Saru Kumari

dblp:06/10193 · DBLP profile ↗
← Back
168ranked-venue papers
14as first author
90since 2021 · last 2026
0000-0003-4929-5383ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 59 · 2 first-author · 39 since 2021Security and privacy · 32 · 3 first-author · 7 since 2021Systems, architecture and hardware · 26 · 4 first-author · 11 since 2021Applied, interdisciplinary, general and emerging computing · 23 · 1 first-author · 21 since 2021Graphics, computer vision, multimedia, augmented reality and games · 14 · 4 first-author · 3 since 2021Artificial intelligence and machine learning · 12 · 8 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 Intelligent orchestration of AI service chains in wireless edge networks
Shu Hui Huang, Zhi Wang 0029, Bo Yi 0002, Saru Kumari, Chien-Ming Chen 0001, Jianhui Lv
Comput. Commun.5
2026 LLM -Driven Sustainable Cybersecurity for Future Intelligent Transportation System: RAG -Based Rule Generation and Edge-Optimisation for Roadside Infrastructure
abstract
ABSTRACT With the rapid development of connected autonomous vehicles, intelligent traffic systems are increasingly integrating Roadside Unit (RSU). However, some edge devices in the RSU telecommunication network with limited computing power, due to their simple structures, struggle to implement complex security measures, making them vulnerable nodes in RSU networks and prime targets for cyberattacks. Hence, technologies such as intrusion detection are essential for providing security. However, designing an intrusion detection method that is both efficient and lightweight enough for deployment on RSU devices remains an urgent challenge. To settle these issues, this paper proposes a novel intrusion detection rule generation method that optimise LLM‐Generated Intrusion Detection Rules with support vector machine (SVM). This approach automates the generation of intrusion detection rules for new attack types and employs SVM to optimise the parameter values within these rules, making the LLM‐generated rules more accurate. The generated detection rules are designed to achieve effective intrusion detection on most edge devices, providing a robust solution for enhancing the security of the RSU network. After the verification of the real machine experiment, the proposed IDS has a detection accuracy of 98.89% for the processed attack types.
Guanjie He, Wen Rong, Xinpeng Yao, Mohammed Amoon, Saru Kumari, Chien-Ming Chen 0001
Expert Syst. J. Knowl. Eng.7
2026 Multi-blockchain traceability architecture for minimizing bogus data in insider threat detection
Tsu-Yang Wu, Yehai Xue, Mohammed Amoon, Saru Kumari, Chien-Ming Chen 0001
Future Gener. Comput. Syst.4
2026 DCAChain: A Decentralized Cross-Domain Access-Control Architecture With Key-Abuse Resistance for the Metaverse
Chien-Ming Chen 0001, Bohao Xiang, Saru Kumari
IEEE Internet Things J.3
2026 Privacy-Preserving Avatar Authentication in the Metaverse via First-Image Commitments
abstract
Masquerade and replay attacks on avatars pose critical threats to user privacy and trust in the emerging metaverse. Existing blockchain or decentralized identity (DID) approaches provide auditability but still struggle with unlinkability and lightweight implementation. This paper introduces a privacy-preserving avatar authentication scheme that anchors each user’s identity to a first-image commitment, derived from visual features and a random nonce through a fuzzy extractor (FE). Under the Real-or-Random (ROR) model, we formally prove that the protocol mitigates a range of common threats and simultaneously provides mutual authentication, forward secrecy, and user anonymity. The practicality of the proposed scheme is demonstrated through a head-mounted device–to–server prototype. The average session cost is approximately 21.08 ms, representing a 79.38%–89.58% improvement in computational efficiency over several state-of-the-art blockchain-assisted metaverse authentication schemes. Meanwhile, the corrected communication overhead is around 1.3 Kbits, yielding an 8.89%–43.83% reduction compared with existing counterparts. These results indicate that first-image commitments, combined with blockchain auditability, offer an efficient and privacy-preserving foundation for trustworthy avatar interactions in immersive environments, paving the way toward secure and user-centric metaverse ecosystems.
Chien-Ming Chen 0001, Zhongchao Xiong, Saru Kumari, Yachao Li 0002
IEEE Internet Things J.3
2026 Optimization-driven data-level defense against privacy leakage in pattern recognition
Chien-Ming Chen 0001, Saru Kumari, Yachao Li 0002
Pattern Recognit.3
2026 Learning From Target-Level Incomplete Annotation: A Novel Perspective for Weakly-Supervised Multi-Lesion Segmentation
abstract
Accurately segmenting various clinically significant lesion areas from whole-body computed tomography (CT) scans is crucial for automated diagnosis and treatment planning. Training an automatic segmentation model effectively is desirable, but it heavily relies on a large scale of pixel-wise labeled data, which is laborious, time-consuming, and expensive to obtain. Existing weakly-supervised segmentation approaches often struggle with regions nearby the lesion boundaries. This paper proposes a target-level incomplete annotation (TIA) for medical image annotation and a multi-lesion segmentation framework. TIA annotates only one complete target region per slice to accurately capture boundaries with minimal annotated effort. Multi-lesion segmentation framework is a weakly supervised learning method, which first implements a medical cut-paste segmentation branch to provide images with pure target pixels and boundaries for training the lesion segmentation model, second utilizes prior anatomical information in the prior-assisted target localization branch to locate and identify target regions, third generates high-confidence pseudo-labels by combining the outputs of cut-paste segmentation branch and prior-assisted target localization branch. A graph neural network (GNN) is adopted to correct noisy labels and propagate reliably labeled pixels to unlabeled pixels. By utilizing TIA, our framework can achieve state-of-the-art results for medical image segmentation, which is validated on Crohn's dataset.
Jianguo Ju, Wenhuan Song, Pengfei Xu 0003, Huijuan Tu, Ziyu Guan, Fa Zhu, Saru Kumari
IEEE J. Biomed. Health Informatics8
2026 Multi-Objective Genetic Programming Assisted Stochastic Deep Reinforcement Learning for Dynamic Knowledge Integration in Transportation Networks
abstract
Transportation Networks (TNs) play a critical role in economic and social systems, yet the dynamic nature and inherent heterogeneity of TN data pose challenges for Dynamic Knowledge Integration (DKI). Traditional approaches for matching entities from different knowledge bases often struggle with the complexity and diversity of TN data, which varies across systems and sources such as traffic sensors and GPS devices. To address this issue, this paper proposes a novel Multi-Objective Genetic Programming assisted Stochastic Deep Reinforcement Learning (MOGP-SDRL) for DKI in TNs. Unlike existing methods, the proposed framework combines SDRL and MOGP to achieve superior efficiency, accuracy and adaptability in handling heterogeneous TN data. First, a novel SDRL framework is designed to automate and optimize the selection of Similarity Features (SFs) for entity matching. This framework incorporates a probabilistic action selection mechanism, which enhances exploration during the SF selection process. Second, a novel MOGP is presented to construct high-quality, diverse SFs by exploring non-dominated feature ensembles, enhancing both accuracy and adaptability in matching results, leading to more accurate and adaptable matching results compared to conventional methods. Lastly, new approximate evaluation metrics are developed to assess alignment quality without relying on predefined entity alignments, guiding the optimization process. Experimental evaluations on OAEI’s knowledge graph (KG) dataset and five pairs of real-world TN dataset demonstrate the effectiveness of the MOGP-SDRL framework, which consistently produces high-quality matching results and achieves significant improvements in both accuracy and robustness over existing approaches.
Xingsi Xue, Guojun Mao, Saru Kumari
IEEE Trans. Intell. Transp. Syst.3
2026 Federated Learning Intersection Vehicle Trajectory Prediction Scheme Within Digital Twin
abstract
Digital Twin (DT) technology has gained significant attention for simulating and optimizing urban traffic systems, especially in intersection vehicle trajectory prediction. However, digital twin traffic system faces significant challenges due to privacy and security regulations that prevent the centralized storage of trajectory and semantic data, which are essential for training accurate predictive models using sensitive traffic information. To address these issues, we introduce the integration of federated learning spatio-temporal-semantic attention-based trajectory (FedSTAST) model into the DT framework for vehicle trajectory prediction. In our FedSTAST, edge servers in physical space utilize local sensor data to perform computations and train models without transmitting raw data, only the model parameters are sent to a cloud server in the twin space for aggregation. This decentralized approach ensures data privacy while enabling collaborative model training. The simulation results demonstrate that the FedSTAST model effectively handles co-training and multi-source semantic input processing within spatio-temporal-semantic attention-based trajectory (STSAT) models, enhancing trajectory prediction accuracy and robustness in the dynamic, real-time context of DT-based urban traffic systems.
Yanan Zhao 0002, Yang Yang 0148, Haiyang Yu 0002, Saru Kumari, Mohammed Amoon, Sachin Kumar 0002, Yilong Ren
IEEE Trans. Intell. Transp. Syst.4
2026 Privacy-Preserving Digital Publishing Framework for Next-Generation Communication Networks: A Verifiable Homomorphic Federated Learning Approach
abstract
Next-generation communication networks are revolutionizing digital publishing through intelligent content distribution and collaborative optimization capabilities. However, existing federated learning approaches face fundamental limitations, including trusted third-party dependencies, excessive communication overhead, and vulnerability to collusion attacks between servers and participants. This paper introduces VHFL-DP, a verifiable homomorphic federated learning framework for digital publishing environments operating within 6G network infrastructures. The framework addresses critical privacy and scalability challenges through four key innovations: a distributed cryptographic key generation protocol that eliminates trusted third-party requirements, Chinese remainder theorem-based dimensionality reduction, auxiliary validation nodes that enable independent verification with constant-time complexity, and an intelligent incentive mechanism that rewards digital publishing platforms based on objective contribution quality metrics. Experimental evaluation on MNIST and Amazon reviews datasets across six baseline methods demonstrates that VHFL-DP achieves superior performance with accuracy improvements of 4.2% over the best baseline method. The framework maintains constant verification time ranging from 2.73 to 2.91 seconds regardless of platform count, increasing from ten to fifty, or dropout rates reaching thirty percent. Security evaluation reveals strong resilience with only 2.4 percentage point accuracy degradation under poisoning attacks compared to 6.7-7.0 points for baseline method, inference attack success near random guessing at 51.3%, and 92.4% successful aggregation under Byzantine adversaries.
Yanxu Lin, Renzhong Zhong, Jingnan Xie 0002, Yueting Zhu, Byung-Gyu Kim, Saru Kumari, Shakila Basheer, Fatimah Alhayan
IEEE Trans. Netw. Serv. Manag.6
2026 Efficient and Privacy-Enhanced Asynchronous Federated Learning for Multimedia Data in Edge-Based IoT
abstract
With the rapid development of smart device technology, the current version of the Internet of Things (IoT) is moving towards a multimedia IoT because of multimedia data. This innovative concept seamlessly integrates multimedia data with the IoT-Edge Continuum. Recently, a distributed learning framework has shown promise in revolutionizing various industries, including smart cities, healthcare, etc. However, these applications may face challenges, such as the presence of malicious devices that invade the privacy of other devices or corrupt uploaded model parameters. Additionally, the existing synchronous federated learning (FL) methods face challenges in effectively training models on local datasets due to the diversity of IoT devices. To tackle these concerns, we propose an efficient and privacy-enhanced asynchronous FL approach for multimedia data in edge-based IoT. In contrast to traditional FL methods, our approach combines revocable attribute-based encryption (RABE) and differential privacy (DP). This guarantees the privacy of the entire process while allowing seamless collaboration between multiple devices and the aggregation server during model training. Also, this combination brings a dynamic nature to the system. Furthermore, we utilize an asynchronous weight-based aggregation algorithm to improve the efficiency of training and the quality of the final returned model. Our proposed scheme is confirmed by theoretical safety proofs and experimental results with multimedia data. Performance evaluation shows that our framework reduces the cryptography runtime by 63.3% and the global model aggregation time by 61.9% compared to cutting-edge schemes. Moreover, our accuracy is comparable to the most primitive FL schemes, maintaining 86.7%, 70.8%, and 86.1% on MNIST, CIFAR-10, and Fashion-MNIST, respectively. The experimental results highlight the remarkable practicality, resilience and effectiveness of the proposed scheme.
Hu Xiong, Hang Yan 0009, Mohammad S. Obaidat, Jingxue Chen, Mingsheng Cao 0001, Sachin Kumar 0002, Kadambri Agarwal, Saru Kumari
ACM Trans. Multim. Comput. Commun. Appl.8
2025 Graph convolutional networks and deep reinforcement learning for intelligent edge routing in IoT environment
Zhi Wang 0029, Bo Yi 0002, Saru Kumari, Chien-Ming Chen 0001, Mohammed J. F. Alenazi
Comput. Commun.3
2025 Advancing explainability of adversarial trained Convolutional Neural Networks for robust engineering applications
Dehua Zhou, Ziyu Song, Zicong Chen, Xianting Huang, Congming Ji, Saru Kumari, Chien-Ming Chen 0001, Sachin Kumar 0002
Eng. Appl. Artif. Intell.6
2025 Efficient malware detection using hybrid approach of transfer learning and generative adversarial examples with image representation
abstract
Abstract Identifying malicious intent within a program, also known as malware, is a critical security task. Many detection systems remain ineffective due to the persistent emergence of zero‐day variants, despite the pervasive use of antivirus tools for malware detection. The application of generative AI in the realm of malware visualization, particularly when binaries are depicted as colour visuals, represents a significant advancement over traditional machine‐learning approaches. Generative AI generates various samples, minimizing the need for specialized knowledge and time‐consuming analysis, hence boosting zero‐day attack detection and mitigation. This paper introduces the Deep Convolutional Generative Adversarial Network for Zero‐Shot Learning (DCGAN‐ZSL), leveraging transfer learning and generative adversarial examples for efficient malware classification. First, a normalization method is proposed, resizing malicious images to 128 × 128 or 300 × 300 for standardized input, enhancing feature transformation for improved malware pattern recognition. Second, greyscale representations are converted into colour images to augment feature extraction, providing a richer input for enhanced model performance in malware classification. Third, a novel DCGAN with progressive training improves model stability, mode collapse, and image quality, thus advancing generative model training. We apply the Attention ResNet‐based transfer learning method to extract texture features from generated samples, which increases security evaluation performance. Finally, the ZSL for zero‐day malware presents a novel method for identifying previously unknown threats, indicating a significant advancement in cybersecurity. The proposed approach is evaluated using two standard datasets, namely dumpware and malimg, achieving malware classification accuracies of 96.21% and 98.91%, respectively.
Yue Zhao 0014, Farhan Ullah 0001, Chien-Ming Chen 0001, Mohammed Amoon, Saru Kumari
Expert Syst. J. Knowl. Eng.5
2025 Privacy-Preserving Lightweight LoRaWAN Authentication Protocol for IoT Applications
abstract
Security and privacy are two primary concerns in critical applications within Internet of Things (IoT) environments. The Long Range Wide Area Network (LoRaWAN) protocol facilitates long-range communication for battery-powered end devices in IoT and has gained widespread adoption among both individuals and industries. To foster trust and facilitate its use, ensuring security and privacy for data collected by end devices is essential. User authentication and key establishment protocols play a pivotal role in this regard. While existing authentication schemes in the literature are unsuitable for LoRaWAN networks, this article proposes an energy-efficient LoRaWAN authentication protocol for privacy preservation in IoT applications. Through formal verification using the Random Oracle Model (ROM) and AVISPA tool, we demonstrate our protocol’s resilience against common attacks including replay, man-in-the-middle, and impersonation threats. Performance evaluations reveal significant advantages over existing schemes: 48% faster computation (0.1953 ms vs. 0.3647 ms baseline), 24% lower communication overhead (2398 bits vs. 3168 bits), and 44% energy savings (1.27 mJ vs. 2.27 mJ) over state-of-the-art protocols. These improvements, combined with enhanced security features, such as resistance to sensor capture and stolen device attacks, make our protocol particularly suitable for practical IoT deployments in smart agriculture and industrial monitoring systems where both security and energy efficiency are paramount. The balance of strong security guarantees and low operational overhead represents a significant advance in LoRaWAN authentication mechanisms.
Muhammad Arslan Akram, Adnan Noor Mian, Arnab Kumar Biswas, Saru Kumari, Chien-Ming Chen 0001
IEEE Internet Things J.4
2025 Protecting Virtual Economies: A Blockchain-Based Anti-Phishing Authentication Protocol for Metaverse Applications
abstract
Phishing attacks pose significant cybersecurity threats in the metaverse, particularly in virtual gaming environments where sensitive identity information and digital assets are at risk. This paper introduces a blockchain-based anti-phishing authentication protocol that enhances the security and efficiency of virtual game recharge orders. The proposed protocol integrates elliptic curve cryptography, symmetric encryption, and Chebyshev chaotic mapping to establish a robust three-factor authentication mechanism. By leveraging blockchain’s decentralized and tamper-proof properties, the protocol securely stores identity information and authentication keys, enabling users to effectively identify phishing websites and ensure secure cross-platform transactions. Security analysis using the Real-Or-Random (ROR) model demonstrates the protocol’s resistance to phishing attacks, and its provision of forward security and anonymity. Comparative performance evaluation also highlights the protocol’s significant advantages in computational and communication efficiency over existing methods. This study contributes to the advancement of secure virtual transactions, fostering trust and sustainability in the metaverse economy.
Chien-Ming Chen 0001, Zhongchao Xiong, Tsu-Yang Wu, Saru Kumari, Mohammed J. F. Alenazi
IEEE Internet Things J.4
2025 Equality Test on Identity-Based Encryption With Cryptographic Reverse Firewalls for Telemedicine Systems
abstract
The emergence of the COVID-Omicron XBB variant has intensified the need for wireless body area networks (WBANs) in telemedicine, underscoring their critical role in remote patient monitoring and demanding robust security solutions to protect health data and patient privacy. To address this need, we introduce the equality test on identity-based encryption with cryptographic reverse firewalls (ET-IBE-CRFs). This protocol allows the medical server in a telemedicine system to execute the equality test on the encrypted data and retrieve the result without knowing any relevant information about the ciphertext. By incorporating cryptographic reverse firewalls (CRFs), the ET-IBE-CRF protocol effectively counters offline message recovery attacks (OMRAs) and algorithm substitution attacks (ASAs) without requiring secure communication channels. Our evaluation indicates that ET-IBE-CRF not only meets the strict requirements for confidentiality and privacy in telemedicine applications but also maintains high efficiency. This makes it well-suited for high-performance telemedicine systems.
Rashad Elhabob, Nabeil Eltayieb, Hu Xiong, Saru Kumari
IEEE Internet Things J.4
2025 An Enhanced Security Protocol for Vehicular Ad Hoc Networks
abstract
The present work aims to address key security vulnerabilities in Vehicular Ad Hoc Networks (VANETs) through an enhanced authentication scheme. This study evaluates the effectiveness of utilizing Elliptic Curve Cryptography (ECC) for improving security efficiency and compares it with conventional techniques used in state-of-the-art authentication protocols. The results demonstrate improvements in both computational and communication efficiency. A rigorous formal analysis using the Tamarin Prover confirms the robustness of the proposed security processes. Real-world implementation of the proposed protocol using Raspberry Pi devices is conducted and empirical performance tests using NS-3 (Network Simulator 3) show a 30% improvement in computational efficiency and a 25% reduction in authentication delay compared to conventional techniques, along with a 98% success rate in evading impersonation attacks and a 95% success rate in preventing replay attacks while maintaining similar efficiency levels.
Hossein Geranfar, Bahman Abolhassani, Nasour Bagheri, Alireza Javadi, Pedro Peris-Lopez, Carmen Camara, Saru Kumari
IEEE Internet Things J.7
2025 Smart IoE-Integrated Traffic Control: Dynamic Multisemantic Graph Attention and Reinforcement Learning for Optimizing Urban Mobility
abstract
The rapid advancement of Internet of Everything (IoE) technologies has transformed the landscape of urban mobility management, necessitating innovative approaches to optimize traffic flow and reduce congestion. This article presents the dynamic multisemantic graph attention network (DMSGAT), leveraging real-time IoE data to construct dynamic spatial graphs that capture complex spatial dependencies across multiple semantic layers. These graphs are processed through the multisemantic graph attention module, which dynamically learns and integrates information from semantic relationships, ensuring accurate spatial modeling. Simultaneously, the temporal module, incorporating a self-forgetting residual connection network with temporal convolution, effectively models temporal dependencies, allowing the system to adapt to the dynamic nature of traffic flows. Additionally, we extend the model for adaptive traffic control by integrating reinforcement learning (RL), namely dynamic multisemantic graph attention with RL (DMSGARL). The integrated RL module further optimizes traffic control strategies in real time, responding to the continuous influx of data from IoE devices. Experimental results demonstrate that the proposed DMSGAT framework significantly improves traffic prediction accuracy and efficiency in urban mobility scenarios. The integrated RL DMSGARL model shows significant throughput improvements, offering a robust solution for smart city traffic management.
Kuo-Kun Tseng, Zhengguang Yang, Haotian Tang, Chien-Ming Chen 0001, Saru Kumari, M. Shamim Hossain
IEEE Internet Things J.5
2025 Rare yet critical: Algorithms for privacy preserving rare itemset mining
Chien-Ming Chen 0001, Jianhui Lv, Saru Kumari
Inf. Sci.4
2025 Open-world multi-modal machine learning decision model based on uncertain data analysis for fetal heart diagnosis
Guosong Zhu, Zhen Qin 0002, Hu Xiong, Saru Kumari, Mohammed J. F. Alenazi, Yingkun Guo, Chien-Ming Chen 0001
Inf. Sci.4
2025 FinSec: A Consortium Blockchain-Enabled Privacy-Preserving and Scalable Framework For Customer Data Protection In FinTech
Akhilesh Sharma, Preeti Chandrakar, Saru Kumari, Chien-Ming Chen 0001
Peer Peer Netw. Appl.3
2025 An enhanced three-factor based authentication and key agreement protocol using PUF in IoMT
Tsu-Yang Wu, Haozhi Wu, Saru Kumari, Chien-Ming Chen 0001
Peer Peer Netw. Appl.3
2025 Multigraph Neural Networks for Social-Aware Session-Based Recommendation in Large-Scale Dynamic Social Computing Environments
abstract
The rapid growth of social media platforms has led to an unprecedented increase in user-generated content and social interactions, posing significant challenges for recommendation systems. This article addresses the challenges of recommendation in large-scale dynamic social environments, where user interactions and preferences evolve rapidly across vast networks. In large-scale dynamic social networks, knowledge discovery requires methods to efficiently process vast amounts of data while capturing the evolving nature of user interactions and preferences. Multigraph neural networks offer a promising approach for this task, as they can model complex relationships and temporal dynamics in these environments. This article proposes a novel social-aware multigraph neural network for the session-based recommendation (SAMGNN-SR) model that leverages dynamic social information and multigraph neural networks to enhance recommendation accuracy and knowledge discovery in complex social computing environments. The model constructs a global social-aware interaction graph from all user session sequences and employs an adaptive subgraph sampling strategy to extract relevant collaborative signals efficiently. A dynamic interest extraction module utilizing dual-direction information propagation captures users' evolving preferences, while a social information fusion network based on graph attention mechanisms models the dynamic nature of social influences. Experiments on three real-world datasets (Douban, Delicious, and Yelp) demonstrate the superiority of SAMGNN-SR over nine state-of-the-art baselines, with improvements of up to 6.79% in NDCG@20 and 6.19% in Hit@20. Ablation studies validate the effectiveness of each model component in capturing complex social dynamics and session-based user behaviors.
Hai Zhu 0001, Jixun Gao, Xingsi Xue, Zhongyang Yu, Chien-Ming Chen 0001, Saru Kumari, Sachin Kumar 0002
IEEE Trans. Comput. Soc. Syst.6
2025 Lightweight Privacy-Friendly Aggregation Scheme Against Internal Attacks for Smart Grids
abstract
While real-time electricity consumption data of users in smart grids can enable value-added services, such as Big Data analytics, each individual user's privacy needs to be protected. How to balance data utility and privacy protection is a significant issue, of which privacy-preserving data aggregation (PPDA) is a viable solution. Prior to this, researchers have proposed a number of PPDA schemes to address the above challenge. Unluckily, most of them suffer from security and privacy drawbacks, while others are inappropriate for resource-limited smart meters due to high cost of cryptographic operations. To tackle this issue, in this article, we propose a pairing-free and exponentiation-free certificateless PPDA scheme named CL-PPDA for smart grids. We prove the security of our design and analyze its performance. Comparative analyses with state-of-the-art work in theory and experiment show that our design not only has better security properties, but also has competitive computation overhead, especially on the resource-constrained smart meter side. Besides, we present an extension of our CL-PPDA scheme to support multidimensional data aggregation, which further enriches the functionality of our design.
Wei Wu 0001, Alsharif Abuadbba, Saru Kumari, Xu Yang 0002, Ibrahim Khalil 0001, Xun Yi
IEEE Trans. Ind. Informatics4
2025 Guest Editorial: On Advancing Healthcare Informatics With Large Language Models
Saru Kumari, Chien-Ming Chen 0001, Mohammad Shojafar, Muhammad Naveed Aman
IEEE J. Biomed. Health Informatics1
2025 SeqNovo: De Novo Peptide Sequencing Prediction in IoMT via Seq2Seq
abstract
In the Internet of Medical Things (IoMT), de novo peptide sequencing prediction is one of the most important techniques for the fields of disease prediction, diagnosis, and treatment. Recently, deep-learning-based peptide sequencing prediction has been a new trend. However, most popular deep learning models for peptide sequencing prediction suffer from poor interpretability and poor ability to capture long-range dependencies. To solve these issues, we propose a model named SeqNovo, which has the encoding-decoding structure of sequence to sequence (Seq2Seq), the highly nonlinear properties of multilayer perceptron (MLP), and the ability of the attention mechanism to capture long-range dependencies. SeqNovo use MLP to improve the feature extraction and utilize the attention mechanism to discover key information. A series of experiments have been conducted to show that the SeqNovo is superior to the Seq2Seq benchmark model, DeepNovo. SeqNovo improves both the accuracy and interpretability of the predictions, which will be expected to support more related research.
Ke Wang 0068, Mingjia Zhu, Wadii Boulila, Maha Driss, G. Thippa Reddy, Chien-Ming Chen 0001, Lei Wang 0005, Saru Kumari, Siu-Ming Yiu
IEEE J. Biomed. Health Informatics8
2025 An Intelligent Blockchain-Enabled Authentication Protocol for Transportation Cyber-Physical Systems
abstract
Transportation Cyber-Physical System (T-CPS) is a pivotal technology for advancing Intelligent Transportation System, integrating physical transportation infrastructure with network technology and computational algorithms. This integration facilitates real-time road condition monitoring, accurate traffic forecasting, and efficient traffic management to reduce congestion and enhance safety. However, relying on public channels for data transmission in T-CPS exposes it to numerous security threats. Addressing these challenges, this paper proposes an intelligence blockchain-based lightweight authentication protocol to enhance the security and trustworthiness of Intelligent Transportation System. The protocol is designed to resist common attacks, such as capture attacks and insider privileged personnel attacks, ensuring secure vehicle communication. Through rigorous Real-Or-Random model formal proofs, the security properties of the protocol are validated. Furthermore, the efficiency of the protocol is demonstrated, showing its lightweight nature and security robustness. This work represents a significant step toward secure, reliable, and efficient communication in vehicular networks, paving the way for more robust T-CPS applications, including autonomous driving and real-time traffic management.
Chien-Ming Chen 0001, Yiru Hao, Saru Kumari, Mohammed Amoon
IEEE Trans. Intell. Transp. Syst.3
2025 Mutual Authentication and Trust Establishment (MATE) Protocol in VANET Using Puncturable Pseudorandom Function (PPRF): MATE-PPRF
abstract
Vehicular Ad hoc NETwork (VANET) refers to an arbitrarily distributed network that is an integral subset of an Intelligent Transport System (ITS) and plays a vital role in providing convenient transportation, improving traffic safety, etc.VANETrealizes interactive communication through wireless medium among Vehicle to Vehicle (V2V) and Vehicle to Infrastructure (V2I). But, owing to the open/public communication nature of the wireless medium, it is often prone to different security threats. On the other hand, security is a significant aspect of theVANETframework. Thus, to address the security concerns, it is a common practice to establish an authentication and key agreement protocol among the communicating entities that ensures to provide the essential security requirements. However, after extensive literature survey, it is identified that all the existing authentication protocols are prone to different security threats. Moreover, the implementation of these protocols in real-world scenarios becomes impractical as it bears higher computation and/or communication overheads. Therefore, in this paper, we have proposed a trust-extended mutual authentication protocol for theVANETframework using a Puncturable Pseudorandom Function (PPRF). The informal and formal security verification of our protocol proves that it provides comparably higher security than the existing schemes. Further, our protocol is simulated using a well-known AVISPA simulation tool and the results show that our protocol is SAFE against replay and man-in-the-middle attacks. Additionally, in comparison to the existing literature our protocol provides higher computation and communication efficiency. Therefore, our protocol is reliable and secure for real-world implementation in theVANETframework.
Priyanka Das 0011, Sangram Ray, Mou Dasgupta, Saru Kumari, Chien-Ming Chen 0001, Mahesh Chandra Govil, Mohammed Amoon
IEEE Trans. Intell. Transp. Syst.4
2025 CALRA: Practical Conditional Anonymous and Leakage-Resilient Authentication Scheme for Vehicular Crowdsensing Communication
abstract
Vehicular crowdsensing (VCS) has aroused extensive attention because of its ability to provide comprehensive data services for intelligent transportation systems. Wherein, secure data transmission is a prerequisite for realizing the above benefits of VCS. Unfortunately, although many works on secure data sharing have been proposed, these schemes suffer from practical weaknesses such as data source authentication, malicious identity traceability, and inefficiency. In this paper, we propose a practical conditional anonymization and leakage-resilient authentication solution for vehicular crowdsensing communication (CALRA). Our proposal not only resists the leakage of sensitive information about vehicles but also realizes the authentication of data senders, while guaranteeing the integrity, authenticity, and confidentiality of data. Besides, CALRA exploits traceability technology to pursue malicious/illegal participants, thus avoiding participants’ accountability evasion caused by absolute anonymity. Furthermore, our CALRA solution delegates complex computational processes into an offline formulation to reduce computational and communication overheads. Finally, our scheme is proved to be secure and unforgeable through the random oracle model, and the performance evaluation illustrates that our CALRA proposal is superior and practical.
Jianru Xiao, Yilong Ren, Jiewei Du, Yanan Zhao 0002, Saru Kumari, Mohammed J. F. Alenazi, Haiyang Yu 0002
IEEE Trans. Intell. Transp. Syst.5
2025 DAGShare: a DAG-based personal file sharing framework with off-chain IPFS and access control
Hira Arshad, Areeb Ahmed Bhutta, Adnan Noor Mian, Sumbal Fatima, Saru Kumari, Chien-Ming Chen 0001
J. Supercomput.5
2024 Towards classification and comprehensive analysis of AI-based COVID-19 diagnostic techniques: A survey
Amna Kosar, Muhammad Asif 0002, Maaz Bin Ahmad, Waseem Akram 0003, Khalid Mahmood 0002, Saru Kumari
Artif. Intell. Medicine6
2024 Privacy preserving support vector machine based on federated learning for distributed IoT-enabled data analysis
abstract
Abstract In a smart city, IoT devices are required to support monitoring of normal operations such as traffic, infrastructure, and the crowd of people. IoT‐enabled systems offered by many IoT devices are expected to achieve sustainable developments from the information collected by the smart city. Indeed, artificial intelligence (AI) and machine learning (ML) are well‐known methods for achieving this goal as long as the system framework and problem statement are well prepared. However, to better use AI/ML, the training data should be as global as possible, which can prevent the model from working only on local data. Such data can be obtained from different sources, but this induces the privacy issue where at least one party collects all data in the plain. The main focus of this article is on support vector machines (SVM). We aim to present a solution to the privacy issue and provide confidentiality to protect the data. We build a privacy‐preserving scheme for SVM (SecretSVM) based on the framework of federated learning and distributed consensus. In this scheme, data providers self‐organize and obtain training parameters of SVM without revealing their own models. Finally, experiments with real data analysis show the feasibility of potential applications in smart cities. This article is the extended version of that of Hsu et al. (Proceedings of the 15th ACM Asia Conference on Computer and Communications Security. ACM; 2020:904‐906).
Yu-Chi Chen 0001, Song-Yi Hsu, Xin Xie 0005, Saru Kumari, Sachin Kumar 0002, Joel J. P. C. Rodrigues, Bander A. Alzahrani
Comput. Intell.4
2024 Digital twin-assisted service function chaining in multi-domain computing power networks with multi-agent reinforcement learning
Kan Wang 0010, Mian Ahmad Jan, Fazlullah Khan, G. Thippa Reddy, Saru Kumari, Lei Liu 0031
Future Gener. Comput. Syst.6
2024 A Post-Quantum Compliant Authentication Scheme for IoT Healthcare Systems
abstract
In an Internet of Things (IoT)-based healthcare system, medical IoT devices gather and transmit critical patient data. Ensuring the security and privacy of medical data is paramount. One of the most critical challenges in this regard is the authentication of participating entities. The literature proposes specific authentication approaches for healthcare systems based on integer factorization and discrete logarithm problems. However, the advent of quantum computers would fundamentally break all of these protocols. In this study, we conducted an analysis of a recently proposed authentication and access control scheme for e-health systems, which is based on lattice-based cryptography and was developed by Gupta et al. Our analysis revealed that the scheme is vulnerable to several types of attacks, including impersonation, de-synchronization, and smart card stolen attacks, which could compromise the confidentiality and integrity of sensitive medical data. To address these security challenges, we propose an alternative authentication and access control scheme that uses Saber, a finalist lattice-based key encapsulation algorithm from round three of the NIST post-quantum cryptography standardization. One of the biggest advantages of Saber is its simplicity and efficiency. Our proposed scheme is designed specifically for e-health systems and provides robust protection against the vulnerabilities identified in Gupta et al.’s scheme. We believe that our proposed scheme represents a significant improvement over existing approaches and could help to enhance the security and privacy of e-health systems. Upon completion of our improved protocol, we proceeded to implement it within the Vivado 2018.3 environment for Zynq UltraScale FPGAs. To gather insight into its performance, we conducted a performance comparison study with various related protocols.
Morteza Adeli, Nasour Bagheri, Hamid Reza Maimani, Saru Kumari, Joel J. P. C. Rodrigues
IEEE Internet Things J.4
2024 An AR-Based Meta Vehicle Road Cooperation Testing Systems: Framework, Components Modeling, and an Implementation Example
abstract
In this study, we introduce an AR-based Meta-Vehicle Road Collaboration Testing System (AR-MVRTs), a significant advancement in autonomous driving testing. This system utilizes vehicle-road collaboration, Augmented Reality (AR), and Metaverse technologies for high-risk scenario simulation and dynamic interaction between virtual data and actual vehicles and infrastructure, enhancing verification and optimization methods. The core contribution is the innovative framework and component model, integrating AR with vehicle-road collaboration technologies for a comprehensive environment that includes real autonomous vehicles, virtual scenarios, and parameterized test settings. The AR-MVRTs method efficiently generates critical testing scenarios, significantly improving testing efficiency. An implementation case shows the system’s practical application, where AR-MVRTs demonstrated a 658-fold efficiency increase, completing tests in 8.5 hours compared to 5580 hours required by traditional test matrices. This integration accelerates the transition from theoretical research to practical applications and offers deep insights into autonomous vehicle safety and reliability. This research promises to advance autonomous driving technology and lay a solid foundation for its future development.
Xuesong Bai, Peng Dong 0002, Yuanhao Huang, Saru Kumari, Haiyang Yu 0002, Yilong Ren
IEEE Internet Things J.4
2024 Blockchain-Based Mutual Authentication Protocol for IoT-Enabled Decentralized Healthcare Environment
abstract
In the ever-evolving landscape of technology, healthcare continuously harnesses its benefits, propelling advancements in medical practices. Within intelligent healthcare, medical robots play a pivotal role, providing integral support to healthcare professionals, streamlining processes, and delivering efficient services. These robots securely transmit patient treatment plans, transferring them to cloud storage and subsequently storing them in blockchain systems. This innovative approach ensures the integrity and accessibility of patient data, introducing novel avenues for seamless interaction with medical information for hospitals and patients’ families. Despite these advantages, the looming privacy risks associated with sensitive patient data transmission pose a compelling challenge, demanding a comprehensive solution. In response to this challenge, we propose a mutual authentication and key agreement protocol designed to optimize healthcare services while prioritizing data security and patient privacy. To validate the robustness of our authentication protocol, we conduct thorough analyses based on both formal and informal models, establishing a foundational framework for evaluating the protocol’s security. Additionally, we perform a comprehensive comparative analysis, assessing the proposed protocol against existing counterparts across various dimensions. This comparative scrutiny reveals the superiority of our protocol in terms of security, as well as its efficiency in communication cost and computational overhead. These findings affirm the efficacy of our proposed solution in navigating the intricate interplay between medical robotics, blockchain, and data security.
Chien-Ming Chen 0001, Zhaoting Chen, Saru Kumari, Mohammad S. Obaidat, Joel J. P. C. Rodrigues, Muhammad Khurram Khan
IEEE Internet Things J.3
2024 A Privacy-Preserving Authentication Protocol for Electric Vehicle Battery Swapping Based on Intelligent Blockchain
abstract
The Internet of Vehicles (IoV) integrates wireless, mobile networking, cloud infrastructure, IoT, and wireless sensor networks, establishing an intelligent transportation system. While electric vehicles (EVs) contribute to environmental sustainability, they encounter challenges; battery-swapping technology emerges as a viable solution. Nevertheless, concerns arise regarding data security, privacy, and potential single points of failure. To address these issues, we propose a privacy-preserving authentication protocol based on intelligent blockchain. This protocol ensures the security and reliability of data storage and transaction verification processes, simultaneously upholding privacy, including user anonymity and untraceability. Additionally, leveraging the decentralized nature of intelligent blockchain, each participating node retains a copy of the data and verifies it through consensus algorithms to ensure its integrity and credibility. Verification using the Real-Oracle Random (ROR) model demonstrates both effectiveness and security, with informal analysis confirming resilience against known attacks. Comparative analysis underscores the proposed protocol’s security and performance advantages, placing emphasis on its reliability.
Chien-Ming Chen 0001, Qingkai Miao, Saru Kumari, Muhammad Khurram Khan, Joel J. P. C. Rodrigues
IEEE Internet Things J.3
2024 Provably Secure Anti-Phishing Scheme for Medical Information in Smart Healthcare
abstract
In the rapidly evolving field of smart healthcare, integrating modern information technologies, such as Internet of Things, big data, and AI, has significantly enhanced the quality, efficiency, and accessibility of medical services. However, this technological advancement also brings substantial security challenges, particularly regarding protecting electronic medical records (EMRs) from phishing attacks. This article presents a provably secure anti-phishing scheme to safeguard EMRs in smart healthcare systems. By utilizing authentication and key agreement technology, our proposed scheme ensures mutual authentication between users and servers, leveraging elliptic curve encryption, symmetric encryption, hash functions, and XOR operations to secure session keys and verify the legitimacy of medical records. Our scheme addresses critical security challenges, including phishing attacks, stolen mobile device attacks, offline password guessing attacks, replay attacks, and temporary information leakage. The real-oracle-random (ROR) model validates the correctness and security of our scheme, confirming its robustness against common cybersecurity threats. Performance evaluations demonstrate that our scheme provides enhanced security and offers lower time and communication costs compared to existing methods. This makes it a highly efficient and practical solution for safeguarding patient data in smart healthcare environments, ultimately contributing to the reliability and trustworthiness of smart healthcare systems.
Shuangshuang Liu, Zhi Wang 0014, Saru Kumari, Jianhui Lv, Chien-Ming Chen 0001
IEEE Internet Things J.3
2024 Practical Feature Inference Attack in Vertical Federated Learning During Prediction in Artificial Internet of Things
abstract
The emergence of edge computing guarantees the combination of the Internet of Things (IoT) and artificial intelligence (AI). The vertical federated learning (VFL) framework, usually deployed by split learning, can analyze and integrate information on different features collected by different terminals in the IoT. The complete model is divided into a top model and multiple bottom models in a specific middle layer. Each passive party as a terminal with certain features owns a bottom model, and an active party as an edge server with labels holds the top model. Feature inference attack aims to infer the party’s features from the model predictions during prediction in VFL. Existing attacks considered the adversary an active party under the white-box or black-box model. However, an attacker usually is a passive party in practice because terminals are more vulnerable than edge servers. Therefore, this article discusses a practical feature inference attack in VFL during prediction in IoT under this setting. We design an adversary builds an inference model to minimize the distance between the predictions from the inferred features and target features. Because the information on the top model and other bottom models is unknown, the adversary cannot directly train the inference model. Therefore, we utilize the zeroth-order gradient estimation method to calculate the parameters’ gradients to train the inference model. Experimental results demonstrate that the performance of our attack is comparable to that of the white-box attacks while retaining apparent advantages over the existing black-box attacks.
Ruikang Yang, Jianfeng Ma 0001, Saru Kumari, Sachin Kumar 0002, Joel J. P. C. Rodrigues
IEEE Internet Things J.4
2024 Transferability of Adversarial Attacks on Tiny Deep Learning Models for IoT Unmanned Aerial Vehicles
abstract
In the realm of miniature machine learning for Internet of Unmanned Aerial Vehicles (UAVs), the security concerns of machine learning models are obvious, especially when it comes to adversarial attacks. Models can become confused and their performance undermined by the introduction of meticulously crafted distortions. These attacks can even infiltrate a variety of models, bringing greater security risks. To understand how it works and mitigate its effects, our research focuses on scrutinizing the transferability of adversarial attacks in the expanding context of miniature machine learning for UAVs. In this paper, we introduce a formula help measure the transferability of adversarial attacks and explore ways to improve the transferability and effectiveness of adversarial attacks (e.g., a combination of attack techniques), and provide visulizations to vividly illustrate the repercussions of adversarial instances across a spectrum of attack intensities, helping facilitate more intuitive exploration and analysis of the results. For instance, our findings demonstrate that even subtle perturbations directed at specific attributes can lead to a significant decrease in model accuracy. We also evaluates the success rates of various attack algorithms and validates the proposed evaluation methodology for measuring transferability. And the outcomes unveiled in this study make noteworthy strides in fostering a profound comprehension of the transferability of adversarial attacks in the distinct realm of miniature machine learning for UAVs. Robust defense mechanisms, which ensure the impregnability of IoT-enabled UAV systems, can be cultivated by pinpointing the most efficacious attack strategies and evaluating their transferability.
Xianting Huang, Mohammad S. Obaidat, Bander A. Alzahrani, Xuming Han, Saru Kumari, Chien-Ming Chen 0001
IEEE Internet Things J.6
2024 Lightweight Verifiable Privacy-Preserving Data Aggregation for Smart Grids
abstract
As an indispensable part of a smart city, the smart grid has gained widespread attention from industrial and academic communities. How to securely collect users’ real-time energy consumption data to provide services such as big data analytics and demand-response services while ensuring the privacy of individual users is a challenging issue in the smart grid. The privacy-preserving data aggregation (P2DA) suggests a feasible solution. For years, researchers have designed numerous P2DA schemes for securing smart grids. Unfortunately, the majority of them have some security and privacy deficiencies. Other schemes are unsuitable for resource-constrained smart meters due to expensive cryptographic operations. In this work, we design a lightweight verifiable certificate-based P2DA scheme LV-P2DA without pairings for smart grids. We formally prove its security under standard cryptographic assumptions. The performance comparison results illustrate that compared with state-of-the-art solutions, our design achieves at least a 99.43% improvement in computational cost and a 32.96% improvement in communication cost on the smart meter side, respectively.
Duan Guo, Alsharif Abuadbba, Xun Yi, Saru Kumari, Tao Peng 0006
IEEE Internet Things J.6
2024 SL3PAKE: Simple Lattice-based Three-party Password Authenticated Key Exchange for post-quantum world
Vivek Dabra, Saru Kumari, Anju Bala, Sonam Yadav
J. Inf. Secur. Appl.2
2024 Heterogeneous and plaintext checkable signcryption for integrating IoT in healthcare system
Abdalla Hadabi, Kuo-Hui Yeh, Chien-Ming Chen 0001, Saru Kumari, Hu Xiong
J. Syst. Archit.5
2024 Traceable Attribute-Based Encryption With Equality Test for Cloud Enabled E-Health System
abstract
The emerging Internet of Things (IoTs) and cloud technologies spark dramatic growth in efficiency and productivity for the conventional e-health sector. However, the extensive applications of the communication network also expose the sensitive medical data to the unprecedented cyber threats. To protect the data privacy in IoTs-based e-health cloud environments, we propose an adaptively secure data sharing scheme with traceability and equality test (T-ABEET). The T-ABEET not only allows flexible access control to the massive data but also provides the functionality of traitor tracing to identity the users who leak their decryption keys. Meanwhile, through carrying out the equality test, the target ciphertext can be retrieved efficiently without revealing anything about the plaintext. Particularly, distinct from previous traceable ABE works, the tracing cost in our T-ABEET scheme keeps constant even with the increasing number of users. Also, by introducing the multi-authority mechanism, our T-ABEET can avoid the inherent key escrow problem of ABE. Furthermore, our T-ABEET is demonstrated adaptively secure under subgroup decision assumption. Finally, performance comparison reveals that our T-ABEET has superior practicality, efficiency, and security in cloud-enabled e-health systems.
Saru Kumari, Mohammad S. Obaidat, Bander A. Alzahrani, Hu Xiong
IEEE J. Biomed. Health Informatics2
2024 Designing Anonymous Key Agreement Scheme for Secure Vehicular Ad-Hoc Networks
abstract
Presently, the Vehicular Ad-hoc Network (VANET) is very important for the entire traffic management system. The 5th Generation (5G) enables VANET and Intelligent Transportation Systems (ITS) to connect devices in the million/sqkm range with improved performance, incredible transmission speed (terabit), and less cost to serve a vast, transformative, and diverse automobile sector. To ensure security and avoid the free flow of information in highly scalable, dynamic 5G, there are many challenges to restrict unauthenticated users access and proper key agreements with fine-grained access control. Here, a lightweight biometrics-based dynamic Anonymous Key Agreement Scheme (AKAS) with a fine-grained authentication feature is proposed to address challenges related to the restriction of unauthenticated users access and proper key agreement with fine-grained access control specifically for Vehicle-to-Vehicle (V2V) communication in VANET. In the proposed scheme, registered and authorized users can access services or information as per access privilege only. We have simulated our scheme using Automated Validation of Internet Security Protocols (AVISPA), Simulation of Urban MObility (SUMO), OMNET$++$(Objective Modular Network Testbed in C$++$), and performed formal security analysis using the Real-or-Random (ROR) oracle model. Analysis and simulation results show that our scheme is secured against various well-known attacks. Further, we have compared the security and efficiency of our scheme with the existing schemes and found that our proposed protocol is more secure, lighter, 5G-friendly, scalable, and even faster than the other related schemes.
Md Ismail, Santanu Chatterjee, Jamuna Kanta Sing, Saru Kumari, Joel J. P. C. Rodrigues
IEEE Trans. Intell. Transp. Syst.4
2024 Blockchain and Machine Learning Integrated Secure Driver Behavior Centric Electric Vehicle Insurance Model
abstract
Traditional insurance policy models involve cumbersome multiparty verification and processing, leading to a prolonged and time-consuming procedure resulting in claim leakage. The existing insurance and blockchain-based systems have no module specifically for electric vehicles to cover physical damage. This becomes particularly significant in electric vehicles (EVs), where insurance is essential due to the high cost of vehicle parts and the vehicles themselves. Electric vehicles with various sensors and IoT devices are susceptible to physical damage and attacks. To address these challenges and provide robust financial support to policyholders, an enhanced blockchain-based electric vehicle insurance policy (BE-VIP) is proposed to cover vehicle damages. BE-VIP leverages sensory and telemetry data from vehicle sensors, IoT devices, and drivers’ behavior for a more comprehensive analysis. However, the insecure nature of the public network in the internet of electric vehicles (IoEV) exposes it to various security threats and attacks. Recognizing this, BE-VIP emphasizes implementing a lightweight privacy-preserving and efficient authentication protocol to enhance network security. A secure driver-driving score (DDS) is proposed to reward and punish the vehicle based on driving behavioral data and easy insurance policy transfer from the previous owner to the current owner. To prevent fraudulent accidental claims, a YOLOv8 model-based damage detection model is combined with IPFS to create permanent evidence of an accident. The feasibility of the BE-VIP model is rigorously evaluated through a comprehensive analysis, considering factors such as computational complexity and gas consumption required for execution over the Ethereum blockchain network.
Brijmohan Lal Sahu, Preeti Chandrakar, Saru Kumari, Chien-Ming Chen 0001, Mohammed Amoon
IEEE Trans. Intell. Transp. Syst.3
2024 Using a privacy-enhanced authentication process to secure IoT-based smart grid infrastructures
Samad Rostampour, Nasour Bagheri, Behnam Ghavami, Ygal Bendavid, Saru Kumari, Honorio Martín, Carmen Camara
J. Supercomput.5
2024 Correction to: Using a privacy‑enhanced authentication process to secure IoT‑based smart grid infrastructures
Samad Rostampour, Nasour Bagheri, Behnam Ghavami, Ygal Bendavid, Saru Kumari, Honorio Martín, Carmen Camara
J. Supercomput.5
2024 DLLF-2EN: Energy-Efficient Next Generation Mobile Network With Deep Learning-Based Load Forecasting
abstract
The exponential growth of mobile data traffic in next generation networks has led to a significant increase in energy consumption, posing critical challenges for network operators. We propose DLLF-2EN, a novel energy-efficient framework that integrates deep learning-based load forecasting, an advanced power consumption model, and a comprehensive energy-saving strategy to address this issue. The load forecasting technique utilizes deep convolutional neural network and long short-term memory model, which is based on deep learning. This model is capable of capturing the spatiotemporal dependencies present in network traffic data. The power consumption model accurately characterizes the base stations’ static and dynamic power consumption components, facilitating the assessment of energy efficiency under various network scenarios. The energy-saving strategy combines base station sleep mode with discontinuous transmission and reception, as well as lightweight transmission of common signals, dynamically adapting the network operation based on the predicted traffic load. Furthermore, DLLF-2EN incorporates an intelligent power management system that leverages machine learning algorithms to continuously monitor the network, analyze collected data, and make optimal energy-saving decisions in real-time. Simulation demonstrate that the superior performance of DLLF-2EN in terms of load forecasting accuracy and energy efficiency compared to state-of-the-art baseline methods. The proposed framework represents a comprehensive solution for energy-efficient and sustainable next generation mobile networks, addressing the critical challenges of minimizing energy consumption while meeting the growing demands for high-quality mobile services.
Xin Wang 0134, Jianhui Lv, Adam Slowik, Parameshachari Bidare Divakarachari, Keqin Li 0001, Chien-Ming Chen 0001, Saru Kumari
IEEE Trans. Netw. Serv. Manag.7
2023 Blockchain-based privacy-preserving authentication protocol for UAV networks
Muhammad Arslan Akram, Hira Ahmad, Adnan Noor Mian, Anca Jurcut, Saru Kumari
Comput. Networks5
2023 A secure protocol for patient monitoring in wireless body area networks
abstract
Summary Recently, an authentication scheme was presented for health‐care in IoT for WBANs by Fotouhi et al. Authors asserted their scheme to be free from a number of attacks. Here, we find that Fotouhi et al.'s scheme suffers from insider attack, fails to provide proper authentication and bears inefficient password update phase. Therefore their scheme has security pitfalls that can lead to further security breaches. We remove the weaknesses of Fotouhi et al.'s scheme and hence propose a user authentication scheme for patient care. Our scheme is suitable for providing special care to patients in the healthcare industry. The proposed scheme facilitates health professionals to access the real‐time data of patients under treatment for some diseases. It also safeguards the medical staff from catching an infection from the patients by minimizing the need to come in direct contact with the patients. We justify the security of our proposed scheme by applying the random oracle model to it. The proposed scheme is compared with some related works to judge its efficacy over the compared counterparts.
Pooja Tyagi, Saru Kumari, Mridul Kumar Gupta, Chien-Ming Chen 0001, Tsu-Yang Wu, Sachin Kumar 0002
Concurr. Comput. Pract. Exp.2
2023 Deep Semantics Sorting of Voice-Interaction-Enabled Industrial Control System
abstract
In recent years, voice-interaction-based control systems have attracted considerable attention for industrial control systems implementing Industrial Internet of Things (IIoT) technologies. The development of automated semantic understanding relates to the industrial Internet equipment used to realize remote voice control as well as to its intelligent management and control. In these emerging voice-interaction-enabled industrial central control systems, sorting technologies are considered critical. For complex user questions, the level of satisfaction regarding the answers given by such systems tends to be low. Driven by these challenges and opportunities, the optimization of conventional retrieval-based question answering through deep learning methods has become popular. In this study, we propose three deep semantic sorting models based on deep learning, including a multilayer convolutional matching sorting model for single documents and two interactive pairwise bidirectional encoder representations from transformers (BERT) sorting models for document pairs. Two main network architectures are proposed to model document pairs, named Pairwise-Twin-BERT and Pairwise-Triple-BERT. Experimental results indicate that proposed models performed better than state-of-the-art methods based on text matching in a candidate document sorting task.
Ke Wang 0068, Chien-Ming Chen 0001, Mohammad S. Obaidat, Saru Kumari, Sachin Kumar 0002, Jinyi Long
IEEE Internet Things J.4
2023 Enhanced privacy-preserving in student certificate management in blockchain and interplanetary file system
Narendra K. Dewangan, Preeti Chandrakar, Saru Kumari, Joel J. P. C. Rodrigues
Multim. Tools Appl.3
2023 χperbp: a cloud-based lightweight mutual authentication protocol
Morteza Adeli, Nasour Bagheri, Sadegh Sadeghi, Saru Kumari
Peer Peer Netw. Appl.4
2023 Fog-based low latency and lightweight authentication protocol for vehicular communication
Muhammad Arslan Akram, Adnan Noor Mian, Saru Kumari
Peer Peer Netw. Appl.3
2023 DisBezant: Secure and Robust Federated Learning Against Byzantine Attack in IoT-Enabled MTS
abstract
With the intelligentization of Maritime Transportation System (MTS), Internet of Thing (IoT) and machine learning technologies have been widely used to achieve the intelligent control and routing planning for ships. As an important branch of machine learning, federated learning is the first choice to train an accurate joint model without sharing ships' data directly. However, there are still many unsolved challenges while using federated learning in IoT-enabled MTS, such as the privacy preservation and Byzantine attacks. To surmount the above challenges, a novel mechanism, namely DisBezant, is designed to achieve the secure and Byzantine-robust federated learning in IoT-enabled MTS. Specifically, a credibility-based mechanism is proposed to resist the Byzantine attack in non-iid (not independent and identically distributed) dataset which is usually gathered from heterogeneous ships. The credibility is introduced to measure the trustworthiness of uploaded knowledge from ships and is updated based on their shared information in each epoch. Then, we design an efficient privacy-preserving gradient aggregation protocol based on a secure two-party calculation protocol. With the help of a central server, we can accurately recognise the Byzantine attackers and update the global model parameters privately. Furthermore, we theoretically discussed the privacy preservation and efficiency of DisBezant. To verify the effectiveness of our DisBezant, we evaluate it over three real datasets and the results demonstrate that DisBezant can efficiently and effectively achieve the Byzantine-robust federated learning. Although there are 40% nodes are Byzantine attackers in participants, our DisBezant can still recognise them and ensure the accurate model training.
XinDi Ma, Qi Jiang 0001, Mohammad Shojafar, Mamoun Alazab, Sachin Kumar 0002, Saru Kumari
IEEE Trans. Intell. Transp. Syst.6
2023 Privacy-Aware Multiagent Deep Reinforcement Learning for Task Offloading in VANET
abstract
Offloading task to roadside units (RSUs) provides a promising solution for enhancing the real-time data processing capacity and reducing energy consumption of vehicles in the vehicular ad-hoc network (VANET). Recently, multi-agent deep reinforcement learning (MADRL)-based offloading approaches have been widely used for task offloading in VANET. However, existing MADRL-based approaches suffer from offloading preference inference (OPI) attack, which utilizes the vulnerability in the policy learning process of MADRL to mislead vehicles to offload tasks to malicious RSUs. In this paper, we first formulate a joint optimization of offloading action and transmitting power with the objective of minimizing the system cost, including local and edge costs, under the privacy requirement of protecting offloading preference during offloading policy learning process in VANET. Despite the non-convexity and centralized of this joint optimization problem, we propose a privacy-aware MADRL (PA-MADRL) approach to solve it, which can allow the offload decision of each vehicle to reach the Nash Equilibrium (NE) without leaking offloading preference. The key to resisting the OPI attack is to protect the offloading preference by 1)elaborately constructing the noise based on ($\beta,\Phi $)-differential privacy mechanism and 2) adding it to the action selection and policy updating process of vanilla MADRL. We conduct a detailed theoretical analysis of the convergence and privacy guarantee of the proposed PA-MADRL, and extensive simulations are conducted to demonstrate the effectiveness, privacy-protecting capacity, and cost-efficiency of PA-MADRL approach.
Dawei Wei, Mohammad Shojafar, Saru Kumari, Ning Xi 0002, Jianfeng Ma 0001
IEEE Trans. Intell. Transp. Syst.4
2022 A Traceable and Revocable Attribute-based Encryption Scheme Based on Policy Hiding in Smart Healthcare Scenarios
Zhaozhong Liu, Jingmin An, Guobin Zhu, Saru Kumari
ISPEC5
2022 Cryptanalysis and improvement of an authentication scheme for IoT
Mridul Kumar Gupta, Saru Kumari
Int. J. Inf. Comput. Secur.3
2022 Secure and Authenticated Data Access and Sharing Model for Smart Wearable Systems
abstract
Contrary to the public cloud storage services that impose users to accept the security restrictions delivered by the service provider, users in the private cloud benefit from self-managed, authenticated data access services. However, this may lead to security issues. A critical challenge is the provision of secure and authenticated data storage for the data owner. Moreover, the data owner should be able to access the stored data and share it with others in a controlled manner. In this article, a secure and authenticated data storage, access, and sharing model is proposed for private cloud storage, which has three components. The data storage component provides the user with secure storage of information. The data-sharing component enables sharing the stored data under the control of the data owner. The data access component enables authenticated access to the cloud storage. The security analysis demonstrates that the model is secure against various attacks. The scheme is validated to be secure via the Scyther tool, BAN Logic, and in Random Oracle Model. The performance analysis regarding the computation and communication cost via simulation in OMNeT++ show that it obtains the required security goals and efficiency of computation and communication, compared to the related methods.
Haleh Amintoosi, Mahdi Nikooghadam, Saru Kumari, Jun Feng 0007, Hu Xiong, Sachin Kumar 0002, Joel J. P. C. Rodrigues
IEEE Internet Things J.3
2022 An Authentication Protocol for Next Generation of Constrained IoT Systems
abstract
With the exponential growth of connected Internet of Things (IoT) devices around the world, security protection and privacy preservation have risen to the forefront of design and development of innovative systems and services. For low-value IoT devices that identify and track billion of goods in various industries—such as radio-frequency identification (RFID) tags—this involves multiple challenges in very constrained environments. IoT devices aim to design low-cost, low-complexity infrastructure while enabling robust authentication protocols with reduced latency and energy consumption. Given these challenges, in this article, we present a new lightweight authentication protocol for IoT applications, employing an authenticated-encryption (AE) cryptosystem with associated data (AEAD). Since AEAD algorithms provide data confidentiality and message integrity simultaneously, security analysis [Real-or-Random (RoR) and Scyther] results prove the robustness of the proposed protocol against IoT threats. Furthermore, to measure the computation and communication cost, FPGA and ASIC simulations using four different AEAD candidates of National Institute of Standards and Technology (NIST) lightweight cryptography competition are executed. The implementation results [e.g., 4744 gate equivalent (GE) and 0.87-mw power] clearly show that our novel design can be applied to a wide range of constrained IoT devices complying with low-cost, lightweight, and high-speed requirements.
Samad Rostampour, Nasour Bagheri, Ygal Bendavid, Masoumeh Safkhani, Saru Kumari, Joel J. P. C. Rodrigues
IEEE Internet Things J.5
2022 Burn After Reading: Adaptively Secure Puncturable Identity-Based Proxy Re-Encryption Scheme for Securing Group Message
abstract
Puncturable proxy re-encryption (PPRE) is envisioned to provide secure access control delegation and fine-grained forward security for asynchronous group messaging systems. Nevertheless, the existing PPRE scheme not only suffers from the burden of certificate management but also merely achieves selective security based on the nonstandard assumption. In this article, a puncturable identity-based PRE (P-IB-PRE) scheme is proposed to efficiently protect the security and privacy of the group message. The proposed scheme introduces a message server as the proxy to transform ciphertext for each participant in the group; thus, the heavy computation overhead is delegated to the message server with abundant resources. Most importantly, our scheme enables the recipient to revoke its private key’s decryption capability of the specific messages without affecting other messages. Moreover, the identity-based mechanism eliminates the burden of certificate management as well as improves efficiency. The proposed scheme achieves adaptive security under the standard decisional bilinear Diffie–Hellman (DBDH) assumption. Eventually, theoretical and experimental analyses demonstrate that the proposed scheme has an excellent performance in efficiency and practicality.
Hu Xiong, Zhida Zhou, Zetong Zhao, Saru Kumari
IEEE Internet Things J.6
2022 A survey on Attribute-Based Signatures
Prince Silas Kwesi Oberko, Victor-Hillary Kofi Setornyo Obeng, Hu Xiong, Saru Kumari
J. Syst. Archit.4
2022 Data Augmentation for Internet of Things Dialog System
Ke Wang 0068, Juntao Yu, Chien-Ming Chen 0001, Saru Kumari, Joel J. P. C. Rodrigues
Mob. Networks Appl.4
2022 Predicting airline customers' recommendations using qualitative and quantitative contents of online reviews
Praphula Kumar Jain, Arjav Patel, Saru Kumari, Rajendra Pamula
Multim. Tools Appl.3
2022 An authentication and key agreement scheme for smart grid
Masoumeh Safkhani, Saru Kumari, Mohammad Shojafar, Sachin Kumar 0002
Peer-to-Peer Netw. Appl.2
2022 Practical and Provably Secure Three-Factor Authentication Protocol Based on Extended Chaotic-Maps for Mobile Lightweight Devices
abstract
Due to the limitations of symmetric-key techniques, authentication and key agreement (AKA) protocols based on public-key techniques have attracted much attention, providing secure access and communication mechanism for various application environments. Among these public-key techniques used for AKA protocols, chaotic-map is more effective than scalar multiplication and modular exponentiation, and it offers a list of desirable cryptographic properties such as un-predictability, un-repeatability, un-certainty, and higher efficiency than scalar multiplication and modular exponentiation. Furthermore, it is usually believed that three-factor AKA protocols can achieve a higher security level than single- and two-factor protocols. However, none of existing three-factor AKA protocols can meet all security requirements. One of the most prevalent problems is how to balance security and usability, and particularly how to achieve truly three-factor security while providing password change friendliness. To deal with this problem, in this article we put forward a provably secure three-factor AKA protocol based on extended chaotic-maps for mobile lightweight devices, by adopting the techniques of “Fuzzy-Verifiers” and “Honeywords”. We prove the security of the proposed protocol in the random oracle model, assuming the intractability of extended chaotic-maps Computational Diffie-Hellman problem. We also simulate the protocol by using the AVISPA tool. The security analysis and simulation results show that our protocol can meet all 13 evaluation criteria regarding security. We also assess the performance of our protocol by comparing with seven other related protocols. The evaluation results demonstrate that our protocol offers better balance between security and usability over state-of-the-art ones.
Shuming Qiu, Ding Wang 0002, Guoai Xu, Saru Kumari
IEEE Trans. Dependable Secur. Comput.4
2022 SAKE*: A Symmetric Authenticated Key Exchange Protocol With Perfect Forward Secrecy for Industrial Internet of Things
abstract
Security in the Industrial Internet of Things (IIoT) is vital as there are some cases where IIoT devices collect sensory information for crucial social production and life. Thus, designing secure and efficient communication channels is always a research hotspot. However, end devices have memory, computation, and power-supplying capacities limitations. Moreover, perfect forward secrecy (PFS), which means that long-term key exposure still discloses previous session keys, is a critical security property for authentication and key exchange (AKE). This article proposes an AKE protocol named SAKE* for the IIoT environment, where two types of keys (i.e., a master key and an evolution key) guarantee PFS. In addition, the SAKE* protocol merely uses concatenation, XOR, and hash-function operations to achieve lightweight authentication, key exchange, and message integrity. We also compare the SAKE* protocol with seven current and IoT-related authentication protocols regarding security properties and performance. Comparison results indicate that the SAKE* protocol consumes the least computation resource and third-least communication cost among eight AKE protocols while equipping 12 security properties.
Jianhua Chen 0002, Mohammad Shojafar, Saru Kumari, Debiao He
IEEE Trans. Ind. Informatics4
2022 Forward Privacy Preservation in IoT-Enabled Healthcare Systems
abstract
In recent years, Internet of Things (IoT)-enabled health monitoring wearable devices have become a trend in healthcare systems, regularly collecting vital sign data from patients and uploading them to the cloud. Through on-demand search queries, data are shared with third-party healthcare service providers to monitor patients' health status and provide timely diagnoses. To ensure privacy and security, patient health data should be encrypted before being uploaded to the cloud. The cloud can give search encryption services. However, current searchable encryption (SE) technologies still have problems with forward privacy security and verifiability. This article proposes an IoT-cloud-enabled healthcare data system incorporating a SE method with forward privacy and verifiability. By designing a trapdoor permutation function, we render the resulting output indistinguishable from meaningless random data to the adversary. Thus, the adversary cannot judge the relationship between a newly inserted record and a past search token, and therefore, the system realizes forward privacy or forward secrecy. We propose a multikeyword search verification mechanism based on a pseudo-random function. Our approach solves verifying the correctness of search results in the top-k search scenario with partial search results.Aformal security analysis proves that our scheme achieves forward privacy preservation, which can help guarantee healthcare data privacy. Additionally, a performance evaluation shows that our method is efficient and effective, providing an information security system to preserve patient privacy in IoT-enabled healthcare systems.
Ke Wang 0068, Chien-Ming Chen 0001, Zhuoyu Tie, Mohammad Shojafar, Sachin Kumar 0002, Saru Kumari
IEEE Trans. Ind. Informatics6
2022 Personalized Privacy-Aware Task Offloading for Edge-Cloud-Assisted Industrial Internet of Things in Automated Manufacturing
abstract
Industrial Internet of Things (IIoT) devices are widely used for monitoring and controlling the process of automated manufacturing. Owing to the limited computing capacity of the IIoT sensors in the production line, the scheduling task in the production line needs to be offloaded to the edge computing server (ECS). To obtain the desired quality of service (QoS) during offloading scheduling tasks, the precise interaction information between the production line and ECSs has to be uploaded to the cloud platform, which poses privacy issues. The existing works mostly assume that all the interaction information, i.e., the offloading decision for the subtask in a scheduling task, has same privacy level, which cannot meet the various privacy requirements of the offloading decision for the subtask. Hence, we propose a local-differential-privacy-based deep reinforcement learning (LDP-DRL) approach in the edge-cloud-assisted IIoT to provide personalized privacy guarantee. The LDP mechanism can generate different levels of noise to satisfy the various privacy requirements of the offloading decision for the subtask. The prioritized experience replay is integrated in DRL to reduce the impact of noise on the QoS performance of task offloading. The formal analysis of LDP-DRL is provided in terms of privacy level and convergence. Finally, extensive experiments are conducted to evaluate the effectiveness, the capacity of privacy protection, the impact of discount factor on the convergence, and the cost efficiency of the LDP-DRL approach.
Dawei Wei, Ning Xi 0002, XinDi Ma, Mohammad Shojafar, Saru Kumari, Jianfeng Ma 0001
IEEE Trans. Ind. Informatics5
2022 AFFIRM: Provably Forward Privacy for Searchable Encryption in Cooperative Intelligent Transportation System
abstract
With the construction of intelligent transportation, big data with heterogeneous, multi-source and massive characteristics has become an important carrier of cooperative intelligent transportation systems (C-ITS) and plays an important role. Big data in C-ITS can break through the restrictions between regions and entities and then learning cooperatively by sharing data. In addition, the combined efficiency and information integration advantages of big data are conducive to the construction of a comprehensive and three-dimensional traffic information system and can enhance traffic prediction. However, such substantial sensitive data, mainly on the cloud infrastructure, exposes several vulnerabilities like data leakages and privacy breaks, especially when data is shared for cooperative learning purposes. To address this, this paper proposes a forward privacy-preserving scheme, named AFFIRM, for multi-party encrypted sample alignment adopting cooperative learning in C-ITS. By introducing the searchable encryption method, we realize the sample alignment of cooperative learning in the multi-party encrypted data space. AFFIRM ensures encrypted sample alignment under the condition of forward privacy security. We have formally proved that the proposed scheme satisfies both forward security and validity. We have assessed AFFIRM by validating the potential threat of malicious tampering by privacy attackers and malicious personnel search for the aligned sample data and verify it. Finally, we numerically tested and compared AFFIRM against the corresponding ones of some state-of-the-art schemes under various record sizes, servers and processing.
Ke Wang 0068, Chien-Ming Chen 0001, Mohammad Shojafar, Zhuoyu Tie, Mamoun Alazab, Saru Kumari
IEEE Trans. Intell. Transp. Syst.6
2022 A lightweight authentication and key agreement protocol for heterogeneous IoT with special attention to sensing devices and gateway
Rahman Hajian, Hossein Erfani, Saru Kumari
J. Supercomput.3
2022 A provably secure lightweight authentication protocol in mobile edge computing environments
Tsu-Yang Wu, Lei Yang 0055, Xinglan Guo, Saru Kumari
J. Supercomput.5
2022 Privacy-Preserving Distributed Multi-Task Learning against Inference Attack in Cloud Computing
abstract
Because of the powerful computing and storage capability in cloud computing, machine learning as a service (MLaaS) has recently been valued by the organizations for machine learning training over some related representative datasets. When these datasets are collected from different organizations and have different distributions, multi-task learning (MTL) is usually used to improve the generalization performance by scheduling the related training tasks into the virtual machines in MLaaS and transferring the related knowledge between those tasks. However, because of concerns about privacy breaches (e.g., property inference attack and model inverse attack), organizations cannot directly outsource their training data to MLaaS or share their extracted knowledge in plaintext, especially the organizations in sensitive domains. In this article, we propose a novel privacy-preserving mechanism for distributed MTL, namely NOInfer, to allow several task nodes to train the model locally and transfer their shared knowledge privately. Specifically, we construct a single-server architecture to achieve the private MTL, which protects task nodes’ local data even if n-1 out of n nodes colluded. Then, a new protocol for the Alternating Direction Method of Multipliers (ADMM) is designed to perform the privacy-preserving model training, which resists the inference attack through the intermediate results and ensures that the training efficiency is independent of the number of training samples. When releasing the trained model, we also design a differentially private model releasing mechanism to resist the membership inference attack. Furthermore, we analyze the privacy preservation and efficiency of NOInfer in theory. Finally, we evaluate our NOInfer over two testing datasets and evaluation results demonstrate that NOInfer efficiently and effectively achieves the distributed MTL.
XinDi Ma, Jianfeng Ma 0001, Saru Kumari, Fushan Wei, Mohammad Shojafar, Mamoun Alazab
ACM Trans. Internet Techn.3
2021 Supervised learning model for identifying illegal activities in Bitcoin
Pranav Nerurkar, Sunil Bhirud, Dhiren R. Patel, Romaric Ludinard, Yann Busnel, Saru Kumari
Appl. Intell.6
2021 Sentiment analysis of tweets using a unified convolutional neural network-long short-term memory network model
abstract
Abstract Sentiment analysis focuses on identifying and classifying the sentiments expressed in text messages and reviews. Social networks like Twitter, Facebook, and Instagram generate heaps of data filled with sentiments, and the analysis of such data is very fruitful when trying to improve the quality of both products and services alike. Classic machine learning techniques have a limited capability to efficiently analyze such large amounts of data and produce precise results; they are thus supported by deep learning models to achieve higher accuracy. This study proposes a combination of convolutional neural network and long short‐term memory (CNN‐LSTM) deep network for performing sentiment analysis on Twitter datasets. The performance of the proposed model is analyzed with machine learning classifiers, including the support vector classifier, random forest (RF), stochastic gradient descent (SGD), logistic regression, a voting classifier (VC) of RF and SGD, and state‐of‐the‐art classifier models. Furthermore, two feature extraction methods (term frequency‐inverse document frequency and word2vec) are also investigated to determine their impact on prediction accuracy. Three datasets (US airline sentiments, women's e‐commerce clothing reviews, and hate speech) are utilized to evaluate the performance of the proposed model. Experiment results demonstrate that the CNN‐LSTM achieves higher accuracy than those of other classifiers.
Muhammad Umer 0001, Imran Ashraf 0003, Arif Mehmood, Saru Kumari, Saleem Ullah, Gyu Sang Choi
Comput. Intell.4
2021 Transfer reinforcement learning-based road object detection in next generation IoT domain
Ke Wang 0068, Chien-Ming Chen 0001, M. Shamim Hossain, Muhammad Ghulam, Sachin Kumar 0002, Saru Kumari
Comput. Networks6
2021 Certificate-Based Parallel Key-Insulated Aggregate Signature Against Fully Chosen Key Attacks for Industrial Internet of Things
abstract
With the emergence of the Industrial Internet of Things (IIoT), numerous operations based on smart devices contribute to producing the convenience and comfortable applications for individuals and organizations. Considering the untrusted feature of the communication channels in IIoT, it is essential to ensure the authentication and incontestableness of the messages transmitted in the IIoT. In this article, we first proposed a certificate-based parallel key-insulated aggregate signature (CB-PKIAS), which can resist the fully chosen-key attacks. Concretely, the adversary who can obtain the private keys of all signers in the system is able to forge a valid aggregate signature by using the invalid single signature. Furthermore, our scheme inherits the merits of certificate based and key insulated to avoid the certificate management problem, key-escrow problems, as well as the key exposures simultaneously. In addition, the rigorous analysis and the concrete simulation experiment demonstrated that our proposed scheme is secure under the random oracle and more suitable for the IIoT environment.
Yingzhe Hou, Hu Xiong, Saru Kumari
IEEE Internet Things J.4
2021 Neural Architecture Search for Robust Networks in 6G-Enabled Massive IoT Domain
abstract
6G technology enables artificial intelligence (AI)-based massive IoT to manage network resources and data with ultra high speed, responsive network, and wide coverage. However, many AI-enabled Internet-of-Things (AIoT) systems are vulnerable to adversarial example attacks. Therefore, designing robust deep learning models that can be deployed on resource-constrained devices has become an important research topic in the field of 6G-enabled AIoT. In this article, we propose a method for automatically searching for robust and efficient neural network structures for AIoT systems. By introducing a skip connection structure, a feature map with reduced front-end influence can be used for calculations during the classification process. Additionally, a novel type of densely connected search space is proposed. By relaxing this space, it is possible to search for network structures efficiently. In addition, combined with adversarial training and model delay constraints, we propose a multiobjective gradient optimization method to realize the automatic searching of network structures. Experimental results demonstrate that our method is effective for AIoT systems and superior to state-of-the-art neural architecture search algorithms.
Ke Wang 0068, Peng Xu 0052, Chien-Ming Chen 0001, Saru Kumari, Mohammad Shojafar, Mamoun Alazab
IEEE Internet Things J.4
2021 Heterogeneous Signcryption With Equality Test for IIoT Environment
abstract
The existing signcryption schemes with equality testing are aimed at a sole cryptosystem and not suitable for the sophisticated heterogeneous network of Industrial Internet of Things (IIoT). To deal with this challenge, we propose a heterogeneous signcryption scheme with equality test (HSC-ET) in this article. This scheme enables a sensor in public key infrastructure (PKI) to execute data encryption and deliver it to the semitrusted entity (cloud server). When a user in an identity-based cryptosystem (IBC) intends to search for some data stored on the cloud server. The delegated cloud server executes tests on ciphertexts for determining whether the same underlying plaintext exists between two ciphertexts. These two ciphertexts can be one signcrypted ciphertext and one encrypted ciphertext, or both encrypted/signcrypted ciphertext, thus achieving a flexible search to the ciphertext. HSC-ET is demonstrated to be secure by the rigorous and detailed analysis. The experimental simulation and analysis results show the efficiency of our scheme.
Hu Xiong, Yanan Zhao 0002, Yingzhe Hou, Chuanjie Jin, Saru Kumari
IEEE Internet Things J.7
2021 Flaw and amendment of a two-party authenticated key agreement protocol for post-quantum environments
Vivek Dabra, Anju Bala, Saru Kumari
J. Inf. Secur. Appl.3
2021 A lightweight and provable secure identity-based generalized proxy signcryption (IBGPS) scheme for Industrial Internet of Things (IIoT)
Insaf Ullah, Hizbullah Khattak, Muhammad Asghar Khan, Chien-Ming Chen 0001, Saru Kumari
J. Inf. Secur. Appl.6
2021 Dissecting bitcoin blockchain: Empirical analysis of bitcoin network (2009-2020)
abstract
Bitcoin system (or Bitcoin) is a peer-to-peer and decentralized payment system that uses cryptocurrency named bitcoins (BTCs) and was released as open-source software in 2009. Unlike fiat currencies, there is no centralized authority or any statutory recognition, backing, or regulation for Bitcoin . All transactions are confirmed for validity by a network of volunteer nodes (miners) and after collective agreement is subsequently recorded into a distributed ledger “Blockchain”. Bitcoin platform has attracted both social and anti-social elements. On the one hand, it is social as it ensures the exchange of value, maintaining trust in a cooperative, community-driven manner without the need for a trusted third party. At the same time, it is anti-social as it creates hurdles for law enforcement to trace suspicious transactions due to anonymity and privacy. To understand how the social and anti-social tendencies in the user base of Bitcoin affect its evolution, there is a need to analyze the Bitcoin system as a network. The current paper aims to explore the local topology and geometry of the Bitcoin network during its first decade of existence. Bitcoin transaction data from 03 Jan 2009 12:45:05 GMT to 08 May 2020 13:21:33 GMT was processed for this purpose to build a Bitcoin user graph. The characteristics, local and global network properties of the user's graph were analyzed at ten intervals between 2009 and 2020 with a gap of one year. Small diameter, skewed distribution of transactions, power-law distributed in and out degrees, disconnected graph, and presence of large connected components were the observations from network analysis . Thus, it could be inferred that despite anti-social tendencies, Bitcoin network shared similarities with other complex networks. Network analysis also uncovered twenty types of legal and anti-social entities operating on Bitcoin and provided a path for uncovering these anti-social entities.
Pranav Nerurkar, Dhiren R. Patel, Yann Busnel, Romaric Ludinard, Saru Kumari, Muhammad Khurram Khan
J. Netw. Comput. Appl.5
2021 Verifiable dynamic ranked search with forward privacy over encrypted cloud data
Chien-Ming Chen 0001, Zhuoyu Tie, Ke Wang 0068, Muhammad Khurram Khan, Sachin Kumar 0002, Saru Kumari
Peer-to-Peer Netw. Appl.6
2021 Improved Authenticated Key Agreement Scheme for Fog-Driven IoT Healthcare System
abstract
The Internet of things (IoT) has been widely used for various applications including medical and transportation systems, among others. Smart medical systems have become the most effective and practical solutions to provide users with low-cost, noninvasive, and long-term continuous health monitoring. Recently, Jia et al. proposed an authentication and key agreement scheme for smart medical systems based on fog computing and indicated that it is safe and can withstand a variety of known attacks. Nevertheless, we found that it consists of several flaws, including known session-specific temporary information attacks and lack of per-verification. The opponent can readily recover the session key and user identity. In this paper, we propose a secure authentication and key agreement scheme, which compensates for the imperfections of the previously proposed. For a security evaluation of the proposed authentication scheme, informal security analysis and the Burrows–Abadi–Needham (BAN) logic analysis are implemented. In addition, the ProVerif tool is used to normalize the security verification of the scheme. Finally, the performance comparisons with the former schemes show that the proposed scheme is more applicable and secure.
Tsu-Yang Wu, Tao Wang 0003, Yu-Qi Lee, Saru Kumari, Sachin Kumar 0002
Secur. Commun. Networks5
2021 Voice-Transfer Attacking on Industrial Voice Control Systems in 5G-Aided IIoT Domain
abstract
At present, specific voice control has gradually become an important means for 5G-Internet-of-Things-aided industrial control systems, such as controlling the operation and adjustment of industrial Internet of Things equipment through telephone voice of the controller. However, the security of specific voice control system needs to be improved, because the voice cloning technology based on transfer learning can easily simulate the voice of the controller, which may lead to industrial accidents and other potential security risks. Therefore, this article mainly aims to study and understand the principle of voice cloning attack technology, putting forward a voice clone attack method, in order to prepare for the construction of a specific voice recognition system in the future. At present, the key technology of voice cloning attack is how to solve the problem that the target speaker's personalized speech with high quality cannot be synthesized under small samples. In fact, voice cloning is a very challenging problem because speech is more difficult to be represented in the hidden space of the model. We propose a transductive voice transfer learning method to learn the predictive function from the source domain and fine-tune in the target domain adaptively. The target learning task and the source learning task are both synthesizing speech signals from the given audio, while the datasets of both domains are different. By adding different penalty values to each instances and minimizing the expected risk, an optimal precise model can be learned. In addition, an evaluation method to verify the audio similarity of the target speaker was given to show the similarity between the synthesized audio and the original audio. Many details of the experimental results show that our method can effectively synthesize the speech of the target speaker with small samples.
Ke Wang 0068, Chien-Ming Chen 0001, Saru Kumari, Mohammad Shojafar, M. Shamim Hossain
IEEE Trans. Ind. Informatics4
2021 HDMA: Hybrid D2D Message Authentication Scheme for 5G-Enabled VANETs
abstract
The fifth-generation (5G) mobile communication technology with higher capacity and data rate, ultra-low device to device (D2D) latency, and massive device connectivity will greatly promote the development of vehicular ad hoc networks (VANETs). Meantime, new challenges such as security, privacy and efficiency are raised. In this article, a hybrid D2D message authentication (HDMA) scheme is proposed for 5G-enabled VANETs, in which a novel group signature-based algorithm is used for mutual authentication between vehicle to vehicle (V2V) communication. In addition, a pre-computed lookup table is adopted to reduce the computation overhead of modular exponentiation operation. Security analysis shows that HDMA is robust to resist various security attacks, and performance analysis also points out that, the authentication overhead of HDMA is more efficient than some traditional schemes with the help of the pre-computed lookup table in V2V and vehicle to infrastructure (V2I) communication.
Chien-Ming Chen 0001, Saru Kumari, Mohammad Shojafar, Rahim Tafazolli, Yi-Ning Liu 0002
IEEE Trans. Intell. Transp. Syst.3
2021 Intelligent monitor for typhoon in IoT system of smart city
Ke Wang 0068, Saru Kumari, Jyh-Haw Yeh, Chien-Ming Chen 0001
J. Supercomput.3
2021 A Provably Secure Three-Factor Authentication Protocol for Wireless Sensor Networks
abstract
The wireless sensor network is a network composed of sensor nodes self‐organizing through the application of wireless communication technology. The application of wireless sensor networks (WSNs) requires high security, but the transmission of sensitive data may be exposed to the adversary. Therefore, to guarantee the security of information transmission, researchers propose numerous security authentication protocols. Recently, Wu et al. proposed a new three‐factor authentication protocol for WSNs. However, we find that their protocol cannot resist key compromise impersonation attacks and known session‐specific temporary information attacks. Meanwhile, it also violates perfect forward secrecy and anonymity. To overcome the proposed attacks, this paper proposes an enhanced protocol in which the security is verified by the formal analysis and informal analysis, Burross‐Abadii‐Needham (BAN) logic, and ProVerif tools. The comparison of security and performance proves that our protocol has higher security and lower computational overhead.
Tsu-Yang Wu, Lei Yang 0055, Zhiyuan Lee, Shu-Chuan Chu 0001, Saru Kumari, Sachin Kumar 0002
Wirel. Commun. Mob. Comput.5
2020 Joint-learning segmentation in Internet of drones (IoD)-based monitor systems
Ke Wang 0068, Chien-Ming Chen 0001, Muhammad Khurram Khan, Saru Kumari
Comput. Commun.5
2020 A privacy-preserving scheme with identity traceable property for smart grid
Fan Wu 0003, Xiong Li 0002, Saru Kumari
Comput. Commun.4
2020 A secure and scalable data integrity auditing scheme based on hyperledger fabric
Ning Lu 0005, Saru Kumari, Kim-Kwang Raymond Choo
Comput. Secur.4
2020 Proof of X-repute blockchain consensus protocol for IoT systems
Ke Wang 0068, RuiPei Sun, Chien-Ming Chen 0001, Zuodong Liang, Saru Kumari, Muhammad Khurram Khan
Comput. Secur.5
2020 An enhanced authentication protocol for client server environment
Muhammad Asad Saleem, Shafiq Ahmed, Khalid Mahmood 0002, Saru Kumari, Hu Xiong
Frontiers Comput. Sci.4
2020 PoRX: A reputation incentive scheme for blockchain consensus of IIoT
Ke Wang 0068, Zuodong Liang, Chien-Ming Chen 0001, Saru Kumari, Muhammad Khurram Khan
Future Gener. Comput. Syst.4
2020 Gateway-oriented two-server password authenticated key exchange protocol for unmanned aerial vehicles in mobile edge computing
abstract
With the popularity of unmanned aerial vehicles (UAVs), more and more valuable data can be collected by UAVs. In order to balance the data usage and communication cost, the data can be preprocessed in UAVs rather than directly transmitting to the data centre in the edge computing paradigm. Users can obtain information of interest by accessing the data centre remotely by authenticating themselves to the data centre using the most pervasive password authentication method. Unfortunately, the data centre becomes the main attack target because it not only stores the data but also maintains the passwords of all the users. Aiming at protecting the data as well as the password in the UAV‐enabled mobile edge computing environment, the authors combine the advantages of gateway‐oriented password authenticated key exchange (PAKE) protocols and two‐server PAKE protocols and put forward an efficient gateway‐oriented two‐server PAKE protocol. The security of the proposed protocol is given in the random oracle model. The performance comparison shows their proposal has comparable efficiency in computation and communication costs. Their protocol provides better protection to the password without sacrificing efficiency. Consequently, their protocol is more suitable for real applications in UAV‐enabled mobile edge computing environment.
Saru Kumari, Mohammad S. Obaidat, Fushan Wei
IET Commun.2
2020 Comments on "Toward Secure and Provable Authentication for Internet of Things: Realizing Industry 4.0"
abstract
Internet of Things (IoT) is the next era of communication networks. The concept of IoT is that everything within the global communication network is interconnected and accessible. Since IoT has various applications, including Industry 4.0. Therefore, upcoming and existing IoT applications are highly auspicious to enhance the level of automation, efficiency, and comfort for the users. However, to a certain extent, there are numerous challenges while deploying IoT devices in the Industry 4.0, like IoT devices are assumed to have inadequate resources to support security solutions. Therefore, in order to protect the communication environment, an efficient and lightweight security solution is needed. Recently, on the basis of a hierarchical approach, Garget al.presented a lightweight, robust key agreement, and provably secure authentication protocol for the IoT environment. Their introduced protocol relies on lightweight operations, including XOR operation, concatenation, hash function, physically unclonable function (PUF), and elliptic curve cryptography. However, in this comment, we point out the security loopholes of Garget al.’s protocol and show that it is vulnerable to the IoT-node impersonation attack. Moreover, it has irrelevant generation and usage of some parameters. Therefore, we put forward some valuable suggestions for attack resilience.
Muhammad Arslan Akram, Khalid Mahmood 0002, Saru Kumari, Hu Xiong
IEEE Internet Things J.3
2020 Comments on "AKM-IoV: Authenticated Key Management Protocol in Fog Computing-Based Internet of Vehicles Deployment"
abstract
Internet of Vehicles (IoV) has become an intelligent application of Internet of Things (IoT) in smart transportation. IoV takes intelligent commitments to the passengers for improving the efficiency and safety of traffic. It also creates an enjoyable riding atmosphere. Another variation of mobile cloud computing is fog cloud-based IoV, where Internet and vehicular cloud can co-operate in an effective way in IoV. Moreover, IoV is becoming dangerous to various attacks due to the increasing dependency of wireless communication and computing technologies. Recently, Wazidet al.proposed “AKM-IoV: Authenticated Key Management Protocol in Fog Computing-Based IoV Deployment” to make the communication secure between vehicles, fog servers, roadside units (RSUs), and cloud servers. In this comment, we cryptanalyzed the protocol of Wazidet al.and found it vulnerable to vehicle impersonation, fog server impersonation, RSU impersonation, and cloud server impersonation attacks.
Muhammad Asad Saleem, Khalid Mahmood 0002, Saru Kumari
IEEE Internet Things J.3
2020 Efficient and Privacy-Preserving Authentication Protocol for Heterogeneous Systems in IIoT
abstract
The Industrial Internet of Things (IIoT) is expected to provide a promising opportunity to revolutionize the production operation of the existing industrial systems by leveraging smart devices. Due to the untrusted nature of communication channels, ensuring data authenticity is a critical challenge. Besides, devices' privacy and communication heterogeneity raise crucial concerns about the IIoT applications since the existing authentication protocols for the IIoT environment face the potential threats of privacy leakage and cannot achieve secure communication between heterogeneous industrial systems. To address these challenges, this article proposes an efficient privacy-preserving authentication protocol for heterogeneous systems in IIoT using proxy resignature. The presented protocol not only provides heterogeneous communication between ID-based and certificateless-based cryptosystems but also achieves various security requirements. The security of our protocol has been proven based on the extended Computational Diffie-Hellman (eCDH) assumption in the random oracle model. The experimental simulation demonstrates that our protocol is feasible for the IIoT-based environment.
Hu Xiong, Yan Wu 0014, Chuanjie Jin, Saru Kumari
IEEE Internet Things J.4
2020 Fuzzy extraction and PUF based three party authentication protocol using USB as mass storage device
Muhammad Faizan Ayub, Muhammad Asad Saleem, Izwa Altaf, Khalid Mahmood 0002, Saru Kumari
J. Inf. Secur. Appl.5
2020 A provably secure ECC-based roaming authentication scheme for global mobility networks
Mahdi Nikooghadam, Haleh Amintoosi, Saru Kumari
J. Inf. Secur. Appl.3
2020 A secure blockchain-based e-health records storage and sharing scheme
Salman Shamshad, Minahil Rana, Khalid Mahmood 0002, Saru Kumari, Chien-Ming Chen 0001
J. Inf. Secur. Appl.4
2020 A Robust user authentication protocol with privacy-preserving for roaming service in mobility environments
Shashidhara, Sriramulu Bojjagani, Anup Kumar Maurya, Saru Kumari, Hu Xiong
Peer-to-Peer Netw. Appl.4
2020 Decentralized Private Information Sharing Protocol on Social Networks
abstract
Social networks are becoming popular, with people sharing information with their friends on social networking sites. On many of these sites, shared information can be read by all of the friends; however, not all information is suitable for mass distribution and access. Although people can form communities on some sites, this feature is not yet available on all sites. Additionally, it is inconvenient to set receivers for a message when the target community is large. One characteristic of social networks is that people who know each other tend to form densely connected clusters, and connections between clusters are relatively rare. Based on this feature, community-finding algorithms have been proposed to detect communities on social networks. However, it is difficult to apply community-finding algorithms to distributed social networks. In this paper, we propose a distributed privacy control protocol for distributed social networks. By selecting only a small portion of people from a community, our protocol can transmit information to the target community.
Shu-Chuan Chu 0001, Sachin Kumar 0002, Saru Kumari, Joel J. P. C. Rodrigues, Chien-Ming Chen 0001
Secur. Commun. Networks4
2020 An Improved Blockchain-Based Authentication Protocol for IoT Network Management
abstract
Communication security between IoT devices is a major concern in this area, and the blockchain has raised hopes that this concern will be addressed. In the blockchain concept, the majority or even all network nodes check the validity and accuracy of exchanged data before accepting and recording them, whether this data is related to financial transactions or measurements of a sensor or an authentication message. In evaluating the validity of an exchanged data, nodes must reach a consensus in order to perform a special action, in which case the opportunity to enter and record transactions and unreliable interactions with the system is significantly reduced. Recently, in order to share and access management of IoT devices information with distributed attitude a new authentication protocol based on blockchain is proposed and it is claimed that this protocol satisfies user privacy preserving and security. However, in this paper, we show that this protocol has security vulnerabilities against secret disclosure, replay, traceability, and Token reuse attacks with the success probability of 1 and constant complexity of also 1. We also proposed an improved blockchain-based authentication protocol (IBCbAP) that has security properties such as secure access management and anonymity. We implemented IBCbAP using JavaScript programming language and Ethereum local blockchain. We also proved IBCbAP’s security both informally and formally through the Scyther tool. Our comparisons showed that IBCbAP could provide suitable security along with reasonable cost.
Mostafa Yavari, Masoumeh Safkhani, Saru Kumari, Sachin Kumar 0002, Chien-Ming Chen 0001
Secur. Commun. Networks3
2020 An approach for solving fully fuzzy multi-objective linear fractional optimization problems
Rubi Arya, Pitam Singh, Saru Kumari, Mohammad S. Obaidat
Soft Comput.3
2019 Privacy Preserving Data Aggregation Scheme for Mobile Edge Computing Assisted IoT Applications
abstract
As the rapid development of 5G and Internet of Things (IoT) techniques, more and more mobile devices with specific sensing capabilities access to the network and large amounts of data. The traditional architecture of the cloud computing cannot satisfy the requirements, such as low latency, fast data access for IoT applications. Mobile edge computing (MEC) can solve these problems, and improve the execution efficiency of the system. In this paper, we propose a privacy preserving data aggregation scheme for MEC assisted IoT applications. In our model, there are three participants, i.e., terminal device (TD), edge server (ES), and public cloud center (PCC). The data generated by the TDs is encrypted and transmitted to the ES, then the ES aggregates the data of the TDs and submits the aggregated data to the PCC. At last, the aggregated plaintext data can be recovered by PCC through its private key. Our scheme not only guarantees data privacy of the TDs but also provides source authentication and integrity. Compared with traditional model, our scheme can save half of communication cost, and is very suitable for MEC assisted IoT applications.
Xiong Li 0002, Shanpeng Liu, Fan Wu 0003, Saru Kumari, Joel J. P. C. Rodrigues
IEEE Internet Things J.4
2019 AEP-PPA: An anonymous, efficient and provably-secure privacy-preserving authentication protocol for mobile services in smart cities
WeiGuo Zhang 0001, Vivek Dabra, Kim-Kwang Raymond Choo, Saru Kumari, Dieter Hogrefe
J. Netw. Comput. Appl.5
2019 A provably secure and anonymous message authentication scheme for smart grids
Xiong Li 0002, Fan Wu 0003, Saru Kumari, Arun Kumar Sangaiah, Kim-Kwang Raymond Choo
J. Parallel Distributed Comput.3
2019 Secure Remote User Mutual Authentication Scheme with Key Agreement for Cloud Environment
Marimuthu Karuppiah, Ashok Kumar Das, Xiong Li 0002, Saru Kumari, Fan Wu 0003, Shehzad Ashraf Chaudhry, Niranchana Radhakrishnan
Mob. Networks Appl.4
2019 Multimodal data modeling for efficiency assessment of social priority based urban bus route transportation system using GIS and data envelopment analysis
Pitam Singh, Ashish Kumar Singh, Priyamvada Singh, Saru Kumari, Arun Kumar Sangaiah
Multim. Tools Appl.4
2019 Duality-based branch-bound computational algorithm for sum-of-linear-fractional multi-objective optimization problem
Deepika Agarwal, Pitam Singh, Deepak Bhati, Saru Kumari, Mohammad S. Obaidat
Soft Comput.4
2019 Optimality criteria for fuzzy-valued fractional multi-objective optimization problem
Deepika Agarwal, Pitam Singh, Xiong Li 0002, Saru Kumari
Soft Comput.4
2019 Secure CLS and CL-AS schemes designed for VANETs
Pankaj Kumar 0006, Saru Kumari, Vishnu Sharma, Xiong Li 0002, Arun Kumar Sangaiah, SK Hafizul Islam
J. Supercomput.2
2018 Design and implementation of a multibiometric system based on hand's traits
Javad Khodadoust, Ali Mohammad Khodadoust, Xiong Li 0002, Saru Kumari
Expert Syst. Appl.4
2018 A secure user authentication and key-agreement scheme using wireless sensor networks for agriculture monitoring
Rifaqat Ali, Arup Kumar Pal, Saru Kumari, Marimuthu Karuppiah, Mauro Conti
Future Gener. Comput. Syst.3
2018 A robust biometrics based three-factor authentication scheme for Global Mobility Networks in smart city
Xiong Li 0002, Jianwei Niu 0002, Saru Kumari, Fan Wu 0003, Kim-Kwang Raymond Choo
Future Gener. Comput. Syst.3
2018 An elliptic curve cryptography based lightweight authentication scheme for smart grid communication
Khalid Mahmood 0002, Shehzad Ashraf Chaudhry, Syed Husnain Abbas Naqvi, Saru Kumari, Xiong Li 0002, Arun Kumar Sangaiah
Future Gener. Comput. Syst.4
2018 Pairing based anonymous and secure key agreement protocol for smart grid edge computing infrastructure
Khalid Mahmood 0002, Xiong Li 0002, Shehzad Ashraf Chaudhry, Syed Husnain Abbas Naqvi, Saru Kumari, Arun Kumar Sangaiah, Joel J. P. C. Rodrigues
Future Gener. Comput. Syst.5
2018 A lightweight and robust two-factor authentication scheme for personalized healthcare systems using wireless medical sensor networks
Fan Wu 0003, Xiong Li 0002, Arun Kumar Sangaiah, Saru Kumari, Liuxi Wu, Jian Shen 0001
Future Gener. Comput. Syst.5
2018 Chaotic Map-Based Anonymous User Authentication Scheme With User Biometrics and Fuzzy Extractor for Crowdsourcing Internet of Things
abstract
The recent proliferation of mobile devices, such as smartphones and wearable devices has given rise to crowdsourcing Internet of Things (IoT) applications. E-healthcare service is one of the important services for the crowdsourcing IoT applications that facilitates remote access or storage of medical server data to the authorized users (for example, doctors, patients, and nurses) via wireless communication. As wireless communication is susceptible to various kinds of threats and attacks, remote user authentication is highly essential for a hazard-free use of these services. In this paper, we aim to propose a new secure three-factor user remote user authentication protocol based on the extended chaotic maps. The three factors involved in the proposed scheme are: 1) smart card; 2) password; and 3) personal biometrics. As the proposed scheme avoids computationally expensive elliptic curve point multiplication or modular exponentiation operation, it is lightweight and efficient. The formal security verification using the widely-accepted verification tool, called the ProVerif 1.93, shows that the presented scheme is secure. In addition, we present the formal security analysis using the both widely accepted real-or-random model and Burrows-Abadi-Needham logic. With the combination of high security and appreciably low communication and computational overheads, our scheme is very much practical for battery limited devices for the healthcare applications as compared to other existing related schemes.
Sandip Roy 0001, Santanu Chatterjee, Ashok Kumar Das, Samiran Chattopadhyay, Saru Kumari, Minho Jo 0001
IEEE Internet Things J.5
2018 A three-factor anonymous authentication scheme for wireless sensor networks in internet of things environments
Xiong Li 0002, Jianwei Niu 0002, Saru Kumari, Fan Wu 0003, Arun Kumar Sangaiah, Kim-Kwang Raymond Choo
J. Netw. Comput. Appl.3
2018 A secure mutual authenticated key agreement of user with multiple servers for critical systems
Azeem Irshad, Shehzad Ashraf Chaudhry, Saru Kumari, Arun Kumar Sangaiah, Xiong Li 0002, Fan Wu 0003
Multim. Tools Appl.4
2018 An improved and secure chaotic map based authenticated key agreement in multi-server architecture
Azeem Irshad, Shehzad Ashraf Chaudhry, Qi Xie 0001, Saru Kumari, Fan Wu 0003
Multim. Tools Appl.5
2018 A provably secure biometrics-based authenticated key agreement scheme for multi-server environments
Saru Kumari, Ashok Kumar Das, Xiong Li 0002, Fan Wu 0003, Muhammad Khurram Khan, Qi Jiang 0001, SK Hafizul Islam
Multim. Tools Appl.1
2018 An improved and provably secure three-factor user authentication scheme for wireless sensor networks
Fan Wu 0003, Saru Kumari, Xiong Li 0002
Peer-to-Peer Netw. Appl.3
2018 A Robust ECC-Based Provable Secure Authentication Protocol With Privacy Preserving for Industrial Internet of Things
abstract
Wireless sensor networks (WSNs) play an important role in the industrial Internet of Things (IIoT) and have been widely used in many industrial fields to gather data of monitoring area. However, due to the open nature of wireless channel and resource-constrained feature of sensor nodes, how to guarantee that the sensitive sensor data can only be accessed by a valid user becomes a key challenge in IIoT environment. Some user authentication protocols for WSNs have been proposed to address this issue. However, previous works more or less have their own weaknesses, such as not providing user anonymity and other ideal functions or being vulnerable to some attacks. To provide secure communication for IIoT, a user authentication protocol scheme with privacy protection for IIoT has been proposed. The security of the proposed scheme is proved under a random oracle model, and other security discussions show that the proposed protocol is robust to various attacks. Furthermore, the comparison results with other related protocols and the simulation by NS-3 show that the proposed protocol is secure and efficient for IIoT.
Xiong Li 0002, Jianwei Niu 0002, Md. Zakirul Alam Bhuiyan, Fan Wu 0003, Marimuthu Karuppiah, Saru Kumari
IEEE Trans. Ind. Informatics6
2018 Attribute-based authentication on the cloud for thin clients
Maged Hamada Ibrahim, Saru Kumari, Ashok Kumar Das, Vanga Odelu
J. Supercomput.2
2018 An efficient and secure design of multi-server authenticated key agreement protocol
Azeem Irshad, Syed Husnain Abbas Naqvi, Shehzad Ashraf Chaudhry, Shouket Raheem, Saru Kumari, Ambrina Kanwal, Muhammad Usman 0018
J. Supercomput.5
2018 A secure authentication scheme based on elliptic curve cryptography for IoT and cloud servers
Saru Kumari, Marimuthu Karuppiah, Ashok Kumar Das, Xiong Li 0002, Fan Wu 0003, Neeraj Kumar 0001
J. Supercomput.1
2017 Anonymous mutual authentication and key agreement scheme for wearable sensors in wireless body area networks
Xiong Li 0002, Maged Hamada Ibrahim, Saru Kumari, Arun Kumar Sangaiah, Vidushi Gupta, Kim-Kwang Raymond Choo
Comput. Networks3
2017 On the design of a secure user authentication and key agreement scheme for wireless sensor networks
abstract
Summary A wireless sensor network (WSN) typically consists of a large number of resource‐constrained sensor nodes and several control or gateway nodes. Ensuring the security of the asymmetric nature of WSN is challenging, and designing secure and efficient user authentication and key agreement schemes for WSNs is an active research area. For example, in 2016, Farash et al. proposed a user authentication and key agreement scheme for WSNs. However, we reveal previously unpublished vulnerabilities in their scheme, which allow an attacker to carry out sensor node spoofing, password guessing, user/sensor node anonymity, and user impersonation attacks. We then present a scheme, which does not suffer from the identified vulnerabilities. To demonstrate the practicality of the scheme, we evaluate the scheme using NS‐2 simulator. We then prove the scheme secure using Burrows–Abadi–Needham logic. Copyright © 2016 John Wiley & Sons, Ltd.
Saru Kumari, Ashok Kumar Das, Mohammad Wazid, Xiong Li 0002, Fan Wu 0003, Kim-Kwang Raymond Choo, Muhammad Khurram Khan
Concurr. Comput. Pract. Exp.1
2017 Design of a provably secure biometrics-based multi-cloud-server authentication scheme
Saru Kumari, Xiong Li 0002, Fan Wu 0003, Ashok Kumar Das, Kim-Kwang Raymond Choo, Jian Shen 0001
Future Gener. Comput. Syst.1
2017 Provably secure authenticated key agreement scheme for distributed mobile cloud computing services
Vanga Odelu, Ashok Kumar Das, Saru Kumari, Xinyi Huang 0001, Mohammad Wazid
Future Gener. Comput. Syst.3
2017 An efficient authentication and key agreement scheme for multi-gateway wireless sensor networks in IoT deployment
Fan Wu 0003, Saru Kumari, Xiong Li 0002, Jian Shen 0001, Kim-Kwang Raymond Choo, Mohammad Wazid, Ashok Kumar Das
J. Netw. Comput. Appl.3
2017 An improved and anonymous two-factor authentication protocol for health-care applications with wireless medical sensor networks
Fan Wu 0003, Saru Kumari, Xiong Li 0002
Multim. Syst.3
2017 A password based authentication scheme for wireless multimedia systems
Nishant Doshi, Saru Kumari, Dheerendra Mishra, Xiong Li 0002, Kim-Kwang Raymond Choo, Arun Kumar Sangaiah
Multim. Tools Appl.2
2017 A secure and provable multi-server authenticated key agreement for TMIS based on Amin et al. scheme
Azeem Irshad, Omer Nawaz, Shehzad Ashraf Chaudhry, Imran Khan 0004, Saru Kumari
Multim. Tools Appl.6
2017 Design flaws of "an anonymous two-factor authenticated key agreement scheme for session initiation protocol using elliptic curve cryptography"
Saru Kumari
Multim. Tools Appl.1
2017 An improved smart card based authentication scheme for session initiation protocol
Saru Kumari, Shehzad Ashraf Chaudhry, Fan Wu 0003, Xiong Li 0002, Mohammad Sabzinejad Farash, Muhammad Khurram Khan
Peer-to-Peer Netw. Appl.1
2017 Efficient anonymous authentication with key agreement protocol for wireless medical sensor networks
Omid Mir, Jorge Munilla, Saru Kumari
Peer-to-Peer Netw. Appl.3
2017 A new and secure authentication scheme for wireless sensor networks with formal proof
Fan Wu 0003, Saru Kumari, Xiong Li 0002
Peer-to-Peer Netw. Appl.3
2017 An efficient authentication and key agreement scheme with user anonymity for roaming service in smart city
Xiong Li 0002, Arun Kumar Sangaiah, Saru Kumari, Fan Wu 0003, Jian Shen 0001, Muhammad Khurram Khan
Pers. Ubiquitous Comput.3
2017 A Two-Factor RSA-Based Robust Authentication System for Multiserver Environments
abstract
The concept of two-factor multiserver authentication protocol was developed to avoid multiple number of registrations using multiple smart-cards and passwords. Recently, a variety of two-factor multiserver authentication protocols have been developed. It is observed that the existing RSA-based multiserver authentication protocols are not suitable in terms of computation complexities and security attacks. To provide lower complexities and security resilience against known attacks, this article proposes a two-factor (password and smart-card) user authentication protocol with the RSA cryptosystem for multiserver environments. The comprehensive security discussion proved that the known security attacks are eliminated in our protocol. Besides, our protocol supports session key agreement and mutual authentication between the application server and the user. We analyze the proof of correctness of the mutual authentication and freshness of session key using the BAN logic model. The experimental outcomes obtained through simulation of the Automated Validation of Internet Security Protocols and Applications (AVISPA) S/W show that our protocol is secured. We consider the computation, communication, and storage costs and the comparative explanations show that our protocol is flexible and efficient compared with protocols. In addition, our protocol offers security resilience against known attacks and provides lower computation complexities than existing protocols. Additionally, the protocol offers password change facility to the authorized user.
Ruhul Amin 0001, SK Hafizul Islam, Muhammad Khurram Khan, Arijit Karati, Debasis Giri, Saru Kumari
Secur. Commun. Networks6
2016 An efficient user authentication and key agreement scheme for heterogeneous wireless sensor network tailored for the Internet of Things environment
Mohammad Sabzinejad Farash, Muhamed Turkanovic, Saru Kumari, Marko Hölbl
Ad Hoc Networks3
2016 A user friendly mutual authentication and key agreement scheme for wireless sensor networks using chaotic maps
Saru Kumari, Xiong Li 0002, Fan Wu 0003, Ashok Kumar Das, Hamed Arshad, Muhammad Khurram Khan
Future Gener. Comput. Syst.1
2016 Cryptanalysis and improvement of a robust smart card secured authentication scheme on SIP using elliptic curve cryptography
Mohammad Sabzinejad Farash, Saru Kumari, Majid Bakhtiari
Multim. Tools Appl.2
2016 A more secure digital rights management authentication scheme based on smart card
Saru Kumari, Muhammad Khurram Khan, Xiong Li 0002
Multim. Tools Appl.1
2016 Single round-trip SIP authentication scheme with provable security for Voice over Internet Protocol using smart card
Saru Kumari, Fan Wu 0003, Xiong Li 0002, Mohammad Sabzinejad Farash, Qi Jiang 0001, Muhammad Khurram Khan, Ashok Kumar Das
Multim. Tools Appl.1
2016 Provably secure three-factor authentication and key agreement scheme for session initiation protocol
abstract
Abstract Session initiation protocol (SIP) is a widely used authentication protocol for the Voice over IP communications. Over the years, several protocols have been proposed in the literature to strengthen the security of SIP. In this paper, we present an efficient elliptic curve cryptography (ECC)‐based provably secure three‐factor authentication and session key agreement scheme for SIP, which uses the identity, password, and personal biometrics of a user as three factors. Our scheme aims to resolve the security weaknesses and drawbacks in existing SIP authentication protocols. In addition, our scheme supports password and biometric update phase without involving the server and the user mobile device revocation phase in case the mobile device is lost/stolen. Formal security analysis under the standard model and the broadly accepted Burrows–Abadi–Needham logic ensures that the proposed scheme can withstand several known security attacks. The proposed scheme has also been analyzed informally. Simulation for formal security verification using the widely known automated validation of internet security protocols and applications tool shows the replay, and the man‐in‐the‐middle attacks are protected by the scheme. High security and low communication and computation costs make the proposed scheme more suitable for practical application as compared with other existing related ECC‐based schemes. Copyright © 2016 John Wiley & Sons, Ltd.
Sravani Challa, Ashok Kumar Das, Saru Kumari, Vanga Odelu, Fan Wu 0003, Xiong Li 0002
Secur. Commun. Networks3
2016 Provably secure user authentication and key agreement scheme for wireless sensor networks
abstract
In recent years, user authentication has emerged as an interesting field of research in wireless sensor networks. Most recently, in 2016, Chang and Le presented a scheme to authenticate the users in wireless sensor network using a password and smart card. They proposed two protocols and . is based on exclusive or (XOR) and hash functions, while deploys elliptic curve cryptography in addition to the two functions used in . Although their protocols are efficient, we point out that both and are vulnerable to session specific temporary information attack and offline password guessing attack, while is also vulnerable to session key breach attack. In addition, we show that both the protocols and are inefficient in authentication and password change phases. To withstand these weaknesses found in their protocols, we aim to design a new authentication and key agreement scheme using elliptic curve cryptography. Rigorous formal security proofs using the broadly accepted, the random oracle models, and the Burrows–Abadi–Needham logic and verification using the well-known Automated Validation of Internet Security Protocols and Applications tool are preformed on our scheme. The analysis shows that our designed scheme has the ability to resist a number of known attacks comprising those found in both Chang–Le's protocols. Copyright © 2016 John Wiley & Sons, Ltd.
Ashok Kumar Das, Saru Kumari, Vanga Odelu, Xiong Li 0002, Fan Wu 0003, Xinyi Huang 0001
Secur. Commun. Networks2
2016 An efficient multi-gateway-based three-factor user authentication and key agreement scheme in hierarchical wireless sensor networks
abstract
Abstract User authentication in wireless sensor network (WSN) plays a very important role in which a legal registered user is allowed to access the real‐time sensing information from the sensor nodes inside WSN. To allow such access, a user needs to be authenticated by the accessed sensor nodes as well as gateway nodes inside WSNs. Because of resource limitations and vulnerability to physical capture of some sensor nodes by an attacker, design of a secure user authentication in WSN continues to be an important and challenging research area in recent years. In this paper, we propose a new three‐factor user authentication scheme based on the multi‐gateway WSN architecture. Through the widely‐accepted Burrows–Abadi–Needham logic, we prove that our scheme provides the secure mutual authentication. We then present the formal security verification of our proposed scheme using AVISPA tool, which is a powerful validation tool for network security applications, and show that our scheme is secure. In addition, the rigorous informal security analysis shows that our scheme is also secure against possible other known attacks including the sensor node capture attack. Furthermore, we present the additional functionality features that our scheme offers, which are efficient in communication and computation. Copyright © 2016 John Wiley & Sons, Ltd.
Ashok Kumar Das, Anil Kumar Sutrala, Saru Kumari, Vanga Odelu, Mohammad Wazid, Xiong Li 0002
Secur. Commun. Networks3
2016 Jamming resistant non-interactive anonymous and unlinkable authentication scheme for mobile satellite networks
abstract
Abstract Most of the previously proposed schemes use temporary identities for mobile users to provide unlinkable anonymous authentication for mobile users to the satellite network control center (NCC), where the temporary identities are picked at random after each session and agreed between a mobile user U and the NCC for the next session. Although such schemes provide full anonymity and are computationally efficient, the common problem with such strategies is that an adversary is able to desynchronize the temporary identity shared between U and NCC by means of simple jamming attack at a certain round in the authentication protocol. It results in the denial of all future sessions unless U re‐registers a new identity at the NCC. In this paper, we propose a new authentication scheme for mobile satellite networks. We avoid using synchronized temporary identities, which are always vulnerable to desynchronization attacks. We also avoid multi‐round authentication phase in order to reduce the jamming effect. Instead, a mobile user is able to create a new blinded version of his clear identity for each established session noninteractively, allowing him to anonymously authenticate himself to NCC in a fully unlinkable fashion. Moreover, in few milliseconds and one move non‐interactive way, U is able to establish a session key with NCC in a fully anonymous and authenticated way. Our new scheme uses recent advances in elliptic curve cryptography, and hence, it is efficient for implementation on mobile devices with limited resources. Through the rigorous security analysis using the broadly accepted Burrows–Abadi–Needham logic, informal security analysis, and the simulation for formal security verification using the widely known automated validation of Internet security protocols and sapplications tool, we show that our scheme is secure against various known attacks. Copyright © 2017 John Wiley & Sons, Ltd.
Maged Hamada Ibrahim, Saru Kumari, Ashok Kumar Das, Vanga Odelu
Secur. Commun. Networks2
2016 A secure lightweight authentication scheme with user anonymity for roaming service in ubiquitous networks
abstract
Abstract Ubiquitous networks provide effective roaming services for mobile users (MUs). Through the worldwide roaming technology, authorized MUs can avail ubiquitous network services. Important security issues to be considered in ubiquitous networks are authentication of roaming MUs and protection of privacy of MUs. However, because of the broadcast nature of wireless channel and resource limitations of terminals, providing efficient user authentication with privacy preservation is a challenging task. Very recently, Farash et al. proposed an authentication scheme with anonymity for consumer roaming in ubiquitous networks and claimed their scheme achieves all security requirements. In this paper, we show that the scheme of Farash et al. fails to achieve user anonymity and mutual authentication. Their scheme also fails to provide local password verification, and it has a faulty password change phase. Moreover, their scheme is vulnerable to replay, offline password guessing, and forgery attacks. To fix the security flaws of the scheme of Farash et al., we present an improved authentication scheme for accessing roaming service provided by ubiquitous networks. We then formally verify the security properties of our scheme by the widely‐accepted push‐button tool called Automated Validation of Internet Security Protocols and Applications. Security and performance analyses show that our scheme is more powerful, efficient, and secure when it is compared with existing schemes. Copyright © 2016 John Wiley & Sons, Ltd.
Marimuthu Karuppiah, Saru Kumari, Ashok Kumar Das, Xiong Li 0002, Fan Wu 0003, Sayantani Basu
Secur. Commun. Networks2
2016 An enhanced and secure trust-extended authentication mechanism for vehicular ad-hoc networks
abstract
Abstract Vehicular Ad‐hoc Networks (VANETs) are a move towards regulating safe traffic and intelligent transportation system. A VANETs is characterized by extremely dynamic topographical conditions owing to speedily moving vehicles. In VANETs, vehicles can transmit messages within a pre‐defined area to achieve safety and efficiency of the system. Then ensuring authenticity of origin of messages to the receiver in such a dynamic environment is a crucial challenge. Another concern in VANET is preservation of privacy of user/vehicle. Recently, Chuang and Lee proposed a trust‐extended authentication mechanism (TEAM) for vehicle‐to‐vehicle communications in VANETs. TEAM not only satisfies various security features but also enhances the performance of the authentication process using transitive trust relationship among vehicles. Nonetheless, our analysis shows that TEAM is vulnerable to insider attack, privacy breach, impersonation attacks and some other problems. In this paper, to eradicate the vulnerabilities found in Chuang‐Lee's scheme, an enhanced trust‐extended authentication scheme for VANET is proposed. We display the efficiency of our scheme through security analysis and comparison. Through simulation results using widely accepted NS‐2 simulator, we show that our scheme authenticates vehicles faster than Chuang‐Lee's scheme. Copyright © 2016 John Wiley & Sons, Ltd.
Saru Kumari, Marimuthu Karuppiah, Xiong Li 0002, Fan Wu 0003, Ashok Kumar Das, Vanga Odelu
Secur. Commun. Networks1
2016 A new authentication protocol for healthcare applications using wireless medical sensor networks with user anonymity
abstract
ABSTRACT With the development and maturation of the wireless communication technologies, the wireless sensor networks have been widely applied in different environments to acquire specific information. The wireless medical sensor networks (WMSNs), as a professional application of the wireless sensor networks in medicine, have attracted more and more attention because of its potential in improving the quality of healthcare services. Through the WMSNs, the parameters of patients' vital signs can be gathered from the sensor nodes equipped on the body of the patients and then can be accessed by the healthcare professionals by using a mobile device. By reason of the open feature of wireless communication, how to guarantee secure communication becomes an important issue. On the other hand, because the vital signs parameters are sensitive to the patients' health status and no one wants to reveal it to the others except the healthcare professionals, the protection of patients' privacy becomes another key issue for WMSNs applications. User authentication protocol with anonymity is the most basic and commonly used method to resolve the security and privacy issues of WMSNs. Recently, He et al. proposed an enhanced authentication protocol for healthcare applications using WMSNs to protect the security and privacy problems. However, we find that their scheme is incorrect in authentication and session key agreement phase. Besides, their scheme has no wrong password detection mechanism, which will not only waste the unnecessary computation and communication costs, but also may deduce the denial of service problem. In this paper, the biometric is introduced as the third authentication factor, and a new user anonymous authentication protocol based on WMSNs is designed so as to remove the drawbacks of the protocol of He et al. Compared with previous protocols, the new presented protocol enhances the security and also keeps the computation efficiency. Copyright © 2015 John Wiley & Sons, Ltd.
Xiong Li 0002, Jianwei Niu 0002, Saru Kumari, Junguo Liao, Wei Liang 0005, Muhammad Khurram Khan
Secur. Commun. Networks3
2016 Design of sinkhole node detection mechanism for hierarchical wireless sensor networks
abstract
Abstract Wireless sensor networks (WSNs) have several applications ranging from the civilian to military applications. WSNs are prone to various hole attacks, such as sinkhole, wormhole, blackhole, and greyhole. Among these hole attacks, the sinkhole attack is the malignant one. A sinkhole attack allows a malicious node, called the sinkhole node, advertises a best possible path to the base station (BS). This misguides its neighbors to utilize that path more frequently. The sinkhole node has the opportunity to tamper with the data, and it also performs the modifications in messages or it drops messages or it produces unnecessary delay before forwarding them to the BS. On the basis of these malicious acts that are performed by a sinkhole attacker node, we consider three types of malicious nodes in a WSN: sinkhole message modification node (SMD), sinkhole message dropping node (SDP), and sinkhole message delay node (SDL). None of the existing techniques in the literature is capable to handle all three types of nodes at a time. This paper presents a new detection scheme for the detection of different types of sinkhole nodes for a hierarchical wireless sensor network (HWSN). To the best of our knowledge, this is the first attempt to design such a detection scheme in HWSNs which can detect SMD, SDP, and SDL nodes. In our approach, the entire HWSN is divided into several disjoint clusters, and each cluster has a powerful high‐end sensor node (called a cluster head), which is responsible for the detection of different sinkhole attacker nodes if present in that cluster. We simulate our scheme using the widely‐accepted NS2 simulator for measurement of various network parameters. The proposed scheme achieves around 95%detection rate and 1.25%false positive rate. These factors are significantly better than the previous related schemes. Furthermore, the computation and communication efficiency is achieved in our scheme. As a result, our scheme seems suitable for the sensitive critical applications, such as military applications. Copyright © 2016 John Wiley & Sons, Ltd.
Mohammad Wazid, Ashok Kumar Das, Saru Kumari, Muhammad Khurram Khan
Secur. Commun. Networks3
2016 Design of an efficient and provably secure anonymity preserving three-factor user authentication and key agreement scheme for TMIS
abstract
Abstract Several remote user authentication techniques for telecare medicine information system (TMIS) have been proposed in the literature. But most existing techniques have limitations such as vulnerable to various attacks, lack of functionalities, and inefficiency. Recently, Amin and Biswas proposed a three‐factor authentication and key agreement technique for TMIS. But their scheme is inefficient and has several security drawbacks. The attacks such as privileged‐insider, user impersonation, and strong reply attacks are possible on their scheme. It also has flaw in password update phase. In order to overcome drawbacks of their scheme, a new provably secure and efficient three‐factor remote user authentication scheme for TMIS is proposed in this paper. The proposed scheme overcomes all drawbacks of their scheme and also provides additional features such as user unlinkability, user anonymity, efficient password, and biometric update. The rigorous informal and formal security analysis using random oracle models and the mostly acceptable Automated Validation of Internet Security Protocols and Applications tool is also performed. During the experimentation, it has been observed that the proposed scheme is secure against various known attacks that include replay and man‐in‐the‐middle attacks. Furthermore, the analysis of computation and communication cost estimation of the proposed scheme depicts that our scheme is efficient as compared with other related exiting schemes. Copyright © 2016 John Wiley & Sons, Ltd.
Mohammad Wazid, Ashok Kumar Das, Saru Kumari, Xiong Li 0002, Fan Wu 0003
Secur. Commun. Networks3
2016 Provably secure biometric-based user authentication and key agreement scheme in cloud computing
abstract
Abstract Cloud computing, the conjoin of many types of computing, has made a great impact on the life of everyone. People from anywhere can access the different cloud‐based services by using the Internet. A user, who wants to access some cloud‐based service, needs to register himself/herself to an authority (service provider), and after that, he/she can use the service. To access the service, each user needs to authenticate to that particular cloud server. Several user authentication schemes for cloud computing have been presented but mostly have limitations/drawbacks as they are prone to various known attacks, such as privileged insider, user and server impersonation, and strong reply attacks, and they also have lack of functionality features. Moreover, these schemes do not provide efficient password change phase. In order to overcome these drawbacks, we propose a new provably secure biometric‐based user authentication and key agreement scheme for cloud computing. The proposed scheme overcomes the weaknesses of the existing schemes and supports extra functionality features including user anonymity and efficient password and biometric update phase for multi‐server environment. The careful formal security analysis under standard model and informal security analysis and the simulation results for formal security verification using the most acceptable AVISPA tool show that the proposed scheme is secure against various known possible attacks. The analysis of computation and communication overheads of our scheme depicts its efficiency over other related existing schemes, and thus, the proposed scheme is suitable for the cloud computing environment. Copyright © 2016 John Wiley & Sons, Ltd.
Mohammad Wazid, Ashok Kumar Das, Saru Kumari, Xiong Li 0002, Fan Wu 0003
Secur. Commun. Networks3
2016 A novel and provably secure authentication and key agreement scheme with user anonymity for global mobility networks
abstract
Ubiquitous networks support the roaming service for mobile communication devices. The mobile user can use the services in the foreign network with the help of the home network. Mutual authentication plays an important role in the roaming services, and researchers put their interests on the authentication schemes. Recently, in 2016, Gope and Hwang found that mutual authentication scheme of He et al. for global mobility networks had security disadvantages such as vulnerability to forgery attacks, unfair key agreement, and destitution of user anonymity. Then, they presented an improved scheme. However, we find that the scheme cannot resist the off-line guessing attack and the de-synchronization attack. Also, it lacks strong forward security. Moreover, the session key is known to HA in that scheme. To get over the weaknesses, we propose a new two-factor authentication scheme for global mobility networks. We use formal proof with random oracle model, formal verification with the tool Proverif, and informal analysis to demonstrate the security of the proposed scheme. Compared with some very recent schemes, our scheme is more applicable. Copyright © 2016 John Wiley & Sons, Ltd.
Fan Wu 0003, Saru Kumari, Xiong Li 0002, Ashok Kumar Das, Muhammad Khurram Khan, Marimuthu Karuppiah, Renuka Baliyan
Secur. Commun. Networks3
2015 User authentication schemes for wireless sensor networks: A review
Saru Kumari, Muhammad Khurram Khan, Mohammed Atiquzzaman
Ad Hoc Networks1
2015 An enhanced privacy preserving remote user authentication scheme with provable security
abstract
Abstract Very recently, Kumariet al.proposed a symmetric key and smart card‐based remote user password authentication scheme to enhance Chunget al.'s scheme. They claimed their enhanced scheme to provide anonymity while resisting all known attacks. In this paper, we analyze that Kumariet al.'s scheme is still vulnerable to anonymity violation attack as well as smart card stolen attack. Then we propose a supplemented scheme to overcome security weaknesses of Kumariet al.'s scheme. We have analyzed the security of the proposed scheme in random oracle model which confirms the robustness of the scheme against all known attacks. We have also verified the security of our scheme using automated tool ProVerif. Copyright © 2015 John Wiley & Sons, Ltd.
Shehzad Ashraf Chaudhry, Mohammad Sabzinejad Farash, Syed Husnain Abbas Naqvi, Saru Kumari, Muhammad Khurram Khan
Secur. Commun. Networks4
2015 A new authenticated key agreement scheme based on smart cards providing user anonymity with formal proof
abstract
Abstract Nowadays, smart‐card‐based user authentication becomes one of the most important security issues. But many schemes of that kind are under different attacks. Recently, Kumari et al. pointed that Chen et al.‘s scheme and Li et al.‘s scheme with the smart card were not secure. They proposed two improved schemes. Unfortunately, we find that the two schemes are not secure. The first scheme of Kumari et al. is under the de‐synchronization attack and lacks strong forward security. The second has the weaknesses including no user anonymity and password leaking. Also, it cannot withstand the user‐impersonation attack. We present a new scheme also based on the smart card overcoming common disadvantages and give a formal proof. We also use the tool ProVerif to verify the security of our scheme. Compared with some recent schemes, our scheme performs well, and it is fit for network applications. Copyright © 2015 John Wiley & Sons, Ltd.
Fan Wu 0003, Saru Kumari, Xiong Li 0002, Abdulhameed Alelaiwi
Secur. Commun. Networks3
2014 Security Issues of Chen et al.'s Dynamic ID-Based Authentication Scheme
abstract
Chen et al. proposed in 2012, a dynamic ID-based authentication scheme for Telecare Medical Information Systems. Chen et al. preferred simpler computations unlike previous schemes proposed for TMIS, so they designed a computational complexity-free protocol. But it entails many security concerns. Here we show that an adversary can cheat the lawful participants of the scheme, can compute the agreed upon session-key, which renders the communication between the participants as un-confidential. We further illustrate that in-spite of using dynamic identity during login phase their scheme does not provide user anonymity. We also demonstrate that their design invites password guessing attack, stolen verifier attack and has an incomplete password change phase.
Muhammad Khurram Khan, Saru Kumari
DASC2
2014 Cryptanalysis and Improvement of "An Efficient and Secure Dynamic ID-based Authentication Scheme for Telecare Medical Information Systems"
abstract
ABSTRACT Recently, telecare medicine information systems (TMIS) have emerged as an effective mechanism to raise quality convenience and availability of healthcare services. User authentication schemes play an important role in solving security problems and grant access to healthcare services only to the authorized users. In 2010, a few authentication schemes were proposed for TMIS. These were based on the concept of static identity. In 2012, Chen et al. proposed a dynamic ID‐based authentication scheme for TMIS, so that the user's identity is not revealed to anyone. However, Chen et al.'s scheme does not involve complex computations like the previous scheme for TMIS, yet it suffers from various security problems. We will show that attackers can not only impersonate the legal participants of the scheme but can also compute the shared session‐key. In fact, it is an attack over the confidential communication between the participants. We will also show other drawbacks, such as password guessing attack, denial‐of‐service attack, immediate replay attack, and incomplete password change phase, present in the scheme. We also demonstrate user anonymity breach in Chen et al.'s scheme. To overcome these problems, we propose an improvement to Chen et al.'s scheme with a different approach. Our approach is aimed at providing an authentication mechanism for TMIS with strong security features. Copyright © 2013 John Wiley & Sons, Ltd.
Muhammad Khurram Khan, Saru Kumari
Secur. Commun. Networks2
2014 An improved timestamp-based password authentication scheme: comments, cryptanalysis, and improvement
abstract
ABSTRACT In 2003, Shen et al. proposed a timestamp‐based password authentication scheme by using smart card. Later, in 2005 and 2008, this scheme was found susceptible to forged login attacks by some researchers, and improved schemes were proposed. In 2011, Awasthi et al. pointed out an additional security threat on the scheme of Shen et al. and also suggested remedy by proposing an enhanced scheme. In this paper, we analyze the additional attack identified by Awasthi et al. on the scheme of Shen et al. show its flaws and rectify it. Further, we find that the scheme of Awasthi et al. still fails to withstand forged login attack, smart card loss attack, offline password guessing attack, and so on, and also inherits some weaknesses from the original scheme. Therefore, we propose an improved version of the scheme of Awasthi et al. Our improved scheme not only resists the attacks that we depict on the scheme of Awasthi et al. but is also free from the attacks pointed out so far on the scheme of Shen et al. Copyright © 2013 John Wiley & Sons, Ltd.
Saru Kumari, Mridul Kumar Gupta, Muhammad Khurram Khan, Xiong Li 0002
Secur. Commun. Networks1
2014 More secure smart card-based remote user password authentication scheme with user anonymity
abstract
ABSTRACT In 2009, Xu et al. designed a smart card‐based user authentication scheme. It was found at risk of offline password guessing and forgery attacks as proved by Sood et al. They also proposed an improvement to Xu et al.'s scheme with a view to fix its defects. Parallel to Sood et al.'s work, Song also identified that a domestic but illicit user of the system can impersonate other innocent users. Later, Chen et al. claimed that designs of Sood et al.'s and Song's schemes are not flawless, and they built a scheme over both of these schemes. In 2013, Li et al. observed absence of forward secrecy and lack of password validity test by smart card in Chen et al.'s scheme. They also asserted password change phase of Chen et al.'s scheme as unfriendly and inefficient and gave rise to a new scheme. However, we discover many flaws including offline password guessing and impersonation threats in Li et al.'s scheme. We find that none of the aforementioned schemes provide user anonymity. Therefore, we propose a user authentication scheme with user anonymity. The analysis shows that our scheme retains merits of its predecessor schemes, is free from faults identified in these schemes, and also offers some extra features that make it more suitable for practical applications. Copyright © 2013 John Wiley & Sons, Ltd.
Saru Kumari, Muhammad Khurram Khan
Secur. Commun. Networks1