.Memorability scores improved from 2.05 to 2.19 on a 3-point scale,with perfect recall for five-image passwords by Day 3.Shoulder-surfing tests recorded a 0%attacker success rate.The preliminary results suggest that the scheme offers a useful balance of usability,memorability,and resistance to single session observation attacks.Future work will explore adaptive complexity and accessibility features to further enhance secure authentication.
基金supported by the Sichuan Science and Technology Program(No.2024YFFK0280)the Natural Science Foundation of Sichuan Province(No.2024NSFSC0657)+2 种基金the National Natural Science Foundation of China(No.82402725)the Key Research Project of Clinical Medical College&Affiliated Hospital of Chengdu University(No.Y202403)the 2024 Undergraduate Innovation Training Program Incubation and Cultivation Project(No.S202411079085),China。
摘要Meat adulteration is a significant global food safety challenge,creating a pressing need for rapid and on-site detection technologies.Herein,we present an intelligent one-pot biosensing platform termed one-pot TLAMP-PfAgo assay(OTPA)that integrates the rapid amplification of turn-back loop primer-accelerated loop-mediated isothermal amplification(LAMP)(TLAMP)with the sequence-specific detection of Pyrococcus furiosus Argonaute(PfAgo).This system features a clever heat-activatable design using microcrystalline wax to spatially separate reactions within a single tube,enabling contamination-free and streamlined operation.The OTPA assay achieves sensitive and specific detection,with limits of detection as low as 3×10-4 ng/μL for pork DNA and 2×10-4 ng/μL for beef DNA within 30 min.It successfully enables duplex target identification and has been validated with commercial meat products,showing perfect concordance with standard polymerase chain reaction(PCR)-based qualitative detection.Notably,the result can be directly visualized under blue light,underscoring the substantial potential of this costeffective and simple platform for point-of-care testing(POCT)and intelligent biosensing in food safety surveillance.
基金supported by National Natural Science Foundation of China:Space-based occultation detection with ground-based GNSS atmospheric horizontal gradient model(41904033).
摘要The satellite-based augmentation system(SBAS)provides differential and integrity augmentation services for life safety fields of aviation and navigation.However,the signal structure of SBAS is public,which incurs a risk of spoofing attacks.To improve the anti-spoofing capability of the SBAS,European Union and the United States conduct research on navigation message authentication,and promote the standardization of SBAS message authentication.For the development of Beidou satellite-based augmentation system(BDSBAS),this paper proposes navigation message authentication based on the Chinese commercial cryptographic standards.Firstly,this paper expounds the architecture and principles of the SBAS message authentication,and then carries out the design of timed efficient streaming losstolerant authentication scheme(TESLA)and elliptic curve digital signature algorithm(ECDSA)authentication schemes based on Chinese commercial cryptographic standards,message arrangement and the design of over-the-air rekeying(OTAR)message.Finally,this paper conducts a theoretical analysis of the time between authentications(TBA)and maximum authentication latency(MAL)for L5 TESLA-I and L5 ECDSA-Q,and further simulates the reception time of OTAR message,TBA and MAL from the aspects of OTAR message weight and demodulation error rate.The simulation results can provide theoretical supports for the standardization of BDSBAS message authentication.
基金supported in part by the National Natural Science Foundation of China(62332004,72304121)part by the Sichuan Provincial Natural Science Foundation for Distinguished Young Scholars(2023NSFSC1963)。
摘要Driven by globalization and digitization,the Mobile Industrial Supply Chain Internet of Things(IoT)has gradually developed,utilizing mobile devices and IoT technologies to enable real-time monitoring and efficient responses across various stages.However,with the growing demand for high-frequency data exchange,the Mobile Industrial Supply Chain IoT faces significant challenges in data security,authentication,and privacy protection.This paper proposes a security authentication scheme based on blockchain and group key management,leveraging the decentralized and tamper-resistant features of blockchain,the privacy-preserving authentication method of Zero-Knowledge Proofs(ZKP),and a hierarchical key management mechanism based on binary key trees.This approach aims to enhance the security and scalability of Mobile Industrial Supply Chain IoT.The experimental section simulates scenarios such as dynamic node addition and key updates,evaluating the performance in terms of encryption,decryption,and key management efficiency,thus demonstrating its superiority in multi-party collaborative environments.
基金supported in part by the National Key R&D Program of China under Grant 2023YFB3107500in part by the National Natural Science Foundation of China under Grant 62272241+1 种基金in part by the State Key Laboratory of Integrated Services Networks(Xidian University),under Grant ISN24-18in part by the Nanjing University of Posts and Telecommunications Scientific Research Foundation under Grant NY221122。
摘要This paper exploits multi-modal Physical(PHY)-layer features in terms of artificial fingerprint,In-phase/Quadrature(IQ)imbalance and Angle of Arrival(AoA)to propose a novel PHY-layer authentication framework for a Millimeter Wave(mmWave)Multiple-Input Multiple-Output(MIMO)Unmanned Aerial Vehicle(UAV)-enabled communication system.First,we resort to the AoA-based spatial fingerprint to effectively address the challenge of channel fingerprint instability induced by high-speed UAV mobility.To further enhance the low discriminability of hardware fingerprints caused by refined manufacturing techniques,artificial Gaussian noise is injected into the transmission signals to assist the receiver in better distinguishing between legitimate and illegitimate UAVs.Then,we jointly combine with inherent IQ imbalance and AoA features to design a hybrid authentication scheme and thus construct a multi-dimensional fingerprint space for a comprehensive characterization of UAV identities.To theoretically evaluate the effectiveness of the proposed authentication framework,the analytical closed-form expressions of performance metrics like false alarm and detection probabilities are also exactly derived based on the statistical signal processing technology and composite hypothesis testing.Finally,we provide large simulation results to validate the correctness and feasibility of the proposed theoretical models,and also discuss the relation between system security and communication service quality under different artificial fingerprint level.
基金supported by the National Natural Science Foundation of China under Grant No.62472075the Innovation Theory and Technology Group Fund of the Southwest China Institute of Electronic Technology under Grant No.2024jsq0207.
摘要With the growing deployment of unmanned aerial vehicles(UAVs)swarms in national defense,military operations,and emergency response,secure and reliable intra-swarm identity authentication has become critical for ensuring coordinated action and mission reliability.To address the drawbacks of public key infrastructure(PKI)based authentication in UAV swarms,namely,complex certificate management,strong dependence on centralized authorities,and authentication latency.We propose a certificateless identity authentication scheme for UAV swarms built on blockchain sharding.The scheme leverages sharding to execute authentication in parallel across multiple shards,significantly improving efficiency.Each UAV locally generates its public/private key pair and then adopts a registration-based encryption(RBE)mechanism:A registration algorithm binds the device identity to its key on the blockchain,ensuring public verifiability and immutability of identity mapping.On this basis,an authentication algorithm runs in which the initiator produces an authentication signature using a common reference string(CRS),on-chain public-key registration information,and its local private key,and the verifier rapidly validates the authentication message using the on-chain registration data and the identity of the initiator.The experimental results demonstrate that the proposed scheme achieves low-latency and high-throughput identity authentication in large-scale UAV swarm environments,providing a solid technical foundation and broad application prospects for trustworthy UAV swarm identity authentication.
基金supported in part by National Natural Science Foundation of China(under Grant 61902163)the Jiangsu“Qing Lan Project”,Natural Science Foundation of the Jiangsu Higher Education Institutions of China(Major Research Project:23KJA520007)Postgraduate Research&Practice Innovation Program of Jiangsu Province(No.SJCX25_1303).
摘要Unmanned Aerial Vehicles(UAVs)in Flying Ad-Hoc Networks(FANETs)are widely used in both civilian and military fields,but they face severe security,trust,and privacy vulnerabilities due to their high mobility,dynamic topology,and open wireless channels.Existing security protocols for Mobile Ad-Hoc Networks(MANETs)cannot be directly applied to FANETs,as FANETs require lightweight,high real-time performance,and strong anonymity.The current FANETs security protocol cannot simultaneously meet the requirements of strong anonymity,high security,and low overhead in high dynamic and resource-constrained scenarios.To address these challenges,this paper proposes an Anonymous Authentication and Key Exchange Protocol(AAKE-OWA)for UAVs in FANETs based on OneWay Accumulators(OWA).During the UAV registration phase,the Key Management Center(KMC)generates an identity ticket for each UAV using OWA and transmits it securely to the UAV’s on-board tamper-proof module.In the key exchange phase,UAVs generate temporary authentication tickets with random numbers and compute the same session key leveraging the quasi-commutativity of OWA.For mutual anonymous authentication,UAVs encrypt random numbers with the session key and verify identities by comparing computed values with authentication values.Formal analysis using the Scyther tool confirms that the protocol resists identity spoofing,man-in-the-middle,and replay attacks.Through Burrows Abadi Needham(BAN)logic proof,it achieves mutual anonymity,prevents simulation and physical capture attacks,and ensures secure connectivity of 1.Experimental comparisons with existing protocols prove that the AAKE-OWA protocol has lower computational overhead,communication overhead,and storage overhead,making it more suitable for resource-constrained FANET scenarios.Performance comparison experiments show that,compared with other schemes,this scheme only requires 8 one-way accumulator operations and 4 symmetric encryption/decryption operations,with a total computational overhead as low as 2.3504 ms,a communication overhead of merely 1216 bits,and a storage overhead of 768 bits.We have achieved a reduction in computational costs from 6.3%to 90.3%,communication costs from 5.0%to 69.1%,and overall storage costs from 33%to 68%compared to existing solutions.It can meet the performance requirements of lightweight,real-time,and anonymity for unmanned aerial vehicles(UAVs)networks.
基金Deanship of Graduate Studies and Scientific Research at Qassim University for financial support(QU-APC-2025).
摘要Cyber-criminals target smart connected devices for spyware distribution and security breaches,but existing Internet of Things(IoT)security standards are insufficient.Major IoT industry players prioritize market share over security,leading to insecure smart products.Traditional host-based protection solutions are less effective due to limited resources.Overcoming these challenges and enhancing the security of IoT Devices requires a security design at the network level that uses lightweight cryptographic parameters.In order to handle control,administration,and security concerns in traditional networking,the Gateway Node offers a contemporary networking architecture.By managing all network-level computations and complexity,the Gateway Node relieves IoT devices of these responsibilities.In this study,we introduce a novel privacy-preserving security architecture for gateway-node smart homes.Subsequently,we develop Smart Homes,An Efficient,Anonymous,and Robust Authentication Scheme(EARAS)based on the foundational principles of this security architecture.Furthermore,we formally examine the security characteristics of our suggested protocol that makes use of methodology such as ProVerif,supplemented by an informal analysis of security.Lastly,we conduct performance evaluations and comparative analyses to assess the efficacy of our scheme.Performance analysis shows that EARAS achieves up to 30%to 54%more efficient than most protocols and lower computation cost compared to Banerjee et al.’s scheme,and significantly reduces communication overhead compared to other recent protocols,while ensuring comprehensive security.Our objective is to provide robust security measures for smart homes while addressing resource constraints and preserving user privacy.
基金supported by National Key Research and Development Program of China No.2023YFB2705000Blockchain System Security Key Technology Research of Henan Province Major Public Welfare Project No.201300210200National Engineering Laboratory for Big Data Distribution and Exchange Technologies.
摘要With the widespread adoption of web applications and cloud services,the OAuth 2.0-based OpenID Connect(OIDC)Single Sign-on(SSO)protocol has become the core of modern digital identity authentication.Although the OIDC protocol itself has strict security specifications,its implementation in real-world web frameworks can introduce critical vulnerabilities,particularly the improper omission of the state parameter,which leads to severe authentication forgery risks.Existing research often overlooks these implementation-level flaws,especially from a formal analysis perspective.This paper addresses this gap by formally analyzing the authentication forgery attack resulting from the missing state parameter.We construct a high-fidelity web framework model and,using the Tamarin formal analysis tool,systematically analyze the flawed OIDC implementation.Specifically,we demonstrate an attack path where cross-site request forgery is leveraged as a vector to deceive the relying party,ultimately achieving identity binding forgery—linking the attacker’s identity to the victim’s session.In response to this forgery vulnerability,this article proposes and formally verifies corresponding patches to successfully defend against such attacks.Finally,this paper provides concrete guidance for developers.This research,through formal methods,characterizes a replicable authentication forgery pattern within modern web architectures,providing a robust theoretical and practical foundation for hardening SSO systems against such advanced forgery threats.
基金supported by the Key Project of Science and Technology Research by Chongqing Education Commission under Grant KJZD-K202400610the Chongqing Natural Science Foundation General Project Grant CSTB2025NSCQ-GPX1263.
摘要The ubiquitous adoption of mobile devices as essential platforms for sensitive data transmission has heightened the demand for secure client-server communication.Although various authentication and key agreement protocols have been developed,current approaches are constrained by homogeneous cryptosystem frameworks,namely public key infrastructure(PKI),identity-based cryptography(IBC),or certificateless cryptography(CLC),each presenting limitations in client-server architectures.Specifically,PKI incurs certificate management overhead,IBC introduces key escrow risks,and CLC encounters cross-system interoperability challenges.To overcome these shortcomings,this study introduces a heterogeneous signcryption-based authentication and key agreement protocol that synergistically integrates IBC for client operations(eliminating PKI’s certificate dependency)with CLC for server implementation(mitigating IBC’s key escrow issue while preserving efficiency).Rigorous security analysis under the mBR(modified Bellare-Rogaway)model confirms the protocol’s resistance to adaptive chosen-ciphertext attacks.Quantitative comparisons demonstrate that the proposed protocol achieves 10.08%–71.34%lower communication overhead than existing schemes across multiple security levels(80-,112-,and 128-bit)compared to existing protocols.
基金supported by the Quantum Science and Technology-National Science and Technology Major Project(QNMP)under Grant Nos.2021ZD0301301,2021ZD0300705the Yunnan Provincial Key Area Science and Technology Program Project under Grant No.202502AD080015.
摘要Quantum Key Distribution(QKD)ensures secure key establishment through the principles of quantum mechanics;however,its effectiveness in practice hinges on dependable identity verification via classical channels during the post-processing phase.Current QKD implementations typically depend on pre-existing symmetric-key authentication,which suffers from limited scalability and complicated key management in extensive networks.Authentication methods utilizing post-quantum cryptography(PQC)signatures,based on complex mathematical assumptions,introduce extra and uncertain security dependencies,potentially compromising the security model integrity that QKD aims to maintain.This paper explores the application of hash-based signatures(HBS)for identity verification in the post-processing of QKD.HBS methods derive their security from cryptographic hash functions,which are integral to QKD protocols,allowing for scalable public-key-style authentication without the need for new computational assumptions.A detailed authentication framework is proposed,incorporating HBS-based verification into all essential phases of QKD post-processing,such as mutual certificate validation,basis sifting,parameter estimation,error correction verification,and privacy amplification.Security assessments indicate that the suggested framework maintains the security model integrity of QKD by relying cryptographically solely on the collision resistance of hash functions—without introducing new computational assumptions.At the system deployment level,it adheres to standard PKI trust assumptions which are necessary for public-key-style authentication and consistent with practical QKD network operations.Additionally,system-level evaluations affirm the scalability and practical applicability of HBS-based authentication,while also addressing the operational trade-offs among various HBS approaches in realistic QKD deployment contexts.
基金funded by the National Natural Science Foundation of China(62572121,U22B2026)Natural Science Foundation of Xizang(XZ202501ZY0094)+1 种基金Frontier Technology R&D Program of Jiangsu(BF2025067)Open Foundation of Key Laboratory of Cyberspace Security,Ministry of Education of China and Henan Key Laboratory of Network Cryptography(No.KLCS20240301).
摘要With the rapid development of the Internet of Things(IoT),the widespread adoption of applications such as smart homes and industrial IoT has raised the demand for secure authentication and key agreement among resource-constrained devices over open communication channels.Traditional authentication protocols often rely on centralized servers for key distribution,which results in high communication overhead and exposes systems to single-point-of-failure risks.Moreover,IoT devices are typically constrained in computational resources and are vulnerable to hardware cloning.These limitations necessitate lightweight yet robust security mechanisms.To address these challenges,we propose a lightweight peer-to-peer authentication protocol based on Physically Unclonable Function(PUF)and Multiple Reference Fuzzy Extractor(MRFE).The proposed protocol enables direct mutual authentication and key agreement between IoT devices without the participation of a trusted third-party server.Formal security analysis,along with evaluations of computation and communication costs,demonstrates that the protocol achieves strong security guarantees while maintaining high efficiency.Therefore,the proposed protocol is well-suited for lightweight peer-to-peer authentication scenarios in IoT environments.
基金This work is part of the‘Intelligent and Cyber-Secure Platform for Adaptive Optimization in the Simultaneous Operation of Heterogeneous Autonomous Robots(PICRAH4.0)’with reference MIG-20232082,funded by MCIN/AEI/10.13039/501100011033supported by the Universidad Internacional de La Rioja(UNIR)through the Precompetitive Research Project entitled“Nuevos Horizontes en Internet de las Cosas y NewSpace(NEWIOT)”,reference PP-2024-13,funded under the 2024 Call for Research Projects.
摘要This work evaluates an architecture for decentralized authentication of Internet of Things(IoT)devices in Low Earth Orbit(LEO)satellite networks using IOTA Identity technology.To the best of our knowledge,it is the first proposal to integrate IOTA’s Directed Acyclic Graph(DAG)-based identity framework into satellite IoT environments,enabling lightweight and distributed authentication under intermittent connectivity.The system leverages Decentralized Identifiers(DIDs)and Verifiable Credentials(VCs)over the Tangle,eliminating the need for mining and sequential blocks.An identity management workflow is implemented that supports the creation,validation,deactivation,and reactivation of IoT devices,and is experimentally validated on the Shimmer Testnet.Three metrics are defined and measured:resolution time,deactivation time,and reactivation time.To improve robustness,an algorithmic optimization is introduced that minimizes communication overhead and reduces latency during deactivation.The experimental results are compared with orbital simulations of satellite revisit times to assess operational feasibility.Unlike blockchain-based approaches,which typically suffer from high confirmation delays and scalability constraints,the proposed DAG architecture provides fast,cost-free operations suitable for resource-constrained IoT devices.The results show that authentication can be efficiently performed within satellite connectivity windows,positioning IOTA Identity as a viable solution for secure and scalable IoT authentication in LEO satellite networks.
基金supported by the Shandong Key R&D Plan(Agricultural Variety Project),China(2022LZGCQY008)the National Program for Quality and Safety Risk Assessment of Agricultural Products of China(GJFP20230210)+1 种基金the Research Foundation for Evaluation of Quality Specification&Nutritional Function of Agricultural Products,China(PJ2023019)the Scientific Research Foundation for High Level Talents of Qingdao Agricultural University,China(6651120015)。
摘要Food fraud is an increasingly prevalent deliberate act of deception for profit.Hence,it is highly necessary to develop robust analytical methods to assess the authenticity of foods.In recent years,the geographical origin authenticity of fruits has attracted considerable public concern.The geographical origin of fruit is generally determined based on specific indicators such as elements,stable isotopes,and metabolites.Many studies have demonstrated that mineral elements and stable isotope ratios are effective indicators for geographical origin authentication as they are directly related to the geographical environment.Other techniques,such as spectroscopy and chromatography,also exhibit promising potential for fruit origin discrimination and authenticity assessment.Omics technologies have emerged as a key approach for authenticating the geographical origin of fruit.The integration of instrumental analysis techniques with machine learning enables highprecision discrimination of fruit geographical origin,and the growing trend toward combining multiple analytical techniques further enhances identification accuracy.Commonly used methods for geographical origin authentication include linear techniques such as PCA,PLS-DA,and LDA.Machine learning algorithms,including SVM,RF,and ANN,have also been applied to identify fruit origin with high accuracy.Future developments in this field should prioritize the consideration of agricultural practices to ensure reliable and practical authentication.
摘要To ensure the access security of 6G,physical-layer authentication(PLA)leverages the randomness and space-time-frequency uniqueness of the channel to provide unique identity signatures for transmitters.Furthermore,the introduction of artificial intelligence(AI)facilitates the learning of the distribution characteristics of channel fingerprints,effectively addressing the uncertainties and unknown dynamic challenges in wireless link modeling.This paper reviews representative AI-enabled PLA schemes and proposes a graph neural network(GNN)-based PLA approach in response to the challenges existing methods face in identifying mobile users.Simulation results demonstrate that the proposed method outperforms six baseline schemes in terms of authentication accuracy.Furthermore,this paper outlines the future development directions of PLA.
基金supported by Institute for Information&Communications Technology Planning&Evaluation(IITP)grant funded by the Korea government(MSIT)(No.RS-2022-II221200)Convergence Security Core Talent Training Business(Chungnam National University).
摘要Pre-Authentication and Post-Connection(PAPC)plays a crucial role in realizing the Zero Trust security model by ensuring that access to network resources is granted only after successful authentication.While earlier approaches such as Port Knocking(PK)and Single Packet Authorization(SPA)introduced pre-authentication concepts,they suffer from limitations including plaintext communication,protocol dependency,reliance on dedicated clients,and inefficiency under modern network conditions.These constraints hinder their applicability in emerging distributed and resource-constrained environments such as AIoT and browser-based systems.To address these challenges,this study proposes a novel port-sequence-based PAPC scheme structured as a modular model comprising a client,server,and ephemeral Key Management System(KMS).The system employs the Advanced Encryption Standard(AES-128)to protect message confidentiality and uses a Hash-Based Message Authentication Code(HMAC-SHA256)to ensure integrity.Authentication messages are securely fragmented and mapped to destination port numbers using a signature-based avoidance algorithm,which prevents collisions with unsafe or reserved port ranges.The server observes incoming port sequences,retrieves the necessary keys from the KMS,reconstructs and verifies the encrypted data,and conditionally updates firewall policies.Unlike SPA,which requires decrypting all incoming payloads and imposes server-side overhead,the proposed system verifies only port-derived fragments,significantly reducing computational burden.Furthermore,it eliminates the need for raw socket access or custom clients,supporting browser-based operation and enabling protocol-independent deployment.Through a functional web-based prototype and emulated testing,the system achieved an F1-score exceeding 95%in detecting unauthorized access while maintaining low resource overhead.Although port sequence generation introduces some client-side cost,it remains lightweight and scalable.By tightly integrating lightweight cryptographic algorithms with a transport-layer communication model,this work presents a conceptually validated architecture that contributes a novel direction for interoperable and scalable Zero Trust enforcement in future network ecosystems.
摘要Machine-to-machine (M2M) communication networks consist of resource-constrained autonomous devices, also known as autonomous Internet of things (IoTs) or machine-type communication devices (MTCDs) which act as a backbone for Industrial IoT, smart cities, and other autonomous systems. Due to the limited computing and memory capacity, these devices cannot maintain strong security if conventional security methods are applied such as heavy encryption. This article proposed a novel lightweight mutual authentication scheme including elliptic curve cryptography (ECC) driven end-to-end encryption through curve25519 such as (i): efficient end-to-end encrypted communication with pre-calculation strategy using curve25519;and (ii): elliptic curve Diffie-Hellman (ECDH) based mutual authentication technique through a novel lightweight hash function. The proposed scheme attempts to efficiently counter all known perception layer security threats. Moreover, the pre-calculated key generation strategy resulted in cost-effective encryption with 192-bit curve security. It showed comparative efficiency in key strength, and curve strength compared with similar authentication schemes in terms of computational and memory cost, communication performance and encryption robustness.
摘要The Internet of Healthcare Things(IoHT)marks a significant breakthrough in modern medicine by enabling a new era of healthcare services.IoHT supports real-time,continuous,and personalized monitoring of patients’health conditions.However,the security of sensitive data exchanged within IoHT remains a major concern,as the widespread connectivity and wireless nature of these systems expose them to various vulnerabilities.Potential threats include unauthorized access,device compromise,data breaches,and data alteration,all of which may compromise the confidentiality and integrity of patient information.In this paper,we provide an in-depth security analysis of LAP-IoHT,an authentication scheme designed to ensure secure communication in Internet of Healthcare Things environments.This analysis reveals several vulnerabilities in the LAP-IoHT protocol,namely its inability to resist various attacks,including user impersonation and privileged insider threats.To address these issues,we introduce LSAP-IoHT,a secure and lightweight authentication protocol for the Internet of Healthcare Things(IoHT).This protocol leverages Elliptic Curve Cryptography(ECC),Physical Unclonable Functions(PUFs),and Three-Factor Authentication(3FA).Its security is validated through both informal analysis and formal verification using the Scyther tool and the Real-Or-Random(ROR)model.The results demonstrate strong resistance against man-in-the-middle(MITM)attacks,replay attacks,identity spoofing,stolen smart device attacks,and insider threats,while maintaining low computational and communication costs.