Ashok Kumar Das

dblp:39/871 · DBLP profile ↗
← Back
225ranked-venue papers
16as first author
136since 2021 · last 2026
0000-0002-5196-9589ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 98 · 5 first-author · 73 since 2021Security and privacy · 40 · 5 first-author · 10 since 2021Applied, interdisciplinary, general and emerging computing · 35 · 1 first-author · 27 since 2021Systems, architecture and hardware · 28 · 2 first-author · 14 since 2021Artificial intelligence and machine learning · 5 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 2 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-authorTheory of computation · 2 · 2 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 Blockchain-Based Secure Product Authenticity Verification for Industrial Networks
abstract
The number of fake products is increasing day by day, which creates many serious problems. These fake items are unsafe for brand reputation as breaks trust and value also unsafe for consumers. Traditional methods like holograms, barcodes, etc., are widely used, but at certain levels, counterfeiters misuse them and copy them, which is not fully transparent. To address these issues, in this paper, we suggest using a blockchain-based system to verify whether a product is real or fake. Leveraging blockchain’s immutability and integrity, the product information is securely recorded using unique block hashes and Quick Response (QR) codes, making unauthorized tampering more difficult once the data is recorded. The consumers can confirm the originality of the product by simply scanning or uploading QR codes, which makes it tough for counterfeiters to clone the QR codes. A key feature of our approach is the integration of multi-scan detection. This system helps to detect unusual or suspicious scanning behavior and creates more trust. The system uses smart contracts to automate secure product registration and verification processes. To demonstrate feasibility, we present the details of the prototype, including database design, flowcharts, and user interface, illustrating its practical deployment.
Varun Dobhal, Saksham Mittal, Mohammad Wazid, Sourav Saha 0002, Ashok Kumar Das, Shantanu Pal, Joel J. P. C. Rodrigues
ICBC5
2026 Securing Financial Transactions Using DLT-Enabled Quantum-Safe Authentication Scheme
Debnath Ghosh, Abhishek Kumar Pandey, Prithwi Bagchi, Ashok Kumar Das, Shantanu Pal, Ravi Kappagantu, Srinivas V. Katakam, Jitendra Chougala
IWCMC4
2026 Pairing-Free Certificateless Searchable Encryption with Forward Secrecy for Cloud-Assisted IoT
Debjani Mallick, Ashok Kumar Das, Joel J. P. C. Rodrigues
IWCMC2
2026 P2AS-EV: Privacy-preserving authentication scheme for electric vehicles using ECC and PUF with anonymity and unlinkability
Mohammad Abdussami, Sanjeev Kumar Dwivedi, Mohd Shariq, Ashok Kumar Das, Adesh Pandey, Khalid Alsubhi, Mehedi Masud
Ad Hoc Networks4
2026 Task offloading and optimization methods in UAV-enabled mobile edge computing: A comprehensive survey
Cheru Haile Tesfay, Long Yang 0002, Jabar Mahmood, Mengmeng Ren, Shuangduo Zhang, Ashok Kumar Das, Shehzad Ashraf Chaudhry
Comput. Commun.7
2026 PDCM-IoD: A Lightweight PUF-Based Drone Access Control Mechanism for Internet of Drones
abstract
The growing number of Unmanned Aerial Vehicles or drones in low altitude airspace has opened multitude of frontiers in diverse applications such as smart city, disaster management, logistics, and surveillance operations. Nonetheless, the open and dynamic communication landscape leads the Internet of Drones (IoD) environment to many security threats including forgery, unauthorized access or physical drone hijacking attacks. One of the pressing challenges is to ensure perfect forward secrecy using symmetric crypto-primitives, since most of the conventional access control schemes rely on costly public key cryptosystems that might not be suitable for constrained environment. We can spot many lightweight key agreement mechanisms for IoD environment, however regrettably, security loopholes render those inappropriate for deployment. In this paper, we propose a lightweight access control mechanism for IoD environment leveraging Physically Unclonable Function (PUF) based on Barrel-Shifter (BS) architectures. The commutative properties of BS oriented PUF (BS-PUF) have been exploited to ensure perfect forward secrecy in PDCM-IoD. Moreover, it ensures privacy, revocation of rogue user’s identity, and resistance from known attacks including physical drone capture threats and forgery attacks. It significantly helps to reduce computational overheads in comparison with other IoD-based schemes. The security features are rigorously analyzed using RoR-based random oracle model. Overall, the PDCM-IoD supports 19.52% increased number of security features. The performance evaluation depicts that PDCM-IoD is highly suitable for IoD-based resource deficient ecosystem.
Shehzad Ashraf Chaudhry, Azeem Irshad, Matloub Hussain, Bander A. Alzahrani, Ashok Kumar Das, Muhammad Nasir Mumtaz Bhutta
IEEE Internet Things J.5
2026 PUF-ILM: A PUF-Enabled Authentication Scheme for Internet of Vehicles Using Improved Logical Mapping
abstract
This article proposes a lightweight two-way authentication scheme, PUF-ILM, that integrates Physical Unclonable Function (PUF) and Improved Logistic Map (ILM). The PUF generates unique challenge-response pairs (CRPs) for each device using its inherent physical randomness, thereby achieving reliable device identity authentication. The ILM encrypts and obfuscates the transmitted CRPs by enhancing their chaotic characteristics, expanding the parameter range, and eliminating periodic windows, effectively resisting modeling and eavesdropping attacks. Security analysis indicates that this scheme possesses several known security attributes, including anti-cloning, anonymity, two-way authentication, forward/backward security, and anti-machine-learning modeling. Performance evaluation shows that PUF-ILM maintains low communication overhead while maintaining a simple system structure and does not rely on complex hardware or external trusted institutions, offering high security and strong practicality, making it especially suitable for large-scale deployment in resource-constrained Internet of Vehicles environments.
Sajjad Hussain Chauhdary, Linhua Jiang, Farrukh Aslam Khan, Ashok Kumar Das, Shehzad Ashraf Chaudhry
IEEE Internet Things J.5
2026 ZTS-CIoHT-PPRF: Zero Trust Security-Based Mutual Authentication Scheme for Cloud-Assisted IoHT Using Puncturable Pseudorandom Function
abstract
The incorporation of cloud to Internet of Health Things (IoHT) referred to as Cloud-assisted IoHT (CIoHT) assures efficient storage of the sensitive health data with better flexibility and scalability. However, owing to the openness nature of the CIoHT infrastructure, it is often susceptible to several security threats. On the contrary, security is an essential aspect of the CIoHT infrastructure. Thus, to address these security concerns, it is a common practice to establish a mutual authentication scheme among the communicating cloud entities that ensures to satisfy all the essential security requirements. In line with this, establishing trust among these entities is also a significant prerequisite. However, after a rigorous literature survey, it is found that all the existing authentication schemes are either vulnerable to various security threats or bear higher computation and/or communication overheads. Above all, these schemes have either taken the security or the trust aspect into consideration, but not both. Thus, we have proposed a Zero Trust Security (ZTS) based mutual authentication scheme for the CIoHT infrastructure using a Puncturable Pseudorandom Function (PPRF) in this paper. The detailed security analysis using informal and formal security analysis, and formal security verification using AVISPA tool ensures that the proposed scheme is highly robust against various known attacks needed in a CIoHT infrastructure. Moreover, the comprehensive comparative analysis exhibit that in comparison to the related literature our scheme provides higher computation and communication efficiency. Thus, unlike the existing schemes, the proposed scheme satisfies the vital security-trust-efficiency traid; ensuring its feasibility for implementation in real-world CIoHT infrastructure.
Priyanka Das 0011, Sangram Ray, Mou Dasgupta, Ashok Kumar Das, Youngho Park 0005, Mahesh Chandra Govil
IEEE Internet Things J.4
2026 Postquantum Secure Lattice-Based Authentication Scheme for IoT-Enabled Crop Recommender System
abstract
Internet of Things (IoT)-enabled smart farming has emerged as one of the most progressive domains, integrating knowledge discovery as a core component to assist farmers in analyzing their fields and obtaining accurate crop recommendations. However, the advent of quantum computing introduces significant security threats to this domain, emphasizing the urgent need to transition from classical to quantum-secure authentication mechanisms. To address this challenge, this article presents a post-quantum, lattice-based secure authentication scheme tailored for intelligent crop recommendation systems. The cryptographic scheme strengthens the data communication pipeline, and additionally, the framework incorporates security-aware design considerations within the machine learning phase, which acts as the second line of defense for the recommendation system. The security of the scheme is thoroughly analyzed for classical as well as quantum attacks. The insights gained from the real-time testbed validate the efficiency and accuracy of the framework.
Snehal Jain, Abhishek Kumar Pandey, Ashok Kumar Das, Shantanu Pal, Youngho Park 0005
IEEE Internet Things J.3
2026 Robust and Lightweight User Authentication Scheme Using Deep Learning-Based Cancelable Biometrics in Smart Home Environments
Deok Kyu Kwon, Ashok Kumar Das, Youngho Park 0005
IEEE Internet Things J.3
2026 Post-Quantum Secure Lattice-Based Lightweight Authentication and Key Agreement Scheme for Multilayer IoT-Enabled Smart Grid System
abstract
The smart grid is a modern electricity network that incorporates sophisticated communication and control technologies to improve efficiency, reliability, and security. This study presents a secure, lightweight authentication and key agreement scheme for multi-layer Internet of Things (IoT)-enabled smart grid systems, targeting the essential requirement to safeguard industrial control networks against cyber threats. The proposed scheme incorporates two security mechanisms to improve authentication and communication security in smart grid systems. Physical Unclonable Functions (PUFs) facilitate secure device authentication between smart meters and the Master Terminal Unit (MTU) by utilizing hardware-level uniqueness, thereby ensuring resilience against cloning attacks. Additionally, post-quantum lattice-based Ring Learning with Errors (RLWE) hard problem ensures secure communication between the MTU and the Remote Terminal Unit (RTU), providing quantum-resistant security and efficient key exchange. The framework’s resilience is rigorously evaluated with the ProVerif security verification tool to confirm its strength against advanced cyberattacks. A formal security analysis quantitatively assesses the cryptographic robustness of the scheme, whereas an informal security analysis examines its ability to withstand practical cyber threats, including replay attacks, man-in-the-middle (MITM) attacks, and device impersonation in actual smart grid environments.
Gagan Kumar, Bala Prakasa Rao Killi, Ashok Kumar Das, Youngho Park 0005
IEEE Internet Things J.3
2026 A Lightweight Authentication Scheme for Securing Patient Information in the Internet of Medical Things Environment
abstract
The Internet of Things (IoT) is an evolving paradigm expected to permeate every aspect of human existence. IoT is a growing trend in which numerous devices interconnect with each other to transmit sensitive data. One of its significant application areas is the Internet of Medical Things (IoMT), which promises a contemporary healthcare environment via linked sensors, clinical systems, and wearable medical devices. However, public communication among these devices faces challenges like security, privacy, authentication, and machine learning/modeling attacks. Additionally, most existing schemes are vulnerable to impersonation, denial-of-service, and machine-learning/modeling attacks. Therefore, this article addresses these challenges by designing a lightweight authentication scheme that utilizes a one-time physical unclonable function (OPUF) and elliptic curve cryptography to reduce the likelihood of machine learning/modeling attacks on wearable medical devices. We utilizeOPUFto resist machine learning/modeling attacks. We also employ a rate-limiting mechanism that restricts the number of authentication requests within a specific time window to enhance resistance against denial-of-service (DoS) attacks. Moreover, the devised scheme also offers resistance to impersonation, session key leakage, ephemeral secret leakage, desynchronization, and ML-based modeling attacks. We analyze the security and reliability of the devised scheme using informal and formal analysis. Informal analysis indicates that the scheme offers essential security features, while formal analysis substantiates these findings. In the end, we present the results of the performance analysis, which show that the devised scheme achieves an average reduction of 26.92% and 21.53% in computational and communication costs, respectively.
Wen-Chung Kuo, Zahid Ghaffar, Khalid Mahmood 0002, Tayyaba Tariq, Salman Shamshad, Ashok Kumar Das
IEEE Internet Things J.6
2026 A Blockchain-Enabled Image Encryption Protocol Based on Quantum Walk for Securing Industrial Internet of Things Environments
abstract
The swift, secure transmission of data, especially sensitive data, such as that acquired from high-resolution image sensors, is a major focus of the Industrial Internet of Things (IIoT). Current strategies do not strike a balance between security and efficiency, causing messages to be lost and/or processing to be delayed to an unacceptable level. We present a new quantum-inspired quantum walk (Q-IQW) encryption protocol. The Q-IQW protocol is used to implement the first blockchain for the safe transfer of data between IIoT devices. For the first time, quantum hash functions based on Q-IQW are used to link blocks in a chain instead of traditional hash functions. The main contributions of the protocol are the efficient data transfer between IIoT nodes and the ability to fully control their data. This work focuses on simulating the protocol to understand the theoretical and empirical performance of the protocol. The results show that in terms of entropy of 7.99 and unified average changing intensity (UACI) of 33.56%, the protocol is very robust as evidenced by 99.58% number of pixel change rate (NPCR), and low correlation, i.e., the protocol exhibits very high security. Further, the protocol is reliable in that it can perfectly recover images under high distortion, for example, a 50% data occlusion in the encrypted images. These outcomes underscore the dependability, utility, and efficiency of the protocol in protecting IIoT information to make it a viable remedy for maintaining the integrity of the information during transfer and storage.
Sunil Prajapat, Pankaj Kumar 0006, Muhammad Ghulam, Ashok Kumar Das
IEEE Internet Things J.5
2026 PQ-AuthV: Post-Quantum Secure Authentication With Aggregated Signatures in IoT-Enabled Smart Vehicle Networks
Arun Sekar Rajasekaran, Ashok Kumar Das, Maria Azees, Gulfishan Firdose Ahmed, Mpyana Mwamba Merlec, Hoh Peter In, Shantanu Pal
IEEE Internet Things J.2
2026 A Robust Tamper-Resistant and Location-Aware Authentication Protocol for Securing Charging Services in V2G Environments
abstract
The rapid increase in electric vehicles (EVs) and the widespread deployment of charging stations have made secure authentication a critical requirement in Vehicle-to-Grid (V2G) environments. The growing interconnection among EVs, charging stations, and grid infrastructure introduces serious security and privacy challenges, including impersonation, replay, ephemeral secret leakage, and physical tampering attacks. Although several authentication protocols have been proposed for EV charging services, many existing schemes lack robust tamper-resistant and location-aware authentication capabilities and remain unsuitable for dynamic and resource-constrained V2G conditions. To address these limitations, this paper proposes a robust, tamper-resistant, and location-sensitive authentication protocol for securing EV charging services in V2G environments. The proposed protocol integrates configurable Arbiter Physical Unclonable Functions (A-PUFs) to provide device-level protection against physical tampering and unauthorized charging access. It also employs lightweight cryptographic primitives and techniques, including one-way hash functions, XOR operations, concatenation operations, and timestamp-based freshness verification, to support efficient mutual authentication and secure session key agreement. The security of the proposed protocol is evaluated through informal analysis and formal verification under the Random Oracle Model (ROM). Furthermore, comparative analysis demonstrates that the proposed protocol achieves a 17.16% reduction in communication cost and a 7.49% reduction in average computation cost compared with existing authentication protocols while maintaining strong security features. The results confirm that the proposed scheme enhances the security, efficiency, and practical deployability of EV charging authentication for next-generation V2G networks.
Muhammad Umer 0001, Muhammad Farooq 0004, Syed Asad Naqvi, Khalid Mahmood 0002, Bander A. Alzahrani, Ashok Kumar Das, Shehzad Ashraf Chaudhry
IEEE Internet Things J.6
2026 LRAEB: Lightweight and Robust Anonymous ECC and Blockchain-Based Protocol for IoT in the Context of Public Cloud
abstract
Authentication is crucial in Internet of Things (IoT) networks as it ensures the integrity, accuracy, and tamper-resistance of information. This research article aims to design a lightweight and robust secure transmission system for IoT-enabled devices, enabling secure interaction with public cloud computing. The proposed system leverages blockchain technology integrated with elliptic curve cryptography (ECC), resulting in a resilient and efficient scheme tailored for resource and energy-constrained devices. We have adopted the SECP256K1 elliptic curve to design a Lightweight and Robust Anonymous ECC and Blockchain (LRAEB) scheme that offers superior performance. The use of blockchain guarantees the integrity and confidentiality of data stored in public cloud servers, addressing security vulnerabilities such as data leakage and unauthorized access. To validate the security of this novel technique, it will undergo verification using the Random Oracle Model (ROM) and Python. Our theoretical analysis confirms that the LRAEB scheme achieves better efficiency compared to existing schemes. In conclusion, we anticipate that this novel technique will significantly enhance information flow while mitigating the security flaws associated with public cloud computing and IoT devices.
Dingyuan Tang, Mustafa A. Al Sibahee, Shehzad Ashraf Chaudhry, Ashok Kumar Das
IEEE Trans. Cloud Comput.6
2026 Big Data Analytics-Envisioned Quantum-Safe Lattice-Based Three-Party Authenticated Key Agreement Protocol for Cloud IoT-Enabled Healthcare Applications
abstract
Cloud-based Internet of Things (IoT)-enabled smart healthcare plays a vital role in modern society, yet security and privacy challenges remain unavoidable. The authenticated key agreement (AKA) process, which serves as the foundation of secure communication, is widely recognized as a key solution to these challenges. However, many existing AKA methods in the literature either involve high communication and computational costs or fail to withstand quantum attacks. Post-quantum cryptography (PQC) introduces a new class of cryptographic algorithms designed to resist future quantum computer threats. In this article, we present a quantum-secure, lattice-based three-party AKA scheme for smart IoT healthcare applications, leveraging the computationally complex Ring-Learning With Errors (Ring-LWE) problem. Our approach integrates secure big-data analytics with blockchain technology by utilizing authentication procedures for secure data aggregation before storing it in the blockchain. A comprehensive security evaluation including formal and informal analysis, demonstrates the scheme's strong resilience against both classical and quantum attacks. Additionally, experimental results confirm that the proposed scheme is well-suited for real-time smart healthcare applications.
Prithwi Bagchi, Aakash Roy, Mohammad Wazid, Ashok Kumar Das, Bharat K. Bhargava, Youngho Park 0005
IEEE Trans. Dependable Secur. Comput.4
2026 Blockchain-Enabled Secure Signature Scheme With Quantum Key Distribution for IoMT-Based Healthcare Systems
abstract
The rapid expansion of Internet of Medical Things (IoMT) networks has enabled continuous data collection from diverse medical sensors and devices, supporting real-time monitoring, diagnostics, and decision-making. However, the resource limitations of IoT nodes and the open nature of communication channels make healthcare data vulnerable to security and privacy breaches. To address these challenges, this paper presents a blockchain-assisted, privacy-preserving signature scheme leveraging Quantum Key Distribution $(\mathcal {QKD})$ to ensure secure and trustworthy data sharing in Healthcare Internet of Things (H-IoT) environments. The proposed scheme integrates a quantum-designated verifier signature mechanism with a private blockchain infrastructure, where peer nodes validate and store healthcare data securely. Formal (software-based) and informal security analyses demonstrate the scheme's resistance to forgery, replay, and quantum attacks. Simulation experiments conducted in Python show that the proposed protocol achieves strong cryptographic performance, with a computational cost of 42.1ms and a communication overhead of 834 bits. Additionally, a blockchain-based prototype implementation quantifies the time required to append various numbers of blocks and process multiple healthcare transactions, confirming the scalability and practicality of the proposed solution. The results affirm that the scheme offers a reliable, efficient, and quantum-resilient framework for securing sensitive medical data across distributed IoMT healthcare systems.
Sunil Prajapat, Deepika Gautam, Pankaj Kumar 0006, Ashok Kumar Das, Shantanu Pal, Chengzu Dong
IEEE J. Biomed. Health Informatics4
2026 PUF-Enabled Key-Exchange Protocol for Vehicular Ad-Hoc Networks
abstract
The Internet of Vehicles (IoV) enables data exchange among individuals, cloud resources, road infrastructures, and vehicles, interconnected through Vehicular Ad Hoc Networks (VANETs). VANETs comprise vehicles with Onboard Units (OBUs), Roadside Units (RSUs), and a Trusted Party Agent (TPA). The data transmission among these entities supports seamless interaction and collaborative traffic management. However, data transmission on public communication channels in VANETs presents significant challenges, including security, privacy, and authentication of participating entities. Although numerous key exchange and authentication protocols have been introduced to tackle these issues, many protocols remain vulnerable to various attacks, such as a vehicle, RSU, TPA impersonation, denial of service, physical cloning, and desynchronization attacks. Therefore, to address these vulnerabilities, we propose a key exchange protocol that leverages hash functions and Advanced Encryption Standard (AES) encryption. Our protocol also integrates the Physical Unclonable Function (PUF), enhancing its resistance to physical or cloning attacks. Additionally, it effectively counters threats like impersonation, session key leakage, ephemeral secret leakage, and desynchronization attacks. We validate the security and reliability of our protocol through both formal and informal analysis. Informal analysis highlights the protocol’s essential security features, while formal analysis provides robust substantiation. Performance evaluation reveals that our protocol achieves an average reduction of 35.53%, and 53.77%, in communication and computation overheads.
Khalid Mahmood 0002, Zahid Ghaffar, Muhammad Farooq 0004, Muhammad Ilyas 0001, Ashok Kumar Das, Shehzad Ashraf Chaudhry
IEEE Trans. Intell. Transp. Syst.5
2026 Quantum Resistant Lattice-Based Access Control Scheme for UAV-Assisted Internet-of-Drones Applications
abstract
The proliferation of Unmanned Aerial Vehicle (UAV) networks and their numerous benefits in critical scenarios, UAV become crucial for Internet of Drones (IoD) operations. However, due to their communication methods, such as the micro-air-vehicle communication (MAVlink) protocol, wireless connections, and potentially insecure Internet channels, UAV networks are highly vulnerable to potentially lethal attacks. To overcome such issues, public key cryptographic techniques relying on integer factorization problem (IFP) and discrete logarithm problems (DLP) have been used form decades. However, with the significant advancements in quantum computing and adaptation of Shor's algorithm such cryptographic techniques based on IFP and DLP become insecure today and vulnerable to quantum attacks, which demand new ways of thinking about security. In this paper, we propose a quantum-secure access control protocol for UAV-based IoD applications, and its primary focus is on preserving user anonymity. A comprehensive security analysis validates the accuracy, security, and resilience against various active and passive attacks in both classical and quantum scenarios. A thorough formal security verification using the Scyther automated software validation tool to showcases the robustness of the proposed scheme. Furthermore, a real-time testbed experiment on Raspberry Pi 4 devices to assess the computational overhead of various cryptographic primitives demonstrates its practicality. Lastly, a detailed comparative performance evaluation, including authentication accuracy, performance under unknown attacks with existing related schemes illustrates its scalability and efficiency in real-world applications.
Basudeb Bera, Ashok Kumar Das, Biplab Sikdar 0001
IEEE Trans. Mob. Comput.2
2026 Provably Secure and Reliable Privacy-Preserving Authentication Scheme for Drone-to-Drone Communications in Internet of Autonomous Things
abstract
With the rapid advancements in wireless communication technologies, Unmanned Aerial Vehicles (UAVs), also known as Small Unmanned Aerial Vehicles (SUAVs) or drones, have been increasingly used in various applications, including the civilian sector. As a result, the security of SUAVs has garnered significant attention from the research community. Furthermore, drones are resource-constrained in nature and can be vulnerable to various known cybersecurity attacks over wireless communication. In light of these considerations, we propose aProvablySecure andReliable Privacy-Preserving AuthenticationScheme forDrone-to-Drone Communications in Internet of Autonomous Things (PSRS-D2D). The proposed scheme employs a secure one-way cryptographic hash and Elliptic Curve Cryptography (ECC) to accomplish a certain level of security. We provide security and privacy analysis, comparing it with competing UAV authentication schemes. This ensures that the PSRS-D2D scheme can withstand various prominent security properties, including mutual authentication and strong anonymity, and is secure against several attacks, such as replay, impersonation, and Man-In-The-Middle (MITM) attacks. We evaluated the performance of the proposed scheme in terms of computational and communicational costs. Furthermore, we conducted a formal security analysis using the Real-Or-Random (ROR) model and the Scyther simulation tools, which demonstrate that our scheme offers significant advantages in terms of security and performance.
Mohd Shariq, Norziana Jamil, Gopal Singh Rawat, Shehzad Ashraf Chaudhry, Mehedi Masud, Ashok Kumar Das
IEEE Trans. Mob. Comput.6
2025 Fortifying V2RSU Communication with Post Quantum Security in the Green Internet of Vehicles
abstract
Communication in the green Internet of Vehicles (IoV) demands significant energy, encompassing both communication and computation costs, along with fuel and electricity for vehicle operation. The rise of quantum computing threatens the security of existing IoV frameworks, particularly those relying on conventional public-key cryptosystems (PKC) like integer factorization and elliptic curve cryptography, which are vulnerable to quantum attacks. This paper proposes a lightweight, postquantum security protocol for electric vehicles (EVs) in IoV, aimed at reducing computation and communication costs while enhancing energy efficiency. We conduct a comprehensive security analysis and compare our protocol with existing solutions, demonstrating its superior security, scalability, and practical effectiveness. Network simulations using NS3 further validate the robustness and efficiency of the proposed scheme for green IoV applications.
Basudeb Bera, Sourav Saha 0002, Ashok Kumar Das, Joel J. P. C. Rodrigues, Biplab Sikdar 0001
ICC3
2025 A Contextual Aware Enhanced LoRaWAN Adaptive Data Rate for mobile IoT applications
Muhammad Ali Lodhi, Lei Wang 0005, Arshad Farhad, Khalid Ibrahim Qureshi, Jenhui Chen, Khalid Mahmood 0002, Ashok Kumar Das
Comput. Commun.7
2025 Privacy preserving unique robust and revocable passcode generation from fingerprint data
Priyabrata Dash, Debasis Samanta, Monalisa Sarma, Ashok Kumar Das, Athanasios V. Vasilakos
Comput. Secur.4
2025 A deep learning ensemble approach for malware detection in Internet of Things utilizing Explainable Artificial Intelligence
Saksham Mittal, Mohammad Wazid, Devesh Pratap Singh, Ashok Kumar Das, M. Shamim Hossain
Eng. Appl. Artif. Intell.4
2025 A blockchain-assisted privacy-preserving signature scheme using quantum teleportation for metaverse environment in Web 3.0
Sunil Prajapat, Pankaj Kumar 0006, Ashok Kumar Das, M. Shamim Hossain
Future Gener. Comput. Syst.4
2025 Secure Cloud-Storage-Based Big Data Analytics Scheme for Intelligent Vehicles Environment
abstract
The Internet of Vehicles (IoV) is a system designed to enhance transportation efficiency and safety by facilitating communication and data exchange among vehicles, infrastructure, and other devices. In IoV, vehicles, roadside units (RSUs), and cloud servers (CSs) are interconnected for seamless communication and data exchange. However, sharing data among various IoV entities poses significant security threats, including privacy breaches, data manipulation, and unauthorized access. These threats can compromise personal information, cause system malfunctions, and endanger the safety of vehicle occupants and other road users. To address these challenges, this article proposes a secure transfer mechanism for data sharing among IoV entities and a framework for secure big data analytics, where the data collected from vehicles undergoes secure analysis at the big data analytics center. Experimental evaluation, along with security and performance analysis, demonstrates that the proposed approach ensures secure data transfer between IoV entities and secure big data analytics in the CS.
Prakash Tekchandani, Soumya Banerjee 0001, Ashok Kumar Das, Shantanu Pal, Sachin Shetty
IEEE Internet Things J.4
2025 Designing Secure Location-Based Authenticated Key Agreement Mechanism in Maritime Internet of Vessels for Big Data Analytics
abstract
Maritime communication, critical for global oceanic trade, faces challenges and opportunities with advancements in Information and Communication Technology (ICT). Traditional methods are susceptible to interception due to open channels, limited authentication, jamming, and other security risks. Securing vessel movements and locations in Internet of Vessels (IoV) is essential to prevent unauthorized data interception and tampering during transmission. We propose a ship authentication method using location-based secure keys to ensure the confidentiality of a vessel’s whereabouts. The proposed scheme’s robustness is validated through formal and informal security analyses, and formal verification using the Scyther automated verification tool, demonstrating its effectiveness against potential attacks in maritime networks. Comparative studies indicate that utilizing location-based keys maintains anonymity and untraceability without imposing significant computational or communication burdens. Experimental findings from comprehensive big data analytics and simulations using NS3 validate the scheme’s feasibility and performance.
Anusha Vangala, Ashok Kumar Das, Neeraj Kumar 0001, Mohammed J. F. Alenazi, Sachin Shetty
IEEE Internet Things J.3
2025 Provably Secure Efficient Key-Exchange Protocol for Intelligent Supply Line Surveillance in Smart Grids
abstract
Intelligent supply line surveillance is critical for modern smart grids (SGs). Smart sensors and gateway nodes are strategically deployed along supply lines to achieve intelligent surveillance. They collect data continuously and transmit it to the control centre in real-time. It enables real-time monitoring, fault detection, and efficient energy management across distribution networks. This advanced surveillance system ensures continuous monitoring of supply lines, detecting anomalies, and optimizing operations to maintain the stability and reliability of the SG. However, the reliance of all participating nodes on public communication channels to transmit supply line surveillance data exposes these systems to critical cyber attacks. These cyber attacks include impersonation, physical tampering, ephemeral secret leakage (ESL), and desynchronization attacks. To address these issues, existing key-exchange protocols often fail to ensure robust security while imposing high computation and communication overheads, limiting their practicality for resource-constrained environments. Therefore, we propose a secure and efficient key exchange and tamper-resistant authentication protocol using elliptic curve cryptography (ECC) and physical unclonable functions (PUFs). The PUF mechanism provides robust resistance against physical tampering and cloning attacks, ensuring enhanced physical security for supply line devices. We validate the security robustness of the devised protocol using the random or real (ROR) model. Furthermore, informal security analysis demonstrates the protocol’s robustness in rigorously resisting various attacks, including physical tampering, impersonation, ESL and desynchronization. Moreover, we determine the performance evaluation that reveals the protocol’s superior efficiency compared to competing protocols, achieving significant reductions of 28.64% in computation overhead and 9.96% in communication overhead.
Muhammad Faizan Ayub, Xiong Li 0002, Khalid Mahmood 0002, Mohammed J. F. Alenazi, Ashok Kumar Das
IEEE Internet Things J.5
2025 A Robust Key Exchange and Tamper-Resistant Protocol for HAN and NAN Networks in Smart Grids
abstract
Smart grids (SGs) rely on home area networks (HANs) and neighborhood area networks (NANs) to ensure efficient power distribution, real-time monitoring, and seamless communication between smart devices. Despite these advantages, the use of public communication channels in HAN and NAN networks introduces critical challenges, such as vulnerability to impersonation, physical tampering, and scalability issues in resource-constrained environments. These issues compromise the stability, reliability, and security of SG environments. Existing protocols often fail to adequately address these challenges, particularly in ensuring resistance to physical tampering of supply lines and impersonation attacks. Additionally, they struggle to minimize the computation, communication, and energy costs associated with securing a resource-constrained SG environment. Therefore, we propose a robust key exchange and tamper-resistant protocol for HAN and NAN networks to address these limitations. The proposed protocol leverages the physical unclonable function (PUF) mechanism to offer physical tampering resistance to smart meters. We validate our protocol formally using the Random or Real (RoR) model, which confirms its security robustness. Additionally, our informal security analysis highlights the protocol’s resilience against impersonation, physical tampering attacks, etc. We analyze and compare the performance of the proposed protocol, which further demonstrates our protocol’s effectiveness and security compared to competing protocols. Moreover, the proposed protocol achieves resource efficiency with 45.99% and 58.85% substantial reductions in computation overhead and energy overhead, respectively, compared to competing protocols. These results showcase the protocol’s enhanced security and practicality for resource-constrained SG environments.
Muhammad Faizan Ayub, Xiong Li 0002, Khalid Mahmood 0002, Salman Shamshad, Ashok Kumar Das
IEEE Internet Things J.5
2025 BSP-IoD: A Secure Drone-Enabled Authentication Protocol Using Barrel-Shifter PUF
abstract
Due to the rapid proliferation of Unmanned Aerial Vehicles (UAVs), also termed as drones, the Internet of Drones (IoD) has revolutionized various domains including disaster response, smart surveillance, remote sensing, by facilitating real time collection of aerial data using autonomous coordination. However, the exposed communication landscape of IoD networks render them highly susceptible to known threats including forgery, impersonation and physical capture threats. Most of the conventional key agreement techniques are costly for computations and not suitable for resource constrained IoD system which necessitate low cost yet secure authentication mechanisms. Though, many lightweight drone authentication schemes have been presented, however with security limitations. This study suggested a novel Barrel-Shifter Physically Unclonable Function (BS-PUF) based drone authentication protocol (BSP-IoD) to augment security of IoD network. Leveraging the intrinsic randomness, commutative and invertible properties of BS-PUF, the BSP-IoD ensures construction of mutually agreed session key employing unique challenge-response pairs (CRPs). The scheme could withstand known threats besides supporting perfect forward secrecy and privacy to the user. The BSP-IoD considerably mitigates computational overheads besides ensuring resilience against known attacks including resistance from drone physical capture threat, promoting viability for next generation IoD networks. The formal analysis and performance assessment exhibit that BSP-IoD could address the critical challenges of next generation IoD applications. Furthermore, it supports 56.6% more number of security properties as compared to preceding schemes.
Azeem Irshad, Abdul Jaleel, Abid Mehmood, Gulam Ali Mallah, Ashok Kumar Das, Shehzad Ashraf Chaudhry
IEEE Internet Things J.5
2025 A Cost-Effective Key Agreement Encryption Protocol for Securing IIoT-Enabled WSN Communication
abstract
Wireless sensor networks (WSNs), pivotal in the industrial Internet of Things (IIoT), encompass resource-limited sensor nodes, users, and gateways. Advancements in Internet technologies have substantially facilitated remote data access, rendering WSNs indispensable across various sectors, such as defense, agriculture, disaster management, and healthcare, where they serve as pivotal components for remote monitoring and control mechanisms. Within the IIoT framework, the transmission of critical and sensitive information over public channels presents significant security challenges. Such challenges disrupt operations and compromise the integrity and reliability of industrial processes. The system must include an authentication mechanism to tackle this critical issue that resists potential security threats. Consequently, this article introduced a reliable and secure the three-factor authentication protocol tailored for IIoT environments. The proposed protocol aims to mitigate unauthorized access and safeguard the integrity of industrial operations. We comprehensively evaluated the protocol’s robustness and security efficiency by employing informal and formal security analysis techniques, highlighting its effectiveness in resisting potential threats. This proposed protocol fortifies the network against potential security threats, ensuring security and system reliability in industrial applications. This protocol assists only legitimate users in accessing the sensing devices remotely. Moreover, the statistical results endorse the resource efficiency of the devised protocol as it achieves 43.2% and 35.8% efficiency in terms of communication and computational costs, respectively.
Khalid Mahmood 0002, Mah Noor Fatima, Salman Shamshad, Zahid Ghaffar, Ashok Kumar Das, Mohammed J. F. Alenazi
IEEE Internet Things J.5
2025 A Privacy-Preserving Access Control Protocol for Consumer Flying Vehicles in Smart City Applications
abstract
The Internet of Drones (IoD) offers supervised admittance to drones in a targeted fly zone as the byproduct of the Internet of Things (IoT). The term drone is the trendy alias for intelligent flying vehicle (IFV). The contemporary sensing, processing, and connectivity services enrich the use of drones in many civilian and military applications. In these applications, consumers can acquire real-time information directly from flying drones in a smart city environment. While this feature undeniably empowers consumers, it poses significant security risks due to the direct access privilege. We propose an anonymous protocol for consumer flying vehicles within smart city applications to mitigate these threats. The proposed protocol utilizes a physically unclonable function to sustain the physical security of flying vehicles. We ratify our protocol’s security fortitude and persistence through inclusive security analysis. We demonstrate the performance evaluation under diverse performance metrics, which shows that the proposed protocol achieves 40.69% and 17.91% efficiency as compared to related protocols in terms of computation and communication cost comparison, respectively.
Khalid Mahmood 0002, Zahid Ghaffar, Lata Nautiyal, Muhammad Wahid Akram, Ashok Kumar Das, Mohammed J. F. Alenazi
IEEE Internet Things J.5
2025 Authenticated Certificateless Verifiable Searchable Public Key Encryption Scheme With Big Data Analytics for IoT-Based Healthcare
abstract
The emerging concept of Internet of Things (IoT)-based healthcare Industry 5.0 emphasizes the integration of human intelligence with cutting-edge technologies, like Artificial Intelligence (AI), blockchain, IoT, big data analytics, and machine learning (ML) models to revolutionize healthcare delivery. However, alongside the immense potential and opportunities of healthcare 5.0, the rapid expansion of sensitive medical data within the cloud-based healthcare systems also brings significant challenges related to data security, privacy, and resource requirements. Since most healthcare infrastructures depend on the semi-trusted centralized cloud storage, it then becomes crucial to store medical records in encrypted form in order to ensure confidentiality and privacy of the data. At the same time, these systems must provide seamless and efficient search capabilities for authorized medical personnel in healthcare system. To address these concerns and enable cost-effective, secure access and data management, we propose a novel authenticated certificateless verifiable searchable public key encryption scheme (ACLV-SPKE) that emerges as a robust and promising solution for securing healthcare data. The proposed framework not only resists diverse adversarial attacks but also ensures efficiency in terms of communication and computation costs, while offering improved functionality over recent state-of-the-art solutions presented in literature. The proposed scheme effectively resists both inside and outside keyword guessing attacks, achieving strong security guarantees like ciphertext and trapdoor indistinguishability, which are proved in the random oracle models. In addition, we applied big data analytics on a real healthcare dataset to evaluate the performance metrics, and the outcomes are presented in this article.
Debjani Mallick, Ashok Kumar Das, Mohammad Wazid, Youngho Park 0005
IEEE Internet Things J.2
2025 Uncrewed Aerial Vehicles Empowering Secure Authentication in Cognitive IoMT for Transformative Knowledge Discovery in Data
abstract
The paradigm shift toward digital transformation is increasingly advancing toward cognitive decision discovery, particularly within the healthcare domain, where it has emerged as a critical area of research. Numerous researchers are actively contributing to this field. However, due to the sensitive nature of healthcare data, ensuring robust security within the cognitive decision-making process is paramount for Internet of Medical Things (IoMT). To address this concern, the present study proposes a comprehensive privacy-preserving authentication scheme associating aerial computing and knowledge discovery. This scheme leverages an elliptic curve-based cryptosystem to establish the authentication protocol and incorporates blockchain technology to ensure data storage security. Furthermore, the scheme facilitates secure knowledge discovery in data (KDD) within cognitive decision-making frameworks. The proposed authentication mechanism is evaluated across communication, computational efficiency, and security parameters to validate its functionality and robustness as well as to formally verify the developed scheme Scyther tool verification is done by authors. Additionally, to demonstrate the necessity and effectiveness of the proposed scheme, the authors conducted a KDD experiment using both a securely authenticated dataset and an insecure, compromised dataset. The results of these experiments are presented and thoroughly analyzed in the article.
Abhishek Kumar Pandey, Ashok Kumar Das, Mohammad Wazid, Kuljeet Kaur, Youngho Park 0005, Mohammad Mehedi Hassan
IEEE Internet Things J.2
2025 Big Data Analytics-Envisioned Authenticated Key Management Scheme in IoT-Based Smart Farming System for Sustainable Development of Smart Cities
abstract
Smart farming enhances sustainable communication practices through the deployment of energy-efficient Internet of Things (IoT) devices, low-power wireless technologies, and edge/fog computing to reduce data transmission and energy usage. Smart cities represent a concept in which technology, data, and innovation enhance urban efficiency, sustainability, and livability. Smart farming has the potential to facilitate the sustainable development of smart cities. However, integrating smart farming into smart city systems presents significant challenges, particularly with respect to the security of their interconnected components. The vulnerability of agricultural information and the likelihood of cybersecurity threats necessitate the development of targeted security solutions for smart farming. To address these challenges, we propose a Big Data Analytics-envisioned secure smart farming scheme for sustainable cities (in short, CSSF-SC). It is an efficient authenticated key agreement mechanism that enables secure mutual authentication, session-key establishment, and dynamic key management among smart farming devices, drones, and cloud servers. Using the Scyther verification tool, security is formally verified under the Dolev–Yao and CK adversary models, demonstrating resilience to various potential attacks. A comparative performance analysis shows that CSSF-SC outperforms current schemes in terms of computation and communication costs while offering stronger security and additional functionalities. Finally, a practical implementation is done using the MangoLeafBD dataset and an EfficientNet-B7 architecture. It achieves 99.16% accuracy, validating the framework’s effectiveness for secure crop-data collection and analysis in real-world scenarios.
Akshita Patwal, Mohammad Wazid, Ashok Kumar Das, Devesh Pratap Singh, Shantanu Pal, Youngho Park 0005
IEEE Internet Things J.3
2025 Generative AI-Enabled Quantum Encryption Algorithm for Securing IoT-Based Healthcare Application Using Blockchain
abstract
The integration of artificial intelligence (AI) with the Internet of Things (IoT) has transformed numerous domains through the AI of Things (AIoT). Nonetheless, AIoT encounters issues related to energy usage and carbon emissions as mobile technology continues to progress. Generative AI (GAI) possesses significant potential to mitigate carbon emissions associated with AIoT, owing to its higher reasoning and generative powers. Conventional security protocols frequently encounter issues with computational efficiency, latency, and overall security comprehensiveness. Blockchain technology, characterized by its decentralized and immutable properties, is a viable approach for improving electronic healthcare data transmission and node authentication in IoT networks. This research examines secure data transmission and node encryption in IoT systems, with a particular emphasis on data management. Conventional approaches encounter constraints in computational efficiency, latency, and comprehensive security. This study presents a novel protocol that combines GAI and blockchain technology with quantum encryption to enhance authentication and ensure secure data transmission. The algorithm comprises multiple consecutive processes, including the encoding and transmission of node requests, followed by the authentication process utilizing hash functions and digital signatures. The authentication approach utilizes a challenge-response technique, guaranteeing that only nodes with authentic credentials can advance. Thereafter, a dynamic key exchange protocol and quantum encryption method provide secure data delivery. The results indicate the procedure’s effectiveness in ensuring secure and regulated access to patient data, underscoring its significance in medical facilities. The system’s functionalities are augmented by a thorough evaluation employing machine learning. The findings indicate that the system exhibits an accuracy of 99.4%, precision of 99.10%, recall of 98.66%, F1-score of 98.50%, and security of 99.2%. An extensive analysis and comparison with the state-of-the-art methods demonstrate the significant advancements of the suggested method in tackling cryptographic security challenges. The algorithm offers a thorough approach to protecting IoT applications, especially in managing healthcare data.
Sunil Prajapat, Pankaj Kumar 0006, Ashok Kumar Das, Muhammad Ghulam
IEEE Internet Things J.3
2025 Lightweight Chebyshev Polynomial-Based Authentication and Signature Framework With Antenna Array for IoT-Enabled V2V and V2X Communications
Arun Sekar Rajasekaran, Ashok Kumar Das, Maria Azees, Kalyan Sundar Kola, Nagaraju Dharavat, Minho Jo 0001
IEEE Internet Things J.2
2025 A Secure IoT-Enabled Medical Data Sharing Scheme Using Blockchain-Assisted Private Set Intersection
abstract
Advances in Internet-of-Things (IoT) technology are enabling the sharing of electronic health records (EHR) via wireless channels. Because EHRs contain sensitive patient information, it is important to preserve data privacy along with medical data sharing. In this paper, we propose a secure medical data sharing scheme using blockchain-assisted private set intersection (PSI). Our approach ensures access control and data availability by having data users upload encrypted private set intersections to the blockchain. We also proposed a mutual authentication phase between the hospital and data user after calculating private set intersection. We thoroughly analyzed the proposed scheme using informal methods and proved security against semi-honest adversary model, correctness, and session key security using formal methods. We also implemented the proposed scheme in real environments using laptop and Raspberry PI 4 to prove the practicality of the proposed scheme. We compared the proposed mutual authentication scheme with existing methods and show that the proposed scheme is better than existing schemes.
Seunghwan Son, Deok Kyu Kwon, YoHan Park 0001, Ashok Kumar Das, Youngho Park 0005
IEEE Internet Things J.4
2025 A Lightweight Authentication Protocol for RFID-Assisted Supply Chain Management System
abstract
In the evolving landscape of supply chain management, the integration of radio-frequency identification (RFID) technology has marked a significant milestone. This development has led to the emergence of a new system in RFID-based supply chain management, which is intricately linked with the advances in the Internet of Things (IoT). RFID technology employs electromagnetic fields to identify and track tags on objects and revolutionizes the management and tracking of items in the supply chain. However, the public communication among RFID tags, RFID readers, and supply chain infrastructure predominantly escalates security and privacy challenges. Several authentication protocols have been proposed to overcome these challenges. However, the vulnerability of most proposed protocols to numerous security attacks renders them inefficient. Therefore, to address these crucial challenges, we devised an RFID-based authentication protocol for supply chain management systems. The incorporation of a physically unclonable function (PUF) into the protocol fortifies the system against physical tampering attacks. To validate the security and effectiveness of the devised protocol, both informal and formal security analysis are conducted. The formal security analysis is conducted using the widely used random oracle model. The informal security analysis reveals that the devised protocol provides enhanced and efficient security features. Furthermore, we perform a comparative analysis with related protocols, focusing on critical performance metrics like communication cost, computation cost, and overall security features. The results of the comparative analysis are promising, indicating a substantial 30.92% reduction in computational cost and a 23.98% reduction in communication cost in comparison to related protocols, thus highlighting the protocol’s superior performance and resource efficiency.
Tayyaba Tariq, Wen-Chung Kuo, Khalid Mahmood 0002, Salman Shamshad, Ashok Kumar Das, Mohammed J. F. Alenazi
IEEE Internet Things J.5
2025 An authenticated key agreement method for secure big data analytics in next-generation wireless networks-enabled smart farming
Akshita Patwal, Mohammad Wazid, Devesh Pratap Singh, Ashok Kumar Das
J. Syst. Archit.5
2025 Secure and privacy-preserving quantum authentication scheme using blockchain identifiers in metaverse environment
Sunil Prajapat, Aryan Rana, Pankaj Kumar 0006, Ashok Kumar Das, Youngho Park 0005, Mohammed J. F. Alenazi
J. Syst. Archit.4
2025 Designing secure blockchain-based authentication and key management mechanism for Internet of Drones applications
Mohammad Wazid, Saksham Mittal, Ashok Kumar Das, SK Hafizul Islam, Mohammed J. F. Alenazi, Athanasios V. Vasilakos
J. Syst. Archit.3
2025 Blockchain-Enabled Secure Collaborative Model Learning Using Differential Privacy for IoT-Based Big Data Analytics
abstract
With the rise of Big data generated by Internet of Things (IoT) smart devices, there is an increasing need to leverage its potential while protecting privacy and maintaining confidentiality. Privacy and confidentiality in big data aims to enable data analysis and machine learning on large-scale datasets without compromising the dataset sensitive information. Usually current big data analytics models either efficiently achieves privacy or confidentiality. In this article, we aim to design a novel blockchain-enabled secured collaborative machine learning approach that provides privacy and confidentially on large scale datasets generated by IoT devices. Blockchain is used as secured platform to store and access data as well as to provide immutability and traceability. We also propose an efficient approach to obtain robust machine learning model through use of cryptographic techniques and differential privacy in which the data among involved parties is shared in a secured way while maintaining privacy and confidentiality of the data. The experimental evaluation along with security and performance analysis show that the proposed approach provides accuracy and scalability without compromising the privacy and security.
Prakash Tekchandani, Abhishek Bisht, Ashok Kumar Das, Neeraj Kumar 0001, Marimuthu Karuppiah, Pandi Vijayakumar, Youngho Park 0005
IEEE Trans. Big Data3
2025 An Efficient Handover Authentication Scheme for 6G-Enabled Space-Terrestrial Integrated Networks With Mobile Edge Computing
abstract
Sixth-generation (6G) services can offer unprecedented data speeds, ultra-low latency, and vast connectivity. Moreover, satellite communication has become crucial to achieving seamless global coverage for 6G networks. Space-terrestrial integrated networks (STIN) combine satellite and ground networks, ensuring continuous services via satellites even when outside terrestrial network coverage. However, existing STIN schemes rely on central ground server, which can potentially lead to bottlenecks and delays. Additionally, a lightweight handover is necessary to address frequent service changes due to the narrow communication ranges in 6G-based STIN environments. To address these challenges, we propose a novel authentication scheme to provide secure and high-speed handover process for STIN environments. The proposed scheme leverages mobile edge computing (MEC)-based low-Earth orbit (LEO) satellites to minimize communications with the central server. Moreover, a key feature of the proposed scheme is the structural separation of computational loads: we utilize elliptic curve cryptography (ECC) for robust initial authentication, and only hash functions and exclusive-OR (XOR) operators for high-speed handover process. To prove the security of our scheme,we perform informal analysis, “Burrows-Abadi-Needham (BAN) logic”, “Real-Or-Random (ROR) model“, “Automated Validation of Internet Security Protocols and Applications (AVISPA) simulation tool”, and “Scyther tool”. Furthermore, we conduct comparative study on security properties, computation, and communication costs of the proposed scheme and the existing related schemes. To verify the practical deployment of the proposed scheme, we perform a simulation study using “Network Simulator 3 (NS-3)”. Our results demonstrate that the proposed scheme can provide efficient and secure communications for MEC-based STIN environments.
Deok Kyu Kwon, Seunghwan Son, Kisung Park 0002, Ashok Kumar Das, Youngho Park 0005
IEEE Trans. Inf. Forensics Secur.4
2025 QPCASIN: A Quantum-Defended Privacy-Aware Preemptive Handover-Enabled Continuous Authentication in Space Information Networks
abstract
The Space Information Network (SIN) plays a crucial role in terrestrial communication, delivering time-bound services from ground stations to users. It relies on moving low-orbit earth (LEO) satellites for uninterrupted coverage. However, untrustworthy connectivity poses several security challenges during handover services for users maintained by the satellites. While traditional cryptographic techniques provide a degree of security, the advent of quantum computing exposes significant vulnerabilities. This work proposes a quantum-safe and continuous authentication mechanism with handover provision. The proposed authentication protocol uses post-quantum primitives of the Frodo key encapsulation mechanism, currently an approved mechanism under ISO/IEC 18033-2. It ensures privacy and ensures users’ anonymity. The security of the proposed protocol is analyzed using the quantum random oracle (QROM) model. Formal verification confirms its safety for practical adoption as a post-quantum candidate. Further, the performance evaluation shows an authentication delay and energy consumption of the proposed protocol within practical limits, making it a suitable candidate for privacy-preserved post-quantum adoption for SIN.
Basker Palaniswamy, Arijit Karati, Ting-Yu Chen 0001, Ashok Kumar Das, Bharat K. Bhargava
IEEE Trans. Inf. Forensics Secur.4
2025 A PUF-Based Lightweight Authentication Scheme for UAV-Assisted Internet of Vehicles
abstract
Unmanned Aerial Vehicles (UAVs)-assisted Internet of Vehicles (IoV) utilizes flexible mobility of UAVs to improve communication issues in traditional IoV model. In UAV-assisted IoV, UAVs expand the communication coverage of roadside units (RSUs) and support the tasks of RSUs. Therefore, UAV-assisted IoV can contribute to the development of Intelligent Transportation System (ITS). However, an adversary can still attempt various attacks because UAV-assisted IoV networks perform wireless communication over open channels. In 2024, Miao et al. proposed an elliptic curve cryptography (ECC)-based authentication scheme for UAV-assisted IoV. Unfortunately, we discover that their scheme cannot prevent man-in-the-middle (MITM) and ephemeral secret leakage (ESL) attacks. Furthermore, Miao et al.’s scheme incurs high computational costs using ECC which is unfavorable for UAVs considering their computational restrictions. In this article, we propose a secure and lightweight authentication scheme for UAV-assisted IoV, considering the computational limitations of UAVs. We apply physical unclonable function (PUF) and fuzzy extractor to mutual authentication, developing the security level. Moreover, the proposed scheme uses only one-way hash functions and exclusive-or (XOR) operations which are compatible with UAVs. To prove the robustness of the proposed scheme, we perform “Burrows-Abadi-Needham (BAN) logic”“, Real-or-Random (RoR) model”, and “Automated Verification of Internet Security Protocols and Applications (AVISPA)” based formal security analysis, and informal analysis. Furthermore, we estimate the performance of the proposed scheme and compare with other relevant works, including computational costs, communication costs, energy consumption, security properties, and storage costs. Consequently, we establish that the proposed scheme is appropriate and efficient for UAV-assisted IoV.
Jihye Choi, Deok Kyu Kwon, Seunghwan Son, YoHan Park 0001, Ashok Kumar Das, Youngho Park 0005
IEEE Trans. Intell. Transp. Syst.5
2025 DBKE: Design of Blockchain-Envisioned Vehicle-to-Vehicle Secure Key Management Protocol Using ECC
abstract
Vehicle-to-vehicle (V2V) authentication is essential in the Vehicular Ad-hoc Network (VANET). V2V communication improves the safety of drivers and assists them in making the appropriate decision according to road conditions. Since V2V communication happens in open public channels, an adversary takes advantage of it and tries to launch several potential threats. This article designs a blockchain-assisted V2V communication and authentication scheme using Elliptic Curve Cryptography (ECC) and a Physically Unclonable Function (PUF) called DBKE. In DBKE, vehicles perform their registration with their nearest Roadside Unit (RSU) without assisting the centralized cloud server. Then, one vehicle can communicate with another using the information stored in the blockchain. During the communication, both vehicles first perform the process of mutual authentication and then securely generate the session keys without sending the private parameters to the public channels. The formal analysis of DBKE is done with the Scyther and Real-or-Random (ROR) models, which confirm that the DBKE is robust and safe from attacks. Furthermore, the detailed comparative study of the security features reveals that the DBKE scheme provides superior security and low computation cost compared to the existing V2V authentication protocols.
Sanjeev Kumar Dwivedi, Ruhul Amin 0001, Muhammad Khurram Khan, Ashok Kumar Das, Adesh Pandey, Saifulla Md. Abdul
IEEE Trans. Intell. Transp. Syst.4
2025 Design of a Provable Secure ECC and HMAC-Based Robust and Efficient Authentication Scheme for Maritime Transportation System
abstract
With the rapid development of the Internet of Things (IoT), modern Maritime Transportation Systems (MTS) have played a crucial role in the transport industry. The various potential privacy and security concerns (such as vessels’ location tracking, message tampering, unauthorized access to data, etc.) have increased substantially in IoT-enabled MTS. Considering the above issues, we propose a secure, robust, and efficient authentication scheme for MTS based on Elliptic-Curve Cryptography (ECC) and Hash-based Message Authentication Code (HMAC) called PSAS-MTS. The proposed PSAS-MTS scheme not only monitors the vessel’s condition but also ensures protection against collisions in route management and provides safety to the vessel’s passengers. The scheme uses simple XOR, a cryptographic one-way hash, an ECC cryptosystem, and HMAC to achieve a high level of security in MTS. The formal security analysis is carried out using a well-known Real-Or-Random (ROR) model, which ensures the security harness features. A rigorous informal security analysis is also done, which ensures various privacy and security features such as mutual authentication, anonymity, forward and backward secrecy, etc. The proposed PSAS-MTS scheme resists various possible well-known active and passive security attacks. The performance analysis shows that the proposed PSAS-MTS scheme is more efficient in terms of computation and communication overheads when compared to other competitive schemes.
Sanjeev Kumar Dwivedi, Mohammad Abdussami, Mohd Shariq, Ruhul Amin 0001, Shehzad Ashraf Chaudhry, Ashok Kumar Das, Norziana Jamil
IEEE Trans. Intell. Transp. Syst.6
2025 BAPS-DITS: Blockchain-Enabled Accountable Privacy-Preserving Scheme for Decentralized Intelligent Transportation Systems
abstract
The integration of intelligent transportation systems (ITS) within the smart grid has significantly enhanced the reliability, efficiency, and security of vehicle-to-grid (V2G) services over the past decade, leading to increased research interest in this technology. Charging stations (CSs) utilize electric vehicles (EVs) to manage demand response and provide sustainable energy solutions. However, the transmission of information between EVs and CSs via public channels causes critical security vulnerabilities. Although much effort has been made to overcome the challenge of protecting security and privacy in V2G environments, these efforts have either been proposed based on a centralized architecture or do not ensure essential security requirements, such as self-sovereignty, reliable, and blockchain scalability. Furthermore, in decentralized network, it is difficult to provide reliable energy distribution because a malicious participant can easily try to inflate trading volumes and manipulate energy prices. In this paper, we propose a new blockchain-enabled, reliable, privacy-preserving scheme using decentralized identifiers (DIDs) for preventing energy wash trading in V2G networks called BAPS-DITS. BAPS-DITS guarantees to tackle the above challenges without a trusted third-party intervention. Additionally, we use informal and formal (mathematical) analysis to prove the security of BAPS-DITS and conduct a comparative analysis comparing the security properties, computational cost, and communication cost of BAPS-DITS to previous studies. Furthermore, we implement BAPS-DITS on a practical Ethereum network, demonstrating its efficiency and feasibility, showing that BAPS-DITS provides self-sovereignty, accountability, and blockchain scalability; thus, it is suitable for actual V2G environments.
Kisung Park 0002, Ashok Kumar Das, Youngho Park 0005
IEEE Trans. Intell. Transp. Syst.2
2025 A Lattice-Based Ring Signcryption Scheme for Secure Communication in 6G-Enabled Vehicular Ad Hoc Networks Using Blockchain
abstract
The emergence of 6G networks enhances the speed and compatibility of Internet-of-Things (IoT) devices in vehicular ad hoc networks (VANETs), leveraging underutilized bands to improve wireless communication and security, though its adaptability may introduce cyber vulnerabilities; to address this, we propose an energy-efficient consortium-based blockchain-enabled heterogeneous (EBH) 6G network for IoT devices, offering secure VANET control through a lattice-based ring signcryption scheme that ensures timely message relaying while preserving vehicle anonymity and cloud data confidentiality, with blockchain blocks formed via secure peer nodes and service provider data; our protocol’s security was rigorously validated through analysis and Python-based implementation, achieving 42.1 ms computational cost and 1026-bit communication overhead, and proving effectiveness across varying block and transaction loads, while guaranteeing key security properties-anonymity, linkable privacy, unforgeability, and confidentiality-even under quantum threats, using lattice-based cryptography, Zero-Knowledge Proofs (ZKP), and blockchain immutability.
Sunil Prajapat, Pankaj Kumar 0006, Ashok Kumar Das, M. Shamim Hossain
IEEE Trans. Intell. Transp. Syst.4
2025 Quantum Secure Energy-Efficient Authentication Protocol for Digital Twins-Enabled Transportation Cyber-Physical Systems
abstract
Digital twins-enabled transportation cyber-physical systems are employed in the transportation sector to enhance environmental quality, mobility, and safety. They are digital representations of transportation networks, enable the simulation of these networks’ behavior under various conditions. They can be employed in various transportation sectors, including forecasting traffic congestion, facilitate the optimization of flow and safety, enhance the efficiency of public transportation, improve the efficiency of freight transportation by offering support in this process, facilitates the consideration of future multimodal infrastructure development requirements, furnish drivers with up-to-date information about weather alerts, road closures, and traffic situations in real time, assess numerous aspects like, impacts of various mobility operators, transport users, and environmental conditions. However, the real-time data synchronization in digital twins-enabled transportation cyber-physical systems is accomplished using an open communication channel. Regrettably, the utilization of virtual-reality synthesizing security threats in the network necessitates the implementation of stringent privacy and security procedures, including authentication, encryption, and signature approaches. This study proposes a quantum-key-distribution (QKD)-based authentication protocol for secure communication of digital twins-enabled transportation cyber-physical systems. The integrated quantum in the system ensures the compactness and verifiability of data. The protocol’s security is examined using the Scyhter tool and is verified to be secure by informal security analysis. The proposed scheme achieves its efficiency over current solutions. Moreover, the latest technology and techniques are used to examine the operational capabilities and security features.
Sunil Prajapat, Pankaj Kumar 0006, Mohammad Wazid, Ashok Kumar Das, M. Shamim Hossain
IEEE Trans. Intell. Transp. Syst.5
2025 TGKAV: Tree-Based Group Key Agreement Scheme With Practical Antenna Implementation for Vehicle Platoon
abstract
Ensuring the safe transfer of information plays an important role in the development of Industry 4.0. Robust authentication and security frameworks are required to establish confidence among vehicles, provide reliable data flow, and improve the overall safety of vehicle platoons. This is crucial for preventing cyber-attacks that could cause accidents or disrupt the synchronized movement of vehicle platoons. Initially, in this study, a novel privacy-preserving mechanism based on an authentication code and cipher test is suggested. Second, an effective authentication system is proposed for vehicle platoons. Third, a novel tree-based group key-sharing mechanism for the exchange of information between vehicle users is proposed. The proposed scheme also supports the sharing of the same group key for entities in Industry 4.0. Finally, a planar array consisting of four elements was specifically built for use in vehicular ad hoc network (VANET) applications operating inside the Dedicated Short-range Communications (DSRC) (802.11p) band to prove the efficacy in terms of practical implementation. To assess the security level of the suggested authentication scheme, both formal and informal analyses were conducted. Finally, the performance of the suggested protocol is evaluated in terms of computational and communication overheads. Moreover, the designed antenna provides complete impedance bandwidth coverage, good gain, and minimal cross-polarization suppression at the optimum frequency of operation in the C band.
Arun Sekar Rajasekaran, Mohammad S. Obaidat, Maria Azees, Kalyan Sundar Kola, Ashok Kumar Das, Youngho Park 0005
IEEE Trans. Intell. Transp. Syst.5
2025 BTC2PA: A Blockchain-Assisted Trust Computation With Conditional Privacy- Preserving Authentication for Connected Vehicles
abstract
Intelligent Transportation Systems (ITS) dwell on Vehicular Ad-hoc NETworks (VANETs) for message dissemination to achieve the goal of traffic safety and efficiency. VANETs achieve communication among vehicles and roadside units via wireless communication. Hence, security and privacy are significant concerns to be addressed for an effective application of secure VANETs in any ITS. Researchers have addressed these issues with trust management-based schemes or cryptography-based schemes. While these schemes can secure VANETs, they have various limitations presenting hindrances in their deployment. In this context, we have proposed a Blockchain-assisted Trust Computation with a Conditional Privacy-preserving Authentication (BTC2PA) scheme for connected vehicles. The BTC2PA scheme uses a blockchain (Ethereum) assisted PKI infrastructure with digital signatures to achieve authentication for secure communication. Furthermore, it integrates a trust score computation scheme based on a reward and punishment mechanism to provide resistance against internal attacks. The feasibility and validity of the proposed BTC2PA scheme have been studied by implementation work in Rinkeby (Ethereum test network) and extensive simulations using NS-3. The results obtained show that the proposed BTC2PA scheme meets the security and privacy requirements while significantly improving the performance metrics such as communication, storage, computation cost, and end-to-end delay when compared to existing schemes.
Gopal Singh Rawat, Karan Singh 0002, Mohd Shariq, Ashok Kumar Das, Shehzad Ashraf Chaudhry, Pascal Lorenz
IEEE Trans. Intell. Transp. Syst.4
2025 Explainable Deep Learning-Enabled Malware Attack Detection for IoT-Enabled Intelligent Transportation Systems
abstract
The Internet of Things (IoT) has the potential to improve the complementary of communication, control, and information processing within the public transportation system. The IoT-enabled Intelligent Transportation System (ITS) ensures that automated transportation is networked and operated collaboratively. The IoT-enabled ITS has revolutionized the transportation industry by enabling the seamless integration of a wide range of devices and systems. It makes the strategic use of networked devices, sensors, and data analytics to improve transportation network efficiency, safety, and environmental friendliness. The usage of the IoT in the ITS has grown in popularity due to its capacity to improve traffic control, reduce congestion, facilitate live monitoring, and optimize transportation operations. The IoT-enabled ITS systems and devices must be protected from cyber-attacks for various reasons, including preserving sensitive data, guaranteeing privacy, preventing unauthorized access, and protecting against the risk of interruptions or manipulations. Malware attacks affect the working and performance of the deployed smart IoT devices. We propose a secure deep learning-enabled malware attack detection for IoT-enabled ITS (in short, SDLMA-IITS). The approach of explainable artificial intelligence (XAI) has been utilized for the effective detection of malware. A deep security analysis of the proposed SDLMA-IITS is presented to prove its security against various potential attacks. The comparative performance analysis of SDLMA-IITS is given with the other similar existing schemes. Finally, a practical implementation of SDLMA-IITS is provided to measure its impact on the security of the IoT-enabled ITS systems and devices.
Mohammad Wazid, Charvi Pandey, Robert Simon Sherratt, Ashok Kumar Das, Debasis Giri, Youngho Park 0005
IEEE Trans. Intell. Transp. Syst.5
2025 A Lightweight and Robust Access Control Protocol for IoT-Based e-Healthcare Network
abstract
Internet of Things (IoT) devices are crucial components in e-healthcare networks. It enables remote patient health monitoring and facilitates seamless communication among medical sensors, wearable devices, and healthcare providers through public communication channels. Despite these advantages, the use of public communication among medical sensors in e-healthcare networks introduces critical challenges, such as vulnerability to impersonation, physical capture, and ephemeral secret leakage, particularly in resource-constrained environments. In recent years, various access control protocols have been developed to mitigate these risks. However, these protocols often fail to ensure robust security while incurring significant communication and computation overhead. To overcome these limitations, we propose a lightweight and robust access control protocol for IoT-based e-healthcare networks using chaotic maps. We propose a novel protocol that integrates a PUF-based mechanism to mitigate the challenges of physical tampering and cloning attacks in e-healthcare networks. It leverages the inherent uniqueness of PUF and enhances security through the high-entropy properties of chaotic maps. We analyze the proposed protocol informally, which confirms that it significantly bolsters efficiency and security. We also validate the security using the Random or Real (RoR) model. Moreover, we verify the security of the proposed protocol using Scyther. These analyses highlight that the proposed protocol offers robust resistance to numerous attacks, such as impersonation, physical capture, and ephemeral secret leakage. Moreover, we also compare it with existing and relevant protocols. The comparative analysis showcases its superior performance. Notably, the proposed authentication protocol significantly reduces 46.84% computational overhead and decreases 31.30% communication overhead, underscoring its enhanced performance and resource efficiency.
Zahid Ghaffar, Wen-Chung Kuo, Khalid Mahmood 0002, Tayyaba Tariq, Salman Shamshad, Ashok Kumar Das, Mohammed J. F. Alenazi
IEEE Trans. Mob. Comput.6
2025 Quantum Safe Lattice-Based Single Round Online Collaborative Multi-Signature Scheme for Blockchain-Enabled IoT Applications
abstract
Multi-signature protocols allow a group of signers to collectively generate a single signature for a shared message. In the context of a decentralized blockchain, multi-signature schemes play a pivotal role in reducing the signature size. Recently, several multi-signature methods have emerged in the literature, some operating in discrete-log settings and others in lattice settings. However, many of the existing lattice-based multi-signature schemes incur high computation costs and online round complexity. Traditional public key-based multi-signature schemes are susceptible to quantum threats, and they are computationally intensive as well. A lattice-based multi-signature can provide robust security, which often falls short in terms of efficiency when it comes to round complexity. In this article, we aim to introduce a single-round lattice-based multi-signature scheme specifically designed for decentralized public blockchains. What sets the proposed scheme apart is its ability to function without the need for trapdoor commitments or sample pre-images, which are common features in existing lattice-based signature methods. Furthermore, we explore some potential applications in a generic Internet of Things (IoT) environment and their integration of the proposed scheme with the blockchain technology. The security of the proposed scheme is based on lattice-hard problems, like Ring-SIS (Shortest Integer Solution) and Ring-LWE (Learning with Errors).
Prithwi Bagchi, Basudeb Bera, Ashok Kumar Das, Biplab Sikdar 0001
ACM Trans. Sens. Networks3
2025 ESALP2: Efficient Signature Aggregation with Location Privacy Preservation in Wireless Body Area Networks
abstract
For Wireless Body Area Networks (WBANs), the security of sensitive data of patients is of the utmost importance, particularly in healthcare environments. This study presents a novel methodology for improving the efficacy of signature aggregation in a scenario involving doctors and patients while mitigating concerns about location privacy. Though there have been prior proposals for signature aggregation schemes, the proposed approach seeks to optimize the aggregation process within the considered scenario, thereby improving performance and reducing computational and communication burden. In addition, the proposed scheme integrates a resilient mechanism that safeguards the doctor’s location privacy by utilizing the Chinese Remainder Theorem (CRT). Advanced cryptographic algorithms and location-anonymization techniques are employed in the proposed method to safeguard the confidentiality of the doctors’ location. The security of the proposed scheme is formally analyzed using the Burrows-Abadi-Needham (BAN) logic and formally verified using the automated software validation tool, known as the Scyther tool, and an informal analysis of various security attributes confirms the security robustness of the proposed scheme. The efficacy is evaluated in comparison to analogous works utilizing the Cygwin software. The performance evaluation shows that the proposed scheme has lower communication costs as compared to existing competing schemes. Moreover, the serving ratio in the proposed scheme is high even if the number of patients is low for doctors.
Arun Sekar Rajasekaran, Maria Azees, Basker Palaniswamy, Ashok Kumar Das, Mohammed J. F. Alenazi
ACM Trans. Sens. Networks4
2024 Secure Location-based Authenticated Key Establishment Scheme for Maritime Communication
abstract
Maritime communication helps vessels and ports plan their movements, exchange environmental information, and communicate among themselves. The vessels' movement and changing location are critical to keep them secure from data interception and data tampering by unauthorized parties during transmission. To secure maritime communication, we propose a novel lightweight authentication scheme sensitive to the current ship location. We assess the effectiveness of the proposed protocol in defending against a range of security threats while keeping communication and computation costs low, and meeting the desired security and functional requirements of anonymity and untraceability. The detailed security analysis using the widely accepted Scyther tool demonstrates that location-based keys as proposed in our protocol are secure against location inference and spoofing attacks among others.
Anusha Vangala, Ashok Kumar Das, Neeraj Kumar 0001, Sachin Shetty, Sajal K. Das 0001
ICC3
2024 EM-PAD: An Effective Mechanism for Phishing Attack Detection
abstract
In the present era, the increasing number of network devices and ubiquitous computing leads to the flow of enormous amounts of data traffic, including sensitive and confidential information, on the internet and carrying out commercial and banking transactions online. This gives cybercriminals an opportunity to launch an attack like phishing to steal confidential information from the user and gain unauthorized access. This can be mitigated by the help of an intelligent machine learning-based phishing detection system, which can detect potential phishing attacks and take appropriate action. In this paper, we have addressed this major cyber issue and proposed a machine learning-based phishing detection scheme (in short, EM-PAD), which is trained on a benchmark dataset and evaluated on standard metrics: F1-score and Accuracy. The proposed model is compared with different existing schemes based on Accuracy, indicating that it has outperformed them with remarkable results.
Aakash, Saksham Mittal, Mohammad Wazid, Ashok Kumar Das, Sachin Shetty, Mohsen Guizani
IWCMC5
2024 AKM-FCCI: Secure Authentication and Key Management Mechanism for Fog Computing-Based IoT-Driven Critical Infrastructure
abstract
Critical infrastructure refers to the key systems, assets, and facilities, whether they are physical or virtual, that are necessary for the overall functioning of a country. As our reliance on technology and networked systems continues to expand, so does the significance of taking precautions to protect critical infrastructure from being compromised by cyberattacks. We need some security schemes to secure the communication happening in the critical infrastructure devices. Therefore, in this paper, we focus on the design of an authentication and key establishment scheme, which is used in the critical infrastructure to secure its data transmissions. A secure authentication and key management mechanism for fog computing-based IoT-driven critical infrastructures (in short, AKM-FCCI) is proposed in the paper. We then provide the network model and threat model of the proposed AKM-FCCI to explain its deployment and organization of devices and servers. The threat model further explains the various threats of this communication environment. In addition, the security analysis of AKM-FCCI is presented to demonstrate that it is secure against the many different kinds of attacks that could be launched against it. The comparisons demonstrate that the performance of AKM-FCCI is superior to that of the other currently used schemes. In addition to that, it offers a high level of security and utility. Therefore, the proposed AKM-FCCI is appropriate for use in protecting critical infrastructure equipment against a wide variety of threats.
Vijay Karnatak, Neha Tripathi, Mohammad Wazid, Ashok Kumar Das, Mohsen Guizani, Sachin Shetty
IWCMC5
2024 Efficient and secure signcryption-based data aggregation for Internet of Drone-based drone-to-ground station communication
Girraj Kumar Verma, Vinay Chamola, Neeraj Kumar 0001, Ashok Kumar Das, Dheerendra Mishra
Ad Hoc Networks4
2024 Provably secure fog-based authentication protocol for VANETs
Syed Muhammad Awais, Wu Yucheng, Khalid Mahmood 0002, Hafiz Muhammad Sanaullah Badar, Rupak Kharel, Ashok Kumar Das
Comput. Networks6
2024 Anonymous and reliable ultralightweight RFID-enabled authentication scheme for IoT systems in cloud computing
Mohd Shariq, Mauro Conti, Karan Singh 0002, Chhagan Lal, Ashok Kumar Das, Shehzad Ashraf Chaudhry, Mehedi Masud
Comput. Networks5
2024 A characterization of unit interval bigraphs of open and closed intervals
Ashok Kumar Das, Rajkamal Sahu
Discret. Appl. Math.1
2024 A Security-Enhanced and Ultralightweight Communication Protocol for Internet of Medical Things
abstract
With the emergence, development, and maturity of various Internet technologies, the healthcare industry is also trying to integrate with these technologies to provide more convenient healthcare services to patients by establishing telemedicine to develop and continuously improve the public healthcare system. Various protocols were proposed in the recent past to provide attack resistance in addition to computational efficiency; however, several such protocols were proved inefficient or prone to one or more attacks. Some of these protocols lack user anonymity and privacy. Keeping in consideration the flaws of existing protocols, in this article, we propose an efficient and secure protocol based on extremely lightweight symmetric key operations. In addition, we provide formal and informal analyses to demonstrate the protocol’s security. Moreover, to measure the efficiency of the proposed protocol, we conducted a real-time experiment, which confirms that the proposed protocol completes an authentication round in 117.1071 ms with an exchange of four messages and 2592 bits among the three participating entities. Finally, by comparing it with other protocols, we show that the proposed protocol has significant security advantages and performance benefits.
Chien-Ming Chen 0001, Zhaoting Chen, Ashok Kumar Das, Shehzad Ashraf Chaudhry
IEEE Internet Things J.3
2024 A Security Enhanced Chaotic-Map-Based Authentication Protocol for Internet of Drones
abstract
The Internet of Drones (IoD) extends the capabilities of unmanned aerial vehicles, enabling them to participate in a connected network. In IoD infrastructure, drones communicate not only among themselves but also with users and a control center. This interconnected communication framework holds promise for various applications, from collaborative decision-making to real-time data exchange. However, the expansion of communication in IoD also introduces new challenges, particularly in terms of security, privacy and authentication. Unfortunately, the current authentication protocols are inadequate in offering robust security features against various attacks in the IoD environment. To address these security issues and limitations, we proposed a secure protocol for the IoD environment using chaotic maps and hash functions. In addition, we also employed a physically unclonable function in the development of the proposed protocol. We assess the security of the protocol through both informal and formal security analysis. The formal security analysis is conducted through a widely used random or real (RoR) model. The informal analysis shows the rigorous security features against various attacks, such as masquerading, anonymity violation, and physical cloning attacks. Moreover, we compare the performance of the devised protocol with similar existing protocols across important performance parameters such as communication overhead, computation overhead, and security features. The devised protocol provides a 67.86% and 17.80% reduction in computation and communication overheads, respectively, as compared to related protocols. The analysis demonstrates the proposed protocol’s capacity to support secure communication in the IoD environment and satisfy desirable security attributes.
Khalid Mahmood 0002, Zahid Ghaffar, Muhammad Farooq 0004, Khalid Yahya, Ashok Kumar Das, Shehzad Ashraf Chaudhry
IEEE Internet Things J.5
2024 Quantum Secure Threshold Private Set Intersection Protocol for IoT-Enabled Privacy-Preserving Ride-Sharing Application
abstract
The Internet of Things (IoT)-enabled ride sharing is one of the most transforming and innovative technologies in the transportation industry. It has myriads of advantages, but with increasing demands there are security concerns as well. Traditionally, cryptographic methods are used to address the security and privacy concerns in a ride sharing system. Unfortunately, due to the emergence of quantum algorithms, these cryptographic protocols may not remain secure. Hence, there is a necessity for privacy-preserving ride sharing protocols which can resist various attacks against quantum computers. In the domain of privacy-preserving ride sharing, a threshold private set intersection (TPSI) can be adopted as a viable solution because it enables the users to determine the intersection of private data sets if the set intersection cardinality is greater than or equal to a threshold value. Although TPSI can help to alleviate privacy concerns, none of the existing TPSI is quantum secure. Furthermore, the existing TPSI faces the issue of long-term security. In contrast to classical and post quantum cryptography, quantum cryptography (QC) provides a more robust solution, where QC is based on the postulates of quantum physics (e.g., Heisenberg uncertainty principle, no cloning theorem, etc.) and it can handle the prevailing issues of quantum threat and long-term security. Herein, we propose the first QC-based TPSI protocol which has a direct application in privacy-preserving ride sharing. Due to the use of QC, our IoT-enabled ride sharing scheme remains quantum secure and achieves long-term security as well.
Tapaswini Mohanty, Sumit Kumar Debnath, Ashok Kumar Das, Biplab Sikdar 0001
IEEE Internet Things J.4
2024 Quantum Secure Authentication Scheme for Internet of Medical Things Using Blockchain
abstract
The Internet of Medical Things (IoMT) is a compelling networking paradigm integrating wireless communications sensors, connected devices, and embedded computing technologies. The IoMT involves the collection of real-time health data using sophisticated medical sensors. In recent years, the IoMT has become increasingly significant within the broader context of the Internet of Things (IoT). It provides accessibility for health monitoring and poses security obstacles to safeguarding the confidentiality and privacy of patient data. Therefore, this article presents a blockchain-integrated quantum authentication scheme in sensor-assisted IoMT networks. The proposed concept utilizes blockchain technology to achieve efficient patient authentication without the need for third-party entities. In addition, a secure quantum authentication scheme is designed not to require patients to authenticate themselves when communicating with multiple doctors simultaneously. This protocol explicitly addresses how clinicians can misuse their professional roles toward patients in IoMT networks. An evaluation analysis assesses the proposed technique’s efficacy compared to existing authentication schemes. The performance analyses demonstrate that the proposed protocol is resilient against various security attacks. Also, the practical usability of the quantum authentication scheme proved its importance as a significant improvement in communication security for IoMT networks.
Sunil Prajapat, Pankaj Kumar 0006, Ashok Kumar Das, M. Shamim Hossain, Joel J. P. C. Rodrigues
IEEE Internet Things J.4
2024 Privacy-Preserving Electronic Medical Record Sharing for IoT-Enabled Healthcare System Using Fully Homomorphic Encryption, IOTA, and Masked Authenticated Messaging
abstract
A significant evolution in healthcare recently uses technological advancements to perform different activities, such as patient electronic medical records (EMRs) data gathering, preserving, processing, diagnosis, and handling. The adaptation of the Internet of Things (IoT) and cloud has further facilitated the enhancement of related healthcare systems, which can considerably improve data connectivity, accessibility, and exchange, which leads to a significant improvement in the quality of services to patients. Furthermore, scientific computations over data in transmission can be exposed to adversaries and may reveal private data for financial benefit. This article uses the Cheon-Kim-Kim-Song fully homomorphic encryption scheme and IOTA Tangle using masked authenticated messaging (MAM) protocol to provide secure communication between patient and doctor. CKKS-FHE-based data encryption provides data privacy, and secured EMRs sharing through IOTA Tangle guarantees data confidentiality. The performance of this work is analyzed in terms of encryption and decryption time, and payload sharing using MAM and NON-MAM protocols results in evidence of the effectiveness of the approach and improves overall security. The proposed scheme performs better overall computation time and performance than other relevant schemes. Further, the security analysis shows that the proposed system is resilient to data immutability and integrity, forward secrecy, and passive and active attacks.
Sivaranjani Reddi, Patruni Muralidhara Rao, Saraswathi Pedada, Jangirala Srinivas, Ashok Kumar Das, Sajjad Shaukat Jamal, Youngho Park 0005
IEEE Trans. Ind. Informatics5
2024 Provably Secure and Lightweight Authentication and Key Agreement Protocol for Fog-Based Vehicular Ad-Hoc Networks
abstract
The increase in popularity of vehicles encourages the development of smart cities. With this advancement, vehicular ad-hoc networks, or VANETs, are now frequently utilized for inter-vehicular communication to gather data regarding traffic congestion, vehicle location, speed, and road conditions. Such a public network is open to various security risks. Overall, protecting personal information on VANET is a vital responsibility. The integration of fog computing and VANETs has gained significant importance in recent years, driven by advancements in cloud computing, Internet of Things (IoT) technologies, and intelligent transportation systems. However, ensuring secure communication in fog-based VANETs remains a major challenge. To overcome this challenge, we introduce a novel authenticated key agreement protocol that achieves mutual authentication, generates a secure session key for secret communication, and provides privacy protection without the use of bilinear pairing. We rigorously prove the security of our proposed protocol, which is designed specifically for fog-based VANETs, and has been shown to meet their stringent security requirements. Moreover, we performed formal and informal analysis that shows our proposed protocol is highly efficient,our protocol’s computational and communication overhead are lower than those of other relevant protocols by 45.570% and 29.432%, respectively. Finally we use NS-3 simulation to prove that our proposed algorithm is a practical and scalable solution for secure communication in fog-based VANETs.
Syed Muhammad Awais, Yucheng Wu 0001, Khalid Mahmood 0002, Mohammed J. F. Alenazi, Ali Kashif Bashir, Ashok Kumar Das, Pascal Lorenz
IEEE Trans. Intell. Transp. Syst.6
2024 Design of Blockchain and ECC-Based Robust and Efficient Batch Authentication Protocol for Vehicular Ad-Hoc Networks
abstract
The intelligent vehicles collect and distribute the data to other vehicles and Roadside Units (RSU), which ultimately strengthens the vehicular services in the Vehicular Ad-hoc Network (VANET). In order to protect against a variety of potential security threats, the VANET system needs a proper authentication mechanism, which requires more computational overheads and cannot perform better, when a cluster of vehicles sends the messages simultaneously. This paper aims to design a decentralized blockchain-based batch authentication protocol using Elliptic Curve Cryptography, where RSU authenticates the group of vehicles together. Moreover. our protocol also supports the verification of both individual messages (signature) generated by the vehicle and batch signature. We have used the Scyther security tool to verify our protocol and found that the protocol is safe and secure. A detailed comparative analysis reveals that the proposed scheme achieves more functionality and security compared to relevant schemes. The security analysis confirms that the proposed scheme is secure against all applicable attacks. Moreover, the ethereum platform simulates the proposed scheme, showing its effectiveness and confirming that it is feasible to deploy and execute transactions in real networks.
Sanjeev Kumar Dwivedi, Ruhul Amin 0001, Satyanarayana Vollala, Ashok Kumar Das
IEEE Trans. Intell. Transp. Syst.4
2024 Blockchain Assisted Intra-Twin and Inter-Twin Authentication Scheme for Vehicular Digital Twin System
abstract
The potency of digital twins to mitigate the shortcomings of traditional mobility systems, such as Vehicular Adhoc Network (VANET) can reconfigure it into an intelligent transportation domain with bolstered processing, storage capabilities and decision-making abilities. The vehicular digital network is emerging as the industrial revolution, where each real-mobile entity (i.e., vehicle) is connected in the virtual environment through their digital replica, known as a digital twin. The real-time data synchronization in the digital twin-centric approach is achieved via an open communication channel. Unfortunately, leveraging the virtual-reality synthesized security perils in the network which consequently obligates rigorous privacy and security countermeasures such as authentication, encryption and signature techniques. In this paper, we have suggested a blockchain-based authentication framework for intra-twin and inter-twin communication in vehicular digital twin networks, and the integrated blockchain in the system assures data compactness and verifiability. The security of the protocol is investigated under the real or random oracle model (ROR) and is confirmed secure with non-mathematical security analysis. Eventually, the operational competences and functionality features are inspected with relevant state-of-the-arts. The findings of study states excel computation and communication overhead of suggested system than others and is seemly for vehicular digital twin network.
Deepika Gautam, Pankaj Kumar 0006, Ashok Kumar Das, Youngho Park 0005
IEEE Trans. Intell. Transp. Syst.4
2024 A Secure Self-Certified Broadcast Authentication Protocol for Intelligent Transportation Systems in UAV-Assisted Mobile Edge Computing Environments
abstract
Unmanned Aerial Vehicle(UAV)-assisted mobile edge computing(MEC) ensures continuous MEC services by promptly restoring overloaded or disabled MEC infrastructure. Equipped with sufficient computing resources, UAVs deploy to areas needing MEC, such as task offloading and entertainment services. However, in areas with paralyzed edge nodes, vehicle users are unable to verify the legitimacy of UAVs as they cannot access to the trusted authority(TA). Furthermore, the integrity of UAV-assisted MEC environments can be compromised by malicious attackers, as all network participants rely on wireless communication for their interactions. Many authentication schemes have been proposed for UAV environments. However, these schemes encounter a problem of having to communicate through TA for authentication with vehicle users, which makes them difficult to apply to UAV-assisted MEC environments. Therefore, we propose a new broadcast authentication protocol, which can recover MEC services using MEC-equipped UAVs. The proposed protocol can provide UAVs and vehicle users with high reliability via a self-certified public-key cryptosystem, which can verify the legitimacy of the communication partner without the TA. Moreover, we guarantee the user privacy and preserve sensitive information using biohash technology. We verify the security robustness of the proposed protocol using various simulation tool, informal, and formal analyses. We also estimate the practical deployment of the proposed protocol using “Network Simulator-3”. Moreover, we estimate the computation and communication overheads and compare with other existing protocols. The results show that the proposed protocol is feasible and provides users with convenient and seamless intelligent transportation services in UAV-assisted MEC environments.
Deok Kyu Kwon, Seunghwan Son, MyeongHyun Kim, JoonYoung Lee, Ashok Kumar Das, Youngho Park 0005
IEEE Trans. Intell. Transp. Syst.5
2024 Design of Blockchain-Based Multi-Domain Authentication Protocol for Secure EV Charging Services in V2G Environments
abstract
Multi-domain vehicle to grid (V2G) is a network environment in which numerous service providers offer charging and discharging services to EV users. This can enhance energy management and traffic flow for efficient intelligent transportation systems (ITS). However, the combination of multiple domains can suffer from various security vulnerabilities, highlighting the need for robust countermeasures. Moreover, existing multi-domain V2G protocols utilized a central trusted authority (TA) which can create a single point of failure (SPOF), or required high computational resources. In this paper, we propose a multi-domain authentication protocol for secure and efficient V2G services using consortium blockchain. The proposed protocol provides lightweight intra-domain authentication using hash functions and XOR operators. Furthermore, the proposed protocol ensures secure cross-domain authentication by integrating elliptic curve cryptography (ECC) and physical unclonable function (PUF). Therefore, the proposed protocol can establish trust, enable efficient communications, and prevent congestion at charging stations. To validate security robustness, comprehensive evaluations are conducted using “Real-Or-Random (ROR) model”, “Scyther tool”, and informal analyses. Comparative computational overheads of the proposed and related protocols are measured using “Multiprecision Integer and Rational Arithmetic Cryptographic Library (MIRACL)” testbed experiments. Additionally, a simulation of the practical deployment is conducted using “Network Simulator-3 (NS-3)”. Results indicate that the proposed protocol can improve ITS by providing secure and efficient services for multi-domain V2G environments.
Deok Kyu Kwon, Seunghwan Son, Kisung Park 0002, Ashok Kumar Das, Youngho Park 0005
IEEE Trans. Intell. Transp. Syst.4
2024 A Cost-Efficient Anonymous Authenticated and Key Agreement Scheme for V2I-Based Vehicular Ad-Hoc Networks
abstract
The rise of smart cities is directly connected to the increasing use of vehicles. The growing vehicle utilization has driven the emergence of Vehicular Ad-hoc Networks (VANETs), facilitating instant information exchange among vehicles. The system provides essential information regarding road conditions, traffic patterns, and more relevant data. VANETs encompass two fundamental categories of communication exchanges, namely Vehicle-to-Vehicle (V2V) and Vehicle-to-Infrastructure (V2I). V2I technology facilitates the integration of cars and transportation infrastructure, enabling effective communication between vehicles and infrastructure. Nevertheless, the potential of V2I communication has various security concerns arising from prevalent security threats. Current authentication techniques encounter challenges regarding complexity, security, and privacy considerations. We designed a hash-based lightweight and anonymous authentication scheme to address the aforementioned restrictions and enhance the effectiveness of authentication in V2I architecture. This scheme effectively combines identity, password, and bio-metric to enhance resistance against impersonation, denial of service, and privileged insider attacks. The devised scheme distinguishes itself by a comparative analysis and security proofs, highlighting its superior capability in guaranteeing secure authentication in V2I communication. The comprehensive security analysis conducted formally and informally showcases the robustness of the proposed solution against several threats. The performance evaluation results show that our scheme demonstrates a decrease in the computational cost of 51.40% approximately and a reduction in communication overhead of around 22.57%. These results establish the efficiency and scalability of the proposed scheme as a viable solution for V2I architecture.
Muhammad Asad Saleem, Xiong Li 0002, Khalid Mahmood 0002, Salman Shamshad, Mohammed J. F. Alenazi, Ashok Kumar Das
IEEE Trans. Intell. Transp. Syst.6
2024 Secure RFID-Assisted Authentication Protocol for Vehicular Cloud Computing Environment
abstract
Vehicular network technology has made substantial advancements in recent years in the field of Intelligent Transportation Systems. Vehicular Cloud Computing (VCC) has emerged as a novel paradigm with a substantial increase in data exchange within Vehicular ad-hoc networks (VANETs). VCC integrates cloud computing, vehicular networking, and Internet of Things (IoT) technologies. It enables Infrastructure-to-Vehicle (I2V), Vehicle-to-Vehicle (V2V), and Vehicle-to-Device (V2D) communication. VCC optimizes vehicle, cloud infrastructure, and IoT resources while addressing significant communication security and vehicle-user privacy challenges. To address these issues, we developed an RFID-based authentication protocol for VCC based on a Henon map using a hash function. In addition, we also incorporated a Physical Unclonable Function (PUF) to resist physical tampering attacks. We validate the protocol’s security formally and informally. The formal security analysis is conducted through a widely used RoR model. We use the Scyther simulation tool to verify the proposed protocol’s security against various attacks. Moreover, we compare the performance of our protocol with similar existing protocols across important performance parameters such as communication and computation overheads and security attributes. The proposed protocol yields substantial improvements, demonstrating a 40.74% reduction in computation overhead and a 13.03% decrease in communication overhead as compared to related protocols, delivering both enhanced performance and resource efficiency. The analysis demonstrates its capacity to support secure communication in the VCC environment and satisfy desirable security attributes.
Muhammad Asad Saleem, Xiong Li 0002, Khalid Mahmood 0002, Tayyaba Tariq, Mohammed J. F. Alenazi, Ashok Kumar Das
IEEE Trans. Intell. Transp. Syst.6
2024 An Authentication and Key Management Framework for Secure and Intelligent Transportation of Internet of Space Things
abstract
Internet of Space Things (IoST), also known as CubeSats, elaborates the uses and functionalities of traditional Internet of Things (IoT) by not only providing a constantly available satellite back-haul network, but also by providing real-time satellite-captured data. IoST can be applied for various applications, like weather forecasting, navigation, satellite phone, satellite TV, satellite Internet, radio, military, and many more. It requires support of mechanisms of Intelligent Transportation System (ITS). In an IoST communication environment, the communication among various users, satellite access points, ground stations, and smart IoT devices occur through insecure channels, i.e., Internet. Due the transmission of data over an insecure channel, various potential attacks are possible. Due to the existence of various attacks, the important data of IoST may be altered or revealed. To mitigate these issues, an authentication and key management framework for secure and intelligent transportation of IoST has been proposed (in short, SAKM-IoST). Through the proposed SAKM-IoST, a legitimate user can access the data of ground station in a secure way. The security analysis reveals that SAKM-IoST is resilient against a variety of potential threats and attacks. Additionally, SAKM-IoST’s performance is compared with other approaches that are similar in nature. It has been noted that SAKM-IoST offers robust security, in addition to extra functional characteristics. Therefore, SAKM-IoST seems to be more suitable for its deployment in the critical applications of the IoST as compared to other competing approaches.
Mohammad Wazid, Ashok Kumar Das, Sachin Shetty
IEEE Trans. Intell. Transp. Syst.2
2024 RLBA-UAV: A Robust and Lightweight Blockchain-Based Authentication and Key Agreement Scheme for PUF-Enabled UAVs
abstract
Unmanned aerial vehicles (UAVs) integrated with the internet of things (IoT) guarantee useful advantages such as facilitating ground communications in regions where the availability of connectivity is restricted owing to physical obstacles. However, the data transmitted by sensors and IoT embedded in UAVs are facing new security issues and privacy challenges with the known security attacks over time. To address these security attacks and threats and meet lightweight UAV communication requirements, a secure and lightweight authentication and key agreement (AKA) scheme is essential. Recently, researchers have designed a lightweight blockchain-enabled AKA scheme with privacy-preserving for UAVs to provide useful and reliable services. However, we prove that the existing scheme is fragile to various security attacks and does not ensure mutual authentication. Thus, we propose a robust and lightweight blockchain-based AKA scheme for PUF-enabled UAVs, called RLBA-UAV to enhance the security problems of the existing scheme. We demonstrate the security of RLBA-UAV by using informal/formal security analyses such as the ROR oracle model and AVISPA simulation. Moreover, we demonstrate the performance comparison analysis between RLBA-UAV and related schemes for UAVs. We demonstrate an implementation of a network simulator (NS) 3 compliant with IEEE 802.11p standards to show its validation and feasibility that RLBA-UAV is appropriate for practical UAVs. Thus, RLBA-UAV offers enhanced security and operational efficiency compared to related schemes and can be applied to practical blockchain-based AKA systems for UAVs.
SungJin Yu, Ashok Kumar Das, Youngho Park 0005
IEEE Trans. Intell. Transp. Syst.2
2024 Digital Twins-Empowered Secure Network Slice Access and Isolation for Consumer Healthcare Applications
abstract
Existing wireless infrastructure and networks are unable to meet the diverse Quality of Service (QoS) demands inherent in a wide range of consumer healthcare applications (CHAs). In this context, the adoption of fifth generation of wireless cellular technology (5G)/Beyond fifth-generation (B5G)-based network slicing technology has become pivotal for CHAs. It facilitates the creation of multiple virtual networks on a shared physical infrastructure by catering to distinct QoS requirements, where digital twins (DTs) are providing a virtual representation and management framework for healthcare smart devices, services, and applications within network slices. This allows different services and applications to coexist. However, network slicing has to address various security concerns, including securing slice access, enabling secure inter-slice communication, ensuring slice isolation within the shared physical network with DTs, and authenticating end users. To address these challenges, we propose a security mechanism that is specifically designed to safeguard network slice access and isolation in CHAs empowered by DTs, where only legitimate devices with corresponding digital twins and matching attributes are granted access. The proposed model incorporates the use of digital certificates for authenticating both slice access and devices by providing enhanced slice isolation to mitigate unauthorized access. Through a detailed comparative assessment, we demonstrate that the proposed scheme offers superior security and improved functionality attributes, while maintaining low communication costs as compared to those for other similar existing schemes. Furthermore, we validate the feasibility of our scheme through testbed simulations.
Basudeb Bera, Ashok Kumar Das, Biplab Sikdar 0001
IEEE Trans. Serv. Comput.2
2024 Boolean Searchable Attribute-Based Signcryption With Search Results Self-Verifiability Mechanism for Data Storage and Retrieval in Clouds
abstract
Storing and sharing confidential data in a public cloud storage system always raises privacy and security issues. When data is outsourced to a cloud server, the basic demands are secure and authenticated data storage, fine-grained data access control, secure search for the outsourced data, and search results verification. Attribute-Based Signcryption (ABSC) is a promising public-key cryptosystem for accomplishing data confidentiality and authenticity together. However, incorporating verifiable Boolean formula based keyword search and verifiable outsourced unsigncryption mechanisms into an ABSC is quite challenging. This is because the data user should be able to check whether the search result, returned by the untrusted cloud, has been correctly created. Precisely, the data user should be able to verify the correctness of the search, transform and signature verification operations involved in generating the search result. In this paper, for the first time, we propose a secure Searchable Attribute-Based Signcryption (sABSC) scheme that simultaneously supports (i) Boolean formula search over signcrypted data, (ii) keyword privacy, (iii) verifiable outsourced unsigncryption, and (iv) search results self-verifiability. In sABSC, each data user can efficiently verify the correctness of the search results returned by the cloud without interacting with any authority. We define more general security definitions of sABSC and provide rigorous security analysis. Performance evaluation exhibits that the proposed sABSC is practical.
Y. Sreenivasa Rao, Suryakant Prasad, Sourav Bera, Ashok Kumar Das, Willy Susilo
IEEE Trans. Serv. Comput.4
2023 Multiclass Classification Approaches for Intrusion Detection in IoT-Driven Aerial Computing Environment
abstract
Aerial Computing is one of the applications of Internet of Things (IoT) which makes use of autonomous aerial devices, such as drones and unmanned aerial vehicles (UAVs). The ubiquitous nature of IoT and aerial computing is poised to revolutionize our daily lives by enabling seamless real-time information sharing among interconnected objects. However, ensuring the safety and security of such network is crucial in preventing potential threats and attacks. The purpose of this study is to develop a sophisticated intrusion detection system that is effective, efficient, and intelligent using complex machine learning models trained on relevant intrusion detection datasets. In this article, the multiclass classification approaches for intrusion detection in IoT-driven aerial computing environment are presented (in short, MCA-IDAC). In the comparative study, it has been observed that proposed MCA-IDAC performs significantly better than the other existing competing schemes, in terms of important performance parameters.
Saksham Mittal, Mohammad Wazid, Devesh Pratap Singh, Ashok Kumar Das, Sachin Shetty
GLOBECOM5
2023 Securing Fog Computing-based Industry 4.0 Communication Using Authenticated Key Agreement Scheme
abstract
Internet of Things (IoT)-based smart factories offer the manufacturing sectors a great opportunity to embrace the fourth industrial revolution (Industry 4.0). The real-time monitoring of manufacturing operations in an Industry 4.0 needs to be ensured by the deployed technologies, like Artificial Intelligence (AI) and Big Data analytics. The overall purpose is to improve the outcomes of the production process. However, Industry 4.0 becomes vulnerable to different potential attacks as the communication takes place via public environments. In this article, an authentication and key agreement method has been suggested to secure the communication that can occur in a Fog-based Industry 4.0 environment. The security proposal provides secure mutual authentication along with key establishment between various smart industrial devices and fog servers, as well as between fog servers and cloud servers. The security analysis and comparative study reveal that the proposed method can mitigate various potential attacks, and it also offers important security and functionality attributes as compared to those for other competing schemes.
Mohammad Wazid, Devesh Pratap Singh, Ashok Kumar Das, Mohsen Guizani
IWCMC4
2023 Embattle The Security of E-Health System Through A Secure Authentication and Key Agreement Protocol
abstract
There has been exponential growth in the field of Internet of Things (IoT)-enabled e-health domain, where several technologies are interconnected with each in order to provide low-cost and efficient services to users. The smart healthcare devices monitor the physiological conditions of a patient and then send data to connected servers (i.e., health server). The smart healthcare devices, servers and associated software applications come under one umbrella to provide live tracking, monitoring and analysis of the the healthcare data to the concerned users. It is also considered as Internet of Medical Things (IoMT) communication environment. All medical records are considered critical and sensitive in nature and therefore any leakage of medical data could potentially turn out to be a the lethal to patients. With the innovation in technology, there is a constant security threat to all smart healthcare devices, which is a main issue in e-health system. Cyber threat actors are actively trying to break into the system or network to gain unauthorized access and privileges to manipulate the data. Therefore, there is a strong urge for cyber security in this domain to secure all computing devices from any computer attack. Proper authentication, authorization, a secure session key exchanges, etc., are required to create a secure channel among the communicating devices. In this paper, an authentication and key agreement scheme to secure the communication of e-health system (named as ASKA-EH, in short) is proposed. The provided security analysis of ASKA-EH proves its security against various attacks. The comparative performance analysis of proposed ASKA-EH and other existing schemes of ehealth system reveals that ASKA-EH is superior than the existing schemes.
Darshan Singh, Mohammad Wazid, Devesh Pratap Singh, Ashok Kumar Das, Joel J. P. C. Rodrigues
IWCMC4
2023 LAKA-UAV: Lightweight authentication and key agreement scheme for cloud-assisted Unmanned Aerial Vehicle using blockchain in flying ad-hoc networks
SungJin Yu, JoonYoung Lee, Anil Kumar Sutrala, Ashok Kumar Das, Youngho Park 0005
Comput. Networks4
2023 Mobile-Chain: Secure blockchain based decentralized authentication system for global roaming in mobility networks
Indushree M, Manish Raj, Vipul Kumar Mishra, Shashidhara, Ashok Kumar Das, Vivekananda Bhat K.
Comput. Commun.5
2023 Impact on blockchain-based AI/ML-enabled big data analytics for Cognitive Internet of Things environment
Ankush Mitra, Basudeb Bera, Ashok Kumar Das, Sajjad Shaukat Jamal, Ilsun You
Comput. Commun.3
2023 A hybrid ensemble machine learning model for detecting APT attacks based on network behavior anomaly detection
abstract
Summary A persistent, targeted cyber attack is called an advanced persistent threat (APT) attack. The attack is mainly launched to gain sensitive information, take over the system, and for financial gain, which creates nowadays more hurdles and challenges for the organization in preventing, detecting, and recovering from such attacks. Due to the nature of APT attacks, it is difficult to detect them quickly. Therefore machine learning techniques come into these research areas. This study uses deep and machine learning models such as random forest, decision tree, convolutional neural network, multilayer perceptron and so forth to categorize and effectively detect APT attacks by utilizing publicly accessible datasets. The datasets used in this study are CSE‐CIC‐IDS2018, CIC‐IDS2017, NSL‐KDD, and UNSW‐NB15. This study proposes the hybrid ensemble machine learning model, a mixed approach of random forest and XGBoost classifiers. It has obtained the maximum prediction accuracy of 98.92%, 99.91%, 99.24%, and 97.11% for datasets CSE‐CIC‐IDS2018, CIC‐IDS2017, NSL‐KDD, and UNSW‐NB15, with a false positive rate of 0.52%, 0.12%, 0.62%, and 5.29% respectively. These results are compared to other closely related recent studies in the literature. Our experiment's findings show that our model has performed significantly better for all datasets.
Neeraj Saini, Vivekananda Bhat Kasaragod, Krishna Prakasha, Ashok Kumar Das
Concurr. Comput. Pract. Exp.4
2023 Provably secure signature-based anonymous user authentication protocol in an Internet of Things-enabled intelligent precision agricultural environment
abstract
Abstract User authentication is a promising security solution in which an external user having his/her mobile device can securely access the real‐time information directly from the deployed smart devices in an Internet of Things‐enabled intelligent precision agricultural environment. To achieve this goal, we present a new signature‐based three factor user authentication scheme. The established session key between a user and the accessed smart device is then used to make secure communication among them to fetch the real‐time data of the device. A detailed security analysis including the random‐oracle based formal security, formal security verification using the broadly recognized automated validation of internet security protocols and applications tool and nonmathematical informal security analysis show the robustness of the proposed scheme against a number of potential attacks. In addition, testbed experiments are performed for measuring computational time of various cryptographic primitives that are used for comparative study among the proposed scheme and other related existing competing schemes. The detailed comparative analysis shows that the proposed scheme has a better trade‐off among its offered security and functionality features, and communication and computational overheads as compared with those for other competing schemes.
Anusha Vangala, Ashok Kumar Das, Jong-Hyouk Lee
Concurr. Comput. Pract. Exp.2
2023 Securing Age-of-Information (AoI)-Enabled 5G Smart Warehouse Using Access Control Scheme
abstract
Low-power wireless sensor networks (WSNs) and Internet of Things (IoT) have great impact for the real-time applications in future 5th generation (5G) mobile networks due to the wireless-powered communication technologies. The Age of Information (AoI) plays a crucial performance metric in an IoT-enabled real-time smart warehouse application, where the freshness of the aggregated data is very important. However, wireless medium communication among the beacon nodes and the user equipments (tracking nodes) gives an opportunity to an adversary not only to eavesdrop the data but also to corrupt the data by means of deleting, modifying or inserting malicious information during communication among the entities involved in the smart warehouse environment. To mitigate these issues, we design a security scheme for AoI-enabled 5G smart warehouse through an access control mechanism, where the secure communication among the beacon nodes and the tracking nodes will take place by mutual device authentication and key agreement process. The fresh data collected at the enterprise cloud is then used for big data analytics for better predictions and analysis, such as optimal device scheduling so that the data becomes very fresh. The rigorous security analysis and comparative study show that the proposed mechanism has significantly better security and comparable communication and computational costs as compared to the relevant schemes. In addition, through the real-time testbed experiments, we show that the proposed scheme is practical in 5G smart warehouse context.
Ashok Kumar Das, Sandip Roy 0001, Eranga Bandara, Sachin Shetty
IEEE Internet Things J.1
2023 Post-Quantum Lattice-Based Secure Reconciliation Enabled Key Agreement Protocol for IoT
abstract
The authenticated key agreement is one of the major security services that can be used to secure an Internet of Things (IoT) environment, where the devices collect the data and the data is then aggregated at the cloud server, and then a user needs to access the data stored at the server(s) securely. For this purpose, after a mutual authentication performed between a user and the accessed server, a session key needs to be established among them for secure communication. In this article, we design an efficient lattice-based authenticated key exchange protocol using ring-based version of learning with errors assumption for the IoT-enabled smart devices. The proposed protocol is basically a key exchange that uses the reconciliation mechanism. The detailed security analysis under the standard model has been performed along with the informal security analysis to show that the proposed protocol is robust against different attacks. We then simulate the proposed protocol under the NS-3 simulator to measure the network performance parameters like network throughput and latency. A comparative analysis shows that the proposed protocol has superior security, less computational cost, and comparable communication cost when compered these parameters with the other competing schemes.
Dharminder Chaudhary, Challa Bhageeratha Reddy, Ashok Kumar Das, Youngho Park 0005, Sajjad Shaukat Jamal
IEEE Internet Things J.3
2023 Fog-Based Single Sign-On Authentication Protocol for Electronic Healthcare Applications
abstract
Increasing use of electronic healthcare (eHealth) services demands efficient and secure solutions. Such solutions need to ensure the prevention of unauthorized access to the patient data and provide faster response. Fog computing is a viable solution to provide faster responses in eHealth systems. Key distribution and authentication play a major role in providing security to patient data. Existing centralized architectures are susceptible to single-point-of-compromise, that is, the entire system is vulnerable when the centralized authority keys are unexpectedly revealed to an adversary. In this article, we present a fog-based semi-centralized architecture for key distribution and authentication, in which the key distribution service is delegated to individual fog servers. Thus, the fog servers become responsible for key distribution to the users without the involvement of the centralized authority, which forms a paradigm of multiple client–server architecture. Thus, achieving centralized trust by designing a single sign-on authentication in such environments is a challenging problem. We design a single sign-on authentication protocol for semi-centralized architectures to achieve centralized trust by ensuring that the user keys are independent of the centralized authority’s keys. A rigorous security analysis under the random oracle model is performed to prove that the proposed protocol is secure against single-point-of-compromise. We also conduct extensive experiments to show the practical perspectives of the proposed scheme. The results show that the protocol is suitable for eHealth applications, including emergency services.
Srijanee Mookherji, Vanga Odelu, Rajendra Prasath, Ashok Kumar Das, Youngho Park 0005
IEEE Internet Things J.4
2023 A Provably Secure and Lightweight Access Control Protocol for EI-Based Vehicle to Grid Environment
abstract
The energy Internet (EI) presents a novel paradigm for renewable energy distribution that utilizes communication and computing technologies to revolutionize the conventional intelligent transportation systems (ITSs) and power grid into a structure that provides assistance to open innovation. The EI offers sustainable and bidirectional transmission for the improvement and analysis of energy convention among electric vehicles (EVs) and service providers. To ensure efficient, reliable, and secure operation, EI must be safe from security attacks. Therefore, efficient and secure key negotiation is a significant issue for the EI-based Vehicle-to-Grid (V2G) architecture. Thus, to ensure the system’s security, we have devised a robust scheme to facilitate a secure key agreement between the entities involved for the secure and efficient renewable energy distribution for the EI-based energy vehicles in V2G. The devised scheme’s robustness is solicited through the widely accepted formal random or real (RoR) model. In addition, the informal security analysis is conducted on the devised scheme, which is evident that the designed scheme achieves all the required security features of EI-based ITS. Moreover, the performance evaluation results endorse that the designed scheme achieves the desired security and minimizes the communication, computation, and energy overhead by 29.33%, 27.94%, and 28.08% in comparison to the existing competitive schemes.
Salman Shamshad, Khalid Mahmood 0002, Usman Shamshad, Ibrar Hussain 0001, Shafiq Hussain, Ashok Kumar Das
IEEE Internet Things J.6
2023 Blockchain-Enabled Secure Big Data Analytics for Internet of Things Smart Applications
abstract
Smart devices in an Internet of Things (IoT) generate a massive amount of big data through sensors. The data is used to build intelligent applications through machine learning (ML). To build these applications, the data is collected from devices into data centers for training ML models. Usually, the training of models is performed on central server, but this approach requires the transfer of data from devices to central server. This centralized training approach is not efficient because the users are much less likely to share data to the centralized data centers due to privacy issues and bandwidth limitations. To mitigate these issues, we propose an efficient hybrid secure federated learning approach with the blockchain to securely train the model locally on devices and then to store the model and its parameters into the blockchain for traceability and immutability. A detailed security and performance analysis is presented to show the efficacy of the proposed approach in terms of security, resilience against many security attacks, and cost effectiveness in computation and communication as compared to other existing competing schemes.
Prakash Tekchandani, Indranil Pradhan, Ashok Kumar Das, Neeraj Kumar 0001, Youngho Park 0005
IEEE Internet Things J.3
2023 Designing attribute-based verifiable data storage and retrieval scheme in cloud computing environment
Sourav Bera, Suryakant Prasad, Y. Sreenivasa Rao, Ashok Kumar Das, Youngho Park 0005
J. Inf. Secur. Appl.4
2023 A provably-secure authenticated key agreement protocol for remote patient monitoring IoMT
Chien-Ming Chen 0001, Shuangshuang Liu, Xuanang Li, SK Hafizul Islam, Ashok Kumar Das
J. Syst. Archit.5
2023 Provably secure public key encryption with keyword search for data outsourcing in cloud environments
Sudeep Ghosh, SK Hafizul Islam, Abhishek Bisht, Ashok Kumar Das
J. Syst. Archit.4
2023 Robust authenticated key agreement protocol for internet of vehicles-envisioned intelligent transportation system
Siddhant Thapliyal, Mohammad Wazid, Devesh Pratap Singh, Ashok Kumar Das, SK Hafizul Islam
J. Syst. Archit.4
2023 MADP-IIME: malware attack detection protocol in IoT-enabled industrial multimedia environment using machine learning approach
Sumit Pundir, Mohammad S. Obaidat, Mohammad Wazid, Ashok Kumar Das, Devesh Pratap Singh, Joel J. P. C. Rodrigues
Multim. Syst.4
2023 A new robust and fragile scheme based on chaotic maps and dwt for medical image security
Supriyo De, Jaydeb Bhaumik, Debasis Giri, Ashok Kumar Das
Multim. Tools Appl.4
2023 BPPS:Blockchain-Enabled Privacy-Preserving Scheme for Demand-Response Management in Smart Grid Environments
abstract
With the ongoing revolutionary growth of the industrial Internet of Things and smart grid networks, smart grid (SG) communication has been acknowledged as a next-generation network for intelligent and efficient electric power transmission. In SG networks, smart meters (SMs) generally send requests for electricity demand to service providers (SPs), which deal with the requests for efficient energy distribution. However, SGs experience many security issues with the deployed SMs and untrusted wireless communication. To tackle these security issues, we propose a privacy-preserving authentication scheme for demand response management in SGs, called BPPS. It can resist various attacks and achieve secure mutual authentication with key agreement; moreover, it provides integrity of demand-response data using blockchain. Moreover, we perform the informal and formal (mathematical) security analysis to confirm that BPPS is secure against various attacks and achieves session key security, respectively. Furthermore, we conduct the performance and simulation analysis for SGs using NS3 and Ethereum testnet. Consequently, BPPS provides high-level security and can be applied to actual SG networks.
Kisung Park 0002, JoonYoung Lee, Ashok Kumar Das, Youngho Park 0005
IEEE Trans. Dependable Secur. Comput.3
2023 Blockchain-Enabled Authenticated Key Agreement Scheme for Mobile Vehicles-Assisted Precision Agricultural IoT Networks
abstract
Precision farming has a positive potential in the agricultural industry regarding water conservation, increased productivity, better development of rural areas, and increased income. Blockchain technology is a better alternative for storing and sharing farm data as it is reliable, transparent, immutable, and decentralized. Remote monitoring of an agricultural field requires security systems to ensure that any sensitive information is exchanged only among authenticated entities in the network. To this end, we design an efficient blockchain-enabled authenticated key agreement scheme for mobile vehicles-assisted precision agricultural Internet of Things (IoT) networks called$AgroMobiBlock$. The limited existing work on authentication in agricultural networks shows passive usage of blockchains with very high costs.$AgroMobiBlock$proposes a novel idea using the elliptic curve operations on an active hybrid blockchain over mobile farming vehicles with low computation and communication costs. Formal and informal security analysis along with the formal security verification using the Automated Validation of Internet Security Protocols and Applications (AVISPA) software tool have shown the robustness of$AgroMobiBlock$against man-in-the-middle, impersonation, replay, physical capture, and ephemeral secret leakage attacks among other potential attacks. The blockchain-based simulation on large-scale nodes shows the computational time for an increase in the network and block sizes. Moreover, the real-time testbed experiments have been performed to show the practical usefulness of the proposed scheme.
Anusha Vangala, Ashok Kumar Das, Ankush Mitra, Sajal K. Das 0001, Youngho Park 0005
IEEE Trans. Inf. Forensics Secur.2
2023 AISCM-FH: AI-Enabled Secure Communication Mechanism in Fog Computing-Based Healthcare
abstract
Fog computing-based Internet of Things (IoT) architecture is useful for various types of delay efficient network communications and services, like digital healthcare. However, there are privacy and security issues with the fog computing-based healthcare systems, which can further increase the risk of leakage of sensitive healthcare data. Therefore, a security mechanism, such as access control for fog computing-based healthcare systems, is needed to protect its data against various potential attacks. Moreover, the blockchain technology can be used to solve the digital healthcare’s data integrity related problems. The use of Artificial Intelligence (AI) further makes the system more effective in case of prediction of health related diseases. In this paper, an AI-enabled secure communication mechanism in fog computing-based healthcare system (in short, AISCM-FH) has been proposed. The security analysis of the proposed AISCM-FH is provided using the standard random oracle model and also with the heuristic (non-mathematical) security analysis. A pragmatic study determines the impact of the proposed AISCM-FH on key performance indicators. Moreover, we include a detailed performance comparison of AISCM-FH with other relevant existing schemes to show that it has low communication and computation costs, and provides superior security and extra functionality attributes as compared to those for other competing existing approaches.
Mohammad Wazid, Ashok Kumar Das, Sachin Shetty, Joel J. P. C. Rodrigues, Mohsen Guizani
IEEE Trans. Inf. Forensics Secur.2
2023 A Provably Secure Mobile User Authentication Scheme for Big Data Collection in IoT-Enabled Maritime Intelligent Transportation System
abstract
The emergence of contemporary technologies like cloud computing and the Internet of Things (IoT) has revolutionized the trends in the cyber world to serve humanity. There are plenty of applications in which they are being used, especially in smart cities and their constituents, Maritime Transportation System (MTS) is one of them. The IoT-enabled MTS has the potential to entertain the growing challenges of modern-day ship transportation. Secure real-time data access from numerous smart IoT devices is the most critical and crucial exercise for Big Data acquisition in IoT-enabled MTS. Therefore, we have developed a Physically Unclonable Function (PUF) based authenticated key agreement solution to deal with this challenge. This solution enables the mobile user and IoT node to mutually authenticate each other via Cloud-Gateway before real-time data exchange and transmission in IoT-enabled MTS. The use of PUF in our solution brings invincibility against physical security threats. An inclusive security analysis under the assumption of the specified threat model is carried out to substantiate the security resilience of our solution. The conduct of our solution is realized through security features, communication, and computation cost and It has been observed that our solution achieves efficiency of 37.3% and 9.7% in communication and computation overhead, respectively. Moreover, the network performance effectiveness of our solution is demonstrated in NS3 implementation.
Khalid Mahmood 0002, Javed Ferzund, Muhammad Asad Saleem, Salman Shamshad, Ashok Kumar Das, Youngho Park 0005
IEEE Trans. Intell. Transp. Syst.5
2023 Design of Provably Secure Authentication Protocol for Edge-Centric Maritime Transportation System
abstract
The epidemic growth of the Internet of Things (IoT) objects have revolutionized Maritime Transportation Systems (MTS). Though, it becomes challenging for the centralized cloud-centric framework to fulfil the application requirements such as low latency and power utilization. The introduction of the distributed edge-centric framework has recently helped the IoT-enabled MTS to meet these requirements by manipulating the tasks at the edge of the networks. Despite the fact that MTS leverages mobile subscribers by overcoming inherent cloud computing limitations, data security and user privacy requirements in establishing the MTS setup are still non-trivial challenges. In this article, we develop a key agreement solution for mobile users to realize mutual authentication in a single round. Our protocol offers user anonymity to maintain user privacy, and it can prevent physical attacks by physically unclonable functions. Initially, the security analysis is conferred to substantiate our protocol’s security persistence or strength. Later, its performance correlation is observed under the assumption of diverse metrics in a predefined empirical setup. The meticulous performance correlation endorses the precedence of our protocol over specified related protocols.
Khalid Mahmood 0002, Salman Shamshad, Muhammad Faizan Ayub, Zahid Ghaffar, Muhammad Khurram Khan, Ashok Kumar Das
IEEE Trans. Intell. Transp. Syst.6
2023 A New Scalable and Secure Access Control Scheme Using Blockchain Technology for IoT
abstract
The growth of IoT devices is so rapid that several billions of such devices would be in use in a span of four-year period. Essential security mechanisms need to be put in place to curb several security attacks prevalent in IoT. Access control is an important security mechanism that ensures legitimate and controlled access to critical and limited resources in IoT. The current access control schemes for IoT could not handle burgeoning number of IoT devices, while meeting the necessary level of security. Consequently, in this paper, we propose a new scalable and secure access control scheme for IoT. With blockchain as the root-of-trust, the proposed scheme performs access control for the IoT devices without having the resource-constrained IoT devices to be part of the blockchain network and to possess substantial amount of blockchain data. Blockchain’s tamper-proof property makes it an ideal candidate to be chosen as the root-of-trust. The scheme is secure against various security attacks prevalent in IoT. A proof-of-concept implementation for the scheme is developed and deployed in Ethereum Mainnet. The transaction costs of the different operations in the scheme are fairly below USD 3. Furthermore, scalability of the proposed scheme in different scenarios is investigated.
Sivaselvan N, Vivekananda Bhat K., Muttukrishnan Rajarajan, Ashok Kumar Das
IEEE Trans. Netw. Serv. Manag.4
2022 Privacy-Preserving Blockchain-Based Authentication in Smart Energy Systems
abstract
Smart Energy Systems (SES) are the need of the hour, given the looming dangers of power crises amid changing climatic conditions. However, sensitive data play a critical role in such systems deserving high privacy and security protection. This paper proposes a novel blockchain-based authentication scheme that preserves privacy using the zero-knowledge protocol. During informal analysis, the proposed scheme shows resistance to various attacks such as man-in-the-middle attacks, replay attacks, impersonation attacks, privileged insider attacks, and ephemeral secret leakage attacks. The formal security verification using AVISPA regards the scheme as safe. In addition, the scheme supports critical features such as anonymity and untraceability within limited computational and communicational costs. A simulation of blockchain using Node.js shows only a linear increase in computation time with an increase in the number of blocks, and transactions, and an exponential increase with the number of nodes.
Anusha Vangala, Ashok Kumar Das
SenSys2
2022 Blockchain-based vehicular ad-hoc networks: A comprehensive survey
Sanjeev Kumar Dwivedi, Ruhul Amin 0001, Ashok Kumar Das, Mark T. Leung, Kim-Kwang Raymond Choo, Satyanarayana Vollala
Ad Hoc Networks3
2022 Secure biometric-based access control scheme for future IoT-enabled cloud-assisted video surveillance system
Palak Bagga, Ankush Mitra, Ashok Kumar Das, Pandi Vijayakumar, Youngho Park 0005, Marimuthu Karuppiah
Comput. Commun.3
2022 Towards achieving efficient access control of medical data with both forward and backward secrecy
Suryakanta Panda, Samrat Mondal, Rinku Dewri, Ashok Kumar Das
Comput. Commun.4
2022 Machine learning security attacks and defense approaches for emerging cyber physical applications: A comprehensive survey
Mohammad Wazid, Ashok Kumar Das, Vinay Chamola, Mohsen Guizani
Comput. Commun.3
2022 Access Control Protocol for Battlefield Surveillance in Drone-Assisted IoT Environment
abstract
Surveillance drones, called as unmanned aerial vehicles (UAVs), are aircrafts that are utilized to collect video recordings, still images, or live video of the targets, such as vehicles, people or specific areas. Particularly in battlefield surveillance, there is high possibility of eavesdropping, inserting, modifying or deleting the messages during communications among the deployed drones and ground station server (GSS). This leads to launch several potential attacks by an adversary, such as main-in-middle, impersonation, drones hijacking, replay attacks, etc. Moreover, anonymity and untraceability are two crucial security properties that need to be maintained in battlefield surveillance communication environment. To deal with such a crucial security problem, we propose a new access control protocol for battlefield surveillance in drone-assisted Internet of Things (IoT) environment, called ACPBS-IoT. Through the detailed security analysis using formal and informal (nonmathematical), and also the formal security verification under automated software simulation tool, we show that the proposed ACPBS-IoT can resist several potential attacks needed in a battlefield surveillance scenario. Furthermore, the testbed experiments for various cryptographic primitives have been performed for measuring the execution time. Finally, a detailed comparative study on communication and computational overheads, and security, as well as functionality features, reveals that the proposed ACPBS-IoT provides superior security and more functionality features, and better or comparable overheads than other existing competing access control schemes.
Basudeb Bera, Ashok Kumar Das, Sahil Garg, Mohammad Jalil Piran, M. Shamim Hossain
IEEE Internet Things J.2
2022 Designing Fine-Grained Access Control for Software-Defined Networks Using Private Blockchain
abstract
Emerging next-generation Internet yields proper administration of a wide-ranging dynamic network to assist rapid ubiquitous resource accessibility, whilst providing higher channel bandwidth. Since its inception, the traditional static network infrastructure-based solutions involve manual configuration and proprietary controls of networked devices. It then leads to improper utilization of the overall resources, and hence experiences various security threats. Although transport layer security (TLS)-based solution is presently advocated in the said framework, it is vulnerable to many security threats like man-in-the-middle, replay, spoofing, privileged insider, impersonation, and denial-of-service attacks. Moreover, the current settings of the said tool do not facilitate any secure and reliable mechanisms for data forwarding, application flow routing, new configuration deployment, and network event management. Also, it suffers from the single point of controller failure issue. In this article, we propose a new private blockchain-enabled fine-grained access control mechanism for the SDN environment. In this regard, attribute-based encryption (ABE) and certificate-based access control protocol are incorporated. This proposed solution can resist several well-known security threats, and alleviate different system-level inconveniences. The formal and informal security inspections and performancewise comparative study of the proposed scheme endorse better qualifying scores as compared to the other existing competing state-of-the-art schemes. Besides, the experimental testbed implementation and blockchain simulation show the implementation feasibility of the proposed mechanism.
Durbadal Chattaraj, Basudeb Bera, Ashok Kumar Das, Joel J. P. C. Rodrigues, Youngho Park 0005
IEEE Internet Things J.3
2022 AI-Envisioned Blockchain-Enabled Signature-Based Key Management Scheme for Industrial Cyber-Physical Systems
abstract
This article proposes a new blockchain-envisioned key management protocol for artificial intelligence (AI)-enabled industrial cyber–physical systems (ICPSs). The designed key management protocol enables key establishment among the Internet of Things (IoT)-enabled smart devices and their respective gateway nodes. The blocks partially constructed with secure data from smart devices by fog servers are provided to cloud servers that are responsible for completing blocks, and then mining those blocks for verification and addition in the blockchain. The most important application of the private blockchain construction is to apply AI algorithms for accurate predictions in Big data analytics. A detailed security analysis along with formal security verification show that the proposed scheme resists various potential attacks in an ICPS environment. Moreover, practical testbed experiments have been conducted using the multiprecision integer and rational arithmetic cryptographic library (MIRACL). Furthermore, a detailed comparative analysis shows superiority of the proposed scheme over recent relevant schemes. In addition, the practical implementation using the blockchain for the proposed scheme demonstrates the total computational costs when the number of transactions per block and also the number of blocks mined in the blockchain are varied.
Ashok Kumar Das, Basudeb Bera, Sourav Saha 0002, Neeraj Kumar 0001, Ilsun You, Han-Chieh Chao
IEEE Internet Things J.1
2022 PUF-Based Authentication and Key Agreement Protocols for IoT, WSNs, and Smart Grids: A Comprehensive Survey
abstract
Physically unclonable function (PUF) is a physical unit fabricated inside a sensor and generally considered as an assurance anchor of resource inhibited device. Essentially, the function is based on the cryptographic approach, where a key is created and utilized such that it cannot be cloned. More specifically, it is an arbitrary function, which maps inherent properties of the hardware devices to a unique bit stream of information. Authentication and key agreement (AKA) protocols are widely used in electronic commerce, electronic stock trading, and many secured business transaction platforms, because they allow the communicating devices to mutually authenticate each other while exchanging authenticated session key (or secret key) that can be used subsequently to establish a secured communication channel. Yet, these protocols are also vulnerable to a broad range of security outbreaks. In light of these notions and practical applications, this article is intended to: 1) provide an overview of AKA protocols, PUF plus the combined PUF-based AKA; 2) systematically and taxonomically examine and discuss with pros and cons of AKA applications to the fast growing areas of Internet of Things, wireless sensor networks, and smart grids based on a meticulous survey of the existing literature; 3) summarize the challenges to deployment and potential security risks of the underlying technologies and possible remedies or mitigation strategies; and 4) to conduct and report a comparative performance and security analysis with respect to the three focused areas.
Priyanka Mall, Ruhul Amin 0001, Ashok Kumar Das, Mark T. Leung, Kim-Kwang Raymond Choo
IEEE Internet Things J.3
2022 An Efficient Privacy-Preserving Authenticated Key Establishment Protocol for Health Monitoring in Industrial Cyber-Physical Systems
abstract
Industry 5.0 is the automation, digitization, and data communication of the industrial procedure that comprises industrial cyber–physical systems (I-CPSs), industrial Internet of Things (IIoT), and artificial intelligence (AI). In the I-CPS-enabled healthcare ecosystem, intelligent wearable devices have been extensively employed to sense body information and measure the health status of the patients. Besides other IIoT applications, the I-CPS-enabled healthcare ecosystem also bears various challenges. For instance, due to the communal communication mediums, the security of a patient’s physiological datum is becoming a significant challenge these days. In order to cope with this challenge, we presented a secure and lightweight key establishment protocol. To the best of our knowledge, this protocol is the first application of physically unclonable function (PUF) in the I-CPS-enabled healthcare. The security of the designed protocol is proved with the help of a widely recognized real-or-random (ROR) model. The practical demonstration of our protocol from the network perspective is also measured through broadly recognized NS3 simulator tool.
Salman Shamshad, Khalid Mahmood 0002, Shafiq Hussain, Sahil Garg, Ashok Kumar Das, Neeraj Kumar 0001, Joel J. P. C. Rodrigues
IEEE Internet Things J.5
2022 Fortifying Smart Transportation Security Through Public Blockchain
abstract
Smart vehicles-enabled intelligent transportation system (ITS) supports a wide range of applications, such as, but not limited to, traffic planning and management, collision avoidance alert system, automated road speed enforcement, electronic toll collection, and real-time parking management, to name a few. However, it suffers from various types of security and privacy issues due to insecure communication among the entities over public channels. Therefore, an efficient and lightweight security mechanism is essential to protect the data that is both at rest as well as in transit. To this direction, we propose a public blockchain-envisioned secure communication framework for ITS (PBSCF-ITS). The proposed PBSCF-ITS guarantees access control and key management among the vehicle to vehicle, vehicle to roadside unit, and roadside unit to cloud server. We analyze the security of PBSCF-ITS to prove its resilience against various types of possible attacks. Furthermore, the performance of PBSCF-ITS with other related competing schemes has been compared. The obtained results illustrate that PBSCF-ITS outperforms the existing ones. Additionally, the pragmatic study of PBSCF-ITS is conducted to check its influence on various network-related performance parameters, like the number of mined blocks and transactions per block.
Mohammad Wazid, Basudeb Bera, Ashok Kumar Das, Saraju P. Mohanty, Minho Jo 0001
IEEE Internet Things J.3
2022 SCS-WoT: Secure Communication Scheme for Web of Things Deployment
abstract
Web of Things (WoT) extends the Internet of Things (IoT) paradigm to facilitate communications among smart things/devices and Web-based applications. In other words, WoT systems generally provide a Web interface for the monitoring and controlling of smart devices over the Web, for example, in applications, such as home automation, intelligent transportation system, smart healthcare, smart cities, and smart agriculture. However, this results in the generation of significant volume of data (i.e., big data) and, hence, the importance of big data analytics. There are also associated security and privacy implications. Therefore, in this article, we present a signature-based authentication and key agreement scheme for the WoT environment and prove its security. We also evaluate the performance of SCS-WoT and compare it against four other competing schemes. The findings show that SCS-WoT achieves better performance in terms of communication cost, computational cost, and security and functionality.
Mohammad Wazid, Ashok Kumar Das, Kim-Kwang Raymond Choo, Youngho Park 0005
IEEE Internet Things J.2
2022 TACAS-IoT: Trust Aggregation Certificate-Based Authentication Scheme for Edge-Enabled IoT Systems
abstract
The Internet of Things (IoT) is a network of interconnected, Internet-connected items (i.e., smart devices) that can collect and transmit data across a wireless network without the need for human intervention. IoT enables the systems to have higher efficiency and dependability in their day-to-day operations due to its strong focus on machine-to-machine (M2M) connectivity, big data, and machine learning. While IoT has many advantages over traditional techniques, it also has a number of security and privacy concerns. Trust is a belief in the competence of a device (computing machine) to act dependably, securely and reliably in some specific context. In an M2M (one IoT device to other IoT device) communication, trust is accomplished by making the use of cryptographic operations (i.e., digital signatures and electronic certificates). Various security threats and attacks have been launched on IoT connectivity in recent years. A trust mechanism is necessary to ensure the quality of collaborative service behaviors and to build confidence between IoT devices. As a result, how to create an effective trust computing mechanism has become an emerging topic in IoT. Therefore, we provide the design of a novel trust-aggregation-based authentication scheme for secure communication of edge-enabled IoT (in short, TACAS-IoT). The security analysis shows that TACAS-IoT is secured against a variety of attacks. Moreover, TACAS-IoT delivers greater security and capabilities with less communication and computation overheads, according to the performance comparison. Finally, a practical implementation of TACAS-IoT is provided in order to assess its impact on the key performance parameters.
Mohammad Wazid, Ashok Kumar Das, Sachin Shetty
IEEE Internet Things J.2
2022 DDoS attack resisting authentication protocol for mobile based online social network applications
Munmun Bhattacharya, Sandip Roy 0001, Ashok Kumar Das, Samiran Chattopadhyay, Soumya Banerjee 0001, Ankush Mitra
J. Inf. Secur. Appl.3
2022 BUAKA-CS: Blockchain-enabled user authentication and key agreement scheme for crowdsourcing system
Mohammad Wazid, Ashok Kumar Das, Rasheed Hussain, Neeraj Kumar 0001, Sandip Roy 0001
J. Syst. Archit.2
2022 Designing Secure and Efficient Biometric-Based Access Mechanism for Cloud Services
abstract
The demand for remote data storage and computation services is increasing exponentially in our data-driven society; thus, the need for secure access to such data and services. In this article, we design a new biometric-based authentication protocol to provide secure access to a remote (cloud) server. In the proposed approach, we consider biometric data of a user as a secret credential. We then derive a unique identity from the user's biometric data, which is further used to generate the user's private key. In addition, we propose an efficient approach to generate a session key between two communicating parties using two biometric templates for a secure message transmission. In other words, there is no need to store the user's private key anywhere and the session key is generated without sharing any prior information. A detailed Real-Or-Random (ROR) model based formal security analysis, informal (non-mathematical) security analysis and also formal security verification using the broadly-accepted Automated Validation of Internet Security Protocols and Applications (AVISPA) tool reveal that the proposed approach can resist several known attacks against (passive/active) adversary. Finally, extensive experiments and a comparative study demonstrate the efficiency and utility of the proposed approach.
Gaurang Panchal, Debasis Samanta, Ashok Kumar Das, Neeraj Kumar 0001, Kim-Kwang Raymond Choo
IEEE Trans. Cloud Comput.3
2022 Authenticated Key Agreement Scheme With User Anonymity and Untraceability for 5G-Enabled Softwarized Industrial Cyber-Physical Systems
abstract
With the tremendous growth of Information and Communications Technology (ICT), Cyber Physical Systems (CPS) have opened the door for many potential applications ranging from smart grids and smart cities to transportation, retail, public safety and networking, healthcare and industrial manufacturing. However, due to communication via public channel occurring among various entities in an industrial CPS (ICPS) with the help of the 5G technology and Software-Defined Networking (SDN), it poses several potential security threats and attacks. To mitigate these issues, we propose a new three-factor user authentication and key agreement scheme (UAKA-5GSICPS) for 5G-enabled SDN based ICPS environment. UAKA-5GSICPS allows an authorized user to access the real-time data directly from some designated Internet of Things (IoT)-based smart devices provided that a successful mutual authentication among them is executed via their controller node in the SDN network. It is shown to be robust against various potential attacks through detailed security analysis including the simulation-based formal security verification. A detailed comparative study with the help of experimental results shows that UAKA-5GSICPS achieves better trade-off among security and functionality features, communication and computation overheads as compared to other existing competing schemes.
Anil Kumar Sutrala, Mohammad S. Obaidat, Sourav Saha 0002, Ashok Kumar Das, Mamoun Alazab, Youngho Park 0005
IEEE Trans. Intell. Transp. Syst.4
2021 SPCS-IoTEH: Secure Privacy-Preserving Communication Scheme for IoT-Enabled e-Health Applications
abstract
In an Internet of Things (IoT) enabled e-health system, smart health devices sense the health data continuously and share the collected data with the neighboring controller device (i.e., personal server) via some wireless communication mechanism (i.e., bluetooth and zigbee), and finally the data is stored on some health server (i.e., a server over the cloud). The health data is then accessible to healthcare service providers (for example, doctors, nursing staff, relatives of patient) for tracking and monitoring of health conditions of the patients for their better treatment at the earliest. In an IoT enabled health system, the smart healthcare devices communicate over public channel, which causes various types of threats and attacks on the ongoing communication. Therefore, we need a powerful privacy-preserving security mechanism to secure the communication happens in an IoT enabled e-health system as the health data is strictly private and confidential. In this paper, we propose a new privacy-preserving access control and key management scheme for the secure communication of IoT enabled e-health system (SPCS-IoTEH). We also conduct informal security analysis of the proposed SPCS-IoTEH to show its robustness against various types of active and passive attacks. The performance of SPCS-IoTEH is also shown to be better than other existing competing schemes.
Neha Garg, Mohammad S. Obaidat, Mohammad Wazid, Ashok Kumar Das, Devesh Pratap Singh
ICC4
2021 Private blockchain-envisioned multi-authority CP-ABE-based user access control scheme in IIoT
Soumya Banerjee 0001, Basudeb Bera, Ashok Kumar Das, Samiran Chattopadhyay, Muhammad Khurram Khan, Joel J. P. C. Rodrigues
Comput. Commun.3
2021 Private blockchain-based access control mechanism for unauthorized UAV detection and mitigation in Internet of Drones environment
Basudeb Bera, Ashok Kumar Das, Anil Kumar Sutrala
Comput. Commun.2
2021 An enhanced lightweight and secured authentication protocol for vehicular ad-hoc network
Tarak Nandy, Mohd Yamani Idna Bin Idris, Rafidah Md Noor, Ashok Kumar Das, Xiong Li 0002, Norjihan Binti Abdul Ghani, Sananda Bhattacharyya
Comput. Commun.4
2021 Designing Blockchain-Based Access Control Protocol in IoT-Enabled Smart-Grid System
abstract
We design a new blockchain-based access control protocol in IoT-enabled smart-grid system, called DBACP-IoTSG. Through the proposed DBACP-IoTSG, the data is securely brought to the service providers from their respective smart meters (SMs). The peer-to-peer (P2P) network is formed by the participating service providers, where the peer nodes are responsible for creating the blocks from the gathered data securely from their corresponding SMs and adding them into the blockchain after validation of the blocks using the voting-based consensus algorithm. In our work, the blockchain is considered as private because the data collected from the consumers of the SMs are private and confidential. By the formal security analysis under the random oracle model, nonmathematical security analysis and software-based formal security verification, DBACP-IoTSG is shown to be resistant against various attacks. We carry out the experimental results of various cryptographic primitives that are needed for comparative analysis using the widely used multiprecision integer and rational arithmetic cryptographic library (MIRACL). A detailed comparative study reveals that DBACP-IoTSG supports more functionality features and provides better security apart from its low communication and computation costs as compared to recently proposed relevant schemes. In addition, the blockchain implementation of DBACP-IoTSG has been performed to measure computational time needed for the varied number of blocks addition and also the varied number of transactions per block in the blockchain.
Basudeb Bera, Sourav Saha 0002, Ashok Kumar Das, Athanasios V. Vasilakos
IEEE Internet Things J.3
2021 Provably Secure Authentication Protocol for Mobile Clients in IoT Environment Using Puncturable Pseudorandom Function
abstract
The Internet of Things (IoT) is a framework of various services and smart technologies that mutually communicate information between mobile devices and users or just between devices with the help of Internet connectivity. The dramatic progression of IoT helps numerous network applications and communication technologies to introduce state-of-the-art communication models for enabling interaction among mobile server, clients, and various other smart entities. Now-a-days, online mobile services have gained huge attention by providing ample convenience to the distant users. However, it is necessary to secure the information, being exchanged among mobile clients and server. Therefore, a large number of authentication protocols have been presented but majority of them are unsuitable to fulfill novel security requirements and standards. Moreover, they are incompatible for the IoT environment due to higher computation and communication complexity. Consequently, there is a dire need of developing an adequate, reliable, and cost-effective authentication protocol. In this article, we introduce a novel identity-based key agreement protocol using the puncturable pseudorandom functions for mobile clients in the IoT environment. The proposed PSK-MC protocol enables two mobile clients to accomplish mutual authentication via server. The proposed protocol is evaluated formally and informally to determine its security strength. The formal security analysis is presented using the widely used random oracle model. Moreover, all the cryptographic operations used at mobile client side are executed on a mobile device, while the operations used at the server side are implemented on a desktop machine to get the experimental results to determine computation cost. The performance analysis reveals the fact that our protocol is comparatively better than related protocols by exhibiting least communication and computation overhead.
Muhammad Asad Saleem, Zahid Ghaffar, Khalid Mahmood 0002, Ashok Kumar Das, Joel J. P. C. Rodrigues, Muhammad Khurram Khan
IEEE Internet Things J.4
2021 Designing Secure User Authentication Protocol for Big Data Collection in IoT-Based Intelligent Transportation System
abstract
Secure access of the real-time data from the Internet-of-Things (IoT) smart devices (e.g., vehicles) by a legitimate external party (user) is an important security service for big data collection in the IoT-based intelligent transportation system (ITS). To deal with this important issue, we design a new three-factor user authentication scheme, called UAP-BCIoT, which relies on elliptic-curve cryptography (ECC). The mutual authentication between the user and an IoT device happens via the semitrusted cloud-gateway (CG) node in UAP-BCIoT. UAP-BCIoT supports several functionality features needed for IoT-based ITS environment including IoT smart device credential validation and big data analytics. A detailed security analysis is conducted based on the defined threat model to show that UAP-BCIoT is resilient against many known attacks. A thorough comparative study reveals that UAP-BCIoT supports better security, offers various functionality attributes, and also provides similar costs in communication as well computation as compared to other relevant schemes Finally, the practical demonstration of the proposed UAP-BCIoT is also provided to measure its impact on the network performance parameters.
Jangirala Srinivas, Ashok Kumar Das, Mohammad Wazid, Athanasios V. Vasilakos
IEEE Internet Things J.2
2021 Smart Contract-Based Blockchain-Envisioned Authentication Scheme for Smart Farming
abstract
A blockchain-based smart farming technology provides the agricultural data to the farmers and other users associated with smart farming on a single integrated platform. Moreover, persistence and auditability of stored data in blocks into the blockchain provide the confidence of using the correct data when needed later and adds transparency, anonymity, and traceability at the same time. To fulfill such a goal, in this article, we design a new smart contract-based blockchain-envisioned authenticated key agreement mechanism in a smart farming environment. The device-to-device (D2D) authentication phase and device-to-gateway (D2G) authentication phase support mutual authentication and key agreement between two Internet-of-Things (IoT)-enabled devices and between an IoT device and the gateway node (GWN) in the network, respectively. The blocks are created by the edge servers on the authenticated data of IoT devices received from the GWNs and then sent to the cloud server (CS). The smart contract-based consensus mechanism allows verification and addition of the formed blocks by a peer-to-peer (P2P) CSs network. The security of the proposed scheme is done through formal and informal security analysis, and also using the formal security verification tool. A detailed comparative study reveals that the proposed scheme offers superior security and more functionality features as compared to existing competing authentication protocols. Finally, the blockchain-based simulation has been conducted to measure computational time for a varied number of mined blocks and also a varied number of transactions per block.
Anusha Vangala, Anil Kumar Sutrala, Ashok Kumar Das, Minho Jo 0001
IEEE Internet Things J.3
2021 Blockchain-based batch authentication protocol for Internet of Vehicles
Palak Bagga, Anil Kumar Sutrala, Ashok Kumar Das, Pandi Vijayakumar
J. Syst. Archit.3
2021 Secure user authentication mechanism for IoT-enabled Wireless Sensor Networks based on multiple Bloom filters
Anup Kumar Maurya, Ashok Kumar Das, Sajjad Shaukat Jamal, Debasis Giri
J. Syst. Archit.2
2021 Designing Anonymous Signature-Based Authenticated Key Exchange Scheme for Internet of Things-Enabled Smart Grid Systems
abstract
Recent technological evolution in the Internet of Things (IoT) age supports better solutions to magnify the management of the power quality and reliability concerns, and imposes the measures of a smart grid. In smart grid environment, a smart meter needs to securely access the services from a service provider via insecure channel. However, since the communication is via public channel, it imposes various security threats by an adversary. To deal with this, in this article we design a new anonymous signature-based authenticated key exchange scheme for IoT-enabled smart grid environment, called AAS-IoTSG. The dynamic smart meter addition phase is also permissible in AAS-IoTSG after initial deployment. The security of AAS-IoTSG has been tested rigorously using formal security analysis under the real-or-random (ROR) model which is one of the broadly-accepted standard random oracle models, formal security verification under the broadly-used automated validation of Internet security protocols and applications (AVISPA) tool and also using informal security analysis. Finally, an exhaustive comparative study unveils that AAS-IoTSG supports better security and functionality features and requires less communication and computation overheads as compared to the existing state-of-art authentication mechanisms in smart grid systems.
Jangirala Srinivas, Ashok Kumar Das, Xiong Li 0002, Muhammad Khurram Khan, Minho Jo 0001
IEEE Trans. Ind. Informatics2
2021 Designing Authenticated Key Management Scheme in 6G-Enabled Network in a Box Deployed for Industrial Applications
abstract
6G-enabled network in a box (NIB) is a multigenerational, rapidly deployable hardware, and software technology for the communication. 6G-enabled NIB provides high level of flexibility which makes it capable to provide connectivity services for different types of applications as it is effective for the communications of after disaster scenario, battlefields scenario, and industrial scenario. In 6G-enabled NIB deployed industrial applications, various passive and active attacks are possible because the involved entities communicate over insecure channel. In this article, a new remote user authentication and key management scheme is proposed for securing 6G-enabled NIB deployed for industrial applications, which we call in short as UAKMS-NIB. The security analysis shows the resilience of UAKMS-NIB against various types of possible attacks. The practical demonstration of UAKMS-NIB is also provided to measure its impact on the network performance parameters. Finally, a comparative analysis with other closely related existing schemes shows that UAKMS-NIB performs better than the existing schemes.
Mohammad Wazid, Ashok Kumar Das, Neeraj Kumar 0001, Mamoun Alazab
IEEE Trans. Ind. Informatics2
2021 LAPTAS: lightweight anonymous privacy-preserving three-factor authentication scheme for WSN-based IIoT
Hossein Abdi Nasib Far, Majid Bayat, Ashok Kumar Das, Mahdi Fotouhi, Seyed Morteza Pournaghi, Mohammad-Ali Doostari
Wirel. Networks3
2020 Cache Poisoning Prevention Scheme in 5G-enabled Vehicular Networks: A Tangle-based Theoretical Perspective
abstract
The modern day traffic continues to evolve in terms of scale, autonomy and access to information. Every vehicle gathers information and contributes its decisions to the global vehicular network every second. With the advent of 5G equipped digital communication and sophisticated algorithms are in place for the vehicles to communicate with each other in a closely monitored, yet decentralized network, there is a need to ensure that no form of incorrect data be propagated without prior validation. There is also a requirement of maintaining cache since there is no centralized network where all vehicles report their activities and gather information from, at a required speed. The distribution of cache is a major hurdle both in terms of validation and propagation. Cache poisoning can occur if a malicious vehicle or a compromised vehicle intentionally or unintentionally puts incorrect data and other vehicles use that data to skew their own future decisions. In this paper, we explore different methodologies to address and combat the cache poisoning scenarios and suggest an efficient and secure scheme for validation and distribution of cache using the Directed Acyclic Graph (DAG) based ledger, which is based on Tangle™.
Santosh Kumar Desai, Amit Dua, Neeraj Kumar 0001, Ashok Kumar Das, Joel J. P. C. Rodrigues
CCNC4
2020 SAC-FIIoT: Secure Access Control Scheme for Fog-Based Industrial Internet of Things
abstract
Industrial Internet of Things (IIoT) is a communication environment that consists of various interconnected sensing devices, instruments, and other devices connected together with industrial software tools and applications. The important applications of IIoT include industrial automation, predictive maintenance, smart logistics management, power management, smart package management and smart robotics. However, IIoT may be vulnerable to different types of attacks as the IoT smart devices communicate among each other via insecure communication means. Thus, there is an essential requirement of deployment of secure access control scheme in IIoT environment, which is one of the important security services for securing IIoT. In this paper, we propose a novel access control scheme for fog based IIoT communication, called SAC-FIIoT. We provide the details of network model as well as threat model, which are required to design SAC-FIIoT. The security analysis of SAC-FIIoT shows its resilience against various types of possible attacks. SAC-FIIoT is also compared with other related competing existing schemes and it was found that its performance is better than these competing schemes. Therefore, SAC-FIIoT is suitable for access control in a fog-based IIoT environment.
Mohammad Wazid, Mohammad S. Obaidat, Ashok Kumar Das, Pandi Vijayakumar
GLOBECOM3
2020 On the Design of Blockchain-Based Access Control Protocol for IoT-Enabled Healthcare Applications
abstract
Access control is one of the important security services that is essential for an Internet of Things (IoT)-enabled authorized user using his/her smart mobile device to authenticate with the trusted Hospital Authority (HA) in a hospital. After mutual authentication, a secret key is established among the user and HA for secure data transmission. The secure data (transactions) gathered by the HA from the users in the hospital is encrypted using a shared key among various trusted hospital authorities involved in the private blockchain network of hospitals. The HA of each hospital is responsible for constructing the blocks in the blockchain using the encrypted transactions because the data in healthcare application is treated as confidential and private. To deal with this important problem, we design a novel access control scheme using private blockchain technology. The proposed scheme is shown to be secure against various well-known attacks. Moreover, the proposed scheme provides better security and functionality features, and also requires low communication and computational costs as compared to relevant approaches.
Sourav Saha 0002, Anil Kumar Sutrala, Ashok Kumar Das, Neeraj Kumar 0001, Joel J. P. C. Rodrigues
ICC3
2020 A lightweight and secure two-factor authentication scheme for wireless body area networks in health-care IoT
Mahdi Fotouhi, Majid Bayat, Ashok Kumar Das, Hossein Abdi Nasib Far, Seyed Morteza Pournaghi, Mohammad-Ali Doostari
Comput. Networks3
2020 Designing secure blockchain-based access control scheme in IoT-enabled Internet of Drones deployment
Basudeb Bera, Durbadal Chattaraj, Ashok Kumar Das
Comput. Commun.3
2020 Design of a blind quantization-based audio watermarking scheme using singular value decomposition
abstract
Summary Watermarking is a mechanism in which owner of the audio file hides the watermark information into a audio for various applications. The identity of the owner of the audio file is hidden in the audio, which is known as watermark. In this article, a quantization‐based audio watermarking using singular value decomposition (SVD) is proposed. The original audio signal is converted into non overlapping two dimensional matrix blocks. The SVD is applied to each block. The watermark is embedded into audio signal by quantization of largest singular value of the block. The watermark is extracted blindly without using original audio signal. Experimental results show the watermark's high imperceptibility in the audio signal and good performance against Stirmark as well as traditional signal processing attacks. Compared with other audio watermarking methods, our method has higher embedding capacity and robust against various traditional signal processing attacks.
Vivekananda Bhat K., Ashok Kumar Das, Jong-Hyouk Lee
Concurr. Comput. Pract. Exp.2
2020 Design and analysis of authenticated key agreement scheme in cloud-assisted cyber-physical systems
Sravani Challa, Ashok Kumar Das, Prosanta Gope, Neeraj Kumar 0001, Fan Wu 0003, Athanasios V. Vasilakos
Future Gener. Comput. Syst.2
2020 Certificateless-Signcryption-Based Three-Factor User Access Control Scheme for IoT Environment
abstract
User access control is a crucial requirement in any Internet of Things (IoT) deployment, as it allows one to provide authorization, authentication, and revocation of a registered legitimate user to access real-time information and/or service directly from the IoT devices. To complement the existing literature, we design a new three-factor certificateless-signcryption-based user access control for the IoT environment (CSUAC-IoT). Specifically, in our scheme, a user U's password, personal biometrics, and mobile device are used as the three authentication factors. By executing the login and access control phase of CSUAC-IoT, a registered user (U) and a designated smart device (Si) can authorize and authenticate mutually via the trusted gateway node (GN) in a particular cell of the IoT environment. In our setting, the environment is partitioned into disjoint cells, and each cell will contain a certain number of IoT devices along with a GN. With the established session key between U and Si, both entities can then communicate securely. In addition, CSUAC-IoT supports new IoT devices deployment, user revocation, and password/biometric update functionality features. We prove the security of CSUAC-IoT under the real-or-random (ROR) model, and demonstrate that it can resist several common attacks found in a typical IoT environment using the AVISPA tool. A comparative analysis also reveals that CSUAC-IoT achieves better tradeoff for security and functionality, and computational and communication costs, in comparison to five other competing approaches.
Shobhan Mandal, Basudeb Bera, Anil Kumar Sutrala, Ashok Kumar Das, Kim-Kwang Raymond Choo, Youngho Park 0005
IEEE Internet Things J.4
2020 Multi-Authority CP-ABE-Based user access control scheme with constant-size key and ciphertext for IoT deployment
Soumya Banerjee 0001, Sandip Roy 0001, Vanga Odelu, Ashok Kumar Das, Samiran Chattopadhyay, Joel J. P. C. Rodrigues, Youngho Park 0005
J. Inf. Secur. Appl.4
2020 LAM-CIoT: Lightweight authentication mechanism in cloud-based IoT environment
Mohammad Wazid, Ashok Kumar Das, Vivekananda Bhat K., Athanasios V. Vasilakos
J. Netw. Comput. Appl.2
2020 On the design of biometric-based user authentication protocol in smart city environment
Basudeb Bera, Ashok Kumar Das, Walter Balzano, Carlo Maria Medaglia
Pattern Recognit. Lett.2
2020 Cloud Centric Authentication for Wearable Healthcare Monitoring System
abstract
Security and privacy are the major concerns in cloud computing as users have limited access on the stored data at the remote locations managed by different service providers. These become more challenging especially for the data generated from the wearable devices as it is highly sensitive and heterogeneous in nature. Most of the existing techniques reported in the literature are having high computation and communication costs and are vulnerable to various known attacks, which reduce their importance for applicability in real-world environment. Hence, in this paper, we propose a new cloud based user authentication scheme for secure authentication of medical data. After successful mutual authentication between a user and wearable sensor node, both establish a secret session key that is used for future secure communications. The extensively-used Real-Or-Random (ROR) model based formal security analysis and the broadly-accepted Automated Validation of Internet Security Protocols and Applications (AVISPA) tool based formal security verification show that the proposed scheme provides the session-key security and protects active attacks. The proposed scheme is also informally analyzed to show its resilience against other known attacks. Moreover, we have done a detailed comparative analysis for the communication and computation costs along with security and functionality features which proves its efficiency in comparison to the other existing schemes of its category.
Jangirala Srinivas, Ashok Kumar Das, Neeraj Kumar 0001, Joel J. P. C. Rodrigues
IEEE Trans. Dependable Secur. Comput.2
2020 Anonymous Lightweight Chaotic Map-Based Authenticated Key Agreement Protocol for Industrial Internet of Things
abstract
With an exponential increase in the popularity of Internet, the real-time data collected by various smart sensing devices can be analyzed remotely by a remote user (e.g., a manager) in the Industrial Internet of Things (IIoT). However, in the IIoT environment, the gathered real-time data is transmitted over the public channel, which raises the issues of security and privacy in this environment. Therefore, to protect illegal access by an adversary, user authentication mechanism is one of the promising security solutions in the IIoT environment. To achieve this goal, we propose a new user authenticated key agreement scheme in which only authorized users can access the services from the designated IoT sensing devices installed in the IIoT environment. In the proposed scheme, fuzzy extractor technique is used for biometric verification. Moreover, three factors, namely smart card, password and personal biometrics of a legal registered user are applied in the proposed scheme to increase the level of security in the system. The proposed scheme supports new devices addition after initial deployment of the devices, password/biometric change phase and also smart card revocation phase in case the smart card is lost or stolen by an adversary. In addition, the proposed scheme is lightweight in nature. We carry out the formal security analysis using the broadly accepted Real-Or-Random (ROR) model and also the non-mathematical (informal) security analysis on the proposed scheme. Furthermore, the formal security verification using the popularly-used AVISPA (Automated Validation of Internet Security Protocols and Applications) tool is carried out on the proposed scheme. The detailed security analysis assures that the proposed scheme can withstand several well-known attacks in the IIoT environment. A practical demonstration using the NS2 simulation study is also performed for the proposed scheme and other related existing schemes. Also, a detailed comparative study shows that the proposed scheme is efficient, and provides superior security in comparison to the other schemes.
Jangirala Srinivas, Ashok Kumar Das, Mohammad Wazid, Neeraj Kumar 0001
IEEE Trans. Dependable Secur. Comput.2
2020 Secure Remote User Authenticated Key Establishment Protocol for Smart Home Environment
abstract
The Information and Communication Technology (ICT) has been used in wide range of applications, such as smart living, smart health and smart transportation. Among all these applications, smart home is most popular, in which the users/residents can control the operations of the various smart sensor devices from remote sites also. However, the smart devices and users communicate over an insecure communication channel, i.e., the Internet. There may be the possibility of various types of attacks, such as smart device capture attack, user, gateway node and smart device impersonation attacks and privileged-insider attack on a smart home network. An illegal user, in this case, can gain access over data sent by the smart devices. Most of the existing schemes reported in the literature for the remote user authentication in smart home environment are not secure with respect to the above specified attacks. Thus, there is need to design a secure remote user authentication scheme for a smart home network so that only authorized users can gain access to the smart devices. To mitigate the aforementioned isses, in this paper, we propose a new secure remote user authentication scheme for a smart home environment. The proposed scheme is efficient for resource-constrained smart devices with limited resources as it uses only one-way hash functions, bitwise XOR operations and symmetric encryptions/decryptions. The security of the scheme is proved using the rigorous formal security analysis under the widely-accepted Real-Or-Random (ROR) model. Moreover, the rigorous informal security analysis and formal security verification using the broadly-accepted Automated Validation of Internet Security Protocols and Applications (AVISPA) tool is also done. Finally, the practical demonstration of the proposed scheme is also performed using the widely-accepted NS-2 simulation.
Mohammad Wazid, Ashok Kumar Das, Vanga Odelu, Neeraj Kumar 0001, Willy Susilo
IEEE Trans. Dependable Secur. Comput.2
2020 Designing Secure Lightweight Blockchain-Enabled RFID-Based Authentication Protocol for Supply Chains in 5G Mobile Edge Computing Environment
abstract
Secure real-time data about goods in transit in supply chains needs bandwidth having capacity that is not fulfilled with the current infrastructure. Hence, 5G-enabled Internet of Things (IoT) in mobile edge computing is intended to substantially increase this capacity. To deal with this issue, in this article, we design a new efficient lightweight blockchain-enabled radio frequency identification (RFID)-based authentication protocol for supply chains in 5G mobile edge computing environment, called lightweight blockchain-enabled RFID-based authentication protocol (LBRAPS). LBRAPS is based on bitwise exclusive-or (XOR), one-way cryptographic hash and bitwise rotation operations only. LBRAPS is shown to be secure against various attacks. Moreover, the simulation-based formal security verification using the broadly-accepted Automated Validation of Internet Security Protocols and Applications (AVISPA) tool assures that LBRAPS is secure. Finally, it is shown that LBRAPS has better trade-off among its security and functionality features, communication and computation costs as compared to those for existing protocols.
Jangirala Srinivas, Ashok Kumar Das, Athanasios V. Vasilakos
IEEE Trans. Ind. Informatics2
2020 2PBDC: privacy-preserving bigdata collection in cloud environment
Jangirala Srinivas, Ashok Kumar Das, Joel J. P. C. Rodrigues
J. Supercomput.2
2019 Government regulations in cyber security: Framework, standards and recommendations
Jangirala Srinivas, Ashok Kumar Das, Neeraj Kumar 0001
Future Gener. Comput. Syst.2
2019 Design of secure key management and user authentication scheme for fog computing services
Mohammad Wazid, Ashok Kumar Das, Neeraj Kumar 0001, Athanasios V. Vasilakos
Future Gener. Comput. Syst.2
2019 A Provably Secure and Lightweight Anonymous User Authenticated Session Key Exchange Scheme for Internet of Things Deployment
abstract
With the ever increasing adoption rate of Internet-enabled devices [also known as Internet of Things (IoT) devices] in applications such as smart home, smart city, smart grid, and healthcare applications, we need to ensure the security and privacy of data and communications among these IoT devices and the underlying infrastructure. For example, an adversary can easily tamper with the information transmitted over a public channel, in the sense of modification, deletion, and fabrication of data-in-transit and data-in-storage. Time-critical IoT applications such as healthcare may demand the capability to support external parties (users) to securely access IoT data and services in real-time. This necessitates the design of a secure user authentication mechanism, which should also allow the user to achieve security and functionality features such as anonymity and un-traceability. In this paper, we propose a new lightweight anonymous user authenticated session key agreement scheme in the IoT environment. The proposed scheme uses three-factor authentication, namely a user's smart card, password, and personal biometric information. The proposed scheme does not require the storing of user specific information at the gateway node. We then demonstrate the proposed scheme's security using the broadly accepted real-or-random (ROR) model, Burrows-Abadi-Needham (BAN) logic, and automated validation of Internet security protocols and applications (AVISPAs) software simulation tool, as well as presenting an informal security analysis to demonstrate its other features. In addition, through our simulations, we demonstrate that the proposed scheme outperforms existing related user authentication schemes, in terms of its security and functionality features, and computation costs.
Soumya Banerjee 0001, Vanga Odelu, Ashok Kumar Das, Jangirala Srinivas, Neeraj Kumar 0001, Samiran Chattopadhyay, Kim-Kwang Raymond Choo
IEEE Internet Things J.3
2019 Certificate-Based Anonymous Device Access Control Scheme for IoT Environment
abstract
As the “Internet communications infrastructure” develops to encircle smart devices, it is very much essential for designing suitable methods for secure communications with these smart devices, in the future Internet of Things (IoT) applications context. Due to wireless communication among the IoT smart devices and the gateway node (GWN), several security threats may arise in the IoT environment, including replay, man-in-the-middle, impersonation, malicious devices deployment, and physical devices capture attacks. In this article, to mitigate such security threats, we design a new certificate-based device access control scheme in IoT environment which is not only secure against mentioned attacks, but it also preserves anonymity property. A detailed security analysis using the widely accepted real-or-random (ROR) model-based formal security analysis, informal security analysis, and also formal security verification based on the broadly accepted automated validation of Internet security protocols and applications (AVISPAs) tool has been performed on the proposed scheme to show that it is secure against various known attacks. In addition, a comprehensive comparative analysis among the proposed scheme and other relevant schemes shows that a better tradeoff among the security and functionality attributes, communication, and computational costs is achieved for the proposed scheme as compared to other schemes.
Saurav Malani, Jangirala Srinivas, Ashok Kumar Das, K. Srinathan 0001, Minho Jo 0001
IEEE Internet Things J.3
2019 AKM-IoV: Authenticated Key Management Protocol in Fog Computing-Based Internet of Vehicles Deployment
abstract
Internet of Vehicles (IoV) is an intelligent application of Internet of Things (IoT) in smart transportation that takes intelligent commitments to the passengers to improve traffic safety and efficiency, and generate a more enjoyable driving and riding environment. Fog cloud-based IoV is another variant of mobile cloud computing where vehicular cloud and Internet can co-operate in more effective way in IoV. However, more increasing dependence on wireless communication, control, and computing technology makes IoV more dangerous to prospective attacks. For secure communication among vehicles, road-side units, fog and cloud servers, we design a secure authenticated key management protocol in fog computing-based IoV deployment, called AKM-IoV. In the designed AKM-IoV, after mutual authentication between communicating entities in IoV they establish session keys for secure communications. AKM-IoV is tested for its security analysis using the formal security analysis under the widely accepted real-or-random (ROR) model, informal, and formal security verification using the broadly accepted automated validation of Internet security protocols and applications (AVISPAs) tool. The practical demonstration of AKM-IoV is shown using the NS2 simulation. In addition, a detailed comparative study is conducted to show the efficiency and functionality and security features supported by AKM-IoV as compared to other existing recent protocols.
Mohammad Wazid, Palak Bagga, Ashok Kumar Das, Sachin Shetty, Joel J. P. C. Rodrigues, Youngho Park 0005
IEEE Internet Things J.3
2019 Design and Analysis of Secure Lightweight Remote User Authentication and Key Agreement Scheme in Internet of Drones Deployment
abstract
The Internet of Drones (IoD) provides a coordinated access to unmanned aerial vehicles that are referred as drones. The on-going miniaturization of sensors, actuators, and processors with ubiquitous wireless connectivity makes drones to be used in a wide range of applications ranging from military to civilian. Since most of the applications involved in the IoD are real-time based, the users are generally interested in accessing real-time information from drones belonging to a particular fly zone. This happens if we allow users to directly access real-time data from flying drones inside IoD environment and not from the server. This is a serious security breach which may deteriorate performance of any implemented solution in this IoD environment. To address this important issue in IoD, we propose a novel lightweight user authentication scheme in which a user in the IoD environment needs to access data directly from a drone provided that the user is authorized to access the data from that drone. The formal security verification using the broadly accepted automated validation of Internet security protocols and applications tool along with informal security analysis show that our scheme is secure against several known attacks. The performance comparison demonstrates that our scheme is efficient with respect to various parameters, and it provides better security as compared to those for the related existing schemes. Finally, the practical demonstration of our scheme is done using the widely accepted NS2 simulation.
Mohammad Wazid, Ashok Kumar Das, Neeraj Kumar 0001, Athanasios V. Vasilakos, Joel J. P. C. Rodrigues
IEEE Internet Things J.2
2019 Authentication in cloud-driven IoT-based big data environment: Survey and outlook
Mohammad Wazid, Ashok Kumar Das, Rasheed Hussain, Giancarlo Succi, Joel J. P. C. Rodrigues
J. Syst. Archit.2
2019 Secure Remote User Mutual Authentication Scheme with Key Agreement for Cloud Environment
Marimuthu Karuppiah, Ashok Kumar Das, Xiong Li 0002, Saru Kumari, Fan Wu 0003, Shehzad Ashraf Chaudhry, Niranchana Radhakrishnan
Mob. Networks Appl.2
2019 User authentication in a tactile internet based remote surgery environment: Security issues, challenges, and future research directions
Mohammad Wazid, Ashok Kumar Das, Jong-Hyouk Lee
Pervasive Mob. Comput.2
2019 Lightweight and Physically Secure Anonymous Mutual Authentication Protocol for Real-Time Data Access in Industrial Wireless Sensor Networks
abstract
Industrial wireless sensor network (IWSN) is an emerging class of a generalized WSN having constraints of energy consumption, coverage, connectivity, and security. However, security and privacy is one of the major challenges in IWSN as the nodes are connected to Internet and usually located in an unattended environment with minimum human interventions. In IWSN, there is a fundamental requirement for a user to access the real-time information directly from the designated sensor nodes. This task demands to have a user authentication protocol. To satisfy this requirement, this paper proposes a lightweight and privacy-preserving mutual user authentication protocol in which only the user with a trusted device has the right to access the IWSN. Therefore, in the proposed scheme, we considered the physical layer security of the sensor nodes. We show that the proposed scheme ensures security even if a sensor node is captured by an adversary. The proposed protocol uses the lightweight cryptographic primitives, such as one way cryptographic hash function, physically unclonable function, and bitwise exclusive operations. Security and performance analysis shows that the proposed scheme is secure, and is efficient for the resource-constrained sensing devices in IWSN.
Prosanta Gope, Ashok Kumar Das, Neeraj Kumar 0001, Yongqiang Cheng 0001
IEEE Trans. Ind. Informatics2
2019 ECCAuth: A Secure Authentication Protocol for Demand Response Management in a Smart Grid System
abstract
The devices in smart grids (SG) transfer data to a utility center (UC) or to the remote control centers. Using these data, the energy balance is maintained between consumers and the grid. However, this flow of data may be tampered by the intruders, which may result in energy imbalance. Thus, a robust authentication protocol, which supports dynamic SG device validation and UC addition, both in the local and global domains, is an essential requirement. For this reason, ECCAuth: a novel elliptic curve cryptography-based authentication protocol is proposed in this paper for preserving demand response in SG. This protocol allows establishment of a secret session key between an SG device and a UC after mutual authentication. Using this key, they can securely communicate for exchanging the sensitive information. The formal security analysis, informal security analysis, and formal security verification show that ECCAuth can withstand several known attacks.
Neeraj Kumar 0001, Gagangeet Singh Aujla, Ashok Kumar Das, Mauro Conti
IEEE Trans. Ind. Informatics3
2019 Provably Secure Fine-Grained Data Access Control Over Multiple Cloud Servers in Mobile Cloud Computing Based Healthcare Applications
abstract
Mobile cloud computing (MCC) allows mobile users to have on-demand access to cloud services. A mobile cloud model helps in analyzing the information regarding the patients' records and also in extracting recommendations in healthcare applications. In MCC, a fine-grained level access control of multiserver cloud data is a prerequisite for successful execution of end-users applications. In this paper, we propose a new scheme that provides a combined approach of fine-grained access control over cloud-based multiserver data along with a provably secure mobile user authentication mechanism for the Healthcare Industry 4.0. To the best of our knowledge, the proposed scheme is the first to pursue fine-grained data access control over multiple cloud servers in a MCC environment. The proposed scheme has been validated extensively in different heterogeneous environment where its performance was found good in comparison to other existing schemes.
Sandip Roy 0001, Ashok Kumar Das, Santanu Chatterjee, Neeraj Kumar 0001, Samiran Chattopadhyay, Joel J. P. C. Rodrigues
IEEE Trans. Ind. Informatics2
2018 Demand Response Management Using Lattice-Based Cryptography in Smart Grids
abstract
The prolonged usage of non-renewable resources like petroleum and coal have adverse affect on the environment and has led to energy crisis in the world. In order to mitigate the situation, efficient strategies have been proposed for generation, distribution and consumption of energy obtained from renewable sources such as tidal, wind and solar power. With the advent of Smart Grids being developed world wide, the most widely accepted strategy is Demand-Response management. In this strategy, the customers or end-users are incentivized to change their energy-utility behavior with time in response to fluid price changes or to induce lower energy consumption during peak demand time. The system is controlled by a cloud of servers that monitor the demand- supply chain over a network all the time. This brings up the issue of security within the operations of the system. Current security mechanisms such as Rivest-Shamir-Alderman (RSA) public key encryption, Advanced Encryption Standard (AES) symmetric encryption, Elliptic Curve Cryptography (ECC) public-key cryptosytem and the recently proposed works are not future- proof in the world of post-quantum cryptography. This paper proposes a lattice based cryptographic scheme to ensure proper security in the system. The proposed scheme has been proven secure against major known attacks.
Santosh Kumar Desai, Amit Dua, Neeraj Kumar 0001, Ashok Kumar Das, Joel J. P. C. Rodrigues
GLOBECOM4
2018 LaCSys: Lattice-Based Cryptosystem for Secure Communication in Smart Grid Environment
abstract
Smart grid (SG) is a modernized power grid that uses information and communication technologies for bidirectional flow of information between the power utilities and the consumers. Nowadays, the focus of SG has shifted towards intelligent processing and control of various operations in order to provide high quality of experience to the end users domain (consumers, smart devices, utility, etc). Therefore, in near future, for smooth execution of various operations in SG, high volume of data is expected to move across different inter-connected smart devices. So, to handle this challenge, a self-configurable network technology known as software-defined networking (SDN)that provides faster and dynamic forwarding of data through adaptable flow-table management is a viable solution. However, in SDN- enabled SG systems, security and privacy are major challenges that need to be handled effectively. So, in this paper, a lattice-based cryptosystem for secure communication in SG environment, called LaCSys, is presented which works in three phases. In first phase, a secure authentication between all the network communication entities based on lattice based key exchange scheme is designed using a third party auditor (TPA). In second phase, a lightweight lattice-based public-key encryption scheme is designed to provide data confidentiality and integrity. In last phase, a temporary key-based scheme for detection of suspicious activity is designed. The proposed crytosystem is evaluated and compared with existing scheme in order to prove its effectiveness.
Rajat Chaudhary, Gagangeet Singh Aujla, Neeraj Kumar 0001, Ashok Kumar Das, Neetesh Saxena, Joel J. P. C. Rodrigues
ICC4
2018 A new two-server authentication and key agreement protocol for accessing secure cloud services
Durbadal Chattaraj, Monalisa Sarma, Ashok Kumar Das
Comput. Networks3
2018 Taxonomy and analysis of security protocols for Internet of Things
Ashok Kumar Das, Sherali Zeadally, Debiao He
Future Gener. Comput. Syst.1
2018 Biometrics-Based Privacy-Preserving User Authentication Scheme for Cloud-Based Industrial Internet of Things Deployment
abstract
Due to the widespread popularity of Internet-enabled devices, Industrial Internet of Things (IIoT) becomes popular in recent years. However, as the smart devices share the information with each other using an open channel, i.e., Internet, so security and privacy of the shared information remains a paramount concern. There exist some solutions in the literature for preserving security and privacy in IIoT environment. However, due to their heavy computation and communication overheads, these solutions may not be applicable to wide category of applications in IIoT environment. Hence, in this paper, we propose a new biometric-based privacy preserving user authentication (BP2UA) scheme for cloud-based IIoT deployment. BP2UA consists of strong authentication between users and smart devices using preestablished key agreement between smart devices and the gateway node. The formal security analysis of BP2UA using the well-known real-or-random model is provided to prove its session key security. Moreover, an informal security analysis of BP2UA is also given to show its robustness against various types of known attacks. The computation and communication costs of BP2UA in comparison to the other existing schemes of its category demonstrate its effectiveness in the IIoT environment. Finally, the practical demonstration of BP2UA is also done using the NS2 simulation.
Ashok Kumar Das, Mohammad Wazid, Neeraj Kumar 0001, Athanasios V. Vasilakos, Joel J. P. C. Rodrigues
IEEE Internet Things J.1
2018 Chaotic Map-Based Anonymous User Authentication Scheme With User Biometrics and Fuzzy Extractor for Crowdsourcing Internet of Things
abstract
The recent proliferation of mobile devices, such as smartphones and wearable devices has given rise to crowdsourcing Internet of Things (IoT) applications. E-healthcare service is one of the important services for the crowdsourcing IoT applications that facilitates remote access or storage of medical server data to the authorized users (for example, doctors, patients, and nurses) via wireless communication. As wireless communication is susceptible to various kinds of threats and attacks, remote user authentication is highly essential for a hazard-free use of these services. In this paper, we aim to propose a new secure three-factor user remote user authentication protocol based on the extended chaotic maps. The three factors involved in the proposed scheme are: 1) smart card; 2) password; and 3) personal biometrics. As the proposed scheme avoids computationally expensive elliptic curve point multiplication or modular exponentiation operation, it is lightweight and efficient. The formal security verification using the widely-accepted verification tool, called the ProVerif 1.93, shows that the presented scheme is secure. In addition, we present the formal security analysis using the both widely accepted real-or-random model and Burrows-Abadi-Needham logic. With the combination of high security and appreciably low communication and computational overheads, our scheme is very much practical for battery limited devices for the healthcare applications as compared to other existing related schemes.
Sandip Roy 0001, Santanu Chatterjee, Ashok Kumar Das, Samiran Chattopadhyay, Saru Kumari, Minho Jo 0001
IEEE Internet Things J.3
2018 Secure Healthcare Data Dissemination Using Vehicle Relay Networks
abstract
In the recent years, vehicular adhoc networks (VANETs) can be an attractive choice for collecting and transferring the healthcare data of the passengers to the remote healthcare centers. In VANETs, some of the intermediate nodes may act as relay nodes in which case, these networks are called as vehicular relay networks (VRNs). However, the transmitted information in VRNs can be captured by intruders during transmission. Moreover, an attacker can launch selective forwarding, blackhole, and sinkhole attacks in the network, which may in turn degrade the network performance parameters like high end-to-end delay, low packet delivery ratio (PDR) and network throughput. Hence, to address these issues, a secure data dissemination scheme using VRNs is proposed. In the proposed scheme, first, a secure vehicular medical relay network system is designed for the users belonging to disconnected rural areas. The collected information is filtered at zonal levels before transmission to a nearby road side units, which further pass it to the incoming vehicles. Second, a secure passenger health monitoring network is designed which continuously monitors health services of the passengers traveling in different vehicles. The information collected through small body sensors installed in the vehicles act as data sets that is forwarded to the on-board monitoring unit within the vehicle. This collected data is then transmitted to centralized healthcare centers for processing by using VRNs. Lastly, a strong elliptic curve cryptography-based cryptographic solution is designed for secure communication among different vehicles. The performance of the proposed scheme is evaluated in various network scenarios with respect to different selected parameters, such as throughput, network delay, PDR, jitter, transmission and computation overheads, and key distribution overhead. The obtained results indicate that the proposed scheme provides improvement of 52% in average delay and 5% in PDR. This further indicates effective message delivery even with high mobility of the vehicles.
Prabhjot Singh, Rasmeet S. Bali, Neeraj Kumar 0001, Ashok Kumar Das, Alexey V. Vinel, Laurence T. Yang
IEEE Internet Things J.4
2018 Design of Secure User Authenticated Key Management Protocol for Generic IoT Networks
abstract
In recent years, the research in generic Internet of Things (IoT) attracts a lot of practical applications including smart home, smart city, smart grid, industrial Internet, connected healthcare, smart retail, smart supply chain and smart farming. The hierarchical IoT network (HIoTN) is a special kind of the generic IoT network, which is composed of the different nodes, such as the gateway node, cluster head nodes, and sensing nodes organized in a hierarchy. In HIoTN, there is a need, where a user can directly access the real-time data from the sensing nodes for a particular application in generic IoT networking environment. This paper emphasizes on the design of a new secure lightweight three-factor remote user authentication scheme for HIoTNs, called the user authenticated key management protocol (UAKMP). The three factors used in UAKMP are the user smart card, password, and personal biometrics. The security of the scheme is thoroughly analyzed under the formal security in the widely accepted real-or-random model, the informal security as well as the formal security verification using the widely accepted automated validation of Internet security protocols and applications tool. UAKMP offers several functionality features including offline sensing node registration, freely password and biometric update facility, user anonymity, and sensing node anonymity compared to other related existing schemes. In addition, UAKMP is also comparable in computation and communication costs as compared to other existing schemes.
Mohammad Wazid, Ashok Kumar Das, Vanga Odelu, Neeraj Kumar 0001, Mauro Conti, Minho Jo 0001
IEEE Internet Things J.2
2018 Authenticated key management protocol for cloud-assisted body area sensor networks
Mohammad Wazid, Ashok Kumar Das, Athanasios V. Vasilakos
J. Netw. Comput. Appl.2
2018 A provably secure biometrics-based authenticated key agreement scheme for multi-server environments
Saru Kumari, Ashok Kumar Das, Xiong Li 0002, Fan Wu 0003, Muhammad Khurram Khan, Qi Jiang 0001, SK Hafizul Islam
Multim. Tools Appl.2
2018 Secure Biometric-Based Authentication Scheme Using Chebyshev Chaotic Map for Multi-Server Environment
abstract
Multi-server environment is the most common scenario for a large number of enterprise class applications. In this environment, user registration at each server is not recommended. Using multi-server authentication architecture, user can manage authentication to various servers using single identity and password. We introduce a new authentication scheme for multi-server environments using Chebyshev chaotic map. In our scheme, we use the Chebyshev chaotic map and biometric verification along with password verification for authorization and access to various application servers. The proposed scheme is light-weight compared to other related schemes. We only use the Chebyshev chaotic map, cryptographic hash function and symmetric key encryption-decryption in the proposed scheme. Our scheme provides strong authentication, and also supports biometrics & password change phase by a legitimate user at any time locally, and dynamic server addition phase. We perform the formal security verification using the broadly-accepted Automated Validation of Internet Security Protocols and Applications (AVISPA) tool to show that the presented scheme is secure. In addition, we use the formal security analysis using the Burrows-Abadi-Needham (BAN) logic along with random oracle models and prove that our scheme is secure against different known attacks. High security and significantly low computation and communication costs make our scheme is very suitable for multi-server environments as compared to other existing related schemes.
Santanu Chatterjee, Sandip Roy 0001, Ashok Kumar Das, Samiran Chattopadhyay, Neeraj Kumar 0001, Athanasios V. Vasilakos
IEEE Trans. Dependable Secur. Comput.3
2018 Design of Secure and Lightweight Authentication Protocol for Wearable Devices Environment
abstract
Wearable devices are used in various applications to collect information including step information, sleeping cycles, workout statistics, and health-related information. Due to the nature and richness of the data collected by such devices, it is important to ensure the security of the collected data. This paper presents a new lightweight authentication scheme suitable for wearable device deployment. The scheme allows a user to mutually authenticate his/her wearable device(s) and the mobile terminal (e.g., Android and iOS device) and establish a session key among these devices (worn and carried by the same user) for secure communication between the wearable device and the mobile terminal. The security of the proposed scheme is then demonstrated through the broadly accepted real-or-random model, as well as using the popular formal security verification tool, known as the Automated validation of Internet security protocols and applications. Finally, we present a comparative summary of the proposed scheme in terms of the overheads such as computation and communication costs, security and functionality features of the proposed scheme and related schemes, and also the evaluation findings from the NS2 simulation.
Ashok Kumar Das, Mohammad Wazid, Neeraj Kumar 0001, Muhammad Khurram Khan, Kim-Kwang Raymond Choo, Youngho Park 0005
IEEE J. Biomed. Health Informatics1
2018 Providing Healthcare-as-a-Service Using Fuzzy Rule Based Big Data Analytics in Cloud Computing
abstract
With advancements in information and communication technology, there is a steep increase in the remote healthcare applications in which patients can get treatment from the remote places also. The data collected about the patients by remote healthcare applications constitute big data because it varies with volume, velocity, variety, veracity, and value. To process such a large collection of heterogeneous data is one of the biggest challenges which requires a specialized approach. To address this challenge, a new fuzzy rule based classifier is presented in this paper with an aim to provide Healthcare-as-a-Service. The proposed scheme is based upon the initial cluster formation, retrieval, and processing of the big data in cloud environment. Then, a fuzzy rule based classifier is designed for efficient decision making for data classification in the proposed scheme. To perform inferencing from the collected data, membership functions are designed for fuzzification and defuzzification processes. The proposed scheme is evaluated on various evaluation metrics, such as average response time, accuracy, computation cost, classification time, and false positive ratio. The results obtained confirm the effectiveness of the proposed scheme with respect to various performance evaluation metrics in cloud computing environment.
Anish Jindal, Amit Dua, Neeraj Kumar 0001, Ashok Kumar Das, Athanasios V. Vasilakos, Joel J. P. C. Rodrigues
IEEE J. Biomed. Health Informatics4
2018 A Novel Authentication and Key Agreement Scheme for Implantable Medical Devices Deployment
abstract
Implantable medical devices (IMDs) are man-made devices, which can be implanted in the human body to improve the functioning of various organs. The IMDs monitor and treat physiological condition of the human being (for example, monitoring of blood glucose level by insulin pump). The advancement of information and communication technology enhances the communication capabilities of IMDs. In healthcare applications, after mutual authentication, a user (for example, doctor) can access the health data from the IMDs implanted in a patient's body. However, in this kind of communication environment, there are always security and privacy issues, such as leakage of health data and malfunctioning of IMDs by an unauthorized access. To mitigate these issues, in this paper, we propose a new secure remote user authentication scheme for IMDs communication environment to overcome security and privacy issues in existing schemes. We provide the formal security verification using the widely accepted Automated Validation of Internet Security Protocols and Applications tool. We also provide the informal security analysis of the proposed scheme. The formal security verification and informal security analysis prove that the proposed scheme is secure against known attacks. The practical demonstration of the proposed scheme is performed using the broadly accepted NS2 simulation tool. The computation and communication costs of the proposed scheme are also comparable with the existing schemes. Moreover, the scheme provides additional functionality features, such as anonymity, untraceability, and dynamic implantable medical device addition.
Mohammad Wazid, Ashok Kumar Das, Neeraj Kumar 0001, Mauro Conti, Athanasios V. Vasilakos
IEEE J. Biomed. Health Informatics2
2018 Attribute-based authentication on the cloud for thin clients
Maged Hamada Ibrahim, Saru Kumari, Ashok Kumar Das, Vanga Odelu
J. Supercomput.3
2018 A secure authentication scheme based on elliptic curve cryptography for IoT and cloud servers
Saru Kumari, Marimuthu Karuppiah, Ashok Kumar Das, Xiong Li 0002, Fan Wu 0003, Neeraj Kumar 0001
J. Supercomput.3
2017 On the design of a secure user authentication and key agreement scheme for wireless sensor networks
abstract
Summary A wireless sensor network (WSN) typically consists of a large number of resource‐constrained sensor nodes and several control or gateway nodes. Ensuring the security of the asymmetric nature of WSN is challenging, and designing secure and efficient user authentication and key agreement schemes for WSNs is an active research area. For example, in 2016, Farash et al. proposed a user authentication and key agreement scheme for WSNs. However, we reveal previously unpublished vulnerabilities in their scheme, which allow an attacker to carry out sensor node spoofing, password guessing, user/sensor node anonymity, and user impersonation attacks. We then present a scheme, which does not suffer from the identified vulnerabilities. To demonstrate the practicality of the scheme, we evaluate the scheme using NS‐2 simulator. We then prove the scheme secure using Burrows–Abadi–Needham logic. Copyright © 2016 John Wiley & Sons, Ltd.
Saru Kumari, Ashok Kumar Das, Mohammad Wazid, Xiong Li 0002, Fan Wu 0003, Kim-Kwang Raymond Choo, Muhammad Khurram Khan
Concurr. Comput. Pract. Exp.2
2017 Graphs and digraphs represented by intervals and circular arcs
Ashok Kumar Das, Ritapa Chakraborty
Discret. Appl. Math.1
2017 Design of a provably secure biometrics-based multi-cloud-server authentication scheme
Saru Kumari, Xiong Li 0002, Fan Wu 0003, Ashok Kumar Das, Kim-Kwang Raymond Choo, Jian Shen 0001
Future Gener. Comput. Syst.4
2017 Provably secure authenticated key agreement scheme for distributed mobile cloud computing services
Vanga Odelu, Ashok Kumar Das, Saru Kumari, Xinyi Huang 0001, Mohammad Wazid
Future Gener. Comput. Syst.2
2017 Robust Anonymous Mutual Authentication Scheme for n-Times Ubiquitous Mobile Cloud Computing Services
abstract
In recent years, mobile computing has gained a huge popularity among mobile users (MUs). It basically combines the mobile devices with the cloud computing. By the means of on-demand self-service and extendibility, it can offer the infrastructures, platform, entertainments, and software services in a cloud to MUs through the mobile network. However, offering secure access to these services by preserving the privacy of the MU is indeed a challenge for any mobile cloud service provider. In this paper, we aim to propose a new robust anonymous mutual authentication scheme for mobile cloud environment. Through this scheme, both the MU and the service cloud need to prove their legitimacy, and it eventually helps the legitimate mobile cloud user to enjoy n times all the ubiquitous services in a secure and efficient way, where the value of n may differ based on the principal he/she has paid for. The security of the proposed scheme is thoroughly analyzed using both formal as well as informal security analysis. Furthermore, functionality and performance comparisons using the testbed simulation among the proposed scheme and other existing relevant schemes reveal that the proposed scheme outperforms other existing schemes.
Prosanta Gope, Ashok Kumar Das
IEEE Internet Things J.2
2017 Secure Authentication Scheme for Medicine Anti-Counterfeiting System in IoT Environment
abstract
A counterfeit drug is a medication or pharmaceutical product which is manufactured and made available on the market to deceptively represent its origin, authenticity and effectiveness, etc., and causes serious threats to the health of a patient. Counterfeited medicines have an adverse effect on the public health and cause revenue loss to the legitimate manufacturing organizations. In this paper, we propose a new authentication scheme for medicine anticounterfeiting system in the Internet of Things environment which is used for checking the authenticity of pharmaceutical products (dosage forms). The proposed scheme utilizes the near field communication (NFC) and is suitable for mobile environment, which also provides efficient NFC update phase. The security analysis using the widely accepted real-or-random model proves that the proposed scheme provides the session key security. The proposed scheme also protects other known attacks which are analyzed informally. Furthermore, the formal security verification using the broadly accepted automated validation of Internet security protocols and applications tool shows that the proposed scheme is secure. The scheme is efficient with respect to computation and communication costs, and also it provides additional functionality features when compared to other existing schemes. Finally, for demonstration of the practicality of the scheme, we evaluate it using the broadly accepted NS2 simulation.
Mohammad Wazid, Ashok Kumar Das, Muhammad Khurram Khan, Abdulatif Al-Dhawailie Al-Ghaiheb, Neeraj Kumar 0001, Athanasios V. Vasilakos
IEEE Internet Things J.2
2017 An efficient authentication and key agreement scheme for multi-gateway wireless sensor networks in IoT deployment
Fan Wu 0003, Saru Kumari, Xiong Li 0002, Jian Shen 0001, Kim-Kwang Raymond Choo, Mohammad Wazid, Ashok Kumar Das
J. Netw. Comput. Appl.8
2017 Secure Three-Factor User Authentication Scheme for Renewable-Energy-Based Smart Grid Environment
abstract
Smart grid (SG) technology has recently received significant attention due to its usage in maintaining demand response management in power transmission systems. In SG, charging of electric vehicles becomes one of the emerging applications. However, authentication between a vehicle user and a smart meter is required so that both of them can securely communicate for managing demand response during peak hours. To address the above mentioned issues, in this paper, we propose a new efficient three-factor user authentication scheme for a renewable energy-based smart grid environment (TUAS-RESG), which uses the lightweight cryptographic computations such as one-way hash functions, bitwise XOR operations, and elliptic curve cryptography. The detailed security analysis shows the robustness of TUAS-RESG against various well-known attacks. Moreover, TUAS-RESG provides superior security with additional features, such as dynamic smart meter addition, flexibility for password and biometric update, user and smart meter anonymity, and untraceability as compared to other related existing schemes. The practical demonstration of TUAS-RESG is also proved using the widely accepted NS2 simulation.
Mohammad Wazid, Ashok Kumar Das, Neeraj Kumar 0001, Joel J. P. C. Rodrigues
IEEE Trans. Ind. Informatics2
2016 An Enhanced Anonymous Two-factor Mutual Authentication with Key-agreement Scheme for Session Initiation Protocol
abstract
A two-factor authenticated key-agreement scheme for session initiation protocol emerged as a best remedy to overcome the ascribed limitations of the password-based authentication scheme. Recently, Lu et al. proposed an anonymous two-factor authenticated key-agreement scheme for SIP using elliptic curve cryptography. They claimed that their scheme is secure against attacks and achieves user anonymity. Conversely, this paper's keen analysis points out several severe security weaknesses of the Lu et al.'s scheme. In addition, this paper puts forward an enhanced anonymous two-factor mutual authenticated key-agreement scheme for session initiation protocol using elliptic curve cryptography. The security analysis and performance analysis sections demonstrates that the proposed scheme is more robust and efficient than Lu et al.'s scheme.
Goutham Reddy Alavalapati, Eun-Jun Yoon, Ashok Kumar Das, Kee-Young Yoo
SIN3
2016 An efficient fast algorithm for discovering closed+ high utility itemsets
Jayakrushna Sahoo, Ashok Kumar Das, Adrijit Goswami
Appl. Intell.2
2016 A user friendly mutual authentication and key agreement scheme for wireless sensor networks using chaotic maps
Saru Kumari, Xiong Li 0002, Fan Wu 0003, Ashok Kumar Das, Hamed Arshad, Muhammad Khurram Khan
Future Gener. Comput. Syst.4
2016 Lightweight authentication with key-agreement protocol for mobile network environment using smart cards
abstract
In 2012, Mun et al . proposed an enhanced secure authentication with key‐agreement protocol for roaming service in global mobility networks environment based on elliptic curve cryptography. They claimed that their protocol is efficient and resistant to prominent security attacks. The careful analysis of this study proves that Mun et al . 's protocol is susceptible to several attacks such as replay attack, man‐in‐middle attack, user impersonation attack, privileged insider attack, denial‐of‐service attack, no login phase and imperfect mutual authentication phase. In addition, this study proposes an enhanced lightweight authentication with key‐agreement protocol for mobile networks based on elliptic curve cryptography using smart cards. The proposed protocol is lightweight and perfectly suitable for real‐time applications as it accomplishes simple one‐way hash function, message authentication code and exclusive‐OR operation. Furthermore, it achieves all the eminent security properties and is resistant to various possible attacks. The security analysis and comparison section demonstrates that the proposed protocol is robust compared with Mun et al . 's protocol.
Goutham Reddy Alavalapati, Eun-Jun Yoon, Ashok Kumar Das, Kee-Young Yoo
IET Inf. Secur.3
2016 Design of a secure smart card-based multi-server authentication scheme
Ankita Chaturvedi, Ashok Kumar Das, Dheerendra Mishra, Sourav Mukhopadhyay
J. Inf. Secur. Appl.2
2016 Single round-trip SIP authentication scheme with provable security for Voice over Internet Protocol using smart card
Saru Kumari, Fan Wu 0003, Xiong Li 0002, Mohammad Sabzinejad Farash, Qi Jiang 0001, Muhammad Khurram Khan, Ashok Kumar Das
Multim. Tools Appl.7
2016 A secure and robust temporal credential-based three-factor user authentication scheme for wireless sensor networks
Ashok Kumar Das
Peer-to-Peer Netw. Appl.1
2016 A secure and efficient ECC-based user anonymity-preserving session initiation authentication protocol using smart card
Dheerendra Mishra, Ashok Kumar Das, Sourav Mukhopadhyay
Peer-to-Peer Netw. Appl.2
2016 Provably secure three-factor authentication and key agreement scheme for session initiation protocol
abstract
Abstract Session initiation protocol (SIP) is a widely used authentication protocol for the Voice over IP communications. Over the years, several protocols have been proposed in the literature to strengthen the security of SIP. In this paper, we present an efficient elliptic curve cryptography (ECC)‐based provably secure three‐factor authentication and session key agreement scheme for SIP, which uses the identity, password, and personal biometrics of a user as three factors. Our scheme aims to resolve the security weaknesses and drawbacks in existing SIP authentication protocols. In addition, our scheme supports password and biometric update phase without involving the server and the user mobile device revocation phase in case the mobile device is lost/stolen. Formal security analysis under the standard model and the broadly accepted Burrows–Abadi–Needham logic ensures that the proposed scheme can withstand several known security attacks. The proposed scheme has also been analyzed informally. Simulation for formal security verification using the widely known automated validation of internet security protocols and applications tool shows the replay, and the man‐in‐the‐middle attacks are protected by the scheme. High security and low communication and computation costs make the proposed scheme more suitable for practical application as compared with other existing related ECC‐based schemes. Copyright © 2016 John Wiley & Sons, Ltd.
Sravani Challa, Ashok Kumar Das, Saru Kumari, Vanga Odelu, Fan Wu 0003, Xiong Li 0002
Secur. Commun. Networks2
2016 Provably secure user authentication and key agreement scheme for wireless sensor networks
abstract
In recent years, user authentication has emerged as an interesting field of research in wireless sensor networks. Most recently, in 2016, Chang and Le presented a scheme to authenticate the users in wireless sensor network using a password and smart card. They proposed two protocols and . is based on exclusive or (XOR) and hash functions, while deploys elliptic curve cryptography in addition to the two functions used in . Although their protocols are efficient, we point out that both and are vulnerable to session specific temporary information attack and offline password guessing attack, while is also vulnerable to session key breach attack. In addition, we show that both the protocols and are inefficient in authentication and password change phases. To withstand these weaknesses found in their protocols, we aim to design a new authentication and key agreement scheme using elliptic curve cryptography. Rigorous formal security proofs using the broadly accepted, the random oracle models, and the Burrows–Abadi–Needham logic and verification using the well-known Automated Validation of Internet Security Protocols and Applications tool are preformed on our scheme. The analysis shows that our designed scheme has the ability to resist a number of known attacks comprising those found in both Chang–Le's protocols. Copyright © 2016 John Wiley & Sons, Ltd.
Ashok Kumar Das, Saru Kumari, Vanga Odelu, Xiong Li 0002, Fan Wu 0003, Xinyi Huang 0001
Secur. Commun. Networks1
2016 An efficient multi-gateway-based three-factor user authentication and key agreement scheme in hierarchical wireless sensor networks
abstract
Abstract User authentication in wireless sensor network (WSN) plays a very important role in which a legal registered user is allowed to access the real‐time sensing information from the sensor nodes inside WSN. To allow such access, a user needs to be authenticated by the accessed sensor nodes as well as gateway nodes inside WSNs. Because of resource limitations and vulnerability to physical capture of some sensor nodes by an attacker, design of a secure user authentication in WSN continues to be an important and challenging research area in recent years. In this paper, we propose a new three‐factor user authentication scheme based on the multi‐gateway WSN architecture. Through the widely‐accepted Burrows–Abadi–Needham logic, we prove that our scheme provides the secure mutual authentication. We then present the formal security verification of our proposed scheme using AVISPA tool, which is a powerful validation tool for network security applications, and show that our scheme is secure. In addition, the rigorous informal security analysis shows that our scheme is also secure against possible other known attacks including the sensor node capture attack. Furthermore, we present the additional functionality features that our scheme offers, which are efficient in communication and computation. Copyright © 2016 John Wiley & Sons, Ltd.
Ashok Kumar Das, Anil Kumar Sutrala, Saru Kumari, Vanga Odelu, Mohammad Wazid, Xiong Li 0002
Secur. Commun. Networks1
2016 Jamming resistant non-interactive anonymous and unlinkable authentication scheme for mobile satellite networks
abstract
Abstract Most of the previously proposed schemes use temporary identities for mobile users to provide unlinkable anonymous authentication for mobile users to the satellite network control center (NCC), where the temporary identities are picked at random after each session and agreed between a mobile user U and the NCC for the next session. Although such schemes provide full anonymity and are computationally efficient, the common problem with such strategies is that an adversary is able to desynchronize the temporary identity shared between U and NCC by means of simple jamming attack at a certain round in the authentication protocol. It results in the denial of all future sessions unless U re‐registers a new identity at the NCC. In this paper, we propose a new authentication scheme for mobile satellite networks. We avoid using synchronized temporary identities, which are always vulnerable to desynchronization attacks. We also avoid multi‐round authentication phase in order to reduce the jamming effect. Instead, a mobile user is able to create a new blinded version of his clear identity for each established session noninteractively, allowing him to anonymously authenticate himself to NCC in a fully unlinkable fashion. Moreover, in few milliseconds and one move non‐interactive way, U is able to establish a session key with NCC in a fully anonymous and authenticated way. Our new scheme uses recent advances in elliptic curve cryptography, and hence, it is efficient for implementation on mobile devices with limited resources. Through the rigorous security analysis using the broadly accepted Burrows–Abadi–Needham logic, informal security analysis, and the simulation for formal security verification using the widely known automated validation of Internet security protocols and sapplications tool, we show that our scheme is secure against various known attacks. Copyright © 2017 John Wiley & Sons, Ltd.
Maged Hamada Ibrahim, Saru Kumari, Ashok Kumar Das, Vanga Odelu
Secur. Commun. Networks3
2016 Design of a provably secure identity-based digital multi-signature scheme using biometrics and fuzzy extractor
abstract
A novel biometric identity-based digital multi-signature BIO-IDMS scheme is put forwarded in this paper. The proposed scheme is constructed with the help of fuzzy extractor and elliptic curve bilinear pairings. Furthermore, we designed the formal model and the security model of the proposed BIO-IDMS scheme. The formal security analysis demonstrates that the forgery of the proposed scheme is infeasible in the random oracle model based on the intractability assumption of the computational Diffie-Hellman CDH problem. The proposed scheme outperforms in terms of computational cost compared with other related existing multi-signature schemes. Copyright © 2016 John Wiley & Sons, Ltd.
SK Hafizul Islam, Ashok Kumar Das, Muhammad Khurram Khan
Secur. Commun. Networks2
2016 A secure lightweight authentication scheme with user anonymity for roaming service in ubiquitous networks
abstract
Abstract Ubiquitous networks provide effective roaming services for mobile users (MUs). Through the worldwide roaming technology, authorized MUs can avail ubiquitous network services. Important security issues to be considered in ubiquitous networks are authentication of roaming MUs and protection of privacy of MUs. However, because of the broadcast nature of wireless channel and resource limitations of terminals, providing efficient user authentication with privacy preservation is a challenging task. Very recently, Farash et al. proposed an authentication scheme with anonymity for consumer roaming in ubiquitous networks and claimed their scheme achieves all security requirements. In this paper, we show that the scheme of Farash et al. fails to achieve user anonymity and mutual authentication. Their scheme also fails to provide local password verification, and it has a faulty password change phase. Moreover, their scheme is vulnerable to replay, offline password guessing, and forgery attacks. To fix the security flaws of the scheme of Farash et al., we present an improved authentication scheme for accessing roaming service provided by ubiquitous networks. We then formally verify the security properties of our scheme by the widely‐accepted push‐button tool called Automated Validation of Internet Security Protocols and Applications. Security and performance analyses show that our scheme is more powerful, efficient, and secure when it is compared with existing schemes. Copyright © 2016 John Wiley & Sons, Ltd.
Marimuthu Karuppiah, Saru Kumari, Ashok Kumar Das, Xiong Li 0002, Fan Wu 0003, Sayantani Basu
Secur. Commun. Networks3
2016 An enhanced and secure trust-extended authentication mechanism for vehicular ad-hoc networks
abstract
Abstract Vehicular Ad‐hoc Networks (VANETs) are a move towards regulating safe traffic and intelligent transportation system. A VANETs is characterized by extremely dynamic topographical conditions owing to speedily moving vehicles. In VANETs, vehicles can transmit messages within a pre‐defined area to achieve safety and efficiency of the system. Then ensuring authenticity of origin of messages to the receiver in such a dynamic environment is a crucial challenge. Another concern in VANET is preservation of privacy of user/vehicle. Recently, Chuang and Lee proposed a trust‐extended authentication mechanism (TEAM) for vehicle‐to‐vehicle communications in VANETs. TEAM not only satisfies various security features but also enhances the performance of the authentication process using transitive trust relationship among vehicles. Nonetheless, our analysis shows that TEAM is vulnerable to insider attack, privacy breach, impersonation attacks and some other problems. In this paper, to eradicate the vulnerabilities found in Chuang‐Lee's scheme, an enhanced trust‐extended authentication scheme for VANET is proposed. We display the efficiency of our scheme through security analysis and comparison. Through simulation results using widely accepted NS‐2 simulator, we show that our scheme authenticates vehicles faster than Chuang‐Lee's scheme. Copyright © 2016 John Wiley & Sons, Ltd.
Saru Kumari, Marimuthu Karuppiah, Xiong Li 0002, Fan Wu 0003, Ashok Kumar Das, Vanga Odelu
Secur. Commun. Networks5
2016 An anonymous and secure biometric-based enterprise digital rights management system for mobile environment
abstract
In 1 the authorship was originally shown as “Ashok Kumar Das, Dheerendra Mishra and Sourav Mukhopadhyay”. This has now been corrected to “Dheerendra Mishra, Ashok Kumar Das and Sourav Mukhopadhyay”. We apologize for any inconvenience caused.
Dheerendra Mishra, Ashok Kumar Das, Sourav Mukhopadhyay
Secur. Commun. Networks2
2016 Design of a new CP-ABE with constant-size secret keys for lightweight devices using elliptic curve cryptography
abstract
Abstract The energy cost of public‐key cryptography is a vital component of modern secure communications. It inhibits the widespread adoption within the ultra‐low energy regimes (for example, implantable medical devices and Radio Frequency Identification tags). In the ciphertext‐policy attribute‐based encryption (CP‐ABE), an encryptor can decide the access policy that who can decrypt the data. Thus, data will be protected from the unauthorized users. However, most of the existing CP‐ABE schemes require huge storage and computational overheads. Moreover, CP‐ABE schemes based on bilinear map loose high efficiency over the elliptic curve cryptography because of the requirement of the security parameters of larger size. These drawbacks prevent the use of ultra‐low energy devices in practice. In this paper, we aim to propose a novel expressive AND gate access structured CP‐ABE scheme with constant‐size secret keys (CSSK) with cost‐efficient solutions for encryption and decryption using elliptic curve cryptography, called the CP‐ABE‐CSSK scheme. In the proposed CP‐ABE‐CSSK, the size of the secret key is as small as 320 bits. In addition, elliptic curve cryptography is efficient and more suitable for lightweight devices as compared with bilinear pairing‐based cryptosystem. Thus, the proposed CP‐ABE‐CSSK scheme provides low computation and storage overheads with an expressive AND gate access structure as compared with related existing schemes. Consequently, our scheme becomes very practical for CP‐ABE key storage and computation cost for ultra‐low energy devices. Copyright © 2016 John Wiley & Sons, Ltd.
Vanga Odelu, Ashok Kumar Das
Secur. Commun. Networks2
2016 Design of sinkhole node detection mechanism for hierarchical wireless sensor networks
abstract
Abstract Wireless sensor networks (WSNs) have several applications ranging from the civilian to military applications. WSNs are prone to various hole attacks, such as sinkhole, wormhole, blackhole, and greyhole. Among these hole attacks, the sinkhole attack is the malignant one. A sinkhole attack allows a malicious node, called the sinkhole node, advertises a best possible path to the base station (BS). This misguides its neighbors to utilize that path more frequently. The sinkhole node has the opportunity to tamper with the data, and it also performs the modifications in messages or it drops messages or it produces unnecessary delay before forwarding them to the BS. On the basis of these malicious acts that are performed by a sinkhole attacker node, we consider three types of malicious nodes in a WSN: sinkhole message modification node (SMD), sinkhole message dropping node (SDP), and sinkhole message delay node (SDL). None of the existing techniques in the literature is capable to handle all three types of nodes at a time. This paper presents a new detection scheme for the detection of different types of sinkhole nodes for a hierarchical wireless sensor network (HWSN). To the best of our knowledge, this is the first attempt to design such a detection scheme in HWSNs which can detect SMD, SDP, and SDL nodes. In our approach, the entire HWSN is divided into several disjoint clusters, and each cluster has a powerful high‐end sensor node (called a cluster head), which is responsible for the detection of different sinkhole attacker nodes if present in that cluster. We simulate our scheme using the widely‐accepted NS2 simulator for measurement of various network parameters. The proposed scheme achieves around 95%detection rate and 1.25%false positive rate. These factors are significantly better than the previous related schemes. Furthermore, the computation and communication efficiency is achieved in our scheme. As a result, our scheme seems suitable for the sensitive critical applications, such as military applications. Copyright © 2016 John Wiley & Sons, Ltd.
Mohammad Wazid, Ashok Kumar Das, Saru Kumari, Muhammad Khurram Khan
Secur. Commun. Networks2
2016 Design of an efficient and provably secure anonymity preserving three-factor user authentication and key agreement scheme for TMIS
abstract
Abstract Several remote user authentication techniques for telecare medicine information system (TMIS) have been proposed in the literature. But most existing techniques have limitations such as vulnerable to various attacks, lack of functionalities, and inefficiency. Recently, Amin and Biswas proposed a three‐factor authentication and key agreement technique for TMIS. But their scheme is inefficient and has several security drawbacks. The attacks such as privileged‐insider, user impersonation, and strong reply attacks are possible on their scheme. It also has flaw in password update phase. In order to overcome drawbacks of their scheme, a new provably secure and efficient three‐factor remote user authentication scheme for TMIS is proposed in this paper. The proposed scheme overcomes all drawbacks of their scheme and also provides additional features such as user unlinkability, user anonymity, efficient password, and biometric update. The rigorous informal and formal security analysis using random oracle models and the mostly acceptable Automated Validation of Internet Security Protocols and Applications tool is also performed. During the experimentation, it has been observed that the proposed scheme is secure against various known attacks that include replay and man‐in‐the‐middle attacks. Furthermore, the analysis of computation and communication cost estimation of the proposed scheme depicts that our scheme is efficient as compared with other related exiting schemes. Copyright © 2016 John Wiley & Sons, Ltd.
Mohammad Wazid, Ashok Kumar Das, Saru Kumari, Xiong Li 0002, Fan Wu 0003
Secur. Commun. Networks2
2016 Provably secure biometric-based user authentication and key agreement scheme in cloud computing
abstract
Abstract Cloud computing, the conjoin of many types of computing, has made a great impact on the life of everyone. People from anywhere can access the different cloud‐based services by using the Internet. A user, who wants to access some cloud‐based service, needs to register himself/herself to an authority (service provider), and after that, he/she can use the service. To access the service, each user needs to authenticate to that particular cloud server. Several user authentication schemes for cloud computing have been presented but mostly have limitations/drawbacks as they are prone to various known attacks, such as privileged insider, user and server impersonation, and strong reply attacks, and they also have lack of functionality features. Moreover, these schemes do not provide efficient password change phase. In order to overcome these drawbacks, we propose a new provably secure biometric‐based user authentication and key agreement scheme for cloud computing. The proposed scheme overcomes the weaknesses of the existing schemes and supports extra functionality features including user anonymity and efficient password and biometric update phase for multi‐server environment. The careful formal security analysis under standard model and informal security analysis and the simulation results for formal security verification using the most acceptable AVISPA tool show that the proposed scheme is secure against various known possible attacks. The analysis of computation and communication overheads of our scheme depicts its efficiency over other related existing schemes, and thus, the proposed scheme is suitable for the cloud computing environment. Copyright © 2016 John Wiley & Sons, Ltd.
Mohammad Wazid, Ashok Kumar Das, Saru Kumari, Xiong Li 0002, Fan Wu 0003
Secur. Commun. Networks2
2016 A novel and provably secure authentication and key agreement scheme with user anonymity for global mobility networks
abstract
Ubiquitous networks support the roaming service for mobile communication devices. The mobile user can use the services in the foreign network with the help of the home network. Mutual authentication plays an important role in the roaming services, and researchers put their interests on the authentication schemes. Recently, in 2016, Gope and Hwang found that mutual authentication scheme of He et al. for global mobility networks had security disadvantages such as vulnerability to forgery attacks, unfair key agreement, and destitution of user anonymity. Then, they presented an improved scheme. However, we find that the scheme cannot resist the off-line guessing attack and the de-synchronization attack. Also, it lacks strong forward security. Moreover, the session key is known to HA in that scheme. To get over the weaknesses, we propose a new two-factor authentication scheme for global mobility networks. We use formal proof with random oracle model, formal verification with the tool Proverif, and informal analysis to demonstrate the security of the proposed scheme. Compared with some very recent schemes, our scheme is more applicable. Copyright © 2016 John Wiley & Sons, Ltd.
Fan Wu 0003, Saru Kumari, Xiong Li 0002, Ashok Kumar Das, Muhammad Khurram Khan, Marimuthu Karuppiah, Renuka Baliyan
Secur. Commun. Networks5
2015 An efficient approach for mining association rules from high utility itemsets
Jayakrushna Sahoo, Ashok Kumar Das, Adrijit Goswami
Expert Syst. Appl.2
2015 A secure password-based authentication and key agreement scheme using smart cards
Dheerendra Mishra, Ashok Kumar Das, Ankita Chaturvedi, Sourav Mukhopadhyay
J. Inf. Secur. Appl.2
2015 An efficient ECC-based privacy-preserving client authentication protocol with key agreement using smart card
Vanga Odelu, Ashok Kumar Das, Adrijit Goswami
J. Inf. Secur. Appl.2
2015 An effective association rule mining scheme using a new generic basis
Jayakrushna Sahoo, Ashok Kumar Das, Adrijit Goswami
Knowl. Inf. Syst.2
2015 An effective ECC-based user access control scheme with attribute-based encryption for wireless sensor networks
abstract
Abstract For critical applications, real‐time data access is essential from the nodes inside a wireless sensor network (WSN). Only the authorized users with unique access privilege should access the specific, but not all, sensing information gathered by the cluster heads in a hierarchical WSNs. Access rights for the correct information and resources for different services from the cluster heads to the genuine users can be provided with the help of efficient user access control mechanisms. In this paper, we propose a new user access control scheme with attribute‐based encryption using elliptic curve cryptography in hierarchical WSNs. In attribute‐based encryption, the ciphertexts are labeled with sets of attributes and secret keys of the users that are associated with their own access structures. The authorized users with the relevant set of attributes can able to decrypt the encrypted message coming from the cluster heads. Our scheme provides high security. Moreover, our scheme is efficient as compared with those for other existing user access control schemes. Through both the formal and informal security analysis, we show that our scheme has the ability to tolerate different known attacks required for a user access control designed for WSNs. Furthermore, we simulate our scheme for the formal security verification using the widely‐accepted automated validation of Internet security protocols and applications tool. The simulation results demonstrate that our scheme is secure. Copyright © 2014 John Wiley & Sons, Ltd.
Santanu Chatterjee, Ashok Kumar Das
Secur. Commun. Networks2
2015 An anonymous and secure biometric-based enterprise digital rights management system for mobile environment
abstract
Abstract Internet‐based content distribution facilitates an efficient platform to sell the digital content to the remote users. However, the digital content can be easily copied and redistributed over the network, which causes huge loss to the right holders. On the contrary, the digital rights management (DRM) systems have been introduced in order to regulate authorized content distribution. Enterprise DRM (E‐DRM) system is an application of DRM technology, which aims to prevent illegal access of data in an enterprise. Earlier works on E‐DRM do not address anonymity, which may lead to identity theft. Recently, Chang et al. proposed an efficient E‐DRM mechanism. Their scheme provides greater efficiency and protects anonymity. Unfortunately, we identify that their scheme does not resist the insider attack and password‐guessing attack. In addition, Chang et al.'s scheme has some design flaws in the authorization phase. We then point out the requirements of E‐DRM system and present the cryptanalysis of Chang et al.'s scheme. In order to remedy the security weaknesses found in Chang et al.'s scheme, we aim to present a secure and efficient E‐DRM scheme. The proposed scheme supports the authorized content key distribution and satisfies the desirable security attributes. Additionally, our scheme offers low communication and computation overheads and user's anonymity as well. Through the rigorous formal and informal security analyses, we show that our scheme is secure against possible known attacks. Furthermore, the simulation results for the formal security analysis using the widely accepted Automated Validation of Internet Security Protocols and Applications tool ensure that our scheme is also secure. Copyright © 2015 John Wiley & Sons, Ltd.
Ashok Kumar Das, Dheerendra Mishra, Sourav Mukhopadhyay
Secur. Commun. Networks1
2015 A secure and efficient ECC-based user anonymity preserving single sign-on scheme for distributed computer networks
abstract
Abstract A user authentication in the distributed computer networks (DCNs) plays a crucial rule to verify whether the user is a legal user and can therefore be granted access to the requested services to that user. In recent years, several RSA‐based single sign‐on mechanisms have been proposed in DCNs. However, most of them cannot preserve the user anonymity when possible attacks occur. The user devices are usually battery limited (e.g., cellular phones) and the elliptic‐curve cryptosystem is much efficient than RSA cryptosystem for the battery‐limited devices. In this paper, we aim to propose a new secure elliptic‐curve cryptosystem‐based single sign‐on mechanism for user authentication and key establishment for the secure communications in a DCNs using biometric‐based smart card. In our scheme, a user only needs to remember a private password and his or her selected unique identity to authenticate and agree on a high‐entropy cryptographic one‐time session key with a provider to communicate over untrusted public networks. Through formal and informal security analysis, we show that our scheme prevents other known possible attacks. In addition, we perform simulation on our scheme for the formal security verification using the widely‐accepted Automated Validation of Internet Security Protocols and Applications tool. The simulation results ensure that our scheme is secure against replay and man‐in‐the‐middle attacks. Furthermore, our scheme provides high security along with lower computational cost and communication cost, and as a result, our scheme is much suitable for the battery‐limited devices as compared to other related RSA‐based schemes. Copyright © 2014 John Wiley & Sons, Ltd.
Vanga Odelu, Ashok Kumar Das, Adrijit Goswami
Secur. Commun. Networks2
2015 An efficient biometric-based privacy-preserving three-party authentication with key agreement protocol using smart cards
abstract
Abstract In communication systems, authentication protocols play an important role in protecting sensitive information against a malicious adversary by means of providing a variety of services such as mutual authentication, user credentials' privacy, and user revocation facility when the smart card of the user is lost/stolen or user's authentication parameters are revealed. Recently, several three‐party authentication with key agreement (3PAKA) schemes are proposed in the literature, but most of them do not provide the basic security requirements such as user anonymity as well as user revocation and re‐registration with the same identity. Thus, we feel that there is a great need to design a secure 3PAKA scheme with these security properties. In this paper, we propose a new secure biometric‐based privacy‐preserving 3PAKA scheme using the elliptic curve cryptography with efficient mechanism for the user revocation and re‐registration with the same identity. The formal security analysis using the widely accepted Burrows–Abadi–Needham logic shows that our scheme provides secure authentication. In addition, we simulate our scheme for the formal security verification using the widely accepted Automated Validation of Internet Security Protocols and Applications tool. The simulation results show that our scheme is secure against passive and active attacks. Furthermore, our scheme is efficient as compared with other related schemes. Our scheme provides high security along with low computation and communication costs, and extra features as compared with other related existing schemes in the literature, and as a result, our scheme is suitable for battery‐limited mobile devices. Copyright © 2015 John Wiley & Sons, Ltd.
Vanga Odelu, Ashok Kumar Das, Adrijit Goswami
Secur. Commun. Networks2
2015 A Secure Biometrics-Based Multi-Server Authentication Protocol Using Smart Cards
abstract
Recently, in 2014, He and Wang proposed a robust and efficient multi-server authentication scheme using biometrics-based smart card and elliptic curve cryptography (ECC). In this paper, we first analyze He-Wang's scheme and show that their scheme is vulnerable to a known session-specific temporary information attack and impersonation attack. In addition, we show that their scheme does not provide strong user's anonymity. Furthermore, He-Wang's scheme cannot provide the user revocation facility when the smart card is lost/stolen or user's authentication parameter is revealed. Apart from these, He-Wang's scheme has some design flaws, such as wrong password login and its consequences, and wrong password update during password change phase. We then propose a new secure multi-server authentication protocol using biometric-based smart card and ECC with more security functionalities. Using the Burrows-Abadi-Needham logic, we show that our scheme provides secure authentication. In addition, we simulate our scheme for the formal security verification using the widely accepted and used automated validation of Internet security protocols and applications tool, and show that our scheme is secure against passive and active attacks. Our scheme provides high security along with low communication cost, computational cost, and variety of security features. As a result, our scheme is very suitable for battery-limited mobile devices as compared with He-Wang's scheme.
Vanga Odelu, Ashok Kumar Das, Adrijit Goswami
IEEE Trans. Inf. Forensics Secur.2
2014 A secure user anonymity-preserving biometric-based multi-server authenticated key agreement scheme using smart cards
Dheerendra Mishra, Ashok Kumar Das, Sourav Mukhopadhyay
Expert Syst. Appl.2
2014 A secure effective key management scheme for dynamic access control in a large leaf class hierarchy
Vanga Odelu, Ashok Kumar Das, Adrijit Goswami
Inf. Sci.2
2012 Cryptanalysis and improvement of an access control in user hierarchy based on elliptic curve cryptosystem
Ashok Kumar Das, Nayan Ranjan Paul, Laxminath Tripathy
Inf. Sci.1
2012 A dynamic password-based user authentication scheme for hierarchical wireless sensor networks
Ashok Kumar Das, Pranay Sharma, Santanu Chatterjee, Jamuna Kanta Sing
J. Netw. Comput. Appl.1
2011 Analysis and improvement on an efficient biometric-based remote user authentication scheme using smart cards
abstract
The author first reviews the recently proposed Li-Hwang's biometric-based remote user authentication scheme using smart cards; then shows that the Li-Hwang's scheme has some design flaws in their scheme. In order to withstand those flaws in their scheme, an improvement of their scheme is further proposed. The author also shows that the improved scheme provides strong authentication with the use of verifying biometric, password as well as random nonces generated by the user and the server as compared to that for the Li-Hwang's scheme and other related schemes.
Ashok Kumar Das
IET Inf. Secur.1
2011 An efficient random key distribution scheme for large-scale distributed sensor networks
abstract
Abstract Key establishment in sensor networks is a challenging problem because of resource constraints of the sensors. Due to resource limitations and vulnerable to physical capture of the sensor nodes, the classical public‐key routines are impractical in most sensor network architectures. In this paper, we propose a new random key pre‐distribution scheme. Our scheme always defines a relationship between the ids of neighbor nodes and the keys possessed by those nodes while maintaining the required randomness in choice of keys. Our proposed scheme provides better security against node capture attack than the existing random key pre‐distribution schemes. Moreover, it has better trade‐off between communication overhead, network connectivity and security against node capture compared to the existing random key pre‐distribution schemes. In addition, it supports dynamic node addition efficiently after initial deployment of the nodes in the network. Copyright © 2009 John Wiley & Sons, Ltd.
Ashok Kumar Das
Secur. Commun. Networks1
2006 A bidirectional linear semi-systolic architecture for DCT-domain image resizing processor
abstract
In recent times, there is an increasing interest in compressed-domain image analysis and its VLSI implementation due to extensive use multimedia communication, specially in mobile devices. This paper deals with the semi systolic architecture of DCT-based (discrete cosine transform) image resizing processor as a compressed domain image processing element. Further, we propose an efficient method for VLSI implementation for DCT-domain image resizing transformation with bidirectional linear semi-systolic array. This method is developed from the investigation of the DCT-domain image resizing operation through a parallel processing of the matrix operations. The use of systolic arrays as a processing block of the matrix operations reduces the number of computation and also amenable for VLSI implementation
Ashok Kumar Das
ISCAS1