Khalid Mahmood 0002

dblp:48/1165-2 · DBLP profile ↗
← Back
54ranked-venue papers
11as first author
46since 2021 · last 2026
0000-0001-5046-7766ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 34 · 5 first-author · 32 since 2021Applied, interdisciplinary, general and emerging computing · 11 · 3 first-author · 10 since 2021Security and privacy · 4 · 1 first-author · 2 since 2021Systems, architecture and hardware · 2 · 2 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2026 Evaluating Large Language Models for Implicit Hate Speech Detection
Raza Ul-Mustafa, Mohammad S. Obaidat, Roi Dupart, Khalid Mahmood 0002, Noman Ashraf
ICC4
2026 ATTA-FL-Lite: Lightweight Byzantine-Robust Federated Learning for Resource-Constrained Medical IoT Devices
abstract
Federated learning (FL) enables privacy-preserving analytics at the medical IoT (IoMT) edge but is vulnerable to model poisoning and distribution shift. We presentATTA-FL-Lite, a lightweight aggregation rule that admits a client update only when three tests are jointly satisfied: (i) scale conformity via a median–absolute–deviation (MAD)z-score, (ii) directional alignment via cosine similarity to a coordinate-wise median reference, and (iii) non-degradation via a validation-lossz-score computed on a small, centrally held clean set. If no update passes, a coordinate-wise median fallback is used. We provide sub-Gaussian tail bounds for the loss test and an expected one-step descent bound forL-smooth objectives under benign mean-alignment and an accepted-set composition assumption; the analysis does not require a positive cosine threshold. Experiments on MNIST, Fashion-MNIST, and PathMNIST, under IID and non-IID partitions with up to 40% adversaries across four attack families, show that ATTA-FL-Lite maintains accuracy representatively ≈ 0.78–0.98 across Tiny/Small/Medium CNNs, reliably filters magnitude/noise attacks, and remains competitive against sign-flip. Server runtime scales approximately linearly with the number of participating clients at fixed model and validation sizes. These results indicate that ATTA-FL-Lite offers practical robustness for FL in resource-constrained IoMT deployments without cryptographic overhead or trusted root data beyond a small validation set.
Hafiz Muhammad Sanaullah Badar, Nadeem Iqbal 0003, Khalid Mahmood 0002, Khan Muhammad 0001, Gaojuan Fan, Chongsheng Zhang
IEEE Internet Things J.3
2026 A Lightweight Authentication Scheme for Securing Patient Information in the Internet of Medical Things Environment
abstract
The Internet of Things (IoT) is an evolving paradigm expected to permeate every aspect of human existence. IoT is a growing trend in which numerous devices interconnect with each other to transmit sensitive data. One of its significant application areas is the Internet of Medical Things (IoMT), which promises a contemporary healthcare environment via linked sensors, clinical systems, and wearable medical devices. However, public communication among these devices faces challenges like security, privacy, authentication, and machine learning/modeling attacks. Additionally, most existing schemes are vulnerable to impersonation, denial-of-service, and machine-learning/modeling attacks. Therefore, this article addresses these challenges by designing a lightweight authentication scheme that utilizes a one-time physical unclonable function (OPUF) and elliptic curve cryptography to reduce the likelihood of machine learning/modeling attacks on wearable medical devices. We utilizeOPUFto resist machine learning/modeling attacks. We also employ a rate-limiting mechanism that restricts the number of authentication requests within a specific time window to enhance resistance against denial-of-service (DoS) attacks. Moreover, the devised scheme also offers resistance to impersonation, session key leakage, ephemeral secret leakage, desynchronization, and ML-based modeling attacks. We analyze the security and reliability of the devised scheme using informal and formal analysis. Informal analysis indicates that the scheme offers essential security features, while formal analysis substantiates these findings. In the end, we present the results of the performance analysis, which show that the devised scheme achieves an average reduction of 26.92% and 21.53% in computational and communication costs, respectively.
Wen-Chung Kuo, Zahid Ghaffar, Khalid Mahmood 0002, Tayyaba Tariq, Salman Shamshad, Ashok Kumar Das
IEEE Internet Things J.3
2026 Digital Twin-Enabled Context-Aware Authentication Protocol for IoT-Based Healthcare Applications
abstract
The convergence of Digital Twin (DT) technology with Internet of Things (IoT)-based healthcare systems offers promising capabilities for real-time monitoring, personalized treatment, and predictive diagnostics. However, the integration of context-aware data flows and dynamic device interactions introduces critical security and privacy challenges such as impersonation, desynchronization, and physical tampering attacks. To address these concerns, this paper proposes a lightweight, context-aware authentication protocol using Authenticated Encryption with Associated Data (AEAD), Physical Unclonable Functions (PUFs), and cryptographic hash functions within a DT-enabled framework. The protocol supports mutual authentication and secure key establishment among sensing devices, gateways, and medical servers, while protecting device identities and ensuring data confidentiality and integrity without relying on stored credentials. A key innovation of this work is context enforcement through data-type authorization, where each sensing device is restricted to transmit only predefined categories of physiological data (e.g., temperature, oxygen saturation), thereby achieving fine-grained, semantics-driven access control. Security analysis under the Real-Or-Random (ROR) model confirms the protocol’s resistance to impersonation, desynchronization, replay, and leakage of ephemeral secrets. Performance evaluation demonstrates a 25.85% reduction in computational overhead and a 31.59% reduction in communication cost compared to relevant baseline protocols. These results validate the protocol’s effectiveness for securing resource-constrained, real-time healthcare systems in DT-enabled IoT environments.
Muhammad Asad Saleem, Xiong Li 0002, Khalid Mahmood 0002, Salman Shamshad, Zahid Ghaffar
IEEE Internet Things J.3
2026 A Robust Tamper-Resistant and Location-Aware Authentication Protocol for Securing Charging Services in V2G Environments
abstract
The rapid increase in electric vehicles (EVs) and the widespread deployment of charging stations have made secure authentication a critical requirement in Vehicle-to-Grid (V2G) environments. The growing interconnection among EVs, charging stations, and grid infrastructure introduces serious security and privacy challenges, including impersonation, replay, ephemeral secret leakage, and physical tampering attacks. Although several authentication protocols have been proposed for EV charging services, many existing schemes lack robust tamper-resistant and location-aware authentication capabilities and remain unsuitable for dynamic and resource-constrained V2G conditions. To address these limitations, this paper proposes a robust, tamper-resistant, and location-sensitive authentication protocol for securing EV charging services in V2G environments. The proposed protocol integrates configurable Arbiter Physical Unclonable Functions (A-PUFs) to provide device-level protection against physical tampering and unauthorized charging access. It also employs lightweight cryptographic primitives and techniques, including one-way hash functions, XOR operations, concatenation operations, and timestamp-based freshness verification, to support efficient mutual authentication and secure session key agreement. The security of the proposed protocol is evaluated through informal analysis and formal verification under the Random Oracle Model (ROM). Furthermore, comparative analysis demonstrates that the proposed protocol achieves a 17.16% reduction in communication cost and a 7.49% reduction in average computation cost compared with existing authentication protocols while maintaining strong security features. The results confirm that the proposed scheme enhances the security, efficiency, and practical deployability of EV charging authentication for next-generation V2G networks.
Muhammad Umer 0001, Muhammad Farooq 0004, Syed Asad Naqvi, Khalid Mahmood 0002, Bander A. Alzahrani, Ashok Kumar Das, Shehzad Ashraf Chaudhry
IEEE Internet Things J.4
2026 SarcAE: embedding fusion and fuzzy logic for advanced sarcasm detection
abstract
Sarcasm is employed widely on various social media platforms. Due to the potential for sarcasm to alter the intended meaning of a statement, the opinion analysis technique is susceptible to inaccuracies. Detecting sarcasm is one of the most challenging problems in analyzing sentiment and mining opinions in social media. Therefore, identifying sarcasm is crucial when making informed public opinion decisions. Preliminary research indicates that sarcastic statements alone have a substantial negative impact on the accuracy of automatic sentiment analysis. Several distinct natural language processing strategies have been previously suggested. However, each technique has limits in terms of textual context and proximity, and the accuracy of classifiers is affected by noise in the dataset. This research introduces SarcAE, a unique method for combining feature-level embedding fusion using an autoencoder and fuzzy logic-based reasoning to classify sarcasm. The evaluation experiments used two benchmark datasets: the News Headlines dataset and Ironic Tweet dataset, subjected to several preprocessing techniques. Extensive experiments conducted using the proposed SarcAE approach demonstrate that the proposed method outperforms other fusion models with an accuracy of 98.53% on the News Headlines dataset and 89.83% on the Ironic Tweet dataset, respectively, surpassing baseline methods by up to 3.7%. These results indicate the effectiveness of SarcAE in capturing contextual and semantic cues needed for sarcasm detection.
Ehtesham Safeer, Sidra Tahir, Nagwan Abdelsamee, Khalid Mahmood 0002, Imran Ashraf 0003
Knowl. Inf. Syst.5
2026 Conv-MTD: A CNN Based Multi-Label Medical Tubes Detection and Classification Model to Facilitate Resource-Constrained Point-of-Care Devices
abstract
Computer-aided detection through deep learning is becoming a prevalent approach across various fields, including the detection of anomalies in medical procedures. One such medical procedure involves the placement of medical tubes to provide nutrition or other medical interventions in critically ill patients. Medical tube placement can be highly complex and prone to subjective errors. Malposition of medical tubes is often observed and associated with significant morbidity and mortality. In addition, continuous verification using manual procedures such as capnography, pH testing, auscultation, and visual inspection through chest X-ray (CXR) imaging is required. In this paper, we propose a Conv-MTD, a medical tube detection (MTD) model that detects the placement of medical tubes using CXR images, assisting radiologists with precise identification and categorizing the tubes into normal, abnormal, and borderline placement. Conv-MTD leverages the EfficientNet-B7 architecture as its backbone, enhanced with an auxiliary head in the intermediate layers to mitigate vanishing gradient issues common in deep neural networks. The Conv-MTD is further optimized using post-training 16-bit floating-point (FP16) quantization, which significantly reduces memory consumption by 50% and 2x improvement in inference speed without compromising accuracy. This optimization allows Conv-MTD to achieve efficient performance without requiring high-end computational resources, making it suitable for deployment on point-of-care devices. Conv-MTD provided the best performance, with an average area under the receiver operating characteristic curve (AUC) of 0.95 using the open-source RANZCR CLiP dataset. The proposed Conv-MTD has the potential to operate on resource-constrained point-of-care devices due to its use of FP16 computation, enabling low-cost and automated assessments in various healthcare settings.
Moneeb Abbas, Wen-Chung Kuo, Khalid Mahmood 0002, Waseem Akram 0003, Sajid Mehmood, Ali Kashif Bashir
IEEE J. Biomed. Health Informatics3
2026 PUF-Enabled Key-Exchange Protocol for Vehicular Ad-Hoc Networks
abstract
The Internet of Vehicles (IoV) enables data exchange among individuals, cloud resources, road infrastructures, and vehicles, interconnected through Vehicular Ad Hoc Networks (VANETs). VANETs comprise vehicles with Onboard Units (OBUs), Roadside Units (RSUs), and a Trusted Party Agent (TPA). The data transmission among these entities supports seamless interaction and collaborative traffic management. However, data transmission on public communication channels in VANETs presents significant challenges, including security, privacy, and authentication of participating entities. Although numerous key exchange and authentication protocols have been introduced to tackle these issues, many protocols remain vulnerable to various attacks, such as a vehicle, RSU, TPA impersonation, denial of service, physical cloning, and desynchronization attacks. Therefore, to address these vulnerabilities, we propose a key exchange protocol that leverages hash functions and Advanced Encryption Standard (AES) encryption. Our protocol also integrates the Physical Unclonable Function (PUF), enhancing its resistance to physical or cloning attacks. Additionally, it effectively counters threats like impersonation, session key leakage, ephemeral secret leakage, and desynchronization attacks. We validate the security and reliability of our protocol through both formal and informal analysis. Informal analysis highlights the protocol’s essential security features, while formal analysis provides robust substantiation. Performance evaluation reveals that our protocol achieves an average reduction of 35.53%, and 53.77%, in communication and computation overheads.
Khalid Mahmood 0002, Zahid Ghaffar, Muhammad Farooq 0004, Muhammad Ilyas 0001, Ashok Kumar Das, Shehzad Ashraf Chaudhry
IEEE Trans. Intell. Transp. Syst.1
2026 DroneSec: Efficient and Secure Communication for Resource-Constrained Drones in IoD Systems
abstract
The Internet of Drones (IoD) represents an emerging paradigm of the Internet of Things (IoT), enabling seamless, coordinated communication among drones and integration with other connected systems. This interconnected network enables autonomous decision-making among drones. As this IoD paradigm continues to expand it faces significant challenges due to its reliance on public channel. Therefore, existing methods often suffer from impersonation, cloning, anonymity violation, and fails to offer end-to-end key secrecy. Moreover, they require high computation resources which present challenges of deployment in resource-constrained IoD environment. To address these challenges, we propose a secure and efficient protocol that provides mutual authentication among participating entities. The protocol resists impersonation, cloning, anonymity violation and offers end-to-end key secrecy. The protocol employs Physical Unclonable Function (PUF) and Elliptic Curve Cryptography (ECC), along with a fuzzy extractor, to ensure secure communication. The resilience of the proposed protocol was evaluated through an informal analysis. Its security properties were rigorously verified using formal analysis based on the Real-Or-Random (ROR) model. Evaluation of its performance shows that the proposed protocol outperforms existing solutions, achieving reductions of 20.9% in computation cost and 32.6% in communication overhead. The results demonstrate that the protocol improves security and provides reliability under the evaluated scenarios of IoD systems.
Anum Lodhi, Xiong Li 0002, Muhammad Asad Saleem, Muhammad Ali Lodhi, Khalid Mahmood 0002, Salman Shamshad
IEEE Trans. Netw. Serv. Manag.5
2025 Distributed Trust Authentication via TPM-Bound Credentials and Byzantine Consensus for Secure Vehicular Digital Twin Ecosystems
abstract
Autonomous vehicles (AVs) are transforming transportation systems, necessitating secure digital infrastructures for reliable operation. Vehicular Digital Twin (VDT) networks address AV limitations by enabling synchronized virtual replicas. However, intra-twin communications over public channels expose systems to severe security threats, including impersonation and data tampering. This paper proposes EDTAP-VDT: an Enhanced Distributed Trust Authentication Protocol for VDT networks, which ensures secure identity verification through a threshold cryptographic model anchored in hardware. The protocol employs a hierarchical edge-fog-cloud architecture to balance authentication loads and leverages Trusted Platform Modules (TPMs) to cryptographically bind credentials. Post-quantum secure primitives and a permissioned blockchain with Byzantine consensus ensure long-term security, pseudonymity, and immutable authentication traceability. Attribute-based access control is integrated into the authentication process for fine-grained data sharing. EDTAP-VDT guarantees confidentiality, forward secrecy, and desynchronization resilience while maintaining decentralized control. The protocol is formally validated using the Random Oracle Model, and additional resistance is demonstrated against active and passive attack vectors. Performance evaluation across realistic vehicular settings shows that EDTAP-VDT achieves up to 24% improvement in computational efficiency and up to 22% reduction in communication overhead compared to state-of-the-art alternatives while fulfilling all standard security attributes. The results establish EDTAP-VDT as a future-ready authentication framework for real-time, secure VDT applications in intelligent transportation environments.
Mohammad Hossein Anisi, Mohammad S. Obaidat, Khalid Mahmood 0002, Shafiq Ahmed
GLOBECOM3
2025 BioElectra-BiLSTM-Dual Attention classifier for optimizing multilabel scientific literature classification
abstract
Abstract Scientific literature is growing in volume with time. The number of papers published each year by 28 100 journals is 2.5 million. The citation indexes and search engines are used extensively to find these publications. An individual receives many documents in response to a query, but only a few are relevant. The final documents lack structure due to inadequate indexing. Many systems index research papers using keywords instead of subject hierarchies. In the scientific literature classification paradigm, various multilabel classification methods have been proposed based on metadata features. The existing metadata-driven statistical measures use bag of words and traditional embedding techniques, like Word2Vec and BERT, which cannot quantify textual properties effectively. In this paper, we try to solve the limitations of existing classification techniques by unveiling the semantic context of the words using an advanced transformer-based recurrent neural networks (RNN) approach incorporating Dual Attention and layer-wise learning rate to enhance the classification performance. We propose a novel model, BioElectra-BiLSTM-Dual Attention that extracts the semantic features from the titles and abstracts of the research articles using BioElectra-encoder and then BILSTM layer along with Dual Attention label embeddings their correlation matrix and layer-wise learning rate strategy employed for performance enhancement. We evaluated the performance of the proposed model on the multilabel scientific literature LitCovid dataset and the results suggest that it significantly improves the macro-F1 and micro-F1 score as compared to the state-of-the-art baselines (ML-Net, Binary Bert, and LitMCBert).
Muhammad Inaam ul haq, Qianmu Li, Khalid Mahmood 0002, Ayesha Shafique, Rizwan Ullah
Comput. J.3
2025 A Contextual Aware Enhanced LoRaWAN Adaptive Data Rate for mobile IoT applications
Muhammad Ali Lodhi, Lei Wang 0005, Arshad Farhad, Khalid Ibrahim Qureshi, Jenhui Chen, Khalid Mahmood 0002, Ashok Kumar Das
Comput. Commun.6
2025 Provably Secure Efficient Key-Exchange Protocol for Intelligent Supply Line Surveillance in Smart Grids
abstract
Intelligent supply line surveillance is critical for modern smart grids (SGs). Smart sensors and gateway nodes are strategically deployed along supply lines to achieve intelligent surveillance. They collect data continuously and transmit it to the control centre in real-time. It enables real-time monitoring, fault detection, and efficient energy management across distribution networks. This advanced surveillance system ensures continuous monitoring of supply lines, detecting anomalies, and optimizing operations to maintain the stability and reliability of the SG. However, the reliance of all participating nodes on public communication channels to transmit supply line surveillance data exposes these systems to critical cyber attacks. These cyber attacks include impersonation, physical tampering, ephemeral secret leakage (ESL), and desynchronization attacks. To address these issues, existing key-exchange protocols often fail to ensure robust security while imposing high computation and communication overheads, limiting their practicality for resource-constrained environments. Therefore, we propose a secure and efficient key exchange and tamper-resistant authentication protocol using elliptic curve cryptography (ECC) and physical unclonable functions (PUFs). The PUF mechanism provides robust resistance against physical tampering and cloning attacks, ensuring enhanced physical security for supply line devices. We validate the security robustness of the devised protocol using the random or real (ROR) model. Furthermore, informal security analysis demonstrates the protocol’s robustness in rigorously resisting various attacks, including physical tampering, impersonation, ESL and desynchronization. Moreover, we determine the performance evaluation that reveals the protocol’s superior efficiency compared to competing protocols, achieving significant reductions of 28.64% in computation overhead and 9.96% in communication overhead.
Muhammad Faizan Ayub, Xiong Li 0002, Khalid Mahmood 0002, Mohammed J. F. Alenazi, Ashok Kumar Das
IEEE Internet Things J.3
2025 A Robust Key Exchange and Tamper-Resistant Protocol for HAN and NAN Networks in Smart Grids
abstract
Smart grids (SGs) rely on home area networks (HANs) and neighborhood area networks (NANs) to ensure efficient power distribution, real-time monitoring, and seamless communication between smart devices. Despite these advantages, the use of public communication channels in HAN and NAN networks introduces critical challenges, such as vulnerability to impersonation, physical tampering, and scalability issues in resource-constrained environments. These issues compromise the stability, reliability, and security of SG environments. Existing protocols often fail to adequately address these challenges, particularly in ensuring resistance to physical tampering of supply lines and impersonation attacks. Additionally, they struggle to minimize the computation, communication, and energy costs associated with securing a resource-constrained SG environment. Therefore, we propose a robust key exchange and tamper-resistant protocol for HAN and NAN networks to address these limitations. The proposed protocol leverages the physical unclonable function (PUF) mechanism to offer physical tampering resistance to smart meters. We validate our protocol formally using the Random or Real (RoR) model, which confirms its security robustness. Additionally, our informal security analysis highlights the protocol’s resilience against impersonation, physical tampering attacks, etc. We analyze and compare the performance of the proposed protocol, which further demonstrates our protocol’s effectiveness and security compared to competing protocols. Moreover, the proposed protocol achieves resource efficiency with 45.99% and 58.85% substantial reductions in computation overhead and energy overhead, respectively, compared to competing protocols. These results showcase the protocol’s enhanced security and practicality for resource-constrained SG environments.
Muhammad Faizan Ayub, Xiong Li 0002, Khalid Mahmood 0002, Salman Shamshad, Ashok Kumar Das
IEEE Internet Things J.3
2025 AI-Enhanced Resource Allocation for LPWAN-Based LoRaWAN:A Hybrid TinyML and Deep Learning Approach
abstract
The integration of Artificial Intelligence (AI) with Low Power Wide Area Networks (LPWAN) offers a promising approach to address resource constraints and dynamic network conditions inherent in these networks. However, deploying complex AI algorithms on resource-limited edge devices presents significant challenges due to their limited computational capabilities. In this study, we propose a hybrid Tiny Machine Learning (TinyML) and Deep Neural Network (DNN)-based solution for optimizing resource allocation in LPWAN-based LoRaWAN networks, targeting both static and mobile applications. Our approach leverages the strengths of a 1-D Convolutional Neural Network (CNN) and Long Short-Term Memory (LSTM) model implemented on the network server, combined with TinyML models deployed on edge devices. The CNN-LSTM model predicts optimal spreading factor and transmission power by analyzing spatial and temporal patterns from real-time data, while the TinyML models enable edge devices to autonomously adjust communication parameters in resource-constrained and disconnected scenarios. This hybrid framework enhances network performance by improving the packet success ratio (PSR), maximizing energy efficiency, and addressing the challenges posed by dynamic IoT environments.
Muhammad Ali Lodhi, Xiaobing Sun 0001, Khalid Mahmood 0002, Anum Lodhi, Youngho Park 0005, Majid Hussain
IEEE Internet Things J.3
2025 A Cost-Effective Key Agreement Encryption Protocol for Securing IIoT-Enabled WSN Communication
abstract
Wireless sensor networks (WSNs), pivotal in the industrial Internet of Things (IIoT), encompass resource-limited sensor nodes, users, and gateways. Advancements in Internet technologies have substantially facilitated remote data access, rendering WSNs indispensable across various sectors, such as defense, agriculture, disaster management, and healthcare, where they serve as pivotal components for remote monitoring and control mechanisms. Within the IIoT framework, the transmission of critical and sensitive information over public channels presents significant security challenges. Such challenges disrupt operations and compromise the integrity and reliability of industrial processes. The system must include an authentication mechanism to tackle this critical issue that resists potential security threats. Consequently, this article introduced a reliable and secure the three-factor authentication protocol tailored for IIoT environments. The proposed protocol aims to mitigate unauthorized access and safeguard the integrity of industrial operations. We comprehensively evaluated the protocol’s robustness and security efficiency by employing informal and formal security analysis techniques, highlighting its effectiveness in resisting potential threats. This proposed protocol fortifies the network against potential security threats, ensuring security and system reliability in industrial applications. This protocol assists only legitimate users in accessing the sensing devices remotely. Moreover, the statistical results endorse the resource efficiency of the devised protocol as it achieves 43.2% and 35.8% efficiency in terms of communication and computational costs, respectively.
Khalid Mahmood 0002, Mah Noor Fatima, Salman Shamshad, Zahid Ghaffar, Ashok Kumar Das, Mohammed J. F. Alenazi
IEEE Internet Things J.1
2025 A Privacy-Preserving Access Control Protocol for Consumer Flying Vehicles in Smart City Applications
abstract
The Internet of Drones (IoD) offers supervised admittance to drones in a targeted fly zone as the byproduct of the Internet of Things (IoT). The term drone is the trendy alias for intelligent flying vehicle (IFV). The contemporary sensing, processing, and connectivity services enrich the use of drones in many civilian and military applications. In these applications, consumers can acquire real-time information directly from flying drones in a smart city environment. While this feature undeniably empowers consumers, it poses significant security risks due to the direct access privilege. We propose an anonymous protocol for consumer flying vehicles within smart city applications to mitigate these threats. The proposed protocol utilizes a physically unclonable function to sustain the physical security of flying vehicles. We ratify our protocol’s security fortitude and persistence through inclusive security analysis. We demonstrate the performance evaluation under diverse performance metrics, which shows that the proposed protocol achieves 40.69% and 17.91% efficiency as compared to related protocols in terms of computation and communication cost comparison, respectively.
Khalid Mahmood 0002, Zahid Ghaffar, Lata Nautiyal, Muhammad Wahid Akram, Ashok Kumar Das, Mohammed J. F. Alenazi
IEEE Internet Things J.1
2025 Real-Time Road Damage Detection Using an Optimized YOLOv9s-Fusion in IoT Infrastructure
abstract
In IoT-enabled smart infrastructure, accurate and real-time road damage detection is crucial for enhancing road safety and optimizing maintenance processes. However, detecting road damage in complex and dynamic environments presents significant challenges, such as varying lighting conditions, diverse damage types, and the need for fast processing to enable real-time decision-making. This study introduces an advanced approach utilizing the YOLOv9s-Fusion model to overcome these challenges. Leveraging the RDD2022 dataset, which comprises 1976 annotated images of road damage from China, we employ comprehensive data preprocessing to create optimal conditions for model training. The YOLOv9s-Fusion model integrates innovative features, including a Transformer-based auxiliary module and enhanced feature extraction layers, specifically designed to detect fine-grained damage patterns accurately. Experimental results demonstrate that the model outperforms existing approaches, achieving notable improvements in mean average precision (mAP) and F1-score. Ablation studies further validate the impact of our modifications, highlighting the model’s robustness in real-time detection across diverse conditions. This IoT-centric approach sets a new standard for autonomous road damage detection, significantly advancing vehicle navigation and smart infrastructure management capabilities.
Khan Muhammad 0001, Mohammad S. Obaidat, Khalid Mahmood 0002, Balqies Sadoun, Hafiz Muhammad Sanaullah Badar, Wu Gao
IEEE Internet Things J.3
2025 Provably Secure Authenticated Key-Management Mechanism for e-Healthcare Environment
abstract
The Internet of Things (IoT) is rapidly permeating all aspects of human life, involving a network of devices that share sensitive data. A notable application is the e-healthcare systems, which employ connected sensors, medical servers, and wearable devices. However, the public nature of communication in e-healthcare systems poses challenges such as security, privacy, and authentication of participating entities. Recently, many authentication protocols have been introduced to address these challenges. However, most of these protocols remain vulnerable to various security attacks, including device or medical server impersonation, denial of service, physical or cloning, and de-synchronization attacks. Therefore, we introduce an authenticated key-management protocol utilizing hash functions and Cipher-Block Chaining-Advanced Encryption Standard encryption (CBC-AES) encryption. The proposed protocol also employs the Physical Unclonable Function (PUF), which makes it more robust and efficient in resisting physical or cloning attacks. Additionally, the proposed scheme resists various security threats, including impersonation, session key leakage, ephemeral secret leakage, and de-synchronization attacks. We analyze the scheme’s security and reliability through formal and informal analysis. The informal analysis demonstrates that the scheme encompasses crucial security features, while the formal analysis substantiates. Moreover, performance analysis of the proposed protocol with various competing results indicates that our protocol achieves an average reduction in communication and computation overheads by 36.03.% and 41.79%, respectively.
Muhammad Asad Saleem, Xiong Li 0002, Khalid Mahmood 0002, Zahid Ghaffar, Yong Xie 0003
IEEE Internet Things J.3
2025 A Lightweight Authentication Protocol for RFID-Assisted Supply Chain Management System
abstract
In the evolving landscape of supply chain management, the integration of radio-frequency identification (RFID) technology has marked a significant milestone. This development has led to the emergence of a new system in RFID-based supply chain management, which is intricately linked with the advances in the Internet of Things (IoT). RFID technology employs electromagnetic fields to identify and track tags on objects and revolutionizes the management and tracking of items in the supply chain. However, the public communication among RFID tags, RFID readers, and supply chain infrastructure predominantly escalates security and privacy challenges. Several authentication protocols have been proposed to overcome these challenges. However, the vulnerability of most proposed protocols to numerous security attacks renders them inefficient. Therefore, to address these crucial challenges, we devised an RFID-based authentication protocol for supply chain management systems. The incorporation of a physically unclonable function (PUF) into the protocol fortifies the system against physical tampering attacks. To validate the security and effectiveness of the devised protocol, both informal and formal security analysis are conducted. The formal security analysis is conducted using the widely used random oracle model. The informal security analysis reveals that the devised protocol provides enhanced and efficient security features. Furthermore, we perform a comparative analysis with related protocols, focusing on critical performance metrics like communication cost, computation cost, and overall security features. The results of the comparative analysis are promising, indicating a substantial 30.92% reduction in computational cost and a 23.98% reduction in communication cost in comparison to related protocols, thus highlighting the protocol’s superior performance and resource efficiency.
Tayyaba Tariq, Wen-Chung Kuo, Khalid Mahmood 0002, Salman Shamshad, Ashok Kumar Das, Mohammed J. F. Alenazi
IEEE Internet Things J.3
2025 TFedSec-HI: Transformer-Driven Federated Security for IoT-Enabled Healthcare Industry 5.0 on Non-IID Data
abstract
The Internet of Things (IoT) enhances the healthcare industry 5.0 by enabling connected devices and data-driven treatments, but it also introduces cyber threats such as data breaches, and unauthorized access. Mobile Edge Computing (MEC) improves security by reducing reliance on cloud transmissions. However, challenges such as Non-Independent and Identically Distributed (Non-IID) data and device intermittency affect security models in healthcare that require real-time analytics and reliable automation. These limitations are crucial in sensitive medical applications that require real-time analytics and reliable automation. This paper proposes TFedSec-HI, a Transformerdriven Federated Learning (TFL) for improving threat detection in the healthcare industry 5.0. Network traffic data is converted to grayscale and multi-channel RGB images using Local Binary Patterns (LBP) and Sobel edge detection. A lightweight mobile Vision Transformer (ViT) is used for effective feature extraction on edge devices, reducing computational load while retaining high performance. The Federated Proximal (FedProx) algorithm is used during the model aggregation phase to address issues with non-IID data distribution, resulting in consistent and effective learning. The global model is then shared with clients for realtime threat classification. The proposed method is evaluated on two real-world datasets, CICIoT2023 and CICIoMT2024, resulting in exceptional classification accuracies of 99.18% and 99.74%, respectively. TFedSec-HI addresses the Non-IID data challenges in Industry 5.0 healthcare by utilizing TFL to enable private, and adaptive threat detection across medical IoT devices.
Yue Zhao 0014, Farhan Ullah 0001, Khalid Mahmood 0002, Jawad Ahmad 0001, Ali Kashif Bashir, Nazik Alturki
IEEE Internet Things J.3
2025 QoE of 2D and 360° Video: Insights from 5G Radio Metrics
Raza Ul-Mustafa, Sesha Dassanayak, Noman Ashraf, Abid Rafiq, Khalid Mahmood 0002, Nazik Alturki, Ali Kashif Bashir
Mob. Networks Appl.5
2025 A Lightweight and Robust Access Control Protocol for IoT-Based e-Healthcare Network
abstract
Internet of Things (IoT) devices are crucial components in e-healthcare networks. It enables remote patient health monitoring and facilitates seamless communication among medical sensors, wearable devices, and healthcare providers through public communication channels. Despite these advantages, the use of public communication among medical sensors in e-healthcare networks introduces critical challenges, such as vulnerability to impersonation, physical capture, and ephemeral secret leakage, particularly in resource-constrained environments. In recent years, various access control protocols have been developed to mitigate these risks. However, these protocols often fail to ensure robust security while incurring significant communication and computation overhead. To overcome these limitations, we propose a lightweight and robust access control protocol for IoT-based e-healthcare networks using chaotic maps. We propose a novel protocol that integrates a PUF-based mechanism to mitigate the challenges of physical tampering and cloning attacks in e-healthcare networks. It leverages the inherent uniqueness of PUF and enhances security through the high-entropy properties of chaotic maps. We analyze the proposed protocol informally, which confirms that it significantly bolsters efficiency and security. We also validate the security using the Random or Real (RoR) model. Moreover, we verify the security of the proposed protocol using Scyther. These analyses highlight that the proposed protocol offers robust resistance to numerous attacks, such as impersonation, physical capture, and ephemeral secret leakage. Moreover, we also compare it with existing and relevant protocols. The comparative analysis showcases its superior performance. Notably, the proposed authentication protocol significantly reduces 46.84% computational overhead and decreases 31.30% communication overhead, underscoring its enhanced performance and resource efficiency.
Zahid Ghaffar, Wen-Chung Kuo, Khalid Mahmood 0002, Tayyaba Tariq, Salman Shamshad, Ashok Kumar Das, Mohammed J. F. Alenazi
IEEE Trans. Mob. Comput.3
2024 Towards classification and comprehensive analysis of AI-based COVID-19 diagnostic techniques: A survey
Amna Kosar, Muhammad Asif 0002, Maaz Bin Ahmad, Waseem Akram 0003, Khalid Mahmood 0002, Saru Kumari
Artif. Intell. Medicine5
2024 Provably secure fog-based authentication protocol for VANETs
Syed Muhammad Awais, Wu Yucheng, Khalid Mahmood 0002, Hafiz Muhammad Sanaullah Badar, Rupak Kharel, Ashok Kumar Das
Comput. Networks3
2024 Online Fault Diagnosis of Industrial Robot Using IoRT and Hybrid Deep Learning Techniques: An Experimental Approach
abstract
The Internet of Robotic Things (IoRT) is growing rapidly with new applications. Co-operatory robotics enables the sharing of information, autonomy, and fail-safe interaction with environment, humans, and other robots. They can also self-maintain, self-aware, and self-heal. To provide reliable and robust online monitoring of the industrial manipulator joint status, this article proposes a new IoRT architecture based on transfer learning (TL) techniques to detect manipulator fault. Robotic manipulator joint status are detected with high accuracy using a hybrid 1-D multichannel convolutional neural network (1D-MCNN), including matrix kernels and recurrent neural network (MCNN-RNN) technique. Moreover, a timestamp mapping method addresses the challenges associated with inconsistencies in sensor data timestamps. Existing data-driven methods struggle with the diverse operating conditions of industrial robots, where load and speed constantly fluctuate. To address this limitation, we propose a novel TL-based MCNN-RNN approach for joint fault diagnosis under varying work conditions. This method leverages the adaptability of TL while incorporating the inherent relations between different failure modes, enhancing the TL process. To demonstrate the performance of the suggested IoRT topology, various experimental scenarios are performed with data acquisition on six degree-of-freedom (DOF) UR16e (universal robot) manipulator. Based on the results, the proposed IoRT architecture can effectively visualize the joint fault status of the manipulator. As a result, TL architecture combined with MCNN-RNN provides an excellent accuracy of 99.03%in detecting faults on manipulator joints, which is significantly higher than traditional convolutional neural network (CNN), deep belief network (DBN), domain adversarial neural network (DANN), and conditional domain-adversarial network (CDAN).
Hazrat Bilal, Mohammad S. Obaidat, Muhammad Shamrooz Aslam, Jing Zhang 0015, Baoqun Yin, Khalid Mahmood 0002
IEEE Internet Things J.6
2024 Tiny Machine Learning for Efficient Channel Selection in LoRaWAN
abstract
Machine learning (ML) has emerged as a promising avenue for enhancing the efficiency and intelligence of channel allocation processes. However, deploying ML algorithms on resource-constrained edge devices poses significant challenges due to their limited computational capabilities and storage capacities. In this study, we propose leveraging tiny ML (TinyML) techniques to address these challenges and optimize channel allocation within long range wide area network (LoRaWAN) deployments. Our key innovation lies in replacing traditional random channel allocation methods with TinyML-based approaches, wherein each edge device autonomously utilizes TinyML to select the most efficient channel prior to each uplink transmission. Furthermore, we conduct comprehensive comparisons between TinyML and conventional channel allocation techniques implemented on edge devices. Through extensive simulations, our results demonstrate that TinyML outperforms existing channel allocation mechanisms in terms of packet success ratio (PSR). Notably, when evaluating TinyML against conventional ML approaches in terms of model size and inference time, TinyML exhibits superior performance without compromising efficiency.
Muhammad Ali Lodhi, Mohammad S. Obaidat, Lei Wang 0005, Khalid Mahmood 0002, Khalid Ibrahim Qureshi, Jenhui Chen, Kuei-Fang Hsiao
IEEE Internet Things J.4
2024 A Security Enhanced Chaotic-Map-Based Authentication Protocol for Internet of Drones
abstract
The Internet of Drones (IoD) extends the capabilities of unmanned aerial vehicles, enabling them to participate in a connected network. In IoD infrastructure, drones communicate not only among themselves but also with users and a control center. This interconnected communication framework holds promise for various applications, from collaborative decision-making to real-time data exchange. However, the expansion of communication in IoD also introduces new challenges, particularly in terms of security, privacy and authentication. Unfortunately, the current authentication protocols are inadequate in offering robust security features against various attacks in the IoD environment. To address these security issues and limitations, we proposed a secure protocol for the IoD environment using chaotic maps and hash functions. In addition, we also employed a physically unclonable function in the development of the proposed protocol. We assess the security of the protocol through both informal and formal security analysis. The formal security analysis is conducted through a widely used random or real (RoR) model. The informal analysis shows the rigorous security features against various attacks, such as masquerading, anonymity violation, and physical cloning attacks. Moreover, we compare the performance of the devised protocol with similar existing protocols across important performance parameters such as communication overhead, computation overhead, and security features. The devised protocol provides a 67.86% and 17.80% reduction in computation and communication overheads, respectively, as compared to related protocols. The analysis demonstrates the proposed protocol’s capacity to support secure communication in the IoD environment and satisfy desirable security attributes.
Khalid Mahmood 0002, Zahid Ghaffar, Muhammad Farooq 0004, Khalid Yahya, Ashok Kumar Das, Shehzad Ashraf Chaudhry
IEEE Internet Things J.1
2024 Cost-Effective Authenticated Solution (CAS) for 6G-Enabled Artificial Intelligence of Medical Things (AIoMT)
abstract
The Internet of Things (IoT) is a network of interconnected objects, which congregate and exchange gigantic amounts of data. Usually, pre-deployed embedded sensors sense this massive data. Soon, several applications of IoT are anticipated to exploit emerging 6G technology. Healthcare is one of them, where the 6G-inspired paradigm may facilitate the users to exchange information through hundreds of sensors under the assumption of Artificial Intelligence of Things (AIoT). Integration of medical sensors with AIoT is known as Artificial Intelligence of Medical Things (AIoMT). The secure and seamless interactions among 6G-enabled AIoMT users should be the primary challenge. Furthermore, resource-constrained wearable sensing devices, with their inability to execute complex security solutions, provide an ideal attraction for malicious entities to launch diverse attacks. These challenges have motivated us to design a cost-effective authenticated solution (CAS) for 6G-enabled AIoMT healthcare applications. Our CAS protocol not only prevents cyber threats like impersonation session key secrecy, but it can also prevent physical threats like hardware tampering. We observe formal and informal security validations to endorse its robustness and effectiveness. Performance comparison reveals that CAS protocol offers maximum security enrichment. Moreover, CAS is cost-effective as it has achieved 33% and 60% reduction in computation and communication overheads, respectively, compared to contemporary competing related protocols.
Khalid Mahmood 0002, Mohammad S. Obaidat, Salman Shamshad, Mohammed J. F. Alenazi, Gulshan Kumar, Mohammad Hossein Anisi, Mauro Conti
IEEE Internet Things J.1
2024 Real-Time Road Damage Detection and Infrastructure Evaluation Leveraging Unmanned Aerial Vehicles and Tiny Machine Learning
abstract
Road damage detection (RDD) through computer vision and deep learning techniques can ensure the safety of vehicles and humans on the roads. Integrating unmanned aerial vehicles (UAVs) in RDD and infrastructure evaluation (IE) has also emerged as a key enabler, contributing significantly to data acquisition and real-time monitoring of road damages such as potholes, cracks, and surface anomalies, facilitating proactive maintenance and improved road conditions. These UAVs are low-powered and resource-constrained devices that work autonomously to perform pattern detection and decision-making leveraging tiny machine learning (Tiny ML) algorithms. These Tiny ML algorithms are designed to run on edge devices, IoT devices, UAVs, etc. In this study, the RDD2022 dataset collected using UAVs and dashboard cameras of vehicles was utilized to train pure and mixed models that exhibit class instance imbalance in certain classes which is addressed by implementing data augmentation as a regularization technique. State-of-the-art two-stage detectors; Faster R-CNN ResNet101 and one-stage detectors; SSD MobileNet V1 FPN, YOLOv5, and Efficientdet D1 are employed. The results indicate that the two-stage detector achieved an impressive mAP of 88.49% overall and 96.62% for focused classes. Notably, the state-of-the-art Efficientdet D1 approach achieved a competitive mAP of 86.47% overall and 95.12% for focused classes, with significantly lower computational cost. These findings highlight the potential of advanced object detection techniques, particularly Efficientdet D1, to enhance the accuracy and efficiency of RDD systems, thereby improving passenger safety and overall performance.
Khan Muhammad 0001, Mohammad S. Obaidat, Khalid Mahmood 0002, Dania Batool, Hafiz Muhammad Sanaullah Badar, Muhammad Aamir 0002, Wu Gao
IEEE Internet Things J.3
2024 Provably Secure and Lightweight Authentication and Key Agreement Protocol for Fog-Based Vehicular Ad-Hoc Networks
abstract
The increase in popularity of vehicles encourages the development of smart cities. With this advancement, vehicular ad-hoc networks, or VANETs, are now frequently utilized for inter-vehicular communication to gather data regarding traffic congestion, vehicle location, speed, and road conditions. Such a public network is open to various security risks. Overall, protecting personal information on VANET is a vital responsibility. The integration of fog computing and VANETs has gained significant importance in recent years, driven by advancements in cloud computing, Internet of Things (IoT) technologies, and intelligent transportation systems. However, ensuring secure communication in fog-based VANETs remains a major challenge. To overcome this challenge, we introduce a novel authenticated key agreement protocol that achieves mutual authentication, generates a secure session key for secret communication, and provides privacy protection without the use of bilinear pairing. We rigorously prove the security of our proposed protocol, which is designed specifically for fog-based VANETs, and has been shown to meet their stringent security requirements. Moreover, we performed formal and informal analysis that shows our proposed protocol is highly efficient,our protocol’s computational and communication overhead are lower than those of other relevant protocols by 45.570% and 29.432%, respectively. Finally we use NS-3 simulation to prove that our proposed algorithm is a practical and scalable solution for secure communication in fog-based VANETs.
Syed Muhammad Awais, Yucheng Wu 0001, Khalid Mahmood 0002, Mohammed J. F. Alenazi, Ali Kashif Bashir, Ashok Kumar Das, Pascal Lorenz
IEEE Trans. Intell. Transp. Syst.3
2024 A Cost-Efficient Anonymous Authenticated and Key Agreement Scheme for V2I-Based Vehicular Ad-Hoc Networks
abstract
The rise of smart cities is directly connected to the increasing use of vehicles. The growing vehicle utilization has driven the emergence of Vehicular Ad-hoc Networks (VANETs), facilitating instant information exchange among vehicles. The system provides essential information regarding road conditions, traffic patterns, and more relevant data. VANETs encompass two fundamental categories of communication exchanges, namely Vehicle-to-Vehicle (V2V) and Vehicle-to-Infrastructure (V2I). V2I technology facilitates the integration of cars and transportation infrastructure, enabling effective communication between vehicles and infrastructure. Nevertheless, the potential of V2I communication has various security concerns arising from prevalent security threats. Current authentication techniques encounter challenges regarding complexity, security, and privacy considerations. We designed a hash-based lightweight and anonymous authentication scheme to address the aforementioned restrictions and enhance the effectiveness of authentication in V2I architecture. This scheme effectively combines identity, password, and bio-metric to enhance resistance against impersonation, denial of service, and privileged insider attacks. The devised scheme distinguishes itself by a comparative analysis and security proofs, highlighting its superior capability in guaranteeing secure authentication in V2I communication. The comprehensive security analysis conducted formally and informally showcases the robustness of the proposed solution against several threats. The performance evaluation results show that our scheme demonstrates a decrease in the computational cost of 51.40% approximately and a reduction in communication overhead of around 22.57%. These results establish the efficiency and scalability of the proposed scheme as a viable solution for V2I architecture.
Muhammad Asad Saleem, Xiong Li 0002, Khalid Mahmood 0002, Salman Shamshad, Mohammed J. F. Alenazi, Ashok Kumar Das
IEEE Trans. Intell. Transp. Syst.3
2024 Secure RFID-Assisted Authentication Protocol for Vehicular Cloud Computing Environment
abstract
Vehicular network technology has made substantial advancements in recent years in the field of Intelligent Transportation Systems. Vehicular Cloud Computing (VCC) has emerged as a novel paradigm with a substantial increase in data exchange within Vehicular ad-hoc networks (VANETs). VCC integrates cloud computing, vehicular networking, and Internet of Things (IoT) technologies. It enables Infrastructure-to-Vehicle (I2V), Vehicle-to-Vehicle (V2V), and Vehicle-to-Device (V2D) communication. VCC optimizes vehicle, cloud infrastructure, and IoT resources while addressing significant communication security and vehicle-user privacy challenges. To address these issues, we developed an RFID-based authentication protocol for VCC based on a Henon map using a hash function. In addition, we also incorporated a Physical Unclonable Function (PUF) to resist physical tampering attacks. We validate the protocol’s security formally and informally. The formal security analysis is conducted through a widely used RoR model. We use the Scyther simulation tool to verify the proposed protocol’s security against various attacks. Moreover, we compare the performance of our protocol with similar existing protocols across important performance parameters such as communication and computation overheads and security attributes. The proposed protocol yields substantial improvements, demonstrating a 40.74% reduction in computation overhead and a 13.03% decrease in communication overhead as compared to related protocols, delivering both enhanced performance and resource efficiency. The analysis demonstrates its capacity to support secure communication in the VCC environment and satisfy desirable security attributes.
Muhammad Asad Saleem, Xiong Li 0002, Khalid Mahmood 0002, Tayyaba Tariq, Mohammed J. F. Alenazi, Ashok Kumar Das
IEEE Trans. Intell. Transp. Syst.3
2023 A Provably Secure and Lightweight Access Control Protocol for EI-Based Vehicle to Grid Environment
abstract
The energy Internet (EI) presents a novel paradigm for renewable energy distribution that utilizes communication and computing technologies to revolutionize the conventional intelligent transportation systems (ITSs) and power grid into a structure that provides assistance to open innovation. The EI offers sustainable and bidirectional transmission for the improvement and analysis of energy convention among electric vehicles (EVs) and service providers. To ensure efficient, reliable, and secure operation, EI must be safe from security attacks. Therefore, efficient and secure key negotiation is a significant issue for the EI-based Vehicle-to-Grid (V2G) architecture. Thus, to ensure the system’s security, we have devised a robust scheme to facilitate a secure key agreement between the entities involved for the secure and efficient renewable energy distribution for the EI-based energy vehicles in V2G. The devised scheme’s robustness is solicited through the widely accepted formal random or real (RoR) model. In addition, the informal security analysis is conducted on the devised scheme, which is evident that the designed scheme achieves all the required security features of EI-based ITS. Moreover, the performance evaluation results endorse that the designed scheme achieves the desired security and minimizes the communication, computation, and energy overhead by 29.33%, 27.94%, and 28.08% in comparison to the existing competitive schemes.
Salman Shamshad, Khalid Mahmood 0002, Usman Shamshad, Ibrar Hussain 0001, Shafiq Hussain, Ashok Kumar Das
IEEE Internet Things J.2
2023 A Provably Secure Lightweight Key Agreement Protocol for Wireless Body Area Networks in Healthcare System
abstract
Wireless Body Area Network (WBAN) is a vital application of the Internet of Things (IoT) that plays a significant role in gathering a patient's healthcare information. This collected data helps special professionals like doctors or physicians analyze patients' health status to cure different diseases. However, collecting such information from an insecure channel can be threatening due to the potential security threats. Therefore, it is crucial to secure this sensitive information. This article proposes a secure and lightweight authentication protocol for WBAN. The devised protocol is scalable, secure, and lightweight compared to various relevant competing protocols. The informal security analysis shows that the designed protocol is lightweight, secure, and efficient in resisting various major attacks. The performance analysis demonstrates our protocol's supremacy over various competing protocols in terms of computation and communication costs, inducing efficiency of 20.3% and 12.3%, respectively. Moreover, the practical performance of the designed protocol from the network point of view is measured using the widely recognized NS3 simulation tool.
Maryam Zia, Mohammad S. Obaidat, Khalid Mahmood 0002, Salman Shamshad, Muhammad Asad Saleem, Shehzad Ashraf Chaudhry
IEEE Trans. Ind. Informatics3
2023 A Provably Secure Mobile User Authentication Scheme for Big Data Collection in IoT-Enabled Maritime Intelligent Transportation System
abstract
The emergence of contemporary technologies like cloud computing and the Internet of Things (IoT) has revolutionized the trends in the cyber world to serve humanity. There are plenty of applications in which they are being used, especially in smart cities and their constituents, Maritime Transportation System (MTS) is one of them. The IoT-enabled MTS has the potential to entertain the growing challenges of modern-day ship transportation. Secure real-time data access from numerous smart IoT devices is the most critical and crucial exercise for Big Data acquisition in IoT-enabled MTS. Therefore, we have developed a Physically Unclonable Function (PUF) based authenticated key agreement solution to deal with this challenge. This solution enables the mobile user and IoT node to mutually authenticate each other via Cloud-Gateway before real-time data exchange and transmission in IoT-enabled MTS. The use of PUF in our solution brings invincibility against physical security threats. An inclusive security analysis under the assumption of the specified threat model is carried out to substantiate the security resilience of our solution. The conduct of our solution is realized through security features, communication, and computation cost and It has been observed that our solution achieves efficiency of 37.3% and 9.7% in communication and computation overhead, respectively. Moreover, the network performance effectiveness of our solution is demonstrated in NS3 implementation.
Khalid Mahmood 0002, Javed Ferzund, Muhammad Asad Saleem, Salman Shamshad, Ashok Kumar Das, Youngho Park 0005
IEEE Trans. Intell. Transp. Syst.1
2023 Design of Provably Secure Authentication Protocol for Edge-Centric Maritime Transportation System
abstract
The epidemic growth of the Internet of Things (IoT) objects have revolutionized Maritime Transportation Systems (MTS). Though, it becomes challenging for the centralized cloud-centric framework to fulfil the application requirements such as low latency and power utilization. The introduction of the distributed edge-centric framework has recently helped the IoT-enabled MTS to meet these requirements by manipulating the tasks at the edge of the networks. Despite the fact that MTS leverages mobile subscribers by overcoming inherent cloud computing limitations, data security and user privacy requirements in establishing the MTS setup are still non-trivial challenges. In this article, we develop a key agreement solution for mobile users to realize mutual authentication in a single round. Our protocol offers user anonymity to maintain user privacy, and it can prevent physical attacks by physically unclonable functions. Initially, the security analysis is conferred to substantiate our protocol’s security persistence or strength. Later, its performance correlation is observed under the assumption of diverse metrics in a predefined empirical setup. The meticulous performance correlation endorses the precedence of our protocol over specified related protocols.
Khalid Mahmood 0002, Salman Shamshad, Muhammad Faizan Ayub, Zahid Ghaffar, Muhammad Khurram Khan, Ashok Kumar Das
IEEE Trans. Intell. Transp. Syst.1
2022 An energy-efficient and secure identity based RFID authentication scheme for vehicular cloud computing
Waseem Akram 0003, Khalid Mahmood 0002, Xiong Li 0002, Mazhar Sadiq, Zhihan Lyu, Shehzad Ashraf Chaudhry
Comput. Networks2
2022 A seamless anonymous authentication protocol for mobile edge computing infrastructure
Khalid Mahmood 0002, Muhammad Faizan Ayub, Syed Zohaib Hassan, Zahid Ghaffar, Zhihan Lyu, Shehzad Ashraf Chaudhry
Comput. Commun.1
2022 An Efficient Privacy-Preserving Authenticated Key Establishment Protocol for Health Monitoring in Industrial Cyber-Physical Systems
abstract
Industry 5.0 is the automation, digitization, and data communication of the industrial procedure that comprises industrial cyber–physical systems (I-CPSs), industrial Internet of Things (IIoT), and artificial intelligence (AI). In the I-CPS-enabled healthcare ecosystem, intelligent wearable devices have been extensively employed to sense body information and measure the health status of the patients. Besides other IIoT applications, the I-CPS-enabled healthcare ecosystem also bears various challenges. For instance, due to the communal communication mediums, the security of a patient’s physiological datum is becoming a significant challenge these days. In order to cope with this challenge, we presented a secure and lightweight key establishment protocol. To the best of our knowledge, this protocol is the first application of physically unclonable function (PUF) in the I-CPS-enabled healthcare. The security of the designed protocol is proved with the help of a widely recognized real-or-random (ROR) model. The practical demonstration of our protocol from the network perspective is also measured through broadly recognized NS3 simulator tool.
Salman Shamshad, Khalid Mahmood 0002, Shafiq Hussain, Sahil Garg, Ashok Kumar Das, Neeraj Kumar 0001, Joel J. P. C. Rodrigues
IEEE Internet Things J.2
2022 An Efficient and Provably Secure Certificateless Protocol for Industrial Internet of Things
abstract
The Internet of Things (IoT) has a wide range of applications that influence the life of people expeditiously. In recent years, IoT becomes an emerging technology in a number of fields. Different devices with divergent functionality are applied in IoT to work in several domains. These domains include smart home, smart farming, and Industrial Internet of Things (IIoT). Among these territories, the IIoT obtains more attention. In an IIoT environment, a legitimate user can control and access devices remotely. Legitimate users can access real-time data and share confidential information. The information is transmitted via public communication channel, which can be vulnerable to security attacks. In this article, we present a provably secure multifactor authenticated key agreement scheme to offer security regarding transmission of data in IIoT environment. This scheme will support the legitimate user to remotely access the sensing devices. Our presented scheme uses only symmetric cryptographic, bitwise XOR operation, and hash function to be resource-constrained. Our scheme is found to be resource efficient through communication and computation analysis. The performance analysis illustrates that the cost of computation and communication of our scheme is comparatively low as compared to other relevant schemes. The formal and informal security analysis proved that our scheme is secure and efficient as it can withstand several known adversarial attacks. We have used some cryptographic operations like XOR and hashing to provide security and privacy to legitimate entities.
Farva Rafique, Mohammad S. Obaidat, Khalid Mahmood 0002, Muhammad Faizan Ayub, Javed Ferzund, Shehzad Ashraf Chaudhry
IEEE Trans. Ind. Informatics3
2021 A clogging resistant secure authentication scheme for fog computing services
Zeeshan Ali 0003, Shehzad Ashraf Chaudhry, Khalid Mahmood 0002, Sahil Garg, Zhihan Lyu, Yousaf Bin Zikria
Comput. Networks3
2021 A secure and lightweight authentication scheme for next generation IoT infrastructure
Minahil Rana, Akasha Shafiq, Izwa Altaf, Mamoun Alazab, Khalid Mahmood 0002, Shehzad Ashraf Chaudhry, Yousaf Bin Zikria
Comput. Commun.5
2021 Provably Secure Authentication Protocol for Mobile Clients in IoT Environment Using Puncturable Pseudorandom Function
abstract
The Internet of Things (IoT) is a framework of various services and smart technologies that mutually communicate information between mobile devices and users or just between devices with the help of Internet connectivity. The dramatic progression of IoT helps numerous network applications and communication technologies to introduce state-of-the-art communication models for enabling interaction among mobile server, clients, and various other smart entities. Now-a-days, online mobile services have gained huge attention by providing ample convenience to the distant users. However, it is necessary to secure the information, being exchanged among mobile clients and server. Therefore, a large number of authentication protocols have been presented but majority of them are unsuitable to fulfill novel security requirements and standards. Moreover, they are incompatible for the IoT environment due to higher computation and communication complexity. Consequently, there is a dire need of developing an adequate, reliable, and cost-effective authentication protocol. In this article, we introduce a novel identity-based key agreement protocol using the puncturable pseudorandom functions for mobile clients in the IoT environment. The proposed PSK-MC protocol enables two mobile clients to accomplish mutual authentication via server. The proposed protocol is evaluated formally and informally to determine its security strength. The formal security analysis is presented using the widely used random oracle model. Moreover, all the cryptographic operations used at mobile client side are executed on a mobile device, while the operations used at the server side are implemented on a desktop machine to get the experimental results to determine computation cost. The performance analysis reveals the fact that our protocol is comparatively better than related protocols by exhibiting least communication and computation overhead.
Muhammad Asad Saleem, Zahid Ghaffar, Khalid Mahmood 0002, Ashok Kumar Das, Joel J. P. C. Rodrigues, Muhammad Khurram Khan
IEEE Internet Things J.3
2021 PUF enable lightweight key-exchange and mutual authentication protocol for multi-server based D2D communication
Khalid Mahmood 0002, Salman Shamshad, Minahil Rana, Akasha Shafiq, Shafiq Ahmad, Muhammad Arslan Akram, Ruhul Amin 0001
J. Inf. Secur. Appl.1
2021 Provably secure biometric-based client-server secure communication over unreliable networks
Muhammad Asad Saleem, SK Hafizul Islam, Shafiq Ahmed, Khalid Mahmood 0002, Majid Hussain
J. Inf. Secur. Appl.4
2020 An enhanced authentication protocol for client server environment
Muhammad Asad Saleem, Shafiq Ahmed, Khalid Mahmood 0002, Saru Kumari, Hu Xiong
Frontiers Comput. Sci.3
2020 Comments on "Toward Secure and Provable Authentication for Internet of Things: Realizing Industry 4.0"
abstract
Internet of Things (IoT) is the next era of communication networks. The concept of IoT is that everything within the global communication network is interconnected and accessible. Since IoT has various applications, including Industry 4.0. Therefore, upcoming and existing IoT applications are highly auspicious to enhance the level of automation, efficiency, and comfort for the users. However, to a certain extent, there are numerous challenges while deploying IoT devices in the Industry 4.0, like IoT devices are assumed to have inadequate resources to support security solutions. Therefore, in order to protect the communication environment, an efficient and lightweight security solution is needed. Recently, on the basis of a hierarchical approach, Garget al.presented a lightweight, robust key agreement, and provably secure authentication protocol for the IoT environment. Their introduced protocol relies on lightweight operations, including XOR operation, concatenation, hash function, physically unclonable function (PUF), and elliptic curve cryptography. However, in this comment, we point out the security loopholes of Garget al.’s protocol and show that it is vulnerable to the IoT-node impersonation attack. Moreover, it has irrelevant generation and usage of some parameters. Therefore, we put forward some valuable suggestions for attack resilience.
Muhammad Arslan Akram, Khalid Mahmood 0002, Saru Kumari, Hu Xiong
IEEE Internet Things J.2
2020 Comments on "AKM-IoV: Authenticated Key Management Protocol in Fog Computing-Based Internet of Vehicles Deployment"
abstract
Internet of Vehicles (IoV) has become an intelligent application of Internet of Things (IoT) in smart transportation. IoV takes intelligent commitments to the passengers for improving the efficiency and safety of traffic. It also creates an enjoyable riding atmosphere. Another variation of mobile cloud computing is fog cloud-based IoV, where Internet and vehicular cloud can co-operate in an effective way in IoV. Moreover, IoV is becoming dangerous to various attacks due to the increasing dependency of wireless communication and computing technologies. Recently, Wazidet al.proposed “AKM-IoV: Authenticated Key Management Protocol in Fog Computing-Based IoV Deployment” to make the communication secure between vehicles, fog servers, roadside units (RSUs), and cloud servers. In this comment, we cryptanalyzed the protocol of Wazidet al.and found it vulnerable to vehicle impersonation, fog server impersonation, RSU impersonation, and cloud server impersonation attacks.
Muhammad Asad Saleem, Khalid Mahmood 0002, Saru Kumari
IEEE Internet Things J.2
2020 Fuzzy extraction and PUF based three party authentication protocol using USB as mass storage device
Muhammad Faizan Ayub, Muhammad Asad Saleem, Izwa Altaf, Khalid Mahmood 0002, Saru Kumari
J. Inf. Secur. Appl.4
2020 A secure blockchain-based e-health records storage and sharing scheme
Salman Shamshad, Minahil Rana, Khalid Mahmood 0002, Saru Kumari, Chien-Ming Chen 0001
J. Inf. Secur. Appl.3
2018 An elliptic curve cryptography based lightweight authentication scheme for smart grid communication
Khalid Mahmood 0002, Shehzad Ashraf Chaudhry, Syed Husnain Abbas Naqvi, Saru Kumari, Xiong Li 0002, Arun Kumar Sangaiah
Future Gener. Comput. Syst.1
2018 Pairing based anonymous and secure key agreement protocol for smart grid edge computing infrastructure
Khalid Mahmood 0002, Xiong Li 0002, Shehzad Ashraf Chaudhry, Syed Husnain Abbas Naqvi, Saru Kumari, Arun Kumar Sangaiah, Joel J. P. C. Rodrigues
Future Gener. Comput. Syst.1
2017 An improved one-to-many authentication scheme based on bilinear pairings with provable security for mobile pay-TV systems
Sajad Sadough, Shehzad Ashraf Chaudhry, Mohammad Sabzinejad Farash, Khalid Mahmood 0002
Multim. Tools Appl.5