Abstract
Recent investigative frame works, digital forensic tools, and techniques are incapable of acquiring the IoT paradigm's dispersion and heterogeneity characteristics that make law enforcement organizations and digital forensic investigators do their tasks. To address these issues, this study presents a Blockchain-assisted digital forensic system for the IoT context. The devices in the perception layer contain several forensic evidences, which are transmitted to the further layer called the Fog layer. Moreover, the secure transmission of messages from the perception layer to the fog layer is a major challenge. To address this issue, the user's identity (investigators and devices) can be mapped to a pseudo-identity and the security of signature and confidentiality mechanisms ensures both privacy and security. Subsequently, the Fog layer verifies the signature data and employs an improved Blowfish encryption algorithm to provide security to the evidence transmission. In order to encrypt the evidence, the optimal key is generated using the SSAJO algorithm. Then the encrypted message is subjected to a distributed ledger called consortium blockchain that improves the security factors with a greater level of control. Moreover, the proposed IoT framework controls the cloud locally to store, and access data, and performs occasional synchronization with a consortium blockchain.
Introduction
The evolution of advancements in communication, sensing devices, and inexpensive computing devices has brought mankind into the era of IoT, enabling the collection and transmission of various contextual data to faraway locations.1–3 By producing incredible devices, tools, and assets, and placing the most important information at reach, advancements in technology make our daily tasks simpler, quicker, and more enjoyable. Nevertheless, advancements in technology have made it simpler to enable criminals to perform their operations in the context of the IoT, since many devices are connected to the Internet. 4 Criminals can simply exploit the security flaws in the IoT structure to gain remote access. In summary, public safety agencies desperately want IoT forensics experts to assist in identifying the case's critical facts.5,6
Digital forensics constitutes an authorized technique for storing, analyzing, gathering, and publishing information on digital evidence. This information is crucial for police investigations since it depicts the reality of cybercrime and links defendants to illegal activities. As a result, it became critical to handle the obtained evidence carefully to ensure its reliability in law enforcement investigations and court cases, as well as to prevent manipulation or misconduct. 7 Moreover, current digital forensic tools, research methods and frameworks are unable to meet the heterogeneity along with dispersion features of the IoT environment. The features deliver substantial challenges for digital forensic investigators as well as criminal justice authorities.8–10
Blockchain technology is a system of shared ledgers that could hold connected records in the manner of a decentralized database on a network comprised of peers.11,12 Also, the data is stored in a time-blocked record connected in a chain, resulting in an immutable, globally viewable, and independently verified audit trail using consensus-based confirmation of trustworthiness.4,13,14 Further more, peers in the blockchain network were given the ability to reject any incorrect operations that crossed the network. The safety of Internet of Things provisioning was ensured via blockchain.15,16 The benefits of integrating blockchain alongside digital forensics include immutability, decentralization, as well as confidentiality. Most of the present blockchain-based digital evidence retention schemes keep only the metadata of the evidence in the blockchain, whilst the proof is held on a centrally located server otherwise in the cloud.
1
To address this issue, a novel digital forensic in the IoT paradigm is proposed. Further more, the major contribution of this work is given as follows:
Proposing a Blowfish algorithm for encrypting the evidence, in which the function F is modified to enhance confidentiality. Proposing a hybrid optimization scheme SSAJO for an optimal key generation that combines both SSOA and JSO algorithms. The comparative analysis is made to validate the effectiveness of the suggested work over the standard techniques.
The rest of the paper is structured as follows: The Study of existing methodology is discussed in Section 2. The proposed framework of the IoT paradigm is elaborated in Section 3. The validation is conducted in Section 4 and the conclusion is summarized in Section 5.
Literature review
In 2021, Gulshan Kumar et al. 17 has delivered an IoT forensics paradigm and suggested the IoF approach takes into account a blockchain-tailored IoT architecture supporting digital forensics. Moreover, it gave a clear visual of the detective's procedure, which included every stakeholder in an integrated structure. In addition, consensus was employed for consortia to address cross-border legitimacy challenges and this additionally proved advantageous for clarity and simplicity of forensic comparison. Reduced complexity was achieved through programmable lattice-based cryptographic primitives, which also offered advantages for power-constrained devices, contributing to the uniqueness of the proposed concept.
In 2021, Meng Li et al. 7 has suggested LE Chain, a blockchain-based legitimate evidence governance system that would monitor the full evidence stream along with all court records, from gathered evidence and availability throughout police investigation using jury voting in court proceedings. In order to safeguard witnesses’ anonymity, they use brief randomizable signatures to surreptitiously authorize their identities. Ultimately, they standardized their analysis of LE Chain's safety and confidentiality, as well as its computing expenses and overhead associated with communication, by building a working model based on a small Ethereum experimental network.
In 2019, Shancang Li et al. 4 has introduced an IoTFC, a block-enabled IoT forensics system that can provide investigative services with strong immutability, authenticity, robustness, traceability, and a network of trust among evidentiary rights with investigators. Moreover, the IoTFC can provide traceability guarantees as well as trace the origin of evidence elements. Additionally, information about evidence proof of identity, analysis, preservation, and dissemination was going to be documented in blockchains.
In 2019, Mehran Pourvahab et al. 15 has developed a successful forensics framework in SDN-IoT that generated the CoC in the context of blockchain technology. Moreover, the suggested SDN-based IoT structure began with circulation chart regulations on switches for all three separate traffics namely, FTP, VoIP, as well as HTTP. All of the controllers were supplied with a classifier, which distinguished the harmful packets according to packet attributes using the Neuro Multi fuzzy. In addition, the suggested SDN-IoT design, and event logs have been implemented and stored on the blockchain.
In 2022, Randa Kama et al. 1 has introduced the FCEP System, a revolutionary framework for IoT-based smart city protection. Also, the suggested system seeks to combine blockchain alongside digital forensics to address forensic investigators’ challenges including modifications in single source evidence, as well as to improve the integrity of maintaining digital evidence by utilizing the blockchain. Moreover, maintaining digital evidence among forensic member nodes minimized the chance of failure in a centralized storage server at a single location.
In 2020, NickolaosKoroniotis et al. 18 has created a PDF scheme that outlines the digital investigative steps for discovering and tracing attack activities in IoT networks. Moreover, the suggested structure encompassed three novel functions including (1) obtaining data from network flows as well as checking their confidentiality in encrypted networks; (2) employing the PSO method to continuously modify DL variables; and (3) establishing a DNN that employs the PSO algorithm to identify and track the inappropriate incidents occurring in smart home IoT networks.
In 2021, Faisal A. Garba et al. 19 has presented a unique low-cost IoT forensic architecture to address the inspection and evaluation component of IoT forensics in which genetic-fuzzy specialist network was employed, and the investigation and analysis phase of IoT forensics employing a genetic-fuzzy. Furthermore, the challenge of protecting the confidentiality as well as chain of ownership of IoT forensics data utilizing hyper ledger fabric, a free and open source private-permission blockchain. Moreover, the proposed genetic-fuzzy IoT forensics system was assessed by being compared to corresponding projects like NFAT to assess its efficacy and precision.
In 2019, Jung Hyun Ryu et al. 20 has presented a blockchain-based digital forensics system for the context of the Internet of Things. In the suggested structure, all IoT device communication has been documented in the blockchain as transactions, making the current chain of custody system more reliable and easier. Blockchain technology ensured the integrity of the data to be analyzed, improved security, and made integrity maintenance more predictable through the implementation of a decentralized integrity preservation system.
In 2019, Mehran Pourvahab and Gholamhossein Ekbattanifard 21 has presented the SRVA model to preserve the system from unauthenticated users. With the utilization of HSO, the secret keys were produced randomly in order to improve the cloud platform. Moreover, the SA-DECC-based approach was presented to encrypt the data for secure transmission. Also, various analyses were performed that ensured the implemented LGoE-based collection against the blockchain.
Problem statement
Table 1 displays the features and limitations of existing systems with regard to digital forensics in the IoT paradigm. The increasing complexity and sophistication of cybercrimes necessitate a robust approach to digital forensics, particularly in the context of network, memory, system, and cloud forensics. Moreover, the current methods lack transparency and completeness, hindering effective investigation and cross-border collaboration. However, the existing blockchain solutions show potential but are not fully developed, particularly in terms of post-quantum resistant cryptography, throughput, delay, and energy efficiency. Additionally, the lack of research into consortium-based frameworks limits the understanding of their applicability in digital forensics. Consequently, there is a pressing need for an integrated solution that addresses these gaps, enabling a comprehensive, transparent, and efficient investigative process. Hence, an improved cryptosystem method is proposed for digital forensics in the IoT paradigm which enhances digital forensic capabilities and tackling cross-border issues in cybercrime investigations.
Features and limitations of current systems.
Features and limitations of current systems.
Proposed work of digital forensics in Iot paradigm
To verify the criminal occurrences in an IoT-based context, the Forensic Investigation Framework (FIF-IoT) makes access to a public digital ledger that records IoT entity interactions as evidence and securely stores them as distributed, actions in a public, and autonomous blockchain network. As a result, central administrative oversight is eliminated, and single-point collapse will be prevented. Moreover, it additionally incorporates a means for checking the authenticity of the evidence obtained directly from the ledger. In order to enhance the security of investigations, this paper proposes a new Blockchain-based Digital Forensics framework with the following four major layers: Perception Layer, Fog layer, Consortium Block Chain and Cloud Layer. The framework of the proposed digital forensics in the IoT paradigm is illustrated in Figure 1. In this suggested framework, the devices present at the perception layer contain forensic evidence, which is transmitted into the further layer called the Fog layer. Secure transmission is the major challenging issue while transmitting the message from the perception layer to the fog layer. To address this issue, the identity of users (investigators and devices) is mapped to a pseudo-identity and the security of signature and confidentiality. Thus, this process ensures confidentiality and security. The Fog layer then uses the Blowfish encryption method to ensure the confidentiality of the message (evidence) transmission after confirming the signature data. To encrypt the message, the optimal key is generated using the SSAJO algorithm. Then the encrypted message is subjected to a distributed ledger called consortium blockchain, assuming that legalization offices are a part of the consortium to improve the security factors with a greater level of control. Further more, the cloud is employed to store and access the data, leading make a shared framework with the aid of blockchain. Moreover, the proposed IoT framework controls the cloud locally and, it occasionally performs synchronization with a consortium blockchain.

Framework of proposed digital forensic in IoT paradigm.
The perception layer 17 is made up of a variety of low-powered devices. Further more, hand evidence entering is considered here and it is often necessary to safeguard the confidentiality of the investigators and the device until the proof is presented in the court. In order to resolve this challenge, users’ identities are being assigned to a pseudo-identity, as well as signature and confidentiality processing. For that, Programmable Hash Functions (PHFs) are additionally employed to process the signing procedure to verify that only certain authorized devices are included in the proposed IoT. This secures the paradigm along with privacy, confidentiality, and reliability of blockchain digital data. As a result, this procedure assures secrecy along with confidentiality. Subsequently, it emphasizes that this framework is consistent for the detection of intrusions; otherwise, superfluous data would have to be collected. Further more, the pseudo-identity, as well as signature and confidentiality processing procedures, are discussed as follows:
Pseudo identity generation
To generate a pseudo-identity, each device offers input as relevant hardware identity such as its MAC address to the hash function and then generates the corresponding output. In the private cloud, the mapping is stacked; on the other hand, pseudo-identities are broadcasted over the public cloud. Likewise, the identity of investigators is mapped, which ensures confidentiality. Moreover, this work selects the trapdoor key when the attackers try to utilize the trapdoors in an IoT environment. Assume that the lattice-based PHF is assigned
Step 1: Initialize Q, U and V.
Step 2: Transform MAC address to the polynomial community
Step 3: Generate a trapdoor matrix
Step 4: Compute the hash function
Step 5:
Step 6:
Step 7: Evaluate
Step 8: Compute
Step 9: Obtain
Step 10: Return
The devices available at the perception layer are finite resources and the main goal is to ensure confidentiality with minimal complexities in computation. Further more, the process deploys the lattice-based PHF pseudo-identity and this can be verified with the verification parameter B. Then the PHF-based signature approach deploys with a verification key as
Step 1: Evaluate the trapdoor by employing hashed concatenation as
Step 2: Produce a short vector e that satisfies the signing rules:
Step 3: Evaluate
Step 4: Set signature
Step 5: Verify
After performing the signing procedure, an encryption process takes place to enable confidentiality during the transmission of evidence. Here, the fog layer acts as a verifier, which verifies and validates the signature. Further more, Figure 2 reveals the interaction between a device at the perception layer and the verifier at the fog layer.

Interaction between the verifier at the fog layer and a device at the perception layer.
This layer includes resource-intensive equipment such as routers, gateways, and switches, as well as local or personal servers to support applications related to forensics. Additionally, the fog layer verifies the signature data given in the preceding part along with retaining and revising it regularly. In addition to the signature encryption responsibility, this layer provided certain digital forensic capabilities as well as a CoC blockchain. Further, when the device is given to users or even a location, digital forensic programs capture the data on it and generate a blockchain transaction with it.
Figure 3 exhibits the fog layer topology. The perception layer's devices interact with the fog layer's devices. When such devices acquire messages via any other layer device, they validate the signature and decrypt the contents of the message. Consider that the verifier can be trustworthy and enforceable. Following the device's validation, applications of digital forensics including memory forensics tools and networks are launched on them to collect the current functioning characteristics. All information is preserved in the blockchain for potential utilization through the CoC investigator(s). Eventually, the blockchain for CoC has been connected to the consortium blockchain for global accountability.

Diagrammatic representation of Fog layer topology in IoT paradigm.
Once the fog layer verifies the signing, the evidence is encrypted by using a secret key block cipher method named Blowfish algorithm 22 for the secure transmission of evidence. Moreover, the Blowfish constitutes the proportioned key block cipher, which employs a 64-bit block size along with the varied length of the key. That is, at a time this cipher algorithm encrypts 64-bit block data. Here, the function F is improved for secure evidence transmission. The procedure of encryption process is discussed as follows:

Framework of function F in the proposed Blowfish algorithm.
To encrypt the evidence, this work suggested a hybrid optimization approach named SSAJO, which takes keys
Objective function
The proposed hybrid optimization SSAJO fixed the objective function as the minimization function according to equation (5). Here,
A metaheuristic approach is a type of algorithm, in which JSO is inspired by jellyfish activity in water and replicates their search behavior. Moreover, the jellyfish uses its tentacles to injure its target as well as paralyze them. Additionally, it includes assessments related to jellyfish in currents of the ocean, a temporal management system for switching among these movements, and the movement within a jellyfish swarm, along their intersections into jellyfish blooms that occur during both the exploration and the extraction phases. Nevertheless, maintaining an equilibrium among the stages is a significant challenge. To address the aforementioned problem, a unique hybrid SSAJO technique is used that combines the SSOA 23 and JSO 24 algorithms. The SSOA technique is implemented by replicating the natural herding routines of shepherds. Further more, the mathematical simulation of the proposed strategy of SSAJO is elaborated in the following.
Mathematical modeling
Parameter settings of the optimization algorithms.
Parameter settings of the optimization algorithms.
The legalization offices will form a consortium. Moreover, the consortium components will work together to provide an autonomous blockchain with a permission infrastructure. Since, a consortium blockchain 17 is controlled through an assembly of recognized persons, advisory committees and police departments; hence, decentralized operation occurs. Moreover, because users on this consortium blockchain are part of a network of already authorized nodes, the consensus-building process on this blockchain is not as stable as it is on the public blockchain. As a result, consortium blockchain adds a higher level of authority to the traditional blockchain security characteristics.
Cloud layer
To establish a system that is distributed using the blockchain, a cloud is required to feed retention and information access. Also, IoF administers the cloud remotely and periodically synchronizes using consortium blockchain. Moreover, the inclusion of these types of cloud companies in a consortium blockchain enhances the accessibility of data.
Threat model
Applications built on blockchain technology are by nature thought to be secure in terms of maintaining non-repudiation, integrity, and confidentiality. Further more, because digital forensic investigations are carried out in a fog layer without human involvement, the data is impervious to tampering. The gathering of evidence is the sole situation that calls for manual intervention. The chain of custody has an impact on the forensic framework's overall coordination and monitoring procedures. Maintaining a suspect's social dignity during the forensic process requires privacy and anonymity until the evidence as well as its analysis are verified. Blockchain uses pseudo-identities; the primary identification mapping procedure is kept locally. It is acknowledged, nonetheless, that the forensic process's traceability of the evidence does not substantiate the privacy concerns. This section shows how the suggested approach improves security and greatly increases security against attacks of a similar nature.
Resistant to man-in-the-middle-attack
In this attack, the eavesdropper intercepts communication among the parties and impersonates a real user or other communicating party, sending and receiving messages to each party and attempting to alter the intercepted messages in a similar way it could get access. The proposed protocol effectively resists this attack.
Resistant to brute-force attack
In this attack, the unauthorized user tries to hack the password and a combination of encryption keys and tries to access the data. This attack depends on doing a thorough trial and error process until the right password is discovered. This technique can readily breach weak or simple passwords. However, the suggested strategy would firmly resist this threat.
Resistant to side-channel attack
The side channel attack is a kind of retrieving information from the leakage of data during communication or while accessing the system. The side channel attack leverages the physical properties of the hardware, software or transmission medium to retrieve sensitive data from the internal functions of the targeted device. Nevertheless, the suggested protocol has successfully resisted this attack.
Resistant to false injection attack
In this attack, the intruder can alter or inject fake data from one or more sensors at any point, allowing the false data to fall within a reasonable range of genuine observations. However, the proposed mechanism has effectively resisted this attack.
Results and discussion
Simulation procedure
The suggested Blockchain-based Digital Forensics system was simulated in PYTHON. Moreover, the Python version was “PYTHON 3.7”. The processor utilized was “11th Gen Intel(R) Core(TM) i3-1115G4 @ 3.00 GHz 3.00 GHz” as well as the installed RAM size was “8.00 GB (7.74 GB usable)”.
Performance analysis
The SSAJO and the standard schemes were analyzed regarding encryption time, decryption time, latency, energy and various types of attacks including KCA, CPA, CCA, and KPA. Moreover, the SSAJO is compared with state-of-the-art methods like HSO 21 and PSO 18 as well as was contrasted with conventional methods, such as BMO, BOA, CA, HGS, JSO and SSOA.
Attack analysis
The attack evaluation on SSAJO is compared with BMO, BOA, CA, HGS, JSO, HSO, 21 PSO 18 and SSOA regarding CCA, CPA, KCA and KPA attacks for blockchain-based digital forensics framework is demonstrated in Figure 5. Lower attack ratings are necessary for the model to function well. Moreover, the CCA attack has been characterized as a cryptanalysis assault mechanism that allows the cryptanalyst to obtain information by gathering decryptions from predefined ciphertexts. Moreover, the CCA attack rate of the SSAJO scheme is 0.457, meanwhile, the conventional approaches yielded higher CCA attack ratings, including, BMO = 0.549, BOA = 0.683, CA = 0.758, HGS = 0.726, JSO = 0.714, HSO 21 = 0.558, PSO 18 = 0.534 and SSOA = 0.519, correspondingly. The CPA assumes that the intruder has got access to the plaintext ciphers for every piece of plaintext in the cryptanalysis attack. The goal of the attack is to gather data that will weaken the system's defences against data encryption. According to this criterion, the model ought to have lower CPA attack rates. Similarly, the CPA attack value of the SSAJO is much lower than BMO, BOA, CA, HGS, JSO, HSO, 21 PSO 18 and SSOA.

Attack analysis on SSAJO and conventional methods (a) CCA (b) CPA (c) KCA and (d) KPA.
The KCA attack is defined as “The known ciphertext attack is a type of cryptanalysis attack in which the attacker is presumptively limited to a particular set of ciphertexts.” Mainly, the KCA attack rate of the SSAJO approach is 0.473, meanwhile, the BMO is 0.695, BOA is 0.783, CA is 0.571, HGS is 0.654, JSO is 0.682, HSO 21 is 0.638, PSO 18 is 0.625 and SSOA is 0.609, correspondingly. According to a summary of the KPA attack study, the KPA attack is a type of cryptanalysis attack that happens when the attacker has access to both the plaintext, also called a crib, and the encrypted version, also called ciphertext. This might be employed to find more hidden information, including code books and secret codes. Additionally, the KPA attack value of the SSAJO methodology is 0.578, whilst the BMO, BOA, CA, HGS, JSO, HSO, 21 PSO 18 and SSOA gained greater KPA attack ratings. Thus, the SSAJO approach is shown to be more effective and offers greater security to the stored data in the cloud architecture. This enhancement is due to the pseudo-identity generation and signature and confidentiality processing for the security process in the perception layer with a hybrid optimization scheme (SSOA and JSO).
The decryption and encryption time analysis on SSAJO over BMO, BOA, CA, HGS, JSO, HSO, 21 PSO 18 and SSOA for blockchain-based digital forensics framework is described in Figure 6(a) and (b). For the model to perform better, the encryption and decryption times need also be reduced. In particular, the decryption time of the SSAJO scheme is 0.0015 s, even though the traditional methods scored greater decryption time, notably, BMO = 0.0022 s, BOA = 0.0023 s, CA = 0.0021 s, HGS = 0.0020 s, JSO = 0.0027 s, HSO 21 = 0.0025 s, PSO 18 = 0.0024 s and SSOA = 0.0018 s, correspondingly. Similarly, the encryption time of the SSAJO approach is lesser than BMO, BOA, CA, HGS, JSO, HSO, 21 PSO 18 and SSOA. Therefore, the SSAJO outperformed other earlier techniques with quick encryption and decryption, demonstrating that it has a larger capacity to safeguard the data kept in the cloud framework.

Validation on SSAJO and conventional methods (a) decryption time and (b) encryption time.
Figure 7(a) depicts the energy assessment on SSAJO compared with BMO, BOA, CA, HGS, JSO, HSO, 21 PSO 18 and SSOA for blockchain-based digital forensics framework. Additionally, it is evaluated for a specific quantity of transactions (0–2000). During the primary transaction, the SSAJO and traditional strategies acquired the highest energy ratings, and though the transactions improved the energy value gradually improved. However, our SSAJO scheme gained maximal energy values. In particular, the energy rate of the SSAJO scheme is 69.835J, this is extremely higher than BMO (32.763J), BOA (34.172J), CA (43.273J), HGS (46.365J), JSO (50.917J), HSO 21 (52.428J), PSO 18 (65.832J) and SSOA (51.828J), correspondingly.

Validation on SSAJO and conventional methods (a) energy and (b) latency.
Simultaneously, the latency evaluation on SSAJO over BMO, BOA, CA, HGS, JSO, HSO, 21 PSO 18 and SSOA for blockchain-based digital forensics framework is represented in Figure 7(b). It is validated under a varied number of rounds (0–2000). Moreover, the SSAJO reached minimum latency values in almost all the rounds. Mainly, the latency of the SSAJO approach is 54.5 at the 1500th round, which is lesser than BMO, BOA, CA, HGS, JSO and SSOA. Because of the hybrid optimization technique (SSOA and JSO) with an upgraded blowfish algorithm for data encryption, the SSAJO has collectively declared its superiority in blockchain-based digital forensics systems with greater power consumption and lower latency values.
The convergence study of the SSAJO is compared over BMO, BOA, CA, HGS, JSO, HSO, 21 PSO 18 and SSOA for blockchain-based digital forensics framework is exposed in Figure 8. Additionally, the unique number of iterations (0–25) is analyzed. In the first iteration, the cost rate was higher for the SSAJO and the standard approaches, but it decreased for all of the algorithms as the iteration progressed. However, the SSAJO achieved faster convergence at a reduced cost rate. Mainly, at iteration 25, the SSAJO acquired the cost value of 0.526, whilst the BMO is 0.598, BOA is 0.581, CA is 0.573, HGS is 0.549, JSO is 0.564, HSO 21 is 0.617, PSO 18 is 0.582 and SSOA is 0.587, correspondingly. The hybrid optimization approach (SSOA and JSO) was added, enabling the SSAJO methodology to attain faster convergence.

Convergence assessment on SSAJO and standard techniques.
Figures 9 and 10 describe the analysis of SSAJO and conventional methods for various attacks (CCA, CPA, KCA, and KPA), encryption times, and decryption times by adjusting the key sizes from (16–128 bits). For the key size 64, the CCA attack rate of the SSAJO scheme is 0.234, even though the BMO is 0.749, BOA is 0.685, CA is 0.582, HGS is 0.674, JSO is 0.563, SSOA is 0.659, HSO 21 is 0.598 and PSO 18 is 0.651, correspondingly. Furthermore, the encryption and decryption of the SSAJO method are extremely greater than BMO, BOA, CA, HGS, JSO, SSOA, HSO 21 and PSO. 18

Attack assessment on SSAJO and standard techniques across various key sizes (a) CCA (b) CPA (c) KCA and (d) KPA.

Evaluation of SSAJO and standard techniques across various key sizes (a) Decryption time and (b) Encryption time.
Table 3 shows the statistical comparison of SSAJO and the traditional methods including BMO, BOA, CA, HGS, JSO, and SSOA for the blockchain-based digital forensics framework. Because metaheuristic procedures are not always reliable, each method is thoroughly examined to ensure better estimation. This is done by estimating in terms of minimum, median, standard deviation, mean, and maximum statistical parameters. Moreover, the fitness rate of the SSAJO method is 0.512 under the minimum statistical measure, whilst the BMO is 0.582, BOA is 0.561, CA is 0.555, HGS is 0.530, JSO is 0.543 and SSOA is 0.571, respectively. Further more, the SSAJO reported a fitness value of 0.605 with the median measure, whereas the BMO, BOA, CA, HGS, JSO, and SSOA recorded higher fitness values.
Statistical analysis of fitness.
Statistical analysis of fitness.
The performance analysis on Improved Blowfish over Blowfish, RSA and AES with regard to varied types of attacks, encryption time and decryption time for blockchain-based digital forensics framework is summarized in Table 4. For the analysis of blockchain-based digital forensics, the Improved Blowfish recorded superior findings than the conventional methodologies. Additionally, the Improved Blowfish scheme's KCA attack rate is 0.373, meanwhile, the blowfish, RSA, and AES are 0.554, 0.432, and 0.502 respectively. Furthermore, in contrast to Blowfish, RSA, and AES, the Improved Blowfish approach has substantially faster encryption and decryption times. Similarly, since we have implemented an enhanced blowfish algorithm, the suggested solution has a lesser impact than traditional approaches for all attacks.
Performance analysis of proposed and conventional encryption methods.
Performance analysis of proposed and conventional encryption methods.
The attack evaluation on SSAJO is compared with BMO, BOA, CA, HGS, JSO, HSO, 21 PSO 18 and SSOA for blockchain-based digital forensics framework in terms of key sizes varies from (16, 32, 64 and 128) are summarized from Tables 5–8. In order to ensure secure cloud data storage, the model should achieve lower attack scores. Considering Table 5 (Key size = 32), for the Side channel attack, the SSAJO obtained a lower attack value of 0.487, meanwhile, the BMO is 0.737, BOA is 0.675, CA is 0.781, HGS is 0.693, JSO is 0.688, HSO 21 is 0.563, PSO 18 is 0.584 and SSOA is 0.563, correspondingly. Further, analyzing Table 8 (key size = 128), for the message tampering attack, the SSAJO acquired the attack rate of 42.105, though the BMO, BOA, CA, HGS, JSO, HSO, 21 PSO 18 and SSOA yielded lower attack ratings. In a similar vein, the SSAJO outperformed the traditional schemes across other attacks.
Attack analysis for key size 16.
Attack analysis for key size 16.
Attack analysis for key size 32.
Attack analysis for key size 64.
Attack analysis for key size 128.
The computation time analysis on SSAJO over BMO, BOA, CA, HGS, JSO, SSOA, HSO 21 and PSO 18 for blockchain-based digital forensics framework is presented in Table 9. Additionally, for the model to function well, the computation time should be shortened. Particularly, the computational time of the SSAJO method is 53.259, even though the existing methods obtained maximum computation time, notably, BMO = 67.633, BOA = 65.395, CA = 89.889, HGS = 83.332, JSO = 79.719, SSOA = 107.804, HSO 21 = 64.215 and PSO 18 = 76.405, correspondingly. This improved SSAJO scheme with reduced time for computation is due to an innovative hybrid optimization approach that uses an improved blowfish algorithm to encrypt the data more effectively.
Analysis of computational time of the SSAJO and standard strategies.
Analysis of computational time of the SSAJO and standard strategies.
The objective of this study was to introduce a novel architecture for digital forensics based on blockchain technology. It consists of four main layers: the Perception Layer, the Fog Layer, the Consortium Block Chain, and the Cloud Layer. Moreover, the forensic evidence is stored on devices within the perception layer and is transferred to the Fog layer, which is the next layer up. Nevertheless, secure transmission was the major challenging issue while transmitting the message from the perception layer to the fog layer. This problem can be solved by mapping user identities (such as investigators and device identities) to pseudo-identities and ensuring signature security and confidentiality. Thus, this process ensured privacy and security. The Fog layer used the Blowfish algorithm for encryption to ensure the privacy of the message (evidence) transfer and confirm the signature data. To encrypt the message, the optimal key was generated using the SSAJO algorithm. Then the encrypted message was subjected to a distributed ledger called consortium blockchain, assuming that legalization offices are a part of the consortium to improve the security factors with a greater level of control. The cloud was used to store and access the data, creating a shared framework with the aid of blockchain. Moreover, the suggested IoT framework controls the cloud locally and performs synchronization with consortium blockchain occasionally.
Footnotes
Funding
The authors received no financial support for the research, authorship, and/or publication of this article.
Declaration of conflicting interests
The authors declared no potential conflicts of interest with respect to the research, authorship, and/or publication of this article.
