VLDB 2026 Research / reviewers in the wild / expert
Shehzad Ashraf Chaudhry
dblp:32/11473 · also Shehzad Ashraf 0001
· DBLP profile ↗
71ranked-venue papers
16as first author
46since 2021 · last 2026
0000-0002-9321-6956ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 31 · 6 first-author · 25 since 2021Applied, interdisciplinary, general and emerging computing · 14 · 3 first-author · 14 since 2021Graphics, computer vision, multimedia, augmented reality and games · 9 · 3 first-author · 1 since 2021Systems, architecture and hardware · 8 · 1 first-author · 1 since 2021Security and privacy · 8 · 3 first-author · 4 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Protecting autonomous systems from GPS spoofing with a machine learning-driven approach
Arslan Shafique, Abid Mehmood, Moatsum Alawida, Shehzad Ashraf Chaudhry |
Ad Hoc Networks | 4 |
| 2026 | A Comprehensive Survey on Handover Management Techniques Toward Seamless Mobility in 5G and Beyond Heterogeneous Networks
Sajjad Ahmad Khan, Waheeb Tashan, Ibraheem Shayea, Kerem Küçük, Sultan Aldirmaz Çolak, Shehzad Ashraf Chaudhry, Khalid Yahya |
Comput. Networks | 6 |
| 2026 | Task offloading and optimization methods in UAV-enabled mobile edge computing: A comprehensive survey
Cheru Haile Tesfay, Long Yang 0002, Jabar Mahmood, Mengmeng Ren, Shuangduo Zhang, Ashok Kumar Das, Shehzad Ashraf Chaudhry |
Comput. Commun. | 8 |
| 2026 | PDCM-IoD: A Lightweight PUF-Based Drone Access Control Mechanism for Internet of DronesabstractThe growing number of Unmanned Aerial Vehicles or drones in low altitude airspace has opened multitude of frontiers in diverse applications such as smart city, disaster management, logistics, and surveillance operations. Nonetheless, the open and dynamic communication landscape leads the Internet of Drones (IoD) environment to many security threats including forgery, unauthorized access or physical drone hijacking attacks. One of the pressing challenges is to ensure perfect forward secrecy using symmetric crypto-primitives, since most of the conventional access control schemes rely on costly public key cryptosystems that might not be suitable for constrained environment. We can spot many lightweight key agreement mechanisms for IoD environment, however regrettably, security loopholes render those inappropriate for deployment. In this paper, we propose a lightweight access control mechanism for IoD environment leveraging Physically Unclonable Function (PUF) based on Barrel-Shifter (BS) architectures. The commutative properties of BS oriented PUF (BS-PUF) have been exploited to ensure perfect forward secrecy in PDCM-IoD. Moreover, it ensures privacy, revocation of rogue user’s identity, and resistance from known attacks including physical drone capture threats and forgery attacks. It significantly helps to reduce computational overheads in comparison with other IoD-based schemes. The security features are rigorously analyzed using RoR-based random oracle model. Overall, the PDCM-IoD supports 19.52% increased number of security features. The performance evaluation depicts that PDCM-IoD is highly suitable for IoD-based resource deficient ecosystem. Shehzad Ashraf Chaudhry, Azeem Irshad, Matloub Hussain, Bander A. Alzahrani, Ashok Kumar Das, Muhammad Nasir Mumtaz Bhutta |
IEEE Internet Things J. | 1 |
| 2026 | PUF-ILM: A PUF-Enabled Authentication Scheme for Internet of Vehicles Using Improved Logical MappingabstractThis article proposes a lightweight two-way authentication scheme, PUF-ILM, that integrates Physical Unclonable Function (PUF) and Improved Logistic Map (ILM). The PUF generates unique challenge-response pairs (CRPs) for each device using its inherent physical randomness, thereby achieving reliable device identity authentication. The ILM encrypts and obfuscates the transmitted CRPs by enhancing their chaotic characteristics, expanding the parameter range, and eliminating periodic windows, effectively resisting modeling and eavesdropping attacks. Security analysis indicates that this scheme possesses several known security attributes, including anti-cloning, anonymity, two-way authentication, forward/backward security, and anti-machine-learning modeling. Performance evaluation shows that PUF-ILM maintains low communication overhead while maintaining a simple system structure and does not rely on complex hardware or external trusted institutions, offering high security and strong practicality, making it especially suitable for large-scale deployment in resource-constrained Internet of Vehicles environments. Sajjad Hussain Chauhdary, Linhua Jiang, Farrukh Aslam Khan, Ashok Kumar Das, Shehzad Ashraf Chaudhry |
IEEE Internet Things J. | 6 |
| 2026 | A Robust Tamper-Resistant and Location-Aware Authentication Protocol for Securing Charging Services in V2G EnvironmentsabstractThe rapid increase in electric vehicles (EVs) and the widespread deployment of charging stations have made secure authentication a critical requirement in Vehicle-to-Grid (V2G) environments. The growing interconnection among EVs, charging stations, and grid infrastructure introduces serious security and privacy challenges, including impersonation, replay, ephemeral secret leakage, and physical tampering attacks. Although several authentication protocols have been proposed for EV charging services, many existing schemes lack robust tamper-resistant and location-aware authentication capabilities and remain unsuitable for dynamic and resource-constrained V2G conditions. To address these limitations, this paper proposes a robust, tamper-resistant, and location-sensitive authentication protocol for securing EV charging services in V2G environments. The proposed protocol integrates configurable Arbiter Physical Unclonable Functions (A-PUFs) to provide device-level protection against physical tampering and unauthorized charging access. It also employs lightweight cryptographic primitives and techniques, including one-way hash functions, XOR operations, concatenation operations, and timestamp-based freshness verification, to support efficient mutual authentication and secure session key agreement. The security of the proposed protocol is evaluated through informal analysis and formal verification under the Random Oracle Model (ROM). Furthermore, comparative analysis demonstrates that the proposed protocol achieves a 17.16% reduction in communication cost and a 7.49% reduction in average computation cost compared with existing authentication protocols while maintaining strong security features. The results confirm that the proposed scheme enhances the security, efficiency, and practical deployability of EV charging authentication for next-generation V2G networks. Muhammad Umer 0001, Muhammad Farooq 0004, Syed Asad Naqvi, Khalid Mahmood 0002, Bander A. Alzahrani, Ashok Kumar Das, Shehzad Ashraf Chaudhry |
IEEE Internet Things J. | 7 |
| 2026 | LRAEB: Lightweight and Robust Anonymous ECC and Blockchain-Based Protocol for IoT in the Context of Public CloudabstractAuthentication is crucial in Internet of Things (IoT) networks as it ensures the integrity, accuracy, and tamper-resistance of information. This research article aims to design a lightweight and robust secure transmission system for IoT-enabled devices, enabling secure interaction with public cloud computing. The proposed system leverages blockchain technology integrated with elliptic curve cryptography (ECC), resulting in a resilient and efficient scheme tailored for resource and energy-constrained devices. We have adopted the SECP256K1 elliptic curve to design a Lightweight and Robust Anonymous ECC and Blockchain (LRAEB) scheme that offers superior performance. The use of blockchain guarantees the integrity and confidentiality of data stored in public cloud servers, addressing security vulnerabilities such as data leakage and unauthorized access. To validate the security of this novel technique, it will undergo verification using the Random Oracle Model (ROM) and Python. Our theoretical analysis confirms that the LRAEB scheme achieves better efficiency compared to existing schemes. In conclusion, we anticipate that this novel technique will significantly enhance information flow while mitigating the security flaws associated with public cloud computing and IoT devices. Dingyuan Tang, Mustafa A. Al Sibahee, Shehzad Ashraf Chaudhry, Ashok Kumar Das |
IEEE Trans. Cloud Comput. | 5 |
| 2026 | An Efficient Intrusion Detection System Using Advanced Machine Learning Techniques in SDN for Healthcare SystemabstractThe quick advancement of healthcare systems necessitates robust and efficient network security keys to defend sensitive patient records and guarantee uninterrupted service delivery. The current IDS has many challenges, such as a high false positive rate, poor accuracy of detection, slow response to threats, and inability to scale well. This paper proposes an efficient and real-time intrusion detection system (IDS) using advanced machine learning techniques within a software-defined networking (SDN) framework specifically tailored for healthcare systems. The proposed architecture implements a Machine Learning (ML) model that combines the SVM and KNN to better identify malicious activities. Full sets of detection and mitigation capabilities are implemented to address different types of traffic in the network with the least interference. Through the different evaluation measures, the efficiency of the proposed model is assured. Network performance is determined by success rate queries, packet losses in each domain path, and the CPU being used by the system. Responsiveness is measured through delay metrics grounded on end-to-end delay, hop-to-hop packet delay, latency rate, and propagation delay. Moreover, model accuracy fidelity is reviewed via precision assessment, alpha ($\alpha$) affecting the accuracy of the model, and confusion matrix with different techniques with the proposed hybrid SVM-KNN model. Last of all, a comparison of the security of the models in question strengthens the argument in favor of the proposed model. More specifically, flow and network topology diagrams are included to show how integration may be accomplished in linkage or merger with existing healthcare networks. The results also present a 30% overall advancement in detection and mitigation by presenting the hybrid SVM-KNN model to overcome other traditional models. This proposed model shows significant improvements not less than 20-30% improvement in CPU use, 30-50% reduction in end-to-end delay, 30-40% less latency rate, 20-40% less propagation delay, and 20-30% better prediction accuracy, and outperforms Fuzzy, Logistic Regression and Decision Tree methods. Muhammad Waseem Asif, Aqsa Aqdus, Rashid Amin, Shehzad Ashraf Chaudhry, Faisal Alsubaei 0001, Sajid Iqbal 0001 |
IEEE J. Biomed. Health Informatics | 4 |
| 2026 | PUF-Enabled Key-Exchange Protocol for Vehicular Ad-Hoc NetworksabstractThe Internet of Vehicles (IoV) enables data exchange among individuals, cloud resources, road infrastructures, and vehicles, interconnected through Vehicular Ad Hoc Networks (VANETs). VANETs comprise vehicles with Onboard Units (OBUs), Roadside Units (RSUs), and a Trusted Party Agent (TPA). The data transmission among these entities supports seamless interaction and collaborative traffic management. However, data transmission on public communication channels in VANETs presents significant challenges, including security, privacy, and authentication of participating entities. Although numerous key exchange and authentication protocols have been introduced to tackle these issues, many protocols remain vulnerable to various attacks, such as a vehicle, RSU, TPA impersonation, denial of service, physical cloning, and desynchronization attacks. Therefore, to address these vulnerabilities, we propose a key exchange protocol that leverages hash functions and Advanced Encryption Standard (AES) encryption. Our protocol also integrates the Physical Unclonable Function (PUF), enhancing its resistance to physical or cloning attacks. Additionally, it effectively counters threats like impersonation, session key leakage, ephemeral secret leakage, and desynchronization attacks. We validate the security and reliability of our protocol through both formal and informal analysis. Informal analysis highlights the protocol’s essential security features, while formal analysis provides robust substantiation. Performance evaluation reveals that our protocol achieves an average reduction of 35.53%, and 53.77%, in communication and computation overheads. Khalid Mahmood 0002, Zahid Ghaffar, Muhammad Farooq 0004, Muhammad Ilyas 0001, Ashok Kumar Das, Shehzad Ashraf Chaudhry |
IEEE Trans. Intell. Transp. Syst. | 6 |
| 2026 | Provably Secure and Reliable Privacy-Preserving Authentication Scheme for Drone-to-Drone Communications in Internet of Autonomous ThingsabstractWith the rapid advancements in wireless communication technologies, Unmanned Aerial Vehicles (UAVs), also known as Small Unmanned Aerial Vehicles (SUAVs) or drones, have been increasingly used in various applications, including the civilian sector. As a result, the security of SUAVs has garnered significant attention from the research community. Furthermore, drones are resource-constrained in nature and can be vulnerable to various known cybersecurity attacks over wireless communication. In light of these considerations, we propose aProvablySecure andReliable Privacy-Preserving AuthenticationScheme forDrone-to-Drone Communications in Internet of Autonomous Things (PSRS-D2D). The proposed scheme employs a secure one-way cryptographic hash and Elliptic Curve Cryptography (ECC) to accomplish a certain level of security. We provide security and privacy analysis, comparing it with competing UAV authentication schemes. This ensures that the PSRS-D2D scheme can withstand various prominent security properties, including mutual authentication and strong anonymity, and is secure against several attacks, such as replay, impersonation, and Man-In-The-Middle (MITM) attacks. We evaluated the performance of the proposed scheme in terms of computational and communicational costs. Furthermore, we conducted a formal security analysis using the Real-Or-Random (ROR) model and the Scyther simulation tools, which demonstrate that our scheme offers significant advantages in terms of security and performance. Mohd Shariq, Norziana Jamil, Gopal Singh Rawat, Shehzad Ashraf Chaudhry, Mehedi Masud, Ashok Kumar Das |
IEEE Trans. Mob. Comput. | 4 |
| 2026 | A Robust Trust Management System for V2X Networks Integrating ISAC With Blockchain Smart ContractsabstractVehicle-to-everything (V2X) networks face critical security challenges due to their dynamic nature, stringent latency requirements, and susceptibility to malicious attacks. Traditional trust management approaches often rely on centralized authorities or historical data, creating vulnerabilities and scalability limitations. This paper presents a new trust management system that leverages integrated sensing and communication (ISAC) technology and blockchain-based smart contracts to provide secure and decentralized trust evaluation in V2X networks. The proposed framework leverages real-time ISAC signal processing to compute five comprehensive trust metrics: behavior score, reputation score, safety score, uptime score, and response time score. These metrics are derived through advanced Kalman filtering and statistical anomaly detection applied to physical-layer measurements, enabling immediate detection of malicious activities that traditional approaches might miss. Trust records are securely stored and validated through smart contracts deployed on 5G base station blockchains, ensuring tamper-proof storage and automated policy enforcement. Numerical results demonstrate that the proposed protocol achieves faster trust convergence, higher communication reliability, significant reduction in false positive rates, improved detection accuracy, acceptable end-to-end latency, and lower computational overhead compared to state-of-the-art approaches. Muhammad Umar Farooq 0002, Weijie Yuan 0001, Lin Zhang 0009, Shehzad Ashraf Chaudhry, Guangjie Han, Yunyang Zhang |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2025 | An anonymous and privacy-preserving lightweight authentication protocol for secure communication in UAV-assisted IoAV networksabstractWith the rapid proliferation of the Internet of Things (IoT), autonomous vehicles (AVs), or self-driving cars, rely heavily on real-time data sharing and message exchanges over wireless networks. AVs use sensors, artificial intelligence, machine learning, and advanced algorithms to perform various functions, enabling users to operate without human intervention. Owing to the flexibility and high mobility of drones, they could aid in the operations of AVs. However, the security and privacy are the main concerns; specifically, the threat of physical capture and violation of anonymity are the main hurdles for realization of secure communication among the AVs and drones. To address these challenges, we propose an anonymous and provably secure lightweight authentication protocol for unmanned-aerial-vehicle-assisted Internet of Autonomous Vehicles (SLAP-IoAV). The proposed protocol uses cryptographic primitives such as exclusive-OR operations, elliptic-curve cryptography, collision-resistant one-way hashing, and concatenation to ensure robust security. An informal security analysis found that SLAP-IoAV is secure against several known attacks, and a performance analysis established that the protocol has less computational and communication overhead than existing competitive protocols. Additionally, Scyther simulation results confirm that no security vulnerabilities are present. Overall, our protocol delivers superior security and performance, making it well-suited to real-world applications in the AV industry. Mohd Shariq, Norziana Jamil, Gopal Singh Rawat, Shehzad Ashraf Chaudhry, Mehedi Masud, Angelo Cangelosi |
Comput. Commun. | 4 |
| 2025 | FA-SMW: Fog-Driven Anonymous Lightweight Access Control for Smart Medical WearablesabstractThe fog-enabled healthcare IoT (F-HIoT) paradigm is impending for the prospective patient-healthcare applications. The fog nodes permit the smart medical wearables (SMWs) to upload the information with low latency using 5G services. The security risks associated with the distributed attributes of fog nodes may hamper the monitoring of real-time medical reports with privacy. Many authenticated key exchange techniques can be witnessed to strengthen the interactions among SMW devices, fog nodes, and cloud server on insecure channels; however these are either based on computation-intensive crypto-primitives, or fail to provide anonymity to the F-HIoT end users. In this scheme, we propose an ultralightweight anonymous authentication protocol (FA-SMW) leveraging low-cost crypto-primitive operations, i.e., Chebyshev chaotic map for setting up a mutually agreed session key among three entities. The security properties of FA-SMW are evaluated and analyzed under random oracle model and Canetti–Krawczyk (eCK) threat model. These findings suggest that the proposed protocol considerably meets the desired requirements in the fog-enabled F-HIoT system. Azeem Irshad, Amer Aljaedi, Zaid Bassfar, Sajjad Shaukat Jamal, Muhammad Usman 0018, Shehzad Ashraf Chaudhry |
IEEE Internet Things J. | 6 |
| 2025 | BSP-IoD: A Secure Drone-Enabled Authentication Protocol Using Barrel-Shifter PUFabstractDue to the rapid proliferation of Unmanned Aerial Vehicles (UAVs), also termed as drones, the Internet of Drones (IoD) has revolutionized various domains including disaster response, smart surveillance, remote sensing, by facilitating real time collection of aerial data using autonomous coordination. However, the exposed communication landscape of IoD networks render them highly susceptible to known threats including forgery, impersonation and physical capture threats. Most of the conventional key agreement techniques are costly for computations and not suitable for resource constrained IoD system which necessitate low cost yet secure authentication mechanisms. Though, many lightweight drone authentication schemes have been presented, however with security limitations. This study suggested a novel Barrel-Shifter Physically Unclonable Function (BS-PUF) based drone authentication protocol (BSP-IoD) to augment security of IoD network. Leveraging the intrinsic randomness, commutative and invertible properties of BS-PUF, the BSP-IoD ensures construction of mutually agreed session key employing unique challenge-response pairs (CRPs). The scheme could withstand known threats besides supporting perfect forward secrecy and privacy to the user. The BSP-IoD considerably mitigates computational overheads besides ensuring resilience against known attacks including resistance from drone physical capture threat, promoting viability for next generation IoD networks. The formal analysis and performance assessment exhibit that BSP-IoD could address the critical challenges of next generation IoD applications. Furthermore, it supports 56.6% more number of security properties as compared to preceding schemes. Azeem Irshad, Abdul Jaleel, Abid Mehmood, Gulam Ali Mallah, Ashok Kumar Das, Shehzad Ashraf Chaudhry |
IEEE Internet Things J. | 6 |
| 2025 | SAC-DeV: Secure Access Control for Drone-Assisted Edge Computing in e-VANETsabstractUnmanned Aerial Vehicles (UAVs) are transforming how we manipulate tasks and respond to the challenges by making processes more proficient, safer, economical, and environment friendly. These intelligent UAVs or drones can act as an intermediate node in electric Vehicular Ad hoc Networks (e-VANETs) for relaying weak 5G/beyond 5G communication signals in mountainous terrain. Such aerial assistance could only be feasible if Internet of Things (IoT)-enabled drones are able to establish a secure channel with vehicles or Road Side Unit (RSUs) or edge cloud servers in Internet of Vehicles (IoV) infrastructure. However, drones may be exposed to the physical examination by malicious adversaries that might reveal the vehicle user’s privacy as well as disrupt the network coverage. To effectively assist this role in rural or underdeveloped terrains, this study proposes a secure access control mechanism SAC-DeV for drone-assisted mobile RSU infrastructure to develop a mutually agreed session key after mediating e-vehicular nodes and edge cloud servers. The scheme is immaculately enhanced with Physically Unclonable Function (PUF) circuits in e-vehicles as well as drones to resist physical capture threats. Employing the formal security analysis based on widely known Real-or-Random (RoR) model, the SEC-DeV is proven to be resilient from several threats. The SEC-DeV exhibits enhanced performance in comparison with comparative studies in terms of computational and communication overheads. Moreover, it supports 24% enhanced security features as compared to preceding studies. Muhammad Usman 0018, Azeem Irshad, Shehzad Ashraf Chaudhry |
IEEE Internet Things J. | 3 |
| 2025 | Design of a Provable Secure ECC and HMAC-Based Robust and Efficient Authentication Scheme for Maritime Transportation SystemabstractWith the rapid development of the Internet of Things (IoT), modern Maritime Transportation Systems (MTS) have played a crucial role in the transport industry. The various potential privacy and security concerns (such as vessels’ location tracking, message tampering, unauthorized access to data, etc.) have increased substantially in IoT-enabled MTS. Considering the above issues, we propose a secure, robust, and efficient authentication scheme for MTS based on Elliptic-Curve Cryptography (ECC) and Hash-based Message Authentication Code (HMAC) called PSAS-MTS. The proposed PSAS-MTS scheme not only monitors the vessel’s condition but also ensures protection against collisions in route management and provides safety to the vessel’s passengers. The scheme uses simple XOR, a cryptographic one-way hash, an ECC cryptosystem, and HMAC to achieve a high level of security in MTS. The formal security analysis is carried out using a well-known Real-Or-Random (ROR) model, which ensures the security harness features. A rigorous informal security analysis is also done, which ensures various privacy and security features such as mutual authentication, anonymity, forward and backward secrecy, etc. The proposed PSAS-MTS scheme resists various possible well-known active and passive security attacks. The performance analysis shows that the proposed PSAS-MTS scheme is more efficient in terms of computation and communication overheads when compared to other competitive schemes. Sanjeev Kumar Dwivedi, Mohammad Abdussami, Mohd Shariq, Ruhul Amin 0001, Shehzad Ashraf Chaudhry, Ashok Kumar Das, Norziana Jamil |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2025 | R2Com: Reliable and Resilient Communication in Duty-Cycled SDN-Based WSN for Urban Traffic Monitoring in Intelligent Transportation SystemsabstractWireless sensor networks (WSNs) are vital for addressing vehicle-related challenges information management, congestion, and safety in Intelligent Transportation Systems (ITS). Ensuring reliable communication is critical, particularly in urban environments where real-time data from roadside infrastructure enhances traffic flow efficiency and safety. This paper proposes R2Com, a reliable and resilient communication protocol for duty-cycled Software-Defined Wireless Sensor Networks (SDWSNs), specifically designed for urban traffic monitoring. By integrating reliable routing and adaptive duty cycling, R2Com ensures low-latency, energy-efficient data exchange between vehicle detection units and traffic control centers. The protocol leverages four attributes: direct trust, recommended trust, signal-to-interference noise ratio, and residual energy, considering their probability distributions to ensure reliability and resilience in the data plane communication. Secondly, the SDN controller calculates these attributes alongside the Expected Duty Cycled Wake-ups (EDC), enhancing reliability through flexible management and low latency. It then assigns communication strategies to each node through reliable nodes and limits the number of forwarding nodes per node to reduce packet duplication. Simulation results demonstrate that the proposed protocol significantly outperforms existing protocols in terms of average energy consumption, packet delivery ratio, average latency, network lifetime, communication overhead, packet success ratio, reliable coverage degree, coverage percentage, traffic density estimation accuracy, and intersection congestion levels. Muhammad Umar Farooq 0002, Weijie Yuan 0001, Paolo Bellavista, Shehzad Ashraf Chaudhry, Guangjie Han |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2025 | BTC2PA: A Blockchain-Assisted Trust Computation With Conditional Privacy- Preserving Authentication for Connected VehiclesabstractIntelligent Transportation Systems (ITS) dwell on Vehicular Ad-hoc NETworks (VANETs) for message dissemination to achieve the goal of traffic safety and efficiency. VANETs achieve communication among vehicles and roadside units via wireless communication. Hence, security and privacy are significant concerns to be addressed for an effective application of secure VANETs in any ITS. Researchers have addressed these issues with trust management-based schemes or cryptography-based schemes. While these schemes can secure VANETs, they have various limitations presenting hindrances in their deployment. In this context, we have proposed a Blockchain-assisted Trust Computation with a Conditional Privacy-preserving Authentication (BTC2PA) scheme for connected vehicles. The BTC2PA scheme uses a blockchain (Ethereum) assisted PKI infrastructure with digital signatures to achieve authentication for secure communication. Furthermore, it integrates a trust score computation scheme based on a reward and punishment mechanism to provide resistance against internal attacks. The feasibility and validity of the proposed BTC2PA scheme have been studied by implementation work in Rinkeby (Ethereum test network) and extensive simulations using NS-3. The results obtained show that the proposed BTC2PA scheme meets the security and privacy requirements while significantly improving the performance metrics such as communication, storage, computation cost, and end-to-end delay when compared to existing schemes. Gopal Singh Rawat, Karan Singh 0002, Mohd Shariq, Ashok Kumar Das, Shehzad Ashraf Chaudhry, Pascal Lorenz |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2024 | Anonymous and reliable ultralightweight RFID-enabled authentication scheme for IoT systems in cloud computing
Mohd Shariq, Mauro Conti, Karan Singh 0002, Chhagan Lal, Ashok Kumar Das, Shehzad Ashraf Chaudhry, Mehedi Masud |
Comput. Networks | 6 |
| 2024 | A Security-Enhanced and Ultralightweight Communication Protocol for Internet of Medical ThingsabstractWith the emergence, development, and maturity of various Internet technologies, the healthcare industry is also trying to integrate with these technologies to provide more convenient healthcare services to patients by establishing telemedicine to develop and continuously improve the public healthcare system. Various protocols were proposed in the recent past to provide attack resistance in addition to computational efficiency; however, several such protocols were proved inefficient or prone to one or more attacks. Some of these protocols lack user anonymity and privacy. Keeping in consideration the flaws of existing protocols, in this article, we propose an efficient and secure protocol based on extremely lightweight symmetric key operations. In addition, we provide formal and informal analyses to demonstrate the protocol’s security. Moreover, to measure the efficiency of the proposed protocol, we conducted a real-time experiment, which confirms that the proposed protocol completes an authentication round in 117.1071 ms with an exchange of four messages and 2592 bits among the three participating entities. Finally, by comparing it with other protocols, we show that the proposed protocol has significant security advantages and performance benefits. Chien-Ming Chen 0001, Zhaoting Chen, Ashok Kumar Das, Shehzad Ashraf Chaudhry |
IEEE Internet Things J. | 4 |
| 2024 | A Security Enhanced Chaotic-Map-Based Authentication Protocol for Internet of DronesabstractThe Internet of Drones (IoD) extends the capabilities of unmanned aerial vehicles, enabling them to participate in a connected network. In IoD infrastructure, drones communicate not only among themselves but also with users and a control center. This interconnected communication framework holds promise for various applications, from collaborative decision-making to real-time data exchange. However, the expansion of communication in IoD also introduces new challenges, particularly in terms of security, privacy and authentication. Unfortunately, the current authentication protocols are inadequate in offering robust security features against various attacks in the IoD environment. To address these security issues and limitations, we proposed a secure protocol for the IoD environment using chaotic maps and hash functions. In addition, we also employed a physically unclonable function in the development of the proposed protocol. We assess the security of the protocol through both informal and formal security analysis. The formal security analysis is conducted through a widely used random or real (RoR) model. The informal analysis shows the rigorous security features against various attacks, such as masquerading, anonymity violation, and physical cloning attacks. Moreover, we compare the performance of the devised protocol with similar existing protocols across important performance parameters such as communication overhead, computation overhead, and security features. The devised protocol provides a 67.86% and 17.80% reduction in computation and communication overheads, respectively, as compared to related protocols. The analysis demonstrates the proposed protocol’s capacity to support secure communication in the IoD environment and satisfy desirable security attributes. Khalid Mahmood 0002, Zahid Ghaffar, Muhammad Farooq 0004, Khalid Yahya, Ashok Kumar Das, Shehzad Ashraf Chaudhry |
IEEE Internet Things J. | 6 |
| 2024 | Scalable computing for large-scale multimedia data analytics
Marimuthu Karuppiah, Shehzad Ashraf Chaudhry, Mohammed H. Alsharif |
J. Intell. Inf. Syst. | 2 |
| 2023 | An efficient and reliable ultralightweight RFID authentication scheme for healthcare systems
Karan Singh 0002, Mohd Shariq, Chhagan Lal, Mauro Conti, Ruhul Amin 0001, Shehzad Ashraf Chaudhry |
Comput. Commun. | 7 |
| 2023 | SUSIC: A Secure User Access Control Mechanism for SDN-Enabled IIoT and Cyber-Physical SystemsabstractThe integration of thriving information and communications technology (ICT) and cyber–physical systems (CPSs) has spawned several innovative applications, such as remote healthcare, smart and intelligent transportation, smart logistics, smart grids, and public safety. An emerging software-defined networks (SDNs) technology further enabled to optimize the communication among Industrial IoT (IIoT) and CPS entities. Nonetheless, the communication on public channel among different IIoT entities in an SDN-enabled environment may be exposed to various security threats due to wireless and insecure communication channels. To counter these security challenges in the way of wider CPS or IIoT adoption, we propose a novel three-factor authenticated key exchange mechanism (SUSIC) for SDN-enabled IIoT ecosystem. The SUSIC enables a registered user to access real-time data from physical IIoT environment directly after having mutual authentication performed through SDN-enabled controller node. The scheme is proved to be secure under rigorous formal and informal security analysis. Moreover, the simulation results and performance evaluation signifies toward achieving a better tradeoff between security functionalities and computational overheads comparatively. Azeem Irshad, Gulam Ali Mallah, Muhammad Bilal 0003, Shehzad Ashraf Chaudhry, Muhammad Shafiq 0002, Houbing Song |
IEEE Internet Things J. | 4 |
| 2023 | A time-efficient and noise-resistant cryptosystem based on discrete wavelet transform and chaos theory: An application in image encryption
Abid Mehmood, Arslan Shafique, Shehzad Ashraf Chaudhry, Moatsum Alawida, Abdul Nasir Khan, Neeraj Kumar 0001 |
J. Inf. Secur. Appl. | 3 |
| 2023 | LAS-SG: An Elliptic Curve-Based Lightweight Authentication Scheme for Smart Grid EnvironmentsabstractThe communication among smart meters (SMs) and neighborhood area network (NAN) gateways is a fundamental requisite for managing the energy consumption at the consumer site. The bidirectional communication among SMs and NANs over the insecure public channel is vulnerable to impersonation, SM traceability, and SM physical capturing attacks. Many existing schemes’ insecurities and/or inefficiencies call for an efficient and secure authentication scheme for smart grid infrastructure. In this article, we present a privacy preserving and lightweight authentication scheme for smart grid (LAS-SG) using elliptic curve cryptography. The proposedLAS-SGis proved as secure under the standard model. Moreover, the efficiency of the LAS-SG is extracted through a real-time experiment, which attests that proposedLAS-SGcompletes a round of authentication in 20.331 ms by exchanging only two messages and 192 B. Due to the adequate efficiency and ample security, the proposedLAS-SGis more appropriate for SG environments. Shehzad Ashraf Chaudhry, Khalid Yahya, Sahil Garg, Georges Kaddoum, Mohammad Mehedi Hassan, Yousaf Bin Zikria |
IEEE Trans. Ind. Informatics | 1 |
| 2023 | A Provably Secure Lightweight Key Agreement Protocol for Wireless Body Area Networks in Healthcare SystemabstractWireless Body Area Network (WBAN) is a vital application of the Internet of Things (IoT) that plays a significant role in gathering a patient's healthcare information. This collected data helps special professionals like doctors or physicians analyze patients' health status to cure different diseases. However, collecting such information from an insecure channel can be threatening due to the potential security threats. Therefore, it is crucial to secure this sensitive information. This article proposes a secure and lightweight authentication protocol for WBAN. The devised protocol is scalable, secure, and lightweight compared to various relevant competing protocols. The informal security analysis shows that the designed protocol is lightweight, secure, and efficient in resisting various major attacks. The performance analysis demonstrates our protocol's supremacy over various competing protocols in terms of computation and communication costs, inducing efficiency of 20.3% and 12.3%, respectively. Moreover, the practical performance of the designed protocol from the network point of view is measured using the widely recognized NS3 simulation tool. Maryam Zia, Mohammad S. Obaidat, Khalid Mahmood 0002, Salman Shamshad, Muhammad Asad Saleem, Shehzad Ashraf Chaudhry |
IEEE Trans. Ind. Informatics | 6 |
| 2023 | Guest Editorial Medical Image Analysis Embedded on MicroprocessorsabstractThe papers in this special section focus on embedded microprocessors under wireless transmission in medical imaging lesion detection systems and provides researchers in related fields with opportunities for discussions. Haibin Lv, Enrico Natalizio, Houbing Song, Shehzad Ashraf Chaudhry |
IEEE J. Biomed. Health Informatics | 4 |
| 2023 | AAKE-BIVT: Anonymous Authenticated Key Exchange Scheme for Blockchain-Enabled Internet of Vehicles in Smart TransportationabstractThe next-generation Internet of vehicles (IoVs) seamlessly connects humans, vehicles, roadside units (RSUs), and service platforms, to improve road safety, enhance transit efficiency, and deliver comfort while conserving the environment. Currently, numerous entities communicate in the IoVs environment via insecure public channels that are susceptible to a variety of security assaults and threats. To address these security challenges, we design an anonymous authenticated key exchange mechanism for the IoVs in smart transportation supported by blockchain, referred to as AAKE-BIVT. AAKE-BIVT securely transmits traffic information to a cluster head, before heading to a nearby RSU utilizing the established secret session keys via mutual authentication and key agreement. A cloud server (CS) then securely aggregates data from related RSUs and generates transactions. The CS combines the transactions into blocks in a peer-to-peer network of CSs, and the blocks are confirmed and added to the blockchain via a voting-based consensus method. By means of rigorous informal security studies and formal security analysis through the random oracle model, we reveal that the proposed AAKE-BIVT is resistant to a broad range of potential security assaults in the IoVs environment. Furthermore, a comparative study reveals that AAKE-BIVT outperforms existing state-of-the-art techniques, in terms of security and functionality while being more efficient in terms of communication and computation. Additionally, the blockchain simulation validates the implementation viability of our proposed AAKE-BIVT. Akhtar Badshah, Muhammad Waqas 0001, Fazal Muhammad, Ghulam Abbas 0002, Ziaul Haq Abbas, Shehzad Ashraf Chaudhry, Sheng Chen 0001 |
IEEE Trans. Intell. Transp. Syst. | 6 |
| 2023 | A Lightweight Authentication Scheme for 6G-IoT Enabled Maritime Transport SystemabstractThe Sixth-Generation (6G) mobile network has the potential to provide not only traditional communication services but also additional processing, caching, sensing, and control capabilities to a massive number of Internet of Things (IoT) devices. Meanwhile, a 6G mobile network may provide global coverage and diverse quality-of-service provisioning to the Maritime Transportation System (MTS) when enabled through satellite systems. Although modern MTS has gained significant benefits from Internet of Things (IoT) and 6G technologies, threats and challenges in terms of security and privacy have also been grown substantially. Tracking the location of vessels, GPS spoofing, unauthorized access to data, and message tampering are some of the potential security and privacy vulnerabilities in the 6G-IoT enabled MTS. In this article, we propose a lightweight authentication protocol for a 6G-IoT enabled maritime transportation system to efficiently assist and ensure the security and privacy of maritime transportation systems. To validate the security characteristics, formal security assessment methods are utilized, i.e., Real-Or-Random (ROR) oracle model. The findings of the security analysis show that the proposed scheme is more secure than the existing schemes. Shehzad Ashraf Chaudhry, Azeem Irshad, Muhammad Asghar Khan, Sajjad Ahmad Khan, Summera Nosheen, Ahmad Ali AlZubi, Yousaf Bin Zikria |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2022 | An energy-efficient and secure identity based RFID authentication scheme for vehicular cloud computing
Waseem Akram 0003, Khalid Mahmood 0002, Xiong Li 0002, Mazhar Sadiq, Zhihan Lyu, Shehzad Ashraf Chaudhry |
Comput. Networks | 6 |
| 2022 | A seamless anonymous authentication protocol for mobile edge computing infrastructure
Khalid Mahmood 0002, Muhammad Faizan Ayub, Syed Zohaib Hassan, Zahid Ghaffar, Zhihan Lyu, Shehzad Ashraf Chaudhry |
Comput. Commun. | 6 |
| 2022 | A Robust Access Control Protocol for the Smart Grid SystemsabstractLightweight cryptography (LWC)-based authenticated encryption with associative data (AEAD) cryptographic primitives require fewer computational and energy resources than conventional cryptographic primitives as a single operation of an AEAD scheme provides confidentiality, integrity, and authenticity of data. This feature of AEAD schemes helps design an access control (AC) protocol to be leveraged for enhancing the security of the resource-constrained Internet of Things (IoT)-enabled smart grid (SG) system with low computational overhead and fewer cryptographic operations. This article presents a novel and robust AC protocol, called RACP-SG, which aims to enhance the security of resource-constrained IoT-enabled SG systems. RACP-SG employs an LWC-based AEAD scheme, ASCON and the hash function, ASCON-hash, along with elliptic curve cryptography to accomplish the AC phase. Besides, RACP-SG enables a smart meter (SM) and a service provider (SEP) to mutually authenticate each other and establish a session key (SK) while communicating across the public communication channel. By using the SK, the SM can securely transfer the gathered data to the SEP. We verify the security of the SK using the widely accepted random oracle model. Moreover, we conduct Scyther-based and informal security analyses to demonstrate that RACP-SG is protected against various covert security risks, such as replay, impersonation, and desynchronization attacks. Besides, we present a comparative study to illustrate that RACP-SG renders superior security features while reducing energy, storage, communication, and computational overheads compared to the state of the art. Muhammad Tanveer 0003, Abd Ullah Khan, Neeraj Kumar 0001, Alamgir Naushad, Shehzad Ashraf Chaudhry |
IEEE Internet Things J. | 5 |
| 2022 | Security, Trust and Privacy for Cloud, Fog and Internet of Things
Chien-Ming Chen 0001, Shehzad Ashraf Chaudhry, Kuo-Hui Yeh, Muhammad Naveed Aman |
Secur. Commun. Networks | 2 |
| 2022 | A Privacy Enhanced Authentication Scheme for Securing Smart Grid InfrastructureabstractThe rapid advancements in smart grid (SG) technology extend a large number of applications including vehicle charging, smart buildings, and smart cities through the efficient use of advanced communication architecture. However, the underlying public channel leads these services to be vulnerable to many threats. Recently, some security schemes were proposed to counter these threats. However, the insecurities of some of these schemes against key compromise impersonation (KCI) and related attacks or compromise on efficiency calls for a secure and efficient authentication scheme for SG infrastructure. A new scheme to secure SG communication is presented in this article to provide a direct device-to-device authentication among smart meter and neighborhood area network gateway. Designed specifically to resists KCI and related attacks, the proposed scheme is more secure and completes the authentication procedure by using the least communication cost as compared with related schemes, which is evident through security and efficiency comparisons. Shehzad Ashraf Chaudhry, Jamel Nebhen, Khalid Yahya, Fadi M. Al-Turjman |
IEEE Trans. Ind. Informatics | 1 |
| 2022 | An Efficient and Provably Secure Certificateless Protocol for Industrial Internet of ThingsabstractThe Internet of Things (IoT) has a wide range of applications that influence the life of people expeditiously. In recent years, IoT becomes an emerging technology in a number of fields. Different devices with divergent functionality are applied in IoT to work in several domains. These domains include smart home, smart farming, and Industrial Internet of Things (IIoT). Among these territories, the IIoT obtains more attention. In an IIoT environment, a legitimate user can control and access devices remotely. Legitimate users can access real-time data and share confidential information. The information is transmitted via public communication channel, which can be vulnerable to security attacks. In this article, we present a provably secure multifactor authenticated key agreement scheme to offer security regarding transmission of data in IIoT environment. This scheme will support the legitimate user to remotely access the sensing devices. Our presented scheme uses only symmetric cryptographic, bitwise XOR operation, and hash function to be resource-constrained. Our scheme is found to be resource efficient through communication and computation analysis. The performance analysis illustrates that the cost of computation and communication of our scheme is comparatively low as compared to other relevant schemes. The formal and informal security analysis proved that our scheme is secure and efficient as it can withstand several known adversarial attacks. We have used some cryptographic operations like XOR and hashing to provide security and privacy to legitimate entities. Farva Rafique, Mohammad S. Obaidat, Khalid Mahmood 0002, Muhammad Faizan Ayub, Javed Ferzund, Shehzad Ashraf Chaudhry |
IEEE Trans. Ind. Informatics | 6 |
| 2022 | A Secure and Lightweight Drones-Access Protocol for Smart City SurveillanceabstractThe rising popularity of ICT and the Internet has enabled Unmanned Aerial Vehicle (UAV) to offer advantageous assistance to Vehicular Ad-hoc Network (VANET), realizing a relay node’s role among the disconnected segments in the road. In this scenario, the communication is done between Vehicles to UAVs (V2U), subsequently transforming into a UAV-assisted VANET. UAV-assisted VANET allows users to access real-time data, especially the monitoring data in smart cities using current mobile networks. Nevertheless, due to the open nature of communication infrastructure, the high mobility of vehicles along with the security and privacy constraints are the significant concerns of UAV-assisted VANET. In these scenarios, Deep Learning Algorithms (DLA) could play an effective role in the security, privacy, and routing issues of UAV-assisted VANET. Keeping this in mind, we have devised a DLA-based key-exchange protocol for UAV-assisted VANET. The proposed protocol extends the scalability and uses secure bitwise XOR operations, one-way hash functions, including user’s biometric verification when users and drones are mutually authenticated. The proposed protocol can resist many well-known security attacks and provides formal and informal security under the Random Oracle Model (ROM). The security comparison shows that the proposed protocol outperforms the security performance in terms of running time cost and communication cost and has effective security features compared to other related protocols. Muhammad Wahid Akram, Ali Kashif Bashir, Salman Shamshad, Muhammad Asad Saleem, Ahmad Ali AlZubi, Shehzad Ashraf Chaudhry, Bander A. Alzahrani, Yousaf Bin Zikria |
IEEE Trans. Intell. Transp. Syst. | 6 |
| 2021 | A clogging resistant secure authentication scheme for fog computing services
Zeeshan Ali 0003, Shehzad Ashraf Chaudhry, Khalid Mahmood 0002, Sahil Garg, Zhihan Lyu, Yousaf Bin Zikria |
Comput. Networks | 2 |
| 2021 | GCACS-IoD: A certificate based generic access control scheme for Internet of drones
Shehzad Ashraf Chaudhry, Khalid Yahya, Marimuthu Karuppiah, Rupak Kharel, Ali Kashif Bashir, Yousaf Bin Zikria |
Comput. Networks | 1 |
| 2021 | A secure blockchain-oriented data delivery and collection scheme for 5G-enabled IoD environment
Azeem Irshad, Shehzad Ashraf Chaudhry, Anwer Ghani, Muhammad Bilal 0003 |
Comput. Networks | 2 |
| 2021 | A secure and lightweight authentication scheme for next generation IoT infrastructure
Minahil Rana, Akasha Shafiq, Izwa Altaf, Mamoun Alazab, Khalid Mahmood 0002, Shehzad Ashraf Chaudhry, Yousaf Bin Zikria |
Comput. Commun. | 6 |
| 2021 | A secure and improved multi server authentication protocol using fuzzy commitment
Anwer Ghani, Shehzad Ashraf Chaudhry, Mohammed H. Alsharif, Narjes Nabipour |
Multim. Tools Appl. | 3 |
| 2021 | Designing an Efficient and Secure Message Exchange Protocol for Internet of VehiclesabstractIn the advancements in computation and communication technologies and increasing number of vehicles, the concept of Internet of Vehicles (IoV) has emerged as an integral part of daily life, and it can be used to acquire vehicle related information including road congestion, road description, vehicle location, and speed. Such information is very vital and can benefit in a variety of ways, including route selection. However, without proper security measures, the information transmission among entities of IoV can be exposed and used for wicked intentions. Recently, many authentication schemes were proposed, but most of those authentication schemes are prone to insecurities or suffer from heavy communication and computation costs. Therefore, a secure message authentication protocol is proposed in this study for information exchange among entities of IoV (SMEP-IoV). Based on secure symmetric lightweight hash functions and encryption operations, the proposed SMEP-IoV meets IoV security and performance requirements. For formal security analysis of the proposed SMEP-IoV, BAN logic is used. The performance comparisons show that the SMEP-IoV is lightweight and completes the authentication process in just 0.198 ms . Shehzad Ashraf Chaudhry |
Secur. Commun. Networks | 1 |
| 2021 | DAWM: Cost-Aware Asset Claim Analysis Approach on Big Data Analytic Computation Model for Cloud Data CentreabstractThe heterogeneous resource-required application tasks increase the cloud service provider (CSP) energy cost and revenue by providing demand resources. Enhancing CSP profit and preserving energy cost is a challenging task. Most of the existing approaches consider task deadline violation rate rather than performance cost and server size ratio during profit estimation, which impacts CSP revenue and causes high service cost. To address this issue, we develop two algorithms for profit maximization and adequate service reliability. First, a belief propagation-influenced cost-aware asset scheduling approach is derived based on the data analytic weight measurement (DAWM) model for effective performance and server size optimization. Second, the multiobjective heuristic user service demand (MHUSD) approach is formulated based on the CPS profit estimation model and the user service demand (USD) model with dynamic acyclic graph (DAG) phenomena for adequate service reliability. The DAWM model classifies prominent servers to preserve the server resource usage and cost during an effective resource slicing process by considering each machine execution factor (remaining energy, energy and service cost, workload execution rate, service deadline violation rate, cloud server configuration (CSC), service requirement rate, and service level agreement violation (SLAV) penalty rate). The MHUSD algorithm measures the user demand service rate and cost based on the USD and CSP profit estimation models by considering service demand weight, tenant cost, and energy cost. The simulation results show that the proposed system has accomplished the average revenue gain of 35%, cost of 51%, and profit of 39% than the state-of-the-art approaches. Mahammad Shareef Mekala, Rizwan Patan, SK Hafizul Islam, Debabrata Samanta, Gulam Ali Mallah, Shehzad Ashraf Chaudhry |
Secur. Commun. Networks | 6 |
| 2021 | Rotating behind Privacy: An Improved Lightweight Authentication Scheme for Cloud-based IoT EnvironmentabstractThe advancements in the internet of things (IoT) require specialized security protocols to provide unbreakable security along with computation and communication efficiencies. Moreover, user privacy and anonymity has emerged as an integral part, along with other security requirements. Unfortunately, many recent authentication schemes to secure IoT-based systems were either proved as vulnerable to different attacks or prey of inefficiencies. Some of these schemes suffer from a faulty design that happened mainly owing to undue emphasis on privacy and anonymity alongside performance efficiency. This article aims to show the design faults by analyzing a very recent hash functions-based authentication scheme for cloud-based IoT systems with misunderstood privacy cum efficiency tradeoff owing to an unadorned design flaw, which is also present in many other such schemes. Precisely, it is proved in this article that the scheme of Wazid et al. cannot provide mutual authentication and key agreement between a user and a sensor node when there exists more than one registered user. We then proposed an improved scheme and proved its security through formal and informal methods. The proposed scheme completes the authentication cycle with a minor increase in computation cost but provides all security goals along with privacy. Shehzad Ashraf Chaudhry, Azeem Irshad, Khalid Yahya, Neeraj Kumar 0001, Mamoun Alazab, Yousaf Bin Zikria |
ACM Trans. Internet Techn. | 1 |
| 2021 | Fuzzy-in-the-Loop-Driven Low-Cost and Secure Biometric User Access to ServerabstractFuzzy systems can aid in diminishing uncertainty and noise from biometric security applications by providing an intelligent layer to the existing physical systems to make them reliable. In the absence of such fuzzy systems, a little random perturbation in captured human biometrics could disrupt the whole security system, which may even decline the authentication requests of legitimate entities during the protocol execution. In the literature, few fuzzy logic-based biometric authentication schemes have been presented; however, they lack significant security features including perfect forward secrecy (PFS), untraceability, and resistance to known attacks. This article, therefore, proposes a novel two-factor biometric authentication protocol enabling efficient and secure combination of physically unclonable functions, a physical object analogous to human fingerprint, with user biometrics by employing fuzzy extractor-based procedures in the loop. This combination enables the participants in the protocol to achieve PFS. The security of the proposed scheme is tested using the well-known real-or-random model. The performance analysis signifies the fact that the proposed scheme not only offers PFS, untraceability, and anonymity to the participants, but is also resilient to known attacks using light-weight symmetric operations, which makes it an imperative advancement in the category of intelligent and reliable security solutions. Azeem Irshad, Muhammad Usman 0001, Shehzad Ashraf Chaudhry, Ali Kashif Bashir, Alireza Jolfaei, Gautam Srivastava 0001 |
IEEE Trans. Reliab. | 3 |
| 2020 | Correcting design flaws: An improved and cloud assisted key agreement scheme in cyber physical systems
Shehzad Ashraf Chaudhry, Taeshik Shon, Fadi M. Al-Turjman, Mohammed H. Alsharif |
Comput. Commun. | 1 |
| 2020 | A robust authentication and access control protocol for securing wireless healthcare sensor networks
Zeeshan Ali 0003, Anwer Ghani, Imran Khan 0004, Shehzad Ashraf Chaudhry, SK Hafizul Islam, Debasis Giri |
J. Inf. Secur. Appl. | 4 |
| 2019 | Comments on "Biometrics-Based Privacy-Preserving User Authentication Scheme for Cloud-Based Industrial Internet of Things Deployment"abstractVery recently, Das et al. (IEEE Internet of Things Journal, pp. 4900-4913, 5(6), DOI: 10.1109/JIOT.2018.2877690, 2018) presented a biometric-based solution for security and privacy in Industrial Internet of Things architecture. Das et al. claimed that their protocol is secure against known attacks. However, this comment shows that their protocol is defenseless against stolen verifier, stolen smart device, and traceability attacks. The attacker having access to public parameters and any of the verifier and parameters stored in smart device can easily expose the session key shared among the user and the smart device. Moreover, their protocol fails to provide perfect forward secrecy. Finally, this article also provides some necessary guidelines on attack resilience for the authentication schemes based on merely the symmetric key primitives, which are overlooked by Das et al. Shehzad Ashraf Chaudhry |
IEEE Internet Things J. | 2 |
| 2019 | Secure Remote User Mutual Authentication Scheme with Key Agreement for Cloud Environment
Marimuthu Karuppiah, Ashok Kumar Das, Xiong Li 0002, Saru Kumari, Fan Wu 0003, Shehzad Ashraf Chaudhry, Niranchana Radhakrishnan |
Mob. Networks Appl. | 6 |
| 2018 | An elliptic curve cryptography based lightweight authentication scheme for smart grid communication
Khalid Mahmood 0002, Shehzad Ashraf Chaudhry, Syed Husnain Abbas Naqvi, Saru Kumari, Xiong Li 0002, Arun Kumar Sangaiah |
Future Gener. Comput. Syst. | 2 |
| 2018 | Pairing based anonymous and secure key agreement protocol for smart grid edge computing infrastructure
Khalid Mahmood 0002, Xiong Li 0002, Shehzad Ashraf Chaudhry, Syed Husnain Abbas Naqvi, Saru Kumari, Arun Kumar Sangaiah, Joel J. P. C. Rodrigues |
Future Gener. Comput. Syst. | 3 |
| 2018 | An enhanced lightweight anonymous biometric based authentication scheme for TMIS
Shehzad Ashraf Chaudhry, Syed Husnain Abbas Naqvi, Muhammad Khurram Khan |
Multim. Tools Appl. | 1 |
| 2018 | A secure mutual authenticated key agreement of user with multiple servers for critical systems
Azeem Irshad, Shehzad Ashraf Chaudhry, Saru Kumari, Arun Kumar Sangaiah, Xiong Li 0002, Fan Wu 0003 |
Multim. Tools Appl. | 3 |
| 2018 | An improved and secure chaotic map based authenticated key agreement in multi-server architecture
Azeem Irshad, Shehzad Ashraf Chaudhry, Qi Xie 0001, Saru Kumari, Fan Wu 0003 |
Multim. Tools Appl. | 3 |
| 2018 | An improved and robust biometrics-based three factor authentication scheme for multiserver environments
Shehzad Ashraf Chaudhry, Syed Husnain Abbas Naqvi, Mohammad Sabzinejad Farash, Taeshik Shon |
J. Supercomput. | 1 |
| 2018 | An efficient and secure design of multi-server authenticated key agreement protocol
Azeem Irshad, Syed Husnain Abbas Naqvi, Shehzad Ashraf Chaudhry, Shouket Raheem, Saru Kumari, Ambrina Kanwal, Muhammad Usman 0018 |
J. Supercomput. | 3 |
| 2018 | An anonymous and provably secure biometric-based authentication scheme using chaotic maps for accessing medical drop box data
Imran Khan 0004, Shehzad Ashraf Chaudhry, Muhammad Khurram Khan |
J. Supercomput. | 2 |
| 2017 | An improved one-to-many authentication scheme based on bilinear pairings with provable security for mobile pay-TV systems
Sajad Sadough, Shehzad Ashraf Chaudhry, Mohammad Sabzinejad Farash, Khalid Mahmood 0002 |
Multim. Tools Appl. | 3 |
| 2017 | A secure and provable multi-server authenticated key agreement for TMIS based on Amin et al. scheme
Azeem Irshad, Omer Nawaz, Shehzad Ashraf Chaudhry, Imran Khan 0004, Saru Kumari |
Multim. Tools Appl. | 4 |
| 2017 | An improved and provably secure privacy preserving authentication protocol for SIP
Shehzad Ashraf Chaudhry, Syed Husnain Abbas Naqvi, Mohammad Sabzinejad Farash |
Peer-to-Peer Netw. Appl. | 1 |
| 2017 | An improved smart card based authentication scheme for session initiation protocol
Saru Kumari, Shehzad Ashraf Chaudhry, Fan Wu 0003, Xiong Li 0002, Mohammad Sabzinejad Farash, Muhammad Khurram Khan |
Peer-to-Peer Netw. Appl. | 2 |
| 2017 | Comments on "A privacy preserving three-factor authentication protocol for e-health clouds"
Azeem Irshad, Shehzad Ashraf Chaudhry |
J. Supercomput. | 2 |
| 2016 | A secure biometric based multi-server authentication scheme for social multimedia networks
Shehzad Ashraf Chaudhry |
Multim. Tools Appl. | 1 |
| 2016 | A provably secure anonymous authentication scheme for Session Initiation ProtocolabstractAbstract Recently, Lu et al. presented a mutual authentication scheme for Session Initiation Protocol. Lu et al. claimed their scheme provides safeguard against familiar attacks and offers efficient authentication facility. However, this paper divulges that the scheme of Lu et al. is prone to server and user impersonation attacks. Additionally, the scheme of Lu et al. implicates correctness concerns. Consequently, an enhanced scheme is proposed, not only to resolve correctness concerns but also to provide robustness against server and user impersonation attacks. The proposed scheme makes use of a user‐specific secret parameter to deal with the security and correctness issues. The formal and informal security analysis proves the robustness and efficiency of the proposed scheme against all familiar attacks. Furthermore, security analysis is also substantiated through popular automated tool PROVERIF. Copyright © 2016 John Wiley & Sons, Ltd. Shehzad Ashraf Chaudhry, Imran Khan 0004, Azeem Irshad, Muhammad Usman Ashraf, Muhammad Khurram Khan, Hafiz Farooq Ahmad |
Secur. Commun. Networks | 1 |
| 2016 | An efficient and anonymous multi-server authenticated key agreement based on chaotic map without engaging Registration Centre
Azeem Irshad, Shehzad Ashraf Chaudhry, Syed Husnain Abbas Naqvi, Mohammad Sabzinejad Farash |
J. Supercomput. | 3 |
| 2015 | Comment on 'Robust and efficient password authenticated key agreement with user anonymity for session initiation protocol-based communications'abstractI am writing this comment with reference to an article published recently by Zhang et al. [1] in IET communications. The Zhang et al.’s protocol for SIP authentication is robust against all known attacks, further it provide user anonymity. They have alternated the need of storing verification tables to reduce storage and computation burden on SIP server, but I am worried about the correctness of their protocol as during authentication phase the client sends W = r1, R = r1(h(PW||c) ⊕ h(username||c))s2 P and V = Em(r1 P||h(PW||c) ⊕ h(username||c)||T). Upon receiving W and V the SIP server computes m = (s−1)2 W and decrypts V by using key m. Then server extracts (h(PW||c) ⊕ h(username||c)) from both W and V independently, further server compare both values of (h(PW||c) ⊕ h(username||c)), if they are equivalent server continues the authentication process. My concern is the server got user's password PW, name username and a random number c protected by one way hash function. The user name or password is not even revealed to the server. Hence the user is not recognised by the server, so how can the user be able to obtain user specific services from the server? The authors need to either clarify the protocol or propose an enhanced protocol in order to make server able to recognise the user who has initiated the login request, at the moment protocol cannot distinguish between two different legal users say Ui and Uj. Shehzad Ashraf Chaudhry |
IET Commun. | 1 |
| 2015 | An efficient signcryption scheme with forward secrecy and public verifiability based on hyper elliptic curve cryptography
Shehzad Ashraf Chaudhry, Nizamuddin, Anwer Ghani, Syed Husnain Abbas Naqvi, Azeem Irshad |
Multim. Tools Appl. | 1 |
| 2015 | A single round-trip SIP authentication scheme for Voice over Internet Protocol using smart card
Azeem Irshad, Eid Rehman, Shehzad Ashraf Chaudhry, Anwer Ghani |
Multim. Tools Appl. | 4 |
| 2015 | An enhanced privacy preserving remote user authentication scheme with provable securityabstractAbstract Very recently, Kumariet al.proposed a symmetric key and smart card‐based remote user password authentication scheme to enhance Chunget al.'s scheme. They claimed their enhanced scheme to provide anonymity while resisting all known attacks. In this paper, we analyze that Kumariet al.'s scheme is still vulnerable to anonymity violation attack as well as smart card stolen attack. Then we propose a supplemented scheme to overcome security weaknesses of Kumariet al.'s scheme. We have analyzed the security of the proposed scheme in random oracle model which confirms the robustness of the scheme against all known attacks. We have also verified the security of our scheme using automated tool ProVerif. Copyright © 2015 John Wiley & Sons, Ltd. Shehzad Ashraf Chaudhry, Mohammad Sabzinejad Farash, Syed Husnain Abbas Naqvi, Saru Kumari, Muhammad Khurram Khan |
Secur. Commun. Networks | 1 |
| 2014 | A secure authentication scheme for session initiation protocol by using ECC on the basis of the Tang and Liu schemeabstractABSTRACT Session initiation protocol (SIP) provides the basis for establishing the voice over internet protocol sessions after authentication and exchanging signaling messages. SIP is one of the significant and extensively used protocols in the multimedia protocol stack. Since the RFC2617 was put forth, numerous schemes for SIP authentication have been presented to overcome the flaws. Recently, in 2012, Tang and Liu proposed SIP based authentication protocol and claimed for eliminating the threats in Arshad and Ikram protocol. However the scheme can be made more robust by making further improvements, as the former scheme may come under a threat by adversaries through impersonating a server, given that the user password is compromised. We have proposed an improved protocol for SIP authentication by using elliptic curve cryptography that encounters the previous threat with enhanced security. The analysis shows that proposed scheme is suitable for applications with higher security requirements. Copyright © 2013 John Wiley & Sons, Ltd. Azeem Irshad, Ch. Muhammad Shahzad Faisal, Anwer Ghani, Shehzad Ashraf Chaudhry |
Secur. Commun. Networks | 6 |