Seong Oun Hwang

dblp:00/6588 · also Seongoun Hwang · DBLP profile ↗
← Back
41ranked-venue papers
3as first author
25since 2021 · last 2026
0000-0003-4240-6255ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 12 · 10 since 2021Artificial intelligence and machine learning · 7 · 1 first-author · 2 since 2021Systems, architecture and hardware · 6 · 5 since 2021Security and privacy · 6 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 When Reasoning Collapses: A Depth-Aware Probe into LLM Reasoning (Student Abstract)
abstract
Large language models (LLMs) often perform better when prompted to explain their reasoning, but it remains unclear how well such gains persist as reasoning depth increases. In this work, we propose a depth-aware evaluation framework alongside the performance results on two structured datasets: CLUTRR (kinship reasoning) and ProofWriter (logical entailment), comparing direct vs. reasoning (reasoning depth = number of inference steps required) prompts across five models. Reasoning gave small gains at shallow depths but quickly weakened and often reversed as tasks grew more complex. In ProofWriter, GPT-5 reached 90% accuracy at depth four in direct model, yet its reasoning accuracy fell below baseline after depth two. Smaller open-source models showed only unstable or negligible gains, underscoring that reasoning in LLMs remains brittle with increased depth.
Azka Ikramullah, Abdul Majeed 0001, Kyunghyun Lee 0008, Seong Oun Hwang
AAAI4
2026 Innovative Multiscroll 6-D Jerk Chaotic System and Its Application in Telemedicine
abstract
The rapid growth of telemedicine has intensified the need for advanced security mechanisms to protect medical images transmitted over open communication networks. Conventional encryption algorithms, while effective for general data protection, often struggle to achieve high security and real-time performance. Chaotic systems have gained considerable attention due to their deterministic yet unpredictable behavior, which makes them promising candidates for cryptographic applications. However, most existing jerk-based chaotic systems exhibit limited dimensionality and restricted control over multi-scroll attractors, thereby constraining their potential for secure image encryption. To overcome these limitations, this study proposes a modified six-dimensional jerk system formulated by integrating three nonlinear control functions into the classical jerk model while preserving its original state variables. The resulting system exhibits rich and tunable chaotic dynamics, capable of producing one-, two-, and three-dimensional multi-scroll attractors and coexisting attractors under different initial conditions. The system’s dynamic characteristics are comprehensively analyzed through bifurcation diagrams, Lyapunov exponents, Poincaré maps, and phase diagrams, confirming its broad chaotic range and high sensitivity to parameters and initial states. Furthermore, a chaos-based medical image encryption scheme is constructed using the proposed system by utilizing SHA-512 key generation and adaptive diffusion mechanisms. Experimental analyses demonstrate near-ideal information entropy ≈ 8.0, low pixel correlation, and strong key sensitivity. The extensive key space of 2512ensures robustness against brute-force attacks, while NPCR and UACI values are consistent with theoretical expectations, confirming resistance to differential attacks.
Noor Munir, Hairong Lin, Seong Oun Hwang
IEEE Internet Things J.3
2026 Blockchain Authorized Privacy-Preserving Framework Using Edge Computing for the Cloud-Assisted Internet of Medical Things
Bakkiam David Deebak, Seong Oun Hwang
IEEE Trans. Cloud Comput.2
2026 Typhon Unleashed: Practical Adversarial Weight Attacks Against On-Device Deep Learning Models
abstract
On-device deep learning (DL) has emerged as a popular approach for mobile apps to deliver artificial intelligence services. Unlike traditional cloud-based approaches, it processes sensitive information locally, addressing severe concerns over sensitive data collection on cloud servers. However, this approach inevitably stores models on user devices and opens a new attack surface, i.e., adversarial weight attacks, which steer DL models to undesirable behaviors through direct model weight modification. Unfortunately, such risks stemming from on-device DL have been left unexplored. In this paper, we present the first practical adversarial weight attack against on-device DL models. To demonstrate this novel attack, we propose TYPHON, an automated attack system that removes the read-only restriction of on-device DL models through the reconstruction of writable counterparts and leverages the inference-only nature of on-device DL models to solve malicious parameters and manipulate model behaviors. Extensive experimental results across diverse datasets and model architectures confirm the superiority of our attack across multiple evaluation metrics. In addition, three real-world case studies are conducted with 100% attack success rates, demonstrating the practicality of TYPHON.
Yujin Huang, Xingliang Yuan, Chunyang Chen 0001, Seong Oun Hwang
IEEE Trans. Dependable Secur. Comput.4
2026 A Sensitivity-Aware and PSO-Driven Differential Privacy Method With Customized Budgets for Structured Data Perturbation
abstract
Differential privacy (DP) is the leading standard for privacy protection, providing rigorous privacy guarantees for various data. However, its conventional approach of treating all records uniformly regarding privacy risk and using a non-adaptive privacy budget ($\epsilon$) often compromises data utility in subsequent analyses. This uniform treatment and fixed$\epsilon$can introduce significant perturbations, making the secondary use of shared data challenging. To overcome these limitations, we introduce a novel record-sensitivity-aware and Particle Swarm Optimization (PSO)-driven customised$\epsilon$-DP method for data perturbation. Our approach significantly enhances data utility without compromising privacy in data sharing by introducing three key optimisations to the traditional DP framework: First, we partition records into three sensitivity classes (high, medium, and low) based on the privacy risk. Second, we adopt a PSO mechanism to determine the optimal$\epsilon$for each partition, perturbing data with a variable$\epsilon$that considers sensitivity, rather than using a single, fixed$\epsilon$for the entire dataset. Finally, noise is injected by grouping attributes horizontally, rather than adding noise to each attribute independently, to prevent the generation of inconsistent values in the perturbed data. Detailed experiments on real benchmark and synthetic datasets demonstrate the superiority of our method in terms of utility and privacy across seven evaluation metrics, compared to the latest state-of-the-art$\epsilon$-DP methods.
Abdul Majeed 0001, Carsten Maple, Seong Oun Hwang
IEEE Trans. Knowl. Data Eng.3
2025 AuGQ: Augmented quantization granularity to overcome accuracy degradation for sub-byte quantized deep neural networks
Ahmed Mujtaba, Wai-Kong Lee, ByoungChul Ko, Hyung Jin Chang, Seong Oun Hwang
Appl. Intell.5
2025 Moving Conditional GAN Close to Data: Synthetic Tabular Data Generation and Its Experimental Evaluation
abstract
Recently, data has ousted oil as the most economical resource in the world, but most companies are reluctant to share customer/user data in pure form and on a large scale due to privacy concerns. Many innovative technologies (e.g., federated learning, split learning) are employed to meet the growing demand for privacy preservation. Despite these technologies, acquiring personal data in order to optimize utility, and then sharing it on a large scale, is still very challenging. Thanks to the rapid development of artificial intelligence (AI), a relatively new and promising solution to resolve these challenges is to generate synthetic data (SD) by mirroring the original dataset’s properties. SD is a promising solution to address growing privacy demands as well as the utility/analytics requirements of many industry stakeholders. In this paper, we propose and implement an SD generation method from a real dataset containing both numerical and categorical attributes by using an improved conditional generative adversarial network (CGAN), and we quantify the feasibility of SD on technical and theoretical grounds. We provide a detailed analysis of SD in original and anonymized forms with the help of multiple use cases, whereas prior research simply assumed that privacy issues in SD are small because AI models do not overfit or SD has a poor connection with real data. We provide insights into the characteristics of SD (distributions, value frequencies, correlations, etc.) produced by the CGAN in relation to the real data. To the best of our knowledge, this is the pioneering work that provides an experiment-based analysis of the quality, privacy, and utility of SD in relation to a real benchmark dataset.
Abdul Majeed 0001, Seong Oun Hwang
IEEE Trans. Big Data2
2025 A Data-Centric $\ell$ℓ-Diversity Model for Securely Publishing Personal Data With Enhanced Utility
abstract
In this paper, we propose and implement a novel anonymization model, called data-centric$\ell$-diversity, to effectively safeguard the privacy of individuals with considerably enhanced utility in data publishing scenarios. Through experimental analysis of real-life datasets, we found that when the data quality is poor (e.g., distributions are uneven), most of the existing methods only anonymize some parts of the data (where distributions are balanced) and leave other parts unprocessed, which can lead to explicit privacy disclosures. Furthermore, they do not identify and repair problematic parts of the data before anonymization, and therefore, they are not secure from the threat of privacy breaches. To address these technical problems, in this paper, we implement an automated method that identifies vulnerabilities in the underlying data to be anonymized w.r.t. distribution, and that repairs them by injecting virtual samples of good quality. Later, we implement a data partitioning strategy that creates compact and diverse classes of size$k$, where$k$is the privacy parameter. Finally, only shallow generalization (or no generalization) is applied to each class to minimally generalize the data, whereas existing methods overly distort data by not improving the quality beforehand, which can lead to poor utility in data-driven services. We conducted detailed experiments on four datasets to justify the performance of our model in realistic scenarios, and achieved promising results from the perspectives of boosted accuracy, privacy preservation, data utility enrichment, and reduced computing overheads. Compared with baseline methods, our model enhanced privacy preservation by 36.56% on three different metrics, and data utility was augmented with 18.65% less information loss and 14.37% greater accuracy. Lastly, our model, on average, has shown a 26.13% reduction in time overheads on four datasets compared to the SOTA baseline methods.
Abdul Majeed 0001, Seong Oun Hwang
IEEE Trans. Big Data2
2025 Privacy-Preserving Authentication With Service Analytics for Forensic-Aware Cyber-Physical Systems
abstract
Forensic Aware Cyber-Physical System (FA-CPS) is an evolving core of digital forensic systems that discovers the integrity of biometric service platforms. Most forensic agencies use emerging technologies such as IoT, Cloud, etc., to integrate a few core elements (networking, communication, and distributed computing) to achieve sustainable memory forensics. This systematic process brings additional capabilities to the physical systems that capture device memories to discover the evidence of malicious tools. Therefore, this paper deals with the Internet of Things (IoT) to form an effective and economical interaction with evolving technologies, including B5G/6G, edge, and cloud computing, to uncover the context of security implications. Most precisely, to sense, collect, share, and analyze numerical data from information systems, the application domain, like healthcare, utilizes computing methods and communications technologies to collect and analyze physiological data from patients in a haphazard way. Since an insecure network has security issues such as information leakage, secret key loss, and fraudulent authentication in Telehealth and remote monitoring, this work applies elliptic curve cryptography (ECC) and a physical unclonable function (PUF) to construct an AI-driven privacy-preserving key authentication framework (AID-PPKAF). In the proposed AID-PPKAF, the PUF generates key information, and ECC encrypts the parameters generated by the system to establish session key agreement and proper mutual authentication. The security analyses (both formal and informal) prove that AID-PPKAF has greater security efficiency than other state-of-the-art approaches. Lastly, a performance analysis using NS3 and a pragmatic study using SVM demonstrate the significance of identity protection in designing a more reliable authentication model.
Bakkiam David Deebak, Seong Oun Hwang
IEEE Trans. Netw. Serv. Manag.2
2024 Efficient TMVP-Based Polynomial Convolution on GPU for Post-Quantum Cryptography Targeting IoT Applications
abstract
Recently proposed lattice-based cryptography algorithms can be used to protect the IoT communication against the threat from quantum computers, but they are computationally heavy. In particular, polynomial convolution is one of the most time-consuming operations in lattice-based cryptography. To achieve efficient implementation, the Number Theoretic Transform (NTT) algorithm is an ideal choice, but it has certain limitations on the parameters, which not all lattice-based schemes can employ directly. Hence, alternative techniques are proposed to accelerate polynomial convolution on lattice-based schemes that cannot utilize the NTT directly. In this paper, we propose a parallel Toeplitz matrix-vector product (TMVP) version to accelerate the polynomial convolution in PQC algorithms implemented it on a graphics processing unit (GPU). This is the first time a TMVP parallel version has been proposed and experimented on different GPU cores (i.e., CUDA-cores and Tensor-cores). The effectiveness of the proposed solution is validated on Saber (the NIST post-quantum standardization finalist) and Sable (an improved version of Saber) schemes. Experimental results show that TMVP-based polynomial convolution using CUDA-cores fails to exhibit a significant enhancement compared to the schoolbook CUDA-core method already proposed by Hafeez et al. 2023. However, when the TMVP technique is applied to Tensor-cores, it outperformed state-of-the-art implementations. The proposed Tensor-core approach outperformed the schoolbook Tensor-core method by up to 1.21×, and outperformed the dot-product-instructions method (Lee et al. 2022) by up to 3.63×. The proposed TMVP Tensor-cores is also faster than the TMVP CUDA-cores method by 13.76×.
Muhammad Asfand Hafeez, Wai-Kong Lee, Angshuman Karmakar, Seong Oun Hwang
IEEE Internet Things J.4
2024 Differential Privacy and k-Anonymity-Based Privacy Preserving Data Publishing Scheme With Minimal Loss of Statistical Information
abstract
Though anonymization mechanisms have made huge progress in fostering the secondary use of data, it is still very challenging to obtain adequate knowledge from anonymized data while preserving privacy. Most existing mechanisms anonymize entire sections of data and fail to maximally preserve the structure/values of real data. Consequently, the performance of those mechanisms and the output (i.e., the anonymized data) remain problematic in real-life scenarios due to the extensive and unneeded anonymization applied. To address these issues, we propose and implement a hybrid (differential privacy (DP) and$k$-anonymity) anonymization scheme that produces supreme-quality anonymized data that offers knowledge similar to real data without compromising privacy. Specifically, we implement a pair of algorithms that divide the dataset into privacy-violating and nonprivacy-violating partitions. Afterward, in a nonprivacy-violating partition, a relaxed privacy budget$\epsilon$is applied to numerical attributes, but most of the categorical attributes are retained (as is) for informative analysis. In privacy-violating partitions, fewer changes are applied to the data by using a reasonable value for$\epsilon$and by exploiting the diversity in sensitive information. Experiments are conducted on three real-life datasets to prove the feasibility of our scheme for futuristic AI applications. Compared with state-of-the-art (SOTA) methods, our scheme preserves 60.81% of the originality in the anonymized data. The privacy risks are reduced by 20.05%, and utility is enhanced by 54.01% and 15.33% based on information loss (IL) and accuracy metrics. Furthermore, the time overhead is 3.13$\times$lower than the SOTA methods.
Abdul Majeed 0001, Seong Oun Hwang
IEEE Trans. Comput. Soc. Syst.2
2024 Healthcare Applications Using Blockchain With a Cloud-Assisted Decentralized Privacy-Preserving Framework
abstract
In recent times, cloud-enabled healthcare services have gained much attention in fulfilling the analysis of privacy risks associated with effective decision management systems including trustworthiness and secure data sharing. This system has revolutionized the medical architecture to evolve unprecedented opportunities in using the technologies of next-generation networks, including services, control, and signaling, to effectively improve content delivery to individuals and organizations. However, it is a highly complex matter to distribute confidential data over a public network because data privacy and device security are at risk. As a result, a cloud-based healthcare application is introduced that integrates the computation capabilities of ubiquitous computing to provide extensive communications over dedicated Internet access in order to store health records. To manage access control mechanisms and process sensitive data without extensive computation, the existing cloud-centric systems access remote servers via dedicated networks. Based on a centralized architecture, a dedicated network uses different application domains to deliver information to the healthcare industry. Unfortunately, computation complexity greatly deteriorates the performance of peer-to-peer (P2P) communications. Thus, this paper presents a cloud-assisted decentralized privacy preserving framework (CA-DPPF) using blockchain and key agreement (KA) mechanisms to achieve secure data storage and privacy. The detailed security analysis proves that the proposed scheme fulfills the desired security properties of healthcare supply chain management (H-SCM) such as conditional traceability, data immutability, and data integrity. Overall, exploratory analysis shows that CA-DPPF guarantees better transaction efficiencies such as less latency and more throughput in order to improve the service utilization factor.
Bakkiam David Deebak, Seong Oun Hwang
IEEE Trans. Mob. Comput.2
2024 High Throughput Lattice-Based Signatures on GPUs: Comparing Falcon and Mitaka
abstract
The US National Institute of Standards and Technology initiated a standardization process for post-quantum cryptography in 2017, with the aim of selecting key encapsulation mechanisms and signature schemes that can withstand the threat from emerging quantum computers. In 2022, Falcon was selected as one of the standard signature schemes, eventually attracting effort to optimize the implementation of Falcon on various hardware architectures for practical applications. Recently, Mitaka was proposed as an alternative to Falcon, allowing parallel execution of most of its operations. These recent advancements motivate us to develop high throughput implementations of Falcon and Mitaka signature schemes on Graphics Processing Units (GPUs), a massively parallel architecture widely available on cloud service platforms. In this paper, we propose the first parallel implementation of Falcon on various GPUs. An iterative version of the sampling process in Falcon, which is also the most time-consuming Falcon operation, was developed. This allows us to implement Falcon signature generation without relying on expensive recursive function calls on GPUs. In addition, we propose a parallel random samples generation approach to accelerate the performance of Mitaka on GPUs. We evaluate our implementation techniques on state-of-the-art GPU architectures (RTX 3080, A100, T4 and V100). Experimental results show that our Falcon-512 implementation achieves 58,595 signatures/second and 2,721,562 verifications/second on an A100 GPU, which is$20.03\times$and$29.51\times$faster than the highly optimized AVX2 implementation on CPU. Our Mitaka implementation achieves 161,985 signatures/second and 1,421,046 verifications/second on the same GPU. Due to the adoption of a parallelizable sampling process, Mitaka signature generation enjoys$\approx 2$–$20 \times$higher throughput than Falcon on various GPUs. The high throughput signature generation and verification achieved by this work can be very useful in various emerging applications, including the Internet of Things.
Wai-Kong Lee, Raymond K. Zhao, Ron Steinfeld, Amin Sakzad, Seong Oun Hwang
IEEE Trans. Parallel Distributed Syst.5
2024 Privacy Preserving Based on Seamless Authentication With Provable Key Verification Using mIoMT for B5G-Enabled Healthcare Systems
abstract
B5G-enabled healthcare systems interconnect a wide range of Internet of Medical Things (IoMT) using supportive networks such as heterogeneous networks and cognitive radio networks to enhance the medical infrastructure. In healthcare, IoMT integrates access technologies, computing infrastructure, and services to connect healthcare systems to handle intensive computation without sharing private data. As a result, healthcare systems accessing a massive IoMT (mIoMT) utilize real-time data sharing to enhance the overall resource efficiency of remote patient monitoring. To optimize the IoT-generated data, the application interface of the computing device regulates self-management messaging systems with healthcare providers. By utilizing direct communication with the networks, they offer a long-lasting service, enhancing the performance trade-off. Since the network has more of a digital existence in the physical universe, a convergence of cloud-server integration with IoT inherently causes more security challenges to preserving the privacy of edge computing systems. Therefore, in this paper, we present privacy preserving based seamless authentication with provable key verification (PPSA-PKV) for securing B5G-enabled healthcare systems. To preserve the identities of the registered users, the proposed PPSA-PKV applies a collision-free cryptographic hash function and elliptic-curve arithmetic. Security analyses including formal and informal show high-level privacy protection for the proposed PPSA-PKV with seamless verification compared to other state-of-the-art approaches. The simulation analysis shows that the proposed PPSA-PKV incurs less delay ($\approx 0.14 sec$) and improves throughput ($\approx 1865 bits$) to fulfill the energy efficiency (at an average 0.294J) of B5G networks. Lastly, a learning model using a support vector machine (SVM) demonstrates the monitoring process of edge data centers to detect malicious authentication requests.
Bakkiam David Deebak, Seong Oun Hwang
IEEE Trans. Serv. Comput.2
2023 Efficient, Error-Resistant NTT Architectures for CRYSTALS-Kyber FPGA Accelerators
abstract
The dawn of cost-effective miniaturised satellites is currently attracting venture capital in a never seen before ratio to launch mega-constellations of satellites for a diverse range of applications. These satellites are vulnerable to attacks by high-capability cyber-criminals (including quantum enabled adversaries), due to the critical data they transmit. Additionally, space missions have long lifespan and a long lead time in terms of development process, requiring a pre-emptive outlook to ensuring their safety. In 2016, National Institute of Standards and Technology (NIST) initiated the competition to standardise the post-quantum cryptography (PQC) schemes, announcing the first portfolio of chosen schemes in 2022. This work targets the only public key exchange (PKE) scheme among the winners of the NIST-PQC standardisation process, CRYSTALS-Kyber, and implements its core bottleneck operation, i.e., number theoretic transform (NTT) extensively used for the polynomial multiplication. To avoid data corruption due to space based radiations, a novel error-resistant model for NTT is presented based on hybrid protection mechanisms, i.e., the use of hamming codes for detection and correction of errors in the twiddle factors and the use of parity computed for all NTT coefficients for error detection. Benchmarking error protection overheads on a Xilinx Virtex-7 FPGA reports 16.4% and 10.8% degradation on the hardware efficiency when the hamming codes for twiddle factors and parity bit for NTT coefficients are used to mitigate errors, respectively. A total of 29.2% area overhead is benchmarked when compared to the standard unprotected NTT implementations.
Safiullah Khan, Ayesha Khalid, Ciara Rafferty, Yasir Ali Shah, Máire O'Neill, Wai-Kong Lee, Seong Oun Hwang
VLSI-SoC7
2023 Intelligent drone-assisted robust lightweight multi-factor authentication for military zone surveillance in the 6G era
Bakkiam David Deebak, Seong Oun Hwang
Comput. Networks2
2023 High Throughput Acceleration of Scabbard Key Exchange and Key Encapsulation Mechanism Using Tensor Core on GPU for IoT Applications
abstract
High throughput key encapsulations and decapsulations are needed by Internet of Things (IoT) applications in order to simultaneously process a multitude of small data in secure communication. In this article, we present two novel techniques for accelerating the implementation of polynomial convolution on a graphics processing unit (GPU), utilizing advanced Tensor cores, which benefit the performance of key encapsulations. First, a polynomial restructuring technique is proposed to allow several polynomials with distinct public keys to be processed in a single communication cycle. This is an improvement compared to the previous work by Lee et al. Next, we observe that polynomial convolution in some key encapsulation mechanisms contains reduction patterns that are not friendly to parallel implementation. We propose separating the multiplication and reduction processes so they can be parallelized independently. To verify the effectiveness of our proposed techniques, we applied it to two key-encapsulation mechanisms from the Scabbard post-quantum key-encapsulation mechanism suite and evaluate their performance. Experimental results show that polynomial convolution using Tensor cores is$1.05\times $faster (for the Florete scheme) and$3.6\times $faster (for the Sable scheme) than using compute unified device architecture core-based multiplication with conventional cores on a GPU. The Tensor cores-based encapsulations and decapsulations are faster than a reference implementation on a CPU supporting AVX2 by more than$5.6\times $and$6.4\times $, respectively, for the Florete scheme and$8.3\times $and$13.3\times $faster, respectively, for the Sable scheme. This shows that the proposed techniques can achieve significantly higher throughput for key exchange and encapsulation mechanisms, which are important for securing IoT applications.
Muhammad Asfand Hafeez, Wai-Kong Lee, Angshuman Karmakar, Seong Oun Hwang
IEEE Internet Things J.4
2023 Area-Time Efficient Implementation of NIST Lightweight Hash Functions Targeting IoT Applications
abstract
To mitigate cybersecurity breaches, secure communication is crucial for the Internet of Things (IoT) environment. Data integrity is one of the most significant characteristics of security, which can be achieved by employing cryptographic hash functions. In view of the demand from IoT applications, the National Institute of Standards and Technology (NIST) initiated a standardization process for lightweight hash functions. This work presents field-programmable gate array (FPGA) implementations and carefully worked out optimizations of four Round-3 finalists in the NIST standardization process. A novel compact PHOTON-Beetle implementation is proposed wherein the underlying matrix multiplication is executed in serialized fashion to achieve a small hardware footprint. Sparkle implementations are carried out by implementing the ARX-box in serialized, parallelized, and hybrid approaches. For Ascon and Xoodyak, the proposed implementations compute certain permutation rounds in one clock cycle in order to explore the tradeoff between computation time and hardware area. As a result, this work achieves the smallest hardware footprint for PHOTON-Beetle consuming an area$3.4 \times $smaller than state-of-the-art implementations. Ascon and Xoodyak are implemented in a flexible manner that achieves throughput-to-area (TP/A) ratios$1.8 \times $and$3.9 \times $higher, respectively, compared to implementations found in the literature. In addition, we propose the first FPGA implementations for the Sparkle hash function. These efficient implementations provide guidelines for choosing a suitable architecture for applications in demand that can be employed in the IoT environment to achieve data integrity for various applications.
Safiullah Khan, Wai-Kong Lee, Angshuman Karmakar, Jose Maria Bermudo Mera, Abdul Majeed 0001, Seong Oun Hwang
IEEE Internet Things J.6
2022 High Throughput Implementation of Post-quantum Key Encapsulation and Decapsulation on GPU for Internet of Things Applications
abstract
[J1C2 Presentation Abstract at IEEE SERVICES 2022 for IEEE Transactions on Services Computing DOI 10.1109/TSC.2021.3103956]
Wai-Kong Lee, Seong Oun Hwang
SERVICES2
2022 RISC32-LP: Low-Power FPGA-Based IoT Sensor Nodes With Energy Reduction Program Analyzer
abstract
Field-programmable gate array (FPGA)-based sensor nodes are popular for their flexible design approach and field reconfigurability. RISC32 is one of the recent Internet of Things (IoT) processors proposed for the development of FPGA-based sensor nodes, and it includes the ability to reconfigure the microarchitecture on the fly in order to reduce dynamic energy consumption. However, such a method does not minimize static energy consumption, which is important in FPGA-based systems. In this work, clock gating (CG) and dynamic voltage and frequency scaling (DVFS) are applied to further reduce the energy consumption in RISC32. In the research presented here, we implemented a new software called the energy reduction program analyzer to estimate the parameters that configure a sensor node to achieve minimum energy consumption, targeting the typical IoT application scenario. Experimental results show that the low-power techniques applied in this work (RISC32-LP) can reduce energy consumption by 47%, compared to the standard RISC32 processor.
Beng-Liong Tan, Kai Ming Mok, Jing-Jing Chang, Wai-Kong Lee, Seong Oun Hwang
IEEE Internet Things J.5
2022 DPCrypto: Acceleration of Post-Quantum Cryptography Using Dot-Product Instructions on GPUs
abstract
Modern NVIDIA GPU architectures offer dot-product instructions (DP2A and DP4A), with the aim of accelerating machine learning and scientific computing applications. These dot-product instructions allow the computation of multiply-and-add instructions in a single clock cycle, effectively achieving higher throughput compared to conventional 32-bit integer units. In this paper, we show that the dot-product instruction can also be used to accelerate matrix-multiplication and polynomial convolution operations, which are widely used in post-quantum lattice-based cryptographic schemes. In particular, we propose a highly optimized implementation of FrodoKEM wherein the matrix-multiplication is accelerated by the dot-product instruction. We also present specially designed data structures that allow an efficient implementation of Saber key-encapsulation mechanism, utilizing the dot-product instruction to speed-up the polynomial convolution. The proposed FrodoKEM implementation achieves$4.37\times $higher throughput than the state-of-the-art implementation on a V100 GPU. This paper also presents the first implementation of Saber on GPU platforms, achieving 124,418, 120,463, and 31,658 key exchanges per second on RTX3080, V100, and T4 GPUs, respectively. Since matrix-multiplication and polynomial convolution operations are the most time-consuming operations in lattice-based cryptographic schemes, we strongly believe that the proposed methods can be beneficial to other KEM and signatures schemes based on lattices.
Wai-Kong Lee, Hwajeong Seo, Seong Oun Hwang, Ramachandra Achar, Angshuman Karmakar, Jose Maria Bermudo Mera
IEEE Trans. Circuits Syst. I Regul. Pap.3
2022 High Throughput Implementation of Post-Quantum Key Encapsulation and Decapsulation on GPU for Internet of Things Applications
abstract
Internet of Things (IoT) sensor nodes are placed ubiquitously to collect information, which is then vulnerable to malicious attacks. For instance, adversaries can perform side channel attack on the sensor nodes to recover the symmetric key for encrypting IoT data. Refreshing the symmetric key frequently can reduce the risk of compromised keys. However, the number of sensor nodes connected to the gateway and cloud server is massive. Refreshed symmetric keys need to be sent to gateway devices and cloud server frequently with a secure key encapsulation mechanism (KEM), which is time-consuming. In this article, novel and efficient implementation techniques are proposed to accelerate Kyber, a post-quantum KEM, on a Graphics Processing Unit (GPU). Fully parallel implementation of number theoretic transform (NTT) with combined levels is presented, which is 2.65× faster than state-of-the-art result on a GPU. Other proposed techniques include parallel rejection sampling, central binomial distribution with coalesced memory access and parallel fine-grain AES-256. These techniques enable high throughput performance with 162760 encapsulations/second and 107631 decapsulations/second on an RTX2060 GPU. This is also the first fine grain implementation of post-quantum KEM (Kyber) on a GPU, which can be used to offer key encapsulation/decapsulation as a service to reduce the burden on IoT systems.
Wai-Kong Lee, Seong Oun Hwang
IEEE Trans. Serv. Comput.2
2021 Novel Postquantum MQ-Based Signature Scheme for Internet of Things With Parallel Implementation
abstract
Internet of Things (IoT) is a paradigm shifting technology that enables many innovative applications in the near future. Proactive measures are required to protect such architecture from cyber attacks. One of the most important security issues in this architecture is the authentication of edge nodes, which can be resolved through the deployment of digital signatures. However, existing standardized digital signatures are vulnerable to attacks from quantum computers, which can be unsafe in the near future. In this article, we propose a new signature scheme based on multivariate polynomials with efficient key and signature sizes, which is resistant to quantum computer attacks. The proposed scheme is also very friendly to parallel implementation, enabling efficient deployment of edge nodes authentication at high throughput. When implemented on a GPU device, the proposed scheme can generate 113 signatures/s and verify 120 signatures/s, which is 12.56× and 10.00× faster than a serial implementation in CPU.
Sedat Akleylek, Meryem Soysaldi, Wai-Kong Lee, Seong Oun Hwang, Denis Chee-Keong Wong
IEEE Internet Things J.4
2021 Scalable and Efficient Hardware Architectures for Authenticated Encryption in IoT Applications
abstract
Internet of Things (IoT) is a key enabling technology, wherein sensors are placed ubiquitously to collect and exchange information with their surrounding nodes. Due to the inherent interconnectivity, IoT devices are vulnerable to cybersecurity attacks. To mitigate these vulnerabilities, cryptographic primitives can be employed, but they require significant computation, which restricts their adoption in IoT. Moreover, IoT systems have diverse requirements, ranging from high-throughput (TP) to the area constrained. This makes it hard to deploy appropriate security measures in a systematic manner. To address these issues, three generic implementation strategies (unrolled, round-based, and serialized) are proposed for developing highly efficient hardware architectures. They are applicable to all authenticated encryption schemes and are lightweight and fast, compared to conventional public key encryption. In this article, Ascon is implemented as an example based on those three strategies: 1) the unrolled architecture achieves TP of 766.9 Mb/s (Ascon-128) and 1389.2 Mb/s (Ascon-128a), which are suitable for high-throughput IoT applications; 2) the round-based architecture achieves 0.153 (Ascon-128) and 0.244 (Ascon-128a) TP-to-area ratio, which are, respectively, 73.8% and 40.2% better than state-of-the-art results; and 3) a novel serialized implementation technique is proposed wherein the substitution-box (S-box) is processed in multiple-bit-per-cycle, in contrast to the conventional one-bit-per-cycle approach. The TP of the two-bits-per-clock-cycle implementation is increased by 230.8% with only 36.8% additional hardware area. The proposed strategies allow us to scale the number of rounds (round-based) and bits-per-clock-cycle (serialized) to meet differing requirements in TP and area which are demonstrated for smart city IoT applications.
Safiullah Khan, Wai-Kong Lee, Seong Oun Hwang
IEEE Internet Things J.3
2021 Parallel implementation of Nussbaumer algorithm and number theoretic transform on a GPU platform: application to qTESLA
Wai-Kong Lee, Sedat Akleylek, Denis Chee-Keong Wong, Wun-She Yap, Bok-Min Goi, Seong Oun Hwang
J. Supercomput.6
2020 Efficient Anonymous Multi-group Broadcast Encryption
Intae Kim, Seong Oun Hwang, Willy Susilo, Joonsang Baek, Jongkil Kim
ACNS (1)2
2020 A PKI without TTP based on conditional trust in blockchain
Kyunghyun Han, Seong Oun Hwang
Neural Comput. Appl.2
2020 Special issue on "Green and Human Information Technology 2019"
Seong Oun Hwang, Sansanee Auephanwiriyakul, M. Usman Akram, Bok-Min Goi, Chee Seng Chan
Neural Comput. Appl.1
2020 A neural network approach to remove rain using reconstruction and feature losses
Kamran Javed, Ghulam Hussain, Furqan Shaukat, Seong Oun Hwang
Neural Comput. Appl.4
2020 An efficient public key functional encryption for inner product evaluations
Intae Kim, Jong Hwan Park, Seong Oun Hwang
Neural Comput. Appl.3
2019 Enhancement of a Lightweight Attribute-Based Encryption Scheme for the Internet of Things
abstract
In this paper, we present the enhancement of a lightweight key-policy attribute-based encryption (KP-ABE) scheme designed for the Internet of Things (IoT). The KP-ABE scheme was claimed to achieve ciphertext indistinguishability under chosen-plaintext attack in the selective-set model but we show that the KP-ABE scheme is insecure even in the weaker security notion, namely, one-way encryption under the same attack and model. In particular, we show that an attacker can decrypt a ciphertext which does not satisfy the policy imposed on his decryption key. Subsequently, we propose an efficient fix to the KP-ABE scheme as well as extending it to be a hierarchical KP-ABE (H-KP-ABE) scheme that can support role delegation in IoT applications. An example of applying our H-KP-ABE on an IoT-connected healthcare system is given to highlight the benefit of the delegation feature. Lastly, using the NIST curves secp192k1 and secp256k1, we benchmark the fixed (hierarchical) KP-ABE scheme on an Android phone and the result shows that the scheme is still the fastest in the literature.
Syh-Yuan Tan, Kin-Woon Yeow, Seong Oun Hwang
IEEE Internet Things J.3
2018 Connectivity analysis of underground sensors in wireless underground sensor networks
Hoang Thi Huyen Trang, Le The Dung, Seong Oun Hwang
Ad Hoc Networks3
2017 A compression sensing and noise-tolerant image encryption scheme based on chaotic maps and orthogonal matrices
Jawad Ahmad 0001, Muazzam Ali Khan, Seong Oun Hwang, Jan Sher Khan
Neural Comput. Appl.3
2016 A secure image encryption scheme based on chaotic maps and affine transformation
Jawad Ahmad 0001, Seong Oun Hwang
Multim. Tools Appl.2
2016 Efficient certificate-based encryption schemes without pairing
abstract
Abstract Recently, a lot of researches focused on identity‐based encryption (IBE). The advantage of this scheme is that it can reduce the cost of the public key infrastructure by simplifying certificate management. Although IBE has its own innovations, one of its weaknesses is the key escrow problem. That is, the private key generator in IBE knows decryption keys for all identities and consequently can decrypt any ciphertexts. The certificate‐based encryption (CBE) scheme proposed in EUROCRYPT 2003 provides a solution for the key escrow problem by allowing the certification authority to possess a partial decryption key that comprises the full decryption key together with the user‐generated private key. In this paper, we propose new CBE schemes without pairing and prove them to be Indistinguishability under Chosen Ciphertext Attack secure in the random oracle model based on the hardness of the computational Diffie–Hellman problem. When compared with other CBE schemes, our schemes are significantly efficient in terms of performance, which makes our schemes suitable for computation‐limited node (e.g., sensor, wearable device) networks. Copyright © 2016 John Wiley & Sons, Ltd.
Minh-Ha Le, Intae Kim, Seong Oun Hwang
Secur. Commun. Networks3
2016 An Efficient Predicate Encryption with Constant Pairing Computations and Minimum Costs
abstract
Predicate encryption is a public-key encryption that supports attribute-hiding as well as payload-hiding and achieves high flexibility in terms of access control. Since Katz, Sahai, and Waters first proposed the predicate encryption scheme in 2008, several predicate encryption schemes have been published. Unfortunately these are impractical as they require$O(n)$pairing computations for decryption with considerably large sized public parameters, secret key, and ciphertext, where$n$is the dimension of the attribute/predicate vectors. In this paper, we propose a very efficient predicate encryption scheme that requires only$n$exponentiation plusthreepairing computations for decryption with shorter sized public parameters, secret key, and ciphertext. The proposed scheme is proven selective attribute-secure against chosen-plaintext attacks in the standard model under the Asymmetric Decisional Bilinear Diffie-Hellman assumptions.
Intae Kim, Seong Oun Hwang, Jong Hwan Park, Chanil Park
IEEE Trans. Computers2
2015 Privacy preserving revocable predicate encryption revisited
abstract
Abstract Predicate encryption (PE) that provides both the access control of ciphertexts and the privacy of ciphertexts is a new paradigm of public‐key encryption. An important application of PE is a searchable encryption system in cloud storage, where it enables a client to securely outsource the search of a keyword on encrypted data without revealing the keyword to the cloud server. One practical issue of PE is to devise an efficient revocation method to revoke a user when the secret key of the user is compromised. Privacy preserving revocable PE (RPE) can provide not only revocation but also the privacy of revoked users. In this paper, we first define two new security models of privacy preserving RPE: the strongly full‐hiding (FH) security and the weakly FH security. Next, we propose a general RPE construction from any PE scheme and prove its security in the weakly FH security model. Our generic RPE scheme is efficient because the number of ciphertext elements is not proportional to the number of users in a receiver set. Additionally, our RPE scheme can support polynomial‐size circuits if a recently proposed functional encryption scheme for polynomial‐size circuits is used as an underlying PE scheme. Copyright © 2014 John Wiley & Sons, Ltd.
Kwangsu Lee, Intae Kim, Seong Oun Hwang
Secur. Commun. Networks3
2014 Efficient identity-based broadcast signcryption schemes
abstract
ABSTRACT Most of broadcast encryption schemes do not provide source authentication property. This allows an adversary to launch impersonating attacks. Therefore, broadcast encryption scheme without source authentication is not applicable in our real life as it is. In this paper, we propose two source‐authenticated broadcast encryption schemes that achieve both confidentiality and authenticity simultaneously. Ciphertexts in both schemes are of constant size, independent of the size of the receiver set. The first scheme is particularly efficient in case of pre‐computation, whereas the overall performance of the second scheme is better than that of Selvi et al.'s scheme. Copyright © 2013 John Wiley & Sons, Ltd.
Intae Kim, Seong Oun Hwang
Secur. Commun. Networks2
2012 Fine-grained user access control in ciphertext-policy attribute-based encryption
abstract
ABSTRACT Key revocation is one of the most challenging and open issues in attribute‐based encryption (ABE). The previous revocable ABE schemes feature a mechanism that revokes the attribute key periodically without any consideration of the user membership associated with the attribute. Thus, non‐revoked users are enforced to access the key authority periodically to receive keying materials in order to update the current key. This is due to the fact that the revocation is done only on the attribute level, which results in security and scalability problems. In this paper, we propose a fine‐grained user revocation scheme without affecting any non‐revoked users who share the same attributes in ciphertext‐policy ABE; it does not require the users to access the key authority and to update keys periodically. The proposed scheme improves the efficiency compared with previous revocable schemes and enhances the security in terms of the backward/forward secrecy on any membership changes in the ciphertext‐policy ABE system. Copyright © 2011 John Wiley & Sons, Ltd.
Junbeom Hur, Chanil Park, Seong Oun Hwang
Secur. Commun. Networks3
2004 Privacy Protection in Ubiquitous Computing Based on Privacy Label and Information Flow
Seong Oun Hwang, Kisong Yoon
ICCSA (2)1
2004 Modeling and implementation of digital rights
Seong Oun Hwang, Kisong Yoon, Kyung Pyo Jun, Kwang Hyung Lee
J. Syst. Softw.1