Nazatul Haque Sultan

dblp:160/3257 · also Nazatul H. Sultan · DBLP profile ↗
← Back
15ranked-venue papers
12as first author
11since 2021 · last 2026
0000-0003-4076-5553ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 5 first-author · 6 since 2021Systems, architecture and hardware · 3 · 3 first-author · 2 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Setup Once, Secure Always: A Single-Setup Secure Federated Learning Aggregation Protocol with Forward and Backward Secrecy for Dynamic Users
abstract
Federated Learning (FL) enables multiple users to collaboratively train a machine learning model without sharing raw data, making it suitable for privacy-sensitive applications. However, local model or weight updates can still leak sensitive information. Secure aggregation protocols mitigate this risk by ensuring that only the aggregated updates are revealed. Among these, single-setup secure aggregation protocols, where key generation and exchange occur only once, are the most efficient due to reduced communication and computation overhead. However, existing single-setup secure aggregation protocols often lack support for dynamic user participation and do not provide strong privacy guarantees such as forward and backward secrecy.
Nazatul Haque Sultan, Yan Bo, Yansong Gao 0001, Seyit Ahmet Çamtepe, Arash Mahboubi, Hang Thanh Bui, Muhammad Aufeef Chauhan, Hamed Aboutorab, Michael Bewong, Praveen Gauravaram, Dinesh Kumar Singh, Md. Rafiqul Islam 0001, Alsharif Abuadbba
AsiaCCS1
2025 Nosy Layers, Noisy Fixes: Tackling DRAs in Federated Learning Systems using Explainable AI
Meghali Nandi, Arash Shaghaghi, Nazatul Haque Sultan, Gustavo Batista, Raymond K. Zhao, Sanjay K. Jha
AsiaCCS3
2025 Active Attack Resilience in 5G: A New Take on Authentication and Key Agreement
abstract
As 5G networks continue to expand into critical infrastructure, ensuring secure and efficient user authentication has become more important than ever. The 5G-AKA protocol, standardized by 3 GPP in TS 33.501, is the cornerstone of authentication in current 5G deployments. It provides mutual authentication, user privacy, and key secrecy. However, despite its widespread adoption, 5G-AKA suffers from known limitations in both security and performance. While it primarily focuses on protecting privacy against passive attackers, recent studies have highlighted its vulnerabilities to active attacks. Furthermore, it relies on a sequence number-based mechanism to prevent replay attacks, requiring the user device and the core network to remain perfectly synchronized. This stateful design introduces operational complexity, frequent desynchronization issues, and additional communication overhead. More critically, 5G-AKA lacks Perfect Forward Secrecy (PFS), leaving past communications vulnerable if long-term keys are ever compromised- a growing concern in the age of sophisticated adversaries. In this paper, we propose an enhanced authentication protocol that builds on the design principles of 5G-AKA while addressing these fundamental shortcomings. First, we present a stateless version of the protocol that eliminates the reliance on sequence numbers, reducing communication complexity while remaining fully compatible with existing SIM cards and network infrastructure. We then extend this design to include PFS with only minimal cryptographic overhead. Both protocols are rigorously analyzed using ProVerif, showing that they meet all major security requirements, including resistance to both passive and active attacks, as well as those outlined by 3GPP and recent academic studies. We also prototype both protocols and evaluate their performance against 5G-AKA and 5G-AKA’ (USENIX’21). Our results show that the proposed protocols offer stronger security guarantees with only minor impact on computational costs, making them practical and forward-compatible solutions for 5G and beyond.
Nazatul Haque Sultan, Xinlong Guan, Josef Pieprzyk, Wei Ni 0001, Alsharif Abuadbba, Hajime Suzuki
RAID1
2024 MIKA: A Minimalist Approach to Hybrid Key Exchange
abstract
Quantum computers are believed to be capable of breaking the security of most classical public key cryptosystems. To mitigate future security risks, researchers have been working on a hybrid approach that uses both classical and post-quantum cryptographic techniques, with the aim of keeping the system secure as long as at least one of the cryptosystems remains secure. However, most existing hybrid cryptosystems require protocol revisions to accommodate post-quantum cryptographic algorithms, leading to extensive modifications of existing code-bases and increased complexity in the state machines. In this paper, we explore a novel generic hybrid model that requires only minimal changes to the codebase of a classical cryptosystem while maintaining the simplicity of the state machines. To illustrate the working principle and provide a benchmark for our generic hybrid model, we conduct a case study on the IKEv2 protocol using the strongS wan library. Our benchmark reveals that, in a hybrid configuration with two protocols, our generic model introduces minimal overhead compared to the combined key exchange time of both protocols. Moreover, our model design allows for the initiation of different protocols in parallel, resulting in an acceleration of the key exchange time, particularly in hybrid configurations Involving more than two protocols.
Raymond K. Zhao, Nazatul Haque Sultan, Phillip Yialeloglou, Dongxi Liu, David Liebowitz, Josef Pieprzyk
PST2
2024 Securely sharing outsourced IoT data: A secure access and privacy preserving keyword search scheme
abstract
The rapid progress in the field of IoT and its wide-ranging applications emphasize the criticality of robust security measures for effectively sharing, storing, and managing sensitive data generated by IoT devices. Regulations such as the Consumer Data Rights (CDR) highlight the need for the seamless sharing of sensitive data with authorized third parties while ensuring confidentiality and privacy. To enable such secure sharing, a data storage and sharing scheme should fulfill the following core requirements: (a) support multi-client data sharing settings, allowing IoT data owners to authorize multiple clients; (b) a dynamic storage environment permitting IoT owners to add or remove files with minimal privacy leak; (c) decentralized storage for distributing data across servers or Cloud Service Providers (CSPs) for greater security; and (d) efficient privilege revocation mechanism which incurs less computation and communication overhead. To address these requirements, we have proposed a novel keyword search scheme using computationally lightweight cryptographic primitives. Our scheme empowers IoT data owners to securely share, store and manage encrypted data in the CSPs, providing better security and privacy. We have provided formal security proof for our scheme as well as validated its efficiency via extensive experiments on the Docker platform. On a database of 12 million keyword/document pairs (with 105 documents and 103 keywords), our scheme took about 18 ms to return all matched documents.
Nazatul Haque Sultan, Shabnam Kasra Kermanshahi, Hong-Yen Tran, Shangqi Lai, Vijay Varadharajan, Surya Nepal, Xun Yi
Ad Hoc Networks1
2024 NDN-RBE: An Accountable Privacy Aware Access Control Framework For NDN
abstract
Abstract Named Data Networking (NDN) is an emerging network architecture. An important characteristic of NDN is its in-network cache, which enables Data packets to be available from multiple locations on the Internet. Hence the enforcement of access control mechanisms becomes even more critical in the NDN. This paper proposes a novel access control scheme referred to as Role-Based Encryption for NDN (NDN-RBE), which uses a broadcast encryption mechanism to achieve secure data access control. Our scheme uses the role inheritance property of the traditional Role-Based Access Control (RBAC) model to achieve efficient data access control over hierarchical content. This makes our scheme particularly suitable for large-scale real-world content-centric services like Netflix. Our scheme also supports additional design features such as anonymous signature-based authentication, batch signature verification and two types of privilege revocations. In addition, our formal security analysis demonstrates that our scheme is provably secure against Chosen Plaintext Attacks. Our performance and functionality comparison show that our scheme outperforms other notable existing works in terms of security, functionality, computation, communication and storage overhead. Furthermore, our experimental results show an improvement in content delivery time of the order of 15 percent compared with the other closely related works.
Nazatul Haque Sultan, Vijay Varadharajan, Saurab Dulal, Seyit Ahmet Çamtepe, Surya Nepal
Comput. J.1
2024 Agriculture 4.0 and beyond: Evaluating cyber threat intelligence sources and techniques in smart farming ecosystems
abstract
The digitisation of agriculture, integral to Agriculture 4.0, has brought significant benefits while simultaneously escalating cybersecurity risks. With the rapid adoption of smart farming technologies and infrastructure, the agricultural sector has become an attractive target for cyberattacks. This paper presents a systematic literature review that assesses the applicability of existing cyber threat intelligence (CTI) techniques within smart farming infrastructures (SFIs). We develop a comprehensive taxonomy of CTI techniques and sources, specifically tailored to the SFI context, addressing the unique cyber threat challenges in this domain. A crucial finding of our review is the identified need for a virtual Chief Information Security Officer (vCISO) in smart agriculture. While the concept of a vCISO is not yet established in the agricultural sector, our study highlights its potential significance. The implementation of a vCISO could play a pivotal role in enhancing cybersecurity measures by offering strategic guidance, developing robust security protocols, and facilitating real-time threat analysis and response strategies. This approach is critical for safeguarding the food supply chain against the evolving landscape of cyber threats. Our research underscores the importance of integrating a vCISO framework into smart farming practices as a vital step towards strengthening cybersecurity. This is essential for protecting the agriculture sector in the era of digital transformation, ensuring the resilience and sustainability of the food supply chain against emerging cyber risks.
Hang Thanh Bui, Hamed Aboutorab, Arash Mahboubi, Yansong Gao 0001, Nazatul Haque Sultan, Muhammad Aufeef Chauhan, Mohammad Zavid Parvez, Michael Bewong, Md. Rafiqul Islam 0001, Md Zahidul Islam 0001, Seyit Ahmet Çamtepe, Praveen Gauravaram, Dinesh Kumar Singh, Muhammad Ali Babar 0001, Shihao Yan
Comput. Secur.5
2023 Securing Organization's Data: A Role-Based Authorized Keyword Search Scheme With Efficient Decryption
abstract
For better data availability and accessibility while ensuring data secrecy, organizations often tend to outsource their encrypted data to the cloud storage servers, thus bringing the challenge of keyword search over encrypted data. In this article, we propose a novel authorized keyword search scheme using Role-Based Encryption (RBE) technique in a cloud environment. The contributions of this article are multi-fold. First, it presents a keyword search scheme which enables only authorized users, having properly assigned roles, to delegate keyword-based data search capabilities over encrypted data to the cloud providers without disclosing any sensitive information. Second, it supports a multi-organization cloud environment, where the users can be associated with more than one organization. Third, the proposed scheme provides efficient decryption, conjunctive keyword search and revocation mechanisms. Fourth, the proposed scheme outsources expensive cryptographic operations in decryption to the cloud in a secure manner. Fifth, we have provided a formal security analysis to prove that the proposed scheme is semantically secure against Chosen Plaintext and Chosen Keyword Attacks. Finally, our performance analysis shows that the proposed scheme is suitable for practical applications.
Nazatul Haque Sultan, Maryline Laurent, Vijay Varadharajan
IEEE Trans. Cloud Comput.1
2023 A Role-Based Encryption (RBE) Scheme for Securing Outsourced Cloud Data in a Multi-Organization Context
abstract
Role-Based Encryption (RBE) is an emerging new technique that integrates role based access control (RBAC) model with encryption. RBE embeds RBAC access policies in encrypted data itself so that only users belonging to appropriate roles are able to decrypt and access the data. However, the existing RBE schemes have been focusing on the single-organization cloud storage system, where the stored data can be accessed by users of the same organization. This paper presents a novel RBE scheme with efficient user revocation for the multi-organization cloud storage system, where the data from multiple independent organizations are stored and can be accessed by the authorized users from any other organization. Additionally, an outsourced decryption mechanism is introduced which enables the users to delegate expensive cryptographic operations to the cloud, thereby reducing the overhead on the end-users. Security and performance analyses of the proposed scheme demonstrate that it is provably secure against Chosen Plaintext Attack and can be useful for practical applications due to its low computation overhead.
Nazatul Haque Sultan, Vijay Varadharajan, Ferdous A. Barbhuiya
IEEE Trans. Serv. Comput.1
2022 Authorized Keyword Search over Outsourced Encrypted Data in Cloud Environment
abstract
For better data availability and accessibility while ensuring data secrecy, end-users often tend to outsource their data to the cloud servers in an encrypted form. However, this brings a major challenge to perform the search for some keywords over encrypted content without disclosing any information to unintended entities. This paper proposes a novel expressive authorized keyword search scheme relying on the concept of ciphertext-policy attribute-based encryption. The originality of the proposed scheme is multifold. First, it supports the generic and convenient multi-owner and multi-user scenario, where the encrypted data are outsourced by several data owners and searchable by multiple users. Second, the formal security analysis proves that the proposed scheme is semantically secure against chosen keyword and outsiders keyword guessing attacks. Third, an interactive protocol is introduced which avoids the need of any secure-channels between users and service provider. Fourth, due to the concept of bilinear-map accumulator, the system can efficiently revoke users and/or their attributes, and authenticate them prior to launching any expensive search operations. Fifth, conjunctive keyword search is provided thus enabling to search for multiple keywords simultaneously, with minimal cost. Sixth, the performance analysis shows that the proposed scheme outperforms closely-related works.
Nazatul Haque Sultan, Nesrine Kaaniche, Maryline Laurent, Ferdous A. Barbhuiya
IEEE Trans. Cloud Comput.1
2021 A Secure Access and Accountability Framework for Provisioning Services in Named Data Networks
abstract
Named Data Networking (NDN) is an emerging network architecture, which is built by keeping data as its pivotal point. The in-network cache, one of the important characteristics, makes data packets to be available from multiple locations on the Internet. Hence data access control and their enforcement mechanisms become even more critical in the NDNs. In this paper, we propose a novel encryption-based data access control scheme using Role-Based Encryption (RBE). The inheritance property of our scheme provides a natural way to achieve efficient data access control over hierarchical content. This in turn makes our scheme suitable for large scale real world content-centric applications and services such as Netflix. Further, the proposed scheme introduces an anonymous signature-based authentication mechanism to reject bogus data requests nearer to the source, thereby preventing them from entering the network. This in turn helps to mitigate better denial of service attacks. In addition, the signature mechanism supports unlinkability, which is essential to prevent leakages of individual user's access patterns. Another major feature of the proposed scheme is that it provides accountability of the Internet Service Providers (ISPs) using batch signature verification. Moreover, we have developed a transparent and secure dispute resolution and payment mechanism using smart-contract and blockchain technologies. We present a formal security analysis of our scheme to show it is provably secure against Chosen Plaintext Attacks. We also demonstrate that our scheme supports more functionalities than the existing schemes and its performance is better in terms of computation, communication and storage.
Nazatul Haque Sultan, Vijay Varadharajan, Chandan Kumar Chaudhary, Seyit Ahmet Çamtepe, Surya Nepal
SRDS1
2020 An Accountable Access Control Scheme for Hierarchical Content in Named Data Networks with Revocation
Nazatul Haque Sultan, Vijay Varadharajan, Seyit Ahmet Çamtepe, Surya Nepal
ESORICS (1)1
2018 ICAuth: A secure and scalable owner delegated inter-cloud authorization
Nazatul Haque Sultan, Ferdous A. Barbhuiya, Maryline Laurent
Future Gener. Comput. Syst.1
2017 A universal cloud user revocation scheme with key-escrow resistance for ciphertext-policy attribute-based access control
abstract
Cloud storage service allows its users to store and share data in a cloud environment. To secure the data from unauthorized entities while sharing, cryptographic mechanisms are used. Ciphertext-Policy Attribute-Based Encryption (CP-ABE) is one such mechanism, which has been widely used to achieve fine-grained access control over encrypted data. However, user revocation and keyescrow, in CP-ABE, are still remaining as challenging problems. In this paper, we propose a key-escrow resistant CP-ABE based access control scheme to provide efficient user revocation. The security analysis of the scheme has been done using Information Theory Tools. The security analysis establishes that it is unconditionally secure and provides any-wise revocation capability. Moreover, comparison with the other notable works in the area shows that it outperforms them in terms of computational and communication overheads.
Nazatul Haque Sultan, Ferdous A. Barbhuiya, Nityananda Sarma
SIN1
2016 A Secure Re-encryption Scheme for Data Sharing in Unreliable Cloud Environment
abstract
To share encrypted data in cloud storage, data owner provides decryption keys to authorised users. When such a user is revoked, the encrypted data related to revoked user is re-encrypted and new decryption keys are re-distributed among the non-revoked users. In this paper, an efficient and secure re-encryption scheme has been proposed for data sharing in unreliable cloud environment. The scheme is built on top of Ciphertext-Policy based Attribute-Based Encryption (CP-ABE), which will provide fine-grained access control to share data. The scheme can achieve user revocation without whole ciphertexts re-encryption and key re-distributions. In addition, re-encryption is not performed until a user requests for that data, which reduces overheads. Further, it does not need any clock synchronization. Moreover, the scheme is proven to be secured under Computational Bilinear Diffie-Hellman (CBDH) assumption. A comparison with the other notable work in this area shows that the performance is better in terms of functionality, computational and communication overheads.
Nazatul Haque Sultan, Ferdous A. Barbhuiya
SERVICES1