Muhammad Tanveer 0003

dblp:312/0063 · DBLP profile ↗
← Back
12ranked-venue papers
11as first author
12since 2021 · last 2026
0000-0001-9836-9970ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 9 · 8 first-author · 9 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 POWER-SG: Privacy-Oriented Lightweight AKE for Smart Grids With ASCON and Reconfigurable PUF
Muhammad Tanveer 0003, Abdullah G. Alharbi, Syed Rizwan Hassan
IEEE Internet Things J.1
2026 MedSec-IoT: A secure authentication framework for IoT-enabled medical systems
Muhammad Tanveer 0003, Alamgir Naushad, Abdullah G. Alharbi
Pervasive Mob. Comput.1
2026 Lightweight authentication framework for iot-centric smart healthcare systems
Muhammad Jawad Akhtar, Abdullah G. Alharbi, Muhammad Tanveer 0003
Peer Peer Netw. Appl.3
2025 RePUF-IoT: Reconfigurable PUF-Based Authentication Protocol for IoT-Driven Healthcare Systems
abstract
Recently, NIST has standardized various security algorithms to provide confidentiality, integrity, and authenticity in resource-limited IoT devices. These algorithms are based on lightweight cryptography, which requires fewer resources to maintain security in IoT environments with constrained resources. By employing these algorithms, lightweight security mechanisms can be designed to meet security requirements efficiently. Authentication techniques are fundamental for secure communication in resource-limited IoT environments. However, most existing authentication protocols rely on conventional asymmetric and symmetric cryptographic primitives, which demand high computational resources from IoT devices, leading to communication delays in latency-sensitive applications. This paper proposes an authentication protocol called RePUF-IoT, utilizing the TinyJAMBU authenticated encryption scheme and reconfigurable PUF and hashing functions for secure access to medical data stored on a healthcare server. One-time PUF enables RePUF-IoT to achieve robust resilience against machine learning and modeling attacks. RePUF-IoT establishes a secure communication channel between entities in the healthcare system. Its resilience against various security attacks is validated through both formal and informal security analyses. Additionally, performance evaluations show that RePUF-IoT enhances security while reducing communication overhead by 32%–64 and time required for execution by 88%–94%.
Muhammad Tanveer 0003, Abdullah G. Alharbi, Saud Alhajaj Aldossari
IEEE Internet Things J.1
2025 SecTwin: A secure and efficient authentication mechanism for vehicular digital twins
Muhammad Tanveer 0003, Kainat Toor, Abdullah G. Alharbi, Syed Rizwan Hassan
J. Inf. Secur. Appl.1
2025 A secure and resource-efficient authenticated key agreement framework for mobile edge computing
Muhammad Tanveer 0003, Abdullah G. Alharbi, Muhammad Jawad Akhtar
Peer Peer Netw. Appl.1
2024 SEAF-IoD: Secure and efficient user authentication framework for the Internet of Drones
Muhammad Tanveer 0003, Abdallah Aldosary, Neeraj Kumar 0001, Saud Alhajaj Aldossari
Comput. Networks1
2022 LAKE-6SH: Lightweight User Authenticated Key Exchange for 6LoWPAN-Based Smart Homes
abstract
Ensuring security and privacy in the Internet of Things (IoT) while taking into account the resource-constrained nature of IoT devices is challenging. In smart home (SH) IoT applications, remote users (RUs) need to communicate securely with resource-constrained network entities through the public Internet to procure real-time information. While the 6LoWPAN adaptation-layer standard provides resource-efficient IPv6 compatibility to low-power wireless networks, the basic 6LoWPAN design does not include security and privacy features. A resource-efficient authenticated key exchange (AKE) scheme becomes imperative for 6LoWPAN-based resource-constrained networks to render indecipherable communication functionality. This article presents a lightweight user AKE scheme for 6LoWPAN-based SH networks (LAKE-6SH) to achieve authenticity of RUs and establish private session keys between the users and network entities by employing the SHA-256 hash function, exclusive-OR operation, and a simple authenticated encryption primitive. Informal security validation illustrates that LAKE-6SH is protected against different pernicious security attacks. The security is further validated formally through the random oracle model. Moreover, through Scyther validation, it is demonstrated that LAKE-6SH is secure. In addition, it is demonstrated that LAKE-6SH renders better security features aside from its low communication and computational overheads.
Muhammad Tanveer 0003, Ghulam Abbas 0002, Ziaul Haq Abbas, Muhammad Bilal 0003, Amrit Mukherjee, Kyung Sup Kwak
IEEE Internet Things J.1
2022 REAP-IIoT: Resource-Efficient Authentication Protocol for the Industrial Internet of Things
abstract
With the widespread utilization of Internet-enabled smart devices (SDs), the Industrial Internet of Things (IIoT) has become prevalent in recent years. SDs exchange information through the open Internet, which creates security and privacy concerns for the exchanged information. To address these concerns, various solutions exist in the literature which, because of high computational and communication overheads, are not appropriate for the resource-constricted IIoT environment. This article proposes a resource-efficient authentication protocol for the IIoT, called REAP-IIoT, which employs a lightweight cryptography (LWC)-based authenticated encryption with associative data (AEAD) primitive AEGIS along with hash function. LWC-based AEAD primitives are suitable for resource constraint SDs because they require fewer computational resources. Moreover, REAP-IIoT renders the privacy-preserving user authentication functionality and establishes a session key (SK) between SDs deployed in the IIoT environment and users. Both user and SD utilize the established SK for encrypted communication. The security of SK, established during the authentication and key exchange (AKE) process of REAP-IIoT, is validated through the broadly accepted random or real model. Besides, Scyther-based security verification is conducted to illustrate that REAP-IIoT is secure and can protect the man-in-the-middle and replay attacks. Additionally, the informal security analysis is carried out to show that REAP-IIoT is protected against various covert security risks. A thorough comparison reveals that REAP-IIoT renders enhanced security characteristics apart from its low communication, storage, and computational overheads than the relevant AKE protocols.
Muhammad Tanveer 0003, Ahmed Alkhayyat 0001, Abd Ullah Khan, Neeraj Kumar 0001, Abdullah G. Alharbi
IEEE Internet Things J.1
2022 RAMP-IoD: A Robust Authenticated Key Management Protocol for the Internet of Drones
abstract
Internet of Drones (IoD) is the interconnection of unmanned aerial vehicles or drones deployed for collecting sensitive data to be used in critical applications. The drones transmit the collected data to the control room (CR) for analysis, while CR sends control commands to the drone to monitor their operations. This exchange of information between the drones and CR takes place through a wireless communication channel, which is susceptible to various security risks. Therefore, it is vital to ensure the confidentiality and integrity of such information in the IoD environment. To this end, authenticated key management (AKM) protocols can be leveraged to provide reliable and secure communication. However, due to the peculiarities associated with IoD environments, it is challenging to devise a robust and resource-efficient AKM protocol. To tackle this challenge, in this article, we propose a robust AKM protocol for IoD (RAMP-IoD). RAMP-IoD uses lightweight cryptography-based authenticated encryption primitive and elliptic-curve cryptography along with a hash function to perform the AKM process. Moreover, RAMP-IoD verifies the user’s authenticity and then sets up a session key (SK) between the user and a specific drone for indecipherable communications. We verify the security of SK using the random oracle model. Scyther-based validation demonstrates that RAMP-IoD is protected against replay and man-in-the-middle attacks. Moreover, the informal analysis illustrates that RAMP-IoD is secure against various covert security attacks. Through a comparative study, we also demonstrate that RAMP-IoD provides enhanced security with low storage, communication, and computational overheads as compared to related AKM protocols.
Muhammad Tanveer 0003, Abd Ullah Khan, Neeraj Kumar 0001, Mohammad Mehedi Hassan
IEEE Internet Things J.1
2022 A Robust Access Control Protocol for the Smart Grid Systems
abstract
Lightweight cryptography (LWC)-based authenticated encryption with associative data (AEAD) cryptographic primitives require fewer computational and energy resources than conventional cryptographic primitives as a single operation of an AEAD scheme provides confidentiality, integrity, and authenticity of data. This feature of AEAD schemes helps design an access control (AC) protocol to be leveraged for enhancing the security of the resource-constrained Internet of Things (IoT)-enabled smart grid (SG) system with low computational overhead and fewer cryptographic operations. This article presents a novel and robust AC protocol, called RACP-SG, which aims to enhance the security of resource-constrained IoT-enabled SG systems. RACP-SG employs an LWC-based AEAD scheme, ASCON and the hash function, ASCON-hash, along with elliptic curve cryptography to accomplish the AC phase. Besides, RACP-SG enables a smart meter (SM) and a service provider (SEP) to mutually authenticate each other and establish a session key (SK) while communicating across the public communication channel. By using the SK, the SM can securely transfer the gathered data to the SEP. We verify the security of the SK using the widely accepted random oracle model. Moreover, we conduct Scyther-based and informal security analyses to demonstrate that RACP-SG is protected against various covert security risks, such as replay, impersonation, and desynchronization attacks. Besides, we present a comparative study to illustrate that RACP-SG renders superior security features while reducing energy, storage, communication, and computational overheads compared to the state of the art.
Muhammad Tanveer 0003, Abd Ullah Khan, Neeraj Kumar 0001, Alamgir Naushad, Shehzad Ashraf Chaudhry
IEEE Internet Things J.1
2022 A new anonymous authentication framework for secure smart grids applications
Muhammad Tanveer 0003, Musheer Ahmad 0002, Hany S. Khalifa, Ahmed Alkhayyat 0001, Ahmed A. Abd El-Latif 0001
J. Inf. Secur. Appl.1