Towards Secure End-To-End Communication using a Nonce Biometric Authentication Code, Based on Iris and Duplicate Steganography
DOI:
https://doi.org/10.56714/bjrs.52.1.16Keywords:
Smart Devices, Iris, Duplicate, Steganography, Nonce Biometric key, nonce MACAbstract
Cloud Computing is the next biggest revolution for research organizations and top-most companies in information technology. But it has run into several security challenges so far. Two main concerns in data security are authentication and integrity, and many interesting works have been proposed to detect or prevent tampering in information transactions between end-to-end smart devices in a cloud environment. This means a robust mechanism to ensure that data is not altered during transfer. We propose a unique Message Authentication Code MAC algorithm in this work, based on duplicate steganography using the discrete wavelet transform, as well as feature matching of the smart device users. The findings from this integration aim to maintain message integrity for all smart device users and protect them from attacks such as insider attacks, forgery, and replay attacks. Next, we describe the realizability of our method through security analysis and demonstrate that it satisfies decisive safety properties such as nonce biometric key management, a user’s nonce biometric key, phase key agreement, message anonymity, resistance against chosen message attack (CMA), data integrity for a smart device user’s message steganography, and a transient MAC session per user. Experimental results demonstrate that the proposed work achieves an execution time of 0.126 seconds that evaluated over 100 runs with 5000 users, and an accuracy 100% when tested on 10,000 users, confirming its efficiency and robustness. Finally, through security analysis and experimental results, we demonstrate and prove that the scheme cannot be compromised by common attacks
Downloads
References
[1] T. Rethika, I. Prathap, R. Anitha, and S. V. Raghavan, “A novel approach to watermark text documents based on eigen values,” in Proc. 9th Int. Conf. Network and Service Security (N2S), Paris, France, Jun. 2009, pp. 1–5.
[2] H. T. Dinh, C. Lee, D. Niyato, and P. Wang, “A survey of mobile cloud computing: Architecture, applications, and approaches,” Wireless Communications and Mobile Computing, vol. 13, no. 18, pp. 1587–1611, 2013, DOI: 10.1002/wcm.1203. DOI: https://doi.org/10.1002/wcm.1203
[3] A. T. Velte, T. J. Velte, and R. Elsenpeter, Cloud Computing: A Practical Approach. New York, NY, USA: McGraw-Hill, 2010, p. 35.
[4] S. Wang, Z. Fan, Y. Su, B. Zheng, Z. Liu, and Y. Dai, “A Lightweight , Efficient , and Physically Secure Key Agreement Authentication Protocol for Vehicular Networks,” 2024. DOI: doi.org/10.3390/electronics13081418. DOI: https://doi.org/10.3390/electronics13081418
[5] Z. Liu, H. S. Lallie, L. Liu, Y. Zhan, and K. Wu, “A hash-based secure interface on plain connection,” in Proc. 6th Int. ICST Conf. Communications and Networking in China (CHINACOM), Harbin, China, Aug. 2011, pp. 1236–1239, DOI: 10.1109/ChinaCom.2011.6158347. DOI: https://doi.org/10.1109/ChinaCom.2011.6158347
[6] Z.-M. Zhao, Y.-F. Liu, H. Li, and Y.-X. Yang, “An efficient user-to-user authentication scheme in peer-to-peer system,” in Proc. 1st Int. Conf. Intelligent Networks and Intelligent Systems (ICINIS), Wuhan, China, Nov. 2008, pp. 263–266, DOI: 10.1109/ICINIS.2008.142. DOI: https://doi.org/10.1109/ICINIS.2008.142
[7] F. Zhang, X. Huang, B. Chen, Y. Huo, and Z. Liu, “Research on the Machinability of Micro-Tapered Hole Group in Piezoelectric Atomizer and the Improvement Method,” 2022, DOI: doi.org/10.3390/s22207891. DOI: https://doi.org/10.3390/s22207891
[8] H. Al-Assam, R. Rashid, and S. Jassim, “Combining steganography and biometric cryptosystems for secure mutual authentication and key exchange,” in Proc. 8th Int. Conf. Internet Technology and Secured Transactions (ICITST), London, U.K., Dec. 2013, pp. 369–374, DOI: 10.1109/ICITST.2013.6750224. DOI: https://doi.org/10.1109/ICITST.2013.6750224
[9] Z. A. Abduljabbar, Z. A. Abduljabbar, and R. J. Mohammed, “Towards nonce biometric-message authentication code in cloud computing,” Journal of Engineering and Applied Sciences, vol. 13, no. 19, 2019.
[10] R. Hossam, F. Heba, M. Yasser, and M. A. El, “A Proposed Biometric Technique for Improving Iris Recognition,” Int. J. Comput. Intell. Syst., pp. 1–11, 2022, DOI: 10.1007/s44196-022-00135-z. DOI: https://doi.org/10.1007/s44196-022-00135-z
[11] V. S. Miller, “Use of elliptic curves in cryptography,” in Advances in Cryptology—CRYPTO ’85, Lecture Notes in Computer Science, vol. 218, Berlin, Germany: Springer, 1986, pp. 417–426, DOI: 10.1007/3-540-39799-X_31. DOI: https://doi.org/10.1007/3-540-39799-X_31
[12] S. Prabhakar, S. Pankanti, and A. K. Jain, “Biometric recognition: Security and privacy concerns,” IEEE Security & Privacy, vol. 1, no. 2, pp. 33–42, Mar./Apr. 2003, DOI: 10.1109/MSECP.2003.1193209. DOI: https://doi.org/10.1109/MSECP.2003.1193206
[13] J. Daugman, “How iris recognition works,” IEEE Trans. Circuits Syst. Video Technol., vol. 14, no. 1, pp. 21–30, Jan. 2004, DOI: 10.1109/TCSVT.2003.818350. DOI: https://doi.org/10.1109/TCSVT.2003.818350
[14] S. Hariprasath and V. Mohan, “Biometric personal identification based on iris recognition using complex wavelet transformations,” in Proc. Int. Conf. Computing, Communication and Networking, St. Thomas, VI, USA, Dec. 2008, pp. 1–5, DOI: 10.1109/ICCCNET.2008.4787736. DOI: https://doi.org/10.1109/ICCCNET.2008.4787736
[15] L. Yu, D. Zhang, and K. Wang, “The relative distance of key point based iris recognition,” Pattern Recognition, vol. 40, no. 2, pp. 423–430, Feb. 2007, DOI: 10.1016/j.patcog.2006.03.008. DOI: https://doi.org/10.1016/j.patcog.2006.03.008
[16] R. L. Rivest, “The MD4 message digest algorithm,” in Advances in Cryptology—CRYPTO ’90, Lecture Notes in Computer Science, vol. 537, Berlin, Germany: Springer, 1991, pp. 303–311. DOI: https://doi.org/10.1007/3-540-38424-3_22
[17] Z. A. Abduljabbar et al., “A robust and efficient authentication protocol for intelligent systems in smart healthcare IoMT,” in 2025 IEEE 24th Int. Conf. Trust, Security and Privacy in Computing and Communications (TrustCom), Guiyang, China, 2025, pp. 1357–1364, DOI: 10.1109/Trustcom66490.2025.00157. DOI: https://doi.org/10.1109/Trustcom66490.2025.00157
[18] I. F. Khazal et al., “Towards secure QR-based message for E2E communication in IoT-cloud,” in Software Engineering: Emerging Trends and Practices in System Development, R. Silhavy and P. Silhavy, Eds., CSOC 2025, Lecture Notes in Networks and Systems, vol. 1560. Cham, Switzerland: Springer, 2025, DOI: 10.1007/978-3-032-00239-6_15. DOI: https://doi.org/10.1007/978-3-032-00239-6_15
[19] P. V. Nadiya and B. M. Imran, “Image steganography in DWT domain using double-stegging with RSA encryption,” in Proc. Int. Conf. Signal Processing, Image Processing & Pattern Recognition (ICSIPR), Coimbatore, India, Feb. 2013, pp. 283–287, DOI: 10.1109/ICSIPR.2013.6497941. DOI: https://doi.org/10.1109/ICSIPR.2013.6497941
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Journal of Basrah Researches (Sciences)

This work is licensed under a Creative Commons Attribution 4.0 International License.
This journal is licensed under the Creative Commons Attribution 4.0 International License (CC BY 4.0).
Under this license, users are permitted to read, download, copy, distribute, print, search, link to the full texts of articles, and create derivative works, including for commercial purposes, provided that appropriate credit is given to the original author(s) and the source.
Authors retain the copyright of their published work, while granting the Journal of Basrah Researches Sciences (JBRS) the right of first publication. Proper attribution must include the article title, author name(s), journal name, DOI, and a link to the Creative Commons license.





