首页 > 最新文献

IEEE journal on selected areas in communications : a publication of the IEEE Communications Society最新文献

英文 中文
DedupChain: A Secure Blockchain-Enabled Storage System With Deduplication for Zero-Trust Network DedupChain:零信任网络中支持重复数据删除的安全区块链存储系统
Saiyu Qi;Qiuhao Wang;Wei Wei;Xu Yang;Hongguang Zhao;Yuhao Liu;Xu Yang;Yong Qi
Permissioned blockchain is a promising methodology to build zero-trust storage foundation with trusted data storage and sharing for the zero-trust network. However, the inherent full-backup feature of the permissioned blockchain poses potential data privacy risks and substantial storage costs, hindering its usage as a storage medium. These issues necessitate the usage of secure data deduplication technology to mitigate them. Unfortunately, current secure data deduplication schemes are predominantly designed with centralized cloud servers in mind and are not suitable for distributed blockchain systems. The reason is that the full backup feature of the permissioned blockchain renders a wide attack surface to offline brute-force and frequency analysis attacks. In response, we propose DedupChain, a secure blockchain-enabled storage system with deduplication for zero-trust networks. DedupChain employs a trusted execution environment (i.e., Inter SGX enclave) in conjunction with Oblivious RAM (ORAM) to offer a novel security guarantee named oblivious data deduplication, which empowers DedupChain with the ability to defend offline brute-force and frequency analysis attacks. DedupChain also proposes several novel techniques to address the security and efficiency issues raised by the SGX enclave. We implemented a system prototype of DedupChain and evaluated its performance metrics. Our experimental results show that DedupChain exhibits satisfactory operational delays, throughput, and storage overhead. Security analysis shows that DedupChain is robust enough to withstand several types of attacks. To the best of our knowledge, we are the first to apply secure data deduplication techniques to address data privacy and storage cost issues raised by permissioned blockchain when used as a zero-trust storage medium.
通过可信数据的存储和共享,为零信任网络构建零信任存储基础是一种很有前途的方法。但由于区块链具有完全备份的特性,存在潜在的数据隐私风险和高昂的存储成本,限制了区块链作为存储介质的使用。这些问题需要使用安全的重复数据删除技术来缓解。不幸的是,目前的安全重复数据删除方案主要是针对集中式云服务器设计的,不适合分布式区块链系统。这是由于区块链的全备份特性,为离线暴力攻击和频率分析攻击提供了广阔的攻击面。作为回应,我们提出了DedupChain,这是一种安全的区块链存储系统,用于零信任网络的重复数据删除。DedupChain采用可信的执行环境(即,Inter SGX enclave)与遗忘RAM (ORAM)相结合,提供一种名为遗忘重复数据删除的新型安全保证,使DedupChain能够抵御离线暴力破解和频率分析攻击。DedupChain还提出了一些新技术来解决新加坡交易所飞地提出的安全和效率问题。我们实现了DedupChain的系统原型,并评估了其性能指标。实验结果表明,DedupChain具有令人满意的操作延迟、吞吐量和存储开销。安全分析表明,DedupChain足够强大,可以抵御多种类型的攻击。据我们所知,我们是第一个应用安全的重复数据删除技术来解决被允许的区块链作为零信任存储介质使用时产生的数据隐私和存储成本问题的公司。
{"title":"DedupChain: A Secure Blockchain-Enabled Storage System With Deduplication for Zero-Trust Network","authors":"Saiyu Qi;Qiuhao Wang;Wei Wei;Xu Yang;Hongguang Zhao;Yuhao Liu;Xu Yang;Yong Qi","doi":"10.1109/JSAC.2025.3560043","DOIUrl":"10.1109/JSAC.2025.3560043","url":null,"abstract":"Permissioned blockchain is a promising methodology to build zero-trust storage foundation with trusted data storage and sharing for the zero-trust network. However, the inherent full-backup feature of the permissioned blockchain poses potential data privacy risks and substantial storage costs, hindering its usage as a storage medium. These issues necessitate the usage of secure data deduplication technology to mitigate them. Unfortunately, current secure data deduplication schemes are predominantly designed with centralized cloud servers in mind and are not suitable for distributed blockchain systems. The reason is that the full backup feature of the permissioned blockchain renders a wide attack surface to offline brute-force and frequency analysis attacks. In response, we propose DedupChain, a secure blockchain-enabled storage system with deduplication for zero-trust networks. DedupChain employs a trusted execution environment (i.e., Inter SGX enclave) in conjunction with Oblivious RAM (ORAM) to offer a novel security guarantee named oblivious data deduplication, which empowers DedupChain with the ability to defend offline brute-force and frequency analysis attacks. DedupChain also proposes several novel techniques to address the security and efficiency issues raised by the SGX enclave. We implemented a system prototype of DedupChain and evaluated its performance metrics. Our experimental results show that DedupChain exhibits satisfactory operational delays, throughput, and storage overhead. Security analysis shows that DedupChain is robust enough to withstand several types of attacks. To the best of our knowledge, we are the first to apply secure data deduplication techniques to address data privacy and storage cost issues raised by permissioned blockchain when used as a zero-trust storage medium.","PeriodicalId":73294,"journal":{"name":"IEEE journal on selected areas in communications : a publication of the IEEE Communications Society","volume":"43 6","pages":"2070-2086"},"PeriodicalIF":0.0,"publicationDate":"2025-04-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"143836711","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
SRv6 and Zero-Trust Policy Enabled Graph Convolutional Neural Networks for Slicing Network Optimization 基于SRv6和零信任策略的图卷积神经网络切片网络优化
Xin Wang;Bo Yi;Qing Li;Shahid Mumtaz;Jianhui Lv
With the rapid advancement of technologies such as B5G/6G and edge computing, network scenarios are becoming increasingly complex and diverse, leading to the emergence of slicing networks. Virtualizing applications into distinct categories and establishing corresponding network slices ensures performance to a certain extent. However, the challenges posed by the complex slicing environment demand more fine-grained routing control and higher costs to locate requested content or services, areas where current state-of-the-art methods fall short. To address these challenges, this work introduces a system framework that integrates the principles of Segment Routing over IPv6 (SRv6). An SRv6 optimization layer is created between the control and infrastructure layers to manage slices effectively and enhance routing control. Additionally, we propose a novel policy routing method based on zero-trust and Graph Convolutional Network (GCN) technology. This method transforms actions into policies that can be flexibly deployed on SRv6 nodes, segment by segment. These actions encompass both routing and security measures, allowing for dynamic and flexible deployment of policies on each segment to achieve the desired goals. This integration of segment routing and zero-trust principles simplifies implementation and enhances security. Comprehensive experiments were conducted to evaluate the proposed method. The results demonstrate significant improvements over state-of-the-art methods, including a higher service acceptance rate, better resource utilization, and reduced average latency and packet loss rate.
随着B5G/6G、边缘计算等技术的快速发展,网络场景日益复杂多样,切片网络应运而生。将应用虚拟化成不同的类别,并建立相应的网络片,可以在一定程度上保证性能。然而,复杂的切片环境带来的挑战需要更细粒度的路由控制和更高的成本来定位所请求的内容或服务,这是目前最先进的方法所无法达到的。为了应对这些挑战,本工作引入了一个集成了IPv6分段路由(SRv6)原理的系统框架。在控制层和基础设施层之间创建了一个SRv6优化层,以有效地管理片并增强路由控制。此外,我们提出了一种新的基于零信任和图卷积网络(GCN)技术的策略路由方法。该方法将动作转换为策略,可以灵活地在SRv6节点上进行分段部署。这些操作包括路由和安全措施,允许在每个段上动态和灵活地部署策略,以实现预期的目标。这种段路由和零信任原则的集成简化了实现并增强了安全性。通过综合实验对该方法进行了评价。结果表明,与最先进的方法相比,该方法有了显著的改进,包括更高的服务接受率、更好的资源利用率以及更低的平均延迟和丢包率。
{"title":"SRv6 and Zero-Trust Policy Enabled Graph Convolutional Neural Networks for Slicing Network Optimization","authors":"Xin Wang;Bo Yi;Qing Li;Shahid Mumtaz;Jianhui Lv","doi":"10.1109/JSAC.2025.3560000","DOIUrl":"10.1109/JSAC.2025.3560000","url":null,"abstract":"With the rapid advancement of technologies such as B5G/6G and edge computing, network scenarios are becoming increasingly complex and diverse, leading to the emergence of slicing networks. Virtualizing applications into distinct categories and establishing corresponding network slices ensures performance to a certain extent. However, the challenges posed by the complex slicing environment demand more fine-grained routing control and higher costs to locate requested content or services, areas where current state-of-the-art methods fall short. To address these challenges, this work introduces a system framework that integrates the principles of Segment Routing over IPv6 (SRv6). An SRv6 optimization layer is created between the control and infrastructure layers to manage slices effectively and enhance routing control. Additionally, we propose a novel policy routing method based on zero-trust and Graph Convolutional Network (GCN) technology. This method transforms actions into policies that can be flexibly deployed on SRv6 nodes, segment by segment. These actions encompass both routing and security measures, allowing for dynamic and flexible deployment of policies on each segment to achieve the desired goals. This integration of segment routing and zero-trust principles simplifies implementation and enhances security. Comprehensive experiments were conducted to evaluate the proposed method. The results demonstrate significant improvements over state-of-the-art methods, including a higher service acceptance rate, better resource utilization, and reduced average latency and packet loss rate.","PeriodicalId":73294,"journal":{"name":"IEEE journal on selected areas in communications : a publication of the IEEE Communications Society","volume":"43 6","pages":"2279-2292"},"PeriodicalIF":0.0,"publicationDate":"2025-04-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"143836720","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Tackling Distribution Shifts in Task-Oriented Communication With Information Bottleneck 基于信息瓶颈的任务通信分布转移问题研究
Hongru Li;Jiawei Shao;Hengtao He;Shenghui Song;Jun Zhang;Khaled B. Letaief
Task-oriented communication aims to extract and transmit task-relevant information to significantly reduce the communication overhead and transmission latency. However, the unpredictable distribution shifts between training and test data, including domain shift and semantic shift, can dramatically undermine the system performance. In order to tackle these challenges, it is crucial to ensure that the encoded features can generalize to domain-shifted data and detect semantic-shifted data, while remaining compact for transmission. In this paper, we propose a novel approach based on the information bottleneck (IB) principle and invariant risk minimization (IRM) framework. The proposed method aims to extract compact and informative features that possess high capability for effective domain-shift generalization and accurate semantic-shift detection without any knowledge of the test data during training. Specifically, we propose an invariant feature encoding approach based on the IB principle and IRM framework for domain-shift generalization, which aims to find the causal relationship between the input data and task result by minimizing the complexity and domain dependence of the encoded feature. Furthermore, we enhance the task-oriented communication with the label-dependent feature encoding approach for semantic-shift detection which achieves joint gains in IB optimization and detection performance. To avoid the intractable computation of the IB-based objective, we leverage variational approximation to derive a tractable upper bound for optimization. Extensive simulation results on image classification tasks demonstrate that the proposed scheme outperforms state-of-the-art approaches and achieves a better rate-distortion tradeoff.
面向任务的通信旨在提取和传输与任务相关的信息,以显著降低通信开销和传输延迟。然而,训练数据和测试数据之间不可预测的分布变化,包括领域变化和语义变化,会极大地破坏系统的性能。为了应对这些挑战,确保编码特征能够推广到领域转移数据并检测语义转移数据,同时保持传输的紧凑性至关重要。在本文中,我们提出了一种基于信息瓶颈(IB)原理和不变风险最小化(IRM)框架的新方法。该方法的目的是在训练过程中不需要了解测试数据的情况下,提取出紧凑且信息量大的特征,这些特征具有高效的域漂移泛化和准确的语义漂移检测能力。具体而言,我们提出了一种基于IB原理和IRM框架的不变特征编码方法,用于域移位泛化,旨在通过最小化编码特征的复杂性和域依赖性来寻找输入数据与任务结果之间的因果关系。此外,我们使用标签相关特征编码方法增强面向任务的通信,用于语义移位检测,从而实现IB优化和检测性能的联合增益。为了避免基于ibc的目标难以处理的计算,我们利用变分逼近来推导一个易于处理的优化上界。对图像分类任务的大量仿真结果表明,所提出的方案优于目前最先进的方法,并实现了更好的率失真权衡。
{"title":"Tackling Distribution Shifts in Task-Oriented Communication With Information Bottleneck","authors":"Hongru Li;Jiawei Shao;Hengtao He;Shenghui Song;Jun Zhang;Khaled B. Letaief","doi":"10.1109/JSAC.2025.3559116","DOIUrl":"10.1109/JSAC.2025.3559116","url":null,"abstract":"Task-oriented communication aims to extract and transmit task-relevant information to significantly reduce the communication overhead and transmission latency. However, the <italic>unpredictable</i> distribution shifts between training and test data, including <italic>domain shift</i> and <italic>semantic shift</i>, can dramatically undermine the system performance. In order to tackle these challenges, it is crucial to ensure that the encoded features can generalize to <italic>domain-shifted</i> data and detect <italic>semantic-shifted</i> data, while remaining compact for transmission. In this paper, we propose a novel approach based on the information bottleneck (IB) principle and invariant risk minimization (IRM) framework. The proposed method aims to extract compact and informative features that possess high capability for effective <italic>domain-shift generalization</i> and accurate <italic>semantic-shift detection</i> without any knowledge of the test data during training. Specifically, we propose an invariant feature encoding approach based on the IB principle and IRM framework for <italic>domain-shift</i> generalization, which aims to find the causal relationship between the input data and task result by minimizing the complexity and domain dependence of the encoded feature. Furthermore, we enhance the task-oriented communication with the label-dependent feature encoding approach for <italic>semantic-shift detection</i> which achieves joint gains in IB optimization and detection performance. To avoid the intractable computation of the IB-based objective, we leverage variational approximation to derive a tractable upper bound for optimization. Extensive simulation results on image classification tasks demonstrate that the proposed scheme outperforms state-of-the-art approaches and achieves a better rate-distortion tradeoff.","PeriodicalId":73294,"journal":{"name":"IEEE journal on selected areas in communications : a publication of the IEEE Communications Society","volume":"43 7","pages":"2667-2683"},"PeriodicalIF":0.0,"publicationDate":"2025-04-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=10964522","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"143836716","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"OA","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Decentralized Federated Graph Learning With Lightweight Zero Trust Architecture for Next-Generation Networking Security 面向下一代网络安全的轻量级零信任架构的去中心化联邦图学习
Xiaokang Zhou;Wei Liang;Kevin I-Kai Wang;Katsutoshi Yada;Laurence T. Yang;Jianhua Ma;Qun Jin
The rapid development and usage of digital technologies in modern intelligent systems and applications bring critical challenges on data security and privacy. It is essential to allow cross-organizational data sharing to achieve smart service provisioning, while preventing unauthorized access and data leak to ensure end users’ efficient and secure collaborations. Federated Learning (FL) offers a promising pathway to enable innovative collaboration across multiple organizations. However, more stringent security policies are needed to ensure authenticity of participating entities, safeguard data during communication, and prevent malicious activities. In this paper, we propose a Decentralized Federated Graph Learning (FGL) with Lightweight Zero Trust Architecture (ZTA) model, named DFGL-LZTA, to provide context-aware security with dynamic defense policy update, while maintaining computational and communication efficiency in resource-constrained environments, for highly distributed and heterogeneous systems in next-generation networking. Specifically, with a re-designed lightweight ZTA, which leverages adaptive privacy preservation and reputation-based aggregation together to tackle multi-level security threats (e.g., data-level, model-level, and identity-level attacks), a Proximal Policy Optimization (PPO) based Deep Reinforcement Learning (DRL) agent is introduced to enable the real-time and adaptive security policy update and optimization based on contextual features. A hierarchical Graph Attention Network (GAT) mechanism is then improved and applied to facilitate the dynamic subgraph learning in local training with a layer-wise architecture, while a so-called sparse global aggregation scheme is developed to balance the communication efficiency and model robustness in a P2P manner. Experiments and evaluations conducted based on two open-source datasets and one synthetic dataset demonstrate the usefulness of our proposed model in terms of training performance, computational and communication efficiency, and model accuracy, compared with other four state-of-the-art methods for next-generation networking security in modern distributed learning systems.
数字技术在现代智能系统和应用中的快速发展和使用给数据安全和隐私带来了严峻的挑战。必须允许跨组织数据共享以实现智能服务供应,同时防止未经授权的访问和数据泄漏,以确保最终用户的高效和安全协作。联邦学习(FL)为实现跨多个组织的创新协作提供了一条很有前途的途径。但是,需要更严格的安全策略来确保参与实体的真实性,保护通信过程中的数据,防止恶意活动。在本文中,我们提出了一种具有轻量级零信任体系结构(ZTA)模型的分散联邦图学习(FGL),命名为DFGL-LZTA,为下一代网络中的高度分布式和异构系统提供具有动态防御策略更新的上下文感知安全性,同时保持资源受限环境中的计算和通信效率。具体而言,通过重新设计的轻量级ZTA,利用自适应隐私保护和基于声誉的聚合来共同应对多层次安全威胁(例如,数据级,模型级和身份级攻击),引入基于近端策略优化(PPO)的深度强化学习(DRL)代理,以实现基于上下文特征的实时和自适应安全策略更新和优化。改进了分层图注意网络(GAT)机制,采用分层结构实现局部训练中的动态子图学习;提出了稀疏全局聚合方案,在P2P模式下平衡通信效率和模型鲁棒性。基于两个开源数据集和一个合成数据集进行的实验和评估表明,与现代分布式学习系统中下一代网络安全的其他四种最先进的方法相比,我们提出的模型在训练性能、计算和通信效率以及模型准确性方面具有实用性。
{"title":"Decentralized Federated Graph Learning With Lightweight Zero Trust Architecture for Next-Generation Networking Security","authors":"Xiaokang Zhou;Wei Liang;Kevin I-Kai Wang;Katsutoshi Yada;Laurence T. Yang;Jianhua Ma;Qun Jin","doi":"10.1109/JSAC.2025.3560012","DOIUrl":"10.1109/JSAC.2025.3560012","url":null,"abstract":"The rapid development and usage of digital technologies in modern intelligent systems and applications bring critical challenges on data security and privacy. It is essential to allow cross-organizational data sharing to achieve smart service provisioning, while preventing unauthorized access and data leak to ensure end users’ efficient and secure collaborations. Federated Learning (FL) offers a promising pathway to enable innovative collaboration across multiple organizations. However, more stringent security policies are needed to ensure authenticity of participating entities, safeguard data during communication, and prevent malicious activities. In this paper, we propose a Decentralized Federated Graph Learning (FGL) with Lightweight Zero Trust Architecture (ZTA) model, named DFGL-LZTA, to provide context-aware security with dynamic defense policy update, while maintaining computational and communication efficiency in resource-constrained environments, for highly distributed and heterogeneous systems in next-generation networking. Specifically, with a re-designed lightweight ZTA, which leverages adaptive privacy preservation and reputation-based aggregation together to tackle multi-level security threats (e.g., data-level, model-level, and identity-level attacks), a Proximal Policy Optimization (PPO) based Deep Reinforcement Learning (DRL) agent is introduced to enable the real-time and adaptive security policy update and optimization based on contextual features. A hierarchical Graph Attention Network (GAT) mechanism is then improved and applied to facilitate the dynamic subgraph learning in local training with a layer-wise architecture, while a so-called sparse global aggregation scheme is developed to balance the communication efficiency and model robustness in a P2P manner. Experiments and evaluations conducted based on two open-source datasets and one synthetic dataset demonstrate the usefulness of our proposed model in terms of training performance, computational and communication efficiency, and model accuracy, compared with other four state-of-the-art methods for next-generation networking security in modern distributed learning systems.","PeriodicalId":73294,"journal":{"name":"IEEE journal on selected areas in communications : a publication of the IEEE Communications Society","volume":"43 6","pages":"1908-1922"},"PeriodicalIF":0.0,"publicationDate":"2025-04-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"143836715","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Dynamic Security Computing Framework With Zero Trust Based on Privacy Domain Prevention and Control Theory 基于隐私域防控理论的零信任动态安全计算框架
Xiang Wu;Baowen Zou;Chuanchuan Lu;Lili Wang;Yongting Zhang;Huanhuan Wang
With a growing security threat in wireless communication networks, a promising method for secure next-generation networks is a zero-trust framework focusing on authentication schemes. How to analyze the risks involved in authentication is a challenge. This study quantifies authentication risks within the zero-trust framework and introduces a privacy domain prevention-control theory. The theory encompasses dynamic privacy risk assessment, intelligent risk classification, and automated selection of privacy protection schemes. First, a dynamic privacy risk assessment method, based on physical entity relationships, is proposed to evaluate all privacy risks. Second, a five-category risk classification method is designed to categorize privacy risks, facilitating the selection of prevention-control schemes, with its rationality mathematically validated. Additionally, an Analytical Hierarchy Process (AHP)-based method is introduced to guide the optimal selection of prevention-control schemes for various scenarios. Finally, the practical application of the theory in medicine multi-modal computing scene of wireless body area networks demonstrates its effectiveness. The experimental results also show the superiority and feasibility of the proposed methods.
随着无线通信网络的安全威胁日益严重,以认证方案为重点的零信任框架是下一代网络安全的一种很有前途的方法。如何分析身份验证中涉及的风险是一个挑战。本文量化了零信任框架下的认证风险,并引入了隐私域预防控制理论。该理论包括动态隐私风险评估、智能风险分类和隐私保护方案的自动选择。首先,提出了一种基于物理实体关系的动态隐私风险评估方法,对所有隐私风险进行评估。其次,设计了一种五类风险分类方法对隐私风险进行分类,方便了防控方案的选择,并对其合理性进行了数学验证。此外,还引入了基于层次分析法(AHP)的预防控制方案优化选择方法。最后,将该理论应用于医学无线体域网络的多模态计算场景,验证了其有效性。实验结果也证明了该方法的优越性和可行性。
{"title":"Dynamic Security Computing Framework With Zero Trust Based on Privacy Domain Prevention and Control Theory","authors":"Xiang Wu;Baowen Zou;Chuanchuan Lu;Lili Wang;Yongting Zhang;Huanhuan Wang","doi":"10.1109/JSAC.2025.3560036","DOIUrl":"10.1109/JSAC.2025.3560036","url":null,"abstract":"With a growing security threat in wireless communication networks, a promising method for secure next-generation networks is a zero-trust framework focusing on authentication schemes. How to analyze the risks involved in authentication is a challenge. This study quantifies authentication risks within the zero-trust framework and introduces a privacy domain prevention-control theory. The theory encompasses dynamic privacy risk assessment, intelligent risk classification, and automated selection of privacy protection schemes. First, a dynamic privacy risk assessment method, based on physical entity relationships, is proposed to evaluate all privacy risks. Second, a five-category risk classification method is designed to categorize privacy risks, facilitating the selection of prevention-control schemes, with its rationality mathematically validated. Additionally, an Analytical Hierarchy Process (AHP)-based method is introduced to guide the optimal selection of prevention-control schemes for various scenarios. Finally, the practical application of the theory in medicine multi-modal computing scene of wireless body area networks demonstrates its effectiveness. The experimental results also show the superiority and feasibility of the proposed methods.","PeriodicalId":73294,"journal":{"name":"IEEE journal on selected areas in communications : a publication of the IEEE Communications Society","volume":"43 6","pages":"2266-2278"},"PeriodicalIF":0.0,"publicationDate":"2025-04-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"143836721","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Building a Zero Trust Federation 建立零信任联盟
Alexandre Poirrier;Laurent Cailleux;Thomas Heide Clausen
Zero trust is a security paradigm whose fundamental philosophy is that every access to a resource must be explicitly verified, without assuming trust based on origin or identity. In a federated environment composed of multiple domains, ensuring zero trust guarantees for accessing shared resources is a challenge, as information on requesters is generated by their originating domain, yet requires explicit verification from the domain owning the resource. This paper proposes a method for federating zero trust architectures, ensuring the preservation of zero trust guarantees when accessing federated resources. The proposed approach relies on remote attestation, enabling continuous authentication and monitoring of requesters, without requiring intrusive software installations on every device within the federation. Moreover, this paper proposes a proof-of-concept architecture that combines several open-source products, to build an architecture with advanced zero trust maturity level. The feasibility of the proposed federation method is demonstrated through this proof-of-concept, providing detailed information on the federation procedure and its implementation.
零信任是一种安全范式,其基本理念是必须显式验证对资源的每次访问,而不假设基于来源或身份的信任。在由多个域组成的联邦环境中,确保访问共享资源的零信任保证是一项挑战,因为有关请求者的信息是由它们的原始域生成的,但需要从拥有资源的域进行显式验证。本文提出了一种联合零信任体系结构的方法,以确保在访问联合资源时保持零信任保证。所建议的方法依赖于远程认证,支持对请求者的持续身份验证和监视,而不需要在联邦内的每个设备上安装侵入性软件。此外,本文还提出了一种结合多个开源产品的概念验证体系结构,以构建具有高级零信任成熟度的体系结构。通过概念验证证明了所提出的联合方法的可行性,并提供了有关联合过程及其实现的详细信息。
{"title":"Building a Zero Trust Federation","authors":"Alexandre Poirrier;Laurent Cailleux;Thomas Heide Clausen","doi":"10.1109/JSAC.2025.3560014","DOIUrl":"10.1109/JSAC.2025.3560014","url":null,"abstract":"Zero trust is a security paradigm whose fundamental philosophy is that every access to a resource must be explicitly verified, without assuming trust based on origin or identity. In a federated environment composed of multiple domains, ensuring zero trust guarantees for accessing shared resources is a challenge, as information on requesters is generated by their originating domain, yet requires explicit verification from the domain owning the resource. This paper proposes a method for federating zero trust architectures, ensuring the preservation of zero trust guarantees when accessing federated resources. The proposed approach relies on remote attestation, enabling continuous authentication and monitoring of requesters, without requiring intrusive software installations on every device within the federation. Moreover, this paper proposes a proof-of-concept architecture that combines several open-source products, to build an architecture with advanced zero trust maturity level. The feasibility of the proposed federation method is demonstrated through this proof-of-concept, providing detailed information on the federation procedure and its implementation.","PeriodicalId":73294,"journal":{"name":"IEEE journal on selected areas in communications : a publication of the IEEE Communications Society","volume":"43 6","pages":"2113-2125"},"PeriodicalIF":0.0,"publicationDate":"2025-04-14","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"143831759","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Blockchain-Enabled Decentralized Services and Networks: Assessing Roles and Impacts 区块链支持的去中心化服务和网络:评估作用和影响
Xintong Ling;Yuwei Le;Shiyi Chen;Jiaheng Wang;Xiaoyang Zhou
The rapid evolution of blockchain has established it as a critical enabler for decentralized zero-trust services and networks. Without relying on traditional trust mechanisms such as pre-established mutual trust or central authentication, blockchain facilitates trust-free services via smart contract. Smart contracts offer verifiable software trust for various blockchain-enabled services (BESs) while protecting participants’ interests. However, the impact of blockchain on BES remains underexplored and unclear. In this work, we consider a general BES framework suitable for diverse decentralized zero-trust services and assess the role of blockchain in BES. We first build an $M/G/1$ -type queuing model for BES and establish the stability conditions using matrix analytic methods. Based on the stability conditions, we identify the blockchain scalability and server capability as two critical bottlenecks of BES. We further use a tandem queuing model to describe the BES latency of the assembling and service phases. We analytically characterize the properties such as the convexity of service-phase latency with respect to traffic intensity, and highlight the BES pooling effects from traffic offloading and resource sharing. At last, we verify our conclusions through simulations and explore potential pathways for more efficient BES frameworks.
区块链的快速发展使其成为去中心化零信任服务和网络的关键推动者。区块链不依赖传统的信任机制,如预先建立的相互信任或中央认证,通过智能合约促进无信任服务。智能合约为各种支持区块链的服务(BESs)提供可验证的软件信任,同时保护参与者的利益。然而,b区块链对BES的影响仍未得到充分探索和明确。在这项工作中,我们考虑了一个适用于各种分散零信任服务的通用BES框架,并评估了区块链在BES中的作用。首先建立了BES的$M/G/1$型排队模型,并利用矩阵分析法建立了稳定性条件。基于稳定性条件,我们确定区块链可伸缩性和服务器能力是BES的两个关键瓶颈。我们进一步使用串联排队模型来描述装配和服务阶段的BES延迟。我们分析了服务阶段延迟相对于流量强度的凹凸性等特性,并强调了流量卸载和资源共享带来的BES池效应。最后,我们通过模拟验证了我们的结论,并探索了更高效的BES框架的潜在途径。
{"title":"Blockchain-Enabled Decentralized Services and Networks: Assessing Roles and Impacts","authors":"Xintong Ling;Yuwei Le;Shiyi Chen;Jiaheng Wang;Xiaoyang Zhou","doi":"10.1109/JSAC.2025.3560044","DOIUrl":"10.1109/JSAC.2025.3560044","url":null,"abstract":"The rapid evolution of blockchain has established it as a critical enabler for decentralized zero-trust services and networks. Without relying on traditional trust mechanisms such as pre-established mutual trust or central authentication, blockchain facilitates trust-free services via smart contract. Smart contracts offer verifiable software trust for various blockchain-enabled services (BESs) while protecting participants’ interests. However, the impact of blockchain on BES remains underexplored and unclear. In this work, we consider a general BES framework suitable for diverse decentralized zero-trust services and assess the role of blockchain in BES. We first build an <inline-formula> <tex-math>$M/G/1$ </tex-math></inline-formula>-type queuing model for BES and establish the stability conditions using matrix analytic methods. Based on the stability conditions, we identify the blockchain scalability and server capability as two critical bottlenecks of BES. We further use a tandem queuing model to describe the BES latency of the assembling and service phases. We analytically characterize the properties such as the convexity of service-phase latency with respect to traffic intensity, and highlight the BES pooling effects from traffic offloading and resource sharing. At last, we verify our conclusions through simulations and explore potential pathways for more efficient BES frameworks.","PeriodicalId":73294,"journal":{"name":"IEEE journal on selected areas in communications : a publication of the IEEE Communications Society","volume":"43 6","pages":"2141-2154"},"PeriodicalIF":0.0,"publicationDate":"2025-04-14","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"143831720","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Enhancing K-User Interference Alignment for Discrete Constellations via Learning 通过学习加强离散星座的 K 用户干扰对齐
Rajesh Mishra;Syed Jafar;Sriram Vishwanath;Hyeji Kim
In this paper, we consider a K-user interference channel where interference among the users is neither too strong nor too weak, a scenario that is relatively underexplored in the literature. We propose a novel deep learning-based approach to design the encoder and decoder functions that aim to maximize the sumrate of the interference channel for discrete constellations. We first consider the MaxSINR algorithm, a state-of-the-art linear scheme for Gaussian inputs, as the baseline and then propose a modified version of the algorithm for discrete inputs. We then propose a neural network-based approach that learns a non-linear constellation mapping with the objective of maximizing the sumrate. We provide numerical results to show that the constellations learned by the neural network-based approach provide enhanced alignments, not just in beamforming directions but also in terms of the effective constellation at the receiver, thereby leading to improved sum-rate performance.
在本文中,我们考虑了一个k用户干扰通道,其中用户之间的干扰既不太强也不太弱,这是文献中相对较少探索的场景。我们提出了一种新颖的基于深度学习的方法来设计编码器和解码器功能,旨在最大化离散星座的干扰通道的覆盖率。我们首先考虑MaxSINR算法,一种最先进的高斯输入线性方案,作为基线,然后提出离散输入算法的修改版本。然后,我们提出了一种基于神经网络的方法,该方法以最大化sumrate为目标学习非线性星座映射。我们提供的数值结果表明,通过基于神经网络的方法学习的星座提供了增强的对准,不仅在波束形成方向上,而且在接收器的有效星座方面,从而导致改进的和速率性能。
{"title":"Enhancing K-User Interference Alignment for Discrete Constellations via Learning","authors":"Rajesh Mishra;Syed Jafar;Sriram Vishwanath;Hyeji Kim","doi":"10.1109/JSAC.2025.3559122","DOIUrl":"10.1109/JSAC.2025.3559122","url":null,"abstract":"In this paper, we consider a <italic>K</i>-user interference channel where interference among the users is neither too strong nor too weak, a scenario that is relatively underexplored in the literature. We propose a novel deep learning-based approach to design the encoder and decoder functions that aim to maximize the sumrate of the interference channel for discrete constellations. We first consider the MaxSINR algorithm, a state-of-the-art linear scheme for Gaussian inputs, as the baseline and then propose a modified version of the algorithm for discrete inputs. We then propose a neural network-based approach that learns a non-linear constellation mapping with the objective of maximizing the sumrate. We provide numerical results to show that the constellations learned by the neural network-based approach provide enhanced alignments, not just in beamforming directions but also in terms of the effective constellation at the receiver, thereby leading to improved sum-rate performance.","PeriodicalId":73294,"journal":{"name":"IEEE journal on selected areas in communications : a publication of the IEEE Communications Society","volume":"43 7","pages":"2405-2416"},"PeriodicalIF":0.0,"publicationDate":"2025-04-14","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"143831761","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Zero Trust: Deep Learning and NLP for HTTP Anomaly Detection in IDS 零信任:深度学习和 NLP 在 IDS 中用于 HTTP 异常检测
Manh Tien Anh Nguyen;Van Tong;Sondes Bannour Souihi;Sami Souihi
Web applications have become integral to daily life due to the migration of applications and data to cloud-based platforms, increasing their vulnerability to attacks. This paper addresses the need for robust intrusion detection systems by proposing a system grounded in Zero Trust architecture, which mandates continuous monitoring and multi-layered defenses. The Zero Trust principles ensure ongoing threat assessment and comprehensive protection against various attack vectors. Building on these foundational Zero Trust principles, our study introduces a system designed to not only distinguish normal HTTP requests from well-known attack patterns but also detect emerging types of anomalous attacks. Our system consists of two models that integrate Natural Language Processing approaches, Deep Learning techniques, and Transfer Learning strategies. The first model is employed to detect new anomalous HTTP requests that differ from normal requests. HTTP requests identified as anomalous are transmitted to the second model in charge of classifying specific categories of both well-known and novel attacks. Experiments show that our end-to-end system achieves the average F1-score of 89% on the combination of the CAPEC dataset and the zero-shot CSIC dataset. The proposed system proves also to be able to identify anomalous requests with a minimal latency of 4.8 milliseconds in production settings.
由于应用程序和数据迁移到基于云的平台,Web应用程序已成为日常生活中不可或缺的一部分,这增加了它们遭受攻击的脆弱性。本文提出了一种基于零信任架构的系统,该系统要求持续监控和多层防御,从而解决了对健壮的入侵检测系统的需求。零信任原则确保持续的威胁评估和针对各种攻击向量的全面保护。基于这些基本的零信任原则,我们的研究引入了一个系统,该系统不仅可以区分正常的HTTP请求和已知的攻击模式,还可以检测新出现的异常攻击类型。我们的系统由两个模型组成,它们集成了自然语言处理方法、深度学习技术和迁移学习策略。第一个模型用于检测不同于正常请求的新的异常HTTP请求。被识别为异常的HTTP请求被传输到第二个模型,该模型负责对已知和新攻击的特定类别进行分类。实验表明,我们的端到端系统在CAPEC数据集和零射击CSIC数据集的组合上达到了89%的平均f1分数。在生产设置中,所提出的系统还证明能够以4.8毫秒的最小延迟识别异常请求。
{"title":"Zero Trust: Deep Learning and NLP for HTTP Anomaly Detection in IDS","authors":"Manh Tien Anh Nguyen;Van Tong;Sondes Bannour Souihi;Sami Souihi","doi":"10.1109/JSAC.2025.3560040","DOIUrl":"10.1109/JSAC.2025.3560040","url":null,"abstract":"Web applications have become integral to daily life due to the migration of applications and data to cloud-based platforms, increasing their vulnerability to attacks. This paper addresses the need for robust intrusion detection systems by proposing a system grounded in Zero Trust architecture, which mandates continuous monitoring and multi-layered defenses. The Zero Trust principles ensure ongoing threat assessment and comprehensive protection against various attack vectors. Building on these foundational Zero Trust principles, our study introduces a system designed to not only distinguish normal HTTP requests from well-known attack patterns but also detect emerging types of anomalous attacks. Our system consists of two models that integrate Natural Language Processing approaches, Deep Learning techniques, and Transfer Learning strategies. The first model is employed to detect new anomalous HTTP requests that differ from normal requests. HTTP requests identified as anomalous are transmitted to the second model in charge of classifying specific categories of both well-known and novel attacks. Experiments show that our end-to-end system achieves the average F1-score of 89% on the combination of the CAPEC dataset and the zero-shot CSIC dataset. The proposed system proves also to be able to identify anomalous requests with a minimal latency of 4.8 milliseconds in production settings.","PeriodicalId":73294,"journal":{"name":"IEEE journal on selected areas in communications : a publication of the IEEE Communications Society","volume":"43 6","pages":"2215-2229"},"PeriodicalIF":0.0,"publicationDate":"2025-04-14","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"143831760","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Toward Decentralized Operationalization of Zero Trust Architecture for Next Generation Networks 下一代网络零信任架构的去中心化运行研究
Shiva Raj Pokhrel;Gang Li;Robin Doss;Surya Nepal
Next-generation networks demand security that evolves as fast as threats do. Our pioneering decentralized Zero Trust Architecture (dZTA), proposed in this paper, redefines protection for IoT and remote collaboration, merging Zero Trust’s ironclad access controls with blockchain’s transparency and federated learning’s privacy-first analytics. Unlike traditional models, dZTA enforces security at every layer: a distributed policy engine eliminates single points of failure, cross-network analytics optimize WiFi-8, satellite, and 6G performance under real-world stressors, and anti-leakage protocols safeguard IoT ecosystems. Rigorous real-world simulations confirm dZTA’s dual triumph—uncompromising security and seamless efficiency—proving its readiness to secure tomorrow’s hyperconnected world.
下一代网络对安全的要求与威胁的发展速度一样快。我们在论文中提出的开创性的去中心化零信任架构(dZTA)重新定义了物联网和远程协作的保护,将零信任的铁甲访问控制与b区块链的透明度和联邦学习的隐私优先分析相结合。与传统模型不同,dZTA在每一层都加强了安全性:分布式策略引擎消除了单点故障,跨网络分析优化了WiFi-8、卫星和6G在现实压力下的性能,防泄漏协议保护了物联网生态系统。严格的现实世界模拟证实了dZTA的双重胜利-不妥协的安全性和无缝的效率-证明了它准备好保护未来的超连接世界。
{"title":"Toward Decentralized Operationalization of Zero Trust Architecture for Next Generation Networks","authors":"Shiva Raj Pokhrel;Gang Li;Robin Doss;Surya Nepal","doi":"10.1109/JSAC.2025.3560039","DOIUrl":"10.1109/JSAC.2025.3560039","url":null,"abstract":"Next-generation networks demand security that evolves as fast as threats do. Our pioneering decentralized Zero Trust Architecture (dZTA), proposed in this paper, redefines protection for IoT and remote collaboration, merging Zero Trust’s ironclad access controls with blockchain’s transparency and federated learning’s privacy-first analytics. Unlike traditional models, dZTA enforces security at every layer: a distributed policy engine eliminates single points of failure, cross-network analytics optimize WiFi-8, satellite, and 6G performance under real-world stressors, and anti-leakage protocols safeguard IoT ecosystems. Rigorous real-world simulations confirm dZTA’s dual triumph—uncompromising security and seamless efficiency—proving its readiness to secure tomorrow’s hyperconnected world.","PeriodicalId":73294,"journal":{"name":"IEEE journal on selected areas in communications : a publication of the IEEE Communications Society","volume":"43 6","pages":"1998-2010"},"PeriodicalIF":0.0,"publicationDate":"2025-04-11","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"143822834","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
期刊
IEEE journal on selected areas in communications : a publication of the IEEE Communications Society
全部 Acc. Chem. Res. ACS Applied Bio Materials ACS Appl. Electron. Mater. ACS Appl. Energy Mater. ACS Appl. Mater. Interfaces ACS Appl. Nano Mater. ACS Appl. Polym. Mater. ACS BIOMATER-SCI ENG ACS Catal. ACS Cent. Sci. ACS Chem. Biol. ACS Chemical Health & Safety ACS Chem. Neurosci. ACS Comb. Sci. ACS Earth Space Chem. ACS Energy Lett. ACS Infect. Dis. ACS Macro Lett. ACS Mater. Lett. ACS Med. Chem. Lett. ACS Nano ACS Omega ACS Photonics ACS Sens. ACS Sustainable Chem. Eng. ACS Synth. Biol. Anal. Chem. BIOCHEMISTRY-US Bioconjugate Chem. BIOMACROMOLECULES Chem. Res. Toxicol. Chem. Rev. Chem. Mater. CRYST GROWTH DES ENERG FUEL Environ. Sci. Technol. Environ. Sci. Technol. Lett. Eur. J. Inorg. Chem. IND ENG CHEM RES Inorg. Chem. J. Agric. Food. Chem. J. Chem. Eng. Data J. Chem. Educ. J. Chem. Inf. Model. J. Chem. Theory Comput. J. Med. Chem. J. Nat. Prod. J PROTEOME RES J. Am. Chem. Soc. LANGMUIR MACROMOLECULES Mol. Pharmaceutics Nano Lett. Org. Lett. ORG PROCESS RES DEV ORGANOMETALLICS J. Org. Chem. J. Phys. Chem. J. Phys. Chem. A J. Phys. Chem. B J. Phys. Chem. C J. Phys. Chem. Lett. Analyst Anal. Methods Biomater. Sci. Catal. Sci. Technol. Chem. Commun. Chem. Soc. Rev. CHEM EDUC RES PRACT CRYSTENGCOMM Dalton Trans. Energy Environ. Sci. ENVIRON SCI-NANO ENVIRON SCI-PROC IMP ENVIRON SCI-WAT RES Faraday Discuss. Food Funct. Green Chem. Inorg. Chem. Front. Integr. Biol. J. Anal. At. Spectrom. J. Mater. Chem. A J. Mater. Chem. B J. Mater. Chem. C Lab Chip Mater. Chem. Front. Mater. Horiz. MEDCHEMCOMM Metallomics Mol. Biosyst. Mol. Syst. Des. Eng. Nanoscale Nanoscale Horiz. Nat. Prod. Rep. New J. Chem. Org. Biomol. Chem. Org. Chem. Front. PHOTOCH PHOTOBIO SCI PCCP Polym. Chem.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1