Figures (4)  Tables (8)
    • Figure 1. 

      A high-level overview of the proposed VishwasQ framework that depicts the relationship between the client layer and the service, edge, and data layers. The architecture features the development of user services using React, integration with Firebase for authentication, use of post-quantum cryptography (Kyber, AES-GCM, and SPHINCS+) for security, secure storage in MySQL, integration with the Ethereum blockchain and smart contracts, and QR code validation for parking accessibility.

    • Figure 2. 

      Operational workflow of the proposed system starting from user authentication, parking reservation, data encryption with PQC, secure storage of data in the database, secure payment using blockchain, generation of QR and validation, parking session management, automated enforcement of penalties, and audit logging in the blockchain.

    • Figure 3. 

      Traditional, IoT-cloud-based, and the proposed PQC-blockchain parking system are compared qualitatively regarding security, transparency, and automation. The proposed framework combines the quantum resistance of cryptography with decentralized blockchain services to achieve the best overall performance.

    • Figure 4. 

      Assessment of the proposed framework. Scalability characteristics of the framework. (a) System latency vs number of concurrent users. In (b), the execution time of the proposed PQC-AES scheme is compared with the conventional RSA-AES method, showing that the computational overhead of PQC is modest.

    • Research study Technology Quantum-resilience Automated penalties Immutable audit trail Access control Scalability Computational overhead Implementation status Performance evaluation Application domain
      Ankarboina
      et al.[9]
      ECC, AES-GCM, and JWT × × × JWT tokens Moderate Low Prototype Throughput and registration delay Smart parking
      Singh et al.[10] AI, blockchain × × ✓ Mobile App Moderate Medium Prototype Slot allocation accuracy Smart parking
      Zhang et al.[11] IoT, blockchain, SC × ✓ ✓ RFID/NFC Moderate Medium Prototype Transaction automation Smart parking
      Vijayalakshmi et al.[12] Intrusion detection system × × × VANET Moderate High Prototype 97% attack detection accuracy Car parking system
      Alymani et al.[13] IoT, machine learning × × × Not specified High Medium Prototype Vehicle detection accuracy Smart cities
      Liu et al.[15] PQC, blockchain ✓ × ✓ Not specified Moderate High Research prototype Security analysis General IoT
      Nanwatkar
      et al.[16]
      IoT, AI, ML, Sensors × × × Mobile/web App High Medium Prototype Smart parking automation Smart parking
      Aslam et al.[5] Quantum-resistant blockchain ✓ ✓ ✓ Blockchain contracts Moderate High Prototype Blockchain performance Intelligent transportation
      Proposed work PQC, blockchain, SC, QR ✓ ✓ ✓ QR code High Moderate
      (15% over RSA)
      Fully implemented prototype Encryption time, blockchain latency, gas cost, QR validation time, end-to-end performance Smart parking
      RFID, Radio Frequency Identification; NFC, Near Field Communication.

      Table 1. 

      Summary of comparison with existing research studies.

    • Input: user booking data message, service public and private keys, and signature key pairs are the input for the PQC-based encryption protocol
      $ \mathrm{m} $: User booking data message
      $ {\text{pk}}_{\text{server}} $: Server public key
      $ {\text{sk}}_{\text{server}} $: Server private key
      $ (\mathrm{pksig},\;\text{sksig}) $: Signature key pairs
      Output: encrypted data tuple, decrypted message after successful verification is used as an output of the algorithm. $ (\text{msgid},\mathrm{c},\text{ct},\sigma ) $: Encrypted data tuple
      $ \mathrm{m} $: Decrypted message after successful verification
      procedure
      1: $ \mathrm{ENCRYPTDATA}\;(\mathrm{message}\;\mathrm{m},{\text{pk}}_{\text{server}}) $
      2: $ (\mathrm{ct},\;\mathrm{k}) \leftarrow \mathrm{Kyber}.\mathrm{Encaps}({\text{pk}}_{\text{server}}) $
      3: $ \mathrm{c} \leftarrow \mathrm{AES}\;\mathrm{GCM}.\mathrm{Encrypt}(\mathrm{k},\;\mathrm{m}) $
      4: $ \sigma \leftarrow \mathrm{SPHINCS}\;+.\;\mathrm{Sign}\;(\text{sksig},\;\mathrm{c},\;\mathrm{ct}) $
      5: $ \mathrm{DB}.\mathrm{store}(\mathrm{msgid},\;\mathrm{c},\;\mathrm{ct},\;\sigma ) $
      6: $ {\mathrm{return}}({\mathrm{msgid}},\; {\mathrm{c}},\; {\mathrm{ct}},\; \sigma) $
      end procedure
      procedure
      7: $ \mathrm{DECRYPTDATA}\;(\mathrm{msgid},{\text{sk}}_{\text{server}}) $
      8: $ (\mathrm{c},\;\mathrm{ct},\;\sigma ) \leftarrow \mathrm{DB}.\;\mathrm{fetch}(\mathrm{msgid}) $
      9: $ \mathrm{k} \leftarrow \mathrm{Kyber}.\mathrm{Decaps}({\text{sk}}_{\text{server}},\;\mathrm{ct}) $
      10: $ \mathrm{m} \leftarrow \mathrm{AES}\;\mathrm{GCM}.\mathrm{Decrypt}(\mathrm{k},\;\mathrm{c}) $
      11: Verify σ with $ pksig $
      12: if verification succeeds, then
      13: return m
      14: else
      15: return Failure
      16: end if
      end procedure

      Table 1. 

      PQC-based encryption protocol for a smart parking system.

    • Input: Identity of the user, QR code identifier, server private key used as input for QR code verification data.
      $ \text{user} $: Identity of the user
      $ \text{QRid} $: QR code identifier
      $ {\text{sk}}_{\text{server}} $: Server private key
      Output: Success/failure status
      Parking session state updated
      procedure
      1: $ \mathrm{V}\text{ALIDATE}\mathrm{QR}(\mathrm{user},\mathrm{QRid}) $
      2: $ \text{booking}\leftarrow \mathrm{DB}.\mathrm{fetch}(\mathrm{QRid}) $
      3: data ← PQC. Decrypt(sk server, booking. encData)
      4: if $ data.valid $ = True then
      5: if $ Session.state $ = "Entry" then
      6: $ \mathrm{SmartContract}.\mathrm{updateState}(\mathrm{QRid},\mathrm{Active}) $
      7: $ \mathrm{Gate}.\mathrm{open}() $
      8: return Success
      9: else if $ Session.state $ = "Exit" then
      10: $ {\mathrm{T}}_{\text{parked}}\leftarrow \text{currentTime}-\mathrm{data}.\text{startTime} $
      11: if $ {\mathrm{T}}_{\text{parked}}> \mathrm{data}.\text{allowedTime} $ then
      12: $ \text{Penalty}\leftarrow ({\mathrm{T}}_{\text{parked}}-\mathrm{data}.\mathrm{allowedTime})\times {\mathrm{P}}_{\text{rate}} $
      13: $ \mathrm{SmartContract}.\mathrm{deduct}(\mathrm{Penalty}) $
      14: else
      15: $ \mathrm{SmartContract}.\mathrm{refund}(\mathrm{user}) $
      16: end if
      17: $ \mathrm{SmartContract}.\mathrm{updateState}(\mathrm{QRid},\mathrm{Ended}) $
      18: $ \mathrm{Gate}.\mathrm{open}() $
      19: $ \text{returnSuccess} $
      20: end if
      21: else
      22: $ \text{returnFailure} $
      23: end if
      end procedure

      Table 2. 

      QR code validation protocol (simplified).

    • Input: Message identifier, parking slot, and user's account are used as input to the smart contract parking workflow
      $ \text{msgid} $: Message identifier
      $ \text{slot} $: Parking slot
      $ \text{price} $: Parking price
      $ \text{user} $: User's account
      Output: Reserved/Active/Ended: parking session state
      Penalty/Refund: payment settlement
      procedure
      1: $ \text{CREATE}\mathrm{R}\text{ESERVATION}(\mathrm{msgid},\mathrm{slot},\mathrm{price}) $
      2: $ \mathrm{require}(\mathrm{slot}.\text{available}=\mathrm{True}) $
      3: $ \mathrm{escrow}[\mathrm{msgid}]\leftarrow \text{price} $
      4: $ \mathrm{state}[\mathrm{msgid}]\leftarrow \text{Reserved} $
      5: $ \text{emit}\mathrm{Event}(\mathrm{ParkingReserved},\mathrm{msgid},\mathrm{slot},\mathrm{price}) $
      end procedure
      procedure
      6: $ \text{START}\mathrm{S}\text{ESSION}(\mathrm{msgid}) $
      7: $ \mathrm{require}(\mathrm{state}[\mathrm{msgid}]=\mathrm{Reserved}) $
      8: $ \mathrm{startTime}[\mathrm{msgid}]\leftarrow \mathrm{block}.\text{timestamp} $
      9: $ \mathrm{state}[\mathrm{msgid}]\leftarrow \text{Active} $
      10: $ \text{emit}\mathrm{Event}(\mathrm{ParkingStarted},\mathrm{msgid},\mathrm{startTime}[\mathrm{msgid}]) $
      end procedure
      procedure
      $ 11\colon ~\text{END}\mathrm{S}\text{ESSION}(\mathrm{msgid}) $
      12: $ \mathrm{require}(\mathrm{state}[\mathrm{msgid}]=\mathrm{Active}) $
      13: $ \text{parkedTime}\leftarrow \mathrm{block}.\text{timestamp}-\mathrm{startTime}[\mathrm{msgid}] $
      14: if $ \text{parkedTime}> \mathrm{allowedTime}[\mathrm{msgid}] $ then
      15: $ \text{overtime}\leftarrow \text{parkedTime}-\mathrm{allowedTime}[\mathrm{msgid}] $
      16: $ \text{penalty}\leftarrow \text{overtime}\times \text{penaltyRate} $
      17: $ \mathrm{escrow}[\mathrm{msgid}]\leftarrow ~\mathrm{escrow}[\mathrm{msgid}]-\text{penalty} $
      18: $ \mathrm{transfer}(\mathrm{penalty},\mathrm{owner}) $
      19: end if
      20: $ \text{refund}\leftarrow \mathrm{escrow}[\mathrm{msgid}] $
      21: $ \mathrm{transfer}(\mathrm{refund},\mathrm{user}[\mathrm{msgid}]) $
      22: $ \mathrm{state}[\mathrm{msgid}]\leftarrow \text{Ended} $
      23: $ \text{emit}\mathrm{Event}(\mathrm{ParkingEnded},\;\mathrm{msgid},\;\mathrm{parkedTime},\;\mathrm{penalty}) $
      end procedure
      procedure
      24: $ \text{WITHDRAW} $
      25: $ \mathrm{require}(\mathrm{msg}.\text{sender}=\mathrm{owner}) $
      26: $ \mathrm{transfer}(\mathrm{contractBalance},\mathrm{owner}) $
      end procedure

      Table 3. 

      Smart contract parking workflow.

    • Layer/module Technology/tools Functionality Description
      Frontend layer React 18, Firebase authentication User interface and secure access Provides a scalable and responsive UI for slot search, booking, and QR display with secure user authentication and session management
      Backend service layer Python 3.11, Flask, PyMySQL API and business logic Handles booking requests, slot allocation, payment initiation, and communication between frontend and database
      PQC security module Kyber-like KEM, AES-GCM Quantum-resistant encryption Implements hybrid encryption where Kyber secures symmetric keys and AES-GCM encrypts sensitive booking data, ensuring confidentiality and integrity
      Database layer MySQL Data storage and management Stores encrypted user data, booking information, cryptographic keys, and signature artifacts in structured tables
      Blockchain layer Ethereum testnet (Sepolia/Goerli), Solidity Decentralized audit and smart contracts Enables immutable audit trails and automates booking, payment, and penalty enforcement using smart contracts
      Edge layer Raspberry Pi
      (or similar IoT device)
      QR code validation and access control Performs real-time QR verification and controls physical gate access for parking entry/exit
      QR code module QR generator and validator Secure access mechanism Generates time-bound QR codes for booking validation and prevents unauthorized access
      Payment and penalty module Smart contracts (Solidity) Automated transactions Handles booking payments and penalty enforcement transparently and automatically via blockchain
      System integration Hybrid architecture End-to-end system coordination Integrates PQC, blockchain, backend, and IoT components to ensure secure, efficient, and real-time smart parking operations

      Table 2. 

      Technology stack and functional components of the proposed quantum-resilient trust framework.

    • Metric Baseline (RSA) Proposed (PQC + AES)
      Key encapsulation time (ms) 18 21
      Booking encryption overhead 0 15%
      QR gen + email (ms) 1,500 1,700
      Blockchain confirmation (s) 10–30 10–30

      Table 3. 

      Performance summary (standard metrics).

    • Attack type Security mechanism Mitigation
      Replay attack QR code with time limit and blockchain verification of transactions Stops reuse of expired or duplicate transactions
      MITM attack Kyber-KEM, AES-256-GCM, TLS-authentication Offers private and authenticated conversations
      Sybil attack Identity verification with blockchain and Firebase authentication Prevents creation of fake identities without permission
      Denial-of-service (DoS) Smart contract verification and backend request validation Reduces malicious handling of requests and unauthorized access
      Smart contract attack Checks-Effects-Interactions pattern along with re-entrancy guard Prevents re-entry and unauthorized contract execution
      Database tampering AES-GCM encryption and unalterable blockchain audit logs Protects confidentiality and integrity of data at rest
      Quantum attack Kyber KEM and SPHINCS+ Resists quantum adversaries

      Table 4. 

      Security analysis of the proposed VishwasQ framework.

    • ParameterIoT-only systemBlockchain-based systemProposed approach (PQC + blockchain + QR)
      Security-levelLow (classical encryption)Medium (blockchain integrity)High (PQC + blockchain security)
      Quantum resistance[35]NoNoYes
      Data integrityVulnerable to tamperingImmutable recordsImmutable + cryptographically secure
      Privacy protectionLimitedModerateStrong (PQC encryption)
      Access controlRFID/sensorsSmart contract-basedQR code + blockchain validation
      Automation of paymentsManual/semi-automaticAutomated via smart contractsFully automated with penalty enforcement
      TransparencyLowHighVery high
      ScalabilityHighModerate (gas cost issues)Moderate (optimizable with layer 2)
      LatencyLowHigh (blockchain delay)Moderate (optimized hybrid flow)
      Suitability for smart cities[36,37]LimitedGoodExcellent

      Table 5. 

      Smart parking framework/architecture comparative analysis.