EDBT 2026 Demo / reviewers in the wild / expert
Pandi Vijayakumar
dblp:173/6785
· DBLP profile ↗
101ranked-venue papers
10as first author
69since 2021 · last 2026
0000-0001-5451-8946ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 37 · 30 since 2021Applied, interdisciplinary, general and emerging computing · 24 · 3 first-author · 19 since 2021Systems, architecture and hardware · 16 · 3 first-author · 8 since 2021Security and privacy · 13 · 4 first-author · 6 since 2021Artificial intelligence and machine learning · 6 · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3Databases, data management, data science and information retrieval · 2 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | EdgePivot: Adaptive and efficient privacy retrieval for personalized federated learning in the edge-cloud continuum
Huijie Yang, Jingang Li, Jian Shen 0001, Pandi Vijayakumar, Sivaraman Audithan, Varsha Arya, Brij B. Gupta |
Future Gener. Comput. Syst. | 4 |
| 2026 | Feature Information Separated Private Data Aggregation in IoT-Based Smart Grid SystemsabstractInternet of Things (IoTs) based smart grid systems require the implementation of diverse functionalities, data privacy protection, and lightweight solutions for terminal devices. Additionally, data aggregation plays a critical role within IoT-based smart grid systems. Currently, homomorphic encryption, a common data aggregation method, is widely adopted to safeguard personal data privacy. However, there are significant challenges associated with utilizing homomorphic encryption for smart grids. Firstly, homomorphic encryption can hinder the efficient processing capabilities of electric utilities, impacting the critical time required to meet specific functional requirements. Secondly, it imposes substantial computational overhead on edge devices, making it unsuitable for grid applications requiring practical, lightweight solutions. To address these barriers, we present a data aggregation scheme that is based on the separation of feature information. We initially employ the Horner’s rule aggregation method to aggregate users’ personal data before transmitting it to the control center, which can efficiently complete functions such as load forecasting and precise pricing by reverse engineering Horner parameters to obtain granular user data. In addition, we separate users’ individual electricity consumption data from their identity labels, using the Fisher-Yates Shuffle algorithm to shuffle the association between electricity consumption data and the corresponding user identity labels. This method ensures that the control center can only access granular electricity consumption data, without knowledge of the associated user identities. The security analysis demonstrates that the proposal effectively resists forgery, rollback, collusion, and eavesdropping attacks. Both theoretical and experimental analyses indicate that the computational overhead of this scheme on edge devices meets the practical requirements of power grid systems. Importantly, the experimental simulations indicate that our scheme improves the execution time of extended functions by a factor of 102and greater. Qingru Ma, Jian Shen 0001, Pandi Vijayakumar, Sivaraman Audithan, L. Jegatha Deborah |
IEEE Internet Things J. | 3 |
| 2026 | ABACPR: Attribute-Based Access Control Supporting Policy Reconstruction for Intent-Based NetworkingabstractWith the rapid advancement of Internet of Things (IoT) and the growing complexity of network infrastructures, the traditional network management model based on manual configuration is no longer able to meet the dynamic IoT secure communication requirements. Intent-based networking (IBN) significantly improves network manageability and agility by driving network automation through high-level business intent. However, policies in IBN are highly dynamic, and issues such as frequent changes in user intent, role or attribute adjustments, and ad-hoc access requirements in multi-tenant environments make it necessary for the system to quickly adapt to policy changes to ensure secure data sharing. Attribute-based encryption has become a key enabler for securing IoT communications, offering fine grained access control and adaptability to users’ dynamic access requirements in real time. In this paper, we propose an attribute-based access control supporting policy reconfiguration (ABACPR) for the highly dynamic nature of policies in IBN, aiming to improve the flexibility and efficiency of policy updating and ensure the security and consistency. Finally, We compared the theoretical and experimental analysis with related works and the results demonstrate that ABACPR is better suited for secure IoT communication in IBN. Tao Zhang 0117, Huijie Yang, Jian Shen 0001, Pandi Vijayakumar, Varsha Arya, Brij B. Gupta |
IEEE Internet Things J. | 4 |
| 2026 | Optimizing Bitcoin Privacy: Securing Mixing Scheme via MultisignatureabstractBitcoin mixing operations are essential for enhancing transaction privacy by obfuscating the link between transaction inputs and outputs. However, the transparency of blockchain transactions presents significant privacy risks, as transaction details are publicly recorded. To address these challenges, Bitcoin mixing operations are crucial for obfuscating the link between transaction inputs and outputs, thereby enhancing transaction privacy. Whereas, current mixing approaches are limited by several issues, including reliance on trusted third-party services, vulnerability to forgery by malicious participants, and suboptimal efficiency. In response to these challenges, we propose a decentralized Bitcoin mixing scheme named CoinMixMultiSig (CMMS). This scheme designs a two-round collaborative public address generation process, allowing participants to jointly create a public address and send their Bitcoin efficiently to this address before signing. This approach mitigates fraud risks, such as participants dropping out during the mixing process or maliciously altering transaction data, which could lead to asset loss. To enhance security and efficiency, CMMS incorporates a multi-signature mechanism that reduces the overall signature size. The multi-signature mechanism reduces computational and communication overhead, enhancing efficiency and practicality for real-world use. A rigorous security analysis demonstrates that CMMS ensures unforgeability and effectively resists rogue key attacks, providing a reliable and secure option for Bitcoin transactions. Tianqi Zhou, Mingdi Shen, Jian Shen 0001, Pandi Vijayakumar, Han-Chieh Chao |
IEEE Internet Things J. | 4 |
| 2026 | Blockchain-Assisted Conditional Anonymous Authentication and Adaptive Tree-Based Group Key Agreement for VANETsabstractVehicular ad-hoc networks (VANETs), considered a pivotal component of intelligent transportation systems (ITS), are susceptible to both established and emerging security vulnerabilities. However, existing authenticated key management schemes fail to provide effective conditional anonymity during decentralized authentication process. Meanwhile, scalable and reliable vehicular pseudonym management is absent, resulting in potential privacy leakage. Furthermore, conventional group key agreement schemes inherently fail to properly accommodate the highly dynamic topological characteristics of vehicular environments, which significantly limits their practical applicability. To address these challenges, the blockchain-assisted anonymous authentication and tree-based group key agreement design is proposed in this paper. Firstly, the pairing-free decentralized authentication mechanism is designed to enable mutual authentication between vehicles and roadside units (RSUs). Secondly, the threshold-varying pseudonym management system is designed, leveraging secret sharing and smart contracts to ensure conditional privacy preservation. This mechanism utilizes the multi-RSU consensus to recover the user's real identity, enabling traceability of malicious entities. Thirdly, the self-balancing tree-based group key agreement mechanism is proposed, optimizing key generation efficiency in dynamic vehicular environments. Crucial security requirements can be satisfied via the security analysis, whereas the performance evaluation substantiates the superiority of the proposed scheme over existing approaches. Haowen Tan, Jian Shen 0001, Pandi Vijayakumar, Sangman Moh, Q. M. Jonathan Wu |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | Unleashing Cross-Domain Potential: Side-Channel Analysis with Autoencoder for Domain AdaptationabstractDeep learning based side-channel analysis (DL-SCA) has achieved remarkable success in recovering cryptographic keys from embedded devices by exploiting physical leakages such as power consumption and electromagnetic emissions, posing a serious threat to the security of cryptographic implementations. However, a major challenge arises in cross-device attacks, where a model trained on profiling devices cannot be directly applied to attack a different device. This is because domain discrepancies emerge from variations in chip architecture, manufacturing, operational conditions, and data acquisition methods between these two devices. Many existing DL-SCA schemes have not adequately addressed the challenges posed by the differences. Therefore, we propose a novel cross-device SCA framework based on an autoencoder, which leverages the encoder—decoder architecture to align feature distributions across devices in the latent space while simultaneously preserving discriminative leakage features through the reconstruction process. To achieve this, Maximum Mean Discrepancy (MMD) is integrated into the loss function and applied to the latent representations, effectively narrowing the distribution gap between profiling and attack devices. Operating in the latent space allows our approach to avoid the training instability of adversarial methods and provides an efficient end-to-end solution for domain alignment. Building on this framework, we further introduce three multi-domain adaptation methods. Experimental results, evaluated in terms of Partial Guessing Entropy (PGE), demonstrate that cross-device attacks can be effectively executed even with device discrepancies, with most keys being successfully recovered within 1,000 traces. Moreover, the proposed adaptation techniques significantly reduce the number of traces required for successful key recovery. Haowen Tan, Jian Shen 0001, Pandi Vijayakumar, Sangman Moh, Q. M. Jonathan Wu |
ACM Trans. Embed. Comput. Syst. | 4 |
| 2026 | An Efficient iTreeKEM-Based Group Key Agreement Protocol for Flying Ad-Hoc NetworksabstractAs Flying Ad-hoc Network (FANET) evolves toward larger scales and higher levels of autonomy, the importance of secure and efficient group communication continues to grow. However, resource-constrained unmanned aerial vehicles (UAVs) face dual challenges: limited computational power struggles to meet the high demands of complex cryptographic algorithms, while bandwidth constraints exacerbate communication overhead caused by multi-round interaction mechanisms. Moreover, existing solutions find it hard to support dynamic group environments and are prone to single point of failure (SPoF) in centralized architectures, which significantly compromises system reliability and scalability. To address these issues, this paper proposes a novel key agreement protocol for FANET. The protocol employs an improved tree-based key encapsulation mechanism (iTreeKEM) to support rapid key updates in highly dynamic environments. It reduces the computational cost for each group member by 90.08% even when the group size reaches 128. To further enhance system robustness, the protocol introduces a smart contract-based distributed leader election mechanism, effectively eliminating SPoF. The security of the proposed protocol is guaranteed by the CDH problem under the generalized selective decryption (GSD) model. Finally, we implement the protocol in NS-3 simulations, and the results demonstrate its effective applicability to FANET. Tianqi Zhou, Shijia Hong, Jian Shen 0001, Md. Zakirul Alam Bhuiyan, Pandi Vijayakumar, Debiao He |
IEEE Trans. Mob. Comput. | 5 |
| 2025 | An Efficient Group Key Agreement Scheme With Antenna Hardware Implementation in VANETsabstractVehicular ad-hoc networks (VANETs) have become the predominant technology in the current era. Although VANETs have numerous benefits, they are prone to different types of attacks owing to their open nature. Therefore, security plays a crucial role in VANET systems. Ensuring a safe and dependable vehicular communication system is crucial when performing anonymous authentication and group key agreement. Many related works have been proposed based on signature aggregation and group key management; however, they suffer from high computational and communication costs. Hence, in this work, signature aggregation scheme is proposed in such a way that the computational overhead is significantly reduced. Moreover, an ECC-based group management scheme is proposed to secure group communication. In comparison to recent works, the proposed work generates and verifies signatures with an efficiency of 50.03% and 26.26%, respectively. Furthermore, 72.32% and 35.45% efficient in terms of transmission overhead and serving ratio when compared to recent works. To validate this work practically, printed antenna consisting of four elements arranged in a linear array is developed for the intended use. Security analysis is performed in formal and informal ways to prove the security strength of the proposed method. Finally, the performance is validated with similar works using the Cygwin platform with the PBC library. Maria Azees, Arun Sekar Rajasekaran, Kalyan Sundar Kola, Pandi Vijayakumar, Fayez Alqahtani 0001, Amr Tolba |
IEEE Internet Things J. | 4 |
| 2025 | Three-factor authentication and key agreement protocol with collusion resistance in VANETs
Guanlin Pan, Haowen Tan, Wenying Zheng, Pandi Vijayakumar, Q. M. Jonathan Wu, Sivaraman Audithan |
J. Inf. Secur. Appl. | 4 |
| 2025 | Blockchain-Enabled Secure Collaborative Model Learning Using Differential Privacy for IoT-Based Big Data AnalyticsabstractWith the rise of Big data generated by Internet of Things (IoT) smart devices, there is an increasing need to leverage its potential while protecting privacy and maintaining confidentiality. Privacy and confidentiality in big data aims to enable data analysis and machine learning on large-scale datasets without compromising the dataset sensitive information. Usually current big data analytics models either efficiently achieves privacy or confidentiality. In this article, we aim to design a novel blockchain-enabled secured collaborative machine learning approach that provides privacy and confidentially on large scale datasets generated by IoT devices. Blockchain is used as secured platform to store and access data as well as to provide immutability and traceability. We also propose an efficient approach to obtain robust machine learning model through use of cryptographic techniques and differential privacy in which the data among involved parties is shared in a secured way while maintaining privacy and confidentiality of the data. The experimental evaluation along with security and performance analysis show that the proposed approach provides accuracy and scalability without compromising the privacy and security. Prakash Tekchandani, Abhishek Bisht, Ashok Kumar Das, Neeraj Kumar 0001, Marimuthu Karuppiah, Pandi Vijayakumar, Youngho Park 0005 |
IEEE Trans. Big Data | 6 |
| 2024 | A Flexible and Verifiable Keyword PIR Scheme for Cloud-Edge-Terminal Collaboration in AIoTabstractAs a cloud storage side in the cloud-edge-terminal collaboration, which empowers the artificial intelligence of things (AIoT), the accuracy of data retrieval and data privacy in the cloud can significantly impact the quality of service in AIoT. Typically, the cloud facilitates data sharing through keyword-based private information retrieval (PIR). However, these keywords may contain the privacy of patients, causing the server to gain patients privacy during database retrieval, resulting in privacy exposure. Concurrently, malicious users seek to access more datasets than those corresponding to the keywords. It is worth to consider the construction of a secure and private retrieval system in AIoT. To protect the privacy of AIoT, this paper proposes two multi-keyword PIR schemes: the fuzzy multi-keyword PIR scheme and the fine-grained flexible multi-keyword PIR scheme. The fuzzy multi-keyword PIR scheme utilizes the proposed batch oblivious pseudo-random function (B-OPRF) based on OTEn1 to implement the batch search. If one of the n keywords in a dataset matches a requested keyword, the corresponding datasets are returned to the user, achieving fuzzy retrieval. The fine-grained flexible multi-keyword PIR scheme incorporates the proposed batch flexible OPRF (BF-OPRF) algorithm, wherein k out of the n keywords in the dataset must match the k requested keywords from users for the corresponding datasets to be returned to the user. Additionally, the cloud server may tamper with the data, and the correctness of the data is periodically verified using a verifiable mechanism. The effectiveness and performance of the proposed schemes are validated through experiments and theoretical analysis. Huijie Yang, Wenying Zheng, Tao Zhang 0117, Pandi Vijayakumar, Brij B. Gupta, Varsha Arya, Mary Subaja Christo |
IEEE Internet Things J. | 4 |
| 2024 | A Robust ECC-Based Authentication and Key Agreement Protocol for 6G-Based Smart Home EnvironmentsabstractWith the rapid evolution of wireless communication technology, smart homes have significantly improved the quality of peoples daily lives by taking advantage of the low latency and high transmission rates of 6G communication technology. Users can now conveniently manage the consumer electronics remotely. However, in the pratical smart home scenarios, the users and consumer electronics communicate with each other through an open public channels where charted and uncharted security risks and privacy vulnerabilities exist. To protect users confidential data from malicious interception and modification, diverse authentication protocols have been proposed so far. However, existing protocols often suffer from efficiency issues or vulnerabilities to known attacks. To address these challenges, this paper proposes a novel three-factor ECC-based anonymous authentication protocol. The protocols security properties can be rigorously proven using the formal analysis under the ROR model. Subsequently, the resistance to numerous types of attacks, including man-in-the-middle and replay attacks, can be demonstrated through informal analysis and the AVISPA verification process. Finally, the protocol is compared with the state-of-the-arts and the results show that the protocol strikes a good balance between security and efficiency and is well suited for smart home environments. Minghua Yuan, Haowen Tan, Wenying Zheng, Pandi Vijayakumar, Fayez Alqahtani 0001, Amr Tolba |
IEEE Internet Things J. | 4 |
| 2024 | Two-Phase Sparsification With Secure Aggregation for Privacy-Aware Federated LearningabstractAs a typical privacy-aware machine learning paradigm, federated learning (FL) provides facilities to individually train edge clients with their private data and aggregate the central global model. In this way, privacy leakage can be prevented. Massive communication overhead caused by exchanging updated weights between clients and the server is one of the main obstacles in this strategy. Prior work advocates compressing the weights by employing quantization, gradient sparsification, and knowledge distillation approaches. However, most of them cannot be readily applied to secure aggregation in privacy-aware FL. Some research has made great progress in directly utilizing benchmark secure aggregation protocols on top of the non-privacy-aware FL. Graph-based and gradient-based sparsification has been widely adopted in previous studies. However, the results of reducing communication costs are still unsatisfactory. In this paper, we present a novel communication-efficient privacy-ware FL algorithm from a distinct perspective. We design a new Two-Phase Sparsification with Secure Aggregation (TPSSA) algorithm. In the subnetwork phase, we identify sparse subnetworks by freezing the initial random weights in sufficiently overparametrized networks. All edge clients collaboratively train to discover their subnetwork inside a dense randomly weighted neural network. Then the server aggregates to compute the global model. In the gradient phase, for each pair of edge clients, we introduce pairwise multiplicative random masks to identify the sparsification pattern. Then updates from surviving clients can be correctly cancelled out during the aggregation process in the server. Theoretical analysis reveals convergence, privacy and performance guarantee. We show improvements in accuracy, communication, and computation over traditional and sparsified secure aggregation benchmarks on two real-world datasets. Xiong Li 0002, Wei Liang 0005, Pandi Vijayakumar, Fayez Alqahtani 0001, Amr Tolba |
IEEE Internet Things J. | 4 |
| 2024 | Deep Fingerprinting Data Learning Based on Federated Differential Privacy for Resource-Constrained Intelligent IoT SystemsabstractWith the rapid integration of Internet of Things (IoT) devices and artificial intelligence (AI) function, the data management and privacy issue has drawn great attentions in intelligent IoT systems where communication infrastructures frequently exchange open data flows over the air. Therefore, lightweight and private access over radio communication pipes becomes a critical but challengeable need for resource-constrained IoT devices due to the limited memory capacity, computing, and energy consumption. In this article, we develop the concept of deep federated scattering fingerprinting aided by differential privacy (DFSF-DP) in which a deep fingerprinting data learning network exploits fingerprinting data to realize lightweight intelligent access and incorporates federated learning with differential privacy to guarantee the data privacy in a way of distributed training. Particularly, first, we employ a wavelet scattering network for the efficient radio frequency fingerprinting (RFF) feature extraction and construct a high information density database. Subsequently, the implementation of distributed learning minimizes the demand for computing resources, by exploiting the full potential of edge and cloud nodes to aggregate the global model. To bolster the data privacy and security, adaptive clipping and gradient noising are incorporated into DFSF-DP. Experimental results demonstrate that DFSF-DP obtains outstanding performance and achieves equivalent advancements while utilizing a mere 25% of the original data set. Moreover, it attains a 93% identification accuracy with 0.1 noise multiplier which confirms the remarkable performance of DFSF-DP while upholding privacy and security considerations. Dongyang Xu 0003, Pandi Vijayakumar, Yongxin Zhu 0001, Amr Tolba |
IEEE Internet Things J. | 4 |
| 2024 | Side-Channel Attacks Based on Multi-Loss Regularized Denoising AutoEncoderabstractRecently, researchers have leveraged the Denoising AutoEncoder (DAE) to reduce the noise in side-channel acquisitions (a.k.a. traces) that reduces the effectiveness of key recovery. Taking the${L}2$Loss (Mean Square Error, MSE) as the objective function of the DAE, it only aims to lessen the Euclidean Distance (ED) between the input and output, overlooking the Intra-Data Correlation (IDC) of the trace which includes the timing information. This paper proposes the Multi-Loss Regularized Denoising AutoEncoder (ML-DAE) framework to improve the generalization capability of the DAE. This framework consists of a shared DAE and Multiple Loss (ML) functions that aim to reduce the noise while preserving the excellent IDC of the output. During the training phase, to avoid issues of overfitting and a high number of training parameters, we pre-train the DAE using MSE and then initiate the ML-DAE which contains a multicore Partial Loss (PL) function with parameters transferred from the pre-trained DAE. During the testing phase, the outputs from the multicore PL are fused using an average pooling layer to yield the final predictions. The experiments on highly noisy datasets (XMEGA_ME, DPA_V2, and AES_GPU) and the masked dataset ASCAD demonstrate that ML-DAE achieves an SNR gain of at least four times, hence Deep-Learning based Side-Channel Attacks (DLSCAs) and Template Attacks (TA) with denoising pre-processing reduce of the number of traces needed to recover the key in the attack phase by more than 55%. Fanliang Hu, Jian Shen 0001, Pandi Vijayakumar |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | A Robust Privacy-Preserving Data Aggregation Scheme for Edge-Supported IIoTabstractEdge-supported Industrial Internet of Things (IIoT) has received remarkable attention recently since edge computing can not only reduce bandwidth consumption but also decrease the response time of industrial systems. However, the sensed data in the industrial environment is considered private. Thus, the data cannot be directly aggregated at the server due to privacy leakage. Although several privacy-preserving-aggregated schemes have been proposed, their security goals are not strong enough. Besides, most schemes are inefficient for resource-constrained devices. Aiming at solving the abovementioned problems, this article proposes a robust privacy-preserving data aggregation scheme for edge-supported IIoT. Specifically, the scheme adopts the Paillier cryptosystem to protect the privacy of users. Additionally, it utilizes ECDSA signature to support batch verification of multiple signatures from different signers, which significantly improves efficiency. Security analysis shows that the proposed scheme not only guarantees the integrity of the data and mutual authentication among entities but also realizes differential privacy protection. Extensive experiments are conducted to compare our scheme with the related work. The results show that our method outperforms most of the compared schemes with respect to communication. Moreover, compared with the related work, our scheme reduces the computational cost by an average of 6.7%, 16.9%, and 27.8% in sensor, edge server, and control center sides, respectively. Shuai Shang, Xiong Li 0002, Ke Gu 0002, Lei Li 0031, Xiaosong Zhang 0001, Pandi Vijayakumar |
IEEE Trans. Ind. Informatics | 6 |
| 2024 | A Two-Stage Differential Privacy Scheme for Federated Learning Based on Edge IntelligenceabstractThe issue of data privacy protection must be considered in distributed federated learning (FL) so as to ensure that sensitive information is not leaked. In this article, we propose a two-stage differential privacy (DP) framework for FL based on edge intelligence. Various levels of privacy preservation can be provided according to the degree of data sensitivity. In the first stage, the randomized response mechanism is used to perturb the original feature data by the user terminal for data desensitization, and the user can self-regulate the level of privacy preservation. In the second stage, noise is added to the local models by the edge server to further guarantee the privacy of the models. Finally, the model updates are aggregated in the cloud. In order to evaluate the performance of the proposed end-edge-cloud FL framework in terms of training accuracy and convergence, extensive experiments are conducted on a real electrocardiogram (ECG) signal dataset. Bi-directional long-short-term memory (BiLSTM) neural network is adopted to training classification model. The effect of different combinations of feature perturbation and noise addition on the model accuracy is analyzed depending on different privacy budgets and parameters. The experimental results demonstrate that the proposed privacy-preserving framework provides good accuracy and convergence while ensuring privacy. Li Zhang 0096, Jianbo Xu, Sivaraman Audithan, L. Jegatha Deborah, Pradip Kumar Sharma, Pandi Vijayakumar |
IEEE J. Biomed. Health Informatics | 6 |
| 2024 | Hybrid CMOS Memristor Based Biometric OBU Authentication and Anonymous Mutual Authentication for Secure Communication in Fog-Based VANETsabstractThe progression of cloud computing, IoT technologies, and intelligent transportation systems has accelerated the speedy growth of vehicular ad-hoc networks (VANETs). Recently, attempts have been made to merge fog computing with VANETs to meet the needs of the real world, such as mobility, low transmission delay, etc. In this work, the VANET system is divided into several fog domains to reduce the burden on the central cloud server. Moreover, hybrid CMOS memristor-based biometric authentication is introduced to ensure only registered users can enable the OBU for making communications in VANETs. The proposed work achieves anonymous mutual authentication to validate the legitimacy and privacy of vehicle users while making communications in VANETs. The formal and informal security analyses are given in this paper to prove that the proposed work encounters the necessities of security in fog-based vehicular ad-hoc networks. In addition, the security of the proposed work is evaluated using the Scyther tool to show that the proposed scheme is highly robust against various attacks. Finally, we conduct a performance evaluation of the proposed work with other related works. The findings indicate that, in comparison to other related works, the proposed work offers a better trade-off between security and performance. Maria Azees, Arun Sekar Rajasekaran, Pandi Vijayakumar, Marimuthu Karuppiah |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2023 | SD-Transformer: A System-Level Denoising Transformer for Encrypted Traffic Behavior IdentificationabstractEncrypted behavior identification is crucial in ensuring network security. Most existing solutions in this area recognize behavior by observing encrypted traffic patterns between users and applications. However, such solutions rely on features such as timing, packet sequence, and packet length, which may be affected by network fluctuations, and thus have weak generalization capabilities. In this paper, we first analyze the impact of noise on the network, such as parameters and network delays during API requests. By combining a noise-based traffic collector with an improved Transformer model, we propose a system-level denoising Transformer method for encrypted traffic behavior identification called SD-Transformer. It is able to filter system noise by utilizing an attention mechanism and targeted noise packet masking. We evaluate the performance of SD-Transformer on three datasets, i.e., ISCX-VPN, USTC-TFC, and our generated noise-containing Web Application Traffic dataset (WEB-APP), and it achieves an accuracy of 95.97%, 93.59%, and 99.82%, respectively. Besides, compared to the state-of-the-art methods, the accuracy is increased to 96.82% (↑16.0%) and 85.41% (↑17.76%) on the WEB-APP dataset under different API parameters and network latency environments, respectively. Additionally, the target mask of the SD-Transformer achieves 96.45% accuracy with an improvement of 11.29% on the WEB-APP dataset with latency. Yizhuo Zhao, Yukun Zhu, Xiong Li 0002, Rui-dong Chen, Mohammad S. Obaidat, Pandi Vijayakumar |
GLOBECOM | 6 |
| 2023 | Ubiquitous intelligent federated learning privacy-preserving scheme under edge computing
Jinshan Lai, Ruijin Wang, Xiong Li 0002, Pandi Vijayakumar, Brij B. Gupta, Wadee Alhalabi |
Future Gener. Comput. Syst. | 5 |
| 2023 | A privacy-preserving logistic regression-based diagnosis scheme for digital healthcare
Yousheng Zhou, Liyuan Song, Yuanni Liu, Pandi Vijayakumar, Brij B. Gupta, Wadee Alhalabi, Hind Alsharif |
Future Gener. Comput. Syst. | 4 |
| 2023 | Edge-Assisted Intelligent Device Authentication in Cyber-Physical SystemsabstractCyber–physical system (CPS) provides a foundation for the Industrial Internet of Things (IIoT) that interconnects all types of devices. The integration of CPS with IIoT generates the large volumes of data forcing the development of artificial intelligence (AI) to extract information more precisely. Nevertheless, the increasing volume/variety of data traffic and the ever-growing number of IIoT devices bring great challenges for the host-centric communication model of the current Internet. In this work, we present a novel information-centric networking (ICN)-based system model in CPS, which enables processing data from IIoT devices closer to the edge as opposed to a content provider. Based on this ICN system model, we propose an edge-assisted authentication scheme in CPS, aiming to protect the system from unauthorized access and reduce workload for resource-constrained devices. The main features of our scheme include a delegation model of security operations and session handshake procedures through edge routers, addressing the rising challenges in managing and securing IIoT devices in the ICN. We formally prove the security of our scheme and conduct performance analysis to show its practicality. Yanrong Lu, Ding Wang 0002, Mohammad S. Obaidat, Pandi Vijayakumar |
IEEE Internet Things J. | 4 |
| 2023 | SAPFS: An Efficient Symmetric-Key Authentication Key Agreement Scheme With Perfect Forward Secrecy for Industrial Internet of ThingsabstractAn edge-cloud Industrial Internet of Things (IIoT) can help meet the computing requirements of industrial applications, particularly in time and latency-sensitive services. Ensuring the security and privacy of (sensitive) information collected by IIoT end devices is crucial, and has an important impact on the decision making as well as operational safety. However, these devices are energy constrained and vulnerable to corruption. The authentication schemes suitable for this environment need to be lightweight, efficient, and concise. In this article, we propose a symmetric-key authentication scheme with a perfect forward secrecy (SAPFS), which relies on both authentication and derivation master keys. The SAPFS scheme uses only XOR operation and hash function to achieve mutual authentication, key exchange, and message integrity. On the condition of the irreversible hash function and indistinguishable master keys, we demonstrate that SAPFS is provably secure under the random oracle model. Finally, a comparative summary with three other competing schemes (in terms of communication cost, storage requirement, and computation complexity) demonstrates its utility. Yunru Zhang, Debiao He, Pandi Vijayakumar, Min Luo 0002, Xinyi Huang 0001 |
IEEE Internet Things J. | 3 |
| 2023 | Efficient identity-based multi-copy data sharing auditing scheme with decentralized trust management
Haowen Tan, Jian Shen 0001, Pandi Vijayakumar, Brij B. Gupta, Varsha Arya |
Inf. Sci. | 4 |
| 2023 | Machine learning and smart card based two-factor authentication scheme for preserving anonymity in telecare medical information system (TMIS)
Brij B. Gupta, Varun Prajapati, Nadia Nedjah, Pandi Vijayakumar, Ahmed A. Abd El-Latif 0001, Xiaojun Chang |
Neural Comput. Appl. | 4 |
| 2023 | A Deep Learning-based Fast Fake News Detection Model for Cyber-Physical Social Services
Zhiwei Guo 0004, Yanyan Zhu, Pandi Vijayakumar, Aniello Castiglione, Brij B. Gupta |
Pattern Recognit. Lett. | 4 |
| 2023 | AKN-FGD: Adaptive Kohonen Network Based Fine-Grained Detection of LDoS AttacksabstractLow-rate denial of service (LDoS) attacks exploit the security vulnerabilities of network protocols adaptive mechanisms to launch periodic bursts. These attacks result in the severe destruction of the quality of service of TCP applications. Therefore, detection of LDoS attacks is a concern among scientific communities. However, the existing coarse-scale detection methods yield poor detection performance and adaptability. To achieve the accurate detection of LDoS attacks, an adaptive Kohonen Network based fine-grained detection (AKN-FGD) model for LDoS attacks is proposed. Based on the burst and periodicity characteristics of attack traffic, the Smith-Waterman (SW) algorithm is used to estimate the pulse period, which is the length of the detection unit. Subsequently, cluster analysis is performed for each detection unit using the adaptive Kohonen network (AKN) algorithm because the discreteness of traffic suffering from LDoS attacks is more pronounced than that of legitimate traffic. Finally, the existence of LDoS attacks can be verified in view of a novel decision metric, denoted as the anomaly degree, based on the clustering results. We conducted experiments not solely in traditional networks using NS3 and in a test-bed environment but also in a software-defined network (SDN), with accuracies of 99.7%, 99.8%, and 95.6% for detecting LDoS bursts, respectively. The experimental results show that the AKN-FGD scheme not only enables accurate fine-grained detection, that is, it can detect every attack burst, but also estimates the start and end times of the attacks. Moreover, we have compared the AKN-FGD scheme with some other detection methods, and a comparison of the results show that our proposed approach displays better detection performance. Dan Tang 0003, Xiyin Wang, Xiong Li 0002, Pandi Vijayakumar, Neeraj Kumar 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | A Multinode Collaborative Decision-Making Scheme for Privacy Protection in IIoTabstractIndustry 5.0 is more focused on sustainability, people-centredness, and resilience. The Industrial Internet of Things (IIoT) enable real-time monitoring of equipment status through sensors deployed in dangerous environments to reduce the probability of hazards. However, the devices are vulnerable to malicious attackers or can be tampered with during the transmission of information. Security has therefore become a major concern in the IIoT. In this article, we propose a privacy-preserving multinode collaborative decision-making scheme in IIoT to ensure the validity and integrity of data under the IIoT. This collaborative decision-making solution primarily uses voting to enable accurate monitoring of sensing devices. The scheme is designed based on an efficient aggregate signature and gives a formal proof of security based on the computational Diffie–Hellman problem (CDHP). The final performance analysis phase gives a detailed presentation of the computational overhead of each phase of the protocol. Mengya Chen, Wenying Zheng, Pandi Vijayakumar, Mamoun Alazab, Sivaraman Audithan |
IEEE Trans. Ind. Informatics | 3 |
| 2023 | Privacy-Preserving Federated Learning for Internet of Medical Things Under Edge ComputingabstractEdge intelligent computing is widely used in the fields, such as the Internet of Medical Things (IoMT), which has advantages, including high data processing efficiency, strong real-time performance and low network delay. However, there are many problems including privacy disclosure, limited calculation force, as well as scheduling and coordination issues. Federated learning can greatly improves training efficiency. However, due to the sensitive nature of the healthcare data, the aforementioned approach of transferring the patient's data to the servers may create serious security and privacy issues. Therefore, this article proposes a Privacy Protection Scheme for Federated Learning under Edge Computing (PPFLEC). First of all, we propose a lightweight privacy protection protocol based on a shared secret and weight mask, which is based on a random mask scheme of secret sharing. It is more accurate and efficient than,homomorphic encryption. It can not only protect gradient privacy without losing model accuracy, but also resist equipment dropping and collusion attacks between devices. Second, we design an algorithm based on a digital signature and hash function, which achieves the integrity and consistency of the message, as well as resisting replay attacks. Finally, we propose a periodic average training strategy, compared with differential privacy to prove that our scheme is 40 % faster in efficiency than in deferential privacy. Meanwhile, compared with federated learning, we can achieve the same efficiency under the condition of ensuring safety. Therefore, our scheme can work well in unstable edge computing environments such as smart healthcare. Ruijin Wang, Jinshan Lai, Xiong Li 0002, Pandi Vijayakumar, Marimuthu Karuppiah |
IEEE J. Biomed. Health Informatics | 5 |
| 2023 | Certificateless Public Auditing Scheme With Data Privacy and Dynamics in Group User Model of Cloud-Assisted Medical WSNsabstractWith the application of wireless sensor network (WSN) in healthcare field, online sharing of medical data has attracted more and more attention. However, wearable sensor nodes are limited in energy, storage space and data processing capacity, which largely restricts their deployment in resource demand application scenarios. Fortunately, cloud storage services can enrich the capabilities of wearable sensors and provide an effective method for people to share data within a group. However, as medical data directly relates to patients' health and privacy information, ensuring the integrity and privacy of medical records stored in cloud servers becomes a key issue to be urgently solved. Many public data auditing schemes have been put forward to address the above issues. Unfortunately, most of them have security vulnerabilities or poor functionality and performance. In this paper, we come up with a secure and efficient certificateless public auditing scheme for cloud-assisted medical WSNs, which not only supports dynamic data sharingand privacy protection, but also achieves efficient group user revocation. Security analysis and performance evaluation demonstrate that our scheme significantly reduce the total computation cost while achieving a higher security level. Compared with other related schemes, our new proposal is more suitable for group user data sharing in cloud-assisted medical WSNs. Zhiyan Xu, Debiao He, Pandi Vijayakumar, Brij B. Gupta, Jian Shen 0001 |
IEEE J. Biomed. Health Informatics | 3 |
| 2023 | Secure and Efficient Authenticated Key Management Scheme for UAV-Assisted Infrastructure-Less IoVsabstractNowadays, with the purpose of fulfilling the increasing demands for emerging extensive and ubiquitous accessibility to modern intelligent transportation systems (ITS), the conventional vehicle-to-everything (V2X) paradigms are progressively evolving into the Internet of vehicles (IoVs). As of now, substantial enhancements in IoV technologies have been witnessed, particularly in the era of vehicular data secure exchange and user privacy protection. On the other hand, unmanned aerial vehicles (UAVs) are envisioned to provide scalable and adaptive stereoscopic service coverage for IoV implementations. However, the existing approaches intended for the common scenarios mainly rely on the well-established local IoV infrastructures, whereas the specific infrastructure-less IoVs with dysfunctional edge facilities have not been properly investigated. Additionally, the related UAV-assisted IoV schemes still fail to independently perform the secure vehicular data transmission but rather as the auxiliary strategies due to the dependence on the assistance of local edge deployment. Therefore, the practical requirements of reliability and scalability in real-world IoV circumstances cannot be satisfied. In this paper, an efficient UAV certificateless group authentication mechanism is developed in order to facilitate the secure data transmission of infrastructure-less IoV. The proposed design deploys the tethered UAV (TUAV) as the specific mobilized base station so that the active edge IoV infrastructure is not needed. The security analysis regarding the key security features are presented first, followed by the performance evaluation. According to the comparison results with the existing designs, improvements in terms of computational cost and communication overhead for different phases can be demonstrated. Haowen Tan, Wenying Zheng, Pandi Vijayakumar |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2023 | An Efficient Vehicle-Assisted Aggregate Authentication Scheme for Infrastructure-Less Vehicular NetworksabstractIn recent years, growing research interest from both industry and academia has been aroused to the vehicular networks, which is regarded as the fundamental component of the modern intelligent transportation system (ITS). Lots of remarkable research outputs with respect to secure vehicular data interactions and user privacy preservation has been witnessed. However, the existing schemes all focus on the common vehicular communication scenarios where facilities are deployed, whereas the secure data exchange in the abnormal infrastructure-less vehicular environment has not been properly investigated. To deal with unpredictable abnormal situations caused by artificial or natural disasters such as earthquakes and floods, a distinctive vehicle-assisted aggregate authentication mechanism for infrastructure-less vehicular networks is presented in this paper. With assistance from the neighboring vehicles, the homomorphic signature involving all requesting vehicles is generated and forwarded to the remaining functional RSUs. Meanwhile, vehicular group communication among the validated entities is enabled. Additionally, the fault-tolerant verification method is adopted such that the ineffective entities can be easily distinguished and removed without interfering with other requesting vehicles. The security proofs and discussions regarding vital security properties are presented, while the performance analysis follows. Compared with the state-of-the-art, advantages in terms of security and performance properties can be proved. Haowen Tan, Wenying Zheng, Pandi Vijayakumar, Kouichi Sakurai, Neeraj Kumar 0001 |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2023 | Attribute-Based Secure Data Aggregation for Isolated IoT-Enabled Maritime Transportation SystemsabstractWith global economic integration, transnational trade plays an important role, and maritime transportation is one of the important means of freight transportation. It is of great significance to build a secure and efficient maritime transportation system (MTS). The introduction of Internet of things technology makes MTS more perfect. The IoT-enabled MTS is composed of marine terminals and on-board sensors, land-based data centers and base stations, as well as satellite networks. Many researchers have carried out significant work to aggregate data in MTS. However, because the terrestrial base stations cannot cover most of the sea area, the isolated maritime terminals, those who drive to the area without base station coverage, need the assistance of satellite networks to complete the contact with the data center. In this paper, we propose an attribute based secure data aggregation scheme for isolated IoT-enabled MTS. In the novel scheme, the constant attributes of a maritime terminal are utilized to generate its certification. In addition, on-board sensors are introduced in the system to help aggregate the status and surrounding environment of the maritime terminal. These monitoring data are encrypted by the sensors and transmitted to the data center for the trustworthiness evaluation of the isolated maritime terminal. Besides, the zero-knowledge proof is utilized to confirm the legitimacy of participating users. What's more, the security analysis and the simulation results show that the novel scheme is secure and efficient for IoT-enabled MTS. Chen Wang 0015, Jian Shen 0001, Pandi Vijayakumar, Brij B. Gupta |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2023 | Nondeterministic Evaluation Mechanism for User Recruitment in Mobile Crowd-SensingabstractBased on the Internet of Behavior (IoB), mobile crowd-sensing (MCS) utilizes the Internet of Things (IoT) to recruit users by analyzing behavioral patterns. MCS is widely used in numerous large-scale and complex monitoring services, but it cannot provide stable and high-quality services due to nondeterministic user mobility and behaviors, which has a vital impact on recruiting high-quality users. In this article, a stochastic semi-algebraic hybrid system (SSAHS) model is constructed to characterize the user mobility and behaviors of the MCS systems. Based on the definition of probabilistic path and task execution rate, a nondeterministic evaluation mechanism is proposed to measure nondeterministic user mobility and behaviors and to give the probability of the user completing the MCS task under the specified time bound and space conditions. The greater the probability is, the higher the quality of the user. Furthermore, a user recruitment scheme based on a nondeterministic evaluation mechanism (NUR) is developed. The NUR employs historical user data to predict user mobility and behaviors; high-quality users are recruited to quickly upload reliable sensing data. We conduct simulation experiments based on a real-world user trace dataset, Geolife.The results show that compared with competing recruitment strategies, NUR achieves a higher quality of service for the same MCS sensing tasks. Ying Xie 0008, Mohammad S. Obaidat, Xiong Li 0002, Pandi Vijayakumar |
ACM Trans. Sens. Networks | 5 |
| 2022 | A Privacy-preserving Data Transmission Protocol with Constant Interactions in E-healthabstractIn recent years, to improve the quality of medical services in e-health systems, various types of sensors supporting collection and online/offline consultation have appeared in life; effectively facilitating doctors' disease prediction and consultation. However, data in e-health systems come from a wide range of sources and are mostly related to patient privacy. Therefore, how to ensure patient privacy and data confidentiality in data transmission is considered serious issues. In addition, the storage volume of cloud servers continues to grow, and how to guarantee that servers can quickly respond to requests has become a pressing problem. To this end, a privacy-preserving data trans-mission protocol is proposed, which only needs constant times interactions to complete the batching requests. In particular, a lightweight OTnk protocol is designed, employing the idea of matrix transformation, which effectively reduces the number of interactions while protecting the privacy of both communicating parties. The security and performance analysis indicate that the proposed protocol can be instantiated in e-health with high security and efficiency. Huijie Yang, Jian Shen 0001, Mohammad S. Obaidat, Pandi Vijayakumar, Kuei-Fang Hsiao |
GLOBECOM | 4 |
| 2022 | RAKI: A Robust ECC Based Three-party Authentication and Key Agreement Scheme for Medical IoTabstractWith its advantages are gradually emerging, the Internet of Things (IoT) is profoundly changing the way people work and live. Among all IoT applications, medical IoT is partic-ularly important, in which the user can communicate with smart medical device through the hospital gateway node. However, due to the inherent defects of these smart devices and the openness of wireless networks, medical IoT is vulnerable to kinds of attacks, such as impersonation attack and password guessing attack. Unfortunately, there are few authentication schemes for medical IoT at present, while existing three-party schemes have various weakness and are not suitable for medical IoT. Given the sensitivity of patient data and the deadly consequences of attacks on medical devices, there is an urgent need to develop a suitable authentication scheme in Medical IoT Network with high security. To alleviate the above problems, a robust ECC based three-party authentication and key agreement scheme for medical IoT(RAKI) has been proposed, which is secure with random oracle model and the informal security analysis. Besides, the performance comparisons against existing competing three-party schemes indicate that our scheme is efficient for medical IoT. Yousheng Zhou, Lunhao Li, Mohammad S. Obaidat, Yuanni Liu, Pandi Vijayakumar, Kuei-Fang Hsiao |
GLOBECOM | 5 |
| 2022 | Secure biometric-based access control scheme for future IoT-enabled cloud-assisted video surveillance system
Palak Bagga, Ankush Mitra, Ashok Kumar Das, Pandi Vijayakumar, Youngho Park 0005, Marimuthu Karuppiah |
Comput. Commun. | 4 |
| 2022 | FTPS: Efficient fault-tolerant dynamic phrase search over outsourced encrypted data with forward and backward privacyabstractSummary With the popularity of cloud computing, more and more users store sensitive information in cloud servers. In order to protect the data over the cloud server, symmetric encryption with keyword search has been developed and the phrase search has been proposed subsequently to overcome the inefficiency produced by single/multi‐keyword search. However, most existing phrase search schemes fails to support fault‐tolerant search which is essential to users. Therefore, this paper proposes a fault‐tolerant dynamic phrase search scheme with forward privacy and backward privacy (FTPS). Piecewise Linear Chaotic Map and minhash function are used to blur information, and Bloom filter based index is constructed to realize efficient search and dynamic update simultaneously. Security analysis proves that FTPS can properly preserve the privacy of search user, and experimental results show that FTPS is practical. Yousheng Zhou, Pandi Vijayakumar |
Concurr. Comput. Pract. Exp. | 3 |
| 2022 | A location-based privacy-preserving oblivious sharing scheme for indoor navigation
Huijie Yang, Pandi Vijayakumar, Jian Shen 0001, Brij B. Gupta |
Future Gener. Comput. Syst. | 2 |
| 2022 | A PUF-based lightweight authentication and key agreement protocol for smart UAV networksabstractAbstract With the advancement of information technology and the reduction of costs, the application of unmanned aerial vehicle (UAV) has gradually expanded from the military field to the industrial field and civilian field. It brings great convenience to people in surveillance, detection, transportation, emergency rescue etc. However, UAVs usually work in harsh natural environments, and their communication security confronts various challenges. Due to UAVs' limited resources, such as computing capability, storage space, and energy, traditional security protection schemes based on complex cryptographic algorithms are not suitable for UAV systems directly. Therefore, a two‐stage lightweight identity authentication and key agreement protocol for UAV is proposed in this paper. The entire process only uses hash and XOR operations, which significantly improves the authentication efficiency. Simultaneously, the physical unclonable function (PUF) is introduced and embedded into the UAV hardware to ensure UAV network communication security when a UAV suffers a physical capture attack. In the paper, the security of the proposed protocol is proved with Burrows–Abadi–Needham (BAN) logic, Real‐or‐Random (ROR) model, and AVISPA simulation tools. An informal security analysis is also provided to illustrate that the protocol satisfies the security requirements of UAV networks. Finally, the protocol is compared with other existing protocols regarding function properties, computation cost, and communication cost, which shows that the proposed protocol has effectiveness and practicality. Li Zhang 0096, Jianbo Xu, Mohammad S. Obaidat, Xiong Li 0002, Pandi Vijayakumar |
IET Commun. | 5 |
| 2022 | MUD-Based Behavioral Profiling Security Framework for Software-Defined IoT NetworksabstractThe rapid development and deployment of Internet of Things (IoT) devices in modern networks and Industry 4.0 have attracted substantial interest from cybersecurity researchers. In this study, we propose a software-defined framework that improves network intrusion detection systems by using manufacturer usage description (MUD) to enhance the behavioral monitoring in IoT networks. We aim to explore whether Industrial IoT (IIoT) devices typically serve a common role in cyber–physical systems, and their communications exhibit predictable patterns that can be defined in MUD profile(s) formally and succinctly. We design a framework that utilizes the concept of digital twins and software-defined networking to improve the security of IIoT environments. The MUD data are profiled, and the actions are evaluated on the network digital twin before they are used in the physical network. The behavioral profiling system is updated in real time, thereby improving the overall system security and compliance to policies in the IoT deployment. Evaluation results show that our solution outperforms existing approaches substantially in terms of attack detection accuracy, predicting security incidents, response time, and resource usage. Prabhakar Krishnan, Kurunandan Jain, Rajkumar Buyya, Pandi Vijayakumar, Anand Nayyar, Muhammad Bilal 0003, Houbing Song |
IEEE Internet Things J. | 4 |
| 2022 | Multifunctional and Multidimensional Secure Data Aggregation Scheme in WSNsabstractIn wireless sensor networks (WSNs), data aggregation (DA) has become one of the most practical techniques to reduce processing delay and improve energy efficiency. To support intelligent applications, sensor nodes need to report heterogeneous and diverse data, which induce the demand for multidimensional DA and multifunctional data analysis. To solve the current security problems and functional requirements, we propose a multifunctional and multidimensional secure DA scheme to strike the balance between data availability and privacy. First, we design a Chinese remainder theorem conversion method with the counter to encode multidimensional data into large integers, which can be operated by linear homomorphic encryption schemes. Then, we introduce a multifunctional data analysis method supporting diversified aggregation functions, including linear, polynomial, and continuous functions. Moreover, we demonstrate that the proposed scheme can achieve confidentiality, integrity, authentication, and resistance against false data injection attacks. The experimental results show that the supported max dimension of one ciphertext in our scheme is at least twice that of existing schemes. Thus, in scenarios with high dimensions, our scheme is superior to the existing schemes in terms of computation and communication costs. Cong Peng 0005, Min Luo 0002, Pandi Vijayakumar, Debiao He, Omar Said, Amr Tolba |
IEEE Internet Things J. | 3 |
| 2022 | An improved entity recognition approach to cyber-social knowledge provision of intellectual property using a CRF-LSTM model
Yang Wang 0090, Pandi Vijayakumar, Brij B. Gupta, Wadee Alhalabi, Sivaraman Audithan |
Pattern Recognit. Lett. | 2 |
| 2022 | Secure Edge-Aided Computations for Social Internet-of-Things SystemsabstractDevices in the Internet-of-Things (IoT) are networked and perform massive computations to support various social IoT systems. Applications in social IoT systems often involve complicated computations that are out of the computation capacity of some resource-constrained IoT devices. Thus, how to enable resource-constrained IoT devices to accomplish complex computations efficiently and securely is of significant importance. To address this problem, we develop a secure edge-aided computation scheme for the social IoT systems. We scope the framework of edge-aided computations and identify the security threats in such a system. We define the security requirements that the outsourcing algorithms should meet. Then, we provide two examples of secure outsourcing algorithms (matrix multiplication and modular exponentiation) that meet the given security requirements. The efficiency and security of the proposed algorithms are supported through the theoretical analysis and experimental results. Hanlin Zhang 0001, Jia Yu 0003, Mohammad S. Obaidat, Pandi Vijayakumar, Linqiang Ge, Jie Lin 0002, Jianxi Fan, Rong Hao |
IEEE Trans. Comput. Soc. Syst. | 4 |
| 2022 | A Privacy-Preserving and Untraceable Group Data Sharing Scheme in Cloud ComputingabstractWith the development of cloud computing, the great amount of storage data requires safe and efficient data sharing. In multiparty storage data sharing, first, the confidentiality of shared data is ensured to achieve data privacy preservation. Second, the security of stored data is ensured. That is, when stored shared data are subject to frequent access operations, the address sequence or access pattern of data is hidden. Therefore, determining how to ensure the untraceability of stored data or efficient hide the data access pattern in sharing stored data is a challenge. By employing the proxy re-encryption algorithm and oblivious random access memory (ORAM), a privacy-preserving and untraceable scheme is proposed to support multiple users in sharing data in cloud computing. On the one hand, group members and a proxy use the key exchange phase to obtain keys and resist multiparty collusion if necessary. The ciphertext obtained according to the proxy re-encryption phase enables group members to implement access control and store data, thereby completing secure data sharing. On the other hand, this article realizes data untraceability and a hidden data access pattern through a one-way circular linked table in a binary tree (OCLT) and obfuscation operation. Additionally, based on the designed structure and pointer tuple, malicious users are identified and data tampering is prevented. The security analysis shows that the protocol designed in this article can meet the security requirements of proxy re-encryption and ORAM. Both theoretical and experimental analyses demonstrate that the proposed scheme is secure and efficient for group data sharing in cloud computing. Jian Shen 0001, Huijie Yang, Pandi Vijayakumar, Neeraj Kumar 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | A Verifiable Privacy-Preserving Machine Learning Prediction Scheme for Edge-Enhanced HCPSsabstractAs a highly integrated industrial system, human cyber-physical systems (HCPSs) provide accurate and high-quality services for Industry 5.0. In HCPSs, machine learning (ML) prediction provides reliable prediction results for users based on matured models, while security and privacy protection are considerable issues. In this article, based on the modified Okamoto–Uchiyama homomorphic encryption, we propose a verifiable privacy-preserving machine learning prediction scheme for the edge-enhanced HCPSs, which outputs the verifiable prediction results for users without privacy leakage. Specifically, a batch of prediction results can be verified at one time, which improves the efficiency of verification. Security analysis shows that our scheme protects the privacy of inputs, ML model, and prediction results. The experiment results demonstrate that the edge computing architecture remarkably alleviates the computational burden of the cloud server. Furthermore, compared with other related schemes, our scheme shows the best execution efficiency, and batch verification optimizes the performance by about 15% compared with single verification on the same scale. Xiong Li 0002, Jiabei He 0001, Pandi Vijayakumar, Xiaosong Zhang 0001, Victor Chang 0001 |
IEEE Trans. Ind. Informatics | 3 |
| 2022 | Achieving Privacy-Preserving DSSE for Intelligent IoT Healthcare SystemabstractAs the product of combining Internet of Things (IoT), cloud computing, and traditional healthcare, Intelligent IoT Healthcare (IIoTH) brings us a lot of convenience, meanwhile security and privacy issues have attracted great attention. Dynamic searchable symmetric encryption (DSSE) technique can make the user search the dynamic healthcare information from IIoTH system under the condition that the privacy is protected. In this article, a novel privacy-preserving DSSE scheme for IIoTH system is proposed. It is the first DSSE scheme designed for personal health record (PHR) files database with forward security. We construct the secure index based on hash chain and realize trapdoor updates for resisting file injection attacks. In addition, we realize fine-grained search over encrypted PHR files database of attribute-value type. When the user executes search operations, he/she gets only a matched attribute value instead of the whole file. As a result, the communication cost is reduced and the disclosure of patient's privacy is minimized. The proposed scheme also achieves attribute access control, which allows users have different access authorities to attribute values. The specific security analysis and experiments show the security and the efficiency of the proposed scheme. Jia Yu 0003, Jianxi Fan, Pandi Vijayakumar, Victor Chang 0001 |
IEEE Trans. Ind. Informatics | 4 |
| 2022 | Blockchain-Based Secure Data Storage Protocol for Sensors in the Industrial Internet of ThingsabstractThe Industrial Internet of Things (IIoT) that introduces Internet of Things (IoT) technology into industrial environments is beneficial to construct smart factories. It utilizes various sensors to collect the data of industrial devices. These data are analyzed to improve the manufacturing efficiency and product quality. Cloud storage provides a solution for storing data outsourced, especially for sensors that have limited local storage and computational capacity. To ensure the privacy preserving of devices, the collected data should be stored in the formal ciphertext. Therefore, encrypted data sharing should be implemented to analyze the devices’ data. In this article, the cloud storage solution for sensors is considered. To achieve a secure and efficient data storage and sharing, a novel group signature scheme, which has less computation overhead and communication overhead, is designed to realize anonymous authentication first. And then, a novel blockchain-based cloud storage protocol for sensors in IIoT is constructed on basis of the proposed group signature scheme. Smart contract and proxy re-encryption are utilized in this protocol to realize secure data sharing with a less computational overhead. Furthermore, security proofs and performance evaluations demonstrate that this protocol is secure, privacy-preserving, and has at least 40% and 20% performance improvement in data storage and sharing phase, respectively. Junqing Lu, Jian Shen 0001, Pandi Vijayakumar, Brij B. Gupta |
IEEE Trans. Ind. Informatics | 3 |
| 2022 | An Anonymous Batch Authentication and Key Exchange Protocols for 6G Enabled VANETsabstractThe continuous growth to the 6G wireless communication technology overcomes storage, stringent computation, privacy and power constraints to make an efficient and intelligent next generation transportation system to alleviate traffic jams and enhance driving experience in vehicular ad-hoc networks (VANETs). In combination with 6G technology, high availability, high reliability and occasionally high throughput are enabled in VANETs. However, the information shared in the VANET system should be secured. In this paper, an efficient batch authentication and key exchange schemes are proposed to provide a high level security by evading communication with the malicious vehicle users. In addition, an anonymous batch authentication scheme is proposed to alleviate the authentication burden on the road side units (RSUs) while performing authentication in the congested areas. Moreover, the integrity of the communicating messages is preserved in this proposed scheme to evade message modification during transmission. Even though many cryptographic schemes were proposed for batch authentication in VANETS, they suffered from lack of privacy-preservation and computational overhead. The discussion of the possible attacks section illustrates that the proposed protocol can survive against potential security attacks. In the performance analysis section, the proposed batch authentication scheme is compared with well-known existing schemes and then it is clearly revealed that the proposed scheme is computationally more efficient than the existing schemes. Pandi Vijayakumar, Maria Azees, Sergei A. Kozlov, Joel J. P. C. Rodrigues |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2022 | A Flexible and Privacy-Preserving Collaborative Filtering Scheme in Cloud Computing for VANETsabstractThe vehicular ad hoc network (VANET) has become a hot topic in recent years. With the development of VANETs, how to achieve secure and efficient machine learning in VANETs is an urgent problem to be solved. Besides, how to ensure that users obtain the accurate results of machine learning is also a challenge. Based on the homomorphic encryption and secure multiparty computing technology, a flexible and privacy-preserving collaborative filtering scheme is proposed to accomplish the personalized recommendation for users, which is based on users’ interests and locations. On the one hand, the data can be updated by users flexibly to ensure the freshness and accuracy of the dataset of interest. On the other hand, the weighted values of user interest can be safely sorted to improve the accuracy of collaborative filtering effectively. Moreover, a novel collaborative filtering algorithm based on the homomorphic encryption technology is designed, which can guarantee that the calculated decryption result by machine learning is the same as the plaintext. Note that the privacy of user data can be preserved during machine learning in this algorithm. Both theoretical and experimental analyses demonstrate that the proposed scheme is secure and efficient for collaborative filtering in cloud computing in VANETs. Huijie Yang, Jian Shen 0001, Tianqi Zhou, Sai Ji, Pandi Vijayakumar |
ACM Trans. Internet Techn. | 5 |
| 2021 | PAMI-Anonymous Password Authentication Protocol for Medical Internet of ThingsabstractWith the continuous maturity of Internet of Things (IoT) technology, it has begun to be frequently used in all walks of life to improve people's work efficiency and living standards. The wide use of IoT in the medical field makes it convenient for patients to obtain medical services, and also enables doctors to obtain patients' physical conditions more timely and accurately, so as to formulate more efficient treatment plans. However, when people enjoy the convenience of medical IoT, how to ensure the security of communication and privacy of patients are all problems that cannot be ignored. In order to achieve secure access the network, this paper proposes an anonymous password authenticated key exchange protocol for medical Internet of Things (PAMI), where only a low-entropy password is required to realize the mutual authentication between medical device and telemedicine server, so as to negotiate a high-entropy session key. The security of PAMI is formally proved under the standard model, and the experiment based performance comparison demonstrates that it is more efficient than the existing similar schemes. Yousheng Zhou, Mohammad S. Obaidat, Pandi Vijayakumar, Xiaojun Wang 0001 |
GLOBECOM | 4 |
| 2021 | Blockchain Based Architecture and Solution for Secure Digital Payment SystemabstractWith the evolution of Internet Technology, payment methods have undergone drastic changes from entity exchange to Internet banking. Almost every sector has gone through the transformation from conventional technologies to digital technologies. With the arrival of online payment and digital wallet system, making payments has become easier than ever and with the increasing demand for such services, the number of users using instant money transfer systems are growing rapidly. However, the existing online payment system has issues like a single point of failure, transparency, and insider problem. Also, security in such online payments is crucial to mitigate risks and financial inefficiencies. In this paper, a private and permissioned Blockchain-based Payment System for the financial sector in India is proposed. The proposed architecture is based on Istanbul Byzantine Fault Tolerance (IBFT) consensus and it also discusses the integration of banks with the system. Mohammad Rasheed Ahmed, Kandala Meenakshi, Mohammad S. Obaidat, Ruhul Amin 0001, Pandi Vijayakumar |
ICC | 5 |
| 2021 | An efficient combined deep neural network based malware detection framework in 5G environment
Ning Lu 0005, Dan Li 0028, Pandi Vijayakumar, Francesco Piccialli, Victor Chang 0001 |
Comput. Networks | 4 |
| 2021 | An optimized Generative Adversarial Network based continuous sign language classification
R. Elakkiya, Pandi Vijayakumar, Neeraj Kumar 0001 |
Expert Syst. Appl. | 2 |
| 2021 | Security preservation in industrial medical CPS using Chebyshev map: An AI approach
Rongxin Qi, Sai Ji, Jian Shen 0001, Pandi Vijayakumar, Neeraj Kumar 0001 |
Future Gener. Comput. Syst. | 4 |
| 2021 | A Novel Lightweight Authentication Protocol for Emergency Vehicle Avoidance in VANETsabstractThe delay of vehicle emergency has led to many serious consequences. A series of studies has been carried out in the field of information security in vehicularad hocnetworks (VANETs). However, open issues such as the authentication of emergency vehicle (EV) avoidance are remaining unsolved. In this article, we propose a novel lightweight authentication protocol to avoid EVs in VANETs. In our protocol, after completing the first mutual authentication with the nearest roadside unit (RSU), EV can complete the mutual identity authentication with the subsequent RSUs without repeating cumbersome calculations. Additionally, EV is required to verify the legitimacy of the driver’s identity when starting to avoid some illegal driving behavior. The RSUs will broadcast avoidance information to ordinary vehicles in their jurisdiction to remind them to clear a temporary emergency lane for EVs in advance. With temporary emergency lanes, emergent mission delays due to traffic congestion could be reduced. The security analysis and efficient analysis prove that our protocol is practical and efficient against attacks, such as impersonation attacks, device theft attacks, reputation attacks, etc. Chen Wang 0015, Jian Shen 0001, Jianwei Liu 0001, Pandi Vijayakumar, Neeraj Kumar 0001 |
IEEE Internet Things J. | 5 |
| 2021 | The Role of Internet of Things to Control the Outbreak of COVID-19 PandemicabstractCurrently, COVID-19 pandemic is the major cause of disease burden globally. So, there is a need for an urgent solution to fight against this pandemic. Internet of Things (IoT) has the ability of data transmission without human interaction. This technology enables devices to connect in the hospitals and other planned locations to combat this situation. This article provides a road map by highlighting the IoT applications that can help to control it. This study also proposes a real-time identification and monitoring of COVID-19 patients. The proposed framework consists of four components using the cloud architecture: 1) data collection of disease symptoms (using IoT-based devices); 2) health center or quarantine center (data collected using IoT devices); 3) data warehouse (analysis using machine learning models); and 4) health professionals (provide treatment). To predict the severity level of COVID-19 patients on the basis of IoT-based real-time data, we experimented with five machine learning models. The results reveal that random forest outperformed among all other models. IoT applications will help management, health professionals, and patients to investigate the symptoms of contagious disease and manage COVID-19 +ve patients worldwide. Aniello Castiglione, Muhammad Umer 0001, Saima Sadiq, Mohammad S. Obaidat, Pandi Vijayakumar |
IEEE Internet Things J. | 5 |
| 2021 | Secure Multifactor Authenticated Key Agreement Scheme for Industrial IoTabstractThe application of Internet of Things (IoT) has generally penetrated into people's life and become popular in recent years. The IoT devices with different functions are integrated and applied to various domains, such as E-health, smart home, Industrial IoT (IIoT), and smart farming. IIoT obtains the general attention among these domains, which allows the authorized user remotely access and control the sensing devices. The user suffices to attain the real-time data collected by sensing devices during the process of production. However, these data is usually transmitted via an insecure channel, which brings the problem of the security and privacy arising from the hostile attacks in IIoT. To resist the hostile attacks by the adversary and protect the security of the transmitted data, we propose a secure multifactor authenticated key agreement scheme for IIoT to support the authorized user remotely accessing the sensing device. The scheme adopts password, biometrics, and smart card to identify the user in the IIoT environment. We employ the secret-sharing technology and Chinese remainder theorem to construct a group key among legitimate sensing devices, and then this group key is utilized to assist in negotiating a secure session key between the user and multiple sensing devices. The proposed scheme is suitable for the resource-constrained IIoT as it only uses hash function, bitwise XOR operation, and symmetric cryptography. The performance analysis indicates that our scheme has less communication and computational costs in contrast to other correlative schemes. Besides, the security analysis indicates that our scheme can withstand many known attacks. L. Jegatha Deborah, Pandi Vijayakumar, Neeraj Kumar 0001 |
IEEE Internet Things J. | 3 |
| 2021 | Privacy-Preserving Implicit Authentication Protocol Using Cosine Similarity for Internet of ThingsabstractInternet of Things provides complicated value-added services to mobile intelligent terminal users. Different sensors collect various data from the users and transmit the data to the mobile intelligent terminal for storage. Consequently, a great amount of personal and sensitive information related to these rich and colorful applications is stored in the mobile intelligent terminal. Mobile intelligent terminals have become the prominent target of network attackers. Security breach and privacy leakage severely thread the application development of the Internet of Things. We present a privacy-preserving implicit authentication framework using users' behavior features sensed by the mobile intelligent terminal based on the artificial intelligence methodology. More precisely, we first summarize the security and privacy requirements for the security authentication of the mobile intelligent terminal. Then, we present a privacy-preserving implicit authentication framework using the cosine similarity and partial homomorphic public-key encryption scheme. Finally, a performance evaluation of the proposed protocol is conducted. The result shows that the communication and computation efficiency of our protocol is more efficient than other related protocols. Fushan Wei, Pandi Vijayakumar, Neeraj Kumar 0001, Qingfeng Cheng |
IEEE Internet Things J. | 2 |
| 2021 | Blockchain-based batch authentication protocol for Internet of Vehicles
Palak Bagga, Anil Kumar Sutrala, Ashok Kumar Das, Pandi Vijayakumar |
J. Syst. Archit. | 4 |
| 2021 | Efficient Identity-Based Distributed Decryption Scheme for Electronic Personal Health Record Sharing SystemabstractThe rapid development of the Internet of Things (IoT) has led to the emergence of more and more novel applications in recent years. One of them is the e-health system, which can provide people with high-quality and convenient health care. Meanwhile, it is a key issue and challenge to protect the privacy and security of the user's personal health record. Some cryptographic methods have been proposed such as encrypt user's data before sharing it. However, it is complicated to share the data with multiple parties (doctors, health departments, etc.), due to the fact that data should be encrypted under each recipient's keys. Although several (t, n) threshold secret sharing schemes can share the data only need one encryption operation, there is a limitation that the decryption private key has to be reconstructed by one party. To offset this shortcoming, in this paper, we propose an efficient identity-based distributed decryption scheme for personal health record sharing system. It is convenient to share their data with multiple parties and does not require to reconstruct the decryption private key. We prove that our scheme is secure under chosen-ciphertext attack (CCA). Moreover, we implement our scheme by using the Java pairing-based cryptography (JPBC) library on a laptop and an Android phone. The experimental results show that our system is practical and effective in the electronic personal health record system. Yudi Zhang 0001, Debiao He, Mohammad S. Obaidat, Pandi Vijayakumar, Kuei-Fang Hsiao |
IEEE J. Sel. Areas Commun. | 4 |
| 2021 | Introduction to the special issue on "Biometrics in Smart Cities: Techniques and Applications (BI_SCI)"
Michele Nappi, Silvio Barra, Aniello Castiglione, Fabio Narducci, Pandi Vijayakumar |
Pattern Recognit. Lett. | 5 |
| 2021 | BBAAS: Blockchain-Based Anonymous Authentication Scheme for Providing Secure Communication in VANETsabstractSmart driving has become conceivable due to the rapid growth of vehicular ad hoc networks. VANETs are considered as the main platform for providing safety road information and instant vehicle communication. Nevertheless, due to the open wireless nature of communication channels, VANET is susceptible to security attacks by malicious users. For this reason, secure anonymous authentication schemes are essential in VANETs. However, when vehicles reach a new roadside unit (RSU) coverage area, the vehicles need to perform reauthentication with the current RSU, which significantly diminishes the efficiency of the entire VANET. Therefore, the introduction of blockchain technology has created opportunities for VANETs to resolve the aforementioned challenges. Due to the decentralized nature of blockchain technology, rapid reauthentication of vehicles is achieved in this paper through secure authentication code transfer between the consecutive RSUs. The security strength of the proposed blockchain-based anonymous authentication scheme against various harmful security attacks is proven in the security analysis section to ensure that it provides better security. In addition, blockchain, as presented in the performance analysis section, is used to substantially diminish the computational cost compared to conventional authentication schemes. Maria Azees, Pandi Vijayakumar, L. Jegatha Deborah, Marimuthu Karuppiah, Mary Subaja Christo |
Secur. Commun. Networks | 2 |
| 2021 | COVID-19: Automatic Detection of the Novel Coronavirus Disease From CT Images Using an Optimized Convolutional Neural NetworkabstractIt is widely known that a quick disclosure of the COVID-19 can help to reduce its spread dramatically. Transcriptase polymerase chain reaction could be a more useful, rapid, and trustworthy technique for the evaluation and classification of the COVID-19 disease. Currently, a computerized method for classifying computed tomography (CT) images of chests can be crucial for speeding up the detection while the COVID-19 epidemic is rapidly spreading. In this article, the authors have proposed an optimized convolutional neural network model (ADECO-CNN) to divide infected and not infected patients. Furthermore, the ADECO-CNN approach is compared with pretrained convolutional neural network (CNN)-based VGG19, GoogleNet, and ResNet models. Extensive analysis proved that the ADECO-CNN-optimized CNN model can classify CT images with 99.99% accuracy, 99.96% sensitivity, 99.92% precision, and 99.97% specificity. Aniello Castiglione, Pandi Vijayakumar, Michele Nappi, Saima Sadiq, Muhammad Umer 0001 |
IEEE Trans. Ind. Informatics | 2 |
| 2021 | Profile Matching for IoMT: A Verifiable Private Set Intersection SchemeabstractThe rapid development of the Internet of Things (IoTs), 5 G and artificial intelligence (AI) technology have been dramatically incentivizing the advancement of Internet of Medical Things (IoMT) in recent years. Profile matching technology can be used to realize the sharing of medical information between patients by matching similar symptom attributes. However, the symptom attributes are associated with patients' sensitive information such as gender, age, physiological data, and other personal health information, thus the privacy of patients will be revealed during the matching process in the IoMT. To solve the problem, this paper proposes a verifiable private set intersection scheme to achieve fine-grained profile matching. On the one hand, the privacy data of patients can be divided by multi-tag to implement fine-grained operations. On the other hand, re-encryption technique is utilized to protect the privacy of patients. In addition, the cloud server may violate the scheme, thus a verifiable mechanism is leveraged to check the correctness of computation. The analysis of security indicates that our proposed scheme can resist the untrusted cloud server and the performance simulation demonstrates that our scheme improves efficiency by reducing the use of bilinear pairs. Yalian Qian, Jian Shen 0001, Pandi Vijayakumar, Pradip Kumar Sharma |
IEEE J. Biomed. Health Informatics | 3 |
| 2021 | A Novel UAV-Enabled Data Collection Scheme for Intelligent Transportation System Through UAV Speed ControlabstractThe rapid and convenient travel of people and the timely transportation of goods depend on the correct decision of the Intelligent Transportation Systems (ITS). Due to the decision-making of ITS requires a large amount of data to support, UAV-enabled periodic data collection is an effective method. However, due to the limited resources of UAV, UAV cannot directly collect data from all storage devices, resulting in unfair data collection. Therefore, we propose a UAV Speed Control based Fairness Data Collection (USCFDC) scheme. First, since the fairness of data collection will affect the decision-making of ITS, a framework for controlling the flight speed of the UAV is proposed to improve the fairness of data collection. The flight speed of UAV will slow down in areas with a large number of nodes, thereby improving the fairness of data collection. Second, a novel method is proposed to maximize the amount of data collected by UAV from each node. With this method, the value of the amount of data will be used as the dichotomous value in the dichotomy algorithm, and the UAV must collect a certain amount of data from each node. The upper and lower limits of the dichotomy algorithm are adjusted according to the time duration for UAV to collect data. Compared with previous schemes, the fairness of data collection can be improved by a maximum of 15.89% under the same flight time of UAV. Besides, the energy consumption is reduced by 49.31%-52.55% and the flight time of the UAV is reduced by 48%-62.38% when the amount of collected data is the same. Xiong Li 0002, Jiawei Tan, Anfeng Liu, Pandi Vijayakumar, Neeraj Kumar 0001, Mamoun Alazab |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2021 | An Intelligent Terminal Based Privacy-Preserving Multi-Modal Implicit Authentication Protocol for Internet of Connected VehiclesabstractThe Internet of connected Vehicles (IOV) can collect, process, compute and release the information of intelligent transportation systems. IOV is an integrated service system that can support the applications for automatic driving, intelligent transport and information services. As the number of incidents on IOV has been on the rise in the past few years, IOV security is becoming increasingly important in the IOV architecture. One of the most notable risks of IOV faces is intelligent terminal security. The vehicle's intelligent terminal can be used to launch for further attacks on the on-board operating system to penetrate into the internal network of connected vehicle, and consequently threaten the safety of the vehicle. Thus, it is of paramount importance that we protect the security of the intelligent terminal. We propose two intelligent terminal based privacy-preserving multi-modal implicit authentication protocols to protect the security of the intelligent terminal in IOV. The proposed protocols use the password and the vehicle owner's behavior features as the authentication factors to protect the security of the intelligent terminal. Since the vehicle owner's behavior features are sensitive and the privacy information of the user must be protected, we also consider the privacy protection of the behavior features. Our protocols do not reveal any information about the vehicle owner's behavior features to the authentication server and the adversary except the ciphertext size of the feature vector. We analyze the security of our proposed protocol and compare them with other related protocols in terms of computation and communications costs. Our results demonstrate that our proposed protocols yield better security and efficiency. Fushan Wei, Sherali Zeadally, Pandi Vijayakumar, Neeraj Kumar 0001, Debiao He |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2021 | Efficient Distributed Decryption Scheme for IoT Gateway-based ApplicationsabstractWith the evolvement of the Internet of things (IoT), privacy and security have become the primary indicators for users to deploy IoT applications. In the gateway-based IoT architecture, gateways aggregate data collected by perception-layer devices and upload message packets to platforms, while platforms automatically push different categories of data to different applications. However, security in processes of data transmission via gateways, storage in platforms, access by applications is the major challenge for user privacy protection. To tackle this challenge, this article presents a secure IoT scheme based on a fine-grained multi-receive signcryption scheme to realize end-to-end secure transmission and data access control. To enhance the security of online application decryption keys, we design a distributed threshold decryption scheme based on secret-sharing. Moreover, from the provable security perspective, we demonstrate that the scheme can achieve the expected IND-CCA security and EUF-CMA security. After the performance analysis, evaluation results show that the computational performance is efficient and linearly subject to the number of messages and the number of receivers. Cong Peng 0005, Jianhua Chen 0002, Pandi Vijayakumar, Neeraj Kumar 0001, Debiao He |
ACM Trans. Internet Techn. | 3 |
| 2021 | An efficient anonymous authentication and confidentiality preservation schemes for secure communications in wireless body area networks
Maria Azees, Pandi Vijayakumar, Marimuthu Karuppiah, Anand Nayyar |
Wirel. Networks | 2 |
| 2020 | SAC-FIIoT: Secure Access Control Scheme for Fog-Based Industrial Internet of ThingsabstractIndustrial Internet of Things (IIoT) is a communication environment that consists of various interconnected sensing devices, instruments, and other devices connected together with industrial software tools and applications. The important applications of IIoT include industrial automation, predictive maintenance, smart logistics management, power management, smart package management and smart robotics. However, IIoT may be vulnerable to different types of attacks as the IoT smart devices communicate among each other via insecure communication means. Thus, there is an essential requirement of deployment of secure access control scheme in IIoT environment, which is one of the important security services for securing IIoT. In this paper, we propose a novel access control scheme for fog based IIoT communication, called SAC-FIIoT. We provide the details of network model as well as threat model, which are required to design SAC-FIIoT. The security analysis of SAC-FIIoT shows its resilience against various types of possible attacks. SAC-FIIoT is also compared with other related competing existing schemes and it was found that its performance is better than these competing schemes. Therefore, SAC-FIIoT is suitable for access control in a fog-based IIoT environment. Mohammad Wazid, Mohammad S. Obaidat, Ashok Kumar Das, Pandi Vijayakumar |
GLOBECOM | 4 |
| 2020 | BUA: A Blockchain-based Unlinkable Authentication in VANETsabstractAuthentication with unlinkability is one of the critical requirements for the security of VANETs. Unlinkability prevents attackers from linking multiple messages to infer vehicular privacy. Pseudonymous authentication schemes are widely adopted to achieve unlinkable authentication. However, they need multiple interactions with a trusted third-party to update pseudonym as well as the attached information. In order to address this issue and provide effective services in distributed systems, we propose a blockchain-based unlinkable authentication protocol called BUA, where Service Manager (SM) of each domain acts as the nodes of consortium blockchain to construct a distributed system. Each SM covers a certain logical area and maintains a sequence of consistent blocks, which hold vehicular registration data. Based on the system, vehicles use homomorphic encryption to self-generate any number of pseudonyms to achieve unlinkability. Pseudonymous validity and ownership can be verified locally by each SM. Performance evaluation results of the proposed scheme show that our protocol provides stronger security with less computation and communication overhead. Jiao Liu 0002, Xinghua Li 0001, Qi Jiang 0001, Mohammad S. Obaidat, Pandi Vijayakumar |
ICC | 5 |
| 2020 | HomeChain: A Blockchain-Based Secure Mutual Authentication System for Smart HomesabstractIncreasingly, governments around the world, particularly in technologically advanced countries, are exploring or implementing smart homes, or the related smart facilities for the benefits of the society. The capability to remotely access and control Internet of Things (IoT) devices (e.g., capturing of images, audios, and other information) is convenient but risky, as vulnerable devices can be exploited to conduct surveillance or perform other nefarious activities on the users and organizations. This highlights the necessity of designing a secure and efficient remote user authentication solution. Most of the existing solutions for this problem are generally based on a single-server architecture, which has limitations in terms of privacy and anonymity (leading to users' daily activities being predicted), and integrity and confidentiality (resulting in an unreliable behavior auditing). While blockchain-based solutions may mitigate these issues, they still face some critical challenges (e.g., providing regulation of behaviors and privacy protection of access policy). Motivated by these facts, in this article, we construct a novel secure mutual authentication system, which can be applied in smart homes and other applications. Specifically, the proposed approach integrates blockchain, group signature, and message authentication code to provide reliable auditing of users' access history, anonymously authenticate group members, and efficiently authenticate home gateway, respectively. We also prove the security and privacy requirements, including anonymity, traceability, and confidentiality, that the proposed system satisfies, with an implementation and evaluation to demonstrate its practicality. Chao Lin 0003, Debiao He, Neeraj Kumar 0001, Xinyi Huang 0001, Pandi Vijayakumar, Kim-Kwang Raymond Choo |
IEEE Internet Things J. | 5 |
| 2020 | Efficient and Provably Secure Multireceiver Signcryption Scheme for Multicast Communication in Edge ComputingabstractWith the popularity of edge computing, edge nodes are connected with the Internet of Things (IoT) devices to process and analyze IoT-created data, and feedback corresponding results to users, devices, or data centers. In the edge computing environment, multicast is a typical communication pattern to support data transmitting between edges and devices. It allows the sender to send messages to multiple receivers in one broadcast message. To construct a secure multicast channel, the primary issue is to ensure the privacy and credibility of the transmitted message in the open wireless communication. Then, another essential issue for multicast channels is receiver anonymity, i.e., only the sender knows the receivers' identities. Also, efficiency and provable security are critical in scheme design. In this article, we design a certificateless multimessage and multireceiver signcryption (CLMMSC) scheme by using the elliptic curve cryptography. To facilitate lightweight deployment, we adapt the certificateless mechanism to reduce the system operation and maintenance costs. Then, through security proofs, we demonstrate that the proposed scheme can achieve the expected security properties. The performance analysis shows that the proposed scheme has lower communication costs than previous CLMMSC schemes. Cong Peng 0005, Jianhua Chen 0002, Mohammad S. Obaidat, Pandi Vijayakumar, Debiao He |
IEEE Internet Things J. | 4 |
| 2020 | A provably secure dynamic ID-based authenticated key agreement framework for mobile edge computing without a trusted party
Dheerendra Mishra, Dharminder Chaudhary, Preeti Yadav, Y. Sreenivasa Rao, Pandi Vijayakumar, Neeraj Kumar 0001 |
J. Inf. Secur. Appl. | 5 |
| 2020 | A novel proxy-oriented public auditing scheme for cloud-based medical cyber physical systems
Zhiyan Xu, Debiao He, Huaqun Wang, Pandi Vijayakumar, Kim-Kwang Raymond Choo |
J. Inf. Secur. Appl. | 4 |
| 2020 | A practical group blind signature scheme for privacy protection in smart grid
Jian Shen 0001, Pandi Vijayakumar, Youngju Cho, Victor Chang 0001 |
J. Parallel Distributed Comput. | 3 |
| 2020 | Efficient data integrity auditing with corrupted data recovery for edge computing in enterprise multimedia security
Dengzhi Liu, Jian Shen 0001, Pandi Vijayakumar, Anxi Wang, Tianqi Zhou |
Multim. Tools Appl. | 3 |
| 2020 | Intelligent e-learning system based on fuzzy logic
Rajendran Karthika, L. Jegatha Deborah, Pandi Vijayakumar |
Neural Comput. Appl. | 3 |
| 2020 | Intelligent Secure Ecosystem Based on Metaheuristic and Functional Link Neural Network for Edge of ThingsabstractInternet of Things (IoT) has evolved for building smart environments in a distributed system, where the data produced by IoT devices are transmitted through Edge computing devices to streamline the flow of traffic from IoT devices to a distributed network. In such a scenario, the attacker introduces many attacks to the edge before forwarding them to distributed servers. This necessitates intrusion detection systems for such environments to mitigate security attacks. This paper has projected a basis for characterization of intrusive behaviors in a distributed system based on the functional link neural nets response weighted-average and teaching-learning metaheuristic with elitism on weight-space. The proposed technique makes use of teaching-learning metaheuristic optimization to obtain suitable parameters for the functional link neural net. Furthermore, the processing of duplicate parameters is successfully avoided by using mutation operation. In addition to this, in this paper the proposed method is found to be more efficient in terms of computational burden. Bighnaraj Naik, Mohammad S. Obaidat, Janmenjoy Nayak, Danilo Pelusi, Pandi Vijayakumar, SK Hafizul Islam |
IEEE Trans. Ind. Informatics | 5 |
| 2020 | Efficient and Secure Anonymous Authentication With Location Privacy for IoT-Based WBANsabstractInternet-of-Things (IoT)-based wireless body area networks (WBANs) play an important role in modern medical systems for patient-health monitoring. WBANs have the capability to collect real-time biological information from the patients' body using intelligent sensors and then send the collected information to the remote doctors or medical experts using the Internet. In recent years, numerous anonymous authentication schemes were proposed to provide security in WBANs. However, many of these schemes are not computationally efficient during anonymous authentication. Moreover, the previous schemes did not provide location privacy for both doctors and patients. In order to overcome these limitations, in this article, we propose an efficient and secure anonymous authentication framework with location privacy preservation for IoT-based WBANs. The comprehensive analysis section shows that the proposed scheme overcomes the security weaknesses in the existing schemes and also provides low computation cost during anonymous authentication. Pandi Vijayakumar, Mohammad S. Obaidat, Maria Azees, SK Hafizul Islam, Neeraj Kumar 0001 |
IEEE Trans. Ind. Informatics | 1 |
| 2020 | A Mobile Intelligent Terminal Based Anonymous Authenticated Key Exchange Protocol for Roaming Service in Global Mobility NetworksabstractWith the rapid development of mobile intelligent terminals, users can conveniently enjoy ubiquitous services in global mobility networks. User authentication and user privacy protection are two important issues for providing secure roaming service in global mobility networks. Until now, many authentication protocols for roaming service with user anonymity are proposed. Unfortunately, most of the existing protocols only have heuristic informal security arguments. Moreover, current works only achieve weak anonymity. A user's identity is only anonymous against eavesdroppers and is known to the home agent and sometimes even the foreign agent. In order to overcome these weaknesses, we propose a privacy-preserving password-authenticated key exchange protocol for roaming service in global mobility networks. The proposed protocol is proven secure in the random oracle model under the CDH and the q-SDH assumptions. Our protocol achieves stronger user anonymity than other related protocols. The performance comparison shows that our protocol is more efficient in terms of on-line computation and enjoys optimal communication complexity. Consequently, it is more suitable for real applications in global mobility networks. Fushan Wei, Pandi Vijayakumar, Qi Jiang 0001 |
IEEE Trans. Sustain. Comput. | 2 |
| 2020 | Privacy-Protection Scheme Based on Sanitizable Signature for Smart Mobile Medical ScenariosabstractWith the popularization of wireless communication and smart devices in the medical field, mobile medicine has attracted more and more attention because it can break through the limitations of time, space, and objects and provide more efficient and quality medical services. However, the characteristics of a mobile smart medical network make it more susceptible to security threats such as data integrity damage and privacy leakage than those of traditional wired networks. In recent years, many digital signature schemes have been proposed to alleviate some of these challenges. Unfortunately, traditional digital signatures cannot meet the diversity and privacy requirements of medical data applications. In response to this problem, this paper uses the unique security attributes of sanitizable signatures to carry out research on the security and privacy protection of medical data and proposes a data security and privacy protection scheme suitable for smart mobile medical scenarios. Security analysis and performance evaluation show that our new scheme effectively guarantees data security and user privacy while greatly reducing computation and communication costs, making it especially suitable for mobile smart medical application scenarios. Zhiyan Xu, Min Luo 0002, Neeraj Kumar 0001, Pandi Vijayakumar, Li Li 0073 |
Wirel. Commun. Mob. Comput. | 4 |
| 2019 | MGPV: A novel and efficient scheme for secure data sharing among mobile users in the public cloud
Pandi Vijayakumar, S. Milton Ganesh, L. Jegatha Deborah, SK Hafizul Islam, Mohammad Mehedi Hassan, Abdulhameed Alelaiwi, Giancarlo Fortino |
Future Gener. Comput. Syst. | 1 |
| 2019 | Secure big data communication for energy efficient intra-cluster in WSNs
Anxi Wang, Jian Shen 0001, Pandi Vijayakumar, Yongxin Zhu 0001 |
Inf. Sci. | 3 |
| 2019 | A Dependable Time Series Analytic Framework for Cyber-Physical Systems of IoT-based Smart GridabstractWith the emergence of cyber-physical systems (CPS), we are now at the brink of next computing revolution. The Smart Grid (SG) built on top of IoT (Internet of Things) is one of the foundations of this CPS revolution, which involves a large number of smart objects connected by networks. The volume of time series of SG equipment is tremendous and the raw time series are very likely to contain missing values because of undependable network transferring. The problem of storing a tremendous volume of raw time series thereby providing a solid support for precise time series analytics now becomes tricky. In this article, we propose a dependable time series analytics (DTSA) framework for IoT-based SG. Our proposed DTSA framework is capable of providing a dependable data transforming from CPS to the target database with an extraction engine to preliminary refining raw data and further cleansing the data with a correction engine built on top of a sensor-network-regularization-based matrix factorization method. The experimental results reveal that our proposed DTSA framework is capable of effectively increasing the dependability of raw time series transforming between CPS and the target database system through the online lightweight extraction engine and the offline correction engine. Our proposed DTSA framework would be useful for other industrial big data practices. Chang Wang 0003, Yongxin Zhu 0001, Weiwei Shi 0002, Victor Chang 0001, Pandi Vijayakumar, Yishu Mao 0001, Yiping Fan |
ACM Trans. Cyber Phys. Syst. | 5 |
| 2019 | Sustainable Computing Based Deep Learning Framework for Writing Research ManuscriptsabstractWriting research manuscripts is always a tough task at the eleventh hour. Often researchers do not find time to rewrite the manuscript to satisfaction, which is not quantifiable though. This paper proposes a sustainable computing based deep learning framework for iterated accumulation of ideas while writing research manuscripts. The framework suggests Deep Author Topic Models (DATM) where every author of the manuscript is modeled. For this, we have assumed time based sustainable computing as a measure of evaluation for research manuscript effectiveness. Using respective DATM, the region contributed by every author in the manuscriptis analyzed and fine-tuned semantically such that the manuscript is made to perfection in least time. G. S. Mahalakshmi 0001, G. Muthu Selvi, Sendhilkumar Selvaraju, Pandi Vijayakumar, Yongxin Zhu 0001, Victor Chang 0001 |
IEEE Trans. Sustain. Comput. | 4 |
| 2018 | A robust and efficient password-based conditional privacy preserving authentication and group-key agreement protocol for VANETs
SK Hafizul Islam, Mohammad S. Obaidat, Pandi Vijayakumar, Enas W. Abdulhay, Fagen Li, M. Krishna Chaitanya Reddy |
Future Gener. Comput. Syst. | 3 |
| 2018 | Key management and key distribution for secure group communication in mobile and cloud network
Pandi Vijayakumar, Victor Chang 0001, L. Jegatha Deborah, Bharat S. Rawal |
Future Gener. Comput. Syst. | 1 |
| 2018 | Computationally efficient privacy preserving anonymous mutual and batch authentication schemes for vehicular ad hoc networks
Pandi Vijayakumar, Victor Chang 0001, L. Jegatha Deborah, Balamurugan Balusamy, P. G. Shynu |
Future Gener. Comput. Syst. | 1 |
| 2018 | A Provably Secure Three-Factor Session Initiation Protocol for Multimedia Big Data CommunicationsabstractThe session initiation protocol (SIP) is an IP-based telephony authentication mechanism for multimedia big data communications over the Internet. It is used to set up, and control voice and video calls, as well as for instant messaging. One of the concerns of this kind of open-text-based protocol is the security for user authentication. The HTTP digest-based challenge-response authentication process is used in the original SIP. However, this kind of authentication procedure is insecure and a pre-existing user configuration on the remote server is required. According to the literature, several authentication mechanisms for SIP are already devised, but none of these SIPs are robust against existing security attacks. Therefore, we design a three-factor SIP (TF-SIP) for multimedia big data communications, which is robust and flexible against existing known security issues. We show that our TF-SIP is provably secure in the random oracle model. We formally verify the mutual authentication and the freshness of the agreed session key between the user and the remote server using the BAN logic analysis. We found that the communication and computation costs are low, but the storage cost is slightly higher for our TF-SIP in comparison with other SIPs. SK Hafizul Islam, Pandi Vijayakumar, Md. Zakirul Alam Bhuiyan, Ruhul Amin 0001, Varun Rajeev M., Balamurugan Balusamy |
IEEE Internet Things J. | 2 |
| 2018 | Provably Secure Identity-Based Signcryption Scheme for Crowdsourced Industrial Internet of Things EnvironmentsabstractNowadays, the Internet of Things (IoT) and cloud computing have become more pervasive in the context of the industry as digitization becomes a business priority for various organizations. Therefore, industries outsource their crowdsourced Industrial IoT (IIoT) data in the cloud in order to reduce the cost for sharing data and computation. However, the privacy of such crowdsourced data in this environment has attracted wide attention across the globe. Signcryption is the significant cryptographic primitive that meets both requirement of authenticity and confidentiality of crowdsourced data among users/industries, and thus, it is ideal for ensuring secure authentic data storage and transmission in industrial crowdsourcing environments. In this paper, we introduce a new identity-based signcryption (IBSC) scheme using bilinear pairing for IIoT deployment. Besides, two hard problems are studied, called as, modified bilinear Diffie-Hellman inversion (MBDHI) assumption and modified bilinear strong Diffie-Hellman (MBSDH) assumption. The rigorous security analysis demonstrates that our IBSC scheme for IIoT is provably secure based on the intractability of decisional-MBDHI and MBSDH assumptions under formal security model without considering the concept of the random oracle. The performance comparison with other signcryption schemes shows satisfactory results. Thus, our IBSC scheme is appropriate for IIoT crowdsourcing environments, and also applicable for low-bandwidth communications. Arijit Karati, SK Hafizul Islam, G. P. Biswas, Md. Zakirul Alam Bhuiyan, Pandi Vijayakumar, Marimuthu Karuppiah |
IEEE Internet Things J. | 5 |
| 2018 | A robust and efficient bilinear pairing based mutual authentication and session key verification over insecure communication
Ruhul Amin 0001, SK Hafizul Islam, Pandi Vijayakumar, Muhammad Khurram Khan, Victor Chang 0001 |
Multim. Tools Appl. | 3 |
| 2018 | Efficient authentication protocol for secure multimedia communications in IoT-enabled wireless sensor networks
Dheerendra Mishra, Pandi Vijayakumar, Venkatasamy Sureshkumar, Ruhul Amin 0001, SK Hafizul Islam, Prosanta Gope |
Multim. Tools Appl. | 2 |
| 2017 | Analysis of Measures to Achieve Resilience during Virtual Machine Interruptions in IaaS Cloud Service
Priya Vedhanayagam, Subha S., Balamurugan Balusamy, Pandi Vijayakumar, Victor Chang 0001 |
IoTBDS | 4 |
| 2017 | Time efficient secure DNA based access control model for cloud computing environment
Suyel Namasudra, Pinki Roy, Pandi Vijayakumar, Sivaraman Audithan, Balamurugan Balusamy |
Future Gener. Comput. Syst. | 3 |
| 2017 | EAAP: Efficient Anonymous Authentication With Conditional Privacy-Preserving Scheme for Vehicular Ad Hoc NetworksabstractProviding an efficient anonymous authentication scheme in vehicular ad hoc networks (VANETs) with low computational cost is a challenging issue. Even though, there are some existing schemes to provide anonymous authentication, the existing schemes suffer from high computational cost in the certificate and the signature verification process, which leads to high message loss. Therefore, they fail to meet the necessity of verifying hundreds of messages per second in VANETs. In our scheme, we propose an efficient anonymous authentication scheme to avoid malicious vehicles entering into the VANET. In addition, the proposed scheme offers a conditional tracking mechanism to trace the vehicles or roadside units that abuse the VANET. As a result, our scheme revokes the privacy of misbehaving vehicles to provide conditional privacy in a computationally efficient way through which the VANET entities will be anonymous to each other until they are revoked from the VANET system. Moreover, the proposed scheme is implemented and the performance analysis shows that our scheme is computationally efficient with respect to the certificate and the signature verification process by keeping conditional privacy in VANETs. Maria Azees, Pandi Vijayakumar, L. Jegatha Deborah |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2016 | An efficient group key agreement protocol for secure P2P communicationabstractAbstract The efficient design of a distributed group key management for a peer to peer (P2P) network with minimal computation complexity in dynamic secure group communication is a challenging issue. This is because of the absence of a centralized coordinator. In order to provide this facility, a self‐composed distributed group key management framework is proposed for secure P2P communication. In this proposed work, group key computation is performed using Chinese remainder theorem and secure communication is performed through RSA encryption algorithm. This self‐composed key management is a one round protocol in which a shared group key is generated using the public key of each individual user, and it is derived from the respective private key. The main advantage of the group key management scheme proposed in this paper is that it reduces the computation complexity of the peer users toO(1). This reduction in computation complexity is achieved by performing one addition and multiplication operation during a single member join and one subtraction operation during a single member leave operation. The proposed algorithm has been implemented and analyzed with well‐known existing distributed group key management protocols and observed that it reduces the computation complexity significantly. Copyright © 2016 John Wiley & Sons, Ltd. Pandi Vijayakumar, Ramu Naresh, L. Jegatha Deborah, SK Hafizul Islam |
Secur. Commun. Networks | 1 |
| 2016 | An effective key distribution for secure internet pay-TV using access key hierarchiesabstractAbstract Distribution of keys in a Conditional Access System takes long computation time because a huge number of keys is to be updated if any user leaves or joins the system. Moreover, it is necessary to send the keys securely to the authorized members. Thus, an effective key distribution protocol for Internet Pay‐TV system is designed in this article to lower the computation time taken to compute the re‐keying information. In the proposed protocol, when the Service Provider needs to refresh a new shared secret key and link values, only a few key updating operations are needed, and they can be achieved using four primary operations, namely, hash function, addition, subtraction, and multiplication. From the experimental results, we perceive that the proposed approach takes less computation cost, communication cost and storage cost compared with other competitive protocols available in the literature. Copyright © 2016 John Wiley & Sons, Ltd. Pandi Vijayakumar, Ramu Naresh, SK Hafizul Islam, L. Jegatha Deborah |
Secur. Commun. Networks | 1 |
| 2016 | Dual Authentication and Key Management Techniques for Secure Data Transmission in Vehicular Ad Hoc NetworksabstractVehicular ad hoc networks (VANETs) are an important communication paradigm in modern-day mobile computing for exchanging live messages regarding traffic congestion, weather conditions, road conditions, and targeted location-based advertisements to improve the driving comfort. In such environments, security and intelligent decision making are two important challenges needed to be addressed. In this paper, a trusted authority (TA) is designed to provide a variety of online premium services to customers through VANETs. Therefore, it is important to maintain the confidentiality and authentication of messages exchanged between the TA and the VANET nodes. Hence, we address the security problem by focusing on the scenario where the TA classifies the users into primary, secondary, and unauthorized users. In this paper, first, we present a dual authentication scheme to provide a high level of security in the vehicle side to effectively prevent the unauthorized vehicles entering into the VANET. Second, we propose a dual group key management scheme to efficiently distribute a group key to a group of users and to update such group keys during the users' join and leave operations. The major advantage of the proposed dual key management is that adding/revoking users in the VANET group can be performed in a computationally efficient manner by updating a small amount of information. The results of the proposed dual authentication and key management scheme are computationally efficient compared with all other existing schemes discussed in literature, and the results are promising. Pandi Vijayakumar, Maria Azees, Arputharaj Kannan, L. Jegatha Deborah |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2015 | CPAV: Computationally Efficient Privacy Preserving Anonymous Authentication Scheme for Vehicular Ad Hoc NetworksabstractIn this paper, we propose a computationally efficient privacy preserving anonymous authentication scheme based on the use of anonymous certificates and signatures for vehicular ad hoc networks (VANETs). Even though there were many existing schemes to provide anonymous authentication based on anonymous certificates and signatures in VANETs, the existing schemes suffer from high computation cost in the certificate revocation list (CRL) checking process and in the certificate and the signature verification process. Therefore, it is not possible to verify a large number of messages per second in VANETs which would lead to high message loss. Hence, we use a computationally efficient anonymous mutual authentication mechanism to validate the message source and anonymous signatures in order to guarantee the integrity of messages. Moreover, a conditional tracking mechanism is introduced to trace the real identity of vehicles and revoke them from VANET in the case of dispute. This proposed scheme is implemented and performance analysis shows that our scheme is more efficient in terms of certificate and signature verification delay, while keeping conditional privacy in VANETs. Pandi Vijayakumar, Maria Azees, L. Jegatha Deborah |
CSCloud | 1 |
| 2014 | Chinese remainder theorem based centralised group key management for secure multicast communicationabstractDesigning a centralised group key management with minimal computation complexity to support dynamic secure multicast communication is a challenging issue in secure multimedia multicast. In this study, the authors propose a Chinese remainder theorem‐based group key management scheme that drastically reduces computation complexity of the key server. The computation complexity of key server is reduced to O (1) in this proposed algorithm. Moreover, the computation complexity of group member is also minimised by performing one modulo division operation when a user join or leave operation is performed in a multicast group. The proposed algorithm has been implemented and tested using a key‐star‐based key management scheme and has been observed that this proposed algorithm reduces the computation complexity significantly. Pandi Vijayakumar, Sundan Bose, Arputharaj Kannan |
IET Inf. Secur. | 1 |