<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE ArticleSet PUBLIC "-//NLM//DTD PubMed 2.0//EN" "http://www.ncbi.nlm.nih.gov:80/entrez/query/static/PubMed.dtd">
<ArticleSet>
<Article>
<Journal>
<PublisherName>انجمن رمز ایران</PublisherName>
<JournalTitle>Biannual Journal Monadi for Cyberspace Security (AFTA)</JournalTitle>
<Issn>2476-3047</Issn>
<Volume>13</Volume>
<Issue>1</Issue>
<PubDate PubStatus = "ppublish">
<Year>2024</Year>
<Month>8</Month>
<Day>1</Day>
</PubDate>
</Journal>


	<ArticleTitle>A Survey Of Code-Based Cryptography Schemes and the Standardization Process of Post-Quantum Cryptography: The Beginning of a New Era</ArticleTitle>
	<FirstPage>1</FirstPage>
	<LastPage>14</LastPage>
	<Language>FA</Language>
<AuthorList>
	<Author>
	<FirstName>Arash</FirstName>
	<LastName>Khalvan</LastName>
	<Affiliation>Coding And Cryptography Laboratory, K. N. Toosi University of Technology, Tehran, Iran</Affiliation>
	 </Author>


	<Author>
	<FirstName>Amirhossein</FirstName>
	<LastName>Zali</LastName>
	<Affiliation>Coding And Cryptography Laboratory, K. N. Toosi University of Technology, Tehran, Iran</Affiliation>
	 </Author>


	<Author>
	<FirstName> Mahmoud</FirstName>
	<LastName>Ahmadian Attari</LastName>
	<Affiliation>Faculty of Electrical Engineering, K. N. Toosi University of Technology, Tehran, Iran</Affiliation>
	 </Author>


</AuthorList>
<Abstract>With the advent of computers and quantum algorithms, the security of current public key cryptography systems can face challenges. Breaking the current cryptographic structures would require multi-million qubit quantum computers, which have not yet been built; however, with significant advancements in quantum technology by leading companies in this field and the concern within the cryptography community, there has been a felt need to quickly provide countermeasures. In 2016, the National Institute of Standards and Technology (NIST) sought proposals from around the world to standardize post-quantum cryptographic schemes to address this issue. At that time, the McEliece code-based encryption system (and its equivalent Niederreiter system), despite being proven resistant to both classical and quantum algorithms, was not accepted due to its large public keys. Ultimately, the Classic McEliece, HQC, and BIKE encryption systems, which fall under code-based cryptography, advanced to the final stage of these competitions, and the winners of this cryptographic category will be announced by the end of 2024. This paper aims to review the developments made to optimize code-based structures and to examine the selected code-based cryptographic schemes and the latest status of Classic McEliece standardization.</Abstract>


</Article>
<Article>
<Journal>
<PublisherName>انجمن رمز ایران</PublisherName>
<JournalTitle>Biannual Journal Monadi for Cyberspace Security (AFTA)</JournalTitle>
<Issn>2476-3047</Issn>
<Volume>13</Volume>
<Issue>1</Issue>
<PubDate PubStatus = "ppublish">
<Year>2024</Year>
<Month>8</Month>
<Day>1</Day>
</PubDate>
</Journal>


	<ArticleTitle>A review of blockchain-based data auditing protocols and analyzing their general framework</ArticleTitle>
	<FirstPage>15</FirstPage>
	<LastPage>37</LastPage>
	<Language>FA</Language>
<AuthorList>
	<Author>
	<FirstName>Saeed</FirstName>
	<LastName>Banaeian Far</LastName>
	<Affiliation>Department of Electrical and Computer Engineering, Science and Research Branch Islamic Azad University, Tehran, Iran</Affiliation>
	 </Author>


	<Author>
	<FirstName>Maryam</FirstName>
	<LastName>Rajabzadeh Asaar</LastName>
	<Affiliation>Department of Electrical and Computer Engineering, Science and Research Branch Islamic Azad University, Tehran, Iran</Affiliation>
	 </Author>


</AuthorList>
<Abstract>Data outsourcing to reliable centers for data maintenance, protection and accessibility is simple and low-cost and does not require physical infrastructure, hardware, software and human resources. However, real-world events and recent researches have shown that even reliable centers can abuse users&#39; trust. For example, 1) make changes in the data they have, 2) delete them, or 3) make them temporarily/permanently unavailable. Data audit methods assure the data owners that the data recorded in the database is the same as the data sent by the user and reveals the changes made in it. But they only solve the first problem. In 2008, the introduction of a technology called blockchain, which had several attractive features such as transparency, immutability, and autonomy, caused the problems of many systems that needed the mentioned features to be solved. In this article, after reviewing and addressing several blockchain-based data auditing architectures and protocols, we review and analyze their general framework. Finally, we compare the reviewed works and specify some future horizons of this field.</Abstract>


</Article>
<Article>
<Journal>
<PublisherName>انجمن رمز ایران</PublisherName>
<JournalTitle>Biannual Journal Monadi for Cyberspace Security (AFTA)</JournalTitle>
<Issn>2476-3047</Issn>
<Volume>13</Volume>
<Issue>1</Issue>
<PubDate PubStatus = "ppublish">
<Year>2024</Year>
<Month>8</Month>
<Day>1</Day>
</PubDate>
</Journal>


	<ArticleTitle>An Overview of Physical-Layer Authentication Methods, Performance Metrics, and Their Vulnerabilities to Attacks</ArticleTitle>
	<FirstPage>38</FirstPage>
	<LastPage>60</LastPage>
	<Language>FA</Language>
<AuthorList>
	<Author>
	<FirstName>Parsa</FirstName>
	<LastName>Rajabi</LastName>
	<Affiliation>Electrical Engineering, Iran University of Science &#38; Technology, Tehran, Iran</Affiliation>
	 </Author>


	<Author>
	<FirstName>Seyed Mohammad</FirstName>
	<LastName>Razavizadeh</LastName>
	<Affiliation>Electrical Engineering, Iran University of Science &#38; Technology, Tehran, Iran</Affiliation>
	 </Author>


	<Author>
	<FirstName>Mohammad Hesam</FirstName>
	<LastName>Tadayon</LastName>
	<Affiliation>Iran Telecommunication Research Center, Tehran, Iran</Affiliation>
	 </Author>


</AuthorList>
<Abstract>Authentication plays a pivotal role in ensuring communication security. Cryptographic methods are frequently employed to fulfill this purpose. These methods, implemented at upper network layers, encounter challenges including complexity, power consumption, and overhead. Particularly for users with limited computational power, these methods encounter challenges. A novel solution to overcome these challenges is physical layer authentication (PLA), which involves utilizing physical layer features to embed a tag in the transmitted signal for authentication, leveraging various channel characteristics such as position, velocity, noise, etc. In this paper, a review of previous research is provided, highlighting the differences between physical layer and upper-layer authentication. Furthermore, existing categorizations for PLA and a novel classification based on covertness levels are provided. Moreover, possible attacks and corresponding countermeasures are investigated, followed by suggestions for future research in this area.</Abstract>


</Article>
<Article>
<Journal>
<PublisherName>انجمن رمز ایران</PublisherName>
<JournalTitle>Biannual Journal Monadi for Cyberspace Security (AFTA)</JournalTitle>
<Issn>2476-3047</Issn>
<Volume>13</Volume>
<Issue>1</Issue>
<PubDate PubStatus = "ppublish">
<Year>2024</Year>
<Month>8</Month>
<Day>1</Day>
</PubDate>
</Journal>


	<ArticleTitle>FIDO Authentication Standard: Key Applications for Securing Information Exchange</ArticleTitle>
	<FirstPage>73</FirstPage>
	<LastPage>61</LastPage>
	<Language>FA</Language>
<AuthorList>
	<Author>
	<FirstName>Morteza </FirstName>
	<LastName>Asadi</LastName>
	<Affiliation>Rahavard Samanehaye Amn (RAHSA)</Affiliation>
	 </Author>


	<Author>
	<FirstName>Mohammad Reza </FirstName>
	<LastName>Zamani</LastName>
	<Affiliation>Rahavard Samanehaye Amn (RAHSA)</Affiliation>
	 </Author>


	<Author>
	<FirstName> Kasra </FirstName>
	<LastName> Tawakoli</LastName>
	<Affiliation>Rahavard Samanehaye Amn (RAHSA)</Affiliation>
	 </Author>


</AuthorList>
<Abstract>Passwords have been utilized as the primary means of authentication since the inception of the World Wide Web and the introduction of online services. The security risks associated with the use of passwords and their vulnerabilities to various types of cyberattacks have rendered this method no longer secure. In recent years, online service providers have sought to protect their users and data from cyber threats by implementing various multi-factor authentication methods. Although these methods have been successful in reducing the incidence of security breaches, they have generally resulted in increased complexity for users. The FIDO standard employs asymmetric encryption, mandates the storage of the private key on the user&#8217;s device, and combines it with biometric factors, thereby enabling the most secure authentication method for systems while simplifying the process for users [1-4]. This standard monitors the entire authentication process and prevents potential risks by establishing regulations within operating systems, browsers, and authentication tools. Rahavard Samanehaye Amn Company has implemented this standard locally, offering FIDO authentication under the product name &#8221;Neshane&#8221; for smart phones. This article discusses the applications, specifications, and capabilities of this standard and the developed product.</Abstract>


</Article>
<Article>
<Journal>
<PublisherName>انجمن رمز ایران</PublisherName>
<JournalTitle>Biannual Journal Monadi for Cyberspace Security (AFTA)</JournalTitle>
<Issn>2476-3047</Issn>
<Volume>13</Volume>
<Issue>1</Issue>
<PubDate PubStatus = "ppublish">
<Year>2024</Year>
<Month>8</Month>
<Day>1</Day>
</PubDate>
</Journal>


	<ArticleTitle>The method of risk analysis of communication and information infrastructure modules and the extraction of preventive security requirements</ArticleTitle>
	<FirstPage>74</FirstPage>
	<LastPage>88</LastPage>
	<Language>FA</Language>
<AuthorList>
	<Author>
	<FirstName>nasrin</FirstName>
	<LastName>Taaj</LastName>
	<Affiliation></Affiliation>
	 </Author>


	<Author>
	<FirstName>Amir Mansour</FirstName>
	<LastName>Yadegari</LastName>
	<Affiliation></Affiliation>
	 </Author>


	<Author>
	<FirstName>Abouzar</FirstName>
	<LastName>Arabsorkhi</LastName>
	<Affiliation></Affiliation>
	 </Author>


	<Author>
	<FirstName>Reza</FirstName>
	<LastName>Kalantari</LastName>
	<Affiliation></Affiliation>
	 </Author>


</AuthorList>
<Abstract>The development of the country&#39;s infrastructure as an independent, safe and stable infrastructure is one of the strategic priorities of the country, the realization of which, in addition to the technological requirements in the field of information and communication technology, laying the foundation for the establishment, development and supply of various services and content of the country&#39;s cyber space, requires the provision of secure communications. And the vital infrastructure of the country is also stable.
Based on the conceptual model contained in the resolution of the 66th meeting of the Supreme Council of Cyberspace, the communication and information infrastructure of the country consists of a series of main modules, whose risk analysis is in line with the reversibility in accidents, protection against threats, monitoring and intelligent response from the basic needs of communication access. It is safe and secure. Due to the space limitations of this article, the author intends to explain how to achieve multi-sample risk analysis from these basic modules and then based on the results, how to exploit the emerging knowledge in the form of a diagram to identify the type of threat and its source and extract Explain the mentioned preventive requirements.</Abstract>


</Article>
<Article>
<Journal>
<PublisherName>انجمن رمز ایران</PublisherName>
<JournalTitle>Biannual Journal Monadi for Cyberspace Security (AFTA)</JournalTitle>
<Issn>2476-3047</Issn>
<Volume>13</Volume>
<Issue>1</Issue>
<PubDate PubStatus = "ppublish">
<Year>2024</Year>
<Month>8</Month>
<Day>1</Day>
</PubDate>
</Journal>


	<ArticleTitle>Preserving privacy in the age of information technology development, lessons from the european general data protection regulation</ArticleTitle>
	<FirstPage>89</FirstPage>
	<LastPage>101</LastPage>
	<Language>FA</Language>
<AuthorList>
	<Author>
	<FirstName>Babak </FirstName>
	<LastName>Siabi</LastName>
	<Affiliation>PayamPardaz Communication Engineering Company, Isfahan, Iran</Affiliation>
	 </Author>


	<Author>
	<FirstName>Parvin </FirstName>
	<LastName>Rastegari</LastName>
	<Affiliation>Electrical and Computer Engineering Group, Golpayegan College of Engineering, Isfahan University of Technology, Golpayegan, 87717-67498, Iran</Affiliation>
	 </Author>


</AuthorList>
<Abstract>Due to the increasing amount of data collection and processing in today&#8217;s digital world, preserving individual and organizational privacy has become an undeniable necessity. In this regard, alongside the efforts of scientific and research centers to address privacy issues, several laws have been established in different countries. Among these, the General Data Protection Regulation (GDPR) at the European level is widely regarded by researchers as the most significant change in the field of privacy laws in recent decades and serves as a strong model for managing personal data. Based on this, in this article, to explore the multifaceted nature of privacy, we first review the history of privacy protection, then focus on the GDPR law. Some of the most important points and considerations regarding the nature and structure of this law, as well as the necessity and challenges of compliance with it, are presented. Additionally, the extensive measures outlined in this law for the implementation and enforcement of privacy protection mechanisms are discussed. Finally, by mapping the discussed content to the current state of privacy in Iran, some key points for the practical implementation of privacy laws in Iran are highlighted.</Abstract>


</Article>
</ArticleSet>
