Youngho Park 0005

dblp:40/8858 · also YoungHo Park 0005 · DBLP profile ↗
← Back
57ranked-venue papers
0as first author
42since 2021 · last 2026
0000-0002-0406-6547ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 33 · 24 since 2021Applied, interdisciplinary, general and emerging computing · 15 · 12 since 2021Security and privacy · 6 · 5 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2026 ZTS-CIoHT-PPRF: Zero Trust Security-Based Mutual Authentication Scheme for Cloud-Assisted IoHT Using Puncturable Pseudorandom Function
abstract
The incorporation of cloud to Internet of Health Things (IoHT) referred to as Cloud-assisted IoHT (CIoHT) assures efficient storage of the sensitive health data with better flexibility and scalability. However, owing to the openness nature of the CIoHT infrastructure, it is often susceptible to several security threats. On the contrary, security is an essential aspect of the CIoHT infrastructure. Thus, to address these security concerns, it is a common practice to establish a mutual authentication scheme among the communicating cloud entities that ensures to satisfy all the essential security requirements. In line with this, establishing trust among these entities is also a significant prerequisite. However, after a rigorous literature survey, it is found that all the existing authentication schemes are either vulnerable to various security threats or bear higher computation and/or communication overheads. Above all, these schemes have either taken the security or the trust aspect into consideration, but not both. Thus, we have proposed a Zero Trust Security (ZTS) based mutual authentication scheme for the CIoHT infrastructure using a Puncturable Pseudorandom Function (PPRF) in this paper. The detailed security analysis using informal and formal security analysis, and formal security verification using AVISPA tool ensures that the proposed scheme is highly robust against various known attacks needed in a CIoHT infrastructure. Moreover, the comprehensive comparative analysis exhibit that in comparison to the related literature our scheme provides higher computation and communication efficiency. Thus, unlike the existing schemes, the proposed scheme satisfies the vital security-trust-efficiency traid; ensuring its feasibility for implementation in real-world CIoHT infrastructure.
Priyanka Das 0011, Sangram Ray, Mou Dasgupta, Ashok Kumar Das, Youngho Park 0005, Mahesh Chandra Govil
IEEE Internet Things J.5
2026 Postquantum Secure Lattice-Based Authentication Scheme for IoT-Enabled Crop Recommender System
abstract
Internet of Things (IoT)-enabled smart farming has emerged as one of the most progressive domains, integrating knowledge discovery as a core component to assist farmers in analyzing their fields and obtaining accurate crop recommendations. However, the advent of quantum computing introduces significant security threats to this domain, emphasizing the urgent need to transition from classical to quantum-secure authentication mechanisms. To address this challenge, this article presents a post-quantum, lattice-based secure authentication scheme tailored for intelligent crop recommendation systems. The cryptographic scheme strengthens the data communication pipeline, and additionally, the framework incorporates security-aware design considerations within the machine learning phase, which acts as the second line of defense for the recommendation system. The security of the scheme is thoroughly analyzed for classical as well as quantum attacks. The insights gained from the real-time testbed validate the efficiency and accuracy of the framework.
Snehal Jain, Abhishek Kumar Pandey, Ashok Kumar Das, Shantanu Pal, Youngho Park 0005
IEEE Internet Things J.5
2026 Ascon-Based Lightweight and Robust Authentication Scheme for IoT-Enabled Healthcare System
Hyeonjung Jang, Deok Kyu Kwon, Youngho Park 0005
IEEE Internet Things J.3
2026 Robust and Lightweight User Authentication Scheme Using Deep Learning-Based Cancelable Biometrics in Smart Home Environments
Deok Kyu Kwon, Ashok Kumar Das, Youngho Park 0005
IEEE Internet Things J.4
2026 Quantum-Resistant Three-Party Mutual Authentication Protocol for Industrial IoT Environments
abstract
The Industrial Internet of Things (IIoT) integrates control systems with IoT technology to enable automation and intelligent operations in industrial environments. As IIoT deployments expand, reliance on wireless communication channels increases the attack surface and exposes systems to various security and privacy threats. Moreover, the limited computational capabilities of IIoT devices and the need to preserve device anonymity introduce additional security requirements. Insufficient protection against these challenges can result in operational disruption and significant economic losses. Existing symmetric-key and hash-based schemes are lightweight but lack scalability for large IIoT deployments, whereas public-key methods provide stronger security. However, the emergence of quantum computing threatens the long-term security of such protocols, as quantum algorithms can efficiently break conventional number-theoretic cryptosystems. To address these challenges, we propose a quantum-resistant three-party authentication and key agreement (AKA) protocol for the IIoT. The ring learning with errors (RLWE)-based protocol provides quantum-safe and efficient mutual authentication and secure session key establishment between workers and devices. Comprehensive security and performance analyses demonstrate that the proposed protocol is robust against security attacks. Performance evaluations confirm lower computational and communication overhead than existing post-quantum schemes, proving its practicality for IIoT.
Chaeeon Kim, Deok Kyu Kwon, YoHan Park 0001, Youngho Park 0005
IEEE Internet Things J.4
2026 Post-Quantum Secure Lattice-Based Lightweight Authentication and Key Agreement Scheme for Multilayer IoT-Enabled Smart Grid System
abstract
The smart grid is a modern electricity network that incorporates sophisticated communication and control technologies to improve efficiency, reliability, and security. This study presents a secure, lightweight authentication and key agreement scheme for multi-layer Internet of Things (IoT)-enabled smart grid systems, targeting the essential requirement to safeguard industrial control networks against cyber threats. The proposed scheme incorporates two security mechanisms to improve authentication and communication security in smart grid systems. Physical Unclonable Functions (PUFs) facilitate secure device authentication between smart meters and the Master Terminal Unit (MTU) by utilizing hardware-level uniqueness, thereby ensuring resilience against cloning attacks. Additionally, post-quantum lattice-based Ring Learning with Errors (RLWE) hard problem ensures secure communication between the MTU and the Remote Terminal Unit (RTU), providing quantum-resistant security and efficient key exchange. The framework’s resilience is rigorously evaluated with the ProVerif security verification tool to confirm its strength against advanced cyberattacks. A formal security analysis quantitatively assesses the cryptographic robustness of the scheme, whereas an informal security analysis examines its ability to withstand practical cyber threats, including replay attacks, man-in-the-middle (MITM) attacks, and device impersonation in actual smart grid environments.
Gagan Kumar, Bala Prakasa Rao Killi, Ashok Kumar Das, Youngho Park 0005
IEEE Internet Things J.4
2026 A Modeling Attack-Resistant PUF-Enabled Robust Authentication and Key Agreement Scheme for Industrial Wireless Sensor Networks
abstract
Industrial wireless sensor networks (IWSNs) are emerging as a new network paradigm in Internet of Things (IoT) for smart manufacturing, monitoring, and automation systems. IWSNs seamlessly integrate with IoT platforms and cloud services to support advanced services such as remote monitoring, AI-powered analytics, and advanced automated control. However, these systems can be vulnerable to potential security attacks because an adversary can attempt to delete, modify, intercept, and block the transmitted messages over an insecure channel. Besides cybersecurity attacks, IoT devices may be vulnerable to physical security attacks because they are deployed in unattended environments. To resolve these security threats and weaknesses, robust and lightweight authentication and key agreement (AKA) schemes are essential. Many researchers have recently presented a PUF-based secure and lightweight AKA scheme for IWSN-based IoT. Unfortunately, we demonstrated that the previous scheme is susceptible to potential security threats and does not guarantee the necessary security functionalities. Moreover, the existing PUF-based AKA schemes may be vulnerable to machine learning (ML)-based modeling attacks. Thus, we propose a ML-based modeling attack-resistant PUF-enabled robust AKA scheme for IWSN-enabled IoT to improve the security flaws of the previous scheme, called PUF-IWSN. We evaluate the security of PUF-IWSN by performing formal security analysis such as AVISPA simulation and ROR oracle model. We demonstrate the analysis of performance comparison between PUF-IWSN and its related schemes. We present the implementation to evaluate the security of existing PUFs and the hybrid PUF against ML-based modeling attacks. Consequently, PUF-IWSN ensures superior efficiency and security than the previous schemes and can be suitable for practical IWSN-enabled IoT systems.
SungJin Yu, Youngho Park 0005
IEEE Internet Things J.2
2026 Big Data Analytics-Envisioned Quantum-Safe Lattice-Based Three-Party Authenticated Key Agreement Protocol for Cloud IoT-Enabled Healthcare Applications
abstract
Cloud-based Internet of Things (IoT)-enabled smart healthcare plays a vital role in modern society, yet security and privacy challenges remain unavoidable. The authenticated key agreement (AKA) process, which serves as the foundation of secure communication, is widely recognized as a key solution to these challenges. However, many existing AKA methods in the literature either involve high communication and computational costs or fail to withstand quantum attacks. Post-quantum cryptography (PQC) introduces a new class of cryptographic algorithms designed to resist future quantum computer threats. In this article, we present a quantum-secure, lattice-based three-party AKA scheme for smart IoT healthcare applications, leveraging the computationally complex Ring-Learning With Errors (Ring-LWE) problem. Our approach integrates secure big-data analytics with blockchain technology by utilizing authentication procedures for secure data aggregation before storing it in the blockchain. A comprehensive security evaluation including formal and informal analysis, demonstrates the scheme's strong resilience against both classical and quantum attacks. Additionally, experimental results confirm that the proposed scheme is well-suited for real-time smart healthcare applications.
Prithwi Bagchi, Aakash Roy, Mohammad Wazid, Ashok Kumar Das, Bharat K. Bhargava, Youngho Park 0005
IEEE Trans. Dependable Secur. Comput.6
2025 PLAKA-MD: PUF-Based Lightweight Authentication and Key Agreement Scheme for Medical Devices in IoHT
abstract
Internet of Health Things (IoHT) integrates medical services and Internet of Things (IoT) to improve the accessibility of healthcare and accuracy of diagnosis. In IoHT environments, the transmission of sensitive data, such as patient medical records, physical characteristics, and genetic information, necessitates robust security mechanisms to protect privacy and ensure the integrity of real-time communication. Moreover, it is essential for healthcare professionals to have seamless access to patient data for accurate diagnoses. To address these demands, a lightweight and secure authentication protocol is critical for IoHT environments. Although some authentication protocols have been recently proposed in IoHT, they are susceptible to user insiders, privileged insiders, stolen verifiers, ephemeral key leakage, sensor insiders, physical attacks, and lack traceability. To overcome these vulnerabilities, we propose a mutual authentication protocol for IoHT environments. We design the proposed protocol as a lightweight using only hash functions and exclusive-OR operators. Furthermore, we utilized biometric information, physical unclonable functions (PUFs), and fuzzy extractors to strengthen security for both users and sensors. We validate the security robustness of the proposed protocol through formal analyses, including Automated Validation of Internet Security Protocols and Applications (AVISPAs), the Real-or-Random (RoR) model, and Burrows-Abadi-Needham (BAN) logic. Additionally, we evaluate the performance of the protocol by measuring the execution time of cryptographic primitives and comparing the computational and communication overheads with existing protocols. Results demonstrate that our protocol provides the most various kinds of security and functional features while maintaining similar efficiency than competing schemes.
Changui Lee, Mingyu Oh, Deok Kyu Kwon, Youngho Park 0005, YoHan Park 0001
IEEE Internet Things J.4
2025 AI-Enhanced Resource Allocation for LPWAN-Based LoRaWAN:A Hybrid TinyML and Deep Learning Approach
abstract
The integration of Artificial Intelligence (AI) with Low Power Wide Area Networks (LPWAN) offers a promising approach to address resource constraints and dynamic network conditions inherent in these networks. However, deploying complex AI algorithms on resource-limited edge devices presents significant challenges due to their limited computational capabilities. In this study, we propose a hybrid Tiny Machine Learning (TinyML) and Deep Neural Network (DNN)-based solution for optimizing resource allocation in LPWAN-based LoRaWAN networks, targeting both static and mobile applications. Our approach leverages the strengths of a 1-D Convolutional Neural Network (CNN) and Long Short-Term Memory (LSTM) model implemented on the network server, combined with TinyML models deployed on edge devices. The CNN-LSTM model predicts optimal spreading factor and transmission power by analyzing spatial and temporal patterns from real-time data, while the TinyML models enable edge devices to autonomously adjust communication parameters in resource-constrained and disconnected scenarios. This hybrid framework enhances network performance by improving the packet success ratio (PSR), maximizing energy efficiency, and addressing the challenges posed by dynamic IoT environments.
Muhammad Ali Lodhi, Xiaobing Sun 0001, Khalid Mahmood 0002, Anum Lodhi, Youngho Park 0005, Majid Hussain
IEEE Internet Things J.5
2025 Authenticated Certificateless Verifiable Searchable Public Key Encryption Scheme With Big Data Analytics for IoT-Based Healthcare
abstract
The emerging concept of Internet of Things (IoT)-based healthcare Industry 5.0 emphasizes the integration of human intelligence with cutting-edge technologies, like Artificial Intelligence (AI), blockchain, IoT, big data analytics, and machine learning (ML) models to revolutionize healthcare delivery. However, alongside the immense potential and opportunities of healthcare 5.0, the rapid expansion of sensitive medical data within the cloud-based healthcare systems also brings significant challenges related to data security, privacy, and resource requirements. Since most healthcare infrastructures depend on the semi-trusted centralized cloud storage, it then becomes crucial to store medical records in encrypted form in order to ensure confidentiality and privacy of the data. At the same time, these systems must provide seamless and efficient search capabilities for authorized medical personnel in healthcare system. To address these concerns and enable cost-effective, secure access and data management, we propose a novel authenticated certificateless verifiable searchable public key encryption scheme (ACLV-SPKE) that emerges as a robust and promising solution for securing healthcare data. The proposed framework not only resists diverse adversarial attacks but also ensures efficiency in terms of communication and computation costs, while offering improved functionality over recent state-of-the-art solutions presented in literature. The proposed scheme effectively resists both inside and outside keyword guessing attacks, achieving strong security guarantees like ciphertext and trapdoor indistinguishability, which are proved in the random oracle models. In addition, we applied big data analytics on a real healthcare dataset to evaluate the performance metrics, and the outcomes are presented in this article.
Debjani Mallick, Ashok Kumar Das, Mohammad Wazid, Youngho Park 0005
IEEE Internet Things J.4
2025 Uncrewed Aerial Vehicles Empowering Secure Authentication in Cognitive IoMT for Transformative Knowledge Discovery in Data
abstract
The paradigm shift toward digital transformation is increasingly advancing toward cognitive decision discovery, particularly within the healthcare domain, where it has emerged as a critical area of research. Numerous researchers are actively contributing to this field. However, due to the sensitive nature of healthcare data, ensuring robust security within the cognitive decision-making process is paramount for Internet of Medical Things (IoMT). To address this concern, the present study proposes a comprehensive privacy-preserving authentication scheme associating aerial computing and knowledge discovery. This scheme leverages an elliptic curve-based cryptosystem to establish the authentication protocol and incorporates blockchain technology to ensure data storage security. Furthermore, the scheme facilitates secure knowledge discovery in data (KDD) within cognitive decision-making frameworks. The proposed authentication mechanism is evaluated across communication, computational efficiency, and security parameters to validate its functionality and robustness as well as to formally verify the developed scheme Scyther tool verification is done by authors. Additionally, to demonstrate the necessity and effectiveness of the proposed scheme, the authors conducted a KDD experiment using both a securely authenticated dataset and an insecure, compromised dataset. The results of these experiments are presented and thoroughly analyzed in the article.
Abhishek Kumar Pandey, Ashok Kumar Das, Mohammad Wazid, Kuljeet Kaur, Youngho Park 0005, Mohammad Mehedi Hassan
IEEE Internet Things J.5
2025 Big Data Analytics-Envisioned Authenticated Key Management Scheme in IoT-Based Smart Farming System for Sustainable Development of Smart Cities
abstract
Smart farming enhances sustainable communication practices through the deployment of energy-efficient Internet of Things (IoT) devices, low-power wireless technologies, and edge/fog computing to reduce data transmission and energy usage. Smart cities represent a concept in which technology, data, and innovation enhance urban efficiency, sustainability, and livability. Smart farming has the potential to facilitate the sustainable development of smart cities. However, integrating smart farming into smart city systems presents significant challenges, particularly with respect to the security of their interconnected components. The vulnerability of agricultural information and the likelihood of cybersecurity threats necessitate the development of targeted security solutions for smart farming. To address these challenges, we propose a Big Data Analytics-envisioned secure smart farming scheme for sustainable cities (in short, CSSF-SC). It is an efficient authenticated key agreement mechanism that enables secure mutual authentication, session-key establishment, and dynamic key management among smart farming devices, drones, and cloud servers. Using the Scyther verification tool, security is formally verified under the Dolev–Yao and CK adversary models, demonstrating resilience to various potential attacks. A comparative performance analysis shows that CSSF-SC outperforms current schemes in terms of computation and communication costs while offering stronger security and additional functionalities. Finally, a practical implementation is done using the MangoLeafBD dataset and an EfficientNet-B7 architecture. It achieves 99.16% accuracy, validating the framework’s effectiveness for secure crop-data collection and analysis in real-world scenarios.
Akshita Patwal, Mohammad Wazid, Ashok Kumar Das, Devesh Pratap Singh, Shantanu Pal, Youngho Park 0005
IEEE Internet Things J.6
2025 A Secure IoT-Enabled Medical Data Sharing Scheme Using Blockchain-Assisted Private Set Intersection
abstract
Advances in Internet-of-Things (IoT) technology are enabling the sharing of electronic health records (EHR) via wireless channels. Because EHRs contain sensitive patient information, it is important to preserve data privacy along with medical data sharing. In this paper, we propose a secure medical data sharing scheme using blockchain-assisted private set intersection (PSI). Our approach ensures access control and data availability by having data users upload encrypted private set intersections to the blockchain. We also proposed a mutual authentication phase between the hospital and data user after calculating private set intersection. We thoroughly analyzed the proposed scheme using informal methods and proved security against semi-honest adversary model, correctness, and session key security using formal methods. We also implemented the proposed scheme in real environments using laptop and Raspberry PI 4 to prove the practicality of the proposed scheme. We compared the proposed mutual authentication scheme with existing methods and show that the proposed scheme is better than existing schemes.
Seunghwan Son, Deok Kyu Kwon, YoHan Park 0001, Ashok Kumar Das, Youngho Park 0005
IEEE Internet Things J.5
2025 A Machine Learning Attack-Resistant PUF-Based Robust and Efficient Mutual Authentication Scheme in Fog-Enabled IoT Environments
abstract
Fog-enabled Internet of Things (IoT) systems have a lot of attention and are being applied in various fields, including smart homes, smart healthcare, smart factories, and smart grids. These fog-enabled IoT systems enhance citizens’ quality of life and provide innovative and high-quality IoT services. However, these systems can be vulnerable to cyber security attacks since an adversary attempts to modify, delete, block, and intercept the exchanged data over an insecure channel. Besides cyber security attacks, IoT can be fragile to physical security attacks because they are deployed in hostile environments. Physical unclonable function (PUF) is a promising solution to address these issues. PUF can protect the security of IoT devices with minimal computation costs against cyber/physical attacks from an adversary. However, with recent advances in artificial intelligence (AI) technology, existing PUFs used in authentication and key agreement (AKA) schemes are susceptible to machine-learning (ML)-based modeling attacks. To address these challenges, we design the ML-based modeling attack-resistant PUF-based robust and efficient AKA scheme in fog-enabled IoT environments. We evaluate the security of the proposed scheme by performing informal and formal security analyses, such as ROR oracle model and AVISPA simulation. We present the implementation to demonstrate the accuracy against ML-based modeling attacks. Moreover, we perform the performance comparison analysis between the proposed scheme and existing schemes based on testbed implementation. Consequently, the proposed scheme provides superior security and efficiency compared to existing schemes and can be suitable for practical fog-enabled IoT systems.
SungJin Yu, Kisung Park 0002, Youngho Park 0005
IEEE Internet Things J.3
2025 Secure and privacy-preserving quantum authentication scheme using blockchain identifiers in metaverse environment
Sunil Prajapat, Aryan Rana, Pankaj Kumar 0006, Ashok Kumar Das, Youngho Park 0005, Mohammed J. F. Alenazi
J. Syst. Archit.5
2025 Blockchain-Enabled Secure Collaborative Model Learning Using Differential Privacy for IoT-Based Big Data Analytics
abstract
With the rise of Big data generated by Internet of Things (IoT) smart devices, there is an increasing need to leverage its potential while protecting privacy and maintaining confidentiality. Privacy and confidentiality in big data aims to enable data analysis and machine learning on large-scale datasets without compromising the dataset sensitive information. Usually current big data analytics models either efficiently achieves privacy or confidentiality. In this article, we aim to design a novel blockchain-enabled secured collaborative machine learning approach that provides privacy and confidentially on large scale datasets generated by IoT devices. Blockchain is used as secured platform to store and access data as well as to provide immutability and traceability. We also propose an efficient approach to obtain robust machine learning model through use of cryptographic techniques and differential privacy in which the data among involved parties is shared in a secured way while maintaining privacy and confidentiality of the data. The experimental evaluation along with security and performance analysis show that the proposed approach provides accuracy and scalability without compromising the privacy and security.
Prakash Tekchandani, Abhishek Bisht, Ashok Kumar Das, Neeraj Kumar 0001, Marimuthu Karuppiah, Pandi Vijayakumar, Youngho Park 0005
IEEE Trans. Big Data7
2025 An Efficient Handover Authentication Scheme for 6G-Enabled Space-Terrestrial Integrated Networks With Mobile Edge Computing
abstract
Sixth-generation (6G) services can offer unprecedented data speeds, ultra-low latency, and vast connectivity. Moreover, satellite communication has become crucial to achieving seamless global coverage for 6G networks. Space-terrestrial integrated networks (STIN) combine satellite and ground networks, ensuring continuous services via satellites even when outside terrestrial network coverage. However, existing STIN schemes rely on central ground server, which can potentially lead to bottlenecks and delays. Additionally, a lightweight handover is necessary to address frequent service changes due to the narrow communication ranges in 6G-based STIN environments. To address these challenges, we propose a novel authentication scheme to provide secure and high-speed handover process for STIN environments. The proposed scheme leverages mobile edge computing (MEC)-based low-Earth orbit (LEO) satellites to minimize communications with the central server. Moreover, a key feature of the proposed scheme is the structural separation of computational loads: we utilize elliptic curve cryptography (ECC) for robust initial authentication, and only hash functions and exclusive-OR (XOR) operators for high-speed handover process. To prove the security of our scheme,we perform informal analysis, “Burrows-Abadi-Needham (BAN) logic”, “Real-Or-Random (ROR) model“, “Automated Validation of Internet Security Protocols and Applications (AVISPA) simulation tool”, and “Scyther tool”. Furthermore, we conduct comparative study on security properties, computation, and communication costs of the proposed scheme and the existing related schemes. To verify the practical deployment of the proposed scheme, we perform a simulation study using “Network Simulator 3 (NS-3)”. Our results demonstrate that the proposed scheme can provide efficient and secure communications for MEC-based STIN environments.
Deok Kyu Kwon, Seunghwan Son, Kisung Park 0002, Ashok Kumar Das, Youngho Park 0005
IEEE Trans. Inf. Forensics Secur.5
2025 A PUF-Based Lightweight Authentication Scheme for UAV-Assisted Internet of Vehicles
abstract
Unmanned Aerial Vehicles (UAVs)-assisted Internet of Vehicles (IoV) utilizes flexible mobility of UAVs to improve communication issues in traditional IoV model. In UAV-assisted IoV, UAVs expand the communication coverage of roadside units (RSUs) and support the tasks of RSUs. Therefore, UAV-assisted IoV can contribute to the development of Intelligent Transportation System (ITS). However, an adversary can still attempt various attacks because UAV-assisted IoV networks perform wireless communication over open channels. In 2024, Miao et al. proposed an elliptic curve cryptography (ECC)-based authentication scheme for UAV-assisted IoV. Unfortunately, we discover that their scheme cannot prevent man-in-the-middle (MITM) and ephemeral secret leakage (ESL) attacks. Furthermore, Miao et al.’s scheme incurs high computational costs using ECC which is unfavorable for UAVs considering their computational restrictions. In this article, we propose a secure and lightweight authentication scheme for UAV-assisted IoV, considering the computational limitations of UAVs. We apply physical unclonable function (PUF) and fuzzy extractor to mutual authentication, developing the security level. Moreover, the proposed scheme uses only one-way hash functions and exclusive-or (XOR) operations which are compatible with UAVs. To prove the robustness of the proposed scheme, we perform “Burrows-Abadi-Needham (BAN) logic”“, Real-or-Random (RoR) model”, and “Automated Verification of Internet Security Protocols and Applications (AVISPA)” based formal security analysis, and informal analysis. Furthermore, we estimate the performance of the proposed scheme and compare with other relevant works, including computational costs, communication costs, energy consumption, security properties, and storage costs. Consequently, we establish that the proposed scheme is appropriate and efficient for UAV-assisted IoV.
Jihye Choi, Deok Kyu Kwon, Seunghwan Son, YoHan Park 0001, Ashok Kumar Das, Youngho Park 0005
IEEE Trans. Intell. Transp. Syst.6
2025 BAPS-DITS: Blockchain-Enabled Accountable Privacy-Preserving Scheme for Decentralized Intelligent Transportation Systems
abstract
The integration of intelligent transportation systems (ITS) within the smart grid has significantly enhanced the reliability, efficiency, and security of vehicle-to-grid (V2G) services over the past decade, leading to increased research interest in this technology. Charging stations (CSs) utilize electric vehicles (EVs) to manage demand response and provide sustainable energy solutions. However, the transmission of information between EVs and CSs via public channels causes critical security vulnerabilities. Although much effort has been made to overcome the challenge of protecting security and privacy in V2G environments, these efforts have either been proposed based on a centralized architecture or do not ensure essential security requirements, such as self-sovereignty, reliable, and blockchain scalability. Furthermore, in decentralized network, it is difficult to provide reliable energy distribution because a malicious participant can easily try to inflate trading volumes and manipulate energy prices. In this paper, we propose a new blockchain-enabled, reliable, privacy-preserving scheme using decentralized identifiers (DIDs) for preventing energy wash trading in V2G networks called BAPS-DITS. BAPS-DITS guarantees to tackle the above challenges without a trusted third-party intervention. Additionally, we use informal and formal (mathematical) analysis to prove the security of BAPS-DITS and conduct a comparative analysis comparing the security properties, computational cost, and communication cost of BAPS-DITS to previous studies. Furthermore, we implement BAPS-DITS on a practical Ethereum network, demonstrating its efficiency and feasibility, showing that BAPS-DITS provides self-sovereignty, accountability, and blockchain scalability; thus, it is suitable for actual V2G environments.
Kisung Park 0002, Ashok Kumar Das, Youngho Park 0005
IEEE Trans. Intell. Transp. Syst.3
2025 TGKAV: Tree-Based Group Key Agreement Scheme With Practical Antenna Implementation for Vehicle Platoon
abstract
Ensuring the safe transfer of information plays an important role in the development of Industry 4.0. Robust authentication and security frameworks are required to establish confidence among vehicles, provide reliable data flow, and improve the overall safety of vehicle platoons. This is crucial for preventing cyber-attacks that could cause accidents or disrupt the synchronized movement of vehicle platoons. Initially, in this study, a novel privacy-preserving mechanism based on an authentication code and cipher test is suggested. Second, an effective authentication system is proposed for vehicle platoons. Third, a novel tree-based group key-sharing mechanism for the exchange of information between vehicle users is proposed. The proposed scheme also supports the sharing of the same group key for entities in Industry 4.0. Finally, a planar array consisting of four elements was specifically built for use in vehicular ad hoc network (VANET) applications operating inside the Dedicated Short-range Communications (DSRC) (802.11p) band to prove the efficacy in terms of practical implementation. To assess the security level of the suggested authentication scheme, both formal and informal analyses were conducted. Finally, the performance of the suggested protocol is evaluated in terms of computational and communication overheads. Moreover, the designed antenna provides complete impedance bandwidth coverage, good gain, and minimal cross-polarization suppression at the optimum frequency of operation in the C band.
Arun Sekar Rajasekaran, Mohammad S. Obaidat, Maria Azees, Kalyan Sundar Kola, Ashok Kumar Das, Youngho Park 0005
IEEE Trans. Intell. Transp. Syst.6
2025 Explainable Deep Learning-Enabled Malware Attack Detection for IoT-Enabled Intelligent Transportation Systems
abstract
The Internet of Things (IoT) has the potential to improve the complementary of communication, control, and information processing within the public transportation system. The IoT-enabled Intelligent Transportation System (ITS) ensures that automated transportation is networked and operated collaboratively. The IoT-enabled ITS has revolutionized the transportation industry by enabling the seamless integration of a wide range of devices and systems. It makes the strategic use of networked devices, sensors, and data analytics to improve transportation network efficiency, safety, and environmental friendliness. The usage of the IoT in the ITS has grown in popularity due to its capacity to improve traffic control, reduce congestion, facilitate live monitoring, and optimize transportation operations. The IoT-enabled ITS systems and devices must be protected from cyber-attacks for various reasons, including preserving sensitive data, guaranteeing privacy, preventing unauthorized access, and protecting against the risk of interruptions or manipulations. Malware attacks affect the working and performance of the deployed smart IoT devices. We propose a secure deep learning-enabled malware attack detection for IoT-enabled ITS (in short, SDLMA-IITS). The approach of explainable artificial intelligence (XAI) has been utilized for the effective detection of malware. A deep security analysis of the proposed SDLMA-IITS is presented to prove its security against various potential attacks. The comparative performance analysis of SDLMA-IITS is given with the other similar existing schemes. Finally, a practical implementation of SDLMA-IITS is provided to measure its impact on the security of the IoT-enabled ITS systems and devices.
Mohammad Wazid, Charvi Pandey, Robert Simon Sherratt, Ashok Kumar Das, Debasis Giri, Youngho Park 0005
IEEE Trans. Intell. Transp. Syst.7
2024 Blockchain-Enabled Key Aggregate Searchable Encryption Scheme for Personal Health Record Sharing With Multidelegation
abstract
The transition from patient-centered medical services to Health 5.0, which provides medical services to all customers using smart healthcare, has led to the use of the Internet of Things (IoT) for medical diagnosis and research based on the personal health records (PHR) of service users. However, PHR contain sensitive personal information, which can cause privacy issues. Additionally, as emergencies may occur in real medical environments, multi-authority delegation must be considered. Although various methods are being studied for data sharing, they often do not meet the necessary security requirements in a real PHR sharing environment. In this study, we propose a system that uses key aggregate searchable encryption (KASE) to satisfy security requirements and leverages blockchain and smart contracts to improve data integrity, data audit records, and transparency. We also propose a method that ensures the data subject rights of PHR data owners when delegating multiple rights using attribute tokens. We conduct formal and informal security analyses to verify the robustness of the proposed system against potential adversarial attacks. Finally, a performance evaluation is conducted to verify the effectiveness of the proposed scheme.
JoonYoung Lee, Ji-Hyeon Oh, Deok Kyu Kwon, MyeongHyun Kim, Keonwoo Kim 0003, Youngho Park 0005
IEEE Internet Things J.6
2024 A Robust Covert Channel With Self-Bit Recovery for IEEE 802.11 Networks
abstract
Covert channels are commonly perceived as potential attack vectors in wireless communication environments and are categorized into covert timing channels and covert storage channels based on their creation method. Although covert timing channels are generally difficult to detect, we identified their potential use as secure message carriers in wireless communication, particularly within the IEEE 802.11 environments. In this context, access points continuously broadcast packets to nearby devices. Our aim was to create a robust covert timing channel using these broadcast packets. However, IEEE 802.11 operates as a one-way communication channel, which prevents the covert receiver from confirming proper message reception. Moreover, in the event of incorrect reception, the receiver cannot send an ACK to the sender to avoid detection risk. This paper proposes a covert timing channel with a self-bit recovery function for consecutive two-bit losses. We validated the practicality of our proposed covert timing channel through simulations involving laptops and a Zynq board. Furthermore, we assessed the robustness of our covert channel and compared its performance with that of existing covert timing channels. The results indicate superior covertness, higher capacity, and transmission accuracy compared with existing covert timing channels. Notably, our study represents the first covert timing channel algorithm capable of recovering consecutive 2-bit losses.
Seunghwan Son, Deok Kyu Kwon, Yongsung Jeon, Youngho Park 0005
IEEE Internet Things J.5
2024 Privacy-Preserving Electronic Medical Record Sharing for IoT-Enabled Healthcare System Using Fully Homomorphic Encryption, IOTA, and Masked Authenticated Messaging
abstract
A significant evolution in healthcare recently uses technological advancements to perform different activities, such as patient electronic medical records (EMRs) data gathering, preserving, processing, diagnosis, and handling. The adaptation of the Internet of Things (IoT) and cloud has further facilitated the enhancement of related healthcare systems, which can considerably improve data connectivity, accessibility, and exchange, which leads to a significant improvement in the quality of services to patients. Furthermore, scientific computations over data in transmission can be exposed to adversaries and may reveal private data for financial benefit. This article uses the Cheon-Kim-Kim-Song fully homomorphic encryption scheme and IOTA Tangle using masked authenticated messaging (MAM) protocol to provide secure communication between patient and doctor. CKKS-FHE-based data encryption provides data privacy, and secured EMRs sharing through IOTA Tangle guarantees data confidentiality. The performance of this work is analyzed in terms of encryption and decryption time, and payload sharing using MAM and NON-MAM protocols results in evidence of the effectiveness of the approach and improves overall security. The proposed scheme performs better overall computation time and performance than other relevant schemes. Further, the security analysis shows that the proposed system is resilient to data immutability and integrity, forward secrecy, and passive and active attacks.
Sivaranjani Reddi, Patruni Muralidhara Rao, Saraswathi Pedada, Jangirala Srinivas, Ashok Kumar Das, Sajjad Shaukat Jamal, Youngho Park 0005
IEEE Trans. Ind. Informatics7
2024 Blockchain Assisted Intra-Twin and Inter-Twin Authentication Scheme for Vehicular Digital Twin System
abstract
The potency of digital twins to mitigate the shortcomings of traditional mobility systems, such as Vehicular Adhoc Network (VANET) can reconfigure it into an intelligent transportation domain with bolstered processing, storage capabilities and decision-making abilities. The vehicular digital network is emerging as the industrial revolution, where each real-mobile entity (i.e., vehicle) is connected in the virtual environment through their digital replica, known as a digital twin. The real-time data synchronization in the digital twin-centric approach is achieved via an open communication channel. Unfortunately, leveraging the virtual-reality synthesized security perils in the network which consequently obligates rigorous privacy and security countermeasures such as authentication, encryption and signature techniques. In this paper, we have suggested a blockchain-based authentication framework for intra-twin and inter-twin communication in vehicular digital twin networks, and the integrated blockchain in the system assures data compactness and verifiability. The security of the protocol is investigated under the real or random oracle model (ROR) and is confirmed secure with non-mathematical security analysis. Eventually, the operational competences and functionality features are inspected with relevant state-of-the-arts. The findings of study states excel computation and communication overhead of suggested system than others and is seemly for vehicular digital twin network.
Deepika Gautam, Pankaj Kumar 0006, Ashok Kumar Das, Youngho Park 0005
IEEE Trans. Intell. Transp. Syst.5
2024 A Secure Self-Certified Broadcast Authentication Protocol for Intelligent Transportation Systems in UAV-Assisted Mobile Edge Computing Environments
abstract
Unmanned Aerial Vehicle(UAV)-assisted mobile edge computing(MEC) ensures continuous MEC services by promptly restoring overloaded or disabled MEC infrastructure. Equipped with sufficient computing resources, UAVs deploy to areas needing MEC, such as task offloading and entertainment services. However, in areas with paralyzed edge nodes, vehicle users are unable to verify the legitimacy of UAVs as they cannot access to the trusted authority(TA). Furthermore, the integrity of UAV-assisted MEC environments can be compromised by malicious attackers, as all network participants rely on wireless communication for their interactions. Many authentication schemes have been proposed for UAV environments. However, these schemes encounter a problem of having to communicate through TA for authentication with vehicle users, which makes them difficult to apply to UAV-assisted MEC environments. Therefore, we propose a new broadcast authentication protocol, which can recover MEC services using MEC-equipped UAVs. The proposed protocol can provide UAVs and vehicle users with high reliability via a self-certified public-key cryptosystem, which can verify the legitimacy of the communication partner without the TA. Moreover, we guarantee the user privacy and preserve sensitive information using biohash technology. We verify the security robustness of the proposed protocol using various simulation tool, informal, and formal analyses. We also estimate the practical deployment of the proposed protocol using “Network Simulator-3”. Moreover, we estimate the computation and communication overheads and compare with other existing protocols. The results show that the proposed protocol is feasible and provides users with convenient and seamless intelligent transportation services in UAV-assisted MEC environments.
Deok Kyu Kwon, Seunghwan Son, MyeongHyun Kim, JoonYoung Lee, Ashok Kumar Das, Youngho Park 0005
IEEE Trans. Intell. Transp. Syst.6
2024 Design of Blockchain-Based Multi-Domain Authentication Protocol for Secure EV Charging Services in V2G Environments
abstract
Multi-domain vehicle to grid (V2G) is a network environment in which numerous service providers offer charging and discharging services to EV users. This can enhance energy management and traffic flow for efficient intelligent transportation systems (ITS). However, the combination of multiple domains can suffer from various security vulnerabilities, highlighting the need for robust countermeasures. Moreover, existing multi-domain V2G protocols utilized a central trusted authority (TA) which can create a single point of failure (SPOF), or required high computational resources. In this paper, we propose a multi-domain authentication protocol for secure and efficient V2G services using consortium blockchain. The proposed protocol provides lightweight intra-domain authentication using hash functions and XOR operators. Furthermore, the proposed protocol ensures secure cross-domain authentication by integrating elliptic curve cryptography (ECC) and physical unclonable function (PUF). Therefore, the proposed protocol can establish trust, enable efficient communications, and prevent congestion at charging stations. To validate security robustness, comprehensive evaluations are conducted using “Real-Or-Random (ROR) model”, “Scyther tool”, and informal analyses. Comparative computational overheads of the proposed and related protocols are measured using “Multiprecision Integer and Rational Arithmetic Cryptographic Library (MIRACL)” testbed experiments. Additionally, a simulation of the practical deployment is conducted using “Network Simulator-3 (NS-3)”. Results indicate that the proposed protocol can improve ITS by providing secure and efficient services for multi-domain V2G environments.
Deok Kyu Kwon, Seunghwan Son, Kisung Park 0002, Ashok Kumar Das, Youngho Park 0005
IEEE Trans. Intell. Transp. Syst.5
2024 RLBA-UAV: A Robust and Lightweight Blockchain-Based Authentication and Key Agreement Scheme for PUF-Enabled UAVs
abstract
Unmanned aerial vehicles (UAVs) integrated with the internet of things (IoT) guarantee useful advantages such as facilitating ground communications in regions where the availability of connectivity is restricted owing to physical obstacles. However, the data transmitted by sensors and IoT embedded in UAVs are facing new security issues and privacy challenges with the known security attacks over time. To address these security attacks and threats and meet lightweight UAV communication requirements, a secure and lightweight authentication and key agreement (AKA) scheme is essential. Recently, researchers have designed a lightweight blockchain-enabled AKA scheme with privacy-preserving for UAVs to provide useful and reliable services. However, we prove that the existing scheme is fragile to various security attacks and does not ensure mutual authentication. Thus, we propose a robust and lightweight blockchain-based AKA scheme for PUF-enabled UAVs, called RLBA-UAV to enhance the security problems of the existing scheme. We demonstrate the security of RLBA-UAV by using informal/formal security analyses such as the ROR oracle model and AVISPA simulation. Moreover, we demonstrate the performance comparison analysis between RLBA-UAV and related schemes for UAVs. We demonstrate an implementation of a network simulator (NS) 3 compliant with IEEE 802.11p standards to show its validation and feasibility that RLBA-UAV is appropriate for practical UAVs. Thus, RLBA-UAV offers enhanced security and operational efficiency compared to related schemes and can be applied to practical blockchain-based AKA systems for UAVs.
SungJin Yu, Ashok Kumar Das, Youngho Park 0005
IEEE Trans. Intell. Transp. Syst.3
2023 LAKA-UAV: Lightweight authentication and key agreement scheme for cloud-assisted Unmanned Aerial Vehicle using blockchain in flying ad-hoc networks
SungJin Yu, JoonYoung Lee, Anil Kumar Sutrala, Ashok Kumar Das, Youngho Park 0005
Comput. Networks5
2023 Post-Quantum Lattice-Based Secure Reconciliation Enabled Key Agreement Protocol for IoT
abstract
The authenticated key agreement is one of the major security services that can be used to secure an Internet of Things (IoT) environment, where the devices collect the data and the data is then aggregated at the cloud server, and then a user needs to access the data stored at the server(s) securely. For this purpose, after a mutual authentication performed between a user and the accessed server, a session key needs to be established among them for secure communication. In this article, we design an efficient lattice-based authenticated key exchange protocol using ring-based version of learning with errors assumption for the IoT-enabled smart devices. The proposed protocol is basically a key exchange that uses the reconciliation mechanism. The detailed security analysis under the standard model has been performed along with the informal security analysis to show that the proposed protocol is robust against different attacks. We then simulate the proposed protocol under the NS-3 simulator to measure the network performance parameters like network throughput and latency. A comparative analysis shows that the proposed protocol has superior security, less computational cost, and comparable communication cost when compered these parameters with the other competing schemes.
Dharminder Chaudhary, Challa Bhageeratha Reddy, Ashok Kumar Das, Youngho Park 0005, Sajjad Shaukat Jamal
IEEE Internet Things J.4
2023 Fog-Based Single Sign-On Authentication Protocol for Electronic Healthcare Applications
abstract
Increasing use of electronic healthcare (eHealth) services demands efficient and secure solutions. Such solutions need to ensure the prevention of unauthorized access to the patient data and provide faster response. Fog computing is a viable solution to provide faster responses in eHealth systems. Key distribution and authentication play a major role in providing security to patient data. Existing centralized architectures are susceptible to single-point-of-compromise, that is, the entire system is vulnerable when the centralized authority keys are unexpectedly revealed to an adversary. In this article, we present a fog-based semi-centralized architecture for key distribution and authentication, in which the key distribution service is delegated to individual fog servers. Thus, the fog servers become responsible for key distribution to the users without the involvement of the centralized authority, which forms a paradigm of multiple client–server architecture. Thus, achieving centralized trust by designing a single sign-on authentication in such environments is a challenging problem. We design a single sign-on authentication protocol for semi-centralized architectures to achieve centralized trust by ensuring that the user keys are independent of the centralized authority’s keys. A rigorous security analysis under the random oracle model is performed to prove that the proposed protocol is secure against single-point-of-compromise. We also conduct extensive experiments to show the practical perspectives of the proposed scheme. The results show that the protocol is suitable for eHealth applications, including emergency services.
Srijanee Mookherji, Vanga Odelu, Rajendra Prasath, Ashok Kumar Das, Youngho Park 0005
IEEE Internet Things J.5
2023 Blockchain-Enabled Secure Big Data Analytics for Internet of Things Smart Applications
abstract
Smart devices in an Internet of Things (IoT) generate a massive amount of big data through sensors. The data is used to build intelligent applications through machine learning (ML). To build these applications, the data is collected from devices into data centers for training ML models. Usually, the training of models is performed on central server, but this approach requires the transfer of data from devices to central server. This centralized training approach is not efficient because the users are much less likely to share data to the centralized data centers due to privacy issues and bandwidth limitations. To mitigate these issues, we propose an efficient hybrid secure federated learning approach with the blockchain to securely train the model locally on devices and then to store the model and its parameters into the blockchain for traceability and immutability. A detailed security and performance analysis is presented to show the efficacy of the proposed approach in terms of security, resilience against many security attacks, and cost effectiveness in computation and communication as compared to other existing competing schemes.
Prakash Tekchandani, Indranil Pradhan, Ashok Kumar Das, Neeraj Kumar 0001, Youngho Park 0005
IEEE Internet Things J.5
2023 Designing attribute-based verifiable data storage and retrieval scheme in cloud computing environment
Sourav Bera, Suryakant Prasad, Y. Sreenivasa Rao, Ashok Kumar Das, Youngho Park 0005
J. Inf. Secur. Appl.5
2023 BPPS:Blockchain-Enabled Privacy-Preserving Scheme for Demand-Response Management in Smart Grid Environments
abstract
With the ongoing revolutionary growth of the industrial Internet of Things and smart grid networks, smart grid (SG) communication has been acknowledged as a next-generation network for intelligent and efficient electric power transmission. In SG networks, smart meters (SMs) generally send requests for electricity demand to service providers (SPs), which deal with the requests for efficient energy distribution. However, SGs experience many security issues with the deployed SMs and untrusted wireless communication. To tackle these security issues, we propose a privacy-preserving authentication scheme for demand response management in SGs, called BPPS. It can resist various attacks and achieve secure mutual authentication with key agreement; moreover, it provides integrity of demand-response data using blockchain. Moreover, we perform the informal and formal (mathematical) security analysis to confirm that BPPS is secure against various attacks and achieves session key security, respectively. Furthermore, we conduct the performance and simulation analysis for SGs using NS3 and Ethereum testnet. Consequently, BPPS provides high-level security and can be applied to actual SG networks.
Kisung Park 0002, JoonYoung Lee, Ashok Kumar Das, Youngho Park 0005
IEEE Trans. Dependable Secur. Comput.4
2023 Blockchain-Enabled Authenticated Key Agreement Scheme for Mobile Vehicles-Assisted Precision Agricultural IoT Networks
abstract
Precision farming has a positive potential in the agricultural industry regarding water conservation, increased productivity, better development of rural areas, and increased income. Blockchain technology is a better alternative for storing and sharing farm data as it is reliable, transparent, immutable, and decentralized. Remote monitoring of an agricultural field requires security systems to ensure that any sensitive information is exchanged only among authenticated entities in the network. To this end, we design an efficient blockchain-enabled authenticated key agreement scheme for mobile vehicles-assisted precision agricultural Internet of Things (IoT) networks called$AgroMobiBlock$. The limited existing work on authentication in agricultural networks shows passive usage of blockchains with very high costs.$AgroMobiBlock$proposes a novel idea using the elliptic curve operations on an active hybrid blockchain over mobile farming vehicles with low computation and communication costs. Formal and informal security analysis along with the formal security verification using the Automated Validation of Internet Security Protocols and Applications (AVISPA) software tool have shown the robustness of$AgroMobiBlock$against man-in-the-middle, impersonation, replay, physical capture, and ephemeral secret leakage attacks among other potential attacks. The blockchain-based simulation on large-scale nodes shows the computational time for an increase in the network and block sizes. Moreover, the real-time testbed experiments have been performed to show the practical usefulness of the proposed scheme.
Anusha Vangala, Ashok Kumar Das, Ankush Mitra, Sajal K. Das 0001, Youngho Park 0005
IEEE Trans. Inf. Forensics Secur.5
2023 A Provably Secure Mobile User Authentication Scheme for Big Data Collection in IoT-Enabled Maritime Intelligent Transportation System
abstract
The emergence of contemporary technologies like cloud computing and the Internet of Things (IoT) has revolutionized the trends in the cyber world to serve humanity. There are plenty of applications in which they are being used, especially in smart cities and their constituents, Maritime Transportation System (MTS) is one of them. The IoT-enabled MTS has the potential to entertain the growing challenges of modern-day ship transportation. Secure real-time data access from numerous smart IoT devices is the most critical and crucial exercise for Big Data acquisition in IoT-enabled MTS. Therefore, we have developed a Physically Unclonable Function (PUF) based authenticated key agreement solution to deal with this challenge. This solution enables the mobile user and IoT node to mutually authenticate each other via Cloud-Gateway before real-time data exchange and transmission in IoT-enabled MTS. The use of PUF in our solution brings invincibility against physical security threats. An inclusive security analysis under the assumption of the specified threat model is carried out to substantiate the security resilience of our solution. The conduct of our solution is realized through security features, communication, and computation cost and It has been observed that our solution achieves efficiency of 37.3% and 9.7% in communication and computation overhead, respectively. Moreover, the network performance effectiveness of our solution is demonstrated in NS3 implementation.
Khalid Mahmood 0002, Javed Ferzund, Muhammad Asad Saleem, Salman Shamshad, Ashok Kumar Das, Youngho Park 0005
IEEE Trans. Intell. Transp. Syst.6
2022 Secure biometric-based access control scheme for future IoT-enabled cloud-assisted video surveillance system
Palak Bagga, Ankush Mitra, Ashok Kumar Das, Pandi Vijayakumar, Youngho Park 0005, Marimuthu Karuppiah
Comput. Commun.5
2022 Designing Fine-Grained Access Control for Software-Defined Networks Using Private Blockchain
abstract
Emerging next-generation Internet yields proper administration of a wide-ranging dynamic network to assist rapid ubiquitous resource accessibility, whilst providing higher channel bandwidth. Since its inception, the traditional static network infrastructure-based solutions involve manual configuration and proprietary controls of networked devices. It then leads to improper utilization of the overall resources, and hence experiences various security threats. Although transport layer security (TLS)-based solution is presently advocated in the said framework, it is vulnerable to many security threats like man-in-the-middle, replay, spoofing, privileged insider, impersonation, and denial-of-service attacks. Moreover, the current settings of the said tool do not facilitate any secure and reliable mechanisms for data forwarding, application flow routing, new configuration deployment, and network event management. Also, it suffers from the single point of controller failure issue. In this article, we propose a new private blockchain-enabled fine-grained access control mechanism for the SDN environment. In this regard, attribute-based encryption (ABE) and certificate-based access control protocol are incorporated. This proposed solution can resist several well-known security threats, and alleviate different system-level inconveniences. The formal and informal security inspections and performancewise comparative study of the proposed scheme endorse better qualifying scores as compared to the other existing competing state-of-the-art schemes. Besides, the experimental testbed implementation and blockchain simulation show the implementation feasibility of the proposed mechanism.
Durbadal Chattaraj, Basudeb Bera, Ashok Kumar Das, Joel J. P. C. Rodrigues, Youngho Park 0005
IEEE Internet Things J.5
2022 SCS-WoT: Secure Communication Scheme for Web of Things Deployment
abstract
Web of Things (WoT) extends the Internet of Things (IoT) paradigm to facilitate communications among smart things/devices and Web-based applications. In other words, WoT systems generally provide a Web interface for the monitoring and controlling of smart devices over the Web, for example, in applications, such as home automation, intelligent transportation system, smart healthcare, smart cities, and smart agriculture. However, this results in the generation of significant volume of data (i.e., big data) and, hence, the importance of big data analytics. There are also associated security and privacy implications. Therefore, in this article, we present a signature-based authentication and key agreement scheme for the WoT environment and prove its security. We also evaluate the performance of SCS-WoT and compare it against four other competing schemes. The findings show that SCS-WoT achieves better performance in terms of communication cost, computational cost, and security and functionality.
Mohammad Wazid, Ashok Kumar Das, Kim-Kwang Raymond Choo, Youngho Park 0005
IEEE Internet Things J.4
2022 A Robust Authentication Protocol for Wireless Medical Sensor Networks Using Blockchain and Physically Unclonable Functions
abstract
Wireless medical sensor networks (WMSNs)-based medical systems are an emerging paradigm of the Internet of Medical Things (IoMT) in which the patients and doctors can access various healthcare services via wireless communication technology without visiting the hospital in person. However, an adversary attempts a variety of security attacks because the sensitive information in various fields is exchanged via an insecure channel. Thus, robust and lightweight authentication protocols are essential for providing dependable healthcare services in WMSN-based medical systems. Recently, Wang et al. (IEEE Internet of Things Journal, doi: 10.1109/JIOT.2021.3117762) proposed blockchain and physically unclonable functions (PUFs)-based lightweight authentication protocol for WMSN. They claimed that their protocol is resistant to cyber and physical security threats and also does provide necessary security requirements. However, we prove that their protocol is vulnerable to various security attacks, such as man-in-the-middle and session key disclosure attacks and also lacks mutual authentication. As a result, we propose a robust authentication protocol for WMSN using blockchain and PUF to address the security problems raised by Wang et al.’s scheme. we assess the security of the proposed scheme by using informal and formal security analyses, such as AVISPA simulation and the ROR oracle model. Furthermore, we present the testbed experiments using Raspberry PI 4 based on MIRACL Crypto SDK. Then, we show the performance of the enhanced scheme compared with related schemes based on testbed experiments. Consequently, our scheme is better suited for practical WMSN-based medical systems because it provides greater security and efficiency than competing schemes.
SungJin Yu, Youngho Park 0005
IEEE Internet Things J.2
2022 Authenticated Key Agreement Scheme With User Anonymity and Untraceability for 5G-Enabled Softwarized Industrial Cyber-Physical Systems
abstract
With the tremendous growth of Information and Communications Technology (ICT), Cyber Physical Systems (CPS) have opened the door for many potential applications ranging from smart grids and smart cities to transportation, retail, public safety and networking, healthcare and industrial manufacturing. However, due to communication via public channel occurring among various entities in an industrial CPS (ICPS) with the help of the 5G technology and Software-Defined Networking (SDN), it poses several potential security threats and attacks. To mitigate these issues, we propose a new three-factor user authentication and key agreement scheme (UAKA-5GSICPS) for 5G-enabled SDN based ICPS environment. UAKA-5GSICPS allows an authorized user to access the real-time data directly from some designated Internet of Things (IoT)-based smart devices provided that a successful mutual authentication among them is executed via their controller node in the SDN network. It is shown to be robust against various potential attacks through detailed security analysis including the simulation-based formal security verification. A detailed comparative study with the help of experimental results shows that UAKA-5GSICPS achieves better trade-off among security and functionality features, communication and computation overheads as compared to other existing competing schemes.
Anil Kumar Sutrala, Mohammad S. Obaidat, Sourav Saha 0002, Ashok Kumar Das, Mamoun Alazab, Youngho Park 0005
IEEE Trans. Intell. Transp. Syst.6
2020 Certificateless-Signcryption-Based Three-Factor User Access Control Scheme for IoT Environment
abstract
User access control is a crucial requirement in any Internet of Things (IoT) deployment, as it allows one to provide authorization, authentication, and revocation of a registered legitimate user to access real-time information and/or service directly from the IoT devices. To complement the existing literature, we design a new three-factor certificateless-signcryption-based user access control for the IoT environment (CSUAC-IoT). Specifically, in our scheme, a user U's password, personal biometrics, and mobile device are used as the three authentication factors. By executing the login and access control phase of CSUAC-IoT, a registered user (U) and a designated smart device (Si) can authorize and authenticate mutually via the trusted gateway node (GN) in a particular cell of the IoT environment. In our setting, the environment is partitioned into disjoint cells, and each cell will contain a certain number of IoT devices along with a GN. With the established session key between U and Si, both entities can then communicate securely. In addition, CSUAC-IoT supports new IoT devices deployment, user revocation, and password/biometric update functionality features. We prove the security of CSUAC-IoT under the real-or-random (ROR) model, and demonstrate that it can resist several common attacks found in a typical IoT environment using the AVISPA tool. A comparative analysis also reveals that CSUAC-IoT achieves better tradeoff for security and functionality, and computational and communication costs, in comparison to five other competing approaches.
Shobhan Mandal, Basudeb Bera, Anil Kumar Sutrala, Ashok Kumar Das, Kim-Kwang Raymond Choo, Youngho Park 0005
IEEE Internet Things J.6
2020 Multi-Authority CP-ABE-Based user access control scheme with constant-size key and ciphertext for IoT deployment
Soumya Banerjee 0001, Sandip Roy 0001, Vanga Odelu, Ashok Kumar Das, Samiran Chattopadhyay, Joel J. P. C. Rodrigues, Youngho Park 0005
J. Inf. Secur. Appl.7
2020 A lightweight three-factor authentication protocol for digital rights management system
SungJin Yu, Kisung Park 0002, YoHan Park 0001, HyungPyo Kim, Youngho Park 0005
Peer-to-Peer Netw. Appl.5
2019 A Secure Authentication and Key Establishment Scheme for Wearable Devices
abstract
With the rapid development of micro-electronics and Information and Communication Technology (ICT), users can utilize various service such as Internet of Things(IoT), smart-healthcare and smart-home using wearable devices. However, the sensitive information of user are revealed by attackers because the medical services are provided through open channel. Therefore, secure mutual authentication and key establishment are essential to provide secure services for legitimate users in Wireless Body Area Networks(WBAN). In 2019, Gupta et al. proposed a lightweight anonymous user authentication and key establishment scheme for wearable devices. We demonstrate that their scheme cannot withstand user impersonation, session key disclosure and wearable device stolen attacks. We also propose a secure and lightweight mutual authentication and key establishment scheme using wearable devices to resolve the security shortcomings of Gupta et al.'s scheme. The proposed scheme can be suitable to resource-limited environments.
MyeongHyun Kim, JoonYoung Lee, SungJin Yu, Kisung Park 0002, YoHan Park 0001, Youngho Park 0005
ICCCN6
2019 A Secure Multi-Factor Remote User Authentication Scheme for Cloud-IoT Applications
abstract
With the development of internet of things (IoT) and communication technology, the sensors and embedded devices collect a large amount of data and handle it. However, IoT environment cannot efficiently treat the big data and is vulnerable to various attacks because IoT is comprised of resource limited devices and provides a service through a open channel. In 2018, Sharma and Kalra proposed a lightweight multi-factor authentication protocol for cloud-IoT environment to overcome this problems. We demonstrate that Sharma and Kalra's scheme is vulnerable to identity and password guessing, replay and session key disclosure attacks. We also propose a secure multifactor authentication protocol to resolve the security problems of Sharma and Kalra's scheme, and then we analyze the security using informal analysis and compare the performance with Sharma and Kalra's scheme. The proposed scheme can be applied to real cloud-IoT environment securely.
JoonYoung Lee, MyeongHyun Kim, SungJin Yu, Kisung Park 0002, Youngho Park 0005
ICCCN5
2019 AKM-IoV: Authenticated Key Management Protocol in Fog Computing-Based Internet of Vehicles Deployment
abstract
Internet of Vehicles (IoV) is an intelligent application of Internet of Things (IoT) in smart transportation that takes intelligent commitments to the passengers to improve traffic safety and efficiency, and generate a more enjoyable driving and riding environment. Fog cloud-based IoV is another variant of mobile cloud computing where vehicular cloud and Internet can co-operate in more effective way in IoV. However, more increasing dependence on wireless communication, control, and computing technology makes IoV more dangerous to prospective attacks. For secure communication among vehicles, road-side units, fog and cloud servers, we design a secure authenticated key management protocol in fog computing-based IoV deployment, called AKM-IoV. In the designed AKM-IoV, after mutual authentication between communicating entities in IoV they establish session keys for secure communications. AKM-IoV is tested for its security analysis using the formal security analysis under the widely accepted real-or-random (ROR) model, informal, and formal security verification using the broadly accepted automated validation of Internet security protocols and applications (AVISPAs) tool. The practical demonstration of AKM-IoV is shown using the NS2 simulation. In addition, a detailed comparative study is conducted to show the efficiency and functionality and security features supported by AKM-IoV as compared to other existing recent protocols.
Mohammad Wazid, Palak Bagga, Ashok Kumar Das, Sachin Shetty, Joel J. P. C. Rodrigues, Youngho Park 0005
IEEE Internet Things J.6
2018 Design of Secure and Lightweight Authentication Protocol for Wearable Devices Environment
abstract
Wearable devices are used in various applications to collect information including step information, sleeping cycles, workout statistics, and health-related information. Due to the nature and richness of the data collected by such devices, it is important to ensure the security of the collected data. This paper presents a new lightweight authentication scheme suitable for wearable device deployment. The scheme allows a user to mutually authenticate his/her wearable device(s) and the mobile terminal (e.g., Android and iOS device) and establish a session key among these devices (worn and carried by the same user) for secure communication between the wearable device and the mobile terminal. The security of the proposed scheme is then demonstrated through the broadly accepted real-or-random model, as well as using the popular formal security verification tool, known as the Automated validation of Internet security protocols and applications. Finally, we present a comparative summary of the proposed scheme in terms of the overheads such as computation and communication costs, security and functionality features of the proposed scheme and related schemes, and also the evaluation findings from the NS2 simulation.
Ashok Kumar Das, Mohammad Wazid, Neeraj Kumar 0001, Muhammad Khurram Khan, Kim-Kwang Raymond Choo, Youngho Park 0005
IEEE J. Biomed. Health Informatics6
2017 Mobile Cloud-Based Interactive 3D Rendering and Streaming System Over Heterogeneous Wireless Networks
abstract
This paper presents an effective mobile cloud-based interactive 3D rendering and streaming system with data-service cost constraints over heterogeneous wireless networks. The proposed system contains software-defined networking (SDN)-enabled adaptive cloud resource management module and context-aware 3D rendering and streaming module to enhance the quality-of-service of interactive 3D rendering and streaming services. The first module is designed to efficiently control the limited cloud resources, such as server computing power and available backbone link bandwidth, and the second module is implemented to pursue an effective tradeoff between 3D rendering quality and compressed image quality. The system is implemented using Mininet network emulator with an OpenDay-light SDN controller, and VirtualGL with an online open-source 3D game, PlaneShift. Finally, the system is examined at a mobile device connected to real long-term evolution and WiFi networks.
Donghyeok Ho, Hyungnam Kim, Wan Kim, Youngho Park 0005, Kyung-Ah Chang, Hyogun Lee, Hwangjun Song
IEEE Trans. Circuits Syst. Video Technol.4
2013 Entire network load-aware cooperative routing algorithm for video streaming over mobile ad hoc networks
abstract
ABSTRACT In this paper, we present an entire network load‐aware cooperative routing algorithm based on IEEE 802.11 multi‐rate for video streaming over mobile ad hoc networks. The proposed routing algorithm is designed to minimize the consumed time slots while guaranteeing the required time slots at all the pairs of adjacent nodes over the route and the contention neighbors of these nodes to support the route. Furthermore, the proposed routing algorithm can distribute the network loads well over the entire network. This technology is essential because video streaming applications require stringent quality of service and even larger network resources compared with traditional data services, and these demands may dramatically increase the entire network load and/or cause network congestion. Finally, experimental results are provided to show a performance of the proposed routing algorithm. Copyright © 2011 John Wiley & Sons, Ltd.
Oh Chan Kwon, Hyung Rai Oh, Zae-Kwun Lee, GyeongCheol Lee, Youngho Park 0005, Hwangjun Song
Wirel. Commun. Mob. Comput.5
2012 Data security in unattended wireless sensor networks with mobile sinks
abstract
ABSTRACT Unattended wireless sensor networks operating in hostile environments face the risk of compromise. Given the unattended nature, sensors must safeguard their sensed data of high value temporarily. However, saving data inside a network creates security problems due to the lack of tamper‐resistance of sensors and the unattended nature of the network. In some occasions, a network controller may periodically dispatch mobile sinks to collect data. If a mobile sink is given too many privileges, it will become very attractive for attack. Thus, the privilege of mobile sinks should be restricted. Additionally, secret keys should be used to achieve data confidentiality, integrity, and authentication between communicating parties. To address these security issues, we presentmAKPS, an asymmetric key predistribution scheme with mobile sinks, to facilitate the key distribution and privilege restriction of mobile sinks, and schemes for sensors to protect their collected data in unattended wireless sensor networks. Copyright © 2011 John Wiley & Sons, Ltd.
Jianfeng Ma 0001, Youngho Park 0005, Shangrong Xiang
Wirel. Commun. Mob. Comput.3
2011 Authentications and Key Management in 3G-WLAN Interworking
Xinghua Li 0001, Xiang Lu 0004, Jianfeng Ma 0001, Zhenfang Zhu, Li Xu 0002, Youngho Park 0005
Mob. Networks Appl.6
2010 Key Infection, Secrecy Transfer, and Key Evolution for Sensor Networks
abstract
Sensor networks are composed of a large number of low power sensor devices. For secure communication among sensors, secret keys are required to be established between them. Considering the strict resource constraints of sensors, key infection has been proposed by Anderson, Chan, and Perrig. However, because the communication keys are broadcasted in plaintext in key infection, some of them may be eavesdropped by an adversary. To address this security issue, secrecy transfer is presented, which utilizes pre-loaded secret keying material to enhance the security performance of key infection. To thwart on-going cryptanalytic attacks, a key evolution scheme is proposed to continuously refresh shared keys. Key evolution forces the adversary to keep monitoring traffic all the time after compromising a key; even if the adversary has compromised a key, it cannot catch up with the key evolution process, and may lose control of the compromised key quickly in a noisy communication environment. Analysis results show that key infection, secrecy transfer, and key evolution present viable trade-offs between security and resource consumption for smart dust sensor networks.
Jianfeng Ma 0001, Qingqi Pei, Liaojun Pang, Youngho Park 0005
IEEE Trans. Wirel. Commun.5
2007 An Enhanced One-Round Pairing-Based Tripartite Authenticated Key Agreement Protocol
Meng-Hui Lim, Sanggon Lee, Youngho Park 0005, Hoonjae Lee 0001
ICCSA (2)3
2007 An Enhanced ID-Based Deniable Authentication Protocol on Pairings
Meng-Hui Lim, Sanggon Lee, Youngho Park 0005, Hoonjae Lee 0001
ICCSA (2)3
2005 An Online Face Recognition System Using Multiple Compressed Images over the Internet
Hwangjun Song, Sun Chung, Youngho Park 0005
WISE3