Enhancing Property-Based Token Attestation With Homomorphic Encryption (PTA-HE) for Secure Mobile Computing
This paper proposes PTA-HE, an enhanced Property-based Token Attestation scheme integrated with Homomorphic Encryption (HE), specifically designed to address critical security challenges in mobile cloud computing environments. Traditional Property-based Token Attestation (PTA) protocols, although fo...
Saved in:
| Main Authors: | , , |
|---|---|
| Format: | Article |
| Language: | English |
| Published: |
IEEE
2025-01-01
|
| Series: | IEEE Access |
| Subjects: | |
| Online Access: | https://ieeexplore.ieee.org/document/10981763/ |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| Summary: | This paper proposes PTA-HE, an enhanced Property-based Token Attestation scheme integrated with Homomorphic Encryption (HE), specifically designed to address critical security challenges in mobile cloud computing environments. Traditional Property-based Token Attestation (PTA) protocols, although foundational, inherently lack robust mechanisms to secure sensitive data during active processing stages, exposing data to potential confidentiality and integrity breaches. Our main contributions are: the introduction of PTA-HE, which resolves these vulnerabilities by enabling computations directly on encrypted data, ensuring continuous protection and resilience against unauthorized access and manipulation; a strategic employment of Trusted Third Parties (TTPs) for secure attestation management, leveraging HE to maintain data confidentiality throughout the entire attestation workflow; rigorous experimental evaluations quantifying computational overhead, communication costs, latency, and scalability implications, transparently illustrating the performance trade-offs associated with enhanced security; and formal verification using the Scyther tool demonstrating PTA-HE’s superior correctness and robustness against multiple security threats, such as replay and man-in-the-middle attacks. Consequently, PTA-HE provides a highly effective and practical solution for secure mobile computing applications requiring stringent assurances of data privacy and integrity. |
|---|---|
| ISSN: | 2169-3536 |