Most Read articles

    Published in last 1 year |  In last 2 years |  In last 3 years |  All

    In last 2 years
    Please wait a minute...
    For Selected: Toggle Thumbnails
    Journal of Information Security Reserach    2025, 11 (E2): 277-.  
    Abstract (1036)      PDF (1198KB)(16)       Save
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2025, 11 (E1): 19-.  
    Abstract (860)      PDF (1799KB)(27)       Save
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2025, 11 (E2): 80-.  
    Abstract (818)      PDF (1807KB)(24)       Save
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 105-.  
    Abstract (811)      PDF (929KB)(407)       Save
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 59-.  
    Abstract (735)      PDF (1210KB)(107)       Save
    Reference | Related Articles | Metrics
    A Federated Learning Privacy Protection Method for Multikey Homomorphic  Encryption in the Internet of Things
    Journal of Information Security Reserach    2024, 10 (10): 958-.  
    Abstract (711)      PDF (1704KB)(254)       Save
    With federated learning, multiple distributed IoT devices can jointly train a global model by updating the transmission model without leaking raw data. However, federated learning systems are susceptible to model inference attacks, resulting in compromised system robustness and data privacy. A federated learning privacy protection method for multikey homomorphic encryption in the Internet of Things is proposed to address the issues of existing federated learning solutions being unable to protect the confidentiality of shared gradients and resisting collusion attacks initiated by clients and servers. This method utilizes multikey homomorphic encryption to achieve gradient update confidentiality protection. Firstly, by using proxy reencryption technology, the ciphertext under different public keys is converted into encrypted data under the public key, ensuring that the cloud server can decrypt the gradient ciphertext. Then, IoT devices use their own public key and random secret factor to encrypt local gradient data, which can resist collusion attacks initiated by malicious devices and servers. Secondly, an identity authentication method based on hybrid cryptography was designed to achieve realtime verification of the identities of participants in federated modeling. In addition, in order to further reduce client computing costs, some decryption calculations are coordinated with trusted servers for computation, and users only need a small amount of computation. A comprehensive analysis was conducted on the proposed solution to evaluate its safety and efficiency. The results indicate that the proposed scheme meets the expected security requirements. Experimental simulation shows that compared to existing schemes, this scheme has lower computational overhead and can achieve faster and more accurate model training.
    Reference | Related Articles | Metrics
    Data Sharing Access Control Method for Distribution Terminal IoT #br# Based on Zero Trust Architecture and Least Privilege Principle#br#
    Journal of Information Security Reserach    2024, 10 (10): 937-.  
    Abstract (582)      PDF (1282KB)(119)       Save
    To maximize the security of IoT data sharing in distribution terminals, a data sharing access control method for distribution terminal IoT based on zero trust architecture and least privilege principle is proposed. We have developed a zerotrustbased IoT data sharing access control framework, which verifies user identity and access control permissions through identity authentication modules. After user access, IDS modules identify obvious network attack behaviors, while behavior trust measurement proxies in user behavior measurement modules, calculate user trust based on historical user behavior measurement data stored in trust measurement databases, and periodically evaluate user behavior trust levels, identify longterm and highly covert network attack behaviors. These proxies also periodically evaluate user behavior trust levels, identify longterm and highly covert network attack behaviors, and use behavioral trustbased access decision agents to allocate user roles based on the user trust level and the principle of least privilege, formulating and implementing access decisions. The IoT controller dynamically adjusts user resource access permissions based on trust measurement results, and achieves dynamic adjustment of user distribution terminal IoT resource access permissions by sending flow tables. The experimental results show that this method can accurately control the shared access of IoT data, and has more comprehensive performance. It has the least redundant permissions while completing user access tasks, which not only meets user access requirements but also ensures network data security.
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 7-.  
    Abstract (521)      PDF (1507KB)(131)       Save
    Reference | Related Articles | Metrics
    Research for Zero Trust Security Model
    Journal of Information Security Reserach    2024, 10 (10): 886-.  
    Abstract (518)      PDF (2270KB)(339)       Save
    Zero trust is considered a new security paradigm. From the perspective of security models, this paper reveals the deepening and integration of security models in zero trust architecture, with “identity and data” as the main focus. Zero trust establishes a panoramic control object chain with identity at its core, builds defenseindepth mechanisms around object attributes, functions, and lifecycles, and centrally redirects the flow of information between objects. It integrates information channels to achieve layered protection and finegrained, dynamic access control. Finally, from an attacker’s perspective, it sets up proactive defense mechanisms at key nodes in the information flow path. Since zero trust systems are bound to become highvalue assets, this paper also explores the essential issues of inherent security and resilient service capabilities in zerotrust systems. Through the analysis of the security models embedded in zerotrust and its inherent security, this paper aims to provide a clearer technical development path for the architectural design, technological evolution, and selfprotection of zero trust in its application.
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2025, 11 (E2): 295-.  
    Abstract (504)      PDF (893KB)(23)       Save
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 117-.  
    Abstract (496)      PDF (625KB)(133)       Save
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 27-.  
    Abstract (494)      PDF (763KB)(235)       Save
    Reference | Related Articles | Metrics
    A Trust Framework for Large Language Model Application
    Journal of Information Security Reserach    2024, 10 (12): 1153-.  
    Abstract (476)      PDF (1420KB)(277)       Save
    The emergence of large language model has greatly propelled the rapid application of artificial intelligence across various domains. In practice, however, there are a series of security and trust challenges in the applications of large language models caused by “model hallucinations”. These challenges make it difficult for practical applications to trust and adopt the results returned by the large language models, especially in securityrelated application domains. In many professional fields, we find that there lacks a unified technical framework to ensure the trustworthiness of results returned by large language models, which seriously hinders the application of largescale model technology in professional fields. To address this issue, a largescale model trusted application framework DKCF, integrating sufficient data (D), expertise knowledge (K), intellectual collaboration (C), and efficient feedback (F), is proposed. This framework is developed based on our practical applications in professional fields such as finance, healthcare, and security. We believe that DKCF can shed light on secure and reliable applications of large language models, and facilitate the intellectual revolution across various professional domains.
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 32-.  
    Abstract (446)      PDF (3674KB)(263)       Save
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 54-.  
    Abstract (441)      PDF (1425KB)(193)       Save
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 88-.  
    Abstract (430)      PDF (684KB)(116)       Save
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 230-.  
    Abstract (426)      PDF (3359KB)(143)       Save
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 68-.  
    Abstract (425)      PDF (1105KB)(149)       Save
    Reference | Related Articles | Metrics
    Design of Adversarial Attack Scheme Based on YOLOv8 Object Detector
    Journal of Information Security Reserach    2025, 11 (3): 221-.  
    Abstract (415)      PDF (3519KB)(89)       Save
    Currently, cameras equipped with AI object detection technology are widely used. However, AI object detection models in realworld applications are vulnerable to adversarial attacks. Existing adversarial attack methods, primarily designed for earlier models, are ineffective against the latest YOLOv8 object detector. To address this issue, we propose a novel adversarial patch attack method specifically for the YOLOv8 object detector. This method minimizes confidence output while incorporating an exponential moving average (EMA) attention mechanism to enhance feature extraction during patch generation, thereby improving the attack’s effectiveness. Experimental results demonstrate that our method achieves superior attack performance and transferability. Validation tests, in which the adversarial patches were printed on clothing, also demonstrated excellent attack results, indicating the strong practicality of our proposed method.
    Reference | Related Articles | Metrics
    Overview of Regulation of Crossborder Data Flow
    Journal of Information Security Reserach    2025, 11 (2): 164-.  
    Abstract (412)      PDF (1274KB)(167)       Save
    The development of the digital economy has made crossborder data flow an inevitable trend, and while bringing economic benefits, the security of crossborder data flow cannot be ignored. Due to the complexity of the subjects and scenes involved in the process of crossborder data flow, and the uncontrollability of the process, how to regulate the possible security problems in the process of crossborder data flow has become the focus of the world. So far, there is no unified governance rule system for crossborder data flow in the world, and at the same time, there are huge differences in legislation on crossborder data flow in different countries, which results in the complex situation of legislation on crossborder data flow in the world. This paper describes the current situation of crossborder data flow from the perspectives of laws and regulations, bilateral agreements and standards, and in this way develops horizontal comparisons, sorts out the existing regulatory differences, analyzes the challenges and opportunities China faces under the current trend, and gives reasonable countermeasures.
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 40-.  
    Abstract (402)      PDF (839KB)(182)       Save
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 24-.  
    Abstract (401)      PDF (555KB)(274)       Save
    Reference | Related Articles | Metrics
    A Blockchain Access Control Model for Grain Traceability Based on #br# Zerotrust Mechanism#br#
    Journal of Information Security Reserach    2024, 10 (10): 944-.  
    Abstract (393)      PDF (2180KB)(113)       Save
    Aiming at the problems of malicious access, untrustworthy data sources, and identity forgery in the existing blockchainbased grain traceability model, a blockchain access control model for grain traceability based on a zerotrust mechanism is proposed. Based on the zerotrust security model and the concept of “never trust, always verify”, the blockchain is combined with tokenbased access control (TBAC). Using tokens as credentials to access resources, while introducing user trust analysis, establishing a dynamic and flexible authorization mechanism to achieve finegrained access control. Adding the blockchain smart contract to guarantee the automatic and trustworthy judgment of access control, TBAC is utilized to realize tokenbased access control; secondly, based on the user’s access behavior, Fuzzy Hierarchical Hierarchy Analysis (FAHP) is used so as to obtain the calculation method of the user’s trust value and to design the corresponding access control policy. Experimental results show that the method can correctly and efficiently respond to access requests, and dynamically grant users access rights on the basis of ensuring effective access to grain traceability data, realizing safe and reliable data access control.
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 207-.  
    Abstract (378)      PDF (1123KB)(97)       Save
    Reference | Related Articles | Metrics
    Keytarget Face Recognition Scheme Based on Homomorphic  Encryption and Edge Computing
    Journal of Information Security Reserach    2024, 10 (11): 1004-.  
    Abstract (375)      PDF (2205KB)(107)       Save
    With the promotion of China’s comprehensive national strength and international status, more and more major international events are held in China’s firsttier cities, such as the 31st Chengdu Universiade and the 19th Hangzhou Asian Games. The huge flow of people and complex crowd categories have caused considerable security pressure on the security team. Because the traditional face recognition system realizes face recognition in the central server in plaintext state and relies on the traditional state secret algorithm to ensure security, the computational efficiency and security of the whole system cannot be fully guaranteed. Therefore, based on the CKKS homomorphic encryption scheme and Insightface face recognition algorithm, this paper proposes a keytarget face recognition scheme supporting edge computing. Firstly, the key face features are encrypted by the CKKS homomorphic encryption scheme, and the ciphertext data are distributed to each frontend monitoring device. After that, the frontend monitoring device is responsible for extracting the face features of the scene crowd and calculating the matching degree with the ciphertext database. Finally, the ciphertext calculation results are returned to the central server and decrypted. Experimental results show that the recognition accuracy of the proposed scheme is 98.2116% when the threshold is 1.23 on LFW data sets, which proves the reliability of the proposed scheme.
    Reference | Related Articles | Metrics
    Multifamily Malicious Domain Intrusion Detection Based on #br# Collaborative Attention#br#
    Journal of Information Security Reserach    2024, 10 (12): 115-.  
    Abstract (365)      PDF (1317KB)(193)       Save
    The timely and accurate detection of illegal domain names can effectively prevent the information loss caused by server crashes or unauthorized intrusions. A multifamily malicious domain name intrusion detection method based on collaborative attention is proposed. Firstly, the deep autoencoder network is used to encode and compress layer by layer, extracting the domain name encoding features at the intermediate layer. Secondly, the longdistance and shortdistance encoding features of the domain name string are extracted from the temporal and spatial dimensions, and the selfattention mechanism is constructed on the temporal and spatial encoding feature maps to enhance the expressiveness of the encoding features in local space. Thirdly, the crossattention mechanism is used to establish information interaction between the temporal and spatial encoding features, enhancing the expressiveness of different dimension encoding features in the global space. Finally, the softmax function is used to predict the probability of the domain name to be tested, and quickly determine the legitimacy of the domain name according to the probability value. The results of testing on multiple families of malicious domain name datasets show that the proposed method can achieve a detection accuracy of 0.9876 in the binary classification task of normal and malicious domain names, and an average recognition accuracy of 0.9568 on 16 family datasets. Compared with other classic methods of the same kind, the proposed method achieves the best detection results on multiple evaluation metrics.
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 2-.  
    Abstract (363)      PDF (1381KB)(155)       Save
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 266-.  
    Abstract (342)      PDF (1927KB)(124)       Save
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 187-.  
    Abstract (341)      PDF (779KB)(71)       Save
    Reference | Related Articles | Metrics
    An Optimized Computation Method for Cipher Symbol Functions  Based on Homomorphic Encryption
    Journal of Information Security Reserach    2025, 11 (2): 100-.  
    Abstract (340)      PDF (1092KB)(173)       Save
    Fully homomorphic encryption extends encryption to computations, allowing ciphertext processing without decryption. Comparative operations, crucial in applications like deep learning, pose a challenge in homomorphic encryption environments restricted to addition and multiplication. Feng et al. (CNS 2023) proposed a comparison method using dynamic polynomial combinations. This paper enhances dynamic polynomial, allowing polynomial fluctuations within (-2,2). It introduces a novel equation system for solving dynamic polynomials and utilizes finite third and fifthdegree polynomials to construct more precise composite polynomials for approximating the sign function. It analyzes the method’s optimality in depth consumption and computational complexity, achieving a 32% reduction in runtime compared to the optimal method in a previous study (CNS 2023). The homomorphic comparison algorithm in this paper, for ε=2-20,α=20 requires only 0.69ms in amortized runtime.
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2025, 11 (E2): 197-.  
    Abstract (340)      PDF (815KB)(21)       Save
    Reference | Related Articles | Metrics
    Research on the Development Trend of Cybersecurity Technology
    Journal of Information Security Reserach    2025, 11 (1): 2-.  
    Abstract (333)      PDF (563KB)(162)       Save
    Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 249-.  
    Abstract (327)      PDF (687KB)(102)       Save
    Reference | Related Articles | Metrics
    Blockchainbased Multifactor Crossdomain Authentication Scheme for IoV
    Journal of Information Security Reserach    2024, 10 (11): 1074-.  
    Abstract (323)      PDF (4252KB)(122)       Save
    With the rapid rise in the number and prevalence of vehicular network (IoV) applications and services, the number of users has continuously increased, making the security of the IoV environment a crucial concern. In IoV systems, there is a risk of vehicle information being stolen or tampered with, which further affects the healthy operation of the system. To address this issue, this paper proposes a blockchainbased crossdomain authentication scheme for IoV. By integrating the entire IoV into a consortium blockchain, the trust gap between different domains is effectively resolved. Multifactor authentication of vehicle user information is employed to effectively prevent information leakage and ensure data security. The combination of blockchain and authentication technologies significantly reduces redundant operations in user identity authentication while enabling synchronized queries of IoV information. From a data security perspective, the security analysis demonstrates the feasibility of this scheme.
    Reference | Related Articles | Metrics
    Design and Implementation of Resourceefficient SM4 Algorithm on FPGA
    Journal of Information Security Reserach    2025, 11 (6): 490-.  
    Abstract (322)      PDF (2238KB)(128)       Save
    In the hardware implementation of the SM4 algorithm, the lookup table method is commonly adopted for realizing the Sbox, which consumes a significant amount of hardware resources. This paper proposes an implementation scheme for the SM4 algorithm based on polynomial basis. Two construction schemes are developed for the 8×8 Sbox used in the SM4 algorithm, one based on composite field GF((24)2) and the other on composite field GF(((22)2)2). The test results indicate that the scheme based on polynomial bases GF((24)2) is optimal. Taking into account both resource utilization and performance, this paper designs two hardware implementation structures for SM4: a state machine parallel structure and a pipelined structure. Compared with the traditional lookup table approach, the state machine parallel structure reduces resource utilization by 21.98% while increasing the operating frequency by 14.4%. The pipelined structure achieves a reduction in resource utilization by 54.23%.
    Reference | Related Articles | Metrics
    A Retrospective and Future Development Study of Zero Trust Architecture
    Journal of Information Security Reserach    2024, 10 (10): 896-.  
    Abstract (321)      PDF (1683KB)(157)       Save
    With the rapid development of the internet, big data, and cloud computing, the zero trust architecture has been proposed as a new security paradigm to address the challenges of modern digitalization. This security model is built on never inherently trusting any internal or external requests, emphasizing that access must be granted through constant verification and monitoring. The core principles of zero trust include comprehensive identity verification, access control, least privilege, pervasive encryption, and continuous risk assessment and response. This article primarily reviews the development history of zero trust architecture, elaborates on the basic concepts of the zero zrust mechanism, and finally summarizes the future development of zero trust architecture.
    Reference | Related Articles | Metrics
    A Survey on Backdoor Attacks and Defenses in Federated Learning
    Journal of Information Security Reserach    2025, 11 (9): 778-.  
    Abstract (319)      PDF (2638KB)(85)       Save
    Federated learning is a machine learning framework that enables participants in different fields to participate in largescale centralized model training together under the condition of protecting local data privacy. In the context of addressing the pressing issue of data silos, federated learning has rapidly emerged as a research hotspot. However, the heterogeneity of training data among different participants in federated learning also makes it more vulnerable to model robustness attacks from malicious participants, such as backdoor attacks. Backdoor attacks inject backdoors into the global model by submitting malicious model updates. These backdoors can only be triggered by carefully designed inputs and behave normally when input clean data samples, which poses a great threat to the robustness of the model. This paper presents a comprehensive review of the current backdoor attack methods and backdoor defense strategies in federated learning. Firstly, the concept of federated learning, the main types of backdoor attacks and backdoor defenses and their evaluation metrics were introduced. Then, the main backdoor attacks and defenses were analyzed and compared, and their advantages and disadvantages were pointed out. On this basis, we further discusses the challenges of backdoor attacks and backdoor defenses in federated learning, and prospects their research directions in the future.
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2025, 11 (2): 173-.  
    Abstract (316)      PDF (1383KB)(90)       Save
    With the rapid development of Internet of Things technology, smart cameras are widely used in personal and public safety due to ease of use and low cost. However, the issue of unauthorized video recording also raises concerns about privacy and security, so the detection and identification of hidden smart cameras in specific environments is of great significance. Existing covert smart camera detection methods cannot accurately detect cameras that delay data transmission or save data locally, because these methods rely primarily on camera audio and video network traffic generated when users view surveillance. To solve this problem, this paper proposes a covert intelligent camera detection method based on device WiFi reconnection traffic. The method uses MDK4 flooding attacks to make all smart devices connected to WiFi hotspots offline and reconnect, then sniffs and analyzes the encrypted traffic generated during the process of smart devices reconnecting to WiFi in the environment, and uses machine learning methods to detect hidden smart camera devices. The experimental results show that even without WiFi access, this method still has a high detection accuracy for hidden smart camera devices with delayed transmission or data stored locally.
    Reference | Related Articles | Metrics
    Research on Security Risk and Governance Path of Large Models
    Journal of Information Security Reserach    2024, 10 (10): 975-.  
    Abstract (315)      PDF (1104KB)(229)       Save
    Reference | Related Articles | Metrics
    Research on Multimodal Cyberbullying Detection Model for #br# Social Networking Platforms#br#
    Journal of Information Security Reserach    2025, 11 (2): 154-.  
    Abstract (309)      PDF (2099KB)(74)       Save
    With the rapid development of social networking platforms, the issue of cyberbullying has become increasingly prominent. The diverse forms of online expression that combine text and images have increased the difficulty of detecting and managing cyberbullying. This paper constructs a Chinese multimodal cyberbullying dataset that includes both text and images. By integrating the BERT(bidirectional encoder representations from transformers) model with the ResNet50 model, we extract singlemodal features from text and images, respectively, and perform decisionlevel fusion. The fused features are then detected, achieving accurate identification of text and images as either cyberbullying or noncyberbullying. Experimental results indicate that the multimodal cyberbullying detection model proposed in this paper can effectively identify social media posts or comments that contain cyberbullying characteristics in both text and images. It enhances the practicality, accuracy, and efficiency of detecting multimodal cyberbullying, providing a new approach and method for the detection and management of cyberbullying on social networking platforms. This contributes to the creation of a healthier and more civilized online environment.
    Reference | Related Articles | Metrics