VLDB 2026 Research / reviewers in the wild / expert
Madhusanka Liyanage
dblp:123/9171
· DBLP profile ↗
109ranked-venue papers
14as first author
82since 2021 · last 2026
0000-0003-4786-030XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 53 · 7 first-author · 36 since 2021Security and privacy · 13 · 2 first-author · 11 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 6 since 2021Systems, architecture and hardware · 5 · 4 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | POSTER: Zero-Touch Mobility Data Governance with Differential Privacy in ZSM-Based Vehicular Edge ServicesabstractConnected-vehicle and roadside telemetry enable low-latency safety navigation, and traffic-optimisation services at the edge, but finegrained mobility streams (locations, speeds, events, and contexts) create high re-identification and linkage risk when accessed by multiple stakeholder domains. We present a Zero Touch Network and Service Management (ZSM) integrated, policy-driven data-collection service that operationalises mobility data governance through intent-based automation. Stakeholders submit high-level collection intents (purpose, fields, spatial/temporal granularity, latency, and utility targets); a policy engine evaluates and rewrites intents into compliant, effective intents; and a plan generator compiles them into executable data-collection pipelines deployable within a ZSM closed loop. Experiments on Beijing taxi mobility traces execute 87,500 DP-protected releases and achieve 1.26% relative error for Road Safety Authority (RSA) at ϵ = 8.0, while DP-Stochastic Gradient Descent (DP-SGD) risk scoring reaches 0.97 ± 0.03 test accuracy at ϵ = 0.5, with δ= 10-5. Awaneesh Kumar Yadav, Pradumn Kumar Pandey, Manoj Misra, Madhusanka Liyanage, An Braeken |
AsiaCCS | 5 |
| 2026 | Post-Quantum Public Key Infrastructures: Hybrid Certificates, Cryptographic Combiners, and Migration StrategiesabstractThe impending threat posed by quantum-capable adversaries necessitates a secure and practical transition of Public Key Infrastructures (PKIs) to support post-quantum cryptography (PQC). This paper addresses the multifaceted challenges of integrating PQC into existing PKI ecosystems by examining novel cryptographic combiners and hybrid certificate designs that can provide quantum-resistant security. We assess the performance, compatibility, and security of these hybrid certificates across standard communication protocols such as TLS, considering variations in root and intermediate certification paths. In addition, we introduce key management procedures that cover signature generation, validation, and lifecycle considerations under both software and hardware constraints. Beyond X.509, alternative trust models and certificate mechanisms are also analyzed for specialized domains, including IoT, firmware signing, and smart cards. Abdullah Aydeger, Engin Zeydan, Awaneesh Kumar Yadav, Madhusanka Liyanage |
CCNC | 4 |
| 2026 | Anon-Spect: A Privacy-Preserving Framework for NFT-Based Dynamic Spectrum Sharing
Lavan Perera, Shen Wang 0006, Madhusanka Liyanage |
ICC | 3 |
| 2026 | Beyond Post-Hoc: A SHAP-Based Feature Selection Framework for High-Accuracy, Class-Aware Intrusion Detection
Farah Abed Zadeh, Bartlomiej Siniarski, Shen Wang 0006, Madhusanka Liyanage |
ICC | 4 |
| 2026 | Security Evaluations of Post-Quantum Cryptographic Primitives Against Quantum and AI-Based Attacks
Engin Zeydan, Abdullah Aydeger, Awaneesh Kumar Yadav, Madhusanka Liyanage |
ICC | 4 |
| 2026 | Federated learning for big data: A survey on opportunities, applications, and future directions
G. Thippa Reddy, Quoc-Viet Pham, Thien Huynh-The, Hailin Feng, Kai Fang 0001, Sharnil Pandya, Madhusanka Liyanage, Wei Wang 0077, Thanh Thi Nguyen 0001 |
Eng. Appl. Artif. Intell. | 7 |
| 2026 | Age-of-Information Aware Mobility-Based Vehicular-Fog Formation Using Deep Reinforcement Learning
Seifu Birhanu Tadele, Binayak Kar, Frezer Guteta Wakgra, Madhusanka Liyanage |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2026 | A Provably Secure Lightweight Three-Factor 5G-AKA Authentication Protocol Relying on an Extendable Output FunctionabstractCompared to 4G, the designed authentication and key agreement protocol for 5G communication (5G-AKA) offers better security. State-of-the-art shows that various protocols indicate the flaws in the 5G-AKA and suggest solutions primarily for the desynchronization attack, traceability attack, and perfect forward secrecy. However, most authentication protocols fail to facilitate the device stolen attack and are expensive; they also do not consider the prominent security issues such as post-compromise security and non-repudiation. Considering the above demerits of these protocols and the necessity to offer additional security, a provably secure lightweight 5G-AKA multi-factor authentication protocol relying on an extendable output function is proposed. The security of the proposed work has been confirmed informally and formally (ROR logic, GNY logic, and Scyther tool) to ensure that the proposed work handles all types of attacks and offers additional security features, such as post-compromise features and non-repudiation. Furthermore, we compute the performance of the proposed work and compare it with its counterparts to show that our work is less costly and more suitable for lightweight devices than others in terms of computational, communication, storage, and energy consumption cost. Awaneesh Kumar Yadav, An Braeken, Madhusanka Liyanage |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2026 | A Provably Secure Multifactor Authentication and Key Exchange Protocol With Anonymity for Next-Generation IoTabstractWith the rapid surge in IoT devices, communication between the IoT devices and the server becomes more frequent. Since IoT devices are considered at the edge of the networks, their communication is completely exposed to the server, making them prone to several attacks. In addition to this, IoT devices have limited energy and computational resources. Therefore, there is an impelling necessity for an authentication mechanism suitable for security and taking into account the resource constraints. This paper shows that a recently proposed protocol by Daojing et al. is prone to serious attacks such as stolen device attacks, suffers from integrity violations, and does not offer perfect forward secrecy. We propose an alternative and more secure authentication mechanism for this type of model and also show that this protocol offers better performance with respect to the state-of-the-art. The proposed protocol achieves reductions of 75%, 40%, 36%, and 71% in computational, communication, storage, and energy consumption costs, respectively. Additionally, the protocol only has two communication phases. Furthermore, prototype implementation and simulation with the NS3 tool are carried out to show the applicability of the proposed work in real-time scenarios. Awaneesh Kumar Yadav, An Braeken, Madhusanka Liyanage |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2026 | An Improved and Provably Secure EDHOC Protocol Supporting the Extended Canetti-Krawczyk (eCK) Security ModelabstractTransport Layer Security (TLS) is considered to be the most used standard security protocol for the Internet of Things (IoT). However, as TLS was originally designed for computer networks, it is not optimal with respect to efficiency. Therefore, a new protocol called Object Security for Constrained RESTful Environments (OSCORE) has been standardized for securing constrained devices. Currently, the Ephemeral Diffie Hellman Over COSE (EDHOC) protocol, which is a key exchange protocol to define a session key used in OSCORE, is also in the process of being standardized. This paper shows that the four authentication modes of the EDHOC protocol are vulnerable in the extended Canetti–Krawczyk (eCK) security model, which is a common security model used in IoT. In addition, also resistance to Distributed Denial of Service (DDoS) attacks is weak. Taking this into account, we propose two new variants of EDHOC. The first variant, EDHOC2, is able to overcome both issues but has a slightly higher cost for communication, computation, storage, and energy consumption. The second variant, EDHOC3, offers only additional protection in the eCK security model and has, on average, similar, even better performance in one authentication mode, compared to EDHOC. Additionally, the Real-Or-Random (ROR) logic and Scyther validation tool are employed to ensure the security of the designed variants. Furthermore, a prototype implementation is conducted to demonstrate the real-time deployment of the designed versions. Awaneesh Kumar Yadav, Madhusanka Liyanage, An Braeken |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2026 | Secure Scalable VPLS: A Lagrangian Relaxation Approach to Tunnel Relaying OptimizationabstractVirtual Private LAN Service (VPLS) is commonly used for secure multi-point communication across geographically scattered industrial sites, simulating a unified LAN broadcast domain for Industrial IoT (IIoT)-type devices. This configuration demands a fully-connected overlay network with encrypted Host Identity Protocol (HIP)/IPsec tunnels exhibiting quadratic scalability to the number of tunnels and a significant increase in forwarding table entries. Herein, we introduce Tunnel Relay Nodes (TRNs) as selected routers that maintain full-mesh connectivity. This approach allows non-TRN routers, or Provider Equipment (PEs) acting as spoke PEs, to connect via a TRN. We explore the challenges of using TRNs in secure HIP-based VPLS (HIPLS) networks, including (i) placing reliable TRNs within provider networks and (ii) scheduling TRNs to minimize their activation/deactivation costs as well as the connection cost among PEs. We then demonstrate how (i) can be addressed in polynomial time using a modified general median problem approach. Additionally, we formulate (ii) as a Mixed Integer Linear Programming (MILP) scheduling problem and prove its NP-completeness. Furthermore, we introduce an algorithm based on Lagrangian relaxation to address the intractability in large-scale deployments. This algorithm offers fast, near-optimal solutions while simultaneously balancing solution quality and execution time. Our simulations on three real-world network topologies with real network demands show a 92% average reduction in forwarding table entries on PE. Compared to existing solutions, our method reduces the number of tunnels established by up to 95%, at the expense of a 1.39-fold increase in tunnel path length. Mohammad Borhani, Ioannis Avgouleas, Madhusanka Liyanage, Andrei V. Gurtov |
IEEE Trans. Netw. | 3 |
| 2026 | Joint Optimization of Sensing, Communication, and Computing for Collaborative Multi-UAV Edge Computing SystemabstractUnmanned aerial vehicle (UAV) and high-altitude platform (HAP)-enabled aerial edge computing (AEC) networks facilitate diverse Internet of Things (IoT) applications. In this paper, we investigate the average task completion time and energy consumption by jointly optimizing sensing, communication and computing in cooperative AEC networks facilitated by multiple UAVs and HAP. The sensing times, multi-UAV trajectories, transmission power control, offloading strategy and communication resource allocation are jointly optimized. We transform the original optimization problem into minimizing the average task completion time while ensuring energy consumption stability by introducing Lyapunov optimization theory. The problem is then decomposed into multiple subproblems, which are solved through numerical analysis, successive convex approximation, and the Dinkelbach algorithm, respectively. These algorithms are embedded into the proximal policy optimization (PPO)-based multi-agent deep reinforcement learning (MADRL) framework to speed up the convergence performance of the MADRL model. Simulation results demonstrate that the proposed algorithm achieves superior performance in terms of average task completion time and energy consumption. Mingan Luan, Madhusanka Liyanage, Zheng Chang 0001 |
IEEE Trans. Wirel. Commun. | 3 |
| 2025 | Demo: Enabling Trustworthy Cold Chain Logistics Through Blockchain and Machine LearningabstractInternet of Things (IoT) sensors monitor temperature-sensitive goods throughout the supply chain. Nowadays, blockchain is being widely used for traceability, transparency, and immutable storage of this data. However, this approach lacks a mechanism to assess the trustworthiness of the data, and as a result, the reliability of the system is constrained by the quality of the data being added. IoT sensor data can be compromised for various reasons, including sensor malfunctions, deliberate tampering, or human error. This demonstration presents a solution that integrates machine learning techniques with blockchain to enhance data trust in cold chain logistics. Rashmi Ratnayake, Madhusanka Liyanage, Liam Murphy 0001 |
CCNC | 2 |
| 2025 | Evaluating Data Trust in Blockchain-Based IoT Systems Using Machine Learning TechniquesabstractThe convergence of blockchain and Internet of Things (IoT) has become increasingly prevalent recently, as it addresses challenges such as single point of failure and security concerns associated with IoT. Blockchain offers immutable data storage, availability, and transparency, but a significant drawback lies in its inability to verify the truthfulness of the data stored on it. State-of-the-art systems attempting to mitigate this concern often rely on conventional reputation-based approaches, which predominantly evaluate historical data from sensors and neglect the critical assessment of data in real-time. Furthermore, there is limited research on incorporating machine learning (ML) methods to enhance data trustworthiness in blockchain systems. This paper proposes a novel ML-based trust assessment approach that takes into account both historical reputation and real-time data trust-worthiness. Our approach integrates multiple ML models within a blockchain framework using edge servers and validators, effectively functioning as a distributed ensemble to enhance classification accuracy, and contributing to more accurate reputation score calculations. Our results demonstrate significant accuracy gains in distinguishing trustworthy and untrustworthy IoT sensor data in blockchain networks. Rashmi Ratnayake, Madhusanka Liyanage, Liam Murphy 0001 |
CCNC | 2 |
| 2025 | Non-Fungible Token Enabled Resource Trading Marketplace for 6G Network SlicingabstractThe shift from fifth generation (5G) to sixth generation (6G) networks is anticipated to significantly advance network slicing. This progress is driven by the growing demand for next-generation applications and services. However, these advancements must be managed within the constraints of limited resources. This evolution opens up opportunities for resource sharing through emerging marketplaces, yet it introduces various business and technical complexities that need to be addressed. Additionally, finding cost-effective solutions is also essential for the future of networks. In this paper, we propose a blockchain-based architecture that utilizes non-fungible tokens (NFTs) for the trading of network resources within the 6G network slicing. To the best of our knowledge, this is the first study to represent network resources as NFTs within the context of network slicing. The architecture employs NFTs to authenticate and manage various network resources, providing a decentralized platform for their secure creation, management, and exchange. Using resource NFTs, our system ensures more granular and flexible control over network resources than existing state-of-the-art systems, where NFTs are tied to network slices. We implemented a prototype of this system to validate its viability. Our performance evaluation confirms that the proposed approach is efficient and cost-effective compared to baseline models in managing network resources within network slicing. These findings highlight the potential of our system to transform network management practices and effectively meet the demands of future networks. Nisita Weerasinghe, Pawani Porambage, An Braeken, Madhusanka Liyanage, Mika Ylianttila |
CCNC | 4 |
| 2025 | Demo: Blockchain-Based NFT Resource Marketplace for Efficient 6G Network SlicingabstractAs 6G networks introduce increasingly diverse and complex applications, network slicing is a key enabling technology for partitioning network resources to meet these dynamic demands. However, efficiently managing and allocating these finite resources has become vital. This necessity drives the adoption of an open marketplace model. To address the business and technical complexities associated with such open marketplaces, this paper presents the demonstration of a non-fungible token (NFT)-enabled resource trading marketplace tailored for 6G network slicing. The proposed solution is implemented on an Ethereum-based blockchain system to assess its viability. Nisita Weerasinghe, Pawani Porambage, An Braeken, Madhusanka Liyanage, Mika Ylianttila |
CCNC | 4 |
| 2025 | Silent Signals, Loud Threats: Using dApps for Radio Signal Intelligence-based Intrusion Detection in 5G O-RANabstractAs 5G networks evolve toward disaggregated Open Radio Access Network (O-RAN) architectures, low-latency, edge-resident security mechanisms are critical. Conventional Extended Application (xApp)-based Intrusion Detection Systems (IDS) at the Central Unit (CU) create high computational overhead and latency due to their reliance on deep packet inspection and centralized analytics. This work proposes a lightweight, Distributed Application (dApp)-based IDS deployed at the Distributed Unit (DU) for near-real-time threat detection at the radio edge. Our approach leverages radio telemetry features from the E2 interface to identify network attacks without inspecting upper-layer packet data. Using a live 5G O-RAN testbed, we constructed synchronized datasets from the DU (lower-layer) and CU (upper-layer) under various attack scenarios to evaluate several Machine Learning (ML) models. The results demonstrate that our dApp-based IDS achieves comparable accuracy to traditional xApp systems while significantly reducing CPU effort, memory usage, and execution time, underscoring the potential of dApps as scalable and effective security primitives in O-RAN. Alan Civciss, Vidura Ravihansa, Farah Abed Zadeh, Chamara Sandeepa, Madhusanka Liyanage |
GLOBECOM | 5 |
| 2025 | Collaborative Sensing, Communication and Computing for UAV-assisted Space-Air NetworksabstractWe propose a collaborative optimization framework for integrated sensing, communication, and computing (ISCC) in the unmanned aerial vehicle (UAV)-assisted space-air networks. This framework employs an UAV for data sensing and relay, providing wireless access to terrestrial sensing devices (TSDs), while a LEO satellite serves as an offloading edge computing server in space. Acknowledging the temporal criticality of tasks within the designated service area, we classify the service area with different priorities, with the UAV prioritizing service delivery to high-priority regions. Based on sensing satisfaction and service duration, we formulate a multi-objective problem with the goal of maximizing the total satisfaction while minimizing the service duration. We propose a PPO-based deep reinforcement learning (DRL) algorithm to find the optimal solutions. To address long-term dependencies in sequential data, we embed a long short-term memory (LSTM) module into the DRL algorithm. Compared to the baseline algorithms, the proposed algorithm achieves improvements in accumulated rewards of approximately 4.1%, 14.5%, and 21.2%, respectively. Pasika Ranaweera, Madhusanka Liyanage, Zheng Chang 0001 |
GLOBECOM | 3 |
| 2025 | DBFFL - Defending Against Dynamic Poisoning Attacks in Federated Learning in 5G and Beyond SystemsabstractFederated Learning (FL) is a distributed Machine Learning (ML) technique that trains a collaborative ML model without sharing data and by sharing only the model updates. FL is critical in 6 G networks as it enables decentralized and privacy-preserving Artificial Intelligence (AI) model training across distributed devices, reducing communication overhead and enhancing data security, which is crucial for supporting AI-driven 6G networks and applications such as autonomous vehicles, healthcare, and immersive Extended Reality. Since the FL clients transmit only the model updates instead of data, FL is vulnerable to poisoning attacks. The result of a poisoning attack is an incorrect outcome at the inference, affecting the application requirements when employed in 6 G systems. Existing defense mechanisms focus on the attacks in a static nature disregarding the dynamic behavior of attackers. Since the 6 G networks are highly AI-driven, attackers can also learn about the network using AI techniques allowing them to execute more sophisticated dynamic attacks. In this paper, we evaluate how existing defense mechanisms fail in the presence of dynamic poisoning attacks. We also propose novel defense DBFFL against dynamic poisoning attacks in FL, to ensure robustness when deployed in 6 G networks and applications. Shashidhar R, Yushan Siriwardhana, Manoj Misra, Madhusanka Liyanage |
ICC | 4 |
| 2025 | Optimizing AoI in Mobility-Based Vehicular Fog Networks: A Dueling-DDQN ApproachabstractVehicular fog computing (VFC) is a growing approach for delivering low-latency services to IoT devices and intelligent traffic systems. In VFC, vehicles and roadside units (RSUs) collaborate to form a fog infrastructure, processing and storing real-time traffic data at the network edges. However, vehicle mobility creates challenges in maintaining stable communication and network connectivity. Differences in distance, location, speed, and direction between vehicles and infrastructure can disrupt vehicle-to-infrastructure (V2I) communication, impacting reliability. To address these challenges, we explored dynamic fog formation using mobile vehicles and RSUs in city scenarios. We focus on real-time RSU association and fog formation to prevent outdated information from causing failures in V2I communication. We propose an approach utilizing deep reinforcement learning (DRL), particularly the dueling double deep Q-network (Dueling DDQN) algorithm. Through simulations using the Constant Speed Mobility (CSM) model, we compared its performance with DQN, DDQN, and Dueling DQN. Results show that Dueling DDQN outperforms the other methods, effectively improving the freshness of real-time system information. Seifu Birhanu Tadele, Binayak Kar, Frezer Guteta Wakgra, Madhusanka Liyanage |
ICC | 4 |
| 2025 | Mobility-Aware Multi-Objective Offloading Optimization in MEC and Vehicular-Fog Systems: A Waited-Ratio Based TD3 ApproachabstractMulti-access Edge Computing (MEC) and Vehicular-Fogs (VFs) are placed nearer to user equipment (UE), reducing propagation latency compared to traditional cloud-based systems and ensuring a high standard of Quality of Service (QoS). Nevertheless, MEC sites can become congested and overloaded during peak traffic periods, such as concerts or sporting events. To address this, offloading techniques can shift intensive computational tasks from devices with limited resources to those with greater capacity, enhancing task performance and thereby increasing battery longevity. This study investigates the offloading within a two-tier framework of MEC and VF, focusing on the offloading of MEC to VF. Maintaining QoS is challenging due to the instability of fog networks caused by high-speed vehicle movement, which disrupts both vehicle-to-vehicle and vehicle-to-infrastructure communications. To mitigate this, we analyze vehicle mobility using a Gauss-Markov Mobility (GMM) model. Our main goal is to reduce the average system cost by optimizing both latency and energy consumption while accounting for vehicle mobility. We approach this challenge as a multi-objective optimization problem and develop a reinforcement learning environment. Additionally, we propose an algorithm based on imitation learning called Weighted-Ratio Based TD3 (WRTD3), an enhancement of the TD3 algorithm, to effectively manage these complexities. Frezer Guteta Wakgra, Binayak Kar, Seifu Birhanu Tadele, Krishna M. Sivalingam, Madhusanka Liyanage |
ICC | 5 |
| 2025 | Analysis of Post-Quantum Cryptography in User Equipment in 5G and BeyondabstractThe advent of quantum computing threatens the security of classical public-key cryptographic systems, prompting the transition to post-quantum cryptography (PQC). While PQC has been analyzed in theory, its performance in practical wireless communication environments remains underexplored. This paper presents a detailed implementation and performance evaluation of NIST-selected PQC algorithms in user equipment (UE) to UE communications over 5G networks. Using a full 5G emulation stack (Open5GS and UERANSIM) and PQC-enabled TLS 1.3 via BoringSSL and liboqs, we examine key encapsulation mechanisms and digital signature schemes across realistic network conditions. We evaluate performance based on handshake latency, CPU and memory usage, bandwidth, and retransmission rates, under varying cryptographic configurations and client loads. Our findings show that ML-KEM with ML-DSA offers the best efficiency for latency-sensitive applications, while SPHINCS+ and HQC combinations incur higher computational and transmission overheads, making them unsuitable for security-critical but time-sensitive 5G scenarios. Sanzida Hoque, Abdullah Aydeger, Engin Zeydan, Madhusanka Liyanage |
LCN | 4 |
| 2025 | Real-Time Medical Training in Virtual Reality over 5G Open RAN: A Performance StudyabstractThe convergence of immersive technologies and next-generation communication networks offers new potential for advancing surgical training. This paper presents the Magos Bakri Balloon Placement Training (MBBPT) system, a Virtual Reality (VR) simulation platform integrated with haptic feedback and 5th Generation (5G) Open Radio Access Network (O-RAN) connectivity. The system enables realistic and interactive medical training, leveraging submillimeter-precision hand tracking and kinesthetic feedback from Magos gloves. To evaluate the feasibility and performance of network-assisted VR training, MBBPT was tested across a disaggregated O-RAN-based private 5G testbed at University College Dublin (UCD), a standalone private 5G testbed at Patras, and a cross-site setup linking both. The setup assessed Key Performance Indicators (KPIs) and Key Value Indicators (KVIs) to show the system supports responsive, multiuser VR interactions across geographically distributed sites, with consistent performance. These findings highlight the role of 5G O-RAN as an enabler for scalable, collaborative, high-fidelity immersive medical education. Vidura Ravihansa, Chamara Sandeepa, Ouranis Vasilapostolos, Fionnuala McAuliffe, Eleni E. Mangina, Madhusanka Liyanage |
LCN | 6 |
| 2025 | From Insight to Action: XAI-Enhanced Detection of DDoS Attacks in Software Defined NetworksabstractSoftware-defined networking (SDN) has revolutionized modern mobile networks by enhancing flexibility and scalability, but its centralized architecture remains a prime target for Distributed Denial of Service (DDoS) attacks. This paper presents a novel detection framework that employs frequency-domain analysis to uncover hidden attack patterns within PacketIn message fluctuations. To further refine detection accuracy, eXplainable AI (XAI) is integrated to optimize the detection accuracy of unseen types of DDoS attacks and enhance the interpretability of the model. Our approach enables a more precise attack classification while minimizing false positives using XAI-driven knowledge transfer. Experimental evaluations confirm that this method significantly strengthens SDN resilience against evolving DDoS threats, providing a more adaptive and intelligent defense mechanism. Thulitha Senevirathna, Betül Güvenç Paltun, Ramin Fouladi, Shen Wang 0006, Madhusanka Liyanage |
PIMRC | 5 |
| 2025 | Optimizing Security in Dynamic Service Migration Scenarios of Multi-Access Edge ComputingabstractSecurity mechanisms and Service Level Guarantees (SLGs) often operate in tension within communication systems, where stronger security protocols introduce overhead, processing delays, and encryption-related latency that can hinder the ability to meet predefined SLGs. This challenge is particularly critical in Multi-Access Edge Computing (MEC), where service migration across edge nodes can significantly impact system performance. Ensuring the security of migrating services while maintaining low-latency communication is vital to preserving service continuity and avoiding disruptions. In this paper, we introduce a novel security framework for MEC-enabled gNodeBs that supports secure and seamless service migration. Central to our framework is an adaptive security optimization model that dynamically adjusts the security level of the migration channel based on real-time bandwidth utilization. This approach maintains the continuity of service without compromising the available bandwidth, thereby upholding the required SLGs while minimizing the impact of security-related overhead. Pasika Ranaweera, Indika A. M. Balapuwaduge, Anca Jurcut, Engin Zeydan, Madhusanka Liyanage |
VTC2025-Fall | 5 |
| 2025 | SHIELD - Secure Aggregation Against Poisoning in Hierarchical Federated LearningabstractFederated Learning (FL) is a privacy-preserving distributed Machine Learning (ML) technique. Hierarchical FL is a novel variant of FL applicable to networks with multiple layers. Instead of transmitting client models to the server, hierarchical FL performs aggregations in the layers between the devices and the server. This further reduces the traffic toward the higher layers, which helps efficient link utilization. An adversary can manipulate a set of clients and send malicious model updates toward upper layers to create a trained model with a malicious objective. These attacks, also known as poisoning attacks, disrupt the model training. Like FL, Hierarchical FL is also vulnerable to poisoning attacks since the aggregators do not possess raw data. The existing robust algorithms are designed for FL systems with$n$clients and a server. Therefore, they are not effective against poisoning attacks in hierarchical FL systems. This paper proposes SHIELD, a novel robust aggregation technique that defends hierarchical FL systems from poisoning attacks. We evaluate SHIELD with several datasets in different application areas with different attack strategies and data distributions. The evaluation results demonstrate that SHIELD effectively defends hierarchical FL systems from poisoning attacks with a negligible impact on the benign performance of the models. Yushan Siriwardhana, Pawani Porambage, Madhusanka Liyanage, Samuel Marchal, Mika Ylianttila |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | A Secure Authentication Protocol for IoT-WLAN Using EAP FrameworkabstractThe plethora of Internet of Things (IoT) devices and their diversified requirements have opted to design security mechanisms that cover all major security requirements. Wireless Local Area Networks (WLANs) is the most common network domains where IoT devices are launched, particularly because of its easy availability. Security, in other words authentication however, remains to be a major constriction for IoT-WLAN deployments. Though there are IoT based authentication protocols prevailing, such protocols are either prone to threats such as perfect forward secrecy violations, insider with database access attack, traceability attack, stolen device attack, ephemeral secret leakage, or they consume excessive computational and communication resources that result in an unprecedented burden for the IoT system. This paper presents an Extensible Authentication Protocol (EAP) based mechanism for IoT devices deployed in a WLAN that addresses the above security issues and achieves cost-effectiveness. Validation follows an informal and formal approaches (using GNY and BAN logic, and Scyther verification tool) for the proposed protocol, demonstrating its robustness. Our performance analysis shows that the proposed protocol is lightweight and more secure in contrast to the state-of-the-art solutions. In addition, performance of the proposed protocol subjected to unknown attacks is investigated, which deduces that the proposed protocol has less overhead under unknown attacks than its competitors. A prototype of the protocol has been developed to demonstrate its feasibility and accuracy. Awaneesh Kumar Yadav, Manoj Misra, Pradumn Kumar Pandey, Pasika Ranaweera, Madhusanka Liyanage, Neeraj Kumar 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | Blockchain-Based Cross-Operator Network Slice Authentication Protocol for 5G CommunicationabstractNetwork slicing enables the facilitation of diverse network requirements of different applications over a single physical network. Due to concepts such as Local 5G Operators (L5GOs), Mobile Virtual Network Operators (MVNOs), and high-frequency utilization of 5G and beyond networks, users need to switch frequently among different network slices as well as different operators than the traditional networks. Even though a couple of researches have been conducted on cross-network slice authentication, cross-operator network slice authentication is still an indeterminate research area. Also, the proposed cross-network slice authentication frameworks possess several limitations, such as vulnerability to severe attacks, high cost, the central point of failure, and the inability to support cross-operator network slice authentication. Therefore, in this research, we develop a blockchain-based cross-network slicing, cross-operator network slice authentication framework. Our framework supports the authentication for different network slices in the same operator as well as in different operators. The security properties of the proposed protocols are validated from formal (using Real-Or-Random logic, Scyther, and AVISPA validation tool) and informal security validation. The comparative analysis is conducted for known and unknown attacks to demonstrate its efficacy in terms of communication, computational, storage, and energy consumption costs. Also, a sample prototype of the protocols is implemented along with the state-of-the-art protocols to evaluate the performance of our framework. Awaneesh Kumar Yadav, Shalitha Wijethilaka, Madhusanka Liyanage |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2024 | Blockchain-Enabled RF Radiation Exposure Level Measurement in Wireless Mobile NetworksabstractThe expansion of telecommunication providers and their efforts to expand network coverage in Sri Lanka has led to an alarming increase in Radio Frequency (RF) radiation exposure. This heightened exposure has raised concerns about its potential adverse effects on human health. Despite the country's growing number of cancer cases, no apparent cause has been identified. This research aims to identify areas exposed to harmful RF radiation levels through the innovative application of blockchain technology. The methodology involves measuring RF radiation in densely populated locations and implementing a blockchain-based spectral power misuse detection system via mobile networks. This system notifies users of harmful RF radiation exposure through an Android app. In this system, the collected data is first clustered and then aggregated after removing potential “outlier” data points, before adding the data to the blockchain. These two steps are important to increase the performance of the blockchain network, which is evaluated based on performance metrics, including success rate, latency, throughput, and memory usage of the blockchain. The data is analyzed in the blockchain network to detect if there are harmful signal levels in the country and to alert the users if there are any. Nivin Madawalage, Tharani Thalgahagoda, Inushi Gunatilake, Pramitha Fernando, Geeth P. Wijesiri, Chatura Seneviratne, Madhusanka Liyanage |
CCNC | 7 |
| 2024 | Towards Faster DRL Training: An Edge AI Approach for UAV Obstacle Avoidance by Splitting Complex EnvironmentsabstractAs autonomous Unmanned Aerial Vehicles (UAVs) are becoming more and more prevalent in everyday life, it is paramount that UAVs are equipped with effective obstacle avoidance capabilities. Edge AI, which runs AI on-device (e.g., on-UAV) or on edge servers, offers many advantages to traditional cloud-based AI when applied to the problem of UAV obstacle avoidance. Literature shows that deep reinforcement learning (DRL) applied to robots (e.g., UAVs) is an effective method of obstacle avoidance. One key issue associated with DRL applied to robotics is the time required to train when the environment is complicated. In this paper, we propose a DRL-based UAV obstacle avoidance system that leverages edge AI. Our system distributes the training and inferencing processes of DRL by splitting large environments into multiple smaller environments. Our main goal is to make DRL training faster and more feasible under relatively large and complex environments. We demonstrate the effectiveness of our system in 3D simulation and all our code is open-sourced on GitHub. Patrick McEnroe, Shen Wang 0006, Madhusanka Liyanage |
CCNC | 3 |
| 2024 | Deceiving Post-Hoc Explainable AI (XAI) Methods in Network Intrusion DetectionabstractArtificial Intelligence used in future networks is vulnerable to biases, misclassifications, and security threats, which seeds constant scrutiny in accountability. Explainable AI (XAI) methods bridge this gap in identifying unaccounted biases in black-box AI/ML models. However, scaffolding attacks can hide the internal biases of the model from XAI methods, jeopardizing any auditory or monitoring processes, service provisions, security systems, regulators, auditors, and end-users in future networking paradigms, including Intent-Based Networking (IBN). For the first time ever, we formalize and demonstrate a framework on how an attacker would adopt scaffoldings to deceive the security auditors in Network Intrusion Detection Systems (NIDS). Furthermore, we propose a detection method that auditors can use to detect the attack efficiently. We rigorously test the attack and detection methods using the NSL-KDD. We then simulate the attack on 5G network data. Our simulation illustrates that the attack adoption method is successful, and the detection method can identify an affected model with extremely high confidence. Thulitha Senevirathna, Bartlomiej Siniarski, Madhusanka Liyanage, Shen Wang 0006 |
CCNC | 3 |
| 2024 | Robust Aggregation Technique Against Poisoning Attacks in Multi-Stage Federated Learning ApplicationsabstractFederated Learning (FL) is a distributed Machine Learning (ML) technique that allows model training without sharing data. FL is vulnerable to poisoning attacks where an adversary manipulates the learning process by providing false information to the federation. Ensuring security in FL is vital before using FL in real applications, as the consequences can be adverse. Multi-stage FL is a novel variant of FL that performs intermediate model aggregations, thereby reducing the traffic toward the FL central server. The existing robust aggregation techniques are insufficient in multi-stage FL systems. This paper proposes a novel robust aggregation algorithm against poisoning attacks in a three-layer multi-stage FL system that consists of device, edge, and cloud layers. We evaluate the proposed robust algorithm considering an Augmented Reality (AR) application with different poisoner placements and attack strategies. The evaluation results show that the proposed algorithm can effectively defend against poisoning attacks in three-layer multi-stage FL systems. Yushan Siriwardhana, Pawani Porambage, Madhusanka Liyanage, Samuel Marchal, Mika Ylianttila |
CCNC | 3 |
| 2024 | Decentralized Defense: Leveraging Blockchain against Poisoning Attacks in Federated Learning SystemsabstractFederated learning (FL) has become the next generation of machine learning (ML) by avoiding local data sharing with a central server. While this becomes a major advantage to client-side privacy, it has a trade-off of becoming vulnerable to poisoning attacks and malicious behavior of the central server. As the decentralization of systems enhances security concerns, integrating decentralized defense for the existing FL systems has been extensively studied to eliminate the security issues of FL systems. This paper proposes a decentralized defense approach to FL systems with blockchain technology to overcome the poisoning attack without affecting the existing FL system's performance. We introduce a reliable blockchain-based FL (BCFL) architecture in two different models, namely, Centralized Aggregated BCFL (CA-BCFL) and Fully Decentralized BCFL (FD-BCFL). Both models utilize secure off-chain computations for malicious mitigation as an alternative to high-cost on-chain computations. Our comprehensive analysis shows that the proposed BCFL architectures can defend in a similar manner against poisoning attacks that compromise the aggregator. As a better measure, the paper has included an evaluation of the gas consumption of our two system models. Rashmi Thennakoon, Arosha Wanigasundara, Sanjaya Weerasinghe, Chatura Seneviratne, Yushan Siriwardhana, Madhusanka Liyanage |
CCNC | 6 |
| 2024 | Spect-NFT: Non-Fungible Tokens for Dynamic Spectrum ManagementabstractDynamic Spectrum Sharing (DSS) is a pivotal technology for optimizing spectrum utilization and fostering efficient sharing among diverse users. However, existing DSS approaches face significant challenges related to security and privacy vulnerabilities, leading to fraudulent practices within spectrum marketplaces. In this paper, we introduce Spect-NFT, a novel framework leveraging Non Fungible Tokens (NFTs) to address these limitations and enhance the spectrum-sharing ecosystem’s efficiency and revenue. Spect-NFT employs NFTs to authenticate ownership of spectrum bands, mitigating fraudulent activities and improving trust among participants. Additionally, Spect-NFT introduces digital Permission Tokens (PTs) to facilitate seamless spectrum sharing between primary users (PUs) and secondary users (SUs) enabling the sharing of a single NFT among multiple owners. We present a methodology for converting spectrum licenses into NFTs and demonstrate the feasibility of our approach using the Ethereum Blockchain. Our proof of concept solution showcases Spect-NFT’s tamperresistant characteristics and its potential to revolutionize DSS paradigms. Lavan Perera, Pasika Ranaweera, Shen Wang 0006, Madhusanka Liyanage |
GLOBECOM | 4 |
| 2024 | Privacy-Preserving Federated Learning Framework for Open Radio Access Networks (ORAN)abstractOpen Radio Access Network (ORAN) is considered the next-generation RAN, which enables several features such as network flexibility, interoperability, and cost efficiency. Leveraging Artificial Intelligence (AI) and Machine Learning (ML) techniques has become commonplace in ORAN applications. The modularized nature of the ORAN architecture and the limitations in traditional ML approaches intensify the requirement of Federated Learning (FL) for training ML models in ORAN environments. However, in multi-BS environments, the conventional plaintext model update sharing of FL is vulnerable to privacy breaches like inference and deep-leakage gradient attacks. Hence, our proposition introduces an innovative blockchain-based framework to conduct FL securely and protect privacy with the support of the Open Radio Access Network (ORAN). Our approach builds upon the traditional masking method for sharing model parameters and enhances it with novel features. These features include individual validation for BSs, the selection of distributed aggregators, and validation for final model aggregation. Our scheme facilitates the sharing of sensitive data among multiple BSs while bolstering privacy and adding security layers without compromising performance metrics. To assess the efficacy of our proposal, we implement the framework atop a Hyperledger Fabric blockchain. Furthermore, comprehensive formal and informal security analyses are conducted to demonstrate the robust and privacy-preserving nature. Shalitha Wijethilaka, Awaneesh Kumar Yadav, An Braeken, Madhusanka Liyanage |
GLOBECOM | 4 |
| 2024 | Demo: Radio Spectrum Data Collection with Distributed-Proof-of-Sense Blockchain NetworkabstractDynamic Spectrum Access (DSA) addresses the underutilized spectrum allocation issues associated with static spectrum allocation. Blockchain is a critical enabler for implementing a DSA system because it allows untrusted parties to conduct business, such as spectrum buying and selling, without the involvement of a trusted third party. A blockchain system is implemented using the Proof-of-Sense consensus algorithm, which is designed to facilitate DSA while also providing several additional benefits, such as spectrum data collection. Pramitha Fernando, Madhusanka Liyanage |
ICBC | 2 |
| 2024 | Machine Learning for Data Trust Evaluations in Blockchain-Enabled IoT SystemsabstractRecently, there has been a surge of interest surrounding the integration of blockchain with the Internet of Things (IoT), aiming to address IoT’s inherent issues like single points of failure and concerns related to data integrity. However, although blockchain provides decentralization and transparency, it does not guarantee the accuracy and reliability of IoT-generated data. Therefore, additional measures are needed to assess and verify the reliability of IoT data stored on blockchains. In this demonstration, we present a novel approach that employs support vector machine (SVM) models in edge servers and multiple machine learning (ML) models executed by validators for data trust evaluations in blockchain-enabled IoT systems. Our approach introduces a composite trust metric that combines past device reputation on the blockchain with real-time data assessment enabled by SVM models. This composite measure provides a dynamic method for determining the trustworthiness of data at the point of submission. The multiple different ML models used by validators work as a distributed ensemble, leading to improved classification accuracy. This novel approach helps to calculate reputation scores more accurately, increasing the system’s reliability. We illustrate the feasibility of our approach through a description of our prototype implementation. Rashmi Ratnayake, Madhusanka Liyanage, Liam Murphy 0001 |
ICBC | 2 |
| 2024 | A Q-Learning Based Transmission Management Strategy for Energy Harvesting SensorsabstractRadio-frequency energy harvesting from ambient cellular energy and drone-based receivers close to the sensors can be effective tools to prolong the lifespan of wireless sensor networks (WSNs). Moreover, the energy management policy of a sensor plays a critical role in increasing the reliability of data transmission under severe energy constraints. Thus, in this paper, we develop an optimal transmission policy to reduce the outage such that a sensor decides on when to transmit and how much power to use given the uncertainties of the harvested energy. To this end, we model sensors with a finite-level battery and a buffer with discrete states, whereas the cellular base stations from which the energy is harvested are modeled according to a Poisson point process. The drone is assumed to be hovering at a fixed height above the field of sensors, and assume path loss and small scale fading with varying intensities depending on the line-of-sight nature of the link. An outage is assumed to occur due to incorrect reception of transmissions and buffer overflow. We formulate the problem as a Markov decision process, and utilize a Q-learning based algorithm to generate the optimal transmission policy. Our numerical results show that the proposed policy significantly outperforms the previously proposed policies under all conditions. Sachitha Kusaladharma, Raviraj S. Adve, Madhusanka Liyanage |
ICC | 3 |
| 2024 | The SPATIAL Architecture: Design and Development Experiences from Gauging and Monitoring the AI Inference Capabilities of Modern ApplicationsabstractDespite its enormous economical and societal impact, lack of human-perceived control and safety is re-defining the design and development of emerging AI-based technologies. New regulatory requirements mandate increased human control and oversight of AI, transforming the development practices and responsibilities of individuals interacting with AI. In this paper, we present the SPATIAL architecture, a system that augments modern applications with capabilities to gauge and monitor trustworthy properties of AI inference capabilities. To design SPATIAL, we first explore the evolution of modern system architectures and how AI components and pipelines are integrated. With this information, we then develop a proof-of- concept architecture that analyzes AI models in a human-in-the- loop manner. SPATIAL provides an AI dashboard for allowing individuals interacting with applications to obtain quantifiable insights about the AI decision process. This information is then used by human operators to comprehend possible issues that influence the performance of AI models and adjust or counter them. Through rigorous benchmarks and experiments in real- world industrial applications, we demonstrate that SPATIAL can easily augment modern applications with metrics to gauge and monitor trustworthiness, however, this in turn increases the complexity of developing and maintaining systems implementing AI. Our work highlights lessons learned and experiences from augmenting modern applications with mechanisms that support regulatory compliance of AI. In addition, we also present a road map of on-going challenges that require attention to achieve robust trustworthy analysis of AI and greater engagement of human oversight. Abdul-Rasheed Ottun, Rasinthe Marasinghe, Toluwani Elemosho, Mohan Liyanage, Mohamad Ragab, Prachi Bagave, Marcus Westberg, Mehrdad Asadi, Michell Boerger, Chamara Sandeepa, Thulitha Senevirathna, Bartlomiej Siniarski, Madhusanka Liyanage, Vinh Hoa La, Manh-Dung Nguyen, Edgardo Montes de Oca, Tessa Oomen, João Fernando Ferreira Gonçalves, Illija Tanaskovic, Sasa Klopanovic, Nicolas Kourtellis, Claudio Soriente, Jason Pridmore, Ana R. Cavalli, Drasko Draskovic, Samuel Marchal, Shen Wang 0006, David Solans Noguero, Nikolay Tcholtchev, Aaron Yi Ding, Huber Flores |
ICDCS | 13 |
| 2024 | SHERPA: Explainable Robust Algorithms for Privacy-Preserved Federated Learning in Future Networks to Defend Against Data Poisoning AttacksabstractWith the rapid progression of communication and localisation of big data over billions of devices, distributed Machine Learning (ML) techniques are emerging to cater for the development of Artificial Intelligence (AI)-based services in a distributed manner. Federated Learning (FL) is such an innovative approach to achieve a privacy-preserved AI that facilitates ML model sharing and aggregation while keeping the participants’ data at the original source. However, recent research has investigated threats from poisoning attacks in FL. Several robust algorithms based on techniques such as similarity metrics or anomaly filtering are proposed as solutions. Yet, these approaches do not focus on investigating the intentions of the attackers or providing justifications and evidence for suspecting the behaviour of clients who are considered poisoners. Therefore, we propose SHERPA, a robust algorithm that uses Shapley Additive Explanations (SHAP) to identify potential poisoners in an FL system. Based on this, we develop a novel algorithm to differentiate poisoners via feature attribution clustering. We launch data poisoning attacks for different scenarios on multiple datasets and showcase our solution to mitigate the attacks. Furthermore, we show that privacy-targeted poisoning attacks can be mitigated with our approach. Accompanying the Explainable AI (XAI) technique for defence, our study reveals the potential for post-hoc feature attributions in countering data poisoning attacks with better explainability and improved justification in eliminating potentially malicious clients in the aggregation process. Chamara Sandeepa, Bartlomiej Siniarski, Shen Wang 0006, Madhusanka Liyanage |
SP | 4 |
| 2024 | A Novel Authentication Protocol for 5G gNodeBs in Service Migration Scenarios of MECabstractEdge computing paradigms were an expedient innovation for elevating the contemporary standards of mobile and Internet networks. As specified in Multi-Access Edge Computing (MEC) standardization, edge computing serviceable infrastructures are running on virtualization technologies to provide dynamic and flexible service instances. Since the inception and operation of the services are executing at the edge level gNodeBs ($gNB$s), migration of services between$gNB$s is an imminent occurrence in edge computing that is contriving challenges to its feasible deployment. Security and service level latency requirements are vital parameters for such service migration operations conducted through$gNB$to$gNB$(g2g) connecting channels. In this paper, our focus is to ensure identity verification among the parties involved in a service migration through authentication and to secure the migrating content through a robust g2g channel establishment. Our proposed authentication protocol was designed in accordance with the MEC architectural standardization. We have verified the proposed protocol employing four different formal verification techniques: Scyther and AVISPA verification tools, GNY and ROR logical approaches. Further, we have developed the proposed protocol in a test-bed environment emulating the MEC system with an integrated 5 G Core network. Pasika Ranaweera, Awaneesh Kumar Yadav, Madhusanka Liyanage, Anca Jurcut |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Blockchain-Based Secure Authentication and Authorization Framework for Robust 5G Network SlicingabstractThe rapid evolution of heterogeneous applications signifies the requirement for network slicing to cater to diverse network requirements. Network Functions (NFs), which are the essential elements of network slices, are required to communicate with each other securely to facilitate network services. Certificates are the established method to authenticate each other. However, dynamic certificate management while allowing NFs to communicate in a multi-operator environment is arduous. Also, sharing NFs between network slices originates authorization-related security challenges such as unauthorized service utilization, deceptive Denial of Service attacks, and data leakages from network slices. In this paper, we develop a novel framework to address the security challenges related to authentication and authorization in 5G network slicing systems. A blockchain-based multi-party distributed certificate management framework with secure communication protocols is developed using elliptic curve cryptography to facilitate certificate services for multi-operator environments. Also, we propose a blockchain-based NF authorization framework to mitigate the security vulnerabilities in NF sharing between network slices. We implement the proposed framework using Hyperledger Fabric blockchain with Java chain codes and perform comprehensive experiments to show the significance of our framework.The Ability to mitigate the single point of failure with respect to state-of-the-art, including traditional certificate authorities and blockchain-based certificate authorities, time analysis for certificate generation, and the potential to eliminate the mentioned authorization attacks are some of the experiments conducted.Also, we have shown that our framework is secure using informal and formal (using Real-Or-Random (ROR) logic and Scyther Validation tool) security verification mechanisms. Shalitha Wijethilaka, Awaneesh Kumar Yadav, An Braeken, Madhusanka Liyanage |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2023 | A Provably Secure and Efficient 5G-AKA Authentication Protocol using BlockchainabstractThe next generation of mobile communication systems must be secured because of the ongoing entrance of numerous security attacks. Thus, to secure the underlying network, the 3GPP has designed an authentication and key agreement protocol, 5G-AKA, to safely and stably access the mobile services. However, some recent observations indicate that 5G-AKA has numerous shortcomings such as perfect forward secrecy violation, malicious Serving Network (SN), de-synchronization attack, privacy theft, stolen device, and denial of Service (DoS) attacks when the user uses the roaming mobile services. Considering the shortcomings of existing protocols and the requirement to offer increased security, we propose a provable secure, efficient 5G-AKA authentication protocol using the blockchain. The security features of the proposed protocol are examined using the Real-Or-Random (ROR) logic and Scyther tool. Furthermore, the performance of the proposed protocol is evaluated, which shows that it is the least costly compared to its counterparts in terms of computational and communication costs. In addition, the comparison of the Ethereum blockchain depicts that the proposed protocol takes less transaction and execution costs compared to its counterparts. Awaneesh Kumar Yadav, An Braeken, Manoj Misra, Madhusanka Liyanage |
CCNC | 4 |
| 2023 | Peer-to-Peer Federated Learning Based Anomaly Detection for Open Radio Access NetworksabstractOpen radio access network (O-RAN) has been recognized as a revolutionized architecture to support the multi-class wireless services required in fifth-generation (5G) and beyond 5G networks. The openness and the distributed nature of the O-RAN architecture have created new forms of threat surfaces than the conventional RAN architecture and require complex anomaly detection mechanisms. Moreover, with the introduction of RAN intelligent controllers (RICs), it is possible to utilize advanced Artificial Intelligence (AI)/ Machine Learning (ML) algorithms based on closed control loops to detect anomalies in a data-driven manner. In this paper, we particularly investigate the use of Federated Learning (FL) for anomaly detection in the O-RAN architecture, which can further preserve data privacy. We propose a peer-to-peer (P2P) FL-based anomaly detection mechanism for the O-RAN architecture and provide a comprehensive analysis of four variants of P2P FL techniques. Moreover, we simulate the proposed models using the UNSW-NB15 dataset. Dinaj Attanayaka, Pawani Porambage, Madhusanka Liyanage, Mika Ylianttila |
ICC | 3 |
| 2023 | Comprehensive Analysis Over Centralized and Federated Learning-Based Anomaly Detection in Networks with Explainable AI (XAI)abstractMany forms of machine learning (ML) and artificial intelligence (AI) techniques are adopted in communication networks to perform all optimizations, security management, and decision-making tasks. Instead of using conventional blackbox models, the tendency is to use explainable ML models that provide transparency and accountability. Moreover, Federate Learning (FL) type ML models are becoming more popular than the typical Centralized Learning (CL) models due to the distributed nature of the networks and security privacy concerns. Therefore, it is very timely to research how to find the explainability using Explainable AI (XAI) in different ML models. This paper comprehensively analyzes using XAI in CL and FL-based anomaly detection in networks. We use a deep neural network as the black-box model with two data sets, UNSW-NB15 and NSLKDD, and SHapley Additive exPlanations (SHAP) as the XAI model. We demonstrate that the FL explanation differs from CL with the client anomaly percentage. Yasintha Rumesh, Thulitha Senevirathna, Pawani Porambage, Madhusanka Liyanage, Mika Ylianttila |
ICC | 4 |
| 2023 | FL-TIA: Novel Time Inference Attacks on Federated LearningabstractFederated Learning (FL) is an emerging privacy-preserved distributed Machine Learning (ML) technique where multiple clients can contribute to training an ML model without sharing private data. Even though FL offers a certain level of privacy by design, recent works show that FL is vulnerable to numerous privacy attacks. One of the key features of FL is the continuous training of FL models over many cycles through time. Observing changes in FL models over time can lead to inferring information on changes to private and sensitive data used in the FL process. However, this potential leakage of private information is not yet investigated significantly. Therefore, this paper introduces a new form of inference-based privacy attacks called FL Time Inference Attacks (FL-TIA). These attacks can reveal private time-related properties such as the presence or absence of a sensitive feature over time and if it is periodical. We consider two forms of such FL-TIA: i.e. identifying changes in membership of target data records over training rounds and detecting significant events in clients over time by observing differences in FL models. We use the network Intrusion Detection System (IDS) as a use case to demonstrate the impact of our attack. We propose a continuous updating attack model method for membership variation detection by sustaining the accuracy of the attack. Furthermore, we provide an efficient detection method that can identify model changes using cosine similarity metric and one-shot mapping on shadow model training. Chamara Sandeepa, Bartlomiej Siniarski, Shen Wang 0006, Madhusanka Liyanage |
TrustCom | 4 |
| 2023 | A Novel Blockchain-based Decentralized Multi-party Certificate Management FrameworkabstractDigital certificates play a significant role in the current communication systems. However, with the limitations in the existing Certificate Management Frameworks (CMFs), such as single point of failure, the profound nature of existing certificates, and malicious Certificate Authorities (CAs), a novel framework is required to optimize certificate management. Even though blockchain is a popular approach in designing CMFs, they also failed to address all these limitations. There are no existing frameworks that distribute the functionality of the centralized CA to address these issues. Therefore, this paper proposes a blockchain-based, lightweight CMF while distributing the centralized certificate generation process among multiple parties. Certificate generation, validation, and revocation can be performed with our framework. We design the required secure communication protocols to deploy our framework in any blockchain. The proposed framework is implemented on top of a Hyperledger Fabric environment and performed a set of experiments to evaluate the performance of the framework. Also, a formal security analysis for the proposed communication protocols is provided using known security verification methods such as BAN logic and the Scyther tool. Shalitha Wijethilaka, Awaneesh Kumar Yadav, An Braeken, Madhusanka Liyanage |
TrustCom | 4 |
| 2023 | A Secure Blockchain-based Authentication and Key Agreement Protocol for 5G RoamingabstractThe fifth generation (5G) is now widely used to access network services due to the emergence of the Internet of Things (IoT) and mobile devices. To secure 5G communication, the Third Generation Partnership Project (3GPP) organization created the 5G-Authentication and Key Agreement (AKA) protocol. Security evaluations have found a number of problems in the 5G-AKA, including a violation of perfect forward secrecy, a traceability attack, and denial of service (DoS) attacks. To address the shortcomings of 5G-AKA, several enhanced versions have been developed. However, it has been shown that either these versions are expensive or do not address security issues. Additionally, less effort is put into providing security when a user utilizes roaming mobile services while a malicious Serving Network (SN) is present. This paper introduces an authentication mechanism to handle the above issues. In addition to this, a handover mechanism is also designed for re-connection. The authentication and handover phase security assessment uses the mathematical model Real-Or-Random (ROR), AVISPA, and Scyther tool. Furthermore, the performance comparison depicts that the authentication and handover phase is more efficient than existing protocols. An assessment of the smart contract function’s cost and effectiveness is also provided. Awaneesh Kumar Yadav, Manoj Misra, An Braeken, Madhusanka Liyanage |
TrustCom | 4 |
| 2023 | Trust Management and Bad Data Reduction in Internet of Vehicles Using Blockchain and AIabstractBlockchain offers cryptographically secure storage for recording transactions. However, one issue with blockchains is the problem of bad data and data reliability, where bad data refers to inaccurate, incomplete, or irrelevant data. This paper investigates how machine learning (ML) can be used to identify inaccurate sensor data added to a blockchain in Internet of Vehicles (IoV) applications. A solution for reducing the inclusion of incorrect data using a reputation-based method is proposed. We suggest that if an accurate ML model can be built for a task that can be completed using the input sensor data, it is possible to use the same model to assess the accuracy of new input data samples for which the actual task outcome is known. A road surface-type classification task is performed using Convolutional Neural Network models on the Passive Vehicular Sensors Datasets, and a pre-trained model is used in a novel solution approach involving edge servers and validators on a blockchain network. Our research shows that ML can be used to identify bad data on the blockchain and to reduce the addition of unreliable data to the blockchain in an IoV context. The proposed solution is generalizable and can be applied to any scenario where an accurate ML model can be devised for a task that can be accomplished using some blockchain input data. Rashmi Ratnayake, Madhusanka Liyanage, Liam Murphy 0001 |
VTC2023-Spring | 2 |
| 2023 | A Survey on Role of Blockchain for IoT: Applications and Technical Aspects
Shikha Mathur, Anshuman Kalla, Gürkan Gür, Manoj Kumar 0001, Madhusanka Liyanage |
Comput. Networks | 5 |
| 2023 | Blockchain for the metaverse: A ReviewabstractSince Facebook officially changed its name to Meta in Oct. 2021, the metaverse has become a new norm of social networks and three-dimensional (3D) virtual worlds. The metaverse aims to bring 3D immersive and personalized experiences to users by leveraging many pertinent technologies. Despite great attention and benefits, a natural question in the metaverse is how to secure its users' digital content and data. In this regard, blockchain is a promising solution owing to its distinct features of decentralization, immutability, and transparency. To better understand the role of blockchain in the metaverse, we aim to provide an extensive survey on the applications of blockchain for the metaverse. We first present a preliminary to blockchain and the metaverse and highlight the motivations behind the use of blockchain for the metaverse. Next, we extensively discuss blockchain-based methods for the metaverse from technical perspectives, such as data acquisition, data storage, data sharing, data interoperability, and data privacy preservation. For each perspective, we first discuss the technical challenges of the metaverse and then highlight how blockchain can help. Moreover, we investigate the impact of blockchain on key-enabling technologies in the metaverse, including Internet-of-Things, digital twins, multi-sensory and immersive applications, artificial intelligence, and big data. We also present some major projects to showcase the role of blockchain in metaverse applications and services. Finally, we present some promising directions to drive further research innovations and developments toward the use of blockchain in the metaverse in the future. Thien Huynh-The, G. Thippa Reddy, Weizheng Wang 0001, Gokul Yenduri, Pasika Ranaweera, Quoc-Viet Pham, Daniel B. da Costa 0001, Madhusanka Liyanage |
Future Gener. Comput. Syst. | 8 |
| 2023 | Federated Learning for the Healthcare Metaverse: Concepts, Applications, Challenges, and Future DirectionsabstractRecent technological advancements have considerably improved healthcare systems to provide various intelligent services, improving life quality. The Metaverse, often described as the next evolution of the Internet, helps the users interact with each other and the environment, thus offering a seamless connection between the virtual and physical worlds. Additionally, the Metaverse, by integrating emerging technologies, such as artificial intelligence (AI), cloud edge computing, Internet of Things (IoT), blockchain, and semantic communications, can potentially transform many vertical domains in general and the healthcare sector (healthcare Metaverse) in particular. The healthcare Metaverse holds huge potential to revolutionize the development of intelligent healthcare systems, thus presenting new opportunities for significant advancements in healthcare delivery, personalized healthcare experiences, medical education, collaborative research, and so on. However, various challenges are associated with the realization of the healthcare Metaverse, such as privacy, interoperability, data management, and security. Federated learning (FL), a new branch of AI, opens up enormous opportunities to deal with the aforementioned challenges in the healthcare Metaverse by exploiting the data and computing resources available at the distributed devices. This motivated us to present a survey on adopting FL for the healthcare Metaverse. Initially, we present the preliminaries of IoT-based healthcare systems, FL in conventional healthcare, and the healthcare Metaverse. Furthermore, the benefits of the FL in the healthcare Metaverse are discussed. Subsequently, we discuss the several applications of FL-enabled healthcare Metaverse, including medical diagnosis, patient monitoring, medical education, infectious disease, and drug discovery. Finally, we highlight the significant challenges and potential solutions toward realizing FL in the healthcare Metaverse. Ali Kashif Bashir, Nancy Victor, Sweta Bhattacharya, Thien Huynh-The, Rajeswari Chengoden, Gokul Yenduri, Praveen Kumar Reddy Maddikunta, Quoc-Viet Pham, G. Thippa Reddy, Madhusanka Liyanage |
IEEE Internet Things J. | 10 |
| 2023 | Open RAN security: Challenges and opportunitiesabstractOpen RAN (ORAN, O-RAN) represents a novel industry-level standard for RAN (Radio Access Network), which defines interfaces that support inter-operation between vendors’ equipment and offer network flexibility at a lower cost. Open RAN integrates the benefits and advancements of network softwarization and Artificial Intelligence to enhance the operation of RAN devices and operations. Open RAN offers new possibilities so different stakeholders can develop the RAN solution in this open ecosystem. However, the benefits of Open RAN bring new security and privacy challenges. As Open RAN offers an entirely different RAN configuration than what exists today, it could lead to severe security and privacy issues if mismanaged, and stakeholders are understandably taking a cautious approach towards the security of Open RAN deployment. In particular, this paper analyzes the security and privacy risks and challenges associated with Open RAN architecture. Then, it discusses possible security and privacy solutions to secure Open RAN architecture and presents relevant security standardization efforts relevant to Open RAN security. Finally, we discuss how Open RAN can be used to deploy more advanced security and privacy solutions in 5G and beyond RAN. Madhusanka Liyanage, An Braeken, Shahriar Shahabuddin, Pasika Ranaweera |
J. Netw. Comput. Appl. | 1 |
| 2023 | KDC Placement Problem in Secure VPLS NetworksabstractVirtual Private LAN Service (VPLS) is a VPN technology that connects remote client sites with provider networks in a transparent manner. Session key-based HIPLS (S-HIPLS) is a VPLS architecture based on the Host Identity Protocol (HIP) that provides a secure VPLS architecture using a Key Distribution Center (KDC) to implement security mechanisms such as authentication, encryption etc. It exhibits limited scalability though. Using multiple distributed KDCs would offer numerous advantages including reduced workload per KDC, distributed key storage, and improved scalability, while simultaneously eliminating the single point of failure of S-HIPLS. It would also come with the need for optimally placing KDCs in the provider network. In this work, we formulate the KDC placement (KDCP) problem for a secure VPLS network as an Integer Linear Programming (ILP) problem. The latter is NP-hard, thereby suggesting a high computational cost for obtaining exact solutions especially for large deployments. Therefore, we motivate the use of a primal-dual algorithm to efficiently produce near-optimal solutions. Extensive evaluations on large-scale network topologies, such as the random Internet graph, demonstrate our method’s time-efficiency as well as its improved scalability and usefulness compared to both HIPLS and S-HIPLS. Mohammad Borhani, Ioannis Avgouleas, Madhusanka Liyanage, Andrei V. Gurtov |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | Blockchain-Based Network Slice Broker to Facilitate Factory-As-a-ServiceabstractThe novel concept of factory-as-a-service (FaaS) allows the agility of adapting the manufacturing process by identifying the industry’s supply chain and user requirements. To cater to FaaS, flexibility in networking and cloud services is a must. 5G network slice broker (NSB) is a third-party mediator that caters to networking resource demand from clients to the service providers. Thus, this article introduces a secure blockchain-based NSB to facilitate FaaS. The proposed secure NSB (SNSB) provides secure, cognitive, and distributed network services for resource allocation and security service level agreement (SSLA) formation with coordination of slice managers and SSLA managers. In SNSB, we introduce a federated slice selection algorithm with Stackelberg game model and reinforcement learning algorithm to compute the real time and the optimal unit price and demand level. We provide an extensive implementation and performance evaluation of SNSB using the slice manager and a custom SSLA manager. Tharaka Mawanane Hewa, Pawani Porambage, Nisita Weerasinghe, Erkki Harjula, Madhusanka Liyanage, Mika Ylianttila |
IEEE Trans. Ind. Informatics | 6 |
| 2023 | An EAP-Based Mutual Authentication Protocol for WLAN-Connected IoT DevicesabstractSeveral symmetric and asymmetric encryption based authentication protocols have been developed for the wireless local area networks (WLANs). However, recent findings reveal that these protocols are either vulnerable to numerous attacks or computationally expensive. Considering the demerits of these protocols and the necessity to provide enhanced security, a lightweight extensible authentication protocol based authentication protocol for WLAN-connected Internet of Things devices is presented. We conduct an informal and formal security analysis to ensure robustness against the attacks. Furthermore, the empirical performance analysis and comparison show that the proposed protocol outperforms its counterparts, reducing computational, communication, storage costs, and energy consumption by up to 99%, 80%, 91.8%, and 98%, respectively. Simulation results of the protocol using the NS3 and its overhead under unknown attacks demonstrate that the proposed protocol performs better in all scenarios. A prototype implementation of the protocol has also been tested to evaluate its feasibility in real-time applications. Awaneesh Kumar Yadav, Manoj Misra, Pradumn Kumar Pandey, Madhusanka Liyanage |
IEEE Trans. Ind. Informatics | 4 |
| 2023 | Blockchain-Based Route Selection With Allocation of Radio and Computing Resources for Connected Autonomous VehiclesabstractWith the advent of connected and autonomous vehicles (CAVs), we observe a growing need for new resource allocation solutions in mobile networks. Currently, most of the resource allocation solutions for CAVs communication do not consider the driving routes of the cars. In this paper, we introduce joint vehicular route selection and radio and computing resource allocation for CAVs. The proposed approach is based on the graph search-based lexicographic A* algorithm that minimizes the ratio of failed tasks along the entire vehicular route considering the availability of both radio and computing resources. To manage the allocation of resources among multiple CAVs for each vehicular route, we develop a blockchain-based framework allowing resource reservation by means of nonfungible tokens (NFTs). Each NFT represents an exclusive right to the required amount of radio and computing resources for the given road segment and defined time interval. The effectiveness of the proposed approach is demonstrated by simulations showing that the proposed vehicular route selection algorithm reduces the ratio of tasks not completed before the deadline by up to 69% compared to the existing state-of-the-art algorithms. Marcel Volosin, Eugen Slapak, Zdenek Becvar, Taras Maksymyuk, Adam Petík, Madhusanka Liyanage, Juraj Gazda |
IEEE Trans. Intell. Transp. Syst. | 6 |
| 2023 | Proof-of-Monitoring (PoM): A Novel Consensus Mechanism for Blockchain-Based Secure Service Level Agreement ManagementabstractIn the current 5th Generation (5G) networking paradigm, the enforcement of Service Level Agreements (SLAs) is a non-trivial measure to ensure the scope and the quality of services and standards between tenants and service providers (SPs). On top of this, Secure Service Level Agreements (SSLA) are introduced to ensure that SPs deliver the most critical and required security-related standards defined in the contract, such as integrity, confidentiality, availability, non-repudiation, and privacy assurance. However, with the tendency for more distributed and multi-stakeholder networking architectures in next-generation networks, the management process of such SSLAs will be challenging due to the diversified security vulnerabilities and complexity of underlying technologies. Although blockchain is emerging as a platform to facilitate such distributed SSLA/SLA management frameworks, its currently available consensus mechanisms are more generic. Still, they need to improve in terms of applying in multi-stakeholder networks. Therefore, this paper presents a novel consensus mechanism called Proof-of-Monitoring (PoM) for a blockchain-based novel SSLA management framework. Moreover, we provide details about the prototype implementation of our proposed consensus algorithm and SSLA management framework. It is proven by comparing our proposal with the other existing solutions that our solution outperforms in many aspects, such as energy consumption, computation cost, and security features. Nisita Weerasinghe, Raaj Anand Mishra, Pawani Porambage, Madhusanka Liyanage, Mika Ylianttila |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2023 | An Enhanced Cross-Network-Slice Authentication Protocol for 5GabstractNetwork slicing is considered one of the key technologies in future telecommunication networks as it can split the physical network into a number of logical networks tailored to diverse purposes that allow users to access various services speedily. The fifth-generation (5G) mobile network can support a variety of applications by using network slicing. However, security (especially authentication) is a significant issue when users access the network slice-based services. Various authentication schemes are designed to secure access, and only a few offer cross-network slice authentication. The security analysis of existing cross-network authentication schemes shows they are vulnerable to several attacks such as device stolen, ephemeral secret leakage, violation of perfect forward secrecy, identity theft. Therefore, we propose an authentication mechanism that offers cross-network slice authentication and prevents all the aforementioned vulnerabilities. The security verification of the authentication mechanism is carried out informally and formally (ROR logic and Scyther tool) to ensure that it handles all the vulnerabilities. The comparison of empirical evaluation shows that the proposed scheme is least costly than its competitors. Java-based implementations of the proposed protocols imitate a real environment, showing that our proposed protocol maintains almost the same performance as state-of-the-art solutions while providing additional security features. Awaneesh Kumar Yadav, Shalitha Wijethilaka, An Braeken, Manoj Misra, Madhusanka Liyanage |
IEEE Trans. Sustain. Comput. | 5 |
| 2022 | A Novel Request Handler Algorithm for Multi-access Edge Computing Platforms in 5GabstractMulti-access Edge Computing (MEC) is envisaging a storage and processing infrastructure at the edge of the mobile network to guarantee ultra-low latency and higher bandwidths for the provisioning services emanated by Internet of Things (IoT) devices. To achieve these dynamic requirements, MEC is adopting virtualization technologies that form a cost effective automated infrastructure ideal for 5G and beyond networks. Orchestration is the paramount task of such virtual platforms to manage and control the virtual entities autonomously. Service request handling is one such key orchestration function that handles the incoming requests to the orchestrator in case of a service initiation. However, existing service request handling procedures in MEC are still in a trivial stage. Thus, this paper proposes an advanced service request handling strategy for MEC orchestrator which can consider several factors such as service priority levels, feasibility, and resource availability. The performance of the proposed strategy is analyzed in a simulated environment and its feasibility is demonstrated using a prototype MEC infrastructure. Gayan Dilanka, Lakshan Viranga, Rajitha Pamudith, Tharindu D. Gamage, Pasika Ranaweera, Indika A. M. Balapuwaduge, Madhusanka Liyanage |
CCNC | 7 |
| 2022 | Deployment Options of 5G Network Slicing for Smart HealthcareabstractNetwork slicing enables the creation of multiple logical independent networks on physical networking infrastructure. Network slice deployment in a Fifth Generation (5G) mobile network can be classified as vertical and horizontal slicing. The paper compares the performance of the two slicing methods through solving two convex optimization problems, considering several smart hospital scenarios that differ from each other based on their medical speciality. The results are used to draw insights on the most appropriate slicing approach for each setup. Rakshitha De Silva, Yushan Siriwardhana, Tharaka Samarasinghe, Madhusanka Liyanage, Mika Ylianttila |
CCNC | 4 |
| 2022 | A Comprehensive Analysis on Network Slicing for Smart Hospital ApplicationsabstractNetwork slicing (NS) is technology that enables emerging smart applications and use cases in Fifth Generation (5G) and beyond networks. One such application is smart hospitals, which has diverse network requirements for applications ranging from Augmented Reality (AR) and robot assisted surgeries to connecting large numbers of medical wearables and sensors. NS can be performed in smart hospitals under different strategies based on dynamicity, ownership, and application. This paper investigates how these strategies can be utilized in different smart hospital applications. The performance of each slicing strategy in a hospital network is analyzed under three matrices: bandwidth utilization, handover count, and block count. Shalitha Wijethilaka, Pawani Porambage, Chamitha de Alwis, Madhusanka Liyanage |
CCNC | 4 |
| 2022 | Service Migration Authentication Protocol for MECabstractMulti-Access Edge Computing (MEC) is a novel edge computing paradigm that enhances the access level capacity of mobile networks by shifting the serviceable Data center infrastructure proximate to the end devices. With this proximate placement and service provisioning, migration of a service from one edge enabled gNodeB (gNB) to another is intrinsic to maintain the service continuity. Since such services are migrated through the channel shared between the gNBs, proper security measures should be inhibited by the communication protocol to prevent any unauthorized interception. Further, each gNB should ensure the legitimacy of the migrating gNBs to avoid any impersonation attempts. As this is an area that lacks focus in current research trends, this paper introduces MEC Service Migration Authentication Protocol (MEC-SMAP), a protocol that take place prior to the migration initiation, and specifically defined for MEC. The proposed protocol ensures the secure transfer of session key generation parameters to form a secure channel while ensuring perfect forward secrecy. It introduces an identity verification mechanism through a trusted third party service. We have validated the proposed protocol through formal analysis using GNY logic and Scyther tool. Further, a prototype virtualized MEC environment was created to evaluate its feasibility and the impact of the employed security mechanisms. Pasika Ranaweera, Awaneesh Kumar Yadav, Madhusanka Liyanage, Anca Jurcut |
GLOBECOM | 3 |
| 2022 | A Federated Learning Approach for Improving Security in Network SlicingabstractNetwork Slicing (NS) is a predominant technology in future telecommunication networks, including Fifth Generation (5G), which supports the realization of heterogeneous applications and services. It allows the allocation of a dedicated logical network slice of the physical network to each application. Security is one of the paramount challenges in an NS ecosystem. Several technologies, including Machine Learning (ML), have been proposed to mitigate security challenges in 5G networks. However, the use of ML for NS security is not properly implemented. Especially, the scarcity of coordination and the difficulties of privacy-protected information sharing between slices cause failures and performance degradation of these ML based NS security solutions. To address this issue, this paper proposes a novel Federated Learning (FL) based coordinated security orchestration architecture named Federated Learning enabled Security Orchestrator (FLeSO) to centrally perform security operations in a slicing ecosystem while preserving the privacy of the data. In addition, the proposed FLeSO architecture enables features such as proactive security deployment and steady security level maintenance independent of the slicing strategy. The proposed architecture is implemented in a real-world slicing testbed, and a comprehensive set of experiments are performed to evaluate the effectiveness of the proposed FLeSO architecture. The test results illustrate the significant advantage of the proposed approach over the legacy system in terms of improving the security of an NS ecosystem. Shalitha Wijethilaka, Madhusanka Liyanage |
GLOBECOM | 2 |
| 2022 | LEMAP: A Lightweight EAP based Mutual Authentication Protocol for IEEE 802.11 WLANabstractThe growing usage of wireless devices has significantly increased the need for Wireless Local Area Network (WLAN) during the past two decades. However, security (most notably authentication) remains a major roadblock to WLAN adoption. Several authentication protocols exist for verifying a supplicant’s identity who attempts to connect his wireless device to an access point (AP) of an organization’s WLAN. Many of these protocols use the Extensible Authentication Protocol (EAP) framework. These protocols are either vulnerable to attacks such as violation of perfect forward secrecy, replay attack, synchronization attack, privileged insider attack, and identity theft or require high computational and communication costs. In this paper, a lightweight EAP-based authentication protocol for IEEE 802.11 WLAN is proposed that not only addresses the security issues in the existing WLAN authentication protocols but is also cost-effective. The security of the proposed protocol is verified using BAN logic and the Scyther tool. Our analysis shows that the proposed protocol is safe against all the above attacks and attacks defined in RFC-4017. A comparison of the computational and communication costs of the proposed protocol with other existing state-of-the-art protocols shows that the proposed protocol is lightweight than existing solutions. Awaneesh Kumar Yadav, Manoj Misra, Pradumn Kumar Pandey, Kuljeet Kaur, Sahil Garg, Madhusanka Liyanage |
ICC | 6 |
| 2022 | MEC-RHA: Demonstration of Novel Service Request Handling Algorithm for MECabstractMulti-Access Edge Computing (MEC) is a cloud computing evolution that delivers end-user services at the mobile network’s edge. As a result, MEC guarantees that users will benefit from ultra-low latency and increased bandwidth when using the services. The orchestration process is the holistic management and control of the edge computing platforms. Handling of service requests forwarded by the MEC subscribers is an inceptive function that requires the intervention of the orchestrator. This paper demonstrates how an advanced service request handler algorithm (MEC-RHA) works on MEC orchestration, considering factors of service priority levels, feasibility, and resource availability when launching a service; while an optimal MEC server selection process is formed based on those factors. Gayan Dilanka, Lakshan Viranga, Rajitha Pamudith, Tharindu D. Gamage, Pasika Ranaweera, Indika A. M. Balapuwaduge, Madhusanka Liyanage |
NOMS | 7 |
| 2022 | Demo: Blockchain-based Secured and Federated Slice Broker (SFSBroker)abstractNetwork slicing is a versatile and distinguishing capability of the 5th and 6th Generation (5G & 6G) mobile networks. Network slicing enables the consumers to deliver individualized and customized telecommunication services on the commonly shared infrastructure. Slice brokering is the dedicated service to facilitate the tenants and resource providers in slice allocation process. We proposed SFSBroker (Secured and Federated Slice Broker) to leverage the slice brokering process with the application of game theory. We formulated the optimal slice selection problem into the Stackelberg game model. The computational logic has been incorporated on smart contracts. Furthermore, the proposed architecture includes Security Service Blockchain (SSB) which has been integrated for Denial of Service (DoS) attack prevention. We implemented the end to end setup including tenant request to slice creation using Hyperledger Fabric blockchain, Katana slice manager, and OpenStack. In this demonstration, the system provisions to obtain hands-on experience on the end to end workflow of slice brokering process. Tharaka Mawanane Hewa, Nisita Weerasinghe, Pawani Porambage, Madhusanka Liyanage, Mika Ylianttila |
NOMS | 4 |
| 2022 | An improved and provably secure symmetric-key based 5G-AKA Protocol
Awaneesh Kumar Yadav, Manoj Misra, Pradumn Kumar Pandey, An Braeken, Madhusanka Liyanage |
Comput. Networks | 5 |
| 2022 | A Survey on the Convergence of Edge Computing and AI for UAVs: Opportunities and ChallengesabstractThe latest 5G mobile networks have enabled many exciting Internet of Things (IoT) applications that employ unmanned aerial vehicles (UAVs/drones). The success of most UAV-based IoT applications is heavily dependent on artificial intelligence (AI) technologies, for instance, computer vision and path planning. These AI methods must process data and provide decisions while ensuring low latency and low energy consumption. However, the existing cloud-based AI paradigm finds it difficult to meet these strict UAV requirements. Edge AI, which runs AI on-device or on edge servers close to users, can be suitable for improving UAV-based IoT services. This article provides a comprehensive analysis of the impact of edge AI on key UAV technical aspects (i.e., autonomous navigation, formation control, power management, security and privacy, computer vision, and communication) and applications (i.e., delivery systems, civil infrastructure inspection, precision agriculture, search and rescue (SAR) operations, acting as aerial wireless base stations (BSs), and drone light shows). As guidance for researchers and practitioners, this article also explores UAV-based edge AI implementation challenges, lessons learned, and future research directions. Patrick McEnroe, Shen Wang 0006, Madhusanka Liyanage |
IEEE Internet Things J. | 3 |
| 2022 | A survey on Zero touch network and Service Management (ZSM) for 5G and beyond networksabstractFaced with the rapid increase in smart Internet-of-Things (IoT) devices and the high demand for new business-oriented services in the fifth-generation (5G) and beyond network, the management of mobile networks is getting complex. Thus, traditional Network Management and Orchestration (MANO) approaches cannot keep up with rapidly evolving application requirements. This challenge has motivated the adoption of the Zero-touch network and Service Management (ZSM) concept to adapt the automation into network services management. By automating network and service management, ZSM offers efficiency to control network resources and enhance network performance visibility. The ultimate target of the ZSM concept is to enable an autonomous network system capable of self-configuration, self-monitoring, self-healing, and self-optimization based on service-level policies and rules without human intervention. Thus, the paper focuses on conducting a comprehensive survey of E2E ZSM architecture and solutions for 5G and beyond networks. The article begins by presenting the fundamental ZSM architecture and its essential components and interfaces. Then, a comprehensive review of the state-of-the-art for key technical areas, i.e., ZSM automation, cross-domain E2E service lifecycle management, and security aspects, are presented. Furthermore, the paper contains a summary of recent standardization efforts and research projects towards the ZSM realization in 5G and beyond networks. Finally, several lessons learned from the literature and open research problems related to ZSM realization are also discussed in this paper. Madhusanka Liyanage, Quoc-Viet Pham, Kapal Dev, Sweta Bhattacharya, Praveen Kumar Reddy Maddikunta, G. Thippa Reddy, Gokul Yenduri |
J. Netw. Comput. Appl. | 1 |
| 2022 | Proof of Sense: A Novel Consensus Mechanism for Spectrum Misuse DetectionabstractOptimal use of scarce radio spectrum is essential in the proliferation of beyond 5G networks, and promising blockchain technology offers various benefits for the spectrum management. However, existing blockchain-based solutions are expensive, nonoptimized, and lack spectrum fraud detection. This article proposes a novel consensus mechanism for a blockchain-based dynamic spectrum access (DSA) system. The proposed “Proof-of-Sense” consensus mechanism operates based on spectrum sensing procedures rather than cryptographic calculations. It is specially designed to address fraudulent/unauthorized access to the spectrum by analyzing the sensed spectrum data. The core of the consensus mechanism is a cryptographic key sharing mechanism inspired by Shamir’s secret sharing scheme. Moreover, the proposed DSA system can enable different microservices, such as automated spectrum auctions, payment and penalty handling, and spectrum fraud detection. A proof of concept based on experimental approaches coupled with Matlab simulations is presented to analyze the performance of the proposed consensus mechanism. Pramitha Fernando, Keshawa Dadallage, Tharindu D. Gamage, Chatura Seneviratne, Arjuna Madanayake, Madhusanka Liyanage |
IEEE Trans. Ind. Informatics | 6 |
| 2022 | Fog Computing and Blockchain-Based Security Service Architecture for 5G Industrial IoT-Enabled Cloud ManufacturingabstractRecent evolution of the industrial Internet of Things empowers the classical manufacturing model with cloud computing integration for Industry 4.0. Cloud integration advances the capabilities of manufacturing systems with cloud-based controlling and real-time process monitoring, which is renowned as cloud manufacturing (CM). However, cloud integration exposes the entire manufacturing ecosystem to a new set of security risks and increments in end-to-end latency. Moving security services toward the edge eradicates message routing latency toward the cloud and eliminates the central point of failure while leveraging the entire system’s performance. We propose a blockchain and fog-computing-enabled security service architecture that operates on fog nodes at the edge of manufacturing equipment clusters. The proposed service facilitates CM equipment authentication and equipment-cloud channel privacy protection while preserving anonymity and unlinkability over the blockchain. We implemented the proposed architecture with hyperledger fabric and compared the performance advantage over the state-of-the-art solutions. Tharaka Mawanane Hewa, An Braeken, Madhusanka Liyanage, Mika Ylianttila |
IEEE Trans. Ind. Informatics | 3 |
| 2021 | Performance Analysis of Softwarized Local Mobile NetworksabstractThe ever growing and revolutionizing demands in telecommunication industry to facilitate numerous business verticals are pushing towards more softwarized mobile communication technologies. Utilizing the capabilities of network softwarization, a novel telecommunication concept of local mobile network has been developed. The local mobile networks are getting popular due to their capability of providing efficient and reliable local services to a focused use case with higher flexibility. This paper presents the practical implementation aspects of a softwarized local mobile network and compare its performance with a conventional mobile network and a hybrid network. Yushan Siriwardhana, Pawani Porambage, Madhusanka Liyanage, Mika Ylianttila |
CCNC | 3 |
| 2021 | Blockchain-based Roaming and Offload Service Platform for Local 5G OperatorsabstractLocal 5G Operator (L5GO) concept is one of the most prominent versatile applications of the 5G in the near future. The popularity of L5GOs will trigger a greater number of roaming and offloading events between mobile operators. However, existing static and the operator-assisted roaming and offloading procedures are inefficient for L5GO ecosystem due to poor service quality, data privacy issues, data transferring delays, excessive costs for intermediary parties and existence of roaming fraud. To address these challenges, we propose a blockchain / Distributed Ledger Technology (DLT) based service platform for L5GOs to facilitate efficient roaming and offload services. As the key contribution, blockchain-based smart contract scheme is proposed to establish dynamic and automated agreements between operators. By using smart contracts, we introduce several novel features such as universal wallet for subscribers, service quality based L5GO rating system, user-initiated roaming process and the roaming fraud prevention system to improve the operational quality of a L5GO. A prototype of the proposed platform is emulated with the Ethereum blockchain platform and Rinkeby Testnet to evaluate the performance and justify the feasibility of the proposal. Upon an extensive evaluation on the prototype, it was observed that the proposed platform offered benefits such as cost effective, more secure and reliable experience. Nisita Weerasinghe, Tharaka Mawanane Hewa, Maheshi B. Dissanayake, Mika Ylianttila, Madhusanka Liyanage |
CCNC | 5 |
| 2021 | Realizing Internet of Things with Network Slicing: Opportunities and ChallengesabstractInternet of Things (IoT) is a lucrative technology within the modern community that realizes the concept of the smart world, by expanding within a myriad of applications. Existing wireless networks require a radical change to fulfill the network requirements and cater the rapid expansion of the IoT ecosystem. 5G architecture is specifically designed to facilitate this demand. Network slicing is a pivotal technology in 5G architecture that has the ability to divide the physical network into multiple logical networks with specific network characteristics. In this paper, we are going to analyze how network slicing can be helpful in the IoT realization. Technical aspects that are required in the IoT realization, and the slicing based solutions which address these aspects, will be discussed here. Moreover, technical challenges that can arise due to network slicing integration in IoT ecosystem, will also be discussed with the potential solutions. Shalitha Wijethilaka, Madhusanka Liyanage |
CCNC | 2 |
| 2021 | How DoS attacks can be mounted on Network Slice Broker and can they be mitigated using blockchain?abstractSeveral recent works talk about the potential use of network slice brokering mechanism to facilitate the resource allocation of network slicing in next generation networks. This involves network tenants on the one hand and resource/infrastructure providers on the other hand. However, the potential downside of deploying Network Slice Broker (NSB) is that it can be victimized by DoS (Denial of Service) attack. Thus, the aim of this work is three fold. First, to present the possible ways in which DoS/DDoS attacks can be mounted on NSB and their adverse effects. Second, to propose and implement initial blockchain-based solution named as Security Service Blockchain (SSB) to prevent DoS attacks on NSB. Third, to enumerate the challenges and future research directions to effectively utilize blockchain for mitigating DoS/DDoS attacks on NSB. To evaluate the performance the proposed SSB framework is implemented using Hyperledger Fabric. The results manifest that the latency impact of the legitimate slice creation over scaled up malicious traffic remains minimal with the use of SSB framework. The integration of SSB with NSB results in gaining several fold reduction in latency under DoS attack scenario. Tharaka Mawanane Hewa, Anshuman Kalla, Pawani Porambage, Madhusanka Liyanage, Mika Ylianttila |
PIMRC | 4 |
| 2021 | Blockchain-based Decentralized Service Provisioning in Local 6G Mobile NetworksabstractThe paper presents a novel vision on the application of blockchain technology to empower the dynamic service provisioning in future 6G mobile networks. We propose a platform for decentralized service level agreement (SLA) negotiation between users and mobile network operators (MNOs) based on smart contracts and cryptocurrencies. In addition, the new quality of experience (QoE) model is proposed for end-users to customize their trade-off between SLA and service price. Finally, we develop the method of dynamic service selection among multiple MNOs that provides border-less connectivity for end-users with the guaranteed QoE regardless of the serving MNO. Taras Maksymyuk, Marcel Volosin, Juraj Gazda, Madhusanka Liyanage |
SenSys | 4 |
| 2021 | A Survey of Virtual Private LAN Services (VPLS): Past, Present and FutureabstractVirtual Private LAN services (VPLS) is a Layer 2 Virtual Private Network (L2VPN) service that has gained immense popularity due to a number of its features, such as protocol independence, multipoint-to-multipoint mesh connectivity, robust security, low operational cost (in terms of optimal resource utilization), and high scalability. In addition to the traditional VPLS architectures, novel VPLS solutions have been designed leveraging new emerging paradigms, such as Software Defined Networking (SDN) and Network Function Virtualization (NFV), to keep up with the increasing demand. These emerging solutions help in enhancing scalability, strengthening security, and optimizing resource utilization. This paper aims to conduct an in-depth survey of various VPLS architectures and highlight different characteristics through insightful comparisons. Moreover, the article discusses numerous technical aspects such as security, scalability, compatibility, tunnel management, operational issues, and complexity, along with the lessons learned. Finally, the paper outlines future research directions related to VPLS. To the best of our knowledge, this paper is the first to furnish a detailed survey of VPLS. Kuntal Gaur, Anshuman Kalla, Jyoti Grover, Mohammad Borhani, Andrei V. Gurtov, Madhusanka Liyanage |
Comput. Networks | 6 |
| 2021 | Privacy Protected Blockchain Based Architecture and Implementation for Sharing of Students' CredentialsabstractSharing of students’ credentials is a necessary and integral process of an education ecosystem that comprises various stakeholders like students, schools, companies, professors and the governmental authorities. As of today, all these stakeholders have to put-in an enormous amount of efforts to ensure the authenticity and privacy of students’ credentials. Despite these efforts, the process of sharing students’ credentials is complex, error-prone and not completely secure. Our aim is to leverage blockchain technology to mitigate the existing security-related issues concerning the sharing of students’ credentials. Thus, the paper proposes a tamper-proof, immutable, authentic, non-repudiable, privacy protected and easy to share blockchain-based architecture for secured sharing of students’ credentials. To increase the scalability, the proposed system uses a secure off-chain storage mechanism. The performance and viability of the proposed architecture is analyzed by using an Ethereum based prototypical implementation. The test results imply that requests can be executed within few seconds (without block-time) and the system has stability to process up to 1000 simultaneous requests. Raaj Anand Mishra, Anshuman Kalla, An Braeken, Madhusanka Liyanage |
Inf. Process. Manag. | 4 |
| 2021 | Survey on blockchain based smart contracts: Applications, opportunities and challenges
Tharaka Mawanane Hewa, Mika Ylianttila, Madhusanka Liyanage |
J. Netw. Comput. Appl. | 3 |
| 2021 | Proxy re-encryption enabled secure and anonymous IoT data sharing platform based on blockchainabstractData is central to the Internet of Things (IoT) ecosystem. With billions of devices connected, most of the current IoT systems are using centralized cloud-based data sharing systems, which will be difficult to scale up to meet the demands of future IoT systems. The involvement of such a third-party service provider requires also trust from both the sensor owner and sensor data user. Moreover, fees need to be paid for their services. To tackle both the scalability and trust issues and to automatize the payments, this paper presents a blockchain-based marketplace for sharing of the IoT data. We also use a proxy re-encryption scheme for transferring the data securely and anonymously, from data producer to the consumer. The system stores the IoT data in cloud storage after encryption. To share the collected IoT data, the system establishes runtime dynamic smart contracts between the sensor and data consumer without the involvement of a trusted third-party. It also uses a very efficient proxy re-encryption scheme which allows that the data is only visible by the owner and the person present in the smart contract. This novel combination of smart contracts with proxy re-encryption provides an efficient, fast and secure platform for storing, trading and managing sensor data. The proposed system is implemented using off-the-shelf IoT sensors and computer devices. We also analyze the performance of our hybrid system by using the permission-less Ethereum blockchain and compare it to the IBM Hyperledger Fabric, a permissioned blockchain. Ahsan Manzoor, An Braeken, Salil S. Kanhere, Mika Ylianttila, Madhusanka Liyanage |
J. Netw. Comput. Appl. | 5 |
| 2021 | Highly efficient key agreement for remote patient monitoring in MEC-enabled 5G networks
An Braeken, Madhusanka Liyanage |
J. Supercomput. | 2 |
| 2020 | Implementation and Analysis of Blockchain Based DApp for Secure Sharing of Students' CredentialsabstractThe paper aims to resolve security issues revolving around the sharing of students' credentials by leveraging the blockchain technology. It proposes a novel blockchain-based architecture followed by its implementation as a decentralized application (DApp). Further, the cost & the performance analysis are carried out based on the experiments conducted. Raaj Anand Mishra, Anshuman Kalla, Nimer Amol Singh, Madhusanka Liyanage |
CCNC | 4 |
| 2020 | Multi-Access Edge Computing and Blockchain-based Secure Telehealth System Connected with 5G and IoTabstractThere is a global hype in the development of digital healthcare infrastructure to cater the massive elderly population and infectious diseases. The digital facilitation is expected to ensure the patient privacy, scalability, and data integrity on the sensitive life critical healthcare data, while aligning to the global healthcare data protection standards. The patient data sharing to third parties such as research institutions and universities is also concerned as a significant contribution to the society to sharpen the research and investigations. The emergence of 5G communication technologies eradicates the borders between patients, hospital and other institutions with high end service standards. In patients' perspective, healthcare service delivery through the digital medium is beneficial in terms of time, costs, and risks. In this paper, we propose a novel Multi-access Edge Computing(MEC) and blockchain based service architecture utilizing the lightweight ECQV (Elliptic Curve Qu-Vanstone) certificates for the realtime data privacy, integrity, and authentication between IoT, MEC, and cloud. We further attached storage offloading capability to the blockchain to ensure scalability with a massive number of connected medical devices to the cloud. We introduced a rewarding scheme to the patients and hospitals through the blockchain to encourage data sharing. The access control is handled through the smart contracts. We evaluated the proposed system in a near realistic implementation using Hyperledger Fabric blockchain platform with Raspberry Pi devices to simulate the activity of the medical sensors. Tharaka Mawanane Hewa, An Braeken, Mika Ylianttila, Madhusanka Liyanage |
GLOBECOM | 4 |
| 2020 | Blockchain-based Automated Certificate Revocation for 5G IoTabstractInternet of Things (IoT) is a key topic of interest in modern communication context with the evolution of 5G and beyond ecosystems. 5G will interconnects billions of IoT devices wirelessly. The wireless communication exposes the devices to massive security risks in different dimensions. The Public Key Infrastructure (PKI) is one of the promising solutions to eliminate security risks. It ensures the authentication and communication integrity by using public key certificates. However, the overhead of certificate storage is a significant problem for the resource constrained IoT devices. We propose an application of Elliptic Curve Qu Vanstone (ECQV) certificates, which are lightweight in size for the resource restricted IoT devices. Furthermore, we incorporate the blockchain based smart contracts to handle the certificate related operations. We utilize the smart contracts in the certificate issuance and developed a smart contract based threat scoring mechanism to automatically revoke the certificates. The lightweight nature of ECQV certificates enables the distributed ledger to store, update, and revoke the certificates. We evaluated the proposed solution in Hyperledger Fabric blockchain platform. Tharaka Mawanane Hewa, An Braeken, Mika Ylianttila, Madhusanka Liyanage |
ICC | 4 |
| 2020 | Dynamic Orchestration of Security Services at Fog Nodes for 5G IoTabstractFog Computing is one of the edge computing paradigms that envisages being the proximate processing and storage infrastructure for a multitude of IoT appliances. With its dynamic deployability as a medium level cloud service, fog nodes are enabling heterogeneous service provisioning infrastructure that features scalability, interoperability, and adaptability. Out of the various 5G based services possible with the fog computing platforms, security services are imperative but minimally investigated direct live. Thus, in this research, we are focused on launching security services in a fog node with an architecture capable of provisioning on-demand service requests. As the fog nodes are constrained on resources, our intention is to integrate light-weight virtualization technology such as Docker for forming the service provisioning infrastructure. We managed to launch multiple security instances configured to be Intrusion Detection and Prevention Systems (IDPSs) on the fog infrastructure emulated via a Raspberry Pi-4 device. This environment was tested with multiple network flows to validate its feasibility. In our proposed architecture, orchestration strategies performed by the security orchestrator were stated as guidelines for achieving pragmatic, dynamic orchestration with fog in IoT deployments. The results of this research guarantee the possibility of developing an ambient security service model that facilitates IoT devices with enhanced security. Vashish N. Imrith, Pasika Ranaweera, Rameshwar A. Jugurnauth, Madhusanka Liyanage |
ICC | 4 |
| 2020 | Security as a Service Platform Leveraging Multi-Access Edge Computing Infrastructure ProvisionsabstractThe mobile service platform envisaged by emerging IoT and 5G is guaranteeing gigabit-level bandwidth, ultra-low latency and ultra-high storage capacity for their subscribers. In spite of the variety of applications plausible with the envisaged technologies, security is a demanding objective that should be applied beyond the design stages. Thus, Security as a Service (SECaaS) is an initiative for a service model that enable mobile and IoT consumers with diverse security functions such as Intrusion Detection and Prevention (IDPaaS), Authentication (AaaS), and Secure Transmission Channel (STCaaS) as a Service. A well-equipped edge computing infrastructure is intrinsic to achieve this goal. The emerging Multi-Access Edge Computing (MEC) paradigm standardized by the ETSI is excelling among other edge computing flavours due to its well-defined structure and protocols. Thus, in our directive, we intend to utilize MEC as the edge computing platform to launch the SECaaS functions. Though, the actual development of a MEC infrastructure is highly dependent on the integration of virtualization technologies to enable dynamic creation, the deployment, and the detachment of virtualized entities that should feature interoperability to cater the heterogeneous IoT devices and services. To that extent, this work is proposing a security service architecture that offers these SECaaS services. Further, we validate our proposed architecture through the development of a virtualized infrastructure that integrates lightweight and hypervisor-based virtualization technologies. Our experiments prove the plausibility of launching multiple security instances on the developed prototype edge platform. Pasika Ranaweera, Vashish N. Imrith, Madhusanka Liyanage, Anca Jurcut |
ICC | 3 |
| 2020 | Secure and User Efficient EAP-based Authentication Protocol for IEEE 802.11 Wireless LANsabstractWireless Local Area Networks (WLANs) have experienced significant growth in the last two decades due to the extensive use of wireless devices. Security (especially authentication) is a staple concern as the wireless medium is accessible to everybody. Extensible Authentication Protocol (EAP) is the widely used authentication framework in WLANs to secure communication. The authentication mechanism designed on EAP is called EAP method. There are numerous EAP based and nonEAP based authentication protocols for WLANs, but there is no protocol that fulfills all the security requirements, as mentioned in RFC-4017 and other additional requirements like perfect forward secrecy, Denial-of-service (DoS) attack protection, and lightweight computation. Hence, it is fair to infer that there is an impelling need to design a protocol that can meet all the security requirements. In this paper, we propose a secure and user efficient EAP-based authentication protocol for IEEE 802.11 WLANs. The proposed protocol has been formally validated by BAN logic and the AVISPA tool [18]. The simulation results depict that the proposed protocol achieves all security requirements, as mentioned in RFC-4017 along with perfect forward secrecy, Denial-of-service (DoS) attack protection, and lightweight computation. The proposed protocol outperforms the existing protocols in terms of computation cost by reducing the computation cost by ≈ 99.9956%, 99.991%, 27.27%, 22.705% in comparison to EAP-TLS, EAP-TTLS, EAP-Ehash, EAP-SELUA, respectively. Keywords-AP, AS, AVISPA, BAN, EAP, WLANs. Awaneesh Kumar Yadav, Manoj Misra, Madhusanka Liyanage, Gaurav Varshney |
MASS | 3 |
| 2020 | Performance Analysis of Local 5G Operator Architectures for Industrial Internetabstract5G calls for a network architecture that ensures ultraresponsive and ultrareliable communication links, in addition to the high degree of flexibility and customization required by different vertical sectors. The novel concept called local 5G networks enables a versatile set of stakeholders to operate 5G networks within their premises with guaranteed quality and reliability to complement mobile network operators' (MNOs) offerings. This article proposes a descriptive architecture for a local 5G operator which provides user specific and location-specific services in a spatially confined environment, i.e., industrial Internet environment. In addition to that, the article proposes hybrid architecture options where both the local 5G operator and MNO collaboratively contribute to establish the core network to cater to such communications. The architecture is discussed in terms of network functions (NFs) and the operational units which entail the core and radio access networks in a smart factory environment which supports Industry 4.0 standards. Moreover, to realize the conceptual design, the article provides simulation results for the latency measurements of the proposed architecture options with respect to an augmented reality (AR), massive wireless sensor networks, and mobile robots use cases. Thereby the article discusses the benefits of deploying core NFs locally to cater to specialized user requirements, rather than continuing with the conventional approach where only MNOs can deploy cellular networks. Yushan Siriwardhana, Pawani Porambage, Mika Ylianttila, Madhusanka Liyanage |
IEEE Internet Things J. | 4 |
| 2019 | Managing Mobile Relays for Secure E2E Connectivity of Low-Power IoT DevicesabstractThe widespread Internet of Things (IoT) ecosystems empower the deployment of various Bluetooth Low Energy (BLE) sensor nodes in many ambient assisted living (AAL) type applications. Regardless of their limitations, these low-power IoT sensor nodes need pervasive and secure connections to transfer the aggregated data to the central servers located in remote clouds which will perform further processing and storing functions. The common practice is to use one or multiple dedicated gateways to assist the communication between the sensor and the cloud. This paper presents a mobile-based relay assistance solution for establishing secure end-to-end (E2E) connectivity between low-power IoT sensors and cloud servers without using a dedicated gateway. za The prototype implementation and the described security features verify the technical readiness of the proposed solution. Pawani Porambage, Ahsan Manzoor, Madhusanka Liyanage, Andrei V. Gurtov, Mika Ylianttila |
CCNC | 3 |
| 2019 | Micro-Operator driven Local 5G Network Architecture for Industrial InternetabstractIn addition to the high degree of flexibility and customization required by different vertical sectors, 5G calls for a network architecture that ensures ultra-responsive and ultra-reliable communication links. The novel concept called micro-operator (uO) enables a versatile set of stakeholders to operate local 5G networks within their premises with a guaranteed quality and reliability to complement mobile network operators' (MNOs) offerings. In this paper, we propose a descriptive architecture for emerging 5G uOs which provides user specific and location specific services in a spatially confined environment. The architecture is discussed in terms of network functions and the operational units which entail the core and radio access networks in a smart factory environment which supports industry 4.0 standards. Moreover, in order to realize the conceptual design, we provide simulation results for the latency measurements of the proposed uO architecture with respect to an augmented reality use case in industrial internet. Thereby we discuss the benefits of having uO driven local 5G networks for specialized user requirements, rather than continuing with the conventional approach where only MNOs can deploy cellular networks. Yushan Siriwardhana, Pawani Porambage, Madhusanka Liyanage, Jaspreet Singh Walia, Marja Matinmikko, Mika Ylianttila |
WCNC | 3 |
| 2018 | Secure and Efficient Data Accessibility in Blockchain Based Healthcare SystemsabstractThe healthcare industry is constantly reforming and adopting new shapes with respect to the technological evolutions and transitions. One of the crucial requirements in the current smart healthcare systems is the protection of patients sensitive data against the potential adversaries. Therefore, it is vital to have secure data access mechanisms that can ensure only authorized entities can access the patients medical information. Hence, this paper considers blockchain technology as a distributed approach protect the data in healthcare systems. This research proposes a blockchain based secure and efficient data accessibility mechanism for the patient and the doctor in a given healthcare system. Proposed system able to protect the privacy of the patients as well. The security analysis of our scheme shows that it can resist to well-known attacks along with maintaining the integrity of the system. Moreover, an Ethereum based implementation has used to verify the feasibility of our proposed system. Vidhya Ramani, Tanesh Kumar, An Braeken, Madhusanka Liyanage, Mika Ylianttila |
GLOBECOM | 4 |
| 2018 | On the security verification of a short message service protocolabstractShort Message Service (SMS) is a text messaging service component of smart phones, web, or mobile communication systems which requires a high level of security to provide user authentication and data confidentiality. To provide such security features, a high security communication protocol for SMS, called Message Security Communication Protocol (MSCP) was proposed. In this paper, MSCP is formally analyzed using an automated logic-based verification tool with attack detection capabilities. The performed formal verification reveals that the proposed protocol is susceptible to parallel session and denial-of-service (DoS) attacks. The reasoning why these attacks are possible is detailed and an amended protocol is proposed to counter the identified attacks. Formal verification of the amended protocol provides confidence regarding the correctness and effectiveness of the proposed modifications. Anca Jurcut, Madhusanka Liyanage, Cornelia Györödi, Jingsha He |
WCNC | 2 |
| 2018 | Demo: A Delay-Tolerant Payment Scheme on the Ethereum BlockchainabstractCash-less payment via a variety of credit, debit or prepaid cards is pervasive in our interconnected society, but not so ubiquitous in remote rural regions where network connectivity is intermittent. We proposed a cash-less payment scheme for remote villages based on blockchains that allow maintaining a record of verifiable transactions in a distributed manner. We overcome the limitations of intermittent network connectivity by solely relying on blockchain mining nodes in the village for transaction processing and verification. The bank joins as a peer and monitors node behaviors, rewards miners and processes currency exchanges whenever the connectivity is available. We take advantage of the Ethereum network to develop our solution and demonstrate the feasibility of the proposed system on off-the-shelf computing devices. We emulate a remote village scenario with intermittent network connectivity and show the robustness and reliability of the proposed system. Ahsan Manzoor, Yining Hu 0001, Madhusanka Liyanage, Parinya Ekparinya, Kanchana Thilakarathna, Guillaume Jourjon, Aruna Seneviratne, Salil S. Kanhere, Mika Ylianttila |
WOWMOM | 3 |
| 2018 | DEMO: Mobile Relay Architecture for Low-Power IoT DevicesabstractInternet of Things (IoT) devices need pervasive and secure connections to transfer the aggregated data to the central servers located in remote clouds where the collected data further processed and stored. However, most low-power IoT devices cannot transmit the collected the data directly to such servers due the limited transmission power and range. Thus, third-party devices such as smart mobile phones are used as a relay to establish the communication link between IoT devices and the cloud server. This paper demonstrates a mobile-based relay assistance solution for secure end-to-end connectivity between low-power IoT sensors and cloud servers by using Bluetooth Low Energy (BLE) technology. The prototype implementation verifies the technical readiness of the proposed solution. Ahsan Manzoor, Pawani Porambage, Madhusanka Liyanage, Mika Ylianttila, Andrei V. Gurtov |
WOWMOM | 3 |
| 2018 | An efficient anonymous authentication protocol in multiple server communication networks (EAAM)
An Braeken, Pardeep Kumar 0001, Madhusanka Liyanage, Ta Thi Kim Hue |
J. Supercomput. | 3 |
| 2017 | Identity privacy preserving biometric based authentication scheme for Naked healthcare environmentabstractRecent developments in Internet of Things (IoT) technologies have already put a huge impact on the medical and health sector. Thus, the patient treatment can be performed in more efficient ways compared with traditional methods. Secure identification is a key system requirement for patients to acquire these health related services. Fast and convenient identification is important in the case of critical and elderly or disabled patients who required frequent health services. In this paper, we are presenting concept of the Naked environment where patients can get health services from smart and intelligent surroundings of hospital without using explicit gadgets. Patients would have direct interaction with the environment and get identified through it. We propose a biometric based authentication scheme for the Naked hospital environment that also protects the patients identity privacy. In addition, we show that this authentication scheme can resist various well known attacks such as insider attacks, replay attacks and identity privacy among others. Tanesh Kumar, An Braeken, Madhusanka Liyanage, Mika Ylianttila |
ICC | 3 |
| 2017 | SDN based operator assisted offloading platform for multi-controller 5G networksabstractThis paper presents an operator-assisted data offloading platform for 5G mobile networks by using Software Defined Networking (SDN). By enabling lateral communication between multiple SDN controllers, operators are able to perform the offloading process without the intervention of the user. Moreover, the offloading decision of proposed platform is based on accurate real time network conditions. The proposed mechanism is implemented on a testbed to verify feasibility and performance. Madhusanka Liyanage, Mahesh Dananjaya, Jude Okwuibe, Mika Ylianttila |
LANMAN | 1 |
| 2017 | Software Defined Monitoring (SDM) for 5G mobile backhaul networksabstractSoftware Defined Network (SDN) is an advanced approach to designing dynamic, manageable, cost-effective, and adaptable network architectures. SDN will play a key role as an enabler for 5G and future networks. Transferring network monitoring functions to a software entity working in conjunction with configurable hardware accelerators through a scheme called Software Defined Monitoring (SDM) is one promising way to attain the dynamism necessary for the monitoring of the next generation-networks. In this paper, we propose a novel SDM architecture for future mobile backhual networks. As an SDN solution, the proposed architecture provides more granular and dynamic network management functions through its programmable interface, centralized control, and virtualized abstractions. At the same time, the SDM framework intuitively seem prone to various challenges that come with the separation of the control and data planes of middleboxes. This paper collects specific opportunities, vulnerabilities as well as challenges related to SDM. It also highlights how SDM can be used to solve the current limitations in legacy monitoring systems. The feasibility of the proposed SDM architecture is verified by using a testbed implementation. Madhusanka Liyanage, Jude Okwuibe, Ijaz Ahmad 0001, Mika Ylianttila, Oscar Lopez Perez, Mikel Uriarte, Edgardo Montes de Oca |
LANMAN | 1 |
| 2017 | Software defined VPLS architectures: Opportunities and challengesabstractVirtual Private LAN Services (VPLS) is an Ethernet based VPN (Virtual Private Network) service which provides protocol independent and high speed multipoint-to-multipoint connectivity. In this article, we discuss the possibility to use emerging networks concepts such as Software Defined Networking (SDN) and Network Function Virtualization (NFV) to improve the performance, flexibility and adaptability of VPLS networks. SDN and NFV based VPLS (SoftVPLS) architectures offer new features such as centralized control, network programmability and abstraction to improve the performance, flexibility and automation of traffic, security and network management functions for future VPLS networks. Madhusanka Liyanage, Mika Ylianttila, Andrei V. Gurtov |
PIMRC | 1 |
| 2017 | Secure communication channel architecture for Software Defined Mobile Networks
Madhusanka Liyanage, An Braeken, Anca Jurcut, Mika Ylianttila, Andrei V. Gurtov |
Comput. Networks | 1 |
| 2016 | Improving the tunnel management performance of secure VPLS architectures with SDNabstractSecure VPLS (Virtual Private LAN Services) networks are becoming attractive in many Enterprise applications. However, the tunnel establishment mechanisms of legacy VPLS architectures are static, complex and inflexible in nature. As a result, secure VPLS architectures are suffering from limitations such as the limited scalability, over utilization of network resources, high tunnel establishment delay and high operational cost. In this article, we propose a novel SDN (Software Defined Networking) based VPLS (Virtual Private LAN Services) architecture to overcome tunnel management limitations in existing secure VPLS architectures. The proposed architecture utilizes IPsec enabled OpenFlow switches as PEs (Provider Edge Equipments) and OpenFlow protocol to install flow rules in PEs. A centralized controller is used to manage the tunnel establishment functions. We also propose a novel tunnel management mechanism which can estimate the tunnel duration based on real time session characteristics. Moreover, a novel tunnel resumption mechanism is proposed to reduce the tunnel establishment delay of subsequent tunnel establishments. Finally, the performance of proposed architecture is analyzed by using a simulation model and a testbed implementation. Madhusanka Liyanage, Mika Ylianttila, Andrei V. Gurtov |
CCNC | 1 |
| 2016 | Novel secure VPN architectures for LTE backhaul networksabstractIn this paper, we propose two secure virtual private network architectures for the long-term evolution backhaul network.They are layer 3 Internet protocol (IP) security virtual private network architectures based on Internet key exchange version 2 mobility and multihoming protocol and host identity protocol.Both architectures satisfy a complete set of 3GPP backhaul security requirements such as authentication, authorization, payload encryption, privacy protection, and IP-based attack prevention.The security analysis and simulation results verify that the proposed architectures are capable enough to protect long-term evolution backhaul traffic against various IP-based attacks. Madhusanka Liyanage, Pardeep Kumar 0001, Mika Ylianttila, Andrei V. Gurtov |
Secur. Commun. Networks | 1 |
| 2014 | A novel distributed spanning tree protocol for provider provisioned VPLS networksabstractSpanning Tree Protocol (STP) is a widely used protocol to maintain a loop free Layer 2 (L2) switching network. On the other hand, Virtual Private LAN Service (VPLS) is a L2 Virtual Private Network (VPN) service which is becoming very popular among many industrial enterprises. In a VPLS network, VPN connections through the provider network are invisible to L2 network devices and protocols. It causes to several issues while utilizing STP in a VPLS enabled Ethernet network. In this paper, we propose a novel Distributed STP (DSTP) to maintain a loop free Ethernet network over a VPLS network. DSTP proposes to run a modified STP instance in each remote network segment and evades the transportation of STP messages through the provider network. In addition, we propose two Redundancy Identification Mechanisms (RIMs) to mitigate the impact of invisible loops in the provider network. Simulation results verify that DSTP is capable of maintaining a loop free Ethernet network over a VPLS network. Furthermore, DSTP significantly reduces the convergence time of the spanning tree and STP overhead over the provider network. Madhusanka Liyanage, Mika Ylianttila, Andrei V. Gurtov |
ICC | 1 |
| 2014 | Access Point selection game for mobile wireless usersabstractSelecting a Access Point (AP) is an important task for a mobile wireless user to achieve the best possible quality of service. We consider AP selection as a game where players make choices selfishly and try to select the closest AP based on Minimum Path-Loss (MPL) criteria. We formulate the AP selection problem as a game where players are mobile wireless users and they choose radio APs to connect to the network. We define a new parameter called Access Point Selection Parameter (APSP) based on Signal to Interference plus Noise Ratio (SINR). Each selfish user chooses an AP which maximizes its APSP value. This APSP value depends on both the distance to AP and the total number of connected users in AP. Furthermore, we extend two players game to n-players game by adopting the KP (Koutsoupias-Papadimitriou) model of parallel links. The performance of the proposed game is illustrated by using simulations. Madhusanka Liyanage, Julia Chirkova, Andrei V. Gurtov |
WoWMoM | 1 |
| 2014 | Securing the control channel of software-defined mobile networksabstractSoftware-Defined Mobile Networks (SDMNs) are becoming popular as the next generation of telecommunication networks due to the enhanced performance, flexibility and scalability. In this paper, we study the new security challenges of the control channel of SDMNs and propose a novel secure control channel architecture based on Host Identity Protocol (HIP). IPsec tunneling and security gateways are widely used in today's mobile networks. The proposed architecture utilized these technologies to protect the control channel of SDMNs. We implement the proposed architecture in a testbed and analyze the security features. Moreover, we measure the performance penalty of security of proposed architecture and analyze its ability to protect the control channel from various IP (Internet Protocol) based attacks. Madhusanka Liyanage, Mika Ylianttila, Andrei V. Gurtov |
WoWMoM | 1 |
| 2014 | Securing virtual private LAN service by efficient key managementabstractVirtual private local area network service VPLS is a layer 2 service provider-provisioned virtual private network service. Security is one of the key system requirements of a VPLS because it delivers the frames via an untrusted network. Several VPLS architectures are proposed during the recent years. However, many of them do not provide a sufficient level of security. On the other hand, the existing secure VPLS architectures are also suffering from the scalability issues, and they are infeasible to implement in large scale networks. Madhusanka Liyanage, Andrei V. Gurtov |
Secur. Commun. Networks | 1 |
| 2013 | A scalable and secure VPLS architecture for provider provisioned networksabstractVirtual Private LAN Service (VPLS) is a Layer 2 Virtual Private Network (VPN) service. Internet Engineering Task Force (IETF) defined the essential system requirements of a VPLS network. Among them, Security is a key requirement as a VPLS delivers the customer data frames via untrusted public networks. However, the existing secure VPLS architectures are suffering from scalability issues and they are infeasible to implement in large scale networks. In this paper, we propose a novel VPLS architecture based on Host Identity Protocol (HIP). It includes a new session key based security mechanism which provides the scalability both in forwarding and security planes. Initial simulations verify that the proposed architecture reduces the key storage in a VPLS node, the total key storage in the network and the number of encryption per broadcast frame than other secure VPLS architectures. Additionally, our proposal provides an efficient broadcast mechanism and comparably higher degree of security features than other existing VPLS proposals. Madhusanka Liyanage, Andrei V. Gurtov |
WCNC | 1 |
| 2012 | Secured VPN Models for LTE Backhaul NetworksabstractThe Long Term Evolution (LTE) architecture proposes a flat all-IP backhaul network. 3rd Generation Partnership Project (3GPP) specified new security and traffic transport requirements of new LTE backhaul network. However, existing LTE backhaul traffic architectures are incapable of achieving these security requirements. In this paper, we propose two secured Virtual Private Network (VPN) architectures for LTE backhaul. Both architectures are layer 3 Internet Protocol security (IPsec) VPNs which are built using Internet Key exchange version 2 (IKEv2) and Host Identity Protocol (HIP). They are capable of fulfilling 3GPP security requirements such as user authentication, user authorization, payload encryption, privacy protection and IP based attack prevention. We study various IP based attacks on LTE backhaul and our proposed architectures can protect the backhaul network from them. Madhusanka Liyanage, Andrei V. Gurtov |
VTC Fall | 1 |