EDBT 2026 Demo / reviewers in the wild / expert
Muhammad Khurram Khan
dblp:69/821
· DBLP profile ↗
207ranked-venue papers
15as first author
82since 2021 · last 2026
0000-0001-6636-0533ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 78 · 2 first-author · 42 since 2021Security and privacy · 40 · 6 first-author · 10 since 2021Applied, interdisciplinary, general and emerging computing · 28 · 2 first-author · 20 since 2021Systems, architecture and hardware · 19 · 2 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 19 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 18 · 2 first-author · 3 since 2021Databases, data management, data science and information retrieval · 4 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Toward Effective Communication Management in Cooperative Robotic-Enabled Healthcare Systems: Open Challenges and Future Research DirectionsabstractCooperative robotic healthcare systems (CRHS) are advanced technologies that enhance medical services by allowing robots to collaborate with healthcare professionals, making clinical practices safer and more efficient. However, for these systems to work efficiently, they need fast and reliable communication and computation, all while managing the limited resources and energy available in robot-embedded sensors. Therefore, this survey focuses on clarifying how various networking and computing decisions impact different aspects of this technology, such as latency, reliability, Quality of Service (QoS), and scalability, etc. We evaluated the recent research on resource allocation, as well as orchestration in edge, fog, and cloud computing, to have a holistic overview of what has been done so far in this field. Moreover, we analyzed communication technologies such as 5G, Ultra-Reliable Low-Latency Communication (URLLC), Time-Sensitive Networking (TSN), Software-Defined Networking (SDN), Network Function Virtualization (NFV), and network slicing to understand their role in RHCS QoS metrics. Our synthesis finds that (i) placing perception/control close to the edge consistently decreases end-to-end delay, (ii) SDN/NFV and time-sensitive networking improve predictable and real-time operation in multi-robot hospital environments; and (iii) learning-based scheduling and offloading often outperform static heuristics in variable workloads. Despite these advancements, we have identified several challenges in the literature, such as limited interoperability between different vendors and a lack of standardized benchmarks for Quality of Service (QoS), etc. Therefore, we conducted a comparative analysis to understand how specific design choices influence the QoS metrics of this technology. In addition, we have proposed potential research directions that address the open challenges to ensure the real deployment of this technology. Muhammad Adil 0002, Muhammad Khurram Khan, Aitizaz Ali, Hussein Abulkasim, Ahmed Farouk, Houbing Song, Zhanpeng Jin |
IEEE Internet Things J. | 2 |
| 2026 | From Sensing to Intelligence: How AI Improves mmWave Radar Capabilities for Contactless Health MonitoringabstractMillimeter-wave (mmWave) radar is becoming an important tool for contactless health monitoring because it can sense very small chest motions while preserving privacy by avoiding visual imagery. Existing surveys on radar- or RF-based vital sign monitoring either focus mainly on classical radar architectures and signal processing, provide broad RF sensing overviews in which mmWave healthcare is treated only briefly, or catalog machine learning models without clearly linking them to mmWave propagation, hardware constraints, datasets, and clinical evaluation practices. Because of these gaps, we believe the existing surveys do not provide a holistic, accurate picture of this technology. To address this, we present a comprehensive survey of AI-enabled mmWave radar for contactless health monitoring, covering the literature from 2015 to 2025. The objective of this work is to provide a clear, top-down understanding of the full sensing and inference pipeline by connecting the physical foundations of mmWave propagation and frequency-modulated continuous wave (FMCW) radar modeling with modern AI-based algorithms. We first summarize mmWave propagation, FMCW waveform and array design, and micromotion modeling, with emphasis on design choices that affect vital sign accuracy and robustness. To do this, we introduce a unified physics-to-intelligence framework that connects sensing configurations, subject scenarios, signal-processing and feature-representation pipelines, and the evolution of AI algorithms such as CNNs, LSTMs, transformers, self-supervised learning, and physics-guided networks. In parallel, we consolidate the scarce public mmWave FMCW datasets, together with windowing protocols and evaluation metrics, and highlight how limited dataset availability and heterogeneous benchmark practices continue to prevent fair comparison, reproducibility, and clinical translation. Building on this view, we discuss major challenges such as domain generalization, motion and interference, model interpretability and trust, privacy, multimodal fusion, and edge deployment, and we outline a practical roadmap for designing mmWave health monitoring systems that are robust across environments, efficient on embedded platforms, and aligned with clinical workflows. The survey is intended to serve researchers working at the intersection of wireless communications, sensing, and AI, both as a reference and a design guide for next-generation contactless health-monitoring applications. Shabih Ul Hassan, Muhammad Adil 0002, Naseer Ahmed Khan, Muhammad Khurram Khan, Zhanpeng Jin |
IEEE Internet Things J. | 4 |
| 2026 | HydraNet-PWCT: Physics-Constrained Dual-Polarimetric mmWave for Texture-Agnostic Soil HydrometryabstractSoil moisture is pivotal for precision irrigation, hydrologic prediction, and climate-resilient agriculture, yet a persistent gap remains between sparse in-situ probes and predominantly near-surface satellite retrievals. We present Polarimetric Wave Coherence Tomography (PWCT), a methodology that does not require soil-specific calibration and explores dual-polarized 77-81 GHz FMCW radar to recover root-zone moisture profiles. PWCT departs from amplitude-centric approaches by exploiting water-induced depolarization through: (i) a Polarimetric Coherence Index (PCI) that quantifies cross-polar phase decorrelation from subsurface reflections; (ii) frequency-hopped, orthogonal dual-pol chirps to better separate surface and volume interactions; and (iii) a Spatial Moisture Metric (SMM) derived fromkz-domain energy decay via wave-interference tomography. Implemented on a TI AWR1443 with a compact dual-pol MIMO setup, PWCT reconstructs depth profiles over 0-30 cm in 5 cm bins, requiring no soil-specific calibration but utilizing a one-time instrument-level calibration to ensure system consistency. We further introduce HydraNet, a physics-constrained network that ingests PCI-SMM features to deliver texture-agnostic VWC estimates. Across sand, loam, and clay, HydraNet achieves an RMSE of 0.82-2.15% VWC with TDR as the reference and demonstrates real-time edge inference. Results indicate that PWCT + HydraNet provides an accurate, low-maintenance framework for periodic field monitoring and irrigation decision support. Naveed Imran, Sana Hameed, Adi Alhudhaif, Jehad Ali, Muhammad Khurram Khan |
IEEE Internet Things J. | 5 |
| 2026 | MTT-TKG: Multitime-Gate, Time-Aware, and Time-Guided Representation Learning for TKGsabstractTemporal Knowledge Graph (TKG) representation learning embeds entities and relations into a low-dimensional space while preserving relational structures across time steps. Existing methods often neglect the critical role of timestamps in capturing evolving relational patterns. To bridge this gap, we propose MTT-TKG, a novel framework integrating three synergistic modules: (1) a Multi-Time Gate module modeling Knowledge Graph (KG) evolution across historical timestamps via multilayer gating; (2) a Time-Aware module capturing timestampspecific relational characteristics; (3) a Time-Guided module handling cross-graph temporal dependencies. An embeddingtime decoder completes the representation learning. Experiments on three real-world datasets demonstrate MTT-TKG’s superior performance in capturing temporal dynamics and relational structures. Qian Liu 0035, Siling Feng, Mengxing Huang, Uzair Aslam Bhatti, Muhammad Khurram Khan |
IEEE Internet Things J. | 5 |
| 2026 | Federated Contrastive Diffusion Prototypes for Robust Private LearningabstractThe secure deployment of Federated Learning (FL) is critically undermined by statistical data heterogeneity and a profound vulnerability to adversarial attacks, these weaknesses are exacerbated by FL’s privacy-preserving preclusion of large-scale, centralized data for robust training. Existing proto-typebased methods suffer from representation collapse when naively aggregating from non-IID clients, while generative approaches often lack a principled mechanism for synthesizing features that confer adversarial resilience. We introduce Federated Contrastive Diffusion Prototypes (Fed-CDP), a novel paradigm that transforms the server from a passive aggregator into an active synthesis hub for robust features. Fed-CDP aggregates lightweight client prototypes to serve as semantic anchors, guiding a server-side diffusion model via a contrastive objective. This process synthesizes a high-fidelity feature space explicitly optimized for maximal inter-class separability, a property intrinsically linked to robust generalization. These server-generated features are then distributed to clients as a potent regularizer, aligning disparate local models and directly mitigating client drift. Our extensive evaluations across multiple challenging datasets establish that Fed-CDP outperforms existing state-of-the-art baselines. For instance, on CIFAR-100 under severe heterogeneity (α = 0.1), Fed-CDP surpasses leading methods by nearly 5% in standard accuracy and over 9% in robust accuracy under Projected Gradient Descent attacks. Fed-CDP provides a new blueprint for building secure and high-performance collaborative AI, laying the foundation for trustworthy systems in critical sectors like finance and multi-institutional healthcare. Xiong Li 0002, Wei Liu 0077, Muhammad Khurram Khan, Jinjun Chen |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2026 | Unified Seamless Authenticated Key Agreement for Heterogeneous Train-to-Train Direct Communications Based on Distributed SDN
Wenfang Zhang, Zhuoqun Yan, Muhammad Khurram Khan |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2026 | Toward Security-Enhanced In-Band Network Telemetry in Programmable NetworksabstractIn-band Network Telemetry (INT) is a widely used monitoring framework in modern large-scale networks. It provides packet-level visibility into network conditions by inserting telemetry data into packets, enabling unprecedented fine-grained network management. However, this mechanism also introduces new vulnerabilities that malicious attackers can exploit. In this paper, we present eight In-band Network Telemetry Manipulation Attacks that take advantage of INT’s weakness, demonstrating that attackers can cause severe damage with little effort by manipulating INT packets. To address this issue, we designed SecureINT, a security-enhanced INT prototype that provides encryption and integrity verification for INT packets. Specifically, SecureINT deploys Even-Mansour and SipHash for confidentiality and integrity, respectively. It also uses a zero-delay rotation mechanism, which enables administrators to dynamically change the version of the deployed Even-Mansour/SipHash running on programmable switches without the need to re-install new programs. In this way, SecureINT can provide lasting security for INT packets using the limited resources of programmable switches. According to the experiments, SecureINT can be deployed on programmable switches using a single pipeline. Besides, the overhead of the rotation mechanism running on the control plane is still minimal. Dezhang Kong, Xiang Chen 0017, Zhengyan Zhou, Yi Shen 0012, Hongyan Liu 0001, Qiumei Cheng, Xuan Liu 0006, Dong Zhang 0010, Chunming Wu 0001, Muhammad Khurram Khan |
IEEE Trans. Netw. Serv. Manag. | 11 |
| 2026 | Mitigating the Lateral Movement of APT in IIoT With an Efficient Moving Target Defense and Cyber Deception ApproachabstractThe convergence of Information Technology (IT) and Operational Technology (OT) has made Industrial Internet of Things (IIoT) systems a prominent target for Advanced Persistent Threats (APTs). Lateral movement is a critical stage in APT infiltration, yet most existing mitigation methods rely on static, reactive approaches, leaving proactive defense mechanisms underexplored. Moreover, in real-world scenarios, attackers and defenders act sequentially under bounded rationality, rendering existing proactive schemes unable to adapt dynamically to evolving adversarial strategies. To address these challenges, this paper proposes a novel hybrid defense framework that integrates Moving Target Defense (MTD) with cyber deception. Our approach actively confuses attackers through camouflage information, dynamically adapts the attack surface, and optimizes defense strategies in real time. We model the strategic interaction between defender and attacker using a Stackelberg game framework enhanced with Prospect Theory (PT) to account for bounded rationality, and we design an efficient algorithm to compute optimal defense policies. Additionally, we introduce a subnet shuffling technique designed to prevent attackers with low privileges from exploiting zero-day vulnerabilities to penetrate higher-privilege subnets. The proposed framework is validated through comprehensive simulations and real-world experiments on a Software-Defined Networking (SDN) testbed. Experimental results demonstrate that our method effectively mitigates lateral movement attacks while maintaining an acceptable level of network shuffling overhead in IIoT environments. Xiaodong Zang, Fangbo Hou, Xuan Liu 0006, Muhammad Khurram Khan, Daohua Liu |
IEEE Trans. Reliab. | 4 |
| 2025 | Overview of AI and communication for 6G network: fundamentals, challenges, and future research opportunitiesabstractAbstract With the growing demand for seamless connectivity and intelligent communication, the integration of artificial intelligence (AI) and sixth-generation (6G) communication networks has emerged as a transformative paradigm. By embedding AI capabilities across various network layers, this integration enables optimized resource allocation, improved efficiency, and enhanced system robust performance. This paper presents a comprehensive overview of AI and communication for 6G networks, with a focus on their foundational principles, inherent challenges, and future research opportunities. We first review the integration of AI and communications in the context of 6G, exploring the driving factors behind incorporating AI into wireless communications, as well as the vision for the convergence of AI and 6G. The discourse then transitions to a detailed exposition of the envisioned integration of AI within 6G networks, divided into three progressive stages. The first stage, AI for network, focuses on employing AI to augment network performance, optimize efficiency, and enhance user service experiences. The second stage, network for AI, highlights the role of the network in facilitating and buttressing AI operations and presents key enabling technologies. We compare wireless network large models with conventional large language models (LLMs), and identify key design principles and components for building wireless network architectures. In the final stage, AI as a service, it is anticipated that future 6G networks will innately provide AI functions as services, supporting application scenarios like immersive communication and intelligent industrial robots. Specifically, we define the quality of AI service, which refers to a framework for measuring AI services within the network. We further summarize the standardization process of AI for wireless networks, highlighting key milestones and ongoing efforts. In addition, we analyze the critical challenges faced by the integration of AI and communications in 6G. Finally, we outline promising future research opportunities that are expected to drive the development and refinement of AI and 6G communications. Qimei Cui, Xiaohu You 0001, Wei Ni 0001, Guoshun Nan, Xuefei Zhang 0003, Jianhua Zhang 0001, Xinchen Lyu, Ming Ai, Xiaofeng Tao 0001, Zhiyong Feng 0001, Ping Zhang 0003, Qingqing Wu 0001, Meixia Tao, Yongming Huang 0001, Chongwen Huang, Guangyi Liu 0001, Chenghui Peng, Zhiwen Pan, Dusit Niyato, Tao Chen 0011, Muhammad Khurram Khan, Abbas Jamalipour, Mohsen Guizani, Chau Yuen |
Sci. China Inf. Sci. | 22 |
| 2025 | NDIF: A distributed framework for efficient in-network neural network inference
Shengrui Lin, Shaowei Xu, Binjie He, Hongyan Liu 0001, Dezhang Kong, Xiang Chen 0017, Dong Zhang 0010, Chunming Wu 0001, Ming Li 0056, Xuan Liu 0006, Yuqin Wu, Muhammad Khurram Khan |
Comput. Secur. | 12 |
| 2025 | LRCN: Layer-residual Co-Attention Networks for visual question answering
Dezhi Han, Jingya Shi, Huafeng Wu, Yachao Zhou, Ling-Huey Li, Muhammad Khurram Khan, Kuanching Li |
Expert Syst. Appl. | 7 |
| 2025 | PDFed-ALD: Adaptive Primal-Dual Federated Learning Under Industrial Internet of ThingsabstractFederated Learning (FL) is a distributed training paradigm that enables multiple devices in the Industrial Internet of Things (IIoT) to collaboratively train a global model without sharing private data. However, non-IID data in FL leads to client drift, which significantly degrades the performance of the global model in IIoT scenarios. While the primal-dual update method effectively mitigates client drift through dynamic regularization, optimizing the global model remains a significant challenge in IIoT due to the high degree of data heterogeneity. To address this challenge, we propose a novel FL method, PDFed-ALD, which effectively mitigates client drift and improves global model’s performance under high data heterogeneity. The core of PDFed-ALD is adaptive local distillation mechanism, which employs an adaptive distillation temperature based on the relative degree of data heterogeneity, dynamically correcting gradient updates, alleviating the issue of client drift. Furthermore, to reduce variance among local gradients, PDFed-ALD introduces a momentum-based minimum sharpness gradient correction method, which enhances local consistency by minimizing the variance between gradients across clients. Extensive experiments on image classification tasks using CIFAR-10, CIFAR-100 and MVTEC datasets demonstrate that PDFed-ALD outperforms state-of-the-art (SOTA) methods in terms of both accuracy and convergence speed across various settings, including client scale, participation rate, and degree of data heterogeneity. Jinshan Lai, Muhammad Khurram Khan, Fengli Zhang, Jieying Zhao, Ruijin Wang, Xiong Li 0002 |
IEEE Internet Things J. | 3 |
| 2025 | Protecting IoT-Enabled Healthcare Data at the Edge: Integrating Blockchain, AES, and Off-Chain Decentralized StorageabstractOver the past two decades, the rapid growth of the Internet of Things (IoT) has begun to transform traditional healthcare systems into intelligent systems; however, hospitals have encountered challenges in securely storing patient data within centralized architectures due to their lack of efficiency and security features. Blockchain technology offers a secure and reliable decentralized framework for storing and sharing healthcare data among various stakeholders, including patients, doctors, nurses, insurance companies, and pharmaceutical firms. In this article, we propose a blockchain-based data-protection scheme deployed at edge nodes. The proposed scheme uses the interplanetary file system (IPFS) model to address storage and data-protection issues in an IoT-edge-enabled smart healthcare system. First, the security issues in smart healthcare systems are identified, and the impact of these issues on patient privacy and hospital infrastructure is considered. Then, a technique based on the 128-bit Advanced Encryption Standard is proposed to encrypt patient information and store it in an IPFS-based decentralized network. Edge-computing techniques are used to perform computations at the edge level within a decentralized architecture, thereby addressing the computational challenges associated with cloud computing. Lastly, the encryption keys are stored using blockchain technology to address the issue of restricted computational power on low-end devices through off-chain and on-chain business processes. The experimental results demonstrate that the proposed scheme achieves a key management time of 0.2 ms, file retrieval time of 0.57 s, throughput of 0.11 Mb/s, encryption time of 1.96 ms, and decryption time of 1.91 ms. These findings indicate that the proposed scheme outperforms previously reported approaches with respect to key management time, file retrieval efficiency, and its potential for edge deployment and off-chain capabilities. Consequently, the proposed scheme is highly suited for efficiently securing patient data within IoT-enabled smart healthcare systems. Bhabendu Kumar Mohanta, Ali Ismail Awad, Mohan Kumar Dehury, Hitesh Mohapatra, Muhammad Khurram Khan |
IEEE Internet Things J. | 5 |
| 2025 | Anomaly Detection in Internet of Things System Calls Using a Centroid-Based Vector-Space ModelabstractIdentifying attacks on Internet of Things (IoT) systems through anomaly detection remains a critical area of research. One common and effective strategy in this field involves monitoring system-related data during normal operation to establish a baseline of expected behavior, followed by continuous monitoring to identify deviations from this baseline. System call sequences, which provide a low-level representation of the behavior of a system, are widely regarded as a valuable resource for anomaly detection; however, challenges such as the categorical nature of system call data, inconsistencies in sequence lengths, repeating patterns, and the diversity of activities across single-and multi-process environments complicate the effectiveness of existing methods. To address these challenges, we propose a centroid-based anomaly detection approach that transforms IoT system call data into word vectors, creating a central vector to represent normal behavior. A weighted vector-space model is then used to set a threshold distance for distinguishing between normal and malicious sequences. The effectiveness of the proposed method is evaluated across three distinct datasets: the Australian Defense Force Academy Linux Dataset (ADFA-LD) and the University of New Mexico (UNM) datasets, including UNM-Sendmail and UNM-Line Printer Remote (LPR). The method surpasses existing approaches on the ADFA-LD dataset, achieving an accuracy of 99.02%, a false-positive rate (FPR) of 1.96%, and an area under the receiver operating characteristic curve (AUC) of 0.9923. For the UNM datasets, the performance metrics indicate a detection accuracy of 99.7%, an FPR of 0.28%, and an AUC of 0.9983. The average processing time was measured as 1–3 ms. The experimental results and subsequent analysis reveal promising performance, demonstrating the generalizability of the proposed method across various datasets. Nouman Shamim, Muhammad Asim 0001, Ali Ismail Awad, Muhammad Khurram Khan |
IEEE Internet Things J. | 4 |
| 2025 | FlowTracker: A refined and versatile data plane measurement approach
Chunming Wu 0001, Zhengyan Zhou, Di Wang 0003, Dezhang Kong, Muhammad Khurram Khan, Xuan Liu 0006 |
J. Netw. Comput. Appl. | 6 |
| 2025 | Blockchain-based Deep Learning Models for Intrusion Detection in Industrial Control Systems: Frameworks and Open IssuesabstractCritical infrastructure and industrial systems are both becoming more and more networked and equipped with computing and communications tools. To manage processes and automate them where possible, Industrial Control Systems (ICS) manage a variety of components, including monitoring tools and software platforms. More complicated data is now being run on the networks, including data(past), money(present), and brains (future). In order to predictably detect specific services and patterns (deep learning) and automatically check authenticity and transfer value (blockchain), deep learning and blockchain are integrated into the ICS network. Hence, we conducted a thorough examination of the models published in the literature in order to comprehend how to integrate machine learning and blockchain efficiently and successfully for intrusion detection services. We also provide useful guidance for future research in this area by noting significant issues that must be addressed before substantial deployments of IDS models in ICS. Devi Priya V. S, S. Sibi Chakkaravarthy, Muhammad Khurram Khan |
J. Netw. Comput. Appl. | 3 |
| 2025 | Comments on "VCD-FL: Verifiable, Collusion-Resistant, and Dynamic Federated Learning"abstractGao et al. (2023)recently proposed a collusion-resistant and verifiable federated learning framework named VCD-FL (IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, vol. 18, pp. 3760–3773, 2023). However, in this letter, we show that VCD-FL fails to achieve its claimed security goals. In particular, we demonstrate that their designed commitment scheme, which serves as the core component of the proposed collusion-resistant verification mechanism, is unsafe, and then we present a feasible collusion attack launched by the aggregation server and corrupt clients by leveraging the existing security vulnerabilities. Zhuoqun Yan, Wenfang Zhang, Muhammad Khurram Khan |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | DBKE: Design of Blockchain-Envisioned Vehicle-to-Vehicle Secure Key Management Protocol Using ECCabstractVehicle-to-vehicle (V2V) authentication is essential in the Vehicular Ad-hoc Network (VANET). V2V communication improves the safety of drivers and assists them in making the appropriate decision according to road conditions. Since V2V communication happens in open public channels, an adversary takes advantage of it and tries to launch several potential threats. This article designs a blockchain-assisted V2V communication and authentication scheme using Elliptic Curve Cryptography (ECC) and a Physically Unclonable Function (PUF) called DBKE. In DBKE, vehicles perform their registration with their nearest Roadside Unit (RSU) without assisting the centralized cloud server. Then, one vehicle can communicate with another using the information stored in the blockchain. During the communication, both vehicles first perform the process of mutual authentication and then securely generate the session keys without sending the private parameters to the public channels. The formal analysis of DBKE is done with the Scyther and Real-or-Random (ROR) models, which confirm that the DBKE is robust and safe from attacks. Furthermore, the detailed comparative study of the security features reveals that the DBKE scheme provides superior security and low computation cost compared to the existing V2V authentication protocols. Sanjeev Kumar Dwivedi, Ruhul Amin 0001, Muhammad Khurram Khan, Ashok Kumar Das, Adesh Pandey, Saifulla Md. Abdul |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2025 | DYNAMIC-TRUST: Blockchain-Enhanced Trust for Secure Vehicle Transitions in Intelligent Transport SystemsabstractIntelligent transportation systems (ITS) improve vehicle connectivity, traffic efficiency, and road safety. Conversely, quick and safe vehicle authentication still poses a significant issue, especially at the handover time when switching between roadside units (RSUs), where network efficacy is influenced by computational overhead and re-authentication delays. To overcome these issues, this paper proposes DYNAMIC-TRUST. This blockchain-based authentication framework relies on the Proof of Trust (PoT) consensus mechanism to avoid redundant re-authentication, minimizing computation and communication costs. Compared to conventional authentication approaches, our method decentralizes vehicle revocation, allowing RSUs to revoke compromised vehicles autonomously without relying on a trusted authority, providing resilience regardless of adversarial conditions. The proposed framework’s resistance to identity theft, replay, and Sybil attacks has been proven by formal security analysis using Scyther and the Real-Or-Random (ROR) oracle model. Also, the Simulation of Urban Mobility (SUMO) is used to evaluate real-world practicality, proving improved scalability, lowered authentication latency, and greater network efficiency over various vehicular circumstances. Blockchain’s potential for enhancing vehicular network performance, trust, and security is highlighted in this study, which helps to develop smart cities and 6G-enabled Internet of Vehicles (IoV) infrastructures. Praneetha Surapaneni, Sriramulu Bojjagani, Muhammad Khurram Khan |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2024 | Model-agnostic generation-enhanced technology for few-shot intrusion detection
Junpeng He, Lingfeng Yao, Xiong Li 0002, Muhammad Khurram Khan, Weina Niu, Xiaosong Zhang 0001, Fagen Li |
Appl. Intell. | 4 |
| 2024 | A comprehensive examination of email spoofing: Issues and prospects for email security
S. Sibi Chakkaravarthy, Devi Priya V. S, Tarun Reddi, Mulka Sai Tharun Reddy, Muhammad Khurram Khan |
Comput. Secur. | 5 |
| 2024 | Global insights and the impact of generative AI-ChatGPT on multidisciplinary: a systematic review and bibliometric analysisabstractIn 2022, OpenAI's unveiling of generative AI Large Language Models (LLMs)- ChatGPT, heralded a significant leap forward in human-machine interaction through cutting-edge AI technologies. With its surging popularity, scholars across various fields have begun to delve into the myriad applications of ChatGPT. While existing literature reviews on LLMs like ChatGPT are available, there is a notable absence of systematic literature reviews (SLRs) and bibliometric analyses assessing the research's multidisciplinary and geographical breadth. This study aims to bridge this gap by synthesising and evaluating how ChatGPT has been integrated into diverse research areas, focussing on its scope and the geographical distribution of studies. Through a systematic review of scholarly articles, we chart the global utilisation of ChatGPT across various scientific domains, exploring its contribution to advancing research paradigms and its adoption trends among different disciplines. Our findings reveal a widespread endorsement of ChatGPT across multiple fields, with significant implementations in healthcare (38.6%), computer science/IT (18.6%), and education/research (17.3%). Moreover, our demographic analysis underscores ChatGPT's global reach and accessibility, indicating participation from 80 unique countries in ChatGPT-related research, with the most frequent countries keyword occurrence, USA (719), China (181), and India (157) leading in contributions. Additionally, our study highlights the leading roles of institutions such as King Saud University, the All India Institute of Medical Sciences, and Taipei Medical University in pioneering ChatGPT research in our dataset. This research not only sheds light on the vast opportunities and challenges posed by ChatGPT in scholarly pursuits but also acts as a pivotal resource for future inquiries. It emphasises that the generative AI (LLM) role is revolutionising every field. The insights provided in this paper are particularly valuable for academics, researchers, and practitioners across various disciplines, as well as policymakers looking to grasp the extensive reach and impact of generative AI technologies like ChatGPT in the global research community. Nauman Khan, Zahid Khan, Anis Koubaa, Muhammad Khurram Khan, Rosli Salleh |
Connect. Sci. | 4 |
| 2024 | Healthcare Internet of Things: Security Threats, Challenges, and Future Research DirectionsabstractInternet of Things (IoT) applications are switching from general to precise in different industries, e.g., healthcare, automation, military, maritime, smart cities, transportation, logistics, and many more. In the healthcare domain, these applications had demonstrated an incredible improvement in patient assessment, monitoring, and prescription, etc., with ease of access through the Internet. Despite its benefits, this technology also offers several security challenges for the research community and healthcare stakeholders, because of its wireless communication and open-area deployment. To explore, patient wearable devices and other networking entities follows unstructured communication format to share their accumulated data in the network, which makes them susceptible to manifold security threats. Considering the significance of these applications, data acquisition, processing, storage, and assessment on client and remote sides need a high standard of secure communication infrastructure. Therefore, security of these applications is one of the major obstacles that prevent their widespread use in different healthcare domains. To discuss different security constraints, in this paper, we present a comprehensive survey of the theoretical literature from 2015-to-2023 to highlight the unresolved security problems of this emerging technology. Based on the evaluated literature pros and cons, we determine the security requirements and challenges of Healthcare-IoT (HC-IoT) applications. Following this, we demonstrate future research directions that could be useful for the researchers and industry stakeholders working in this domain. To demonstrate the uniqueness of this work and claim its contribution, we compare our work section-wise with previously published papers to answer the question of reviewers, editors, students, and readers, why this review article is required in the presence of already published review articles. Muhammad Adil 0002, Muhammad Khurram Khan, Neeraj Kumar 0001, Muhammad Attique 0001, Ahmed Farouk, Mohsen Guizani, Zhanpeng Jin |
IEEE Internet Things J. | 2 |
| 2024 | Blockchain-Based Mutual Authentication Protocol for IoT-Enabled Decentralized Healthcare EnvironmentabstractIn the ever-evolving landscape of technology, healthcare continuously harnesses its benefits, propelling advancements in medical practices. Within intelligent healthcare, medical robots play a pivotal role, providing integral support to healthcare professionals, streamlining processes, and delivering efficient services. These robots securely transmit patient treatment plans, transferring them to cloud storage and subsequently storing them in blockchain systems. This innovative approach ensures the integrity and accessibility of patient data, introducing novel avenues for seamless interaction with medical information for hospitals and patients’ families. Despite these advantages, the looming privacy risks associated with sensitive patient data transmission pose a compelling challenge, demanding a comprehensive solution. In response to this challenge, we propose a mutual authentication and key agreement protocol designed to optimize healthcare services while prioritizing data security and patient privacy. To validate the robustness of our authentication protocol, we conduct thorough analyses based on both formal and informal models, establishing a foundational framework for evaluating the protocol’s security. Additionally, we perform a comprehensive comparative analysis, assessing the proposed protocol against existing counterparts across various dimensions. This comparative scrutiny reveals the superiority of our protocol in terms of security, as well as its efficiency in communication cost and computational overhead. These findings affirm the efficacy of our proposed solution in navigating the intricate interplay between medical robotics, blockchain, and data security. Chien-Ming Chen 0001, Zhaoting Chen, Saru Kumari, Mohammad S. Obaidat, Joel J. P. C. Rodrigues, Muhammad Khurram Khan |
IEEE Internet Things J. | 6 |
| 2024 | A Privacy-Preserving Authentication Protocol for Electric Vehicle Battery Swapping Based on Intelligent BlockchainabstractThe Internet of Vehicles (IoV) integrates wireless, mobile networking, cloud infrastructure, IoT, and wireless sensor networks, establishing an intelligent transportation system. While electric vehicles (EVs) contribute to environmental sustainability, they encounter challenges; battery-swapping technology emerges as a viable solution. Nevertheless, concerns arise regarding data security, privacy, and potential single points of failure. To address these issues, we propose a privacy-preserving authentication protocol based on intelligent blockchain. This protocol ensures the security and reliability of data storage and transaction verification processes, simultaneously upholding privacy, including user anonymity and untraceability. Additionally, leveraging the decentralized nature of intelligent blockchain, each participating node retains a copy of the data and verifies it through consensus algorithms to ensure its integrity and credibility. Verification using the Real-Oracle Random (ROR) model demonstrates both effectiveness and security, with informal analysis confirming resilience against known attacks. Comparative analysis underscores the proposed protocol’s security and performance advantages, placing emphasis on its reliability. Chien-Ming Chen 0001, Qingkai Miao, Saru Kumari, Muhammad Khurram Khan, Joel J. P. C. Rodrigues |
IEEE Internet Things J. | 4 |
| 2024 | 5G/6G-enabled metaverse technologies: Taxonomy, applications, and open security challenges with future research directions
Muhammad Adil 0002, Houbing Song, Muhammad Khurram Khan, Ahmed Farouk, Zhanpeng Jin |
J. Netw. Comput. Appl. | 3 |
| 2024 | Blockchain applications in UAV industry: Review, opportunities, and challenges
Diana Hawashin, Mohamed Nemer, Senay A. Gebreab, Khaled Salah 0001, Raja Jayaraman, Muhammad Khurram Khan, Ernesto Damiani |
J. Netw. Comput. Appl. | 6 |
| 2024 | Terra: Low-latency and reliable event collection in network measurement
Hongyan Liu 0001, Xiang Chen 0017, Qun Huang 0001, Dong Zhang 0010, Haifeng Zhou, Chunming Wu 0001, Xuan Liu 0006, Muhammad Khurram Khan |
J. Netw. Comput. Appl. | 9 |
| 2024 | Deep Neural Networks meet computation offloading in mobile edge networks: Applications, taxonomy, and open issues
Ehzaz Mustafa, Junaid Shuja, Faisal Rehman, Ahsan Riaz, Mohammed Maray, Muhammad Bilal 0003, Muhammad Khurram Khan |
J. Netw. Comput. Appl. | 7 |
| 2024 | Skin lesion classification using modified deep and multi-directional invariant handcrafted features
Jitesh Pradhan, Abhinav Kumar 0005, Muhammad Khurram Khan |
J. Netw. Comput. Appl. | 4 |
| 2024 | Development of a provably secure and privacy-preserving lightweight authentication scheme for roaming services in global mobility network
Dipanwita Sadhukhan, Sangram Ray, Mou Dasgupta, Muhammad Khurram Khan |
J. Netw. Comput. Appl. | 4 |
| 2024 | RPIFL: Reliable and Privacy-Preserving Federated Learning for the Internet of Things
Ruijin Wang, Jinshan Lai, Xiong Li 0002, Donglin He, Muhammad Khurram Khan |
J. Netw. Comput. Appl. | 5 |
| 2024 | CESA: Communication efficient secure aggregation scheme via sparse graph in federated learningabstractAs a distributed learning paradigm , federated learning can be effectively applied to the decentralized system since it can resolve the “data island” problem. However, it is also vulnerable to serious privacy breaches . Although existing secure aggregation technique can address privacy concerns, they also incur significant additional computation and communication costs. To address these challenges, this paper offers a C ommunication E fficient S ecure A ggregation scheme. Firstly, the central server uses the communication delay between terminals as the weight of the fully terminal-connected graph to transform it into a sparse connected graph based on the minimal spanning tree. Secondly, instead of relying on central server for key advertisement , the terminals advertise keys via a neighboring terminal forwarding approach based on sparsely graph. Thirdly, we propose using the central server for auxiliary advertising to address unexpected terminal dropout. Simultaneously, we theoretically demonstrate our scheme’s security and have lower computation and communication costs. Experiments show that CESA can reduce the running time by 28.2% without sacrificing security and model accuracy compared to conventional secure aggregation when there are 10 terminals in the system. Ruijin Wang, Xiong Li 0002, Jinshan Lai, Fengli Zhang, Xikai Pei, Muhammad Khurram Khan |
J. Netw. Comput. Appl. | 7 |
| 2024 | Detecting and Mitigating the Dissemination of Fake News: Challenges and Future Research OpportunitiesabstractFake news is a major threat to democracy (e.g., influencing public opinion), and its impact cannot be understated particularly in our current socially and digitally connected society. Researchers from different disciplines (e.g., computer science, political science, information science, and linguistics) have also studied the dissemination, detection, and mitigation of fake news; however, it remains challenging to detect and prevent the dissemination of fake news in practice. In addition, we emphasize the importance of designing artificial intelligence (AI)-powered systems that are capable of providing detailed, yet user-friendly, explanations of the classification / detection of fake news. Hence, in this article, we systematically survey existing state-of-the-art approaches designed to detect and mitigate the dissemination of fake news, and based on the analysis, we discuss several key challenges and present a potential future research agenda, especially incorporating AI explainable fake news credibility system. Wajiha Shahid, Bahman Jamshidi, Saqib Hakak, Haruna Isah, Wazir Zada Khan, Muhammad Khurram Khan, Kim-Kwang Raymond Choo |
IEEE Trans. Comput. Soc. Syst. | 6 |
| 2024 | rDefender: A Lightweight and Robust Defense Against Flow Table Overflow Attacks in SDNabstractThe flow table is a critical component of Software-Defined Networking (SDN). However, flow tables’ limited capacity makes them highly vulnerable to flow table overflow attacks (FTOAs). Due to the low attack cost and highly flexible attack forms, it is hard to eradicate FTOAs. This paper addresses three unsolved problems for table security and proposes a robust defense accordingly. First, we reveal that the existing defenses with fixed defense speeds will cause severe packet loss when handling diverse traffic. We prove that deleting multiple rules can efficiently solve this problem and give a rigorous derivation to calculate the suitable deletion number according to the environment. Second, we illustrate that abnormal table occupancy squeezing is a constant characteristic of FTOAs regardless of attack forms. It can be used to identify attacked ports accurately in different scenarios. Third, we mathematically prove that random deletion can guarantee the continuous decrease of malicious flow rules after confirming attacked ports. It achieves fast speed and robust effectiveness in different environments. Based on these findings, we design rDefender, a robust and lightweight defense prototype. We evaluate its effect by designing diverse, powerful attacks and using real-world datasets and topology. The results demonstrate that it achieves the best overall performance compared to six existing mainstream defenses, providing stable security for switch flow tables. Dezhang Kong, Xiang Chen 0017, Chunming Wu 0001, Yi Shen 0012, Zhengyan Zhou, Qiumei Cheng, Xuan Liu 0006, Yubing Qiu, Dong Zhang 0010, Muhammad Khurram Khan |
IEEE Trans. Inf. Forensics Secur. | 11 |
| 2024 | Guest Editorial XAI Based Biomedical Big Data Privacy and SecurityabstractAs artificial intelligence, the Internet of Things, and information and communication technologies continue to advance, smart healthcare systems are increasingly becoming a cornerstone of modern society. However, this progress brings with it significant concerns regarding the privacy and security of biomedical Big Data. Within smart healthcare systems, biomedical data forms an expansive and intricate web, encompassing a wide array of information from imaging to audio recordings, and various biological signals [1]. Moreover, the widespread adoption of wearable devices, coupled with a heightened public awareness of health, has precipitated a surge in data volume to a Big Data scale. This escalation presents unprecedented challenges to ensuring the confidentiality and integrity of data, demanding robust protection measures for privacy and security [2]. Houbing Song, Muhammad Khurram Khan |
IEEE J. Biomed. Health Informatics | 3 |
| 2024 | Security Enhanced Authentication Protocol for Space-Ground Integrated Railway NetworksabstractThe Software Defined Network (SDN)-based space-ground integrated railway communication networks have attracted widespread attention from academia and industry. In such environments, the security of initial authentication and handover authentication for moving trains are two important challenges that need to be addressed. In this paper, a secure and efficient authentication key agreement scheme is proposed for the SDN-based space-ground integrated railway networks. Specifically, a lightweight mutual authentication mechanism based on the Number Theory Research Unit (NTRU) is proposed for the initial authentication process, which effectively prevents the unauthorized On-Board Unit (OBU) accessing networks. Then, according to the predictable path, we propose a key generation algorithm based on the hash chain and a fast key distribution mechanism based on the Chinese Remainder Theorem (CRT), which greatly reduce the calculation and communication burden of the key transmission process. On this basis, we adopt a hash-based message authentication code to achieve unified handover authentication in heterogeneous integrated railway networks. The Burrows-Abadi-Needham (BAN) logic proof and informal security analysis demonstrate that the proposed scheme can provide several robust security properties, including forward/backward security, universality, traceability, and resistance against quantum attacks. The performance evaluations show that our scheme outperforms other related schemes in computation cost, communication overhead, and performance under unknown attacks while guaranteeing higher security. Yu Wang 0264, Wenfang Zhang, Muhammad Khurram Khan, Pingzhi Fan |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2024 | Cryptographic Primitives in Privacy-Preserving Machine Learning: A SurveyabstractAdvances in machine learning have enabled a broad range of complex applications, such as image recognition, recommendation system and machine translation. Data plays an important role in our increasingly complex and diverse environments, and this also reinforces the importance of data privacy in machine learning-enabled applications. Although there are a number of literature survey articles on machine learning, only a few studies have investigated the cryptographic primitives used in privacy-preserving machine learning (PPML). In other words, there is no, or limited, systematization of knowledge (SoK) that provides a comprehensive introduction to cryptography that have been deployed in PPML. In this paper, we firstly introduce some basic concepts such as machine learning tasks and processes. Then, we review and systematize the cryptographic primitives used in PPML. We analyze these existing privacy-preserving schemes in their learning process, especially training and inference. Finally, we conclude our survey and provide an outlook on future trends and research directions in the field. Hong Qin 0009, Debiao He, Muhammad Khurram Khan, Min Luo 0002, Kim-Kwang Raymond Choo |
IEEE Trans. Knowl. Data Eng. | 4 |
| 2024 | Secure Data Sharing over Vehicular Networks Based on Multi-sharding BlockchainabstractInternet of Vehicles (IoV) has become an indispensable technology to bridge vehicles, persons, and infrastructures and is promising to make our cities smarter and more connected. It enables vehicles to exchange vehicular data (e.g., GPS, sensors, and brakes) with different entities nearby. However, sharing these vehicular data over the air raises concerns about identity privacy leakage. Besides, the centralized architecture adopted in existing IoV systems is fragile to single point-of-failure and malicious attacks. With the emergence of blockchain technology, there is the chance to solve these problems due to its features of being tamper-proof, traceability, and decentralization. In this article, we propose a privacy-preserving vehicular data sharing framework based on blockchain. In particular, we design an anonymous and auditable data sharing scheme using Zero-Knowledge Proof (ZKP) technology so as to protect the identity privacy of vehicles while preserving the vehicular data auditability for Trusted Authorities (TAs). In response to high mobility of vehicles, we design an efficient multi-sharding protocol to decrease blockchain communication costs without compromising the blockchain security. We implement a prototype of our framework and conduct extensive experiments and simulations on it. Evaluation and analysis results indicate that our framework can not only strengthen system security and data privacy but also reduce communication complexity by \(O(\frac{n\sqrt {m}}{m^2})\) times compared to existing sharding protocols. Junqin Huang, Linghe Kong, Guihai Chen, Gang Huang 0004, Muhammad Khurram Khan |
ACM Trans. Sens. Networks | 7 |
| 2024 | An Anonymous Authenticated Group Key Agreement Scheme for Transfer Learning Edge Services SystemsabstractThe visual information processing technology based on deep learning can play many important yet assistant roles for unmanned aerial vehicles (UAV) navigation in complex environments. Traditional centralized architectures usually rely on a cloud server to perform model inference tasks, which can lead to long communication latency. Using transfer learning to unload deep neural networks to the edge-fog collaborative networks has become a new paradigm for dealing with the conflicts between computing resources and communication latency. However, ensuring the security of edge-fog collaborative networks entity remains challenging. For such, we propose an anonymous authentication and group key agreement scheme for the UAV-enabled edge-fog collaborative networks, consisting of the UAV authentication protocol and the collaborative networks authentication protocol. Utilizing the AVISPA assessment tool and security analysis, the security requirements and functional features of the proposed scheme are demonstrated. From the performance results of the proposed scheme, we show that it is superior to existing authentication schemes and promising. Wei Liang 0005, Zisang Xu, Kuanching Li, Muhammad Khurram Khan, Xiaoyan Kui |
ACM Trans. Sens. Networks | 5 |
| 2023 | An improved authentication and key management scheme in context of IoT-based wireless sensor network using ECC
Uddalak Chatterjee, Sangram Ray, Sharmistha Adhikari, Muhammad Khurram Khan, Mou Dasgupta |
Comput. Commun. | 4 |
| 2023 | Container security: Precaution levels, mitigation strategies, and research perspectives
Devi Priya V. S, S. Sibi Chakkaravarthy, Muhammad Khurram Khan |
Comput. Secur. | 3 |
| 2023 | Security analysis and improvement of a public auditing scheme for secure data storage in fog-to-cloud computing
Wenfang Zhang, Heng Jiao, Zhuoqun Yan, Muhammad Khurram Khan |
Comput. Secur. | 5 |
| 2023 | GTxChain: A Secure IoT Smart Blockchain Architecture Based on Graph Neural NetworkabstractWith the expansion of scale, the Internet of Things (IoT) suffers more and more security threats, and vulnerability and sensitivity to attacks are also increasing. As a distributed and secure network architecture, Blockchain is suitable for protecting the security and privacy of the IoT. In this article, we propose a secure smart blockchain IoT architecture based on Graph Neural Networks (GNN) named GTxChain, using a distributed intelligent prophecy machine to obtain off-chain data and construct the transaction data structure of the blockchain through the blockchain-directed acyclic graph (DAG). In the off-chain transaction and off-chain storage part, we use the lightning network, improved IPFS and GNN to obtain transaction information and continuously update the blockchain network and blockchain for transaction verification and other operations. GTxChain employs an IPFS storage architecture to enhance user privacy and reduce data processing time. Compared to other blockchain architectures, it improves by 10.51% and has better efficiency and stability in terms of Merkle-proof time overhead. Experimental results show that the GTxChain architecture can effectively ensure the IoT’s trustworthiness, security, and privacy (TSP). Jiahong Cai, Wei Liang 0005, Xiong Li 0002, Kuanching Li, Zhenwen Gui, Muhammad Khurram Khan |
IEEE Internet Things J. | 6 |
| 2023 | A Secure Certificateless Signcryption Scheme Without Pairing for Internet of Medical ThingsabstractThe Internet of Medical Things (IoMT), which integrates medical sensors with the Internet of Things, is helpful for providing remote diagnosis and real-time decision making. Massive data collected by medical and healthcare monitoring sensors in the IoMT involves sensitive patient information. It brings some security challenges to validate the legitimacy of participating entities and protect patient data privacy. A certificateless signcryption (CLSC) scheme combines encryption and signature that can offer authenticity, confidentiality, and unforgeability, providing a viable solution to the data privacy issue of the IoMT. However, existing CLSC schemes fail to meet confidentiality or unforgeability, or require expensive computation overhead to perform pairing operations. This article first presents a new CLSC scheme for secure data transmission and better smart services in IoMT, which replaces the signature part with the Schnorr signature. We then give a thorough security proof under the random oracle model. Besides, we elaborately evaluate the performance and security of some existing solutions with our solution. Finally, the experiment results indicate that our solution can achieve a better balance between security and performance than some existing schemes. Therefore, in terms of feasibility, our scheme is more suitable for the IoMT scenario. Xin Chen 0051, Debiao He, Muhammad Khurram Khan, Min Luo 0002, Cong Peng 0005 |
IEEE Internet Things J. | 3 |
| 2023 | An object detection-based few-shot learning approach for multimedia quality assessment
Rajdeep Chatterjee, Ankita Chatterjee, SK Hafizul Islam, Muhammad Khurram Khan |
Multim. Syst. | 4 |
| 2023 | Redefining food safety traceability system through blockchain: findings, challenges and open issues
Adnan Abdul-Aziz Gutub, Anand Nayyar, Muhammad Khurram Khan |
Multim. Tools Appl. | 4 |
| 2023 | Stalker Attacks: Imperceptibly Dropping Sketch Measurement Accuracy on Programmable SwitchesabstractDue to limited memory usage and provably high accuracy, sketches running on programmable switches have been commonly used by the literature for network measurement. However, their vulnerabilities are still largely unknown and neglected, which is highly concerning given the increasing popularity of network measurement. In this paper, we identify the Stalker attacks, where attackers aim to degrade the accuracy of sketches running on programmable switches. More precisely, attackers tamper with some sketch operations during sketch deployment atop programmable switches. At runtime, the tampered sketch will record highly inaccurate flow data, which degrades measurement accuracy. We implement Stalker attacks on Tofino switches. The results indicate that Stalker attacks significantly drop the accuracy of network management applications, e.g., reducing the F1 score of heavy hitter detection to zero. However, our analysis indicates that none of existing methods can detect Stalker attacks since they can hardly verify the correctness of sketch operations. Finally, we analyze potential defense mechanisms and identify challenges to enable further research in this context. Xiang Chen 0017, Hongyan Liu 0001, Qun Huang 0001, Dong Zhang 0010, Haifeng Zhou, Chunming Wu 0001, Xuan Liu 0006, Muhammad Khurram Khan |
IEEE Trans. Inf. Forensics Secur. | 8 |
| 2023 | PBidm: Privacy-Preserving Blockchain-Based Identity Management System for Industrial Internet of ThingsabstractIndustrial Internet of Things (IIoT) is revolutionizing plenty of industrial applications by utilizing large-scale smart devices in manufacturing and industrial processes. However, IIoT is facing the disclosure of identity privacy. The identity information is precious and critical, thereby inspiring a line of follow-up privacy-preserving studies, i.e., anonymous credential protocols, or privacy-preserving identity management schemes. However, they are either too anonymous to be used in the IIoT environment, or the system is highly centralized, which implies the risk of a single point of failure. In this article, we proposePBidm, a privacy-preserving blockchain-based identity management scheme for IIoT. Specifically, by leveraging blockchain and diversified cryptographic tools,PBidmcan fully support the desirable properties, i.e., unforgeability, blindness, unlikability, traceability, revocability, and public verifiability. Then, we provide security analysis to ensure reasonable security assurance. Finally, we present a performance evaluation of the proposed scheme to demonstrate the practicability in IIoT applications. Zijian Bao, Debiao He, Muhammad Khurram Khan, Min Luo 0002, Qi Xie 0001 |
IEEE Trans. Ind. Informatics | 3 |
| 2023 | Guest Editorial: Cybersecurity Intelligence in the Healthcare System
Abhinav Kumar 0005, Zahid Akhtar, Muhammad Khurram Khan |
IEEE Trans. Ind. Informatics | 4 |
| 2023 | AISChain: Blockchain-Based AIS Data Platform With Dynamic Bloom Filter TreeabstractSince 2002, hundreds of thousands of vessels have equipped the Automatic Identification System (AIS), which continuously broadcasts its identity and location information for vessel collision avoidance. To utilize these scattered AIS data for further analysis, there are multiple AIS data platforms collecting AIS data from vessels around the world through their satellites and land-based stations. Thus, users can obtain AIS data of vessels from these platforms without dedicated devices. However, existing platforms work in silos, and AIS data is distributed across different platforms, resulting in reduced data availability. In addition, AIS is vulnerable to jamming and spoofing attacks, which can undermine the authenticity of AIS data. In this paper, we propose AISChain, a secure and fast blockchain-based AIS data platform. AISChain adopts consortium blockchain, which only permits those authorized parties (i.e., AIS data providers) to participate in the consensus protocol, and is compatible with current commodity AIS hardware. Since the whole system is co-maintained by multiple authorized parties, AISChain can integrate AIS data resources in a secure way. For avoiding repeated recording of AIS data on the chain, we design the Dynamic Bloom Filter Tree (DBFT) to realize efficient duplication detection in the transaction verification phase. We also propose the dual signature scheme to clarify the AIS data ownership. Moreover, we leverage the geographical location-based blockchain sharding approach to further improve the scalability of AISChain. We implement a prototype of AISChain, and conduct extensive experiments to evaluate the performance of AISChain. Evaluation results show that the search time of DBFT is negligible (4.3 ms) with an extreme low error ratio (0.4%). Meanwhile, AISChain can achieve more than 730 tx/s throughput even when nodes scale to 36. To the best of our knowledge, AISChain is the first work to apply the blockchain technology to secure the AIS data platform. Yongshuai Duan, Junqin Huang, Jiale Lei, Linghe Kong, Yibin Lv, Zhiliang Lin, Guihai Chen, Muhammad Khurram Khan |
IEEE Trans. Intell. Transp. Syst. | 8 |
| 2023 | Design of Provably Secure Authentication Protocol for Edge-Centric Maritime Transportation SystemabstractThe epidemic growth of the Internet of Things (IoT) objects have revolutionized Maritime Transportation Systems (MTS). Though, it becomes challenging for the centralized cloud-centric framework to fulfil the application requirements such as low latency and power utilization. The introduction of the distributed edge-centric framework has recently helped the IoT-enabled MTS to meet these requirements by manipulating the tasks at the edge of the networks. Despite the fact that MTS leverages mobile subscribers by overcoming inherent cloud computing limitations, data security and user privacy requirements in establishing the MTS setup are still non-trivial challenges. In this article, we develop a key agreement solution for mobile users to realize mutual authentication in a single round. Our protocol offers user anonymity to maintain user privacy, and it can prevent physical attacks by physically unclonable functions. Initially, the security analysis is conferred to substantiate our protocol’s security persistence or strength. Later, its performance correlation is observed under the assumption of diverse metrics in a predefined empirical setup. The meticulous performance correlation endorses the precedence of our protocol over specified related protocols. Khalid Mahmood 0002, Salman Shamshad, Muhammad Faizan Ayub, Zahid Ghaffar, Muhammad Khurram Khan, Ashok Kumar Das |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2022 | A privacy-preserving authentication scheme based on Elliptic Curve Cryptography and using Quotient Filter in fog-enabled VANET
Shidrokh Goudarzi, Seyed Ahmad Soleymani, Mohammad Hossein Anisi, Mohammad Abdollahi Azgomi, Zeinab Movahedi, Nazri Kama, Hazlifah Mohd Rusli, Muhammad Khurram Khan |
Ad Hoc Networks | 8 |
| 2022 | Co-Learning to Hash Palm Biometrics for Flexible IoT DeploymentabstractSecurity enhancement via trustworthy identity authentication in Internet of Things (IoT) has soared recently. Biometrics offers a promising remedy to improve the security and utility of IoT and play a role in securing a variety of low-power and limited computing capability IoT devices to address identity management challenges. This article proposes an IoT-compliant co-learned biometric hashing network derived from palm print and palm vein dubbed PalmCohashNet. The PalmCohashNet comprises two hashing subnetworks, one for each palm modality, and is trained collaboratively to generate shared hash codes for respective modality (co-hash codes). A cross-modality hashing (CMH) loss is devised to encourage co-hash codes of palm vein and palm print from the same identity to be adjacent and consistent; meanwhile, pull the co-hash codes of each identity to a preassigned identity-specific hash centroid that is shared by both palm modalities. Two palm-based co-hash codes of a person can be generated simultaneously for deployment. The binary co-hash code is IoT compliant attributed to its highly compact form for storage and fast matching. A trained PalmCohashNet can be flexibly deployed under four operation modes: single-modality matching (print versus print or vein versus vein), multimodality matching where both print and vein are utilized, and cross-modality matching (print versus vein) depending on the IoT service context. Our empirical results on four publicly available palm databases show that the proposed method consistently outperforms state-of-the-art methods. Xingbo Dong, Muhammad Khurram Khan, Lu Leng, Andrew Beng Jin Teoh |
IEEE Internet Things J. | 2 |
| 2022 | An Efficient Privacy-Preserving Aggregation Scheme for Multidimensional Data in IoTabstractInternet of Things (IoT) enables terminal devices connecting with the Internet and provides various intelligent applications by analyzing devices data. As a typical IoT technique, edge computing provides a three-tier architecture to reduce communications and improve efficiency. Specifically, edge nodes are responsible for collecting and aggregating device data, and then send processed results to the cloud for subsequent analysis. However, the data aggregation function will compromise the privacy of device data. In this article, we proposed an efficient privacy-preserving multidimensional data aggregation scheme for IoT, called PMDA. The scheme uses the Chinese remainder theorem to design a homomorphic encryption method that encryptes a multiple-dimensional small integer vector into one ciphertext and keeps linear homomorphic properties per dimension. Combining with the signature mechanism and the batch verification method, the scheme guarantees nonrepudiation of device data and enhance verification efficiency at edge nodes. Through theoretical analysis, we demonstrate that the proposed scheme can achieve correctness, privacy, authentication, and integrity. After performance evaluation, we demonstrate that our scheme is superior to other schemes in terms of computation and communication costs. In particular, as the message dimension increases, our scheme computation costs almost a tenth of others at the 80-bits security level. Cong Peng 0005, Min Luo 0002, Huaqun Wang, Muhammad Khurram Khan, Debiao He |
IEEE Internet Things J. | 4 |
| 2022 | An Improved Lightweight PUF-PKI Digital Certificate Authentication Scheme for the Internet of ThingsabstractProsanta and Biplab presented a lightweight two-factor authentication scheme for the Internet of Things (IoT) devices based on the physical unclonable function (PUF). Their presented scheme was based on the fuzzy extractor and analyzed various security reasonings, such as mutual authentication, session key agreement, privacy and protection against impersonation, message tampering, and replay attacks. In this article, we present sufficient security analysis to demonstrate that the scheme has various security and privacy issues in its setup and authentication phases. We propose a highly secure and robust authentication protocol based on a public key infrastructure (PKI) digital certificate based on two certificate authorities (CAs) for cloud IoT systems. The proposed authentication method is verified and validated using the Tamarin prover and supported with a detailed security and performance analysis discussion. The scheme security and privacy attributes are compared with other IoT authentication schemes. The analysis has proved that the proposed authentication scheme is more secure and highly reliable as compared to the Prosanta and Biplab authentication scheme. Zeeshan Siddiqui, Jiechao Gao, Muhammad Khurram Khan |
IEEE Internet Things J. | 3 |
| 2022 | Consumer, Commercial, and Industrial IoT (In)Security: Attack Taxonomy and Case StudiesabstractInternet of Things (IoT) devices are becoming ubiquitous in our lives, with applications spanning from theconsumerdomain tocommercialandindustrialsystems. The steep growth and vast adoption of IoT devices reinforce the importance of sound and robust cybersecurity practices during the device development life cycles. IoT-related vulnerabilities, if successfully exploited can affect, not only the device itself but also the application field in which the IoT device operates. Evidently, identifying and addressing every single vulnerability are an arduous, if not impossible, task. Attack taxonomies can assist in classifying attacks and their corresponding vulnerabilities. Security countermeasures and best practices can then be leveraged to mitigate threats and vulnerabilities before they emerge into catastrophic attacks and ensure overall secure IoT operation. Therefore, in this article, we provide an attack taxonomy, which takes into consideration the different layers of the IoT stack, i.e., device, infrastructure, communication, and service, and each layer’s designated characteristics, which can be exploited by adversaries. Furthermore, using nine real-world cybersecurity incidents that had targeted IoT devices deployed in the consumer, commercial, and industrial sectors, we describe the IoT-related vulnerabilities, exploitation procedures, attacks, impacts, and potential mitigation mechanisms and protection strategies. These (and many other) incidents highlight the underlying security concerns of IoT systems and demonstrate the potential attack impacts of such connected ecosystems, while the proposed taxonomy provides a systematic procedure to categorize attacks based on the affected layer and corresponding impact. Christos Xenofontos, Ioannis Zografopoulos, Charalambos Konstantinou, Alireza Jolfaei, Muhammad Khurram Khan, Kim-Kwang Raymond Choo |
IEEE Internet Things J. | 5 |
| 2022 | Improving the Software-Defined Wireless Sensor Networks Routing Performance Using Reinforcement LearningabstractSoftware-defined networking (SDN) is an emerging architecture used in many applications because of its flexible architecture. It is expected to become an essential enabler for the Internet of Things (IoTs). It decouples the control plane from the data plane, and the controller manages the whole underlying network. SDN has been used in wireless sensor networks (WSNs) for routing. The SDN controller uses some algorithms to calculate the routing path; however, none of these algorithms have enough ability to obtain the optimized routing path. Therefore, reinforcement learning (RL) is a helpful technique to select the best routing path. In this article, we optimize the routing path of SDWSN through RL. A reward function is proposed that includes all required metrics regarding energy efficiency and network Quality-of-Service (QoS). The agent gets the reward and takes the next action based on the reward received, while the SDWSN controller improves the routing path based on the previous experience. However, the whole network is also controlled remotely through the Web. The performance of the RL-based SDWSN is compared with SDN-based techniques, including traditional SDN and energy-aware SDN (EASDN), QR-SDN, TIDE and non SDN-based techniques, such as$Q$-learning and RL-based routing (RLBR). The proposed RL-based SDWSN outperforms in terms of lifetime from 8% to 33% and packet delivery ratio (PDR) from 2% to 24%. It is envisioned that this work will help the engineers for achieving the desired WSN performance through efficient routing. Muhammad Usman Younus, Muhammad Khurram Khan, Abdul Rauf Bhatti |
IEEE Internet Things J. | 2 |
| 2022 | A blockchain-based conditional privacy-preserving authentication scheme for edge computing services
Xiaoying Jia 0002, Yongbo Xia, Muhammad Khurram Khan, Debiao He |
J. Inf. Secur. Appl. | 4 |
| 2022 | Radiological image retrieval technique using multi-resolution texture and shape features
Jitesh Pradhan, Arup Kumar Pal, SK Hafizul Islam, Muhammad Khurram Khan |
Multim. Tools Appl. | 5 |
| 2022 | Computational intelligence based secure three-party CBIR scheme for medical data for cloud-assisted healthcare applications
Mukul Majhi, Arup Kumar Pal, Jitesh Pradhan, SK Hafizul Islam, Muhammad Khurram Khan |
Multim. Tools Appl. | 5 |
| 2022 | Privacy-Enabling Framework for Cloud-Assisted Digital Healthcare IndustryabstractAs the technology era progresses, many opportunities are brought to the healthcare industry. With the support of technology and Internet of Things platforms, e-healthcare is now more common than ever. However, the sensitive nature of healthcare records makes them vulnerable to many attacks. Therefore, a privacy-enabled framework for cloud-based e-healthcare systems is proposed to achieve privacy-preserved and secured communication in e-healthcare. The analysis of the proposed protocol is presented in this article to demonstrate that it is secure against all well-known security attacks and provides patient anonymity, doctor anonymity, and patient and doctor unlinkability while ensuring data confidentiality. Additionally, the security simulations are performed using the Automated Validation of Internet Security Protocols and Applications tool. We also performed the proposed framework's performance analysis and compared it with existing frameworks. The analysis result indicates that the proposed framework achieves encouraging performance over other frameworks while ensuring security. Aman Ahmad Ansari, Bharavi Mishra, Poonam Gera, Muhammad Khurram Khan, Chinmay Chakraborty, Dheerendra Mishra |
IEEE Trans. Ind. Informatics | 4 |
| 2022 | Guest Editorial: Privacy-Preserving Federated Machine Learning Solutions for Enhanced Security of Critical Energy InfrastructuresabstractCritical energy infrastructure (CEI) is specific engineering information about proposed or existing critical infrastructure. Modern critical infrastructures are increasingly turning into distributed, complex cyber-physical systems that need proactive protection and fast restoration to mitigate physical or cyber incidents or attacks. Most importantly, combined cyber-physical attacks are much more challenging and are expected to become the most intrusive attack. This is particularly true for the CEIs. During 2015, the Industrial Control Systems Cyber Emergency Response Team in the Unites States responded to more than 245 incidents; the energy sector tops the list with 32% incidents. Considering the importance of energy in our daily lives and its influence on other critical infrastructures, CEI requires significant attention comparatively. For example, the wind-turbine system is considered one of the most complex cyber-physical infrastructures, causing huge cascading effects to other CEIs, such as electrical power and energy systems and transportation, healthcare sector, communications, industry, and finance. Wind turbines are mainly composed of condition monitoring and operational data (i.e., supervisory command and data acquisition), including air temperature, air pressure, voltage, and power with multiple parameters and periodic characteristics. Muhammad Imran Razzak, Guandong Xu, Muhammad Khurram Khan |
IEEE Trans. Ind. Informatics | 3 |
| 2022 | An Efficient Privacy-Preserving Public Auditing Protocol for Cloud-Based Medical Storage SystemabstractThe booming Internet of Things makes smart healthcare a reality, while cloud-based medical storage systems solve the problems of large-scale storage and real-time access of medical data. The integrity of medical data outsourced in cloud-based medical storage systems has become crucial since only complete data can make a correct diagnosis, and public auditing protocol is a key technique to solve this problem. To guarantee the integrity of medical data and reduce the burden of the data owner, we propose an efficient privacy-preserving public auditing protocol for the cloud-based medical storage systems, which supports the functions of batch auditing and dynamic update of data. Detailed security analysis shows that our protocol is secure under the defined security model. In addition, we have conducted extensive performance evaluations, and the results indicate that our protocol not only remarkably reduces the computational costs of both the data owner and the third-party auditor (TPA), but also significantly improves the communication efficiency between the TPA and the cloud server. Specifically, compared with other related work, the computational cost of the TPA in our protocol is negligible and the data owner saves more than 2/3 of computational cost. In addition, as the number of challenged blocks increases, our protocol saves nearly 90% of communication overhead between the TPA and the cloud server. Xiong Li 0002, Shanpeng Liu, Rongxing Lu, Muhammad Khurram Khan, Ke Gu 0002, Xiaosong Zhang 0001 |
IEEE J. Biomed. Health Informatics | 4 |
| 2022 | Secure Authentication and Key Management Protocol for Deployment of Internet of Vehicles (IoV) Concerning Intelligent Transport SystemsabstractIntelligent transport systems amalgamated with advanced technologies are an important element of the automotive industry, including critical infrastructure and transportation. Internet of Vehicles (IoV) is the modern technological framework designed for intelligent transportation. IoV creates a network of information relations among vehicles, thus contributing to reduced congestion, roadside infrastructure, driver/traveller safety, and traffic efficiency through wireless communication and sensing technology. However, a significant challenge in IoV applications is security, as criminals could potentially exploit these applications. It is clear that despite increasing industry awareness, the potential danger posed by security vulnerabilities and cyber threats is high. In this study, we have designed a new system called AKAP-IoV, which supports secure communication, mutual authentication, and key management among vehicles, roadside units, and fog and cloud servers. AKAP-IoV was tested and verified using Scyther and Tamarin to ensure its resistance to cyber threats. Furthermore, we conducted a formal security analysis using the Real-or-Random (RoR) oracle model to assess security properties logically. In addition, a detailed, comprehensive comparative study was considered to evaluate the performance, functionality, efficiency and security features supported by AKAP-IoV compared to those of recently developed schemes. Sriramulu Bojjagani, Y. C. A. Padmanabha Reddy, Thati Anuradha, P. V. Venkateswara Rao, B. Ramachandra Reddy, Muhammad Khurram Khan |
IEEE Trans. Intell. Transp. Syst. | 6 |
| 2022 | Histogram-Based Intrusion Detection and Filtering Framework for Secure and Safe In-Vehicle NetworksabstractIn this paper, we propose H-IDFS, a Histogram-based Intrusion Detection and Filtering framework, which assembles the CAN packets into windows, and computes their corresponding histograms. The latter are fed to a multi-class IDS classifier to identify the class of the traffic windows. If the window is found malicious, the filtering system is invoked to filter out the normal CAN packets from each malicious window. To this end, we propose a novel one-class SVM, namedOCSVM-attackthat is trained on normal traffic and considers the invariant and quasi-invariant features of the attack. Experimental results on two CAN datasets: OTIDS and Car-Hacking, show the superiority of the proposed H-IDFS, as it achieves an accuracy of 100% for window classification, and correctly filters out between 94.93% and 100% of normal packets from malicious windows. Abdelouahid Derhab, Mohamed Belaoued, Irfan Mohiuddin, Fajri Kurniawan, Muhammad Khurram Khan |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2022 | DeFLoc: Deep Learning Assisted Indoor Vehicle Localization Atop FM Fingerprint MapabstractIndoor vehicle localization is an underlying technology for realizing Autonomous Valet Parking (AVP), which demands high accuracy and reliability. However, existing localization technologies, such as GPS, WiFi, Bluetooth, suffer from either low availability or high cost, which are not practical in the real world. In order to put AVP into practice, We desperately need an efficient and reliable indoor vehicle localization technology. In this paper, we propose aDeep learning andFM fingerprint map based indoor vehicleLocalization method, namely DeFLoc, which leverages FM signals to achieve accurate and practical indoor localization. In order to reduce the workload of the FM fingerprints collecting process, DeFLoc uses partially uniform sampling to decrease sample data volume and reconstructs the FM fingerprint map from collected incomplete fingerprints precisely using a dedicated deep Convolutional Neural Network (CNN). To alleviate the influence of signal distortions in some FM frequencies, we further design smooth layers in the neural network for improving the accuracy of map reconstruction. Moreover, we devise a continuous vehicle localization algorithm by considering the preferences of vehicle movements to assist us to calibrate localization. We implemented a prototype of DeFLoc and conducted extensive experiments both in simulation and practice. Evaluation results show that our proposed reconstruction model improves accuracy by 40% over conventional matrix completion methods even under the 60% data missing rate. With the precisely reconstructed fingerprint map, DeFLoc achieves over 90% localization accuracy, which indicates DeFLoc can realize accurate and practical indoor vehicle localization. Jiale Lei, Junqin Huang, Linghe Kong, Guihai Chen, Muhammad Khurram Khan |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2022 | Improving the Security of LTE-R for High-Speed Railway: From the Access Authentication ViewabstractSecurity and efficiency are crucial considerations for Long Term Evolution for Railway (LTE-R) which bears real-time transmission of train control information for future high-speed railway. In this article, we first analyze the vulnerabilities of LTE-R access authentication protocol, and then propose a proxy signature based authentication scheme to enhance the security of LTE-R without sacrificing efficiency. The proposed scheme consists of three main security mechanisms: a novel Elliptic Curve Cryptosystem based Certificateless Proxy Signature (ECC-CLPS) designed for authentication security, a hash-based puzzle introduced to defend against denial of service (DoS) attack and a key pre-generation mechanism used to improve the efficiency of fast handover authentication. The security analysis and performance simulation show that our scheme has advantages over existing LTE-based authentication schemes in terms of security, functionality, computation and communication costs. Moreover, the authentication requirements for security and efficiency in different LTE-R communication scenarios are fully considered, which makes our scheme more suitable for the access authentication in the future LTE-R based high-speed railway. Yu Wang 0264, Wenfang Zhang, Muhammad Khurram Khan, Pingzhi Fan |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2022 | Secure Distributed Mobile Volunteer Computing with AndroidabstractVolunteer Computing provision of seamless connectivity that enables convenient and rapid deployment of greener and cheaper computing infrastructure is extremely promising to complement next-generation distributed computing systems. Undoubtedly, without tactile Internet and secure VC ecosystems, harnessing its full potentials and making it an alternative viable and reliable computing infrastructure is next to impossible. Android-enabled smart devices, applications, and services are inevitable for Volunteer computing. Contrarily, the progressive developments of sophisticated Android malware may reduce its exponential growth. Besides, Android malwares are considered the most potential and persistent cyber threat to mobile VC systems. To secure Android-based mobile volunteer computing, the authors proposed MulDroid, an efficient and self-learning autonomous hybrid (Long-Short-Term Memory, Convolutional Neural Network, Deep Neural Network) multi-vector Android malware threat detection framework. The proposed mechanism is highly scalable with well-coordinated infrastructure and self-optimizing capabilities to proficiently tackle fast-growing dynamic variants of sophisticated malware threats and attacks with 99.01% detection accuracy. For a comprehensive evaluation, the authors employed current state-of-the-art malware datasets (Android Malware Dataset, Androzoo) with standard performance evaluation metrics. Moreover, MulDroid is compared with our constructed contemporary hybrid DL-driven architectures and benchmark algorithms. Our proposed mechanism outperforms in terms of detection accuracy with a trivial tradeoff speed efficiency. Additionally, a 10-fold cross-validation is performed to explicitly show unbiased results. Iram Bibi, Adnan Akhunzada, Jahanzaib Malik, Muhammad Khurram Khan, Muhammad Dawood |
ACM Trans. Internet Techn. | 4 |
| 2021 | WiBWi: Encoding-based Bidirectional Physical-Layer Cross-Technology Communication between BLE and WiFiabstractThe booming of mobile technologies and Internet of Things (IoTs) have facilitated the explosion of wireless devices and brought convenience to people's daily lives. Coming with the explosive growth of wireless devices, incompatibility of heterogeneous wireless technologies hindered the growing demands for everything connected. And spectrum sharing among heterogeneous wireless technologies has led to severe Cross-Technology Interference (CTI), which is a vital obstacle for network reliability and spectrum utilization. Researches in recent years have shown that Cross-Technology Communication (CTC) turns out to be a promising solution with broad perspective for the coexistence of heterogeneous wireless technologies. However, due to the physical layer incompatibility of WiFi and Bluetooth Low Energy (BLE), the researches about CTC between these two most wildly used wireless technologies are limited by now. In this paper, we propose WiBWi, a payload encoding-based bidirectional CTC scheme between BLE and WiFi, which can achieve near-optimal throughput and powerful robustness. For uplink, i.e., BLE to WiFi communication, WiBWi leverages a novel extended WiFi preamble detection rule and probabilistic inference based encode mapping to achieve fast and reliable communication. For downlink, i.e., WiFi to BLE communication, WiBWi introduces an encoding mapping scheme in the sight of BLE receiver with little modification to accomplish high throughput and robustness. Extensive evaluation shows that WiBWi can offer near-optimal throughput (near the maximum throughput of BLE) and extremely low bit error rate (less than 1%). Yuanhe Shu, Linghe Kong, Jiadi Yu, Guisong Yang, Yueping Cai, Zhen Wang 0004, Muhammad Khurram Khan |
ICPADS | 8 |
| 2021 | Private blockchain-envisioned multi-authority CP-ABE-based user access control scheme in IIoT
Soumya Banerjee 0001, Basudeb Bera, Ashok Kumar Das, Samiran Chattopadhyay, Muhammad Khurram Khan, Joel J. P. C. Rodrigues |
Comput. Commun. | 5 |
| 2021 | Ransomware: Recent advances, analysis, challenges and future research directions
Craig Beaman, Ashley Barkworth, Toluwalope David Akande, Saqib Hakak, Muhammad Khurram Khan |
Comput. Secur. | 5 |
| 2021 | Trust Management in Social Internet of Things: Architectures, Recent Advancements, and Future ChallengesabstractSocial Internet of Things (SIoT) is an extension of the Internet of Things (IoT) that converges with social networking concepts to create social networks of interconnected smart objects. This convergence allows the enrichment of the two paradigms, resulting into new ecosystems. While IoT follows two interaction paradigms, human to human (H2H) and thing to thing (T2T), SIoT adds on human-to-thing (H2T) interactions. SIoT enables smart “social objects” that intelligently mimic the social behavior of human in the daily life. These social objects (SOs) are equipped with social functionalities capable of discovering other SOs in the surroundings and establishing social relationships. They crawl through the social network of objects for the sake of searching for services and information of interest. The notion of trust and trustworthiness in social communities formed in SIoT is still new and in an early stage of investigation. In this article, our contributions are threefold. First, we present the fundamentals of SIoT and trust concepts in SIoT, clarifying the similarities and differences between IoT and SIoT. Second, we categorize the trust management solutions proposed so far in the literature for SIoT over the last six years and provide a comprehensive review. We then perform a comparison of the state-of-the-art trust management schemes devised for SIoT by performing comparative analysis in terms of trust management process. Third, we identify and discuss the challenges and requirements in the emerging new wave of SIoT, and also highlight the challenges in developing trust and evaluating trustworthiness among the interacting SOs. Wazir Zada Khan, Quratul-Ain Arshad, Saqib Hakak, Muhammad Khurram Khan, Saeed Ur Rehman 0002 |
IEEE Internet Things J. | 4 |
| 2021 | Provably Secure Authentication Protocol for Mobile Clients in IoT Environment Using Puncturable Pseudorandom FunctionabstractThe Internet of Things (IoT) is a framework of various services and smart technologies that mutually communicate information between mobile devices and users or just between devices with the help of Internet connectivity. The dramatic progression of IoT helps numerous network applications and communication technologies to introduce state-of-the-art communication models for enabling interaction among mobile server, clients, and various other smart entities. Now-a-days, online mobile services have gained huge attention by providing ample convenience to the distant users. However, it is necessary to secure the information, being exchanged among mobile clients and server. Therefore, a large number of authentication protocols have been presented but majority of them are unsuitable to fulfill novel security requirements and standards. Moreover, they are incompatible for the IoT environment due to higher computation and communication complexity. Consequently, there is a dire need of developing an adequate, reliable, and cost-effective authentication protocol. In this article, we introduce a novel identity-based key agreement protocol using the puncturable pseudorandom functions for mobile clients in the IoT environment. The proposed PSK-MC protocol enables two mobile clients to accomplish mutual authentication via server. The proposed protocol is evaluated formally and informally to determine its security strength. The formal security analysis is presented using the widely used random oracle model. Moreover, all the cryptographic operations used at mobile client side are executed on a mobile device, while the operations used at the server side are implemented on a desktop machine to get the experimental results to determine computation cost. The performance analysis reveals the fact that our protocol is comparatively better than related protocols by exhibiting least communication and computation overhead. Muhammad Asad Saleem, Zahid Ghaffar, Khalid Mahmood 0002, Ashok Kumar Das, Joel J. P. C. Rodrigues, Muhammad Khurram Khan |
IEEE Internet Things J. | 6 |
| 2021 | From smart parking towards autonomous valet parking: A survey, challenges and future Works
Kezhi Wang, Nauman Aslam, Yue Cao 0002, Naveed Ahmad 0003, Muhammad Khurram Khan |
J. Netw. Comput. Appl. | 6 |
| 2021 | Dissecting bitcoin blockchain: Empirical analysis of bitcoin network (2009-2020)abstractBitcoin system (or Bitcoin) is a peer-to-peer and decentralized payment system that uses cryptocurrency named bitcoins (BTCs) and was released as open-source software in 2009. Unlike fiat currencies, there is no centralized authority or any statutory recognition, backing, or regulation for Bitcoin . All transactions are confirmed for validity by a network of volunteer nodes (miners) and after collective agreement is subsequently recorded into a distributed ledger “Blockchain”. Bitcoin platform has attracted both social and anti-social elements. On the one hand, it is social as it ensures the exchange of value, maintaining trust in a cooperative, community-driven manner without the need for a trusted third party. At the same time, it is anti-social as it creates hurdles for law enforcement to trace suspicious transactions due to anonymity and privacy. To understand how the social and anti-social tendencies in the user base of Bitcoin affect its evolution, there is a need to analyze the Bitcoin system as a network. The current paper aims to explore the local topology and geometry of the Bitcoin network during its first decade of existence. Bitcoin transaction data from 03 Jan 2009 12:45:05 GMT to 08 May 2020 13:21:33 GMT was processed for this purpose to build a Bitcoin user graph. The characteristics, local and global network properties of the user's graph were analyzed at ten intervals between 2009 and 2020 with a gap of one year. Small diameter, skewed distribution of transactions, power-law distributed in and out degrees, disconnected graph, and presence of large connected components were the observations from network analysis . Thus, it could be inferred that despite anti-social tendencies, Bitcoin network shared similarities with other complex networks. Network analysis also uncovered twenty types of legal and anti-social entities operating on Bitcoin and provided a path for uncovering these anti-social entities. Pranav Nerurkar, Dhiren R. Patel, Yann Busnel, Romaric Ludinard, Saru Kumari, Muhammad Khurram Khan |
J. Netw. Comput. Appl. | 6 |
| 2021 | Verifiable dynamic ranked search with forward privacy over encrypted cloud data
Chien-Ming Chen 0001, Zhuoyu Tie, Ke Wang 0068, Muhammad Khurram Khan, Sachin Kumar 0002, Saru Kumari |
Peer-to-Peer Netw. Appl. | 4 |
| 2021 | A robust provable-secure privacy-preserving authentication protocol for Industrial Internet of Things
Diksha Rangwani, Dipanwita Sadhukhan, Sangram Ray, Muhammad Khurram Khan, Mou Dasgupta |
Peer-to-Peer Netw. Appl. | 4 |
| 2021 | Designing Anonymous Signature-Based Authenticated Key Exchange Scheme for Internet of Things-Enabled Smart Grid SystemsabstractRecent technological evolution in the Internet of Things (IoT) age supports better solutions to magnify the management of the power quality and reliability concerns, and imposes the measures of a smart grid. In smart grid environment, a smart meter needs to securely access the services from a service provider via insecure channel. However, since the communication is via public channel, it imposes various security threats by an adversary. To deal with this, in this article we design a new anonymous signature-based authenticated key exchange scheme for IoT-enabled smart grid environment, called AAS-IoTSG. The dynamic smart meter addition phase is also permissible in AAS-IoTSG after initial deployment. The security of AAS-IoTSG has been tested rigorously using formal security analysis under the real-or-random (ROR) model which is one of the broadly-accepted standard random oracle models, formal security verification under the broadly-used automated validation of Internet security protocols and applications (AVISPA) tool and also using informal security analysis. Finally, an exhaustive comparative study unveils that AAS-IoTSG supports better security and functionality features and requires less communication and computation overheads as compared to the existing state-of-art authentication mechanisms in smart grid systems. Jangirala Srinivas, Ashok Kumar Das, Xiong Li 0002, Muhammad Khurram Khan, Minho Jo 0001 |
IEEE Trans. Ind. Informatics | 4 |
| 2021 | A lightweight remote user authentication scheme for IoT communication using elliptic curve cryptography
Dipanwita Sadhukhan, Sangram Ray, G. P. Biswas, Muhammad Khurram Khan, Mou Dasgupta |
J. Supercomput. | 4 |
| 2021 | EPRT: An Efficient Privacy-Preserving Medical Service Recommendation and Trust Discovery Scheme for eHealth SystemabstractAs one of the essential applications of health information technology, the eHealth system plays a significant role in enabling various internet medicine service scenes, most of which primarily rely on service recommendation or an evaluation mechanism. To avoid privacy leakage, some privacy-preserving mechanisms must be adopted to protect raters’ privacy and make evaluation trust reliable. To tackle this challenge, this article proposes an efficient service recommendation and evaluation scheme, called EPRT , which is based on a similarity calculation and trust discovery method. This scheme uses homomorphic encryption technology to encrypt the sensitive data and combines the threshold mechanism and double-trap mechanism to realize the secure computing on the encrypted data, so as to ensure that the plaintexts of the final calculation results (e.g., recommendation value and evaluation truth) are only obtained by the authorized subject. In addition, a detailed security analysis shows that the proposed EPRT scheme can achieve the expected security. In addition, performance comparison results are carried out, demonstrating its effectiveness and accuracy. Cong Peng 0005, Debiao He, Jianhua Chen 0002, Neeraj Kumar 0001, Muhammad Khurram Khan |
ACM Trans. Internet Techn. | 5 |
| 2021 | Privacy-preserving Data Aggregation against Malicious Data Mining Attack for IoT-enabled Smart GridabstractInternet of Things (IoT)-enabled smart grids can achieve more reliable and high-frequency data collection and transmission compared with existing grids. However, this frequent data processing may consume a lot of bandwidth, and even put the user’s privacy at risk. Although many privacy-preserving data aggregation schemes have been proposed to solve the problem, they still suffer from some security weaknesses or performance deficiency, such as lack of satisfactory data confidentiality and resistance to malicious data mining attack. To address these issues, we propose a novel privacy-preserving data aggregation scheme (called PDAM) for IoT-enabled smart grids, which can support efficient data source authentication and integrity checking, secure dynamic user join and exit. Unlike existing schemes, the PDAM is resilient to the malicious data mining attack launched by internal or external attackers and can achieve perfect data confidentiality against not only a malicious aggregator but also a curious control center for an authorized user. The detailed security and performance analysis show that our proposed PDAM can satisfy several well-known security properties and desirable efficiency for a smart grid system. Moreover, the comparative studies and experiments demonstrate that the PDAM is superior to other recently proposed works in terms of both security and performance. Jing Wang 0036, Sherali Zeadally, Muhammad Khurram Khan, Debiao He |
ACM Trans. Sens. Networks | 4 |
| 2020 | An authentication and plausibility model for big data analytic under LOS and NLOS conditions in 5G-VANET
Seyed Ahmad Soleymani, Mohammad Hossein Anisi, Abdul Hanan Abdullah, Md. Asri Ngadi, Shidrokh Goudarzi, Muhammad Khurram Khan, Nazri Kama |
Sci. China Inf. Sci. | 6 |
| 2020 | Joint-learning segmentation in Internet of drones (IoD)-based monitor systems
Ke Wang 0068, Chien-Ming Chen 0001, Muhammad Khurram Khan, Saru Kumari |
Comput. Commun. | 4 |
| 2020 | Applications of blockchain in ensuring the security and privacy of electronic health record systems: A survey
Shuyun Shi, Debiao He, Li Li 0073, Neeraj Kumar 0001, Muhammad Khurram Khan, Kim-Kwang Raymond Choo |
Comput. Secur. | 5 |
| 2020 | Proof of X-repute blockchain consensus protocol for IoT systems
Ke Wang 0068, RuiPei Sun, Chien-Ming Chen 0001, Zuodong Liang, Saru Kumari, Muhammad Khurram Khan |
Comput. Secur. | 6 |
| 2020 | PoRX: A reputation incentive scheme for blockchain consensus of IIoT
Ke Wang 0068, Zuodong Liang, Chien-Ming Chen 0001, Saru Kumari, Muhammad Khurram Khan |
Future Gener. Comput. Syst. | 5 |
| 2020 | Blockchain-based identity management systems: A review
Yang Liu 0368, Debiao He, Mohammad S. Obaidat, Neeraj Kumar 0001, Muhammad Khurram Khan, Kim-Kwang Raymond Choo |
J. Netw. Comput. Appl. | 5 |
| 2020 | DCAP: A Secure and Efficient Decentralized Conditional Anonymous Payment System Based on BlockchainabstractBlockchain, a distributed ledger technology, can potentially be deployed in a wide range of applications. Among these applications, decentralized payment systems (e.g. Bitcoin) have been one of the most mature blockchain applications with widespread adoption. While the early designs (e.g. Bitcoin) are often the currency of choice by cybercriminals (e.g., in ransomware incidents), they only provide pseudo-anonymity, in the sense that anyone can deanonymize Bitcoin transactions by using information in the blockchain. To strengthen the privacy protection of decentralized payment systems, a number of solutions such as Monero and Zerocash have been proposed. However, completely Decentralized Anonymous Payment (DAP) systems can be criminally exploited, for example in online extortion and money laundering activities. Recognizing the importance of regulation, we present a novel definition of Decentralized Conditional Anonymous Payment (DCAP) and describe the corresponding security requirements. In order to construct a concrete DCAP system, we first design a Condition Anonymous Payment (CAP) scheme (based on our proposed signature of knowledge), whose security can be demonstrated under the defined formal semantic and security models. To demonstrate utility, we compare the performance of our proposal with that of Zerocash under the same parameters and testing environment. Chao Lin 0003, Debiao He, Xinyi Huang 0001, Muhammad Khurram Khan, Kim-Kwang Raymond Choo |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2019 | Understanding Multi-Path Routing Algorithms in Datacenter NetworksabstractDatacenter is an irreplaceable and crucial infrastructure to power the ever-growing Internet services and applications. In response to today's application constraints (e.g., throughput, end-to-end delay, bandwidth), most datacenter networks are designed to maintain multiple parallel paths between any given pair of hosts. Consequently, multi-path routing has emerged as a technology of choice which can fully utilize the dormant path diversity. However, due to the growing heterogeneity of datacenter topologies and resource requirements, it demands intensive efforts to configure the right multi-path routing algorithms in real deployment according to the specific service targets. Such user burdens are caused by the lack of empirical knowledge about characteristics of various routing algorithms. To fill this gap, we develop a customized simulator DRE based on OMNET++ simulation environment and INET framework, and measure 5 state-of-the-art multi-path routing algorithms in datacenter covering various topologies and metrics. Apart from evaluating the standard macro metrics, we propose three new micro metrics to explore path-level characteristics, which have not been studied before. Our simulator provides a user-friendly interface for users who are interested in datacenter measurements, and the measurement results can promote future multi- path routing algorithm designs. Zhenzao Wen, Linghe Kong, Guihai Chen, Muhammad Khurram Khan, Shahid Mumtaz, Joel J. P. C. Rodrigues |
GLOBECOM | 4 |
| 2019 | CrowdSwitch: Crowdsensing Based Switch between Multiple Cellular Operators in SubwaysabstractSurfing the Internet with mobile phones is a popular fashion to kill time in subways. However, users usually meet the intermittent connectivity caused by the high- speed movement, leading to poor user experience. We observe that almost every city is covered by multiple cellular operators. In addition, more and more mobile phones support multiple SIM cards. These motivate us to leverage multiple cellular operators together for a reliable connectivity, which is also a trend for next generation cellular network. It is challenging to build collaborations between operators, because there is no interaction between different operators and the traditional handover methods would consume much time on cross-operator cellular detection. To address these challenges, we propose a Crowdsensing based Switch (CrowdSwitch) system between multiple cellular operators in subways. CrowdSwitch uses a large number of mobile phones to measure and collect wireless signals from different locations along subway tracks, uploads them to cloud servers for analysis, and finally recommends the optimal switch strategy to users. We implement CrowdSwitch in off-the-shelf mobile phones and conduct extensive experiments on Shanghai Metro. The results show that CrowdSwitch can depict the accurate LTE distribution and recommend the optimal operator for users to connect. Zucheng Wu, Linghe Kong, Guihai Chen, Muhammad Khurram Khan, Shahid Mumtaz, Joel J. P. C. Rodrigues |
GLOBECOM | 4 |
| 2019 | Energy Management in RFID-Sensor Networks: Taxonomy and ChallengesabstractUbiquitous computing is foreseen to play an important role for data production and network connectivity in the coming decades. The Internet of Things (IoT) research which has the capability to encapsulate identification potential and sensing capabilities, strives toward the objective of developing seamless, interoperable, and securely integrated systems which can be achieved by connecting the Internet with computing devices. This gives way for the evolution of wireless energy harvesting (EH) and power transmission using computing devices. Radio frequency (RF) based energy management (EM) has become the backbone for providing energy to wireless integrated systems. The two main techniques for EM in RF identification sensor networks (RSN) are EH and energy transfer (ET). These techniques enable the dynamic energy level maintenance and optimization as well as ensuring reliable communication which adheres to the goal of increased network performance and lifetime. In this paper, we present an overview of RSN, its types of integration and relative applications. We then provide the state-of-the-art EM techniques and strategies for RSN from August 2009 till date, thereby reviewing the existing EH and ET mechanisms designed for RSN. The taxonomy on various challenges for EM in RSN has also been articulated for open research directives. Shaik Shabana Anjum, Rafidah Md Noor, Mohammad Hossein Anisi, Ismail Bin Ahmedy, Fazidah Othman, Muhammad Alam 0002, Muhammad Khurram Khan |
IEEE Internet Things J. | 7 |
| 2019 | Trust and reputation for Internet of Things: Fundamentals, taxonomy, and open research challenges
Abdelmuttlib Ibrahim Abdallaahmed, Siti Hafizah Ab Hamid, Abdullah Gani, Suleman Khan 0001, Muhammad Khurram Khan |
J. Netw. Comput. Appl. | 5 |
| 2019 | A survey on privacy protection in blockchain system
Debiao He, Sherali Zeadally, Muhammad Khurram Khan, Neeraj Kumar 0001 |
J. Netw. Comput. Appl. | 4 |
| 2019 | A survey on software defined networking enabled smart buildings: Architecture, challenges and use cases
Muhammad Usman Younus, Saif ul Islam, Ihsan Ali, Suleman Khan 0001, Muhammad Khurram Khan |
J. Netw. Comput. Appl. | 5 |
| 2019 | Towards augmented proactive cyberthreat intelligence
Tanveer Khan, Masoom Alam, Adnan Akhunzada, Ali Hur, Muhammad Khurram Khan |
J. Parallel Distributed Comput. | 6 |
| 2019 | A scene image classification technique for a ubiquitous visual surveillance system
Maryam Asadzadeh Kaljahi, Palaiahnakote Shivakumara, Mohammad Hossein Anisi, Mohd Yamani Idna Bin Idris, Michael Blumenstein, Muhammad Khurram Khan |
Multim. Tools Appl. | 6 |
| 2019 | An identity-based encryption technique using subtree for fuzzy user data sharing under cloud computing environment
Chandrashekhar Meshram, Cheng-Chi Lee, Sarita Gajbhiye Meshram, Muhammad Khurram Khan |
Soft Comput. | 4 |
| 2018 | A secure chaotic map-based remote authentication scheme for telecare medicine information systems
Xiong Li 0002, Fan Wu 0003, Muhammad Khurram Khan, Jian Shen 0001, Minho Jo 0001 |
Future Gener. Comput. Syst. | 3 |
| 2018 | A robust and anonymous patient monitoring system using wireless medical sensor networks
Ruhul Amin 0001, SK Hafizul Islam, G. P. Biswas, Muhammad Khurram Khan, Neeraj Kumar 0001 |
Future Gener. Comput. Syst. | 4 |
| 2018 | Wireless Sensor Networks in oil and gas industry: Recent advances, taxonomy, requirements, and open challenges
Mohammed Y. Aalsalem, Wazir Zada Khan, Wajeb Gharibi, Muhammad Khurram Khan, Quratul-Ain Arshad |
J. Netw. Comput. Appl. | 4 |
| 2018 | Structures and data preserving homomorphic signatures
Naina Emmanuel, Abid Khan, Masoom Alam, Tanveer Khan, Muhammad Khurram Khan |
J. Netw. Comput. Appl. | 5 |
| 2018 | Recent advancements in garbled computing: How far have we come towards achieving secure, efficient and reusable garbled circuits
Ahsan Saleem, Abid Khan, Furqan Shahid, Masoom Alam, Muhammad Khurram Khan |
J. Netw. Comput. Appl. | 5 |
| 2018 | Intelligent Technique for Seamless Vertical Handover in Vehicular Networks
Shidrokh Goudarzi, Wan Haslina Hassan, Mohammad Hossein Anisi, Muhammad Khurram Khan, Seyed Ahmad Soleymani |
Mob. Networks Appl. | 4 |
| 2018 | A robust and efficient bilinear pairing based mutual authentication and session key verification over insecure communication
Ruhul Amin 0001, SK Hafizul Islam, Pandi Vijayakumar, Muhammad Khurram Khan, Victor Chang 0001 |
Multim. Tools Appl. | 4 |
| 2018 | An enhanced lightweight anonymous biometric based authentication scheme for TMIS
Shehzad Ashraf Chaudhry, Syed Husnain Abbas Naqvi, Muhammad Khurram Khan |
Multim. Tools Appl. | 3 |
| 2018 | A provably secure biometrics-based authenticated key agreement scheme for multi-server environments
Saru Kumari, Ashok Kumar Das, Xiong Li 0002, Fan Wu 0003, Muhammad Khurram Khan, Qi Jiang 0001, SK Hafizul Islam |
Multim. Tools Appl. | 5 |
| 2018 | Digital multimedia audio forensics: past, present and future
Mohammed Zakariah, Muhammad Khurram Khan, Hafiz Malik |
Multim. Tools Appl. | 2 |
| 2018 | Design of Secure and Lightweight Authentication Protocol for Wearable Devices EnvironmentabstractWearable devices are used in various applications to collect information including step information, sleeping cycles, workout statistics, and health-related information. Due to the nature and richness of the data collected by such devices, it is important to ensure the security of the collected data. This paper presents a new lightweight authentication scheme suitable for wearable device deployment. The scheme allows a user to mutually authenticate his/her wearable device(s) and the mobile terminal (e.g., Android and iOS device) and establish a session key among these devices (worn and carried by the same user) for secure communication between the wearable device and the mobile terminal. The security of the proposed scheme is then demonstrated through the broadly accepted real-or-random model, as well as using the popular formal security verification tool, known as the Automated validation of Internet security protocols and applications. Finally, we present a comparative summary of the proposed scheme in terms of the overheads such as computation and communication costs, security and functionality features of the proposed scheme and related schemes, and also the evaluation findings from the NS2 simulation. Ashok Kumar Das, Mohammad Wazid, Neeraj Kumar 0001, Muhammad Khurram Khan, Kim-Kwang Raymond Choo, Youngho Park 0005 |
IEEE J. Biomed. Health Informatics | 4 |
| 2018 | An anonymous and provably secure biometric-based authentication scheme using chaotic maps for accessing medical drop box data
Imran Khan 0004, Shehzad Ashraf Chaudhry, Muhammad Khurram Khan |
J. Supercomput. | 4 |
| 2017 | On Software-Defined Wireless Network (SDWN) Network Virtualization: Challenges and Open IssuesabstractSoftware-defined networking (SDN) is new network architecture that emerges as to implement network virtualization (NV) with vast features, especially when it is applied it in multi-tenant scenarios. The rapid growth of wireless network applications and services, let to adopt NVs into software-defined wireless network (SDWN). This is because wireless networks require specific features that can be hindered of implementing NVs such as updated location information, dynamic channel configuration, and rapid client re-association. This paper presents state-of-the-art NV methods for SDWN with the aim of highlighting issues and challenges of applying NVs techniques of SDN into SDWN. We discuss three SDN techniques that facilitate NV in the cloud, namely proxy-based virtualization, layer two prefixes-based virtualizations and programing language-based virtualization. Moreover, the paper points out the possibility of providing effective VNs in the SDWN architecture. We also taxonomies the SDWN proposed virtualization methods based on hypervisor controller in the different networks. Finally, the potential requirements and challenges and open issues of SDWN NVs are also identified and presented as the future directions in SDWN research. Tan Fong Ang, Abdullah Gani, Suleman Khan 0001, Faiz Alotaibi, Muhammad Khurram Khan |
Comput. J. | 6 |
| 2017 | On the design of a secure user authentication and key agreement scheme for wireless sensor networksabstractSummary A wireless sensor network (WSN) typically consists of a large number of resource‐constrained sensor nodes and several control or gateway nodes. Ensuring the security of the asymmetric nature of WSN is challenging, and designing secure and efficient user authentication and key agreement schemes for WSNs is an active research area. For example, in 2016, Farash et al. proposed a user authentication and key agreement scheme for WSNs. However, we reveal previously unpublished vulnerabilities in their scheme, which allow an attacker to carry out sensor node spoofing, password guessing, user/sensor node anonymity, and user impersonation attacks. We then present a scheme, which does not suffer from the identified vulnerabilities. To demonstrate the practicality of the scheme, we evaluate the scheme using NS‐2 simulator. We then prove the scheme secure using Burrows–Abadi–Needham logic. Copyright © 2016 John Wiley & Sons, Ltd. Saru Kumari, Ashok Kumar Das, Mohammad Wazid, Xiong Li 0002, Fan Wu 0003, Kim-Kwang Raymond Choo, Muhammad Khurram Khan |
Concurr. Comput. Pract. Exp. | 7 |
| 2017 | Attribute-based data access control in mobile cloud computing: Taxonomy and open issues
Mehdi Sookhak, F. Richard Yu, Muhammad Khurram Khan, Yang Xiang 0001, Rajkumar Buyya |
Future Gener. Comput. Syst. | 3 |
| 2017 | ABC-PSO for vertical handover in heterogeneous wireless networks
Shidrokh Goudarzi, Wan Haslina Hassan, Mohammad Hossein Anisi, Seyed Ahmad Soleymani, Mehdi Sookhak, Muhammad Khurram Khan, Aisha-Hassan A. Hashim, Mahdi Zareei |
Neurocomputing | 6 |
| 2017 | Secure Authentication Scheme for Medicine Anti-Counterfeiting System in IoT EnvironmentabstractA counterfeit drug is a medication or pharmaceutical product which is manufactured and made available on the market to deceptively represent its origin, authenticity and effectiveness, etc., and causes serious threats to the health of a patient. Counterfeited medicines have an adverse effect on the public health and cause revenue loss to the legitimate manufacturing organizations. In this paper, we propose a new authentication scheme for medicine anticounterfeiting system in the Internet of Things environment which is used for checking the authenticity of pharmaceutical products (dosage forms). The proposed scheme utilizes the near field communication (NFC) and is suitable for mobile environment, which also provides efficient NFC update phase. The security analysis using the widely accepted real-or-random model proves that the proposed scheme provides the session key security. The proposed scheme also protects other known attacks which are analyzed informally. Furthermore, the formal security verification using the broadly accepted automated validation of Internet security protocols and applications tool shows that the proposed scheme is secure. The scheme is efficient with respect to computation and communication costs, and also it provides additional functionality features when compared to other existing schemes. Finally, for demonstration of the practicality of the scheme, we evaluate it using the broadly accepted NS2 simulation. Mohammad Wazid, Ashok Kumar Das, Muhammad Khurram Khan, Abdulatif Al-Dhawailie Al-Ghaiheb, Neeraj Kumar 0001, Athanasios V. Vasilakos |
IEEE Internet Things J. | 3 |
| 2017 | Cross-VM cache-based side channel attacks and proposed prevention mechanisms: A survey
Shahid Anwar, Zakira Inayat, Mohamad Fadli Bin Zolkipli, Jasni Mohamad Zain, Abdullah Gani, Nor Badrul Anuar, Muhammad Khurram Khan, Victor Chang 0001 |
J. Netw. Comput. Appl. | 7 |
| 2017 | Information collection centric techniques for cloud resource management: Taxonomy, analysis and challenges
Sidra Aslam, Saif ul Islam, Abid Khan, Mansoor Ahmed, Adnan Akhunzada, Muhammad Khurram Khan |
J. Netw. Comput. Appl. | 6 |
| 2017 | Towards port-knocking authentication methods for mobile cloud computing
Suleman Khan 0001, Muhammad Shiraz, Laleh Boroumand, Abdullah Gani, Muhammad Khurram Khan |
J. Netw. Comput. Appl. | 5 |
| 2017 | Towards next-generation heterogeneous mobile data stream mining applications: Opportunities, challenges, and future research directions
Muhammad Habib Ur Rehman, Chee Sun Liew, Ying Wah Teh, Muhammad Khurram Khan |
J. Netw. Comput. Appl. | 4 |
| 2017 | Cloud monitoring: A review, taxonomy, and open research issues
Hassan Jamil Syed, Abdullah Gani, Raja Wasim Ahmad, Muhammad Khurram Khan, Abdelmuttlib Ibrahim Abdallaahmed |
J. Netw. Comput. Appl. | 4 |
| 2017 | Cryptanalysis of an identity-based public auditing protocol for cloud storageabstractPublic verification of data integrity is crucial for promoting the serviceability of cloud storage systems. Recently, Tan and Jia (2014) proposed an identity-based public verification (NaEPASC) protocol for cloud data to simplify key management and alleviate the burden of check tasks. They claimed that NaEPASC enables a third-party auditor (TPA) to verify the integrity of outsourced data with high efficiency and security in a cloud computing environment. However, in this paper, we pinpoint that NaEPASC is vulnerable to the signature forgery attack in the setup phase; i.e., a malicious cloud server can forge a valid signature for an arbitrary data block by using two correct signatures. Moreover, we demonstrate that NaEPASC is subject to data privacy threats in the challenge phase; i.e., an external attacker acting as a TPA can reveal the content of outsourced data. The analysis shows that NaEPASC is not secure in the data verification process. Therefore, our work is helpful for cryptographers and engineers to design and implement more secure and efficient identity-based public auditing schemes for cloud storage. Jing Wang 0036, Debiao He, Muhammad Khurram Khan |
Frontiers Inf. Technol. Electron. Eng. | 4 |
| 2017 | Cloud resource allocation schemes: review, taxonomy, and opportunities
Abdullah Yousafzai, Abdullah Gani, Rafidah Md Noor, Mehdi Sookhak, Hamid Talebian, Muhammad Shiraz, Muhammad Khurram Khan |
Knowl. Inf. Syst. | 7 |
| 2017 | Formal modeling and verification of security controls for multimedia systems in the cloud
Masoom Alam, Saif Ur Rehman Malik, Qaisar Javed, Abid Khan, Shamaila Bisma Khan, Adeel Anjum, Nadeem Javed, Adnan Akhunzada, Muhammad Khurram Khan |
Multim. Tools Appl. | 9 |
| 2017 | An improved smart card based authentication scheme for session initiation protocol
Saru Kumari, Shehzad Ashraf Chaudhry, Fan Wu 0003, Xiong Li 0002, Mohammad Sabzinejad Farash, Muhammad Khurram Khan |
Peer-to-Peer Netw. Appl. | 6 |
| 2017 | An efficient authentication and key agreement scheme with user anonymity for roaming service in smart city
Xiong Li 0002, Arun Kumar Sangaiah, Saru Kumari, Fan Wu 0003, Jian Shen 0001, Muhammad Khurram Khan |
Pers. Ubiquitous Comput. | 6 |
| 2017 | A Two-Factor RSA-Based Robust Authentication System for Multiserver EnvironmentsabstractThe concept of two-factor multiserver authentication protocol was developed to avoid multiple number of registrations using multiple smart-cards and passwords. Recently, a variety of two-factor multiserver authentication protocols have been developed. It is observed that the existing RSA-based multiserver authentication protocols are not suitable in terms of computation complexities and security attacks. To provide lower complexities and security resilience against known attacks, this article proposes a two-factor (password and smart-card) user authentication protocol with the RSA cryptosystem for multiserver environments. The comprehensive security discussion proved that the known security attacks are eliminated in our protocol. Besides, our protocol supports session key agreement and mutual authentication between the application server and the user. We analyze the proof of correctness of the mutual authentication and freshness of session key using the BAN logic model. The experimental outcomes obtained through simulation of the Automated Validation of Internet Security Protocols and Applications (AVISPA) S/W show that our protocol is secured. We consider the computation, communication, and storage costs and the comparative explanations show that our protocol is flexible and efficient compared with protocols. In addition, our protocol offers security resilience against known attacks and provides lower computation complexities than existing protocols. Additionally, the protocol offers password change facility to the authorized user. Ruhul Amin 0001, SK Hafizul Islam, Muhammad Khurram Khan, Arijit Karati, Debasis Giri, Saru Kumari |
Secur. Commun. Networks | 3 |
| 2017 | On Emerging Family of Elliptic Curves to Secure Internet of Things: ECC Comes of AgeabstractLightweight Elliptic Curve Cryptography (ECC) is a critical component for constructing the security system of Internet of Things (IoT). In this paper, we define an emerging family of lightweight elliptic curves to meet the requirements on some resource-constrained devices. We present the design of a scalable, regular, and highly-optimized ECC library for both MICAz and Tmote Sky nodes, which supports both widely-used key exchange and signature schemes. Our parameterized implementation of elliptic curve group arithmetic supports pseudo-Mersenne prime fields at different security levels with two optimized-specific designs: the high-speed version (HS) and the memory-efficient (ME) version. The former design achieves record times for computation of cryptographic schemes at roughly$80\sim 128$-bit security levels, while the latter implementation only requires half of the code size of the current best implementation. We also describe our efforts to evaluate the energy consumption and harden our library against some basic side-channel attacks, e.g., timing attacks and simple power analysis (SPA) attacks. Zhe Liu 0001, Xinyi Huang 0001, Muhammad Khurram Khan, Hwajeong Seo, Lu Zhou 0002 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2017 | Security analysis of a publicly verifiable data possession scheme for remote storage
Zhiyan Xu, Debiao He, Muhammad Khurram Khan |
J. Supercomput. | 4 |
| 2017 | A secure and efficient public auditing scheme using RSA algorithm for cloud storage
Zhiyan Xu, Muhammad Khurram Khan, Kim-Kwang Raymond Choo, Debiao He |
J. Supercomput. | 3 |
| 2016 | EHR: Routing Protocol for Energy Harvesting Wireless Sensor NetworksabstractA well-designed energy-efficient routing protocol is an indispensable part for prolonging the lifetime of wireless sensor networks (WSNs) because a sensor node usually has limited energy. Many research efforts are contributed on routing design in WSNs. With the development of green technology, the energy harvesting technique is being applied to real WSNs. Therefore, existing routing protocols are not suitable for such new WSNs with energy harvesting. In this paper, we concentrate on designing a novel routing protocol, named energy harvesting routing (EHR), which takes energy harvesting as one major factor into routing design to improve the energy efficiency. First, we introduce a hybrid routing metric combining the effect of residual energy and energy harvesting rate. Then we propose an updating mechanism allowing every node to maintain dynamic energy information of its neighbors. Based on the hybrid metric and the neighbor information, EHR is able to locally select the optimal next hop. Extensive simulations are conducted to evaluate the performance of EHR. Results demonstrate that EHR outperforms existing routing protocols in energy harvesting WSNs in term of the energy efficiency. Yifeng Cao, Xiao-Yang Liu, Linghe Kong, Min-You Wu, Muhammad Khurram Khan |
ICPADS | 5 |
| 2016 | Design of an anonymity-preserving three-factor authenticated key exchange protocol for wireless sensor networks
Ruhul Amin 0001, SK Hafizul Islam, G. P. Biswas, Muhammad Khurram Khan, Lu Leng, Neeraj Kumar 0001 |
Comput. Networks | 4 |
| 2016 | A user friendly mutual authentication and key agreement scheme for wireless sensor networks using chaotic maps
Saru Kumari, Xiong Li 0002, Fan Wu 0003, Ashok Kumar Das, Hamed Arshad, Muhammad Khurram Khan |
Future Gener. Comput. Syst. | 6 |
| 2016 | Lightweight anonymous key distribution scheme for smart grid using elliptic curve cryptographyabstractDue to efficiency, security and reliability, the smart grid attracts more and more attentions from both industry and researchers. To implement secure communication in the smart grid, how to distribute secret keys among participants become an important issue. Several key distribution schemes for the smart grid have been proposed to guarantee secure communication. However, most of them cannot provide smart meter anonymity or have unsatisfactory performance. Based on the identity‐based cryptography, this study proposes an anonymous key distribution (AKD) scheme for the smart grid using the elliptic curve cryptography. The proposed AKD scheme can provide the smart meter anonymity and mutual authentication between two participants without any help of the trusted anchor. Due to the fact that no bilinear paring operation is involved in the execution, the proposed AKD scheme has much better performance than the latest AKD scheme proposed by Tsai and Lo. Detailed performance analysis shows that the computation and the communication costs of the authors’ AKD scheme is about 82.39 and 52.33% less than that of Tsai and Lo's AKD scheme. Besides, security analysis shows that the proposed AKD scheme is provably secure in the random oracle model. Debiao He, Huaqun Wang, Muhammad Khurram Khan, Lina Wang 0001 |
IET Commun. | 3 |
| 2016 | Secure and dependable software defined networks
Adnan Akhunzada, Abdullah Gani, Nor Badrul Anuar, Muhammad Khurram Khan, Amir Hayat, Samee Ullah Khan |
J. Netw. Comput. Appl. | 5 |
| 2016 | Intrusion response systems: Foundations, design, and challenges
Zakira Inayat, Abdullah Gani, Nor Badrul Anuar, Muhammad Khurram Khan, Shahid Anwar |
J. Netw. Comput. Appl. | 4 |
| 2016 | On cloud security attacks: A taxonomy and intrusion detection and prevention as a service
Salman Iqbal, Miss Laiha Mat Kiah, Babak Daghighi, Suleman Khan 0001, Muhammad Khurram Khan, Kim-Kwang Raymond Choo |
J. Netw. Comput. Appl. | 6 |
| 2016 | Towards native code offloading based MCC frameworks for multimedia applications: A survey
Junaid Shuja, Abdullah Gani, Muhammad Habib Ur Rehman, Ejaz Ahmed 0003, Sajjad Ahmad Madani, Muhammad Khurram Khan, Kwangman Ko |
J. Netw. Comput. Appl. | 6 |
| 2016 | Cloud-assisted Industrial Systems and Applications
Jiafu Wan, Muhammad Khurram Khan, Meikang Qiu, Daqiang Zhang 0001 |
Mob. Networks Appl. | 2 |
| 2016 | A more secure digital rights management authentication scheme based on smart card
Saru Kumari, Muhammad Khurram Khan, Xiong Li 0002 |
Multim. Tools Appl. | 2 |
| 2016 | Single round-trip SIP authentication scheme with provable security for Voice over Internet Protocol using smart card
Saru Kumari, Fan Wu 0003, Xiong Li 0002, Mohammad Sabzinejad Farash, Qi Jiang 0001, Muhammad Khurram Khan, Ashok Kumar Das |
Multim. Tools Appl. | 6 |
| 2016 | Cryptanalysis and improvement of 'a secure authentication scheme for telecare medical information system' with nonce verification
Zeeshan Siddiqui, Abdul Hanan Abdullah, Muhammad Khurram Khan, Abdullah Sharaf Alghamdi |
Peer-to-Peer Netw. Appl. | 3 |
| 2016 | A more secure and privacy-aware anonymous user authentication scheme for distributed mobile cloud computing environmentsabstractAbstract Now‐a‐days, the low‐power handheld mobile devices make our life more comfortable. With the fast advancement of mobile communication technologies and Internet, mobile users are accessing remote services at home over the Internet. Recently, Tsai and Lo put forwarded a user authentication scheme for distributing mobile cloud environments. Unfortunately, we observed that Tsai and Lo's scheme suffers from user impersonation attack and known session‐specific temporary information attack. Besides, the scheme does not support the wrong password and fingerprint detection in the authentication phase. The scheme also violates the user anonymity property. Moreover, the password update functionality is absent in Tsai and Lo's scheme. In order to provide more securities and functionalities, this article put forwarded an enhanced scheme for distributing mobile cloud environments. The simulation on automated validation of Internet security protocols and applications tool ensures that our scheme is secure against the active and passive attacks. Our cryptanalysis gives surety that the scheme can defend related security attacks. We also compare our scheme with the previous schemes with respect to computation cost and security aspects. Copyright © 2016 John Wiley & Sons, Ltd. Ruhul Amin 0001, SK Hafizul Islam, G. P. Biswas, Debasis Giri, Muhammad Khurram Khan, Neeraj Kumar 0001 |
Secur. Commun. Networks | 5 |
| 2016 | A provably secure anonymous authentication scheme for Session Initiation ProtocolabstractAbstract Recently, Lu et al. presented a mutual authentication scheme for Session Initiation Protocol. Lu et al. claimed their scheme provides safeguard against familiar attacks and offers efficient authentication facility. However, this paper divulges that the scheme of Lu et al. is prone to server and user impersonation attacks. Additionally, the scheme of Lu et al. implicates correctness concerns. Consequently, an enhanced scheme is proposed, not only to resolve correctness concerns but also to provide robustness against server and user impersonation attacks. The proposed scheme makes use of a user‐specific secret parameter to deal with the security and correctness issues. The formal and informal security analysis proves the robustness and efficiency of the proposed scheme against all familiar attacks. Furthermore, security analysis is also substantiated through popular automated tool PROVERIF. Copyright © 2016 John Wiley & Sons, Ltd. Shehzad Ashraf Chaudhry, Imran Khan 0004, Azeem Irshad, Muhammad Usman Ashraf, Muhammad Khurram Khan, Hafiz Farooq Ahmad |
Secur. Commun. Networks | 5 |
| 2016 | Design of a provably secure identity-based digital multi-signature scheme using biometrics and fuzzy extractorabstractA novel biometric identity-based digital multi-signature BIO-IDMS scheme is put forwarded in this paper. The proposed scheme is constructed with the help of fuzzy extractor and elliptic curve bilinear pairings. Furthermore, we designed the formal model and the security model of the proposed BIO-IDMS scheme. The formal security analysis demonstrates that the forgery of the proposed scheme is infeasible in the random oracle model based on the intractability assumption of the computational Diffie-Hellman CDH problem. The proposed scheme outperforms in terms of computational cost compared with other related existing multi-signature schemes. Copyright © 2016 John Wiley & Sons, Ltd. SK Hafizul Islam, Ashok Kumar Das, Muhammad Khurram Khan |
Secur. Commun. Networks | 3 |
| 2016 | A new authentication protocol for healthcare applications using wireless medical sensor networks with user anonymityabstractABSTRACT With the development and maturation of the wireless communication technologies, the wireless sensor networks have been widely applied in different environments to acquire specific information. The wireless medical sensor networks (WMSNs), as a professional application of the wireless sensor networks in medicine, have attracted more and more attention because of its potential in improving the quality of healthcare services. Through the WMSNs, the parameters of patients' vital signs can be gathered from the sensor nodes equipped on the body of the patients and then can be accessed by the healthcare professionals by using a mobile device. By reason of the open feature of wireless communication, how to guarantee secure communication becomes an important issue. On the other hand, because the vital signs parameters are sensitive to the patients' health status and no one wants to reveal it to the others except the healthcare professionals, the protection of patients' privacy becomes another key issue for WMSNs applications. User authentication protocol with anonymity is the most basic and commonly used method to resolve the security and privacy issues of WMSNs. Recently, He et al. proposed an enhanced authentication protocol for healthcare applications using WMSNs to protect the security and privacy problems. However, we find that their scheme is incorrect in authentication and session key agreement phase. Besides, their scheme has no wrong password detection mechanism, which will not only waste the unnecessary computation and communication costs, but also may deduce the denial of service problem. In this paper, the biometric is introduced as the third authentication factor, and a new user anonymous authentication protocol based on WMSNs is designed so as to remove the drawbacks of the protocol of He et al. Compared with previous protocols, the new presented protocol enhances the security and also keeps the computation efficiency. Copyright © 2015 John Wiley & Sons, Ltd. Xiong Li 0002, Jianwei Niu 0002, Saru Kumari, Junguo Liao, Wei Liang 0005, Muhammad Khurram Khan |
Secur. Commun. Networks | 6 |
| 2016 | Robust three-factor remote user authentication scheme with key agreement for multimedia systemsabstractAbstract As the fast growth of multimedia information, the security of multimedia systems is becoming a rather important topic nowadays. Multimedia systems are often suffering attacks when users access the information and online services. Because of the excellent features of the biometric, many biometric‐based three‐factor remote user authentication schemes have been proposed to provide high level of security for different network‐based application systems. Recently, An pointed out the weaknesses of Das's three‐factor remote user authentication scheme and proposed an improved biometric‐based three‐factor remote user authentication scheme. An's scheme improves the security problems of previous schemes while keeping the efficiency. However, after detailed analysis, we find that An's scheme exists some weaknesses such as vulnerable to denial‐of‐service attack and forgery attack, cannot detect unauthorized login quickly, and does not provide session key agreement. In order to provide high level of security for multimedia systems, we design a robust three‐factor remote user authentication scheme with key agreement using elliptic curve cryptosystem. Copyright © 2014 John Wiley & Sons, Ltd. Xiong Li 0002, Jianwei Niu 0002, Muhammad Khurram Khan, Junguo Liao, Xiaoke Zhao |
Secur. Commun. Networks | 3 |
| 2016 | An enhanced multi-server authentication protocol using password and smart-card: cryptanalysis and designabstractAbstract At the present time, application of online communication systems are rapidly increasing and most of the clients depend on a set of servers to fulfill their daily needs. In order to access these servers, a client (user) needs to register to each server with different login credentials. To circumvent this situation, the concept of multi‐server authentication has been adopted, where a user can access all the servers using a single login credential. In this paper, a two‐factor multi‐server authentication protocol, which is proposed by Leu and Hsieh, is analyzed and observed that the forgery attack and the off‐line password‐guessing attack can be made on it. Further, the off‐line password‐guessing attack and other security threats are found in similar kind of multi‐server authentication protocol, which is designed by Li et al. This paper mainly focuses on enhancing the securities of the previously mentioned protocols and thus proposed a new protocol. We have employed formal and informal security analysis to analyze the proposed protocol. The performance of our protocol is also compared with the related protocols. It can also be noted that the designed protocol accomplishes mutual authentication, session key verification, and identity and password change phases. Copyright © 2016 John Wiley & Sons, Ltd. Tanmoy Maitra, SK Hafizul Islam, Ruhul Amin 0001, Debasis Giri, Muhammad Khurram Khan, Neeraj Kumar 0001 |
Secur. Commun. Networks | 5 |
| 2016 | Design of sinkhole node detection mechanism for hierarchical wireless sensor networksabstractAbstract Wireless sensor networks (WSNs) have several applications ranging from the civilian to military applications. WSNs are prone to various hole attacks, such as sinkhole, wormhole, blackhole, and greyhole. Among these hole attacks, the sinkhole attack is the malignant one. A sinkhole attack allows a malicious node, called the sinkhole node, advertises a best possible path to the base station (BS). This misguides its neighbors to utilize that path more frequently. The sinkhole node has the opportunity to tamper with the data, and it also performs the modifications in messages or it drops messages or it produces unnecessary delay before forwarding them to the BS. On the basis of these malicious acts that are performed by a sinkhole attacker node, we consider three types of malicious nodes in a WSN: sinkhole message modification node (SMD), sinkhole message dropping node (SDP), and sinkhole message delay node (SDL). None of the existing techniques in the literature is capable to handle all three types of nodes at a time. This paper presents a new detection scheme for the detection of different types of sinkhole nodes for a hierarchical wireless sensor network (HWSN). To the best of our knowledge, this is the first attempt to design such a detection scheme in HWSNs which can detect SMD, SDP, and SDL nodes. In our approach, the entire HWSN is divided into several disjoint clusters, and each cluster has a powerful high‐end sensor node (called a cluster head), which is responsible for the detection of different sinkhole attacker nodes if present in that cluster. We simulate our scheme using the widely‐accepted NS2 simulator for measurement of various network parameters. The proposed scheme achieves around 95%detection rate and 1.25%false positive rate. These factors are significantly better than the previous related schemes. Furthermore, the computation and communication efficiency is achieved in our scheme. As a result, our scheme seems suitable for the sensitive critical applications, such as military applications. Copyright © 2016 John Wiley & Sons, Ltd. Mohammad Wazid, Ashok Kumar Das, Saru Kumari, Muhammad Khurram Khan |
Secur. Commun. Networks | 4 |
| 2016 | A novel and provably secure authentication and key agreement scheme with user anonymity for global mobility networksabstractUbiquitous networks support the roaming service for mobile communication devices. The mobile user can use the services in the foreign network with the help of the home network. Mutual authentication plays an important role in the roaming services, and researchers put their interests on the authentication schemes. Recently, in 2016, Gope and Hwang found that mutual authentication scheme of He et al. for global mobility networks had security disadvantages such as vulnerability to forgery attacks, unfair key agreement, and destitution of user anonymity. Then, they presented an improved scheme. However, we find that the scheme cannot resist the off-line guessing attack and the de-synchronization attack. Also, it lacks strong forward security. Moreover, the session key is known to HA in that scheme. To get over the weaknesses, we propose a new two-factor authentication scheme for global mobility networks. We use formal proof with random oracle model, formal verification with the tool Proverif, and informal analysis to demonstrate the security of the proposed scheme. Compared with some very recent schemes, our scheme is more applicable. Copyright © 2016 John Wiley & Sons, Ltd. Fan Wu 0003, Saru Kumari, Xiong Li 0002, Ashok Kumar Das, Muhammad Khurram Khan, Marimuthu Karuppiah, Renuka Baliyan |
Secur. Commun. Networks | 6 |
| 2016 | A privacy preserving three-factor authentication protocol for e-Health clouds
Qi Jiang 0001, Muhammad Khurram Khan, Xiang Lu 0004, Jianfeng Ma 0001, Debiao He |
J. Supercomput. | 2 |
| 2015 | A Secure Cross-Domain SIP Solution for Mobile Ad Hoc Network Using Dynamic Clustering
Ala' F. A. Aburumman, Wei Jye Seo, Md. Rafiqul Islam 0001, Muhammad Khurram Khan, Kim-Kwang Raymond Choo |
SecureComm | 4 |
| 2015 | User authentication schemes for wireless sensor networks: A review
Saru Kumari, Muhammad Khurram Khan, Mohammed Atiquzzaman |
Ad Hoc Networks | 2 |
| 2015 | An efficient certificateless aggregate signature with conditional privacy-preserving for vehicular sensor networks
Shi-Jinn Horng, Shiang-Feng Tzeng, Po-Hsian Huang, Xian Wang 0002, Tianrui Li 0001, Muhammad Khurram Khan |
Inf. Sci. | 6 |
| 2015 | Seamless application execution in mobile cloud computing: Motivation, taxonomy, and open challenges
Ejaz Ahmed 0003, Abdullah Gani, Muhammad Khurram Khan, Rajkumar Buyya, Samee Ullah Khan |
J. Netw. Comput. Appl. | 3 |
| 2015 | Man-At-The-End attacks: Analysis, taxonomy, human aspects, motivation and future directions
Adnan Akhunzada, Mehdi Sookhak, Nor Badrul Anuar, Abdullah Gani, Ejaz Ahmed 0003, Muhammad Shiraz, Steven Furnell, Amir Hayat, Muhammad Khurram Khan |
J. Netw. Comput. Appl. | 9 |
| 2015 | Orientation range of transposition for vertical correlation suppression of 2DPalmPhasor Code
Lu Leng, Andrew Beng Jin Teoh, Ming Li 0056, Muhammad Khurram Khan |
Multim. Tools Appl. | 4 |
| 2015 | An enhanced privacy preserving remote user authentication scheme with provable securityabstractAbstract Very recently, Kumariet al.proposed a symmetric key and smart card‐based remote user password authentication scheme to enhance Chunget al.'s scheme. They claimed their enhanced scheme to provide anonymity while resisting all known attacks. In this paper, we analyze that Kumariet al.'s scheme is still vulnerable to anonymity violation attack as well as smart card stolen attack. Then we propose a supplemented scheme to overcome security weaknesses of Kumariet al.'s scheme. We have analyzed the security of the proposed scheme in random oracle model which confirms the robustness of the scheme against all known attacks. We have also verified the security of our scheme using automated tool ProVerif. Copyright © 2015 John Wiley & Sons, Ltd. Shehzad Ashraf Chaudhry, Mohammad Sabzinejad Farash, Syed Husnain Abbas Naqvi, Saru Kumari, Muhammad Khurram Khan |
Secur. Commun. Networks | 5 |
| 2015 | Anonymous and provably secure certificateless multireceiver encryption without bilinear pairingabstractRecently, numerous multireceiver identity-based encryption or identity-based broadcast encryption schemes have been introduced with bilinear pairing and probabilistic map-to-point MTP function. As the bilinear pairing and MTP functions are expensive operations, any cryptographic schemes based on these operations experience high computational burden. The certificateless public key cryptography sidesteps the private key escrow problem occurring in identity-based cryptosystem and certificate management troubles of certificate authority-based public key cryptography CA-PKC. We observed that certificateless multireceiver encryption CL-MRE scheme without pairing and MTP hash function has not yet been considered in the literature. In this paper, we proposed a bilinear pairing and MTP hash-function-free CL-MRE scheme with chosen ciphertext attack resilience. The detailed analyses provide evidence that our scheme achieves forward secrecy, backward secrecy, and low computation costs than others. The scheme also provides confidentiality of the message and receiver anonymity in the random oracle model with the hardness of computational Diffie-Hellman problem. Copyright © 2014 John Wiley & Sons, Ltd. SK Hafizul Islam, Muhammad Khurram Khan, Ali M. Al-Khouri |
Secur. Commun. Networks | 2 |
| 2015 | A virtual bridge certificate authority-based cross-domain authentication mechanism for distributed collaborative manufacturing systemsabstractAbstract The virtual enterprise (VE) is a new collaborative intelligent manufacturing paradigm that pools the core competencies of its member enterprises through computer networks to exploit transient market opportunities. The successful operation of such an organization is strongly dependent on its information securities, in which cross‐domain authentication among entities of different member enterprises is a crucial issue. This problem is particularly difficult in VEs because of their collaborative nature in terms of agility, market dynamics, low cost, and diversity of collaboration modes. In this paper, we put forward a novel virtual bridge certificate authority (BCA) trust model, based on which an efficient cross‐domain authentication scheme is further presented. The proposed scheme is implemented by the distributed verifiable secret sharing protocol and the threshold elliptic curve cryptosystem signature algorithm. It has the same advantages of simple construction and short length of inter‐enterprise certification paths as the BCA model but does not need to create and maintain a dedicated physical BCA. In addition, the proposed scheme has the merits of high bit security, high efficiency, low cost, conspiracy attack resistance, and adaptability to diverse collaboration modes of VE. Therefore, the scheme is suitable for cross‐domain authentications in VEs, especially for resource‐limited applications. Copyright © 2014 John Wiley & Sons, Ltd. Wenfang Zhang, Muhammad Khurram Khan |
Secur. Commun. Networks | 3 |
| 2014 | Security Issues of Chen et al.'s Dynamic ID-Based Authentication SchemeabstractChen et al. proposed in 2012, a dynamic ID-based authentication scheme for Telecare Medical Information Systems. Chen et al. preferred simpler computations unlike previous schemes proposed for TMIS, so they designed a computational complexity-free protocol. But it entails many security concerns. Here we show that an adversary can cheat the lawful participants of the scheme, can compute the agreed upon session-key, which renders the communication between the participants as un-confidential. We further illustrate that in-spite of using dynamic identity during login phase their scheme does not provide user anonymity. We also demonstrate that their design invites password guessing attack, stolen verifier attack and has an incomplete password change phase. Muhammad Khurram Khan, Saru Kumari |
DASC | 1 |
| 2014 | Analysis of correlation of 2DPalmHash Code and orientation range suitable for transposition
Lu Leng, Andrew Beng Jin Teoh, Ming Li 0056, Muhammad Khurram Khan |
Neurocomputing | 4 |
| 2014 | A review on remote data auditing in single cloud server: Taxonomy and open issues
Mehdi Sookhak, Hamid Talebian, Ejaz Ahmed 0003, Abdullah Gani, Muhammad Khurram Khan |
J. Netw. Comput. Appl. | 5 |
| 2014 | An adaptive watermarking scheme for e-government document images
Shi-Jinn Horng, Didi Rosiyadi, Pingzhi Fan, Xian Wang 0002, Muhammad Khurram Khan |
Multim. Tools Appl. | 5 |
| 2014 | Cryptanalysis and Improvement of "An Efficient and Secure Dynamic ID-based Authentication Scheme for Telecare Medical Information Systems"abstractABSTRACT Recently, telecare medicine information systems (TMIS) have emerged as an effective mechanism to raise quality convenience and availability of healthcare services. User authentication schemes play an important role in solving security problems and grant access to healthcare services only to the authorized users. In 2010, a few authentication schemes were proposed for TMIS. These were based on the concept of static identity. In 2012, Chen et al. proposed a dynamic ID‐based authentication scheme for TMIS, so that the user's identity is not revealed to anyone. However, Chen et al.'s scheme does not involve complex computations like the previous scheme for TMIS, yet it suffers from various security problems. We will show that attackers can not only impersonate the legal participants of the scheme but can also compute the shared session‐key. In fact, it is an attack over the confidential communication between the participants. We will also show other drawbacks, such as password guessing attack, denial‐of‐service attack, immediate replay attack, and incomplete password change phase, present in the scheme. We also demonstrate user anonymity breach in Chen et al.'s scheme. To overcome these problems, we propose an improvement to Chen et al.'s scheme with a different approach. Our approach is aimed at providing an authentication mechanism for TMIS with strong security features. Copyright © 2013 John Wiley & Sons, Ltd. Muhammad Khurram Khan, Saru Kumari |
Secur. Commun. Networks | 1 |
| 2014 | An improved timestamp-based password authentication scheme: comments, cryptanalysis, and improvementabstractABSTRACT In 2003, Shen et al. proposed a timestamp‐based password authentication scheme by using smart card. Later, in 2005 and 2008, this scheme was found susceptible to forged login attacks by some researchers, and improved schemes were proposed. In 2011, Awasthi et al. pointed out an additional security threat on the scheme of Shen et al. and also suggested remedy by proposing an enhanced scheme. In this paper, we analyze the additional attack identified by Awasthi et al. on the scheme of Shen et al. show its flaws and rectify it. Further, we find that the scheme of Awasthi et al. still fails to withstand forged login attack, smart card loss attack, offline password guessing attack, and so on, and also inherits some weaknesses from the original scheme. Therefore, we propose an improved version of the scheme of Awasthi et al. Our improved scheme not only resists the attacks that we depict on the scheme of Awasthi et al. but is also free from the attacks pointed out so far on the scheme of Shen et al. Copyright © 2013 John Wiley & Sons, Ltd. Saru Kumari, Mridul Kumar Gupta, Muhammad Khurram Khan, Xiong Li 0002 |
Secur. Commun. Networks | 3 |
| 2014 | More secure smart card-based remote user password authentication scheme with user anonymityabstractABSTRACT In 2009, Xu et al. designed a smart card‐based user authentication scheme. It was found at risk of offline password guessing and forgery attacks as proved by Sood et al. They also proposed an improvement to Xu et al.'s scheme with a view to fix its defects. Parallel to Sood et al.'s work, Song also identified that a domestic but illicit user of the system can impersonate other innocent users. Later, Chen et al. claimed that designs of Sood et al.'s and Song's schemes are not flawless, and they built a scheme over both of these schemes. In 2013, Li et al. observed absence of forward secrecy and lack of password validity test by smart card in Chen et al.'s scheme. They also asserted password change phase of Chen et al.'s scheme as unfriendly and inefficient and gave rise to a new scheme. However, we discover many flaws including offline password guessing and impersonation threats in Li et al.'s scheme. We find that none of the aforementioned schemes provide user anonymity. Therefore, we propose a user authentication scheme with user anonymity. The analysis shows that our scheme retains merits of its predecessor schemes, is free from faults identified in these schemes, and also offers some extra features that make it more suitable for practical applications. Copyright © 2013 John Wiley & Sons, Ltd. Saru Kumari, Muhammad Khurram Khan |
Secur. Commun. Networks | 2 |
| 2014 | A remote cancelable palmprint authentication protocol based on multi-directional two-dimensional PalmPhasor-fusionabstractABSTRACT Biometric template security and privacy issues are critical in biometric authentication systems and require special attention. However, remote biometric authentication systems demand wider array of measures for maximum protection. This paper proposes a remote cancelable palmprint authentication protocol based on multi‐directional two‐dimensional PalmPhasor‐fusion. The main contribution is three‐fold. First, with a transposition direction selection mechanism, multi‐directional two‐dimensional PalmPhasor (MTDPP) improves the accuracy performance of two‐dimensional PalmPhasor. Second, we provide the theoretical analysis of the effect of transposition on the accuracy performance of two‐dimensional PalmPhasor, and hence establish an effective transposition direction range for the proposed MTDPP. Third, according to our analysis, the existing remote palmprint authentication system does not satisfy non‐invertibility criterion of secure template protection and is vulnerable to interception. Besides, secret message embedding as a countermeasure for database attacks deteriorates accuracy performance and causes inconvenience in updating authenticator. The proposed protocol uses multi‐directional two‐dimensional PalmPhasor‐fusion, one‐time random number encrypted with asymmetric cryptography and encrypted hash codes of MTDPP to address the problems. Copyright © 2013 John Wiley & Sons, Ltd. Lu Leng, Andrew Beng Jin Teoh, Ming Li 0056, Muhammad Khurram Khan |
Secur. Commun. Networks | 4 |
| 2013 | Lattice-based signcryptionabstractSUMMARY Signcryption is a cryptographic primitive that performs simultaneously both the functions of digital signature and public‐key encryption, at a cost significantly lower than that required by the traditional signature‐ then‐encryption approach. In this paper, we provide a positive answer to the question of if it is possible to construct signcryption based on lattice problems. More precisely, we design an efficient signcryption scheme that can send a message of length l one time. We prove that the proposed scheme has the indistinguishability against adaptive chosen ciphertext attacks under the learning with errors assumption and strong unforgeability against adaptive chosen messages attacks under the inhomogeneous small integer solution assumption in the random oracle model. Copyright © 2012 John Wiley & Sons, Ltd. Fagen Li, Fahad Bin Muhaya, Muhammad Khurram Khan, Tsuyoshi Takagi |
Concurr. Comput. Pract. Exp. | 3 |
| 2013 | An enhanced smart card based remote user password authentication scheme
Xiong Li 0002, Jianwei Niu 0002, Muhammad Khurram Khan, Junguo Liao |
J. Netw. Comput. Appl. | 3 |
| 2013 | A framework for preservation of cloud users' data privacy using dynamic reconstruction of metadata
Adeela Waqar, Asad Raza, Haider Abbas, Muhammad Khurram Khan |
J. Netw. Comput. Appl. | 4 |
| 2013 | Using Sorted Switching Median Filter to remove high-density impulse noises
Shi-Jinn Horng, Ling-Yuan Hsu, Tianrui Li 0001, Shaojie Qiao, Xun Gong 0002, Hsien-Hsin Chou, Muhammad Khurram Khan |
J. Vis. Commun. Image Represent. | 7 |
| 2013 | A blind image copyright protection scheme for e-government
Shi-Jinn Horng, Didi Rosiyadi, Tianrui Li 0001, Takao Terano, Minyi Guo, Muhammad Khurram Khan |
J. Vis. Commun. Image Represent. | 6 |
| 2013 | b-SPECS+: Batch Verification for Secure Pseudonymous Authentication in VANETabstractThe security and privacy preservation issues are prerequisites for vehicular ad hoc networks. Recently, secure and privacy enhancing communication schemes (SPECS) was proposed and focused on intervehicle communications. SPECS provided a software-based solution to satisfy the privacy requirement and gave lower message overhead and higher successful rate than previous solutions in the message verification phase. SPECS also presented the first group communication protocol to allow vehicles to authenticate and securely communicate with others in a group of known vehicles. Unfortunately, we find out that SPECS is vulnerable to impersonation attack. SPECS has a flow such that a malicious vehicle can force arbitrary vehicles to broadcast fake messages to other vehicles or even a malicious vehicle in the group can counterfeit another group member to send fake messages securely among themselves. In this paper, we provide a secure scheme that can achieve the security and privacy requirements, and overcome the weaknesses of SPECS. Moreover, we show the efficiency merits of our scheme through performance evaluations in terms of verification delay and transmission overhead. Shi-Jinn Horng, Shiang-Feng Tzeng, Yi Pan 0001, Pingzhi Fan, Xian Wang 0002, Tianrui Li 0001, Muhammad Khurram Khan |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2012 | A blind reversible method for watermarking relational databases based on a time-stamping protocol
Mahmoud E. Farfoura, Shi-Jinn Horng, Jui-Lin Lai, Ray-Shine Run, Rong-Jian Chen, Muhammad Khurram Khan |
Expert Syst. Appl. | 6 |
| 2012 | High performance biometrics recognition algorithms and systems
Muhammad Khurram Khan |
Future Gener. Comput. Syst. | 1 |
| 2012 | A biometric identity-based signcryption scheme
Fagen Li, Muhammad Khurram Khan |
Future Gener. Comput. Syst. | 2 |
| 2012 | Adaptively weighted sub-directional two-dimensional linear discriminant analysis for face recognition
Lijun Yan, Jeng-Shyang Pan 0001, Shu-Chuan Chu 0001, Muhammad Khurram Khan |
Future Gener. Comput. Syst. | 4 |
| 2012 | Identity-based online/offline signcryption for low power devices
Fagen Li, Muhammad Khurram Khan, Khaled Alghathbar, Tsuyoshi Takagi |
J. Netw. Comput. Appl. | 2 |
| 2012 | Analysis of existing remote attestation techniquesabstractABSTRACT This paper has been written as a part of the research project that is working towards the implementation of dynamic behavioral attestation for mobile platforms. The motivation behind this paper was to analyze the existing remote attestation techniques in order to figure out their strengths and weaknesses. We have analyzed Integrity Measurement Architecture, Policy‐reduced Integrity Measurement Architecture, Property‐based Attestation, Remote Attestation on Program Execution, Semantic Remote Attestation, Trustable Remote Verification of Web Services, and Model‐based Behavior Attestation. Each of the existing remote attestation techniques was found to be effective in some situations but was found to be infeasible in others. Therefore, a new remote attestation technique is needed, which is platform independent and flexible enough to meet the challenges of today's scalable computing environments. Copyright © 2011 John Wiley & Sons, Ltd. Masoom Alam, Tamleek Ali, Sanaullah Khan, Shahbaz Khan 0003, Mohammad Nauman, Amir Hayat, Muhammad Khurram Khan, Khaled Alghathbar |
Secur. Commun. Networks | 8 |
| 2012 | Mobile one-time passwords: two-factor authentication using mobile phonesabstractABSTRACT Static password authentication has security drawbacks. In two‐factor authentication (2FA,) each user carries a device, called token, to generate passwords that are valid only one time. 2FA based on one‐time passwords (OTPs) provides improved protection because users are prompted to provide something they know (i.e., PIN) and something they have (i.e., token). Many systems have satisfied the 2FA requirements by sending an OTP through an SMS to the user's phone device. Unfortunately, international roaming, and SMS costs, delays, and security put restrictions on this system reliability. Also, time synchronous‐based solutions are not applicable for mobile phones. In this paper, we present a novel 2FA scheme whereby multiple OTPs are being produced by utilizing an initial seed and two different nested hash chains: one dedicated to seed updating and the other used for OTP production. We overcome all the restrictions that come from other techniques. We analyze our proposal from the viewpoint of security and performance compared with the other algorithms. Copyright © 2011 John Wiley & Sons, Ltd. Mohamed Eldefrawy, Muhammad Khurram Khan, Khaled Alghathbar, Tai-Hoon Kim, Hassan M. Elkamchouchi |
Secur. Commun. Networks | 2 |
| 2012 | A new dynamic identity-based authentication protocol for multi-server environment using elliptic curve cryptographyabstractABSTRACT With the popularity of Internet and wireless networks, more and more network architectures are used in multi‐server environment, in which users remotely access servers through open networks. For the reliability of accessing these remote services, user must pass a verification procedure to obtain the authorization for legal resource acquisition and data exchange. Recently, several dynamic identity‐based authentication protocols for multi‐server environment have been proposed, but all of these protocols have been cryptanalyzed by other scholars. In this paper, we propose a new dynamic identity‐based authentication protocol for multi‐server environment using elliptic curve cryptography. The analysis shows that our protocol could overcome security weaknesses in the previously published protocols. Hence, our protocol is more suitable for practical applications. Copyright © 2012 John Wiley & Sons, Ltd. Muhammad Khurram Khan, Debiao He |
Secur. Commun. Networks | 1 |
| 2011 | Biometric driven initiative system for passive continuous authenticationabstractIn this paper, a passive continuous authentication system based on both the hard and the soft biometrics is implemented. The passive continuous authentication system keeps verifying the user without interrupting the user concentrating on his work. It also provides the capacity for the machine to recognize who is in front of the terminal, reduces the potential security leak of the user is temporarily absent front the terminal, and denies the invader to login the system with the stolen account and password. Our system forces to logoff the user when the authentication result identifies the user leaves his seat, but the system won't logoff the user if the user only turns his face to some other directions. The reliability of the system is verified by 7 registered users. According to the experimental results, combining the soft and the hard biometrics in our theoretical framework achieves the goal of continuous authentication efficiently and correctly. Muhammad Khurram Khan, Pei-Wei Tsai, Jeng-Shyang Pan 0001, Bin-Yih Liao |
IAS | 1 |
| 2011 | Polymorphic Malware Detection Using Hierarchical Hidden Markov ModelabstractBinary signatures have been widely used to detect malicious software on the current Internet. However, this approach is unable to achieve the accurate identification of polymorphic malware variants, which can be easily generated by the malware authors using code generation engines. Code generation engines randomly produce varying code sequences but perform the same desired malicious functions. Previous research used flow graph and signature tree to identify polymorphic malware families. The key difficulty of previous research is the generation of precisely defined state machine models from polymorphic variants. This paper proposes a novel approach, using Hierarchical Hidden Markov Model (HHMM), to provide accurate inductive inference of the malware family. This model can capture the features of self-similar and hierarchical structure of polymorphic malware family signature sequences. To demonstrate the effectiveness and efficiency of this approach, we evaluate it with real malware samples. Using more than 15,000 real malware, we find our approach can achieve high true positives, low false positives, and low computational cost. Fahad Bin Muhaya, Muhammad Khurram Khan, Yang Xiang 0001 |
DASC | 2 |
| 2011 | Application of evolutionary algorithms in detecting SMS spam at access layerabstractIn recent years, Short Message Service (SMS) has been widely exploited in arbitrary advertising campaigns and the propagation of scam. In this paper, we first analyze the role of SMS spam as an increasing threat to mobile and smart phone users. Afterward, we present a filtering method for controlling SMS spam on the access layer of mobile devices. We analyze the role of different evolutionary and non evolutionary classifiers for our spam filter by assimilating the byte-level features of SMS. We evaluated our framework on real-world benign and spam datasets collected from Grumbletext and the users in our social networking community. The results of carefully designed experiments demonstrated that the evolutionary classifiers, like the Structural Learning Algorithm in Vague Environment (SLAVE), could efficiently detect spam messages at the access layer of a mobile device. To the best of our knowledge, the current work is the first SMS spam filter based on evolutionary classifier that works on the access layer of a mobile device. The results of our experiments show that our framework, using evolutionary algorithms, achieves a detection accuracy of more than 93%, with false alarm rate of 0.13$% in classifying spam SMS. Moreover, the memory requirement for incorporating SMS features is relatively small, and it takes less than one second to classify a message as spam or benign. M. Zubair Rafique, Nasser Alrayes, Muhammad Khurram Khan |
GECCO | 3 |
| 2011 | Two-Directional Two-Dimensional Random Projection and Its Variations for Face and Palmprint Recognition
Lu Leng, Jiashu Zhang, Muhammad Khurram Khan, Khaled Alghathbar |
ICCSA (5) | 4 |
| 2011 | Cryptanalysis and security enhancement of a 'more efficient & secure dynamic ID-based remote user authentication scheme'
Muhammad Khurram Khan, Sookyun Kim, Khaled Alghathbar |
Comput. Commun. | 1 |
| 2011 | A fast RFID tag identification algorithm based on counter and stack
Mingxing He, Shi-Jinn Horng, Pingzhi Fan, Muhammad Khurram Khan, Ray-Shine Run, Jui-Lin Lai, Rong-Jian Chen |
Expert Syst. Appl. | 4 |
| 2011 | An efficient phishing webpage detector
Mingxing He, Shi-Jinn Horng, Pingzhi Fan, Muhammad Khurram Khan, Ray-Shine Run, Jui-Lin Lai, Rong-Jian Chen, Adi Sutanto |
Expert Syst. Appl. | 4 |
| 2011 | MTPSO algorithm for solving planar graph coloring problem
Ling-Yuan Hsu, Shi-Jinn Horng, Pingzhi Fan, Muhammad Khurram Khan, Yuh-Rau Wang, Ray-Shine Run, Jui-Lin Lai, Rong-Jian Chen |
Expert Syst. Appl. | 4 |
| 2011 | Mutual funds trading strategy based on particle swarm optimization
Ling-Yuan Hsu, Shi-Jinn Horng, Mingxing He, Pingzhi Fan, Tzong-Wann Kao, Muhammad Khurram Khan, Ray-Shine Run, Jui-Lin Lai, Rong-Jian Chen |
Expert Syst. Appl. | 6 |
| 2011 | A hybrid forecasting model for enrollments based on aggregated fuzzy time series and particle swarm optimization
Yao-Lin Huang, Shi-Jinn Horng, Mingxing He, Pingzhi Fan, Tzong-Wann Kao, Muhammad Khurram Khan, Jui-Lin Lai, I-Hong Kuo |
Expert Syst. Appl. | 6 |
| 2011 | An efficient wavelet-tree-based watermarking method
Ray-Shine Run, Shi-Jinn Horng, Wei-Hung Lin, Tzong-Wann Kao, Pingzhi Fan, Muhammad Khurram Khan |
Expert Syst. Appl. | 6 |
| 2011 | Challenge-response-based biometric image scrambling for secure personal identification
Muhammad Khurram Khan, Jiashu Zhang, Khaled Alghathbar |
Future Gener. Comput. Syst. | 1 |
| 2011 | An effective memetic differential evolution algorithm based on chaotic local search
Dongli Jia, Guoxin Zheng, Muhammad Khurram Khan |
Inf. Sci. | 3 |
| 2011 | 3D block-based medial axis transform and chessboard distance transform based on dominance
Shih-Ying Lin, Shi-Jinn Horng, Tzong-Wann Kao, Chin-Shyurng Fahn, Pingzhi Fan, Yuan-Hsin Chen, Muhammad Khurram Khan, Anu G. Bourgeois, Takao Terano |
Image Vis. Comput. | 7 |
| 2011 | Research advances in data hiding for multimedia security
Muhammad Khurram Khan |
Multim. Tools Appl. | 1 |
| 2011 | Statistical analysis of several reversible data hiding algorithms
Hongxia Wang 0001, Muhammad Khurram Khan |
Multim. Tools Appl. | 3 |
| 2011 | Steganalysis for palette-based images using generalized difference image and color correlogram
Hongxia Wang 0001, Muhammad Khurram Khan |
Signal Process. | 3 |
| 2010 | Special issue on: Recent advances and future directions in biometrics personal identification
Muhammad Khurram Khan, Mohamed S. Kamel, Xudong Jiang 0001 |
J. Netw. Comput. Appl. | 1 |
| 2010 | Performance evaluation of score level fusion in multimodal biometric systems
Mingxing He, Shi-Jinn Horng, Pingzhi Fan, Ray-Shine Run, Rong-Jian Chen, Jui-Lin Lai, Muhammad Khurram Khan, Kevin Octavius Sentosa |
Pattern Recognit. | 7 |
| 2009 | Modified AES Using Chaotic Key Generator for Satellite Imagery Encryption
Fahad Bin Muhaya, Muhammad Khurram Khan |
ICIC (1) | 3 |
| 2009 | Enhancing the Security of a 'More Efficient & Secure Dynamic ID-Based Remote User Authentication Scheme'abstractRecently, Wang et al. proposed a dynamic ID-based remote user authentication scheme using smart cards. They claimed that their scheme preserves anonymity of a user, has the features of strong password chosen by the server, and protected from several attacks. However, in this paper, we point out that Wang et al.'s scheme has practical pitfalls and is not feasible for real-life implementation. We identify that their scheme: does not provide anonymity of a user during authentication, user has no choice in choosing his password, vulnerable to insider attack, no provision for revocation of lost or stolen smart card, and does provide session key agreement. To remedy these security flaws, we propose an enhanced authentication scheme, which covers all the identified weaknesses of Wang et al.'s scheme and is more secure and efficient for practical application environment. Muhammad Khurram Khan |
NSS | 1 |
| 2008 | Multimodal face and fingerprint biometrics authentication on space-limited tokens
Muhammad Khurram Khan, Jiashu Zhang |
Neurocomputing | 1 |
| 2007 | An Intelligent Fingerprint-Biometric Image Scrambling Scheme
Muhammad Khurram Khan, Jiashu Zhang |
ICIC (2) | 1 |
| 2006 | Enhancing the Transmission Security of Content-Based Hidden Biometric Data
Muhammad Khurram Khan, Jiashu Zhang |
ISNN (2) | 1 |
| 2006 | An Efficient and Practical Fingerprint-Based Remote User Authentication Scheme with Smart Cards
Muhammad Khurram Khan, Jiashu Zhang |
ISPEC | 1 |
| 2005 | Securing Biometric Templates for Reliable Identity Authentication
Muhammad Khurram Khan, Jiashu Zhang |
ICIC (2) | 1 |