The booming technologies of the Internet of Things (IoT) enable various applications and develop well. E-healthcare system is one of the successful examples, where people manage their healthcare information, diagnosis data, physical examination results, and so on. These types of sensitive information cause crucial security risks, posing threats to the security of the lives and property of the people. Given this concern, safeguard measures, such as authentication and encryption, are necessary. However, due to the openness of the wireless networks, authentication protocols for IoT-enabled e-healthcare systems are usually vulnerable to serious attacks. Furthermore, the quantum era is around the corner, urging authentication protocols to possess post-quantum security properties. In this paper, we propose a multi-factor password authentication scheme, named PAMA, with post-quantum security for the e-healthcare system. The lattice cryptography is adopted for post-quantum security. We formally prove the proposed PAMA scheme to be secure, and also informally verify the security against common attacks. Furthermore, we compare the performance of the communication efficiency of the PAMA scheme with other related works from both theoretical and experimental aspects. The efficiency comparison results demonstrate that our PAMA scheme approximately reduces the computation cost by 37.59% and the energy consumption by 37.5%, compared to the related post-quantum schemes. In summary, the PAMA scheme has a great advantage in secure authentication and agreement on a session key in the e-healthcare system.
Boosted by the explosive development of the Internet of Things (IoT) technology, the Internet of Vehicles (IoV) has become mature. Various and heterogeneous devices are increasingly included in IoV, which greatly facilitates people's lives, from navigation, charging, refueling, and other aspects. However, numerous devices in the IoV also bring serious security problems. Communications between vehicle entities and service entities are always exposed to powerful adversaries who can eavesdrop, intercept, and tamper communication messages. Besides, users' personal information faces leakage risks that seriously threaten people's life security (either passengers or pedestrians). Authentication and key agreement schemes for IoV are neither able to resist quantum attacks nor communication efficient. Therefore, in this paper, we propose a lattice-based anonymous certificateless authentication and key agreement scheme, PQACLA, for secure communication between vehicular entities and service entities. The PQACLA scheme leverages pseudonym identity technology and conditional malicious tracking to realize and guarantee the vehicle entities' anonymity and untraceability. Adopting provable security, the PQACLA scheme is proved secure under the random oracle model. Its security is also verified using the Scyther formal tool and informal security analysis. Compared to relative schemes, the PQACLA scheme behaves better, as its communication cost and computation cost are well balanced in total.
Covert communication technology embeds important information into carrier files and transmits them through open channels to realize safe information sharing without causing external perception. Blockchain is a new technology that has gradually developed with the rise of digital cryptocurrencies. Blockchain has the characteristics of anonymity, anti-tampering, and decentralization, which can solve the problems of traditional covert communication, such as the anonymity of the communicating parties being challenging to guarantee, the integrity of secret information being vulnerable to the channel, and the communication process is overly dependent on the third parties. Based on this, this paper analyzes and researches the existing covert communication technology using digital cryptocurrency as the transactions. First, the consensus mechanisms and cryptographic algorithms used by the current mainstream digital cryptocurrencies are expounded. Next, the covert communication schemes are classified based on digital encryption currency, the advantages and disadvantages of these schemes are sorted out, and the performance analysis and comparison of these schemes are carried out. Finally, this paper implements three typical covert communication schemes, conducts multi-dimensional comparative experiments using different digital cryptocurrencies as the transportation medium, and further discusses the covert communication scheme that improves the cost transmission performance of transmission according to the practical requirements.
Machine learning is a rapidly evolving field with applications in all aspects of human life. Utilizing the decentralized computing architecture can alleviate the high training and computational burden of central servers and improve service accuracy. However, the inherent properties of decentralized networks pose great challenges to communication security. It is urgent to design novel and appropriate security schemes, as malicious adversaries are curious about user private information, sensing data, and service demands. Furthermore, end devices always cooperate to accomplish the service targets, which means that group security schemes are needed to protect transmissions among them. In this paper, a certificateless-based group authentication and key agreement (CL-GAKA) scheme is proposed, named 2PCLGA, for distributed learning-based mobile edge computing (DL-MEC) networks. The proposed scheme establishes a session key among the end device group with the group leader MEC server based on the elliptic curve cryptography. Besides, the 2PCLGA scheme adopts dynamic pseudonym identity technology to realize the anonymity. The provable security analysis under the random oracle model, the formal analysis tool, and the informal analysis are adopted. The performance of 2PCLGA is also evaluated with the benchmarks, and the results show that the 2PCLGA scheme is greatly applicable to the resource-constrained circumstance.
Heat/peroxymonosulfate (heat/PMS) system has two intrinsic drawbacks, including low oxidation performance caused by the sharp pH drop and high potential to generate carcinogenic halogenated by-products in halide-containing waters. This study demonstrated that the eco-friendly sodium percarbonate (SPC) could effectively enhance the organic pollutant's removal and significantly suppress the halogenated byproduct formation. In the SPC/heat/PMS system, 10 mu M bisphenol A (BPA) removal reached 97% within 10 min under optimal conditions (65 degrees C, initial pH 7.0, 1 mM SPC, 1.5 mM PMS), with a pseudo-first-order rate constant 38.8 times higher than that of the heat/PMS system. The added SPC was hydrolyzed to produce sodium carbonate (Na2CO3) and hydrogen peroxide (H2O2). The generated Na2CO3 maintained a stable alkaline environment. Quenching tests coupled with electron paramagnetic resonance (EPR) experiments confirmed that singlet oxygen served as the predominant reactive species for BPA degradation. Meanwhile, H2O2 could rapidly reduce hypohalous acid generated via the reaction between halogen ions and PMS, back to halogen ions, thereby preventing the subsequent reactions between natural organic matter and hypohalous acid to form halogenated byproducts when treating halide-containing natural water. Three distinct BPA degradation pathways were proposed according to the detected eleven intermediates, and a reduction in the biotoxicity of the reaction solution was observed. Furthermore, the SPC/heat/PMS system exhibited high resistance to natural water matrices. In summary, this study presents a novel and eco-friendly strategy to enhance the oxidative efficiency of the heat/PMS system while suppressing hypohalous acid formation in halide-containing water.
Wireless sensor networks (WSNs) not only improve system automation and intelligence, but also significantly boost energy utilization efficiency, thus contributing to the sustainable development of related systems. With the continuous advancement of technology, WSNs are poised to play an increasingly indispensable role in future industrial applications. While WSNs offer numerous advantages in practical applications, they are confronted with critical challenges such as privacy preservation and communication security. To address these issues, this paper presents a dynamic and lightweight anonymous authentication protocol towards resource-constrained WSNs. The protocol only adopts elliptic curve cryptography (ECC) and one-way hash functions to achieve cryptographic binding between long-term private keys and ephemeral keys of three communicating entities, while supporting anonymous communication and dynamic node updates for WSNs. Through formal verification using the Scyther tool and informal security analysis, the protocol is proven to satisfy forward secrecy and known session key security, while resisting impersonation attacks. Furthermore, the protocol is demonstrated to maintain security under the eCK model. Finally, we conduct a comprehensive performance evaluation of our protocol against six authentication protocols, in terms of security properties, computational overhead, communication overhead, energy efficiency, node storage and average latency. It is shown that while ensuring communication security, the proposed protocol can effectively reduce energy consumption overhead.
Permanganate (Mn(VII)) is a commonly used oxidant for water treatment. However, manganese dioxide (MnO2) produced in situ during permanganate oxidation reactions significantly interferes with the spectrophotometric measurement of Mn(VII) when using the previously reported spectrophotometry. In this study, a convenient, low-cost, and reliable spectrophotometry method was firstly established for measuring trace Mn(VII) (µmol/L–level) during the permanganate oxidation reactions without the need to filter out MnO2. The method was based on the oxidation of 2,2-azino-bis(3-ethylbenzothiazoline-6-sulfonate) (ABTS) by Mn(VII) to produce a stable green radical (ABTS•+) under mildly alkaline conditions (pH ❾ 8), with detection at long wavelengths (i.e., 732 nm and 820 nm). The strong resistance to interference from MnO2 of the modified ABTS method was attributed to the inertness of MnO2 toward ABTS under mildly alkaline conditions and the relatively low molar absorptivity of MnO2 at long wavelengths compared to ABTS•+. Using the characteristic peak at 732 nm as the detection wavelength, the sensitivity of the modified ABTS method for the Mn(VII) measurement was determined to be 4.84 × 104 L/(mol·cm). Additionally, the modified ABTS method exhibited high tolerance towards common environmental background matrices and was reliable in measuring the Mn(VII) concentration in natural water samples. The accuracy of the modified ABTS method for the measurement of Mn(VII) in the presence of MnO2 was also validated by comparing different detection methods. Furthermore, the modified ABTS method was successfully applied to detect the variation of Mn(VII) concentration during diclofenac removal with the humic acid-enhanced Mn(VII) process.
Internet of Drones (IoD), an important component of 6G air-based networks, uses drone cluster collaboration to accomplish efficient communication. Group authentication scheme (GAS) is essential for verifying members’ identities and controlling dynamic networking privileges in order to guarantee secure communication of drone clusters in an open IoD environment. However, current GAS schemes still struggle technically to balance security, functionality, and lightweight design, and they are unable to fully support security requirements in complex drone application scenarios with cross-domain interconnections and dynamic topology. In order to tackle the aforementioned issues, we propose a blockchain-assisted BAGAS scheme that supports distributed authentication and dynamic change of IoD members. The eCK model provides a rigorous proof of the scheme’s security, while the Scyther tool is used to further validate security properties. The scheme guarantees low computation, communication, and energy cost by utilizing Shamir’s secret sharing and Chebyshev chaotic map. The total computation cost is reduced by an average of 41.6%, the total communication cost by an average of 39.8%, and the total energy consumption by an average of 54.3% in comparison to mainstream schemes of the same type, as demonstrated by experiments (refer to Table VIII for a more detailed comparison). For drone swarm communications, the BAGAS scheme achieves synergistic optimization of communication security and performance.
The hydraulic retention time (HRT) of a denitrifying filter (DF) is crucial in influencing total nitrogen (TN) removal. Therefore, the effect of HRT on the performance of advanced synergistic nitrogen removal (ASNR) processes, including denitrification and partial-denitrification anammox (PDA), was investigated using a labscale DF. NH4+-N and organic matter from the secondary influent were utilized as electron donors. As the HRT decreased from 8 to 2 h, the filtered effluent TN increased from 0.51 to 2.45 mg/L, with the corresponding removal efficiency decreasing from 97.7 % to 88.9 %. Besides, the effluent COD ranged from 17.26 to 18.98 mg/ L, with a removal efficiency between 58.5 % and 61.5 %, indicating the minimal impact from HRT variation. Furthermore, 60.9 %-63.2 % of the removed TN was eliminated via the PDA pathway, with 1.29 to 1.36 mg of COD consumed per mg of TN removal. The presence of denitrifying, anammox and hydrolytic bacteria confirmed the effectiveness of ASNR. These results demonstrated that the technique holds significant potential in practice due to its cost-effective and high TN and COD removal under low HRT.
With the advancement of intelligent transportation systems, advanced traffic information service systems have emerged as critical infrastructure that integrates multi-source data to offer real-time traffic condition services. Current systems mainly rely on cloud computing for centralized data storage and flexible resource scheduling. However, this architecture is vulnerable to service disruptions from single-point failures. The centrally stored sensitive data raises privacy breach risks, and massive terminal requests can cause computing and communication bottlenecks, hindering real-time response. To tackle these challenges, we propose a blockchain-based certificateless anonymous aggregate signcryption (BCAAS) scheme. It combines edge computing and distributed ledger technology to build a decentralized, trustworthy architecture. The scheme uses certificateless signcryption to safeguard vehicle identity anonymity and data transmission encryption. A lightweight aggregate verification algorithm is designed to boost edge node efficiency. The blockchain serves as a public key storage directory to prevent device public key replacement. Smart contracts enable malicious behavior tracing, ensuring privacy while precisely identifying malicious vehicles. Security analysis shows that BCAAS can effectively resist various potential security threats. Performance analysis and simulations on blockchain and vehicular networks indicate that BCAAS has better practical significance.
In order to cost-effectively remove carbon (C), nitrogen (N) and phosphorus (P) from secondary effluent (SE), a lab-scale denitrifying filter (DF) for generating biogenic manganese oxides (BMOs) was constructed, and its influent was the mixture of real SE and secondary influent (SI). When NH4+-N in the influent rose to around 3.2 mg/L with the improvement of the SI ratio, the effluent COD, filtered total nitrogen (TN) and phosphorus (TP) were 7.80, 0.63 and 0.014 mg/L with the corresponding removal rate (CRR) of 84.72 %, 97.17 % and 95.15 %, respectively. The refractory organics were oxidized and hydrolyzed to biodegradable organics, providing carbon source, and the residual organics were hardly further removed, owing to their extremely poor biodegradability. N was synergistically removed by denitrification coupled with partial-denitrification anammox (PDA), which was confirmed by the fact that the contribution rate of PDA to TN removal was 30.43 % and removing 1 mg TN actually consumed 2.02 mg COD. P was mainly removed by reacting with Mn2+ from the influent or BMOs reduction to form chemical precipitation (Mn3(PO4)2). The presence of the main functional bacteria (manganese oxidizing bacteria (MnOB), anammox, denitrifying and hydrolytic bacteria) and the main functional genes further explained the efficient C, N and P removal and clarified the advanced C, N and P removal mechanism. This novel technique removed C, N and P with extremely high efficiency, extremely low operational cost and no secondary pollution.
Reducing and chelating agents have been extensively employed to strengthen the oxidizing capability of Cu(II)/H2O2 process. However, the risk of secondary pollution and the strong scavenging effect for reactive species severely limit their application in wastewater treatment. Herein, a new strategy was proposed for enhanced oxidation of organic contaminants in Cu(II)/H2O2 process by adding oxidizing agents (e.g., peroxydisulfate (PDS)). With naproxen (NPX) as the target contaminant, the introduction of PDS improved the degradation efficiency of NPX in Cu(II)/H2O2 process across the pH range of 7.0 to 10.5, and enhanced the utilization efficiency of oxidants (over 7-fold). More importantly, the deprotonated H2O2 (HO2-) acted as a reductant (not an oxidant) playing a crucial role in the reduction of Cu(II) to Cu(I) in PDS/Cu(II)/H2O2 process. PDS took precedence over H2O2 for reacting with the formed Cu(I) to generate multiple reactive species including •OH, SO4•- and Cu(III). PDS/Cu(II)/H2O2 process also demonstrated well interference resistance to common natural inorganic ions (e.g., NO3-, HCO3-) and humic acid. Furthermore, two possible conversion pathways were proposed based on the detected seven degradation intermediates, and no significant change in toxicity was observed. In summary, this study described a novel strategy to enhance the oxidizing capacity of Cu(II)/H2O2 process utilizing oxidants rather than reducing and chelating agents, revealing a new perspective into synergistic role of dual oxidants in the metal valence cycle.
The rapid evolution of the Industrial Internet of Things (IIoT) and widespread adoption of smart devices have profoundly reshaped traditional industrial production and management. Facilitated cross-domain data transmission between these devices has greatly boosted intelligence and efficiency in IIoT. Yet despite progress in cross-domain transmission, existing schemes still face severe challenges: complex hierarchical architectures, cross-domain trust issues, and high computational costs. To tackle these problems, we propose a blockchain based cross-domain data transmission scheme for IIoT, integrated with edge-cloud computing. First, we enhance crossdomain transmission in edge-cloud environments by developing a lightweight blockchain-assisted framework, which cuts down redundant entity interactions. Second, we address inter-domain trust in IIoT by establishing trust relationships and computing relationship keys. Finally, we introduce a lightweight blockchain based authentication and key agreement protocol to simplify cross-domain data transmission between smart devices. Security analysis shows the proposed scheme achieves strong security in the real-or-random model, effectively resisting various potential threats. Performance analysis and blockchain simulations further confirm its practical applicability for IIoT deployment
To effectively remove carbon (C), nitrogen (N) and phosphorus (P) from wastewater with a C/N (chemical oxygen demand (COD)/total nitrogen (TN)) ratio of 1.6-1.7, anammox enhanced anoxic/oxic/oxic/anoxic process was proposed, in which Mn2+ was added for P removal. The effluent COD, TN and total phosphorus were 9.1 ± 0.9, 3.4 ± 0.1 and 0.3 ± 0.1 mg/L with the corresponding removal rate of 96.4 ± 0.4 %, 97.8 ± 0.08 % and 94.2 ± 2.7 %, respectively. The apparent sludge yield coefficient Yobs was only 0.02-0.03 kg mixed liquor suspended solid/kg COD, mainly due to the sludge being hydrolyzed and consumed as a carbon source. The N removal was enhanced by anammox, confirmed by Candidatus Brocadia (13.0 % in A1, 16.9 % in O1, and 33.4 % in O2) and the functional genes related to anammox (hdh: 0.008 %-1.1 % and hzs: 0.002 %-0.005 %). Hydrolysis and anammox enhanced the refractory organic matters removal. The novel technique effectively removed C, N and P from the wastewater with extremely low C/N ratio.
In order to cost-effectively remove carbon (C) and nitrogen (N) from secondary effluent (SE), a lab-scale denitrifying filter (DF) inoculated with anammox bacteria and acclimated hydrolytic bacteria was constructed, whose influent was the mixture of real SE and secondary influent (SI). With the improvement of the SI ratio, the effluent total nitrogen (TN) was progressively reduced, and the effluent COD and filtered TN were reduced to 8.94 and 0.85 mg/L with the corresponding removal rate (CRR) of 82.50 % and 96.19 %, separately. Organic matters, including polysaccharides, proteins and fluorescent organic matters, were efficiently removed by hydrolysis and denitrification, and most of the removed organic matters were eventually oxidized to CO2 and H2O. TN was removed efficiently by denitrification coupled with partial-denitrification anammox (PDA), which was demonstrated by only consuming 1.98 mg COD to remove 1 mg TN and the removal of 30.41 % of the removed TN though PDA. Multiple identified functional bacteria (anammox, denitrifying and hydrolytic bacteria) and the
To improve the efficiency of advanced nitrogen removal (ANR) and reduce its operational cost, a novel technique of advanced synergistic nitrogen removal (ASNR) of denitrification and partial-denitrification anammox (PDA) was developed in denitrifying filter (DF), consuming organics and NH4+-N from secondary influent as electron donors. With the increase of the secondary influent proportion, the filtered effluent TN was reduced to 0.51 mg/L with the corresponding removal rate (CRR) of 97.68 %, and the rate of denitrification and the ASNR increased accordingly. The ASNR occurrence was confirmed by the fact that 61.00 % of the removed TN was removed by PDA and the actual CODcr consumption (ACC) for removing 1 mg TN decreased to 1.30 mg accordingly. The presence of the anammox, denitrifying and hydrolytic bacteria further demonstrated the achievement of the ASNR. This technology presented practical application perspective due to its extremely high efficiency of TN removal, chemical-free, minimal carbon source demand and very low operational cost.
The flourishing development of the Internet of Medical Things (IoMT) is bringing personalized and timely healthcare to an increasing number of people. Fog-cloud-based IoMT pushes computing and data processing to the edge network, enabling low latency and real-time response. However, the heterogeneity of IoMT and medical data privacy make designing secure and efficient authentication schemes a highly challenging task. In this article, we first design a blockchain-assisted fog-cloud-based IoMT authentication architecture, leveraging blockchain technology to enhance the security and efficiency of medical data sharing. Additionally, we propose a novel anonymous authentication scheme that utilizes lightweight cryptographic primitives, physically unclonable functions, and fuzzy extractors suitable for resource-constrained IoMT devices. We use formal and informal security analysis to prove the security of the proposed scheme. Furthermore, we evaluate the performance of the proposed scheme from the perspectives of computation, communication, energy, average delay time, and smart contract resource consumption. Compared to five related schemes, our scheme achieves higher security while maintaining low resource consumption.
The consumer drone market has grown rapidly, making it necessary to integrate drones with the internet to explore low-altitude areas. Internet of Drones (IoD) offers a more potent data stream to connect the global Big Data system, it will also have to deal with the issue of exposure and malicious use of flight trajectory, communication data, and identity information when a cyber attacker unlawfully eavesdrops, gains access to, attacks, or even takes control of drones. Numerous authentication protocols have been developed for the IoD context in order to solve the aforementioned issues. Ali et al. provide a cross-domain communication scheme (henceforth known as the AJ protocol) in IoD environment by utilizing blockchain-assisted authentication to improve the security of IoD data transmission. Nevertheless, this scheme is vulnerable to key compromise impersonation attack and fails to achieve the crucial security attribute of anonymity. In order to address the aforementioned security concerns, we develop an enhanced certificateless authentication and key agreement (CL-AKA) protocol in IoD environment, based on blockchain technology and Chebyshev chaotic mapping. Our protocol can achieve necessary security attributes for IoD and withstand a variety of known attacks, as demonstrated by proof of security under the eCK model and automated validation by the Scyther tool. Additionally, our protocol performs better in terms of computation and communication overhead when compared to similar protocols to achieve lightweight anonymous authentication.
With the vibrant development of the Internet, smart grids have been provided with a suitable environment to flourish. Smart meters record and transmit electricity consumption information and send it to gateways and service providers. Power suppliers process the data to evaluate and predict the frequency of electricity consumption by users, to save resources. However, the power consumption information contained in the data may reveal users’ identity, community address or the frequency at home. If malicious attackers get these messages, the residential safety will be greatly threatened. Therefore, data needs to be protected. Authentication and key agreement protocol is a promising solution, which first realizes mutual authentication between communication parties, and then establishes a session key between them to protect transmitted data. Recently, Chai et al. proposed an authentication scheme based on SM2 authentication key exchange (AKE) protocol. Unfortunately, after our analysis, it is difficult to achieve forward security as they stated. Specifically, if the long term key of the communicating smart meter is leaked, the adversary can recover the session keys established before. Further, we propose a provable secure certificateless authentication and key agreement scheme. The security of the proposed scheme is analyzed by provable security and BAN logic. Compared with the existing scheme, our proposed scheme can achieve a better balance from the security properties, communication cost, and computation cost three aspects.
With the widespread application of vehicular ad-hoc networks, ensuring secure and seamless cross-regional roaming for mobile users and obtaining corresponding services has become a focal point. However, designing an efficient and secure roaming authentication protocol is challenging due to the confidentiality and privacy issues that data transmission during the roaming authentication process may cause and the limited computational capabilities of mobile devices. Researchers have proposed many security-oriented schemes to address this thorny challenge. However, many state-of-the-art schemes need help meeting various security requirements and facing privacy leakage and single points of failure. Recently, Xue et al. proposed a distributed authentication scheme for roaming services in mobile vehicular networks based on smart contracts. Regrettably, it is noted that their scheme is vulnerable to ephemeral key leakage attacks. Further, we present a blockchain-based anonymous roaming authentication scheme called BARA, which changes how session keys are generated and significantly reduces on-chain storage costs using probabilistic data structure techniques. We utilize Scyther and Burrows–Abadi–Needham (BAN) logic to prove the security of BARA and compare it with similar protocols in terms of computation, communication, and revocation check. The analysis results demonstrate that BARA achieves a good balance between security performance and execution efficiency.