VLDB 2026 Research / reviewers in the wild / expert
Deok Kyu Kwon
dblp:286/0444 · also DeokKyu Kwon
· DBLP profile ↗
11ranked-venue papers
3as first author
11since 2021 · last 2026
0000-0003-0014-1965ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 7 · 7 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author · 3 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Ascon-Based Lightweight and Robust Authentication Scheme for IoT-Enabled Healthcare System
Hyeonjung Jang, Deok Kyu Kwon, Youngho Park 0005 |
IEEE Internet Things J. | 2 |
| 2026 | Robust and Lightweight User Authentication Scheme Using Deep Learning-Based Cancelable Biometrics in Smart Home Environments
Deok Kyu Kwon, Ashok Kumar Das, Youngho Park 0005 |
IEEE Internet Things J. | 2 |
| 2026 | Quantum-Resistant Three-Party Mutual Authentication Protocol for Industrial IoT EnvironmentsabstractThe Industrial Internet of Things (IIoT) integrates control systems with IoT technology to enable automation and intelligent operations in industrial environments. As IIoT deployments expand, reliance on wireless communication channels increases the attack surface and exposes systems to various security and privacy threats. Moreover, the limited computational capabilities of IIoT devices and the need to preserve device anonymity introduce additional security requirements. Insufficient protection against these challenges can result in operational disruption and significant economic losses. Existing symmetric-key and hash-based schemes are lightweight but lack scalability for large IIoT deployments, whereas public-key methods provide stronger security. However, the emergence of quantum computing threatens the long-term security of such protocols, as quantum algorithms can efficiently break conventional number-theoretic cryptosystems. To address these challenges, we propose a quantum-resistant three-party authentication and key agreement (AKA) protocol for the IIoT. The ring learning with errors (RLWE)-based protocol provides quantum-safe and efficient mutual authentication and secure session key establishment between workers and devices. Comprehensive security and performance analyses demonstrate that the proposed protocol is robust against security attacks. Performance evaluations confirm lower computational and communication overhead than existing post-quantum schemes, proving its practicality for IIoT. Chaeeon Kim, Deok Kyu Kwon, YoHan Park 0001, Youngho Park 0005 |
IEEE Internet Things J. | 2 |
| 2025 | PLAKA-MD: PUF-Based Lightweight Authentication and Key Agreement Scheme for Medical Devices in IoHTabstractInternet of Health Things (IoHT) integrates medical services and Internet of Things (IoT) to improve the accessibility of healthcare and accuracy of diagnosis. In IoHT environments, the transmission of sensitive data, such as patient medical records, physical characteristics, and genetic information, necessitates robust security mechanisms to protect privacy and ensure the integrity of real-time communication. Moreover, it is essential for healthcare professionals to have seamless access to patient data for accurate diagnoses. To address these demands, a lightweight and secure authentication protocol is critical for IoHT environments. Although some authentication protocols have been recently proposed in IoHT, they are susceptible to user insiders, privileged insiders, stolen verifiers, ephemeral key leakage, sensor insiders, physical attacks, and lack traceability. To overcome these vulnerabilities, we propose a mutual authentication protocol for IoHT environments. We design the proposed protocol as a lightweight using only hash functions and exclusive-OR operators. Furthermore, we utilized biometric information, physical unclonable functions (PUFs), and fuzzy extractors to strengthen security for both users and sensors. We validate the security robustness of the proposed protocol through formal analyses, including Automated Validation of Internet Security Protocols and Applications (AVISPAs), the Real-or-Random (RoR) model, and Burrows-Abadi-Needham (BAN) logic. Additionally, we evaluate the performance of the protocol by measuring the execution time of cryptographic primitives and comparing the computational and communication overheads with existing protocols. Results demonstrate that our protocol provides the most various kinds of security and functional features while maintaining similar efficiency than competing schemes. Changui Lee, Mingyu Oh, Deok Kyu Kwon, Youngho Park 0005, YoHan Park 0001 |
IEEE Internet Things J. | 3 |
| 2025 | A Secure IoT-Enabled Medical Data Sharing Scheme Using Blockchain-Assisted Private Set IntersectionabstractAdvances in Internet-of-Things (IoT) technology are enabling the sharing of electronic health records (EHR) via wireless channels. Because EHRs contain sensitive patient information, it is important to preserve data privacy along with medical data sharing. In this paper, we propose a secure medical data sharing scheme using blockchain-assisted private set intersection (PSI). Our approach ensures access control and data availability by having data users upload encrypted private set intersections to the blockchain. We also proposed a mutual authentication phase between the hospital and data user after calculating private set intersection. We thoroughly analyzed the proposed scheme using informal methods and proved security against semi-honest adversary model, correctness, and session key security using formal methods. We also implemented the proposed scheme in real environments using laptop and Raspberry PI 4 to prove the practicality of the proposed scheme. We compared the proposed mutual authentication scheme with existing methods and show that the proposed scheme is better than existing schemes. Seunghwan Son, Deok Kyu Kwon, YoHan Park 0001, Ashok Kumar Das, Youngho Park 0005 |
IEEE Internet Things J. | 2 |
| 2025 | An Efficient Handover Authentication Scheme for 6G-Enabled Space-Terrestrial Integrated Networks With Mobile Edge ComputingabstractSixth-generation (6G) services can offer unprecedented data speeds, ultra-low latency, and vast connectivity. Moreover, satellite communication has become crucial to achieving seamless global coverage for 6G networks. Space-terrestrial integrated networks (STIN) combine satellite and ground networks, ensuring continuous services via satellites even when outside terrestrial network coverage. However, existing STIN schemes rely on central ground server, which can potentially lead to bottlenecks and delays. Additionally, a lightweight handover is necessary to address frequent service changes due to the narrow communication ranges in 6G-based STIN environments. To address these challenges, we propose a novel authentication scheme to provide secure and high-speed handover process for STIN environments. The proposed scheme leverages mobile edge computing (MEC)-based low-Earth orbit (LEO) satellites to minimize communications with the central server. Moreover, a key feature of the proposed scheme is the structural separation of computational loads: we utilize elliptic curve cryptography (ECC) for robust initial authentication, and only hash functions and exclusive-OR (XOR) operators for high-speed handover process. To prove the security of our scheme,we perform informal analysis, “Burrows-Abadi-Needham (BAN) logic”, “Real-Or-Random (ROR) model“, “Automated Validation of Internet Security Protocols and Applications (AVISPA) simulation tool”, and “Scyther tool”. Furthermore, we conduct comparative study on security properties, computation, and communication costs of the proposed scheme and the existing related schemes. To verify the practical deployment of the proposed scheme, we perform a simulation study using “Network Simulator 3 (NS-3)”. Our results demonstrate that the proposed scheme can provide efficient and secure communications for MEC-based STIN environments. Deok Kyu Kwon, Seunghwan Son, Kisung Park 0002, Ashok Kumar Das, Youngho Park 0005 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | A PUF-Based Lightweight Authentication Scheme for UAV-Assisted Internet of VehiclesabstractUnmanned Aerial Vehicles (UAVs)-assisted Internet of Vehicles (IoV) utilizes flexible mobility of UAVs to improve communication issues in traditional IoV model. In UAV-assisted IoV, UAVs expand the communication coverage of roadside units (RSUs) and support the tasks of RSUs. Therefore, UAV-assisted IoV can contribute to the development of Intelligent Transportation System (ITS). However, an adversary can still attempt various attacks because UAV-assisted IoV networks perform wireless communication over open channels. In 2024, Miao et al. proposed an elliptic curve cryptography (ECC)-based authentication scheme for UAV-assisted IoV. Unfortunately, we discover that their scheme cannot prevent man-in-the-middle (MITM) and ephemeral secret leakage (ESL) attacks. Furthermore, Miao et al.’s scheme incurs high computational costs using ECC which is unfavorable for UAVs considering their computational restrictions. In this article, we propose a secure and lightweight authentication scheme for UAV-assisted IoV, considering the computational limitations of UAVs. We apply physical unclonable function (PUF) and fuzzy extractor to mutual authentication, developing the security level. Moreover, the proposed scheme uses only one-way hash functions and exclusive-or (XOR) operations which are compatible with UAVs. To prove the robustness of the proposed scheme, we perform “Burrows-Abadi-Needham (BAN) logic”“, Real-or-Random (RoR) model”, and “Automated Verification of Internet Security Protocols and Applications (AVISPA)” based formal security analysis, and informal analysis. Furthermore, we estimate the performance of the proposed scheme and compare with other relevant works, including computational costs, communication costs, energy consumption, security properties, and storage costs. Consequently, we establish that the proposed scheme is appropriate and efficient for UAV-assisted IoV. Jihye Choi, Deok Kyu Kwon, Seunghwan Son, YoHan Park 0001, Ashok Kumar Das, Youngho Park 0005 |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2024 | Blockchain-Enabled Key Aggregate Searchable Encryption Scheme for Personal Health Record Sharing With MultidelegationabstractThe transition from patient-centered medical services to Health 5.0, which provides medical services to all customers using smart healthcare, has led to the use of the Internet of Things (IoT) for medical diagnosis and research based on the personal health records (PHR) of service users. However, PHR contain sensitive personal information, which can cause privacy issues. Additionally, as emergencies may occur in real medical environments, multi-authority delegation must be considered. Although various methods are being studied for data sharing, they often do not meet the necessary security requirements in a real PHR sharing environment. In this study, we propose a system that uses key aggregate searchable encryption (KASE) to satisfy security requirements and leverages blockchain and smart contracts to improve data integrity, data audit records, and transparency. We also propose a method that ensures the data subject rights of PHR data owners when delegating multiple rights using attribute tokens. We conduct formal and informal security analyses to verify the robustness of the proposed system against potential adversarial attacks. Finally, a performance evaluation is conducted to verify the effectiveness of the proposed scheme. JoonYoung Lee, Ji-Hyeon Oh, Deok Kyu Kwon, MyeongHyun Kim, Keonwoo Kim 0003, Youngho Park 0005 |
IEEE Internet Things J. | 3 |
| 2024 | A Robust Covert Channel With Self-Bit Recovery for IEEE 802.11 NetworksabstractCovert channels are commonly perceived as potential attack vectors in wireless communication environments and are categorized into covert timing channels and covert storage channels based on their creation method. Although covert timing channels are generally difficult to detect, we identified their potential use as secure message carriers in wireless communication, particularly within the IEEE 802.11 environments. In this context, access points continuously broadcast packets to nearby devices. Our aim was to create a robust covert timing channel using these broadcast packets. However, IEEE 802.11 operates as a one-way communication channel, which prevents the covert receiver from confirming proper message reception. Moreover, in the event of incorrect reception, the receiver cannot send an ACK to the sender to avoid detection risk. This paper proposes a covert timing channel with a self-bit recovery function for consecutive two-bit losses. We validated the practicality of our proposed covert timing channel through simulations involving laptops and a Zynq board. Furthermore, we assessed the robustness of our covert channel and compared its performance with that of existing covert timing channels. The results indicate superior covertness, higher capacity, and transmission accuracy compared with existing covert timing channels. Notably, our study represents the first covert timing channel algorithm capable of recovering consecutive 2-bit losses. Seunghwan Son, Deok Kyu Kwon, Yongsung Jeon, Youngho Park 0005 |
IEEE Internet Things J. | 2 |
| 2024 | A Secure Self-Certified Broadcast Authentication Protocol for Intelligent Transportation Systems in UAV-Assisted Mobile Edge Computing EnvironmentsabstractUnmanned Aerial Vehicle(UAV)-assisted mobile edge computing(MEC) ensures continuous MEC services by promptly restoring overloaded or disabled MEC infrastructure. Equipped with sufficient computing resources, UAVs deploy to areas needing MEC, such as task offloading and entertainment services. However, in areas with paralyzed edge nodes, vehicle users are unable to verify the legitimacy of UAVs as they cannot access to the trusted authority(TA). Furthermore, the integrity of UAV-assisted MEC environments can be compromised by malicious attackers, as all network participants rely on wireless communication for their interactions. Many authentication schemes have been proposed for UAV environments. However, these schemes encounter a problem of having to communicate through TA for authentication with vehicle users, which makes them difficult to apply to UAV-assisted MEC environments. Therefore, we propose a new broadcast authentication protocol, which can recover MEC services using MEC-equipped UAVs. The proposed protocol can provide UAVs and vehicle users with high reliability via a self-certified public-key cryptosystem, which can verify the legitimacy of the communication partner without the TA. Moreover, we guarantee the user privacy and preserve sensitive information using biohash technology. We verify the security robustness of the proposed protocol using various simulation tool, informal, and formal analyses. We also estimate the practical deployment of the proposed protocol using “Network Simulator-3”. Moreover, we estimate the computation and communication overheads and compare with other existing protocols. The results show that the proposed protocol is feasible and provides users with convenient and seamless intelligent transportation services in UAV-assisted MEC environments. Deok Kyu Kwon, Seunghwan Son, MyeongHyun Kim, JoonYoung Lee, Ashok Kumar Das, Youngho Park 0005 |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2024 | Design of Blockchain-Based Multi-Domain Authentication Protocol for Secure EV Charging Services in V2G EnvironmentsabstractMulti-domain vehicle to grid (V2G) is a network environment in which numerous service providers offer charging and discharging services to EV users. This can enhance energy management and traffic flow for efficient intelligent transportation systems (ITS). However, the combination of multiple domains can suffer from various security vulnerabilities, highlighting the need for robust countermeasures. Moreover, existing multi-domain V2G protocols utilized a central trusted authority (TA) which can create a single point of failure (SPOF), or required high computational resources. In this paper, we propose a multi-domain authentication protocol for secure and efficient V2G services using consortium blockchain. The proposed protocol provides lightweight intra-domain authentication using hash functions and XOR operators. Furthermore, the proposed protocol ensures secure cross-domain authentication by integrating elliptic curve cryptography (ECC) and physical unclonable function (PUF). Therefore, the proposed protocol can establish trust, enable efficient communications, and prevent congestion at charging stations. To validate security robustness, comprehensive evaluations are conducted using “Real-Or-Random (ROR) model”, “Scyther tool”, and informal analyses. Comparative computational overheads of the proposed and related protocols are measured using “Multiprecision Integer and Rational Arithmetic Cryptographic Library (MIRACL)” testbed experiments. Additionally, a simulation of the practical deployment is conducted using “Network Simulator-3 (NS-3)”. Results indicate that the proposed protocol can improve ITS by providing secure and efficient services for multi-domain V2G environments. Deok Kyu Kwon, Seunghwan Son, Kisung Park 0002, Ashok Kumar Das, Youngho Park 0005 |
IEEE Trans. Intell. Transp. Syst. | 1 |