- Book Chapter
- 10.1016/b978-192899484-8/50043-2
Chapter 8 - IPv6 Security
- Jan 01, 2002
- Configuring IPv6 For Cisco IOS
- Sam Brown + 8 more +8
Chapter 8 - IPv6 Security
The LoRaWAN security design adheres to state-of-the-art principles: use of standard, well-vetted algorithms, and end-to-end security. The fundamental properties supported in LoRaWAN security are mutual end-point authentication, data origin authentication, integrity and replay protection, and confidentiality. The use of symmetric cryptography and prior secret key sharing between a device and a server enables an extremely power efficient and network efficient activation procedure.
Chapter 8 - IPv6 Security
Chapter 8 - IPv6 Security
Integrity preservation for communication in sensor networks
We propose a novel data integrity protection scheme, which relies on multiple, intervoven authentication chains instead of data origin authentication. We show that the scheme allows for secure node-to-node communication at very low implementation cost, under a certain attacker model, without reliance on a base station.
Read morePractical Cryptographic Data Integrity Protection with Full Disk Encryption
Full Disk Encryption (FDE) has become a widely used security feature. Although FDE can provide confidentiality, it generally does not provide cryptographic data integrity protection. We introduce an algorithm-agnostic solution that provides both data integrity and confidentiality protection at the disk sector layer. Our open-source solution is intended for drives without any special hardware extensions and is based on per-sector metadata fields implemented in software. Our implementation has been included in the Linux kernel since the version 4.12.
Read moreTowards secure end-to-end data aggregation in AMI through delayed-integrity-verification
The integrity and authenticity of the energy usage data in Advanced Metering Infrastructure (AMI) is crucial to ensure the correct energy load to facilitate generation, distribution and customer billing. Any malicious tampering to the data must be detected immediately. This paper introduces secure end-to-end data aggregation for AMI, a security protocol that allows the concentrators to securely aggregate the data collected from the smart meters, while enabling the utility back-end that receives the aggregated data to verify the integrity and data originality. Compromise of concentrators can be detected. The aggregated data is protected using Chameleon Signatures and then forwarded to the utility back-end for verification, accounting, and analysis. Using the Trapdoor Chameleon Hash Function, the smart meters can periodically send an evidence to the utility back-end, by computing an alternative message and a random value (m′, r) such that m′ consists of all previous energy usage measurements of the smart meter in a specified period of time. By verifying that the Chameleon Hash Value of (m′, r) and that the energy usage matches those aggregated by the concentrators, the utility back-end is convinced of the integrity and authenticity of the data from the smart meters. Any data anomaly between smart meters and concentrators can be detected, thus indicating potential compromise of concentrators.
Read moreAn energy efficient authentication scheme for cluster-based wireless IoT sensor networks
An energy efficient authentication scheme for cluster-based wireless IoT sensor networks
Long-term integrity protection of genomic data
Genomic data is crucial in the understanding of many diseases and for the guidance of medical treatments. Pharmacogenomics and cancer genomics are just two areas in precision medicine of rapidly growing utilization. At the same time, whole-genome sequencing costs are plummeting below $ 1000, meaning that a rapid growth in full-genome data storage requirements is foreseeable. While privacy protection of genomic data is receiving growing attention, integrity protection of this long-lived and highly sensitive data much less so.We consider a scenario inspired by future pharmacogenomics, in which a patient’s genome data is stored over a long time period while random parts of it are periodically accessed by authorized parties such as doctors and clinicians. A protection scheme is described that preserves integrity of the genomic data in that scenario over a time horizon of 100 years. During such a long time period, cryptographic schemes will potentially break and therefore our scheme allows to update the integrity protection. Furthermore, integrity of parts of the genomic data can be verified without compromising the privacy of the remaining data. Finally, a performance evaluation and cost projection shows that privacy-preserving long-term integrity protection of genomic data is resource demanding, but in reach of current and future hardware technology and has negligible costs of storage.
Read moreIntegrity Protection for the Neighborhood Discovery Protocol (NHDP) and Optimized Link State Routing Protocol Version 2 (OLSRv2)
This document specifies integrity and replay protection for the Mobile Ad Hoc Network (MANET) Neighborhood Discovery Protocol (NHDP) and the Optimized Link State Routing Protocol version 2 (OLSRv2). This protection is achieved by using an HMAC-SHA-256 Integrity Check Value (ICV) TLV and a Timestamp TLV based on Portable Operating System Interface (POSIX) time. The mechanism in this specification can also be used for other protocols that use the generalized packet/message format described in RFC 5444. This document updates RFC 6130 and RFC 7181 by mandating the implementation of this integrity and replay protection in NHDP and OLSRv2.
Read morePrivacy and Integrity Protection for IoT Multimodal Data Using Machine Learning and Blockchain
With the wide application of Internet of Things (IoT) technology, large volumes of multimodal data are collected and analyzed for various diagnoses, analyses, and predictions to help in decision-making and management. However, the research on protecting data integrity and privacy is quite limited, while the lack of proper protection for sensitive data may have significant impacts on the benefits and gains of data owners. In this research, we propose a protection solution for data integrity and privacy. Specifically, our system protects data integrity through distributed systems and blockchain technology. Meanwhile, our system guarantees data privacy using differential privacy and Machine Learning (ML) techniques. Our system aims to maintain the usability of the data for further data analytical tasks of data users, while encrypting the data according to the requirements of data owners. We implement our solution with smart contracts, distributed file systems, and ML models. The experimental results show that our proposed solution can effectively encrypt source IoT data according to the requirements of data users while data integrity can be protected under the blockchain.
Read morePKDIP: Efficient Public-Key-Based Data Integrity Protection for Wireless Image Sensors
Due to limited energy of “wireless image sensors (WISs),” existing data integrity protection mechanisms typically employ a hash-function-based signing algorithm to generate “message authentication codes (MACs)” for long image frames. However, hash-function-based signing algorithm requires the WIS and the “end user (EU)” sharing a secret, which leads to a new security issue: Once the EU becomes malicious due to some reasons, it will be able to forge the WIS’s data since it holds the shared secret. Therefore, public-key cryptography is desirable. Unfortunately, public-key cryptographic operations are quite time-consuming for energy-restrained WISs. Facing this dilemma, we present a novel data integrity protection protocol named PKDIP in this paper. Similar to the mechanisms of this field, PKDIP generates MACs for data integrity protection. However, different from other well-known approaches, PKDIP introduces the “Montgomery Modular Multiplication (MontMM)” technique to current public-key-based signing algorithms. Since MontMM is much more efficient than hash functions, PKDIP can reduce the signing cost significantly. Experimental results show PKDIP can even be more efficient than hash-function-based schemes.
Read moreDesigning Cybersecurity Measures for Enterprise Software Applications to Protect Data Integrity
In an era of escalating cyber threats, safeguarding data integrity in enterprise software applications is critical for maintaining trust and operational stability. Designing robust cybersecurity measures is essential to protect sensitive information from unauthorized access, alteration, and loss. This review explores key strategies and methodologies for developing comprehensive cybersecurity frameworks tailored for enterprise software applications. Effective cybersecurity begins with a thorough risk assessment to identify potential vulnerabilities and threats specific to the enterprise's software environment. Implementing multilayered security measures, including encryption, access controls, and authentication protocols, is vital for mitigating risks. Encryption protects data in transit and at rest, ensuring that even if intercepted, the data remains unintelligible to unauthorized parties. Access controls and authentication mechanisms, such as multifactor authentication (MFA), enhance security by verifying the identity of users and restricting access based on roles and permissions. Regular security audits and vulnerability assessments play a crucial role in detecting and addressing potential weaknesses. These audits should be conducted both internally and externally to provide a comprehensive view of the security posture. Additionally, adopting secure coding practices and integrating security into the software development lifecycle (SDLC) help in identifying and mitigating vulnerabilities during the development phase. Incident response planning is another critical aspect of cybersecurity. Developing a well-defined incident response plan ensures that the enterprise can quickly and effectively address security breaches, minimizing potential damage and restoring data integrity. This includes establishing protocols for detecting, responding to, and recovering from cyber incidents. Educating and training employees about cybersecurity best practices is essential for maintaining a secure environment. Employees should be aware of common threats, such as phishing and social engineering attacks, and understand their role in safeguarding the enterprise’s data. In conclusion, designing effective cybersecurity measures for enterprise software applications requires a multifaceted approach that includes risk assessment, encryption, access controls, regular audits, secure coding practices, incident response planning, and employee training. By implementing these strategies, enterprises can enhance their defenses, protect data integrity, and ensure the resilience of their software applications against evolving cyber threats. Keywords: Designing, Cybersecurity, Data Integrity, Software Applications, Enterprise.
Read moreMaintaining User Control While Storing and Processing Sensor Data in the Cloud
Clouds provide a platform for efficiently and flexibly aggregating, storing, and processing large amounts of data. Eventually, sensor networks will automatically collect such data. A particular challenge regarding sensor data in Clouds is the inherent sensitive nature of sensed information. For current Cloud platforms, the data owner loses control over her sensor data once it enters the Cloud. This imposes a major adoption barrier for bridging Cloud computing and sensor networks, which we address henceforth. After analyzing threats to sensor data in Clouds, the authors propose a Cloud architecture that enables end-to-end control over sensitive sensor data by the data owner. The authors introduce a well-defined entry point from the sensor network into the Cloud, which enforces end-to-end data protection, applies encryption and integrity protection, and grants data access. Additionally, the authors enforce strict isolation of services. The authors show the feasibility and scalability of their Cloud architecture using a prototype and measurements.
Read moreInvisible watermarking using a novel MRA-based image fusion method
In today's technical era, transmission of digital data plays a key role in our everyday lives; it is only natural that the protection of data integrity and confidentiality has assumed paramount proportions. To avoid interception and misuse, an efficient and reliable data hiding technique has to be developed and deployed in almost every sphere of electronic data management. For this purpose, the concept of watermarking has always been used widely. In this paper we have presented a novel technique based on wavelet transforms and image fusion and proposed a new algorithm for robust and effective watermarking. In this algorithm, we have used the Multi-Resolution Analysis (MRA) technique to decompose an image and then fusing it with a logo image rather than a pseudo-random number sequence. The algorithm has been applied on multiple images and results have proved its effectiveness.
Read moreData Integrity Protection in Cloud
In cloud computing integrity of data and access control are challenging issues. Protection of outsourced data in cloud storage becomes critical. Codes which are regenerating of data provide fault tolerance. Therefore, remotely checking the integrity of data against corruptions and other issues under a real time cloud storage setting is our problem of study. It practically design and implement Data Integrity Protection (DIP) environment.
Read moreEndometrial whole-slide images dataset for detection of malignancy in endometrial biopsies
BackgroundWhole-slide imaging enables the digitization of entire histological slides at a high resolution, allowing pathologists and researchers to analyze tissue samples digitally rather than through traditional microscopy. This technology has become increasingly valuable in pathology for research, education, and clinical diagnostics. Endometrial biopsy is very common, often being undertaken to exclude noncancerous disease. This means that most cases do not contain cancer, and the challenge is to accurately and efficiently exclude serious pathology rather than simply make a diagnosis of malignancy. A well-curated, expert-annotated, endometrial whole-slide dataset covering a spread of cancer and noncancer diagnoses will support machine learning applications in automated diagnosis, facilitate research into the pathology of endometrial cancer, and serve as an educational resource for medical professionals.ResultsWe introduce a newly constructed, large-scale dataset of endometrial biopsy specimens, comprising 2,909 whole-slide images in iSyntax format, each accompanied by a corresponding annotation file in JSON format. Each whole-slide image is labeled with a primary class label representing its final diagnosis and a subcategory label providing further details within that diagnostic class. These class labels are critical for machine learning applications, as they enable the development of artificial intelligence models capable of distinguishing between different types of endometrial abnormalities, improving automated classification, and guiding clinical decision-making.ConclusionsConstructing and curating a high-quality endometrial whole-slide dataset requires significant effort to ensure accurate annotations, data integrity, and patient privacy protection. However, the availability of a well-annotated dataset with detailed class labels is crucial for advancing digital pathology. Such a resource can enhance diagnostic accuracy, support personalized treatment strategies, and ultimately improve outcomes for patients with endometrial cancer and other endometrial conditions.
Read moreLow-Complexity Elliptic Galois Cryptography-Based Secure Data Integrity Verification Scheme for Cloud Storage
The Data Integrity Based Secure Cloud Data Outsourcing Model involves designing a framework that ensures data outsourced to the cloud remains secure, intact, and authentic. Cloud computing has become an indispensable resource for businesses and individuals alike, providing scalable and cost-effective solutions for data storage and management. However, outsourcing data to external cloud service providers (CSPs) raises serious questions around data security, integrity, and authenticity. It is essential to retain confidence and comply with regulatory criteria to make sure that outsourced data is authentic, obtainable, and unaltered. In this article, the Low-Complexity Elliptic Galois Cryptography based Secure Data Integrity Verification Scheme for Cloud Storage (LCEGC-SDIV-CS) is proposed. Initially, the integration of the advantages in Trusted Execution Environment (TEE) and identity-based encryption using Low-Complexity Elliptic Galois Cryptography (LCEGC) is provided to create a safe data integrity verification scheme. Then, data integrity using Block Access Signature Oriented Merle Hash Tree (BS-MHT) is used for the integrity-preserving structure for encrypted block-oriented storage systems. The random Oracle model's security analysis, depending upon the computational Diffie-Hellman assumption, provides security by preventing attacks when the adversary chooses the messages with targets’ identities. The proposed LCEGC-SDIV-CS model is implemented and the performance metrics like Data uploading with downloading time, Memory usage on data uploading with downloading, Encryption time, Decryption time, and Security levels are examined. The proposed LCEGC-SDIV-CS method attains 21.56%, 23.98%, and 21.19% lower data uploading with downloading time 24.78%, 23.82%, and 23.52% lower encryption time are analyzed with existing methods EDI-SPD-SCS, NSA-SADS-BDEPDP-SDS-RCS respectively.
Read more