Secure communication in resource-constrained Internet of Things (IoT) networks demands cryptographic primitives that simultaneously provide authentication, confidentiality, and privacy at minimal cost. Certificateless signcryption (CL-SC) eliminates certificate management and key escrow, yet conventional CL-SC schemes produce publicly verifiable signcryptexts, exposing sender-receiver relationships to any party that obtains the ciphertext. The standard cryptographic countermeasure is a designated-verifier (DV) mechanism, which restricts verification to the holder of the designated verifier's private key and thereby delivers non-transferability. No existing CL-SC construction integrates such a mechanism, and existing schemes additionally suffer from bilinear-pairing overhead and random-oracle reliance. No prior construction resolves all three within a single scheme. This paper proposes a lightweight pairing-free CL-SC scheme with an integrated DV mechanism. Relying solely on elliptic-curve scalar multiplication and hash functions, IND-CCA2 confidentiality and EUF-CMA unforgeability are proved in the standard model under EC-CDH. The embedded DV mechanism delivers non-transferability at zero additional cost, since verification is algebraically fused with unsigncryption. Comparisons against seven state-of-the-art CL-SC schemes confirm up to 59.7% lower total computation time and up to 57.2% lower end-to-end delay, offering a deployable cryptographic foundation for privacy-sensitive IoT applications.
针对云计算中无证书签名方案计算代价高、撤销不即时的缺点,提出一种基于椭圆曲线加密的可即时撤销签名方案.采用椭圆曲线标量乘运算降低计算开销,KGC(key generation center)将时间参数加密与系统主密钥结合生成时间密钥,当出现用户密钥泄漏或身份过期时,KGC立即更新撤销时间表中未被撤销用户的时间密钥,防止用户的隐私泄露.理论与仿真分析结果表明,方案在随机预言模型下被证明是安全的,并且能够抵抗已撤销用户的攻击.
The core of standardized training for residents is the cultivation of clinical practice ability,which is also the main content of the professional degree graduate training.With the integration of professional degree graduate training and standardized training of residents,the evaluation system of professional degree graduate tutors should be included in the quality index of graduate clinical skills training.Through the methods of document retrieval and expert consultation,the index structure,the examination content and the weight were set up,and the detailed rules for the evaluation of the professional degree graduate tutors were established to guide them strengthen the training of clinical skills for graduates and improve the cultivation quality of professional degree graduates.
In this note we present a formulae for all possible values of $(n-j)\times(n-j)$ minors of an Hadamard matrix of order $n$.
In a strong designated verifier signature with message recovery (SDVSWMR) scheme, only the designated receiver has the capability to recover and validate the message-signature pair. In 2015, using the bilinear pairing, Islam and Biswas presented an SDVSWMR scheme (we call it: IsBi-SDVSWMR) with non-delegatability, which has better performance than other schemes in terms of communication and computation cost. However, in this study, we address that IsBi-SDVSWM scheme does not satisfy the security property of non-delegatability as they claimed and we present two types of delegatability attack to their scheme. We also propose a new and pairing-free SDVSWMR scheme that possesses the following security requirements: non-delegatability, unforgeability, non-transferability and privacy of signer's identity (PrSI). Compared our scheme with other existing related schemes, our scheme obtains better performance; that is, the computational cost is only 58%(lower) of IsBi-SDVSWM scheme (other schemes), and the communication cost is 800bits that is only 68%(lower) of IsBi-SDVSWM scheme (other schemes). Copyright (C) 2017 John Wiley & Sons, Ltd.
Due to resolving the key escrow problem and public key authentication problem, certificateless public key cryptography has drawn many attentions from numerous scholars and experts in recent years and becomes a hotspot for cryptography research. Most recently, the scholars of He and Du proposed a forward secure certificateless proxy blind signature scheme. Through the security analysis on the forward secure certificateless proxy blind signature scheme proposed by He and Du, this paper points out that their scheme is still unable to satisfy unforgeability as they claimed due to its two security drawbacks, i.e., the forgery attack from the original signer and the forgery attack from the ordinary user. We also present the reason analysis on the potential reasons of insecurity. At the same time, we also make a detailed analysis on the computation cost from attacks, which show that the cost of attacks is low.
Identity-based batch verification (IBBV) scheme is very desirable to solve efficiency, security and privacy preservation issues for vehicular ad hoc network (VANET). In 2015, Tzeng et al. proposed an IBBV scheme which was published in IEEE Transaction on Vehicular Technology. Their scheme has superior performance than other existing similar schemes in terms of security, computation cost and transmission overhead by performance evaluations. However, one time signature verification of their scheme needs two bilinear pairing operations. As it is well known, bilinear pairing is one of the most time-consuming operation in modern cryptography. Therefore, some efforts can be made to prevent the appearance of pairing and obtain better efficiency. In this paper, we propose an improved scheme of Tzeng et al.'s IBBV. Our improved IBBV scheme needs not use bilinear pairing without the lack of security and privacy-preserving. The total computation cost for signing and verifying is the constant 1.2 ms for single message and n messages respectively, which is far better performance than Tzeng et al. scheme and other similar schemes. So our improved IBBV scheme is more suitable for practical use. Finally, we apply the recovering technology of the vehicle's real identity of Tzeng et al.'s IBBV scheme to a public key authentication scheme for mobile Ad-hoc networks to address an improved pairing-free authentication scheme.
Most of existing designated verifier proxy signature (DVPSt) schemes which are proved to be secure in the standard model is constructed based on Water’s identity-based encryption. Therefore, security reduction efficiency of these schemes is very low and it may decrease these schemes’ security. In this study, we propose a new DVPSt scheme and present a detailed security proof of the proposed DVPSt in the standard model. We also address a tight security reduction of the proposed scheme based on the gap bilinear Diffie-Hellman assumption. Compared with other DVPSt schemes, our proposed DVPSt has two advantages, i.e., the computational cost is lower and security reduction is tighter. Therefore, our proposed DVPSt scheme is very suitable for application in some communication network situations in where the resources are limited.
Certificateless cryptography avoids the key escrow problem in identity-based crytosystems and certificate management in traditional public-key crytosystems, it has been researched by many scholars and many certificateless signature schemes have been proposed. However, most of them exist some security drawbacks and are insecure for some kinds of attacks. In this paper, we analyze two certificateless signature schemes and one proxy re-signature scheme proposed by some scholars recently. And we show that these schemes are insecure and also present the detailed attack steps. In order to overcome this problem, we also address some improved schemes which have the same or better performance than the original schemes.
Traditional method of key distribution does not fit the need to run in wireless sensor network (WSN) due to limitation on energy, computation and memory capacity of WSN. In this paper, we propose a scheme based on Hierarchical Identity-Based Encryption (HIBE) to distribute encrypt key. Comparing with key distribution based on Identity-Based Encryption (IBE), the proposed scheme reduces the computation time and saves memory space of wireless sensor node.
TCP/IP protocol architecture is complex and difficult to understand. In addition to classroom teaching, practical teaching is also very important.The paper introduces protocol simulation system into practical teaching,illustrates analysis examples of ICMP,IP and ARP packets run under the system and stresses the important roles the system plays on theoretical teaching. Importance of TCP/IP Protocol Experiment Course TCP/IP protocol is the suite of communications protocols used to connect hosts on the Internet and provides the most basic mechanism for computer network to achieve its functions. A large number of abstract and complex protocols run at all levels in the computer network architecture,so it is very difficult for students to understand and master the contents only through theoretical teaching.How to improve experimental teaching of TCP/IP protocol by building a simulation platform for network protocol experimental teaching,which enables students to better understand, validate and consolidate classroom teaching contents and enhances their perceptual knowledge on network protocol and thereby cultivates their ability to integrate theory with practice is a problem to be solved. To experiments of the TCP/IP course is Computer Protocol Simulation System from JLCSS applied.Through the system,students can visually observe not only transmission of data streams across the network and protocol conversations,but roles protocols from different levels play in one communication,which enhances students ' understanding of protocols and improves their ability to analyze and solve problems. Simulation Platform Introduction Components. The simulation platform is composed of two functional softwares:Simulation Editor and Protocol Analyzer. Simulation Editor Simulation Editor is used to visually edit some protocol packets of TCP/IP,and after that send them to network. Protocol Analyzer Protocol Analyzer is responsible for capturing frames in the network and analyzing protocols contained in the different layers.It includes two functional modules: Conversation Analysis and Protocol Analysis. Conversation Analysis can add captured data frames of commonly used protocols to the list of sessions and shows session sequences and data transmission directions,which enables students to observe and analyze a full session visually and understand in-depth protocol principles and working process. Protocol Analysis incoudes the display of outline codes, detailed decoding and initial data,which provides detailed explanation and description of protocols and dynamic tracking display depending on choices so as to analyze data easily. Experiment Form. Experiment form is to divide hosts into groups.Each group consists of six hosts 3rd International Conference on Science and Social Research (ICSSR 2014) © 2014. The authors Published by Atlantis Press 188 marked A,B,C,D,E,F respectively.There are three topology available for experiment environment.In each topology,six hosts can edit and capture packets acting as different roles to show working process of TCP/IP protocols. Protocol Analysis Teaching Examples Applying Simulation System ARP is an auxiliary protocol of IP.When a packet reaches a node,IP will select the path for the being transmitted packet based on its destination IP address to get IP address of the next node.At this point,ARP is responsible for resolving the IP address of the next node into MAC address provided for the frame formed on the layer of data link. It can be seen from this process that ARP acts as a connecting bridge between network layer and data link layer.Studying ARP,students are able to understand the roles played by MAC address and data link layer in the network communication. This section should be taught by associating it with routing table that describes how IP packets are passed from the perspective of network layer,whereas ARP reflects at a certain extent how data frames are passed at the data link layer.The combination helps students have a relatively complete understanding of the roles IP address and MAC address play during the network transferring and thereby understand the meanings of network layer and data link layer.In addition, specific experiment can be used to verify this combination of two points. With regards to this, a verification experiment is designed with the second topology simulation platform gives,which is shown in Fig 1. In the topology,Host A,C and D are in the same subnet (172.16.1.0/24),and Host E and F are in the same subnet(172.16.0.0/24).Host B with two network interface cards functions as a router connected to two subnets after routing configuration. Now Host A(172.16.1.2) Ping Host E (172.16.0.2).Since Ping is the application of ICMP,the Ping packet is first encapsulated as ICMP packet and in turn encapsulated as IP packet (shown in Fig.2),and then makes routing according to the routing table of Host A(as shown in Fig.3).Due to A and E in the different subnets,A is not able to directly transfer the IP packet to E.After referring to the routing table, A learns that the packet should be transmitted to the router's interfaces b1 (172.16.1.1). As for specific transmission,the IP packet requires encapsulating in the frame with the corresponding MAC address of 172.16.1.1 as its destination MAC address.Next, ARP is needed to play the role as a bridge.Given that there is no mapping of MAC address to 172.16.1.1,ARP needs to send a request packet(shown in Fig.4) in which MAC address(008899-000495),IP address(172.16.1.2)of Sender A,and Destination MAC address(000000-000000),IP address(172.16.1.1)are specified respectively. Fig. 1 topology structure
Recently, Au et al. proposed a hierarchical identity-based signature scheme and Hu-Huang proposed a proxy key generation protocol. Based on the both schemes, we present a novel identity-based proxy signature scheme. The proposed scheme is provablly secure in the standard model and its security can be reduced to the hardness assumption of the g-strong Diffie-Hellman problem. Compared with all existing identity-based proxy signature schemes secure in the standard model, the proposed scheme has the following two advantages: shorter signature length and less computational cost. So, the proposed scheme is very suitable for application in some low resource situations.
TCP/IP Protocolholds an important place in programs for specialty in Network Engineering. After making an analysis on the features and the problems facing the course teaching, the paper proposes the thinking of teaching reform, covering the organization of teaching contents, the carrying out of practice teaching and curriculumdesign, which proves to be effective teaching ideas and hopes to provide some reference for similar courses.
Wireless sensor networks (WSNs), consisting of many small low powered nodes, are applied into different scenarios. These nodes sense surrounding environments and deliver back collected data periodically or on-demand. The overall delay experienced in the delivery process is almost always proportional to the number of hops of data delivery paths. For time-critical applications, such delay is most desirable to be bounded. Most of existing works deploy additional relay nodes to shorten data delivery paths. In contrast, this paper introduces additional sinks such that each sensor can reach at least one sink in a bounded number of hops. Specifically, this paper formulates provisioned sink placement problem in senor networks composed by sensors of Heterogeneous wireless broadcast regions. Then the problem is proved to be NP-complete and subsequently one heuristic algorithm is presented to obtain approximate solutions.
Matlab is a high-performance language for scientific and technical computing. It integrates computation, visualization, and programming in an environment which provides many specific toolboxes. Different toolboxes can be used in corresponding areas, such as math, control theory, economics. We described the design of the Leontief input-output model toolbox which can simulate the trajectories of input and output of economic systems and automatically control the run of economic systems. By means of mathematic methods, the Leontief input-output systems were directly treated without converted to general systems. A sufficient condition under which the Leontief input-output models are stable is investigated. Based on this, the control algorithm is derived. Finally, the code of the input-output toolbox is provided.
In a group signature scheme,any legal member of this group can sign on behalf of this group,and no one can find out which member is the actual signer except the group manager.The focus of this paper is to design a new ID-based group signature without trusted PKG(group manager) or random oracles,and the security of the scheme,such as forward security.According to the analysis result,legal group members can sign on behalf of the group;an arbiter(OM) can open a legal signature to find out the actual signer,and he can also point out that whether the group manager is legal or not.So this is a scheme without trusted PKG without random oracles.Besides,this paper takes advantage of the information of time section to implement the forward security of this scheme in case of key exposure or revocation of group members.