Author
Listed:
- Junaid Akram
(College of the University of New South Wales, University of New South Wales, Kensington, NSW 2033, Australia
School of Computer Science, The University of Sydney, Camperdown, NSW 2008, Australia
Transdisciplinary School, University of Technology Sydney, Camperdown, NSW 2008, Australia)
- Awais Akram
(School of Computing, Korea Advanced Institute of Science and Technology, Daejeon 34141, Republic of Korea)
- Ali Anaissi
(School of Computer Science, The University of Sydney, Camperdown, NSW 2008, Australia
Transdisciplinary School, University of Technology Sydney, Camperdown, NSW 2008, Australia)
Abstract
Smart objects in the Social Internet of Things (SIoT), such as cameras, drones, and vehicles, exchange images that act as visual evidence and drive automated decisions. These images can be altered in their pixels or their metadata, replayed, or injected by unauthorized publishers. Central verification services can check them, but such services must be reachable at verification time, form a bottleneck, and observe who produced which image. This paper presents a decentralized scheme that makes an SIoT image object self-verifiable, so that an intermittently connected verifier can check it offline. Each object binds its image hash, its name, its provenance record, and its source identity in one signature, and it carries its own key documents and authorization chain. Trust anchors are Decentralized Identifiers computed as key thumbprints, so no registry, ledger, or certificate authority is queried during verification. Our central technical point is that a signed hash alone gives only name-bound replay prevention. We therefore add temporal layers that such schemes usually omit: a freshness mechanism with interactive, beacon, and transparency log variants; signed status lists with a proven bounded staleness revocation guarantee; and monotone epochs that resist rollback of rotated keys and documents. We prove the base goals by reduction to signature unforgeability and hash collision resistance under a Dolev–Yao adversary, and we prove the temporal properties as unbounded inductive invariants discharged in Z3. An Ed25519 and SHA-256 implementation verifies a typical image in under two milliseconds with about 1.6 kB of metadata. The evidentiary levels are stated separately and are not interchangeable. The base object is proven, implemented, and measured; the freshness, revocation, and rollback layers are proven but not measured; the pseudonymous mode is design-only. “Self-verifiable” means that provenance is checked cryptographically from the object and one anchor. It does not mean the scheme proves that the captured scene is real, and it is conditional on a preconfigured root identifier and, for the temporal layers, on a status list or time source.
Suggested Citation
Junaid Akram & Awais Akram & Ali Anaissi, 2026.
"Decentralized Self-Verifiable Cryptographic Image Provenance in Social Internet of Things,"
Future Internet, MDPI, vol. 18(8), pages 1-72, July.
Handle:
RePEc:gam:jftint:v:18:y:2026:i:8:p:402-:d:2003683
Download full text from publisher
Corrections
All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:gam:jftint:v:18:y:2026:i:8:p:402-:d:2003683. See general information about how to correct material in RePEc.
If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.
We have no bibliographic references for this item. You can help adding them by using this form .
If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.
For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: MDPI Indexing Manager The email address of this maintainer does not seem to be valid anymore. Please ask MDPI Indexing Manager to update the entry or send us the correct address
(email available below). General contact details of provider: https://www.mdpi.com .
Please note that corrections may take a couple of weeks to filter through
the various RePEc services.