Sign in to use this feature.

Years

Between: -

Subjects

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Journals

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Article Types

Countries / Regions

remove_circle_outline
remove_circle_outline
remove_circle_outline

Search Results (140)

Search Parameters:
Keywords = unlinkability

Order results
Result details
Results per page
Select all
Export citation of selected articles as:
21 pages, 4086 KB  
Article
Protecting Facial Biometric Templates with Threshold Secret Sharing: A Comparative Resource-Aware Study of a Non-Positional Polynomial Scheme and a Multivariable Verification Scheme
by Nursulu Kapalova and Nursultan Yergesh
Computers 2026, 15(9), 604; https://doi.org/10.3390/computers15090604 - 10 Sep 2026
Viewed by 155
Abstract
Facial biometric templates are permanent identifiers: once exposed, the underlying identity cannot be reissued, so single-copy storage is a critical single point of failure. This study protects facial templates by combining a non-invertible BioHashing transform and authenticated encryption with a threshold secret-sharing layer [...] Read more.
Facial biometric templates are permanent identifiers: once exposed, the underlying identity cannot be reissued, so single-copy storage is a critical single point of failure. This study protects facial templates by combining a non-invertible BioHashing transform and authenticated encryption with a threshold secret-sharing layer that distributes the protected record across independent storage nodes and reconstructs it only when a quorum of shares is collected. Two threshold schemes, previously proposed by our group for fingerprint and for general confidential data, are, for the first time, applied to facial templates and compared on a common platform as a resource-aware architecture: a non-positional polynomial notation scheme with the Chinese remainder theorem, and a verifiable multivariable-function scheme. Both reconstruct the template exactly and, across 2000 trials per attack, resist or detect every attack in our evaluation (for example, malicious-share tampering is detected in 100% of 2000 trials and stolen-token recovery succeeds in 0 of 2000), whereas a single read breach of one-copy storage discloses the template in full. Below the threshold they differ: the polynomial scheme is a compact, deterministic ramp scheme for edge and Internet-of-Things nodes that discloses only ciphertext bytes and, under separate key and token storage, neither the biometric nor the key; the multivariable scheme adds native share verification and, in its randomized single-secret mode, provides information-theoretic perfect secrecy for a single high-value secret, while for the packed record it is a verified ramp. Rather than ranking the schemes, we quantify this trade-off. Because the protection layer is lossless, recognition accuracy is inherited unchanged from the face encoder; on the LFW verification protocol, the complete pipeline attains an equal error rate of 2.12% ± 0.57% (95% CI [1.77%, 2.47%]) against a per-fold raw-embedding cosine baseline of 1.37% ± 0.62%. Full article
Show Figures

Graphical abstract

35 pages, 595 KB  
Article
Privacy-Preserving Health Insurance Eligibility Verification on Blockchain Using zk-SNARKs
by Warit Werapun and Warodom Werapun
Cryptography 2026, 10(5), 66; https://doi.org/10.3390/cryptography10050066 - 9 Sep 2026
Viewed by 174
Abstract
Verifying a patient’s eligibility for insurance reimbursement typically requires disclosing sensitive clinical data—diagnosis codes, laboratory values, and policy details—to third parties, conflicting with the data-minimization principle of modern data-protection regimes. Blockchain platforms improve auditability but, when health records are placed on-chain, amplify the [...] Read more.
Verifying a patient’s eligibility for insurance reimbursement typically requires disclosing sensitive clinical data—diagnosis codes, laboratory values, and policy details—to third parties, conflicting with the data-minimization principle of modern data-protection regimes. Blockchain platforms improve auditability but, when health records are placed on-chain, amplify the privacy problem. This paper presents a zero-knowledge framework in which a patient proves that an authority-signed health record satisfies a set of policy predicates—a covered diagnosis, a laboratory value within an approved range, and a claim amount within the policy ceiling—without revealing the underlying values. Records are committed to an on-chain Merkle registry, and a record-bound nullifier prevents double claims without linking a claim to the patient. We state the NP relation proved by the circuit and reduce claim soundness, claim unlinkability, and front-running resistance to the knowledge soundness and zero-knowledge of the argument, the collision resistance of the hash, and the unforgeability of the signature scheme. A circom and snarkjs prototype with a Solidity verifier compiles to 10,050 R1CS constraints, of which the eligibility predicates contribute only 2.1%, and produces a constant 256-byte proof verified on-chain by a fixed four-pair check. On-chain cost scales with the number of public inputs rather than circuit size, and we identify the attack surface such designs commonly leave open—proof front-running, issuer-side linkability, and anonymity-set size, which the registry population bounds rather than tree depth. Full article
(This article belongs to the Section Blockchain Security)
Show Figures

Figure 1

28 pages, 10719 KB  
Article
HRCred: Revocation-Consistent Hardware-Rooted Credentials for Cross-Domain Industrial Cyber–Physical Systems
by Haozhe Zhou, Hang Lei and Maolin Yang
Electronics 2026, 15(17), 4004; https://doi.org/10.3390/electronics15174004 - 4 Sep 2026
Viewed by 257
Abstract
Mobile industrial devices increasingly cross administrative domains. A maintenance terminal certified in one factory can be dispatched to another, while autonomous vehicles cross fog domains while reaching cloud digital twins. Existing solutions force a trade-off. Long-lived certificates expose a stable identity that every [...] Read more.
Mobile industrial devices increasingly cross administrative domains. A maintenance terminal certified in one factory can be dispatched to another, while autonomous vehicles cross fog domains while reaching cloud digital twins. Existing solutions force a trade-off. Long-lived certificates expose a stable identity that every visited domain can track and that is clonable once a device is captured, while single-gateway token services concentrate issuing power in one trusted node and asynchronous revocation leaves an unquantified window in which a revoked device is still accepted. Here, we present HRCred, which converts hardware identities rooted in physical unclonable functions (PUFs) into domain-bound, epoch-bound, and threshold-issued short-lived pseudonymous credentials. A device proves possession of its reconstructed root key to its home domain using only symmetric primitives. A set of fog issuers jointly signs each credential with a t-of-n threshold BLS signature, so no coalition of fewer than t issuers can mint one. Finally, a monotonic revocation-epoch mechanism yields a configurable upper bound on how long a revoked credential can still be accepted, which we prove and validate. On constrained hardware, the device side costs 3.6 mJ (18.8 ms authentication and 5.4 ms verification, on par with the lightest single-gateway token) while resisting up to t1 compromised issuers, cutting cross-domain linkage AUC to 0.55, and keeping all 12,000 measured post-revocation acceptances below the analytical bound. Full article
(This article belongs to the Special Issue Advanced and Intelligent Industrial IoT Systems for Industry 5.0)
Show Figures

Figure 1

30 pages, 1343 KB  
Article
A Lattice-Based Hierarchical Identity Authentication Scheme for Low-Voltage Metering Devices in Power Grids
by Xinhong Li, Haibo Pen, Hao Xiao, Zhishuang Wang, Chao Pang and Jiancheng Yu
Appl. Sci. 2026, 16(16), 8199; https://doi.org/10.3390/app16168199 - 17 Aug 2026
Viewed by 731
Abstract
The identity security of massive metering terminals in low-voltage power distribution systems is a foundational requirement for smart grids. These devices, deployed in physically exposed user-side environments, face threats of identity impersonation, data tampering, and future quantum attacks. Conventional public-key certificates and pre-shared [...] Read more.
The identity security of massive metering terminals in low-voltage power distribution systems is a foundational requirement for smart grids. These devices, deployed in physically exposed user-side environments, face threats of identity impersonation, data tampering, and future quantum attacks. Conventional public-key certificates and pre-shared key schemes lack quantum resistance and scalability, respectively, while existing post-quantum solutions do not address the combination of hierarchical key management and batch authentication that power metering at scale demands. This paper proposes a lattice-based hierarchical identity authentication method that maps the three-tier power system architecture onto a three-level key derivation chain of hierarchical identity-based signatures, compresses multiple terminal lattice signatures into a compact aggregate verifiable in a single equation, and embeds key agreement into the authentication flow so that terminals and the substation derive independent session keys without extra round trips. A prototype was implemented and tested across multiple security levels. The signature communication volume remained quasi-constant as the terminal count increased, reducing the signature transmission delay on narrowband PLC links. All terminals successfully established independent session keys with exact agreement between both sides. Security reduces to the average-case hardness of the small integer solution problem on lattices, satisfying mutual authentication, conditional anonymity, and unlinkability. The proposed scheme trades higher signing latency for security based on quantum-hard lattice assumptions, group batch authentication, and protocol integration, offering a viable pathway for identity security upgrades in power metering systems during the quantum migration window. Full article
(This article belongs to the Special Issue Cybersecurity and Privacy Under the IoT Era)
Show Figures

Figure 1

28 pages, 2584 KB  
Article
An Efficient Privacy-Preserving Batch Authentication Scheme in Fog-Enabled VANETs
by Cong Zhao, Xuan Ge, Yikang Yang, Qinglei Qi and He Li
Future Internet 2026, 18(8), 404; https://doi.org/10.3390/fi18080404 - 30 Jul 2026
Viewed by 305
Abstract
Vehicular ad hoc networks (VANETs), as a key communication component of the Internet of Vehicles (IoV), enable vehicles and roadside infrastructure to exchange information efficiently, thereby supporting road safety and traffic management. However, because these communications take place over open wireless channels, VANETs [...] Read more.
Vehicular ad hoc networks (VANETs), as a key communication component of the Internet of Vehicles (IoV), enable vehicles and roadside infrastructure to exchange information efficiently, thereby supporting road safety and traffic management. However, because these communications take place over open wireless channels, VANETs are exposed to message forgery, replay, identity disclosure, and unauthorised access by revoked vehicles. To address these issues, this paper proposes EPAF, an efficient privacy-preserving batch authentication scheme with revocation support for fog-enabled VANETs. EPAF uses roadside fog nodes to distribute update keys and report information related to misbehaving vehicles, thereby reducing reliance on remote centralised processing. Rather than assuming ideal tamper-proof devices that store system-wide secrets, EPAF requires protected storage only for vehicle-local certificates, limiting the impact of compromising an individual vehicle device. The scheme employs batch verification to authenticate multiple messages from different vehicles in a single procedure, reducing verification overhead in message-intensive traffic conditions. It further introduces an update-key mechanism through which legitimate vehicles obtain current authentication keys, whereas revoked vehicles are prevented from generating valid authentication messages in subsequent revocation periods. Under the honest-authority model, the security analysis establishes the EUF-CMA security of an authentication packet in the random-oracle model and separately addresses conditional identity privacy, traceability, and unlinkability across different pseudonym periods. Performance evaluation examines the trade-off among authentication efficiency, communication overhead, and revocation performance, showing that EPAF is a practical solution for fog-enabled vehicular communication. Full article
Show Figures

Figure 1

14 pages, 3346 KB  
Article
Genetic Investigations on the Sicilian Populations of Prunus mahaleb L. and Prunus cupaniana Guss ex E. Huet & A. Huet (Rosaceae): Implications for Conservation
by Claudia Mattioni, Salvatore Pasta, Marcello Cherubini, Luca Leonardi, Giuseppe Clementi, Emilio Badalamenti, Giuseppe Traina and Tommaso La Mantia
Diversity 2026, 18(7), 438; https://doi.org/10.3390/d18070438 - 21 Jul 2026
Viewed by 375
Abstract
Assessing genetic diversity of species and populations can help reduce the risk of biodiversity loss by identifying areas deserving the greatest attention in terms of conservation priority. Our study was focused on evaluating the genetic variability of Prunus mahaleb L. and Prunus cupaniana [...] Read more.
Assessing genetic diversity of species and populations can help reduce the risk of biodiversity loss by identifying areas deserving the greatest attention in terms of conservation priority. Our study was focused on evaluating the genetic variability of Prunus mahaleb L. and Prunus cupaniana Guss. ex E. Huet & A. Huet (Rosaceae), both of which are quite rare and unevenly distributed in Sicily (Italy). In this region, P. mahaleb occurs in scattered populations, mostly concentrated on the mountain ranges close to the northern Tyrrhenian coast, while P. cupaniana, which is endemic in Sicily, is known to occur only on Sicani Mountains and on the Madonie Massif. A total of 118 georeferenced individuals of P. mahaleb and P. cupaniana were sampled across eight different sites. The samples were genotyped using nine unlinked nSSr loci. A high percentage of clonal individuals was observed especially in P. cupaniana. Low intrapopulation diversity, as well as high divergence among populations were recorded. The analysis performed using STRUCTURE separated P. mahaleb and P. cupaniana into two different gene pools (K = 2) and revealed the complete absence of introgression between them. These results, if confirmed through further molecular analysis, indicate that these taxa should be considered as two distinct species. Moreover, more detailed analyses allowed us to distinguish four gene pools for P. mahaleb, while the extant populations of P. cupaniana could be grouped into two clusters suggesting their strong isolation and a very low, if any, absent gene flow between them. Our results underline the urgent need for interventions aimed at conserving and managing the genetic heritage of the Sicilian populations of both species. Full article
(This article belongs to the Section Plant Diversity)
Show Figures

Figure 1

32 pages, 545 KB  
Article
A Secure and Ultra-Lightweight Authentication Protocol for RFID Systems Using Epoch-Based Pseudonym Indexing
by Pierre E. Abi-Char, Mehdi Al Housseini and Mohammed Al-Husseini
Cryptography 2026, 10(4), 50; https://doi.org/10.3390/cryptography10040050 - 13 Jul 2026
Viewed by 630
Abstract
Mobile Radio Frequency Identification (RFID) systems are emerging as a fundamental part of modern smart environments, enabling automatic identification, tracking, and data exchange among different mobile platforms. While these systems are increasingly being adopted, they have a major drawback: an RFID tag has [...] Read more.
Mobile Radio Frequency Identification (RFID) systems are emerging as a fundamental part of modern smart environments, enabling automatic identification, tracking, and data exchange among different mobile platforms. While these systems are increasingly being adopted, they have a major drawback: an RFID tag has very little computational power, and the wireless communication channels can be attacked by adversaries. Several authentication and key management mechanisms to protect data and provide secure access have been proposed to solve these problems. In this study, we propose a new scheme that improves system security through explicit three-party mutual authentication, epoch-based pseudonym indexing for O(1) server lookup, and comprehensive resiliency against replay, impersonation, and man-in-the-middle attacks. An in-depth security analysis, along with performance evaluation, substantiates that the proposed protocol improves privacy and resilience without losing compatibility with low-cost RFID tags equipped only to perform lightweight cryptographic functions. This protocol also provides epoch-based unlinkability and is well suited for large-scale deployments, as found in healthcare, logistics, and Internet of Things (IoT) applications. Full article
(This article belongs to the Section Hardware Security)
Show Figures

Figure 1

25 pages, 1891 KB  
Review
Carbon and Electron Recovery in Integrated Biohydrogen Systems: A Critical Review of Dark Fermentation, Photo-Fermentation, and Microbial Electrolysis Cells
by Ravi Shankar Yadav and Ju-Hyeong Jung
Energies 2026, 19(13), 3152; https://doi.org/10.3390/en19133152 - 2 Jul 2026
Viewed by 454
Abstract
Hydrogen is increasingly recognized as a key energy carrier for decarbonizing hard-to-electrify sectors, yet more than 95% of current global production remains fossil-derived. Biological hydrogen (biohydrogen) produced by dark fermentation (DF), photo-fermentation (PF), or microbial electrolysis cells (MEC) offers the dual advantage of [...] Read more.
Hydrogen is increasingly recognized as a key energy carrier for decarbonizing hard-to-electrify sectors, yet more than 95% of current global production remains fossil-derived. Biological hydrogen (biohydrogen) produced by dark fermentation (DF), photo-fermentation (PF), or microbial electrolysis cells (MEC) offers the dual advantage of valorizing organic wastes while delivering low-carbon H2; however, none of these standalone technologies mobilizes more than 25–33% (DF), 40–70% (PF), or 40–60% (MEC) of feedstock organic carbon through H2-producing oxidation pathways. Most existing reviews compare these pathways on hydrogen yield alone, a metric that conceals where the majority of feedstock carbon and electrons are actually lost and obscures the quantitative rationale for system integration. This review reframes the comparison around carbon and electron flow, explicitly tracking how much input carbon is mobilized through H2-producing oxidation pathways, how much is retained in volatile fatty acids (VFAs), biomass, or unlinked CO2, and what happens to the associated electrons. Stoichiometric, mechanistic, and reactor-level evidence is synthesized to show that DF channels only 25–33% of input organic carbon through H2-yielding decarboxylation on real heterogeneous substrates, with 40–60% retained as residual VFAs and unhydrolyzed solids; PF can recover 60–80% of VFA carbon but is constrained by photon economics and nitrogenase sensitivity; and MEC achieves >85% COD removal only when coupled to an upstream acidogenic stage. Two-stage (DF–PF, DF–MEC) and three-stage (DF–PF–MEC, DF–MEC–AD) configurations are critically evaluated, with theoretical yields separated from experimentally demonstrated performance on real wastes and hidden energy inputs (pretreatment, inter-stage transfer, gas separation, and compression) explicitly accounted for. DF–MEC coupling is identified as the most near-term tractable configuration, achieving 55–70% H2-pathway carbon mobilization and 80–92% COD removal at an electrical input of 0.9–1.5 kWh/m3 H2, with levelized hydrogen costs of US$3–5.5/kg under favorable waste-tipping-fee conditions. Multi-stage systems push carbon recovery above 70% but carry unresolved capital, methanogenesis control, and scale-up penalties. This review closes by proposing a standardized ten-descriptor reporting framework including H2-pathway carbon mobilization (%), cathodic hydrogen recovery (rCAT), net energy recovery (NEB), and LCA carbon intensity under both attributional and consequential boundaries, and demonstrates its backward compatibility by retrospective application to seven studies already in the literature. Research priorities tractable on a 5–10 year horizon are identified, centered on methanogen suppression at pilot scale, real-waste MEC performance, and renewable-electricity coupling. Full article
(This article belongs to the Topic Advances in Biomass and Bioenergy)
Show Figures

Figure 1

26 pages, 522 KB  
Article
A Secure and Efficient ECC-Based User-to-User Authentication and Key Agreement Protocol for Smart Grid
by Yujin Nam, Hyewon Park and Yohan Park
Appl. Sci. 2026, 16(12), 6059; https://doi.org/10.3390/app16126059 - 15 Jun 2026
Viewed by 435
Abstract
Smart grid environments increasingly require secure user-to-user (U2U) communication for decentralized applications such as peer-to-peer energy trading and electric vehicle energy exchange. However, many existing authentication and key agreement schemes rely on centralized entities during authentication or provide insufficient protection against impersonation, insider, [...] Read more.
Smart grid environments increasingly require secure user-to-user (U2U) communication for decentralized applications such as peer-to-peer energy trading and electric vehicle energy exchange. However, many existing authentication and key agreement schemes rely on centralized entities during authentication or provide insufficient protection against impersonation, insider, and ephemeral secret leakage (ESL) attacks. To address these limitations, this paper proposes an Elliptic Curve Cryptography (ECC)-based secure U2U authentication and key agreement protocol for smart grid environments. The proposed protocol employs ECDH-based session key establishment and Schnorr verification to enable mutual authentication without directly exposing long-term credentials. In addition, the protocol provides user anonymity and unlinkability by using session-dependent identity protection mechanisms. Security analysis demonstrates that the proposed scheme can resist various attacks, including impersonation, replay, denial-of-service, privileged insider, stolen device, and ESL attacks. Furthermore, simulation-based comparative analysis shows that the proposed protocol achieves stronger security features than several existing schemes, although it incurs moderately higher computational and communication costs due to additional elliptic curve operations and verification parameters. Full article
(This article belongs to the Special Issue Power System Protection: Current and Future Perspectives)
Show Figures

Figure 1

44 pages, 2947 KB  
Article
RUIP-BA: Renewable, Unlinkable, and Irreversible Privacy-Preserving Behavioral Authentication via Random Projection and Local Differential Privacy
by Md Morshedul Islam, Khondokar Fida Hasan, Wali Mohammad Abdullah and Baidya Nath Saha
Electronics 2026, 15(11), 2287; https://doi.org/10.3390/electronics15112287 - 25 May 2026
Viewed by 429
Abstract
Behavioral authentication (BA) systems verify user identity claims based on unique behavioral characteristics using machine learning (ML)-based classifiers trained on user behavioral profiles. Although effective, ML-based BA systems face serious privacy threats, including profile inference and reconstruction attacks. This paper presents RUIP-BA (Renewable, [...] Read more.
Behavioral authentication (BA) systems verify user identity claims based on unique behavioral characteristics using machine learning (ML)-based classifiers trained on user behavioral profiles. Although effective, ML-based BA systems face serious privacy threats, including profile inference and reconstruction attacks. This paper presents RUIP-BA (Renewable, Unlinkable, and Irreversible Privacy-Preserving Behavioral Authentication), a non-cryptographic framework designed for settings where computational resources may be limited. Random Projection (RP) maps behavioral profiles into lower-dimensional protected templates while approximately preserving utility-relevant geometry, and local Differential Privacy (DP) injects calibrated stochastic perturbations to provide formal privacy protection. The proposed design jointly targets the ISO/IEC 24745 requirements of renewability, unlinkability, and irreversibility. We provide complete algorithmic realizations for enrollment, verification, template renewal, unlinkability testing, and GAN-based adversarial privacy evaluation. We also introduce rigorous formal privacy derivations and proofs under explicit assumptions, including formal security games, information-theoretic theorem-level guarantees, Cramér–Rao lower bounds for irreversibility, full Jensen–Shannon divergence derivations for unlinkability, and a GAN Nash-equilibrium attack bound. Comprehensive dimensionality ablation across all three modalities confirms robust utility at compact template sizes, and an expanded analysis of the privacy–utility trade-off under varying ϵ values is provided. Experiments on voice, swipe, and drawing datasets show authentication accuracy above 96% while sharply limiting feature recoverability under strong GAN-based attacks. All reported FAR/FRR figures are single-session best-case estimates; cross-session longitudinal evaluation remains future work. RUIP-BA provides a scalable, mathematically grounded, and deployment-ready privacy-preserving BA solution. Full article
(This article belongs to the Special Issue Secure and Privacy-Enhanced Data Sharing)
Show Figures

Figure 1

23 pages, 1341 KB  
Article
DPS: A Post-Quantum Proxy Signature Scheme from Dilithium for IoT Applications
by Yuteng Wang, Ruoyu Ding, Tianrun Yu, Zhen Han, Jian Weng and Jiasi Weng
Cryptography 2026, 10(3), 33; https://doi.org/10.3390/cryptography10030033 - 15 May 2026
Viewed by 974
Abstract
Proxy signatures enable the secure delegation of signing authority, which is particularly useful in resource-constrained Internet of Things (IoT) environments. However, most existing schemes rely on classical hardness assumptions and therefore cannot resist quantum attacks. To address the challenge, we propose a post-quantum [...] Read more.
Proxy signatures enable the secure delegation of signing authority, which is particularly useful in resource-constrained Internet of Things (IoT) environments. However, most existing schemes rely on classical hardness assumptions and therefore cannot resist quantum attacks. To address the challenge, we propose a post-quantum proxy signature scheme based on Dilithium for IoT scenarios. We first propose an asynchronous remote key generation (ARKG) scheme based on CRYSTALS-Kyber, enabling the delegator and proxy signer to generate proxy keys of Dilithium without real-time interaction. We further integrate ARKG with the Dilithium signature scheme to construct a proxy signature scheme called DPS while ensuring the unlinkability of proxy signatures. Additionally, our proposed DPS achieves post-quantum security and provides unforgeability, distinguishability, verifiability, and undeniability with formal proofs. Experimental performance evaluation shows that our scheme yields significant efficiency gains over existing quantum-safe proxy signature solutions, with 10× speedup for both the delegation and proxy signing phases, as well as a 2.4× improvement in the verification phase. Full article
(This article belongs to the Special Issue Advances in Post-Quantum Cryptography)
Show Figures

Figure 1

19 pages, 19027 KB  
Article
Affine–Covariant Mesh Instancing for Lightweight Large-Scale 3D Scenes
by Siyuan Sun, Lin Su, Xukun Yang, Chunyu Qi, Xinyu Liu and Licheng Pan
Geomatics 2026, 6(3), 51; https://doi.org/10.3390/geomatics6030051 - 14 May 2026
Viewed by 603
Abstract
Large-scale engineering of the 3D scenes used in BIM, GIS, digital twins, and geospatial web delivery frequently suffer from significant geometric redundancy after export to mesh-based delivery formats, arising in part from the inconsistent reuse of geometry, where many repetitive components are stored [...] Read more.
Large-scale engineering of the 3D scenes used in BIM, GIS, digital twins, and geospatial web delivery frequently suffer from significant geometric redundancy after export to mesh-based delivery formats, arising in part from the inconsistent reuse of geometry, where many repetitive components are stored as independent meshes rather than being fully instantiated. This paper proposes an affine–covariant mesh instancing framework designed to achieve a lightweight representation of watertight triangular solids. The core of the method lies in a canonicalization pipeline: each mesh is normalized via volume-centroid translation, principal-axis alignment derived from volume covariance, and anisotropic covariance whitening. This process effectively decouples the influence of translation, rotation, and non-uniform scaling, projecting diverse geometries into a unified canonical space. Within this space, geometric similarity is quantified by evaluating compact descriptors against user-defined tolerances. A greedy clustering strategy is then employed to group affine–similar models based on these descriptors. Finally, the scene is efficiently reconstructed by applying inverse affine transformations to the representative instance of each cluster. The output stores one shared geometry per cluster alongside per-instance 4×4 transform matrices, preserving the original spatial layout while reducing redundant geometry storage. Experiments on four real-world engineering scenes demonstrate varying compression benefits. The results prove particularly effective for scenes containing unlinked repetitive parts and affine–similar parametric components, while also revealing a controllable trade-off between fidelity and compression rate. The method is therefore suitable as a post-export geometry-lightweighting step in mesh-based BIM/GIS integration, infrastructure digital twins, and large-scale 3D mapping workflows. Full article
Show Figures

Figure 1

27 pages, 533 KB  
Article
LEPA: Low-Overhead and Efficient Privacy-Preserving Authentication Scheme in VANETs
by Shafika S. Moni and Dakshnamoorthy Manivannan
Network 2026, 6(2), 29; https://doi.org/10.3390/network6020029 - 9 May 2026
Viewed by 638
Abstract
The dynamic nature of Vehicular Ad-hoc Networks (VANETs) necessitates robust authentication mechanisms to prevent adversaries from compromising vehicle privacy. To address privacy concerns, many existing approaches employ pseudonyms in place of real vehicle identities. However, the use of a single pseudonym is insufficient, [...] Read more.
The dynamic nature of Vehicular Ad-hoc Networks (VANETs) necessitates robust authentication mechanisms to prevent adversaries from compromising vehicle privacy. To address privacy concerns, many existing approaches employ pseudonyms in place of real vehicle identities. However, the use of a single pseudonym is insufficient, as vehicle trajectories can still enable tracking. Consequently, vehicles must frequently change pseudonyms, typically selecting them from a pre-assigned pool, to ensure unlinkability and preserve privacy. In most existing schemes, a central authority issues certificates corresponding to each pseudonym, which vehicles present for authentication. While effective, this approach incurs significant computation, storage, and communication overhead, particularly in managing certificate revocation lists (CRLs), since each vehicle may possess a large number of pseudonyms. To address these challenges, we propose a Low-overhead and Efficient Privacy-preserving Authentication (LEPA) scheme for VANETs, leveraging Merkle Hash Trees (MHTs) and Cuckoo Filters (CFs) to efficiently manage pseudonym sets and revocation. We analyze the security of the proposed scheme against various attacks and demonstrate, through performance evaluation, that LEPA significantly reduces authentication and revocation overhead while maintaining strong privacy and security guarantees. Full article
Show Figures

Figure 1

15 pages, 1743 KB  
Article
Essential HDRescue: A Co-Targeting Strategy to Enhance Precision Genome Editing by Co-Editing Essential Genes
by Jamaica F. Siwak, Jon P. Connelly and Shondra M. Pruett-Miller
Cells 2026, 15(9), 768; https://doi.org/10.3390/cells15090768 - 24 Apr 2026
Viewed by 1308
Abstract
Genome editing is widely used and conceptually simple, yet in practice, it is hindered by laborious workflows and high costs. These challenges stem from the difficulty of identifying and isolating cells that contain the desired user-defined modifications, a problem compounded by the wide [...] Read more.
Genome editing is widely used and conceptually simple, yet in practice, it is hindered by laborious workflows and high costs. These challenges stem from the difficulty of identifying and isolating cells that contain the desired user-defined modifications, a problem compounded by the wide variability in editing efficiencies across cell types. While homology-directed repair (HDR) provides a mechanism for precise genome modification following nuclease-induced double-strand breaks (DSBs), it is frequently outcompeted by the dominant mutagenic non-homologous end-joining (NHEJ) pathway in mammalian cells. Therefore, we developed a novel enrichment method, Essential HDRescue, to increase the frequency of HDR events at a target site by co-targeting an essential genomic locus. Using both intrinsic positive and negative selection at a common essential gene, we enabled enrichment of precise editing events at a second, unlinked target site. We demonstrated that co-targeting essential genes in cancer cell lines and iPSCs increased HDR rates without the need for an exogenous reporter or selective drug. Analysis of resulting clones revealed that Essential HDRescue produced up to a 6-fold increase in single-allele edits and an ~4-fold increase in homozygous edits relative to single-targeted controls. By harnessing the intrinsic cellular dependencies that arise from DSB repair at essential loci, Essential HDRescue offers a widely applicable method to improve precise genome editing outcomes in mammalian cells, leaving only a minimal, protein-silent scar at the essential gene. Full article
(This article belongs to the Special Issue Genome Editing in Biomedicine)
Show Figures

Figure 1

32 pages, 2076 KB  
Article
Contextual Zero-Knowledge Authentication with IPFS-Backed Hyperledger Fabric for Privacy-Preserving Blood Supply Chain Management
by Leda Kamal and Jeberson Retna Raj R
Appl. Sci. 2026, 16(9), 4182; https://doi.org/10.3390/app16094182 - 24 Apr 2026
Viewed by 524
Abstract
Ensuring data security and privacy has emerged as a serious concern in the realm of blood supply chain. This is mainly because of sensitivity of donor information, the involvement of multiple stakeholders, and the need for transparent traceability. This paper proposes a novel [...] Read more.
Ensuring data security and privacy has emerged as a serious concern in the realm of blood supply chain. This is mainly because of sensitivity of donor information, the involvement of multiple stakeholders, and the need for transparent traceability. This paper proposes a novel privacy-preserving, permissioned blockchain framework for blood supply chain management that integrates Hyperledger Fabric, the InterPlanetary File System (IPFS), and a Zero-Knowledge Proof (ZKP)-based authentication protocol. The framework introduces a Pseudonymous Role-Bound Zero-Knowledge Authentication (PRZKA) mechanism that enables donors to authenticate and authorize access to their medical data without revealing their real identities. Context-specific pseudonyms derived through cryptographic hash-to-curve operations ensure unlinkability across different healthcare interactions, while Schnorr-style challenge–response proofs prevent replay attacks and credential misuse. Sensitive donor information is protected using Fabric Private Data Collections, whereas encrypted medical records are stored off-chain in IPFS, with only secure content identifiers recorded on the blockchain. Smart contracts enforce fine-grained, consent-aware access control policies and maintain immutable audit logs of all access events. The proposed system architecture combines an off-chain ZKP gateway with on-chain authorization logic to minimize blockchain overhead while preserving strong security guarantees. Furthermore, a performance evaluation framework is defined, including metrics, workload scenarios, and system configurations, to support future empirical validation. Security analysis indicates that the proposed framework enhances privacy, prevents identity linkage, and enables auditable, consent-driven data sharing compared with existing blockchain-based healthcare solutions. Full article
Show Figures

Figure 1

Back to TopTop