{"title":"Token-Guided Flow Tracing for Auditable Zero-Knowledge Smart Contract Transfers","authors":"Junhee Lee, Jihye Kim, Hyunok Oh, Heejin Park","doi":"10.1049/ise2/1765419","DOIUrl":"https://doi.org/10.1049/ise2/1765419","url":null,"abstract":"<p>Private transfers on public smart contract blockchains hide transaction values and private transfer links, but accountable privacy requires controlled auditability. Existing auditable zero-knowledge transfer systems make per-transaction audit information available to an authorized auditor, but their audit model may allow the auditor to inspect transactions beyond the flow connected to the authorized audit target. In such a model, granting audit capability for one investigation can expose unrelated transactions or allow tracing to continue farther than intended. In this paper, we propose token-guided flow tracing for auditable zero-knowledge smart contract transfers, enabling audit authorization to be scoped to a transaction flow and epoch range. The construction separates audit authorization from audit capability by introducing a tracing-token manager and an auditor. The auditor can open audit information only when it holds the auditor secret key, an epoch secret key for an authorized epoch, and a tracing token associated with the target transaction flow. Direction-specific tracing tokens confine tracing to the authorized direction, while epoch public keys and a binary key-derivation tree support compact authorization of audit intervals. We analyze security through ledger indistinguishability, transaction nonmalleability, balance, audit correctness, and restricted audit authorization. Restricted audit authorization is established in an honest authorization model that assumes the tracing-token manager and the auditor do not collude beyond explicit audit authorizations; under these assumptions, the auditor cannot open or trace transactions outside the authorized flow, direction, and epoch scope. Our implementation adds 16,349 transfer-circuit constraints, about 178,000 gas to each accepted transfer, and 448 bytes to the serialized transfer transaction, showing that scoped auditability can be added with moderate on-chain overhead.</p>","PeriodicalId":50380,"journal":{"name":"IET Information Security","volume":"2026 1","pages":""},"PeriodicalIF":2.0,"publicationDate":"2026-08-20","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1049/ise2/1765419","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"148783931","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"OA","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"A Context-Aware Secure Two-Tier Account-Based Retail Central Bank Digital Currency Framework: A Case Study of Tanzania","authors":"Godbless Gibson Minja, Anael Elikana Sam, Devotha Godfrey Nyambo","doi":"10.1049/ise2/3917324","DOIUrl":"https://doi.org/10.1049/ise2/3917324","url":null,"abstract":"<p>Central bank digital currencies (CBDCs) are increasingly being explored as a means to enhance financial inclusion, reduce transaction costs and modernise payment systems. However, their design and implementation pose significant challenges, particularly in emerging economies such as Tanzania, where security risks, infrastructural constraints and interoperability issues persist in the digital financial services (DFS) ecosystem. This study proposes a context-aware, secure, two-tier, account-based retail CBDC framework for Tanzania, developed using the design science research (DSR) methodology. Furthermore, the proposed framework is structured around the access, service, asset and platform (ASAP) model and integrates the security-by-design principles, including zero-trust architecture, defence-in-depth and cryptographic agility. It further incorporates context-aware considerations, such as interoperability with existing mobile money systems, tiered know-your-customer mechanisms for financial inclusion, and support for connectivity and usability constraints. Moreover, the framework is demonstrated and evaluated using objective-based, security-oriented and contextual assessments. The evaluation indicated that the framework promises to provide a coherent and practical approach for the design of secure, interoperable and inclusive CBDC systems. This study contributes a prescriptive and contextually grounded CBDC design framework that offers both academic value and practical guidance for CBDC implementation in Tanzania and similar emerging economies.</p>","PeriodicalId":50380,"journal":{"name":"IET Information Security","volume":"2026 1","pages":""},"PeriodicalIF":2.0,"publicationDate":"2026-07-16","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1049/ise2/3917324","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"148467334","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"OA","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"A Private-Identifier System From Scalable Private Set Union","authors":"Sangmin Lee, Jiseung Kim, Yongha Son","doi":"10.1049/ise2/5802869","DOIUrl":"https://doi.org/10.1049/ise2/5802869","url":null,"abstract":"<p>Modern data-driven collaborations, such as spanning healthcare analysis and advertising attribution, need to merge large identifier sets without revealing which records overlap. A private set union (PSU) protocol enables two parties, each holding a private set <i>X</i> and <i>Y</i>, to securely compute their union <i>X</i> ∪ <i>Y</i> without revealing any additional information. In this work, we revisit recent constructions of PSU protocol to understand it in modular fashion, which enables a better instantiation of such submodules. Furthermore, we further propose an optimization that reduces communication cost, which comes from a novel application permutation-based hashing (phasing). The proposed PSU protocol shows up to 6.9x speed up over high-speed network, and up to 43% reduction in communication costs than the original protocol due for <i>n</i> = 2<sup>12</sup> − 2<sup>20</sup> sized set, which is the best performance over LAN network; up to 2.3x faster than the state-of-the-art PSU protocol. Based on this core primitive, we propose a database anonymization system called private-ID (PID). End-to-end evaluations show our PID inherits the PSU improvements, outperforming previous works over high-bandwidth links while remaining competitive on WAN network. Taken together, our results provide a drop-in, high-throughput building block for privacy-preserving data-driven collaborations.</p>","PeriodicalId":50380,"journal":{"name":"IET Information Security","volume":"2026 1","pages":""},"PeriodicalIF":2.0,"publicationDate":"2026-07-16","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1049/ise2/5802869","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"148467476","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"OA","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"A Type of Differential Fault Attacks of the Stream Cipher SNOW-V Based on AES Structure","authors":"Shaoyu Du, Bin Zhang, Lin Jiao, Hongfang Li","doi":"10.1049/ise2/9918170","DOIUrl":"https://doi.org/10.1049/ise2/9918170","url":null,"abstract":"<p>SNOW-V is a member in the SNOW family of stream ciphers designed for the 5G mobile communication system. In order to have a high speed, both the linear feedback shift register (LFSR) and finite state machine (FSM) are updated to better align with vectorized implementations and the update function is based on the round function of AES. In this paper, we find the 512-bit LFSR can be approximately divided into four parts and each clock one 128-bit part updates the FSM, another 128-bit part masks the 128-bit keystream. Differences in different bytes of the LFSR have distinguishable propagations in the keystream, which all behaves not randomly. Under the assumption that the cipher can be reset several times with the same key and IV to permit the adversary to inject different one-byte faults in the higher 16 bytes of LFSR-B during the keystream-generating phase, the state of SNOW-V can be revealed. For the simplified version of SNOW-V that addition with carry is replaced by XOR, the 384-bit FSM state can be revealed from the faulty and fault-free keystreams of seven faults with evenly 2<sup>23</sup> computational complexity, and then the 512-bit LFSR state can be revealed with no more complexity. For the full version of SNOW-V, we can conduct another fault attack with 2<sup>48</sup> computational complexity and 64 faults on average.</p>","PeriodicalId":50380,"journal":{"name":"IET Information Security","volume":"2026 1","pages":""},"PeriodicalIF":2.0,"publicationDate":"2026-07-12","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1049/ise2/9918170","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"148466903","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"OA","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Olusesi Balogun, Mohammad GhasemiGol, Zhipeng Cai, Daniel Takabi
{"title":"Toward Secure and Practical Machine Learning-Based Access Control: A Framework With Real-World Constraints and Adversarial Analysis","authors":"Olusesi Balogun, Mohammad GhasemiGol, Zhipeng Cai, Daniel Takabi","doi":"10.1049/ise2/7123849","DOIUrl":"10.1049/ise2/7123849","url":null,"abstract":"<p>Attribute-Based Access Control (ABAC) frameworks coordinate access requests based on subject, object, and environment attributes, as well as policy rules, and are widely used in corporate security systems. Recently, machine learning has been applied to ABAC to address policy-generation imbalances, misassigned privileges, and attribute leakages. However, existing MLBAC techniques do not consider the structural constraints and attribute interdependencies present in traditional ABAC systems. Moreover, these frameworks have not been extensively evaluated under black-box attack scenarios. To address these gaps, we propose extensions to MLBAC that integrate structural constraints, attribute dynamism, and attribute weighting into the MLBAC objective function. Additionally, we study the behavior of these extended MLBAC models under black-box adversarial attacks. We implemented the framework using five deep-learning models: RNN, LSTM, Deep Belief Network (DBN), TabTransformer, and DeepFM, on both synthetic and real-world datasets. Our findings show that the DBN model consistently achieves the best performance, while the black-box adversarial attacks reveal general vulnerabilities across MLBAC systems. These outcomes highlight the need for more robust defense mechanisms in future research. Accordingly, we propose several potential mitigation strategies against black-box attacks.</p>","PeriodicalId":50380,"journal":{"name":"IET Information Security","volume":"2026 1","pages":""},"PeriodicalIF":2.0,"publicationDate":"2026-06-29","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1049/ise2/7123849","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"148381176","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"OA","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Guoqiang Liu, Yijia Yang, Bing Sun, Da Lin, Kangquan Li
{"title":"Design of Iterative MDS Matrices Based on MISTY Structure","authors":"Guoqiang Liu, Yijia Yang, Bing Sun, Da Lin, Kangquan Li","doi":"10.1049/ise2/7441214","DOIUrl":"https://doi.org/10.1049/ise2/7441214","url":null,"abstract":"<p>The security of symmetric-key ciphers critically depends on the diffusion efficiency of their linear components. Iterative maximum distance separable (MDS) matrices, as fundamental elements of diffusion layer, play a pivotal role in constructing secure cryptographic systems. This study focuses on the construction of iterative MDS matrices based on the iterative MISTY structure. First, we present iterative MISTY structures with same round functions over <span></span><math></math>, along with the corresponding necessary conditions for constructing iterative MDS matrices. Then, we investigate the construction of 4th-order iterative MDS matrices over <span></span><math></math> for <i>m</i> = 4, 5, 6, 8, and evaluate the implementation cost in terms of gate count for some instances. Second, we extend this paradigm to MISTY structures with distinct round functions, establishing corresponding necessary conditions and generating 4th-order iterative MDS matrices over <span></span><math></math> for <i>m</i> = 3, 4. Based on which, we investigate 4th-order iterative MDS matrices over <span></span><math></math> for <i>m</i> = 3, 4 and exhibit some instances selected from the resulting matrices.</p>","PeriodicalId":50380,"journal":{"name":"IET Information Security","volume":"2026 1","pages":""},"PeriodicalIF":2.0,"publicationDate":"2026-06-25","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1049/ise2/7441214","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"148324610","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"OA","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Cipher-Guard: A Machine Learning Model for Adaptive and Context-Aware Password Security","authors":"Mohammed Naif Alatawi","doi":"10.1049/ise2/3930060","DOIUrl":"https://doi.org/10.1049/ise2/3930060","url":null,"abstract":"<p>This research aims to enhance password security by designing, training and testing Cipher-Guard, a machine learning (ML) algorithm that incorporates complex features and techniques derived from proven feature engineering. The current model is inherently built on the equations of mathematical modelling concerning complexity metrics of passwords and contextualisation. This is in terms of password length (PL), entropy (<i>E</i>) and the character set diversity (CSD) of the passwords, as well as contextual embeddings such as user-specific password history (UPH) and temporal patterns (TPs). A simulation of the data matrix was created, containing 1000 records, which formed the basis of the model and a thorough exploratory data analysis (EDA). The proposed model demonstrates interpretability and credibility in distinguishing patterns related to password complexity metrics, yielding promising formative results in the specified evaluation metrics. PL, <i>E</i> and CSD were analysed thoroughly, and the importance of increasing password security was identified. Specific contextual embeddings were identified as UPH and TPs, which reflect the model’s ability to adapt to the particular user’s actions. Including adversarial training features also helped protect the model from potential manipulations through a proactive defence plan. Moreover, the enhancement of cryptographic principles, which include hashing and salting, also improved the dataset security, thereby increasing the standard practice within the industry. The metrics involved in the comparative assessment included receiver operating characteristic-area under the curve (ROC-AUC), learning curves, confusion matrix, precision matrix and precision-recall curves, among others. Cipher-Guard performed consistently well across these parameters, which has reinforced its authenticity in strengthening password protection. However, to appreciate such findings, certain constraints need to be well addressed, such as the quality of the chosen dataset, some ethical concerns raised in the study and the fact that new threats are constantly emerging. Recommendations for enhancing continuous dataset monitoring and establishing an ethical framework for the case are also suggested. The research directions broaden future possibilities for research while emphasising continuous model updating, individual-centred protection and compatibility with other emerging technologies. Therefore, Cipher-Guard represents a significant advancement in password protection and offers a promising prospect for flexible and personalised security in the modern era.</p>","PeriodicalId":50380,"journal":{"name":"IET Information Security","volume":"2026 1","pages":""},"PeriodicalIF":2.0,"publicationDate":"2026-06-19","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1049/ise2/3930060","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"148282279","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"OA","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Ahmad Bilal, Huma Jamshed, Muhammad Ayoub Kamal, Qurat-ul-ain Mastoi, Toqeer Ali Syed, It Ee Lee
{"title":"An Enhanced Approach for Intrusion Detection Modeling to Secure IoT Network by Using Big Data Analytics","authors":"Ahmad Bilal, Huma Jamshed, Muhammad Ayoub Kamal, Qurat-ul-ain Mastoi, Toqeer Ali Syed, It Ee Lee","doi":"10.1049/ise2/1301034","DOIUrl":"https://doi.org/10.1049/ise2/1301034","url":null,"abstract":"<p>Since 1980, the arrival of the internet has made fabulous changes, and presently, the Internet of Things (IoT) is having the same track. IoT becomes more attractive due to its potential, but on the other hand, the IoT network is targeted to be demolished. IoT networks are always under the risk of denial of services (DoSs) attacks, which have shocking significance. Under this situation, the need for cybersecurity actions like intrusion detection systems (IDSs) are very much essential. The scope of this article is to propose an IDS for big data architecture. The IoT dataset (BoT-IoT) was used with libraries of Apache Spark, and experimental work was evaluated on the F1 measure. The dataset was divided into few parts; the partial part of dataset was examined by random forest for binary classification resulted in 98.6% F1 measure. Main categorical phase was resulted in 98.4% and subcategory classification resulted in 84.1% F1 measure. For overall classification of dataset decision tree resulted in 96.4 for binary classification, 78.6 for major category and 74% for categorical classification.</p>","PeriodicalId":50380,"journal":{"name":"IET Information Security","volume":"2026 1","pages":""},"PeriodicalIF":2.0,"publicationDate":"2026-06-17","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1049/ise2/1301034","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"148282136","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"OA","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Permanent Anchors and Adaptive Throughput: Extending Proof-of-Access Consensus to Resolve the Blockchain Trilemma","authors":"Saha Reno, G. M. Abdullah Al Kafi, Koushik Roy","doi":"10.1049/ise2/7733436","DOIUrl":"https://doi.org/10.1049/ise2/7733436","url":null,"abstract":"<p>Contemporary distributed ledgers face an inherent trilemma when attempting to simultaneously optimize three critical properties: transaction throughput (measured in transactions per second [TPS]), network security, and node decentralization. Current decentralized storage platforms such as Filecoin encounter constraints in managing peak transaction loads effectively. We propose a novel storage architecture that integrates Arweave’s permanent data layer with an enhanced proof-of-access (PoA) consensus protocol and adaptive block management. While control-theoretic methods are established, their novel integration with Arweave’s permanent storage and PoA consensus creates a unique symbiotic relationship that directly tackles the blockchain trilemma. Through transaction metadata compression to 48-byte entries, our framework achieves a transaction density of 7200 entries per megabyte of block capacity. Under baseline conditions (1 MB blocks generated every 44 s), this yields 162 TPS, scaling to a simulated peak of 7200 TPS with 200 MB blocks under optimal network parameters. Experimental validation through simulation and a multiphase global testbed (25–112 nodes) demonstrates robust security characteristics with 0.82 chain quality under 40% adversarial presence, defense mechanisms against prevalent network attacks, and 99% reduction in annual storage growth compared to conventional blockchain systems, outperforming modern alternatives including Sui (5.3× storage efficiency) and Avalanche (3.5× storage efficiency). Game-theoretic proofs establish formal security guarantees, while extended adversarial modeling confirms resilience under worst-case conditions. To ensure reproducibility and foster further research, all simulation code and deployment tools for the testbed have been made publicly available on GitHub. These findings present a viable equilibrium between essential blockchain properties for practical implementations.</p>","PeriodicalId":50380,"journal":{"name":"IET Information Security","volume":"2026 1","pages":""},"PeriodicalIF":2.0,"publicationDate":"2026-06-14","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1049/ise2/7733436","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"148281993","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"OA","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Corruption-Correctable MACs via Combinatorial Group Testing and Erasure Correcting Codes","authors":"Isamu Furuya, Akiko Inoue, Kazuhiko Minematsu","doi":"10.1049/ise2/6678007","DOIUrl":"https://doi.org/10.1049/ise2/6678007","url":null,"abstract":"<p>We have developed a corruption-correctable message authentication code (CCMAC) that enables data integrity to be verified and corruptions of data to be corrected up to a certain threshold. As in a previous technique for identifying corrupted points, called corruption detectable MAC (CDMAC), the proposed scheme utilizes a system model composed of two types of storage: general and secure. General storage is vulnerable, that is, data stored in it could be attacked by a malicious third party, whereas secure storage is not vulnerable. In this study, we present two methods of the proposed scheme, each of which has a trade-off relationship regarding the data size requirements between general and secure storage. We also define security notions for our methods and prove that they can be reduced to those of the MAC or CDMAC used as an internal component.</p>","PeriodicalId":50380,"journal":{"name":"IET Information Security","volume":"2026 1","pages":""},"PeriodicalIF":2.6,"publicationDate":"2026-06-12","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1049/ise2/6678007","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"148237836","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"OA","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}