Mehmood Ul Hassan;Yawar Abbas Bangash;Waseem Iqbal;Abdellah Chehri;Javed Iqbal
{"title":"PRIDA-ME:一种面向元环境的隐私保护、可互操作和分散的身份验证方案","authors":"Mehmood Ul Hassan;Yawar Abbas Bangash;Waseem Iqbal;Abdellah Chehri;Javed Iqbal","doi":"10.1109/OJCOMS.2024.3523518","DOIUrl":null,"url":null,"abstract":"The metaverse is a new virtual world that has the potential to significantly impact our interactions with digital content and with each other. It is a shared virtual environment where users can seamlessly and with immersive experiences create, interact, and enjoy digital assets. Nevertheless, the metaverse also poses fundamental challenges, particularly about security and privacy concerns, that require careful consideration. One of the most daunting aspects of securing the metaverse is authentication. Several solutions have been proposed, including deployment of blockchain technology and smart contracts, to address these authentication challenges. While these methods provide a secure and tamper-proof authentication mechanism, they fail to meet certain critical security and privacy requirements like interoperability and decentralization. This research proposes an enhanced privacy-preserving authentication scheme based on blockchain, elliptic curve cryptography, biohashing, and a physical unclonable function that guards against various attacks. The proposed scheme does not rely on a single central authority and consists of various phases, including user and avatar authentication, password change, and avatar generation phases. The proposed scheme underwent security assessment using the Burrows Abadi Needham (BAN) logic, ProVerif tool, and Scyther tool. The results demonstrate that it provides a better level of security against a wide range of attack vectors. The proposed scheme offers a swift and efficient authentication mechanism that adheres to the requirements of the metaverse environment, such as interoperability, decentralization, and privacy protection, and requires less computation cost as compared to state-of-the-art schemes.","PeriodicalId":33803,"journal":{"name":"IEEE Open Journal of the Communications Society","volume":"6 ","pages":"493-515"},"PeriodicalIF":6.3000,"publicationDate":"2025-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=10819498","citationCount":"0","resultStr":"{\"title\":\"PRIDA-ME: A Privacy-Preserving, Interoperable and Decentralized Authentication Scheme for Metaverse Environment\",\"authors\":\"Mehmood Ul Hassan;Yawar Abbas Bangash;Waseem Iqbal;Abdellah Chehri;Javed Iqbal\",\"doi\":\"10.1109/OJCOMS.2024.3523518\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The metaverse is a new virtual world that has the potential to significantly impact our interactions with digital content and with each other. It is a shared virtual environment where users can seamlessly and with immersive experiences create, interact, and enjoy digital assets. Nevertheless, the metaverse also poses fundamental challenges, particularly about security and privacy concerns, that require careful consideration. One of the most daunting aspects of securing the metaverse is authentication. Several solutions have been proposed, including deployment of blockchain technology and smart contracts, to address these authentication challenges. While these methods provide a secure and tamper-proof authentication mechanism, they fail to meet certain critical security and privacy requirements like interoperability and decentralization. This research proposes an enhanced privacy-preserving authentication scheme based on blockchain, elliptic curve cryptography, biohashing, and a physical unclonable function that guards against various attacks. The proposed scheme does not rely on a single central authority and consists of various phases, including user and avatar authentication, password change, and avatar generation phases. The proposed scheme underwent security assessment using the Burrows Abadi Needham (BAN) logic, ProVerif tool, and Scyther tool. The results demonstrate that it provides a better level of security against a wide range of attack vectors. The proposed scheme offers a swift and efficient authentication mechanism that adheres to the requirements of the metaverse environment, such as interoperability, decentralization, and privacy protection, and requires less computation cost as compared to state-of-the-art schemes.\",\"PeriodicalId\":33803,\"journal\":{\"name\":\"IEEE Open Journal of the Communications Society\",\"volume\":\"6 \",\"pages\":\"493-515\"},\"PeriodicalIF\":6.3000,\"publicationDate\":\"2025-01-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=10819498\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"IEEE Open Journal of the Communications Society\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://ieeexplore.ieee.org/document/10819498/\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q1\",\"JCRName\":\"ENGINEERING, ELECTRICAL & ELECTRONIC\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"IEEE Open Journal of the Communications Society","FirstCategoryId":"1085","ListUrlMain":"https://ieeexplore.ieee.org/document/10819498/","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"ENGINEERING, ELECTRICAL & ELECTRONIC","Score":null,"Total":0}
PRIDA-ME: A Privacy-Preserving, Interoperable and Decentralized Authentication Scheme for Metaverse Environment
The metaverse is a new virtual world that has the potential to significantly impact our interactions with digital content and with each other. It is a shared virtual environment where users can seamlessly and with immersive experiences create, interact, and enjoy digital assets. Nevertheless, the metaverse also poses fundamental challenges, particularly about security and privacy concerns, that require careful consideration. One of the most daunting aspects of securing the metaverse is authentication. Several solutions have been proposed, including deployment of blockchain technology and smart contracts, to address these authentication challenges. While these methods provide a secure and tamper-proof authentication mechanism, they fail to meet certain critical security and privacy requirements like interoperability and decentralization. This research proposes an enhanced privacy-preserving authentication scheme based on blockchain, elliptic curve cryptography, biohashing, and a physical unclonable function that guards against various attacks. The proposed scheme does not rely on a single central authority and consists of various phases, including user and avatar authentication, password change, and avatar generation phases. The proposed scheme underwent security assessment using the Burrows Abadi Needham (BAN) logic, ProVerif tool, and Scyther tool. The results demonstrate that it provides a better level of security against a wide range of attack vectors. The proposed scheme offers a swift and efficient authentication mechanism that adheres to the requirements of the metaverse environment, such as interoperability, decentralization, and privacy protection, and requires less computation cost as compared to state-of-the-art schemes.
期刊介绍:
The IEEE Open Journal of the Communications Society (OJ-COMS) is an open access, all-electronic journal that publishes original high-quality manuscripts on advances in the state of the art of telecommunications systems and networks. The papers in IEEE OJ-COMS are included in Scopus. Submissions reporting new theoretical findings (including novel methods, concepts, and studies) and practical contributions (including experiments and development of prototypes) are welcome. Additionally, survey and tutorial articles are considered. The IEEE OJCOMS received its debut impact factor of 7.9 according to the Journal Citation Reports (JCR) 2023.
The IEEE Open Journal of the Communications Society covers science, technology, applications and standards for information organization, collection and transfer using electronic, optical and wireless channels and networks. Some specific areas covered include:
Systems and network architecture, control and management
Protocols, software, and middleware
Quality of service, reliability, and security
Modulation, detection, coding, and signaling
Switching and routing
Mobile and portable communications
Terminals and other end-user devices
Networks for content distribution and distributed computing
Communications-based distributed resources control.