Shalitha Wijethilaka

dblp:287/6995 · DBLP profile ↗
← Back
8ranked-venue papers
6as first author
8since 2021 · last 2025
0000-0002-7605-7789ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 4 · 3 first-author · 4 since 2021Systems, architecture and hardware · 1 · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Blockchain-Based Cross-Operator Network Slice Authentication Protocol for 5G Communication
abstract
Network slicing enables the facilitation of diverse network requirements of different applications over a single physical network. Due to concepts such as Local 5G Operators (L5GOs), Mobile Virtual Network Operators (MVNOs), and high-frequency utilization of 5G and beyond networks, users need to switch frequently among different network slices as well as different operators than the traditional networks. Even though a couple of researches have been conducted on cross-network slice authentication, cross-operator network slice authentication is still an indeterminate research area. Also, the proposed cross-network slice authentication frameworks possess several limitations, such as vulnerability to severe attacks, high cost, the central point of failure, and the inability to support cross-operator network slice authentication. Therefore, in this research, we develop a blockchain-based cross-network slicing, cross-operator network slice authentication framework. Our framework supports the authentication for different network slices in the same operator as well as in different operators. The security properties of the proposed protocols are validated from formal (using Real-Or-Random logic, Scyther, and AVISPA validation tool) and informal security validation. The comparative analysis is conducted for known and unknown attacks to demonstrate its efficacy in terms of communication, computational, storage, and energy consumption costs. Also, a sample prototype of the protocols is implemented along with the state-of-the-art protocols to evaluate the performance of our framework.
Awaneesh Kumar Yadav, Shalitha Wijethilaka, Madhusanka Liyanage
IEEE Trans. Netw. Serv. Manag.2
2024 Privacy-Preserving Federated Learning Framework for Open Radio Access Networks (ORAN)
abstract
Open Radio Access Network (ORAN) is considered the next-generation RAN, which enables several features such as network flexibility, interoperability, and cost efficiency. Leveraging Artificial Intelligence (AI) and Machine Learning (ML) techniques has become commonplace in ORAN applications. The modularized nature of the ORAN architecture and the limitations in traditional ML approaches intensify the requirement of Federated Learning (FL) for training ML models in ORAN environments. However, in multi-BS environments, the conventional plaintext model update sharing of FL is vulnerable to privacy breaches like inference and deep-leakage gradient attacks. Hence, our proposition introduces an innovative blockchain-based framework to conduct FL securely and protect privacy with the support of the Open Radio Access Network (ORAN). Our approach builds upon the traditional masking method for sharing model parameters and enhances it with novel features. These features include individual validation for BSs, the selection of distributed aggregators, and validation for final model aggregation. Our scheme facilitates the sharing of sensitive data among multiple BSs while bolstering privacy and adding security layers without compromising performance metrics. To assess the efficacy of our proposal, we implement the framework atop a Hyperledger Fabric blockchain. Furthermore, comprehensive formal and informal security analyses are conducted to demonstrate the robust and privacy-preserving nature.
Shalitha Wijethilaka, Awaneesh Kumar Yadav, An Braeken, Madhusanka Liyanage
GLOBECOM1
2024 Blockchain-Based Secure Authentication and Authorization Framework for Robust 5G Network Slicing
abstract
The rapid evolution of heterogeneous applications signifies the requirement for network slicing to cater to diverse network requirements. Network Functions (NFs), which are the essential elements of network slices, are required to communicate with each other securely to facilitate network services. Certificates are the established method to authenticate each other. However, dynamic certificate management while allowing NFs to communicate in a multi-operator environment is arduous. Also, sharing NFs between network slices originates authorization-related security challenges such as unauthorized service utilization, deceptive Denial of Service attacks, and data leakages from network slices. In this paper, we develop a novel framework to address the security challenges related to authentication and authorization in 5G network slicing systems. A blockchain-based multi-party distributed certificate management framework with secure communication protocols is developed using elliptic curve cryptography to facilitate certificate services for multi-operator environments. Also, we propose a blockchain-based NF authorization framework to mitigate the security vulnerabilities in NF sharing between network slices. We implement the proposed framework using Hyperledger Fabric blockchain with Java chain codes and perform comprehensive experiments to show the significance of our framework.The Ability to mitigate the single point of failure with respect to state-of-the-art, including traditional certificate authorities and blockchain-based certificate authorities, time analysis for certificate generation, and the potential to eliminate the mentioned authorization attacks are some of the experiments conducted.Also, we have shown that our framework is secure using informal and formal (using Real-Or-Random (ROR) logic and Scyther Validation tool) security verification mechanisms.
Shalitha Wijethilaka, Awaneesh Kumar Yadav, An Braeken, Madhusanka Liyanage
IEEE Trans. Netw. Serv. Manag.1
2023 A Novel Blockchain-based Decentralized Multi-party Certificate Management Framework
abstract
Digital certificates play a significant role in the current communication systems. However, with the limitations in the existing Certificate Management Frameworks (CMFs), such as single point of failure, the profound nature of existing certificates, and malicious Certificate Authorities (CAs), a novel framework is required to optimize certificate management. Even though blockchain is a popular approach in designing CMFs, they also failed to address all these limitations. There are no existing frameworks that distribute the functionality of the centralized CA to address these issues. Therefore, this paper proposes a blockchain-based, lightweight CMF while distributing the centralized certificate generation process among multiple parties. Certificate generation, validation, and revocation can be performed with our framework. We design the required secure communication protocols to deploy our framework in any blockchain. The proposed framework is implemented on top of a Hyperledger Fabric environment and performed a set of experiments to evaluate the performance of the framework. Also, a formal security analysis for the proposed communication protocols is provided using known security verification methods such as BAN logic and the Scyther tool.
Shalitha Wijethilaka, Awaneesh Kumar Yadav, An Braeken, Madhusanka Liyanage
TrustCom1
2023 An Enhanced Cross-Network-Slice Authentication Protocol for 5G
abstract
Network slicing is considered one of the key technologies in future telecommunication networks as it can split the physical network into a number of logical networks tailored to diverse purposes that allow users to access various services speedily. The fifth-generation (5G) mobile network can support a variety of applications by using network slicing. However, security (especially authentication) is a significant issue when users access the network slice-based services. Various authentication schemes are designed to secure access, and only a few offer cross-network slice authentication. The security analysis of existing cross-network authentication schemes shows they are vulnerable to several attacks such as device stolen, ephemeral secret leakage, violation of perfect forward secrecy, identity theft. Therefore, we propose an authentication mechanism that offers cross-network slice authentication and prevents all the aforementioned vulnerabilities. The security verification of the authentication mechanism is carried out informally and formally (ROR logic and Scyther tool) to ensure that it handles all the vulnerabilities. The comparison of empirical evaluation shows that the proposed scheme is least costly than its competitors. Java-based implementations of the proposed protocols imitate a real environment, showing that our proposed protocol maintains almost the same performance as state-of-the-art solutions while providing additional security features.
Awaneesh Kumar Yadav, Shalitha Wijethilaka, An Braeken, Manoj Misra, Madhusanka Liyanage
IEEE Trans. Sustain. Comput.2
2022 A Comprehensive Analysis on Network Slicing for Smart Hospital Applications
abstract
Network slicing (NS) is technology that enables emerging smart applications and use cases in Fifth Generation (5G) and beyond networks. One such application is smart hospitals, which has diverse network requirements for applications ranging from Augmented Reality (AR) and robot assisted surgeries to connecting large numbers of medical wearables and sensors. NS can be performed in smart hospitals under different strategies based on dynamicity, ownership, and application. This paper investigates how these strategies can be utilized in different smart hospital applications. The performance of each slicing strategy in a hospital network is analyzed under three matrices: bandwidth utilization, handover count, and block count.
Shalitha Wijethilaka, Pawani Porambage, Chamitha de Alwis, Madhusanka Liyanage
CCNC1
2022 A Federated Learning Approach for Improving Security in Network Slicing
abstract
Network Slicing (NS) is a predominant technology in future telecommunication networks, including Fifth Generation (5G), which supports the realization of heterogeneous applications and services. It allows the allocation of a dedicated logical network slice of the physical network to each application. Security is one of the paramount challenges in an NS ecosystem. Several technologies, including Machine Learning (ML), have been proposed to mitigate security challenges in 5G networks. However, the use of ML for NS security is not properly implemented. Especially, the scarcity of coordination and the difficulties of privacy-protected information sharing between slices cause failures and performance degradation of these ML based NS security solutions. To address this issue, this paper proposes a novel Federated Learning (FL) based coordinated security orchestration architecture named Federated Learning enabled Security Orchestrator (FLeSO) to centrally perform security operations in a slicing ecosystem while preserving the privacy of the data. In addition, the proposed FLeSO architecture enables features such as proactive security deployment and steady security level maintenance independent of the slicing strategy. The proposed architecture is implemented in a real-world slicing testbed, and a comprehensive set of experiments are performed to evaluate the effectiveness of the proposed FLeSO architecture. The test results illustrate the significant advantage of the proposed approach over the legacy system in terms of improving the security of an NS ecosystem.
Shalitha Wijethilaka, Madhusanka Liyanage
GLOBECOM1
2021 Realizing Internet of Things with Network Slicing: Opportunities and Challenges
abstract
Internet of Things (IoT) is a lucrative technology within the modern community that realizes the concept of the smart world, by expanding within a myriad of applications. Existing wireless networks require a radical change to fulfill the network requirements and cater the rapid expansion of the IoT ecosystem. 5G architecture is specifically designed to facilitate this demand. Network slicing is a pivotal technology in 5G architecture that has the ability to divide the physical network into multiple logical networks with specific network characteristics. In this paper, we are going to analyze how network slicing can be helpful in the IoT realization. Technical aspects that are required in the IoT realization, and the slicing based solutions which address these aspects, will be discussed here. Moreover, technical challenges that can arise due to network slicing integration in IoT ecosystem, will also be discussed with the potential solutions.
Shalitha Wijethilaka, Madhusanka Liyanage
CCNC1