EDBT 2026 Demo / reviewers in the wild / expert
Muhammad Asad Saleem
dblp:263/6821
· DBLP profile ↗
14ranked-venue papers
9as first author
11since 2021 · last 2026
0000-0001-5471-8446ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Applied, interdisciplinary, general and emerging computing · 7 · 4 first-author · 6 since 2021Computer networks · 5 · 4 first-author · 4 since 2021Security and privacy · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Digital Twin-Enabled Context-Aware Authentication Protocol for IoT-Based Healthcare ApplicationsabstractThe convergence of Digital Twin (DT) technology with Internet of Things (IoT)-based healthcare systems offers promising capabilities for real-time monitoring, personalized treatment, and predictive diagnostics. However, the integration of context-aware data flows and dynamic device interactions introduces critical security and privacy challenges such as impersonation, desynchronization, and physical tampering attacks. To address these concerns, this paper proposes a lightweight, context-aware authentication protocol using Authenticated Encryption with Associated Data (AEAD), Physical Unclonable Functions (PUFs), and cryptographic hash functions within a DT-enabled framework. The protocol supports mutual authentication and secure key establishment among sensing devices, gateways, and medical servers, while protecting device identities and ensuring data confidentiality and integrity without relying on stored credentials. A key innovation of this work is context enforcement through data-type authorization, where each sensing device is restricted to transmit only predefined categories of physiological data (e.g., temperature, oxygen saturation), thereby achieving fine-grained, semantics-driven access control. Security analysis under the Real-Or-Random (ROR) model confirms the protocol’s resistance to impersonation, desynchronization, replay, and leakage of ephemeral secrets. Performance evaluation demonstrates a 25.85% reduction in computational overhead and a 31.59% reduction in communication cost compared to relevant baseline protocols. These results validate the protocol’s effectiveness for securing resource-constrained, real-time healthcare systems in DT-enabled IoT environments. Muhammad Asad Saleem, Xiong Li 0002, Khalid Mahmood 0002, Salman Shamshad, Zahid Ghaffar |
IEEE Internet Things J. | 1 |
| 2026 | DroneSec: Efficient and Secure Communication for Resource-Constrained Drones in IoD SystemsabstractThe Internet of Drones (IoD) represents an emerging paradigm of the Internet of Things (IoT), enabling seamless, coordinated communication among drones and integration with other connected systems. This interconnected network enables autonomous decision-making among drones. As this IoD paradigm continues to expand it faces significant challenges due to its reliance on public channel. Therefore, existing methods often suffer from impersonation, cloning, anonymity violation, and fails to offer end-to-end key secrecy. Moreover, they require high computation resources which present challenges of deployment in resource-constrained IoD environment. To address these challenges, we propose a secure and efficient protocol that provides mutual authentication among participating entities. The protocol resists impersonation, cloning, anonymity violation and offers end-to-end key secrecy. The protocol employs Physical Unclonable Function (PUF) and Elliptic Curve Cryptography (ECC), along with a fuzzy extractor, to ensure secure communication. The resilience of the proposed protocol was evaluated through an informal analysis. Its security properties were rigorously verified using formal analysis based on the Real-Or-Random (ROR) model. Evaluation of its performance shows that the proposed protocol outperforms existing solutions, achieving reductions of 20.9% in computation cost and 32.6% in communication overhead. The results demonstrate that the protocol improves security and provides reliability under the evaluated scenarios of IoD systems. Anum Lodhi, Xiong Li 0002, Muhammad Asad Saleem, Muhammad Ali Lodhi, Khalid Mahmood 0002, Salman Shamshad |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2025 | Provably Secure Authenticated Key-Management Mechanism for e-Healthcare EnvironmentabstractThe Internet of Things (IoT) is rapidly permeating all aspects of human life, involving a network of devices that share sensitive data. A notable application is the e-healthcare systems, which employ connected sensors, medical servers, and wearable devices. However, the public nature of communication in e-healthcare systems poses challenges such as security, privacy, and authentication of participating entities. Recently, many authentication protocols have been introduced to address these challenges. However, most of these protocols remain vulnerable to various security attacks, including device or medical server impersonation, denial of service, physical or cloning, and de-synchronization attacks. Therefore, we introduce an authenticated key-management protocol utilizing hash functions and Cipher-Block Chaining-Advanced Encryption Standard encryption (CBC-AES) encryption. The proposed protocol also employs the Physical Unclonable Function (PUF), which makes it more robust and efficient in resisting physical or cloning attacks. Additionally, the proposed scheme resists various security threats, including impersonation, session key leakage, ephemeral secret leakage, and de-synchronization attacks. We analyze the scheme’s security and reliability through formal and informal analysis. The informal analysis demonstrates that the scheme encompasses crucial security features, while the formal analysis substantiates. Moreover, performance analysis of the proposed protocol with various competing results indicates that our protocol achieves an average reduction in communication and computation overheads by 36.03.% and 41.79%, respectively. Muhammad Asad Saleem, Xiong Li 0002, Khalid Mahmood 0002, Zahid Ghaffar, Yong Xie 0003 |
IEEE Internet Things J. | 1 |
| 2024 | A Cost-Efficient Anonymous Authenticated and Key Agreement Scheme for V2I-Based Vehicular Ad-Hoc NetworksabstractThe rise of smart cities is directly connected to the increasing use of vehicles. The growing vehicle utilization has driven the emergence of Vehicular Ad-hoc Networks (VANETs), facilitating instant information exchange among vehicles. The system provides essential information regarding road conditions, traffic patterns, and more relevant data. VANETs encompass two fundamental categories of communication exchanges, namely Vehicle-to-Vehicle (V2V) and Vehicle-to-Infrastructure (V2I). V2I technology facilitates the integration of cars and transportation infrastructure, enabling effective communication between vehicles and infrastructure. Nevertheless, the potential of V2I communication has various security concerns arising from prevalent security threats. Current authentication techniques encounter challenges regarding complexity, security, and privacy considerations. We designed a hash-based lightweight and anonymous authentication scheme to address the aforementioned restrictions and enhance the effectiveness of authentication in V2I architecture. This scheme effectively combines identity, password, and bio-metric to enhance resistance against impersonation, denial of service, and privileged insider attacks. The devised scheme distinguishes itself by a comparative analysis and security proofs, highlighting its superior capability in guaranteeing secure authentication in V2I communication. The comprehensive security analysis conducted formally and informally showcases the robustness of the proposed solution against several threats. The performance evaluation results show that our scheme demonstrates a decrease in the computational cost of 51.40% approximately and a reduction in communication overhead of around 22.57%. These results establish the efficiency and scalability of the proposed scheme as a viable solution for V2I architecture. Muhammad Asad Saleem, Xiong Li 0002, Khalid Mahmood 0002, Salman Shamshad, Mohammed J. F. Alenazi, Ashok Kumar Das |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2024 | Secure RFID-Assisted Authentication Protocol for Vehicular Cloud Computing EnvironmentabstractVehicular network technology has made substantial advancements in recent years in the field of Intelligent Transportation Systems. Vehicular Cloud Computing (VCC) has emerged as a novel paradigm with a substantial increase in data exchange within Vehicular ad-hoc networks (VANETs). VCC integrates cloud computing, vehicular networking, and Internet of Things (IoT) technologies. It enables Infrastructure-to-Vehicle (I2V), Vehicle-to-Vehicle (V2V), and Vehicle-to-Device (V2D) communication. VCC optimizes vehicle, cloud infrastructure, and IoT resources while addressing significant communication security and vehicle-user privacy challenges. To address these issues, we developed an RFID-based authentication protocol for VCC based on a Henon map using a hash function. In addition, we also incorporated a Physical Unclonable Function (PUF) to resist physical tampering attacks. We validate the protocol’s security formally and informally. The formal security analysis is conducted through a widely used RoR model. We use the Scyther simulation tool to verify the proposed protocol’s security against various attacks. Moreover, we compare the performance of our protocol with similar existing protocols across important performance parameters such as communication and computation overheads and security attributes. The proposed protocol yields substantial improvements, demonstrating a 40.74% reduction in computation overhead and a 13.03% decrease in communication overhead as compared to related protocols, delivering both enhanced performance and resource efficiency. The analysis demonstrates its capacity to support secure communication in the VCC environment and satisfy desirable security attributes. Muhammad Asad Saleem, Xiong Li 0002, Khalid Mahmood 0002, Tayyaba Tariq, Mohammed J. F. Alenazi, Ashok Kumar Das |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2023 | A Provably Secure Lightweight Key Agreement Protocol for Wireless Body Area Networks in Healthcare SystemabstractWireless Body Area Network (WBAN) is a vital application of the Internet of Things (IoT) that plays a significant role in gathering a patient's healthcare information. This collected data helps special professionals like doctors or physicians analyze patients' health status to cure different diseases. However, collecting such information from an insecure channel can be threatening due to the potential security threats. Therefore, it is crucial to secure this sensitive information. This article proposes a secure and lightweight authentication protocol for WBAN. The devised protocol is scalable, secure, and lightweight compared to various relevant competing protocols. The informal security analysis shows that the designed protocol is lightweight, secure, and efficient in resisting various major attacks. The performance analysis demonstrates our protocol's supremacy over various competing protocols in terms of computation and communication costs, inducing efficiency of 20.3% and 12.3%, respectively. Moreover, the practical performance of the designed protocol from the network point of view is measured using the widely recognized NS3 simulation tool. Maryam Zia, Mohammad S. Obaidat, Khalid Mahmood 0002, Salman Shamshad, Muhammad Asad Saleem, Shehzad Ashraf Chaudhry |
IEEE Trans. Ind. Informatics | 5 |
| 2023 | A Provably Secure Mobile User Authentication Scheme for Big Data Collection in IoT-Enabled Maritime Intelligent Transportation SystemabstractThe emergence of contemporary technologies like cloud computing and the Internet of Things (IoT) has revolutionized the trends in the cyber world to serve humanity. There are plenty of applications in which they are being used, especially in smart cities and their constituents, Maritime Transportation System (MTS) is one of them. The IoT-enabled MTS has the potential to entertain the growing challenges of modern-day ship transportation. Secure real-time data access from numerous smart IoT devices is the most critical and crucial exercise for Big Data acquisition in IoT-enabled MTS. Therefore, we have developed a Physically Unclonable Function (PUF) based authenticated key agreement solution to deal with this challenge. This solution enables the mobile user and IoT node to mutually authenticate each other via Cloud-Gateway before real-time data exchange and transmission in IoT-enabled MTS. The use of PUF in our solution brings invincibility against physical security threats. An inclusive security analysis under the assumption of the specified threat model is carried out to substantiate the security resilience of our solution. The conduct of our solution is realized through security features, communication, and computation cost and It has been observed that our solution achieves efficiency of 37.3% and 9.7% in communication and computation overhead, respectively. Moreover, the network performance effectiveness of our solution is demonstrated in NS3 implementation. Khalid Mahmood 0002, Javed Ferzund, Muhammad Asad Saleem, Salman Shamshad, Ashok Kumar Das, Youngho Park 0005 |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2023 | An Efficient and Physically Secure Privacy-Preserving Key-Agreement Protocol for Vehicular Ad-Hoc NetworkabstractThe popularity of vehicles promotes the evolution of smart cities. This development makes vehicular ad-hoc network (VANET) a widely used inter-vehicular communication to obtain information about road conditions, speed, vehicle location and traffic congestion. Such a public network is vulnerable to different security threats. Overall, the security of private data in VANET is a critical task. It has been observed that various authentication protocols have been devised for VANETs. However, most of the proposed protocols are not secure and reliable because of different security threats, including denial of service, replay, forgery and impersonation attacks, etc. Furthermore, the existing protocols used extra communication overhead and computational cost, so they become infeasible for resource-constrained environments. In this article, we design a lightweight and secure privacy-preserving key agreement protocol for VANETs using the hashing technique, which provides an efficient and secure data transmission mechanism over a public communication channel. Detailed security analysis shows that the proposed protocol is secure against various attacks. To evaluate the performance of the protocol, we simulate key cryptographic operations of vehicles, a roadside unit, and a trusted party agent on Arduino, low-end and high-end devices, respectively. The experimental results show that compared with the other related protocols, the computational cost and communication overhead of our protocol are reduced on average by 8.797% and 22.06 %, respectively. Additionally, simulation results on NS3 show that our protocol consistently achieves a packet delivery ratio higher than 99.91 %. Therefore, our protocol is secure and reliable for VANET environment. Muhammad Asad Saleem, Xiong Li 0002, Muhammad Faizan Ayub, Salman Shamshad, Fan Wu 0003, Haider Abbas |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2022 | A Secure and Lightweight Drones-Access Protocol for Smart City SurveillanceabstractThe rising popularity of ICT and the Internet has enabled Unmanned Aerial Vehicle (UAV) to offer advantageous assistance to Vehicular Ad-hoc Network (VANET), realizing a relay node’s role among the disconnected segments in the road. In this scenario, the communication is done between Vehicles to UAVs (V2U), subsequently transforming into a UAV-assisted VANET. UAV-assisted VANET allows users to access real-time data, especially the monitoring data in smart cities using current mobile networks. Nevertheless, due to the open nature of communication infrastructure, the high mobility of vehicles along with the security and privacy constraints are the significant concerns of UAV-assisted VANET. In these scenarios, Deep Learning Algorithms (DLA) could play an effective role in the security, privacy, and routing issues of UAV-assisted VANET. Keeping this in mind, we have devised a DLA-based key-exchange protocol for UAV-assisted VANET. The proposed protocol extends the scalability and uses secure bitwise XOR operations, one-way hash functions, including user’s biometric verification when users and drones are mutually authenticated. The proposed protocol can resist many well-known security attacks and provides formal and informal security under the Random Oracle Model (ROM). The security comparison shows that the proposed protocol outperforms the security performance in terms of running time cost and communication cost and has effective security features compared to other related protocols. Muhammad Wahid Akram, Ali Kashif Bashir, Salman Shamshad, Muhammad Asad Saleem, Ahmad Ali AlZubi, Shehzad Ashraf Chaudhry, Bander A. Alzahrani, Yousaf Bin Zikria |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2021 | Provably Secure Authentication Protocol for Mobile Clients in IoT Environment Using Puncturable Pseudorandom FunctionabstractThe Internet of Things (IoT) is a framework of various services and smart technologies that mutually communicate information between mobile devices and users or just between devices with the help of Internet connectivity. The dramatic progression of IoT helps numerous network applications and communication technologies to introduce state-of-the-art communication models for enabling interaction among mobile server, clients, and various other smart entities. Now-a-days, online mobile services have gained huge attention by providing ample convenience to the distant users. However, it is necessary to secure the information, being exchanged among mobile clients and server. Therefore, a large number of authentication protocols have been presented but majority of them are unsuitable to fulfill novel security requirements and standards. Moreover, they are incompatible for the IoT environment due to higher computation and communication complexity. Consequently, there is a dire need of developing an adequate, reliable, and cost-effective authentication protocol. In this article, we introduce a novel identity-based key agreement protocol using the puncturable pseudorandom functions for mobile clients in the IoT environment. The proposed PSK-MC protocol enables two mobile clients to accomplish mutual authentication via server. The proposed protocol is evaluated formally and informally to determine its security strength. The formal security analysis is presented using the widely used random oracle model. Moreover, all the cryptographic operations used at mobile client side are executed on a mobile device, while the operations used at the server side are implemented on a desktop machine to get the experimental results to determine computation cost. The performance analysis reveals the fact that our protocol is comparatively better than related protocols by exhibiting least communication and computation overhead. Muhammad Asad Saleem, Zahid Ghaffar, Khalid Mahmood 0002, Ashok Kumar Das, Joel J. P. C. Rodrigues, Muhammad Khurram Khan |
IEEE Internet Things J. | 1 |
| 2021 | Provably secure biometric-based client-server secure communication over unreliable networks
Muhammad Asad Saleem, SK Hafizul Islam, Shafiq Ahmed, Khalid Mahmood 0002, Majid Hussain |
J. Inf. Secur. Appl. | 1 |
| 2020 | An enhanced authentication protocol for client server environment
Muhammad Asad Saleem, Shafiq Ahmed, Khalid Mahmood 0002, Saru Kumari, Hu Xiong |
Frontiers Comput. Sci. | 1 |
| 2020 | Comments on "AKM-IoV: Authenticated Key Management Protocol in Fog Computing-Based Internet of Vehicles Deployment"abstractInternet of Vehicles (IoV) has become an intelligent application of Internet of Things (IoT) in smart transportation. IoV takes intelligent commitments to the passengers for improving the efficiency and safety of traffic. It also creates an enjoyable riding atmosphere. Another variation of mobile cloud computing is fog cloud-based IoV, where Internet and vehicular cloud can co-operate in an effective way in IoV. Moreover, IoV is becoming dangerous to various attacks due to the increasing dependency of wireless communication and computing technologies. Recently, Wazidet al.proposed “AKM-IoV: Authenticated Key Management Protocol in Fog Computing-Based IoV Deployment” to make the communication secure between vehicles, fog servers, roadside units (RSUs), and cloud servers. In this comment, we cryptanalyzed the protocol of Wazidet al.and found it vulnerable to vehicle impersonation, fog server impersonation, RSU impersonation, and cloud server impersonation attacks. Muhammad Asad Saleem, Khalid Mahmood 0002, Saru Kumari |
IEEE Internet Things J. | 1 |
| 2020 | Fuzzy extraction and PUF based three party authentication protocol using USB as mass storage device
Muhammad Faizan Ayub, Muhammad Asad Saleem, Izwa Altaf, Khalid Mahmood 0002, Saru Kumari |
J. Inf. Secur. Appl. | 2 |