Distributed online social network (DOSN) solves the challenges of single-point failure and user data privacy faced by traditional online social network (OSN). Online discussion group, allowing a user to facilitate the communications with other users, is one of the most important components of (D)OSN. Key management is the key technology to ensure the secure establishment of discussion groups in DOSNs. However, the existing key management schemes for secure discussion group establishment in DOSNs cannot meet the requirements of sender non-restriction, receiver controllability, round optimal, certificate freeness simultaneously. In this paper, we propose a novel key management scheme for secure discussion group establishment in DOSNs. In our scheme, any user could use our key management scheme to initialize a discussion group with a piece of discussion group information. Users who are interested in the group topic contained in the discussion group information can join and leave the discussion group at any time once the discussion group is initialized with one-round communication. Any user/sender can find the users that he/she wants to communicate with by looking up the discussion group information of a discussion group and then send encrypted messages to some or all of the users in the discussion group. Therefore, our scheme achieves sender non-restriction, receiver controllability, round optimal, certificate freeness simultaneously. Security analysis also shows that our scheme achieves confidentiality, authentication, full collusion resistance, known-key security and perfect forward security.
Web services are service-oriented computing technology which allows computers running different operating domains to access and share each other's databases. Each web service is an application (like online business) which may require the private information of users. Thus, it will be important to preserve these web users' individual privacy. The traditional approaches to achieve this goal in web security is to use the cryptographic technologies, such as digital signature, NIZK proof system. Whereas, some recent research results indicate that these cryptographic technologies may suffer from the algorithm substitution attack (ASA). ASA means that the cryptographic technology would be embedded some backdoor in the process of its implementation by the attacker, and with the backdoor information the attacker can steal the user's private information. To address this problem, the concept of cryptographic reverse firewall (CRF) has been introduced, which could sanitize the messages inputting and outputting the user's computer. In this paper, we construct the CRFs for the efficient Pointcheval-Sanders (PS) signature as well as the NIZK proof system.
Mobile ad hoc networks (MANETs) are self-configuring networks of wireless nodes, i.e., mobile devices. Since communications in MANETs occur via wireless channels, it is of significance to secure communications among wireless and mobile nodes. Group key management, as a widely used method for securing group communications, has potentially been used in MANETs for years. Most recently, a secure receiver-unrestricted group key management scheme for MANETs has been proposed, which is used to establish a secure channel among a group of wireless nodes without a trusted dealer, which has some advantages such as eliminating the certificate management problem and receiver restriction. However, a formal security analysis of this scheme is still lacking. Therefore, in this paper, we propose the complete security proof to demonstrate that the scheme satisfies the essential security properties including authentication, message confidentiality, known-key security and dynamic secrecy. We also give a brief discussion about the efficiency of the scheme.
In cloud computing, resources are usually in cloud service provider’s network and typically accessed remotely by the cloud users via public channels. Key agreement enables secure channel establishment over a public channel for the secure communications between a cloud user and a cloud service provider. Existing key agreement protocols for cloud computing suffer from some challenges, e.g., realizing low connection delay, eliminating certificate management problem, enhancing user privacy and avoiding bad randomness. To tackle these challenges, we propose a certificateless 0-RTT anonymous AKA protocol against bad randomness for secure channel establishment in cloud computing. As a 0-RTT protocol, it significantly speeds up the efficiency of the secure channel establishment process. Further, our protocol does not need for the certificates to bind a public key with an entity’s identity and hence solves the certificate management problem. Finally, concrete security analysis of the protocol is also proposed. The protocol not only satisfies the traditional security attributes (e.g., known-key security, unknown key-share), but also strong security guarantees, i.e., user privacy and bad randomness resistance.
There are a number of benefits associated with the deployment of fog computing, for example, by analyzing and computing data from Internet-of-Things (IoT) devices at the fog nodes reduce the bandwidth, computational, and storage overheads at the cloud servers and improve user quality of experience (e.g., due to reduced latency). However, there are also additional security implications and requirements. For example, secure keys are needed to establish secure channels among these distributed fog nodes. Therefore, to facilitate fog nodes in managing secure keys and establishing secure group channels, we present a novel fog system and propose a blockchain-based group key management scheme that builds on an earlier work. We also design a new resource authentication mechanism based on Proof of Work (PoW), and when deployed in our fog system facilitates resource authentication (i.e., a fog node in a fog system can evaluate the capability of a fog device's computing power before the device is permitted to enter the system). Findings from our simulations and secure analysis demonstrate the utility of our system.
迄今为止,大多数密码原语的安全性都依赖于高质量的不可预测的随机数.密码学中,通常用伪随机数生成器(pseudorandom number generator,简称PRNG)生成随机数.因此,密码算法中所用的PRNG的安全性将直接影响着密码算法的安全性.然而,近年来,越来越多的研究结果表明:在实际应用中,很多人为因素会导致PRNG生成的随机数是不随机或可预测的,称这种不安全的PRNG为有后门的PRNG(backdoored pseudorandom number generator,简称BPRNG).BPRNG最典型的例子是双椭圆曲线伪随机数生成器(dual elliptic curves pseudorandom number generator,简 称Dual EC PRNG),其算法于2014年被曝出存在后门.BPRNG的出现,使密码算法的研究面临着新的挑战.因此,研究抗随机数后门攻击的密码算法显得尤为重要.首先概述了抗随机数后门攻击密码算法的研究背景,然后着重对已有抗随机数后门攻击密码算法进行了总结和梳理.
Smart homes are an increasingly common concept, particularly in technologically advanced countries. In these settings, the smart devices [also commonly referred to as the Internet of Things (IoT) devices] typically communicate via the radio frequency (RF) channel. In such an open communication channel, key establishment protocols are used to generate a session key between the command senders and the command receivers. The commands or messages are then encrypted using the session key. However, not all the smart home devices have sufficient computational capability to generate and store session keys. Therefore, in this article, we construct a communication protocol using the home limited channel (HLC). The protocol constructed in this article takes into account the existence of malicious indoor smart devices and the need to defend against such malicious indoor smart devices.
Vehicular cloud (VC) extends cloud computing to vehicles participating in vehicular ad hoc networks, aiming to provide computing and storage services at low cost to vehicles, improve traffic efficiency and safety, ensure real-time services, etc. Due to the highly dynamic nature of VC, it is challenging to efficiently form a dynamic VC securely and anonymously or to securely deliver messages to the dynamic VC without potentially violating the privacy of cloud users. In this paper, we present a concrete secure and privacy-preserving communication scheme for VC establishment and data dissemination. Our scheme allows a group of vehicles that are geographically close to each other to form a VC securely, anonymously and dynamically. This allows vehicle resources to be integrated and shared securely. Once a VC is formed, any cloud user may deliver messages to be securely and anonymously processed in the VC.
Task allocation is a significant research issue in Mobile Crowd Sensing, and research on Mobile Crowd-Sensing has indicated that it can be applied in Vehicle Ad Hoc Networks. However, few of the works pay attention to the task allocation issues in Mobile Crowd-Sensing. In our paper, we propose a task allocation scheme in Mobile Crowd-Sensing. In order to make it applicable to Vehicle Ad Hoc Networks, we introduce the Markov location prediction in our scheme, which can perform a location prediction before the task allocation, and a differential privacy mechanism to protect the location privacy of vehicles. Besides, we design a calculation method of task completion rate that can ensure that the task has a significant probability of completing successfully and the number of notified servers is as small as possible. Experiments are also implemented to evaluate the performance of our scheme, which demonstrate that our proposed scheme is feasible and efficient.
Crowd sensing, an important research direction in wireless communication, realizes the allocation and collection of tasks through the smart devices carried by users. However, in the task allocation process, how to protect user privacy from being leaked and select high-quality users to guarantee the quality of task completion are two major challenges. Particularly, individual quality of service (QoS) affects the quality of the task completion. In this paper, we propose a differentially private task allocation scheme. During the process of task allocation, differential privacy is utilized for the location privacy protection. In addition, in order to reduce unnecessary privacy leakage, we simplify the task allocation process and select users with higher QoS to guarantee the QoS of task. Security analysis and experimental results state that our scheme provides differential privacy protection while ensuring QoS of tasks.
Most of the existing cryptographic schemes, e.g., key agreement protocol, call for good randomness. Otherwise, the security of these cryptographic schemes cannot be fully guaranteed. Nonce-based cryptosystem is recently introduced to improve the security of public key encryption and digital signature schemes by ensuring security when randomness fails. In this paper, we first investigate the security of key agreement protocols when randomness fails. Then we define the security model for nonce-based key agreement protocols and propose a nonce-based key agreement protocol that protects against bad randomness. The new protocol is proven to be secure in our proposed security model.
As the number of vehicles grows, traffic efficiency is becoming a worldwide problem. Intelligent transportation system aims to improve the traffic efficiency, where intelligent traffic light control is an important component. Existing intelligent traffic light control systems face some challenges, e.g., avoiding heavy roadside sensors, resisting malicious vehicles and avoiding single-point failure. To cope with those challenges, we propose two secure intelligent traffic light control schemes using fog computing whose security are based on the hardness of the computational Diffie–Hellman puzzle and the hash collision puzzle respectively. The two schemes assume the traffic lights are fog devices. The first scheme is a simple extension of a recent scheme for defending denial-of-service attacks. We show this simple extension is not efficient when the vehicle density is high. The second scheme is much more efficient and is fog device friendly. Even the vehicle density is high, the traffic light may verify the validity of the vehicles efficiently.