VLDB 2026 Research / reviewers in the wild / expert
Akhtar Badshah
dblp:27/10662
· DBLP profile ↗
14ranked-venue papers
4as first author
14since 2021 · last 2026
0000-0001-7867-2657ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 7 · 7 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 first-author · 3 since 2021Security and privacy · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SELAP: A security-enhanced lightweight authentication protocol for UAV-assisted VANETs in emergency scenarios
Xin Ai 0009, Akhtar Badshah, Shanshan Tu, Hisham Alfuhaid, Muhammad Waqas 0001, Zahid Halim |
Comput. Networks | 3 |
| 2026 | A Lightweight Heterogeneous Signcryption Scheme Seamlessly Compatible for Multi-Infrastructure IoT EnvironmentsabstractThe Internet of Things (IoT) interconnects vast numbers of sensors and devices that operate under different cryptographic infrastructures, making secure cross-domain communication essential. Most existing signcryption schemes are designed for a single infrastructure or, at best, two fixed ones, which limits applicability in heterogeneous and evolving IoT deployments. To address this need, we introduce LH3SC, a seamless elliptic-curve heterogeneous signcryption scheme that supports three infrastructures: certificateless cryptography, public key infrastructure, and identity-based cryptography, with a CLC sender. LH3SC enables devices across these domains to communicate securely without major architectural changes. The security analysis establishes IND-CCA2 confidentiality and EUF-CMA unforgeability, and the performance evaluation demonstrates lower computation and communication costs than representative schemes. These properties make LH3SC suitable for resource-constrained IoT settings, including healthcare automation, smart grids, and other distributed systems that require seamless cross-domain security. Nimra Bari, Ghulam Abbas 0002, Abdul Waheed 0003, Akhtar Badshah, Ziaul Haq Abbas, Muhammad Waqas 0001 |
IEEE Internet Things J. | 4 |
| 2026 | Desynchronization-Resistant Anonymous Authentication Protocol for RFID Systems Utilizing Physically Unclonable FunctionsabstractRadio frequency identification (RFID) systems are an indispensable part of many critical Internet of Things (IoT) applications, including supply chain management and access control. Ensuring strong security in these systems is critical to safeguarding sensitive information and protecting user privacy. In recent years, in order to meet the diversified security needs of RFID systems, authentication and key protocols based on physical unclonable functions (PUFs) have received wide attention. Nevertheless, existing protocols typically require RFID tags to pre-store an excessive number of secret credentials and impose considerable computational and communication overheads, which prove challenging for resource-constrained RFID tag. Additionally, certain lightweight protocols fall short of achieving their intended security and functional objectives, exhibiting insufficient anonymity and untraceability, and vulnerability to desynchronization attacks. To address these critical challenges, this paper first proposes a lightweight anonymous authentication and key agreement protocol designed for an ideal PUF environment. The proposed protocol integrates the arbiter PUF with cryptographic hash functions, providing robust resistance to potential attacks while minimizing system overhead. Subsequently, an enhanced protocol specifically tailored for noisy PUF scenarios is presented. This protocol employs a fuzzy extractor to reliably derive stable keys from noisy PUF responses, thereby mitigating the instability caused by inherent noise. Through comprehensive security analysis and formal verification, as well as performance evaluations compared with existing state-of-the-art protocols, both protocols are demonstrated to overcome the limitations of prior protocols and provide efficient and practically feasible solutions well suited for resource-constrained RFID environments. Fazal Muhammad, Akhtar Badshah, Xin Ai 0009, Muhammad Waqas 0001, Jalal Khan, Athanasios V. Vasilakos, Houbing Song |
IEEE Internet Things J. | 2 |
| 2026 | Comments on "LAS-SG: An Elliptic Curve-Based Lightweight Authentication Scheme for Smart Grid Environments"abstractLightweight authentication is essential for resource-constrained devices in smart grids. Recently, Chaudhry et al. (2023) proposed an elliptic curve cryptography-based lightweight authentication scheme for smart grids (LAS-SG), claiming to ensure both security and efficiency. This comment presents a detailed cryptographic analysis of LAS-SG and identifies a critical inconsistency in its design, namely, a misinterpretation between scalars and elliptic curve points. This nonstandard formulation compromises the protocol's correctness and undermines its claimed security guarantees. To address these issues, a corrected version of LAS-SG is proposed, rectifying the identified flaws while preserving the original goals of efficiency and mutual authentication. Akhtar Badshah |
IEEE Trans. Ind. Informatics | 1 |
| 2026 | SUAD: A Secure Attribute-Based Data Sharing Framework with User-Controlled Key Management for Cloud-Assisted IoTabstractCloud computing supports the Internet of Things (IoT) in handling diverse and large-scale data. However, outsourcing data control to the cloud raises security concerns, particularly in key management. Although Ciphertext-Policy Attribute-Based Encryption (CP-ABE) preserves data confidentiality, it entrusts key management to a centralized attribute authority, resulting in the key escrow problem. Furthermore, existing CP-ABE schemes lack mechanisms for key verification and identity authentication, leaving IoT systems susceptible to key errors and impersonation attacks. To overcome these limitations, we propose Secure and User-autonomous Attribute-based Data Sharing (SUAD) for cloud-assisted IoT. The SUAD scheme transfers key management from the authority to data users themselves, thereby eliminating key escrow. Built on a data user-centric architecture, the SUAD scheme removes the decryption privilege of the attribute authority. To prevent key forgeries and operational errors, we design a correctness verification mechanism covering five critical keys and the decryption result, along with a two-way interactive authentication protocol based on the Schnorr scheme for reliable identity verification. The SUAD scheme further supports dynamic user management, enabling user logout, replacement, and joining while optimizing maintenance overhead through periodic updates. We formally prove that SUAD achieves selective IND-CCA security in the random oracle model. Both theoretical analysis and experimental evaluations demonstrate that SUAD enhances user autonomy and strengthens security without incurring additional encryption or decryption costs, confirming its practicality for IoT deployments. Bei Gong, Akhtar Badshah, Xin Ai 0009, Hisham Alasmary, Muhammad Waqas 0001, Muhammad Taimoor Khan 0001 |
ACM Trans. Priv. Secur. | 3 |
| 2025 | Lightweight and Robust Key Agreement for Securing IIoT-Driven Flexible Manufacturing SystemsabstractThe ever-evolving Internet of Things (IoT) has ushered in a new era of intelligent manufacturing across multiple industries. However, the security and privacy of real-time data transmitted over the public channel of the Industrial IoT (IIoT) remain formidable challenges. Existing lightweight protocols often omit one or more critical security features, such as anonymity and untraceability, and are susceptible to threats like desynchronization attacks. Additionally, they struggle to achieve an optimal balance between robust security and performance efficiency. To bridge these gaps, we introduce a new lightweight key agreement security scheme that guarantees secure access to the IIoT-enabled flexible manufacturing system (FMS). The strength of our scheme lies in its utilization of the authenticated encryption with associative data (AEAD) primitive, AEGIS, along with hash functions and physical unclonable functions, which secure the IIoT ecosystem. Additionally, our scheme offers flexibility in the form of the addition of new machines, password updates, and revocation in cases of theft or loss. A comprehensive security analysis demonstrates the efficacy of the proposed scheme in thwarting various attacks. The formal analysis, based on the Real-or-Random (RoR) model, ensures session key indistinguishability, while the informal analysis highlights its resilience against known attacks. The comparative assessment demonstrates that the proposed scheme consistently outperforms the benchmark schemes across multiple dimensions, including security and functionality features, computational and communication overheads, and runtime efficiency. Specifically, the proposed scheme achieves peak performance enhancements of 77.55%, 44.73%, and 69.6% in computational overhead, runtime overhead, and communication overhead, respectively, underscoring its substantial performance advantages. Muhammad Hammad 0006, Akhtar Badshah, Mohammed Almeer, Muhammad Waqas 0001, Houbing Song, Sheng Chen 0001, Zhu Han 0001 |
IEEE Internet Things J. | 2 |
| 2025 | Privacy-Preserving and Traceable Certificateless Anonymous Mutual Authentication Scheme for IoTabstractBy utilizing the sensing and perception capabilities of various devices, the Internet of Things (IoT) enables more precise awareness of the real world, thereby enhancing management and resource utilization efficiency. However, due to their open deployment environments and frequent message exchanges, IoT endpoints are highly vulnerable to a wide range of security threats and privacy breaches, including forgery, data theft, and information leakage. Therefore, to address these challenges and ensure device legitimacy verification and secure data exchange among IoT devices, we propose a privacy-preserving and traceable certificateless anonymous mutual authentication scheme (PPT-CLAMA). PPT-CLAMA not only eliminates the need for a secure channel during key generation but also prevents attackers from tracing the real identity of devices through their own identity or public keys while providing pseudonym and anonymous authentication to devices, demonstrating greater practicality. Furthermore, through security proofs and analysis, PPT-CLAMA satisfies various high-level security properties, including mutual authentication, key agreement, nonrepudiation, unlinkability, perfect forward secrecy, known session-specific temporary information security, traceability, anonymity, and privacy preservation. The simulation results indicate that, compared to authentication and key agreement schemes, PPT-CLAMA reduces the average computational overhead and average communication overhead during the authentication process by 6.73% and 3.31%, respectively, demonstrating higher computational and communication efficiency. Bei Gong, Akhtar Badshah, Muhammad Waqas 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | An Improved Ultra-Lightweight Anonymous Authenticated Key Agreement Protocol for Wearable DevicesabstractFor wearable devices with constrained computational resources, it is typically required to offload processing tasks to more capable servers. However, this practice introduces vulnerabilities to data confidentiality and integrity due to potential malicious network attacks, unreliable servers, and insecure communication channels. A robust mechanism that ensures anonymous authentication and key agreement is therefore imperative for safeguarding the authenticity of computing entities and securing data during transmission. Recently, Guoet al.proposed an anonymous authentication key agreement and group proof protocol specifically designed for wearable devices. This protocol, benefiting from the strengths of previous research, is designed to thwart a variety of cyber threats. However, inaccuracies in their protocol lead to issues with authenticity verification, ultimately preventing the establishment of secure session keys between communication entities. To address these design flaws, an improved ultra-lightweight protocol was proposed, employing cryptographic hash functions to ensure authentication and privacy during data transmission in wearable devices. Supported by rigorous security validations and analyses, the proposed protocol significantly boosts both security and efficiency, marking a substantial advancement over prior methodologies. Xin Ai 0009, Akhtar Badshah, Shanshan Tu, Muhammad Waqas 0001, Iftekhar Ahmad |
IEEE Trans. Mob. Comput. | 2 |
| 2025 | A Security-Enhanced Ultra-Lightweight and Anonymous User Authentication Protocol for Telehealthcare Information SystemsabstractThe surge in smartphone and wearable device usage has propelled the advancement of the Internet of Things (IoT) applications. Among these, e-healthcare stands out as a fundamental service, enabling the remote access and storage of patient-related data on a centralized medical server (MS), and facilitating connections between authorized individuals such as doctors, patients, and nurses over the public Internet. However, the inherent vulnerability of the public Internet to diverse security threats underscores the critical need for a robust and secure user authentication protocol to safeguard these essential services. This research presents a novel, resource-efficient user authentication protocol specifically designed for healthcare systems. Our proposed protocol leverages the lightweight authenticated encryption with associated data (AEAD) primitive Ascon combined with hash functions and XoR, specifically tailored for encrypted communication in resource-constrained IoT devices, emphasizing resource efficiency. Additionally, the proposed protocol establishes secure session keys between users and MS, facilitating future encrypted communications and preventing unauthorized attackers from illegally obtaining users' private data. Furthermore, comprehensive security validation, including informal security analyses, demonstrates the protocol's resilience against a spectrum of security threats. Extensive analysis reveals that our proposed protocol significantly reduces computational and communication resource requirements during the authentication phase in comparison to similar authentication protocols, underscoring its efficiency and suitability for deployment in healthcare systems. Dake Zeng, Akhtar Badshah, Shanshan Tu, Muhammad Waqas 0001, Zhu Han 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2024 | Blockchain-Assisted Lightweight Authenticated Key Agreement Security Framework for Smart Vehicles-Enabled Intelligent Transportation SystemabstractIntelligent Transportation Systems (ITS) supported by smart vehicles have revolutionized modern transportation, offering a wide range of applications and services, such as electronic toll collection, collision avoidance alarms, real-time parking management, and traffic planning. However, the open communication channels among various entities, including smart vehicles, roadside infrastructure, and fleet management systems, introduce security and privacy vulnerabilities. To address these concerns, we propose a novel security framework, named blockchain-assisted lightweight authenticated key agreement security framework for smart vehicles-enabled ITS (BASF-ITS), which ensures data protection both during transit and while stored on cloud servers. BASF-ITS employs a combination of efficient cryptographic primitives, including hash functions, XOR operator, ASCON, elliptic curve cryptography, and physical unclonable functions (PUF), to design authenticated key agreement schemes. The inclusion of PUF significantly enhances the system’s resistance to physical attacks, preventing tampering attempts. To ensure data integrity when stored on the cloud, our framework incorporates blockchain technology. By leveraging the immutability and decentralization of the blockchain, BASF-ITS effectively safeguards data at rest, providing an additional layer of security. We rigorously analyze the security of BASF-ITS and demonstrate its strong resistance against potential security ass aults, making it a robust and reliable solution for smart vehicle-enabled ITS. In a comparative analysis with contemporary competing schemes, BASF-ITS emerges as a promising approach, offering superior functionality traits, enhanced security features, and reduced computation, communication, and storage costs. Furthermore, we present a practical implementation of BASF-ITS using blockchain technology, showcasing the computational time versus the “transactions per block” and the “number of mined blocks”, confirming its efficiency and viability in real-world scenarios.Note to Practitioners—This article is motivated by designing an efficient, lightweight, and anonymous blockchain-enabled authenticated security framework that can fix the security and privacy concerns in insecure environments for ITS applications, such as automated road speed enforcement, collision avoidance alarm systems, and traffic planning and management, etc. Authenticated key agreement schemes are extensively used to secure communications in the ITS environment. However, the existing state-of-the-art schemes are not efficient in terms of performance, are not resilient against potential security attacks, and do not support anonymity, untraceability, and unlinkability. Therefore, we propose the authenticated security framework to secure communication among the participating entities in the ITS environment. It utilizes efficient cryptographic primitives, such as hash function, XOR-operator, ASCON, elliptic curve cryptography, and PUF. It is shown that the proposed framework can be deployed as a robust tool to address the ITS security problems efficiently. Moreover, the proposed framework is lightweight and efficient and can be easily deployed in various ITS applications and other resource-constrained environments. However, the participating entities, such as vehicles and roadside units, must be PUF-enabled to deploy the proposed framework. Akhtar Badshah, Ghulam Abbas 0002, Muhammad Waqas 0001, Fazal Muhammad, Ziaul Haq Abbas, Muhammad Bilal 0003, Houbing Song |
IEEE Trans Autom. Sci. Eng. | 1 |
| 2024 | EAKE-WC: Efficient and Anonymous Authenticated Key Exchange Scheme for Wearable ComputingabstractWearable computing has shown tremendous potential to revolutionize and uplift the standard of our lives. However, researchers and field experts have often noted several privacy and security vulnerabilities in the field of wearable computing. In order to tackle these problems, various schemes have been proposed in the literature to improve the efficiency of authentication and key establishment procedure. However, the existing schemes have relatively high computation and communication overheads and are not resilient to various potential security attacks, which reduces their significance for applicability in constrained wearable devices. In this work, we propose an efficient and anonymous authenticated key exchange scheme for wearable computing (EAKE-WC), which performs mutual authentication between the user and the wearable device, and between the cloud server and the user. It also establishes secret session keys for each session to secure communication among the communicating entities. Additionally, the proposed EAKE-WC scheme is designed using authenticated encryption with associated data (AEAD) primitives like ASCON, bitwise XOR, and hash functions. Our results from the security analysis depict compliance of the proposed EAKE-WC with wearable computing's security criteria. In addition, we also demonstrate through a comprehensive comparative analysis that the proposed scheme, EAKE-WC, outperforms the existing benchmark schemes in various key performance areas, including lower communication and computational overheads, enhanced security, and added functionality. Shanshan Tu, Akhtar Badshah, Hisham Alasmary, Muhammad Waqas 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2023 | AAKE-BIVT: Anonymous Authenticated Key Exchange Scheme for Blockchain-Enabled Internet of Vehicles in Smart TransportationabstractThe next-generation Internet of vehicles (IoVs) seamlessly connects humans, vehicles, roadside units (RSUs), and service platforms, to improve road safety, enhance transit efficiency, and deliver comfort while conserving the environment. Currently, numerous entities communicate in the IoVs environment via insecure public channels that are susceptible to a variety of security assaults and threats. To address these security challenges, we design an anonymous authenticated key exchange mechanism for the IoVs in smart transportation supported by blockchain, referred to as AAKE-BIVT. AAKE-BIVT securely transmits traffic information to a cluster head, before heading to a nearby RSU utilizing the established secret session keys via mutual authentication and key agreement. A cloud server (CS) then securely aggregates data from related RSUs and generates transactions. The CS combines the transactions into blocks in a peer-to-peer network of CSs, and the blocks are confirmed and added to the blockchain via a voting-based consensus method. By means of rigorous informal security studies and formal security analysis through the random oracle model, we reveal that the proposed AAKE-BIVT is resistant to a broad range of potential security assaults in the IoVs environment. Furthermore, a comparative study reveals that AAKE-BIVT outperforms existing state-of-the-art techniques, in terms of security and functionality while being more efficient in terms of communication and computation. Additionally, the blockchain simulation validates the implementation viability of our proposed AAKE-BIVT. Akhtar Badshah, Muhammad Waqas 0001, Fazal Muhammad, Ghulam Abbas 0002, Ziaul Haq Abbas, Shehzad Ashraf Chaudhry, Sheng Chen 0001 |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2023 | Network Intrusion Detection System (NIDS) Based on Pseudo-Siamese Stacked Autoencoders in Fog ComputingabstractThe proliferation of Internet of Things (IoT) devices in the 5G era has resulted in increased security vulnerabilities and zero-day attacks, underscoring the importance of network intrusion detection systems (NIDS). However, existing NIDS have limitations in terms of accuracy, recall rates, false alarm rates, and generalization capabilities, and they cannot meet the IoT's requirements for low latency and limited computing resources. To overcome these challenges, we propose a NIDS based on a pseudo-siamese stacked autoencoder (PSSAE), deployed in the fog computing layer. Our system uses unsupervised training of stacked autoencoders (SAEs) to extract deep semantic features of normal and abnormal traffic, followed by supervised learning with labels to improve characterization and classification capabilities. The results show that our proposed method's accuracy and detection rate (DR) is 2% to 15% and 1%–14% higher than the existing techniques using the KDDTest+ dataset, respectively. Our proposed method outperformed the existing methods by 1% to 4% using the KDDTest+ dataset. The F1-Score is higher by 3%–11.55% using the KDDTest+ dataset. On the other hand, using the KDDTest-21 dataset, the accuracy of our proposed method also outperformed the existing technique by 6.09%–13.81%. The DR and F1-Score are higher by 7.02% and 5.57%, respectively, using the KDDTest+ dataset. This is due to the fact that each layer of the network trained by SAEs is more capable of extracting the semantic features of the data than the DNN-trained network directly. Shanshan Tu, Muhammad Waqas 0001, Akhtar Badshah, Mingxi Yin, Ghulam Abbas 0002 |
IEEE Trans. Serv. Comput. | 3 |
| 2022 | Enhancing Security in The Internet of Things Ecosystem using Reinforcement Learning and BlockchainabstractInternet of Things (IoT) is a promising technology that attains significant consideration in diverse industrial areas, i.e., agriculture, engineering, logistics, trading, ecological examining, security surveillance, energy, and healthcare. IoT gains much more attention with the rapid advancement of wireless communication and sensor networks as millions of intelligent devices get involved in IoT. These intelligent devices' raw data must be captured and processed to support decision-making. However, IoT applications trust the central server for information storage, processing, and mediators for wireless transmission. Consequently, it can leak the information and lead to high costs and delays. Hence, data security is the leading interest for the IoT. Blockchain technology can be deployed to overcome the security and effectiveness of the gigantic data in IoT. Blockchain is studied as a key to permitting storing, processing and sharing of data in an efficient, secure manner. In addition, reinforcement learning can convene the high data rate requirements. It will help us to optimize the performance of the blockchain-enabled IoT framework. Akhtar Badshah, Muhammad Waqas 0001, Shanshan Tu, Ghulam Abbas 0002 |
IWCMC | 1 |