VLDB 2026 Research / reviewers in the wild / expert
Md Yeasin Ali
dblp:386/3519
· DBLP profile ↗
5ranked-venue papers
1as first author
5since 2021 · last 2026
0000-0002-7789-9945ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Secure and Trustworthy Digital Passport System Using Self-Sovereign Identity and Blockchain
Sifat Jahan Sajin, Mohammad Mahmudul Haque Siam, Abdullah Al Anan, Sunjid Ibnul Anim, Md Yeasin Ali, Hossain Shahriar, Md Sadek Ferdous |
COMPSAC | 5 |
| 2026 | Evaluating FIDO2: Security and Cross-Platform Adoption on Various Mobile Devices
Puyuan Sun, Md Yeasin Ali, Hossain Shahriar, Md Sadek Ferdous |
COMPSAC | 2 |
| 2026 | A Passwordless Authentication Mechanism for the Web Using Self-Sovereign IdentityabstractThe traditional protected web services rely on a user authentication process. The combination of an identifier (e.g., username, email address and so on) and credential (e.g., password) still remains the most widely deployed user authentication process, even though such a process is one of the major sources of security breaches. Moreover, in this traditional setting, the management and sharing of user identity information is cumbersome. The consequence of this is that users increasingly find it difficult to manage their identity data scattered across multiple sites and they have limited controls over their own identity data. In recent times, Self-sovereign Identity (SSI) has emerged as a new mechanism for managing and exchanging identity information in a more user-centric and privacy-friendly way. There are many explorations of SSI in different application domains, however, its utility for passwordless authentication for the web mostly remains unexplored. In this article, we present SSI4Web , a framework which can facilitate a passwordless authentication mechanism for the web by employing a state-of-the-art SSI technology for providing web services with much more user control and greater flexibility. We present its architecture which is based on a threat model and requirement analysis, discuss its implementation details and sketch out its use-cases along with protocol flows. In addition, we analyse its performance, evaluate its security using ProVerif , a state-of-the-art protocol verifier and discuss its advantages and limitations. Md Sadek Ferdous, Md Yeasin Ali, Fairuz Rahaman Chowdhury, Md Masum Alam Nahid, Andrei Ionita, Wolfgang Prinz |
ACM Trans. Web | 2 |
| 2025 | Decentralized Access Control using Hyperledger FabricabstractTraditional access control systems often use the extensible access control markup language (XACML), a widely adopted standard for defining and enforcing access control policies. XACML is flexible and compatible with various access control models. It comprises key components such as the Policy Decision Point (PDP), Policy Enforcement Point (PEP), Policy Administration Point (PAP), and Policy Information Point (PIP), which are centrally managed in traditional setups. However, this central management introduces vulnerabilities like Single Point of Failure (SPOF) and other security risks. This research addresses these challenges by proposing a decentralized access control architecture built on Hyperledger Fabric. The design distributes the four core components of XACML— PEP, PDP, PAP, and PIP- across multiple blockchain nodes, eliminating SPOF while enhancing scalability and data integrity. A proof of concept (PoC) implementation is developed to evaluate the system’s performance. The architecture and PoC are analyzed against predefined threats and requirements, demonstrating how the system delivers a secure, scalable, and resilient access control solution. Jubayer Hossain, Mehedi Hasan Nabil, Farhan Labib Jahin, Md Yeasin Ali, Hossain Shahriar, Md Sadek Ferdous |
COMPSAC | 4 |
| 2025 | AuthVR: Securing Authentication Against Shoulder Surfing and Keystroke Inference Attacks using Virtual RealityabstractPasswords serve as the primary authentication mechanism for knowledge-based systems, facilitating user access across a diverse spectrum of applications. Although password-based authentication is commonly employed in high-security environments such as security checkpoints and central control and command systems, it remains susceptible to fraudulent activities, e.g. shoulder-surfing and inference attacks (via direct observation, eavesdropping, or recording) particularly in public or monitored spaces equipped with CCTV cameras. In this paper, we present AuthVR, a Virtual Reality (VR) enabled authentication mechanism creating an additional layer of security in such high-security environments, significantly enhancing existing systems' security. Using Design Science Research Methodology, we assess potential threats and establish the system requirements. We present the architecture, its detailed protocol flow, validate its security through a formal analysis using ProVerif and provide a thorough analysis of the proposal's probable resistance against a number of attack vectors. Additionally, a user study is conducted to evaluate the usability and practical aspects of the system showing a positive impression towards the system. Md Yeasin Ali, Touhid Islam Udoy, Md. Ishmam Tasin, Md Masum Alam Nahid, Fairuz Rahaman Chowdhury, Farida Chowdhury, Md Sadek Ferdous |
TrustCom | 1 |