Vehicular ad hoc networks (VANETs) are a critical component of modern transportation systems, offering significant benefits in terms of safety, efficiency, and user experience. However, addressing challenges related to security, privacy, and scalability is essential for their successful implementation and widespread adoption. The verification of digital signatures in VANETs is crucial for security and privacy issues, but it can generate significant communication overhead due to certificate management, signature transmissions, and verification computations. This can lead to scalability issues, where the system becomes less efficient and more prone to delays. In this article, we propose an efficient certificateless aggregate signature scheme (ECLAS) to address the above three challenges. The ECLAS scheme is proven to be a secure certificateless signature scheme against chosen-message attacks in the random oracle model. Therefore, the ECLAS scheme eliminates certificate management in the system. Furthermore, the performance comparison shows that the ECLAS scheme achieves the shortest signature size and the most efficient verification cost for traffic-related message transmissions. Consequently, the ECLAS scheme achieves minimal communication latency in VANETs.
Smart grids enable two-way communication between control centers and smart meters. However, this capability introduces security and privacy risks and has consequently prompted extensive research. Liu et al. proposed a fog-blockchain-assisted certificateless aggregate signcryption (FB-ASC) scheme to achieve confidentiality and unforgeability in smart grids. Our research demonstrates that their signcryption design achieves neither confidentiality nor unforgeability, and we show that the supporting lemmas in their paper do not hold. Under the same system models, we presented effective attacks on their scheme and consequently proposed the FB-ASC+ scheme that provides provable security guarantees against the aforementioned attacks. Comparison results further illustrate its performance advantages over pairing-based alternatives in typical smart-grid scenarios.
A constant-pairing certificateless aggregate signature (CP-CLAS) is a fundamental cryptographic primitive that simultaneously addresses the certificate management and key escrow problems, making it ideal for vehicle-to-grid (V2G) communications. However, the CP-CLAS field still suffers from widespread security vulnerabilities leading to a persistent ”propose-break-propose” cycle. In this paper, we demonstrate that PKI-based and identity-based aggregate signature primitives can be combined to form a two-component CLAS construction. On this basis, we establish a generic modular construction framework with provable security and efficiency preservation guarantees. We further prove two core theorems: the security composition theorem, which states that combining a CMA-secure identity-based primitive with a CMA-secure PKI-based primitive yields a CMA-secure CLAS scheme, and the efficiency preservation theorem, which guarantees that the constant-pairing property is fully preserved. Guided by this framework, we conduct a survey of state-of-the-art primitives and construct a higher performing CMA-secure constant-pairing CLAS scheme. Extensive performance comparisons demonstrate that our scheme outperforms all known counterparts, and our work establishes a unified design methodology for future CLAS research.
Smart grids must safeguard their critical infrastructures against both physical and cyber attacks. Therefore, real-time operation and cybersecurity are two fundamental requirements for smart grid systems. Advanced metering infrastructure (AMI) is a critical part of the smart grid that specifically deals with the measurement, collection, and analysis of electricity usage data. Digital signatures help prevent data tampering and ensure cybersecurity during AMI communications. However, as the number of smart meters and transactions in an AMI network increases, deploying digital signatures can lead to communication delays. This article designs a quasi-constant and synchronized aggregate signature scheme (QCSAS), which can protect usage data without hash functions. The QCSAS scheme simplifies the synchronized aggregate signatures, and is proved secure against chosen message attacks in the random oracle model. The QCSAS scheme incorporates the features of synchronized aggregate signatures, such as the constant aggregate signature size, thereby minimizing the data management system's storage space. Furthermore, the length of usage data does not exceed 12-bit, in compliance with existing governmental standards. The computational cost of multiplying a 12-bit integer is negligible compared to other cryptographic operations. Thus, the verification cost of the QCSAS scheme remains quasi-constant.
Federated learning has been used to collaboratively train a decentralized model without sharing confidential model records. However, many security risks are involved in this regard, and scholars have conducted numerous studies on related topics. Fan et al. proposed a scheme to achieve model unforgeability and confidentiality in blockchained federated learning (lightweight privacy blockchained federated-learning (LPBFL) scheme) in the Internet of Things. Our research demonstrates that their scheme is insecure in terms of signature design and that their theorem is invalid. We present an effective attack on their signature algorithm and create a new signature method and a formal security model to provide security guarantee against the mentioned attack. Extensive simulations demonstrate that our signature algorithm does not harm the highly efficient LPBFL scheme.
Existing security and privacy preserving schemes have too much wastage in token-based prepaid smart grids. In this paper, we propose a novel token concept and construct a security and privacy preserving prepaid scheme based on the power request model. In the proposed scheme, honest consumers keep their anonymity, while consumers who send used tokens can be tracked for law enforcement and maintenance purposes. In addition to security and privacy preservation, the computational cost of verification is independent of the number of tokens based on the novel token concept in the power request model. Therefore, the number of points can be the basic unit in order to minimize the wastage. Finally, we prove the security features and demonstrate the performances of our scheme.
Searchable encryption (SE) has emerged as a cryptographic primitive that allows data users to search on encrypted data. Most existing SE schemes usually delegate search operations to an intermediary such as a cloud server, which would inevitably result in single-point failure, privacy leakage, and even untrustworthy results. Several blockchain-based SE schemes have been proposed to alleviate these issues; however, they suffer from some issues, such as the support for multi-keyword multi-owner model, query privacy and data storage availability. In this paper, we propose BPMS, blockchain-based privacy-preserving multi-keyword search in multi-owner setting, which supports searching over encrypted data in trustworthy, private and efficient manners. The attribute Bloom filter has been introduced into our BPMS to build indexes, which protects query privacy and improves index generation performance. To guarantee data storage availability, our BPMS leverages the advantages of IPFS (InterPlanetary File System) to store large scale of encrypted data. Security proof and comparative analysis in theory indicate that our BPMS is more secure and efficient. A series of experiments conducted on a real-world dataset further demonstrate that our BPMS is feasible in practice.
Fast Probabilistic Consensus Protocol (FPC) is a novel Consensus Protocol in IOTA Tangle. Focusing on FPC and IOTA Tangle, this paper applies FPC to all-pass topology and triangle Tangle topology for comparison. Under the same network model and attack model, we analyze the two network topologies on FPC, and figure out which one has better performance on reaching a consensus. The experimental results show that all-pass topologies overperformance triangle Tangle structures due to the randomness of the model, when the number of nodes is small; however, triangle Tangle topologies overperformance all-pass topologies when the number of nodes is larger and the model tends to stabilize.
China’s economic level and people’s living standards have developed rapidly in recent years, and the medical level and medical technology have made breakthroughs continuously.With the promotion and deepening of“Internet Plus” to business model innovation in various fields, the development of “Internet Plus” medical has been rapidly developed.Due to the continuous development of data processing technologies such as machine learning and data mining, the risk of users’ personal medical data disclosure in the process of online medical treatment has also attracted the attention of researchers.Considering the deductibility of information, the discount mechanism was adopted to describe the change of user’s private information value in different stages of the game.Combined with the current research status in the field of online medical privacy protection motivation, how to mobilize the enthusiasm of both players from the level of privacy protection motivation was explored with game analysis.In view of the game characteristics of users’ strong willingness to continually use the online medical platform and intermittently provide privacy, the repeated game method was adopted to better describe the game process between users and the online medical platform.The tendency change law of the players on both sides of the game was obtained.Moreover, the Nash equilibrium of the game model was analyzed under different model parameters and the change trend of the game strategy of both sides with the progress of the game stage.When the parameters were met 2(cp-cn)≥lp(pn-pp), the user started to choose from “agree to share private data” to “refuse to share private data”.The above conclusion was verified by simulation experiments.Based on the above conclusions, from the perspective of online medical platform and users, policy suggestions on how to realize privacy protection from the level of privacy protection motivation in the process of online medical treatment were given.
The Internet of Things (IoT) provides significant benefits for industry due to connect the devices together through the internet. Attribute-Based Encryption (ABE) is a technique can enforce an access control over data to guarantee the data security. In this paper, we propose an ABE scheme for data in industrial IoT. The scheme achieves both security and high performance. When there is a shared subpolicy among the access policies of a sensor, the scheme optimizes the encryption of the messages. Through analysis and simulation, we show that our solution is security and efficient.
Traditional identity authentication solutions mostly rely on a trusted central entity, so they cannot handle single points of failure well. In addition, most of these traditional schemes need to store a large amount of identity authentication or public key information, which makes the schemes difficult to expand and use in distributed situations. In addition, the user prefers to protect the privacy of their information during the identity verification process. Due to the open and decentralized nature of the blockchain, the existing identity verification schemes are difficult to apply well in the blockchain. To solve this problem, in this article, we propose a privacy protection identity authentication scheme based on the blockchain. The user independently generates multiple-identity information, and these identities can be used to apply for an identity certificate. Authorities use the ECDSA signature algorithm and the RSA encryption algorithm to complete the distribution of the identity certificate based on the identity information and complete the registration of identity authentication through the smart contract on the blockchain. On the one hand, it can realize the protection of real identity information; on the other hand, it can avoid the storage overhead caused by the need to store a large number of certificates or key pairs. Due to the use of the blockchain, there is no single point of failure in the authentication process, and it can be applied to distributed scenarios. The security and performance analysis show that the proposed scheme can meet security requirements and is feasible.
Advancing network technologies allow the setup of two-way communication links between energy providers and consumers. These developing technologies aim to enhance grid reliability and energy efficiency in smart grids. To achieve this goal, energy usage reports from consumers are required to be both trustworthy and confidential. In this paper, we construct a new data aggregation scheme in smart grids based on a homomorphic encryption algorithm. In the constructed scheme, obedient consumers who follow the instruction can prove their data consumption's adjustment by using a range proof protocol. Additionally, we propose a new identity-based signature algorithm in order to ensure authentication and integrity of the constructed scheme. By using this signature algorithm, data usage reports are verified in real time. Extensive simulations demonstrate that our scheme outperforms other data aggregation schemes.
Aggregation trees have been proposed for privacy preservation to reduce data collectors' computational cost in smart grids. In aggregation tree models, smart meter usage data should be forwarded by all its ancestors, which delays usage data transmissions. We report the design of an identity-based signcryption protocol without oracles for aggregation trees. The designed protocol significantly reduces smart meter computational costs due to its homomorphic features. (1) Compressed signatures can be verified in batches. The computational cost of verification is independent of the number of usage reports. (2) A smart meter can generate a signature on the aggregated cipher without executing signing algorithms during transmissions. Extensive simulations demonstrate that, based on the proposed protocol, the communication efficiency of our privacy preservation scheme outperforms other aggregation tree-based schemes regarding transmission delay and computational cost.
As a lightweight protocol, the Message Queuing Telemetry Transport (MQTT) is widely used in the scopes of Internet of Things on account of its quite low bandwidth requirements. We built a temperature and humidity monitoring system using the Raspberry Pi and NodeMcu to communicate with each other through the MQTT protocol. This work applies network analytics tools such as Wireshark to capture and analyze network data. We looped message to broker with different QoS level and time interval and then observed the RTT (Round Trip Time) to analyze correlation between them.
The Internet of Things (IOT) is an Internet-based network that covers everything. Message Queuing Telemetry Transport (MQTT) is one of the commonly used communication protocols for any platform in the Internet of Things. Whether it is from the perspective of overall security or device compatibility and resource consumption, the MQTT protocol has certain advantages and is the most competitive communication protocol in the current Internet of Things. However, the user password login form adopted by the MQTT protocol has a certain degree of security problems. IOTA is an encrypted currency, and the Tangle network it uses is a new distributed structure. Based on this situation, this article innovatively combines the Tangle network with the MQTT protocol, and proposes a new communication option for MQTT nodes. When a new node enters the network, start from the Broker with the help of a “walker”, by judging the connection and survival of the node, using the Markov Chain Monte Carlo (MCMC) random walk algorithm to complete the node selection, and finally realize MQTT Communication between nodes. This article puts forward the design idea of this scheme, and realizes the scheme through simulation experiment.
Smart grids offer benefits compared to the current power grid by using technologies, such as advanced metering infrastructure and demand-response schemes. However, the introduction of these technologies also leads to challenges in the areas of privacy and identification of disobedient users. Current solutions to these challenges heavily rely on a trusted third party, which may lead to scenarios where the privacy of obedient consumers cannot be preserved. To tackle these concerns, anonymity provides a promising approach to obviating privacy preservation in smart grids. In this paper, a threshold-based anonymous identification scheme (TAI) for overload audit and privacy preservation in smart grids is proposed, where the use of a trusted third party is no longer required. Privacy preservation depends on the power consumption of consumers in the presence of a demand-response request from the power provider that defines an acceptable consumption threshold at periods of power shortage. Consumers must follow the instruction and curtail their consumption to meet the threshold. By doing so, the consumers who adhere to the power providers' instructions keep their anonymity, whilst the disobedient are be identified. According to our security and performance analysis, TAI significantly improves efficiency compared to previous anonymous identification schemes, while providing anonymity and identification.