Abubakar Sadiq Sani

dblp:210/6080 · DBLP profile ↗
← Back
10ranked-venue papers
8as first author
4since 2021 · last 2023
0000-0001-8201-8770ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 3 first-author · 3 since 2021Systems, architecture and hardware · 3 · 2 first-authorComputer networks · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2023 Enhancing federated learning robustness in adversarial environment through clustering Non-IID features
abstract
Federated Learning (FL) enables many clients to train a joint model without sharing the raw data. While many byzantine-robust FL methods have been proposed, FL remains vulnerable to security attacks such as poisoning attacks and evasion attacks due to its distributed adversarial environment. Additionally, real-world training data used in FL are usually Non-Independent and Identically Distributed (Non-IID), which further weakens the robustness of the existing FL methods (such as Krum, Median, Trimmed-Mean, etc.), thereby making it possible for a global model in FL to be broken in extreme Non-IID scenarios. In this work, we mitigate the aforementioned weaknesses of existing FL methods in Non-IID and adversarial scenarios by proposing a new FL framework called Mini-Federated Learning (Mini-FL). Mini-FL follows the general FL approach but considers the Non-IID sources of FL and aggregates the gradients by groups. Specifically, Mini-FL first performs unsupervised learning for the gradients received to define the grouping policy. Then, the server divides the gradients received into different groups according to the grouping policy defined and performs byzantine-robust aggregation. Finally, the server calculates the weighted mean of gradients from each group to update the global model. Owning the strong generality, Mini-FL can utilize the most existing byzantine-robust method. We demonstrate that Mini-FL effectively enhances FL robustness and achieves greater global accuracy than existing FL methods when against security attacks and in Non-IID settings.
Dong Yuan 0001, Abubakar Sadiq Sani, Wei Bao 0001
Comput. Secur.3
2022 SPrivAD: A secure and privacy-preserving mutually dependent authentication and data access scheme for smart communities
Abubakar Sadiq Sani, Elisa Bertino, Dong Yuan 0001, Ke Meng 0001, Zhao Yang Dong
Comput. Secur.1
2021 Crypto-Chain: A Relay Resilience Framework for Smart Vehicles
abstract
Recent findings show that smart vehicles can be exposed to relay attacks resulting from weaknesses in cryptographic operations, such as authentication and key derivation, or poor implementation of these operations. Relay attacks refer to attacks in which authentication is evaded without needing to attack a smart vehicle itself. They are a recurrent problem in practice. In this paper, we formulate the necessary relay resilience settings for strengthening authentication and key derivation and achieving the secure design and efficient implementation of cryptographic protocols based on universal composability, which allows the modular design and analysis of cryptographic protocols. We introduce Crypto-Chain, a relay resilience framework that extends Kusters’s universal composition theorem on a fixed number of protocol systems to prevent bypass of cryptographic operations and avoid implementation errors. Our framework provides an ideal crypto-chain functionality that supports several cryptographic primitives. Furthermore, we provide an ideal functionality for mutual authentication and key derivation in Crypto-Chain by which cryptographic protocols can use cryptographic operations, knowledge about the computation time of the operations, and cryptographic timestamps to ensure relay resilience. As a proof of concept, we first propose and implement a mutual authentication and key derivation protocol (MKD) that confirms the efficiency and relay resilience capabilities of Crypto-Chain and then apply Crypto-Chain to fix two protocols used in smart vehicles, namely Megamos Crypto and Hitag-AES/Pro.
Abubakar Sadiq Sani, Dong Yuan 0001, Elisa Bertino, Zhao Yang Dong
ACSAC1
2021 A Universally Composable Key Exchange Protocol for Advanced Metering Infrastructure in the Energy Internet
abstract
The increasing adoption of multiway communications in the advanced metering infrastructure (AMI) of the energy Internet, which is known as the Internet-based smart grid, raises a new question about the security of customers' sensitive data and how the data can be protected from growing cyber attacks such as side-channel and false data injection attacks. The dynamic nature of remote connect/disconnect of components in the AMI also brings new types of security threats. To achieve secure multiway communications and remote connect/disconnect of components, the AMI requires a key exchange protocol (KEP) that meets a number of its security requirements such as confidentiality, integrity, availability, identification, authentication, and access control. In this context, in this article we present a KEP that uses an ideal crypto functionality and an ideal AMI key exchange functionality based on universal composability, which allows modular design and analysis of cryptographic protocols. The former functionality enables AMI components or users to perform authenticated cryptographic operations, while the later functionality enables the users to meet the AMI security requirements before generating a shared secret session key, which can be used in an ideal manner. We carry out experiments to validate the performance of our protocol, and the results show that our protocol offers better performance benefits compared to the existing related protocols and is suitable for the Energy Internet. We further demonstrate the usefulness of our ideal functionalities as a security reinforcement for a widely used KEP, namely the Elliptic Curve Diffie-Hellman.
Abubakar Sadiq Sani, Dong Yuan 0001, Wei Bao 0001, Zhao Yang Dong
IEEE Trans. Ind. Informatics1
2019 Xyreum: A High-Performance and Scalable Blockchain for IIoT Security and Privacy
abstract
As cyber attacks to Industrial Internet of Things (IIoT) remain a major challenge, blockchain has emerged as a promising technology for IIoT security due to its decentralization and immutability characteristics. Existing blockchain designs, however, introduce high computational complexity and latency challenges which are unsuitable for IIoT. This paper proposes Xyreum, a new high-performance and scalable blockchain for enhanced IIoT security and privacy. Xyreum uses a Time-based Zero-Knowledge Proof of Knowledge (T-ZKPK) with authenticated encryption to perform Mutual Multi-Factor Authentication (MMFA). T-ZKPK properties are also used to support Key Establishment (KE) for securing transactions. Our approach for reaching consensus, which is a blockchain group decision-making process, is based on lightweight cryptographic algorithms. We evaluate our scheme with respect to security, privacy, and performance, and the results show that, compared with existing relevant blockchain solutions, our scheme is secure, privacy-preserving, and achieves a significant decrease in computation complexity and latency performance with high scalability. Furthermore, we explain how to use our scheme to strengthen the security of the REMME protocol, a blockchain-based security protocol deployed in several application domains.
Abubakar Sadiq Sani, Dong Yuan 0001, Wei Bao 0001, Phee Lep Yeoh, Zhao Yang Dong, Branka Vucetic, Elisa Bertino
ICDCS1
2019 Cyber security framework for Internet of Things-based Energy Internet
Abubakar Sadiq Sani, Dong Yuan 0001, Jiong Jin, Longxiang Gao, Shui Yu 0001, Zhao Yang Dong
Future Gener. Comput. Syst.1
2019 A novel directional and non-local-convergent particle swarm optimization based workflow scheduling in cloud-edge environment
Ying Xie 0002, Yuanwei Zhu, Yeguo Wang, Yongliang Cheng, Rongbin Xu, Abubakar Sadiq Sani, Dong Yuan 0001, Yun Yang 0001
Future Gener. Comput. Syst.6
2019 Universally Composable Key Bootstrapping and Secure Communication Protocols for the Energy Internet
abstract
The Energy Internet is an advanced smart grid solution to increase energy efficiency by jointly operating multiple energy resources via the Internet. However, such an increasing integration of energy resources requires secure and efficient communication in the Energy Internet. To address such a requirement, we propose a new secure key bootstrapping protocol to support the integration and operation of energy resources. By using a universal composability model that provides a strong security notion for designing and analyzing cryptographic protocols, we define an ideal functionality that supports several cryptographic primitives used in this paper. Furthermore, we provide an ideal functionality for key bootstrapping and secure communication, which allows exchanged session keys to be used for secure communication in an ideal manner. We propose the first secure key bootstrapping protocol that enables a user to verify the identities of other users before key bootstrapping. We also present a secure communication protocol for unicast and multicast communications. The ideal functionalities help in the design and analysis of the proposed protocols. We perform some experiments to validate the performance of our protocols, and the results show that our protocols are superior to the existing related protocols and are suitable for the Energy Internet. As a proof of concept, we apply our functionalities to a practical key bootstrapping protocol, namely generic bootstrapping architecture.
Abubakar Sadiq Sani, Dong Yuan 0001, Wei Bao 0001, Zhao Yang Dong, Branka Vucetic, Elisa Bertino
IEEE Trans. Inf. Forensics Secur.1
2018 A Lightweight Security and Privacy-Enhancing Key Establishment for Internet of Things Applications
abstract
Recent findings show that many mission critical Internet of Things (IoT) applications are exposed to increasing security risks. The complex and dynamic nature of the IoT and its applications also bring new types of security threats. To achieve end-to-end secure communication, IoT applications need key establishment schemes with integrated security fundamentals such as identification and authentication of IoT components, as well as integrity, confidentiality, availability and authenticity of data, to prevent security attacks from weakening and disrupting the communication. In this context, we present a new lightweight key establishment scheme that comprises a novel Identity-Based Credentials (IBC) mechanism and key establishment protocol. The IBC mechanism enables an IoT component to securely disclose a single identity for security support and privacy enhancement for key establishment. In this paper, we model IoT application attributes to develop our lightweight security and privacy enhancing key establishment scheme. The formal verification and analysis show that, compared to the existing schemes, our proposed scheme is resilient against more types of security attacks, and incurs lower computational and communication costs in IoT applications.
Abubakar Sadiq Sani, Dong Yuan 0001, Phee Lep Yeoh, Wei Bao 0001, Shiping Chen 0001, Branka Vucetic
ICC1
2017 Towards secure energy internet communication scheme: An identity-based key bootstrapping protocol supporting unicast and multicast
abstract
It is expected that there are a variety of energy resources to be jointly operated by the power system in the future. Through jointly operating all types of energy resources via the Internet, Energy Internet is a promising solution to increase energy efficiency. However, the increasing integration of energy resources inevitably imposes challenges in secure communication in the Energy Internet. Resourceful and reliable communication with high Quality of Security Service (QoSS) are crucial to the success of information exchange in Energy Internet. In this light, we advocate a new identity-based key bootstrapping protocol to support energy resources integration and operation, and satisfy the increasing requirements in QoSS. The proposed scheme enables a component to verify the identities of other components and ensure the authenticity and integrity of messages for key bootstrapping, which supports an identity-based communication paradigm for unicast and multicast communication. A system model is defined, and the identity-based communication paradigm is applied to address communication security concerns in real-time. The security and performance analyses show that the proposed scheme is superior to existing schemes.
Abubakar Sadiq Sani, Dong Yuan 0001, Wei Bao 0001, Zhao Yang Dong
NCA1