Syed Wajid Ali Shah

dblp:120/7801 · also Syed W. Shah · DBLP profile ↗
← Back
10ranked-venue papers
5as first author
6since 2021 · last 2024
0000-0001-5420-5499ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 2 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 4 · 3 first-author · 1 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2024 Examining usable security features and user perceptions of Physical Authentication Devices
abstract
Despite the enhanced security benefits offered by Physical Authentication Devices (PADs) compared to other forms of Multi-Factor Authentication (MFA), the adoption and retention of PADs remain relatively low in comparison to other MFA methods. Evidence indicates that the limited widespread adoption and usage of PADs are primarily due to negative user perceptions concerning their usability and security features. Moreover, there's a limited understanding of how users from diverse backgrounds perceive PADs with their varying standards and features. To bridge this knowledge gap, we undertook a multiple case study with 23 users spanning varied demographic characteristics (age, gender, education, and experience with MFA) to use and test three distinct PADs. Case study participants were provided with three unique PAD devices featuring different characteristics/features and were prompted to share their experiences of installation, usage, and troubleshooting over a 2-week span via an initial questionnaire, logbook, and a final interview. The gathered data were analysed using NVIVO, a Qualitative Research Software platform, uncovering notable disparities between user groups and their predilections for specific PADs. Further discussions from our research illuminate four primary areas (Compatibility, Support, Quality and Simplicity) where usable security features impede positive user perception of PAD devices and addressing these areas is crucial for enhancing PAD adoption and retention rates.
Ashish Nanda, Jongkil Jeong, Syed Wajid Ali Shah, Mohammad Reza Nosouhi, Robin Doss
Comput. Secur.3
2024 User Characteristics and Their Impact on the Perceived Usable Security of Physical Authentication Devices
abstract
Physical authentication devices (PADs) offer a higher level of security than other authentication technologies commonly used in multifactor authentication (MFA) schemes because they are much less vulnerable to attack. However, PAD uptake remains significantly lower than that for SMS and app-based approaches, accounting for only 10% of all authentication technologies currently being utilized in MFA. Prior studies indicate that the primary reason for this low adoption rate is due to negative users' perceptions and attitudes toward the usability of PADs; many of these studies often skew toward a particular set of users (e.g., young university students, etc.), often creating a bias toward what usable security entails. To address this limitation, we have formulated an original research methodology that segments users into specific groups based on their user characteristics (i.e., age, education, and experience) and examines how each group defines usability and ranks their preferences regarding certain security features. Based on a survey of 410 participants, our results indicate that there are indeed different usable security preferences for each user group, and we, therefore, provide recommendations on how existing PADs might be enhanced to support usability and improve adoption rates.
Jongkil Jeong, Syed Wajid Ali Shah, Ashish Nanda, Robin Doss, Mohammad Reza Nosouhi, Jeb Webb
IEEE Trans. Hum. Mach. Syst.2
2023 Weak-Key Analysis for BIKE Post-Quantum Key Encapsulation Mechanism
abstract
The evolution of quantum computers poses a serious threat to contemporary public-key encryption (PKE) schemes. To address this impending issue, the National Institute of Standards and Technology (NIST) is currently undertaking the Post-Quantum Cryptography (PQC) standardization project intending to evaluate and subsequently standardize the suitable PQC scheme(s). One such attractive approach, called Bit Flipping Key Encapsulation (BIKE), has entered the final round of the competition. Despite having some attractive features, the IND-CCA security of BIKE depends on the average decoder failure rate (DFR), a higher value of which can facilitate a particular type of side-channel attack. Although BIKE adopts the Black-Grey-Flip (BGF) decoder that offers a negligible DFR, the effect of weak-keys on the average DFR has not been fully investigated. In this paper, we implement the BIKE scheme, and then through extensive experiments show that the weak-keys can be a potential threat to IND-CCA security of the BIKE scheme and thus need attention from the relevant research community. We also propose a key-check algorithm that can potentially supplement the BIKE mechanism and prevent users from adopting weak-keys.
Mohammad Reza Nosouhi, Syed Wajid Ali Shah, Lei Pan 0002, Yevhen Zolotavkin, Ashish Nanda, Praveen Gauravaram, Robin Doss
IEEE Trans. Inf. Forensics Secur.2
2022 Traceability in supply chains: A Cyber security analysis
Naeem Firdous Syed, Syed Wajid Ali Shah, Rolando Trujillo-Rasua, Robin Doss
Comput. Secur.2
2021 LCDA: Lightweight Continuous Device-to-Device Authentication for a Zero Trust Architecture (ZTA)
Syed Wajid Ali Shah, Naeem Firdous Syed, Arash Shaghaghi, Adnan Anwar, Zubair A. Baig, Robin Doss
Comput. Secur.1
2021 Data Augmentation and Dense-LSTM for Human Activity Recognition Using WiFi Signal
abstract
Recent research has devoted significant efforts on the utilization of WiFi signals to recognize various human activities. An individual's limb motions in the WiFi coverage area could interfere with wireless signal propagation, that manifested as unique patterns for activity recognition. Existing approaches though yielding reasonable performance in certain cases, are ignorant of two major challenges. The performed activities of the individual normally have inconsistent speed in different situations and time. Besides that the wireless signal reflected by human bodies normally carries substantial information that is specific to that subject. The activity recognition model trained on a certain individual may not work well when being applied to predict another individual's activities. Since only recording activities of limited subjects in a certain speed and scale, recent works commonly have a moderate amount of activity data for training the recognition model. The small-size data could often incur the overfitting issue that negative affect the traditional classification model. To address these challenges, we propose a WiFi-based human activity recognition system that synthesizes variant activities data through eight channel state information (CSI) transformation methods to mitigate the impact of activity inconsistency and subject-specific issues, and also design a novel deep-learning model that caters to the small-size WiFi activity data. We conduct extensive experiments and show synthetic data improve performance by up to 34.6% and our system achieves around 90% of accuracy with well robustness in adapting to small-size CSI data.
Jin Zhang 0013, Fuxiang Wu, Bo Wei 0003, Qieshi Zhang, Hui Huang 0014, Syed Wajid Ali Shah, Jun Cheng 0002
IEEE Internet Things J.6
2020 Towards a Lightweight Continuous Authentication Protocol for Device-to-Device Communication
abstract
Continuous Authentication (CA) has been proposed as a potential solution to counter complex cybersecurity attacks that exploit conventional static authentication mechanisms that authenticate users only at an ingress point. However, widely researched human user characteristics-based CA mechanisms cannot be extended to continuously authenticate Internet of Things (IoT) devices. The challenges are exacerbated with the increased adoption of device-to-device (d2d) communication in critical infrastructures. Existing d2d authentication protocols proposed in the literature are either prone to subversion or are computationally infeasible to be deployed on constrained IoT devices. In view of these challenges, we propose a novel, lightweight and secure CA protocol that leverages communication channel properties and a tunable mathematical function to generate dynamically changing session keys. Our preliminary informal protocol analysis suggests that the proposed protocol is resistant to known attack vectors and thus has strong potential for deployment in securing critical and resource-constrained d2d communication.
Syed Wajid Ali Shah, Naeem Firdous Syed, Arash Shaghaghi, Adnan Anwar, Zubair A. Baig, Robin Doss
TrustCom1
2019 Smart user identification using cardiopulmonary activity
Syed Wajid Ali Shah, Salil S. Kanhere
Pervasive Mob. Comput.1
2018 Wi-Sign: Device-free Second Factor User Authentication
abstract
Most two-factor authentication (2FA) implementations rely on the user possessing and interacting with a secondary device (e.g. mobile phone) which has contributed to the lack of widespread uptake. We present a 2FA system, called Wi-Sign that does not rely on a secondary device for establishing the second factor. The user is required to sign at a designated place on the primary device with his finger following a successful first step of authentication (i.e. username + password). Wi-Sign captures the unique perturbations in the WiFi signals incurred due to the hand motion while signing and uses these to establish the second factor. Wi-Sign detects these perturbations by measuring the fine-grained Channel State Information (CSI) of the ambient WiFi signals at the device from which log-in attempt is being made. The logic is that, the user's hand geometry and the way he moves his hand while signing cause unique perturbations in CSI time-series. After filtering noise from the CSI data, principal component analysis is employed for compressing the CSI data. For segmentation of sign related perturbations, Wi-Sign utilizes the thresholding approach based on the variance of the first-order difference of the selected principal component. Finally, the authentication decision is made by feeding scrupulously selected features to a One-Class SVM classifier. We implement Wi-Sign using commodity off-the-shelf 802.11n devices and evaluate its performance by recruiting 14 volunteers. Our evaluation shows that Wi-Sign can on average achieve 79% TPR. Moreover, Wi-Sign can detect attacks with an average TNR of 86%.
Syed Wajid Ali Shah, Salil S. Kanhere
MobiQuitous1
2017 Wi-Auth: WiFi based Second Factor User Authentication
abstract
While second factor authentication (2FA) is now widely available, user adoption is still very low, as most of 2FA implementations require significant interaction from the user. In this paper, we present a novel 2FA system, called Wi-Auth that requires minimal participation from the user. A user after confirming her credentials with an online service, simply has to place a pre-registered secondary device in close proximity (< 2.5 inches) of the primary device from which the login attempt is being made. Wi-Auth detects the proximity of these two devices by comparing the fine-grained Channel State Information (CSI) of the ambient WiFi signals measured at the two devices. The logic being that two devices that are in such close proximity will exhibit very similar CSI characteristics. Wi-Auth uses a lightweight two-step matching algorithm to compare the two CSI measurements. We also address (for the first time in literature) the issue of targeted attacks where an attacker may be co-located with the victim. We implement Wi-Auth using commodity off-the-shelf 802.11n devices and evaluate its performance in three different practical settings including an open office, an apartment and a large meeting space. Our experiments performed at 90 different location reveal that Wi-Auth can on average achieve 94% authentication accuracy with 5% false positives and 6% false negatives. Moreover, Wi-Auth is very robust in preventing co-located attacks with a 95% attack detection accuracy.
Syed Wajid Ali Shah, Salil S. Kanhere
MobiQuitous1