Irina Pavlovna Bolodurina

dblp:142/4688 · also Irina Bolodurina · DBLP profile ↗
← Back
33ranked-venue papers
1as first author
30since 2021 · last 2026
0000-0003-0096-2587ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 16 · 16 since 2021Security and privacy · 9 · 9 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 1 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 first-authorSystems, architecture and hardware · 2 · 2 since 2021
YearPublicationVenuePosition
2026 BliChain: A Blockchain-Assisted and Lightweight Cross-Domain Authentication Scheme for 6G-Enabled VANET
abstract
In the evolution of 6G-based Vehicular Ad-hoc Networks (VANETs) from closed single-domain environments to open cross-domain environments, several security challenges arise, including heterogeneous domain trust barriers, vehicle identity privacy leakage, and high authentication overhead in dynamic scenarios. Existing schemes based on centralized public key infrastructure (PKI) suffer from single point failure risks and have difficulty balancing low latency with conditional privacy preservation. Meanwhile, blockchain-assisted solutions are often constrained by on-chain storage expansion and high computational overhead. To address these issues, this paper proposes a blockchain-assisted anonymous authentication scheme for 6G-VANETs. The proposed scheme uses blockchain to construct distributed trust anchors and enable secure sharing of public parameters across domains. By generating lightweight authentication parameters based on Lagrange interpolation polynomials, the scheme supports direct mutual authentication and session key agreement between vehicles without requiring massive certificate-related on-chain transactions. In addition, a pseudo-identity mechanism is introduced to achieve conditional privacy preservation, thereby balancing vehicle identity privacy and traceability. Security analysis demonstrates that the proposed scheme satisfies the required security properties under the random oracle model. Performance evaluation shows that compared with existing solutions, the proposed scheme significantly reduces computational overhead by 22.31%, 11.02%, and 29.19%, respectively, and communication overhead by 51.2%, 20.08%, and 24.61%, respectively.
Jiaxin Li 0001, Hong Zhong 0001, Lu Wei 0003, Irina Pavlovna Bolodurina, Jie Cui 0004
IEEE Internet Things J.5
2026 Privacy-Accountable Distributed Collaborative Authentication for Malicious Node Resistance in Vehicular Ad Hoc Networks
abstract
In vehicular ad hoc networks (VANETs), distributed identity authentication provides the foundation for securing sessions among entities over wireless channels while eliminating single points of failure. However, existing distributed authentica tion schemes for VANETs typically make unrealistic assumptions about node reliability and trustworthiness, failing to account for scenarios where authentication nodes may be compromised or collude with vehicles. Moreover, these schemes expose the com munication process to linkability attacks while allowing vehicles to self-register their public keys. To address these limitations, we propose a privacy-preserving and accountable distributed collab orative authentication scheme for VANETs that is resilient to ma licious nodes. Using threshold signature techniques, distributed authentication nodes collaboratively perform decentralized ve hicle identity authentication using a predefined threshold. Zero knowledge proof protects the privacy of the signing process while maintaining accountability and effectively preventing malicious behavior by nodes under external or internal adversarial attacks. Furthermore, vehicles self-register their public keys via smart contracts and blockchain technology, ensuring anonymity and unlinkability during registration while enabling the traceability of malicious vehicles. Security and performance analyses show that the proposed scheme enhances the security and robustness of distributed collaborative authentication in VANETs, achieving a better balance between computational and communication costs than existing schemes
Ru Li 0005, Jie Cui 0004, Lu Wei 0003, Irina Pavlovna Bolodurina, Jing Zhang 0024, Hong Zhong 0001
IEEE Trans. Dependable Secur. Comput.4
2026 Blockchain-Based Asynchronous Authentication and Key Agreement Scheme for Securing VANETs
abstract
In vehicular ad hoc networks (VANETs), authentication and key agreement (AKA) protocols are crucial for establishing secure authentication and session keys for network communications, ensuring security for short-term vehicle interactions. However, traditional VANETs AKA schemes heavily rely on centralized trust architectures. This dependence raises significant concerns about overall system security and resilience, especially when these schemes operate over insecure wireless channels. Although recent studies have introduced decentralized architectures to mitigate this issue, a key limitation remains. These approaches typically assume synchronous network environments, which in practice limits their true decentralization capabilities in dynamic VANETs. To address these challenges, we propose a decentralized and asynchronous AKA scheme based on a consortium blockchain that enables the execution of the key agreement process in asynchronous VANETs environments. Furthermore, we employ lightweight cryptographic techniques combined with a Cuckoo filter to optimize computational efficiency, reduce communication overhead, and minimize on-chain storage costs. Security analyses and simulation experiments demonstrate that the proposed scheme delivers robust security and high performance under realistic network conditions.
Lu Wei 0003, Yujia Zhong, Jie Cui 0004, Irina Pavlovna Bolodurina, Jiaxin Li 0001, Hong Zhong 0001
IEEE Trans. Dependable Secur. Comput.4
2026 Blockchain-Assisted Secure Announcement Sharing Scheme With Controllable Verifiable Distributed Security for VANETs
abstract
In recent years, vehicle announcement sharing has become increasingly important in intelligent transportation networks. However, the demand for secure communication and real-time responses necessitates the development of an efficient and confidential announcement sharing scheme. Existing solutions are constrained by inadequate privacy in inter-group sharing and lack of storage security consideration. To address these issues, we propose a blockchain-assisted secure announcement sharing scheme with controllable verifiable distributed security. This scheme constructs a re-encrypted group signature framework to achieve controlled confidentiality of announcements while ensuring efficient and secure sharing. Additionally, by designing a lightweight verification algorithm powered by the Inter Planetary File System (IPFS) and blockchain, the scheme ensures rapid verifiable secure both the initial and long-term storage of announcements. Security proof and analysis show that the proposed scheme offers enhanced security and robust privacy protection. Performance analysis demonstrates that, while providing better computational efficiency than other schemes, the proposed scheme maintains low communication overhead and smaller storage verification costs, outperforming existing announcement sharing schemes.
Jie Cui 0004, Jing Zhang 0024, Ru Li 0005, Yimin Wang 0004, Irina Pavlovna Bolodurina, Hong Zhong 0001
IEEE Trans. Mob. Comput.6
2026 Post-Quantum Secure Authenticated Key Agreement Scheme for Vehicular Digital Twin
Jie Cui 0004, Jiyu Liu, Lu Wei 0003, Irina Pavlovna Bolodurina, Jiaxin Li 0001, Hong Zhong 0001
IEEE Trans. Mob. Comput.4
2026 Game Theory and Trust Management Driven Dynamic Proof-of-Work Blockchain Consensus Algorithm for Securing Internet of Vehicles
Lu Wei 0003, Yuanzhi Cao, Jie Cui 0004, Hong Zhong 0001, Irina Pavlovna Bolodurina, Debiao He
IEEE Trans. Mob. Comput.5
2026 Toward Stable and Low-Latency Task Offloading: A Multi-Agent Framework for Vehicular Edge Computing
Lu Wei 0003, Jie Cui 0004, Xianfeng Xie, Jing Zhang 0024, Irina Pavlovna Bolodurina, Hong Zhong 0001
IEEE Trans. Netw. Serv. Manag.6
2025 TDID: A Three-Factor Decentralized Identity Authentication Scheme in Metaverse
abstract
The Metaverse, an immersive parallel digital world, faces critical security challenges such as data leakage and impersonation attack. Existing authentication schemes often suffer from single-point failures due to centralization, incomplete decentralization, and low efficiency. To address these challenges, this paper proposes TDID, a three-factor decentralized identity authentication scheme. Our core contribution lies in the novel synergy of a confidential smart contract, executed within a Trusted Execution Environment (TEE), with the offline attackresistant OPAQUE password-authenticated key exchange protocol. The scheme achieves full decentralization by using the TEE-based contract as a decentralized root of trust. It allows users to establish a globally unique, collision-resistant identity, and ensures that a user's password and biometric key are never revealed to the server during authentication, thus providing robust resistance against offline dictionary attacks even from a compromised server. Rigorous security analysis, including formal verification using ProVerif and a provable security proof, along with performance evaluations, demonstrates that the proposed scheme significantly enhances security while maintaining efficient computational and communication performance.
Jie Cui 0004, Mengfei Cheng, Jing Zhang 0024, Li Wang 0139, Irina Pavlovna Bolodurina, Hong Zhong 0001
ICPADS5
2025 LSHSC: Lightweight and Secure Handover Scheme With Conditional Privacy-Preserving for Group-Based SDVN
abstract
Introducing the SDN paradigm can further improve the handover efficiency of mobile nodes, and researchers have proposed corresponding solutions to the security problems in the handover process. Some existing cryptography-based schemes delegate authentication to the fog nodes to accelerate the handover process, however, the computation and communication overheads are not low enough to satisfy the requirements of delay-sensitive vehicular applications. To realize secure handover of vehicles in software defined vehicular networks (SDVN), in this paper, based on symmetric cryptography, we propose a lightweight and secure handover scheme with conditional privacy-preserving for group-based SDVN. The handover authentication only involves lightweight operation, without based on elliptic curve cryptography or involving complex bilinear pairing operations. After successfully authenticating with the SDN controller, the vehicle can directly authenticate with the fog nodes in the same group. The polynomial and one-way hash chain are used to realize group key update. We use BAN logic and ProVerif to formally analyze and test the security of our scheme. The detailed security analyses show that the scheme can resist common types of attacks and meet the essential security and privacy requirements. Compared with other related and represented works, our scheme exhibits better performance in computation and communication overheads.
Hong Zhong 0001, Jie Cui 0004, Irina Pavlovna Bolodurina, Chengjie Gu, Debiao He
IEEE Trans. Dependable Secur. Comput.4
2025 BAST: Blockchain-Assisted Secure and Traceable Data Sharing Scheme for Vehicular Networks
abstract
In vehicular networks, caching service content on edge servers (ESs) is a widely accepted strategy for promptly responding to vehicle requests, reducing communication overhead, and improving service experience. However, implementing such an architecture requires addressing the challenges associated with ES response data reliability and communication security. In this study, to tackle the ES response data reliability issue, a blockchain-assisted threshold signature scheme for cache-based vehicular networks is proposed. The scheme utilizes a threshold mechanism to sign the data broadcast by the ES, incorporates blockchain to trace malicious signers, and avoids the shortcomings and limitations associated with idealized assumptions for the ES in existing data-sharing schemes. Moreover, considering the communication security and high-speed mobility of vehicles, using the non-interactive signatures of knowledge based on the Σ-protocol, a secure and efficient message authentication scheme for vehicles and ESs is provided. Through rigorous security proofs and comprehensive analyses, our scheme satisfies the communication security requirements of vehicular networks. By leveraging the JPBC library for performance analysis, the proposed scheme demonstrates advantages as concerns both computation and communication overheads compared to related schemes. Moreover, we implemented the proposed scheme on an Ethereum test network (i.e., Goerli) to validate its feasibility.
Xinzhong Liu 0002, Jie Cui 0004, Jing Zhang 0024, Rongwang Yin, Hong Zhong 0001, Lu Wei 0003, Irina Pavlovna Bolodurina, Debiao He
IEEE Trans. Inf. Forensics Secur.7
2025 A Blockchain-Driven Hierarchical Authentication and Key Agreement Scheme for VANETs With Cloud-Edge Collaboration
abstract
Vehicular ad-hoc networks (VANETs) are the cornerstone of intelligent transportation systems, designed to enhance road safety and traffic efficiency. However, their dynamic and distributed nature poses significant challenges for secure communication and key management. Traditional authentication and key agreement (AKA) schemes for VANETs often rely on centralized trust architectures, resulting in system security and reliability issues. Despite the introduction of distributed trust architecture schemes that have appeared recently, they fail to solve one issue, i.e., how the key agreement requests can be authenticated in the distributed communication scenario where the authentication authorities are all non-full-credible and have differentiated credibility. To solve this issue, we propose a hierarchical AKA scheme for VANETs with cloud-edge collaboration powered by consortium blockchain. Specifically, we first proposed a vehicle reputation evaluation algorithm for evaluating the trustworthiness of the vehicle, so that the AKA requests sent by vehicles with low reputation will be rejected. On the basis of the reputation evaluation algorithm, we proposed a hierarchical threshold-based AKA scheme for VANETs where cloud servers (CSs) and edge servers (ESs) can collaboratively authenticate the AKA requests, so that the authentication service can be trusted upon getting authenticated by a series of valid combinations of CSs and ESs. Both formal and informal security proofs validate the security of our proposed scheme, and simulation experiments demonstrate its efficiency.
Lu Wei 0003, Yongjuan Zhang, Jie Cui 0004, Hong Zhong 0001, Irina Pavlovna Bolodurina, Debiao He
IEEE Trans. Inf. Forensics Secur.5
2025 False Message Detection System for VANETs: A Reputation Evaluation Method Based on Voting Mechanism
abstract
Vehicular ad hoc networks (VANETs) enable vehicles to engage in vehicle-to-vehicle and vehicle-to-infrastructure communications to enhance driving safety. However, the open nature of the network and the uncertainty of information sources make VANETs vulnerable to false message attacks, potentially causing severe traffic accidents. Existing false-message detection systems suffer from high false alarm rates and high resource consumption. To address these challenges, we propose a false message attack detection system based on a software-defined network architecture that can efficiently and accurately detect false message attacks with minimal consumption of system resources. The system aims to detect emergency and normal beacon messages broadcast by vehicles, construct an automotive reputation evaluation system using the voting mechanism of the Byzantine consensus, and introduce an XGBoost-based traffic event classifier to improve classification accuracy. Experimental results show that the system can reliably assess vehicle reputation levels, effectively defend against conspiracy attacks, and perform well in intrusion detection.
Jie Cui 0004, Danting Yu, Jing Zhang 0024, Lu Wei 0003, Xianfeng Xie, Irina Pavlovna Bolodurina, Hong Zhong 0001
IEEE Trans. Intell. Transp. Syst.6
2025 Reputation System-Based Vehicle Violation Reporting Service With Invalid Signature Identification in VANETs
abstract
Owing to frequent traffic accidents, the violation reporting service is a promising method to enhance road safety in vehicular ad hoc networks (VANETs). However, to implement such a service, it is critical to ensure security, privacy, and efficiency when vehicles send messages to roadside units (RSU). In this study, to address these issues, a vehicle violation reporting service is proposed using reputation systems and a physically unclonable function. The proposed scheme ensures secure authentication between vehicles and RSUs, facilitates an efficient search for invalid signatures, and overcomes the limitations present in ID-based conditional privacy-preserving authentication schemes. Moreover, considering the dynamic VANET environment, the distribution of invalid signatures may vary across multiple scenarios. Therefore, a fault-tolerant mechanism is proposed to ensure the robustness of this approach. Security proof with the random oracle model and detailed security analysis proved that the scheme could satisfy the security requirements of VANETs. Our scheme outperforms related approaches in terms of authentication overhead and the identification of invalid signatures, achieving superior performance in both aspects.
Jing Zhang 0024, Chengzhi Xia, Jie Cui 0004, Hong Zhong 0001, Lu Wei 0003, Irina Pavlovna Bolodurina, Debiao He
IEEE Trans. Intell. Transp. Syst.6
2025 Robust Intrusion Detection System for Vehicular Networks: A Federated Learning Approach Based on Representative Client Selection
abstract
The rapid development of network technology has allowed numerous vehicular applications to be deployed in vehicles, thereby enriching the driving experience of users. However, the openness of vehicular networks enables attackers to launch network attacks on vehicles through network ports, leading to the destruction of vehicular networks. To develop an intrusion detection system suitable for distributed vehicular networks, researchers have utilized federated learning to train detection models. Nevertheless, most federated learning-based vehicular intrusion detection systems seldom consider rapidly updating the detection model and fail to detect unknown attacks effectively. In this study, we propose a federated learning-based vehicular intrusion detection system that fully considers the traffic characteristics of multiple network regions and selects representative clients to participate in model aggregation, thereby accelerating the convergence of the global model. Furthermore, to enhance the robustness of the detection system, we utilize extreme value theory and multilayer activation vectors to construct an unknown attack discriminator that can determine whether a network flow is an unknown attack. Comprehensive experiments on three open datasets demonstrate that the proposed intrusion detection system can quickly update and effectively identify known/unknown attacks in open vehicular networks
Chunyang Fan, Jie Cui 0004, Hulin Jin, Hong Zhong 0001, Irina Pavlovna Bolodurina, Debiao He
IEEE Trans. Mob. Comput.5
2025 Security-Enhanced Data Sharing via Efficient Sanitization for VANETs
abstract
With the widespread deployment of vehicular ad-hoc networks (VANETs), data sharing has garnered considerable attention as a core feature of VANETs. Attribute-based proxy re-encryption (ABPRE) enables fine-grained access control and provides flexible ciphertext updates. The initially authorized vehicle generates the re-encryption key to enable ciphertext-to-ciphertext conversion in the cloud, allowing ciphertext to be shared with new recipients. However, initially authorized vehicles may not always be trustworthy and could share data with malicious receivers. In addition, the computation and communication overhead of ABPRE hinders its widespread application in VANETs. To address these issues, we propose a lightweight sanitizable scheme for edge-assisted VANETs based on ABPRE. In this scheme, the re-encryption key is verified by a sanitizer, to prevent the data from being shared with malicious data receivers. In addition, key-splitting techniques and edge computing are employed to reduce the communication and computation overhead of re-encryption. A comprehensive security analysis and performance evaluation demonstrate that the proposed scheme is efficient and practical.
Hong Zhong 0001, Jie Cui 0004, Li Wang 0139, Jing Zhang 0024, Irina Pavlovna Bolodurina, Debiao He
IEEE Trans. Mob. Comput.6
2024 MM-SDVN: Efficient Mobility Management Scheme for Optimal Network Handover in Software-Defined Vehicular Network
abstract
Providing high-quality network services for vehicles is a challenge because of the fast-moving character of the vehicles. To address the shortcomings of traditional centralized and distributed mobility management schemes, such as triangular routing and poor scalability, many researchers use software-defined networking (SDN) to build mobility management schemes. However, most schemes rarely consider how to select the optimal base station for high-speed mobile vehicles in a dense network environment. Only using the received signal strength to select the base station tends to cause a ping-pong effect. Moreover, due to the high mobility of vehicles, the routing updates between vehicles and communication nodes will frequently occur, resulting in the significant consumption of network resources. In this article, we propose a mobility management scheme MM-SDVN based on SDN for vehicles. MM-SDVN uses deep Q-network to construct the optimal base station selection model, designs a multipath prefix matching algorithm to reduce the cost of route update, and realizes the seamless handover of vehicles in SDN intradomain and interdomain scenarios. The comprehensive experimental results show that MM-SDVN greatly improves the network service quality and handover performance of the vehicle. Compared to the other schemes, MM-SDVN improved vehicle throughput by 6.14%, 8.85%, and 10.34%, respectively.
Chunyang Fan, Jie Cui 0004, Hong Zhong 0001, Irina Pavlovna Bolodurina, Debiao He
IEEE Internet Things J.4
2024 Secure and Efficient User-Centric V2C Communication for Intelligent Cyber-Physical Transportation System
abstract
Recently, the concept of intelligent cyber-physical transportation systems (ICTS) has entered the vehicle network, providing more efficient, safe, and sustainable services by applying intelligent technology to the transportation system. Because the communication channel between the vehicle and the cloud service provider (CSP) is open and insecure. Therefore, we must construct a secure Vehicle-to-CSP (V2C) communication scheme to ensure the security of vehicle privacy data. Current communication schemes mainly have two limitations. One is that the user’s role in communication is not considered, and the other is that the computational and communication overhead are not sufficiently low to satisfy the low latency requirements. To address the deficiencies, we propose a user-centric V2C communication scheme. The primary key in the signature is concealed, which ensures the confidentiality of the user’s legal real identity. Its main steps, based on the extended Chebyshev chaotic map and hash function, reduce the computational and communication overhead in the process. The security proof and analysis show that our proposed scheme satisfies the security and privacy requirements. The performance analysis shows that our proposed scheme outperforms other related schemes.
Jing Zhang 0024, Ruonan Ying, Jie Cui 0004, Hong Zhong 0001, Irina Pavlovna Bolodurina, Debiao He
IEEE Trans. Inf. Forensics Secur.5
2024 A Two-Layer Dynamic ECU Group Management Scheme for In-Vehicle CAN Bus
abstract
To enable the vehicle control system to provide better service, an increasing number of network nodes are being introduced into the vehicle; this also dramatically expands the attack surface of modern vehicles. In recent years, the security of vehicle communication buses and electronic control units (ECUs) has been extensively studied. However, in actual deployment, there is little concern for the fine management of secure communication schemes with respect to the security level of the ECU on the controller area network (CAN). On this basis, this paper proposes a two-layer ECU group dynamic management scheme based on the Chinese remainder theorem. Dynamic grouping management based on the credibility of ECUs while the vehicle is running can effectively balance efficiency and security. During communication, different groups use different modes to achieve higher efficiency. Security analysis shows that the proposed scheme can satisfy the requirements of security and privacy. Simulation results further demonstrate that the proposed scheme performs well in terms of computing and communication costs.
Jie Cui 0004, Hong Zhong 0001, Jing Zhang 0024, Irina Pavlovna Bolodurina, Debiao He
IEEE Trans. Intell. Transp. Syst.5
2024 LH-IDS: Lightweight Hybrid Intrusion Detection System Based on Differential Privacy in VANETs
abstract
Vehicular Ad hoc Networks (VANETs) are vulnerable to various types of attacks. Intrusion Detection System (IDS) based on machine learning can effectively detect malicious network attacks in VANETs. However, machine learning training necessitates ample data which contain significant ample private information, increasing the risk of privacy disclosure. The privacy protection of training data for machine learning used in the IDS of VANETs is rarely investigated. Meanwhile, Differential Privacy (DP) is one of the most secure privacy protection methods based on perturbations. Therefore, we propose a lightweight hybrid IDS (LH-IDS) based on machine learning and DP. It uses algorithms based on unsupervised learning to detect anomalous network behaviour with high performance, especially unknown attacks in VANETs, while protecting data privacy. The DP is used to secure the privacy of the training data. Noise from different privacy budgets is added to datasets to obtain DP datasets. Subsequently, LH-IDS is used to verify the utility of the DP datasets. Extensive experiments confirm LH-IDS can not only detect anomalous and normal traffic with excellent performance but can also protect the private information of the training data. Additionally, the proposed model incurs only minimal CPU and memory overhead, making it a lightweight solution.
Jie Cui 0004, Jietian Xiao, Hong Zhong 0001, Jing Zhang 0024, Lu Wei 0003, Irina Pavlovna Bolodurina, Debiao He
IEEE Trans. Mob. Comput.6
2024 Privacy-Preserving and Secure Distributed Data Sharing Scheme for VANETs
abstract
Data sharing is one of the essential services of vehicular ad hoc networks (VANETs), which primarily requires data security and access control, and ciphertext-policy attribute-based encryption (CP-ABE) is a promising tool. However, data sharing schemes of distributed CP-ABE have concerns about the single-point performance bottleneck and privacy leakage. The factor for the former is that the authority manages a disjoint attribute set. The latter is because the user's identity and attributes are required to submit to authorities, which targets to bind this information to decryption keys for collusion-resistant. We propose a privacy-preserving distributed data sharing scheme for VANETs. This scheme introduces asymmetric group key agreement to distributed CP-ABE, which realizes that multiple authorities manage an attribute, and the user can obtain the attribute key bound with his identity from any authority in the group. To match up to the requirement of privacy-preserving, a key extract protocol provided user anonymity is proposed, which implements that attribute keys can be obtained without revealing the user's identity and attributes. Moreover, partial policy hiding is satisfied. Finally, we analyze and evaluate the proposed scheme, and the results indicate that our scheme is secure and efficient.
Li Wang 0139, Hong Zhong 0001, Jie Cui 0004, Jing Zhang 0024, Lu Wei 0003, Irina Pavlovna Bolodurina, Debiao He
IEEE Trans. Mob. Comput.6
2024 A Decentralized Authenticated Key Agreement Scheme Based on Smart Contract for Securing Vehicular Ad-Hoc Networks
abstract
Since the communication channels in vehicular ad-hoc networks (VANETs) are wireless and open, malicious adversaries can monitor or fabricate messages transmitted across them. To secure vehicular communications, an authenticated key agreement (AKA) scheme needs to be designed for VNAETs. Traditional VANETs AKA schemes require the trusted authority (TA) to authenticate the legality of message and corresponding sender. However, the TA in these schemes is vulnerable to suffer from single-point-of-failure issues. Some blockchain-based VANETs AKA schemes have been proposed recently to address the deficiency. However, these schemes rely on the consortium or private blockchain in which TAs are still required for key generation, resulting that the practicality is limited. To solve the issue, we design a smart contract-based VANETs AKA scheme, where the AKA algorithm of our proposed scheme is implemented on smart contract deployed on a public blockchain system and the TA that is responsible for key generation will not be required. The security proof and analysis show that our proposed scheme satisfies the session-key semantic security and essential security and privacy requirements, respectively. The performance analysis demonstrates that our proposed scheme outperforms existing blockchain-based VANETs AKA schemes.
Lu Wei 0003, Jie Cui 0004, Hong Zhong 0001, Irina Pavlovna Bolodurina, Chengjie Gu, Debiao He
IEEE Trans. Mob. Comput.4
2024 A Threshold-Based Full-Decentralized Authentication and Key Agreement Scheme for VANETs Powered by Consortium Blockchain
abstract
The authentication and key agreement (AKA) scheme for VANETs can produce a series of short-term session keys, which can be used to secure the vehicular communications across open and insecure wireless channels. Traditional VANETs AKA schemes tend to employ the centralized trust architecture as the core authentication backend, which raises concerns about system security and reliability. Recently, several VANETs AKA schemes that are constructed on decentralized trust architecture have been proposed. However, these schemes do not achieve full decentralization and tend to suffer from key exposure issues, insufficient performance, and lack of optimization for on-chain storage costs. To address these shortcomings, we propose a threshold-based full-decentralized VANETs AKA scheme that is powered by consortium blockchain. In our proposed scheme, the threshold-based voting concept is employed to mitigate the key exposure issue inherent to the network infrastructure. Furthermore, we leverage lightweight cryptography in conjunction with the Cuckoo filter to reduce computational, communication, and on-chain operation costs brought by cryptographic operations and smart contracts. The security proof together with the cryptographic protocol validation tool prove the security of our proposed scheme, whereas the simulation experiment demonstrates the efficiency of our proposed scheme.
Lu Wei 0003, Yongjuan Zhang, Jie Cui 0004, Hong Zhong 0001, Irina Pavlovna Bolodurina, Debiao He
IEEE Trans. Mob. Comput.5
2024 DBCPA: Dual Blockchain-Assisted Conditional Privacy-Preserving Authentication Framework and Protocol for Vehicular Ad Hoc Networks
abstract
Vehicular ad hoc networks (VANETs) connect all vehicles through wireless channels. They provide extensive real-time traffic information services that improve driving safety and traffic management efficiency. However, VANETs are vulnerable to security attacks because of the open wireless nature of their communication channels. Most security mechanisms for traditional VANETs are centralized and have certain limitations in satisfying security requirements, such as anti-single-point failure, distributed security authentication of messages, and privacy preservation in VANETs. To address these issues, herein, we propose a dual blockchain-assisted conditional privacy-preserving authentication framework and protocol for VANETs. The identity authentication and privacy preservation of vehicles in VANETs can be realized without relying on a centralized trusted third party. The proposed scheme also allows for the conditional tracking of illegal vehicles. The decentralized dynamic revocation of illegal vehicles can be realized through smart contracts, rendering the scheme efficient and scalable. We implement this scheme in an Ethereum test network to demonstrate its feasibility and conduct an in-depth security analysis and comprehensive performance evaluation of the proposed scheme. The results demonstrate that the proposed scheme is an effective solution for the development of a decentralized authentication system for VANETs.
Jing Zhang 0024, Jie Cui 0004, Debiao He, Irina Pavlovna Bolodurina, Hong Zhong 0001
IEEE Trans. Mob. Comput.5
2024 CBDDS: Secure and Revocable Cache-Based Distributed Data Sharing for Vehicular Networks
abstract
In vehicular networks, caching content on an edge server (ES) is a popular method for quickly responding to massive vehicle service requests, reducing communication delays, and enhancing driver and passenger service experiences. However, after integrating ESs with vehicular networks to provide vehicles access to the cached content in these ESs, significant challenges regarding protecting the privacy of vehicle data and communication security arise. In this study, to address security and privacy-preserving issues, we propose a secure and revocable cache-based distributed data sharing scheme for vehicular networks wherein a token authentication mechanism and multi-authority ciphertext-policy attribute-based encryption are integrated. In this scheme, both authentication and authorization capabilities are delegated to an ES while restricting access to service content to only legal vehicles, achieving proper access control between vehicles and ESs, and effectively preserving the privacy of vehicle data. Moreover, we attributed the revocations of ESs to the associated attribute authorities, eliminating the need for a system-wide update of keying materials. Through rigorous security proofs and detailed security analyses, we demonstrate that the scheme meets the security requirements of vehicular networks and can resist more security attacks. The proposed scheme achieves better balance between computational and communication costs than related schemes.
Jing Zhang 0024, Xinzhong Liu 0002, Jie Cui 0004, Hong Zhong 0001, Lu Wei 0003, Irina Pavlovna Bolodurina, Debiao He
IEEE Trans. Mob. Comput.6
2023 A Lightweight and Conditional Privacy-Preserving Authenticated Key Agreement Scheme With Multi-TA Model for Fog-Based VANETs
abstract
Recently, the fog computing concept has been introduced into vehicular ad-hoc networks (VANETs) to formulate fog-based VANETs. Since the communication channels between vehicles and fog nodes are open and insecure, it is necessary to construct an authenticated key agreement (AKA) scheme for securing the channels. The existing AKA schemes have two main deficiencies. One is that the computational and communication overhead are not low enough to satisfy the requirements of delay-sensitive applications. The other is that the multi-trusted-authority (multi-TA) model has not been considered. To solve the deficiencies, we propose a lightweight and conditional privacy-preserving AKA scheme, where the main steps are designed with symmetric cryptography methods. The design can reduce the computational and communication overhead of the AKA process. Additionally, we consider the multi-TA model in the AKA process to solve the single-point-of-failure issue. By integrating Cuckoo filter into the multi-TA model, the secrecy of real identities of legal vehicles is guaranteed and the identity revocation function for illegal vehicles is supported in the AKA process. The security proof and analysis show that our proposed scheme satisfies the essential security and privacy requirements of VANETs. The performance analysis shows that our proposed scheme outperforms other related and represented schemes.
Lu Wei 0003, Jie Cui 0004, Hong Zhong 0001, Irina Pavlovna Bolodurina, Lu Liu 0001
IEEE Trans. Dependable Secur. Comput.4
2023 Secure Edge Computing-Assisted Video Reporting Service in 5G-Enabled Vehicular Networks
abstract
Since traffic accidents occur frequently, a real-time video traffic reporting service is necessary in vehicular networks for a prompt response to accidents. Although the fifth-generation (5G) network provides a solution for real-time services in vehicular networks, the security and privacy of the services needs to be addressed first. The existing secure video reporting service schemes in 5G-enabled vehicular networks have significant computing, communication, and storage overheads, because of public key certificates, expensive bilinear pairing operations, and repeated video reporting to the cloud. To address these issues, we propose a secure edge computing-assisted video reporting service in 5G-enabled vehicular networks. In the proposed method, edge nodes complete the message verification and classification. Moreover, these nodes send the first received report message of the same accident to the designated official vehicles to realizes a local upload and download of video reports and to minimize the storage of repeated accident reports in the cloud. Security analysis indicates the proposed scheme is secure under the random oracle model and meets a series of vehicular networks requirements. In addition, performance evaluations show that the scheme achieves lower authentication overhead than existing signature schemes, and has lower total delay than other relevant video reporting service schemes.
Hong Zhong 0001, Li Wang 0139, Jie Cui 0004, Jing Zhang 0024, Irina Pavlovna Bolodurina
IEEE Trans. Inf. Forensics Secur.5
2023 AC-SDVN: An Access Control Protocol for Video Multicast in Software Defined Vehicular Networks
abstract
The way to use limited bandwidth resources to achieve high-quality video services in vehicular networks is an important research topic. A large number of studies have shown that the fast-growing field of software defined networking (SDN) can provide solutions to the problems encountered by traditional IP networks when implementing video multicasting. However, there is no research addressing the security issues for this scenario. In this paper, we explore the application scenarios of video multicast in software defined vehicular networks (SDVN), and propose a secure and effective access control protocol to solve multicast security issues. This protocol realizes the authentication of multicast video requesting vehicles and RSUs. According to the authentication results, the SDN controller constructs multicast paths that only reach legitimate RSUs and vehicles, and only the vehicle passing the authentication can obtain video decryption keys. The protocol resists common attacks and satisfies the security requirements in vehicular networks. In addition, the scheme supports batch verification, which reduces the time cost of authentication, and adopts broadcast encryption technology to effectively reduce the communication load. Compared with related schemes, our protocol performs better in terms of computation and communication cost, packet loss rate, and time delay.
Hong Zhong 0001, Jie Cui 0004, Chengjie Gu, Irina Pavlovna Bolodurina, Lu Liu 0001
IEEE Trans. Mob. Comput.5
2023 Collaborative Intrusion Detection System for SDVN: A Fairness Federated Deep Learning Approach
abstract
With the continuous innovations and development in communication technology and intelligent transportation systems, a new generation of vehicular ad hoc networks (VANETs) has become increasingly popular, making VANET communication security increasingly important. An intrusion detection system (IDS) is an important tool for detecting network attacks and is an effective means of improving network security. However, existing IDSs encounter several problems involving inaccurate detections, low detection efficiencies, and incomplete detections owing to extensive changes in vehicle locations in VANETs. This study explores federated learning in software-defined VANETs and designs an efficient and accurate collaborative intrusion detection system (CIDS) model. The model utilizes the collaboration among local software-defined networks (SDNs) to jointly train the CIDS model without directly exchanging local network data flows to improve the expansibility and globality of IDSs. To reduce the model difference between different SDN clients and improve the detection accuracy, this study regards the prediction loss for each SDN client as an objective from the perspective of constrained multi-objective optimization. By optimizing a surrogate maximum function containing all the objectives, the method adopts two-stage gradient optimization to achieve Pareto optimality for SDN clients with the worst fairness constraint maximization performance. In addition, this study evaluates the training model using two open-source datasets and compares it with the latest methods. Experimental results reveal that the proposed model ensures local data privacy and demonstrates high accuracy and efficiency in detecting attacks and is thus superior to the current schemes.
Jie Cui 0004, Hong Zhong 0001, Jing Zhang 0024, Lu Wei 0003, Irina Pavlovna Bolodurina, Debiao He
IEEE Trans. Parallel Distributed Syst.6
2022 Secure and Lightweight Conditional Privacy-Preserving Authentication for Fog-Based Vehicular Ad Hoc Networks
abstract
Vehicular ad hoc networks (VANETs) play an ever-increasing important role in improving traffic management and enhancing driving safety. However, vehicular communication using a wireless channel faces security and privacy challenges. The conditional privacy-preserving authentication (CPPA) scheme is suitable for solving the above challenges, but the existing identity-based CPPA schemes suffer from inborn key escrow issues. Motivated by this, we propose a lightweight CPPA scheme based on elliptic curve cryptography to solve the above issues, in which the pseudonym and public/private key pair of the vehicle is generated by itself, so that the proposed scheme avoids the key escrow issue. Furthermore, to achieve efficient vehicular communication, a CPPA scheme is proposed using a fog computing model that supports mobility, low latency, and location awareness. The pseudonym of the vehicle is generated by two hash chains in the proposed scheme, so that the storage overhead can be reduced efficiently under the condition that backward security is guaranteed. Security analysis shows that the scheme is secure under the random oracle and satisfies the security requirements of VANETs. Performance evaluation demonstrates that the proposed scheme outperforms related schemes in terms of computational and communication overhead.
Hong Zhong 0001, Jie Cui 0004, Jing Zhang 0024, Irina Pavlovna Bolodurina, Lu Liu 0001
IEEE Internet Things J.5
2022 CBACS: A Privacy-Preserving and Efficient Cache-Based Access Control Scheme for Software Defined Vehicular Networks
abstract
In vehicular networks, caching content in fog nodes is a widely accepted and favorable way to quickly respond to massive vehicle requests, reduce content retrieval delay and improve service quality. However, to implement such caching mode, it is critical to ensure efficient security and privacy protection when vehicles access the cached content in fog nodes. In this paper, aiming at the security issue, a novel lightweight cryptography-based access control scheme for software defined vehicular networks (SDVN) is proposed, by using TESLA broadcast authentication protocol and Pederson commitment. The scheme realizes direct and efficient authentication between vehicles and fog nodes while limiting only legitimate vehicles can get request responses, and avoids limitations or deficiencies in existing access control schemes. Moreover, considering the limited cache space of the fog node, by utilizing the flexibility of the SDN paradigm, a cooperative cache update mechanism is provided. The security verification with ProVerif and detailed security analyses prove that the scheme can meet the security requirements in SDVN. And compared with the related works, our scheme achieves better performance in terms of computation and communication costs.
Hong Zhong 0001, Chunyang Fan, Irina Pavlovna Bolodurina, Jie Cui 0004
IEEE Trans. Inf. Forensics Secur.4
2018 Adaptive technology to support talented secondary school students with the educational IT infrastructure
abstract
This paper describes the project of an automated adaptive system for individual support of talented students with the educational IT infrastructure. A model of the process of self-learning and self-development of talented students in the educational IT infrastructure is developed on the basis of a multilevel competence system using Petri nets. To design optimal student's individual learning paths algorithms of the ant colony have been used. Methods for calculating the relative values of the student's rating are proposed based on accounting their academic achievements in a specific subject area. A preliminary version of the Web portal has been developed to provide the storage of talented student's profiles with their achievements and ratings, information on courses and training competitions, ILP planning, user interaction, integration with external educational resources.
Alexander Shukhman, Irina Pavlovna Bolodurina, Petr Polezhaev, Yury A. Ushakov, Leonid Legashev
EDUCON2
2017 Creation of regional center for shared access to educational software based on cloud technology
abstract
The paper describes the concept and implementation of regional center for shared access to educational software based on cloud technology (RCSA). Students are provided the access via Internet to remote desktop with needed software. Developed service is provided as cloud DaaS. This service is profitable for educational institutions because they don't need to update hardware and to buy paid software.
Alexander Shukhman, Petr Polezhaev, Leonid Legashev, Yury A. Ushakov, Irina Pavlovna Bolodurina
EDUCON5
2013 Efficient access to multimedia resources in distributed systems of distance learning
abstract
This work proposes an approach to improve the effectiveness of access to multimedia learning resources of distance learning systems on the basis of the load balancing.
Irina Pavlovna Bolodurina, Denis Igorevich Parfenov, Alexander Shukhman
EDUCON1