VLDB 2026 Research / reviewers in the wild / expert
Masoumeh Safkhani
dblp:09/8815
· DBLP profile ↗
22ranked-venue papers
6as first author
10since 2021 · last 2025
0000-0002-1897-0828ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 11 · 2 first-author · 8 since 2021Security and privacy · 5 · 2 first-author · 1 since 2021Systems, architecture and hardware · 3 · 2 first-authorHuman-computer interaction and ubiquitous computing · 2 · 1 since 2021Artificial intelligence and machine learning · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | ERASMIS: An ECC-based robust authentication protocol suitable for medical IoT systems
Mohammad Reza Servati, Masoumeh Safkhani, Amir Masoud Rahmani, Mehdi Hosseinzadeh 0001 |
Comput. Networks | 2 |
| 2025 | SCF-VPEKS: secure channel free verifiable public key encryption with keyword search
Mohammad Zamani, Masoumeh Safkhani, Negin Daneshpour |
Wirel. Networks | 2 |
| 2023 | SAPWSN: A Secure Authentication Protocol for Wireless Sensor Networks
Foroozan Ghosairi Darbandeh, Masoumeh Safkhani |
Comput. Networks | 2 |
| 2023 | ECCPWS: An ECC-based protocol for WBAN systemsabstractThe development of Wireless Body Area Network (WBAN) and Wearable Health Monitoring Systems (WHMS) play a key role in healthcare monitoring. WBAN includes medical sensors that monitor vital signs of patients, collect data and usually transmit them to medical servers via wireless channels. Therefore, the patient’s sensitive information sent over the channel can be vulnerable to various attacks. Hence, designing lightweight authentication security protocols for these systems with the lowest computational and communication costs has become a major challenge. Recently, Sowjanya et al. (2020) presented a lightweight authentication scheme for WHMS based on Elliptic Curve Cryptography (ECC), which provides optimal security features and low storage, communication and computational costs. In this paper, the security of their scheme is evaluated and passive insider secret disclosure and replay attacks against their scheme are presented. It is obvious that other attacks such as desynchronization attack and impersonation attack can be applied to this protocol by obtaining the secret value of network manager. The complexity of our proposed attacks is just one run of the protocol and their success probability equals to one. Finally, by remedying the Sowjanya et al. (2020) ’s protocol, a lightweight ECC-based authentication scheme called ECCPWS is proposed. Moreover, the proposed protocol’s security proof is performed via informal methods and also formally through Real-Or-Random (ROR) model, BAN logic, Scyther and AVISPA tools. The security verification results of ECCPWS show that the ECCPWS has complete security against various security vulnerabilities and attacks. Fatemeh Pirmoradian, Masoumeh Safkhani, Mohammad Dakhilalian |
Comput. Networks | 2 |
| 2023 | ECCbAS: An ECC based authentication scheme for healthcare IoT systems
Mohammad Reza Servati, Masoumeh Safkhani |
Pervasive Mob. Comput. | 2 |
| 2023 | A new method for privacy preserving association rule mining using homomorphic encryption with a secure communication protocol
S. Zehtabchi, Negin Daneshpour, Masoumeh Safkhani |
Wirel. Networks | 3 |
| 2022 | An Authentication Protocol for Next Generation of Constrained IoT SystemsabstractWith the exponential growth of connected Internet of Things (IoT) devices around the world, security protection and privacy preservation have risen to the forefront of design and development of innovative systems and services. For low-value IoT devices that identify and track billion of goods in various industries—such as radio-frequency identification (RFID) tags—this involves multiple challenges in very constrained environments. IoT devices aim to design low-cost, low-complexity infrastructure while enabling robust authentication protocols with reduced latency and energy consumption. Given these challenges, in this article, we present a new lightweight authentication protocol for IoT applications, employing an authenticated-encryption (AE) cryptosystem with associated data (AEAD). Since AEAD algorithms provide data confidentiality and message integrity simultaneously, security analysis [Real-or-Random (RoR) and Scyther] results prove the robustness of the proposed protocol against IoT threats. Furthermore, to measure the computation and communication cost, FPGA and ASIC simulations using four different AEAD candidates of National Institute of Standards and Technology (NIST) lightweight cryptography competition are executed. The implementation results [e.g., 4744 gate equivalent (GE) and 0.87-mw power] clearly show that our novel design can be applied to a wide range of constrained IoT devices complying with low-cost, lightweight, and high-speed requirements. Samad Rostampour, Nasour Bagheri, Ygal Bendavid, Masoumeh Safkhani, Saru Kumari, Joel J. P. C. Rodrigues |
IEEE Internet Things J. | 4 |
| 2022 | Improving RFID/IoT-based generalized ultra-lightweight mutual authentication protocols
Masoumeh Safkhani, Samad Rostampour, Ygal Bendavid, Sadegh Sadeghi, Nasour Bagheri |
J. Inf. Secur. Appl. | 1 |
| 2022 | An authentication and key agreement scheme for smart grid
Masoumeh Safkhani, Saru Kumari, Mohammad Shojafar, Sachin Kumar 0002 |
Peer-to-Peer Netw. Appl. | 1 |
| 2021 | LAPCHS: A lightweight authentication protocol for cloud-based health-care systems
Fahimeh Nikkhah, Masoumeh Safkhani |
Comput. Networks | 2 |
| 2020 | CNCAA: A new anti-collision algorithm using both collided and non-collided parts of information
Amir Abbasian, Masoumeh Safkhani |
Comput. Networks | 2 |
| 2020 | IoT in medical & pharmaceutical: Designing lightweight RFID security protocols for ensuring supply chain integrity
Masoumeh Safkhani, Samad Rostampour, Ygal Bendavid, Nasour Bagheri |
Comput. Networks | 1 |
| 2020 | ECCbAP: A secure ECC-based authentication protocol for IoT edge devices
Samad Rostampour, Masoumeh Safkhani, Ygal Bendavid, Nasour Bagheri |
Pervasive Mob. Comput. | 2 |
| 2020 | An Improved Blockchain-Based Authentication Protocol for IoT Network ManagementabstractCommunication security between IoT devices is a major concern in this area, and the blockchain has raised hopes that this concern will be addressed. In the blockchain concept, the majority or even all network nodes check the validity and accuracy of exchanged data before accepting and recording them, whether this data is related to financial transactions or measurements of a sensor or an authentication message. In evaluating the validity of an exchanged data, nodes must reach a consensus in order to perform a special action, in which case the opportunity to enter and record transactions and unreliable interactions with the system is significantly reduced. Recently, in order to share and access management of IoT devices information with distributed attitude a new authentication protocol based on blockchain is proposed and it is claimed that this protocol satisfies user privacy preserving and security. However, in this paper, we show that this protocol has security vulnerabilities against secret disclosure, replay, traceability, and Token reuse attacks with the success probability of 1 and constant complexity of also 1. We also proposed an improved blockchain-based authentication protocol (IBCbAP) that has security properties such as secure access management and anonymity. We implemented IBCbAP using JavaScript programming language and Ethereum local blockchain. We also proved IBCbAP’s security both informally and formally through the Scyther tool. Our comparisons showed that IBCbAP could provide suitable security along with reasonable cost. Mostafa Yavari, Masoumeh Safkhani, Saru Kumari, Sachin Kumar 0002, Chien-Ming Chen 0001 |
Secur. Commun. Networks | 2 |
| 2020 | SEOTP: a new secure and efficient ownership transfer protocol based on quadric residue and homomorphic encryption
Farokhlagha Moazami, Masoumeh Safkhani |
Wirel. Networks | 2 |
| 2018 | An improved low-cost yoking proof protocol based on Kazahaya's flaws
Nasour Bagheri, Masoumeh Safkhani, Mojtaba Eslamnezhad Namin, Samad Rostampour |
J. Supercomput. | 2 |
| 2018 | Implementation of secret disclosure attack against two IoT lightweight authentication protocols
Masoumeh Safkhani, Mahyar Shariat |
J. Supercomput. | 1 |
| 2017 | Passive secret disclosure attack on an ultralightweight authentication protocol for Internet of Things
Masoumeh Safkhani, Nasour Bagheri |
J. Supercomput. | 1 |
| 2014 | Cryptanalysis of a new EPC class-1 generation-2 standard compliant RFID protocol
Nasour Bagheri, Masoumeh Safkhani, Majid Naderi |
Neural Comput. Appl. | 2 |
| 2014 | Weaknesses in a new ultralightweight RFID authentication protocol with permutation - RAPPabstractABSTRACT Tian et al. proposed a novel ultralightweight RFID mutual authentication protocol [1] that has recently been analyzed in several articles. In this letter, we first propose a desynchronization attack that succeeds with probability almost 1, which improves upon the 0.25 given in a previous analysis by Ahmadian et al. We also show that the bad properties of the proposed permutation function can be exploited to disclose several bits of the tag's secret (rather than just 1 bit as previously shown by Avoine et al.), which increases the power of a traceability attack. Finally, we show how to extend the aforementioned attack to run a full disclosure attack, which requires to eavesdrop less protocol runs than the proposed attack by Wang et al. (i.e., 192 < < 2 30). Copyright © 2013 John Wiley & Sons, Ltd. Nasour Bagheri, Masoumeh Safkhani, Pedro Peris-Lopez, Juan Tapiador |
Secur. Commun. Networks | 2 |
| 2012 | Another Fallen Hash-Based RFID Authentication Protocol
Julio César Hernández Castro, Pedro Peris-Lopez, Masoumeh Safkhani, Nasour Bagheri, Majid Naderi |
WISTP | 3 |
| 2011 | Tag Impersonation Attack on Two RFID Mutual Authentication ProtocolsabstractSecurity concerns of RFID systems engaged a lot of researchers to design and to cryptanalyze RFID mutual authentication protocols. A suitable mutual authentication protocol for an RFID system should provide mutual authentication along with user privacy. In addition, such protocol must be resistant to active and passive attacks, e.g. man-in-the-middle attack, reply attack, reader-/tag-impersonation, denial of service and traceability attack. Among them, tag-impersonation refers to a process that the adversary's tag fools the legitimate reader to authenticate it as a valid tag. In this paper we exam the security of two RFID mutual authentication protocols, i.e., [6] and [17], under tag impersonation attack. We found that these two protocols share a same vulnerability in each session, the tag and the reader generates a random value respectively and they use the exclusive or (XOR) of those random values in the authentication process. We exploit this vulnerability to present two effective and efficient tag impersonation attacks against these protocols, e.g., the success probabilities of our attacks are "1" and the complexity is at most two runs of each protocol. At last, we exhibit the improved version of these protocols, which are immune from tag impersonation attacks. Masoumeh Safkhani, Nasour Bagheri, Majid Naderi, Yiyuan Luo, Qi Chai |
ARES | 1 |