EDBT 2026 Demo / reviewers in the wild / expert
Zahid Ghaffar
dblp:261/8334
· DBLP profile ↗
11ranked-venue papers
1as first author
11since 2021 · last 2026
0000-0002-5546-2689ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 9 · 1 first-author · 9 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Lightweight Authentication Scheme for Securing Patient Information in the Internet of Medical Things EnvironmentabstractThe Internet of Things (IoT) is an evolving paradigm expected to permeate every aspect of human existence. IoT is a growing trend in which numerous devices interconnect with each other to transmit sensitive data. One of its significant application areas is the Internet of Medical Things (IoMT), which promises a contemporary healthcare environment via linked sensors, clinical systems, and wearable medical devices. However, public communication among these devices faces challenges like security, privacy, authentication, and machine learning/modeling attacks. Additionally, most existing schemes are vulnerable to impersonation, denial-of-service, and machine-learning/modeling attacks. Therefore, this article addresses these challenges by designing a lightweight authentication scheme that utilizes a one-time physical unclonable function (OPUF) and elliptic curve cryptography to reduce the likelihood of machine learning/modeling attacks on wearable medical devices. We utilizeOPUFto resist machine learning/modeling attacks. We also employ a rate-limiting mechanism that restricts the number of authentication requests within a specific time window to enhance resistance against denial-of-service (DoS) attacks. Moreover, the devised scheme also offers resistance to impersonation, session key leakage, ephemeral secret leakage, desynchronization, and ML-based modeling attacks. We analyze the security and reliability of the devised scheme using informal and formal analysis. Informal analysis indicates that the scheme offers essential security features, while formal analysis substantiates these findings. In the end, we present the results of the performance analysis, which show that the devised scheme achieves an average reduction of 26.92% and 21.53% in computational and communication costs, respectively. Wen-Chung Kuo, Zahid Ghaffar, Khalid Mahmood 0002, Tayyaba Tariq, Salman Shamshad, Ashok Kumar Das |
IEEE Internet Things J. | 2 |
| 2026 | Digital Twin-Enabled Context-Aware Authentication Protocol for IoT-Based Healthcare ApplicationsabstractThe convergence of Digital Twin (DT) technology with Internet of Things (IoT)-based healthcare systems offers promising capabilities for real-time monitoring, personalized treatment, and predictive diagnostics. However, the integration of context-aware data flows and dynamic device interactions introduces critical security and privacy challenges such as impersonation, desynchronization, and physical tampering attacks. To address these concerns, this paper proposes a lightweight, context-aware authentication protocol using Authenticated Encryption with Associated Data (AEAD), Physical Unclonable Functions (PUFs), and cryptographic hash functions within a DT-enabled framework. The protocol supports mutual authentication and secure key establishment among sensing devices, gateways, and medical servers, while protecting device identities and ensuring data confidentiality and integrity without relying on stored credentials. A key innovation of this work is context enforcement through data-type authorization, where each sensing device is restricted to transmit only predefined categories of physiological data (e.g., temperature, oxygen saturation), thereby achieving fine-grained, semantics-driven access control. Security analysis under the Real-Or-Random (ROR) model confirms the protocol’s resistance to impersonation, desynchronization, replay, and leakage of ephemeral secrets. Performance evaluation demonstrates a 25.85% reduction in computational overhead and a 31.59% reduction in communication cost compared to relevant baseline protocols. These results validate the protocol’s effectiveness for securing resource-constrained, real-time healthcare systems in DT-enabled IoT environments. Muhammad Asad Saleem, Xiong Li 0002, Khalid Mahmood 0002, Salman Shamshad, Zahid Ghaffar |
IEEE Internet Things J. | 5 |
| 2026 | PUF-Enabled Key-Exchange Protocol for Vehicular Ad-Hoc NetworksabstractThe Internet of Vehicles (IoV) enables data exchange among individuals, cloud resources, road infrastructures, and vehicles, interconnected through Vehicular Ad Hoc Networks (VANETs). VANETs comprise vehicles with Onboard Units (OBUs), Roadside Units (RSUs), and a Trusted Party Agent (TPA). The data transmission among these entities supports seamless interaction and collaborative traffic management. However, data transmission on public communication channels in VANETs presents significant challenges, including security, privacy, and authentication of participating entities. Although numerous key exchange and authentication protocols have been introduced to tackle these issues, many protocols remain vulnerable to various attacks, such as a vehicle, RSU, TPA impersonation, denial of service, physical cloning, and desynchronization attacks. Therefore, to address these vulnerabilities, we propose a key exchange protocol that leverages hash functions and Advanced Encryption Standard (AES) encryption. Our protocol also integrates the Physical Unclonable Function (PUF), enhancing its resistance to physical or cloning attacks. Additionally, it effectively counters threats like impersonation, session key leakage, ephemeral secret leakage, and desynchronization attacks. We validate the security and reliability of our protocol through both formal and informal analysis. Informal analysis highlights the protocol’s essential security features, while formal analysis provides robust substantiation. Performance evaluation reveals that our protocol achieves an average reduction of 35.53%, and 53.77%, in communication and computation overheads. Khalid Mahmood 0002, Zahid Ghaffar, Muhammad Farooq 0004, Muhammad Ilyas 0001, Ashok Kumar Das, Shehzad Ashraf Chaudhry |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2025 | A Cost-Effective Key Agreement Encryption Protocol for Securing IIoT-Enabled WSN CommunicationabstractWireless sensor networks (WSNs), pivotal in the industrial Internet of Things (IIoT), encompass resource-limited sensor nodes, users, and gateways. Advancements in Internet technologies have substantially facilitated remote data access, rendering WSNs indispensable across various sectors, such as defense, agriculture, disaster management, and healthcare, where they serve as pivotal components for remote monitoring and control mechanisms. Within the IIoT framework, the transmission of critical and sensitive information over public channels presents significant security challenges. Such challenges disrupt operations and compromise the integrity and reliability of industrial processes. The system must include an authentication mechanism to tackle this critical issue that resists potential security threats. Consequently, this article introduced a reliable and secure the three-factor authentication protocol tailored for IIoT environments. The proposed protocol aims to mitigate unauthorized access and safeguard the integrity of industrial operations. We comprehensively evaluated the protocol’s robustness and security efficiency by employing informal and formal security analysis techniques, highlighting its effectiveness in resisting potential threats. This proposed protocol fortifies the network against potential security threats, ensuring security and system reliability in industrial applications. This protocol assists only legitimate users in accessing the sensing devices remotely. Moreover, the statistical results endorse the resource efficiency of the devised protocol as it achieves 43.2% and 35.8% efficiency in terms of communication and computational costs, respectively. Khalid Mahmood 0002, Mah Noor Fatima, Salman Shamshad, Zahid Ghaffar, Ashok Kumar Das, Mohammed J. F. Alenazi |
IEEE Internet Things J. | 4 |
| 2025 | A Privacy-Preserving Access Control Protocol for Consumer Flying Vehicles in Smart City ApplicationsabstractThe Internet of Drones (IoD) offers supervised admittance to drones in a targeted fly zone as the byproduct of the Internet of Things (IoT). The term drone is the trendy alias for intelligent flying vehicle (IFV). The contemporary sensing, processing, and connectivity services enrich the use of drones in many civilian and military applications. In these applications, consumers can acquire real-time information directly from flying drones in a smart city environment. While this feature undeniably empowers consumers, it poses significant security risks due to the direct access privilege. We propose an anonymous protocol for consumer flying vehicles within smart city applications to mitigate these threats. The proposed protocol utilizes a physically unclonable function to sustain the physical security of flying vehicles. We ratify our protocol’s security fortitude and persistence through inclusive security analysis. We demonstrate the performance evaluation under diverse performance metrics, which shows that the proposed protocol achieves 40.69% and 17.91% efficiency as compared to related protocols in terms of computation and communication cost comparison, respectively. Khalid Mahmood 0002, Zahid Ghaffar, Lata Nautiyal, Muhammad Wahid Akram, Ashok Kumar Das, Mohammed J. F. Alenazi |
IEEE Internet Things J. | 2 |
| 2025 | Provably Secure Authenticated Key-Management Mechanism for e-Healthcare EnvironmentabstractThe Internet of Things (IoT) is rapidly permeating all aspects of human life, involving a network of devices that share sensitive data. A notable application is the e-healthcare systems, which employ connected sensors, medical servers, and wearable devices. However, the public nature of communication in e-healthcare systems poses challenges such as security, privacy, and authentication of participating entities. Recently, many authentication protocols have been introduced to address these challenges. However, most of these protocols remain vulnerable to various security attacks, including device or medical server impersonation, denial of service, physical or cloning, and de-synchronization attacks. Therefore, we introduce an authenticated key-management protocol utilizing hash functions and Cipher-Block Chaining-Advanced Encryption Standard encryption (CBC-AES) encryption. The proposed protocol also employs the Physical Unclonable Function (PUF), which makes it more robust and efficient in resisting physical or cloning attacks. Additionally, the proposed scheme resists various security threats, including impersonation, session key leakage, ephemeral secret leakage, and de-synchronization attacks. We analyze the scheme’s security and reliability through formal and informal analysis. The informal analysis demonstrates that the scheme encompasses crucial security features, while the formal analysis substantiates. Moreover, performance analysis of the proposed protocol with various competing results indicates that our protocol achieves an average reduction in communication and computation overheads by 36.03.% and 41.79%, respectively. Muhammad Asad Saleem, Xiong Li 0002, Khalid Mahmood 0002, Zahid Ghaffar, Yong Xie 0003 |
IEEE Internet Things J. | 4 |
| 2025 | A Lightweight and Robust Access Control Protocol for IoT-Based e-Healthcare NetworkabstractInternet of Things (IoT) devices are crucial components in e-healthcare networks. It enables remote patient health monitoring and facilitates seamless communication among medical sensors, wearable devices, and healthcare providers through public communication channels. Despite these advantages, the use of public communication among medical sensors in e-healthcare networks introduces critical challenges, such as vulnerability to impersonation, physical capture, and ephemeral secret leakage, particularly in resource-constrained environments. In recent years, various access control protocols have been developed to mitigate these risks. However, these protocols often fail to ensure robust security while incurring significant communication and computation overhead. To overcome these limitations, we propose a lightweight and robust access control protocol for IoT-based e-healthcare networks using chaotic maps. We propose a novel protocol that integrates a PUF-based mechanism to mitigate the challenges of physical tampering and cloning attacks in e-healthcare networks. It leverages the inherent uniqueness of PUF and enhances security through the high-entropy properties of chaotic maps. We analyze the proposed protocol informally, which confirms that it significantly bolsters efficiency and security. We also validate the security using the Random or Real (RoR) model. Moreover, we verify the security of the proposed protocol using Scyther. These analyses highlight that the proposed protocol offers robust resistance to numerous attacks, such as impersonation, physical capture, and ephemeral secret leakage. Moreover, we also compare it with existing and relevant protocols. The comparative analysis showcases its superior performance. Notably, the proposed authentication protocol significantly reduces 46.84% computational overhead and decreases 31.30% communication overhead, underscoring its enhanced performance and resource efficiency. Zahid Ghaffar, Wen-Chung Kuo, Khalid Mahmood 0002, Tayyaba Tariq, Salman Shamshad, Ashok Kumar Das, Mohammed J. F. Alenazi |
IEEE Trans. Mob. Comput. | 1 |
| 2024 | A Security Enhanced Chaotic-Map-Based Authentication Protocol for Internet of DronesabstractThe Internet of Drones (IoD) extends the capabilities of unmanned aerial vehicles, enabling them to participate in a connected network. In IoD infrastructure, drones communicate not only among themselves but also with users and a control center. This interconnected communication framework holds promise for various applications, from collaborative decision-making to real-time data exchange. However, the expansion of communication in IoD also introduces new challenges, particularly in terms of security, privacy and authentication. Unfortunately, the current authentication protocols are inadequate in offering robust security features against various attacks in the IoD environment. To address these security issues and limitations, we proposed a secure protocol for the IoD environment using chaotic maps and hash functions. In addition, we also employed a physically unclonable function in the development of the proposed protocol. We assess the security of the protocol through both informal and formal security analysis. The formal security analysis is conducted through a widely used random or real (RoR) model. The informal analysis shows the rigorous security features against various attacks, such as masquerading, anonymity violation, and physical cloning attacks. Moreover, we compare the performance of the devised protocol with similar existing protocols across important performance parameters such as communication overhead, computation overhead, and security features. The devised protocol provides a 67.86% and 17.80% reduction in computation and communication overheads, respectively, as compared to related protocols. The analysis demonstrates the proposed protocol’s capacity to support secure communication in the IoD environment and satisfy desirable security attributes. Khalid Mahmood 0002, Zahid Ghaffar, Muhammad Farooq 0004, Khalid Yahya, Ashok Kumar Das, Shehzad Ashraf Chaudhry |
IEEE Internet Things J. | 2 |
| 2023 | Design of Provably Secure Authentication Protocol for Edge-Centric Maritime Transportation SystemabstractThe epidemic growth of the Internet of Things (IoT) objects have revolutionized Maritime Transportation Systems (MTS). Though, it becomes challenging for the centralized cloud-centric framework to fulfil the application requirements such as low latency and power utilization. The introduction of the distributed edge-centric framework has recently helped the IoT-enabled MTS to meet these requirements by manipulating the tasks at the edge of the networks. Despite the fact that MTS leverages mobile subscribers by overcoming inherent cloud computing limitations, data security and user privacy requirements in establishing the MTS setup are still non-trivial challenges. In this article, we develop a key agreement solution for mobile users to realize mutual authentication in a single round. Our protocol offers user anonymity to maintain user privacy, and it can prevent physical attacks by physically unclonable functions. Initially, the security analysis is conferred to substantiate our protocol’s security persistence or strength. Later, its performance correlation is observed under the assumption of diverse metrics in a predefined empirical setup. The meticulous performance correlation endorses the precedence of our protocol over specified related protocols. Khalid Mahmood 0002, Salman Shamshad, Muhammad Faizan Ayub, Zahid Ghaffar, Muhammad Khurram Khan, Ashok Kumar Das |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2022 | A seamless anonymous authentication protocol for mobile edge computing infrastructure
Khalid Mahmood 0002, Muhammad Faizan Ayub, Syed Zohaib Hassan, Zahid Ghaffar, Zhihan Lyu, Shehzad Ashraf Chaudhry |
Comput. Commun. | 4 |
| 2021 | Provably Secure Authentication Protocol for Mobile Clients in IoT Environment Using Puncturable Pseudorandom FunctionabstractThe Internet of Things (IoT) is a framework of various services and smart technologies that mutually communicate information between mobile devices and users or just between devices with the help of Internet connectivity. The dramatic progression of IoT helps numerous network applications and communication technologies to introduce state-of-the-art communication models for enabling interaction among mobile server, clients, and various other smart entities. Now-a-days, online mobile services have gained huge attention by providing ample convenience to the distant users. However, it is necessary to secure the information, being exchanged among mobile clients and server. Therefore, a large number of authentication protocols have been presented but majority of them are unsuitable to fulfill novel security requirements and standards. Moreover, they are incompatible for the IoT environment due to higher computation and communication complexity. Consequently, there is a dire need of developing an adequate, reliable, and cost-effective authentication protocol. In this article, we introduce a novel identity-based key agreement protocol using the puncturable pseudorandom functions for mobile clients in the IoT environment. The proposed PSK-MC protocol enables two mobile clients to accomplish mutual authentication via server. The proposed protocol is evaluated formally and informally to determine its security strength. The formal security analysis is presented using the widely used random oracle model. Moreover, all the cryptographic operations used at mobile client side are executed on a mobile device, while the operations used at the server side are implemented on a desktop machine to get the experimental results to determine computation cost. The performance analysis reveals the fact that our protocol is comparatively better than related protocols by exhibiting least communication and computation overhead. Muhammad Asad Saleem, Zahid Ghaffar, Khalid Mahmood 0002, Ashok Kumar Das, Joel J. P. C. Rodrigues, Muhammad Khurram Khan |
IEEE Internet Things J. | 2 |