Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Crypto-agility performance analysis for AIS data sharing confidentiality based on attribute-based encryption
Blekinge Institute of Technology, Faculty of Computing, Department of Computer Science.ORCID iD: 0000-0003-0183-3613
Blekinge Institute of Technology, Faculty of Computing, Department of Computer Science.ORCID iD: 0000-0002-0518-6532
2024 (English)In: CS & IT Conference Proceedings / [ed] D. C. Wyld & D. Nagamalai, AIRCC Publishing Corporation , 2024, Vol. 14, p. 193-212Conference paper, Published paper (Refereed)
Abstract [en]

The research presented in the paper evaluates practices of Attribute-Based Encryption as a key encapsulation mechanism and proposes end-to-end encryption architecture for a cloudbased ship tracking system confidentiality. Though extensively used for efficiently gathering and sharing maritime data, these systems draw information from Automated Identification Systems, ports, and vessels, which can lead to cyber-security vulnerabilities. This paper presents a study addressing the current state of knowledge, methodologies, and challenges associated with supporting cryptographic agility for End-to-End Encryption (E2EE) for AIS data. To study cryptographic agility performance, a new metric has been introduced for cryptographic library analysis that improves the methodology by comparing Attribute-Based Encryption (ABE) with state of the art CRYSTALS-Kyber key encapsulation mechanism (KEM) that belongs to Post-Quantum Cryptography (PQC). A comprehensive series of experiments are undertaken to simulate large-scale cryptographic migration within the proposed system, showcasing the practical applicability of the proposed approach in measuring cryptographic agility performance.

Place, publisher, year, edition, pages
AIRCC Publishing Corporation , 2024. Vol. 14, p. 193-212
Series
Computer Science & Information Technology (CS & IT), E-ISSN 2231-5403
Keywords [en]
AIS ship tracking data, Key encapsulation mechanism, end-to-end encryption, cryptographic agility, CRYSTALS-Kyber, Post-Quantum Cryptography
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:bth-26989DOI: 10.5121/csit.2024.141714OAI: oai:DiVA.org:bth-26989DiVA, id: diva2:1904678
Conference
14th International Conference on Computer Science and Information Technology (CCSIT 2024), Copenhagen Sept 21-22, 2024
Available from: 2024-10-10 Created: 2024-10-10 Last updated: 2025-09-30Bibliographically approved
In thesis
1. Understanding the role of Key Encapsulation Mechanisms in Cryptographic Migrations: Towards Cryptographic-Agility in IoT Systems Based on End-to-End Encryption Approach
Open this publication in new window or tab >>Understanding the role of Key Encapsulation Mechanisms in Cryptographic Migrations: Towards Cryptographic-Agility in IoT Systems Based on End-to-End Encryption Approach
2025 (English)Licentiate thesis, comprehensive summary (Other academic)
Abstract [en]

The increasing data-security regulation and cyber-threats requires IT vendors to use new cryptographic tools or refactor live systems to encrypt existing data. One step in that direction is integrating an appropriate security protocol and cryptographic software library during the system design phase. However, it is not sufficient when it happens to migrate existing data to encrypted form in the live system on-the-fly, re-encrypt data to a different encryption standard, or have the data of the same origin but encrypted with different standards. This thesis explores the new emergent area of cryptographic agility, which focuses on various challenges while adopting cryptographic migrations in live systems. We proposed End-to-End Encryption (E2EE) design for telemetry data security in two different applications: maritime surveillance and drone-management. We aimed to understand the role of Key Encapsulation Mechanism (KEM) cryptographic primitive in the data-security domain. The notion of crypto-agility constitutes a context-sensitive, activity-based perspective on data security. In this thesis, we aim at both understanding and exploring practical possibilities of this notion. We employ a mixed-methods approach to achieve our aim: Experimentation, Literature Review and Survey. We have studied and applied quantum-safe KEM cryptographic primitives to simulate practical cryptographic migration in live IoT systems. We have shown the importance of KEM security properties and the performance of KEM primitives for telemetry data confidentiality. We proposed new crypto-agility values and trade offs as decision making support tool for consumers of cryptographic technologies. Furthermore, we have employed systematization of knowledge to structure how different types of contributions developed various KEM notions, its influence on the standardization process, and presence in cryptographic software libraries over the last 40 years. The proposed approaches have been shown to be capable of explaining the role of KEM in cryptographic migrations and underlying properties of crypto agility. This can facilitate domain experts in narrowing down the scope of analysis while achieving sufficiency for cryptographic migrations in live IoT systems based on end-to-end encryption protocols.

Place, publisher, year, edition, pages
Karlskrona: Blekinge Tekniska Högskola, 2025. p. 160
Series
Blekinge Institute of Technology Licentiate Dissertation Series, ISSN 1650-2140 ; 2025:04
Keywords
Cryptographic agility, end-to-end encryption, application-level encryption, key-encapsulation mechanism
National Category
Security, Privacy and Cryptography
Research subject
Computer Science
Identifiers
urn:nbn:se:bth-27713 (URN)978-91-7295-498-4 (ISBN)
Presentation
2025-09-24, J1630, Campus Karlskrona, 10:00 (English)
Opponent
Supervisors
Projects
Connect2SmallPorts
Available from: 2025-04-11 Created: 2025-04-11 Last updated: 2025-09-30Bibliographically approved

Open Access in DiVA

fulltext(364 kB)177 downloads
File information
File name FULLTEXT01.pdfFile size 364 kBChecksum SHA-512
8787214c783a9aeb7fc354e749902f81e99a85bcb9cc16f2c234a96cb30da653f9ef217a3761e42ea59ad34fb0b7208ad843dcf54f88c87ccaabf8b1e17ef896
Type fulltextMimetype application/pdf

Other links

Publisher's full text

Authority records

Silonosov, AlexandrHenesey, Lawrence

Search in DiVA

By author/editor
Silonosov, AlexandrHenesey, Lawrence
By organisation
Department of Computer Science
Computer Sciences

Search outside of DiVA

GoogleGoogle Scholar
Total: 178 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

doi
urn-nbn

Altmetric score

doi
urn-nbn
Total: 660 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf