EDBT 2026 Demo / reviewers in the wild / expert
Arijit Karati
dblp:177/7510
· DBLP profile ↗
21ranked-venue papers
12as first author
15since 2021 · last 2026
0000-0001-5605-7354ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 3 first-author · 8 since 2021Computer networks · 4 · 4 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 3 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Maliciously Secure and Fully Decentralized Threshold FHE Scheme with Native RNS Acceleration
Ting-Yu Chen 0001, Arijit Karati, Er-Shuo Zhuang, Chun-I Fan |
SECRYPT (1) | 2 |
| 2025 | Attribute-Based Encryption Supporting Multi-Keyword Search With Effective User Revocation in Public Cloud StorageabstractCloud computing has become a prevalent service for data proprietors to outsource their data to public cloud servers while allowing data consumers to retrieve cloud-stored data. While encrypting cloud data helps individuals ensure the security and privacy of cloud data, all-or-nothing encryption hinders effective access control and data search. To address this issue, this paper proposes fine-grained attribute-based encryption supporting multi-keyword-based data search to circumvent critical issues, including the assumption of online third-party authority, expensive user revocation, and a lack of expressiveness on keyword search problems. The proposed protocol empowers users to authorize cloud servers to perform keyword searches on encrypted data without forfeiting data privacy. Besides, the length of the ciphertext and the user key is short and fixed, having no noteworthy impact on the user growth in the system. The proposed protocol is formally secure against the indistinguishability under chosen-plaintext (IND-CPA) attack under the standard model with the generalized decisional Diffie-Hellman assumption. The comprehensive performance analysis of the proposed scheme demonstrates that it outperforms state-of-the-art solutions. Thus, our system is suitable for real-world applications due to its enhanced security characteristics, adaptability, and efficacy. Chun-I Fan, Si-Jing Wu, Yi-Fan Tseng, Arijit Karati |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | QPCASIN: A Quantum-Defended Privacy-Aware Preemptive Handover-Enabled Continuous Authentication in Space Information NetworksabstractThe Space Information Network (SIN) plays a crucial role in terrestrial communication, delivering time-bound services from ground stations to users. It relies on moving low-orbit earth (LEO) satellites for uninterrupted coverage. However, untrustworthy connectivity poses several security challenges during handover services for users maintained by the satellites. While traditional cryptographic techniques provide a degree of security, the advent of quantum computing exposes significant vulnerabilities. This work proposes a quantum-safe and continuous authentication mechanism with handover provision. The proposed authentication protocol uses post-quantum primitives of the Frodo key encapsulation mechanism, currently an approved mechanism under ISO/IEC 18033-2. It ensures privacy and ensures users’ anonymity. The security of the proposed protocol is analyzed using the quantum random oracle (QROM) model. Formal verification confirms its safety for practical adoption as a post-quantum candidate. Further, the performance evaluation shows an authentication delay and energy consumption of the proposed protocol within practical limits, making it a suitable candidate for privacy-preserved post-quantum adoption for SIN. Basker Palaniswamy, Arijit Karati, Ting-Yu Chen 0001, Ashok Kumar Das, Bharat K. Bhargava |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | DSR-CAAP: A Novel Denial of Service Resilient Channel-Aware Authenticated Key Exchange Protocol Suite for SAE J1939abstractThe SAE J1939, a higher-layer broadcast communication protocol with ISO 11898-1 specification at its lower layer, has significantly impacted the automobile industry. However, the SAE J1939 frames lack authenticity and secrecy, rendering it vulnerable to denial-of-service (DoS) attacks. While current authentications establish keys among electronic control units (ECUs), they abort ongoing sessions to re-initiate fresh sessions. We present DSR-CAAP, a robust authenticated key exchange protocol that establishes session keys among ECUs without aborting ongoing sessions during DoS and adaptive DoS. DSR-CAAP offers channel-aware key establishment using a hierarchical-challenge response mechanism. It is provably secure under the random oracle model and verified using the Tamarin. The empirical analysis reveals that DSR-CAAP supports comprehensive security attributes with enhanced 3R (robustness, reliability, and resilience) and reduces bus load, communication, computation, and energy costs. Besides, simulation in MATLAB 2023a reveals that DSR-CAAP outperforms existing protocols in communication response time. Thus, DSR-CAAP provides lightweight, secure solutions for in-vehicle heavy-duty vehicles. Basker Palaniswamy, Arijit Karati |
IEEE Trans. Ind. Informatics | 2 |
| 2024 | QuDPas-FHA: Quantum-Defended Privacy-Preserved Fast Handover Authentication in Space Information Networks
Arijit Karati, Ting-Yu Chen 0001, Kai-Yao Lin |
SECRYPT | 1 |
| 2024 | QPTA: Quantum-Safe Privacy-Preserving Multi-Factor Authentication Scheme for Lightweight Devices
Basker Palaniswamy, Arijit Karati |
SECRYPT | 2 |
| 2024 | SMEBE-CAN: Selective Multicast Encryption Enabled Broadcast Encryption for CAN 2.0BabstractBroadcast encryption schemes for the standard Controller Area Network (CAN 2.0B) reduce bandwidth for data transmission from one electronic control unit (ECU) to others while assuring confidentiality. If received data is damaged, CAN 2.0B enables remote transmission request (RTR), allowing recipient ECUs to request retransmissions. However, retransmission for n ECUs increases the communication cost of current broadcast encryption techniques to a complexity O(n) for intra-vehicular networks (IVNs). This paper designs a novel broadcast encryption called SMEBE-CAN that retains its sublinear complexity of $O(\sqrt {\text{n}} )$ throughout IVN retransmissions. Besides, we devise a robust authenticated key exchange (AKE) protocol using SMEBE-CAN to address IVN data corruption during regular communication. Our protocol is provably secure in the standard model under the harness of the bilinear Diffie-Hellman exponent (BDHE) assumption. Besides, it is formally verified using the Scyther tool. As proof of concept, a performance comparison for 100 ECUs, with 10 ECUs per group, shows that the SMEBE-CAN has a lower authentication delay when ECUs are run at higher frequencies. Nonetheless, it ensures a lower bus load than related schemes, making it fit for practical usage. Basker Palaniswamy, Ting-Yu Chen 0001, Arijit Karati |
VTC Fall | 3 |
| 2024 | A Privacy-Aware Provably Secure Smart Card Authentication Protocol Based on Physically Unclonable FunctionsabstractFor many industrial applications, the smart card is a necessary safety component in user authentication. Smart cards provided to the users are used in open and public places, making them susceptible to physical and cloning attacks. Thus, the opponent can break the authentication process without the smart card if the information is exposed. In addition, many existing authentication systems employ challenge-response pairs (CRPs) to identify users by creating large numbers of data on the server and spending much time looking for and comparing responses. To address these concerns, we propose a lightweight privacy-preserving authentication protocol in which the physically unclonable function is considered a necessary tool. The suggested technique avoids creating a significant number of CRPs on the server to identify users uniquely. Under formal security models, the proposed protocol is resistant to user impersonation attacks and session key disclosure attacks and achieves robust mutual authentication. Nonetheless, it is immune to other essential security vulnerabilities. Empirical performance analysis demonstrates its viability in comparison to prior works. Chun-I Fan, Arijit Karati, Shou-Li Wu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | AnonMAKE: Toward Secure and Anonymous Mutually Authenticated Key Exchange Protocol for Vehicular CommunicationsabstractDue to real-time data sharing in the Intelligent Transportation System (ITS), the automobile industry has evolved enormously in recent years. However, as more vehicles become connected, the peril of cyberattacks increases, necessitating safeguarding traffic safety-related data provided by individual vehicles and public transportation to avoid perilous situations and infringement of confidentiality. In this regard, a recent work (10.1109/TITS.2021.3099488) suggested an anonymous batch data authentication and key exchange protocol. This paper shows that the work lacks true anonymity during authentication, employs a session-independent key, and is prone to session key disclosure and replay attacks. Apart from cryptanalysis, we present a novel privacy-enhancing mutual authentication and key agreement protocol supporting batch authentication resisting comprehensive security attacks in the vehicular system, including traffic data replay, vehicle impersonation, and man-in-the-middle attacks. The suggested scheme achieves security correctness under formal BAN logic analysis and is safer against the STRIDE effect. The empirical performance estimation reveals that the novel approach under adequate security assumptions outperforms the state-of-the-art solutions by achieving about 20% higher security traits while lowering 15% authentication delay, consuming 15% less bandwidth, and increasing 44% storage efficiency. Thus, our protocol is more suitable for lightweight vehicular communications. Arijit Karati, Li-Chun Chang |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2023 | Cryptanalysis of a Lightweight Privacy Enhancing Authentication Scheme for Internet of VehiclesabstractRecent attention has been focused on using authentication and key agreement (AKA) protocols to allow secure vehicle-to-everything (V2X) communication. Typically, such security solutions are effective against passive eavesdroppers who tap the lines and attempt to decipher the message. It has been noted, however, that an improperly designed protocol could be susceptible to an active saboteur, who could impersonate another vehicle or alter the broadcast message. In this paper, we conduct cryptanalytic attacks on a recently proposed energy-efficient authentication protocol. To do this, we employ hybrid techniques to solve the algebraic systems that occur naturally while mounting multiple forgeries. Based on cryptanalysis, we demonstrate that the algorithms and characterizations utilized in this protocol are susceptible to several security flaws, such as inappropriate anonymity, session-independent key agreement, exposing multiple keys, replay, and vehicle impersonation. In addition, this paper provides precepts for constructing a safe V2X authentication system. Arijit Karati, Li-Chun Chang |
ISCC | 1 |
| 2023 | Robust Three-Factor Lightweight Authentication Based on Extended Chaotic Maps for Portable Resource-Constrained Devices
Arijit Karati, Yu-Sheng Chang, Ting-Yu Chen 0001 |
SECRYPT | 1 |
| 2022 | Federated Secure Data Sharing by Edge-Cloud Computing ModelabstractData sharing by cloud computing enjoys benefits in management, access control, and scalability. However, it suffers from certain drawbacks, such as high latency of downloading data, non-unified data access control management, and no user data privacy. Edge computing provides the feasibility to overcome the drawbacks mentioned above. Therefore, providing a security framework for edge computing becomes a prime focus for researchers. This work introduces a new key-aggregate cryptosystem for edge-cloud-based data sharing integrating cloud storage services. The proposed protocol secures data and provides anonymous authentication across multiple cloud platforms, key management flexibility for user data privacy, and revocability. Performance assessment in feasibility and usability paves satisfactory results. Therefore, this work directs a new horizon to detailed new edge-computing-based data sharing services based on the proposed protocol for low latency, secure unified access control, and user data privacy in the modern edge enabled reality. Arijit Karati, Sajal K. Das 0001 |
GLOBECOM | 1 |
| 2022 | Reliable Data Sharing by Certificateless Encryption Supporting Keyword Search Against Vulnerable KGC in Industrial Internet of ThingsabstractOutsourcing Industrial Internet of Things (IIoT) data on the cloud extends the diversity of data analysis for decision making with minimized costs in communications and storage. However, it is adverse to the confidentiality of IIoT data from the owner as access control is performed by honest-but-curious platforms. Although the encryption strategy guarantees data security, it hinders deliverance due to its inbred all-or-nothing decryption. Certificateless encryption supporting keyword search eliminates the overhead of certificates and privileges to retrieve the required data through encrypted keyword search. However, most of the prior works are precarious against a malicious key generation center, which exposes data protected by users’ private keys. We design a certificateless secure data sharing by uniting the functionalities of encryption and access control on search. Our technique resists in/outside keyword guessing attacks and sustains on-demand user revocation. Besides, it achieves Girault’s Level-3 security in the standard model. Nonetheless, empirical performance analysis under a suitable scenario exhibits its feasibility compared to the other related schemes. Arijit Karati, Chun-I Fan, Er-Shuo Zhuang |
IEEE Trans. Ind. Informatics | 1 |
| 2021 | Reliable file transfer protocol with producer anonymity for Named Data Networking
Chun-I Fan, Arijit Karati, Pei-Shan Yang |
J. Inf. Secur. Appl. | 2 |
| 2021 | Provably Secure and Lightweight Identity-Based Authenticated Data Sharing Protocol for Cyber-Physical Cloud EnvironmentabstractSecure and efficient file storage and sharing via authenticated physical devices remain challenging to achieve in a cyber-physical cloud environment, particularly due to the diversity of devices used to access the services and data. Thus in this paper, we present a lightweight identity-based authenticated data sharing protocol to provide secure data sharing among geographically dispersed physical devices and clients. The proposed protocol is demonstrated to resist chosen-ciphertext attack (CCA) under the hardness assumption of decisional-Strong Diffie-Hellman (SDH) problem. We also evaluate the performance of the proposed protocol with existing data sharing protocols in terms of computational overhead, communication overhead, and response time. Arijit Karati, Ruhul Amin 0001, SK Hafizul Islam, Kim-Kwang Raymond Choo |
IEEE Trans. Cloud Comput. | 1 |
| 2019 | Provably Secure and Generalized Signcryption With Public Verifiability for Secure Data Transmission Between Resource-Constrained IoT DevicesabstractThe Internet of Things (IoT) is revolutionizing our modern lives by introducing active connection between smart devices. However, IoT devices are repeatedly exhibiting many security flaws, which will inevitably lead to eavesdropping and impersonation attacks. Thus, providing a proper security in IoT becomes a prime focus for the researchers. In cryptography, certificateless signcryption (CLSC) is one of the recent public key techniques for the security requirements of the authenticity and confidentiality of any message between the parties. In this article, a new generalized CLSC (gCLSC) is introduced to provide the functions of digital signature and encryption to fulfill the authenticity and confidentiality for the resource-constrained IoT devices. Besides, the gCLSC supports the property of public verifiability and security of an ideal signcryption under the strong Diffie-Hellman and bilinear Diffie-Hellman inversion problems without random oracle model. Performance assessment of the gCLSC gives satisfactory results after comparing with other competitive CLSC schemes in terms of its functionality. Therefore, the gCLSC can be adopted in the IoT networks where authenticity, confidentiality, and lightweight are the essential factors. Arijit Karati, Chun-I Fan, Ruei-Hau Hsu |
IEEE Internet Things J. | 1 |
| 2018 | Provably Secure Identity-Based Signcryption Scheme for Crowdsourced Industrial Internet of Things EnvironmentsabstractNowadays, the Internet of Things (IoT) and cloud computing have become more pervasive in the context of the industry as digitization becomes a business priority for various organizations. Therefore, industries outsource their crowdsourced Industrial IoT (IIoT) data in the cloud in order to reduce the cost for sharing data and computation. However, the privacy of such crowdsourced data in this environment has attracted wide attention across the globe. Signcryption is the significant cryptographic primitive that meets both requirement of authenticity and confidentiality of crowdsourced data among users/industries, and thus, it is ideal for ensuring secure authentic data storage and transmission in industrial crowdsourcing environments. In this paper, we introduce a new identity-based signcryption (IBSC) scheme using bilinear pairing for IIoT deployment. Besides, two hard problems are studied, called as, modified bilinear Diffie-Hellman inversion (MBDHI) assumption and modified bilinear strong Diffie-Hellman (MBSDH) assumption. The rigorous security analysis demonstrates that our IBSC scheme for IIoT is provably secure based on the intractability of decisional-MBDHI and MBSDH assumptions under formal security model without considering the concept of the random oracle. The performance comparison with other signcryption schemes shows satisfactory results. Thus, our IBSC scheme is appropriate for IIoT crowdsourcing environments, and also applicable for low-bandwidth communications. Arijit Karati, SK Hafizul Islam, G. P. Biswas, Md. Zakirul Alam Bhuiyan, Pandi Vijayakumar, Marimuthu Karuppiah |
IEEE Internet Things J. | 1 |
| 2018 | A pairing-free and provably secure certificateless signature scheme
Arijit Karati, SK Hafizul Islam, G. P. Biswas |
Inf. Sci. | 1 |
| 2018 | Provably Secure and Lightweight Certificateless Signature Scheme for IIoT EnvironmentsabstractIn recent years, two technologies, the cloud computing and the Internet of Things (IoT), have a synergistic effect in the modern organizations as digitization is a new business trend for various industries. Therefore, many organizations outsource their crowdsourced industrial-IoT (IIoT) data in the cloud system to reduce data management overhead. However, data authentication is one of the fundamental security/trust requirements in such IIoT network. The certificateless signature (CLS) scheme is a cryptographic primitive that provides data authenticity in IIoT systems. Recently, CLS has become a prime research focus due to its ability to solve the key-escrow problem in a very recent identity-based signature technique. Many CLS schemes have already been developed using map-to-point (MTP) hash function and random oracle model (ROM). However, due to the implementation difficulty and probabilistic nature of MTP function and ROM, those CLSs are impractical. Hence, the development of a CLS for lightweight devices mounted in IIoT has become one of the most focused research trends. This paper presents a new pairing-based CLS scheme without MTP function and ROM. The new CLS scheme is secure against both the Type-I and Type-II adversaries under the hardness of extended bilinear strong Diffie-Hellman (BSDH) and BSDH assumptions, respectively. Performance evaluation and comparison proves that our scheme outperforms other CLS schemes. Arijit Karati, SK Hafizul Islam, Marimuthu Karuppiah |
IEEE Trans. Ind. Informatics | 1 |
| 2017 | A Two-Factor RSA-Based Robust Authentication System for Multiserver EnvironmentsabstractThe concept of two-factor multiserver authentication protocol was developed to avoid multiple number of registrations using multiple smart-cards and passwords. Recently, a variety of two-factor multiserver authentication protocols have been developed. It is observed that the existing RSA-based multiserver authentication protocols are not suitable in terms of computation complexities and security attacks. To provide lower complexities and security resilience against known attacks, this article proposes a two-factor (password and smart-card) user authentication protocol with the RSA cryptosystem for multiserver environments. The comprehensive security discussion proved that the known security attacks are eliminated in our protocol. Besides, our protocol supports session key agreement and mutual authentication between the application server and the user. We analyze the proof of correctness of the mutual authentication and freshness of session key using the BAN logic model. The experimental outcomes obtained through simulation of the Automated Validation of Internet Security Protocols and Applications (AVISPA) S/W show that our protocol is secured. We consider the computation, communication, and storage costs and the comparative explanations show that our protocol is flexible and efficient compared with protocols. In addition, our protocol offers security resilience against known attacks and provides lower computation complexities than existing protocols. Additionally, the protocol offers password change facility to the authorized user. Ruhul Amin 0001, SK Hafizul Islam, Muhammad Khurram Khan, Arijit Karati, Debasis Giri, Saru Kumari |
Secur. Commun. Networks | 4 |
| 2016 | Efficient and provably secure random oracle-free adaptive identity-based encryption with short-signature schemeabstractAbstract Identity‐based encryption (IBE) is one of the important public key encryption techniques where not only the identity of the receiver is used for secure and efficient encryption, but it also has several merits over other traditional public‐key ones. However, two main disadvantages of many such IBE‐based systems are the requirement of a large number of public parameters and different random oracle operations, where it is known that a random oracle due to improper implementation is vulnerable under chosen ciphertext attack. This paper designs an efficient IBE scheme (ROFIBE) with recipient anonymity, reduction in public parameters and random oracle‐free operation. The scheme is developed based on a proposed hard problem, named as decisional extended bilinear Diffie‐Hellman assumption (DEBDH) and on analysis it is found to be secured under standard security model. In addition, a new short‐signature scheme based on the proposed IBE is developed under the difficulty of solving proposed q−extended bilinear strong Diffie–Hellman assumption (q‐EBSDH). As performance analysis, we compare both the proposed schemes with other existing related ones and find that our schemes are computationally and communicationally efficient and effectively usable in real life applications. Copyright © 2016 John Wiley & Sons, Ltd. Arijit Karati, G. P. Biswas |
Secur. Commun. Networks | 1 |