EDBT 2026 Demo / reviewers in the wild / expert
Shantanu Pal
dblp:00/9387
· DBLP profile ↗
49ranked-venue papers
12as first author
41since 2021 · last 2026
0000-0002-8784-0154ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 28 · 9 first-author · 23 since 2021Security and privacy · 7 · 1 first-author · 7 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 1 first-author · 5 since 2021Software engineering, systems software and programming languages · 5 · 5 since 2021Systems, architecture and hardware · 3 · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Blockchain-Based Secure Product Authenticity Verification for Industrial NetworksabstractThe number of fake products is increasing day by day, which creates many serious problems. These fake items are unsafe for brand reputation as breaks trust and value also unsafe for consumers. Traditional methods like holograms, barcodes, etc., are widely used, but at certain levels, counterfeiters misuse them and copy them, which is not fully transparent. To address these issues, in this paper, we suggest using a blockchain-based system to verify whether a product is real or fake. Leveraging blockchain’s immutability and integrity, the product information is securely recorded using unique block hashes and Quick Response (QR) codes, making unauthorized tampering more difficult once the data is recorded. The consumers can confirm the originality of the product by simply scanning or uploading QR codes, which makes it tough for counterfeiters to clone the QR codes. A key feature of our approach is the integration of multi-scan detection. This system helps to detect unusual or suspicious scanning behavior and creates more trust. The system uses smart contracts to automate secure product registration and verification processes. To demonstrate feasibility, we present the details of the prototype, including database design, flowcharts, and user interface, illustrating its practical deployment. Varun Dobhal, Saksham Mittal, Mohammad Wazid, Sourav Saha 0002, Ashok Kumar Das, Shantanu Pal, Joel J. P. C. Rodrigues |
ICBC | 6 |
| 2026 | DualCare: A Blockchain Framework for Secure Medical Data Sharing with Dual Consent
Kumari Hemlata, Sanjana Saxena, Divyansh Barodiya, Raman, Sujata Pal, Shantanu Pal |
ICBC | 6 |
| 2026 | Securing Financial Transactions Using DLT-Enabled Quantum-Safe Authentication Scheme
Debnath Ghosh, Abhishek Kumar Pandey, Prithwi Bagchi, Ashok Kumar Das, Shantanu Pal, Ravi Kappagantu, Srinivas V. Katakam, Jitendra Chougala |
IWCMC | 5 |
| 2026 | HoSig-Align I: Edge-Native Threat Attribution using Homology Blocks in IoT-Pervasive NetworksabstractA primary challenge in network defense is to mine potential attack campaigns from massive, continuously arriving alerts and telemetry data in real time. This paper presents HoSig-Align I, an edge side unsupervised method designed for network streams to discover homologous blocks. Our approach innovatively fuses heterogeneous features like Internet Protocol (IP) and Payload into a unified representation while strictly excluding temporal information from it, only incorporating time via a dual time scale decay model during graph construction to capture temporal proximity. A density robust similarity is computed using an isolation style random partition forest, leading to a sparse k-Nearest Neighbors (k-NN) graph. The stream is then accurately segmented into internally cohesive and mutually isolated homologous blocks through spectral ordering and contrastive change point detection. Each block is encoded into a lightweight HoSig signature, forming the basis for cross organizational collaboration. Experiments on real network streams show that HoSig-Align I identifies coherent attack campaign blocks and improves separation and boundary clarity over baselines, while meeting low-latency and low-overhead requirements for edge processing. Aiting Yao, Shantanu Pal, Chengzu Dong, Di Shao, Wenying Feng 0003, Zhaoquan Gu |
PerCom | 2 |
| 2026 | Trajectory-aware predictive handover framework for task offloading in vehicular edge networks
Sushma S. A, Mohammed Talib, Sourav Kanti Addya, Saifur Rahman 0002, Shantanu Pal, Chandan K. Karmakar |
Ad Hoc Networks | 5 |
| 2026 | Edge and serverless computing for the next generation of ad hoc networks
Sourav Kanti Addya, Shantanu Pal, Anurag Satpathy, Dheryta Jaisinghani |
Ad Hoc Networks | 2 |
| 2026 | A patient-centric secure access control architecture with dynamic edge data integrity verification in Internet of Medical ThingsabstractIn the Internet of Medical Things (IoMT), securing patient data access is critical, but must be achieved without overwhelming the limited computational resources of edge devices. While cryptographic methods and access policies are widely applied to secure medical data, existing solutions often assume high computational capacity, centralized infrastructure, or predefined key structures, which are not ideal for the heterogeneous and resource-constrained environments found in IoMT. In addition to security, patient-centricity is becoming an essential design principle, where patients must have control over who accesses their data and under what conditions. Similarly, edge computing has emerged as a means to reduce latency, but edge devices are often semi-trusted, exposed to physical threats, and limited in processing power, making them unsuitable for heavyweight integrity verification or outsourced computation. Therefore, this paper presents a lightweight, patient-centric architecture that unifies attribute-based access control, dynamic edge data integrity verification, and consent-driven sharing in a secure and scalable architecture. The system minimizes communication and computational overhead by eliminating predefined keys, restricting edge computation, and guaranteeing verifiable data delivery. The experimental results demonstrate efficient handling of tampered and untampered cases, achieving fast, verifiable, and secure access with minimal resource consumption. This paper offers a practical and integrative solution to ensure security without sacrificing lightweight performance in real-world IoMT deployments. Keerat Kaur, Saifur Rahman 0002, Shantanu Pal, Chandan K. Karmakar |
Ad Hoc Networks | 3 |
| 2026 | Zero trust-driven access control delegation using blockchainabstractAs digital ecosystems become more complex with decentralized technologies like the Internet of Things (IoT) and blockchain, traditional access control models fail to meet the security needs of dynamic, high-risk environments. The need for dynamic, fine-grained access control mechanisms has become critical, particularly in environments where trust must be continuously evaluated, and access decisions must adapt to real-time conditions. Traditional models often rely on static identity management and centralized trust assumptions, which are inadequate for modern, decentralized, and highly dynamic environments such as IoT ecosystems. Consequently, existing solutions lack fine-grained identity management, flexible delegation, and continuous trust evaluation, highlighting the need for a more robust, adaptive, and decentralized access control architecture. To address these gaps, this paper presents a novel access control architecture that integrates self-sovereign identity (SSI) and decentralized identifier (DID)-based access control with zero trust principles, enhanced by a flexible capability-based access control (CapBAC) approach. Leveraging SSI and DID allows entities to manage their identities without relying on a central authority, aligning with zero-trust principles. The integration of CapBAC ensures flexible, context-aware, and attribute-based access control, where access rights are dynamically granted based on the requester's capabilities. This enables fine-grained delegation of access rights, allowing trusted entities to delegate specific privileges to others without compromising overall security. Continuous trust evaluation is employed to assess the authenticity of access requests, mitigating the risks posed by compromised devices or users. The proposed architecture also incorporates blockchain technology to ensure transparent, immutable, and secure management of access logs, providing traceability and accountability for all access events. We demonstrate the feasibility and effectiveness of this solution through performance evaluations and comparisons with existing access control schemes, showing its superior security, scalability, and adaptability in real-world scenarios. Our work demonstrates a comprehensive, decentralized, and scalable solution for secure access control delegation using zero trust-driven principles. Rahma Mukta, Shantanu Pal, Kowshik Chowdhury, Michael Hitchens, Hye-Young Paik, Salil S. Kanhere |
Blockchain Res. Appl. | 2 |
| 2026 | Postquantum Secure Lattice-Based Authentication Scheme for IoT-Enabled Crop Recommender SystemabstractInternet of Things (IoT)-enabled smart farming has emerged as one of the most progressive domains, integrating knowledge discovery as a core component to assist farmers in analyzing their fields and obtaining accurate crop recommendations. However, the advent of quantum computing introduces significant security threats to this domain, emphasizing the urgent need to transition from classical to quantum-secure authentication mechanisms. To address this challenge, this article presents a post-quantum, lattice-based secure authentication scheme tailored for intelligent crop recommendation systems. The cryptographic scheme strengthens the data communication pipeline, and additionally, the framework incorporates security-aware design considerations within the machine learning phase, which acts as the second line of defense for the recommendation system. The security of the scheme is thoroughly analyzed for classical as well as quantum attacks. The insights gained from the real-time testbed validate the efficiency and accuracy of the framework. Snehal Jain, Abhishek Kumar Pandey, Ashok Kumar Das, Shantanu Pal, Youngho Park 0005 |
IEEE Internet Things J. | 4 |
| 2026 | PQ-AuthV: Post-Quantum Secure Authentication With Aggregated Signatures in IoT-Enabled Smart Vehicle Networks
Arun Sekar Rajasekaran, Ashok Kumar Das, Maria Azees, Gulfishan Firdose Ahmed, Mpyana Mwamba Merlec, Hoh Peter In, Shantanu Pal |
IEEE Internet Things J. | 7 |
| 2026 | Vulnerabilities in Machine Learning for cybersecurity: Current trends and future research directionsabstractMachine learning (ML) has become integral to cybersecurity applications, e.g., phishing detection, intrusion detection systems, malware analysis, and botnet identification. However, the integration of ML also exposes novel attack surfaces that can be exploited through adversarial machine learning (AML). While prior surveys have examined individual threats or defenses, they often focus narrowly on specific stages, e.g., training or testing. In contrast, in this paper, we provide the first comprehensive survey of adversarial attacks and defenses across the entire ML development life cycle within the cybersecurity domain. Using a structured methodology, we categorize vulnerabilities and countermeasures at each stage, data gathering, model training, testing, deployment, and maintenance, highlighting cross-stage interactions and emerging distributed threat models. Our study addresses key gaps in current defenses, including their limited generalizability and lack of standardized evaluation practices, and identifies promising directions, e.g., lifecycle-aware robustness, distributed resilience, and the integration of statistical with generative methods. Consolidating fragmented research into an end-to-end perspective, this study advances the understanding of AML in cybersecurity and outlines a roadmap for building more trustworthy, and resilient ML-driven security systems. Shantanu Pal, Geeta Yadav, Zahra Jadidi, Ahsan Habib 0003, Md Palash Uddin, Chandan K. Karmakar, Sandeep K. Shukla |
J. Inf. Secur. Appl. | 1 |
| 2026 | Social Equity and Inclusion With Fair Dataset Representation of Diverse Populations in Diffusion ModelsabstractGenerative artificial intelligence (AI), an advancing frontier, uses machine learning to autonomously create media content, though it faces challenges with bias and fair representation. This research investigates demographic bias within the LAION dataset, specifically focusing on the representation of Indigenous Australians. Large image generative models are typically trained on extensive datasets scraped from the Internet, which often reflect the demographics of the most active online communities rather than accurately representing local populations. While existing studies have examined hate speech, gender balance, and broad ethnic diversity within LAION, limited research addresses representation relative to specific national demographics or minority subgroups. Auditing the dataset with state-of-the-art facial recognition and sentiment analysis models, we assessed the age, gender, and ethnicity of images in LAION and compared these distributions against census data for Australia and the United States. We also conducted a focused analysis of Indigenous Australian representation by identifying relevant images using keyword searches and applying the aforementioned models. Our findings reveal that the dataset demographic composition poorly aligns with the actual population of Australia, with regional subgroups under-represented, potentially leading to inaccurate portrayals of Indigenous Australians. These results underscore the need for either strengthened safeguards on globally developed generative models or the development of locally trained models to ensure responsible and inclusive cultural representation in AI-generated imagery. Ryan Holland, Saifur Rahman 0002, Shantanu Pal, Chandan K. Karmakar, Lei Pan 0002 |
IEEE Trans. Comput. Soc. Syst. | 3 |
| 2026 | Blockchain-Enabled Secure Signature Scheme With Quantum Key Distribution for IoMT-Based Healthcare SystemsabstractThe rapid expansion of Internet of Medical Things (IoMT) networks has enabled continuous data collection from diverse medical sensors and devices, supporting real-time monitoring, diagnostics, and decision-making. However, the resource limitations of IoT nodes and the open nature of communication channels make healthcare data vulnerable to security and privacy breaches. To address these challenges, this paper presents a blockchain-assisted, privacy-preserving signature scheme leveraging Quantum Key Distribution $(\mathcal {QKD})$ to ensure secure and trustworthy data sharing in Healthcare Internet of Things (H-IoT) environments. The proposed scheme integrates a quantum-designated verifier signature mechanism with a private blockchain infrastructure, where peer nodes validate and store healthcare data securely. Formal (software-based) and informal security analyses demonstrate the scheme's resistance to forgery, replay, and quantum attacks. Simulation experiments conducted in Python show that the proposed protocol achieves strong cryptographic performance, with a computational cost of 42.1ms and a communication overhead of 834 bits. Additionally, a blockchain-based prototype implementation quantifies the time required to append various numbers of blocks and process multiple healthcare transactions, confirming the scalability and practicality of the proposed solution. The results affirm that the scheme offers a reliable, efficient, and quantum-resilient framework for securing sensitive medical data across distributed IoMT healthcare systems. Sunil Prajapat, Deepika Gautam, Pankaj Kumar 0006, Ashok Kumar Das, Shantanu Pal, Chengzu Dong |
IEEE J. Biomed. Health Informatics | 5 |
| 2026 | Privacy-Preserving Lightweight Federated Learning for Heterogeneous Data in Internet of Medical ThingsabstractThe Internet of Medical Things (IoMT) systems enable the continuous monitoring and collection of healthcare data from various medical devices and sensors, facilitating real-time analysis and timely interventions. One such example of the IoMT system is the early and accurate detection of arrhythmia using electrocardiogram (ECG) signals, which plays a crucial role in improving patient health. However, healthcare data contains sensitive information that raises privacy concerns for users. In recent years, Federated Learning (FL) offers a promising solution by enabling collaborative model training on distributed ECG data at the device level while preserving data privacy. However, FL is computationally expensive and suffers from data heterogeneity, which slower convergence, reduces performance, and hinders generalization across diverse client datasets. In this work, we propose a lightweight FL-based model designed explicitly for arrhythmia detection with data heterogeneity. We evaluate our model's performance on two publicly available ECG datasets (PTBD and MIT-BIH arrhythmia). The proposed model achieves high accuracy (between 0.95 and 0.98) while maintaining robustness against heterogeneous data distributions. Furthermore, the experimental results demonstrate significant efficiency gains compared to a baseline model (ResNet). Our proposed lightweight FL-based model requires substantially less mega floating point operations (MFLOPS) (0.07 vs. 2.14 for ResNet) and communication cost (1000 Mb vs. 7500 Mb for ResNet) to achieve convergence. These results indicate the potential of our proposed approach for practical and privacy-preserving arrhythmia detection in resource-constrained IoMT settings. Saifur Rahman 0002, Shantanu Pal, Chandan K. Karmakar |
IEEE J. Biomed. Health Informatics | 2 |
| 2025 | Adaptive Incremental Provenance Analysis for Trustworthy Federated Learning
Aiting Yao, Chengzu Dong, Shantanu Pal, Frank Jiang 0001, Haiyan Wang 0009, Wenying Feng 0003, Lichen Liu, Zhaoquan Gu |
ADMA (2) | 3 |
| 2025 | Poster: BlockFL-Med: Blockchain-Enabled and Lightweight Federated Learning for Smart Medical SpacesabstractWe propose a blockchain-enabled lightweight federated learning (BlockFL-Med) framework tailored for smart medical spaces, e.g., the Internet of Medical Things (IoMT), addressing key challenges, e.g., privacy preservation, trust management, and scalability. The framework ensures the privacy of sensitive patient data by employing federated learning, where only model updates are shared instead of raw data. To enhance trust, the framework integrates blockchain technology, creating a decentralized and tamper-proof network that verifies client contributions and mitigates risks from malicious participants. Experimental results demonstrate the scalability and efficiency issues by optimizing communication costs, e.g., transmitting lightweight kilobyte-sized model updates instead of larger megabyte-sized models, making it well-suited for heterogeneous and resource-constrained IoMT environments. Shantanu Pal, Saifur Rahman 0002, Robin Doss, Chandan K. Karmakar |
MobiCom | 1 |
| 2025 | RAD-IoMT: Robust adversarial defence mechanisms for IoMT medical image analysisabstractThe Internet of Medical Things (IoMT) represents a significant technological advancement with exceptional capabilities across various domains, particularly in healthcare. IoMT integrates medical devices, software applications, and healthcare systems, enabling seamless communication and data exchange over the Internet. As deep learning (DL) continues to evolve, applications within IoMT are increasingly dominant. However, these DL applications face new reliability challenges, particularly due to the security threat posed by adversarial attacks. These attacks introduce subtle and often imperceptible perturbations that can lead to significantly erroneous predictions by classifiers. To address these reliability concerns, we propose a novel security mechanism using an attack detector specifically designed to counter adversarial attacks within IoMT environments. This approach leverages a transformer model to enhance resistance against such attacks. We validate our method through experiments using datasets for skin cancer, retina damage, and chest X-rays, testing against both white-box attacks (e.g., Fast Gradient Sign Method (FGSM) and Projected Gradient Descent (PGD)) and black-box attacks (e.g., Additive Gaussian Noise (AGN) and Additive Uniform Noise (AUN)). Our proposed attack detector exhibited F1 and accuracy 0.91 and 0.94. Following the successful application of our attack detector, the disease classification model achieved an average F1 and accuracy of 0.97 and 0.98 compared to the attack model performance (F1 and accuracy of 0.64 and 0.60, respectively) across the three datasets. Saifur Rahman 0002, Shantanu Pal, Amir Mohammad Fallah, Robin Doss, Chandan K. Karmakar |
Ad Hoc Networks | 2 |
| 2025 | Attack-data independent defence mechanism against adversarial attacks on ECG signalabstractAdversarial attacks pose a significant threat to the integrity and reliability of electrocardiogram (ECG) signals, compromising their use in critical applications, e.g., arrhythmia detection and classification. In this paper, we propose an attack-data-independent defence mechanism to effectively mitigate adversarial attacks on ECG signals. Unlike existing defence mechanisms that rely on learning from adversarial samples, our proposed approach operates as a ‘gatekeeper,’ selectively discarding noisy and attack signals while allowing only clean and non-attack ECG signals to be stored in the data layer. This ensures the availability of reliable and high-quality ECG data for subsequent analysis. The proposed defence mechanism not only detects and filters out the attack and noisy ECG signals but also provides robust protection against adversarial attacks, enhancing the integrity and trustworthiness of ECG data for critical applications. To evaluate the effectiveness of our proposal, we conduct experiments using physiologic and synthetic ECG datasets against two well-known attacks: a white-box attack (Fast Gradient Signed Method (FGSM) and Projected Gradient Descent (PGD)) and a black-box attack (HopSkipJump and Boundary). Our experimental results demonstrate the superiority and effectiveness of our approach in defending against adversarial attacks on ECG signals, making it a promising solution for ensuring the security and reliability of ECG-based diagnosis in smart healthcare applications. Saifur Rahman 0002, Shantanu Pal, Ahsan Habib 0003, Lei Pan 0002, Chandan K. Karmakar |
Comput. Networks | 2 |
| 2025 | Optimizing UAV delivery for pervasive systems through blockchain integration and adversarial machine learningabstractUnmanned Aerial Vehicles (UAVs), play a significant role in the advancement of pervasive systems by providing efficient, scalable, and innovative solutions in various sectors, such as smart cities or location-based services. However, the current UAV delivery scenario presents various challenges for recipients, including lengthy identity verification processes, privacy concerns, and risks of fraud and theft. In response to these issues, this paper proposes an innovative system that leverages Blockchain technology and Adversarial Machine Learning (AML) to tackle these problems effectively. The proposed system streamlines the verification process, enhances privacy safeguards, and reduces fraud risks. The integration of AML is crucial as it enables users to have greater control over their personal data, boosting privacy and security. AML also plays a critical role in this system by creating test scenarios that reinforce the machine learning model against adversarial threats, ensuring its precision and dependability in the face of malicious manipulations. The paper also provides details on the practical implementation and evaluation of this system in real-life adversarial situations. The evaluation results demonstrate superior performance on selected metrics, highlighting the potential of this system as an effective solution for verifying recipients in UAV delivery. Chengzu Dong, Shantanu Pal, Aiting Yao, Frank Jiang 0001, Shiping Chen 0001, Xiao Liu 0004 |
Comput. Commun. | 2 |
| 2025 | FedShufde: A privacy preserving framework of federated learning for edge-based smart UAV delivery systemabstractFedShufde: A privacy preserving framework of federated learning for edge-based smart UAV delivery system Aiting Yao, Shantanu Pal, Gang Li 0009, Xuejun Li 0001, Frank Jiang 0001, Chengzu Dong, Jia Xu 0010, Xiao Liu 0004 |
Future Gener. Comput. Syst. | 2 |
| 2025 | Secure Cloud-Storage-Based Big Data Analytics Scheme for Intelligent Vehicles EnvironmentabstractThe Internet of Vehicles (IoV) is a system designed to enhance transportation efficiency and safety by facilitating communication and data exchange among vehicles, infrastructure, and other devices. In IoV, vehicles, roadside units (RSUs), and cloud servers (CSs) are interconnected for seamless communication and data exchange. However, sharing data among various IoV entities poses significant security threats, including privacy breaches, data manipulation, and unauthorized access. These threats can compromise personal information, cause system malfunctions, and endanger the safety of vehicle occupants and other road users. To address these challenges, this article proposes a secure transfer mechanism for data sharing among IoV entities and a framework for secure big data analytics, where the data collected from vehicles undergoes secure analysis at the big data analytics center. Experimental evaluation, along with security and performance analysis, demonstrates that the proposed approach ensures secure data transfer between IoV entities and secure big data analytics in the CS. Prakash Tekchandani, Soumya Banerjee 0001, Ashok Kumar Das, Shantanu Pal, Sachin Shetty |
IEEE Internet Things J. | 5 |
| 2025 | A Privacy-Aware Task Distribution Architecture for UAV Communications System Using BlockchainabstractUnmanned aerial vehicles (UAVs) have witnessed significant growth in various domains, such as agriculture, disaster management, and remote health management systems. However, the use of UAVs necessitates secure and efficient solutions that uphold privacy during task distribution. To address this challenge, this article introduces a novel architecture for privacy-aware task distribution in UAV communication systems. Our approach leverages the benefits of blockchain and smart token-based identification within the proposed architecture, ensuring decentralized, transparent, and tamper-proof operations. By adopting a crowdsourced task distribution model, our approach further optimizes task assignment among UAVs while prioritizing data privacy, user access control, and scalability. The architecture is designed to enhance fault tolerance, enabling seamless operation under dynamic and unpredictable conditions. We present a comprehensive implementation details of a proof-of-concept prototype of our proposed architecture, detailing its design and functionality. The experimental results demonstrate the feasibility, efficiency, and adaptability of our approach in diverse real-world scenarios, highlighting its potential for broader adoption across UAV applications. Chengzu Dong, Shantanu Pal, Shiping Chen 0001, Frank Jiang 0001, Xiao Liu 0004 |
IEEE Internet Things J. | 2 |
| 2025 | Big Data Analytics-Envisioned Authenticated Key Management Scheme in IoT-Based Smart Farming System for Sustainable Development of Smart CitiesabstractSmart farming enhances sustainable communication practices through the deployment of energy-efficient Internet of Things (IoT) devices, low-power wireless technologies, and edge/fog computing to reduce data transmission and energy usage. Smart cities represent a concept in which technology, data, and innovation enhance urban efficiency, sustainability, and livability. Smart farming has the potential to facilitate the sustainable development of smart cities. However, integrating smart farming into smart city systems presents significant challenges, particularly with respect to the security of their interconnected components. The vulnerability of agricultural information and the likelihood of cybersecurity threats necessitate the development of targeted security solutions for smart farming. To address these challenges, we propose a Big Data Analytics-envisioned secure smart farming scheme for sustainable cities (in short, CSSF-SC). It is an efficient authenticated key agreement mechanism that enables secure mutual authentication, session-key establishment, and dynamic key management among smart farming devices, drones, and cloud servers. Using the Scyther verification tool, security is formally verified under the Dolev–Yao and CK adversary models, demonstrating resilience to various potential attacks. A comparative performance analysis shows that CSSF-SC outperforms current schemes in terms of computation and communication costs while offering stronger security and additional functionalities. Finally, a practical implementation is done using the MangoLeafBD dataset and an EfficientNet-B7 architecture. It achieves 99.16% accuracy, validating the framework’s effectiveness for secure crop-data collection and analysis in real-world scenarios. Akshita Patwal, Mohammad Wazid, Ashok Kumar Das, Devesh Pratap Singh, Shantanu Pal, Youngho Park 0005 |
IEEE Internet Things J. | 5 |
| 2025 | Software-Defined-Network-Based Energy-Efficient Multipath Flow Control for Aerial ComputingabstractSoftware-defined networking (SDN) centralizes and abstracts network control, potentially introducing single points of failure. To enhance scalability and flexibility, a distributed SDN (DSDN) approach is essential. This research introduces MLB-DSDN, an energy-efficient multipath load-balancing protocol for flow control in DSDNs, with a specific focus on an eco-friendly aerial computing environment. MLB-DSDN protocol identifies multiple routes between source and destination nodes, dynamically distributing data packets based on an inverse proportionality mechanism relative to route traversal time. This strategy balances traffic loads across various channels, significantly reducing the total routing time for data packet delivery. Moreover, the proposed framework enhances network performance and resilience in dynamic, high-mobility environments. It achieves this by incorporating unmanned aerial vehicles (UAVs) and satellite nodes as mobile network components. Experimental results demonstrate that MLB-DSDN improves average response time by 14.40% and increases average transactions per second by 14.63%, surpassing state-of-the-art methodologies. The integration of UAVs and satellites contributes to an additional 10% improvement in network throughput and a 12% reduction in latency compared to ground-based solutions alone. These findings highlight the robustness and efficiency of MLB-DSDN in enabling seamless and reliable data dissemination across terrestrial and aerial networks. Thus, the proposed framework enhances scalability, reliability, and flexibility in aerial computing, offering a robust and adaptable solution for resilient modern networks. Rakesh Salam, Vikas Tyagi, Samayveer Singh, Neeraj Kumar 0001, Shantanu Pal |
IEEE Internet Things J. | 5 |
| 2025 | Delay-aware partial task offloading using multicriteria decision model in IoT-fog-cloud networksabstractFog computing plays a prominent role in offloading computational tasks in heterogeneous environments since it provides less service delay than traditional cloud computing. The Internet of Things (IoT) devices cannot handle complex tasks due to less battery power, storage and computational capability. Full offloading has issues in providing efficient computation delay due to more response time and transmission cost. A suitable solution to overcome this problem is to partition the tasks into splittable subtasks. Considering multi-criteria decision parameters like processing efficiency and deadline helps to achieve efficient resource allocation and task assignment. The matching theory is applied to map task nodes to heterogeneous fog nodes and VMs for stability. Compared to baseline algorithms, proposed algorithms like Resource Allocation based on Processing Efficiency (RABP) and Task Assignment Based on Completion Time (TAC) are efficient enough to provide reasonable service delay and discard the non-beneficial tasks, i.e., tasks that do not execute within the deadline. Sushma S. A, Madhunisha E., Sourav Kanti Addya, Saifur Rahman 0002, Shantanu Pal, Chandan K. Karmakar |
J. Netw. Comput. Appl. | 5 |
| 2025 | Robust Cyber Threat Intelligence Sharing Using Federated Learning for Smart GridsabstractGiven the escalating diversity, sophistication, and frequency of cyber attacks, it is imperative for critical infrastructure entities, e.g. smart grids, to recognize the inherent risks of operating in isolation. Sharing cyber threat intelligence (CTI) helps them stand together and build a collective cyber defense by knowledge, skills, and experience encompassing information related to identifying and evaluating cyber and physical threats. The present studies lack on robust CTI sharing strategies in smart grid systems. To address the critical need for secure and effective CTI sharing in smart grid systems, this article proposes a novel approach. Our solution leverages encrypted federated learning (FL) with integrated malicious client detection mechanisms. This approach facilitates collaborative learning of a threat detection model while preserving the privacy of raw CTI data. Employing real-world, heterogeneous smart grid datasets, we rigorously evaluated our approach under two distinct attack scenarios. The results demonstrate resilience against both man-in-the-middle attacks and malicious clients, exceeding the performance typically observed in traditional FL models. Saifur Rahman 0002, Shantanu Pal, Zahra Jadidi, Chandan K. Karmakar |
IEEE Trans. Comput. Soc. Syst. | 2 |
| 2024 | A Dual-Defense Self-balancing Framework Against Bilateral Model Attacks in Federated Learning
Aiting Yao, Shantanu Pal, Frank Jiang 0001, Xuejun Li 0001, Jia Xu 0010, Chengzu Dong, Xuefei Chen, Xiuyi Zhang, Xiao Liu 0004 |
ICA3PP (1) | 3 |
| 2024 | A privacy-preserving location data collection framework for intelligent systems in edge computingabstractWith the rise of smart city applications, the accessibility of users’ location data by smart devices has increased significantly. However, this poses a privacy concern as attackers can deduce personal information from the raw location data. In this paper, we propose a framework to collect user location data while ensuring local differential privacy (LDP) in the last-mile delivery system of Unmanned Aerial Vehicles (UAVs) within an edge computing environment. Firstly, we obtain the user location distribution Quad-tree by employing a region partitioning method based on Quad-tree retrieval in the specified data collection area. Next, the user location matrix is retrieved from the obtained Quad-tree, and we perturb the user location data using an LDP perturbation scheme on the location matrix. Finally, the collected data is aggregated using blockchain to evaluate the utility of the dataset from various regions. Furthermore, to validate the effectiveness of our framework in a real-world scenario, we conduct extensive simulations using datasets from multiple cities with varying urban densities and mobility patterns. These simulations not only demonstrate the scalability of our approach but also showcase its adaptability to different urban environments and delivery demands. Finally, our research opens new avenues for future work, including the exploration of more sophisticated LDP mechanisms that can offer higher levels of privacy without significantly compromising the quality of service. Additionally, the integration of emerging technologies such as 5G and beyond in the edge computing environment could further enhance the efficiency and reliability of UAV-based delivery systems, while also offering new challenges and opportunities for privacy-preserving data collection and analysis. Aiting Yao, Shantanu Pal, Xuejun Li 0001, Chengzu Dong, Frank Jiang 0001, Xiao Liu 0004 |
Ad Hoc Networks | 2 |
| 2024 | Enhancing quality of service through federated learning in edge-cloud architectureabstractThe traditional cloud computing paradigm faces challenges with the increasing number of Artificial Intelligence of Things (AIoT) devices generated at the network edge. Edge computing provides a novel approach to overcoming the limitations of cloud computing by delivering lower service latency and higher quality of service (QoS) to AIoT devices. However, edge computing encounters constraints due to scarce resources on edge servers and the long distance between AIoT devices and remote cloud servers. To ensure high QoS for AIoT devices, a balance is required between limited computing resources on the network edge and high latency caused by the geographic distance on the cloud side. In this paper, we propose an edge-cloud architecture that achieves optimal QoS for AIoT devices. We employ a federated learning-based architecture to train AIoT devices’ data locally, thereby ensuring privacy. We evaluate the effectiveness and efficiency of our proposed approach by comparing it with the centralized approach from the state-of-the-art using two widely used datasets. The experimental results demonstrate that our architecture achieves higher effectiveness and efficiency in improving AIoT devices’ QoS. Overall, our proposed edge-cloud architecture overcomes the limitations of traditional cloud computing, enhances user privacy, and delivers high QoS to AIoT devices. Shantanu Pal, Chengzu Dong, Kaibin Wang |
Ad Hoc Networks | 2 |
| 2024 | Priv-Share: A privacy-preserving framework for differential and trustless delegation of cyber threat intelligence using blockchainabstractThe emergence of the Internet of Things (IoT), Industry 5.0 applications and associated services have caused a powerful transition in the cyber threat landscape. As a result, organisations require new ways to proactively manage the risks associated with their infrastructure. In response, a significant amount of research has focused on developing efficient Cyber Threat Intelligence (CTI) sharing. However, in many cases, CTI contains sensitive information that has the potential to leak valuable information or cause reputational damage to the sharing organisation. While a number of existing CTI sharing approaches have utilised blockchain to facilitate privacy, it can be highlighted that a comprehensive approach that enables dynamic trust-based decision-making, facilitates decentralised trust evaluation and provides CTI producers with highly granular sharing of CTI is lacking. Subsequently, in this paper, we propose a blockchain-based CTI sharing framework, called Priv-Share, as a promising solution towards this challenge. In particular, we highlight that the integration of differential sharing, trustless delegation, democratic group managers and incentives as part of Priv-Share ensures that it can satisfy these criteria. The results of an analytical evaluation of the proposed framework using both queuing and game theory demonstrate its ability to provide scalable CTI sharing in a trustless manner. Moreover, a quantitative evaluation of an Ethereum proof-of-concept prototype demonstrates that applying the proposed framework within real-world contexts is feasible. Kealan Dunnett, Shantanu Pal, Zahra Jadidi, Volkan Dedeoglu, Raja Jurdak |
Comput. Networks | 2 |
| 2024 | Current approaches and future directions for Cyber Threat Intelligence sharing: A surveyabstractCyber Threat Intelligence (CTI) is essential knowledge concerning cyber and physical threats aimed at mitigating potential cyber attacks. The rapid evolution of Information and Communications Technology (ICT), the Internet of Things (IoT), and Industry 5.0 has spawned a multitude of sources regarding current or potential cyber threats against organizations. Consequently, CTI sharing among organizations holds considerable promise for facilitating swift responses to attacks and enabling mutual benefits through active participation. However, exchanging CTI among different organizations poses significant challenges, including legal and regulatory obligations, interoperability standards, and data reliability. The current CTI sharing landscape remains inadequately explored, hindering a comprehensive examination of organizations’ critical needs and the challenges they encounter during CTI sharing. This paper presents a comprehensive survey on CTI sharing, beginning with an exploration of CTI fundamentals and its advancements in assessing cyber and physical threats and threat actors from various perspectives. For instance, we discuss the benefits of CTI, its applications, and diverse CTI sharing architectures. Additionally, we extensively discuss a list of CTI sharing challenges and evaluate how available CTI sharing proposals address these challenges. Finally, we provide an inventory of unique future research directions to offer insightful guidelines for CTI sharing. Poopak Alaeifar, Shantanu Pal, Zahra Jadidi, Mukhtar Hussain, Ernest Foo |
J. Inf. Secur. Appl. | 2 |
| 2024 | A Blockchain-Based Approach for Parametric Insurance Under Multiple Sources of TruthabstractThe use of parametric insurance is promising as its payouts can be directly tied to hazard indicators and thus provide a fast-tracked claim-to-payout process, which improves liquidity in times of disaster. In parametric insurance, policies are determined by a loss threshold (modelled or sustained) or physical hazard severity (e.g., rainfall or wind speed). In the latter, when the severity of the hazard exceeds a threshold, a payout is automatically triggered according to the insurance contract terms to compensate the policyholder without needing a loss assessment. Recently, blockchains have been proposed to improve the efficiency of insurance product offerings (e.g., to cut administrative costs associated with the premium collection and claim processing) and to efficiently store and maintain information (e.g., immutable distributed storage for audits). While parametric insurance would certainly benefit from these blockchain implementations, existing proposals mostly depend on a single source of truth for payout calculations. In this paper, we present a novel trust-based framework to handle multiple sources of truth in parametric insurance products which use blockchain technology. This framework alleviates the reliance on a single point of failure (either through accidents or malicious abuses) and outperforms its statistical counterparts. We discuss how parametric insurance would work under such a framework using real-world use-case scenarios, show the use of subjective logic to reason about multiple sources of truth, present the architecture of the framework, and examine a detailed blockchain-based implementation using an Ethereum private blockchain. Our results show the feasibility of the proposed system in practice. Tahiry M. Rabehaja, Shantanu Pal, Ambrose Hill, Michael Hitchens |
IEEE Trans. Serv. Comput. | 2 |
| 2023 | A Blockchain-Based Framework for Scalable and Trustless Delegation of Cyber Threat IntelligenceabstractCTI sharing is increasingly used by organisations to strengthen security. The sensitivity of CTI has led to research on trust-based sharing, yet most existing CTI sharing approaches only support static trust-based decisions or centralised trust evaluation, limiting their scalability and lead to centralised risk. This paper proposes a blockchain-based CTI sharing framework that relies on trustless delegates for dynamic trust-based decision-making and decentralised trust evaluation. To facilitate trustless delegation, our proposal allows CTI producers to intentionally inject false data on a periodic basis into the system to audit the behaviour of delegates. Moreover, unlike existing approaches, delegates within our framework facilitate sharing of CTI directly with consumers such that scalable CTI sharing occurs. The results of a qualitative evaluation of the proposed framework's security show that it is resilient to common privacy and trust concerns. Moreover, a quantitative evaluation of a proof-of-concept prototype using Ethereum show that the proposed framework is scalable and cost-effective. Kealan Dunnett, Shantanu Pal, Zahra Jadidi, Raja Jurdak |
ICBC | 2 |
| 2023 | A Blockchain-Based Interoperable Architecture for IoT with Selective Disclosure of InformationabstractWith the improvement of Internet of Things (IoT) technologies, services, and applications, there is a proliferation of access to smart devices in everyday life. However, granting access and controlling access rights for each resource is challenging in highly dynamic and large-scale IoT deployments. In particular, multiple access information may need to be provided to an entity when granting access rights to several resources. The situation becomes more complex when an entity is required to share its identity attribute to receive the access information. These raise the question of what identity information an entity needs to provide to obtain the required access to a particular resource and, subsequently, what access information needs to be provided when accessing that resource. That said, there is a need for a flexible approach where an entity can share a distinct identity and access attributes for accessing a resource without revealing additional information. Such flexibility in sharing information is significant given the privacy risk of an entity’s identity. This paper presents an architecture that delivers access rights to an entity with selective disclosure of information. Our approach ensures the minimum exchange of information (identity and access attribute) to enhance an entity’s privacy when granting access rights to an entity. We use blockchain to provide data authenticity (i.e., tamper-proof), transparency and automatic execution of access rights based on shared attributes using smart contracts. We implement a proof of concept of the proposed system using Hyperledger fabric as a permissioned blockchain network. Our results demonstrate the feasibility of the proposed system showing efficiency in granting access rights. Rahma Mukta, Shantanu Pal, Hye-Young Paik, Salil S. Kanhere, Michael Hitchens |
PRDC | 2 |
| 2022 | A Democratically Anonymous and Trusted Architecture for CTI Sharing using BlockchainabstractCyber Threat Intelligence (CTI) sharing has become a significant issue with the increasing number of cyberattacks. In CTI sharing, one entity (e.g., an organisation or a user) intends to share specific threat information to another entity that might otherwise be unavailable to another entity. However, this process needs to address many challenges, including privacy, trust, and accountability. In this paper, we propose a novel blockchain-based architecture that facilitates the secure dissemination of CTI data. The motivation for this study is to provide a solution that can efficiently address privacy, trust, and accountability when sharing CTI among organisations as well as maintaining an intelligence-based informed decisions. We discuss the current problems within the domain of CTI sharing using blockchain, and our proposal leverages the salient properties of the blockchain, e.g., decentralised, cryptographic keys, immutability, etc., to address those issues. We discuss the detailed design of the proposed architecture. We demonstrate that our approach offers a more effective and efficient way of CTI sharing that has the potential to overcome the trust barriers, data privacy, and accountability issues inherent in this domain. Kealan Dunnett, Shantanu Pal, Zahra Jadidi, Guntur D. Putra, Raja Jurdak |
ICCCN | 2 |
| 2022 | Security of Machine Learning-Based Anomaly Detection in Cyber Physical SystemsabstractWith the emergence of the Internet of Things (IoT) and Artificial Intelligence (AI) services and applications in the Cyber Physical Systems (CPS), the methods of protecting CPS against cyber threats is becoming more and more challenging. Various security solutions are implemented to protect CPS networks from cyber attacks. For instance, Machine Learning (ML) methods have been deployed to automate the process of anomaly detection in CPS environments. The core of ML is deep learning. However, it has been found that deep learning is vulnerable to adversarial attacks. Attackers can launch the attack by applying perturbations to input samples to mislead the model, which results in incorrect predictions and low accuracy. For example, the Fast Gradient Sign Method (FGSM) is a white-box attack that calculates gradient descent oppositely to maximize the loss and generates perturbations by adding the gradient to unpolluted data. In this study, we focus on the impact of adversarial attacks on deep learning-based anomaly detection in CPS networks and implement a mitigation approach against the attack by retraining models using adversarial samples. We use the Bot-IoT and Modbus IoT datasets to represent the two CPS networks. We train deep learning models and generate adversarial samples using these datasets. These datasets are captured from IoT and Industrial IoT (IIoT) networks. They both provide samples of normal and attack activities. The deep learning model trained with these datasets showed high accuracy in detecting attacks. An Artificial Neural Network (ANN) is adopted with one input layer, four intermediate layers, and one output layer. The output layer has two nodes representing the binary classification results. To generate adversarial samples for the experiment, we used a function called the 'fast_gradient_method’ from the Cleverhans library. The experimental result demonstrates the influence of FGSM adversarial samples on the accuracy of the predictions and proves the effectiveness of using the retrained model to defend against adversarial attacks. Zahra Jadidi, Shantanu Pal, Nithesh Nayak K, Arawinkumaar Selvakkumar, Chih-Chia Chang, Maedeh Beheshti, Alireza Jolfaei |
ICCCN | 2 |
| 2022 | VeriBlock: A Blockchain-Based Verifiable Trust Management Architecture with Provable InteractionsabstractThere has been considerable advancement in the use of blockchain for trust management in large-scale dynamic systems. In such systems, blockchain is mainly used to store the trust score or trust-related information of interactions among the various entities. However, present trust management archi-tectures using blockchain lack verifiable interactions among the entities on which the trust score is calculated. In this paper, we propose a blockchain-based trust management framework that allows independent trust providers to implement different trust metrics on a common set of trust evidence and provide individual trust value. We employ geo-location as proof of interaction. Some of the existing proposals rely upon geo-location data, but they do not support trust calculation by multiple trust providers. Instead, they can only support a centralised system. Our proposed architecture does not depend upon a single centralised third-party entity to ensure trusted interactions. Our architecture is supported by provable interactions that can easily be verified using blockchain. Therefore, it allows a high degree of confidence in trust management by ensuring the actual interactions between the entities. We provide a detailed design and development of the architecture using real-world use case examples. The proof of prototype was implemented on the Ethereum blockchain platform. Experimental results demonstrate that the employment of independent trust providers adequately provides a high degree of trust scores and that the proposed architecture can be used in a real-world environment. Shantanu Pal, Ambrose Hill, Tahiry M. Rabehaja, Michael Hitchens |
ICCCN | 1 |
| 2022 | A Trusted, Verifiable and Differential Cyber Threat Intelligence Sharing Framework using BlockchainabstractCyber Threat Intelligence (CTI) is the knowledge of cyber and physical threats that help mitigate potential cyber attacks. The rapid evolution of the current threat landscape has seen many organisations share CTI to strengthen their security posture for mutual benefit. However, in many cases, CTI data contains attributes (e.g., software versions) that have the potential to leak sensitive information or cause reputational damage to the sharing organisation. While current approaches allow restricting CTI sharing to trusted organisations, they lack solutions where the shared data can be verified and disseminated ‘differentially’ (i.e., selective information sharing) with policies and metrics flexibly defined by an organisation. In this paper, we propose a blockchain-based CTI sharing framework that allows organisations to share sensitive CTI data in a trusted, verifiable and differential manner. We discuss the limitations associated with existing approaches and highlight the advantages of the proposed CTI sharing framework. We further present a detailed proof of concept using the Ethereum blockchain network. Our experimental results show that the proposed framework can facilitate the exchange of CTI without creating significant additional overheads. Kealan Dunnett, Shantanu Pal, Guntur D. Putra, Zahra Jadidi, Raja Jurdak |
TrustCom | 2 |
| 2022 | Device Identification in Blockchain-Based Internet of ThingsabstractIn recent years, blockchain technology has received tremendous attention. Blockchain users are known by a changeable public key (PK) that introduces a level of anonymity; however, studies have shown that anonymized transactions can be linked to deanonymize the users. Most of the existing studies on user deanonymization focus on monetary applications; however, the blockchain has received extensive attention in nonmonetary applications such as the Internet of Things (IoT). In this article, we study the impact of deanonymization on the IoT-based blockchain. We populate a blockchain with data of smart home devices and then apply machine learning algorithms in an attempt to classify the transactions to a particular device that, in turn, risks the privacy of the users. Two types of attack models are defined: 1) informed attacks: where attackers know the type of devices installed in a smart home and 2) blind attacks: where attackers do not have this information. We show that machine learning algorithms can successful classify the transactions with 90% accuracy. To enhance the anonymity of the users, we introduce multiple obfuscation methods which include combining multiple packets into a transaction, merging ledgers of multiple devices, and delaying transactions. The implementation results show that these obfuscation methods significantly reduce the attack success rates to 20%–30% and, thus, enhance the user privacy. Ali Dorri, Clemence Roulin, Shantanu Pal, Sarah Baalbaki, Raja Jurdak, Salil S. Kanhere |
IEEE Internet Things J. | 3 |
| 2022 | Blockchain for IoT access control: Recent trends and future research directions
Shantanu Pal, Ali Dorri, Raja Jurdak |
J. Netw. Comput. Appl. | 1 |
| 2021 | A blockchain-based trust management framework with verifiable interactions
Shantanu Pal, Ambrose Hill, Tahiry M. Rabehaja, Michael Hitchens |
Comput. Networks | 1 |
| 2020 | On the Integration of Blockchain to the Internet of Things for Enabling Access Right DelegationabstractWith the advancement of the Internet of Things (IoT) in recent years, there is a bigger potential to use online services than ever before. The use of the IoT brings numerous opportunities for both service providers and end users, however, it faces critical questions of security and privacy. Toward this, access control is one of the significant security challenges for the IoT, in particular, considering the characteristics of such IoT systems. To develop a secure access control architecture for the IoT, the propagation of access right delegation is a major issue. Many proposals present access control issues for the IoT but given the specific context of access right delegation, it is still in its infancy. This article presents an approach to address such a delegation issue for the IoT using the blockchain technology. We propose a delegation model that employv the critical issues, e.g., the use of nonunique identities, asynchronous and flexible delegation nature of communication for the IoT without the need of a centralized system. The goal of our primitive is to use attributes for validating the identity of an entity instead of relying on a concrete unique identity of an entity. To provide privacy for the attributes, we propose a dual blockchain architecture that moves the attribute storage and access of the public blockchain and onto a secure private blockchain. To demonstrate the feasibility of our proposed approach, we evaluate the system performances using the Ethereum blockchain network. Shantanu Pal, Tahiry M. Rabehaja, Ambrose Hill, Michael Hitchens, Vijay Varadharajan |
IEEE Internet Things J. | 1 |
| 2020 | On the Design of a Flexible Delegation Model for the Internet of Things Using BlockchainabstractThe Internet of things (IoT) presents new opportunities and challenges due to its scale and dynamic nature. One significant challenge for the IoT is the need for security, in particular access control solutions, that are designed to meet the characteristics of these systems. Delegation of rights, from one entity to another, is a crucial component of an access control system. The IoT requires a secure, flexible, and fine-grained delegation model. While there has been considerable work in the area of delegation, much of it assumes a centralized, well-resourced system and these solutions have limited capacity in the context of the IoT. Where delegation models for the IoT have been proposed they typically provide only coarse-grained control over the delegation of rights. Moreover, many of them require a centralized trusted authority, which can suffer from a single-point failure and is not an ideal base for a large and dynamic system like the IoT. In this paper, we propose an identity-less, asynchronous, and decentralized delegation model for the IoT based on blockchain technology. We describe system components, architecture, and key aspects related to the security of the system. We use attributes to validate an entity rather than depending upon unique identities. We demonstrate the feasibility of our model through use-case examples and analyze the performance with a proof of concept testbed implementation using Ethereum private blockchain. Shantanu Pal, Tahiry M. Rabehaja, Michael Hitchens, Vijay Varadharajan, Ambrose Hill |
IEEE Trans. Ind. Informatics | 1 |
| 2019 | Design and implementation of a secure and flexible access-right delegation for resource constrained environments
Tahiry M. Rabehaja, Shantanu Pal, Michael Hitchens |
Future Gener. Comput. Syst. | 2 |
| 2019 | Policy-based access control for constrained healthcare resources in the context of the Internet of Things
Shantanu Pal, Michael Hitchens, Vijay Varadharajan, Tahiry M. Rabehaja |
J. Netw. Comput. Appl. | 1 |
| 2018 | Policy-Based Access Control for Constrained Healthcare ResourcesabstractIn this paper, we propose an access control architecture for constrained healthcare resources in the IoT. Our policy-based approach provides fine-grained access for authorised users to services while protecting valuable resources from unauthorised access. We use a hybrid approach by employing attributes, roles and capabilities for our authorisation design. We apply attributes for role membership assignment and in permission evaluation. Membership of roles grants capabilities. The capabilities which are issued may be parameterised based on further attributes of the user and are then used to access specific services provided by IoT devices. This significantly reduces the number of policies required for specifying access control settings. The proposed scheme is XACML driven. Our approach requires very little additional overhead when compared to other proposals employing capabilities for access control in the IoT. We have implemented a proof of concept prototype and provide a performance evaluation of the implementation. Shantanu Pal, Michael Hitchens, Vijay Varadharajan, Tahiry M. Rabehaja |
WOWMOM | 1 |
| 2017 | Towards a Secure Access Control Architecture for the Internet of ThingsabstractIn this paper, we propose an access control architecture for IoT systems by developing a hybrid model with attributes, capabilities and role-based access control. We apply attributes for role-membership assignment and in permission evaluation, Membership of roles grants capabilities which are used to access specific services provided by things. This approach improves policy management for IoT systems with a large number of things and users. Shantanu Pal, Michael Hitchens, Vijay Varadharajan |
LCN | 1 |
| 2017 | On Design of A Fine-Grained Access Control Architecture for Securing IoT-Enabled Smart Healthcare SystemsabstractThe Internet of Things (IoT) is facilitating the development of novel and cost-effective applications that promise to deliver efficient and improved medical facilities to patients and health organisations. This includes the use of smart 'things' as medical sensors attached to patients to deliver real-time data. However, the security of patient data is an ever-present concern in the healthcare arena. In the wider deployment of IoT-enabled smart healthcare systems one particular issue is the need to protect smart 'things' from unauthorised access. Commonly used access control approaches e.g. Attribute Based Access Control (ABAC), Role Based Access Control (RBAC) and capability based access control do not, in isolation, provide a complete solution for securing access to IoT-enabled smart healthcare devices. They may, for example, require an overly-centralised solution or an unmanageably large policy base. To address these issues we propose a novel access control architecture which improves policy management by reducing the required number of authentication policies in a large-scale healthcare system while providing fine-grained access control. We devise a hybrid access control model employing attributes, roles and capabilities. We apply attributes for role-membership assignment and in permission evaluation. Membership of roles grants capabilities. The capabilities which are issued may be parameterised based on further attributes of the user and are then used to access specific services provided by IoT 'things'. We also provide a formal specification of the model and a description of its implementation and demonstrate its application through different use-case scenarios. Evaluation results of core functionality of our architecture are provided. Shantanu Pal, Michael Hitchens, Vijay Varadharajan, Tahiry M. Rabehaja |
MobiQuitous | 1 |
| 2017 | Evaluating the impact of network loads and message size on mobile opportunistic networks in challenged environments
Shantanu Pal |
J. Netw. Comput. Appl. | 1 |