Aug 2026· Frontiers of Physics· Vol 14· 0 citations· 14 references
TL;DR
This work proposes a self-calibrating side-channel attack (SC-SCA) that enables high-accuracy HMAC-SM3 key recovery using only a single power trace during the attack phase, and provides both a practical security benchmark for CPSS edge devices and theoretical foundations for designing side-channel-resistant cryptographic implementations.
Abstract
Cyber-Physical-Social Systems (CPSS) face escalating side-channel threats that undermine secure data transmission and authentication. As China’s national cryptographic hash standard, SM3 is widely deployed in CPSS-integrated social network ecosystems for identity authentication, API signing, and cross-platform data integrity verification—yet its key-dependent input vulnerabilities against side-channel attacks remain inadequately addressed. This study tackles two critical limitations of traditional side-channel attacks for HMAC-SM3 key recovery: non-profiling methods fail due to absent plaintext correlations, while profiling-based approaches suffer from error accumulation and near-zero success rates in single-trace scenarios. We propose a self-calibrating side-channel attack (SC-SCA) that enables high-accuracy HMAC-SM3 key recovery using only a single power trace during the attack phase. The method constructs a Bayesian network to integrate power trace statistics with prior knowledge of input dependencies, then performs joint probabilistic inference
via
belief propagation. Experimental results demonstrate 100% key recovery success under simulated noiseless conditions, 91.45% success on a real smart card system, and 73% effectiveness at a 10 dB signal-to-noise ratio. Crucially, this work exposes a previously overlooked attack surface in CPSS-based social networks: a single compromised HMAC-SM3 key can enable forged device control commands, large-scale privacy breaches, and cascading identity theft across linked social platforms. Our findings provide both a practical security benchmark for CPSS edge devices and theoretical foundations for designing side-channel-resistant cryptographic implementations.
The proposed novel password reset standard performs authentication and password update in a single cryptographically bound flow, eliminating the need for sessions, cookies, OTPs, or email-based verification, and mitigating phishing, session hijacking, CSRF, and replay attacks.
Aditya Mitra, Amar Kumar Mandal, Amaan Rais Shah et al.· 0 citations
Modern cyber--physical, Internet-of-Things (IoT), wearable, and edge systems increasingly require trust in three distinct entities: the human requesting access, the physical device executing the computation, and the hardware function that is permitted to operate. These requirements are usually studied in separate communities. Biometrics establish human identity but remain vulnerable to presentation attacks, intra-user variability, template leakage, and limited revocability. Physical unclonable functions (PUFs) provide device-specific physical identity and on-demand secret derivation, yet must address environmental instability, helper-data exposure, side channels, and modeling attacks. Hardware obfuscation and logic locking condition correct circuit behavior on an activation secret, but face oracle-guided, approximate, structural, removal, and physical attacks. This survey develops a unified human--device--function view of trust. We first decompose each primitive into its complete processing chain and identify the corresponding security assumptions, implementation mechanisms, and evaluation metrics. We then formalize pairwise compositions---biometric--PUF, PUF--obfuscation, and biometric--obfuscation---and a three-way architecture in which correct functionality is bound jointly to an authorized user and a genuine device. Particular attention is given to biometric key reconstruction, PUF stabilization and modeling resistance, logic-locking attack evaluation, cross-layer error propagation, enrollment trust, key lifecycle, and interface leakage. The survey concludes with a taxonomy and research agenda for revocable human--device credentials, compositional security, leakage-aware integration, reconfigurable activation, and standardized end-to-end evaluation.
A hybrid key exchange protocol combining DHKE with Learning With Errors (LWE), a lattice-based post-quantum primitive that provides authentication via a Public Key Infrastructure together with CRYSTALS-Dilithium digital signature, resilience against MITM attacks, and robustness against classical and quantum threats.
A. K. M. Fakhrul Hossain, Article Info· 0 citations
Vehicle-to-Everything (V2X) communication enables vehicles to exchange safety-critical messages, but its reliance on temporary pseudonymous identities makes it vulnerable to Sybil attacks, where a single attacker fabricates multiple identities to inject false information into the network. This paper presents a lightweight cryptographic mechanism that combines SHA-256 Proof-of-Work token mining with a time-windowed ratecontrol layer to limit the number of new identities a vehicle can activate within a given interval. The mechanism was implemented in Java and evaluated through a parametric simulation across three independent variables: PoW difficulty, rate limit, and attack intensity. Results show that a difficulty of 4 and a rate limit of 5 tokens per 10-second window provide an effective balance between Sybil resistance and legitimate vehicle access in an 8-vehicle scenario, with an average mining time of 0.227 seconds. The evaluation identifies the rate-control layer as the primary security mechanism, while PoW difficulty increases the computational cost per identity without independently capping accepted tokens. The proposed approach is infrastructure-free and suitable for regulated V2X deployments where attackers represent a minority of the network.
Maher Fayyad, Abdullah Awad, Edison Pignaton De Freitas et al.· International Conference on...· 0 citations
In Critical Energy Infrastructures (CEI), the standard cryptographic synchronization model failed once return paths were physically severed by one-way data diodes. Conventional interactive workflows, including Diffie-Hellman key exchanges and TCP-style handshakes, could not function in these zero-feedback environments. Consequently, industrial deployments often relied on static pre-shared keys or unprotected telemetry, exposing critical systems to considerable risk. This study proposed a multi-layer security framework for non-interactive key coordination and asynchronous integrity verification over strictly unbuffered industrial channels. The framework combined Geo-Spatial Temporal Identity-Based Initialization (TIBI), which derived session entropy from localized spatiotemporal anchors, with Interleaved Merkle-Hash Chains (IM-Forest), which enabled recursive forensic auditing. The proposed approach was evaluated using a high-fidelity discrete-event simulation engine under simulated Man-in-the-Middle and replay-attack conditions. Results showed that the TIBI-IM approach achieved 100% detection accuracy for bit-level forgeries and replay attacks. When benchmarked against conventional RSA-2048 configurations, the proposed framework reduced computational latency by approximately 34.6% and bandwidth overhead by approximately 87.5%, while peak memory consumption remained below 150 MB. These findings indicated that the framework established a mathematically self-contained isolation boundary that supported resilience among geographically separated organizations. The approach enabled asynchronous attestation without requiring two-way signaling or interactive trust establishment, addressing a persistent limitation of conventional cryptographic protocols in unidirectional industrial environments.
Ahmed H. Alfuraiji· Al-Noor Journal of Engineeri...· 0 citations
OPC Unified Architecture (OPC UA) encryption conceals application-layer semantics and restricts intrusion detection to residual communication structure. Although machine learning-based intrusion detection systems (IDSs) can detect attacks in encrypted OPC UA traffic, the relationship between residual structural observability and attack detectability remains insufficiently understood. This paper presents an explanatory framework combining a structural observability profile, the Structural Leakage Score (SLS), controlled within-family and cross-family comparisons, phase-specific analysis, and dimension-ablation analysis. Jensen--Shannon divergence is used to characterize transport, temporal, and protocol-lifecycle dimensions, while the SLS summarizes the residual structural magnitude. Evaluation on an industrial private 5G testbed covers four attack families with progressively reduced nominal activity. SLS generally tracks within-family recall trends but does not reproduce cross-family detectability ordering. Interpreting these mismatches also requires temporal prevalence, inter-burst persistence, predictive utility, unique contribution, and redundancy. The framework complements conventional IDS metrics by relating detection outcomes to the magnitude, temporal distribution, and predictive role of observable structural evidence.
Son-Ha Song, Florian Foerster, Henry Beuster et al.· arXiv.org· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.