In intelligent connected vehicles(ICVs)system,driving users connect to service providers(SPs)to obtain location-based services(LBS).Users transmit large volumes of encrypted sensitive information related to their itin...In intelligent connected vehicles(ICVs)system,driving users connect to service providers(SPs)to obtain location-based services(LBS).Users transmit large volumes of encrypted sensitive information related to their itineraries to SPs to access value-added services.Attackers may launch chosen-ciphertext attacks(CCA)against SPs by exploiting the malleability of homomorphic encryption.This enables adversaries to infer or steal private key information,thereby threatening the long-term privacy of user data.Furthermore,existing key management technologies in ICVs system predominantly rely on passive defense strategies and suffer from limitations such as single protection mechanisms,delayed updates,and limited adaptability.To address these issues,this paper proposes an adaptive key update security mechanism based on a differential game framework.This mechanism treats the cumulative information leakage of the private key as a contested resource to construct a differential game model.Based on the feedback Nash equilibrium(NE),the mechanism adaptively derives the optimal homomorphic private key update frequency in response to the attack frequency,thereby maximizing the defense benefit.Finally,numerical simulations validate the correctness of the proposed model and demonstrate the effectiveness of the mechanism.展开更多
Secure data communication is an essential requirement for an Internet of Things(IoT)system.Especially in Industrial Internet of Things(IIoT)and Internet of Medical Things(IoMT)systems,when important data are hacked,it...Secure data communication is an essential requirement for an Internet of Things(IoT)system.Especially in Industrial Internet of Things(IIoT)and Internet of Medical Things(IoMT)systems,when important data are hacked,it may induce property loss or life hazard.Even though many IoTrelated communication protocols are equipped with secure policies,they still have some security weaknesses in their IoT systems.LoRaWAN is one of the low power wide-area network protocols,and it adopts Advanced Encryption Standard(AES)to provide message integrity and confidentiality.However,LoRaWAN’s encryption key update scheme can be further improved.In this paper,a Two-stage High-efficiency LoRaWAN encryption key Update Scheme(THUS for short)is proposed to update LoRaWAN’s root keys and session keys in a secure and efficient way.The THUS consists of two stages,i.e.,the Root Key Update(RKU)stage and the Session Key Update(SKU)stage,and with different update frequencies,the RKU and SKU provide higher security level than the normal LoRaWAN specification does.A modified AES encryption/decryption process is also utilized in the THUS for enhancing the security of the THUS.The security analyses demonstrate that the THUS not only protects important parameter during key update stages,but also satisfies confidentiality,integrity,and mutual authentication.Moreover,The THUS can further resist replay and eavesdropping attacks.展开更多
Many identity-based signature (IBS) schemes solving key escrow were proposed, But the updating of the private keys wasn't discussed in these literatures. For the problem of key update, an identity-based key-insulat...Many identity-based signature (IBS) schemes solving key escrow were proposed, But the updating of the private keys wasn't discussed in these literatures. For the problem of key update, an identity-based key-insulated signature scheme with secure key-updates has been proposed. But their scheme inherited the key escrow property. In this paper, we propose a new identity-based strong key-insulated signature scheme without key escrow. It makes the IBS scheme more applicable to the real world. After analyzing the security and the performance, an application example in E-passport passive authentication scenario is described.展开更多
1 Introduction Access control and key update are crucial for secure data sharing.Currently,many access control strategies have been proposed to address unauthorized access and privacy breaches[1,2].However,these strat...1 Introduction Access control and key update are crucial for secure data sharing.Currently,many access control strategies have been proposed to address unauthorized access and privacy breaches[1,2].However,these strategies typically focus only on the unilateral access control of data requesters,potentially failing to prevent unauthorized individuals from maliciously publishing data.Additionally,existing key update schemes rely on trusted key generation center(KGC)and have significant performance limitations,which are not practical[3,4].展开更多
基金supported in part by the Key Program of the National Natural Science Foundation of China under Grant 62436004in part by the General Program under Grant 62372317.
摘要In intelligent connected vehicles(ICVs)system,driving users connect to service providers(SPs)to obtain location-based services(LBS).Users transmit large volumes of encrypted sensitive information related to their itineraries to SPs to access value-added services.Attackers may launch chosen-ciphertext attacks(CCA)against SPs by exploiting the malleability of homomorphic encryption.This enables adversaries to infer or steal private key information,thereby threatening the long-term privacy of user data.Furthermore,existing key management technologies in ICVs system predominantly rely on passive defense strategies and suffer from limitations such as single protection mechanisms,delayed updates,and limited adaptability.To address these issues,this paper proposes an adaptive key update security mechanism based on a differential game framework.This mechanism treats the cumulative information leakage of the private key as a contested resource to construct a differential game model.Based on the feedback Nash equilibrium(NE),the mechanism adaptively derives the optimal homomorphic private key update frequency in response to the attack frequency,thereby maximizing the defense benefit.Finally,numerical simulations validate the correctness of the proposed model and demonstrate the effectiveness of the mechanism.
摘要Secure data communication is an essential requirement for an Internet of Things(IoT)system.Especially in Industrial Internet of Things(IIoT)and Internet of Medical Things(IoMT)systems,when important data are hacked,it may induce property loss or life hazard.Even though many IoTrelated communication protocols are equipped with secure policies,they still have some security weaknesses in their IoT systems.LoRaWAN is one of the low power wide-area network protocols,and it adopts Advanced Encryption Standard(AES)to provide message integrity and confidentiality.However,LoRaWAN’s encryption key update scheme can be further improved.In this paper,a Two-stage High-efficiency LoRaWAN encryption key Update Scheme(THUS for short)is proposed to update LoRaWAN’s root keys and session keys in a secure and efficient way.The THUS consists of two stages,i.e.,the Root Key Update(RKU)stage and the Session Key Update(SKU)stage,and with different update frequencies,the RKU and SKU provide higher security level than the normal LoRaWAN specification does.A modified AES encryption/decryption process is also utilized in the THUS for enhancing the security of the THUS.The security analyses demonstrate that the THUS not only protects important parameter during key update stages,but also satisfies confidentiality,integrity,and mutual authentication.Moreover,The THUS can further resist replay and eavesdropping attacks.
基金Supported by the Science and Technology Planned Projects of Wuhan, China (20061005119)
摘要Many identity-based signature (IBS) schemes solving key escrow were proposed, But the updating of the private keys wasn't discussed in these literatures. For the problem of key update, an identity-based key-insulated signature scheme with secure key-updates has been proposed. But their scheme inherited the key escrow property. In this paper, we propose a new identity-based strong key-insulated signature scheme without key escrow. It makes the IBS scheme more applicable to the real world. After analyzing the security and the performance, an application example in E-passport passive authentication scenario is described.
基金supported by the National Key R&D Projects(No.2021YFB00900)the National Natural Science Foundation of China(Grant Nos.U20A20174,U22B2062,62302230,62202051,62372068,62302229,and 62302162)the China Postdoctoral Science Foundation(Nos.2021M700435,2024M751480).
摘要1 Introduction Access control and key update are crucial for secure data sharing.Currently,many access control strategies have been proposed to address unauthorized access and privacy breaches[1,2].However,these strategies typically focus only on the unilateral access control of data requesters,potentially failing to prevent unauthorized individuals from maliciously publishing data.Additionally,existing key update schemes rely on trusted key generation center(KGC)and have significant performance limitations,which are not practical[3,4].