EDBT 2026 Demo / reviewers in the wild / expert
Awaneesh Kumar Yadav
dblp:270/0766
· DBLP profile ↗
30ranked-venue papers
19as first author
29since 2021 · last 2026
0000-0002-2924-0361ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 16 · 11 first-author · 15 since 2021Security and privacy · 6 · 2 first-author · 6 since 2021Systems, architecture and hardware · 2 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | POSTER: Zero-Touch Mobility Data Governance with Differential Privacy in ZSM-Based Vehicular Edge ServicesabstractConnected-vehicle and roadside telemetry enable low-latency safety navigation, and traffic-optimisation services at the edge, but finegrained mobility streams (locations, speeds, events, and contexts) create high re-identification and linkage risk when accessed by multiple stakeholder domains. We present a Zero Touch Network and Service Management (ZSM) integrated, policy-driven data-collection service that operationalises mobility data governance through intent-based automation. Stakeholders submit high-level collection intents (purpose, fields, spatial/temporal granularity, latency, and utility targets); a policy engine evaluates and rewrites intents into compliant, effective intents; and a plan generator compiles them into executable data-collection pipelines deployable within a ZSM closed loop. Experiments on Beijing taxi mobility traces execute 87,500 DP-protected releases and achieve 1.26% relative error for Road Safety Authority (RSA) at ϵ = 8.0, while DP-Stochastic Gradient Descent (DP-SGD) risk scoring reaches 0.97 ± 0.03 test accuracy at ϵ = 0.5, with δ= 10-5. Awaneesh Kumar Yadav, Pradumn Kumar Pandey, Manoj Misra, Madhusanka Liyanage, An Braeken |
AsiaCCS | 2 |
| 2026 | Post-Quantum Public Key Infrastructures: Hybrid Certificates, Cryptographic Combiners, and Migration StrategiesabstractThe impending threat posed by quantum-capable adversaries necessitates a secure and practical transition of Public Key Infrastructures (PKIs) to support post-quantum cryptography (PQC). This paper addresses the multifaceted challenges of integrating PQC into existing PKI ecosystems by examining novel cryptographic combiners and hybrid certificate designs that can provide quantum-resistant security. We assess the performance, compatibility, and security of these hybrid certificates across standard communication protocols such as TLS, considering variations in root and intermediate certification paths. In addition, we introduce key management procedures that cover signature generation, validation, and lifecycle considerations under both software and hardware constraints. Beyond X.509, alternative trust models and certificate mechanisms are also analyzed for specialized domains, including IoT, firmware signing, and smart cards. Abdullah Aydeger, Engin Zeydan, Awaneesh Kumar Yadav, Madhusanka Liyanage |
CCNC | 3 |
| 2026 | Security Evaluations of Post-Quantum Cryptographic Primitives Against Quantum and AI-Based Attacks
Engin Zeydan, Abdullah Aydeger, Awaneesh Kumar Yadav, Madhusanka Liyanage |
ICC | 3 |
| 2026 | Efficient Privacy-Preserving 5G Authentication and Key Agreement for Applications (5G-AKMA) in Multi-Access Edge ComputingabstractThe 5G Authentication and Key Management for Applications (AKMA) protocol is a 5G standard proposed by 3GPP in order to standardize the authentication procedure of mobile users towards applications based on the authentication of the user to the mobile network. As pointed out by several authors, the 5G-AKMA protocol inherently poses severe security issues, including privacy, unlinkability, ephemeral secret leakage and stolen device attacks. Also, the protocol does not offer perfect forward secrecy. In addition, the network operator is able to record all applications to which the user is subscribed and any outsider eavesdropping the communication channel is able to link requests to different applications coming from the same user. While the state of the shows that various protocols are proposed to solve the 5G-AKMA security issues, they are either vulnerable to severe attacks or are computationally extensive. In this paper, we provide a new version of the protocol able to solve these privacy issues in an effective manner. In addition, we also extend the protocol such that it can be used for communications in multiaccess edge computing (MEC) applications, taking into account handover procedures from one MEC server to another. The proposed protocol has been thoroughly compared to existing ones, revealing its efficiency in terms of communication, computation storage, and energy costs. The comparative analysis shows that the proposed 5G-AKMA reduces computational cost by 92%, communication cost by 74%, storage cost by 38%, and energy consumption cost by 58%. The security verification has been conducted using informal and formal methods (Real-Or-Random (ROR) and Scyther Validation tools) to ensure the protocol’s security. Additionally, we conduct a comparative analysis under an unknown attack scenario. Furthermore, the simulation is carried out using NS3. Awaneesh Kumar Yadav, An Braeken |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2026 | A Provably Secure Lightweight Three-Factor 5G-AKA Authentication Protocol Relying on an Extendable Output FunctionabstractCompared to 4G, the designed authentication and key agreement protocol for 5G communication (5G-AKA) offers better security. State-of-the-art shows that various protocols indicate the flaws in the 5G-AKA and suggest solutions primarily for the desynchronization attack, traceability attack, and perfect forward secrecy. However, most authentication protocols fail to facilitate the device stolen attack and are expensive; they also do not consider the prominent security issues such as post-compromise security and non-repudiation. Considering the above demerits of these protocols and the necessity to offer additional security, a provably secure lightweight 5G-AKA multi-factor authentication protocol relying on an extendable output function is proposed. The security of the proposed work has been confirmed informally and formally (ROR logic, GNY logic, and Scyther tool) to ensure that the proposed work handles all types of attacks and offers additional security features, such as post-compromise features and non-repudiation. Furthermore, we compute the performance of the proposed work and compare it with its counterparts to show that our work is less costly and more suitable for lightweight devices than others in terms of computational, communication, storage, and energy consumption cost. Awaneesh Kumar Yadav, An Braeken, Madhusanka Liyanage |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2026 | A Provably Secure Multifactor Authentication and Key Exchange Protocol With Anonymity for Next-Generation IoTabstractWith the rapid surge in IoT devices, communication between the IoT devices and the server becomes more frequent. Since IoT devices are considered at the edge of the networks, their communication is completely exposed to the server, making them prone to several attacks. In addition to this, IoT devices have limited energy and computational resources. Therefore, there is an impelling necessity for an authentication mechanism suitable for security and taking into account the resource constraints. This paper shows that a recently proposed protocol by Daojing et al. is prone to serious attacks such as stolen device attacks, suffers from integrity violations, and does not offer perfect forward secrecy. We propose an alternative and more secure authentication mechanism for this type of model and also show that this protocol offers better performance with respect to the state-of-the-art. The proposed protocol achieves reductions of 75%, 40%, 36%, and 71% in computational, communication, storage, and energy consumption costs, respectively. Additionally, the protocol only has two communication phases. Furthermore, prototype implementation and simulation with the NS3 tool are carried out to show the applicability of the proposed work in real-time scenarios. Awaneesh Kumar Yadav, An Braeken, Madhusanka Liyanage |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2026 | An Improved and Provably Secure EDHOC Protocol Supporting the Extended Canetti-Krawczyk (eCK) Security ModelabstractTransport Layer Security (TLS) is considered to be the most used standard security protocol for the Internet of Things (IoT). However, as TLS was originally designed for computer networks, it is not optimal with respect to efficiency. Therefore, a new protocol called Object Security for Constrained RESTful Environments (OSCORE) has been standardized for securing constrained devices. Currently, the Ephemeral Diffie Hellman Over COSE (EDHOC) protocol, which is a key exchange protocol to define a session key used in OSCORE, is also in the process of being standardized. This paper shows that the four authentication modes of the EDHOC protocol are vulnerable in the extended Canetti–Krawczyk (eCK) security model, which is a common security model used in IoT. In addition, also resistance to Distributed Denial of Service (DDoS) attacks is weak. Taking this into account, we propose two new variants of EDHOC. The first variant, EDHOC2, is able to overcome both issues but has a slightly higher cost for communication, computation, storage, and energy consumption. The second variant, EDHOC3, offers only additional protection in the eCK security model and has, on average, similar, even better performance in one authentication mode, compared to EDHOC. Additionally, the Real-Or-Random (ROR) logic and Scyther validation tool are employed to ensure the security of the designed variants. Furthermore, a prototype implementation is conducted to demonstrate the real-time deployment of the designed versions. Awaneesh Kumar Yadav, Madhusanka Liyanage, An Braeken |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2025 | A Provably Secure Post-Quantum Based EDHOC ProtocolabstractTransport Layer Security (TLS) is considered to be the most used standard security protocol for the Internet of Things (IoT). However, as TLS was originally designed for computer networks, it is not optimal with respect to efficiency. Therefore, a new protocol called Object Security for Constrained RESTful Environments (OSCORE) has been standardized for securing constrained devices. Currently, the Ephemeral-Diffie-Hellman-Over-COSE (EDHOC) protocol, which is a key exchange protocol to define a session key used in OSCORE, is also in the process of being standardized. EDHOC consists of four authentication modes, each offering different security strengths and performance. However, these modes are not yet secure against quantum attacks. Since we are in a transition period and do not yet possess deeply analyzed post-quantum algorithms, we propose a generic hybrid protocol. As such, the protocol can easily update from one post-quantum algorithm to the other and becomes secure against either a post-quantum attack or a potential attack against a newly defined post-quantum algorithm. The proposed mode does not require any changes to the original EDHOC protocol and offers perfect backward compatibility. The security is ensured using Real-Or-Random (ROR) logic, and additional performance costs are analyzed using different variants of post-quantum algorithms. Awaneesh Kumar Yadav, Mohammad Shojafar, An Braeken |
CCNC | 1 |
| 2025 | A Post Quantum Secured Authentication Protocol for the MetaverseabstractThe Metaverse, comprising multiple universes referred to as verses, is envisioned as the future Internet. While this concept has sparked numerous discussions, insufficient attention has been given to the security challenges inherent in these virtual worlds. Communication between users and platform servers is particularly concerning, as sensitive information is exchanged over public channels, making them vulnerable to attacks. In addition, the security of many of these protocols depends on the complexity of factoring or the discrete logarithm problem. However, with the advent of Shor's algorithm, high-scale quantum computers can efficiently solve these challenges. Consequently, traditional cryptographic schemes utilised in Authentication and Key Agreement (AKA) protocols are increasingly vulnerable as quantum computers come to fruition. Considering this, a novel post-quantum secured authentication and key agreement protocol for the Metaverse is proposed. The security of the designed protocol has been rigorously verified using the Real-Or-Random (ROR) logic and Scyther validation tool. Awaneesh Kumar Yadav |
ICC | 1 |
| 2025 | A Secure D2D 5G-AKA Protocol with Anonymity Resistance and Perfect Forward SecrecyabstractDevice-to-Device (D2D) communication operating in relay mode has become an essential strategy for extending network coverage and ensuring reliable connectivity, particularly in environments where direct links are unavailable in 5G network communications. However, securing D2D communication in 5G networks in resource-constrained Internet of Things (IoT) environments remains a significant challenge, especially authentication. The state-of-the-art for D2D communication in 5G reveals that existing authentication and key agreement protocols are often vulnerable to severe security threats, including denial-of-service (DoS) attacks, anonymity, ephemeral secret leakage and replay attacks, also do not offer perfect forward secrecy. Moreover, their computational complexity makes them unsuitable for deployment on constrained IoT devices. To address these limitations, this paper proposes a Secure and Efficient D2D authentication Protocol for 5G Communication based on Elliptic Curve Diffie-Hellman (ECDH) key exchange. The proposed protocol is rigorously evaluated through both informal and formal security methods (Real-Or-Random (ROR) logic and Scyther tool) to demonstrate its robustness against various known attacks. Additionally, a comprehensive performance comparison with existing schemes highlights the proposed protocol’s advantages in terms of security features, computational efficiency, communication overhead, and storage requirements. Shivam Patel, Awaneesh Kumar Yadav, Manoj Misra |
MASS | 3 |
| 2025 | A Secure Authentication Protocol for IoT-WLAN Using EAP FrameworkabstractThe plethora of Internet of Things (IoT) devices and their diversified requirements have opted to design security mechanisms that cover all major security requirements. Wireless Local Area Networks (WLANs) is the most common network domains where IoT devices are launched, particularly because of its easy availability. Security, in other words authentication however, remains to be a major constriction for IoT-WLAN deployments. Though there are IoT based authentication protocols prevailing, such protocols are either prone to threats such as perfect forward secrecy violations, insider with database access attack, traceability attack, stolen device attack, ephemeral secret leakage, or they consume excessive computational and communication resources that result in an unprecedented burden for the IoT system. This paper presents an Extensible Authentication Protocol (EAP) based mechanism for IoT devices deployed in a WLAN that addresses the above security issues and achieves cost-effectiveness. Validation follows an informal and formal approaches (using GNY and BAN logic, and Scyther verification tool) for the proposed protocol, demonstrating its robustness. Our performance analysis shows that the proposed protocol is lightweight and more secure in contrast to the state-of-the-art solutions. In addition, performance of the proposed protocol subjected to unknown attacks is investigated, which deduces that the proposed protocol has less overhead under unknown attacks than its competitors. A prototype of the protocol has been developed to demonstrate its feasibility and accuracy. Awaneesh Kumar Yadav, Manoj Misra, Pradumn Kumar Pandey, Pasika Ranaweera, Madhusanka Liyanage, Neeraj Kumar 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | A Practical Transition to Post-Quantum Security in 5G-AKAabstractThe current 5G-AKA protocol faces significant security challenges, including the lack of Perfect Forward Secrecy and Post-Quantum (PQ) security. In particular, the absence of PQ protection makes current communications vulnerable to future quantum adversaries who may decrypt stored messages once large-scale quantum computers become available. To mitigate this risk, a transition to PQ security must be implemented as soon as possible. Two primary approaches exist for this transition: (1) symmetric key-based techniques, which require a secure channel for key distribution, leading to increased costs, and (2) modern PQ public-key primitives, which offer stronger security but come with high communication overhead. In this paper, we propose a solution that leverages PQ cryptographic primitives for confidentiality and privacy protection, while retaining classical public-key cryptography for authentication. This approach is viable because digital signatures must be secure today, even if they are compromised in the future. Moreover, our framework allows for a seamless transition to fully PQ-secure authentication when quantum threats become imminent. In addition, the framework also supports the zero-trust architecture in which no secure channel between Serving Network (SN) and Home Network (HN) is assumed. We have carefully analysed the security of the proposed protocol using both informal and formal (Real-Or-Random (ROR) logic and Scyther Validation tool) methods. We also compared its performance in terms of computation, communication, and storage, and found that it performs better than existing protocols. An Braeken, Awaneesh Kumar Yadav, Jorge Munilla |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Blockchain-Based Cross-Operator Network Slice Authentication Protocol for 5G CommunicationabstractNetwork slicing enables the facilitation of diverse network requirements of different applications over a single physical network. Due to concepts such as Local 5G Operators (L5GOs), Mobile Virtual Network Operators (MVNOs), and high-frequency utilization of 5G and beyond networks, users need to switch frequently among different network slices as well as different operators than the traditional networks. Even though a couple of researches have been conducted on cross-network slice authentication, cross-operator network slice authentication is still an indeterminate research area. Also, the proposed cross-network slice authentication frameworks possess several limitations, such as vulnerability to severe attacks, high cost, the central point of failure, and the inability to support cross-operator network slice authentication. Therefore, in this research, we develop a blockchain-based cross-network slicing, cross-operator network slice authentication framework. Our framework supports the authentication for different network slices in the same operator as well as in different operators. The security properties of the proposed protocols are validated from formal (using Real-Or-Random logic, Scyther, and AVISPA validation tool) and informal security validation. The comparative analysis is conducted for known and unknown attacks to demonstrate its efficacy in terms of communication, computational, storage, and energy consumption costs. Also, a sample prototype of the protocols is implemented along with the state-of-the-art protocols to evaluate the performance of our framework. Awaneesh Kumar Yadav, Shalitha Wijethilaka, Madhusanka Liyanage |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2024 | Privacy-Preserving Federated Learning Framework for Open Radio Access Networks (ORAN)abstractOpen Radio Access Network (ORAN) is considered the next-generation RAN, which enables several features such as network flexibility, interoperability, and cost efficiency. Leveraging Artificial Intelligence (AI) and Machine Learning (ML) techniques has become commonplace in ORAN applications. The modularized nature of the ORAN architecture and the limitations in traditional ML approaches intensify the requirement of Federated Learning (FL) for training ML models in ORAN environments. However, in multi-BS environments, the conventional plaintext model update sharing of FL is vulnerable to privacy breaches like inference and deep-leakage gradient attacks. Hence, our proposition introduces an innovative blockchain-based framework to conduct FL securely and protect privacy with the support of the Open Radio Access Network (ORAN). Our approach builds upon the traditional masking method for sharing model parameters and enhances it with novel features. These features include individual validation for BSs, the selection of distributed aggregators, and validation for final model aggregation. Our scheme facilitates the sharing of sensitive data among multiple BSs while bolstering privacy and adding security layers without compromising performance metrics. To assess the efficacy of our proposal, we implement the framework atop a Hyperledger Fabric blockchain. Furthermore, comprehensive formal and informal security analyses are conducted to demonstrate the robust and privacy-preserving nature. Shalitha Wijethilaka, Awaneesh Kumar Yadav, An Braeken, Madhusanka Liyanage |
GLOBECOM | 2 |
| 2024 | An Enhanced Authentication Protocol for IoT-AmI EnvironmentabstractThe rapid proliferation of the Internet of Things (IoT) in recent years has fostered the swift development of various applications, enabling seamless connections between consumers and everyday utilities. One sector that has seen significant transformation is healthcare, thanks to the adoption of IoT and Ambient Intelligence (AmI). However, this growing utilization of IoT-AmI systems has raised substantial concerns about privacy and security, particularly in user authentication. Numerous authentication techniques have been established for IoT-AmI systems. Nevertheless, the current state-of-the-art reveals that these methods are vulnerable to various severe attacks, such as impersonation, Man-in-the-middle (MITM), traceability, replay, privacy and violation of perfect forward secrecy. Considering the above, this paper aims to propose a secure authentication protocol for IoT-AmI systems. The security of the proposed protocol for IoT-AmI is verified using the formal analysis tool Scyther. Furthermore, the performance of the designed protocol is assessed to show that it has lower computational and communication costs compared to existing protocols. Shree Chand Khichar, Awaneesh Kumar Yadav, Manoj Misra, Brij B. Gupta |
IWCMC | 2 |
| 2024 | A Novel Authentication Protocol for 5G gNodeBs in Service Migration Scenarios of MECabstractEdge computing paradigms were an expedient innovation for elevating the contemporary standards of mobile and Internet networks. As specified in Multi-Access Edge Computing (MEC) standardization, edge computing serviceable infrastructures are running on virtualization technologies to provide dynamic and flexible service instances. Since the inception and operation of the services are executing at the edge level gNodeBs ($gNB$s), migration of services between$gNB$s is an imminent occurrence in edge computing that is contriving challenges to its feasible deployment. Security and service level latency requirements are vital parameters for such service migration operations conducted through$gNB$to$gNB$(g2g) connecting channels. In this paper, our focus is to ensure identity verification among the parties involved in a service migration through authentication and to secure the migrating content through a robust g2g channel establishment. Our proposed authentication protocol was designed in accordance with the MEC architectural standardization. We have verified the proposed protocol employing four different formal verification techniques: Scyther and AVISPA verification tools, GNY and ROR logical approaches. Further, we have developed the proposed protocol in a test-bed environment emulating the MEC system with an integrated 5 G Core network. Pasika Ranaweera, Awaneesh Kumar Yadav, Madhusanka Liyanage, Anca Jurcut |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | SKAP-NS: A Symmetric Key-Based Authentication Protocol for 5G Network SlicingabstractNetwork slicing is a pivotal technology in upcoming telecommunications. It enables the segmentation of the physical network into multiple tailored logical networks. These networks serve diverse purposes, facilitating users swift access to a range of services. The 5G mobile network leverages network slicing to accommodate various consumer applications. Nevertheless, security concerns, particularly regarding authentication, pose a significant challenge in network slicing. Various asymmetric encryption-based authentication protocols are designed to protect network-slicing communication. The state-of-the-art shows that these solutions are either expensive or vulnerable. They face severe attacks, including privacy issues, traceability, and ephemeral secret leakage. They also do not offer the perfect forward secrecy. Most of the existing protocols are based on asymmetric encryption. Therefore, considering the above-mentioned, a symmetric encryption-based authentication protocol is designed to tackle the problem of cost and security. The security of the designed protocol is verified using both informal and formal methods. These include real-or-random logic and the Scyther validation tool. This ensures that the proposed protocol offers robust security. Moreover, a comparative analysis is conducted to demonstrate the effectiveness of the proposed protocol. This analysis evaluates computational, communication, storage, and energy consumption costs, comparing the protocol to its competitors. Awaneesh Kumar Yadav |
IEEE Trans. Ind. Informatics | 1 |
| 2024 | Blockchain-Based Secure Authentication and Authorization Framework for Robust 5G Network SlicingabstractThe rapid evolution of heterogeneous applications signifies the requirement for network slicing to cater to diverse network requirements. Network Functions (NFs), which are the essential elements of network slices, are required to communicate with each other securely to facilitate network services. Certificates are the established method to authenticate each other. However, dynamic certificate management while allowing NFs to communicate in a multi-operator environment is arduous. Also, sharing NFs between network slices originates authorization-related security challenges such as unauthorized service utilization, deceptive Denial of Service attacks, and data leakages from network slices. In this paper, we develop a novel framework to address the security challenges related to authentication and authorization in 5G network slicing systems. A blockchain-based multi-party distributed certificate management framework with secure communication protocols is developed using elliptic curve cryptography to facilitate certificate services for multi-operator environments. Also, we propose a blockchain-based NF authorization framework to mitigate the security vulnerabilities in NF sharing between network slices. We implement the proposed framework using Hyperledger Fabric blockchain with Java chain codes and perform comprehensive experiments to show the significance of our framework.The Ability to mitigate the single point of failure with respect to state-of-the-art, including traditional certificate authorities and blockchain-based certificate authorities, time analysis for certificate generation, and the potential to eliminate the mentioned authorization attacks are some of the experiments conducted.Also, we have shown that our framework is secure using informal and formal (using Real-Or-Random (ROR) logic and Scyther Validation tool) security verification mechanisms. Shalitha Wijethilaka, Awaneesh Kumar Yadav, An Braeken, Madhusanka Liyanage |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2023 | A Provably Secure and Efficient 5G-AKA Authentication Protocol using BlockchainabstractThe next generation of mobile communication systems must be secured because of the ongoing entrance of numerous security attacks. Thus, to secure the underlying network, the 3GPP has designed an authentication and key agreement protocol, 5G-AKA, to safely and stably access the mobile services. However, some recent observations indicate that 5G-AKA has numerous shortcomings such as perfect forward secrecy violation, malicious Serving Network (SN), de-synchronization attack, privacy theft, stolen device, and denial of Service (DoS) attacks when the user uses the roaming mobile services. Considering the shortcomings of existing protocols and the requirement to offer increased security, we propose a provable secure, efficient 5G-AKA authentication protocol using the blockchain. The security features of the proposed protocol are examined using the Real-Or-Random (ROR) logic and Scyther tool. Furthermore, the performance of the proposed protocol is evaluated, which shows that it is the least costly compared to its counterparts in terms of computational and communication costs. In addition, the comparison of the Ethereum blockchain depicts that the proposed protocol takes less transaction and execution costs compared to its counterparts. Awaneesh Kumar Yadav, An Braeken, Manoj Misra, Madhusanka Liyanage |
CCNC | 1 |
| 2023 | PSLP-5G: A Provably Secure and Lightweight Protocol for 5G CommunicationabstractDue to the constant influx of multiple security attacks into the next generation of mobile communication technologies, the Third Generation Partnership Project (3GPP) has established authentication and key agreement protocol, 5-GAKA, to securely access the 5G communication services while maintaining the integrity of the underlying network. However, some recent findings pointed out that 5G-AKA has many drawbacks, including perfect forward secrecy violations, malicious Serving Network (SN) attacks, desynchronization attacks, privacy theft, stolen device, and denial of service (DoS) attacks when the user uses roaming mobile services. Considering the drawbacks of current 5G communication protocols and the necessity to facilitate additional security, a provably secure and lightweight protocol for 5G communication (PSLP-5G) is introduced. The PSLP-5G's security is guaranteed using the Scyther tool and Real-Or-Random (ROR) logic. Furthermore, performance comparisons are made to show how much lighter the PSLP-5G is than its counterparts. Additionally, the PSLP-5G's suitability for use in real-time applications is demonstrated by comparing the network performance of PSLP-5G and its counterparts using the Network Simulator tool NS3. Awaneesh Kumar Yadav, Pradumn Kumar Pandey, Kuljeet Kaur, Abbas Bradai |
ICC | 1 |
| 2023 | A Novel Blockchain-based Decentralized Multi-party Certificate Management FrameworkabstractDigital certificates play a significant role in the current communication systems. However, with the limitations in the existing Certificate Management Frameworks (CMFs), such as single point of failure, the profound nature of existing certificates, and malicious Certificate Authorities (CAs), a novel framework is required to optimize certificate management. Even though blockchain is a popular approach in designing CMFs, they also failed to address all these limitations. There are no existing frameworks that distribute the functionality of the centralized CA to address these issues. Therefore, this paper proposes a blockchain-based, lightweight CMF while distributing the centralized certificate generation process among multiple parties. Certificate generation, validation, and revocation can be performed with our framework. We design the required secure communication protocols to deploy our framework in any blockchain. The proposed framework is implemented on top of a Hyperledger Fabric environment and performed a set of experiments to evaluate the performance of the framework. Also, a formal security analysis for the proposed communication protocols is provided using known security verification methods such as BAN logic and the Scyther tool. Shalitha Wijethilaka, Awaneesh Kumar Yadav, An Braeken, Madhusanka Liyanage |
TrustCom | 2 |
| 2023 | A Secure Blockchain-based Authentication and Key Agreement Protocol for 5G RoamingabstractThe fifth generation (5G) is now widely used to access network services due to the emergence of the Internet of Things (IoT) and mobile devices. To secure 5G communication, the Third Generation Partnership Project (3GPP) organization created the 5G-Authentication and Key Agreement (AKA) protocol. Security evaluations have found a number of problems in the 5G-AKA, including a violation of perfect forward secrecy, a traceability attack, and denial of service (DoS) attacks. To address the shortcomings of 5G-AKA, several enhanced versions have been developed. However, it has been shown that either these versions are expensive or do not address security issues. Additionally, less effort is put into providing security when a user utilizes roaming mobile services while a malicious Serving Network (SN) is present. This paper introduces an authentication mechanism to handle the above issues. In addition to this, a handover mechanism is also designed for re-connection. The authentication and handover phase security assessment uses the mathematical model Real-Or-Random (ROR), AVISPA, and Scyther tool. Furthermore, the performance comparison depicts that the authentication and handover phase is more efficient than existing protocols. An assessment of the smart contract function’s cost and effectiveness is also provided. Awaneesh Kumar Yadav, Manoj Misra, An Braeken, Madhusanka Liyanage |
TrustCom | 1 |
| 2023 | An EAP-Based Mutual Authentication Protocol for WLAN-Connected IoT DevicesabstractSeveral symmetric and asymmetric encryption based authentication protocols have been developed for the wireless local area networks (WLANs). However, recent findings reveal that these protocols are either vulnerable to numerous attacks or computationally expensive. Considering the demerits of these protocols and the necessity to provide enhanced security, a lightweight extensible authentication protocol based authentication protocol for WLAN-connected Internet of Things devices is presented. We conduct an informal and formal security analysis to ensure robustness against the attacks. Furthermore, the empirical performance analysis and comparison show that the proposed protocol outperforms its counterparts, reducing computational, communication, storage costs, and energy consumption by up to 99%, 80%, 91.8%, and 98%, respectively. Simulation results of the protocol using the NS3 and its overhead under unknown attacks demonstrate that the proposed protocol performs better in all scenarios. A prototype implementation of the protocol has also been tested to evaluate its feasibility in real-time applications. Awaneesh Kumar Yadav, Manoj Misra, Pradumn Kumar Pandey, Madhusanka Liyanage |
IEEE Trans. Ind. Informatics | 1 |
| 2023 | Symmetric key-based authentication and key agreement scheme resistant against semi-trusted third party for fog and dew computing
Awaneesh Kumar Yadav, An Braeken, Manoj Misra |
J. Supercomput. | 1 |
| 2023 | An Enhanced Cross-Network-Slice Authentication Protocol for 5GabstractNetwork slicing is considered one of the key technologies in future telecommunication networks as it can split the physical network into a number of logical networks tailored to diverse purposes that allow users to access various services speedily. The fifth-generation (5G) mobile network can support a variety of applications by using network slicing. However, security (especially authentication) is a significant issue when users access the network slice-based services. Various authentication schemes are designed to secure access, and only a few offer cross-network slice authentication. The security analysis of existing cross-network authentication schemes shows they are vulnerable to several attacks such as device stolen, ephemeral secret leakage, violation of perfect forward secrecy, identity theft. Therefore, we propose an authentication mechanism that offers cross-network slice authentication and prevents all the aforementioned vulnerabilities. The security verification of the authentication mechanism is carried out informally and formally (ROR logic and Scyther tool) to ensure that it handles all the vulnerabilities. The comparison of empirical evaluation shows that the proposed scheme is least costly than its competitors. Java-based implementations of the proposed protocols imitate a real environment, showing that our proposed protocol maintains almost the same performance as state-of-the-art solutions while providing additional security features. Awaneesh Kumar Yadav, Shalitha Wijethilaka, An Braeken, Manoj Misra, Madhusanka Liyanage |
IEEE Trans. Sustain. Comput. | 1 |
| 2022 | Service Migration Authentication Protocol for MECabstractMulti-Access Edge Computing (MEC) is a novel edge computing paradigm that enhances the access level capacity of mobile networks by shifting the serviceable Data center infrastructure proximate to the end devices. With this proximate placement and service provisioning, migration of a service from one edge enabled gNodeB (gNB) to another is intrinsic to maintain the service continuity. Since such services are migrated through the channel shared between the gNBs, proper security measures should be inhibited by the communication protocol to prevent any unauthorized interception. Further, each gNB should ensure the legitimacy of the migrating gNBs to avoid any impersonation attempts. As this is an area that lacks focus in current research trends, this paper introduces MEC Service Migration Authentication Protocol (MEC-SMAP), a protocol that take place prior to the migration initiation, and specifically defined for MEC. The proposed protocol ensures the secure transfer of session key generation parameters to form a secure channel while ensuring perfect forward secrecy. It introduces an identity verification mechanism through a trusted third party service. We have validated the proposed protocol through formal analysis using GNY logic and Scyther tool. Further, a prototype virtualized MEC environment was created to evaluate its feasibility and the impact of the employed security mechanisms. Pasika Ranaweera, Awaneesh Kumar Yadav, Madhusanka Liyanage, Anca Jurcut |
GLOBECOM | 2 |
| 2022 | A Provably Secure ECC-based Multi-factor 5G-AKA Authentication ProtocolabstractDue to the constant penetration of various security attacks, it is highly important to secure the underlying communication networks between the IoT, Fog and Cloud in the next generation of mobile communication system (5G). Thus, secure authentication and key agreement protocol, namely 5G-AKA, has been proposed in the literature to safely and stably access the 5G mobile services. However, some recent findings reveal that 5G-AKA and its numerous versions based on symmetric or asymmetric encryption are either vulnerable to different attacks such as perfect forward secrecy violation, malicious Serving Network (SN), de-synchronization attack, privacy theft, stolen device, or are computationally intensive. Apart from that, these protocols use single-factor authentication. Considering the above demerits of these protocols and the necessity to provide enhanced security, we propose an Elliptic Curve-Cryptography (ECC)-based multi-factor 5G-AKA authentication protocol. It provides additional security and achieves cost-effectiveness in terms of computational, communication, storage costs and energy consumption. The formal security analysis using Real-Or-Random (ROR) logic has been done to confirm its security. Moreover, we evaluate the performance of the proposed protocol in terms of computational, communication, storage costs and energy consumption. The evaluation results show that the proposed protocol requires less cost than its counterparts, reducing computational cost by up to 57%, communication cost by up to 59%, storage cost by up to 52%, and energy consumption by up to 51%. Awaneesh Kumar Yadav, Manoj Misra, Pradumn Kumar Pandey, Kuljeet Kaur, Sahil Garg, Xi Chen 0009 |
GLOBECOM | 1 |
| 2022 | LEMAP: A Lightweight EAP based Mutual Authentication Protocol for IEEE 802.11 WLANabstractThe growing usage of wireless devices has significantly increased the need for Wireless Local Area Network (WLAN) during the past two decades. However, security (most notably authentication) remains a major roadblock to WLAN adoption. Several authentication protocols exist for verifying a supplicant’s identity who attempts to connect his wireless device to an access point (AP) of an organization’s WLAN. Many of these protocols use the Extensible Authentication Protocol (EAP) framework. These protocols are either vulnerable to attacks such as violation of perfect forward secrecy, replay attack, synchronization attack, privileged insider attack, and identity theft or require high computational and communication costs. In this paper, a lightweight EAP-based authentication protocol for IEEE 802.11 WLAN is proposed that not only addresses the security issues in the existing WLAN authentication protocols but is also cost-effective. The security of the proposed protocol is verified using BAN logic and the Scyther tool. Our analysis shows that the proposed protocol is safe against all the above attacks and attacks defined in RFC-4017. A comparison of the computational and communication costs of the proposed protocol with other existing state-of-the-art protocols shows that the proposed protocol is lightweight than existing solutions. Awaneesh Kumar Yadav, Manoj Misra, Pradumn Kumar Pandey, Kuljeet Kaur, Sahil Garg, Madhusanka Liyanage |
ICC | 1 |
| 2022 | An improved and provably secure symmetric-key based 5G-AKA Protocol
Awaneesh Kumar Yadav, Manoj Misra, Pradumn Kumar Pandey, An Braeken, Madhusanka Liyanage |
Comput. Networks | 1 |
| 2020 | Secure and User Efficient EAP-based Authentication Protocol for IEEE 802.11 Wireless LANsabstractWireless Local Area Networks (WLANs) have experienced significant growth in the last two decades due to the extensive use of wireless devices. Security (especially authentication) is a staple concern as the wireless medium is accessible to everybody. Extensible Authentication Protocol (EAP) is the widely used authentication framework in WLANs to secure communication. The authentication mechanism designed on EAP is called EAP method. There are numerous EAP based and nonEAP based authentication protocols for WLANs, but there is no protocol that fulfills all the security requirements, as mentioned in RFC-4017 and other additional requirements like perfect forward secrecy, Denial-of-service (DoS) attack protection, and lightweight computation. Hence, it is fair to infer that there is an impelling need to design a protocol that can meet all the security requirements. In this paper, we propose a secure and user efficient EAP-based authentication protocol for IEEE 802.11 WLANs. The proposed protocol has been formally validated by BAN logic and the AVISPA tool [18]. The simulation results depict that the proposed protocol achieves all security requirements, as mentioned in RFC-4017 along with perfect forward secrecy, Denial-of-service (DoS) attack protection, and lightweight computation. The proposed protocol outperforms the existing protocols in terms of computation cost by reducing the computation cost by ≈ 99.9956%, 99.991%, 27.27%, 22.705% in comparison to EAP-TLS, EAP-TTLS, EAP-Ehash, EAP-SELUA, respectively. Keywords-AP, AS, AVISPA, BAN, EAP, WLANs. Awaneesh Kumar Yadav, Manoj Misra, Madhusanka Liyanage, Gaurav Varshney |
MASS | 1 |