Most enterprises utilize smart card-based authentication systems to facilitate smooth remote access. To address this demand, researchers have devised remote authentication protocols based on dynamic IDs tailored for multi-server deployment to enhance the security of interactions between users and servers. Andola et al. have recently introduced a novel smart card-centric remote user authentication protocol tailored for these intricate environments. They assert that their framework not only ensures mutual authentication and key agreement but also guarantees user anonymity while fortifying resilience against a spectrum of potential attacks. However, despite these claims, their scheme has inherent vulnerabilities that could lead to information leakage and compromise user privacy. To address these concerns, we propose a robust and anonymous authentication scheme utilizing smart cards and dynamic IDs to effectively mitigate various vulnerabilities. Our scheme is designed to withstand various attacks. To validate its strength, we conducted an informal security analysis to demonstrate its resilience to existing attacks. Furthermore, in-depth formal security analyses were performed using ProVerif, the Random Oracle Model, and BAN Logic to provide comprehensive validation of the proposed protocol’s safety. Additionally, a performance analysis demonstrates the proposed scheme’s effectiveness.
The rapid convergence of artificial intelligence (AI), cloud computing, and 5G communication has positioned extended reality (XR) as a core technology bridging the physical and virtual worlds. Encompassing virtual reality (VR), augmented reality (AR), and mixed reality (MR), XR has demonstrated transformative potential across sectors such as healthcare, industry, education, and defense. However, the compact architecture and limited computational capabilities of XR devices render conventional cryptographic authentication schemes inefficient, while the real-time transmission of biometric and positional data introduces significant privacy and security vulnerabilities. To overcome these challenges, this study introduces PXRA (PUF-based XR authentication), a lightweight and secure authentication and key distribution protocol optimized for cloud-assisted XR environments. PXRA utilizes a physically unclonable function (PUF) for device-level hardware authentication and offloads elliptic curve cryptography (ECC) operations to the cloud to enhance computational efficiency. Authenticated encryption with associated data (AEAD) ensures message confidentiality and integrity, while formal verification through ProVerif confirms the protocol's robustness under the Dolev-Yao adversary model. Experimental results demonstrate that PXRA reduces device-side computational overhead by restricting XR terminals to lightweight PUF and hash functions, achieving an average authentication latency below 15 ms sufficient for real-time XR performance. Formal analysis verifies PXRA's resistance to replay, impersonation, and key compromise attacks, while preserving user anonymity and session unlinkability. These findings establish the feasibility of integrating hardware-based PUF authentication with cloud-assisted cryptographic computation to enable secure, scalable, and real-time XR systems. The proposed framework lays a foundation for future XR applications in telemedicine, remote collaboration, and immersive education, where both performance and privacy preservation are paramount. Our contribution lies in a hybrid PUF-cloud ECC architecture, context-bound AEAD for session-splicing resistance, and a noise-resilient BCH-based fuzzy extractor supporting up to 15% BER.
Medical Internet of Things (IoT) systems can be used to monitor and treat patient health conditions. Security and privacy issues in medical IoT services are more important than those in any other IoT-enabled service. Therefore, various mutual authentication and key-distribution schemes have been proposed for secure communication in medical IoT services. We analyzed Hu et al.’s scheme and found that an attacker can impersonate legitimate sensor nodes and generate illegitimate session keys using the information stored in the sensor node and the information transmitted over the public channel. To overcome these vulnerabilities, we propose a scheme that utilizes physically unclonable functions to ensure a secure session key distribution and increase the computational efficiency of resource-limited sensor nodes. In addition, the proposed scheme enhances privacy protection using pseudonyms, which we prove using a formal security analysis tool, ProVerif 2.05.
Medical Internet of Things (IoT) systems are crucial in monitoring the health status of patients. Recently, telemedicine services that manage patients remotely by receiving real-time health information from IoT devices attached to or carried by them have experienced significant growth. A primary concern in medical IoT services is ensuring the security of transmitted information and protecting patient privacy. To address these challenges, various authentication schemes have been proposed. We analyze the authentication scheme by Wang et al. and identified several limitations. Specifically, an attacker can exploit information stored in an IoT device to generate an illegitimate session key. Additionally, despite using a cloud center, the scheme lacks efficiency. To overcome these limitations, we propose an authentication and key distribution scheme that incorporates a physically unclonable function (PUF) and public-key computation. To enhance efficiency, computationally intensive public-key operations are performed exclusively in the cloud center. Furthermore, our scheme addresses privacy concerns by employing a temporary ID for IoT devices used to identify patients. We validate the security of our approach using the formal security analysis tool ProVerif.
As distributed energy resources (DER) are increasing, a variety of business models and markets are appearing. Business models such as virtual power plants (VPPs) contribute to enhanced stability of the power system while improving the profits of participating resources. However, the uncertainty of the behavior of DERs and the resulting stability issues are a major barrier to DER deployment and require a coordination framework between grid operators and business models to overcome. Therefore, in this paper, a hierarchical robust day-ahead coordination of a VPP and distribution system operator (DSO) based on the local market is proposed to improve the voltage stability of the distribution network by considering the uncertainty of DERs. For fairness reasons, the contribution of DERs to the distribution system can be addressed by a market-based approach. Local markets are divided into local energy markets (LEM) and local flexibility markets (LFM), which can consider the uncertainty and profitability of DERs. First, the DER determines the seller and buyer status of the LEM based on its self- scheduling with expected prices and is matched based on a double-auction mechanism. At this time, the worst-case scenario of load and renewable energy generation predicted by the Gaussian process (GP) is considered. The mismatched amounts in the LEM are aggregated by the VPP and bid into the wholesale energy market (WEM) operated by the TSO (Transmission system operator). Subsequently, DSO operates a LFM that coordinates microgrid (MG) and VPP on the distribution grid to increase voltage stability. The LFM and WEM problems are considered as interval optimization in the form of mixed integer linear programming and are applied together. The flexibility supply resulting from the adjustment of VPP is compensated by a loss-sensitivity-based flexibility price. Since voltage stability exists in upper and lower bounds, the upper and lower bound of net load through GP-based forecasting is considered along with the linearized network constraints. The results are validated through Monte-Carlo simulation-based scenarios on IEEE benchmark system in MATLAB environment. As a result, it is proved that the proposed model improves the distribution network voltage stability and the profit of the participants.
The Internet of Things (IoT) is progressively being integrated into everyday life, with cloud computing systems being widely employed to monitor and manage IoT devices. Cloud servers offer centralized high-performance processing of large-scale data utilizing millions of connected sensors and geographically distributed devices. Distributed data processing with low latency is important for autonomous driving, healthcare, virtual reality, and augmented reality in cloud services based on 5G technology. Mobile edge computing (MEC) infrastructure enables cloud services at the edge of the network in a 5G ecosystem, allowing for real-time processing of large amounts of data. MEC involves an open infrastructure that allows for access by heterogeneous devices, increasing the complexity of security challenge. This, in turn, brings the potential risk of attacks that could result in information leakage and compromise the privacy of users. In extreme cases, attacks may even pose a risk to human life. Thus, an effective authentication mechanism is required to prevent attacks and protect privacy in MEC environments. To address this issue, we propose a secure and anonymous authentication scheme that enhances security in MEC environments. In the proposed scheme, the user and MEC server establish a secure session key without the need of a trusted third party. The proposed scheme is designed to be secure from various known attacks attempted by internal and external adversaries. We have conducted both formal and informal analyses to prove the security of the proposed scheme and compared its performance with related schemes to validate its effectiveness and practical application.
As decarbonization policies emerge around the world, research on cost-effective renewable energy is increasingly emphasized, but the uncertainty inherent in renewable energy disrupts the operation of power systems. Considering these issues, this paper presents a peer-to-peer (P2P) transaction platform that minimizes the cost of each transaction participant while considering photovoltaic (PV) generation uncertainty using stochastic programming. First, in the proposed algorithm, P2P energy transactions are conducted between prosumers who own PV and consumers. Then, prosumers purchase uncertainty demand response (UDR) capacity from consumers to counter the uncertainty of their PV. The performance of the proposed platform is verified through a case study using MATLAB 2021b Academic, Optimization Tool toolbox, and MATPOWER toolbox to demonstrate the economic feasibility by comparing the operating costs of participants and the power flow of Point of common coupling (PCC) with and without UDR transaction. The case studies show that the prosumers reduce the cost damage caused by the PV generation forecast error through the day-ahead UDR transaction, and the consumers reduce operating cost by bidding additional capacity in the UDR transaction that was not matched in the P2P transaction. In addition, the result of the power flow analysis indicates that the subject grid operates closer to day-ahead scheduling when the UDR transactions and implementations are performed.
Smart grids integrate information and communications technology into the processes of electricity production, transportation, and consumption, thereby enabling interactions between power suppliers and consumers to increase the efficiency of the power grid. To achieve this, smart meters (SMs) are installed in households or buildings to measure electricity usage and allow power suppliers or consumers to monitor and manage it in real time. However, SMs require a secure service to address malicious attacks during memory protection and communication processes and a lightweight communication protocol suitable for devices with computational and communication constraints. This paper proposes an authentication protocol based on a one-way hash function to address these issues. This protocol includes message authentication functions to address message tampering and uses a changing encryption key for secure communication during each transmission. The security and performance analysis of this protocol shows that it can address existing attacks and provides 105,281.67% better computational efficiency than previous methods.
Forecasting accuracy of electricity prices is crucial to the optimal operation of the electricity market, as improper forecasting can lead to inefficiencies, increased costs, and market instability. Thus, it is highly desired to develop a robust electricity price forecasting framework. The development of an optimal forecasting model depends on the proper choice of exogenous variables, and as the impact/characteristics of the input variables may change over time, thus the choice of appropriate external variables should be a dynamic task. Therefore, it is necessary to develop an online adaptive forecasting model, which will not only continuously forecast but also learn automatically by sensing the changes in the relationship of the variables. To sense the changes and to develop a parsimonious model proper feature engineering is required. Multi-level correlation with multicollinearity has been considered as the feature engineering tool for online training to create an accurate forecasting model. After analyzing existing studies and analyzing the gaps, an approach is proposed, utilizing a General Regression Neural Network (GRNN) with advanced feature engineering and simultaneous adaptive learning, that can outperform traditional models like ANN, RNN, and LSTM in terms of forecasting accuracy.
We report on the first production of an antihydrogen beam by charge exchange of 6.1 keV antiprotons with a cloud of positronium in the GBAR experiment at CERN. The antiproton beam was delivered by the AD/ELENA facility. The positronium target was produced from a positron beam itself obtained from an electron linear accelerator. We observe an excess over background indicating antihydrogen production with a significance of 3-4 standard deviations.
Federated authentication, such as Google ID, enables users to conveniently access multiple websites using a single login credential. Despite this convenience, securing federated authentication services requires addressing a single point of failure, which can result from using a centralized authentication server. In addition, because the same login credentials are used, anonymity and protection against user impersonation attacks must be ensured. Recently, researchers introduced distributed authentication schemes based on blockchains and smart contracts (SCs) for systems that require high availability and reliability. Data on a blockchain are immutable, and deployed SCs cannot be changed or tampered with. Nonetheless, updates may be necessary to fix programming bugs or modify business logic. Recently, methods for updating SCs to address these issues have been investigated. Therefore, this study proposes a distributed and federated authentication scheme that uses SCs to overcome a single point of failure. Additionally, an updatable SC is designed to fix programming bugs, add to the function of an SC, or modify business logic. ProVerif, which is a widely known cryptographic protocol verification tool, confirms that the proposed scheme can provide protection against various security threats, such as single point of failure, user impersonation attacks, and user anonymity, which is vital in federated authentication services. In addition, the proposed scheme exhibits a performance improvement of 71% compared with other related schemes.
With the increasing popularity of electric vehicles (EVs), countries are setting up new charging stations to meet up the rising demand. Therefore, accurately forecasting charging demand and charging events is highly significant. Historical data are crucial for developing a quality forecasting model, but countries or locations with recently installed EV stations suffer from data inadequacy. Delayed data accumulation for forecasting model creation impedes EV's optimal operation, and an offline or fixed-sized data-based learning model may not perform optimally due to the future uncertainties of input variables. Therefore, it is required to create an online forecasting model that can learn right from the beginning of the operation of charging stations, forecast, and relearn, when necessary, by considering the impact of input/external variables. For optimal model development, impactful input variables should be chosen online using appropriate feature engineering. In this research, a unique feature engineering considering multi-level correlation with multicollinearity and simultaneous online learning General Regression Neural Network (GRNN) based on has been suggested. Also due to the discrete and asynchronous nature of the charging event a detailed data handling method has been developed to create meaningful time series data. It is interestingly realized that the proposed model outperforms general Artificial Neural Networks (ANN), various sophisticated models, such as Recurrent Neural Networks (RNN), Long Short-Term Memory (LSTM), Bi-LSTM, Gated Recurrent Unit (GRU), and the Deep Neural Network (DNN) model when the appropriate inputs and their delayed variables are used.
Recently, data experts can obtain a large amount of data with the development of the Internet. When computing such data, cloud services that do not use the personal device's memory are becoming popular. However, storing sensitive data as a source in the cloud carries the risk of hijacking. To compensate for this, homomorphic encryption, which encrypts and stores sensitive data, and can safely operate in an encrypted state, is being studied. In this paper, we analyze four methods of partially homomorphic encryption among homomorphic encryption methods. We compare and analyze the key size and ciphertext size of four partially homomorphic encryptions, Paillier, ElGamal, ASHE, and Symmetria.
The Internet of Medical Things (IoMT) is used in the medical ecosystem through medical IoT sensors, such as blood glucose, heart rate, temperature, and pulse sensors. To maintain a secure sensor network and a stable IoMT environment, it is important to protect the medical IoT sensors themselves and the patient medical data they collect from various security threats. Medical IoT sensors attached to the patient's body must be protected from security threats, such as being controlled by unauthorized persons or transmitting erroneous medical data. In IoMT authentication, it is necessary to be sensitive to the following attack techniques. (1) The offline password guessing attack easily predicts a healthcare administrator's password offline and allows for easy access to the healthcare worker's account. (2) Privileged-insider attacks executed through impersonation are an easy way for an attacker to gain access to a healthcare administrator's environment. Recently, previous research proposed a lightweight and anonymity preserving user authentication scheme for IoT-based healthcare. However, this scheme was vulnerable to offline password guessing, impersonation, and privileged insider attacks. These attacks expose not only the patients' medical data such as blood pressure, pulse, and body temperature but also the patients' registration number, phone number, and guardian. To overcome these weaknesses, in the present study we propose an improved lightweight user authentication scheme for the Internet of Medical Things (IoMT). In our scheme, the hash function and XOR operation are used for operation in low-spec healthcare IoT sensor. The automatic cryptographic protocol tool ProVerif confirmed the security of the proposed scheme. Finally, we show that the proposed scheme is more secure than other protocols and that it has 266.48% better performance than schemes that have been previously described in other studies.
The modern power system is becoming a more inverter dominant system. In inverter dominant systems the grids can be controlled using grid forming and grid following converters. Historically the grids are controlled by the separate operation of such kinds of inverters. But often, for small systems or microgrids, the cost of the system and reliability can be improved only by using a single inverter with two different controllers acting based on grid conditions. In this work, a novel Monte Carlo Artificial Bee Colony (ABC) optimized fractional-order PI controllers have been used to develop a single inverter to operate optimally on both grid-connected and islanding conditions. Monte Carlo simulation has been performed for determining the initial optimal search space for the optimizer. The performance of the proposed controller has been compared with two other different optimization algorithms namely, Particle Swarm Optimization (PSO) and Gray Wolf Optimization (GWO). The performance of the proposed controller has been validated in different scenarios by real-time simulation in OPAL-RT.
Fast Proxy Mobile IPv6 (FPMIPv6) is an extension of the PMIPv6 mobility management deployed as part of the next-generation internet protocol. It allows location-independent routing of IP datagrams, based on local mobility to IPv6 hosts without involvement of stations in the IP address signaling. A mobile node keeps its IP address constant as it moves from link to link, which avoids signaling overhead and latency associated with changing IP address. Even though local mobility requirements hold, it entails security threats such as Mobile Node, Mobile Access Gateway, as well as Local Mobility Anchor impersonation that go beyond those already exist in IPv6. As mobile station keeps moving across different serving networks, its IP remains constant during handover, and location privacy may not also be preserved. Moreover, homogeneous network dependence of PMIPv6 is one of the gaps, which FPMIPv6 could not mitigate. FPMIPv6 does not support heterogeneous network handover, for which numerous researchers have proposed Media Independent Handover (MIH) enabled FPMIPv6 schemes to allow fast handover among heterogeneous networks, but in the absence of security solutions. As a comprehensive solution, we propose a new handover authentication scheme and a key agreement protocol for the ‘MIH-enabled Network Only FPMIPv6’ model. As one of the basic requirements, mobility management should minimize signaling overhead, handover delay and power consumption of the mobile node. The proposed scheme improves wireless link overhead (mobile node overhead) by 6-86% as cell radius, wireless failure probability and number of hop vary. The security of the proposed scheme has also been analyzed under BAN logic and Automated Validation of Internet Security Protocols and Applications (AVISPA) tool and its performance has numerically been evaluated through a pre-determined performance matrix and found to be effective and preferably applicable compared with other schemes.
With the rapid development of mobile devices and information technology in recent years, electronic contract systems, by which mutually agreed contracts can be easily and conveniently signed and stored, have steadily advanced. In addition, as the concept of self-sovereign identity has emerged, it is recommended to select and submit only the data an individual wants to prove, out of all data related to the individual, when using data that contains personal information. Although several multi-signature schemes have been proposed, they have limitations such as sequential signing or disclosure of the original data. Thus, in this paper we developed and implemented a Multi-signature scheme, in which only the data to be verified are disclosed and verified. We analyzed the security of the scheme to demonstrate its usability in electronic contract system environments.
The rapid growth of the Internet of Things (IoT) has enabled prompt services over mobile devices. The Global Mobility Network (GLOMONET) is an important global network that allows mobile users to access the Internet anywhere. Although implementing a secure mechanism in GLOMONET is a difficult and complex task due to the computational and processing limitations of most mobile devices, an authentication system is vital for secure communications among such mobile devices. In 2021, Rahmani et al. proposed an authentication method, called the advanced mobile authentication protocol for GLOMONET (AMAPG). However, we found three serious vulnerabilities in AMAPG. First, AMAPG contains large amounts of information on the smart card of the mobile phone. Therefore, they are vulnerable to attacks that steal critical information. Second, it is susceptible to password-guessing attacks. Third, AMAPG cannot guarantee the security of future messages because attackers can steal the session key. In this study, we discuss the weaknesses of AMAPG and propose a new three-factor authentication scheme called the secure mobile authentication scheme for GLOMONET (SMASG). We performed informal and formal security analyses using ProVerif and BAN Logic on SMASG. In addition, we analyzed and compared its performance with that of the latest GLOMONET-based authentication schemes. SMASG saves an average of 93% time in user login and authentication phase.
Split learning is considered a state-of-the-art solution for machine learning privacy that takes place between clients and servers. In this way, the model is split and trained, so that the original data does not move to the client from the server, and the model is properly split between the client and the server, reducing the burden of training. This paper introduces the concept of split learning, reviews traditional, novel, and state-of-the-art split learning methods, and discusses current challenges and trends.