Similar papers
Post-Quantum Secure Lattice-Based Lightweight Authentication Scheme for Energy Internet-Based V2G Communication
Electric Vehicles (EVs) now function as both energy consumers and producers within the energy internet-enabled smart grid, enabling bidirectional energy exchange with the grid. To facilitate secure Vehicle-to-Grid (V2G) communication, mutual authentication between EVs and charging stations (CSs) over open wireless channels is crucial. While several authentication schemes have been proposed, most are vulnerable to post-quantum threats. To address this gap, this article presents an efficient lattice-based lightweight authentication protocol specifically designed for V2G communication. The protocol’s security is rigorously validated through formal analysis and formal security verification using an automated verification tool, known as the Automated Validation of Internet Security Protocols and Applications (AVISPA) tool. Additionally, an informal security analysis is performed to evaluate resilience against practical attacks. Moreover, comprehensive performance simulations confirm the protocol’s efficiency and feasibility for real-world V2G communication.
QuantumShield-IoT: A Quantum-Resilient Hybrid Framework for Secure Data Transmission Using Quantum Key Distribution, Lightweight Cryptography and Blockchain Technology
The proposed Quantum Shield-IoT is a quantum-resilient hybrid security framework that combines the Quantum Key Distribution (QKD) protocol of BB84 with ASCON lightweight authenticated encryption, blockchain security, and cloud computing to ensure secure end-to-end data transmission in IoT.
An Efficient Privacy-Preserving Batch Authentication Scheme in Fog-Enabled VANETs
Vehicular ad hoc networks (VANETs), as a key communication component of the Internet of Vehicles (IoV), enable vehicles and roadside infrastructure to exchange information efficiently, thereby supporting road safety and traffic management. However, because these communications take place over open wireless channels, VANETs are exposed to message forgery, replay, identity disclosure, and unauthorised access by revoked vehicles. To address these issues, this paper proposes EPAF, an efficient privacy-preserving batch authentication scheme with revocation support for fog-enabled VANETs. EPAF uses roadside fog nodes to distribute update keys and report information related to misbehaving vehicles, thereby reducing reliance on remote centralised processing. Rather than assuming ideal tamper-proof devices that store system-wide secrets, EPAF requires protected storage only for vehicle-local certificates, limiting the impact of compromising an individual vehicle device. The scheme employs batch verification to authenticate multiple messages from different vehicles in a single procedure, reducing verification overhead in message-intensive traffic conditions. It further introduces an update-key mechanism through which legitimate vehicles obtain current authentication keys, whereas revoked vehicles are prevented from generating valid authentication messages in subsequent revocation periods. Under the honest-authority model, the security analysis establishes the EUF-CMA security of an authentication packet in the random-oracle model and separately addresses conditional identity privacy, traceability, and unlinkability across different pseudonym periods. Performance evaluation examines the trade-off among authentication efficiency, communication overhead, and revocation performance, showing that EPAF is a practical solution for fog-enabled vehicular communication.
Blockchain-Assisted Authentication, Authorization, and Audit for MQTT-Based Smart-City IoT
Smart-city services increasingly rely on Internet of Things (IoT) deployments using lightweight Message Queuing Telemetry Transport (MQTT), yet weakly protected systems remain exposed to spoofing, unauthorized state changes, and limited accountability. This work evaluates blockchain and smart contracts as a complementary trust layer for MQTT-based smart-city IoT rather than as a replacement for transport-layer security. The proposed architecture provides owner-controlled device registration, per-sensor nonce management, replay-resistant Elliptic Curve Digital Signature Algorithm (ECDSA) authentication, authorization of state-changing operations, and tamper-evident event logging. MQTT confidentiality remains dependent on Transport Layer Security (TLS) or payload encryption. A prototype was implemented using ESP32 microcontrollers, a Raspberry Pi MQTT broker, Node-RED supervision, MongoDB storage, and Ethereum smart contracts deployed on Sepolia. The evaluation combines practical attack scenarios (unauthorized sensor modification, identity spoofing, and data manipulation) with measurements of blockchain latency, throughput, and gas consumption. Results show auditable nonce-bound signed updates, with mean transaction latency close to 12 s. Because the contract updates one sensor per transaction, costs are interpreted per confirmed write operation and scenario size. The findings position blockchain as an audit and policy-enforcement component for MQTT-based IoT.
Chaotic map based efficient anonymous authentication and key agreement scheme for VANETS
Vehicular Ad Hoc Networks (VANETs) have been developed as an important technology for improving road safety and traffic efficiency in intelligent transport systems. However, due to the increase in the number of cyberattacks, they have become vulnerable to several security threats that must be addressed. Although several works related to authentication and key agreement protocols have been proposed in the past, there is a significant overhead in both communication and computation. To overcome this burden, a Chebyshev chaotic map-driven anonymous authentication scheme with a key agreement scheme is proposed in this work. This work shows integrates a chaotic map with anonymous authentication, thereby balancing security and efficiency. The proposed scheme removes the bilinear pairing operations, thereby reducing the time required for cryptographic operations, which leads to a significant reduction in computation overhead. Moreover, Quantitative evaluation shows that the proposed scheme achieves a total execution time of only 0.9494ms representing a (49.7%−71%) reduction compared to existing schemes (1.8878-3.7756 ms) and a communication overhead of 264 bytes, which is (13.2%−57.4%) lower than most related works (84–620) bytes. Furthermore, the security analysis section addresses the secure nature of the proposed protocol in contrast to different types of security attacks. The efficiency of the proposed schema is validated against similar works based on the computation time of cryptographic operations using the Cygwin platform and is proven to be noteworthy.
A Security-Enhanced Certificateless Aggregate Signature-Based Conditional Privacy-Preserving Authentication Scheme for VANETs
Vehicular ad hoc networks (VANETs) have become a vital component of intelligent transport systems, with their security concerns increasingly drawing attention. To safeguard user privacy and ensure data authenticity and integrity, researchers have devised numerous certificateless conditional privacy-preserving authentication (CLCPPA) schemes. However, existing schemes generally suffer from insufficient security or high computational and communication overhead. Moreover, most implicitly assume the existence of a secure channel between vehicles and trusted entities during pseudonym generation and transmission, making it difficult to meet the real-time demands and practical deployment requirements of VANETs. To address these issues, this paper constructs a certificateless aggregated conditional privacy-preserving authentication (CL-ACPPA) scheme under elliptic curve cryptography that does not require bilinear operations. Formal security analysis demonstrates that, under the Random Oracle Model and the elliptic curve discrete logarithm problem assumption, the proposed scheme resists adaptive chosen-message attacks from adversaries with varying capabilities. Performance analysis and experimental results demonstrate that, compared with existing schemes, the proposed scheme achieves higher security while maintaining low communication and computational overhead.