This paper presents TALOS, a unified reusable 6G CryptoProcessor architecture for high-assurance symmetric security services under a 256-bit private-key baseline. The design addresses a core hardware challenge in future mobile systems: supporting heterogeneous strong symmetric primitives without duplicating complete cipher cores. TALOS combines a Hierarchical Common Data Path (HCDP) with a three-tier cryptographic encapsulation model spanning AES-256, Snow 5G/SNOW-V-class, and ZUC-256. Tier-1 captures native nonlinear substitutions, Tier-2 compiles bounded arithmetic nonlinearities into exact micro-S-boxes, and Tier-3 consolidates shared permutation, XOR, affine, diffusion, and state-transport fabrics. This decomposition preserves cipher correctness while exposing realistic sharing opportunities across substitution, arithmetic, and linear transport layers. The architecture also supports confidentiality processing and integration with integrity- and authentication-oriented service logic through a common control/resource framework. Compared with monolithic universal-box or loosely aggregated multi-core approaches, TALOS provides a disciplined, RTL-oriented taxonomy for crypto-agile symmetric-core hardware. The proposed framework advances 6G cryptographic hardware design by combining operator-exact reuse, architectural scalability, and implementation-oriented efficiency within a single CryptoProcessor paradigm.
Zero-touch network service automation in the future mobile networks, alike 6G, is a key enabler for their agile network service management and closed-loop handling. Towards this new technological breakthrough, there exist several SotA global standards, for instance the Zero-touch network and service management (ZSM) intelligent framework, that manage to instantiate, deploy, and govern a variety of such closed-loops (thus enabling zero-touch administration) of the 6G end-to-end user resource demanding network services across versatile management domains (from the resource layer, business and to the service layer, above). However, the hierarchical closed-loop automation (from top to bottom and the opposite) of the service handling operation of virtually numerous such closed loops, due to the extreme computational and networking resource-hungry 6G applications, together with the plethora of end-users is left as on open challenge. In such trivial occasions, it is almost non avoidable that there will exist intent conflicts between users and resources. These conflicts, if not detected at all, will create bottlenecks in the idle network conditions of 6G testbeds, deployments and interdomain scenarios, therefore causing disharmony in the ZSM concept. In this paperwork, we depict a ready-state software prototype solution that is based on a Private LLM (Qwen 2.5) that is properly and ad-hoc configured to detect such intent-based contradictions and alongside provide very astute eXplainability (XAI) features and quick conflict recognition. The results received appear quite promising.
This article introduces SAT-IOTA, a lightweight and artificial intelligence (AI)-driven cybersecurity framework designed for blockchain-powered satellite infrastructures. Unlike traditional detection approaches, SAT-IOTA employs predictive anomaly analytics combined with a sliding window (SW) machine learning mechanism to proactively identify and mitigate security threats in SAGIN. The proposed framework integrates IOTA distributed ledger technology (DLT) for secure, decentralized telemetry data management, tokenized satellite components, and resilience against cyber-physical attacks. Through a custom-built testbed with Hornet nodes, we evaluate the framework's performance under Denial of Service (DoS) scenarios, achieving 97% prediction accuracy and an F-measure of 80%. The results confirm that SAT-IOTA enhances space system security by combining blockchain-driven trust with AI-based anomaly prediction, offering a scalable and resource-efficient solution for next-generation satellite communications.
Virtual reality (VR)/the metaverse is transforming into a ubiquitous technology by leveraging smart devices to provide highly immersive experiences at an affordable price. Cryptographically securing such augmented reality schemes is of paramount importance. Securely transferring the same secret key, i.e., obfuscated, between several parties is the main issue with symmetric cryptography, the workhorse of modern cryptography, because of its ease of use and quick speed. Typically, asymmetric cryptography establishes a shared secret between parties, after which the switch to symmetric encryption can be made. However, several SoTA (State-of-The-Art) security research schemes lack flexibility and scalability for industrial Internet-of-Things (IoT)-sized applications. In this paper, we present the full architecture of the PRIVocular framework. PRIVocular (i.e., PRIV(acy)-ocular) is a VR-ready hardware–software integrated system that is capable of visually transmitting user data over three versatile modes of encapsulation, encrypted—without loss of generality—using an asymmetric-key cryptosystem. These operation modes can be optical character-based or QR-tag-based. Encryption and decryption primarily depend on each mode’s success ratio of correct encoding and decoding. We investigate the most efficient means of ocular (encrypted) data transfer by considering several designs and contributing to each framework component. Our pre-prototyped framework can provide such privacy preservation (namely virtual proof of privacy (VPP)) and visually secure data transfer promptly (<1000 ms), as well as the physical distance of the smart glasses (∼50 cm).
Automation, which has been used successfully for a long time in a variety of industries, most recently networking and computers, requires closed loops. The Zero-touch network and service management (ZSM) system, which supplied standardized components that allow the development, execution, and governance of multiple closed loops, enables zero-touch administration of end-to-end services across different management domains. The outstanding problem of how to implement many closed loops in an optimal and coordinated way will need to be addressed by the ZSM standards. One essential 6G enabler that aids in automating network elements and computational infrastructures is intent-based networking. In this field, artificial intelligence (AI)-powered intent-based automation will be able to guarantee a high degree of sustainability, efficiency, scalability, and security; especially in situations for cross-domain and interoperable deployment, where points of presence (PoPs) are nonindependent (non-IID) and uniformly dispersed. To do this, we discuss a brand-new intended Conflict Reconciliation (CR) method that uses ultra-fast converging Game-Theoretic actors in conjunction with fully end-to-end Deep Reinforcement Learning (DRL) and closed loops from the resource layer to the business layer.
Sixth generation (6G)-enabled massive network MANO orchestration, alongside distributed supervision and fully reconfigurable control logic that manages dynamic arrangement of network components, such as cell-free, Open-Air Interface (OAI) and RIS, is a potent enabler for the upcoming pervasive digitalization of the vertical use cases. In such a disruptive domain, artificial intelligence (AI)-driven zero-touch “Network of Networks” intent-based automation shall be able to guarantee a high degree of security, efficiency, scalability, and sustainability, especially in cross-domain and interoperable deployment environments (i.e., where points of presence (PoPs) are non-independent and identically distributed (non-IID)). To this extent, this paper presents a novel breakthrough, open, and fully reconfigurable networking architecture for 6G cellular paradigms, named 6G-BRICKS. To this end, 6G-BRICKS will deliver the first open and programmable O-RAN Radio Unit (RU) for 6G networks, termed as the OpenRU, based on an NI USRP-based platform. Moreover, 6G-BRICKS will integrate the RIS concept into the OAI alongside Testing as a Service (TaaS) capabilities, multi-tenancy, disaggregated Operations Support Systems (OSS) and Deep Edge adaptation at the forefront. The overall ambition of 6G-BRICKS is to offer evolvability, granularity, while, at the same time, tackling big challenges such as interdisciplinary efforts and big investments in 6G integration.
In this paper, we present approaches to generating random numbers, along with potential applications. Rather than trying to provide extensive coverage of several techniques or algorithms that have appeared in the scientific literature, we focus on some representative approaches, presenting their workings and properties in detail. Our goal is to delineate their strengths and weaknesses, as well as their potential application domains, so that the reader can judge what would be the best approach for the application at hand, possibly a combination of the available approaches. For instance, a physical source of randomness can be used for the initial seed; then, suitable preprocessing can enhance its randomness; then, the output of preprocessing can feed different types of generators, e.g., a linear congruential generator, a cryptographically secure one and one based on the combination of one-way hash functions and shared key cryptoalgorithms in various modes of operation. Then, if desired, the outputs of the different generators can be combined, giving the final random sequence. Moreover, we present a set of practical randomness tests that can be applied to the outputs of random number generators in order to assess their randomness characteristics. In order to demonstrate the importance of unpredictable random sequences, we present an application of cryptographically secure generators in domains where unpredictability is one of the major requirements, i.e., eLotteries and cryptographic key generation.
The advent of 6G networks is anticipated to introduce a myriad of new technology enablers, including heterogeneous radio, RAN softwarization, multi-vendor deployments, and AI-driven network management, which is expected to broaden the existing threat landscape, demanding for more sophisticated security controls. At the same time, privacy forms a fundamental pillar in the EU development activities for 6G. This decentralized and globally connected environment necessitates robust privacy provisions that encompass all layers of the network stack. In this paper, we present PRIVATEER’s approach for enabling “privacy-first” security enablers for 6G networks. PRIVATEER aims to tackle four major privacy challenges associated with 6G security enablers, i.e., i) processing of infrastructure and network usage data, ii) security-aware orchestration, iii) infrastructure and service attestation and iv) cyber threat intelligence sharing. PRIVATEER addresses the above by introducing several innovations, including decentralised robust security analytics, privacy-aware techniques for network slicing and service orchestration and distributed infrastructure and service attestation mechanisms.
With the faster maturity and stability of digitization, connectivity and edge technologies, the number of the Internet of Things (IoT) devices and sensors is flourishing fast in important junctions such as homes, hotels, hospitals, retail stores, manufacturing floors, railway stations, airports, oil wells, warehouses, etc. However, in this extremely connected world, the security implications for IoT devices are getting worse with the constant rise in malicious cyberattacks. The challenge is how to secure IoT sensors, services and data. The blockchain technology, a prominent distributed ledger technology (DLT), is being pronounced as the way forward for safeguarding IoT devices and data. The Directed Acyclic Graph (DAG)-based DLT has the inherent potential to realize the benefits of blockchain with better performance. IOTA is a DAG-based blockchain implementation for the IoT era. The Tangle, the IOTA’s network immutably records the exchange of data and value. It ensures that the information is trustworthy and cannot be tampered with nor destroyed. In this work, we depict a thorough analysis of the existing security studies for IOTA. Then, we identify the gaps and the limitations of these security solution schemes, and finally, propose future security research recommendations that can potentially fill these gaps to secure DLT-enabled IoT devices.
IOTA is a Digital Ledger Technology (DLT) prototype for IoT applications that has attracted a rising popularity in recent years. One issue that acts as obstacle to its widespread adoption are the cybersecurity concerns. Some of the security concerns in IOTA include Denial of Service (DoS) double spending, parasite attacks, and DDoS attacks. In this work, we developed a Machine-Learning (ML) approach to create security threat index that can be utilized to proactively provide defenses to the IOTA decentralized infrastructure as well as individual nodes against potential compromises. Our approach is established on the sliding window customized technique to classify the data generated from the DAG-based nodes for cybersecurity anomaly detection. To validate the approach, we implemented "DoS attacks" threat model in the DLT-based IoT environment using Raspberry Pi devices and experimented our security methods and algorithms in this environment. The preliminary experimental results are promising.
The Blockchain concept is often mostly associated with Bitcoin and monetary transactions, however, the technology has enormous potential for several industries including the space sector. Cybersecurity enhancement plays a detrimental role in critical core operations inside the space functional flow: from the supply chain, satellite orbital tracking, and digital communications efficacy. The increasing adaption of connected highly advanced technologies exposes satellites, aeronautical drones, space vehicles, and ground stations to new types of cybersecurity risks. Hacking, cyber threats, as well as cyber-crimes in space are new trends. Such industrial ecosystems can benefit from Blockchain & distributed ledger technologies (DLT) that make it possible to intelligently decentralize governance. This work attempts to further demystify the linkage between space and the Blockchain, address the ledger's potential to provide added-on cybersecurity to the critical space core functionalities, via a ready-prototyped DLT/IOTA secure framework (SWIoTA), and finally, illuminate the roles of DLT ledger to secure networks of satellites orbits, as well as space tokenization concept.
Distributed Ledger Technologies (DLT) are based on the Blockchain concept and have been specifically designed for enterprise-level devices with acceptable computing powers and network bandwidth. Direct Acyclic Graph (DAG) ledger(s) is a new form of DLT technology designed for Internet-of- Things (IoT) devices due to the nature of its disadvantages of the computing powers and limited network bandwidth. IOTA is a DAG-based Blockchain implementation for IoT applications that has gained an increased attention in recent years. One of the major concerns that is hindering for its wide adaptation is the security concerns. Many security attack occurrences against the IOTA such as parasite attacks, double spending, and DDoS to disrupt availability resources of the new ledger can become both widespread and disruptive. Existing security studies are ad-hoc and typically address a solution scheme for a specific security threat. In this paper, we present an adaptive Reinforcement-Learning (RL) approach to best classify the monitored resource consumption parameters of the DAG-based nodes or devices for any potential security anomaly detection. The aim is to create high accuracy security threat index that can be used to proactively defend the decentralized IOTA infrastructure and individual nodes against compromises. The performance evaluation results of this solution against DoS attacks are promising. The framework implementation derives a stochastic interpretation and output and the same time it converges deterministically.
The widespread development of Internet of Things (IoT) technology has introduced numerous wearable Internet-Protocol (IP)-based devices and smart wireless sensors that can obtain and analyze various real-world data from their human user. Deploying these wearable intelligent devices has not left the healthcare area inattentive. IoT health applications are well recognized for their value of helping us to track our health status so that early warnings of potential issues can be identified so that we can make changes to improve certain aspects of our health. But on the same level, trust, privacy, and security concerns arise and pose significant importance because of the interconnectivity of such medical devices. Expressly, the growing list of cybersecurity flaws and vulnerabilities in health devices represent challenging risks to patients whose privacy or health management depends on the idle functionality of these instruments. This chapter presents a forensic study of the most state of the art security and privacy risks, challenges, and conceptual issues in IoT healthcare, in general. A full security assessment and trust comparison of various already studied security models, and frameworks for IoT healthcare is being illustrated together with future security and privacy recommendations for IoT eHealth.
The whole security architecture of LTE/SAE (Long Term Evolution/System Architecture Evolution) is being consisted of four main hardware-oriented cryptographic algorithms: KASUMI block ciphers, SNOW-3G stream cipher, the MILENAGE algorithm set, and the 4G development of ZUC algorithm. This paper presents an FPGA deployment of a universal security architecture crypto processor for 4G LTE, consisting of both four ciphers enabling each one on demand, which is based on two novel design principles. One is a more intelligent implementation of the four algorithm's substitution boxes (S-boxes) based on a common intersection assumption of their contents. The second includes the use of a common data path hardware block deployed along the four cipher's architectural design. This universal security architecture crypto processor proves to reduce the area space at least 1.5 times, and also provides almost double throughput compared with the state-of-the-art realizations of the individual ciphers, something which is a high necessity when producing components for the demanding post-4G cellular market.
The recent emergence of ultra-high-speed and high-definition data and video services has pushed wireless network capacity to its limits. Cellular network capacity is therefore a valuable resource, whereas indoor coverage poses itself as a challenging issue. At the same time, real-world paradigms of multimedia transmission require effective Quality-of-Service (QoS) provisioning as well as power admission. To confront issues like delay-sensitive QoS requirements and traffic provisioning, as well as meet the mobile customer needs, this paper presents a traffic-aware Orthogonal Frequency-Division Multiple-Access (OFDMA) hybrid small-cell deployment for QoS provisioning and an optimal admission control strategy for 4G cellular systems. The traffic awareness in the proposed framework is provided by a utility function, which differentiates the traffic QoS levels with the user's grouping priority indexes, channel conditions, and traffic characteristics. To further enhance the proposed framework, an admission power control algorithm based on an efficient algorithm handover is also proposed.
Orthogonal frequency-division multiple-access (OFDMA) small-cell networks of next-generation Long-Term Evolution (LTE-Advanced) standard, is perhaps a key factor to efficiently provide beneficial usage of expensive radio resources, while maintaining adequate network capacity. Network capacity is without doubt a critical resource for LTE networks. At the same time, real-time multimedia transmission requires effective quality-of-service (QoS) provisioning, as well as power admission. This paper proposes a traffic-aware OFDMA hybrid small-cell deployment for QoS provisioning and an optimal power admission control strategy for 4G cellular systems. By performing real-case scenario simulations of user-type multimedia transmission, we show that the implemented framework achieves high QoS levels of performance, increased throughput capacity, lower delay levels and optimally adapted network traffic.
This work presents a new converged access architecture for LTE mobile backhaul networks. In the proposed architecture, evolved NodeBs (eNBs) are interconnected with local ring-based wavelength-division-multiplexed (WDM) passive optical networks (PONs), which aggregate and efficiently transport traffic to the evolved packet core (EPC). The proposed WDM-PON ring design supports a dynamic setup of virtual circuits for inter-base-station communication, over a dedicated Alan channel. It also supports load balancing, by dynamically reallocating and sharing the capacity of the downstream wavelengths. The reservation mechanism is arbitrated by the optical line terminal, which monitors the traffic imbalances of downstream channels and orchestrates the setup of subwavelength transient flows.
In this paper the problem of IP watermark proof is attacked by a new technique applied at the state machine level along with assisting hardware. Experiments on benchmark circuits and an example system-on-chip (SoC) indicate that the overhead of the proposed technique on the delay and area is negligible and extremely small respectively.
The authors give an overview on the state of the art of potential security issues that occur in the deployment of the LTE/SAE (Long-Term Evolution/System Architecture Evolution) protocol in emerging 4G wireless technologies. Although security concerns and challenges in wireless networks will remain a hot topic in the future, the LTE/SAE standard could adapt to these rising challenges, becoming more robust and secure. By looking at the authentication and ciphering algorithms, such as EAP-AKA (Extensible Authentication Protocol for Authentication and Key Agreement), currently operating within the LTE protocol, the authors analyze several vulnerabilities in LTE/SAE security architecture - specifically, insecure AKA key derivation procedures and the lack of fast reauthentications during handovers.
Haridimos T. Vergos合作论文数Computer Engineering & Informatics Department;Technology and Computer Architecture Laboratory1