As a significant building block in the intelligent healthcare system, wireless body area networks (WBANs) collect users’ real-time biomedical data, enabling application providers to provide wide medical services. Due to the open environment and wireless transmission of WBANs, the sensitive biomedical data suffers from various security threats. Although authenticated key agreement (AKA) is a promising technology to deal with these threats, the existing AKA protocols encounter deficiencies in security, privacy, and practicality. Therefore, in this paper, we propose a blockchain-aided authenticated key agreement protocol with message-dependent traceability (BAKA-MT) for WBANs. In the proposed BAKA-MT, the user device can establish one or more different session keys with application providers to guarantee security of the transmitted biomedical data. Meanwhile, the manager is able to monitor network status by revealing the real identity of malicious entities that release illegal messages. Conversely, the identity privacy of honest entities transmitting legitimate data is still protected. In addition, blockchain with smart contract is adopted in BAKA-MT to ensure mutual authentication between communication entities and revoke malicious entities. Finally, the rigorous security proof and performance evaluation demonstrate that BAKA-MT is secure and practical.
In vehicular ad hoc networks (VANETs), various in-vehicle services have been provided through data sharing to enhance traffic safety and reduce accident rates. Cryptographic techniques have been employed in data sharing to resolve security concerns arising from the complexity of the communication environment in VANETs. However, existing schemes still suffer from challenges regarding practicality, security, and functionality. In this paper, by introducing an innovative primitive named traceable attribute-based conditional proxy re-encryption, we design TFDS-DPC, a traceable fine-grained data sharing scheme with dual policy control for VANETs. In TFDS-DPC, application service providers are capable of controlling vehicle access to services at a fine-grained level. By specifying access and authorization policies, data subscribers can share service data with others in a flexible and controllable manner. Furthermore, malicious vehicles engaged in leaking their secret keys for profit can be tracked down effectively. TFDS-DPC is confirmed to attain the expected design goals through rigorous analysis. The comprehensive performance evaluation indicates that TFDS-DPC offers richer functionality and superior efficiency than related schemes, being more suitable for VANETs.
As the sharp growth of cloud storage, a rising quantity of public auditing techniques are employed to check outsourced data integrity. However, existing public auditing schemes have issues with storage efficiency, security, and practicality. During the traditional auditing process, the cloud is required to store all data blocks and corresponding tags, resulting in poor storage space utilization. Besides, public auditing schemes that leverage the public key infrastructure (PKI) encounter certificate management challenges, and identity-based schemes inherently suffer from key escrow vulnerabilities. Furthermore, the demand for data dynamic operations cannot be well implemented in existing schemes. Therefore, this article proposes a storage-efficient certificateless public auditing (SECPA) scheme with data dynamics, which allows any authorized third-party auditor (TPA) to perform integrity checking such that outsourced data will not be tampered with. Meanwhile, an improved locally verifiable technology is designed to optimize the cloud storage resources. In addition, our scheme avoids the certificate management and key escrow problems while supporting the user to conduct data insertion, deletion, and modification. The security analysis demonstrates that SECPA fulfills unforgeability, auditing soundness, data privacy protection, and detectability. The experiment results indicate that our scheme exhibits appropriate performance.
Vehicle platoon, an increasingly significant technology in vehicular ad hoc networks (VANETs), effectively reduces energy consumption and environmental pollution, mitigates traffic congestion, and enhances road capacity and traffic safety. Collaborative communication between platoons is available to promote the reliability of data dissemination, ameliorate driving strategies, and further strengthen traffic efficiency. Nevertheless, existing efforts for secure multi-platoon data dissemination still face the following issues: (i) lack of a direct authorization strategy for platoons working on different systems; (ii) no effective mechanism to protect vehicle privacy during platoon communications; (iii) absence of a practical verification approach for cross-system ciphertext transformation. This paper builds a privacy-preserving and verifiable cross-system authorization (PVCA) scheme to mitigate the above issues. Specifically, we first put forth the optimized anonymous identity-based broadcast encryption (IBBE) and policy-hiding attribute-based encryption (ABE) protocols to adapt platoon communications while protecting identity and attribute privacy. After that, the authorized token bridging the proposed protocols is designed to enable ciphertexts of IBBE format to be transformed into new ciphertexts of ABE format, enabling flexible authorization. Furthermore, inspired by the Fujisaki-Okamoto transformation, we devise an efficient zero knowledge proof of knowledge protocol, making our PVCA achieve verifiability and fairness. Rigorous security proof and analysis demonstrate that our PVCA is not only secure against chosen plaintext attacks and collusion attacks, but also satisfies the necessary security requirements. We implement a prototype of PVCA (on a desktop computer and Raspberry Pi) and provide a simulation utilizing NS-2 to validate its feasibility for platoon communications in VANETs. The results indicate that, compared to the state-of-the-art ciphertext transformation solutions, PVCA reduces the running time for original ciphertext generation, transformation, and decryption by at least 91.57%, 49.87%, and 50%, respectively, while compressing the original ciphertext and authorization token sizes by over 78.07% and 15.20%.
Threshold attribute-based anonymous credentials improve the security of traditional credentials systems by distributing the power of credential issuance across multiple independent issuers, and have attracted widespread attention, particularly for decentralized systems such as blockchain. However, existing solutions still exhibit shortcomings in terms of scalability, security, flexibility, and practicality. In this paper, we introduce EDT-ABC, an expressive dynamic threshold attribute-based anonymous credential system with succinct showing. Specifically, EDT-ABC allows each issuer to generate the secret key independently without relying on distributed key generation protocols or a trusted party. The thresholds can be dynamically adjusted, enabling verifiers to flexibly define thresholds for different services. Meanwhile, EDT-ABC achieves more expressive and practical selective disclosure by supporting non-possession proofs. By putting forth two novel primitives called universal set commitments and structure-preserving multi-signatures on equivalence classes with randomizable tags, which may both be of independent interest, we design a generic construction of EDT-ABC with provable security and provide an efficient instantiation. Comprehensive performance evaluation on personal computer and Raspberry Pi demonstrates that, compared to existing solutions, our EDT-ABC decreases the running time for issuing and showing the credentials by at least 67.44% and 28.78%, respectively, while achieving a token size reduction of over 82.10%.
As a critical technology in the era of vehicle interconnection, vehicular ad hoc networks (VANETs) have significantly improved various aspects of transportation, such as traffic efficiency, driving safety, and traveling comfort. With the privacy and security problems in mind, conditional privacy-preserving authentication (CPPA) schemes are introduced. However, existing efforts still have some issues regarding practicality, efficiency, and security. To solve these challenges, this paper constructs a communication-efficient CPPA (CE-CPPA) scheme based on ring signature in VANETs. With the transformation of the signature format and employment of the non-interactive sum argument technique, a logarithmic-size signature is realized by CE-CPPA, improving the communication efficiency. Meanwhile, by devising the concise tag containing information about the event and real signer, CE-CPPA realizes traceability and linkability simultaneously. Furthermore, the certificate management and key escrow problems are eliminated combining with certificateless cryptography. Rigorous security analysis indicates that CE-CPPA not only achieves unforgeability and anonymity but also meets the necessary security requirements. Comprehensive performance evaluation indicates that our CE-CPPA is feasible and efficient enough for VANETs security-related applications.
The diverse properties of wireless networks are fulfilled with the assistance of digital twin (DT), which utilizes a virtual model of the physical object (PO) to provide predictions and control decisions. However, the open wireless channels and key leakage of compromised entities (including DT and PO) pose significant security issues, highlighting the need for secure data transmission schemes. Meanwhile, it is impractical to directly apply the existing works and cryptographic primitives to DT-empowered wireless networks (DTWNs) due to the absence of a solution to capture the security requirements comprehensively. Moreover, the essential characteristics for protecting historical data cannot be met. Therefore, this paper proposes a security-enhanced data transmission scheme with fine-grained and flexible revocation by customizing a novel cryptographic primitive named forward-secure puncturable signed encryption (FS-PSE). Our scheme enables confidential data dissemination/acquisition between the physical and virtual space while ensuring authentication of the real-time information and feedback results. In addition, three revocation modes are defined. Based on these modes, the entities can flexibly revoke any decryption-&-signature, decryption, and signature capability in a fine-grained approach, thereby providing security protections for the historically transmitted data even though the entity is compromised. Moreover, our scheme is instantiated with a concrete FS-PSE construction and extended to support outsourced computing to improve efficiency. Finally, the formal security proof and performance evaluation demonstrate the security and practicality of our scheme.
In vehicular digital twin networks (VDTNs), digital twin (DT) can assist the vehicle in data handling and report traffic data to the management server, thereby providing enhanced and scalable services for intelligent transport systems. However, the reported data may suffer from forgery and eavesdropping attacks due to the transmission on the open channel. In addition, a critical threat in VDTNs is the physical vehicle capture attack, namely, an adversary is capable of compromising the vehicle to obtain the current secret key, which can break the reliability of historical reported data and make the services provided by DT unavailable. Puncturable signature (PS) is a promising solution to eliminate these concerns, despite that the existing PS constructions have non-negligible false-positive errors and impose a significant cost on practical deployments. In this article, we design a novel PS and apply it to privacy-aware data reporting protocol (PA-DRP) for VDTNs. Specifically, the designed PS adopts a derivation-based way to achieve puncturing functionality, which is free from false-positive errors while extremely reducing the storage overhead of the secret keys. Meanwhile, we employ the designed PS to construct PA-DRP that enjoys authentication and forward security. Additionally, PA-DRP not only allows DT to remove privacy-sensitive information from the signed data but also provides fuzzy identity for protecting the real identity of the vehicle. Furthermore, the security analysis and performance evaluation demonstrate that the designed PS and PA-DRP not only can withstand various security and privacy assaults for VDTNs but also are efficient and practical.
In recent years, with the increasing prevalence of online group chat applications, malicious information has been more easily disseminated on the internet. Asymmetric group message franking (AGMF) allows users to report received malicious messages to moderators, achieving content moderation in large-scale online end-to-end messaging systems. However, the state-of-the-art construction is built upon traditional public key cryptosystems, resulting in the complex certificate management problem. This paper systematically explores identity-based AGMF (IB-AGMF) to resolve this issue. Specifically, we first introduce a novel primitive called hash proof system-based anonymous identity-based key encapsulation mechanism supporting sigma protocol (HPS-AIB-KEMS) and present a practical construction based on DBDH assumption. After formalizing the concept and security notions of IB-AGMF, we propose the generic construction of IB-AGMF based on HPS-AIB-KEMS and non-interactive zero knowledge proof system. Finally, we conduct comprehensive performance evaluations and comparisons to demonstrate the feasibility of IB-AGMF in group communication scenarios.
Vehicular social networks (VSNs), as an innovative mobile communication system, significantly enhance the driving experience and improve urban traffic management efficiency. To address the privacy issues that arise from the use of public channels in VSNs, fine-grained access control (AC) should be ensured. Nevertheless, existing schemes still face some practical challenges in the aspects of data source identification, key escrow, and dynamic vehicle management. Therefore, this article proposes a registration-based bilateral fine-grained AC scheme (RBF-AC) in VSNs. Specifically, RBF-AC allows service providers (SPs) to select target vehicles and offer tailored services, while allowing vehicles to identify the most suitable SPs based on their needs, and all of which are realized in a fine-grained level. Meanwhile, SPs and vehicles are capable of locally generating their own private and public keys without relying on any fully trusted authority. RBF-AC also keeps high flexibility and enables the vehicles to join, leave and update their attributes in a dynamic manner. Additionally, outsourced verification and decryption are provided to minimize the computation cost for vehicles. We present formal security proofs to validate the security of RFB-AC. The performance evaluation illustrates the practical applicability of RBF-AC in VSNs.
Linear codes are widely studied due to their applications in communication, cryptography, quantum codes, distributed storage and many other fields. In this paper, we use the trace and norm functions over finite fields to construct a family of linear codes. The weight distributions of the codes are determined in three cases via Gaussian sums. The codes are shown to be self-orthogonal divisible codes with only three, four or five nonzero weights in these cases. In particular, we prove that this family of linear codes has locality 2. Several optimal or almost optimal linear codes and locally recoverable codes are derived. In particular, an infinite family of distance-optimal binary linear codes with respect to the sphere-packing bound is obtained. The self-orthogonal codes derived in this paper can be used to construct lattices and have nice application in distributed storage.
As an emerging class of internet of vehicles, vehicular social networks (VSNs) provide passengers, drivers, and vehicles with extensive data sharing services to improve traffic congestion and road safety. However, the insecure transmissions of shared data may disclose sensitive information, such as private data, location, and driving route. Although attribute-based encryption (ABE) is a promising technology to enable secure data sharing, the existing ABE solutions applied to VSNs encounter three-fold deficiencies: (1) the shared data stored in vehicular cloud server would be leaked in the event of key compromise; (2) relying on one or more fully trusted entities to generate keys for vehicles through secure channels; (3) private information leakage and misbehavior of data user vehicles are neglected. Motivated by these challenges, this article proposes a puncturable registered ABE scheme called PR-ABE for VSNs with enhanced security and practicality. To be specific, our PR-ABE achieves flexible access control and precise data deletion. The former ensures that only registered vehicles with authorized attributes can obtain the shared data. The latter prevents data disclosure when key compromise happens. Meanwhile, PR-ABE enables vehicles to generate keys independently and eliminates the need for any fully trusted authority. In addition, hidden policy and traceability are fulfilled in PR-ABE to protect private information and deal with malicious vehicles, respectively. Finally, the rigorous security proof and performance evaluation demonstrate that PR-ABE is a practical and efficient solution.
In transportation 5.0, digital twin (DT) is considered a promising paradigm to integrate physical entities into cyber physical systems by collecting massive data. However, the open collection process and key exposure issues bring critical security challenges. Furthermore, applying the existing authentication schemes to data collection in transportation DT (TDT) systems encounters three deficiencies: 1) forward security for collected data can only be achieved at a coarse-grained level; 2) one or more additional trusted authorities are introduced, causing the robustness of TDT systems to be downgraded; 3) dynamic attribute updating and revocability of physical entities are rarely considered. Therefore, we propose a dual fine-grained authentication scheme (DFAS) in this paper. Our DFAS can not only ensure data integrity and authenticity but also enable fine-grained access control, namely, only registered physical entities with authorized attributes can generate valid signatures. Meanwhile, DFAS provides the key puncturing for physical entities to guarantee fine-grained forward security without relying on any trusted authority. In addition, a non-interactive attribute updating and revocation of malicious entities are realized in DFAS. Finally, the security analysis indicates that DFAS can deal with various security challenges for data collection in TDT systems. The performance evaluation demonstrates that DFAS is efficient and practical.
With the continuous development of digitization evolutions, vehicular digital twin networks (VDTNs) facilitate traffic data and optimization results to be exchanged between the vehicle and digital twin as well as shared among a group of digital twins. However, the data exchange and group sharing processes take place in real-time over public communication channels, which suffer from various security and privacy threats. Key agreement technologies are promising to enable secure data communications for entities, but the existing key agreement schemes generally fail to fulfill the requirements of synchronization, privacy, and entity management for VDTNs. Therefore, we propose a blockchain-assisted privacy-preserving and synchronized key agreement scheme for VDTNs. In the proposed scheme, the anonymous vehicle and digital twin can negotiate a secret session key in the case of synchronization to achieve secure data exchange. Meanwhile, digital twins are capable of utilizing synchronized state information to dynamically establish a common group encryption key but hold individual decryption keys, which guarantee the security of group sharing. Additionally, the proposed scheme is able to protect identity privacy and manage vehicles and digital twins with the assistance of blockchain and smart contract. The security analysis demonstrates that the proposed scheme provides security and privacy assurances for VDTNs. The performance evaluation indicates that it has excellent expressions in terms of efficiency, practicality, and smart contract consumption.
The Industrial Internet of Things (IIoT) has brought practical application value to many industries, where significant amounts of IIoT data and resources are outsourced to cloud server (CS) via diverse networks for data fusion, monitoring, sharing, and calculation analysis. Considering privacy, there is a need to execute the encryption operation on the data before outsourcing, while how to retrieve the encrypted data from CS becomes a thorny issue. Furthermore, the untrusted CS in charge of storing and searching the ciphertexts may return incorrect or incomplete search results for some interest. Verifiable public key searchable encryption (VPKSE) provides the ability to encrypt data, retrieve ciphertext, and verify search results simultaneously. However, the malicious behavior of CS has not been sufficiently considered in most existing schemes, that is, their verifiability only ensures the correctness of search results, neglecting completeness. In this paper, the verifiability of VPKSE is re-examined, and three verifiability levels are defined detailedly. On this basis, a blockchain-assisted verifiable certificated-based searchable encryption (BVCBSE) scheme for IIoT is put forward. The integration of blockchain and cryptographic accumulator ensures that an untrusted CS must return correct and complete search results, achieving the highest level of verifiability. In addition, security analysis demonstrates that BVCBSE can resist keyword guessing attack. Performance evaluation illustrates that BVCBSE is efficient and practical.
Vehicular social networks (VSNs), as the convergence of social networks and vehicular ad hoc networks, have brought many useful services to vehicle communication by collecting and sharing data between vehicles. In order to efficiently share data and satisfy the growing requirement of privacy protection, data owners typically encrypt and outsource the data to the cloud. Nevertheless, encryption undoubtedly reduces the availability of shared data, e.g., keyword search. Although a number of schemes supporting keyword search of shared data have been put forward, they still have issues with respect to security, functionality, and efficiency. In this paper, a server-assisted data sharing (SADS) system with support for conjunctive keyword search is presented. Specifically, to resist online keyword guessing attack, we devise an advanced keyword derivation mechanism to derive the keyword set, in which the conception of verifiable parallel oblivious unpredictable function is proposed to check whether the assisted server honestly responds to the derived keyword request. Moreover, the computation and communication costs of keyword trapdoor in SADS are constant. Concurrently, SADS achieves the anonymous data sharing and traceability of malicious vehicle data owner. The security of SADS is formally proved and analyzed. Performance evaluation also shows that our system is efficient and practical.
Vehicular ad hoc networks (VANETs), an increasingly significant technology in intelligent transportation systems, achieve information sharing, intelligent traffic flow control, and road condition prediction through data sharing between vehicles and other devices, enhancing traffic efficiency and driving safety. Nevertheless, there are still challenges to data sharing with respect to efficiency, flexibility, and security. In this paper, we build a flexible selective data sharing with fine-grained erasure (FSDS-FE) scheme in VANETs by introducing the novel cryptographic primitive called puncturable identity-based fine-grained proxy re-encryption and employing identity-based signature. In FSDS-FE, with the support for ciphertext transformation, the vehicles are able to flexibly share the outsourced traffic data with others. Different sharing content can be customized for various entities through fine-grained re-encryption to protect sensitive information. Furthermore, the outsourced traffic data could be erased in a fine-grained way by the vehicles. In order to optimize the efficiency and practicality of FSDS-FE, we construct an improved FSDS-FE scheme by designing a novel puncturable identity-based fine-grained broadcast proxy re-encryption with verifiable outsourced decryption scheme. Rigorous security analysis demonstrates that FSDS-FE can achieve the desired security requirements. The comprehensive performance evaluation shows that our schemes are efficient and practical enough in VANETs.
Vehicular digital twin networks (VDTNs) offer great opportunities for driver safety enhancements. By leveraging digital twin (DT) technology, VDTNs can collect and analyze traffic data to optimize driving routes, and allow the out-of-field vehicles to share traffic data via their DTs. However, the real-time data sharing process over a public channel raises concerns about security and privacy. Existing data sharing schemes cannot be directly adopted for VDTNs because they rarely consider dual (data and identity) privacy, synchronization, and flexibility, while also imposing a significant cost on resource-limited entities. To address these challenges, we propose a secure and flexible data sharing scheme with dual privacy protection for VDTNs. In the proposed scheme, a signature of knowledge protocol is developed for protecting the vehicle’s real identity and ensuring authentication, smart contract algorithms are designed to assist in realizing accountability, and a verification control mechanism is devised for allowing the vehicle to flexibly share the traffic data. Additionally, DT with consistent states is capable of removing sensitive information from the shared data, which guarantees synchronization and data privacy. The security analysis demonstrates that the proposed scheme is resilient against potential security threats in VDTNs. Furthermore, the performance evaluation indicates that the proposed scheme not only outperforms the state-of-the-art schemes but also achieves feasible blockchain consumption and data authentication delay.
Proxy re-encryption, as a cryptographic primitive, allows an untrusted proxy to transform a ciphertext encrypted with the data owner’s public key to a ciphertext encrypted with the authorized user’s public key, without any knowledge of the underlying plaintext, which achieves the sharing of ciphertext data. As an identity-based cryptosystem, SM9 has been adopted as a Chinese national standard and an ISO/IEC international standard. However, the SM9 encryption algorithm can only achieve the function of data encryption without considering the ciphertext transformation. In this paper, based on SM9, we first propose an identity-based proxy re-encryption scheme (termed IBPRE-I). IBPRE-I has the same user secret key as SM9, so it can be effectively integrated with SM9-based systems. Security proof indicates that IBPRE-I achieves the ciphertext indistinguishability against selective identity and chosen plaintext attack, and the secret key leakage resistance against collusion attack in the random oracle model. Then, by extending the IBPRE-I scheme, we present our second scheme IBPRE-II to achieve the security under chosen ciphertext attack. Finally, the performance is evaluated and the results show that the proposed schemes are practical.