
We prove that the path-finding problem in isogeny graphs and the endomorphism ring problem for supersingular elliptic curves are equivalent under reductions of polynomial expected time, assuming the generalised Riemann hypothesis. The presumed hardness of these problems is foundational for isogeny-based cryptography. As an essential tool, we develop a rigorous algorithm for the quaternion analog of the path-finding problem, building upon the heuristic method of Kohel, Lauter, Petit and Tignol. This problem, and its (previously heuristic) resolution, are both a powerful cryptanalytic tool and a building-block for cryptosystems. This is an extended abstract of the full article available at http://arxiv.org/abs/2111.01481. This full article will be referred to as “the full version” throughout the text.
Since the beginning of the 21st century, modern information technology and electronic integrated circuit technology have developed rapidly. In the chip industry, the ability to resist side-channel attacks has become an important indicator for international mainstream evaluation agencies to evaluate chip security. This paper proposes an improved method for side channel analysis based on the $${CNN}_{best}$$ model, incorporating a lightweight combined channel and space convolutional attention module, optimising the position of the attention module, improving the learning efficiency of key features of the power consumption curve, and effectively reducing the number of traces used by the attack model. The addition of dropout layer network structure solves the problem that the model is prone to rapid overfitting. The optimal value of drop rate is sought through comparative experiments to speed up the convergence of the model and reduce the number of traces required for a successful attack. The experimental results show that the number of traces required by the method in this paper for side-channel attacks is reduced by 88% compared with the original model, which significantly improves the attack performance and can meet the requirements of side-channel modeling and analysis.
Federated learning has received extensive attention in recent years since the clients only need to share their local gradients with the servers without directly sharing their datasets to train the model. However, the existing research shows that the attackers can still reconstruct private information from shared gradients, resulting in privacy leakage. In addition, the aggregated results could be tampered with by servers or attackers. In this paper, we propose a secure and verifiable federated learning training scheme (SVFLS) to protect the privacy of data owners and verify aggregated results. Specifically, we employ threshold paillier encryption to protect the local gradients of data owners and use the bilinear aggregate signature to verify the correctness (or integrity) of aggregated results. Furthermore, our scheme can tolerate data owners dropping out during the training phase. We conduct extensive experiments on real datasets and demonstrate that our scheme is effective and practical.
Online restore reduces the downtime during backup restore, such that users can operate on the already restored files even if the other files are still being restored. However, due to the inconsistency between the access sequence and the restore sequence, the file to be accessed currently is sometimes not restored, thereby leading to long-delay time to access the file. We propose two approaches, which build on users’ historical access sequence to schedule the restore sequence, in order to reduce users’ waiting time to file access: (i) the frequency-based approach, which restores files based on the access frequencies of historical files; and (ii) the graph-based approach, which preferentially restores the frequently accessed files as well as their correlated files. Trace-driven experiments on two datasets show that our approaches significantly reduce users’ waiting time.
Port scanning attacks remain one of the major penetration testing schemes attackers employ to undertake maliferous intentions. With the increasingly sophisticated nature of cyber criminals and advanced technology and the failure of traditional network intrusion detection systems, the challenge of effectively detecting open ports with much efficiency in minimal time continues to linger. Thus, several recent studies, particularly those that employed machine learning approaches, have attempted to resolve and address the issue of enhancing this intrusion detection technique, yet suffer many performance challenges demanding further investigation. This paper employed seven machine learning classifiers to detect port scanning attacks after successfully using principal component analysis to resolve the relevant component and enhance the results. Comparison is made between the outcome of the various models and previous studies using accuracy, precision, recall, area-under-curve, f1-score, false-positive rate, and training time as performance metrics. Our results indicate that XGBoost was the best classifier with the highest accuracy of 99.98%, no false positive detected, a precision of 99.99%, a recall of 99.98, and an area-under-curve of 99.99% compared with the other classifiers and previous studies on port scan attack detection.
To evade being detected by the content-based or frequency-based IDS, the attack model in the automotive CAN has shifted from the traditional packet flooding and payload modification attacks to stealth attacks such as shutdown attacks. These new types of stealth attacks are difficult to be effectively detected by content-based IDS and frequency-based IDS. The CAN bus physical voltage-based IDS can identify the source of each message and detect these stealth attacks effectively. However, the state of art research has discovered a novel masquerade attack called DUET, which can tamper with the existing voltage-based IDS by generating overlapping voltage signals with an accomplice to distort the fingerprint of the specified ECU. We propose a detection mechanism to prevent the manipulated voltage attacks of overlapping voltage signal samples, which is based on anomaly detection by applying the LSTM autoencoder model. By filtering the overlapped signal and rectifying the voltage fingerprint instance of the original voltage signal, the improved voltage-based IDS can effectively resist the DUET attack. Experiments demonstrated the proposed detection mechanism can authenticate the victim ECU and the accomplice ECU before and after the DUET two-stage attack, and prevent the receiver ECU from being deceived by the forged messages generated by the attacker and accomplice ECUs.
The smart grid (SG) is one of the largest Internet of Things (IoT) applications. Therefore, it encompasses a variety of smart objects, including smart appliances, smart meters, and sensors, among others. All of these devices are scattered throughout the SG to serve a variety of objectives. As a result, the SG network architecture is exposed to various security threats. Furthermore, numerous authentication and key agreement techniques have been developed throughout the years to protect the communication between entities. However, several of them are homogeneous protocols, which means that only entities running similar cryptographic schemes can communicate. In addition, the SG communication system is centralized and susceptible to a single point of failure and management. Moreover, the existing protocols involve extensive cryptographic elements that cannot be processed by a smart meter’s (SM) computing power. To address the aforementioned issues, an AP-HBSG: authentication protocol for heterogeneous blockchain-based smart grid environment is designed. The designed protocol operates in a decentralized environment, thus eliminating a single point of failure and management. Furthermore, a blind signature is applied to the blockchain network to add authentication security among blockchain nodes. In addition, AP-HBSG is lightweight and it fits the SM computing capability. Moreover, AP-HBSG can protect the communication of parties interacting in a heterogeneous environment. On the other hand, the security of the presented protocol is analyzed in the random oracle model (ROM) and proved under the elliptic curve discrete logarithm (ECDL) problem and the computational Diffie–Hellman (CDH) problem. The protocol’s performance analysis shows that, compared to the most recent protocols, ours has lower communication and computation costs. The computation cost (ms) is 122,68, 216.86, 391.34, and 92.01 for WHZS, KKN, WLCTA, and ours, respectively. On the other hand, the communication cost (bytes) is 344, 184, 568, and 182 for WHZS, KKN, WLCTA, and ours, respectively.
The multi-secret visual cryptography scheme (MVCS) can recover different secret images according to multiple stacking methods of shares. The rotating multi-secret visual cryptography scheme can restore additional secrets by stacking the share with another share after rotating a specific angle. The existing rotating multi-secret scheme is associated with the problem of meaningless noise-like shares, shares poor camouflage and security risks in the process of storage and transmission. At the same time, there are many problems in the existing schemes, such as no color image, low contrast of the recovered image and poor scalability of the algorithm. Therefore, this paper proposes a rotating multi-secret color visual cryptography scheme based on meaningful shares. The secret images are encrypted respectively, and the secret information is embedded into the cover images, and the cover images are processed by halftoning technology to obtain the meaningful shares, which improves the security of the rotating multi-secret scheme. The experimental results show that the scheme has the characteristics of gray and color secret images and cover images, the recovered images have no cross interference of cover images and extra secret, the shares and the recovered images have good visual effect, and the scheme meets the security requirements.
Backdoor attacks, as an insidious security threat to deep neural networks (DNNs), are adept at injecting triggers into DNNs. A malicious attacker can create a link between the customized trigger and the targeted label, such that the prediction of the poisoned model will be manipulated if the input contains the predetermined trigger. However, most existing backdoor attacks define an obvious trigger (eg: conspicuous pigment block) and need to modify the poisoned images' label, causing these images seems to be labeled incorrectly, which leads to these images can not pass human inspection. In addition, the design of the trigger always needs the information of the entire training data set, an extremely stringent experiment setting. These settings above remarkably restrict the practicality of backdoor attacks in the real world. In our paper, the proposed algorithm effectively solves these restrictions of existing backdoor attack. Our Label-Specific backdoor attack can design a unique trigger for each label, while just accessing the images of the target label. The victim model trained on our poisoned training dataset will maliciously output attacker-manipulated predictions while the poisoned model is activated by the trigger. Meanwhile victim model still maintains a good performance confronting benign data samples. Hence, our proposed backdoor attack approach must be more practical.
Public auditing checks the integrity of outsourced data via random sampling and verifying sample data blocks. In practice, however, users do not pay attention to the entire data set but focus on the integrity of only the part of the data containing keywords of interest. Therefore, the keyword-based auditing paradigm is proposed; it depends entirely on the subjective choice or access habits, which makes it possible for malicious storage servers to analyze the auditing frequency, or reduce redundant backups. For government data, auditing frequency privacy leakage or corruption of any file could be catastrophic. In this paper, we propose a hidden frequency keyword-based auditing scheme for a smart government named HFKA, which is compatible with distributed storage architecture. HFKA leverages a Bloom filter, which adjusts the false positive rate to consider auditing files corresponding to specified keywords and auditing random files obtained via fuzzy matching. To obtain privacy-preserving fuzzy matching, HFKA constructs an index table embedded with update times to retrieve a wide range of files to be audited. This approach is secure against the replay attack and supports the index table update through structure iteration instead of recalculation. HFKA provides storage robustness, privacy protection of hidden frequencies, and data security. Additionally, HFKA can reduce audit computation overhead by 32.6% compared to the probabilistic public auditing.
With the wide application of machine learning algorithms in medical diagnosis, we gradually confronted the problem of computing and storing large-scale data. Outsourcing cloud computing has become the most cost-effective option to address these challenges. However, privacy and security issues have always existed in outsourced computing. Therefore, in this article, we propose an efficient index nearest neighbor query scheme based on Secret Sharing (SS) and Secure Multi-Party Computation (MPC) with the dual-cloud model architecture. For secure and efficient queries, we have designed a comprehensive set of secure index generation algorithms and secure index query algorithms. The cloud server creates indexes for the outsourced data and saves them through index generation algorithms in the offline phase, and uses index query algorithms to complete secure and efficient nearest neighbor query tasks in the online phase where users participate. Security analysis proves that our scheme protects the security of outsourced data and the privacy of query data. Simulation results on real datasets also demonstrate that the proposed scheme has higher efficiency and lower communication overhead compared with existing schemes.
The emergence of blockchain decentralization has garnered considerable interest from the scientific and scholarly communities since it addresses scalability issues and provides security for its users. Since its inception, numerous encryption methods have adopted its methodology to develop medically applicable schemes. However, most proposed schemes involve time-consuming operations, while others rely on standard pairing libraries. Both approaches cause complexity delays, affecting the blockchain’s execution speed. In the case of blockchain digital signatures, participants’ cryptographic keys are tied to their assets instead of their identities. This contradicts the non-repudiation feature of public key digital signatures. Therefore, this article proposes a lightweight hybrid encryption protocol employing the key encapsulation technique to generate encapsulated keys for blockchain network participants. The proposed method allows users to generate encapsulated keys linked to their identities. In order to increase the speed of cryptographic execution on the blockchain, we evaluate the computational overhead of the proposed model using the pairing Ethereum library (Py-eth library). In addition, the Ethereum Improvement Proposals (EIPs) library measures the consumption of gas costs on the blockchain. Our performance analysis demonstrates that the proposed protocol achieves a lower computational cost with less gas consumption, accelerating blockchain transaction executions.
Many sanitizable signature schemes have been proposed to facilitate and secure the secondary use of medical data. These schemes allow a patient, authorized by the doctor, to modify and re-sign his/her electronic health record (EHR) to hide sensitive information and the new signature can be verified successfully. However, this may lead to fraud because patients may forge medical records for profit. To further standardize sanitization and reduce the sanitizers power, this paper proposes a new limited sanitizable signature scheme, which allows the signer to not only decide which message blocks can be modified but also determine the maximum of modifiable blocks and the expiration time for sanitization. We also propose a secure EHR sharing scheme suitable for medical scenarios based on the above limited sanitizable signature to realize privacy preserving medical data sharing. Finally, the security analysis and experimental results show that the security and efficiency of our scheme can be accepted.
Smart building uses sophisticated and integrated building technology and allows numerous IoT systems to interact as well as provide convenience to its users. Unfortunately, smart buildings have become a point of attraction for cybercriminals. Due to the fact that the majority of these IoT devices lack the memory and computing power required for robust security operations, they are inherently vulnerable. IoT devices are consequently vulnerable to various attacks. Therefore, a single attack on network systems or devices can cause serious harm to the security of data as well as privacy in a smart building. This paper presents LightGBM-RF, a machine learning model that accurately detects anomalies in a smart building by utilizing a combination of Light Gradient Boosting Machine and Random Forest algorithms. The model detects anomalies with an accuracy of 99.19%, thereby providing an effective scheme for detecting different attack families, and the potential to significantly improve security in smart buildings.
To ensure the confidentiality of medical data, the medical information is usually encrypted before outsourcing to a third party for processing. Encryption technology can ensure the privacy of data, but it limits the search for data. The problem is usually solved using public key encryption with keyword search (PEKS). Recently, a few certificateless PEKS (CPEKS) schemes have been proposed. However, they rely on the high-consuming bilinear pairing, and some of them are vulnerable to inside keyword guessing attacks (IKGA). To solve these problems, we propose a lightweight CPEKS scheme for the Medical Internet of things (IoMT), which does not contain bilinear pairing. The scheme is proved to be secure in the random oracle model. The analysis results show that it has better comprehensive performance than the existing schemes according to the security property, the computation cost, and the communication cost.
As the number of users of cloud services increases, so does the frequency of attacks against cloud infrastructure and systems. Cloud service providers do possess some control over the security of their systems. Nonetheless, these measures are only partially effective. End-users and clients should be informed of which cloud service provider delivers the best security for their services. This study aims to investigate the threat landscape of three cloud service providers: Google Cloud Services, Linode, and Amazon Web Services. Honeypots have been added to adequately monitor attacks and the attack sequence, allowing for a more thorough examination of the attack procedure. This research will clearly lay out the statistics regarding the Cloud service provider with the least threat landscape, as well as provide supporting information for all stakeholders in the cloud computing industry’s cyber threat awareness and provide recommendations for the base security configurations of all public-facing infrastructure.
In recent years, smart contracts on the Ethereum platform have attracted considerable attention, and smart contracts have increasingly become targets of cyberattacks for the purpose of stealing cryptoassets. One of the emerging attack methods is to intentionally deploy contracts that appear to contain vulnerabilities but have backdoors, and that, lure attackers who are targeting vulnerable contracts to steal cryptoassets. These are called smart contract honeypots (henceforth referred to simply as “contract honeypots”). Torres et al. analyzed contract honeypots for the first time at USNIX Security 2019. In this study, we look at eight types of contract honeypots organized by Torres et al. and calculate the damages caused by each of them. We also analyze the code of contract honeypots by focusing on the arguments of the money transfer process, and we discovered a new type of contract honeypot. This analysis suggests that smart contracts with “this.balance” in the money transfer process may be contract honeypots. Furthermore, we discuss the impact of contract honeypots on general users.
The data analysis in the process of vehicle collaboration for the Internet of Vehicles (IoV) environment improves the driving experience and service quality. However, the privacy issue is becoming one of the problems of obstructing the development of data sharing among vehicles. To overcome the disadvantage, in this work, we propose a privacy-preserving data sharing scheme based on federated learning by the collaboration of participants, which can resist gradient leakage, poisoning attacks, etc. Firstly, the gradient data is encrypted by random masking to protect the privacy of training data. Then, the Pearson correlation coefficient is utilized to distinguish the correctness of the model parameters uploaded from the vehicle at uplink. Finally, the proposed scheme can verify the correctness of the global model distributed from AS at downlink using the Lagrange interpolation The experimental results show that the proposed privacy-preserving data sharing scheme provides higher learning accuracy by eliminating malicious gradients.
Despite the importance of preimage sampling algorithm in lattice-based cryptography, its low efficiency limits its applications. In this study, we propose a family of gadget-based trapdoors on NTRU lattice. Our construction is compatible with existing efficient preimage sampling algorithms and offer compact secret. Comparison with two trapdoor schemes of [10], the hash-and-sign signature scheme based on our trapdoor scheme has better security and the sizes of secret and signature are reduced. In the first scheme, the sizes of public key and secret key are 6.25 kB and 5.0 kB for an estimation of 63.95-bit security. In the second one, they are 6.25 kB and 5.0 kB for an estimation of 75.92-bit security. Our proof-of-concept shows that the sizes of secret key and public key can be reduced to 0.88 kB and 3.06 kB for an estimation of 86.72-bit security.
In an increasingly complex cyber environment, where the role of traditional protection tools is increasingly limited, intelligence is the key point in the battle. Through the information monitoring of Internet social platforms, potential cyberattack threats to enterprises, governments, and other institutions could be analyzed. Twitter, the world’s largest social media platform, spreads news and shares tweets about cybersecurity-related events and technologies daily, with cross-site scripting attacks being one of them. In the status quo, this paper proposes a cross-site scripting threat intelligence detection model based on deep learning, which can detect tweets involving threats related to cross-site scripting attacks. We utilized a variety of word vector extraction tools blended with topic word extraction techniques to construct a word vector matrix with multi-dimensional features. Then, the threat event detection model is trained using a bidirectional recurrent convolutional neural network with a self-attentive mechanism. In the experiment, the accuracy rate of our proposed model exceeds 0.96, and through multiple sets of control experimental data results, it is proved that the structure designed in the model is conducive to improving the performance of the model and that the model is effective in detecting tweets that involve cross-site scripting threats.