SK Hafizul Islam

dblp:170/4220 · DBLP profile ↗
← Back
70ranked-venue papers
12as first author
30since 2021 · last 2026
0000-0002-2703-0213ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 20 · 6 first-author · 8 since 2021Systems, architecture and hardware · 18 · 1 first-author · 10 since 2021Computer networks · 12 · 2 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 8 · 5 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 4 · 1 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author
YearPublicationVenuePosition
2026 A provably secure identity-based aggregate signcryption scheme for Vehicle-to-Infrastructure communication in VANETs
Neetu Sharma, Krittibas Parai, SK Hafizul Islam
J. Inf. Secur. Appl.3
2026 Blockchain-assisted provably secure identity-based public key encryption with keyword search scheme for medical data sharing
Sudeep Ghosh, SK Hafizul Islam, Athanasios V. Vasilakos
J. Syst. Archit.2
2025 Designing secure blockchain-based authentication and key management mechanism for Internet of Drones applications
Mohammad Wazid, Saksham Mittal, Ashok Kumar Das, SK Hafizul Islam, Mohammed J. F. Alenazi, Athanasios V. Vasilakos
J. Syst. Archit.4
2024 PF-IBDA: Provably secure and pairing-free identity-based deniable authentication protocol for MANET environments
SK Hafizul Islam, Krittibas Parai, Daya Sagar Gupta
Comput. Networks1
2024 Private Blockchain-Assisted Certificateless Public Key Encryption With Multikeyword Search for Fog-Based IIoT Environments
abstract
Various sensors are utilized to gather data for the Industrial Internet of Things (IIoT) environments and stored in an adaptable and affordable cloud computing infrastructure. The cloud server performs data analytics intelligently using AI-enabled applications. IIoT data must be encrypted to protect privacy because it is kept on a cloud server, which is untrusted. Nevertheless, there is a difficulty with searching encrypted data, which may be resolved by using a Public key Encryption with Keyword Search (PEKS) method. Furthermore, most existing PEKS schemes are vulnerable to Inside/Outside Keyword Guessing Attacks (IKGAs/OKGAs). Recently, some Certificateless PEKS (CL-PEKS) schemes have been proposed to circumvent certificate management issues, key escrow problems, and IKGA/OKGA. However, they are vulnerable to a malicious Key Generation Center (KGC) attack as they do not satisfy the Girault’s level-3 security. We proposed a private blockchain-assisted CL-PEKS for Multikeyword (BCT-CL-PEMKS) search in a fog-based IIoT environment. The BCT-CL-PEMKS scheme meets the Girault’s level-3 security. It used a private blockchain to manage all the fog nodes. The BCT-CL-PEMKS provides ciphertext indistinguishability, trapdoor indistinguishability, and designated-server testability in the random oracle model. We estimated the computation and communication overheads of BCT-CL-PEMKS and compared them with the other PEKS schemes for 80, 112, 128, 192, and 256-bit security levels.
Sudeep Ghosh, SK Hafizul Islam, Athanasios V. Vasilakos
IEEE Internet Things J.2
2024 IoT-ID3PAKA: Efficient and Robust ID-3PAKA Protocol for Resource-Constrained IoT Devices
abstract
The Internet of Things (IoT) is an emerging technology that has become popular in many applications, such as transportation, agriculture, healthcare, industrial automation, robotics, etc. IoT devices are interconnected via the Internet, and secure message communication between them is a challenging task. An authenticated key agreement (AKA) protocol can solve such an issue. This article designed and implemented an identity-based three-party AKA (IoT-ID3PAKA) protocol to establish a shared session key among three IoT devices. The current state-of-the-art identity-based 3PAKA (ID-3PAKA) protocols are unsuitable for resource-constrained IoT devices because almost all of them undergo various security attacks and require higher execution and communication overheads. The provable security of the proposed IoT-ID3PAKA protocol relies on the hardness assumption of the elliptic curve-based computational Diffie–Hellman problem. The execution time of IoT-ID3PAKA for the security levels: 80, 112, 128, 192, and 256 bits on a Raspberry Pi 4 device is estimated and compared with the existing ID-3PAKA protocols.
Krittibas Parai, Daya Sagar Gupta, SK Hafizul Islam
IEEE Internet Things J.3
2024 2F-MASK-VSS: Two-factor mutual authentication and session key agreement scheme for video surveillance system
Arup Kumar Pal, SK Hafizul Islam
J. Syst. Archit.3
2024 CCM-PRNG: Pseudo-random bit generator based on cross-over chaotic map and its application in image encryption
Sathya Krishnamoorthi, Rajesh Kumar Dhanaraj, SK Hafizul Islam
Multim. Tools Appl.3
2023 A provably-secure authenticated key agreement protocol for remote patient monitoring IoMT
Chien-Ming Chen 0001, Shuangshuang Liu, Xuanang Li, SK Hafizul Islam, Ashok Kumar Das
J. Syst. Archit.4
2023 Provably secure public key encryption with keyword search for data outsourcing in cloud environments
Sudeep Ghosh, SK Hafizul Islam, Abhishek Bisht, Ashok Kumar Das
J. Syst. Archit.2
2023 IoT-RRHM: Provably secure IoT-based real-time remote healthcare monitoring framework
Krittibas Parai, SK Hafizul Islam
J. Syst. Archit.2
2023 Robust authenticated key agreement protocol for internet of vehicles-envisioned intelligent transportation system
Siddhant Thapliyal, Mohammad Wazid, Devesh Pratap Singh, Ashok Kumar Das, SK Hafizul Islam
J. Syst. Archit.5
2023 An object detection-based few-shot learning approach for multimedia quality assessment
Rajdeep Chatterjee, Ankita Chatterjee, SK Hafizul Islam, Muhammad Khurram Khan
Multim. Syst.3
2023 Secure and efficient image retrieval through invariant features selection in insecure cloud environments
Arup Kumar Pal, SK Hafizul Islam, Mohammad Hammoudeh
Neural Comput. Appl.3
2023 Cybersecurity Attack-Resilience Authentication Mechanism for Intelligent Healthcare System
abstract
People focus on the intelligent healthcare system expecting sufficient medical facilities even from a remote location. However, to make the healthcare system more trustworthy, secure access control plays a vital role in resisting several cyber-attacks. Security threat on medical data is highly sensitive since it is associated with life risks. When a user accesses a healthcare system through the Internet, the main concern is preventing unauthorized access to vital healthcare-related data. Traditional authentication (based on a password, smartcard, and/or biometric) provides a solution to allow such kind of application only to the authorized users. But once a user is authenticated, and he/she is idle for a while, the chances of security threat are reasonably high. This article has designed an intelligent user recognization mechanism for continuous monitoring of the user’s activity throughout the session. We have made the system user-friendly through single sign-on and eliminated trusted third-party dependence to avoid data breaches. Once the authentication is performed, then in a later stage, the continuous monitoring mechanism based on machine learning techniques helps to decide the user’s unique behavior allowing the application server to make better decisions regarding the user’s authenticity in the current session. The security analysis shows that the proposed system is more secure than the traditional authentication mechanisms.
Preeti Soni, Jitesh Pradhan, Arup Kumar Pal, SK Hafizul Islam
IEEE Trans. Ind. Informatics4
2022 Deep learning techniques for observing the impact of the global warming from satellite images of water-bodies
Rajdeep Chatterjee, Ankita Chatterjee, SK Hafizul Islam
Multim. Tools Appl.3
2022 Radiological image retrieval technique using multi-resolution texture and shape features
Jitesh Pradhan, Arup Kumar Pal, SK Hafizul Islam, Muhammad Khurram Khan
Multim. Tools Appl.4
2022 Computational intelligence based secure three-party CBIR scheme for medical data for cloud-assisted healthcare applications
Mukul Majhi, Arup Kumar Pal, Jitesh Pradhan, SK Hafizul Islam, Muhammad Khurram Khan
Multim. Tools Appl.4
2022 A cryptographic paradigm to detect and mitigate blackhole attack in VANET environments
Rajesh Kumar Dhanaraj, SK Hafizul Islam, Vani Rajasekar
Wirel. Networks2
2021 Encrypted Medical Image Storage in DNA Domain
abstract
Medical images have become an integral part of healthcare systems to provide quick and accurate treatment of diseases. The challenge, however, is to store these data, as they are huge in volume. DNA provides an efficient medium for the storage of bulk data. This data can be secured against malicious use using DNA based encryption algorithms. This paper presents a novel DNA based compression-encryption algorithm, specially designed for medical images. A significant part of medical images contains homogeneous pixels, which are even more prominent when decomposed into their bit-planes. This redundancy can be removed while compression, based on which the proposed DNA-based QuadTree Decomposition algorithm has been designed. A sequence of four DNA nucleotides represents the entire image, and these can be used to recover back the original image using the decoding algorithm. To secure the obtained sequences, DNA-based Advanced Encryption Standard (AES) algorithm is applied in Cipher Block Chaining (CBC) mode which encrypts the sequences using the symmetric key and initial vector parameters. The image cannot be recovered from these encrypted sequences unless decrypted using the correct key, and the algorithm for AES is secured against cryptographic attacks.
Chiranjeev Bhaya, Mohammad S. Obaidat, Arup Kumar Pal, SK Hafizul Islam
ICC4
2021 PB-3PAKA: Password-based three-party authenticated key agreement protocol for mobile devices in post-quantum environments
SK Hafizul Islam, Swagatam Basu
J. Inf. Secur. Appl.1
2021 A comprehensive review on collision-resistant hash functions on lattices
Nimish Mishra, SK Hafizul Islam, Sherali Zeadally
J. Inf. Secur. Appl.2
2021 Provably secure biometric-based client-server secure communication over unreliable networks
Muhammad Asad Saleem, SK Hafizul Islam, Shafiq Ahmed, Khalid Mahmood 0002, Majid Hussain
J. Inf. Secur. Appl.2
2021 Bi-GISIS KE: Modified key exchange protocol with reusable keys for IoT security
Kübra Seyhan, Tu N. Nguyen 0001, Sedat Akleylek, Korhan Cengiz, SK Hafizul Islam
J. Inf. Secur. Appl.5
2021 Provably secure and biometric-based secure access of e-Governance services using mobile devices
Preeti Soni, Arup Kumar Pal, SK Hafizul Islam, Aadarsh Singh, Priyanshu Kumar
J. Inf. Secur. Appl.3
2021 A provably secure and lightweight authentication scheme for Internet of Drones for smart city surveillance
Mahdi Nikooghadam, Haleh Amintoosi, SK Hafizul Islam, Mostafa Farhadi Moghadam
J. Syst. Archit.3
2021 DAWM: Cost-Aware Asset Claim Analysis Approach on Big Data Analytic Computation Model for Cloud Data Centre
abstract
The heterogeneous resource-required application tasks increase the cloud service provider (CSP) energy cost and revenue by providing demand resources. Enhancing CSP profit and preserving energy cost is a challenging task. Most of the existing approaches consider task deadline violation rate rather than performance cost and server size ratio during profit estimation, which impacts CSP revenue and causes high service cost. To address this issue, we develop two algorithms for profit maximization and adequate service reliability. First, a belief propagation-influenced cost-aware asset scheduling approach is derived based on the data analytic weight measurement (DAWM) model for effective performance and server size optimization. Second, the multiobjective heuristic user service demand (MHUSD) approach is formulated based on the CPS profit estimation model and the user service demand (USD) model with dynamic acyclic graph (DAG) phenomena for adequate service reliability. The DAWM model classifies prominent servers to preserve the server resource usage and cost during an effective resource slicing process by considering each machine execution factor (remaining energy, energy and service cost, workload execution rate, service deadline violation rate, cloud server configuration (CSC), service requirement rate, and service level agreement violation (SLAV) penalty rate). The MHUSD algorithm measures the user demand service rate and cost based on the USD and CSP profit estimation models by considering service demand weight, tenant cost, and energy cost. The simulation results show that the proposed system has accomplished the average revenue gain of 35%, cost of 51%, and profit of 39% than the state-of-the-art approaches.
Mahammad Shareef Mekala, Rizwan Patan, SK Hafizul Islam, Debabrata Samanta, Gulam Ali Mallah, Shehzad Ashraf Chaudhry
Secur. Commun. Networks3
2021 Improved ECC-Based Three-Factor Multiserver Authentication Scheme
abstract
A multiserver environment can improve the efficiency of mobile network services more effectively than a single server in managing the increase in users. Because of the large number of users, the security of users’ personal information and communication information is more important in a multiserver environment. Recently, Wang et al. proposed a multiserver authentication scheme based on biometrics and proved the security of their scheme. However, we first demonstrate that their scheme is insecure against a known session-specific temporary information attacks, user impersonation attacks, and server impersonation attacks. To solve the security weakness, we propose an improved scheme based on Wang et al.’s scheme. The security of our improved scheme is also validated based on the formal security analysis, Burrows–Abadi–Needham (BAN) logic, ProVerif, and informal security analysis. Security and performance comparisons prove the security and efficiency of our scheme.
Tsu-Yang Wu, Lei Yang 0055, Zhiyuan Lee, Chien-Ming Chen 0001, Jeng-Shyang Pan 0001, SK Hafizul Islam
Secur. Commun. Networks6
2021 Provably Secure and Lightweight Identity-Based Authenticated Data Sharing Protocol for Cyber-Physical Cloud Environment
abstract
Secure and efficient file storage and sharing via authenticated physical devices remain challenging to achieve in a cyber-physical cloud environment, particularly due to the diversity of devices used to access the services and data. Thus in this paper, we present a lightweight identity-based authenticated data sharing protocol to provide secure data sharing among geographically dispersed physical devices and clients. The proposed protocol is demonstrated to resist chosen-ciphertext attack (CCA) under the hardness assumption of decisional-Strong Diffie-Hellman (SDH) problem. We also evaluate the performance of the proposed protocol with existing data sharing protocols in terms of computational overhead, communication overhead, and response time.
Arijit Karati, Ruhul Amin 0001, SK Hafizul Islam, Kim-Kwang Raymond Choo
IEEE Trans. Cloud Comput.3
2021 A secure blockchain-based group key agreement protocol for IoT
Chien-Ming Chen 0001, Xiaoting Deng, Wensheng Gan, Jiahui Chen 0002, SK Hafizul Islam
J. Supercomput.5
2020 A robust authentication and access control protocol for securing wireless healthcare sensor networks
Zeeshan Ali 0003, Anwer Ghani, Imran Khan 0004, Shehzad Ashraf Chaudhry, SK Hafizul Islam, Debasis Giri
J. Inf. Secur. Appl.5
2020 Provably secure two-party authenticated key agreement protocol for post-quantum environments
SK Hafizul Islam
J. Inf. Secur. Appl.1
2020 Provably secure identity-based two-party authenticated key agreement protocol based on CBi-ISIS and Bi-ISIS problems on lattices
SK Hafizul Islam, Sherali Zeadally
J. Inf. Secur. Appl.1
2020 Intelligent Secure Ecosystem Based on Metaheuristic and Functional Link Neural Network for Edge of Things
abstract
Internet of Things (IoT) has evolved for building smart environments in a distributed system, where the data produced by IoT devices are transmitted through Edge computing devices to streamline the flow of traffic from IoT devices to a distributed network. In such a scenario, the attacker introduces many attacks to the edge before forwarding them to distributed servers. This necessitates intrusion detection systems for such environments to mitigate security attacks. This paper has projected a basis for characterization of intrusive behaviors in a distributed system based on the functional link neural nets response weighted-average and teaching-learning metaheuristic with elitism on weight-space. The proposed technique makes use of teaching-learning metaheuristic optimization to obtain suitable parameters for the functional link neural net. Furthermore, the processing of duplicate parameters is successfully avoided by using mutation operation. In addition to this, in this paper the proposed method is found to be more efficient in terms of computational burden.
Bighnaraj Naik, Mohammad S. Obaidat, Janmenjoy Nayak, Danilo Pelusi, Pandi Vijayakumar, SK Hafizul Islam
IEEE Trans. Ind. Informatics6
2020 Efficient and Secure Anonymous Authentication With Location Privacy for IoT-Based WBANs
abstract
Internet-of-Things (IoT)-based wireless body area networks (WBANs) play an important role in modern medical systems for patient-health monitoring. WBANs have the capability to collect real-time biological information from the patients' body using intelligent sensors and then send the collected information to the remote doctors or medical experts using the Internet. In recent years, numerous anonymous authentication schemes were proposed to provide security in WBANs. However, many of these schemes are not computationally efficient during anonymous authentication. Moreover, the previous schemes did not provide location privacy for both doctors and patients. In order to overcome these limitations, in this article, we propose an efficient and secure anonymous authentication framework with location privacy preservation for IoT-based WBANs. The comprehensive analysis section shows that the proposed scheme overcomes the security weaknesses in the existing schemes and also provides low computation cost during anonymous authentication.
Pandi Vijayakumar, Mohammad S. Obaidat, Maria Azees, SK Hafizul Islam, Neeraj Kumar 0001
IEEE Trans. Ind. Informatics4
2020 A heterogeneous user authentication and key establishment for mobile client-server environment
Fagen Li, Jiye Wang, SK Hafizul Islam
Wirel. Networks5
2019 A robust and efficient mutual authentication and key agreement scheme with untraceability for WBANs
Marko Kompara, SK Hafizul Islam, Marko Hölbl
Comput. Networks2
2019 A novel machine learning based feature selection for motor imagery EEG signal classification in Internet of medical things environment
Rajdeep Chatterjee, Tanmoy Maitra, SK Hafizul Islam, Mohammad Mehedi Hassan, Atif Alamri, Giancarlo Fortino
Future Gener. Comput. Syst.3
2019 MGPV: A novel and efficient scheme for secure data sharing among mobile users in the public cloud
Pandi Vijayakumar, S. Milton Ganesh, L. Jegatha Deborah, SK Hafizul Islam, Mohammad Mehedi Hassan, Abdulhameed Alelaiwi, Giancarlo Fortino
Future Gener. Comput. Syst.4
2019 A lightweight machine learning-based authentication framework for smart IoT devices
P. Punithavathi, S. Geetha 0001, Marimuthu Karuppiah, SK Hafizul Islam, Mohammad Mehedi Hassan, Kim-Kwang Raymond Choo
Inf. Sci.4
2019 Intelligent temporal classification and fuzzy rough set-based feature selection algorithm for intrusion detection system in WSNs
K. Selvakumar 0001, Marimuthu Karuppiah, L. Sai Ramesh, SK Hafizul Islam, Mohammad Mehedi Hassan, Giancarlo Fortino, Kim-Kwang Raymond Choo
Inf. Sci.4
2019 Anonymity Preserving and Lightweight Multimedical Server Authentication Protocol for Telecare Medical Information System
abstract
Electronic health systems, such as telecare medical information system (TMIS), allow patients to exchange their health information with a medical center/doctor for diagnosis in real time, and across borders. Given the sensitive nature of health information/medical data, ensuring the security of such systems is crucial. In this paper, we revisit Das et al.'s authentication protocol, which is designed to ensure patient anonymity and untraceability. Then, we demonstrate that the security claims are invalid, by showing how both security features (i.e., patient anonymity and untraceability) can be compromised. We also demonstrate that the protocol suffers from smartcard launch attacks. To mitigate such design flaws, we propose a new lightweight authentication protocol using the cryptographic hash function for TMIS. We then analyze the security of the proposed protocol using AVISPA and Scyther, two widely used formal specification tools. The performance analysis demonstrates that our protocol is more efficient than other competing protocols.
Ruhul Amin 0001, SK Hafizul Islam, Prosanta Gope, Kim-Kwang Raymond Choo, Nachiket Tapas
IEEE J. Biomed. Health Informatics2
2019 Secure CLS and CL-AS schemes designed for VANETs
Pankaj Kumar 0006, Saru Kumari, Vishnu Sharma, Xiong Li 0002, Arun Kumar Sangaiah, SK Hafizul Islam
J. Supercomput.6
2018 A robust mutual authentication protocol for WSN with multiple base-stations
Ruhul Amin 0001, SK Hafizul Islam, G. P. Biswas, Mohammad S. Obaidat
Ad Hoc Networks2
2018 A robust and anonymous patient monitoring system using wireless medical sensor networks
Ruhul Amin 0001, SK Hafizul Islam, G. P. Biswas, Muhammad Khurram Khan, Neeraj Kumar 0001
Future Gener. Comput. Syst.2
2018 An intelligent/cognitive model of task scheduling for IoT applications in cloud computing environment
Sayantani Basu, Marimuthu Karuppiah, K. Selvakumar 0001, Kuanching Li, SK Hafizul Islam, Mohammad Mehedi Hassan, Md. Zakirul Alam Bhuiyan
Future Gener. Comput. Syst.5
2018 Lightweight and privacy-preserving RFID authentication scheme for distributed IoT infrastructure with secure localization services for smart city environment
Prosanta Gope, Ruhul Amin 0001, SK Hafizul Islam, Neeraj Kumar 0001, Vinod Kumar Bhalla
Future Gener. Comput. Syst.3
2018 A robust and efficient password-based conditional privacy preserving authentication and group-key agreement protocol for VANETs
SK Hafizul Islam, Mohammad S. Obaidat, Pandi Vijayakumar, Enas W. Abdulhay, Fagen Li, M. Krishna Chaitanya Reddy
Future Gener. Comput. Syst.1
2018 A Provably Secure Three-Factor Session Initiation Protocol for Multimedia Big Data Communications
abstract
The session initiation protocol (SIP) is an IP-based telephony authentication mechanism for multimedia big data communications over the Internet. It is used to set up, and control voice and video calls, as well as for instant messaging. One of the concerns of this kind of open-text-based protocol is the security for user authentication. The HTTP digest-based challenge-response authentication process is used in the original SIP. However, this kind of authentication procedure is insecure and a pre-existing user configuration on the remote server is required. According to the literature, several authentication mechanisms for SIP are already devised, but none of these SIPs are robust against existing security attacks. Therefore, we design a three-factor SIP (TF-SIP) for multimedia big data communications, which is robust and flexible against existing known security issues. We show that our TF-SIP is provably secure in the random oracle model. We formally verify the mutual authentication and the freshness of the agreed session key between the user and the remote server using the BAN logic analysis. We found that the communication and computation costs are low, but the storage cost is slightly higher for our TF-SIP in comparison with other SIPs.
SK Hafizul Islam, Pandi Vijayakumar, Md. Zakirul Alam Bhuiyan, Ruhul Amin 0001, Varun Rajeev M., Balamurugan Balusamy
IEEE Internet Things J.1
2018 Provably Secure Identity-Based Signcryption Scheme for Crowdsourced Industrial Internet of Things Environments
abstract
Nowadays, the Internet of Things (IoT) and cloud computing have become more pervasive in the context of the industry as digitization becomes a business priority for various organizations. Therefore, industries outsource their crowdsourced Industrial IoT (IIoT) data in the cloud in order to reduce the cost for sharing data and computation. However, the privacy of such crowdsourced data in this environment has attracted wide attention across the globe. Signcryption is the significant cryptographic primitive that meets both requirement of authenticity and confidentiality of crowdsourced data among users/industries, and thus, it is ideal for ensuring secure authentic data storage and transmission in industrial crowdsourcing environments. In this paper, we introduce a new identity-based signcryption (IBSC) scheme using bilinear pairing for IIoT deployment. Besides, two hard problems are studied, called as, modified bilinear Diffie-Hellman inversion (MBDHI) assumption and modified bilinear strong Diffie-Hellman (MBSDH) assumption. The rigorous security analysis demonstrates that our IBSC scheme for IIoT is provably secure based on the intractability of decisional-MBDHI and MBSDH assumptions under formal security model without considering the concept of the random oracle. The performance comparison with other signcryption schemes shows satisfactory results. Thus, our IBSC scheme is appropriate for IIoT crowdsourcing environments, and also applicable for low-bandwidth communications.
Arijit Karati, SK Hafizul Islam, G. P. Biswas, Md. Zakirul Alam Bhuiyan, Pandi Vijayakumar, Marimuthu Karuppiah
IEEE Internet Things J.2
2018 A pairing-free and provably secure certificateless signature scheme
Arijit Karati, SK Hafizul Islam, G. P. Biswas
Inf. Sci.2
2018 An untraceable and anonymous password authentication protocol for heterogeneous wireless sensor networks
Ruhul Amin 0001, SK Hafizul Islam, Neeraj Kumar 0001, Kim-Kwang Raymond Choo
J. Netw. Comput. Appl.2
2018 A robust and efficient bilinear pairing based mutual authentication and session key verification over insecure communication
Ruhul Amin 0001, SK Hafizul Islam, Pandi Vijayakumar, Muhammad Khurram Khan, Victor Chang 0001
Multim. Tools Appl.2
2018 A provably secure biometrics-based authenticated key agreement scheme for multi-server environments
Saru Kumari, Ashok Kumar Das, Xiong Li 0002, Fan Wu 0003, Muhammad Khurram Khan, Qi Jiang 0001, SK Hafizul Islam
Multim. Tools Appl.7
2018 Efficient authentication protocol for secure multimedia communications in IoT-enabled wireless sensor networks
Dheerendra Mishra, Pandi Vijayakumar, Venkatasamy Sureshkumar, Ruhul Amin 0001, SK Hafizul Islam, Prosanta Gope
Multim. Tools Appl.5
2018 Provably Secure and Lightweight Certificateless Signature Scheme for IIoT Environments
abstract
In recent years, two technologies, the cloud computing and the Internet of Things (IoT), have a synergistic effect in the modern organizations as digitization is a new business trend for various industries. Therefore, many organizations outsource their crowdsourced industrial-IoT (IIoT) data in the cloud system to reduce data management overhead. However, data authentication is one of the fundamental security/trust requirements in such IIoT network. The certificateless signature (CLS) scheme is a cryptographic primitive that provides data authenticity in IIoT systems. Recently, CLS has become a prime research focus due to its ability to solve the key-escrow problem in a very recent identity-based signature technique. Many CLS schemes have already been developed using map-to-point (MTP) hash function and random oracle model (ROM). However, due to the implementation difficulty and probabilistic nature of MTP function and ROM, those CLSs are impractical. Hence, the development of a CLS for lightweight devices mounted in IIoT has become one of the most focused research trends. This paper presents a new pairing-based CLS scheme without MTP function and ROM. The new CLS scheme is secure against both the Type-I and Type-II adversaries under the hardness of extended bilinear strong Diffie-Hellman (BSDH) and BSDH assumptions, respectively. Performance evaluation and comparison proves that our scheme outperforms other CLS schemes.
Arijit Karati, SK Hafizul Islam, Marimuthu Karuppiah
IEEE Trans. Ind. Informatics2
2017 A Two-Factor RSA-Based Robust Authentication System for Multiserver Environments
abstract
The concept of two-factor multiserver authentication protocol was developed to avoid multiple number of registrations using multiple smart-cards and passwords. Recently, a variety of two-factor multiserver authentication protocols have been developed. It is observed that the existing RSA-based multiserver authentication protocols are not suitable in terms of computation complexities and security attacks. To provide lower complexities and security resilience against known attacks, this article proposes a two-factor (password and smart-card) user authentication protocol with the RSA cryptosystem for multiserver environments. The comprehensive security discussion proved that the known security attacks are eliminated in our protocol. Besides, our protocol supports session key agreement and mutual authentication between the application server and the user. We analyze the proof of correctness of the mutual authentication and freshness of session key using the BAN logic model. The experimental outcomes obtained through simulation of the Automated Validation of Internet Security Protocols and Applications (AVISPA) S/W show that our protocol is secured. We consider the computation, communication, and storage costs and the comparative explanations show that our protocol is flexible and efficient compared with protocols. In addition, our protocol offers security resilience against known attacks and provides lower computation complexities than existing protocols. Additionally, the protocol offers password change facility to the authorized user.
Ruhul Amin 0001, SK Hafizul Islam, Muhammad Khurram Khan, Arijit Karati, Debasis Giri, Saru Kumari
Secur. Commun. Networks2
2016 Design of an anonymity-preserving three-factor authenticated key exchange protocol for wireless sensor networks
Ruhul Amin 0001, SK Hafizul Islam, G. P. Biswas, Muhammad Khurram Khan, Lu Leng, Neeraj Kumar 0001
Comput. Networks2
2016 A more secure and privacy-aware anonymous user authentication scheme for distributed mobile cloud computing environments
abstract
Abstract Now‐a‐days, the low‐power handheld mobile devices make our life more comfortable. With the fast advancement of mobile communication technologies and Internet, mobile users are accessing remote services at home over the Internet. Recently, Tsai and Lo put forwarded a user authentication scheme for distributing mobile cloud environments. Unfortunately, we observed that Tsai and Lo's scheme suffers from user impersonation attack and known session‐specific temporary information attack. Besides, the scheme does not support the wrong password and fingerprint detection in the authentication phase. The scheme also violates the user anonymity property. Moreover, the password update functionality is absent in Tsai and Lo's scheme. In order to provide more securities and functionalities, this article put forwarded an enhanced scheme for distributing mobile cloud environments. The simulation on automated validation of Internet security protocols and applications tool ensures that our scheme is secure against the active and passive attacks. Our cryptanalysis gives surety that the scheme can defend related security attacks. We also compare our scheme with the previous schemes with respect to computation cost and security aspects. Copyright © 2016 John Wiley & Sons, Ltd.
Ruhul Amin 0001, SK Hafizul Islam, G. P. Biswas, Debasis Giri, Muhammad Khurram Khan, Neeraj Kumar 0001
Secur. Commun. Networks2
2016 Design of a provably secure identity-based digital multi-signature scheme using biometrics and fuzzy extractor
abstract
A novel biometric identity-based digital multi-signature BIO-IDMS scheme is put forwarded in this paper. The proposed scheme is constructed with the help of fuzzy extractor and elliptic curve bilinear pairings. Furthermore, we designed the formal model and the security model of the proposed BIO-IDMS scheme. The formal security analysis demonstrates that the forgery of the proposed scheme is infeasible in the random oracle model based on the intractability assumption of the computational Diffie-Hellman CDH problem. The proposed scheme outperforms in terms of computational cost compared with other related existing multi-signature schemes. Copyright © 2016 John Wiley & Sons, Ltd.
SK Hafizul Islam, Ashok Kumar Das, Muhammad Khurram Khan
Secur. Commun. Networks1
2016 An enhanced multi-server authentication protocol using password and smart-card: cryptanalysis and design
abstract
Abstract At the present time, application of online communication systems are rapidly increasing and most of the clients depend on a set of servers to fulfill their daily needs. In order to access these servers, a client (user) needs to register to each server with different login credentials. To circumvent this situation, the concept of multi‐server authentication has been adopted, where a user can access all the servers using a single login credential. In this paper, a two‐factor multi‐server authentication protocol, which is proposed by Leu and Hsieh, is analyzed and observed that the forgery attack and the off‐line password‐guessing attack can be made on it. Further, the off‐line password‐guessing attack and other security threats are found in similar kind of multi‐server authentication protocol, which is designed by Li et al. This paper mainly focuses on enhancing the securities of the previously mentioned protocols and thus proposed a new protocol. We have employed formal and informal security analysis to analyze the proposed protocol. The performance of our protocol is also compared with the related protocols. It can also be noted that the designed protocol accomplishes mutual authentication, session key verification, and identity and password change phases. Copyright © 2016 John Wiley & Sons, Ltd.
Tanmoy Maitra, SK Hafizul Islam, Ruhul Amin 0001, Debasis Giri, Muhammad Khurram Khan, Neeraj Kumar 0001
Secur. Commun. Networks2
2016 Security analysis and design of an efficient ECC-based two-factor password authentication scheme
abstract
Abstract Client‐server‐based communications provide a facility by which users can get several services from home via the Internet. As the Internet is an insecure channel, it is needed to protect information of communicators. An authentication scheme can fulfill the aforementioned requirements. Recently, Huang et al. presented an elliptic curve cryptosystem‐based password authentication scheme. This work has demonstrated that the scheme of Huang et al. has security weakness against the forgery attack. In addition, this paper also presented that the scheme of Huang et al. has some design drawbacks. Therefore, this paper has focused on excluding the security vulnerabilities of the scheme of Huang et al. by proposing an elliptic curve cryptosystem‐based password authentication scheme using smart card. The security of our scheme is based on the hardness assumption of the one‐way hash functions and elliptic curve discrete logarithm problem. Furthermore, we have demonstrated that our scheme is secured against known attacks. The performance of our scheme is also nearly equal when compared to related competing schemes. Copyright © 2016 John Wiley & Sons, Ltd.
Tanmoy Maitra, Mohammad S. Obaidat, SK Hafizul Islam, Debasis Giri, Ruhul Amin 0001
Secur. Commun. Networks3
2016 An efficient group key agreement protocol for secure P2P communication
abstract
Abstract The efficient design of a distributed group key management for a peer to peer (P2P) network with minimal computation complexity in dynamic secure group communication is a challenging issue. This is because of the absence of a centralized coordinator. In order to provide this facility, a self‐composed distributed group key management framework is proposed for secure P2P communication. In this proposed work, group key computation is performed using Chinese remainder theorem and secure communication is performed through RSA encryption algorithm. This self‐composed key management is a one round protocol in which a shared group key is generated using the public key of each individual user, and it is derived from the respective private key. The main advantage of the group key management scheme proposed in this paper is that it reduces the computation complexity of the peer users toO(1). This reduction in computation complexity is achieved by performing one addition and multiplication operation during a single member join and one subtraction operation during a single member leave operation. The proposed algorithm has been implemented and analyzed with well‐known existing distributed group key management protocols and observed that it reduces the computation complexity significantly. Copyright © 2016 John Wiley & Sons, Ltd.
Pandi Vijayakumar, Ramu Naresh, L. Jegatha Deborah, SK Hafizul Islam
Secur. Commun. Networks4
2016 An effective key distribution for secure internet pay-TV using access key hierarchies
abstract
Abstract Distribution of keys in a Conditional Access System takes long computation time because a huge number of keys is to be updated if any user leaves or joins the system. Moreover, it is necessary to send the keys securely to the authorized members. Thus, an effective key distribution protocol for Internet Pay‐TV system is designed in this article to lower the computation time taken to compute the re‐keying information. In the proposed protocol, when the Service Provider needs to refresh a new shared secret key and link values, only a few key updating operations are needed, and they can be achieved using four primary operations, namely, hash function, addition, subtraction, and multiplication. From the experimental results, we perceive that the proposed approach takes less computation cost, communication cost and storage cost compared with other competitive protocols available in the literature. Copyright © 2016 John Wiley & Sons, Ltd.
Pandi Vijayakumar, Ramu Naresh, SK Hafizul Islam, L. Jegatha Deborah
Secur. Commun. Networks3
2015 Leakage-Free and Provably Secure Certificateless Signcryption Scheme Using Bilinear Pairings
abstract
Signcryption schemes play a vital role to accomplish confidentiality, integrity, authentication and non-repudiation of messages simultaneously. In the literature, many certificateless signcryption (CLSC) schemes have been designed; however, most of them are vulnerable to ephemeral secret leakage (ESL) attack. In these schemes, sender uses an ephemeral secret to compute a ciphertext on a message. However, there is a possibility to compromise the ephemeral secret, since it is generally pre-computed and stored in an insecure device. Furthermore, it is generated by an external source, which can be controlled by an adversary. Thus, from the knowledge of compromised ephemeral secret, an adversary may calculate the private key of the sender and the message from the eavesdropped ciphertext, and this problem is called ESL attack. In this paper, we proposed a leakage-free CLSC, which is secure against ESL attack in the random oracle model. The proposed scheme provides confidentiality under the Co-Bilinear Diffie–Hellman (Co-BDH) assumption and unforgeability based on Co-Computational Diffie–Hellman assumption.
SK Hafizul Islam, Fagen Li
Comput. J.1
2015 A provably secure and efficient two-party password-based explicit authenticated key exchange protocol resistance to password guessing attacks
abstract
Summary Password‐based two‐party authenticated key exchange (2PAKE) protocol enables two or more entities, who only share a low‐entropy password between them, to authenticate each other and establish a high‐entropy secret session key. Recently, Zhenget al.proposed a password‐based 2PAKE protocol based on bilinear pairings and claimed that their protocol is secure against the known security attacks. However, in this paper, we indicate that the protocol of Zhenget al.is insecure against the off‐line password guessing attack, which is a serious threat to such protocols. Consequently, we show that an attacker who obtained the users' password by applying the off‐line password guessing attack can easily obtain the secret session key. In addition, the protocol of Zhenget al.does not provide the forward secrecy of the session key. As a remedy, we also improve the protocol of Zhenget al.and prove the security of our enhanced protocol in the random oracle model. The simulation result shows that the execution time of our 2PAKE protocol is less compared with other existing protocols. Copyright © 2015 John Wiley & Sons, Ltd.
Mohammad Sabzinejad Farash, SK Hafizul Islam, Mohammad S. Obaidat
Concurr. Comput. Pract. Exp.2
2015 Design and analysis of a three party password-based authenticated key exchange protocol using extended chaotic maps
SK Hafizul Islam
Inf. Sci.1
2015 Anonymous and provably secure certificateless multireceiver encryption without bilinear pairing
abstract
Recently, numerous multireceiver identity-based encryption or identity-based broadcast encryption schemes have been introduced with bilinear pairing and probabilistic map-to-point MTP function. As the bilinear pairing and MTP functions are expensive operations, any cryptographic schemes based on these operations experience high computational burden. The certificateless public key cryptography sidesteps the private key escrow problem occurring in identity-based cryptosystem and certificate management troubles of certificate authority-based public key cryptography CA-PKC. We observed that certificateless multireceiver encryption CL-MRE scheme without pairing and MTP hash function has not yet been considered in the literature. In this paper, we proposed a bilinear pairing and MTP hash-function-free CL-MRE scheme with chosen ciphertext attack resilience. The detailed analyses provide evidence that our scheme achieves forward secrecy, backward secrecy, and low computation costs than others. The scheme also provides confidentiality of the message and receiver anonymity in the random oracle model with the hardness of computational Diffie-Hellman problem. Copyright © 2014 John Wiley & Sons, Ltd.
SK Hafizul Islam, Muhammad Khurram Khan, Ali M. Al-Khouri
Secur. Commun. Networks1
2015 Design of provably secure and efficient certificateless blind signature scheme using bilinear pairing
abstract
Abstract In the literature, several pairing‐based blind signature schemes have been put forwarded using identity‐based cryptography. However, the private key escrow problem of these schemes makes them unsuitable in practical environments because the private key generator computes signer private key using signer public identity. Therefore, an untrusted/semitrusted private key generator may perform malicious activity on behalf of the signer. We took the advantage of certificateless public key cryptography and constructed a robust and efficient certificateless blind signature (CL‐BS) scheme using bilinear pairing. Furthermore, the probabilistic map‐to‐point hash function, which requires more computation time than the execution time of an elliptic curve scalar point multiplication, is circumvented in our scheme. We found that our scheme is unlinkable and provably secure against the adaptive chosen message and identity adversaries. From the perspective of computational costs, our scheme is more efficient and secure than other related schemes. Copyright © 2015 John Wiley & Sons, Ltd.
SK Hafizul Islam, Mohammad S. Obaidat
Secur. Commun. Networks1
2011 A more efficient and secure ID-based remote mutual authentication with key agreement scheme for mobile devices on elliptic curve cryptosystem
SK Hafizul Islam, G. P. Biswas
J. Syst. Softw.1