Sign in to use this feature.

Years

Between: -

Subjects

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Journals

Article Types

Countries / Regions

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Search Results (400)

Search Parameters:
Keywords = light-weight encryption

Order results
Result details
Results per page
Select all
Export citation of selected articles as:
27 pages, 3009 KB  
Article
SM2-PRE+: A Lightweight Pairing-Free Proxy Re-Encryption Scheme for Secure IoMT Healthcare Data Sharing
by Shuanggen Liu, Mingxing Zhu, Xu-An Wang, Ziqi Fan and Xinyu Zhou
Sensors 2026, 26(18), 5761; https://doi.org/10.3390/s26185761 - 10 Sep 2026
Abstract
With the rapid development of the Internet of Medical Things (IoMT), wearable sensors and intelligent medical terminals continue to generate a large amount of sensitive medical data, which needs to be uploaded to the cloud platform for storage and sharing. However, IoMT devices [...] Read more.
With the rapid development of the Internet of Medical Things (IoMT), wearable sensors and intelligent medical terminals continue to generate a large amount of sensitive medical data, which needs to be uploaded to the cloud platform for storage and sharing. However, IoMT devices usually have the characteristics of limited computing resources and limited energy, and it is difficult for traditional high-complexity encryption schemes to meet the requirements of security and efficiency. In addition, the existing Proxy Re-Encryption (PRE) scheme has the risk of authorization transfer, and it is difficult to achieve fine-grained and secure sharing of medical data. In response to the above problems, this paper proposes a lightweight non-pairing proxy re-encryption enhancement scheme SM2-PRE+ based on the SM2 algorithm, which is used for the secure sharing of IoMT medical sensing data. The scheme combines the SM2 elliptic curve cipher algorithm and the SM4 symmetric encryption algorithm to achieve data protection through a double-layer key structure, and it uses the re-encryption mechanism of message binding to enhance the authorization control ability. Compared with the traditional PRE scheme, the proposed scheme avoids bilinear pairing operations, reduces the computing overhead of resource-limited equipment, and supports collusion-resistant and authorization non-transferability. Security analysis shows that the scheme meets the security requirements of IND-CCA under the Random Oracle Model (ROM). Performance analysis results show that SM2-PRE+ has low computing overhead and storage burden, which is suitable for wearable medical devices, intelligent sensing terminals, and cloud-assisted IoMT data sharing scenarios. Full article
(This article belongs to the Special Issue Cyber Security and Privacy in Internet of Things (IoT))
Show Figures

Figure 1

11 pages, 512 KB  
Proceeding Paper
A Secure, Lightweight, and Low-Latency Edge–Cloud Architecture for Intelligent V2X Communication Systems
by Sema Bayraktar, Adnan Kavak, Muhammad Jamil, Ali Can Doğru, Muhammad Farhan and Günay Aslan
Eng. Proc. 2026, 154(1), 73; https://doi.org/10.3390/engproc2026154073 - 9 Sep 2026
Abstract
Next-generation Intelligent Transportation Systems (ITSs) require ultra-reliable, low-latency Vehicle-to-Everything (V2X) communication frameworks that support safety-critical vehicular services. Conventional centralized, monolithic architectures suffer from excessive transmission latency, limited scalability, and authentication overheads that are ill-suited to the highly dynamic and dense vehicular environment. This [...] Read more.
Next-generation Intelligent Transportation Systems (ITSs) require ultra-reliable, low-latency Vehicle-to-Everything (V2X) communication frameworks that support safety-critical vehicular services. Conventional centralized, monolithic architectures suffer from excessive transmission latency, limited scalability, and authentication overheads that are ill-suited to the highly dynamic and dense vehicular environment. This paper presents a secure and low-latency edge–cloud architecture for intelligent V2X communications based on a lightweight microservice-driven design paradigm. A formal latency-constrained model is presented to ensure that the end-to-end delay satisfies tight real-time constraints. The proposed framework is lightweight and includes HMAC-based authentication, nonce-based replay protection, timestamp validation, and short-lived encrypted session tokens in a stateless architecture using the Laravel framework deployed at the edge layer. Security validation is performed at edge gateways, and asynchronous SQLite-backed job queues support non-blocking telemetry processing and scalable service orchestration. Experimental evaluation shows that the edge-based deployment achieves a mean response time of 2.58 ms with small variance under repeated request conditions, while centralized processing exhibits significantly higher latency. The results demonstrate that secure authentication and telemetry exchange can be achieved without breaching strict latency requirements. The proposed solution creates a deployable, scalable, and security-aware foundation for next-generation V2X ecosystems and Intelligent Transportation Systems (ITSs) in real time. Full article
Show Figures

Figure 1

27 pages, 4270 KB  
Article
A Privacy-Preserving TinyML-Driven IoT Edge Architecture for Low-Latency Smart Sensing and Autonomous AI-Based Control
by P. Kannan, K. Aruna Kumari, Punith Kumar, P. Hema Sree, C. M. Velu, V. Sangeetha, Rokesh Kumar Yarava and N. Rajeswaran
Chips 2026, 5(3), 28; https://doi.org/10.3390/chips5030028 - 8 Sep 2026
Viewed by 80
Abstract
As smart sensing applications grow rapidly, the IoT edge architectures need to support low latency, make decisions with little memory, power, and communication resources while preserving the privacy of the data. But traditional cloud-based IoT solutions come with transmission delay, increased energy consumption, [...] Read more.
As smart sensing applications grow rapidly, the IoT edge architectures need to support low latency, make decisions with little memory, power, and communication resources while preserving the privacy of the data. But traditional cloud-based IoT solutions come with transmission delay, increased energy consumption, and privacy issues because of the constant transfer of raw data. In this paper, we propose a privacy-preserving TinyML-driven IoT edge architecture that enables real-time smart sensing and autonomous AI-based control. The proposed framework includes on-device sensor pre-processing, lightweight TinyML inference, adaptive model selection, encrypted feature-level communication, trust-aware decision validation, and local control execution. Raw data streams from the sensors are also processed locally, and only compact encrypted features or a summary of the decisions are sent if necessary to minimize privacy exposure. The experimental evaluation reveals that the proposed architecture has an accuracy of 97.4%, an F1 score of 96.9%, and a secure-event detection rate of 98.1% and reduces the inference latency by 14.8%, the energy consumption by 4.1 mJ per inference and the amount of data transmitted by 74.5% compared to conventional edge-cloud processing. Results show that the proposed architecture is a scalable, privacy-aware, and energy-efficient solution for real-time autonomous IoT control of smart environments with limited resources. Full article
(This article belongs to the Special Issue Emerging Issues in Hardware and IC System Security)
Show Figures

Figure 1

21 pages, 642 KB  
Article
Improved Differential Cryptanalysis of the Ultra-Lightweight Block Cipher PICO
by Yu Wang, Zhuofeng Liang, Ting Fan and Tao Zhou
Entropy 2026, 28(9), 1006; https://doi.org/10.3390/e28091006 - 8 Sep 2026
Viewed by 63
Abstract
PICO is an ultra-lightweight substitution–permutation network block cipher designed for resource-constrained devices such as Internet of Things terminals and edge agents. For fixed endpoints, summing the characteristic probabilities over an enumerated finite weight window gives a verifiable lower bound on the differential probability. [...] Read more.
PICO is an ultra-lightweight substitution–permutation network block cipher designed for resource-constrained devices such as Internet of Things terminals and edge agents. For fixed endpoints, summing the characteristic probabilities over an enumerated finite weight window gives a verifiable lower bound on the differential probability. We use a PICO-specific workflow that combines mixed-integer linear programming bounds on active substitution boxes, exact-weight Boolean satisfiability search, optional Matsui pruning, and fixed-endpoint enumeration. For the selected endpoints, enumeration over W=63,,76 and W=66,,79 gives finite-window lower bounds of 259.95 and 261.95 for 21 and 22 rounds, respectively. We prepend two rounds and append three rounds to the 21-round differential distinguisher. The resulting 26-round analysis is an analytical equivalent-round-key filtering-and-ranking procedure for a 108-bit tuple. The verified 21-round finite-window probability input is a factor of 20.80321.745 larger than the previously reported input, increasing the expected right-tuple support at fixed S under the analytical accounting. For the illustrative choice S=242, the analytical resources are D=262 chosen plaintexts, a normalized substitution-box filtering workload of T=2100.11 equivalent 26-round encryptions, and M=262 stored plaintext–ciphertext records. This setting is not tied to a demonstrated success probability and does not establish an equal-success complexity advantage over prior work. Full article
(This article belongs to the Section Information Theory, Probability and Statistics)
Show Figures

Figure 1

30 pages, 819 KB  
Article
SoP-CTR: A Lightweight Stream Cipher with Beyond-Birthday-Bound Security for IoT and Embedded Devices
by Andriani Adi Lestari, Suryadi MT, Kalamullah Ramli, Susila Windarta and Teddy Surya Gunawan
J. Cybersecur. Priv. 2026, 6(5), 157; https://doi.org/10.3390/jcp6050157 - 8 Sep 2026
Viewed by 144
Abstract
As systems migrate toward post-quantum readiness, symmetric keys are kept longer and protect larger data volumes, a regime in which keystream security beyond the birthday bound matters. The dominant block–cipher counter mode, AES-CTR (Advanced Encryption Standard, counter mode), caps keystream security at the [...] Read more.
As systems migrate toward post-quantum readiness, symmetric keys are kept longer and protect larger data volumes, a regime in which keystream security beyond the birthday bound matters. The dominant block–cipher counter mode, AES-CTR (Advanced Encryption Standard, counter mode), caps keystream security at the birthday bound regardless of key length, and, to our knowledge, no lightweight stream cipher pairs provable beyond-birthday-bound security with a permutation standardised by the National Institute of Standards and Technology (NIST). We propose SoP-CTR, a stream cipher built from the NIST-standardised Ascon-p12 permutation via the Sum of Permutations (SoP) paradigm. The z-split SoP framework achieves single-key beyond-birthday-bound (BBB) security by XORing a split constant into the counter word, eliminating independent key derivation. We prove an explicit two-term pseudorandom-function (PRF) advantage bound Advq3/2/2320+2pq/2256, valid for pairwise-distinct counters in [0,263). The online term is negligible throughout this 263-block range, and the offline term bounds adversarial key-search and is the binding constraint for post-quantum offline budgets. The SoP construction provably eliminates the birthday distinguisher that breaks a hypothetical single-call CTR-Ascon at q2160. We also give the first quantum analysis of this domain-separated single-key variant in the Q1 model, where construction queries are classical and the public permutation may be evaluated quantumly, obtaining an attack at 285.3 and an unconditional lower bound of 264.3, so the post-quantum figure is the best known attack cost of 285.3 rather than the generic 2128 Grover level. On a physical STM32F407 ARM Cortex-M4 (168 MHz), hardware cycle-counter measurements yield 61.44 cycles per byte (cpb) for the unrolled variant, about 4.6% faster than Ascon-128 keystream extraction (64.39 cpb), and 63.78 cpb for the memory-optimised rolled variant (3832 bytes Flash), while providing a strictly stronger BBB guarantee. An x86-64 AVX2 two-block variant achieves 2.57 cpb at 1 KiB. Full article
(This article belongs to the Section Cryptography and Cryptology)
Show Figures

Graphical abstract

49 pages, 2226 KB  
Article
Adaptive Encryption Framework for Web Applications: A Risk-Based Approach to Dynamic Algorithm Selection
by Flavius G. Stașac, Cornelia A. Győrödi and Robert S. Győrödi
Appl. Sci. 2026, 16(17), 8889; https://doi.org/10.3390/app16178889 - 7 Sep 2026
Viewed by 117
Abstract
Web applications increasingly handle sensitive data in diverse use cases, but conventional encryption implementations apply a uniform level of cryptographic protection to all traffic, regardless of the associated risk. This static approach results in either excessive computational overhead when applying maximum encryption universally, [...] Read more.
Web applications increasingly handle sensitive data in diverse use cases, but conventional encryption implementations apply a uniform level of cryptographic protection to all traffic, regardless of the associated risk. This static approach results in either excessive computational overhead when applying maximum encryption universally, or inadequate protection when using lightweight encryption to preserve performance. This paper proposes an Adaptive Encryption Framework (AEF) designed to bridge the gap between performance and security in web applications. Rather than relying on a static protocol, AEF dynamically adjusts encryption algorithms based on a real-time composite risk score (0–100). This score is derived from six weighted variables: network risk (25%), authentication strength (20%), behavioral risk (20%), device trust (15%), data sensitivity (15%), and temporal risk (5%). Depending on the calculated risk, the system automatically transitions between three distinct security tiers: GREEN (utilizing ChaCha20-Poly1305), YELLOW (AES-256-GCM), or RED (AES-256-GCM with per-request HKDF key derivation for key isolation). All three profiles use exclusively standardized cryptographic primitives. The proposed weighting distribution was evaluated through sensitivity analysis on 27 framework-executed scenarios and further calibrated using 40,000 labeled application requests. Within these experimental conditions, it achieved complete agreement with the expected scenario classifications, and no alternative weight configuration produced better held-out performance. Additional validation on 61,065 HTTP requests from the CSIC 2010 dataset yielded an area under the ROC curve (ROC AUC) of 0.860, with no attack request assigned to the lightweight profile under the evaluated operating conditions. Across three hardware platforms and four payload sizes, all encryption profiles maintained sub-millisecond latency. Extended load testing showed that a four-worker Node.js cluster sustained 4948 requests per second at 2000 concurrent connections, a 7.1-fold improvement over a single process. When hardware cryptographic acceleration was disabled, ChaCha20-Poly1305 became up to 9.1 times faster than AES-256-GCM, supporting its use as the lightweight profile. The framework proposed in this paper operationalizes the qualitative risk assessment guidelines from NIST SP 800-30 and SP 800-63 into a quantitative, automated encryption selection mechanism for web applications, evaluated under the hardware platforms, concurrency levels and traffic assumptions described in this study. Full article
(This article belongs to the Section Computing and Artificial Intelligence)
Show Figures

Figure 1

12 pages, 2375 KB  
Proceeding Paper
Hierarchical Security Framework for Drone Control in Parcel Delivery
by Ivan Ivanov and Filip Tsvetanov
Eng. Proc. 2026, 154(1), 13; https://doi.org/10.3390/engproc2026154013 - 31 Aug 2026
Viewed by 112
Abstract
Secure delivery of packages by drones requires reliable management of cryptographic keys, despite limited on-board resources, multiple users, and the risk of interception or manipulation. This paper proposes a hierarchical model of a Key Distribution Center that manages the generation, distribution, storage, control, [...] Read more.
Secure delivery of packages by drones requires reliable management of cryptographic keys, despite limited on-board resources, multiple users, and the risk of interception or manipulation. This paper proposes a hierarchical model of a Key Distribution Center that manages the generation, distribution, storage, control, and destruction of cryptographic keys. The model uses public-key mechanisms for secure transmission of session keys and lightweight symmetric encryption for communication between the drone and the recipient. A session key lifecycle is defined, including verification, encrypted storage, validity control, and secure deletion. The operational workflow for the secure delivery of packages is also described. The proposed approach improves confidentiality, scalability, and access control. Full article
Show Figures

Figure 1

21 pages, 371 KB  
Article
Blockchain-Assisted Authentication, Authorization, and Audit for MQTT-Based Smart-City IoT
by Rida Lkhluf, David Santo Orcero and Francisco Javier González Cañete
Future Internet 2026, 18(9), 463; https://doi.org/10.3390/fi18090463 - 29 Aug 2026
Viewed by 245
Abstract
Smart-city services increasingly rely on Internet of Things (IoT) deployments using lightweight Message Queuing Telemetry Transport (MQTT), yet weakly protected systems remain exposed to spoofing, unauthorized state changes, and limited accountability. This work evaluates blockchain and smart contracts as a complementary trust layer [...] Read more.
Smart-city services increasingly rely on Internet of Things (IoT) deployments using lightweight Message Queuing Telemetry Transport (MQTT), yet weakly protected systems remain exposed to spoofing, unauthorized state changes, and limited accountability. This work evaluates blockchain and smart contracts as a complementary trust layer for MQTT-based smart-city IoT rather than as a replacement for transport-layer security. The proposed architecture provides owner-controlled device registration, per-sensor nonce management, replay-resistant Elliptic Curve Digital Signature Algorithm (ECDSA) authentication, authorization of state-changing operations, and tamper-evident event logging. MQTT confidentiality remains dependent on Transport Layer Security (TLS) or payload encryption. A prototype was implemented using ESP32 microcontrollers, a Raspberry Pi MQTT broker, Node-RED supervision, MongoDB storage, and Ethereum smart contracts deployed on Sepolia. The evaluation combines practical attack scenarios (unauthorized sensor modification, identity spoofing, and data manipulation) with measurements of blockchain latency, throughput, and gas consumption. Results show auditable nonce-bound signed updates, with mean transaction latency close to 12 s. Because the contract updates one sensor per transaction, costs are interpreted per confirmed write operation and scenario size. The findings position blockchain as an audit and policy-enforcement component for MQTT-based IoT. Full article
Show Figures

Graphical abstract

25 pages, 500 KB  
Article
Secure UPnP Resource Discovery Using a PUF-Assisted Hardware Accelerator for IoT
by Kasem Khalil
Sensors 2026, 26(17), 5410; https://doi.org/10.3390/s26175410 - 27 Aug 2026
Viewed by 261
Abstract
Universal Plug and Play (UPnP) is widely used for resource discovery in internet of things and smart-edge environments because of its lightweight and decentralized operation. However, conventional UPnP and Simple Service Discovery Protocol (SSDP) mechanisms expose static identifiers and service metadata, making them [...] Read more.
Universal Plug and Play (UPnP) is widely used for resource discovery in internet of things and smart-edge environments because of its lightweight and decentralized operation. However, conventional UPnP and Simple Service Discovery Protocol (SSDP) mechanisms expose static identifiers and service metadata, making them vulnerable to spoofing, replay, unauthorized resource enumeration, device fingerprinting, and long-term traffic correlation. Existing software-based authentication methods rely on stored credentials and do not protect discovery privacy, while conventional Arbiter Physical Unclonable Functions (PUFs) remain vulnerable to machine-learning modeling attacks and are typically used only for device authentication. This paper presents a novel Recursive Hybrid Entropy PUF (RHE-PUF) and a privacy-preserving secure UPnP discovery architecture. The proposed RHE-PUF introduces recursive adaptive delay propagation, entropy injection, feed-forward coupling, and multi-path timing diversification to increase challenge–response nonlinearity and modeling resistance. Its responses are used to generate dynamic ephemeral identities, authenticate devices anonymously, and encrypt SSDP service advertisements without exposing permanent device identifiers. The complete framework was implemented on a Xilinx Spartan-7 FPGA and evaluated under realistic UPnP discovery and attack scenarios. The RHE-PUF achieved 49.31% uniqueness, 98.14% reliability, 50.22% uniformity, and 98.91% entropy. The implementation operated at up to 192 MHz with 0.84 W dynamic power, 0.88 µs authentication latency, and 13.4 ms secure discovery delay. The strongest deep-neural-network modeling attack achieved only 58.27% prediction accuracy. Replay and spoofing attack success rates were reduced to at or below 1.1% and 0.8%, respectively, while long-term tracking probability remained below 13%. These results demonstrate that the proposed joint hardware-security and privacy-preserving discovery framework provides resource-efficient authentication, anonymous UPnP resource discovery, and resistance to network and machine-learning attacks. Full article
Show Figures

Figure 1

28 pages, 2826 KB  
Review
Encrypted-Traffic Detection in the TLS 1.3 Era: A Comprehensive Review and Future Research Directions
by Hazem Abu-Adaiq, Md Israfil Biswas, Ahmad Y. Alnajjar and Sijing Zhang
Electronics 2026, 15(17), 3846; https://doi.org/10.3390/electronics15173846 - 27 Aug 2026
Viewed by 423
Abstract
Transport Layer Security (TLS) 1.3 strengthens Internet privacy by encrypting protocol metadata increasingly used by network monitoring and intrusion-detection systems, while Encrypted ClientHello (ECH) further reduces visibility into connection establishment. This paper presents a systematic and technically grounded review of encrypted-traffic detection approaches [...] Read more.
Transport Layer Security (TLS) 1.3 strengthens Internet privacy by encrypting protocol metadata increasingly used by network monitoring and intrusion-detection systems, while Encrypted ClientHello (ECH) further reduces visibility into connection establishment. This paper presents a systematic and technically grounded review of encrypted-traffic detection approaches under TLS 1.3 and ECH, with an emphasis on their observable features, analytical formulations, and practical limitations. Unlike previous reviews that primarily classify detection techniques, this study explicitly examines the methodological assumptions and mathematical foundations underlying representative approaches, including Random Forest aggregation, Kullback–Leibler divergence, Discrete Fourier Transform (DFT), and Shannon entropy. The literature is systematically organised into machine learning, statistical/rule-based, and behavioural/flow-level approaches and assessed against feature dependency, interpretability, reproducibility, scalability, deployment feasibility, and resilience to reduced visibility. The review identifies continued dependence on TLS-specific or handshake-derived features and highlights persistent challenges in dataset representativeness, cross-environment generalisation, explainability, and adversarial robustness. In contrast, residual observables—including packet timing, size distributions, directional asymmetry, flow dynamics, frequency-domain characteristics, and burst behaviour—remain potentially useful without inspecting encrypted payloads or concealed protocol fields. The synthesis identifies behavioural–statistical fusion as a promising research direction; however, its effectiveness remains empirically unvalidated as an integrated framework. Future research should therefore prioritise reproducible datasets, cross-environment and adversarial evaluation, and lightweight, interpretable detection mechanisms capable of operating under progressively restricted network visibility. Full article
Show Figures

Figure 1

28 pages, 4738 KB  
Article
nD-NDHS: An n-Dimensional Non-Degenerate Hyperchaotic System with Controllable All-Positive Lyapunov Exponents
by Xiaobing Liu, Qing Ye, Jinnan Li, Wei Liu, Zhimin Yuan, Qian Zhou and Zebin Song
Mathematics 2026, 14(16), 2988; https://doi.org/10.3390/math14162988 - 18 Aug 2026
Viewed by 298
Abstract
Constructing scalable, non-degenerate, and intensity-tunable high-dimensional hyperchaotic maps is a key challenge for chaotic cryptography. Existing n-dimensional real-valued chaotic systems frequently suffer from dynamical degradation, limited adjustability of Lyapunov exponents, and reduced complexity under high-dimensional settings. To mitigate these drawbacks, this paper [...] Read more.
Constructing scalable, non-degenerate, and intensity-tunable high-dimensional hyperchaotic maps is a key challenge for chaotic cryptography. Existing n-dimensional real-valued chaotic systems frequently suffer from dynamical degradation, limited adjustability of Lyapunov exponents, and reduced complexity under high-dimensional settings. To mitigate these drawbacks, this paper proposes an n-dimensional non-degenerate hyperchaotic system (nD-NDHS). Rigorous theoretical derivations demonstrate that all Lyapunov exponents can be continuously adjusted to positive values using a single global control parameter, which guarantees stable hyperchaotic behavior for different tested dimensions. Four evaluation metrics including Lyapunov exponents, correlation dimension, sample entropy, and Kolmogorov entropy are adopted for comprehensive assessment, alongside comparisons with state-of-the-art n-dimensional chaotic maps. Bifurcation diagrams, phase trajectories and Lyapunov exponent spectra are employed to analyze multiple instantiations and validate the generality of the presented framework. A 4D instantiation is physically realized on an STM32 embedded platform, and the corresponding pseudorandom number generator is subjected to the complete NIST SP800-22 and TestU01 test suites. Experimental results reveal that nD-NDHS exhibits compelling chaotic properties and improved dimensional robustness, where all statistical tests are passed to confirm favorable statistical randomness. The proposed model provides a novel complexity-controllable and degradation-resistant hyperchaotic paradigm, which is well adapted to high-dimensional encryption and lightweight hardware-oriented pseudorandom number generation. Full article
Show Figures

Figure 1

25 pages, 23619 KB  
Article
Lightweight Homomorphic Pixel Scrambling for Privacy-Preserving Image Fusion
by Tieyu Zhao
Electronics 2026, 15(16), 3637; https://doi.org/10.3390/electronics15163637 - 15 Aug 2026
Viewed by 291
Abstract
Image fusion integrates complementary multi-source visual information, yet plaintext fusion poses severe privacy risks. Conventional lattice-based homomorphic encryption enables ciphertext computation but incurs substantial computational overhead and exhibits poor compatibility with image fusion tasks. This work investigates lightweight privacy-preserving image fusion built upon [...] Read more.
Image fusion integrates complementary multi-source visual information, yet plaintext fusion poses severe privacy risks. Conventional lattice-based homomorphic encryption enables ciphertext computation but incurs substantial computational overhead and exhibits poor compatibility with image fusion tasks. This work investigates lightweight privacy-preserving image fusion built upon pixel scrambling. Any pixel-scrambling technique that only rearranges pixel coordinates without modifying pixel values inherently satisfies the homomorphic properties required for pixel-level spatial fusion. In this paper, we adopt full-size random permutation matrix scrambling as a representative pixel-disordering method for systematic theoretical and experimental verification. The scheme generates a secret key matching the resolution of test images; it merely reorders pixel positions while preserving all original intensity values, allowing direct cipher-domain fusion that yields distortion-free outputs for averaging, weighted averaging, maximum-value and minimum-value fusion rules. Free from intricate lattice calculations and ciphertext expansion, the proposed lightweight framework achieves an optimal trade-off among security, computational efficiency and fusion quality for cloud computing scenarios. Full article
Show Figures

Figure 1

26 pages, 3518 KB  
Article
Cost-Aware Android Malware Detection Using an Early-Warning Behaviour Score
by Ali Fenjan, Mohammed Almulla and Jalil Md. Desa
Computers 2026, 15(8), 504; https://doi.org/10.3390/computers15080504 - 5 Aug 2026
Viewed by 312
Abstract
Android malware detection systems commonly emphasize predictive accuracy while paying less attention to feature-acquisition cost, deployment efficiency, and early decision making. This paper presents a staged model-input budget framework for cost-aware Android malware screening and evaluates classification performance under progressively expanded static feature [...] Read more.
Android malware detection systems commonly emphasize predictive accuracy while paying less attention to feature-acquisition cost, deployment efficiency, and early decision making. This paper presents a staged model-input budget framework for cost-aware Android malware screening and evaluates classification performance under progressively expanded static feature representations. The proposed framework uses a lightweight Behaviour Score as an early-warning model input derived from multiple static behavioural indicators, including permission risk, encryption evidence, network activity, and suspicious keyword evidence. Rather than treating the score as a cost-free feature, the framework distinguishes between the derived model input and the underlying static indicators required to construct it. Uncertain samples are progressively escalated from the early-warning stage to richer feature budgets using a confidence-based decision rule, while confident samples can be resolved before full-feature analysis. The experimental evaluation reports hyperparameter-tuned model performance, empirical inference-time profiling, confidence-based escalation behaviour, Matthews correlation coefficient, false positive rate analysis, low false-positive-rate operating points, cross-validation, statistical testing, and external proxy-budget validation using the Drebin benchmark. On the main Android application dataset, the Behaviour-Score stage achieved an F1-score of 0.8750. When low-cost static indicators were added, the framework achieved an F1-score of 0.9654 and a Matthews correlation coefficient of 0.9267. The full feature set achieved the highest F1-score of 0.9878 and Matthews correlation coefficient of 0.9741. The confidence-based escalation experiment showed that, at a predefined 0.95 confidence operating point, 90.32% of samples were resolved before full-feature analysis, reducing the average number of classifier model inputs used from 9 to 3.50 while maintaining an F1-score of 0.9785. These findings indicate that the proposed framework provides an incremental model-input budget approach for deployment-oriented Android malware screening, while preserving full analysis for uncertain samples. Full article
(This article belongs to the Topic Addressing Security Issues Related to Modern Software)
Show Figures

Graphical abstract

26 pages, 699 KB  
Article
Secure PUF-ASCON-Based Gateway-Assisted D2D Authentication for Resource-Constrained Smart-Manufacturing IIoT Devices
by Alanoud Subahi
Mathematics 2026, 14(15), 2800; https://doi.org/10.3390/math14152800 - 4 Aug 2026
Viewed by 251
Abstract
Smart-manufacturing Industrial Internet of Things (IIoT) deployments increasingly depend on low-latency device-to-device (D2D) communication among resource-constrained, physically exposed field devices. This setting makes mutual authentication and session-key establishment difficult: public-key-intensive or cloud-dependent schemes add overhead, availability dependence, and single points of failure, while [...] Read more.
Smart-manufacturing Industrial Internet of Things (IIoT) deployments increasingly depend on low-latency device-to-device (D2D) communication among resource-constrained, physically exposed field devices. This setting makes mutual authentication and session-key establishment difficult: public-key-intensive or cloud-dependent schemes add overhead, availability dependence, and single points of failure, while weak PUF-based designs may expose challenge-response pairs (CRPs) to replay, disclosure, and modeling attacks. This paper proposes PASMAP, a lightweight PUF-ASCON mutual authentication protocol for gateway-assisted D2D communication in smart-manufacturing IIoT. PASMAP combines SRAM-PUF key reconstruction, fuzzy-extractor helper data, hash- and XOR-based obfuscation, and ASCON authenticated encryption with associated data (AEAD) to protect hardware-rooted identities, hide raw PUF responses, and establish fresh session keys for post-authentication data exchange under an explicitly trusted local-gateway model. The protocol is evaluated against physical, protocol-level, and insider threats, including cloning, tampering, replay, man-in-the-middle, CRP disclosure, PUF modeling, stolen-verifier, and known-key attacks. A real-or-random (ROR) analysis bounds the adversary’s session-key advantage using hash collisions, PUF-response prediction, online guessing, and ASCON AEAD security. A mixed-platform evaluation based on ESP32 primitive timings for the edge devices and desktop timings for the resource-rich gateway yields an estimated total computation cost of 4.762 ms. The initiator and responder require 2.006 ms/264.79 μJ and 2.679 ms/353.63 μJ of computational energy, respectively, while the five-message exchange carries 4704 bits. These results indicate low computational overhead under the stated benchmark and power-model assumptions. However, the protocol totals are operation-count-based estimates, the PUF and fuzzy-extractor operations are simulated, and the energy model excludes several platform- and communication-dependent costs. A complete embedded implementation is therefore required to validate end-to-end latency, memory use, energy consumption, communication-stack overhead, SRAM-PUF reliability, and fuzzy-extractor performance. Full article
(This article belongs to the Special Issue Cryptography, Data Security, and Cloud Computing)
Show Figures

Figure 1

14 pages, 1019 KB  
Article
A Conceptual Reference Architecture for Robust, Leakage-Resilient and Verifiable Access Control in Secure IoT Outsourcing
by Siddig M. Elkhider
Sensors 2026, 26(15), 4878; https://doi.org/10.3390/s26154878 - 2 Aug 2026
Viewed by 372
Abstract
Outsourcing Internet-of-Things (IoT) data and computation to cloud and fog infrastructure exposes both the data and the access-control process to integrity, confidentiality, and privacy risks. Attribute-based encryption (ABE) provides fine-grained access control but, as deployed today, suffers from single-authority bottlenecks, expensive policy updates, [...] Read more.
Outsourcing Internet-of-Things (IoT) data and computation to cloud and fog infrastructure exposes both the data and the access-control process to integrity, confidentiality, and privacy risks. Attribute-based encryption (ABE) provides fine-grained access control but, as deployed today, suffers from single-authority bottlenecks, expensive policy updates, weak auditability, and exposure to secret-key leakage, classical primitives are additionally threatened by future quantum adversaries. This paper does not propose a new cryptographic scheme. Instead, it contributes a conceptual reference architecture that systematizes how a set of existing, standardized primitives can be composed into a single access-control framework for IoT outsourcing, and it makes the resulting design precise enough to reason about. Concretely, we (i) define a system model and a threat model covering passive, active, colluding, bounded-leakage, and harvest-now-decrypt-later quantum adversaries; (ii) instantiate each layer with a named construction decentralized multi-authority ABE, attribute-based proxy re-encryption for policy updates, a bounded leakage resilient key model, ASCON lightweight AEAD, and ML-KEM/ML-DSA post-quantum primitives, together with a permissioned, on-chain digest/off-chain payload logging layer; (iii) specify the end-to-end data flow and module interfaces; and (iv) give a goal-by-goal security rationale and an analytical evaluation based only on standardized parameter sizes and asymptotic complexity. We are explicit about what is inherited from prior work, what remains to be proven for the composed system, and that a measured prototype evaluation remains future work. The intended value of this paper is to provide a clear, composable, and honestly scoped design that subsequent implementation studies can build upon. Full article
(This article belongs to the Special Issue Cyber Security and Privacy in Internet of Things (IoT))
Show Figures

Figure 1

Back to TopTop