Azeem Irshad

dblp:33/7938 · DBLP profile ↗
← Back
22ranked-venue papers
14as first author
11since 2021 · last 2026
0000-0002-1366-2834ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 7 · 4 first-author · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 4 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 3 since 2021Systems, architecture and hardware · 3 · 3 first-authorSecurity and privacy · 2 · 1 first-author
YearPublicationVenuePosition
2026 PDCM-IoD: A Lightweight PUF-Based Drone Access Control Mechanism for Internet of Drones
abstract
The growing number of Unmanned Aerial Vehicles or drones in low altitude airspace has opened multitude of frontiers in diverse applications such as smart city, disaster management, logistics, and surveillance operations. Nonetheless, the open and dynamic communication landscape leads the Internet of Drones (IoD) environment to many security threats including forgery, unauthorized access or physical drone hijacking attacks. One of the pressing challenges is to ensure perfect forward secrecy using symmetric crypto-primitives, since most of the conventional access control schemes rely on costly public key cryptosystems that might not be suitable for constrained environment. We can spot many lightweight key agreement mechanisms for IoD environment, however regrettably, security loopholes render those inappropriate for deployment. In this paper, we propose a lightweight access control mechanism for IoD environment leveraging Physically Unclonable Function (PUF) based on Barrel-Shifter (BS) architectures. The commutative properties of BS oriented PUF (BS-PUF) have been exploited to ensure perfect forward secrecy in PDCM-IoD. Moreover, it ensures privacy, revocation of rogue user’s identity, and resistance from known attacks including physical drone capture threats and forgery attacks. It significantly helps to reduce computational overheads in comparison with other IoD-based schemes. The security features are rigorously analyzed using RoR-based random oracle model. Overall, the PDCM-IoD supports 19.52% increased number of security features. The performance evaluation depicts that PDCM-IoD is highly suitable for IoD-based resource deficient ecosystem.
Shehzad Ashraf Chaudhry, Azeem Irshad, Matloub Hussain, Bander A. Alzahrani, Ashok Kumar Das, Muhammad Nasir Mumtaz Bhutta
IEEE Internet Things J.2
2025 FA-SMW: Fog-Driven Anonymous Lightweight Access Control for Smart Medical Wearables
abstract
The fog-enabled healthcare IoT (F-HIoT) paradigm is impending for the prospective patient-healthcare applications. The fog nodes permit the smart medical wearables (SMWs) to upload the information with low latency using 5G services. The security risks associated with the distributed attributes of fog nodes may hamper the monitoring of real-time medical reports with privacy. Many authenticated key exchange techniques can be witnessed to strengthen the interactions among SMW devices, fog nodes, and cloud server on insecure channels; however these are either based on computation-intensive crypto-primitives, or fail to provide anonymity to the F-HIoT end users. In this scheme, we propose an ultralightweight anonymous authentication protocol (FA-SMW) leveraging low-cost crypto-primitive operations, i.e., Chebyshev chaotic map for setting up a mutually agreed session key among three entities. The security properties of FA-SMW are evaluated and analyzed under random oracle model and Canetti–Krawczyk (eCK) threat model. These findings suggest that the proposed protocol considerably meets the desired requirements in the fog-enabled F-HIoT system.
Azeem Irshad, Amer Aljaedi, Zaid Bassfar, Sajjad Shaukat Jamal, Muhammad Usman 0018, Shehzad Ashraf Chaudhry
IEEE Internet Things J.1
2025 BSP-IoD: A Secure Drone-Enabled Authentication Protocol Using Barrel-Shifter PUF
abstract
Due to the rapid proliferation of Unmanned Aerial Vehicles (UAVs), also termed as drones, the Internet of Drones (IoD) has revolutionized various domains including disaster response, smart surveillance, remote sensing, by facilitating real time collection of aerial data using autonomous coordination. However, the exposed communication landscape of IoD networks render them highly susceptible to known threats including forgery, impersonation and physical capture threats. Most of the conventional key agreement techniques are costly for computations and not suitable for resource constrained IoD system which necessitate low cost yet secure authentication mechanisms. Though, many lightweight drone authentication schemes have been presented, however with security limitations. This study suggested a novel Barrel-Shifter Physically Unclonable Function (BS-PUF) based drone authentication protocol (BSP-IoD) to augment security of IoD network. Leveraging the intrinsic randomness, commutative and invertible properties of BS-PUF, the BSP-IoD ensures construction of mutually agreed session key employing unique challenge-response pairs (CRPs). The scheme could withstand known threats besides supporting perfect forward secrecy and privacy to the user. The BSP-IoD considerably mitigates computational overheads besides ensuring resilience against known attacks including resistance from drone physical capture threat, promoting viability for next generation IoD networks. The formal analysis and performance assessment exhibit that BSP-IoD could address the critical challenges of next generation IoD applications. Furthermore, it supports 56.6% more number of security properties as compared to preceding schemes.
Azeem Irshad, Abdul Jaleel, Abid Mehmood, Gulam Ali Mallah, Ashok Kumar Das, Shehzad Ashraf Chaudhry
IEEE Internet Things J.1
2025 SAC-DeV: Secure Access Control for Drone-Assisted Edge Computing in e-VANETs
abstract
Unmanned Aerial Vehicles (UAVs) are transforming how we manipulate tasks and respond to the challenges by making processes more proficient, safer, economical, and environment friendly. These intelligent UAVs or drones can act as an intermediate node in electric Vehicular Ad hoc Networks (e-VANETs) for relaying weak 5G/beyond 5G communication signals in mountainous terrain. Such aerial assistance could only be feasible if Internet of Things (IoT)-enabled drones are able to establish a secure channel with vehicles or Road Side Unit (RSUs) or edge cloud servers in Internet of Vehicles (IoV) infrastructure. However, drones may be exposed to the physical examination by malicious adversaries that might reveal the vehicle user’s privacy as well as disrupt the network coverage. To effectively assist this role in rural or underdeveloped terrains, this study proposes a secure access control mechanism SAC-DeV for drone-assisted mobile RSU infrastructure to develop a mutually agreed session key after mediating e-vehicular nodes and edge cloud servers. The scheme is immaculately enhanced with Physically Unclonable Function (PUF) circuits in e-vehicles as well as drones to resist physical capture threats. Employing the formal security analysis based on widely known Real-or-Random (RoR) model, the SEC-DeV is proven to be resilient from several threats. The SEC-DeV exhibits enhanced performance in comparison with comparative studies in terms of computational and communication overheads. Moreover, it supports 24% enhanced security features as compared to preceding studies.
Muhammad Usman 0018, Azeem Irshad, Shehzad Ashraf Chaudhry
IEEE Internet Things J.2
2023 SUSIC: A Secure User Access Control Mechanism for SDN-Enabled IIoT and Cyber-Physical Systems
abstract
The integration of thriving information and communications technology (ICT) and cyber–physical systems (CPSs) has spawned several innovative applications, such as remote healthcare, smart and intelligent transportation, smart logistics, smart grids, and public safety. An emerging software-defined networks (SDNs) technology further enabled to optimize the communication among Industrial IoT (IIoT) and CPS entities. Nonetheless, the communication on public channel among different IIoT entities in an SDN-enabled environment may be exposed to various security threats due to wireless and insecure communication channels. To counter these security challenges in the way of wider CPS or IIoT adoption, we propose a novel three-factor authenticated key exchange mechanism (SUSIC) for SDN-enabled IIoT ecosystem. The SUSIC enables a registered user to access real-time data from physical IIoT environment directly after having mutual authentication performed through SDN-enabled controller node. The scheme is proved to be secure under rigorous formal and informal security analysis. Moreover, the simulation results and performance evaluation signifies toward achieving a better tradeoff between security functionalities and computational overheads comparatively.
Azeem Irshad, Gulam Ali Mallah, Muhammad Bilal 0003, Shehzad Ashraf Chaudhry, Muhammad Shafiq 0002, Houbing Song
IEEE Internet Things J.1
2023 Review: a comparative study of state-of-the-art skin image segmentation techniques with CNN
Ghazala Nasreen, Kashif Haneef, Maria Tamoor, Azeem Irshad
Multim. Tools Appl.4
2023 A Lightweight Authentication Scheme for 6G-IoT Enabled Maritime Transport System
abstract
The Sixth-Generation (6G) mobile network has the potential to provide not only traditional communication services but also additional processing, caching, sensing, and control capabilities to a massive number of Internet of Things (IoT) devices. Meanwhile, a 6G mobile network may provide global coverage and diverse quality-of-service provisioning to the Maritime Transportation System (MTS) when enabled through satellite systems. Although modern MTS has gained significant benefits from Internet of Things (IoT) and 6G technologies, threats and challenges in terms of security and privacy have also been grown substantially. Tracking the location of vessels, GPS spoofing, unauthorized access to data, and message tampering are some of the potential security and privacy vulnerabilities in the 6G-IoT enabled MTS. In this article, we propose a lightweight authentication protocol for a 6G-IoT enabled maritime transportation system to efficiently assist and ensure the security and privacy of maritime transportation systems. To validate the security characteristics, formal security assessment methods are utilized, i.e., Real-Or-Random (ROR) oracle model. The findings of the security analysis show that the proposed scheme is more secure than the existing schemes.
Shehzad Ashraf Chaudhry, Azeem Irshad, Muhammad Asghar Khan, Sajjad Ahmad Khan, Summera Nosheen, Ahmad Ali AlZubi, Yousaf Bin Zikria
IEEE Trans. Intell. Transp. Syst.2
2023 MCLA Task Offloading Framework for 5G-NR-V2X-Based Heterogeneous VECNs
abstract
Ensuring dependable quality of service (QoS) and quality of experience (QoE) for computation-intensive and delay-sensitive applications in vehicles can be a challenging task that impacts performance. While multi-access edge computing (MEC) based vehicular edge computing network (VECN) and vehicular cloudlets (VC) enable task offloading, but their prompt and optimal accessibility is another challenge. The conventional wireless technologies may not suffice to meet the stringent ultra-low latency and cost constraints of such applications. Nonetheless, the combination of different wireless technologies can enhance network performance and satisfy these requirements. Focusing on the computational efficacy of VECN, this paper proposes a mobility, contact, and computational load-aware (MCLA) task offloading scheme for heterogeneous VECN. The MCLA scheme dynamically considers the mobility, contact, and computational load of vehicles for making task offloading decisions. To optimize the performance, the MCLA scheme integrates the Mode-1 and Mode-2 of the 5G-NR-V2X standard, along with mmWave communications. The MCLA scheme provides an opportunistic switching mechanism between these modes and heterogeneous radio access technologies (RATs) to reduce communication delays and costs. Moreover, the MCLA scheme leverages public vehicles (i.e., public buses), in proximity by using their computational power to manage computational latency and cost. Furthermore, it also considers the shareable computations from passengers’ mobile equipment within the public vehicle to improve the computation capacity of the public vehicles. Extensive evaluations and numerical results show that the proposed MCLA scheme significantly improves the task turnover ratio by 4%–15% with 4.7%–29.8% lower transmission and computation costs.
Muhammad Ayzed Mirza, Junsheng Yu, Salman Raza, Manzoor Ahmed, Muhammad Asif 0002, Azeem Irshad, Neeraj Kumar 0001
IEEE Trans. Intell. Transp. Syst.6
2021 A secure blockchain-oriented data delivery and collection scheme for 5G-enabled IoD environment
Azeem Irshad, Shehzad Ashraf Chaudhry, Anwer Ghani, Muhammad Bilal 0003
Comput. Networks1
2021 Rotating behind Privacy: An Improved Lightweight Authentication Scheme for Cloud-based IoT Environment
abstract
The advancements in the internet of things (IoT) require specialized security protocols to provide unbreakable security along with computation and communication efficiencies. Moreover, user privacy and anonymity has emerged as an integral part, along with other security requirements. Unfortunately, many recent authentication schemes to secure IoT-based systems were either proved as vulnerable to different attacks or prey of inefficiencies. Some of these schemes suffer from a faulty design that happened mainly owing to undue emphasis on privacy and anonymity alongside performance efficiency. This article aims to show the design faults by analyzing a very recent hash functions-based authentication scheme for cloud-based IoT systems with misunderstood privacy cum efficiency tradeoff owing to an unadorned design flaw, which is also present in many other such schemes. Precisely, it is proved in this article that the scheme of Wazid et al. cannot provide mutual authentication and key agreement between a user and a sensor node when there exists more than one registered user. We then proposed an improved scheme and proved its security through formal and informal methods. The proposed scheme completes the authentication cycle with a minor increase in computation cost but provides all security goals along with privacy.
Shehzad Ashraf Chaudhry, Azeem Irshad, Khalid Yahya, Neeraj Kumar 0001, Mamoun Alazab, Yousaf Bin Zikria
ACM Trans. Internet Techn.2
2021 Fuzzy-in-the-Loop-Driven Low-Cost and Secure Biometric User Access to Server
abstract
Fuzzy systems can aid in diminishing uncertainty and noise from biometric security applications by providing an intelligent layer to the existing physical systems to make them reliable. In the absence of such fuzzy systems, a little random perturbation in captured human biometrics could disrupt the whole security system, which may even decline the authentication requests of legitimate entities during the protocol execution. In the literature, few fuzzy logic-based biometric authentication schemes have been presented; however, they lack significant security features including perfect forward secrecy (PFS), untraceability, and resistance to known attacks. This article, therefore, proposes a novel two-factor biometric authentication protocol enabling efficient and secure combination of physically unclonable functions, a physical object analogous to human fingerprint, with user biometrics by employing fuzzy extractor-based procedures in the loop. This combination enables the participants in the protocol to achieve PFS. The security of the proposed scheme is tested using the well-known real-or-random model. The performance analysis signifies the fact that the proposed scheme not only offers PFS, untraceability, and anonymity to the participants, but is also resilient to known attacks using light-weight symmetric operations, which makes it an imperative advancement in the category of intelligent and reliable security solutions.
Azeem Irshad, Muhammad Usman 0001, Shehzad Ashraf Chaudhry, Ali Kashif Bashir, Alireza Jolfaei, Gautam Srivastava 0001
IEEE Trans. Reliab.1
2018 A secure mutual authenticated key agreement of user with multiple servers for critical systems
Azeem Irshad, Shehzad Ashraf Chaudhry, Saru Kumari, Arun Kumar Sangaiah, Xiong Li 0002, Fan Wu 0003
Multim. Tools Appl.1
2018 An improved and secure chaotic map based authenticated key agreement in multi-server architecture
Azeem Irshad, Shehzad Ashraf Chaudhry, Qi Xie 0001, Saru Kumari, Fan Wu 0003
Multim. Tools Appl.1
2018 An efficient and secure design of multi-server authenticated key agreement protocol
Azeem Irshad, Syed Husnain Abbas Naqvi, Shehzad Ashraf Chaudhry, Shouket Raheem, Saru Kumari, Ambrina Kanwal, Muhammad Usman 0018
J. Supercomput.1
2017 A secure and provable multi-server authenticated key agreement for TMIS based on Amin et al. scheme
Azeem Irshad, Omer Nawaz, Shehzad Ashraf Chaudhry, Imran Khan 0004, Saru Kumari
Multim. Tools Appl.1
2017 Comments on "A privacy preserving three-factor authentication protocol for e-health clouds"
Azeem Irshad, Shehzad Ashraf Chaudhry
J. Supercomput.1
2016 A provably secure anonymous authentication scheme for Session Initiation Protocol
abstract
Abstract Recently, Lu et al. presented a mutual authentication scheme for Session Initiation Protocol. Lu et al. claimed their scheme provides safeguard against familiar attacks and offers efficient authentication facility. However, this paper divulges that the scheme of Lu et al. is prone to server and user impersonation attacks. Additionally, the scheme of Lu et al. implicates correctness concerns. Consequently, an enhanced scheme is proposed, not only to resolve correctness concerns but also to provide robustness against server and user impersonation attacks. The proposed scheme makes use of a user‐specific secret parameter to deal with the security and correctness issues. The formal and informal security analysis proves the robustness and efficiency of the proposed scheme against all familiar attacks. Furthermore, security analysis is also substantiated through popular automated tool PROVERIF. Copyright © 2016 John Wiley & Sons, Ltd.
Shehzad Ashraf Chaudhry, Imran Khan 0004, Azeem Irshad, Muhammad Usman Ashraf, Muhammad Khurram Khan, Hafiz Farooq Ahmad
Secur. Commun. Networks3
2016 An efficient and anonymous multi-server authenticated key agreement based on chaotic map without engaging Registration Centre
Azeem Irshad, Shehzad Ashraf Chaudhry, Syed Husnain Abbas Naqvi, Mohammad Sabzinejad Farash
J. Supercomput.1
2015 An efficient signcryption scheme with forward secrecy and public verifiability based on hyper elliptic curve cryptography
Shehzad Ashraf Chaudhry, Nizamuddin, Anwer Ghani, Syed Husnain Abbas Naqvi, Azeem Irshad
Multim. Tools Appl.6
2015 A single round-trip SIP authentication scheme for Voice over Internet Protocol using smart card
Azeem Irshad, Eid Rehman, Shehzad Ashraf Chaudhry, Anwer Ghani
Multim. Tools Appl.1
2014 A secure authentication scheme for session initiation protocol by using ECC on the basis of the Tang and Liu scheme
abstract
ABSTRACT Session initiation protocol (SIP) provides the basis for establishing the voice over internet protocol sessions after authentication and exchanging signaling messages. SIP is one of the significant and extensively used protocols in the multimedia protocol stack. Since the RFC2617 was put forth, numerous schemes for SIP authentication have been presented to overcome the flaws. Recently, in 2012, Tang and Liu proposed SIP based authentication protocol and claimed for eliminating the threats in Arshad and Ikram protocol. However the scheme can be made more robust by making further improvements, as the former scheme may come under a threat by adversaries through impersonating a server, given that the user password is compromised. We have proposed an improved protocol for SIP authentication by using elliptic curve cryptography that encounters the previous threat with enhanced security. The analysis shows that proposed scheme is suitable for applications with higher security requirements. Copyright © 2013 John Wiley & Sons, Ltd.
Azeem Irshad, Ch. Muhammad Shahzad Faisal, Anwer Ghani, Shehzad Ashraf Chaudhry
Secur. Commun. Networks1
2011 An Algorithm for Prediction of Overhead Messages in Client-Server Based Wireless Networks
Azeem Irshad, Muddesar Iqbal, Amjad Ali 0002, Muhammad Shafiq 0002
ICCSA (4)1