Sign in to use this feature.

Years

Between: -

Subjects

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Journals

Article Types

Countries / Regions

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Search Results (499)

Search Parameters:
Keywords = ciphertext

Order results
Result details
Results per page
Select all
Export citation of selected articles as:
29 pages, 3998 KB  
Article
Image Encryption Method Based on Logarithmic Chaotic System and DNA Mutation
by Ping Gao, Caiwen Chen, Tianxiu Lu and Jiahua Dong
Mathematics 2026, 14(18), 3323; https://doi.org/10.3390/math14183323 - 13 Sep 2026
Abstract
Existing chaos-based image ciphers may suffer from limited dynamical complexity in low-dimensional maps and insufficient diversification of encryption-control sequences across different encryption instances. To address these limitations, a one-dimensional logarithmic chaotic map and a plaintext-dependent encryption scheme with dynamic DNA point mutation are [...] Read more.
Existing chaos-based image ciphers may suffer from limited dynamical complexity in low-dimensional maps and insufficient diversification of encryption-control sequences across different encryption instances. To address these limitations, a one-dimensional logarithmic chaotic map and a plaintext-dependent encryption scheme with dynamic DNA point mutation are presented. The map combines logarithmic stretching with modular folding and exhibits persistent complex dynamics over the investigated parameter interval. Compared with the logistic map and the one-dimensional Cosine Logistic compound map (1DCLC), it shows a broader positive-Lyapunov-exponent region and more stable normalized permutation entropy, while derived binary sequences satisfy the adopted NIST SP 800-22 criteria. The encryption architecture integrates block-reversal permutation, dynamic DNA encoding, involutive point mutation, and chaotic XOR masking. A SHA-512 plaintext digest, a fresh 128-bit public nonce, and a 256-bit master key are processed through HMAC-SHA-256 and HKDF-SHA-256 to derive the chaotic parameters. Experiments on standard grayscale images show near-uniform ciphertext distributions, negligible adjacent-pixel correlations, near-maximal entropy, differential characteristics close to theoretical references, and pronounced one-bit key sensitivity. The MATLAB implementation achieves encryption and decryption throughputs of approximately 1 MB/s. Full article
Show Figures

Figure 1

44 pages, 13333 KB  
Article
A Color Image Encryption Scheme Using an Enhanced One-Dimensional Chaotic Map and Adaptive DNA Encoding
by Jie Jiang, Liyuan Jiao, Yanchun Liang, Adriano Tavares and Lidong Wang
Entropy 2026, 28(9), 1015; https://doi.org/10.3390/e28091015 - 11 Sep 2026
Viewed by 67
Abstract
Secure transmission and storage of color images remain challenging tasks due to strong inter-pixel correlations and high data volume. This work proposes a one-dimensional sine-tent-logistic-exponential map (STLEM) equipped with numerical boundary correction rules to mitigate finite-precision numerical degradation so as to enhance the [...] Read more.
Secure transmission and storage of color images remain challenging tasks due to strong inter-pixel correlations and high data volume. This work proposes a one-dimensional sine-tent-logistic-exponential map (STLEM) equipped with numerical boundary correction rules to mitigate finite-precision numerical degradation so as to enhance the unpredictability of chaos-driven cryptosystems. We benchmark STLEM against classic logistic, tent, and sine maps via Lyapunov exponents, autocorrelation, approximate entropy, permutation entropy, Lempel-Ziv complexity, and Kolmogorov–Sinai entropy. Bifurcation diagrams, the 0–1 test, and NIST statistical tests are further adopted to characterize its chaotic dynamics and randomness. Comparative results verify that STLEM achieves improved dynamical complexity and randomness performance. Built upon the proposed STLEM, this paper constructs a color-image encryption scheme that employs a 256-bit master key and two groups of chaotic parameters to produce key-related chaotic sequences. The cryptosystem integrates dynamic edge expansion, chaotic permutation, position-dependent adaptive DNA encoding, DNA-domain chained diffusion, and two successive row-column permutation phases. HMAC-SHA-256 is utilized to generate plaintext-aware initial conditions and perform ciphertext authentication prior to decryption. Experimental validations demonstrate complete plaintext recovery under valid secret inputs, while authentication rejects invalid keys and tampered ciphertexts. Ciphered images exhibit high information entropy, negligible adjacent-pixel correlations, and satisfactory number of pixel change rate (NPCR) and unified average changing intensity (UACI) metrics. Benefiting from a sufficiently large key space and O(MNlog(MN)) computational complexity, the proposed scheme is resilient against brute-force attacks and well suited for secure color-image communication scenarios, rather than acting as a general-purpose replacement for standard block ciphers. Full article
(This article belongs to the Section Information Theory, Probability and Statistics)
Show Figures

Figure 1

31 pages, 2447 KB  
Article
A Batch Identity-Based Encryption Scheme for Object-Level Authorization of Smart Tourism Data
by Lixia Sun, Dengshuo Zhu, Changgen Peng, Chenran Xiong and Chuanda Cai
Cryptography 2026, 10(5), 67; https://doi.org/10.3390/cryptography10050067 - 10 Sep 2026
Viewed by 138
Abstract
When smart tourism data are shared across scenic areas, hotels, transportation platforms, and regulatory authorities, existing access control schemes often struggle to simultaneously support batch authorization for data object sets, multi-authority collaboration, revocation-version binding, and low-latency online encryption. To address these challenges, this [...] Read more.
When smart tourism data are shared across scenic areas, hotels, transportation platforms, and regulatory authorities, existing access control schemes often struggle to simultaneously support batch authorization for data object sets, multi-authority collaboration, revocation-version binding, and low-latency online encryption. To address these challenges, this paper proposes a Threshold Distributed Batch Identity-Based Encryption scheme for object-level authorization of smart tourism data, termed TD-BIBE. The scheme jointly binds data object identities, batch labels, authorization periods, revocation versions, and authorization contexts to ciphertext access control. It employs Shamir secret sharing for threshold distributed key generation, preventing any single authorization authority from obtaining the complete master secret key. Set-polynomial digests and membership witnesses are used to support batch authorization over identity sets and object-level membership verification. A revocation-version binding mechanism restricts the validity scope of authorization materials, while an offline/online encryption structure reduces the online computational overhead of data providers. Formal security analyses are conducted in the random oracle model with respect to data confidentiality, object-level authorization, batch-label binding, revocation-version binding, resistance to unauthorized key-combination attacks, and threshold authorization security. Experimental results demonstrate that TD-BIBE is suitable for cross-departmental, multi-object, and on-demand data sharing in smart tourism scenarios. Full article
(This article belongs to the Topic Security and Privacy in Distributed and Trustless Systems)
21 pages, 4086 KB  
Article
Protecting Facial Biometric Templates with Threshold Secret Sharing: A Comparative Resource-Aware Study of a Non-Positional Polynomial Scheme and a Multivariable Verification Scheme
by Nursulu Kapalova and Nursultan Yergesh
Computers 2026, 15(9), 604; https://doi.org/10.3390/computers15090604 - 10 Sep 2026
Viewed by 110
Abstract
Facial biometric templates are permanent identifiers: once exposed, the underlying identity cannot be reissued, so single-copy storage is a critical single point of failure. This study protects facial templates by combining a non-invertible BioHashing transform and authenticated encryption with a threshold secret-sharing layer [...] Read more.
Facial biometric templates are permanent identifiers: once exposed, the underlying identity cannot be reissued, so single-copy storage is a critical single point of failure. This study protects facial templates by combining a non-invertible BioHashing transform and authenticated encryption with a threshold secret-sharing layer that distributes the protected record across independent storage nodes and reconstructs it only when a quorum of shares is collected. Two threshold schemes, previously proposed by our group for fingerprint and for general confidential data, are, for the first time, applied to facial templates and compared on a common platform as a resource-aware architecture: a non-positional polynomial notation scheme with the Chinese remainder theorem, and a verifiable multivariable-function scheme. Both reconstruct the template exactly and, across 2000 trials per attack, resist or detect every attack in our evaluation (for example, malicious-share tampering is detected in 100% of 2000 trials and stolen-token recovery succeeds in 0 of 2000), whereas a single read breach of one-copy storage discloses the template in full. Below the threshold they differ: the polynomial scheme is a compact, deterministic ramp scheme for edge and Internet-of-Things nodes that discloses only ciphertext bytes and, under separate key and token storage, neither the biometric nor the key; the multivariable scheme adds native share verification and, in its randomized single-secret mode, provides information-theoretic perfect secrecy for a single high-value secret, while for the packed record it is a verified ramp. Rather than ranking the schemes, we quantify this trade-off. Because the protection layer is lossless, recognition accuracy is inherited unchanged from the face encoder; on the LFW verification protocol, the complete pipeline attains an equal error rate of 2.12% ± 0.57% (95% CI [1.77%, 2.47%]) against a per-fold raw-embedding cosine baseline of 1.37% ± 0.62%. Full article
Show Figures

Graphical abstract

21 pages, 642 KB  
Article
Improved Differential Cryptanalysis of the Ultra-Lightweight Block Cipher PICO
by Yu Wang, Zhuofeng Liang, Ting Fan and Tao Zhou
Entropy 2026, 28(9), 1006; https://doi.org/10.3390/e28091006 - 8 Sep 2026
Viewed by 99
Abstract
PICO is an ultra-lightweight substitution–permutation network block cipher designed for resource-constrained devices such as Internet of Things terminals and edge agents. For fixed endpoints, summing the characteristic probabilities over an enumerated finite weight window gives a verifiable lower bound on the differential probability. [...] Read more.
PICO is an ultra-lightweight substitution–permutation network block cipher designed for resource-constrained devices such as Internet of Things terminals and edge agents. For fixed endpoints, summing the characteristic probabilities over an enumerated finite weight window gives a verifiable lower bound on the differential probability. We use a PICO-specific workflow that combines mixed-integer linear programming bounds on active substitution boxes, exact-weight Boolean satisfiability search, optional Matsui pruning, and fixed-endpoint enumeration. For the selected endpoints, enumeration over W=63,,76 and W=66,,79 gives finite-window lower bounds of 259.95 and 261.95 for 21 and 22 rounds, respectively. We prepend two rounds and append three rounds to the 21-round differential distinguisher. The resulting 26-round analysis is an analytical equivalent-round-key filtering-and-ranking procedure for a 108-bit tuple. The verified 21-round finite-window probability input is a factor of 20.80321.745 larger than the previously reported input, increasing the expected right-tuple support at fixed S under the analytical accounting. For the illustrative choice S=242, the analytical resources are D=262 chosen plaintexts, a normalized substitution-box filtering workload of T=2100.11 equivalent 26-round encryptions, and M=262 stored plaintext–ciphertext records. This setting is not tied to a demonstrated success probability and does not establish an equal-success complexity advantage over prior work. Full article
(This article belongs to the Section Information Theory, Probability and Statistics)
Show Figures

Figure 1

27 pages, 2358 KB  
Article
A Privacy-Preserving and Fault-Tolerant Data Aggregation Scheme with User-Driven Differentiated Access for V2G Interaction Service
by Nan Zhang, Fan Yang, Quangui Hu, Peijun Li, Wenkui She, Jian Xu, Tianbao Liu and Nian Wang
World Electr. Veh. J. 2026, 17(9), 474; https://doi.org/10.3390/wevj17090474 - 8 Sep 2026
Viewed by 114
Abstract
Vehicle-to-Grid (V2G) enables energy and information exchange between electric vehicles (EVs) and the power grid. Large amounts of distributed data are generated in V2G systems. The charging data of EVs connected to charging piles (CPs) are aggregated by charging stations (CSs), charging service [...] Read more.
Vehicle-to-Grid (V2G) enables energy and information exchange between electric vehicles (EVs) and the power grid. Large amounts of distributed data are generated in V2G systems. The charging data of EVs connected to charging piles (CPs) are aggregated by charging stations (CSs), charging service operators (COs), and load aggregation platforms. The aggregated results support grid regulation and electricity market trading. However, some CPs within a station are idle or offline due to hardware failures or communication disruptions, preventing their data from being aggregated in time. Consequently, traditional schemes that rely on full-pile participation result in incomplete ciphertext aggregation results due to the absence of data contributions from some CPs, making correct decryption unreliable. In addition, most existing data aggregation schemes only provide a single result. They cannot satisfy the differentiated data access demands of V2G business entities. To address these challenges, a user-driven differentiated fault-tolerant data aggregation scheme for V2G interaction is proposed. First, the EC-ElGamal encryption scheme is employed to preserve data confidentiality, while the ECDSA batch signature verification mechanism is adopted to ensure data integrity. Second, a mask compensation mechanism is designed to restore the completeness of the aggregated ciphertext under the failures of some CPs. Finally, on-demand differential de-aggregation and controlled authorized decryption are designed based on Shamir’s secret sharing scheme. Data users (DUs) are allowed to access target ciphertexts on demand, only upon obtaining sufficient authorization from CPs. Security and performance analyses demonstrate that the proposed scheme effectively resists chosen-plaintext and key-collusion attacks with practical efficiency. The proposed scheme provides a secure and reliable solution for V2G data aggregation. Full article
Show Figures

Figure 1

48 pages, 12100 KB  
Article
A Simulation-Based Quantum-Synchronized Ephemeral Encryption Framework for QKD-Secured IoT Networks with Transformer-Based Cyber-Quantum Attack Detection
by Mohammad Sameer Aloun, Ala Mughaid, Bashar S. Khassawneh and Mahmoud AlJamal
Computation 2026, 14(9), 207; https://doi.org/10.3390/computation14090207 - 7 Sep 2026
Viewed by 145
Abstract
This paper presents a simulation-based cyber-quantum Internet of Things (IoT) security framework for modeling, securing, and detecting attacks in QKD-secured IoT communication environments. The proposed framework integrates heterogeneous IoT traffic generation, gateway-assisted routing, edge processing, QKD key-pool management, Quantum-Synchronized Ephemeral Encryption (Q-SEE), cross-layer [...] Read more.
This paper presents a simulation-based cyber-quantum Internet of Things (IoT) security framework for modeling, securing, and detecting attacks in QKD-secured IoT communication environments. The proposed framework integrates heterogeneous IoT traffic generation, gateway-assisted routing, edge processing, QKD key-pool management, Quantum-Synchronized Ephemeral Encryption (Q-SEE), cross-layer adversarial attack injection, and AI-based multiclass detection. Unlike conventional IoT intrusion datasets that mainly capture packet- or flow-level abnormalities, the generated dataset represents the joint behavior of IoT sessions, network delay, queue pressure, QKD state, key consumption, encryption-mode transitions, ciphertext metadata, and cyber-quantum risk. A Python/SimPy/NetworkX simulation was developed using 80 IoT devices, 3 gateways, 2 edge servers, 4 cyber-quantum control-plane nodes, and 1 adversarial orchestrator. The final simulation produced 46,351 records with 76 features covering normal traffic, five traditional IoT attacks, and six novel cyber-quantum attacks, including QKD key-pool starvation, QBER camouflage, false QKD-health injection, encryption downgrade induction, queue–key coupling, and multi-vector cyber-quantum orchestration. Q-SEE adaptively selects among QKD-OTP, QKD-synchronized AES-256 ephemeral mode, PQC fallback, degraded mode, and blocked mode according to QBER, secret key rate, key availability, device criticality, downgrade pressure, and risk. A leakage-aware Quantum-Aware Kolmogorov–Arnold Network (QKAN) was then trained using deployable cyber-quantum evidence. The final nonrisk QKAN achieved 98.79% test accuracy, 98.61% macro-F1, 98.85% weighted-F1, and 99.78% macro-AUC, demonstrating effective detection of traditional and cyber-quantum IoT attacks. Full article
(This article belongs to the Section Computational Intelligence)
Show Figures

Figure 1

27 pages, 1765 KB  
Article
Privacy-Preserving Power System Anomaly Detection via Physics-Guided Sparse Graph Temporal Prediction and Homomorphic Inference
by Yuxuan Li, Jie Hua, Weidong Huang and Ali Anaissi
Technologies 2026, 14(9), 550; https://doi.org/10.3390/technologies14090550 - 3 Sep 2026
Viewed by 221
Abstract
Energy systems are crucial to residential life and industrial production. During practical operation, these systems may experience various anomalies that disrupt the stability of system operation. Recent years have witnessed remarkable progress in power system anomaly detection. However, existing methods still suffer from [...] Read more.
Energy systems are crucial to residential life and industrial production. During practical operation, these systems may experience various anomalies that disrupt the stability of system operation. Recent years have witnessed remarkable progress in power system anomaly detection. However, existing methods still suffer from two limitations. First, detection algorithms neglect privacy protection, although privacy security is also a critical issue in energy systems. Second, existing studies have difficulty characterizing latent dependencies and topology changes, which limits detection performance. To bridge these gaps, we present a power system anomaly detection method that integrates physics-informed sparse graph temporal modeling with homomorphic encryption, enabling anomalous-event identification and anomalous-bus localization under privacy-preserving conditions. Specifically, we construct a sparse graph using the power-grid topology and normal measurement residuals. We then obtain system-state predictions through polynomial graph temporal prediction and physics-guided affine correction and use anomaly scores to diagnose anomalous conditions. Furthermore, we employ homomorphic encryption to perform ciphertext computation for the affine prediction model without exposing historical measurement data, thereby enabling privacy-preserving remote anomaly detection. We conduct experiments on IEEE bus benchmarks to verify the effectiveness of the proposed method under multiple anomaly scenarios. Full article
(This article belongs to the Section Electrical Technologies)
Show Figures

Figure 1

20 pages, 515 KB  
Article
CipherBench: A Fine-Grained Benchmark Dataset for Algorithm-Level Fragmented Payload Identification
by Jinhui Shen, Kai Liu, Mengnan Zhao, Ziye Yue, Jiaqi Mao and Xiaofeng Li
Appl. Sci. 2026, 16(17), 8763; https://doi.org/10.3390/app16178763 - 3 Sep 2026
Viewed by 213
Abstract
Algorithm-level payload identification (determining the specific encryption algorithm, compression format, or encoding scheme from raw byte fragments) is a foundational capability for ransomware detection, digital forensics, and cryptographic compliance auditing. To the best of our knowledge, no public benchmark dataset simultaneously satisfies three [...] Read more.
Algorithm-level payload identification (determining the specific encryption algorithm, compression format, or encoding scheme from raw byte fragments) is a foundational capability for ransomware detection, digital forensics, and cryptographic compliance auditing. To the best of our knowledge, no public benchmark dataset simultaneously satisfies three essential requirements: algorithm-level label granularity, simulation of real-world network fragmentation, and coverage of the SM2 and SM4 algorithms that have been adopted as ISO/IEC 18033-3 international standards. Existing datasets are either annotated at the application level, use complete flows as classification units, or lack Chinese national cryptographic algorithm samples, preventing reproducible and standardized performance comparisons across different methods. To address this gap, we introduce CipherBench, a benchmark dataset comprising 50 algorithm-level data types organized into seven categories, with 50,000 samples in total. Each sample passes through a random-offset 1024-byte sliding window with zero-padding to simulate payload truncation caused by TCP fragmentation. The dataset is generated following the key-size recommendations of the NIST SP 800-131A standard, with independent random keys and initialization vectors per encryption operation. Each class is annotated with NIST SP 800-22 randomness benchmark metrics and a 9-field metadata record. We calibrate the benchmark through five families of experiments. A fragmentation-versus-non-fragmentation control experiment (Δ=3.01 pp, concentrated in compression) shows that random-offset windowing contributes a quantifiable, well-understood difficulty. Layered difficulty measurement reveals a progressive gradient: encoding and hash classes are nearly perfectly identifiable (≈100%), compression accuracy is strongly header-dependent, and fine-grained inter-cipher classification among symmetric encryption algorithms converges to random levels (4.81% vs. a 5.56% random baseline over 18 real algorithm implementations), consistent with IND-CPA semantic security. Cross-library control experiments further show that classifiers cannot distinguish SM4 ciphertexts produced by independent implementations, and a random-padding probe demonstrates that asymmetric-encryption accuracy collapses from 64.89% to 0.33% when padding leakage is removed. A held-out corpus validation over ten corpus-level partitions (52.06 ± 0.54% vs. 51.79%) rules out plaintext memorization as a shortcut. CipherBench is designed to fill this gap for algorithm-level fragmented payload identification. Full article
(This article belongs to the Section Computing and Artificial Intelligence)
Show Figures

Figure 1

18 pages, 893 KB  
Article
Ciphertext-Policy Attribute-Based Boolean Keyword Search with Negation for EHR Sharing
by Hongjian Yin, Xiangbo Wang, Haicheng Chen, Guangyu Ding, Binrong Cheng and Lei Zhang
Symmetry 2026, 18(9), 1459; https://doi.org/10.3390/sym18091459 - 30 Aug 2026
Viewed by 163
Abstract
The growing volume of electronic health records (EHRs) has made cloud-assisted storage increasingly important, but outsourced records require both encrypted storage and controlled retrieval. Attribute-based keyword searchable encryption (ABKS) combines search with fine-grained authorization; nevertheless, many existing constructions provide only restricted Boolean queries, [...] Read more.
The growing volume of electronic health records (EHRs) has made cloud-assisted storage increasingly important, but outsourced records require both encrypted storage and controlled retrieval. Attribute-based keyword searchable encryption (ABKS) combines search with fine-grained authorization; nevertheless, many existing constructions provide only restricted Boolean queries, particularly when negation is involved. This paper presents a ciphertext-policy ABKS search layer for EHR sharing. The proposed construction operates over a fixed application dictionary and assumes a non-colluding honest-but-curious cloud server. Each record is represented by one signed literal per dictionary term, where a positive literal denotes presence and a negated literal denotes absence. Before query evaluation, Boolean formulas involving AND, OR, and NOT are converted into negation normal form using De Morgan’s laws, so that NOT appears only at leaf nodes. The resulting query is then evaluated as a monotone threshold tree. An authorized user can generate a valid query token only when the user’s multi-valued attribute vector matches the policy selected by the data owner. Keyed pseudorandom tags hide literal and policy values from the cloud server while enabling efficient component lookup. We define a selective chosen-keyword security model, state the resulting leakage, and give a game-based proof under the decisional bilinear Diffie–Hellman and pseudorandom-function assumptions. Theoretical and implementation-based comparisons show that the pairing-dominant costs grow linearly with the attribute and dictionary sizes. The construction therefore improves Boolean expressiveness while retaining practical search-layer overhead under the stated assumptions. Full article
(This article belongs to the Section A: Computer Science)
Show Figures

Figure 1

24 pages, 38466 KB  
Article
Optical Color Zero-Watermarking via Phase-Shifting Digital Holography Coupled with High-Robustness Bimodal Biometric Keys
by Guanghai Liu, Zhe Zhang, Wang Fu, Cui Zhang, Boyu Wang, Yanfeng Su and Zhijian Cai
Entropy 2026, 28(9), 966; https://doi.org/10.3390/e28090966 - 29 Aug 2026
Viewed by 190
Abstract
In this paper, an optical color zero-watermarking scheme based on robust bimodal biometric keys and phase-shifting digital holography is proposed. The color watermark is first encrypted into three amplitude ciphertexts through an optical encryption framework combining grating modulation, Fresnel-domain double random phase encoding [...] Read more.
In this paper, an optical color zero-watermarking scheme based on robust bimodal biometric keys and phase-shifting digital holography is proposed. The color watermark is first encrypted into three amplitude ciphertexts through an optical encryption framework combining grating modulation, Fresnel-domain double random phase encoding (DRPE), and phase-shifting digital holography, where the phase masks are generated from biometric keys derived from the iris and three-dimensional (3D) face features of the encryption user. These high-level biometric features are extracted by a bimodal biometric high-order feature extraction network (BBHEN), including an iris high-order data extraction network and a 3D face high-order data extraction network. The extracted features of the color host image are then XORed with the corresponding ciphertexts, and the results are merged to construct a single zero-watermark image containing both host and watermark information. During extraction, biometric authentication is first performed to verify the identity of the decryption user. Only authorized users can recover the original watermark through zero-watermark reconstruction and extraction; otherwise, the process is terminated. Numerical simulations demonstrate the effectiveness, security, and robustness of the proposed scheme, particularly the strong protection capability of the bimodal biometric keys. Full article
(This article belongs to the Section Multidisciplinary Applications)
Show Figures

Figure 1

30 pages, 894 KB  
Article
BAPPS: A Blockchain-Assisted Privacy-Preserving Sharing Scheme for Secure Data Exchange in the Internet of Vehicles
by Lin Wang, Ke Chen, Fangxiao Li and Leyi Shi
Electronics 2026, 15(17), 3882; https://doi.org/10.3390/electronics15173882 - 28 Aug 2026
Viewed by 247
Abstract
The Internet of Vehicles (IoV) is evolving into a distributed electronic sensing and communication infrastructure in which vehicles, roadside units, and service platforms continuously exchange data for intelligent transportation services. However, cross-organization sharing of vehicle-borne sensing data can expose identity links, location traces, [...] Read more.
The Internet of Vehicles (IoV) is evolving into a distributed electronic sensing and communication infrastructure in which vehicles, roadside units, and service platforms continuously exchange data for intelligent transportation services. However, cross-organization sharing of vehicle-borne sensing data can expose identity links, location traces, task routes, and raw sensor content. This paper proposes BAPPS, a Blockchain-Assisted Privacy-Preserving Sharing Scheme for Secure Data Exchange in the Internet of Vehicles. BAPPS combines anonymous identity issuance, zk-SNARK-based data-quality verification, elliptic-curve proxy re-encryption, and on-chain audit records. Data owners can prove that encrypted observations satisfy task-specific quality or access constraints without disclosing raw data, while a semi-honest service provider transforms ciphertexts only under authorization. The consortium blockchain records task publication, access verification, proof submission, and data-hash evidence, enabling traceable sharing without exposing plaintext observations. We further implement a Tendermint-style BFT consensus layer, denoted BAPPS-T, to reduce confirmation latency in the data-sharing workflow. Using the three available real Tendermint benchmark workbooks as repeated records, BAPPS-T achieved a mean consensus latency of 776.3 ms at 100 nodes (SD = 80.8 ms, n = 3, 95% CI = 575.5–977.1 ms), corresponding to a 90.17% latency reduction relative to Baseline 1. The results indicate that BAPPS can provide a reproducible protocol layer for trusted, privacy-aware sharing of mobile electronics observations under explicit deployment assumptions. Full article
(This article belongs to the Topic Advanced Electric Vehicle Technology, 3rd Edition)
Show Figures

Figure 1

22 pages, 12032 KB  
Article
Tile-Wise Authenticated Selective Encryption and Public-Geometry Leakage Evaluation for Graphite Ore Images
by Kaiyun Hu, Xueyu Huang, Zeyang Qiu, Chen Yang and Le Chen
Appl. Sci. 2026, 16(17), 8540; https://doi.org/10.3390/app16178540 - 27 Aug 2026
Viewed by 231
Abstract
Images used in intelligent graphite ore sorting can reveal grade-related visual and spatial information. Selective encryption reduces the cost of full-image protection and preserves nonsensitive background regions, but the number, location, and shape of protected regions may become public side channels. This paper [...] Read more.
Images used in intelligent graphite ore sorting can reveal grade-related visual and spatial information. Selective encryption reduces the cost of full-image protection and preserves nonsensitive background regions, but the number, location, and shape of protected regions may become public side channels. This paper proposes TASR-AE (Tile-wise Authenticated Selective ROI Encryption), a tile-wise authenticated selective ROI (region of interest) encryption method for graphite ore images. Low-, mid-, and high-grade ore instances are merged into a grade-agnostic ore ROI, dilated for boundary tolerance, quantized onto a fixed grid, and encrypted tile by tile with HKDF (HMAC-based Extract-and-Expand Key Derivation Function)-separated ChaCha20-Poly1305 (an authenticated encryption algorithm). An authenticated sidecar binds tile coordinates, anonymized object identity, algorithm metadata, and the public background. We evaluate correctness, overhead, automatic ROI localization, public-geometry grade-membership inference, decoy-budget trade-offs, ciphertext-position leakage, and adaptive real-ROI recovery. On an audited 121-image graphite test split, TASR-AE with ground-truth masks achieves exact recovery and background authentication while protecting 10.81% of pixels without decoys. Grade-agnostic ROI selection removes deterministic high-grade existence leakage, but full public geometry still yields a High-membership ROC-AUC (area under the receiver operating characteristic curve) of 0.7539. A frozen 576-tile decoy budget lowers the validation ROC-AUC to 0.5088, but the test ROC-AUC rises to 0.6491 while protecting 80.86% of the image. Ciphertext texture does not distinguish real and decoy tiles (pooled ROC-AUC 0.5064), yet a position-and-occupancy adaptive attack recovers real ROI membership with ROC-AUC 0.9868 and mean tile IoU (intersection over union) 0.7051. The results show that TASR-AE provides authenticated content protection with public background visibility, but fixed-budget decoys do not provide strong ROI-location hiding. Full article
(This article belongs to the Section Computing and Artificial Intelligence)
Show Figures

Figure 1

20 pages, 4008 KB  
Article
RSA-OAEP Encryption with a Ciphertext Equality Testing Scheme in Intelligent Healthcare
by Huijun Zhu, Tianfeng Li, Xiaobin Yan and Licheng Wang
Appl. Sci. 2026, 16(17), 8518; https://doi.org/10.3390/app16178518 - 27 Aug 2026
Viewed by 201
Abstract
Driven by digital transformation, intelligent healthcare systems (IHS) have achieved the upgrading of modules covering diagnosis, treatment and public services. Against this backdrop, comprehensive security protection has become key for stabilizing the operation of medical systems and safeguarding patients’ legitimate rights and interests, [...] Read more.
Driven by digital transformation, intelligent healthcare systems (IHS) have achieved the upgrading of modules covering diagnosis, treatment and public services. Against this backdrop, comprehensive security protection has become key for stabilizing the operation of medical systems and safeguarding patients’ legitimate rights and interests, as well as being an essential foundation for the sustainable development of IHS. Equality test function-based public key encryption (PKEwET) plays a vital role in IHS, the Internet of Things (IoT), etc. The scheme enables individual users to encrypt and store personal privacy data by themselves. Furthermore, it supports ciphertext matching and retrieval in a non-decryption manner in the public encryption system. To meet the needs of a variety of applications, many PKEwET applications for flexible authorization schemes have been proposed. In this paper, the equality test function is integrated with the Optimal Asymmetric Encryption Padding (RSA-OAEP) scheme. The aim is to offer an equality test function to RSA-OAEP algorithms without a secret key sk. In contrast to the original PKEwET primitive scheme, the proposed scheme integrates a flexible authorization mechanism. Authorized users can test the encrypted personal health information. Compared to the RSA-OAEP scheme, the proposed scheme in this paper supports the equality test function to the ciphertexts. The security of the proposed scheme is demonstrated to two different security levels, the OW-CCA level and the IND-CCA level. Finally, a performance analysis is presented. Appropriate comparisons with relevant works confirm that the proposed scheme offers a new function and shows good efficiency. Full article
Show Figures

Figure 1

46 pages, 6687 KB  
Article
An Explainable Federated Intrusion Detection Framework for SDN Using Distributed Key Generation and Threshold Homomorphic Encryption
by S. M. Shamim, Yuta Kodera, Md. Arshad Ali and Yasuyuki Nogami
Sensors 2026, 26(17), 5337; https://doi.org/10.3390/s26175337 - 23 Aug 2026
Viewed by 344
Abstract
The rapid advancement of software-defined networking (SDN) has enhanced network programmability, centralized control, and traffic management flexibility, while also increasing exposure to sophisticated attacks targeting the control plane. Although federated learning (FL) enables collaborative intrusion detection without centralized raw data sharing, existing FL-based [...] Read more.
The rapid advancement of software-defined networking (SDN) has enhanced network programmability, centralized control, and traffic management flexibility, while also increasing exposure to sophisticated attacks targeting the control plane. Although federated learning (FL) enables collaborative intrusion detection without centralized raw data sharing, existing FL-based intrusion detection systems remain vulnerable to plaintext model update leakage, centralized cryptographic trust, limited interpretability, and insufficient validation in operational SDN environments. To address these limitations, this paper presents an explainable federated intrusion detection framework that integrates distributed key generation (DKG), CKKS-based threshold homomorphic encryption, collaborative decryption, and SHapley Additive exPlanations (SHAP). Unlike conventional HE-enabled FL systems that rely on a trusted authority or a globally shared secret key, the proposed framework removes the trusted key-generation dealer, avoids centralized custody of the complete secret key, and prevents any single client or aggregation server from independently decrypting ciphertexts using locally held key material. A gated recurrent unit (GRU)-based model is used for privacy-preserving intrusion detection, and SHAP provides global and local explanations of model decisions. The framework is further deployed in a real-time SDN testbed to evaluate the online inference pipeline following threshold-secured federated training. Computationally intensive cryptographic operations, including DKG, encrypted aggregation, and threshold decryption, are performed during offline training, while the converged global model enables low-latency inference at runtime. Experiments on the InSDN, CICDDoS2017, and CICDDoS2019 datasets with 4, 8, and 12 client federated configurations achieved detection accuracies above 99% across all datasets. The evaluation also examines encryption latency, collaborative decryption overhead, secure aggregation cost, communication complexity, and scalability. The results demonstrate that the proposed framework provides a practical balance among decentralized key management, privacy-preserving aggregation, explainability, detection performance, and real-time SDN deployment feasibility. Full article
(This article belongs to the Section Sensor Networks)
Show Figures

Figure 1

Back to TopTop