Mohammad Wazid

dblp:122/2287 · DBLP profile ↗
← Back
54ranked-venue papers
26as first author
31since 2021 · last 2026
0000-0001-9898-0921ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 21 · 11 first-author · 12 since 2021Security and privacy · 11 · 5 first-author · 5 since 2021Systems, architecture and hardware · 8 · 4 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 5 first-author · 4 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 Blockchain-Based Secure Product Authenticity Verification for Industrial Networks
abstract
The number of fake products is increasing day by day, which creates many serious problems. These fake items are unsafe for brand reputation as breaks trust and value also unsafe for consumers. Traditional methods like holograms, barcodes, etc., are widely used, but at certain levels, counterfeiters misuse them and copy them, which is not fully transparent. To address these issues, in this paper, we suggest using a blockchain-based system to verify whether a product is real or fake. Leveraging blockchain’s immutability and integrity, the product information is securely recorded using unique block hashes and Quick Response (QR) codes, making unauthorized tampering more difficult once the data is recorded. The consumers can confirm the originality of the product by simply scanning or uploading QR codes, which makes it tough for counterfeiters to clone the QR codes. A key feature of our approach is the integration of multi-scan detection. This system helps to detect unusual or suspicious scanning behavior and creates more trust. The system uses smart contracts to automate secure product registration and verification processes. To demonstrate feasibility, we present the details of the prototype, including database design, flowcharts, and user interface, illustrating its practical deployment.
Varun Dobhal, Saksham Mittal, Mohammad Wazid, Sourav Saha 0002, Ashok Kumar Das, Shantanu Pal, Joel J. P. C. Rodrigues
ICBC3
2026 Big Data Analytics-Envisioned Quantum-Safe Lattice-Based Three-Party Authenticated Key Agreement Protocol for Cloud IoT-Enabled Healthcare Applications
abstract
Cloud-based Internet of Things (IoT)-enabled smart healthcare plays a vital role in modern society, yet security and privacy challenges remain unavoidable. The authenticated key agreement (AKA) process, which serves as the foundation of secure communication, is widely recognized as a key solution to these challenges. However, many existing AKA methods in the literature either involve high communication and computational costs or fail to withstand quantum attacks. Post-quantum cryptography (PQC) introduces a new class of cryptographic algorithms designed to resist future quantum computer threats. In this article, we present a quantum-secure, lattice-based three-party AKA scheme for smart IoT healthcare applications, leveraging the computationally complex Ring-Learning With Errors (Ring-LWE) problem. Our approach integrates secure big-data analytics with blockchain technology by utilizing authentication procedures for secure data aggregation before storing it in the blockchain. A comprehensive security evaluation including formal and informal analysis, demonstrates the scheme's strong resilience against both classical and quantum attacks. Additionally, experimental results confirm that the proposed scheme is well-suited for real-time smart healthcare applications.
Prithwi Bagchi, Aakash Roy, Mohammad Wazid, Ashok Kumar Das, Bharat K. Bhargava, Youngho Park 0005
IEEE Trans. Dependable Secur. Comput.3
2025 A deep learning ensemble approach for malware detection in Internet of Things utilizing Explainable Artificial Intelligence
Saksham Mittal, Mohammad Wazid, Devesh Pratap Singh, Ashok Kumar Das, M. Shamim Hossain
Eng. Appl. Artif. Intell.2
2025 Authenticated Certificateless Verifiable Searchable Public Key Encryption Scheme With Big Data Analytics for IoT-Based Healthcare
abstract
The emerging concept of Internet of Things (IoT)-based healthcare Industry 5.0 emphasizes the integration of human intelligence with cutting-edge technologies, like Artificial Intelligence (AI), blockchain, IoT, big data analytics, and machine learning (ML) models to revolutionize healthcare delivery. However, alongside the immense potential and opportunities of healthcare 5.0, the rapid expansion of sensitive medical data within the cloud-based healthcare systems also brings significant challenges related to data security, privacy, and resource requirements. Since most healthcare infrastructures depend on the semi-trusted centralized cloud storage, it then becomes crucial to store medical records in encrypted form in order to ensure confidentiality and privacy of the data. At the same time, these systems must provide seamless and efficient search capabilities for authorized medical personnel in healthcare system. To address these concerns and enable cost-effective, secure access and data management, we propose a novel authenticated certificateless verifiable searchable public key encryption scheme (ACLV-SPKE) that emerges as a robust and promising solution for securing healthcare data. The proposed framework not only resists diverse adversarial attacks but also ensures efficiency in terms of communication and computation costs, while offering improved functionality over recent state-of-the-art solutions presented in literature. The proposed scheme effectively resists both inside and outside keyword guessing attacks, achieving strong security guarantees like ciphertext and trapdoor indistinguishability, which are proved in the random oracle models. In addition, we applied big data analytics on a real healthcare dataset to evaluate the performance metrics, and the outcomes are presented in this article.
Debjani Mallick, Ashok Kumar Das, Mohammad Wazid, Youngho Park 0005
IEEE Internet Things J.3
2025 Uncrewed Aerial Vehicles Empowering Secure Authentication in Cognitive IoMT for Transformative Knowledge Discovery in Data
abstract
The paradigm shift toward digital transformation is increasingly advancing toward cognitive decision discovery, particularly within the healthcare domain, where it has emerged as a critical area of research. Numerous researchers are actively contributing to this field. However, due to the sensitive nature of healthcare data, ensuring robust security within the cognitive decision-making process is paramount for Internet of Medical Things (IoMT). To address this concern, the present study proposes a comprehensive privacy-preserving authentication scheme associating aerial computing and knowledge discovery. This scheme leverages an elliptic curve-based cryptosystem to establish the authentication protocol and incorporates blockchain technology to ensure data storage security. Furthermore, the scheme facilitates secure knowledge discovery in data (KDD) within cognitive decision-making frameworks. The proposed authentication mechanism is evaluated across communication, computational efficiency, and security parameters to validate its functionality and robustness as well as to formally verify the developed scheme Scyther tool verification is done by authors. Additionally, to demonstrate the necessity and effectiveness of the proposed scheme, the authors conducted a KDD experiment using both a securely authenticated dataset and an insecure, compromised dataset. The results of these experiments are presented and thoroughly analyzed in the article.
Abhishek Kumar Pandey, Ashok Kumar Das, Mohammad Wazid, Kuljeet Kaur, Youngho Park 0005, Mohammad Mehedi Hassan
IEEE Internet Things J.3
2025 Big Data Analytics-Envisioned Authenticated Key Management Scheme in IoT-Based Smart Farming System for Sustainable Development of Smart Cities
abstract
Smart farming enhances sustainable communication practices through the deployment of energy-efficient Internet of Things (IoT) devices, low-power wireless technologies, and edge/fog computing to reduce data transmission and energy usage. Smart cities represent a concept in which technology, data, and innovation enhance urban efficiency, sustainability, and livability. Smart farming has the potential to facilitate the sustainable development of smart cities. However, integrating smart farming into smart city systems presents significant challenges, particularly with respect to the security of their interconnected components. The vulnerability of agricultural information and the likelihood of cybersecurity threats necessitate the development of targeted security solutions for smart farming. To address these challenges, we propose a Big Data Analytics-envisioned secure smart farming scheme for sustainable cities (in short, CSSF-SC). It is an efficient authenticated key agreement mechanism that enables secure mutual authentication, session-key establishment, and dynamic key management among smart farming devices, drones, and cloud servers. Using the Scyther verification tool, security is formally verified under the Dolev–Yao and CK adversary models, demonstrating resilience to various potential attacks. A comparative performance analysis shows that CSSF-SC outperforms current schemes in terms of computation and communication costs while offering stronger security and additional functionalities. Finally, a practical implementation is done using the MangoLeafBD dataset and an EfficientNet-B7 architecture. It achieves 99.16% accuracy, validating the framework’s effectiveness for secure crop-data collection and analysis in real-world scenarios.
Akshita Patwal, Mohammad Wazid, Ashok Kumar Das, Devesh Pratap Singh, Shantanu Pal, Youngho Park 0005
IEEE Internet Things J.2
2025 Rhetorical Structure Theory-based machine intelligence-driven deceptive phishing attack detection scheme
Chanchal Patra, Debasis Giri, Bibekananda Kundu, Tanmoy Maitra, Mohammad Wazid
J. Inf. Secur. Appl.5
2025 An authenticated key agreement method for secure big data analytics in next-generation wireless networks-enabled smart farming
Akshita Patwal, Mohammad Wazid, Devesh Pratap Singh, Ashok Kumar Das
J. Syst. Archit.2
2025 Designing secure blockchain-based authentication and key management mechanism for Internet of Drones applications
Mohammad Wazid, Saksham Mittal, Ashok Kumar Das, SK Hafizul Islam, Mohammed J. F. Alenazi, Athanasios V. Vasilakos
J. Syst. Archit.1
2025 Quantum Secure Energy-Efficient Authentication Protocol for Digital Twins-Enabled Transportation Cyber-Physical Systems
abstract
Digital twins-enabled transportation cyber-physical systems are employed in the transportation sector to enhance environmental quality, mobility, and safety. They are digital representations of transportation networks, enable the simulation of these networks’ behavior under various conditions. They can be employed in various transportation sectors, including forecasting traffic congestion, facilitate the optimization of flow and safety, enhance the efficiency of public transportation, improve the efficiency of freight transportation by offering support in this process, facilitates the consideration of future multimodal infrastructure development requirements, furnish drivers with up-to-date information about weather alerts, road closures, and traffic situations in real time, assess numerous aspects like, impacts of various mobility operators, transport users, and environmental conditions. However, the real-time data synchronization in digital twins-enabled transportation cyber-physical systems is accomplished using an open communication channel. Regrettably, the utilization of virtual-reality synthesizing security threats in the network necessitates the implementation of stringent privacy and security procedures, including authentication, encryption, and signature approaches. This study proposes a quantum-key-distribution (QKD)-based authentication protocol for secure communication of digital twins-enabled transportation cyber-physical systems. The integrated quantum in the system ensures the compactness and verifiability of data. The protocol’s security is examined using the Scyhter tool and is verified to be secure by informal security analysis. The proposed scheme achieves its efficiency over current solutions. Moreover, the latest technology and techniques are used to examine the operational capabilities and security features.
Sunil Prajapat, Pankaj Kumar 0006, Mohammad Wazid, Ashok Kumar Das, M. Shamim Hossain
IEEE Trans. Intell. Transp. Syst.4
2025 Explainable Deep Learning-Enabled Malware Attack Detection for IoT-Enabled Intelligent Transportation Systems
abstract
The Internet of Things (IoT) has the potential to improve the complementary of communication, control, and information processing within the public transportation system. The IoT-enabled Intelligent Transportation System (ITS) ensures that automated transportation is networked and operated collaboratively. The IoT-enabled ITS has revolutionized the transportation industry by enabling the seamless integration of a wide range of devices and systems. It makes the strategic use of networked devices, sensors, and data analytics to improve transportation network efficiency, safety, and environmental friendliness. The usage of the IoT in the ITS has grown in popularity due to its capacity to improve traffic control, reduce congestion, facilitate live monitoring, and optimize transportation operations. The IoT-enabled ITS systems and devices must be protected from cyber-attacks for various reasons, including preserving sensitive data, guaranteeing privacy, preventing unauthorized access, and protecting against the risk of interruptions or manipulations. Malware attacks affect the working and performance of the deployed smart IoT devices. We propose a secure deep learning-enabled malware attack detection for IoT-enabled ITS (in short, SDLMA-IITS). The approach of explainable artificial intelligence (XAI) has been utilized for the effective detection of malware. A deep security analysis of the proposed SDLMA-IITS is presented to prove its security against various potential attacks. The comparative performance analysis of SDLMA-IITS is given with the other similar existing schemes. Finally, a practical implementation of SDLMA-IITS is provided to measure its impact on the security of the IoT-enabled ITS systems and devices.
Mohammad Wazid, Charvi Pandey, Robert Simon Sherratt, Ashok Kumar Das, Debasis Giri, Youngho Park 0005
IEEE Trans. Intell. Transp. Syst.1
2024 EM-PAD: An Effective Mechanism for Phishing Attack Detection
abstract
In the present era, the increasing number of network devices and ubiquitous computing leads to the flow of enormous amounts of data traffic, including sensitive and confidential information, on the internet and carrying out commercial and banking transactions online. This gives cybercriminals an opportunity to launch an attack like phishing to steal confidential information from the user and gain unauthorized access. This can be mitigated by the help of an intelligent machine learning-based phishing detection system, which can detect potential phishing attacks and take appropriate action. In this paper, we have addressed this major cyber issue and proposed a machine learning-based phishing detection scheme (in short, EM-PAD), which is trained on a benchmark dataset and evaluated on standard metrics: F1-score and Accuracy. The proposed model is compared with different existing schemes based on Accuracy, indicating that it has outperformed them with remarkable results.
Aakash, Saksham Mittal, Mohammad Wazid, Ashok Kumar Das, Sachin Shetty, Mohsen Guizani
IWCMC3
2024 AKM-FCCI: Secure Authentication and Key Management Mechanism for Fog Computing-Based IoT-Driven Critical Infrastructure
abstract
Critical infrastructure refers to the key systems, assets, and facilities, whether they are physical or virtual, that are necessary for the overall functioning of a country. As our reliance on technology and networked systems continues to expand, so does the significance of taking precautions to protect critical infrastructure from being compromised by cyberattacks. We need some security schemes to secure the communication happening in the critical infrastructure devices. Therefore, in this paper, we focus on the design of an authentication and key establishment scheme, which is used in the critical infrastructure to secure its data transmissions. A secure authentication and key management mechanism for fog computing-based IoT-driven critical infrastructures (in short, AKM-FCCI) is proposed in the paper. We then provide the network model and threat model of the proposed AKM-FCCI to explain its deployment and organization of devices and servers. The threat model further explains the various threats of this communication environment. In addition, the security analysis of AKM-FCCI is presented to demonstrate that it is secure against the many different kinds of attacks that could be launched against it. The comparisons demonstrate that the performance of AKM-FCCI is superior to that of the other currently used schemes. In addition to that, it offers a high level of security and utility. Therefore, the proposed AKM-FCCI is appropriate for use in protecting critical infrastructure equipment against a wide variety of threats.
Vijay Karnatak, Neha Tripathi, Mohammad Wazid, Ashok Kumar Das, Mohsen Guizani, Sachin Shetty
IWCMC4
2024 An Authentication and Key Management Framework for Secure and Intelligent Transportation of Internet of Space Things
abstract
Internet of Space Things (IoST), also known as CubeSats, elaborates the uses and functionalities of traditional Internet of Things (IoT) by not only providing a constantly available satellite back-haul network, but also by providing real-time satellite-captured data. IoST can be applied for various applications, like weather forecasting, navigation, satellite phone, satellite TV, satellite Internet, radio, military, and many more. It requires support of mechanisms of Intelligent Transportation System (ITS). In an IoST communication environment, the communication among various users, satellite access points, ground stations, and smart IoT devices occur through insecure channels, i.e., Internet. Due the transmission of data over an insecure channel, various potential attacks are possible. Due to the existence of various attacks, the important data of IoST may be altered or revealed. To mitigate these issues, an authentication and key management framework for secure and intelligent transportation of IoST has been proposed (in short, SAKM-IoST). Through the proposed SAKM-IoST, a legitimate user can access the data of ground station in a secure way. The security analysis reveals that SAKM-IoST is resilient against a variety of potential threats and attacks. Additionally, SAKM-IoST’s performance is compared with other approaches that are similar in nature. It has been noted that SAKM-IoST offers robust security, in addition to extra functional characteristics. Therefore, SAKM-IoST seems to be more suitable for its deployment in the critical applications of the IoST as compared to other competing approaches.
Mohammad Wazid, Ashok Kumar Das, Sachin Shetty
IEEE Trans. Intell. Transp. Syst.1
2023 Ransomware Attacks Detection Methodology to Protect IoT-Enabled Critical Infrastructures
abstract
Critical infrastructure is a collection of physical and cyber systems, which are essentially required to support the day-to-day operations of our daily life. In the critical infrastructure, the computing systems (i.e., Internet of Things (loT) devices) communicate through the Internet. Therefore, most of the time, critical infrastructures are targeted by hackers by launching some cyber-attack, i.e., ransomware. Hence we require some security mechanisms to protect the data and systems of critical infrastructures. This paper proposes a scheme for the detection, analysis and mitigation of ransomware attacks to protect Internet of Things (loT)-enabled critical infrastructure (in short, RADM-ICI). We also practically demonstrated RADM-ICI and computed essential performance parameters, i.e., accuracy and F1-score under different machine learning models. The conducted security analysis of RADM-ICI proved its excellent security for the ransom ware attacks. During the performance comparison of the proposed RADM-ICI and other similar competing existing schemes, it has been observed that the proposed RADM-ICI achieved better accuracy than the other existing competing schemes.
Mohammad S. Obaidat, Harshit Bhajpai, Pranjal Trivedi, Mohammad Wazid, Devesh Pratap Singh, Joel J. P. C. Rodrigues, Balqies Sadoun
GLOBECOM5
2023 Multiclass Classification Approaches for Intrusion Detection in IoT-Driven Aerial Computing Environment
abstract
Aerial Computing is one of the applications of Internet of Things (IoT) which makes use of autonomous aerial devices, such as drones and unmanned aerial vehicles (UAVs). The ubiquitous nature of IoT and aerial computing is poised to revolutionize our daily lives by enabling seamless real-time information sharing among interconnected objects. However, ensuring the safety and security of such network is crucial in preventing potential threats and attacks. The purpose of this study is to develop a sophisticated intrusion detection system that is effective, efficient, and intelligent using complex machine learning models trained on relevant intrusion detection datasets. In this article, the multiclass classification approaches for intrusion detection in IoT-driven aerial computing environment are presented (in short, MCA-IDAC). In the comparative study, it has been observed that proposed MCA-IDAC performs significantly better than the other existing competing schemes, in terms of important performance parameters.
Saksham Mittal, Mohammad Wazid, Devesh Pratap Singh, Ashok Kumar Das, Sachin Shetty
GLOBECOM3
2023 Securing Fog Computing-based Industry 4.0 Communication Using Authenticated Key Agreement Scheme
abstract
Internet of Things (IoT)-based smart factories offer the manufacturing sectors a great opportunity to embrace the fourth industrial revolution (Industry 4.0). The real-time monitoring of manufacturing operations in an Industry 4.0 needs to be ensured by the deployed technologies, like Artificial Intelligence (AI) and Big Data analytics. The overall purpose is to improve the outcomes of the production process. However, Industry 4.0 becomes vulnerable to different potential attacks as the communication takes place via public environments. In this article, an authentication and key agreement method has been suggested to secure the communication that can occur in a Fog-based Industry 4.0 environment. The security proposal provides secure mutual authentication along with key establishment between various smart industrial devices and fog servers, as well as between fog servers and cloud servers. The security analysis and comparative study reveal that the proposed method can mitigate various potential attacks, and it also offers important security and functionality attributes as compared to those for other competing schemes.
Mohammad Wazid, Devesh Pratap Singh, Ashok Kumar Das, Mohsen Guizani
IWCMC2
2023 Embattle The Security of E-Health System Through A Secure Authentication and Key Agreement Protocol
abstract
There has been exponential growth in the field of Internet of Things (IoT)-enabled e-health domain, where several technologies are interconnected with each in order to provide low-cost and efficient services to users. The smart healthcare devices monitor the physiological conditions of a patient and then send data to connected servers (i.e., health server). The smart healthcare devices, servers and associated software applications come under one umbrella to provide live tracking, monitoring and analysis of the the healthcare data to the concerned users. It is also considered as Internet of Medical Things (IoMT) communication environment. All medical records are considered critical and sensitive in nature and therefore any leakage of medical data could potentially turn out to be a the lethal to patients. With the innovation in technology, there is a constant security threat to all smart healthcare devices, which is a main issue in e-health system. Cyber threat actors are actively trying to break into the system or network to gain unauthorized access and privileges to manipulate the data. Therefore, there is a strong urge for cyber security in this domain to secure all computing devices from any computer attack. Proper authentication, authorization, a secure session key exchanges, etc., are required to create a secure channel among the communicating devices. In this paper, an authentication and key agreement scheme to secure the communication of e-health system (named as ASKA-EH, in short) is proposed. The provided security analysis of ASKA-EH proves its security against various attacks. The comparative performance analysis of proposed ASKA-EH and other existing schemes of ehealth system reveals that ASKA-EH is superior than the existing schemes.
Darshan Singh, Mohammad Wazid, Devesh Pratap Singh, Ashok Kumar Das, Joel J. P. C. Rodrigues
IWCMC2
2023 Robust authenticated key agreement protocol for internet of vehicles-envisioned intelligent transportation system
Siddhant Thapliyal, Mohammad Wazid, Devesh Pratap Singh, Ashok Kumar Das, SK Hafizul Islam
J. Syst. Archit.2
2023 MADP-IIME: malware attack detection protocol in IoT-enabled industrial multimedia environment using machine learning approach
Sumit Pundir, Mohammad S. Obaidat, Mohammad Wazid, Ashok Kumar Das, Devesh Pratap Singh, Joel J. P. C. Rodrigues
Multim. Syst.3
2023 AISCM-FH: AI-Enabled Secure Communication Mechanism in Fog Computing-Based Healthcare
abstract
Fog computing-based Internet of Things (IoT) architecture is useful for various types of delay efficient network communications and services, like digital healthcare. However, there are privacy and security issues with the fog computing-based healthcare systems, which can further increase the risk of leakage of sensitive healthcare data. Therefore, a security mechanism, such as access control for fog computing-based healthcare systems, is needed to protect its data against various potential attacks. Moreover, the blockchain technology can be used to solve the digital healthcare’s data integrity related problems. The use of Artificial Intelligence (AI) further makes the system more effective in case of prediction of health related diseases. In this paper, an AI-enabled secure communication mechanism in fog computing-based healthcare system (in short, AISCM-FH) has been proposed. The security analysis of the proposed AISCM-FH is provided using the standard random oracle model and also with the heuristic (non-mathematical) security analysis. A pragmatic study determines the impact of the proposed AISCM-FH on key performance indicators. Moreover, we include a detailed performance comparison of AISCM-FH with other relevant existing schemes to show that it has low communication and computation costs, and provides superior security and extra functionality attributes as compared to those for other competing existing approaches.
Mohammad Wazid, Ashok Kumar Das, Sachin Shetty, Joel J. P. C. Rodrigues, Mohsen Guizani
IEEE Trans. Inf. Forensics Secur.1
2023 BACKM-EHA: A Novel Blockchain-enabled Security Solution for IoMT-based E-healthcare Applications
abstract
E-health is the use of information and communication technology (ICT) for the healthcare-related services. It uses various types of digital technologies and telecommunications, such as computers, sensing devices, Internet, and mobile devices to deliver medical services. Internet of Medical Things (IoMT) is a communication environment optimized for low-power devices (for example, health sensors and actuators) and operation on, in, or around the human body (i.e., a patient). It can be used in various applications that are related to healthcare, such as “body automation,” “healthcare,” “medical monitoring,” “body interaction,” and “medical implants (i.e., pacemaker).” Most of the communications happen in IoMT-based e-healthcare system are wireless in nature. This may cause severe threats to the security of the system. Various information security-related attacks, i.e., replay, man-in-the-middle attack (MiTM), impersonation, privileged insider, unauthorised session key computation, credentials leakage, stolen verifier, malware injection are possible in IoMT-based e-healthcare system. These threats and attacks can create serious problems in the social life of an individual, as this may reveal their confidential healthcare information to other unauthorised parties. Therefore, it is essential to propose an access control and key management scheme to secure the communication of a IoMT-based e-healthcare system. Moreover, the security of such kind of scheme can also be enhanced through the deployment of a blockchain mechanism. Therefore, in this article, we propose a blockchain-enabled access control and key management protocol for IoMT-based e-healthcare system that is named as “BACKM-EHA” in short. The security analysis of proposed BACKM-EHA is also provided through the standard, i.e., “Real-Or-Random model.” The various conducted security analyses prove the security of BACKM-EHA against the different types of potential attacks. The performance of BACKM-EHA is better than the other existing schemes, as it requires less communication cost, computation cost, and provides more “security and functionality features.”
Mohammad Wazid, Prosanta Gope
ACM Trans. Internet Techn.1
2022 Machine learning security attacks and defense approaches for emerging cyber physical applications: A comprehensive survey
Mohammad Wazid, Ashok Kumar Das, Vinay Chamola, Mohsen Guizani
Comput. Commun.2
2022 Fortifying Smart Transportation Security Through Public Blockchain
abstract
Smart vehicles-enabled intelligent transportation system (ITS) supports a wide range of applications, such as, but not limited to, traffic planning and management, collision avoidance alert system, automated road speed enforcement, electronic toll collection, and real-time parking management, to name a few. However, it suffers from various types of security and privacy issues due to insecure communication among the entities over public channels. Therefore, an efficient and lightweight security mechanism is essential to protect the data that is both at rest as well as in transit. To this direction, we propose a public blockchain-envisioned secure communication framework for ITS (PBSCF-ITS). The proposed PBSCF-ITS guarantees access control and key management among the vehicle to vehicle, vehicle to roadside unit, and roadside unit to cloud server. We analyze the security of PBSCF-ITS to prove its resilience against various types of possible attacks. Furthermore, the performance of PBSCF-ITS with other related competing schemes has been compared. The obtained results illustrate that PBSCF-ITS outperforms the existing ones. Additionally, the pragmatic study of PBSCF-ITS is conducted to check its influence on various network-related performance parameters, like the number of mined blocks and transactions per block.
Mohammad Wazid, Basudeb Bera, Ashok Kumar Das, Saraju P. Mohanty, Minho Jo 0001
IEEE Internet Things J.1
2022 SCS-WoT: Secure Communication Scheme for Web of Things Deployment
abstract
Web of Things (WoT) extends the Internet of Things (IoT) paradigm to facilitate communications among smart things/devices and Web-based applications. In other words, WoT systems generally provide a Web interface for the monitoring and controlling of smart devices over the Web, for example, in applications, such as home automation, intelligent transportation system, smart healthcare, smart cities, and smart agriculture. However, this results in the generation of significant volume of data (i.e., big data) and, hence, the importance of big data analytics. There are also associated security and privacy implications. Therefore, in this article, we present a signature-based authentication and key agreement scheme for the WoT environment and prove its security. We also evaluate the performance of SCS-WoT and compare it against four other competing schemes. The findings show that SCS-WoT achieves better performance in terms of communication cost, computational cost, and security and functionality.
Mohammad Wazid, Ashok Kumar Das, Kim-Kwang Raymond Choo, Youngho Park 0005
IEEE Internet Things J.1
2022 TACAS-IoT: Trust Aggregation Certificate-Based Authentication Scheme for Edge-Enabled IoT Systems
abstract
The Internet of Things (IoT) is a network of interconnected, Internet-connected items (i.e., smart devices) that can collect and transmit data across a wireless network without the need for human intervention. IoT enables the systems to have higher efficiency and dependability in their day-to-day operations due to its strong focus on machine-to-machine (M2M) connectivity, big data, and machine learning. While IoT has many advantages over traditional techniques, it also has a number of security and privacy concerns. Trust is a belief in the competence of a device (computing machine) to act dependably, securely and reliably in some specific context. In an M2M (one IoT device to other IoT device) communication, trust is accomplished by making the use of cryptographic operations (i.e., digital signatures and electronic certificates). Various security threats and attacks have been launched on IoT connectivity in recent years. A trust mechanism is necessary to ensure the quality of collaborative service behaviors and to build confidence between IoT devices. As a result, how to create an effective trust computing mechanism has become an emerging topic in IoT. Therefore, we provide the design of a novel trust-aggregation-based authentication scheme for secure communication of edge-enabled IoT (in short, TACAS-IoT). The security analysis shows that TACAS-IoT is secured against a variety of attacks. Moreover, TACAS-IoT delivers greater security and capabilities with less communication and computation overheads, according to the performance comparison. Finally, a practical implementation of TACAS-IoT is provided in order to assess its impact on the key performance parameters.
Mohammad Wazid, Ashok Kumar Das, Sachin Shetty
IEEE Internet Things J.1
2022 BUAKA-CS: Blockchain-enabled user authentication and key agreement scheme for crowdsourcing system
Mohammad Wazid, Ashok Kumar Das, Rasheed Hussain, Neeraj Kumar 0001, Sandip Roy 0001
J. Syst. Archit.1
2021 SPCS-IoTEH: Secure Privacy-Preserving Communication Scheme for IoT-Enabled e-Health Applications
abstract
In an Internet of Things (IoT) enabled e-health system, smart health devices sense the health data continuously and share the collected data with the neighboring controller device (i.e., personal server) via some wireless communication mechanism (i.e., bluetooth and zigbee), and finally the data is stored on some health server (i.e., a server over the cloud). The health data is then accessible to healthcare service providers (for example, doctors, nursing staff, relatives of patient) for tracking and monitoring of health conditions of the patients for their better treatment at the earliest. In an IoT enabled health system, the smart healthcare devices communicate over public channel, which causes various types of threats and attacks on the ongoing communication. Therefore, we need a powerful privacy-preserving security mechanism to secure the communication happens in an IoT enabled e-health system as the health data is strictly private and confidential. In this paper, we propose a new privacy-preserving access control and key management scheme for the secure communication of IoT enabled e-health system (SPCS-IoTEH). We also conduct informal security analysis of the proposed SPCS-IoTEH to show its robustness against various types of active and passive attacks. The performance of SPCS-IoTEH is also shown to be better than other existing competing schemes.
Neha Garg, Mohammad S. Obaidat, Mohammad Wazid, Ashok Kumar Das, Devesh Pratap Singh
ICC3
2021 Designing Secure User Authentication Protocol for Big Data Collection in IoT-Based Intelligent Transportation System
abstract
Secure access of the real-time data from the Internet-of-Things (IoT) smart devices (e.g., vehicles) by a legitimate external party (user) is an important security service for big data collection in the IoT-based intelligent transportation system (ITS). To deal with this important issue, we design a new three-factor user authentication scheme, called UAP-BCIoT, which relies on elliptic-curve cryptography (ECC). The mutual authentication between the user and an IoT device happens via the semitrusted cloud-gateway (CG) node in UAP-BCIoT. UAP-BCIoT supports several functionality features needed for IoT-based ITS environment including IoT smart device credential validation and big data analytics. A detailed security analysis is conducted based on the defined threat model to show that UAP-BCIoT is resilient against many known attacks. A thorough comparative study reveals that UAP-BCIoT supports better security, offers various functionality attributes, and also provides similar costs in communication as well computation as compared to other relevant schemes Finally, the practical demonstration of the proposed UAP-BCIoT is also provided to measure its impact on the network performance parameters.
Jangirala Srinivas, Ashok Kumar Das, Mohammad Wazid, Athanasios V. Vasilakos
IEEE Internet Things J.3
2021 A blockchain based secure communication framework for community interaction
Mohammad Wazid, Prosanta Gope
J. Inf. Secur. Appl.2
2021 Designing Authenticated Key Management Scheme in 6G-Enabled Network in a Box Deployed for Industrial Applications
abstract
6G-enabled network in a box (NIB) is a multigenerational, rapidly deployable hardware, and software technology for the communication. 6G-enabled NIB provides high level of flexibility which makes it capable to provide connectivity services for different types of applications as it is effective for the communications of after disaster scenario, battlefields scenario, and industrial scenario. In 6G-enabled NIB deployed industrial applications, various passive and active attacks are possible because the involved entities communicate over insecure channel. In this article, a new remote user authentication and key management scheme is proposed for securing 6G-enabled NIB deployed for industrial applications, which we call in short as UAKMS-NIB. The security analysis shows the resilience of UAKMS-NIB against various types of possible attacks. The practical demonstration of UAKMS-NIB is also provided to measure its impact on the network performance parameters. Finally, a comparative analysis with other closely related existing schemes shows that UAKMS-NIB performs better than the existing schemes.
Mohammad Wazid, Ashok Kumar Das, Neeraj Kumar 0001, Mamoun Alazab
IEEE Trans. Ind. Informatics1
2020 SAC-FIIoT: Secure Access Control Scheme for Fog-Based Industrial Internet of Things
abstract
Industrial Internet of Things (IIoT) is a communication environment that consists of various interconnected sensing devices, instruments, and other devices connected together with industrial software tools and applications. The important applications of IIoT include industrial automation, predictive maintenance, smart logistics management, power management, smart package management and smart robotics. However, IIoT may be vulnerable to different types of attacks as the IoT smart devices communicate among each other via insecure communication means. Thus, there is an essential requirement of deployment of secure access control scheme in IIoT environment, which is one of the important security services for securing IIoT. In this paper, we propose a novel access control scheme for fog based IIoT communication, called SAC-FIIoT. We provide the details of network model as well as threat model, which are required to design SAC-FIIoT. The security analysis of SAC-FIIoT shows its resilience against various types of possible attacks. SAC-FIIoT is also compared with other related competing existing schemes and it was found that its performance is better than these competing schemes. Therefore, SAC-FIIoT is suitable for access control in a fog-based IIoT environment.
Mohammad Wazid, Mohammad S. Obaidat, Ashok Kumar Das, Pandi Vijayakumar
GLOBECOM1
2020 LAM-CIoT: Lightweight authentication mechanism in cloud-based IoT environment
Mohammad Wazid, Ashok Kumar Das, Vivekananda Bhat K., Athanasios V. Vasilakos
J. Netw. Comput. Appl.1
2020 Anonymous Lightweight Chaotic Map-Based Authenticated Key Agreement Protocol for Industrial Internet of Things
abstract
With an exponential increase in the popularity of Internet, the real-time data collected by various smart sensing devices can be analyzed remotely by a remote user (e.g., a manager) in the Industrial Internet of Things (IIoT). However, in the IIoT environment, the gathered real-time data is transmitted over the public channel, which raises the issues of security and privacy in this environment. Therefore, to protect illegal access by an adversary, user authentication mechanism is one of the promising security solutions in the IIoT environment. To achieve this goal, we propose a new user authenticated key agreement scheme in which only authorized users can access the services from the designated IoT sensing devices installed in the IIoT environment. In the proposed scheme, fuzzy extractor technique is used for biometric verification. Moreover, three factors, namely smart card, password and personal biometrics of a legal registered user are applied in the proposed scheme to increase the level of security in the system. The proposed scheme supports new devices addition after initial deployment of the devices, password/biometric change phase and also smart card revocation phase in case the smart card is lost or stolen by an adversary. In addition, the proposed scheme is lightweight in nature. We carry out the formal security analysis using the broadly accepted Real-Or-Random (ROR) model and also the non-mathematical (informal) security analysis on the proposed scheme. Furthermore, the formal security verification using the popularly-used AVISPA (Automated Validation of Internet Security Protocols and Applications) tool is carried out on the proposed scheme. The detailed security analysis assures that the proposed scheme can withstand several well-known attacks in the IIoT environment. A practical demonstration using the NS2 simulation study is also performed for the proposed scheme and other related existing schemes. Also, a detailed comparative study shows that the proposed scheme is efficient, and provides superior security in comparison to the other schemes.
Jangirala Srinivas, Ashok Kumar Das, Mohammad Wazid, Neeraj Kumar 0001
IEEE Trans. Dependable Secur. Comput.3
2020 Secure Remote User Authenticated Key Establishment Protocol for Smart Home Environment
abstract
The Information and Communication Technology (ICT) has been used in wide range of applications, such as smart living, smart health and smart transportation. Among all these applications, smart home is most popular, in which the users/residents can control the operations of the various smart sensor devices from remote sites also. However, the smart devices and users communicate over an insecure communication channel, i.e., the Internet. There may be the possibility of various types of attacks, such as smart device capture attack, user, gateway node and smart device impersonation attacks and privileged-insider attack on a smart home network. An illegal user, in this case, can gain access over data sent by the smart devices. Most of the existing schemes reported in the literature for the remote user authentication in smart home environment are not secure with respect to the above specified attacks. Thus, there is need to design a secure remote user authentication scheme for a smart home network so that only authorized users can gain access to the smart devices. To mitigate the aforementioned isses, in this paper, we propose a new secure remote user authentication scheme for a smart home environment. The proposed scheme is efficient for resource-constrained smart devices with limited resources as it uses only one-way hash functions, bitwise XOR operations and symmetric encryptions/decryptions. The security of the scheme is proved using the rigorous formal security analysis under the widely-accepted Real-Or-Random (ROR) model. Moreover, the rigorous informal security analysis and formal security verification using the broadly-accepted Automated Validation of Internet Security Protocols and Applications (AVISPA) tool is also done. Finally, the practical demonstration of the proposed scheme is also performed using the widely-accepted NS-2 simulation.
Mohammad Wazid, Ashok Kumar Das, Vanga Odelu, Neeraj Kumar 0001, Willy Susilo
IEEE Trans. Dependable Secur. Comput.1
2019 Design of secure key management and user authentication scheme for fog computing services
Mohammad Wazid, Ashok Kumar Das, Neeraj Kumar 0001, Athanasios V. Vasilakos
Future Gener. Comput. Syst.1
2019 AKM-IoV: Authenticated Key Management Protocol in Fog Computing-Based Internet of Vehicles Deployment
abstract
Internet of Vehicles (IoV) is an intelligent application of Internet of Things (IoT) in smart transportation that takes intelligent commitments to the passengers to improve traffic safety and efficiency, and generate a more enjoyable driving and riding environment. Fog cloud-based IoV is another variant of mobile cloud computing where vehicular cloud and Internet can co-operate in more effective way in IoV. However, more increasing dependence on wireless communication, control, and computing technology makes IoV more dangerous to prospective attacks. For secure communication among vehicles, road-side units, fog and cloud servers, we design a secure authenticated key management protocol in fog computing-based IoV deployment, called AKM-IoV. In the designed AKM-IoV, after mutual authentication between communicating entities in IoV they establish session keys for secure communications. AKM-IoV is tested for its security analysis using the formal security analysis under the widely accepted real-or-random (ROR) model, informal, and formal security verification using the broadly accepted automated validation of Internet security protocols and applications (AVISPAs) tool. The practical demonstration of AKM-IoV is shown using the NS2 simulation. In addition, a detailed comparative study is conducted to show the efficiency and functionality and security features supported by AKM-IoV as compared to other existing recent protocols.
Mohammad Wazid, Palak Bagga, Ashok Kumar Das, Sachin Shetty, Joel J. P. C. Rodrigues, Youngho Park 0005
IEEE Internet Things J.1
2019 Design and Analysis of Secure Lightweight Remote User Authentication and Key Agreement Scheme in Internet of Drones Deployment
abstract
The Internet of Drones (IoD) provides a coordinated access to unmanned aerial vehicles that are referred as drones. The on-going miniaturization of sensors, actuators, and processors with ubiquitous wireless connectivity makes drones to be used in a wide range of applications ranging from military to civilian. Since most of the applications involved in the IoD are real-time based, the users are generally interested in accessing real-time information from drones belonging to a particular fly zone. This happens if we allow users to directly access real-time data from flying drones inside IoD environment and not from the server. This is a serious security breach which may deteriorate performance of any implemented solution in this IoD environment. To address this important issue in IoD, we propose a novel lightweight user authentication scheme in which a user in the IoD environment needs to access data directly from a drone provided that the user is authorized to access the data from that drone. The formal security verification using the broadly accepted automated validation of Internet security protocols and applications tool along with informal security analysis show that our scheme is secure against several known attacks. The performance comparison demonstrates that our scheme is efficient with respect to various parameters, and it provides better security as compared to those for the related existing schemes. Finally, the practical demonstration of our scheme is done using the widely accepted NS2 simulation.
Mohammad Wazid, Ashok Kumar Das, Neeraj Kumar 0001, Athanasios V. Vasilakos, Joel J. P. C. Rodrigues
IEEE Internet Things J.1
2019 Authentication in cloud-driven IoT-based big data environment: Survey and outlook
Mohammad Wazid, Ashok Kumar Das, Rasheed Hussain, Giancarlo Succi, Joel J. P. C. Rodrigues
J. Syst. Archit.1
2019 User authentication in a tactile internet based remote surgery environment: Security issues, challenges, and future research directions
Mohammad Wazid, Ashok Kumar Das, Jong-Hyouk Lee
Pervasive Mob. Comput.1
2018 Biometrics-Based Privacy-Preserving User Authentication Scheme for Cloud-Based Industrial Internet of Things Deployment
abstract
Due to the widespread popularity of Internet-enabled devices, Industrial Internet of Things (IIoT) becomes popular in recent years. However, as the smart devices share the information with each other using an open channel, i.e., Internet, so security and privacy of the shared information remains a paramount concern. There exist some solutions in the literature for preserving security and privacy in IIoT environment. However, due to their heavy computation and communication overheads, these solutions may not be applicable to wide category of applications in IIoT environment. Hence, in this paper, we propose a new biometric-based privacy preserving user authentication (BP2UA) scheme for cloud-based IIoT deployment. BP2UA consists of strong authentication between users and smart devices using preestablished key agreement between smart devices and the gateway node. The formal security analysis of BP2UA using the well-known real-or-random model is provided to prove its session key security. Moreover, an informal security analysis of BP2UA is also given to show its robustness against various types of known attacks. The computation and communication costs of BP2UA in comparison to the other existing schemes of its category demonstrate its effectiveness in the IIoT environment. Finally, the practical demonstration of BP2UA is also done using the NS2 simulation.
Ashok Kumar Das, Mohammad Wazid, Neeraj Kumar 0001, Athanasios V. Vasilakos, Joel J. P. C. Rodrigues
IEEE Internet Things J.2
2018 Design of Secure User Authenticated Key Management Protocol for Generic IoT Networks
abstract
In recent years, the research in generic Internet of Things (IoT) attracts a lot of practical applications including smart home, smart city, smart grid, industrial Internet, connected healthcare, smart retail, smart supply chain and smart farming. The hierarchical IoT network (HIoTN) is a special kind of the generic IoT network, which is composed of the different nodes, such as the gateway node, cluster head nodes, and sensing nodes organized in a hierarchy. In HIoTN, there is a need, where a user can directly access the real-time data from the sensing nodes for a particular application in generic IoT networking environment. This paper emphasizes on the design of a new secure lightweight three-factor remote user authentication scheme for HIoTNs, called the user authenticated key management protocol (UAKMP). The three factors used in UAKMP are the user smart card, password, and personal biometrics. The security of the scheme is thoroughly analyzed under the formal security in the widely accepted real-or-random model, the informal security as well as the formal security verification using the widely accepted automated validation of Internet security protocols and applications tool. UAKMP offers several functionality features including offline sensing node registration, freely password and biometric update facility, user anonymity, and sensing node anonymity compared to other related existing schemes. In addition, UAKMP is also comparable in computation and communication costs as compared to other existing schemes.
Mohammad Wazid, Ashok Kumar Das, Vanga Odelu, Neeraj Kumar 0001, Mauro Conti, Minho Jo 0001
IEEE Internet Things J.1
2018 Authenticated key management protocol for cloud-assisted body area sensor networks
Mohammad Wazid, Ashok Kumar Das, Athanasios V. Vasilakos
J. Netw. Comput. Appl.1
2018 Design of Secure and Lightweight Authentication Protocol for Wearable Devices Environment
abstract
Wearable devices are used in various applications to collect information including step information, sleeping cycles, workout statistics, and health-related information. Due to the nature and richness of the data collected by such devices, it is important to ensure the security of the collected data. This paper presents a new lightweight authentication scheme suitable for wearable device deployment. The scheme allows a user to mutually authenticate his/her wearable device(s) and the mobile terminal (e.g., Android and iOS device) and establish a session key among these devices (worn and carried by the same user) for secure communication between the wearable device and the mobile terminal. The security of the proposed scheme is then demonstrated through the broadly accepted real-or-random model, as well as using the popular formal security verification tool, known as the Automated validation of Internet security protocols and applications. Finally, we present a comparative summary of the proposed scheme in terms of the overheads such as computation and communication costs, security and functionality features of the proposed scheme and related schemes, and also the evaluation findings from the NS2 simulation.
Ashok Kumar Das, Mohammad Wazid, Neeraj Kumar 0001, Muhammad Khurram Khan, Kim-Kwang Raymond Choo, Youngho Park 0005
IEEE J. Biomed. Health Informatics2
2018 A Novel Authentication and Key Agreement Scheme for Implantable Medical Devices Deployment
abstract
Implantable medical devices (IMDs) are man-made devices, which can be implanted in the human body to improve the functioning of various organs. The IMDs monitor and treat physiological condition of the human being (for example, monitoring of blood glucose level by insulin pump). The advancement of information and communication technology enhances the communication capabilities of IMDs. In healthcare applications, after mutual authentication, a user (for example, doctor) can access the health data from the IMDs implanted in a patient's body. However, in this kind of communication environment, there are always security and privacy issues, such as leakage of health data and malfunctioning of IMDs by an unauthorized access. To mitigate these issues, in this paper, we propose a new secure remote user authentication scheme for IMDs communication environment to overcome security and privacy issues in existing schemes. We provide the formal security verification using the widely accepted Automated Validation of Internet Security Protocols and Applications tool. We also provide the informal security analysis of the proposed scheme. The formal security verification and informal security analysis prove that the proposed scheme is secure against known attacks. The practical demonstration of the proposed scheme is performed using the broadly accepted NS2 simulation tool. The computation and communication costs of the proposed scheme are also comparable with the existing schemes. Moreover, the scheme provides additional functionality features, such as anonymity, untraceability, and dynamic implantable medical device addition.
Mohammad Wazid, Ashok Kumar Das, Neeraj Kumar 0001, Mauro Conti, Athanasios V. Vasilakos
IEEE J. Biomed. Health Informatics1
2017 On the design of a secure user authentication and key agreement scheme for wireless sensor networks
abstract
Summary A wireless sensor network (WSN) typically consists of a large number of resource‐constrained sensor nodes and several control or gateway nodes. Ensuring the security of the asymmetric nature of WSN is challenging, and designing secure and efficient user authentication and key agreement schemes for WSNs is an active research area. For example, in 2016, Farash et al. proposed a user authentication and key agreement scheme for WSNs. However, we reveal previously unpublished vulnerabilities in their scheme, which allow an attacker to carry out sensor node spoofing, password guessing, user/sensor node anonymity, and user impersonation attacks. We then present a scheme, which does not suffer from the identified vulnerabilities. To demonstrate the practicality of the scheme, we evaluate the scheme using NS‐2 simulator. We then prove the scheme secure using Burrows–Abadi–Needham logic. Copyright © 2016 John Wiley & Sons, Ltd.
Saru Kumari, Ashok Kumar Das, Mohammad Wazid, Xiong Li 0002, Fan Wu 0003, Kim-Kwang Raymond Choo, Muhammad Khurram Khan
Concurr. Comput. Pract. Exp.3
2017 Provably secure authenticated key agreement scheme for distributed mobile cloud computing services
Vanga Odelu, Ashok Kumar Das, Saru Kumari, Xinyi Huang 0001, Mohammad Wazid
Future Gener. Comput. Syst.5
2017 Secure Authentication Scheme for Medicine Anti-Counterfeiting System in IoT Environment
abstract
A counterfeit drug is a medication or pharmaceutical product which is manufactured and made available on the market to deceptively represent its origin, authenticity and effectiveness, etc., and causes serious threats to the health of a patient. Counterfeited medicines have an adverse effect on the public health and cause revenue loss to the legitimate manufacturing organizations. In this paper, we propose a new authentication scheme for medicine anticounterfeiting system in the Internet of Things environment which is used for checking the authenticity of pharmaceutical products (dosage forms). The proposed scheme utilizes the near field communication (NFC) and is suitable for mobile environment, which also provides efficient NFC update phase. The security analysis using the widely accepted real-or-random model proves that the proposed scheme provides the session key security. The proposed scheme also protects other known attacks which are analyzed informally. Furthermore, the formal security verification using the broadly accepted automated validation of Internet security protocols and applications tool shows that the proposed scheme is secure. The scheme is efficient with respect to computation and communication costs, and also it provides additional functionality features when compared to other existing schemes. Finally, for demonstration of the practicality of the scheme, we evaluate it using the broadly accepted NS2 simulation.
Mohammad Wazid, Ashok Kumar Das, Muhammad Khurram Khan, Abdulatif Al-Dhawailie Al-Ghaiheb, Neeraj Kumar 0001, Athanasios V. Vasilakos
IEEE Internet Things J.1
2017 An efficient authentication and key agreement scheme for multi-gateway wireless sensor networks in IoT deployment
Fan Wu 0003, Saru Kumari, Xiong Li 0002, Jian Shen 0001, Kim-Kwang Raymond Choo, Mohammad Wazid, Ashok Kumar Das
J. Netw. Comput. Appl.7
2017 Secure Three-Factor User Authentication Scheme for Renewable-Energy-Based Smart Grid Environment
abstract
Smart grid (SG) technology has recently received significant attention due to its usage in maintaining demand response management in power transmission systems. In SG, charging of electric vehicles becomes one of the emerging applications. However, authentication between a vehicle user and a smart meter is required so that both of them can securely communicate for managing demand response during peak hours. To address the above mentioned issues, in this paper, we propose a new efficient three-factor user authentication scheme for a renewable energy-based smart grid environment (TUAS-RESG), which uses the lightweight cryptographic computations such as one-way hash functions, bitwise XOR operations, and elliptic curve cryptography. The detailed security analysis shows the robustness of TUAS-RESG against various well-known attacks. Moreover, TUAS-RESG provides superior security with additional features, such as dynamic smart meter addition, flexibility for password and biometric update, user and smart meter anonymity, and untraceability as compared to other related existing schemes. The practical demonstration of TUAS-RESG is also proved using the widely accepted NS2 simulation.
Mohammad Wazid, Ashok Kumar Das, Neeraj Kumar 0001, Joel J. P. C. Rodrigues
IEEE Trans. Ind. Informatics1
2016 An efficient multi-gateway-based three-factor user authentication and key agreement scheme in hierarchical wireless sensor networks
abstract
Abstract User authentication in wireless sensor network (WSN) plays a very important role in which a legal registered user is allowed to access the real‐time sensing information from the sensor nodes inside WSN. To allow such access, a user needs to be authenticated by the accessed sensor nodes as well as gateway nodes inside WSNs. Because of resource limitations and vulnerability to physical capture of some sensor nodes by an attacker, design of a secure user authentication in WSN continues to be an important and challenging research area in recent years. In this paper, we propose a new three‐factor user authentication scheme based on the multi‐gateway WSN architecture. Through the widely‐accepted Burrows–Abadi–Needham logic, we prove that our scheme provides the secure mutual authentication. We then present the formal security verification of our proposed scheme using AVISPA tool, which is a powerful validation tool for network security applications, and show that our scheme is secure. In addition, the rigorous informal security analysis shows that our scheme is also secure against possible other known attacks including the sensor node capture attack. Furthermore, we present the additional functionality features that our scheme offers, which are efficient in communication and computation. Copyright © 2016 John Wiley & Sons, Ltd.
Ashok Kumar Das, Anil Kumar Sutrala, Saru Kumari, Vanga Odelu, Mohammad Wazid, Xiong Li 0002
Secur. Commun. Networks5
2016 Design of sinkhole node detection mechanism for hierarchical wireless sensor networks
abstract
Abstract Wireless sensor networks (WSNs) have several applications ranging from the civilian to military applications. WSNs are prone to various hole attacks, such as sinkhole, wormhole, blackhole, and greyhole. Among these hole attacks, the sinkhole attack is the malignant one. A sinkhole attack allows a malicious node, called the sinkhole node, advertises a best possible path to the base station (BS). This misguides its neighbors to utilize that path more frequently. The sinkhole node has the opportunity to tamper with the data, and it also performs the modifications in messages or it drops messages or it produces unnecessary delay before forwarding them to the BS. On the basis of these malicious acts that are performed by a sinkhole attacker node, we consider three types of malicious nodes in a WSN: sinkhole message modification node (SMD), sinkhole message dropping node (SDP), and sinkhole message delay node (SDL). None of the existing techniques in the literature is capable to handle all three types of nodes at a time. This paper presents a new detection scheme for the detection of different types of sinkhole nodes for a hierarchical wireless sensor network (HWSN). To the best of our knowledge, this is the first attempt to design such a detection scheme in HWSNs which can detect SMD, SDP, and SDL nodes. In our approach, the entire HWSN is divided into several disjoint clusters, and each cluster has a powerful high‐end sensor node (called a cluster head), which is responsible for the detection of different sinkhole attacker nodes if present in that cluster. We simulate our scheme using the widely‐accepted NS2 simulator for measurement of various network parameters. The proposed scheme achieves around 95%detection rate and 1.25%false positive rate. These factors are significantly better than the previous related schemes. Furthermore, the computation and communication efficiency is achieved in our scheme. As a result, our scheme seems suitable for the sensitive critical applications, such as military applications. Copyright © 2016 John Wiley & Sons, Ltd.
Mohammad Wazid, Ashok Kumar Das, Saru Kumari, Muhammad Khurram Khan
Secur. Commun. Networks1
2016 Design of an efficient and provably secure anonymity preserving three-factor user authentication and key agreement scheme for TMIS
abstract
Abstract Several remote user authentication techniques for telecare medicine information system (TMIS) have been proposed in the literature. But most existing techniques have limitations such as vulnerable to various attacks, lack of functionalities, and inefficiency. Recently, Amin and Biswas proposed a three‐factor authentication and key agreement technique for TMIS. But their scheme is inefficient and has several security drawbacks. The attacks such as privileged‐insider, user impersonation, and strong reply attacks are possible on their scheme. It also has flaw in password update phase. In order to overcome drawbacks of their scheme, a new provably secure and efficient three‐factor remote user authentication scheme for TMIS is proposed in this paper. The proposed scheme overcomes all drawbacks of their scheme and also provides additional features such as user unlinkability, user anonymity, efficient password, and biometric update. The rigorous informal and formal security analysis using random oracle models and the mostly acceptable Automated Validation of Internet Security Protocols and Applications tool is also performed. During the experimentation, it has been observed that the proposed scheme is secure against various known attacks that include replay and man‐in‐the‐middle attacks. Furthermore, the analysis of computation and communication cost estimation of the proposed scheme depicts that our scheme is efficient as compared with other related exiting schemes. Copyright © 2016 John Wiley & Sons, Ltd.
Mohammad Wazid, Ashok Kumar Das, Saru Kumari, Xiong Li 0002, Fan Wu 0003
Secur. Commun. Networks1
2016 Provably secure biometric-based user authentication and key agreement scheme in cloud computing
abstract
Abstract Cloud computing, the conjoin of many types of computing, has made a great impact on the life of everyone. People from anywhere can access the different cloud‐based services by using the Internet. A user, who wants to access some cloud‐based service, needs to register himself/herself to an authority (service provider), and after that, he/she can use the service. To access the service, each user needs to authenticate to that particular cloud server. Several user authentication schemes for cloud computing have been presented but mostly have limitations/drawbacks as they are prone to various known attacks, such as privileged insider, user and server impersonation, and strong reply attacks, and they also have lack of functionality features. Moreover, these schemes do not provide efficient password change phase. In order to overcome these drawbacks, we propose a new provably secure biometric‐based user authentication and key agreement scheme for cloud computing. The proposed scheme overcomes the weaknesses of the existing schemes and supports extra functionality features including user anonymity and efficient password and biometric update phase for multi‐server environment. The careful formal security analysis under standard model and informal security analysis and the simulation results for formal security verification using the most acceptable AVISPA tool show that the proposed scheme is secure against various known possible attacks. The analysis of computation and communication overheads of our scheme depicts its efficiency over other related existing schemes, and thus, the proposed scheme is suitable for the cloud computing environment. Copyright © 2016 John Wiley & Sons, Ltd.
Mohammad Wazid, Ashok Kumar Das, Saru Kumari, Xiong Li 0002, Fan Wu 0003
Secur. Commun. Networks1