Singcryption is a very important concept to bind confidentiality and authenticity. This is a logical step to reduce both computation and communication costs. The proposed an identity based signcryption that removes the overhead of certificates. The proposed design is provably secure in the standard model (a widely accepted model). Furthermore, the IBSC design uses modified bilinear Diffie‐Hellman inversion and modified strong bilinear Diffie‐Hellman assumption as building blocks of the security. The proposed design is secure, efficient, and shortest to the best of our knowledge. In this design, a user does pairing free computation, and he sends only a triplet on the public channel, that makes it efficient in terms of computation and communication costs.
The adoption of telemedicine has improved health care quality and its reachability to remote patients. There are substantial contributions towards the implementation of secure communication of medical records such as digital images, documents, videos, etc. However, less attention is paid to efficiency, privacy-preserving communication, and access control. Moreover, existing constructions have either failed to support distributed revocation or the symmetric encryption approach, which requires ensuring encryption of arbitrary length messages. As scalability and flexibility in the delegation of keys and revocation of mobile users are very fundamental issues in attribute-based access control and its application to e-healthcare, we propose a new cryptographic concept called attribute-based fully distributed access control architecture that supports fine-grained access control, data protection, data validity, and efficient data search in the context of an electronic personal health record system. The proposed design supports the symmetric key approach to encrypt/decrypt the data. The proposed design is secure and efficient, and it also provides a fully distributed access control on the stored data at a central authority with a revocation facility. It provides access to the user, doctor, and health department according to the set of attributes/ credentials shown by them. It benefits in key delegation and revocation of the user, which will help to improve the robustness of e-healthcare systems.
The authenticated key agreement is one of the major security services that can be used to secure an Internet of Things (IoT) environment, where the devices collect the data and the data is then aggregated at the cloud server, and then a user needs to access the data stored at the server(s) securely. For this purpose, after a mutual authentication performed between a user and the accessed server, a session key needs to be established among them for secure communication. In this article, we design an efficient lattice-based authenticated key exchange protocol using ring-based version of learning with errors assumption for the IoT-enabled smart devices. The proposed protocol is basically a key exchange that uses the reconciliation mechanism. The detailed security analysis under the standard model has been performed along with the informal security analysis to show that the proposed protocol is robust against different attacks. We then simulate the proposed protocol under the NS-3 simulator to measure the network performance parameters like network throughput and latency. A comparative analysis shows that the proposed protocol has superior security, less computational cost, and comparable communication cost when compered these parameters with the other competing schemes.
The quantum computing being a threat motivates us to design a post quantum secure authentication protocol for mobile digital rights management system. In current, a post quantum secure protocol “learning with error based secure mobile digital rights management system” has been proposed. The protocol has been claimed to post quantum secure under the ring learning with errors assumption. We have analyzed that this protocol allows the server to keep a fixed private/public key that causes less communication and computation overheads. But, this leads to signal leakage/modified signal leakage attacks. In this paper, we have discussed signal leakage attacks during the authentication phase of the existing protocol. We have proposed a new post quantum authenticated key agreement protocol for the digital rights management system. In the proposed protocol, the server uses a random value instead of using fixed value chosen by the user, and it establishes a session key with the user. Moreover, this protocol needs to exchange just two messages that confirm the efficiency. The protocol has been proved secure in a random oracle model under ring learning with errors assumption. Moreover, the article contains an informal security discussion and a simulation using NS3 simulator.
SummarySatellite's communication system is used to communicate under significant distance and circumstances where the other communication systems are not comfortable. Since all the data are exchanged over a public channel, so the security of the data is an essential component for the communicating parties. Both key exchange and authentication are two cryptographic tools to establish a secure communication between two parties. Currently, various kinds of authentication protocols are available to establish a secure network, but all of them depend on number–theoretical (discrete logarithm problem/factorization assumption) hard assumptions. Due to Shor's and Grover's computing algorithm number theoretic assumptions are breakable by quantum computers. Although Kumar and Garg have proposed a quantum attack‐resistant protocol for satellite communication, it cannot resist stolen smart card attack. We have analyzed that how Kumar and Garg is vulnerable to the stolen smart card attack using differential power analysis attack described in He et al and Chen and Chen. We have also analyzed the modified version of signal leakage attack and sometimes called improved signal leakage attack on Kumar and Garg's protocol. We have tried to construct a secure and efficient authentication protocol for satellites communication that is secure against quantum computing. This is more efficient as it requires only three messages of exchange. This paper includes security proof and performance of the proposed authentication and key agreement protocol.
The primary objective of postquantum cryptography (also known as quantum‐resistant cryptography) is to develop the cryptographic systems that need to be robust against both quantum and classical computers, and can also interoperate with the existing communications protocols and networks. In an Internet of Things (IoT) environment, the communicated messages contain sensitive information that are transmitted over an open channel, where message integrity and data privacy become challenging tasks. Although several traditional cryptographic security protocols can be applied for IoT security and data privacy, such as authentication, access control, key agreement, and digital signature, but they are not resilient against quantum attacks. To overcome these issues, in this article, we first present an advanced and efficient construction of postquantum lattice‐based signcryption scheme, and then apply the constructed lattice‐based signcryption in IoT applications, where data sensed by the deployed IoT smart devices is securely stored at the cloud, via the gateway nodes (aggregators). The data stored at the cloud servers cannot be even modified by them due to the involved signatures generated by the aggregators. The formal security analysis shows the robustness of our designed lattice‐based signcryption scheme. Other detailed information security analysis and a performance analysis with the traditional number‐theoretical based public key cryptosystems show the efficacy, and significantly better security and functionality features of the proposed scheme under the lattice‐based postquantum context.
In this article, we have discussed various authentication and key agreement protocols for satellite communication system and their flaws off‐line passwords guess, stolen smart card attack, insider attack and replay attack and so forth. We have analyzed the security of a recently published Uddeshaya et al's protocol for satellite communication, and discussed how it suffers from design flaws and insider attack. This protocol cannot stop the Bergamo attack, but the proposed protocol is applicable in specific environment against Bergamo attack. We have compared and illustrated the performance and security analysis of several existing protocols for satellite communication. The proposed authenticated key agreement protocol possesses both low computation and low communication cost. This protocol establishes a verified session key with only two messages of exchange. We have discussed the security of proposed framework in the random oracle model.
SummaryInternet of things environment is adopted widely in different industries and business organizations with varying capacity. It provides a favorable environment to outsource the crowdsourced data in the cloud to minimize the cost of computation, which is called crowdsourcing. Crowdsourcing is a technique where individuals or organizations obtain goods and services. A professional or industry outsource the crowdsourced data in the cloud, where confidentiality and authenticity of data become essential. Signcryption is the cryptographic technique that serves both the authenticity and the privacy of transmitted messages. This technique ensures secure authentic data transmission and storage. Therefore, this paper proposes an identity‐based signcryption scheme. In the proposed PSSCC framework, the user does pairing free computation during signcryption, which makes efficient calculation on user‐side. Moreover, PSSCC framework is proved secure under modified bilinear Diffie‐Hellman inversion and modified bilinear strong Diffie‐Hellman problems. The performance analysis of PSSCC with related schemes indicates that the proposed system supports efficient communication along with less computation cost.
Mobile communication is very important for an individual users, enterprisers, industries, businesses, and organizations. Since the nodes communicate through a public channel, security, and privacy become essential component for mobile communication. Both key exchange and authentication are two important security attributes to establish secure communication between two parties. In the past few years, various post‐quantum secure authentication protocols have been designed, but we have found that either some of the protocols are vulnerable to stolen smart card attack, invalid login, or signal leakage attack. In this article, we have discussed how the protocol Dharminder et al (Dharminder D, Chandran KP. J Ambient Intell Humaniz Comput. 2020; 11:4089‐4100.) is vulnerable to modified version of signal leakage attack, and sometimes called improved signal leakage attack. We have also suggested a remedy over the current existing protocol suffering from signal leakage attacks. The proposed protocol is secure against quantum attacks. We have proved the security of the proposed protocol under ring learning with errors assumption. The proposed authentication and key agreement needs only two messages exchange. We have also found the proposed is efficient in terms of computation with respect to relevant protocols.
Identity-based encryption is an important cryptographic system that is employed to ensure confidentiality of a message in communication. This article presents a provably secure identity based encryption based on post quantum security assumption. The security of the proposed encryption is based on the hard problem, namely Learning with Errors on integer lattices. This construction is anonymous and produces pseudo random ciphers. Both public-key size and ciphertext-size have been reduced in the proposed encryption as compared to those for other relevant schemes without compromising the security. Next, we incorporate the constructed identity based encryption (IBE) for Internet of Things (IoT) applications, where the IoT smart devices send securely the sensing data to their nearby gateway nodes(s) with the help of IBE and the gateway node(s) secure aggregate the data from the smart devices by decrypting the messages using the proposed IBE decryption. Later, the gateway nodes will securely send the aggregated data to the cloud server(s) and the Big data analytics is performed on the authenticated data using the Artificial Intelligence (AI)/Machine Learning (ML) algorithms for accurate and better predictions.
Mobile multimedia security is essential to ensure a secure communication in industries, businesses, and organizations. Mobile multimedia is a new concept for an enterprise, where organizations need to be secure. In the last decade, a number of anonymous authentication protocols have been designed based on factorization and discrete logarithm assumptions. Shor's algorithm solves a number‐theoretic assumption in polynomial time using postquantum computers that creates a trouble. However, learning with errors is an advanced hard assumption that cannot be solved by any known existing quantum algorithm. This inspires one to design an anonymous postquantum authentication protocol for the mobile digital rights management system. The protocol has been proved secure in a random oracle model under learning with errors assumption. Moreover, the article contributes an informal security discussion, an implementation using automated validation of internet security protocols and applications. The performance analysis ensures its efficiency even in the postquantum era.
A vehicular ad hoc network possesses highly advanced functioning in the intelligent transportation system. This system helps moving nodes equipped with advanced smart devices, to establish reliable communication with vehicles or usable roadside units (RSUs). It has been ascertained that the privacy of the user is essential in vehicular communication to share resources among both unknown vehicles and unknown RSUs. There are some privacy‐preserving authentication schemes based on number‐theoretic assumptions, but they do not support security against quantum computers due to Shor's algorithm. Moreover, these schemes have disfavor with repeated authentication of the earlier transmitted message and being unsuccessful to search messages no longer valid during batch verification. To resolve most of the existing issues, this article brings something new to an environment, that is, edge‐computing construction into the message‐verification procedure of the system. In the proposed design, a RSU can expeditiously verify messages from nearby legitimate vehicles and broadcast to all vehicles within its communication range, which leads to a reduction in redundant verification of messages. To ensure security against quantum attacks, we have introduced an advanced design based on the hardness of a short integer solution in some random lattice. This framework guarantees autonomous driving, regular vehicular traffic flow, and a process of revocation in the advanced quantum era.
The outbreak of coronavirus has caused widespread global havoc, and the implementation of lockdown to contain the spread of the virus has caused increased levels of online healthcare services. Upgraded network technology gives birth to a new interface “telecare medicine information systems” in short TMIS. In this system, a user from a remote area and a server located at the hospital can establish a connection to share the necessary information between them. But, it is very clear that all the information is always being transmitted over a public channel. Chaotic map possesses a dynamic structure and it plays a very important role in the construction of a secure and efficient authentication protocols, but they are generally found vulnerable to identity-guess, password-guess, impersonation, and stolen smart-card. We have analyzed (Li et al. in Fut Gen Comput Syst 840:149–159, 2018; Madhusudhan and Nayak Chaitanya in A robust authentication scheme for telecare medical information systems, 2008; Zhang et al in Privacy protection for telecare medicine information systems using a chaotic map-based three-factor authenticated key agreement scheme, 2017; Dharminder and Gupta in Pratik security analysis and application of Chebyshev Chaotic map in the authentication protocols, 2019) and found that Bergamo’s attack (IEEE Trans Circ Syst 52(7):1382–1393, 2005) cannot be resisted by the protocol. Although few of the protocols ensures efficient computations but they cannot ensure an anonymous and secure communication. Therefore, we have proposed a secure and efficient chaotic map based authentication protocol that can be used in telecare medicine information system. This protocol supports verified session keys with only two messages of exchange. Moreover, we have analysed the performance of proposed protocol with relevant protocols and it is being implemented in “Automated Validation of Internet Security Protocols and Applications” respectively.
In this paper, we propose a novel variant of the Hill cipher based on vector spaces.In the classical Hill cipher, a non-singular matrix is used for encryption but it is well known that this cipher is vulnerable to the known-plaintext attack.In our proposed cryptosystem, we eradicate this problem by encrypting each plaintext block with a new invertible key matrix.This makes our scheme immune to all existing attacks in literature on this type of ciphers and so the resulting cipher can be used as other state-of-art block cipher.To generate the invertible matrices which serve as the dynamic keys, we make use of the vector spaces along with randomly generated basis and non-singular linear transformation.In addition to this, we also study the computational complexity of the proposed cryptosystem and compare this with the computational complexities of other schemes based on Hill cipher.
Vehicular networking allows vehicles with sensing capabilities to carry out communication from vehicle to vehicle or with accessible roadside units. To attain effective communication in vehicular networking, we have proposed a hybrid technological solution in terms of vehicular edge computing (VEC) utilizing resources, cloud and edge server environment. The proposed architecture supports a frequent communication between a vehicle and a legitimate edge server without any trusted party communication. Both security and privacy are two key challenges in edge based vehicular communications due to the adoption of a real-time environment that is required to respond to hundreds of moving vehicles. This paper presents an edge computing-based framework for vehicular communication to ensure security, message integrity, and privacy. The presented framework attains all security attributes in the presence of active as well as passive adversaries. The formal security proof ensures its correctness and robustness. The analysis indicates that it is secure and efficient, being based on new edge computing framework as compared to general cloud computing framework.
Multimedia contents are digitally utilized these days. Thus, the development of an effective method to access the content is becoming the topmost priority of the entertainment industry to protect the digital content from unauthorized access. Digital rights management (DRM) systems are the technique that makes digital content accessible only to the legal rights holders. As the Internet of Things environment is used in the distribution and access of digital content, a secure and efficient content delivery mechanism is also required. Keeping the focus on these points, this article proposes a content distribution framework for DRM system using chaotic map. Formal security verification under the random oracle model, which uncovers the proposed protocol's capability to resist the critical attacks is given. Moreover, simulation study for security verification is performed using the broadly accepted “automated validation of Internet security protocols and applications,” which indicates that the protocol is safe. Moreover, the detailed comparative study with related protocols demonstrates that it provides better security and improves the computational and communication efficiency.
Singcryption was first proposed by Yuliang Zheng [1] in 1997, based on the construction of a shortened ElGamal-based signature scheme in parallel to authenticated encryption in a symmetric environment. Signcryption is a cryptographic primitive that enables the conventional two-step method of secure and authenticated message transmission or storage (sign-then-encrypt or encrypt-then-sign) to be done in a single step at a much lower computational cost than the traditional two-step approach. This article concentrates on designing a provably secure identity-based signcryption (IBSC) scheme. The user performs pairing-free computation during encryption in the proposed scheme, making it user-side effective. In addition, the IBSC structure is shown to be secure when dealing with modified bilinear Diffie-Hellman inversion (MBDHI) and modified bilinear strong Diffie-Hellman (MBSDH) problems. The proposed framework supports efficient communication, protection against chosen cipher attack, and existential unforgeability against chosen message attack, according to the performance review of IBSC with related schemes.
Upgraded network technology presents an advanced technological platform for telecare medicine information systems (TMIS) for patients. However, TMIS generally suffers various attacks since the information being shared through the insecure channel. Recently, many authentication techniques have been proposed relying on the chaotic map. However, many of these designs are not secure against the known attacks. In spite of the fact that some of the constructions attain low computation overhead, they cannot establish an anonymous communication and many of them fail to ensure forward secrecy. In this work, our aim is to present authentication and key agreement protocol for TMIS utilizing a chaotic map to achieve both security and efficiency. The underlying security assumptions are chaotic theory assumptions. This scheme supports forward secrecy and a secure session is established with just two messages of exchange. Moreover, we present a comparative analysis of related authentication techniques.
Modern network technology yields new interface for telecare medicine information systems in short TMIS used for patient's healthcare. This system is used to provide healthcare services to patients at their home. It can be observed, telecare medicine information systems generally suffer several attacks as information being transmitted over a public network. Therefore, various authentication and key agreement schemes are proposed for TMIS to ensure secure and authorized patients communication over given public network. However, most of the schemes fail to achieve essential attributes discussed in this article. Although the key attributes of security and efficiency should be achieved in a common framework. This paper proposes construction of an RSA based authentication scheme for authorized access to healthcare services and achieves desirable key attributes of authentication protocols. Proof of security against polynomial time adversary is given in the random oracle to justify the security of proposed scheme. Communication analysis and computation analysis of proposed scheme indicates that proposed scheme's performance is comparable and having better security.