SearcharxivSearch

arXiv subjects

David Megias

Publications and source records attributed to David Megias.

3 recordsLinked to original sources

Complex domain approach for reversible data hiding and homomorphic encryption: General framework and application to dispersed data

Ensuring the trustworthiness of data from distributed and resource-constrained environments, such as Wireless Sensor Networks or IoT devices, is critical. Existing Reversible Data Hiding (RDH) methods for scalar data suffer from low embedding capacity and poor intrinsic entanglement between host data and watermark. This paper introduces Hiding in the Imaginary Domain with Data Encryption (H[$i$]dden), a novel framework based on complex number arithmetic for simultaneous information embedding and encryption. The H[$i$]dden framework offers perfect reversibility, highly scalable watermark capacity decoupled from the host data's range, and intrinsic data-watermark entanglement. The paper further introduces two protocols: H[$i$]dden-EG, for joint reversible data hiding and encryption, and H[$i$]dden-AggP, for privacy-preserving aggregation of watermarked data, based on partially homomorphic encryption. Rigorous comparative evaluation against recent state-of-the-art baselines demonstrates that the framework significantly expands embedding capacity and achieves an exponential improvement in False Data Injection (FDI) resilience ---ranging from $10^5$ to $10^{19}$ under standard configurations--- effectively neutralizing targeted structural vulnerabilities such as homomorphic injection attacks. Furthermore, empirical performance analysis ---encompassing hardware-agnostic cryptographic metrics and direct IoT edge hardware emulation (ESP32)--- confirms the practical deployment feasibility of the framework within standard sensor duty cycles. Ultimately, these protocols provide efficient and resilient solutions for data integrity, provenance (or group-level integrity in the aggregated case), and confidentiality, serving as a foundation for new schemes based on the algebraic properties of the complex domain.work and application to dispersed data

cs.CR

RIOT-based smart metering system for privacy-preserving data aggregation using watermarking and encryption

The remarkable advancement of smart grid technology in the IoT sector has raised concerns over the privacy and security of the data collected and transferred in real-time. Smart meters generate detailed information about consumers' energy consumption patterns, increasing the risks of data breaches, identity theft, and other forms of cyber attacks. This study proposes a privacy-preserving data aggregation protocol that uses reversible watermarking and AES cryptography to ensure the security and privacy of the data. There are two versions of the protocol: one for low-frequency smart meters that uses LSB-shifting-based reversible watermarking (RLS) and another for high-frequency smart meters that uses difference expansion-based reversible watermarking (RDE). This enables the aggregation of smart meter data, maintaining confidentiality, integrity, and authenticity. The proposed protocol significantly enhances privacy-preserving measures for smart metering systems, conducting an experimental evaluation with real hardware implementation using Nucleo microcontroller boards and the RIOT operating system and comparing the results to existing security schemes.

cs.CR

Security Approaches for Data Provenance in the Internet of Things: A Systematic Literature Review

The Internet of Things (IoT) relies on resource-constrained devices deployed in unprotected environments. Given their constrained nature, IoT systems are vulnerable to security attacks. Data provenance, which tracks the origin and flow of data, provides a potential solution to guarantee data security, including trustworthiness, confidentiality, integrity, and availability in IoT systems. Different types of risks may be faced during data transmission in single-hop and multi-hop scenarios, particularly due to the interconnectivity of IoT systems, which introduces security and privacy concerns. Attackers can inject malicious data or manipulate data without notice, compromising data integrity and trustworthiness. Data provenance offers a way to record the origin, history, and handling of data to address these vulnerabilities. A systematic literature review of data provenance in IoT is presented, exploring existing techniques, practical implementations, security requirements, and performance metrics. Respective contributions and shortcomings are compared. A taxonomy related to the development of data provenance in IoT is proposed. Open issues are identified, and future research directions are presented, providing useful insights for the evolution of data provenance research in the context of the IoT.

cs.CR