Yang Shi;Minyu Teng;Jingwen Liang;Jingxuan Han;Jiayao Gao;Guoyue Xiong;Xiaoping Wang;Hongfei Fan
{"title":"Intrusion-Resilient Undetachable Signature for Mobile-Agent-Based Collaborative Commerce Systems","authors":"Yang Shi;Minyu Teng;Jingwen Liang;Jingxuan Han;Jiayao Gao;Guoyue Xiong;Xiaoping Wang;Hongfei Fan","doi":"10.1109/TNSE.2025.3532691","DOIUrl":null,"url":null,"abstract":"Mobile agents are valuable in collaborative commerce systems due to their mobility and autonomy, enabling them to traverse the Internet and purchase goods and services on behalf of their owners. However, in the face of potential attacks from malicious hosts, securely executing a contract on behalf of the original signer poses a significant challenge. In this paper, we propose an Intrusion-Resilient Undetachable Signature (IRUS) approach for mitigating security risks associated with signing key leakage on the signer's host, base device, and even potentially malicious remote hosts. Additionally, it addresses the risk of signing algorithm misuse on remote hosts. Our approach ensures that adversaries cannot forge past or future signatures as long as the base device remains secure, even if the current signing key is compromised. In cases where the base device is compromised, although future signatures may be forged, all past signatures remain secure. Furthermore, we integrate the encrypted signing function with the original signer's requirements to prevent the misuse of the signing algorithm and the exposure of the original signing key on malicious hosts. Security proofs have confirmed that our scheme can effectively defend against various types of attacks, and experimental evaluations have demonstrated the strong performance of the proposed approach with enhanced security, meanwhile reducing the execution times of the signing phase by at most 75% and the verification phase by 95% compared with three existing undetachable signature schemes.","PeriodicalId":54229,"journal":{"name":"IEEE Transactions on Network Science and Engineering","volume":"12 3","pages":"1510-1523"},"PeriodicalIF":6.7000,"publicationDate":"2025-01-22","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"IEEE Transactions on Network Science and Engineering","FirstCategoryId":"94","ListUrlMain":"https://ieeexplore.ieee.org/document/10849659/","RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"ENGINEERING, MULTIDISCIPLINARY","Score":null,"Total":0}
引用次数: 0
Abstract
Mobile agents are valuable in collaborative commerce systems due to their mobility and autonomy, enabling them to traverse the Internet and purchase goods and services on behalf of their owners. However, in the face of potential attacks from malicious hosts, securely executing a contract on behalf of the original signer poses a significant challenge. In this paper, we propose an Intrusion-Resilient Undetachable Signature (IRUS) approach for mitigating security risks associated with signing key leakage on the signer's host, base device, and even potentially malicious remote hosts. Additionally, it addresses the risk of signing algorithm misuse on remote hosts. Our approach ensures that adversaries cannot forge past or future signatures as long as the base device remains secure, even if the current signing key is compromised. In cases where the base device is compromised, although future signatures may be forged, all past signatures remain secure. Furthermore, we integrate the encrypted signing function with the original signer's requirements to prevent the misuse of the signing algorithm and the exposure of the original signing key on malicious hosts. Security proofs have confirmed that our scheme can effectively defend against various types of attacks, and experimental evaluations have demonstrated the strong performance of the proposed approach with enhanced security, meanwhile reducing the execution times of the signing phase by at most 75% and the verification phase by 95% compared with three existing undetachable signature schemes.
期刊介绍:
The proposed journal, called the IEEE Transactions on Network Science and Engineering (TNSE), is committed to timely publishing of peer-reviewed technical articles that deal with the theory and applications of network science and the interconnections among the elements in a system that form a network. In particular, the IEEE Transactions on Network Science and Engineering publishes articles on understanding, prediction, and control of structures and behaviors of networks at the fundamental level. The types of networks covered include physical or engineered networks, information networks, biological networks, semantic networks, economic networks, social networks, and ecological networks. Aimed at discovering common principles that govern network structures, network functionalities and behaviors of networks, the journal seeks articles on understanding, prediction, and control of structures and behaviors of networks. Another trans-disciplinary focus of the IEEE Transactions on Network Science and Engineering is the interactions between and co-evolution of different genres of networks.