Existing pseudonym certificate schemes fail to adequately address the collaboration needs of multiple entities in the certificate issuance process.To address this,a sanitizable multi-signature(SMS)scheme based on chameleon Hash(CH)and multi-signature(MS)was proposed.By introducing a sanitizability function,SMS scheme allowed authorized sanitizers to update signature data without interacting with the original signers,resolving the issue of rapid response when vehicles frequently change pseudonyms.To prevent the abuse of sanitizability privileges,SMS verified the source of multi-signatures to trace malicious sanitizability actions.Furthermore,the proposed scheme deployed the sanitizability function on road-side units(RSU)and proposed an efficient pseudonym certificate distribution scheme.Security analysis shows that the scheme effectively resists correlation and impersonation attacks,with minimal computational overhead on RSU and vehicles,ensuring good efficiency and security during pseudonym certificate and anonymous authentication processes.
In the multicast communication scenario, compared with broadcast encryption, broadcast signcryption or multi-receiver signcryption has additional ability to authenticate the source of the message. With the enhanced awareness of privacy preservation, ordinary users pay more attention to the identity leakage in the communication process. The primitive of anonymous broadcast signcryption has been proposed to solve this problem, which provides additional anonymity compared with the existing broadcast signcryption. However, most anonymous broadcast signcryption schemes only ensure the sender's identity concealment but ignore the anonymity of the receiver set. In this paper, we present a fully anonymous identity-based broadcast signcryption scheme, which meets insider unforgeability, outsider confidentiality, identity concealment of sender and full anonymity of the receiver set. In addition, our scheme has two further desirable characteristics. One is public verifiability which means any third party can verify the validity of the message source without knowing the private key provided by the receiver. The other is statelessness which means the user does not need to update the private key due to the join or revocation of other users. Moreover, our scheme has constant-size public parameters and private key as well as constant decryption complexity, which makes the scheme more suitable for deployment in devices with limited storage or low computing power such as IoT devices.
In order to resist the security risks caused by quantum computing, post-quantum cryptography (PQC) has been a research focus. Constructing a key encapsulation mechanism (KEM) based on lattices is one of the promising PQC routines. The algebraically structured learning with errors (LWE) problem over power-of-two cyclotomics has been one of the most widely used hardness assumptions for lattice-based cryptographic schemes. However, power-of-two cyclotomic rings may be exploited in the inflexibility of selecting parameters. Recently, trinomial cyclotomic rings of the form Zq[x]/(xn−xn/2+1), where n=2k3l, k≥1,l≥0, have received widespread attention due to their flexible parameter selection. In this paper, we propose Tyber, a variant scheme of the NIST-standardized KEM candidate Kyber over trinomial cyclotomic rings. We provide three parameter sets, aiming at the quantum security of 128, 192, and 256 bits (actually achieving 129, 197, and 276 bits) with matching and negligible error probabilities. When compared to Kyber, our Tyber exhibits stronger quantum security, by 22, 31, and 44 bits, than Kyber for three security levels.
Compared with traditional voting methods, electronic voting can effectively avoid the phenomenon of fraud for personal gains in various links, it is faster and more accurate in the tallying stage. However, many electronic voting systems have many problems such as inability to verify ballots, easy to be forged, and low computing efficiency. We propose an electronic voting protocol based on homomorphic signcryption and blockchain. The protocol makes the voting process public through blockchain and replaces the traditional trusted third party with the smart contract. It uses the homomorphic encryption algorithm and the homomorphic signcryption algorithm to encrypt and sign the ballot and uses their aggregation properties to perform homomorphic tally on the encrypted votes. This not only reduces the excessive burden on the voters but also improves the voting efficiency. At the same time, it can satisfy the security of electronic voting, and the amount of calculation is small, so it is more convenient and flexible to use in large-scale voting.
With the maturity of Internet-of-Things technology, location-based service (LBS) is developing rapidly in intelligent terminal devices, and it brings new vitality to the fields of logistics, transportation, product traceability and so on. The popularity of LBS produces a lot of spatial data, which inevitably brings burden to the storage and management of LBS provider (LBSP). With the help of cloud computing and cloud storage, outsourcing spatial data to cloud server has become a new trend. However, due to the cloud server is not trusted, data outsourcing will face the problems of data disclosure and query disclosure. Range query is a common query in LBS, considering the situation of data outsourcing, this article proposes an accurate range query (ARQ) scheme, which can realize efficient range query while preserving LBSP's data privacy and user's query privacy from being disclosed to the cloud server. The ARQ scheme is suitable for spatial data in any form without being limited to the case that the data points are only integers, which has a certain practical significance. In addition, by dividing the region into atomic regions, ARQ can realize sublinear search time and ensure dynamic update of spatial data. We proved the security of the proposed scheme through security analysis, and demonstrated the effectiveness of the scheme through experiments.
SummaryWith the development of intelligent vehicles, the research on road condition monitoring has attracted much attention in the vehicular ad hoc network (VANET). The combination of VANET, cloud computing, and fog computing provides on‐demand computational resources while creating a lot of new challenges. In this paper, we propose an efficient privacy‐preserving cloud‐fog–based traceable road surface condition monitoring scheme. We use certificateless aggregate signcryption technology to implement multiple messages aggregation verification, which greatly saves computing resources and bandwidth. Moreover, we also use a traceable vehicle pseudo identity generated by a trace authority (TRA) to achieve identity privacy protection. To ensure the privacy of the fog and cloud server, the road condition information is reported in ciphertext format. In addition, the cloud server can perform ciphertext equivalence test operation to distinguish different road condition information of the same area without compromising the confidentiality. The ciphertext, which exceeds the set threshold, is uploaded to the blockchain. It can be stored permanently and never be tampered with or deleted. Finally, we demonstrate the correctness of the proposed scheme and show that the proposed scheme has higher efficiency.
With the enhancement of the positioning function of mobile devices and the upgrade of communication networks, location-based service (LBS) has become an important application of mobile devices. Among the numerous researches on location privacy preservation, cloud-based location privacy preservation has become a hot topic, but it undoubtedly brings new problems such as data confidentiality and user privacy disclosure. This paper proposes an accountable outsourced LBS privacy-preserving scheme. In the outsourcing scenario, in order to make users interact with cloud server to obtain query data, firstly we construct location hierarchical index and attribute hierarchical index based on Bloom Filter, and secondly we divide one region into atomic regions using Hilbert Curve, both of which ensure the privacy of query and improve the efficiency of query. At last, we realize the sharing of encrypted data among different users by accountable proxy re-encryption (APRE) technology, which can effectively suppress the abuse of proxy re-encryption key. We demonstrate the correctness of the proposed scheme through security analysis, and show the effectiveness of the scheme through performance analysis.
More and more users are uploading their data to the cloud without storing any copies locally. Under the premise that cloud users cannot fully trust cloud service providers, how to ensure the integrity of users’ shared data in the cloud storage environment is one of the current research hotspots. In this paper, we propose a secure and effective data sharing scheme for dynamic user groups. (1) In order to realize the user identity tracking and the addition and deletion of dynamic group users, we add a new role called Rights Distribution Center (RDC) in our scheme. (2) To protect the privacy of user identity, when performing third party audit to verify data integrity, it is not possible to determine which user is a specific user. Therefore, the fairness of the audit can be promoted. (3) Define a new integrity audit model for shared cloud data. In this scheme, the user sends the encrypted data to the cloud and the data tag to the Rights Distribution Center (RDC) by using data blindness technology. Finally, we prove the security of the scheme through provable security theory. In addition, the experimental data shows that our proposed scheme is more efficient and scalable than the state-of-the-art solution.