DPCZK: Enhancing Device Privacy Through Certificate-Free Encryption and Zero-Knowledge Proof in Multidomain IoT Environments

Hongmei Ma, Yifan Liu, Yi Liu, Fan Feng, Zhenpeng Liu · IEEE Internet of Things Journal · 2025

The vast number of IoT devices is distributed across multiple trust domains, each with distinct security policies, trust models, and permission management methods. This diversity increases the risk of privacy exposure during cross-domain communications. At the same time, traditional authentication methods have problems, such as complex certificate management, high risk of key escrow, and reliance on trusted third parties. To address the above problems, this article proposes a novel method, enhancing device privacy through certificateless encryption and zero-knowledge proof (DPCZK). DPCZK achieves decentralization by leveraging a consortium blockchain as a trust bridge across different domains. The adoption of certificateless encryption mitigates the incomplete trust issues associated with the key generation center. Furthermore, DPCZK incorporates an identity-hiding mechanism based on zero-knowledge proof, enabling devices to authenticate and interact with resources anonymously during cross-domain operations, thereby safeguarding their privacy. Additionally, through threshold technology, the target domain can reveal the true identities of malicious devices and revoke their access rights, ensuring a balanced approach to security and privacy protection. The proposed scheme has been experimentally validated in a virtual environment and compared with existing solutions. Results demonstrate that DPCZK offers significant improvements in both effectiveness and efficiency.

Read the paper · More papers on PaperTik