EDBT 2026 Demo / reviewers in the wild / expert
Rabiah Alnashwan
dblp:322/9516
· DBLP profile ↗
5ranked-venue papers
4as first author
5since 2021 · last 2025
0000-0001-9156-1679ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 4 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Path Privacy and Handovers: Preventing Insider Traceability Attacks During Secure HandoversabstractThe rise of 5G and IoT has shifted secure communication from centralized and homogeneous to a landscape of heterogeneous mobile devices constantly travelling between myriad networks. In such environments, it is desirable for devices to securely extend their connection from one network to another, often referred to as a handover. In this work we introduce the first cryptographic formalisation of secure handover schemes. We leverage our formalisation to propose path privacy, a novel security property for handovers that has hitherto remained unexplored. We further develop a syntax for secure handovers, and identify security properties appropriate for secure handover schemes. Finally, we introduce a generic handover scheme that captures all the strong notions of security we have identified, combining our novel path privacy concept with other security properties characteristic to existing handover schemes, demonstrating the robustness and versatility of our framework. Bhagya Wimalasiri, Benjamin Dowling, Rabiah Alnashwan |
CSF | 3 |
| 2025 | PGUP: Pretty Good User Privacy for 5G-enabled Secure Mobile Communication ProtocolsabstractWith the proliferation of 5G networks, it is essential to prioritise robust security and seamless compatibility with existing infrastructure. The Authentication and Key Agreement (AKA) and Handover (HO) protocols are crucial in securing communication links and maintaining user privacy in 5G networks. While 5G-AKA represents a significant improvement over its predecessors, it still cannot achieve some important security features, such as perfect forward security (PFS) and forward privacy (PFP), leaving data confidentiality and user privacy susceptible to compromise. Moreover, linkability vulnerabilities in the 5G-AKA pose additional privacy concerns, particularly in the face of active adversaries seeking to compromise user anonymity. To enhance the security and privacy of 5G protocols (5G-AKA and 5G-HO) , we aim to achieve PFS and PFP while aligning with 5G's symmetric-key foundations. In this article, we introduce Pretty Good User Privacy (PGUP), a novel symmetric-based scheme aimed at addressing security and privacy vulnerabilities in the current 5G-AKA and HO protocols. In this article, we introduce a new variant of Puncturable Key Wrapping (i.e., PKW+), which allows us to ensure PFS and PFP while maintaining resilience against DoS (desynchronization) attacks in our proposed protocols. We demonstrate that our proposed scheme is resilient against all the essential security threats by performing a comprehensive formal security analysis. We also conduct relevant experiments to show the cost-effectiveness of the proposed scheme. Rabiah Alnashwan, Prosanta Gope, Benjamin Dowling, Yang Yang 0138 |
Proc. Priv. Enhancing Technol. | 1 |
| 2024 | Strong Privacy-Preserving Universally Composable AKA Protocol with Seamless Handover Support for Mobile Virtual Network OperatorabstractConsumers seeking a new mobile plan have many choices in the present mobile landscape. The Mobile Virtual Network Operator (MVNO) has recently gained considerable attention among these options. MVNOs offer various benefits, making them an appealing choice for a majority of consumers. These advantages encompass flexibility, access to cutting-edge technologies, enhanced coverage, superior customer service, and substantial cost savings. Even though MVNO offers several advantages, it also creates some security and privacy concerns for the customer simultaneously. For instance, in the existing solution, MVNO needs to hand over all the sensitive details, including the users' identities and master secret keys of their customers, to a mobile operator (MNO) to validate the customers while offering any services. This allows MNOs to have unrestricted access to the MVNO subscribers' location and mobile data, including voice calls, SMS, and Internet, which the MNOs frequently sell to third parties (e.g., advertisement companies and surveillance agencies) for more profit. Although critical for mass users, such privacy loss has been historically ignored due to the lack of practical and privacy-preserving solutions for registration and handover procedures in cellular networks. In this paper, we propose a universally composable authentication and handover scheme with strong user privacy support, where each MVNO user can validate a mobile operator (MNO) and vice-versa without compromising user anonymity and unlinkability support. Here, we anticipate that our proposed solution will most likely be deployed by the MVNO(s) to ensure enhanced privacy support to their customer(s). Rabiah Alnashwan, Yang Yang 0138, Yilu Dong, Prosanta Gope, Behzad Abdolmaleki, Syed Rafiul Hussain |
CCS | 1 |
| 2024 | UniHand: Privacy-Preserving Universal Handover for Small-Cell Networks in 5G-Enabled Mobile Communication with KCI ResilienceabstractIntroducing Small Cell Networks (SCN) has significantly improved wireless link quality, spectrum efficiency and network capacity, which has been viewed as one of the key technologies in the fifth-generation (5G) mobile network. However, this technology increases the frequency of handover (HO) procedures caused by the dense deployment of cells in the network with reduced cell coverage, bringing new security and privacy issues. The current 5G-AKA and HO protocols are vulnerable to security weaknesses, such as the lack of forward secrecy and identity confusion attacks. The high HO frequency of HOs might magnify these security and privacy concerns in the 5G mobile network. This work addresses these issues by proposing a secure privacy-preserving universal HO scheme (UniHand) for SCNs in 5G mobile communication. UniHand can achieve mutual authentication, strong anonymity, perfect forward secrecy, keyescrow-free and key compromise impersonation (KCI) resilience. To the best of our knowledge, this is the first scheme to achieve secure, privacy-preserving universal HO with KCI resilience for roaming users in 5G environment. We demonstrate that our proposed scheme is resilient against all the essential security threats by performing a comprehensive formal security analysis and conducting relevant experiments to show the cost-effectiveness of the proposed scheme. Rabiah Alnashwan, Prosanta Gope, Benjamin Dowling |
CSF | 1 |
| 2023 | Privacy-Aware Secure Region-Based Handover for Small Cell Networks in 5G-Enabled Mobile CommunicationabstractThe 5G mobile communication network provides seamless communication between users and service providers and promises to achieve several stringent requirements, such as seamless mobility and massive connectivity. Although 5G can offer numerous benefits, security and privacy issues still need to be addressed. For example, the inclusion of small cell networks (SCN) into 5G brings the network closer to the connected users, providing a better quality of services (QoS), resulting in a significant increase in the number of Handover procedures (HO), which will affect the security, latency and efficiency of the network. It is then crucial to design a scheme that supports seamless handovers through a secure authentication process. With this aim, in this article, we propose a secure region-based handover scheme that supports seamless connectivity for SCNs in 5G. Our proposed scheme is based on asymmetric-key-based authenticated key exchange and handover protocols that preserve user privacy and network security while providing a seamless region-based handover mechanism and effective membership revocation management. In this context, we introduce three privacy-preserving protocols, i.e., an initial authentication protocol, an intra-region handover protocol and an inter-region handover protocol, for dealing with three communication scenarios. To the best of our knowledge, this is thefirstpaper to consider the privacy and security in both the intra-region and inter-region handover scenarios in 5G communication with effective membership revocation management support. Detailed security and performance analysis of our proposed scheme is presented to show that it is resilient against many security threats, is cost-effective and provides an efficient solution for 5G-enabled mobile communication. Rabiah Alnashwan, Prosanta Gope, Benjamin Dowling |
IEEE Trans. Inf. Forensics Secur. | 1 |