Masoud Barati

dblp:123/6730 · DBLP profile ↗
← Back
19ranked-venue papers
10as first author
14since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Applied, interdisciplinary, general and emerging computing · 5 · 3 first-author · 3 since 2021Systems, architecture and hardware · 4 · 2 first-author · 3 since 2021Security and privacy · 4 · 2 first-author · 3 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Computer networks · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 Trusted Execution for Secure and Privacy-Preserving Data Handling in Internet of Medical Things
abstract
With the prosperity of the Internet of Medical Things (IoMT), ensuring privacy regulation-compliant, patient-trusted data management without reliance on IoMT providers is critical. While legislation mandates providers to be accountable, the trustworthiness of IoMT providers is undermined by their conflicting roles of data processor and data processing activity logger. A curious or malicious provider can easily copy and abuse data undetected, with both roles. Moreover, the IoMT data processing code is a proprietary asset of the provider, making public verification infeasible. This necessitates a trusted data processing paradigm that operates securely even when both the IoMT provider and their code are untrusted. By leveraging trusted execution environments (TEE), we propose a time-series data management system (DMS) with trust shifted from IoMT providers to hardware vendors, enabling low-overhead trusted data processing with a small trusted computing base (TCB). Benchmarks are performed over a minimal prototype, and the results show low latency, low memory footprint, and a small TCB for custom code (excluding dependencies). Security analysis of the architecture confirms end-to-end confidentiality, integrity, and rollback resistance under a strong threat model with untrusted providers. Our approach complies with privacy principles, is scalable via patient-wise microservice partitioning for edge-cloud deployments, and can integrate cross-platform TEE solutions for portability.
Masoud Barati
ACM Trans. Priv. Secur.2
2025 Transparent Consent Tracking in Child-Oriented LLM Applications via Smart Contracts
Masoud Barati, Nafiseh Kahani, Diana Rogachova, Diana Addae, Raymond Xiao
CRiSIS1
2025 Optimizing Service Allocation in Vehicular Cloud Networks: A User-Preference-Based Approach using NSGA-II
abstract
Vehicular Cloud Networks (VCNs) represent a promising paradigm for delivering dynamic, low-latency services by leveraging the resources of connected vehicles. However, the highly mobile and resource-constrained nature of VCNs poses significant challenges for reliable service allocation, particularly when considering user-specific preferences. In this paper, we propose a user-preference-based service allocation mechanism that optimizes three key Service Level Agreement (SLA) parameters: delay, availability, and price. Our approach utilizes the Non-dominated Sorting Genetic Algorithm II (NSGA-II) to generate Pareto-optimal solutions, allowing users to select services that best match their preferences. We evaluate the proposed approach through simulation, comparing its performance against alternative methods in terms of execution time, SLA adherence rate, and service stability. The results demonstrate that our approach not only achieves higher SLA adherence but also maintains efficiency under various vehicular conditions.
Farhoud Jafari Kaleibar, Marc St-Hilaire, Masoud Barati
ISNCC3
2025 Toward Scalable and Secure Blockchain in Internet of Things: A Preference-Driven Committee Member Auction Consensus Approach
abstract
Blockchain technology is acclaimed for eliminating the need for a central authority while ensuring stability, security, and immutability. However, its integration into Internet of Things (IoT) environments is hampered by the limited computational resources of IoT devices. Consensus algorithms, vital for blockchain safety and efficiency, often require substantial computational power and face challenges related to security, scalability, and resource demands. To address these critical issues, we propose a novel model that significantly enhances the security and performance of blockchain in IoT environments. Our model introduces three key innovations: (1) a bidirectional-linked blockchain system that strengthens security against long-range attacks by exploiting dual reference points for block validation; (2) the integration of user preferences into the Committee Member Auction (CMA) consensus algorithm, optimizing miner selection to balance resource efficiency with security; and (3) a comprehensive performance and frequency analysis that demonstrates the system’s resilience against double-spend, long-range, and eclipse attacks. The proposed model not only reduces block validation delays but also enhances overall system performance, as evidenced by simulations comparing its effectiveness with existing CMA algorithms. These advancements have the potential to significantly impact the deployment of blockchain in resource-constrained IoT environments, offering a more secure and efficient solution.
Akshaya Mathur, Masoud Barati, Gagangeet Singh Aujla, Omer F. Rana
Distributed Ledger Technol. Res. Pract.2
2025 A TEE-Guarded Data Management System for Time-Scale Data in Industrial Internet of Things
abstract
With the prosperity of the Industrial Internet of Things (IIoT), concerns have arisen about its energy efficiency and data security. A manufacturer, especially a medium or small one, usually depends partially or fully on third-party providers for IIoT infrastructures (e.g., cloud services, edge devices, IIoT applications), leading to concerns about trusted and confidential data processing. Moreover, the processed IIoT data may include personal information (e.g., employee status), introducing privacy compliance concern as well. Data protection depends on trust, which can be achieved through distributed trust (e.g., blockchains) or centralized trust (e.g., Trusted Third Parties (TTPs)). However, the energy cost for trust is high, as the former requires extra redundancy and the latter introduces workload transfer to the TTP. Fortunately, trusted execution environment (TEE) technologies provide a more efficient solution for trust. A TEE enables efficient, confidential, and protected execution while establishing centralized trust via remote attestation of executables. This paper proposes a TEE-based data management architecture for IIoT, inspired by an extensive and secure personal data management system, but with a reduced trusted computing base (TCB). The proposed architecture is feasible for time-scale data in IIoT, which are only appended over time and never updated, such as machine status monitoring data. A single-threaded SGX-based prototype of the data access component in the architecture is implemented for the time-scale data scenario. Benchmarks and evaluations are provided to demonstrate the prototype performance for time-scale data and the potential TCB reduction of the proposed design. The proposal reveals a more verifiable and feasible integration of TEE-based trusted data processing in an IIoT data management system, with reduced TCB, high efficiency, and security, under a strong threat model.
Masoud Barati
IEEE Internet Things J.2
2025 A Customized Genetic Algorithm for SLA-Aware Service Provisioning in Infrastructure-Less Vehicular Cloud Networks
abstract
Vehicular Ad-hoc Networks (VANETs) and in-vehicle networks offer complementary perspectives on Intelligent Transportation Systems (ITS), enabling communication between vehicles and within individual vehicles, respectively. While VANETs focus on vehicle-to-vehicle communication, the growing demand for dynamic resource sharing and data processing across a fleet of vehicles highlights the need for Vehicular Cloud Networks (VCNs). VCNs, despite their lack of fixed infrastructure and the continuous mobility of vehicles, provide a promising solution for improving resource management and data sharing, making them critical for achieving efficient Service Level Agreements (SLAs) in infrastructure-less environments. This paper addresses these challenges by employing a hierarchical clustering technique and proposing a novel mathematical formulation for resource provisioning in infrastructure-less vehicular clouds. The formulation considers diverse criteria, including provider and requester mobility, data volume, and service delay tolerance, to ensure SLA adherence. A customized genetic algorithm is used to solve the maximization problem, incorporating a grouping mechanism for efficient problem solving. Simulations using the NS2 network simulator and the IBM CPLEX optimization tool validate the feasibility of the proposed approach and demonstrate its superior performance compared to the other methods.
Farhoud Jafari Kaleibar, Marc St-Hilaire, Masoud Barati
IEEE Trans. Serv. Comput.3
2024 Blockchain Based Auditable Access Control for Business Processes With Event Driven Policies
abstract
The use of blockchain technology has been proposed to provide auditable access control for individual resources. Unlike the case where all resources are owned by a single organization, this work focuses on distributed applications such as business processes and distributed workflows. These applications are often composed of multiple resources/services that are subject to the security and access control policies of different organizational domains. Here, blockchains provide an attractive decentralized solution to provide auditability. However, the underlying access control policies may have event-driven constraints and can be overlapping in terms of the component conditions/rules as well as events. Existing work cannot handle event-driven constraints and does not sufficiently account for overlaps leading to significant overhead in terms of cost and computation time for evaluating authorizations over the blockchain. In this work, we propose an automata-theoretic approach for generating a cost-efficient composite access control policy. We reduce this composite policy generation problem to the standard weighted set cover problem. We show that the composite policy correctly captures all the local access control policies and reduces the policy evaluation cost over the blockchain. We have implemented the initial prototype of our approach using Ethereum as the underlying blockchain and empirically validated the effectiveness and efficiency of our approach. Ablation studies were conducted to determine the impact of changes in individual service policies on the overall cost.
Ahmed Akhtar, Masoud Barati, Basit Shafiq, Omer F. Rana, Ayesha Afzal, Jaideep Vaidya, Shafay Shamail
IEEE Trans. Dependable Secur. Comput.2
2024 Data protection in internet of medical things using blockchain and secret sharing method
Shreyshi Shree, Masoud Barati
J. Supercomput.3
2023 Compliance Checking of Cloud Providers: Design and Implementation
abstract
The recognition of capabilities supplied by cloud systems is presently growing. Collecting or sharing healthcare data and sensitive information especially during the Covid-19 pandemic has motivated organizations and enterprises to leverage the upsides coming from cloud-based applications. However, the privacy of electronic data in such applications remains a significant challenge for cloud vendors to adapt their solutions with existing privacy legislation standards such as general data protection regulation (GDPR). This article first proposes a formal model and verification for data usage requests of providers in a cloud composite service using a model checking tool. A cloud pharmacy scenario is presented to illustrate the connectivity of providers in the composite service and the stream of their requests for both collection and movement of patient data. A set of verifications is then undertaken over the pharmacy service in accordance with three significant GDPR obligations, namely user consent, data access, and data transfer. Following that, the article designs and implements a cloud container virtualization based on the verified formal model realizing GDPR requirements. The container makes use of some enforcement smart contracts to only proceed with the providers’ requests that are compliant with GDPR. Finally, several experiments are provided to investigate the performance of our approach in terms of time, memory, and cost.
Masoud Barati, Kwabena Adu-Duodu, Omer F. Rana, Gagangeet Singh Aujla, Rajiv Ranjan 0001
Distributed Ledger Technol. Res. Pract.1
2023 A compliance-based architecture for supporting GDPR accountability in cloud computing
abstract
The implementation of the General Data Protection Regulation (GDPR) in the cloud posed technical challenges for the design of compliance solutions. In particular, the accountability principle in the GDPR requires cloud providers to demonstrate their compliance, which implies that a GDPR compliance solution should maintain tamper-proof evidence for the massive data processing activities in cloud services. Additionally, the transparency of a compliance solution is essential for improving the trust of cloud users. Most of the existing solutions implemented their compliance logic as smart contracts on a blockchain to utilize its immutable transaction history for accountability and to gain user trust through its transparency. However, this widely adopted pattern in the solutions imposed the throughput constraint of blockchains on the implementation of compliance logic. In order to address this, we first conduct a requirement analysis of the GDPR accountability principle. After the analysis, we introduce a domain model of the principle and propose a modularized architecture to support the accountability in the cloud. Then, we present a prototype implementation of the architecture, in which a blockchain-based technique is used to provide immutability and data integrity for event records (e.g., data processing activities of cloud providers), while the compliance logic is not affected by the overhead of blockchains. Finally, we evaluate the prototype using benchmarks and analyses to investigate the throughput, resource consumption, and scalability of the architecture.
Masoud Barati, M. Omair Shafiq
Future Gener. Comput. Syst.2
2022 Privacy-Aware Cloud Auditing for GDPR Compliance Verification in Online Healthcare
abstract
Emerging multitenant cloud computing ecosystems allow multiple applications to share virtualized pool of computing and networking resources. As a result, such ecosystems are becoming increasingly prone to data privacy concerns (personal data leakages and unauthorized access). While cloud computing providers support robust security and privacy mechanisms (e.g., public key cryptography, firewalls, and virtual private networks, among many others), they lack mechanisms and frameworks to monitor, audit, and verify these data privacy concerns. The emergence of data protection regulations around the world, such as General Data Protection Regulation in Europe and the Data Protection Act in the U.K., further emphasizes the need to overcome these privacy limitations. In this article, a novel technique for monitoring, auditing, and verifying the operations carried out on a user’s personal data in cloud computing ecosystems is proposed. Our research methodology leverages distributed ledger technologies (e.g., blockchain and smart contracts) for developing an immutable recording technique, which transparently logs, monitors, and verifies the operations carried out on user data. Using a healthcare pharmacy scenario and extensive real-world experiments, we validate the feasibility of the proposed technique. The proposed work handles a large pool of requests ($>$13K) ensuring minimal latency ($\approx$50–60 ms) and overheads for three different service packages varied with respect to the number of actors and operations.
Masoud Barati, Gagangeet Singh Aujla, Jose Tomas Llanos, Kwabena Adu-Duodu, Omer F. Rana, Madeline Carr, Rajiv Ranjan 0001
IEEE Trans. Ind. Informatics1
2022 Tracking GDPR Compliance in Cloud-Based Service Delivery
abstract
The European General Data Protection Regulation (GDPR) has had a far-reaching impact on data privacy and compliance for cloud providers. GDPR influences access to, storage, processing and transmission of personal data, requiring these operations to be verified by a cloud user through explicit consent prior to execution. GDPR rules implemented for such operations can be ambiguous and often open to interpretation, making manual verification a time consuming and error prone process for cloud providers. An encoding of GDPR rules is described, with each operation carried out using these rules recorded into a Blockchain for auditing purposes. Specifically, this work shows how some GDPR rules can appear asopcodesin smart contracts to verify the operations of providers on user data in a transparent and automatic way. An abstract model is designed to demonstrate how cloud providers can access and deploy such smart contracts through a Blockchain-based virtual machine. A case study is used to demonstrate how this approach can be used in practice. The case study uses a collection of design patterns and smart contracts to verify provider operations, includingread,write,executionandtransferon user data. Validation is undertaken by deploying the smart contracts in a Blockchain test network to investigate the execution costs of GDPR compliance checking.
Masoud Barati, Omer F. Rana
IEEE Trans. Serv. Comput.1
2021 Checking GDPR Compliance for Cloud-based Services
abstract
Accessing a cloud-hosted service may involve executing a number of sub-services which are unknown to the user. A user is only aware of the service they directly invoke, not the sub-services which may be hosted across other cloud providers (including advertising and data processing services). Each service in this chain may collect and process personal user data via read, write and transfer operations. The European General Data Protection Regulation (GDPR) enforces cloud providers to receive explicit consent from their users prior to executing any such operations. We present a Blockchain-based architecture that supports GDPR compliance verification (especially in the context of such a service chain) for enhancing the data privacy of cloud users. The architecture supports a factory of smart contracts, including user consent , GDPR compliance , container and verification , each of which is activated by an actor within a cloud environment. Figure 1 illustrates the interactions between the different components that make up our system – classified into three different phases:
Masoud Barati, Omer F. Rana
SERVICES1
2021 Privacy-aware cloud ecosystems: Architecture and performance
abstract
Summary With an increasing number of cloud providers offering services made use of by both individual users and other providers, there is a realization that service provision now involves an “ecosystem” of providers. Some providers may be directly visible to a user, while others may be contributors to composite services and not directly known to the user—as only the provider offering the composite service is visible. Such services may include: domain specific services (eg, simulation), advertising services, or profiling/analytics services. Understanding the impact on data privacy of a user for such a composite service remains a challenge, and providing transparency (and obtaining user consent for data use) remains a key requirement of the European General Data Protection Regulation (GDPR). An architecture that makes use of blockchains and smart contracts is proposed that addresses this requirement. An implementation of the architecture is used to demonstrate how access control can be managed and audited. The scalability and cost of undertaking access control, as the number of actors (both service providers and “voters”) increases, is also described. The proposed approach can be used to support service aggregation across both private and public clouds.
Masoud Barati, Omer F. Rana
Concurr. Comput. Pract. Exp.1
2020 Automating GDPR Compliance Verification for Cloud-hosted Services
abstract
Cloud-hosted business processes require access to customer data to complete a transaction, to improve a customer's on-line experience or provide useful product recommendations. However, privacy concerns associated with the use of this data have led to legal regulations that impose restrictions on how such data is requested or processed by an on-line service, with large penalties for violating these restrictions, e.g. the European General Data Protection Regulation (GDPR). We propose a framework for helping cloud-hosted services automate GDPR compliance checking. The framework comprises three steps: represent data flow in business processes with an appropriate abstraction (timed transition systems), formalise GDPR rules and obligations and incorporate them into the same abstraction, and implement the abstraction in a model checking tool (Uppaal) in order to automatically verify compliance of business process activities with GDPR. We demonstrate the approach using a cloud-based purchase order system.
Masoud Barati, George Theodorakopoulos 0001, Omer F. Rana
ISNCC1
2020 C-Blondel: An Efficient Louvain-Based Dynamic Community Detection Algorithm
abstract
One of the most interesting topics in the scope of social network analysis is dynamic community detection, keeping track of communities' evolutions in a dynamic network. This article introduces a new Louvain-based dynamic community detection algorithm relied on the derived knowledge of the previous steps of the network evolution. The algorithm builds a compressed graph, where its supernodes represent the detected communities of the previous step and its superedges show the edges among the supernodes. The algorithm not only constructs the compressed graph with low computational complexity but also detects the communities through the integration of the Louvain algorithm into the graph. The efficiency of the proposed algorithms is widely investigated in this article. By doing so, several evaluations have been performed over three standard real-world data sets, namely Enron Email, Cit-HepTh, and Facebook data sets. The obtained results indicate the superiority of the proposed algorithm with respect to the execution time as an efficiency metric. Likewise, the results show the modularity of the proposed algorithm as another effectiveness metric compared with the other well-known related algorithms.
Mahsa Seifikar, Saeed Farzi, Masoud Barati
IEEE Trans. Comput. Soc. Syst.3
2019 Enhancing User Privacy in IoT: Integration of GDPR and Blockchain
Masoud Barati, Omer F. Rana
BlockSys1
2015 Behavior Composition Meets Supervisory Control
abstract
With the evolution of software engineering since the advent of structured programming until now, software engineers are faced with tremendous challenges mostly due to the development of large software programs that behave as open systems. Multi-agent systems, which consist of multiple cooperating intelligent agents within an environment, form a particular class of such systems. This sort of software program, which carries out operations by repeatedly interacting with dynamic environments, has become more and more complex with the emergence of ubiquitous communication and computing technologies that constantly grow and evolve. Agent-oriented computing constitutes an appealing solution for coping with this level of complexity because systems can be built by combining agents. The automated composition of software artifacts to generate new ones may rest on recent progress in artificial intelligence and automatic control that has its roots in the tradition of program synthesis. The goal is to provide software engineers with effective methods in which the planning and control of software actions are integral parts of composition operators, together with synthesis procedures that automatically generate an execution strategy that governs the discrete dynamics of the composed artifact in order to satisfy given requirements. This approach ensures a higher degree of safety because it relies on formal methods. This paper shows how the behavior composition problem issued from the artificial intelligence community can be solved within the framework of the supervisory control theory with the aim to benefit from all of its rich facets.
Masoud Barati
SMC1
2015 A hybrid heuristic-based tuned support vector regression model for cloud load prediction
Masoud Barati, Saeed Sharifian
J. Supercomput.1