{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,9]],"date-time":"2026-04-09T01:06:00Z","timestamp":1775696760990,"version":"3.50.1"},"reference-count":41,"publisher":"MDPI AG","issue":"12","license":[{"start":{"date-parts":[[2021,12,7]],"date-time":"2021-12-07T00:00:00Z","timestamp":1638835200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100006378","name":"Universitas Indonesia","doi-asserted-by":"publisher","award":["NKB-788\/UN2.RST\/HKP.05.00\/2020"],"award-info":[{"award-number":["NKB-788\/UN2.RST\/HKP.05.00\/2020"]}],"id":[{"id":"10.13039\/501100006378","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Symmetry"],"abstract":"<jats:p>Over recent years, the incidence of data breaches and cyberattacks has increased significantly. This has highlighted the need for sectoral organizations to share information about such events so that lessons can be learned to mitigate the prevalence and severity of cyber incidents against other organizations. Sectoral organizations embody a governance relationship between cross-sector public and private entities, called public-private partnerships (PPPs). However, organizations are hesitant to share such information due to a lack of trust and business-critical confidentially issues. This problem occurs because of the absence of any protocols that guarantee privacy protection and protect sensitive information. To address this issue, this paper proposes a novel protocol, Putra-Ramli Secure Cyber-incident Information Sharing (PURA-SCIS), to secure cyber incident information sharing. PURA-SCIS has been designed to offer exceptional data and privacy protection and run on the cloud services of sectoral organizations. The relationship between organizations in PURA-SCIS is symmetrical, where the entities must collectively maintain the security of classified cyber incident information. Furthermore, the organizations must be legitimate entities in the PURA-SCIS protocol. The Scyther tool was used for protocol verification in PURA-SCIS. The experimental results showed that the proposed PURA-SCIS protocol provided good security properties, including public verifiability for all entities, blockless verification, data privacy preservation, identity privacy preservation and traceability, and private information sharing. PURA-SCIS also provided a high degree of confidentiality to protect the security and integrity of cyber-incident-related information exchanged among sectoral organizations via cloud services.<\/jats:p>","DOI":"10.3390\/sym13122347","type":"journal-article","created":{"date-parts":[[2021,12,7]],"date-time":"2021-12-07T02:48:13Z","timestamp":1638845293000},"page":"2347","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":7,"title":["PURA-SCIS Protocol: A Novel Solution for Cloud-Based Information Sharing Protection for Sectoral Organizations"],"prefix":"10.3390","volume":"13","author":[{"given":"Fandi Aditya","family":"Putra","sequence":"first","affiliation":[{"name":"Department of Electrical Engineering, Universitas Indonesia, Depok 10430, Indonesia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0374-4465","authenticated-orcid":false,"given":"Kalamullah","family":"Ramli","sequence":"additional","affiliation":[{"name":"Department of Electrical Engineering, Universitas Indonesia, Depok 10430, Indonesia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0960-2182","authenticated-orcid":false,"given":"Nur","family":"Hayati","sequence":"additional","affiliation":[{"name":"Department of Electrical Engineering, Universitas Indonesia, Depok 10430, Indonesia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3345-4669","authenticated-orcid":false,"given":"Teddy Surya","family":"Gunawan","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, International Islamic University Malaysia, Kuala Lumpur 53100, Malaysia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2021,12,7]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1093\/cybsec\/tyy008","article-title":"Threat intelligence sharing between cybersecurity vendors: Network, dyadic, and agent views","volume":"4","author":"Zrahia","year":"2018","journal-title":"J. Cybersecur."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"530","DOI":"10.1049\/iet-ifs.2018.5079","article-title":"Fair and private rewarding in a coalitional game of cybersecurity information sharing","volume":"13","author":"Vakilinia","year":"2019","journal-title":"IET Inf. Secur."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"1136","DOI":"10.1109\/TCC.2016.2545668","article-title":"Secure data sharing in cloud computing using revocable-storage identity-based encryption","volume":"6","author":"Wei","year":"2016","journal-title":"IEEE Trans. Cloud Comput."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"996","DOI":"10.1109\/TDSC.2017.2725953","article-title":"Block Design-Based Key Agreement for Group Data Sharing in Cloud Computing","volume":"16","author":"Shen","year":"2019","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"20799","DOI":"10.1109\/ACCESS.2020.2968728","article-title":"Information privacy protection based on verifiable (t, n)-Threshold multi-secret sharing scheme","volume":"8","author":"Wang","year":"2020","journal-title":"IEEE Access"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Ghernaouti, S., Cellier, L., and Wanner, B. (2019, January 23\u201325). Information sharing in cybersecurity: Enhancing security, trust and privacy by capacity building. Proceedings of the 2019 3rd Cyber Security in Networking Conference, CSNet, Quito, Ecuador.","DOI":"10.1109\/CSNet47905.2019.9108944"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"101589","DOI":"10.1016\/j.cose.2019.101589","article-title":"Cyber threat intelligence sharing: Survey and research directions","volume":"87","author":"Wagner","year":"2019","journal-title":"Comput. Secur."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"60067","DOI":"10.1109\/ACCESS.2019.2915387","article-title":"A Secure Incentive Mechanism for Competitive Organization Data Sharing: A Contract Theoretic Approach","volume":"7","author":"Guo","year":"2019","journal-title":"IEEE Access"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1093\/cybsec\/tyz006","article-title":"To share or not to share: A behavioral perspective on human participation in security information sharing","volume":"5","author":"Mermoud","year":"2019","journal-title":"J. Cybersecur."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"26031","DOI":"10.1109\/ACCESS.2019.2894344","article-title":"Emerging Privacy Issues and Solutions in Cyber-Enabled Sharing Services: From Multiple Perspectives","volume":"7","author":"Yan","year":"2019","journal-title":"IEEE Access"},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"387","DOI":"10.1109\/JSYST.2019.2911391","article-title":"Improving Security and Privacy Attribute Based Data Sharing in Cloud Computing","volume":"14","author":"Zhang","year":"2020","journal-title":"IEEE Syst. J."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"127","DOI":"10.1016\/j.cose.2016.12.011","article-title":"PRACIS: Privacy-preserving and aggregatable cybersecurity information sharing","volume":"69","author":"Tapiador","year":"2017","journal-title":"Comput. Secur."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"179","DOI":"10.1049\/cje.2018.02.017","article-title":"Privacy-preserving public auditing scheme for data confidentiality and accountability in cloud storage","volume":"28","author":"Yang","year":"2019","journal-title":"Chin. J. Electron."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Loh, J.-C.n., Heng, S.-H., and Tan, S.-Y. (2019). A Generic Framework for Accountable Optimistic Fair Exchange Protocol Fair Exchange Protocol. Symmetry, 11.","DOI":"10.3390\/sym11020285"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Mihalkovich, A., Sakalauskas, E., and Luksys, K. (2020). Key Exchange Protocol Defined over a Non-Commuting Group Based on an NP-Complete Decisional Problem. Symmetry, 12.","DOI":"10.3390\/sym12091389"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Harun, N.Z., Zukarnain, Z.A., Hanapi, Z.M., and Ahmad, I. (2020). Multi-Stage Quantum Secure Direct Communication Using Secure Shared Authentication Key. Symmetry, 12.","DOI":"10.3390\/sym12091481"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"122091","DOI":"10.1109\/ACCESS.2019.2938528","article-title":"Efficient Privacy-Preserving Certificateless Provable Data Possession Scheme for Cloud Storage","volume":"7","author":"Ming","year":"2019","journal-title":"IEEE Access"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Chuang, Y.-H., Lei, C.-L., and Shiu, H.-J. (2021). How to Design a Secure Anonymous Authentication and Key Agreement Protocol for Multi-Server Environments and Prove Its Security. Symmetry, 13.","DOI":"10.3390\/sym13091629"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"331","DOI":"10.1109\/TIFS.2018.2850312","article-title":"Enabling Identity-Based Integrity Auditing and Data Sharing with Sensitive Information Hiding for Secure Cloud Storage","volume":"14","author":"Shen","year":"2018","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_20","first-page":"68","article-title":"Attribute based sharing in cybersecurity information exchange framework","volume":"49","author":"Vakilinia","year":"2017","journal-title":"Simul. Ser."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Hong, M.Q., Wang, P.Y., and Zhao, W.B. (2016, January 9\u201310). Homomorphic Encryption Scheme Based on Elliptic Curve Cryptography for Privacy Protection of Cloud Computing. Proceedings of the 2016 IEEE 2nd International Conference on Big Data Security on Cloud (BigDataSecurity), IEEE International Conference on High Performance and Smart Computing (HPSC), and IEEE International Conference on Intelligent Data and Security (IDS), New York, NY, USA.","DOI":"10.1109\/BigDataSecurity-HPSC-IDS.2016.51"},{"key":"ref_22","unstructured":"Chaudhary, P., Gupta, R., Singh, A., and Majumder, P. (2019, January 27\u201328). Analysis and Comparison of Various Fully Homomorphic Encryption Techniques. Proceedings of the 2019 International Conference on Computing, Power and Communication Technologies, GUCON, New Delhi, India."},{"key":"ref_23","unstructured":"European Union Agency for Cybersecurity (2018). Information Sharing and Analysis Centres (ISACs) Cooperative Models, ENISA."},{"key":"ref_24","unstructured":"Koepke, P. (2017). Cybersecurity Information Sharing Incentives and Barriers. Working Paper CISL #2017-13, MIT Management Sloan School."},{"key":"ref_25","first-page":"1687","article-title":"Public Health as a Model for Cybersecurity Information Sharing","volume":"30","author":"Sedenberg","year":"2015","journal-title":"Berkeley Technol. Law J."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"265","DOI":"10.1080\/23738871.2016.1229804","article-title":"Trust and information sharing: ISACs and U.S. Policy","volume":"1","author":"Kollars","year":"2016","journal-title":"J. Cyber Policy"},{"key":"ref_27","first-page":"8","article-title":"Information Sharing as a Dimension of Smartness: Understanding Benefits and Challenges in Two Megacities","volume":"57","author":"Pardo","year":"2019","journal-title":"Urban Aff. Rev."},{"key":"ref_28","first-page":"23","article-title":"Toward Automated Information Sharing California: Cybersecurity Integration Center\u2019s approach to improve on the traditional information sharing models","volume":"3","author":"Tresh","year":"2018","journal-title":"Cyber Def. Rev. JSTOR"},{"key":"ref_29","unstructured":"II, L.W., Tsuchiya, M., and Repko, R. (2020). Improving Cybersecurity Cooperation between the Governments of the United States and Japan, SASAKAWA USA."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"131723","DOI":"10.1109\/ACCESS.2020.3009876","article-title":"Data Security and Privacy Protection for Cloud Storage: A Survey","volume":"8","author":"Yang","year":"2020","journal-title":"IEEE Access"},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"114246","DOI":"10.1109\/ACCESS.2019.2932430","article-title":"Identity-Based Auditing for Shared Cloud Data with Efficient and Secure Sensitive Information Hiding","volume":"7","author":"Fan","year":"2019","journal-title":"IEEE Access"},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"61656","DOI":"10.1109\/ACCESS.2019.2916503","article-title":"A Review of Secure and Privacy-Preserving Medical Data Sharing","volume":"7","author":"Jin","year":"2019","journal-title":"IEEE Access"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"414","DOI":"10.1007\/978-3-540-70545-1_38","article-title":"The Scyther tool: Automatic verification of security protocols","volume":"5423","author":"Cremers","year":"2008","journal-title":"Comput. Aided Verif."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Cremers, C., and Mauw, S. (2012). Operational Semantics and Verification of Security Protocols, Springer.","DOI":"10.1007\/978-3-540-78636-8"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Kahya, N., Ghoualmi, N., and Lafourcade, P. (2012, January 24\u201326). Formal analysis of PKM using scyther tool. Proceedings of the International Conference on Information Technology and e-Services (ICITeS), Sousse, Tunisia.","DOI":"10.1109\/ICITeS.2012.6216598"},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Navas, R.E., and Toutain, L. (2018, January 4\u20137). LATe: A Lightweight Authenticated Time Synchronization Protocol for IoT. Proceedings of the Global Internet of Things Summit (GIoTS), Bilbao, Spain.","DOI":"10.1109\/GIOTS.2018.8534565"},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Thammara, C. (2020). Efficient and Secure NFC Authentication for Mobile Payment Ensuring Fair Exchange Protocol. Symmetry, 12.","DOI":"10.3390\/sym12101649"},{"key":"ref_38","unstructured":"Madhoun, N.E., Guenane, F.A., and Pujolle, G. (2015, January 5\u20137). A Cloud-Based Secure Authentication Protocol for Contactless-NFC Payment. Proceedings of the IEEE International Conference on Cloud Networking (CLOUDNET), Niagara Falls, ON, Canada."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Shehada, D., Yeun, C.Y., Zemerly, M.J., Qutayri, M.A., Hammadi, Y., Damiani, E., and Hu, J. (2017). BROSMAP: A Novel Broadcast Based Secure Mobile Agent Protocol for Distributed Service Applications. Secur. Commun. Netw., 2017.","DOI":"10.1155\/2017\/3606424"},{"key":"ref_40","unstructured":"Palombo, H.M. (2015). A Comparative Study of Formal Verification Techniques for Authentication Protocols. [Master\u2019s Thesis, University of South Florida]."},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"1801","DOI":"10.1109\/TIFS.2019.2950125","article-title":"Using Private and Public Assessments in Security Information Sharing Agreements","volume":"15","author":"Naghizadeh","year":"2019","journal-title":"IEEE Trans. Inf. Forensics Secur."}],"container-title":["Symmetry"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-8994\/13\/12\/2347\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T07:42:10Z","timestamp":1760168530000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-8994\/13\/12\/2347"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,12,7]]},"references-count":41,"journal-issue":{"issue":"12","published-online":{"date-parts":[[2021,12]]}},"alternative-id":["sym13122347"],"URL":"https:\/\/doi.org\/10.3390\/sym13122347","relation":{},"ISSN":["2073-8994"],"issn-type":[{"value":"2073-8994","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,12,7]]}}}