
In this paper, we substantially modify Hung et al. [1] Anonymous Multi-receiver Certificateless Encryption (AMCLE) scheme to a Multi-receiver Certificateless Signcryption (MCLS) scheme, which provides authentication and introduces public verifiability as an additional feature. We show that, as compared to existing signcryption, our scheme requires less computation for the signcryption and unsigncryption phases. Additionally, the signcryption cost is linear with the number of designated receivers, while the unsigncryption cost remains constant. We compare the results with existing single-receiver and multi-receiver signcryption schemes and show that our proposed MCLS scheme is more efficient for single and multi-receiver signcryption schemes while providing an exemption from the key escrow problem and working in certificateless public key settings.
In this article, we give an easy method to distinguish different cases of additions on Jacobians of hyperelliptic curves of genus 3. In addition, we give an advanced algorithm for group laws on Jacobian of hyperelliptic curves of genus 3. By this method, our algorithm can handle all kinds of inputs without recalling a generic algorithm. Our method is mainly based on Harley's algorithm. However, we use linear algebra over finite fields, instead of Chinese Reminder Theorem over function fields. Moreover, We did $2\times 10^{8}$ experiments in the finite field $\mathbb{F}_{2^{61}-1}$ , our algorithm runs 0.033% faster than previous works in general addition.
Encryption is a method of hiding data so that it cannot be read by anyone who does not know the key. The key is used to lock and unlock data. In a hack-prone society like ours now, this method would prevent unauthorized individuals from understanding your most protected correspondences. Hence, the development of an encryptor and decryptor is necessary. haydIT offers a user-friendly interface using intuitive icons that most of us are familiar with. Users can encrypt data, generate private key that serves as a unique lock of encryption, and send it thru any means to its recipient. Receivers can also use the same system to decrypt the data using the private key that must be manually entered to the system. haydIT prides itself in supporting the conversion of different language scriptures, providing asymmetrical way of data conversion through double encryption of randomly selected characters. It also supports multi- level of encryption and applies parity checking for data integrity. Thus, provides a virtually- pattern-less way of encoding and decoding data. The developers utilized the Spiral Methodology in developing the project. It combines the elements of both design and prototyping-in-stages, in an effort to combine advantages of top- down and bottom-up concepts. The developed PC app was tested by 15 IT Professionals based on several metrics and proved that haydIT is performing efficiently as expected with a grand mean of 4.75 interpreted as Excellent. With haydIT, everyone can guarantee that messages will be understood only by its intended reader.
Recently, American National Institute of Standards and Technology (NIST) announced Kyber as the first KEM candidate to be standardized. The security of Kyber is based on the modular learning with errors (MLWE) problem, which achieves excellent efficiency and size. This work proposes an improved key mismatch on Kyber, which can reduce the number of queries required to recover the secret key. We first transform the problem of finding a certain parameter of ciphertexts into a quantum ordered search problem. Then we give the procedure of finding the value of a parameter in the ciphertexts by the quantum method. Finally, we instantiate this attack method on Kyber512, Kyber768 and Kyber1024. Compared with the existing attack algorithm, our improved attack reduces the number of queries for Kyber512, Kyber768 and Kyber1024 by 63%, 59% and 45%, respectively.
Users can compare the equality of two encryption texts encrypted by different public keys in the public key encryption with equality test (PKEET) scheme. And the encryption texts do not have to be decrypted. Actually, users may need to verify the equality of two ciphertext sets. A trivial solution using typical PKEET scheme is testing two ciphertexts respectively from two sets and repeating multiple times until all ciphertexts are tested. Obviously, the above solution not only spends a lot of time, but also discloses the equality between any two ciphertexts in the two sets. For fear of the aforementioned issue, we propose an efficient public key encryption with set equality test (PKE-SET). PKE-SET does not use expensive bilinear pairings. Experimental results indicate that, compared to other PKEET schemes, our PKE-SET has higher computational efficiency and only our PKE-SET does not disclose the equality between any two ciphertexts.
Long-duration flows are extended network flows in the Internet that result from various network activities such as file transfers, persistent connections, and control command transmissions. These flows are utilized by a broad range of applications in the Internet, both benign and malicious, and their management and security are crucial for the functioning of the Internet. In this study, we categorize long-duration flows into three types: control flows, mixed flows, and information flows, based on their purpose for existence. Subsequently, features are extracted based on three characteristics: flow, time series, and packet length. The selected features are used to construct a dataset for training a classification model. The empirical analysis of real-world traffic data from high-speed network boundaries demonstrates that the classification model is capable of accurately identifying control flows in long-duration flows and determining specific applications within them.
Dishonest majority considered in the SPDZ(the nickname of the protocol of Damgard et al. from Crypto 2012) protocols implies the impossibility of fairness(which means that corrupted parties can prevent the honest parties from learning output). The corrupted parties can learn the outputs of the honest parties and abort the protocol. Settling for the second best, there are many works focusing on the detection of the cheaters. We construct a SPDZ-like protocol which achieves fairness when at most $n/2$ parties behave maliciously and supports identifiable abort for dishonest majority. We suggest a sharing stage after the parties finish their computation. The parties share the returns of the computation in this stage. The correctness of the sharing is guaranteed by verifiable secret sharing and homomorphic signature. The honest parties can reconstruct the outputs of the cheaters in the setting of an honest majority. We can't prevent the corrupted parties from learning the outputs and aborting the protocol for dishonest majority. Therefore, the sharing stage does not harm to the honest parties. Instead, we provide the honest parties with the identities of all cheaters in this case.
Blockchain technology is moving towards multichain interconnection, i.e., various blockchains sharing data, assets and functions to collaborate. To enable different blockchains to work together, Cross-chain Data Transfer technology is significant and developing rapidly, attracting the attention of both industry and academia. This paper defines Cross-chain Data Transfer (CDT) at the level of technical goals, explains the unique importance of CDT and discuss schemes for designing CDT approaches. We collect the latest approaches that have been applied in the field and analyze their advantages and disadvantages. Moreover, we discuss future challenges and research directions, show the broad research prospects in the field of CDT technology.
This paper proposes a highly scalable dynamic cryptosystem, Modified Affine Hill Cipher (AHC-M), which effectively addresses the known vulnerabilities of the classical Hill Cipher and provides an innovative design approach to the development of modern cryptography. By analyzing the existing Hill Cipher variations, the key concepts and design principles, such as non-linear encryption, dynamic key expansion, non-square matrix algebra and dynamic cryptosystem are investigated in detail. Building on these concepts, two practical modifications are proposed that can significantly improve computational complexity and enhance security. We also propose a cryptanalysis technique by extending the chosen-plaintext attack, which can be applied to break the Affine Hill Cipher and serves as a motivation towards the proposed cryptosystem. Lastly, these concepts are generalized as the starting point for further research.
Once, system thinking was about singular systems. Today we exist in a far more complex world, with systems interacting with systems, directly or indirectly. Information security, therefore, must involve all systems in the chain. New legal European regulations such as Guidelines for Data Protection Regulation demand that the ICT/IT world must include systems outside the organizational border to be involved and accounted for under enterprise information security umbrella. Recent mega hacks analyzed in this article point to the fact that a systems thinking perspective is needed to create modern governance, risk, and compliance security model framework. This research work puts forth a conceptual model based on Viable System Model appropriate for a major global information security restructuring. A motive for VSM is grounded in that it works fine with securing modern laws like GDPR and CCPA in supporting a needed enterprise perspective.
The random number generator (RNG) plays a crucial role in modern cryptography. While true RNG (TRNG) is available, pseudo RNG (PRNG) is often preferred due to its better compatibility. However, PRNGs have long been vulnerable to the leakage of internal states, which compromises their properties of resilience, forward security, and backward security. Furthermore, this threat will become more prevalent as adversaries gain full control of the PRNG. Inspired by white-box cryptography, we aim to provide a definition of white-box PRNG that protects against the leakage of internal states. Additionally, we bind the white-box PRNG with a specific application to resist code-lifting attacks. We implement the white-box PRNG based on various types of white-box SM4 ciphers and measure their storage overhead and random number generation speed. Meanwhile, we evaluate the randomness of the generated numbers using randomness test standards, including NIST SP 800-90B and GM/T 0005–2021, and compare the testing results to the output of Linux entropy pool and OpenSSL.
Now a day, Internet Banking is a popular service for the customer of the Banks. As a convenient way of doing banking more and more customers are registering for the internet banking. The banks also getting benefits of providing services to the customer round the clock without any manual involvement of the banker. As all the services done through an automated process, the security features should be implemented properly to protect the customers for any fraudulent transactions. The system should be available round the clock and transactions should be monitors as well as the systems should also monitored for any abnormal behavior of transactions and the system. The hacker group continuously try to penetrate the system and if become successful, the bank and customer both will bear loss. for banks, if the hackers cannot be protected, the bank may go out of business. This study intends to find out the issues of different internet banking site of Bangladeshi banks and recommend the best practices for the banks to be followed to do banking business securely. This will also secure the economy of the Country as a whole, as the banking system is the key to the Financial system of a country.
Data privacy has become the center of attention to many researchers and engineers. With high speed data transmission, data privacy can be at risk. Data stream anonymization is a fairly new and effective technique that is being currently investigated. It aims to protect data from third-party attackers. A user must keep in mind that when applying anonymization on a dataset, there will be a tradeoff between data utility and the risk of data identification. I n this paper, w e propose various anonymization cores that can be used to hide the sensitive parts of the data. The hardware implementation on FPGA of these cores is also discussed. Each implementation takes into consideration the trade-off between the throughput and the power consumption in addition to the application type and specifications. The first architecture treats a simple application where two anonymization techniques are used (i.e. Perturbation and character masking). The second implementation requires more complex anonymization techniques and extends K-anonymity criteria and L-diversity for more sensitive applications where data identification is crucial. Results are compared with existing work implementations and many improvements are applied in terms of resource utilization and throughput.
The word-oriented BeepBeep stream cipher, developed by Driscoll in FSE 2002, is proposed to provide integrity and confidentiality for embedded systems. There has been no attack on BeepBeep published until now. By exploiting a weakness of the BeepBeep stream cipher during its initialization, this paper presents a key recovery attack on the BeepBeep stream cipher in the related key setting. The attack recovers the 192-bit secret key of BeepBeep with a time complexity of $2^{128}$ , requiring two related keys, $2^{32}$ chosen IVs and $2^{33}$ keystream words. This is the first cryptanalytic attack on BeepBeep which is significantly better than the exhaustive key search. The result shows that the BeepBeep stream cipher is vulnerable against the related key attack and can not provide the 192-bit security.
Protecting personal identifiable information (PII) is essential for privacy and data protection. The leakage of PII can lead to privacy and safety issues like personal embarrassment, workplace discrimination, and identity theft. Driven by privacy laws and regulations, business is becoming more diligent in privacy protection when handling PII. Individual users, on the other hand, are free to produce and share content online that might contain sensitive information. This paper proposed a personal privacy risk assessment framework from the user's perspective. The risk score would help PII owners assess their privacy risks so that they can more actively control their information release and protect their privacy.
Homomorphic Encryption (HE) is a very attractive solution to ensure privacy when outsourcing confidential data to the cloud, as it enables computation on the data without de-cryption. However HE starts to lose effectiveness when scaled to multiple parties. In this paper, we propose the first multi-key HE search and computation framework. To achieve an efficient set-up for multi-party search and compute, we explore the different approaches to multi-key HE and secure search schemes to reduce rounds of communication. We propose a novel framework to search homomorphically encrypted data outsourced to a semi-honest server and shared with multiple parties dynamically using proxy re-encryption schemes. Our framework performs search with linear search complexity with just one round of communication between the two parties. The protocol provides multi-hop ca-pabilities that enable further computations on the search results.
Enabling registered users to match friends with the same interest, location, etc. is the most fundamental service provided by social network. With expanding openness of social network, the amount of data is growing exponentially. Cloud computing is then introduced into social network to mitigate the issue of storing and analyzing a substantial amount of data. How to realize user matching while protecting users' privacy remains a key challenge in cloud-based social network. As a cryptography tool, identity-based encryption with equality test (IBEET) can be used to match users with the same interest, location, etc. without decrypting the corresponding ciphertexts, therefore, it can well meet the key challenge in cloud-based social network. In this article, we propose an authenticated identity-based encryption with equality test (A-IBEET) scheme based on the observation that the cloud server may recover users' private information from the ciphertexts through offline message recovery attack (OMRA). Our scheme provides stronger security guarantee for social network users by resisting against OMRA in single-server setting. It could better protect users' privacy without sacrificing efficiency compared with related works.
Attribute-based access control (ABAC) model manages access to resources by policies. Incoming requests must satisfy some policy to be permitted to execute. Polices and requests are based on attributes, which are basic elements for constructing four components of each one, including Subject, Environment, Resource and Action. In XACML standard, for a given request the response can be one of the following values: Permit, Deny, Not Applicable and Indeterminate. The two last values are not decisive, bring no value to the requesters. We focus on the requests received Not Applicable in this article. Modifying the polices individually or rewriting the request by reducing the resource from the original one are solutions of existing studies. We theoretically introduce inference rules, which are applied to the policy set for computing the closure of it to evaluate whether the request is responded with firmed decision of permit or deny. Our proposals guide the security administrators in building the policy set satisfying an important property called completeness - the ability to be able to give determined responses to all the possible legal requests in the real world. In addition, we find out other necessary properties of the policy set and suggest the algorithms for ensuring some of them.
Deep learning allows building high-accuracy malware detectors without complicated feature engineering. However, research shows that the deep learning model is vulnerable and can be deceived if attackers add perturbation to input samples to craft adversarial examples deliberately. By altering the pixel values of the images, attackers have been able to generate adversarial examples that can fool state-of-the-art deep learning based image classifiers. However, Windows malware is a structured binary program file. Therefore, arbitrarily altering its contents will often break the program's functionality. In order to solve this problem, a standard but inefficient method is to run the sample in the sandbox to verify whether its functionality is preserved. This paper proposes a multi-strategy adversarial attack method, which can generate malware adversarial examples with functionality-preserving. Our method manipulates the redundant or extended space in the Windows malware binary, so it will not break functionality. Experiments show that our method has a high attack success rate and efficiency.
Shamir Secrets Sharing (SSS) is a foundational element of many Multi-Party Computation (MPC) protocols. Although SSS has the ability to handle linear combinations of multiple secrets natively, its ability to handle the multiplication of secrets is limited. In general, the multiplication of secrets requires more participants, due to the increased “degree”. In this paper, we present a verifiable method for handling the multiplication of SSS without increasing its degree. Our method is based on the Gilboa Protocol or its variants, which are built on top of Oblivious Transfer (OT). We also provide a security analysis, demonstrating that the method is secure under the assumption of a malicious adversary security model. As an application use case, we present a new ECDSA threshold signature scheme built on top of our method.