Multiparty computation (MPC) is a computation technique where many participants provide their data and jointly compute operations to get a computation result. Earlier MPC protocols were mostly depended on communication between the users. Several schemes have been presented that mainly work by delegating operations to two non-colluding servers. Peter et al. propose a protocol that perfectly eliminates the need of users’ participation during the whole computation process. However, the drawback of their scheme is the excessive dependence on the server communication. To cater this issue, we propose a protocol that reduce server communication overhead using the proxy re-encryption (PRE). Recently, some authors have put forward their efforts based on the PRE. However, these schemes do not achieve the desired goals and suffer from attacks that are based on the collusion between users and server. This paper, first presents a comprehensive analysis of the existing schemes and then proposes a secure and efficient MPC protocol. The proposed protocol completely eliminates the need of users’ participation, incurs less communication overhead and does not need to solve the discrete logarithm problem (DLP) in order to get the computation results.
A vehicular ad hoc network (VANET) serves as an application of the intelligent transportation system that improves traffic safety as well as efficiency. Vehicles in a VANET broadcast traffic and safety-related information used by road safety applications, such as an emergency electronic brake light. The broadcast of these messages in an open-access environment makes security and privacy critical and challenging issues in the VANET. A misuse of this information may lead to a traffic accident and loss of human lives at worse and, therefore, vehicle authentication is a necessary requirement. During authentication, a vehicle's privacy-related data, such as identity and location information, must be kept private. This paper presents an approach for privacy-preserving authentication in a VANET. Our hybrid approach combines the useful features of both the pseudonym-based approaches and the group signature-based approaches to preclude their respective drawbacks. The proposed approach neither requires a vehicle to manage a certificate revocation list, nor indulges vehicles in any group management. The proposed approach utilizes efficient and lightweight pseudonyms that are not only used for message authentication, but also serve as a trapdoor in order to provide conditional anonymity. We present various attack scenarios that show the resilience of the proposed approach against various security and privacy threats. We also provide analysis of computational and communication overhead to show the efficiency of the proposed technique. In addition, we carry out extensive simulations in order to present a detailed network performance analysis. The results show the feasibility of our proposed approach in terms of end-to-end delay and packet delivery ratio.
Proximity Based Mobile Social Networks (PMSN) is a special type of Mobile Social Network (MSN) where a user interacts with other users present in near proximity in order to make social relationships between them. The users' mobile devices directly communicate with each other with the help of Bluetooth/Wi-Fi interfaces. The possible presence of a malicious user in the near proximity poses significant threats to the privacy of legitimate users. Therefore, an efficient trust evaluation mechanism is necessary that enables a legitimate user to evaluate and decide about the trustworthiness of other user in order to make friendship. This paper proposes a protocol that evaluates various parameters in order to calculate a trust value that assists a PMSN user in decision making for building new social ties. This paper describes various components of trust such as friend of friend, credibility and the type of social spot where trust evaluation is being performed and then calculates these parameters in order to compute the final trust value. We utilize semi-trusted servers to authenticate users as well as to perform revocation of malicious users. In case of an attack on servers, real identities of users remain secure. We not only hide the real identity of the user from other users but also from the semi-trusted servers. The inherent mechanism of our trust evaluation protocol provides resilience against Sybil and Man-In-The- Middle (MITM) attacks. Towards the end of the paper, we present various attack scenarios to find the effectiveness and robustness of our trust evaluation protocol.
Vehicular ad hoc network (VANET) is an application of intelligent transportation system (ITS) with emphasis on improving traffic safety as well as efficiency. VANET can be thought as a subset of mobile ad hoc network (MANET) where vehicles form a network by communicating with each other (V2V) or with infrastructure (V2I). Vehicles broadcast not only traffic messages but also safety critical messages such as electronic emergency braking light (EEBL). A misuse of this application may result in a traffic accident and loss of life at worse. This situation makes vehicles' authentication a necessary requirement in VANET. During authentication, vehicle's privacy related data such as vehicle and owner's identity and location information should be kept private in order to prevent an attacker from stealing this information. This paper presents a cloud-assisted conditional privacy preserving authentication (CACPPA) protocol for VANET. CACPPA is a hybrid approach that utilizes both the concept of pseudonym-based approaches and group-signaturebased approaches but cleverly avoids the inherent drawbacks of these approaches. CACPPA neither requires a vehicle to manage a certificate revocation list nor does it require vehicle to manage any groups. In fact an efficient cloud-based certification authority is used to assist vehicles getting credentials and subsequently using them during authentication. CACPPA provides conditional anonymity that a vehicle's anonymity preserved only until it honestly follows the protocol. Furthermore, we analyze CACPPA with various attack scenarios, present a computational and communication cost analysis as well as comparison with existing approaches to show its feasibility and robustness.
Mobile social networks (MSNs) are getting increasingly popular day by day. With the help of MSNs people can connect with each other online as well as offline. One of the famous applications of MSNs is profile matchmaking in which users share their interests in order to find mutual friends. However, the user of such application can be a victim of various privacy related attacks due to the revelations of user's personal interests during profile matchmaking. More recent dimension of MSN is encounter-based social networks. In this scenario, the users make social contacts while sharing a common location and time. Mobile devices record the encounter information when two users are within physical proximity and at a later time, their encounter history should be matched when they try to find each other again. In this paper, we propose a privacy preserving matchmaking protocol in which users share the encounter information and later utilize a cloud server to post encounter information in order to privately match their profiles with unknowns to whom they shared the encounter. In our protocol, neither the users nor the cloud server is able to discover the interests of either participants during matchmaking. To the best of our knowledge, this approach is the first attempt that combines encounter based social networks and fine-grained profile matchmaking. Towards the end of the paper, we present security analysis as well as performance evaluation that shows the effectiveness and feasibility of our protocol.
Bitcoin has emerged as a popular crypto currency. It was introduced in 2008 by Satoshi Nakamoto (A pseudonym). The reasons for its popularity include its decentralized nature, double spending prevention, smart strategy to counter inflation and providing a certain degree of anonymity. In February 2014, Bitcoin community was shocked to know that a Japan based company named Mt. Gox who, were dealing 70 percent of Bitcoin transactions that time, announced that they were hit by a bug in the Bitcoin protocol named as Transaction Malleability. The company lost hundreds of millions of dollars worth bitcoin. Soon after this, another company SilkRoad 2 also claimed to have affected by same issue. To date there is little research literature available on this recent issue and it is hard to grasp this problem. The purpose of writing this paper is twofold. We discuss Transaction Malleability in detail with respect to the structure of Bitcoin transactions in order to make reader properly understands what Transaction Malleability is and how it works. We also propose a mechanism to counter this issue.
Due to the rapid growth of online social networking and mobile devices, proximity based mobile social networks (PMSN) are gaining increasing popularity. PMSN refers to the social interaction among physically proximate mobile users where they directly communicate through Bluetooth/Wi-Fi. In PMSN, while making friends, users match their profiles in accordance with their interests. In this regard, preserving a user's privacy is crucial during profile matching. Users use their profiles for matching. An attacker in user's near proximity can learn these profiles' values. This poses significant threat to a user's privacy. In this regard, we propose a protocol to preserve user's sensitive information. During discovery of friends in our protocol we use a broker that is an intermediate entity between interacting mobile users. Our protocol does not require trustworthy broker and hence no valuable information is given to broker that can cause a privacy threat. For secure computations paillier encryption has been used in our protocol. Furthermore, we implement and analyze our protocol to show its acceptable computational and communication cost.
CAS used in IPTV and DTV was designed to transfer a single content through a single stream. But, if CAS is combined with SVC coding technique, it can be improved to support diverse video applications through a single streaming. In this paper, we analyze the issues that can occur if SVC is applied to CAS, and also propose SVC encryption module in the CAS environment. The proposed scheme's safety is guaranteed by the safety of the existing CAS and oneway hash function. Also, the proposed scheme has an advantage of relatively small overheads in the existing CAS.
Technological advancements in mobile technology and cloud computing open the door for another paradigm known as Mobile Cloud Computing (MCC). This integration of cloud computing and mobile technology gives numerous facilities to a mobile user, such as the ubiquitous availability of Location Based Services (LBS). The utilization of these LBS services require the knowledge of a user's location, hence threatens the privacy of a user. In this paper we take advantages of ultra-fast processing and reliability of cloud computing and aim to solve the privacy threat issue faced by a mobile user while getting LBS services. We propose a model that utilizes a cloud based server which helps in making of a cloaking region. We highlight that how our model utilizes an untrusted cloud based server and eliminates the use of a trusted anonymizer while providing LBS services to a user securely and anonymously.
제한수신시스템(Conditional Access System, CAS)은 사용자의 조건에 따라 방송에 대한 접근을 제어하는 시스템으로 유료 TV 시스템에서 인가된 사용자만이 해당 프로그램에 접근할 수 있도록 하는 콘텐츠 보안 기술이다. 최근에는 기존의 하드웨어 기반 CAS가 가지는 이기종 기기간 호환성, 다른 서비스와의 연동 등의 문제를 해결하고자 CAS의 클라이언트를 소프트웨어로 구현하여 네트워크를 통해 전송하는 다운로드가 가능한 제한수신시스템(Downloadable CAS, DCAS)에 대한 연구와 개발이 활발히 진행되고 있다. 본 논문에서는 서로 다른 DCAS 간 효율적인 상호운용이 가능한 PBC(Pairing Based Cryptography) 기반의 키 생성 및 관리 기법을 제안한다. CAS (Conditional Access System) is a content protection solution that restricts access to the system according to user's standing and only authorized users can access the content in a pay-TV system. DCAS (Downloadable Conditional Access System) can download CAS client which is a software implemented via network. In recent years, research and development has been carried out on DCAS to solve the problems of compatibility among heterogeneous devices and internetworking with other services. In this paper, we propose key generation and management scheme for efficient interoperability among different DCASs based on PBC (Pairing Based Cryptography).
사용자들은 외부 스토리지를 사용함으로써 언제, 어디서나 자신의 데이터에 접근할 수 있다. 하지만 자신의 데이터가 어떻게 관리되고 있는지는 알 수 없다. 심지어 자신의 데이터에 손상이 발생하여도 인지할 수 없다. 이와 같은 불편을 해결하기 위해 외부 스토리지 검증기법들이 제안되었다. 대부분의 기법들이 준동형 검증 태그(homomorphic verifiable tags)를 사용하고 있지만, 이는 데이터를 지수로 하여 계산하기 때문에 효율성에 한계가 있다. 본 논문에서는 외부 스토리지 무결성 검증의 새로운 접근 방법으로써 계수행렬을 이용한 기법을 제안한다. 제안하는 기법은 데이터를 계수행렬의 형태로 변환하여 검증에 사용한다. 검증과정은 선형연립방정식의 해를 구하는 형태로 진행되며, 검증자는 수식에 해벡터를 대입함으로써 쉽게 검증을 수행할 수 있다. 제안하는 기법을 사용하면 검증자는 sqrt(n) 크기의 데이터로 크기가 n인 데이터를 검증할 수 있다. Users can access their data anywhere, at any time by using outsourced storage. But they cannot know how service provider manage the data. Even user cannot know when data damaged. To solve these problems, the outsourced storage auditing schemes has been proposed. Most proposed schemes are based on Homomorphic Verifiable Tags. But it has computational efficiency limitation because data used to exponent. In this paper, we propose a novel approach to outsourced storage auditing scheme using coefficient matrix. In the proposed scheme, data used to auditing by coefficient matrix form. Auditing procedures are proceed as solving the linear simultaneous equation. The auditor can audit easily by solving the equation using solution vector. The auditor can audit the n size data using sqrt(n) size data through out proposed scheme.
As a cornerstone of VANET (Vehicular Ad Hoc Networks) system, vehicles need to have awareness information about other vehicles in the vicinity for safe driving. In this paper, we propose a lightweight geocast-based piggybacking mechanism for cooperative awareness applications in VANET. We leverage only one-hop beacons to construct both local and extended traffic views for drivers. Since multi-hop communication does not scale well, consequently our proposed scheme only exploits single-hop beacons to provide the same comparable functionality as multi-hop communication would do. The goal is achieved at the expense of a small piece of additional information (traffic classes) in the scheduled beacons. Geocast-based piggybacking has a twofold advantage over traditional flooding-based approaches; it serves as virtual multi-hop communication paradigm and it avoids broadcast storm problem.
The foreseen dream of reliable, safe, and comfortable driving experience is yet to become reality since automobile industries are testing their waters for VANET (Vehicular Ad Hoc NETwork) deployment. But nevertheless, security and privacy issues have been the root cause of hindrance in VANET deployment. Recently, VANET evolved to VANET-based clouds as a result of resources-rich high-end cars. Soon after, Hussain et al. defined different architectural frameworks for VANET-based clouds. In this paper, we aim at a specific framework namely VuC (VANET using Clouds) where VANET and CC (Cloud Computing) cooperate with each other in order to provide VANET users (more precisely subscribers) with services. We propose a lightweight privacy-aware revocation and route tracing mechanism for VuC. Beacons broadcasted by vehicles are stored in cloud infrastructure as cooperation from VANET and after processing, cloud provides VANET subscribers with services. Revocation authorities can revoke and trace the path taken by the target node for a specified timespan by exploiting the beacons stored in the cloud. Our proposed scheme is secure, preserves conditional privacy, and is computationally less expensive than the previously proposed schemes.
RSA-CRT is one of the commonly used techniques to speedup RSA operation. Since RSA-CRT performs its operations based on the modulus of two private primes, it is about four times faster than RSA. In RSA, the two primes are normally thrown away after generating the public key pair. However, in RSA-CRT, the two primes are directly used in RSA operations. This led to hardware fault attacks which can be used to factor the public modulus. The most common way to counter these attacks is based on error propagation. In these schemes, all the outputs of RSA are affected by the infected error which makes it difficult for an adversary to use the output to factor the public modulus. However, the error propagation has sequentialized the RSA operation. Moreover, these schemes have been found to be still vulnerable to hardware fault attacks. In this paper, we propose two new RSA-CRT schemes which are both resistant to hardware fault attack and support parallel execution: one uses common modulus and the other one perform operations in each prime modulus. Both proposed schemes takes about a time equal to two exponentiations to complete the RSA operation if parallel execution is fully used and can protect the two private primes from hardware fault attacks.
In this paper, we propose a key management scheme for content protection in the OPMD (One Person Multi Device) environment where one user owns multiple devices. IBTD (ID-Based Threshold Decryption) was applied for the proposed scheme, and this uses the user IDs and the device IDs as their public key. It is the key management scheme that can decrypt the encrypted content only when more than t secret sharing values are combined among the n secret sharing values generated by the contents server. Our scheme enables the users to use their own contents anytime and anywhere on any device that they own. For the contents server, it enables an effective key management which is user-oriented, not device-oriented.
Despite the surge in Vehicular Ad Hoc NETwork (VANET) research, future high-end vehicles are expected to under-utilize the on-board computation, communication, and storage resources. Olariu et al. envisioned the next paradigm shift from conventional VANET to Vehicular Cloud Computing (VCC) by merging VANET with cloud computing. But to date, in the literature, there is no solid architecture for cloud computing from VANET standpoint. In this paper, we put forth the taxonomy of VANET based cloud computing. It is, to the best of our knowledge, the first effort to define VANET Cloud architecture. Additionally we divide VANET clouds into three architectural frameworks named Vehicular Clouds (VC), Vehicles using Clouds (VuC), and Hybrid Vehicular Clouds (HVC). We also outline the unique security and privacy issues and research challenges in VANET clouds.
Recently, various mobile terminals equipped with NFC are released. However, The NFC security standard currently applied uses the user's public key constantly in the process of key agreement. Since it does not provide with unlinkability between user messages, privacy infringement may happen. This paper proposes a method provide a conditional anonymity using dynamic public key to solve this problem. Also it defines PDU for the conditional anonymity, so that the user can use the dynamic public key selectively. Through this, the user can protect privacy and can verify identity through a trusted authority if necessary.