Sign in to use this feature.

Years

Between: -

Subjects

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Journals

Article Types

Countries / Regions

Search Results (64)

Search Parameters:
Keywords = proxy re-encryption

Order results
Result details
Results per page
Select all
Export citation of selected articles as:
14 pages, 1019 KB  
Article
A Conceptual Reference Architecture for Robust, Leakage-Resilient and Verifiable Access Control in Secure IoT Outsourcing
by Siddig M. Elkhider
Sensors 2026, 26(15), 4878; https://doi.org/10.3390/s26154878 - 2 Aug 2026
Viewed by 300
Abstract
Outsourcing Internet-of-Things (IoT) data and computation to cloud and fog infrastructure exposes both the data and the access-control process to integrity, confidentiality, and privacy risks. Attribute-based encryption (ABE) provides fine-grained access control but, as deployed today, suffers from single-authority bottlenecks, expensive policy updates, [...] Read more.
Outsourcing Internet-of-Things (IoT) data and computation to cloud and fog infrastructure exposes both the data and the access-control process to integrity, confidentiality, and privacy risks. Attribute-based encryption (ABE) provides fine-grained access control but, as deployed today, suffers from single-authority bottlenecks, expensive policy updates, weak auditability, and exposure to secret-key leakage, classical primitives are additionally threatened by future quantum adversaries. This paper does not propose a new cryptographic scheme. Instead, it contributes a conceptual reference architecture that systematizes how a set of existing, standardized primitives can be composed into a single access-control framework for IoT outsourcing, and it makes the resulting design precise enough to reason about. Concretely, we (i) define a system model and a threat model covering passive, active, colluding, bounded-leakage, and harvest-now-decrypt-later quantum adversaries; (ii) instantiate each layer with a named construction decentralized multi-authority ABE, attribute-based proxy re-encryption for policy updates, a bounded leakage resilient key model, ASCON lightweight AEAD, and ML-KEM/ML-DSA post-quantum primitives, together with a permissioned, on-chain digest/off-chain payload logging layer; (iii) specify the end-to-end data flow and module interfaces; and (iv) give a goal-by-goal security rationale and an analytical evaluation based only on standardized parameter sizes and asymptotic complexity. We are explicit about what is inherited from prior work, what remains to be proven for the composed system, and that a measured prototype evaluation remains future work. The intended value of this paper is to provide a clear, composable, and honestly scoped design that subsequent implementation studies can build upon. Full article
(This article belongs to the Special Issue Cyber Security and Privacy in Internet of Things (IoT))
Show Figures

Figure 1

20 pages, 1849 KB  
Article
Cross-Domain Data Sharing Scheme Based on Threshold Proxy Re-Encryption
by Bingtao Wu, Qiuling Yue, Jie Zhu and Sidi Jiang
Information 2026, 17(4), 330; https://doi.org/10.3390/info17040330 - 31 Mar 2026
Viewed by 631
Abstract
Cross-domain data exchange is an important technical approach for realizing the value of data assets. However, lacking a single trusted root CA across domains, cross-domain schemes often encounter difficulties in authentication, controlled data flow, and fine-grained authorization. We propose a cross-domain data sharing [...] Read more.
Cross-domain data exchange is an important technical approach for realizing the value of data assets. However, lacking a single trusted root CA across domains, cross-domain schemes often encounter difficulties in authentication, controlled data flow, and fine-grained authorization. We propose a cross-domain data sharing scheme that uses decentralized identifiers and threshold proxy re-encryption. This scheme adopts the intra-domain leader node to verify the user identity, and the inter-domain multi-agent nodes collaborate in a threshold manner to handle cross-domain registration requests and re-encryption requests. Through threshold cooperation, the problem of single point of failure is effectively solved. The hash value of cross-domain registration information is stored on the blockchain, leveraging the immutable and traceable characteristics of blockchain to achieve trusted cross-domain data sharing. In addition, we introduce a ciphertext version tag to enable fast updates of re-encryption keys and use zero-knowledge proofs to verify re-encrypted ciphertext correctness. The security analysis indicates that our scheme has IND-CCA2 security under the DBDH assumption and can effectively resist collusion attacks. Performance analysis shows that our scheme is efficient, and can better meet the needs of cross-domain data sharing. Full article
(This article belongs to the Section Information Security and Privacy)
Show Figures

Graphical abstract

33 pages, 6232 KB  
Article
Access Control Development Within the Framework of an IOTA-Based Electronic Medical Record Management System
by Hari Purnama, I Putu Bakta Hari Sudewa, Tazkia Nizami, Bagas Sambega Rosyada, Pradipta Rafa Mahesa and Nur Ahmadi
Sensors 2026, 26(5), 1422; https://doi.org/10.3390/s26051422 - 24 Feb 2026
Cited by 1 | Viewed by 1204
Abstract
Electronic Medical Records (EMRs) are mandatory in Indonesia following the Ministry of Health regulation, which raises significant challenges in data security and patient-centric access control. Current implementations rely on centralized healthcare systems or third-party vendors, creating risks of unauthorized access, data leakage, and [...] Read more.
Electronic Medical Records (EMRs) are mandatory in Indonesia following the Ministry of Health regulation, which raises significant challenges in data security and patient-centric access control. Current implementations rely on centralized healthcare systems or third-party vendors, creating risks of unauthorized access, data leakage, and uncertain data integrity. To address these issues, this study proposes DecMed, a decentralized EMR management framework built on IOTA Distributed Ledger Technology (DLT). DecMed integrates Capability-Based Access Control (CapBAC), Proxy Re-Encryption (PRE), and the InterPlanetary File System (IPFS) to enforce patient ownership of medical data. Patients actively grant or revoke access, define access duration, and selectively share data with healthcare personnel. The system is implemented using smart contracts in the Move programming language on the IOTA ledger, while encrypted clinical data is stored on IPFS. Evaluation through unit testing of various unauthorized access scenarios demonstrates that DecMed effectively enforces fine-grained access rules, preserves data confidentiality and integrity, and ensures compliance with national healthcare requirements. Full article
(This article belongs to the Special Issue Securing E-Health Data Across IoMT and Wearable Sensor Networks)
Show Figures

Figure 1

32 pages, 8110 KB  
Article
A Secure and Efficient Sharing Framework for Student Electronic Academic Records: Integrating Zero-Knowledge Proof and Proxy Re-Encryption
by Xin Li, Minsheng Tan and Wenlong Tian
Future Internet 2026, 18(1), 47; https://doi.org/10.3390/fi18010047 - 12 Jan 2026
Cited by 1 | Viewed by 1103
Abstract
A sharing framework based on Zero-Knowledge Proof (ZKP) and Proxy Re-encryption (PRE) technologies offers a promising solution for sharing Student Electronic Academic Records (SEARs). As core credentials in the education sector, student records are characterized by strong identity binding, the need for long-term [...] Read more.
A sharing framework based on Zero-Knowledge Proof (ZKP) and Proxy Re-encryption (PRE) technologies offers a promising solution for sharing Student Electronic Academic Records (SEARs). As core credentials in the education sector, student records are characterized by strong identity binding, the need for long-term retention, frequent cross-institutional verification, and sensitive information. Compared with electronic health records and government archives, they face more complex security, privacy protection, and storage scalability challenges during sharing. These records not only contain sensitive data such as personal identity and academic performance but also serve as crucial evidence in key scenarios such as further education, employment, and professional title evaluation. Leakage or tampering could have irreversible impacts on a student’s career development. Furthermore, traditional blockchain technology faces storage capacity limitations when storing massive academic records, and existing general electronic record sharing solutions struggle to meet the high-frequency verification demands of educational authorities, universities, and employers for academic data. This study proposes a dedicated sharing framework for students’ electronic academic records, leveraging PRE technology and the distributed ledger characteristics of blockchain to ensure transparency and immutability during sharing. By integrating the InterPlanetary File System (IPFS) with Ethereum Smart Contract (SC), it addresses blockchain storage bottlenecks, enabling secure storage and efficient sharing of academic records. Relying on optimized ZKP technology, it supports verifying the authenticity and integrity of records without revealing sensitive content. Furthermore, the introduction of gate circuit merging, constant folding techniques, Field-Programmable Gate Array (FPGA) hardware acceleration, and the efficient Bulletproofs algorithm alleviates the high computational complexity of ZKP, significantly reducing proof generation time. The experimental results demonstrate that the framework, while ensuring strong privacy protection, can meet the cross-scenario sharing needs of student records and significantly improve sharing efficiency and security. Therefore, this method exhibits superior security and performance in privacy-preserving scenarios. This framework can be applied to scenarios such as cross-institutional academic certification, employer background checks, and long-term management of academic records by educational authorities, providing secure and efficient technical support for the sharing of electronic academic credentials in the digital education ecosystem. Full article
Show Figures

Graphical abstract

27 pages, 760 KB  
Article
OO-IB-MPRE: A Post-Quantum Secure Online/Offline Identity-Based Matchmaking Proxy Re-Encryption Scheme for Exercise Physiology Data
by You Zhao, Ye Song, Weiyi Song and Juyan Li
Mathematics 2025, 13(24), 4004; https://doi.org/10.3390/math13244004 - 16 Dec 2025
Cited by 1 | Viewed by 709
Abstract
As smart education evolves, there is an increasing need for the cloud-centric management and sharing of student exercise physiological data gathered through wearable devices in the physical education domain. However, challenges arise in achieving authentication for data sources, ensuring the security of sensitive [...] Read more.
As smart education evolves, there is an increasing need for the cloud-centric management and sharing of student exercise physiological data gathered through wearable devices in the physical education domain. However, challenges arise in achieving authentication for data sources, ensuring the security of sensitive data, and implementing efficient dynamic access control. Traditional cryptographic schemes face limitations in resisting quantum attacks, authenticating data sources, protecting identity privacy, handling dynamic permission changes, and computational efficiency. To tackle these challenges, we put forward a lattice-based Online/Offline Identity-Based Matchmaking Proxy Re-Encryption (OO-IB-MPRE) scheme. The scheme offers post-quantum security assurances grounded in lattice cryptography (under the LWE/ISIS assumptions); incorporates Identity-Based matchmaking encryption (IB-ME) to realize bidirectional identity matching, which not only enables identity authentication for data sources but also safeguards the sender’s identity privacy from exposure to other entities; leverages Proxy Re-Encryption (PRE) to support dynamic management of access control; and combines online/offline encryption to adapt to resource constrained sensors. The security of the OO-IB-MPRE scheme is verified under standard lattice assumptions to meet the security requirements of semi-selective privacy and authenticity. Performance analysis and experimental validation demonstrate that in comparison to existing lattice-based PRE schemes, the devised scheme shows notable advantages in both space and computational overhead. Therefore, the proposed OO-IB-MPRE offers a secure, efficient, and scalable solution for the sensitive health data in smart physical education. Full article
(This article belongs to the Special Issue Applications of Cryptography Theory in Network Security)
Show Figures

Figure 1

18 pages, 695 KB  
Article
Certificateless Proxy Re-Encryption Scheme for the Internet of Medical Things
by Han-Yu Lin, Ching-Wei Yeh and Chi-Shiu Chen
Electronics 2025, 14(23), 4654; https://doi.org/10.3390/electronics14234654 - 26 Nov 2025
Viewed by 677
Abstract
With the rapid development of the Internet of Medical Things (IoMT), the data generated and collected by various sensors and medical devices are gradually increasing. How to realize flexible, efficient, and secure data sharing while ensuring data confidentiality and patient privacy has become [...] Read more.
With the rapid development of the Internet of Medical Things (IoMT), the data generated and collected by various sensors and medical devices are gradually increasing. How to realize flexible, efficient, and secure data sharing while ensuring data confidentiality and patient privacy has become a critical research challenge. The traditional Public Key Infrastructure (PKI) must deal with the complicated certificate management problem. An identity-based cryptosystem has the inherent key-escrow risk. These concerns make them unsuitable for resource-constrained and dynamic IoMT environments. To address it, this paper introduces a cloud data sharing protocol for IoMT using a Certificateless Proxy Re-encryption (CL-PRE) scheme that integrates an efficient access-list-based user revocation mechanism. In our system, a patient’s data can be encrypted and securely stored in a semi-trusted third party like the cloud server. When the patient wants to grant the access to designated users, e.g., doctors or medical institutions, a delegated proxy server will re-encrypt the ciphertext to a new one, which is decryptable by the designators. The proxy server also learns nothing during the re-encryption process, so as to maintain the end-to-end confidentiality. As for the security, the authors formally prove that the proposed CL-PRE mechanism for IoMT achieves Type-I and Type-II indistinguishability against adaptive chosen-identity and chosen-ciphertext attacks (IND-PrID-CCA) under the Decisional Bilinear Diffie–Hellman (DBDH) assumption. Moreover, the functional and computational comparisons with previous studies reveal the qualitative advantage of simultaneously achieving certificateless properties and user revocation, and the quantitative advantage of an optimized encryption cost (requiring only one bilinear pairing and two scalar multiplications), making it a theoretically efficient solution for resource-constrained IoMT devices. Full article
(This article belongs to the Special Issue Security and Privacy Challenges in Integrated IoT and Edge Systems)
Show Figures

Figure 1

29 pages, 1003 KB  
Article
A Secure and Efficient KA-PRE Scheme for Data Transmission in Remote Data Management Environments
by JaeJeong Shin, Deok Gyu Lee, Daehee Seo, Wonbin Kim and Su-Hyun Kim
Electronics 2025, 14(21), 4339; https://doi.org/10.3390/electronics14214339 - 5 Nov 2025
Viewed by 914
Abstract
In recent years, remote data management environments have been increasingly deployed across diverse infrastructures, accompanied by a rapid surge in the demand for sharing and collaborative processing of sensitive data. Consequently, ensuring data security and privacy protection remains a fundamental challenge. A representative [...] Read more.
In recent years, remote data management environments have been increasingly deployed across diverse infrastructures, accompanied by a rapid surge in the demand for sharing and collaborative processing of sensitive data. Consequently, ensuring data security and privacy protection remains a fundamental challenge. A representative example of such an environment is the cloud, where efficient mechanisms for secure data sharing and access control are essential. In domains such as finance, healthcare, and public administration, where large volumes of sensitive information are processed by multiple participants, traditional access-control techniques often fail to satisfy the stringent security requirements. To address these limitations, Key-Aggregate Proxy Re-Encryption (KA-PRE) has emerged as a promising cryptographic primitive that simultaneously provides efficient key management and flexible authorization. However, existing KA-PRE constructions still suffer from several inherent security weaknesses, including aggregate-key leakage, ciphertext insertion and regeneration attacks, metadata exposure, and the lack of participant anonymity within the data-management framework. To overcome these limitations, this study systematically analyzes potential attack models in the KA-PRE setting and introduces a novel KA-PRE scheme designed to mitigate the identified vulnerabilities. Furthermore, through theoretical comparison with existing approaches and an evaluation of computational efficiency, the proposed scheme is shown to enhance security while maintaining practical performance and scalability. Full article
Show Figures

Figure 1

28 pages, 2443 KB  
Article
Blockchain for Secure IoT: A Review of Identity Management, Access Control, and Trust Mechanisms
by Behnam Khayer, Siamak Mirzaei, Hooman Alavizadeh and Ahmad Salehi Shahraki
IoT 2025, 6(4), 65; https://doi.org/10.3390/iot6040065 - 28 Oct 2025
Cited by 9 | Viewed by 5653
Abstract
Blockchain technologies offer transformative potential in terms of addressing the security, trust, and identity management issues that exist in large-scale Internet of Things (IoT) deployments. This narrative review provides a comprehensive survey of various studies, focusing on decentralized identity management, trust mechanisms, smart [...] Read more.
Blockchain technologies offer transformative potential in terms of addressing the security, trust, and identity management issues that exist in large-scale Internet of Things (IoT) deployments. This narrative review provides a comprehensive survey of various studies, focusing on decentralized identity management, trust mechanisms, smart contracts, privacy preservation, and real-world IoT applications. According to the literature, blockchain-based solutions provide robust authentication through mechanisms such as Physical Unclonable Functions (PUFs), enhance transparency via smart contract-enabled reputation systems, and significantly mitigate vulnerabilities, including single points of failure and Sybil attacks. Smart contracts enable secure interactions by automating resource allocation, access control, and verification. Cryptographic tools, including zero-knowledge proofs (ZKPs), proxy re-encryption, and Merkle trees, further improve data privacy and device integrity. Despite these advantages, challenges persist in areas such as scalability, regulatory and compliance issues, privacy and security concerns, resource constraints, and interoperability. By reviewing the current state-of-the-art literature, this review emphasizes the importance of establishing standardized protocols, performance benchmarks, and robust regulatory frameworks to achieve scalable and secure blockchain-integrated IoT solutions, and provides emerging trends and future research directions for the integration of blockchain technology into the IoT ecosystem. Full article
(This article belongs to the Special Issue Blockchain-Based Trusted IoT)
Show Figures

Figure 1

39 pages, 938 KB  
Article
A Survey of Data Security Sharing
by Dexin Zhu, Zhiqiang Zhou, Yuanbo Li, Huanjie Zhang, Yang Chen, Zilong Zhao and Jun Zheng
Symmetry 2025, 17(8), 1259; https://doi.org/10.3390/sym17081259 - 7 Aug 2025
Cited by 6 | Viewed by 4912
Abstract
In the digital era, secure data sharing has become a core requirement for enabling cross-domain collaboration, cloud computing, and Internet of Things (IoT) applications, as well as a critical measure for safeguarding privacy and defending against malicious attacks. In light of the risks [...] Read more.
In the digital era, secure data sharing has become a core requirement for enabling cross-domain collaboration, cloud computing, and Internet of Things (IoT) applications, as well as a critical measure for safeguarding privacy and defending against malicious attacks. In light of the risks of data leakage and misuse in open environments, achieving efficient, controllable, and privacy-preserving data sharing has emerged as a key research focus. This paper first provides a systematic review of the prevailing secure data sharing technologies, including proxy re-encryption, searchable encryption, key agreement and distribution, and attribute-based encryption, summarizing their design principles and application features. Subsequently, game-theoretic modeling based on incentive theory is introduced to construct a strategic interaction framework between data owners and data users, aiming to analyze and optimize benefit allocation mechanisms. Furthermore, the paper explores the integration of game theory with secure sharing mechanisms to enhance the sustainability and stability of the data sharing ecosystem. Finally, it outlines the critical challenges currently faced in secure data sharing and discusses future research directions, offering theoretical insights and technical references for building a more comprehensive data sharing framework. Full article
(This article belongs to the Section A: Computer Science)
Show Figures

Figure 1

22 pages, 1156 KB  
Article
An Attribute-Based Proxy Re-Encryption Scheme Supporting Revocable Access Control
by Gangzheng Zhao, Weijie Tan and Changgen Peng
Electronics 2025, 14(15), 2988; https://doi.org/10.3390/electronics14152988 - 26 Jul 2025
Cited by 1 | Viewed by 2509
Abstract
In the deep integration process between digital infrastructure and new economic forms, structural imbalance between the evolution rate of cloud storage technology and the growth rate of data-sharing demands has caused systemic security vulnerabilities such as blurred data sovereignty boundaries and nonlinear surges [...] Read more.
In the deep integration process between digital infrastructure and new economic forms, structural imbalance between the evolution rate of cloud storage technology and the growth rate of data-sharing demands has caused systemic security vulnerabilities such as blurred data sovereignty boundaries and nonlinear surges in privacy leakage risks. Existing academic research indicates current proxy re-encryption schemes remain insufficient for cloud access control scenarios characterized by diversified user requirements and personalized permission management, thus failing to fulfill the security needs of emerging computing paradigms. To resolve these issues, a revocable attribute-based proxy re-encryption scheme supporting policy-hiding is proposed. Data owners encrypt data and upload it to the blockchain while concealing attribute values within attribute-based encryption access policies, effectively preventing sensitive information leaks and achieving fine-grained secure data sharing. Simultaneously, proxy re-encryption technology enables verifiable outsourcing of complex computations. Furthermore, the SM3 (SM3 Cryptographic Hash Algorithm) hash function is embedded in user private key generation, and key updates are executed using fresh random factors to revoke malicious users. Ultimately, the scheme proves indistinguishability under chosen-plaintext attacks for specific access structures in the standard model. Experimental simulations confirm that compared with existing schemes, this solution delivers higher execution efficiency in both encryption/decryption and revocation phases. Full article
(This article belongs to the Topic Recent Advances in Security, Privacy, and Trust)
Show Figures

Figure 1

25 pages, 1047 KB  
Article
Integrated Blockchain and Federated Learning for Robust Security in Internet of Vehicles Networks
by Zhikai He, Rui Xu, Binyu Wang, Qisong Meng, Qiang Tang, Li Shen, Zhen Tian and Jianyu Duan
Symmetry 2025, 17(7), 1168; https://doi.org/10.3390/sym17071168 - 21 Jul 2025
Cited by 9 | Viewed by 3267
Abstract
The Internet of Vehicles (IoV) operates in an environment characterized by asymmetric security threats, where centralized vulnerabilities create a critical imbalance that can be disproportionately exploited by attackers. This study addresses this imbalance by proposing a symmetrical security framework that integrates Blockchain and [...] Read more.
The Internet of Vehicles (IoV) operates in an environment characterized by asymmetric security threats, where centralized vulnerabilities create a critical imbalance that can be disproportionately exploited by attackers. This study addresses this imbalance by proposing a symmetrical security framework that integrates Blockchain and Federated Learning (FL) to restore equilibrium in the Vehicle–Road–Cloud ecosystem. The evolution toward sixth-generation (6G) technologies amplifies both the potential of vehicle-to-everything (V2X) communications and its inherent security risks. The proposed framework achieves a delicate balance between robust security and operational efficiency. By leveraging blockchain’s symmetrical and decentralized distribution of trust, the framework ensures data and model integrity. Concurrently, the privacy-preserving approach of FL balances the need for collaborative intelligence with the imperative of safeguarding sensitive vehicle data. A novel Cloud Proxy Re-Encryption Offloading (CPRE-IoV) algorithm is introduced to facilitate efficient model updates. The architecture employs a partitioned blockchain and a smart contract-driven FL pipeline to symmetrically neutralize threats from malicious nodes. Finally, extensive simulations validate the framework’s effectiveness in establishing a resilient and symmetrically secure foundation for next-generation IoV networks. Full article
(This article belongs to the Section A: Computer Science)
Show Figures

Figure 1

18 pages, 809 KB  
Article
Identity-Based Broadcast Proxy Re-Encryption with Dynamic Functionality for Flexible Data Sharing in Cloud Environments
by Huidan Hu, Huasong Jin and Changlu Lin
Symmetry 2025, 17(7), 1008; https://doi.org/10.3390/sym17071008 - 26 Jun 2025
Cited by 1 | Viewed by 1586
Abstract
Cloud computing has witnessed widespread adoption across numerous sectors, primarily due to its substantial storage capacity and powerful computational resources. In this context, secure data sharing in cloud environments is critically important. Identity-based broadcast proxy re-encryption (IB-BPRE) has emerged as a promising solution; [...] Read more.
Cloud computing has witnessed widespread adoption across numerous sectors, primarily due to its substantial storage capacity and powerful computational resources. In this context, secure data sharing in cloud environments is critically important. Identity-based broadcast proxy re-encryption (IB-BPRE) has emerged as a promising solution; however, existing IB-BPRE schemes lack dynamic functionality—specifically, the ability to support user revocation and addition without updating re-encryption keys. Consequently, data owners must frequently reset and distribute these keys in response to user membership changes, leading to increased system complexity and communication overhead. In this paper, we propose an identity-based broadcast proxy re-encryption scheme with dynamic functionality (IB-BPRE-DF) to address this challenge. The proposed scheme utilizes a symmetric design of re-encryption keys to enable dynamic user updates while preserving a constant re-encryption key size. Furthermore, IB-BPRE-DF is constructed under the (f,g,F)-GDDHE assumption and achieves semantic security in the random oracle model. Performance evaluations demonstrate that IB-BPRE-DF significantly reduces both the communication overhead (by maintaining a constant size for the re-encryption key and re-encrypted ciphertext) and the computational burden (with near-zero computational cost for generating the re-encryption key) for resource-constrained users. This work provides a practical and scalable cryptographic solution for secure and efficient data sharing in dynamic cloud environments. Full article
(This article belongs to the Section A: Computer Science)
Show Figures

Figure 1

25 pages, 980 KB  
Article
Optimized Space-Filling Curve-Driven Forward-Secure Range Query on Location-Related Data for Unmanned Aerial Vehicle Networks
by Zhen Lv, Xin Li, Yanguo Peng and Jin Huang
Electronics 2025, 14(10), 1978; https://doi.org/10.3390/electronics14101978 - 13 May 2025
Cited by 1 | Viewed by 1119
Abstract
Unmanned aerial vehicle networks (UAVNs) are widely used to collect various location-related data, with applications ranging from military reconnaissance to the low-altitude economy. Data security and privacy are critical concerns when outsourcing location-related data to a public cloud. To alleviate these concerns, location-related [...] Read more.
Unmanned aerial vehicle networks (UAVNs) are widely used to collect various location-related data, with applications ranging from military reconnaissance to the low-altitude economy. Data security and privacy are critical concerns when outsourcing location-related data to a public cloud. To alleviate these concerns, location-related data are encrypted before outsourcing to the public cloud. However, encryption decreases the operability of the outsourced encrypted data; thus, unmanned aerial vehicles cannot operate on the encrypted data directly. Among operations on encrypted location-related data, the forward-secure range query is one of the most fundamental operations. In this paper, we present a forward-secure range query based on spatial division to achieve a highly efficient range query on encrypted location-related data while preserving both data security and privacy. Specifically, various space-filling curves were experimentally investigated for both the range query and the k-nearest-neighbor query. Then, a forward-secure range query (namely, OSFC-FSQ) was constructed on an encrypted dual dictionary. The proposed scheme was evaluated on real-world datasets, and the results show that it outperforms state-of-the-art schemes in terms of accuracy and query time in the cloud. Full article
(This article belongs to the Special Issue Unmanned Aerial Vehicles (UAVs) Communication and Networking)
Show Figures

Figure 1

22 pages, 1400 KB  
Article
Research on Data Ownership and Controllable Sharing Schemes in the Process of Logistics Data Flow
by Ziqi Liu, Zhanling Shi, Wenjing Wang, Rui Kong, Deqian Fu and Jianlong Qiu
Electronics 2025, 14(9), 1714; https://doi.org/10.3390/electronics14091714 - 23 Apr 2025
Cited by 1 | Viewed by 1457
Abstract
The secure and effective dissemination of logistics data is frequently obstructed by issues pertaining to ownership verification and unwanted access during data exchange. This study introduces an innovative strategy for data ownership verification and regulated sharing based on the notion of “three rights [...] Read more.
The secure and effective dissemination of logistics data is frequently obstructed by issues pertaining to ownership verification and unwanted access during data exchange. This study introduces an innovative strategy for data ownership verification and regulated sharing based on the notion of “three rights separation”, which delineates data ownership into control rights, usage rights, and management rights. The proposed approach incorporates chameleon signatures and blockchain technology to facilitate dynamic, non-falsifiable ownership marking and verification. Additionally, it utilizes searchable encryption and proxy re-encryption methods to guarantee that data are viewed solely under allowed circumstances, thereby averting misuse by third-party data administrators. Security analysis verifies resilience against adaptive chosen-message assaults and keyword-guessing threats, while simulation studies illustrate the scheme’s robustness, efficiency, and practical applicability in real-world logistical settings. This framework offers a scalable and safe solution for multi-party data sharing with explicitly defined ownership control. Full article
(This article belongs to the Special Issue Recent Advances in Cybersecurity and Information Security)
Show Figures

Figure 1

17 pages, 1688 KB  
Article
Privacy-Preserving Multi-User Graph Intersection Scheme for Wireless Communications in Cloud-Assisted Internet of Things
by Shumei Yang
Sensors 2025, 25(6), 1892; https://doi.org/10.3390/s25061892 - 18 Mar 2025
Cited by 1 | Viewed by 1299
Abstract
Cloud-assisted Internet of Things (IoT) has become the core infrastructure of smart society since it solves the computational power, storage, and collaboration bottlenecks of traditional IoT through resource decoupling and capability complementarity. The development of a graph database and cloud-assisted IoT promotes the [...] Read more.
Cloud-assisted Internet of Things (IoT) has become the core infrastructure of smart society since it solves the computational power, storage, and collaboration bottlenecks of traditional IoT through resource decoupling and capability complementarity. The development of a graph database and cloud-assisted IoT promotes the research of privacy preserving graph computation. We propose a secure graph intersection scheme that supports multi-user intersection queries in cloud-assisted IoT in this article. The existing work on graph encryption for intersection queries is designed for a single user, which will bring high computational and communication costs for data owners, or cause the risk of secret key leaking if directly applied to multi-user scenarios. To solve these problems, we employ the proxy re-encryption (PRE) that transforms the encrypted graph data with a re-encryption key to enable the graph intersection results to be decrypted by an authorized IoT user using their own private key, while data owners only encrypt their graph data on IoT devices once. In our scheme, different IoT users can query for the intersection of graphs flexibly, while data owners do not need to perform encryption operations every time an IoT user makes a query. Theoretical analysis and simulation results demonstrate that the graph intersection scheme in this paper is secure and practical. Full article
Show Figures

Figure 1

Back to TopTop