Muhammad Naveed Aman

dblp:71/7910 · DBLP profile ↗
← Back
39ranked-venue papers
15as first author
23since 2021 · last 2026
0000-0002-4629-7589ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 31 · 14 first-author · 17 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Intelligent Reflecting Surfaces-Aided Authentication Mechanism for IoT Devices
abstract
The proliferation of Internet of Things (IoT) devices necessitates robust authentication mechanisms to ensure security and privacy in resource-constrained environments. Existing authentication protocols face limitations, including vulnerability to physical attacks, high computational overhead, and scalability challenges. This paper presents a novel IRS-aided authentication mechanism for IoT devices that leverages Intelligent Reflecting Surfaces (IRS) to enhance location-based authentication through controllable signal enhancement. Our approach employs IRS to amplify Received Signal Strength (RSS) variations in response to device mobility, enabling precise location change detection while integrating pseudo-identity verification and RSS filtering to mitigate Denial of Service (DoS) attacks. Comprehensive robustness analysis demonstrates exceptional performance under realistic deployment constraints: simulations with Rician channel models show 99.82%−99.99% authentication performance across commercial IRS implementations (1-bit to 3-bit phase shifters), with 4.6 dB signal enhancement over direct paths and minimal system overhead (< 0.03%). The mechanism achieves high suitability for infrastructure-dense deployments, including smart buildings and industrial IoT, while providing comprehensive protection against major attack vectors with lower computational complexity compared to existing protocols.
Muhammad Naveed Aman, Biplab Sikdar 0001
IEEE Internet Things J.2
2026 Quantum-Inspired Meta-PPO for Trust-Aware Semantic Offloading in Digital Twin-Enabled IoV Networks With Energy Harvesting
abstract
The convergence of intelligent transportation, digital twin (DT) ecosystems, and vehicular edge intelligence is reshaping smart cities. With the rise of autonomous and context-aware vehicles, ultra-reliable, low-latency, and energy-efficient task orchestration frameworks are crucial in Internet of Vehicles (IoV) networks. In mission-critical situations, such as emergency response routing, disaster relief, and high-priority health transport, semantic task offloading must account for trust, adapt to high vehicle mobility, edge node reliability, and energy limitations. This paper proposes a quantum-inspired meta Proximal Policy Optimization (Qi-mPPO) algorithm for trust-aware semantic offloading in DT-enabled IoV systems with wireless energy harvesting. The approach leverages variational quantum circuits integrated with meta-learning to address non-stationary environments. A multi-objective reward function is formulated to jointly optimize latency, energy efficiency, semantic accuracy, and trust preservation. To ensure semantic relevance under vehicular mobility and energy constraints, quantum-informed policy regularization is applied. Simulation results demonstrate that Qi-mPPO outperforms classical and meta-reinforcement learning baselines in convergence rate, task latency, trust robustness, and energy consumption under realistic vehicular conditions.
James Adu Ansere, Eric Gyamfi, Sylvester B. Aboagye, Kusi Ankrah Bonsu, Mohsin Kamal, Muhammad Naveed Aman
IEEE Trans. Mob. Comput.6
2025 A Time-Series Based Convolutional VAE for Spoof Detection in Commercial GPS Receivers
abstract
Global Positioning System (GPS) technology is widely used in personal and industrial applications to acquire precise timing and positional information. However, its open-standard signals are vulnerable to spoofing attacks, which can cause serious damage if undetected. Employing detection methods is crucial in critical applications. Machine Learning (ML) methods have been successfully applied for spoofing detection, typically performing detection on individual samples. This work proposes a framework that takes a multivariate time-series window as input, enabling the neural network model to extract meaningful temporal information from the sample window for improved detection performance. We train a Convolutional Variational Autoencoder model using spoof-free samples under a representation learning framework. The detector's performance is evaluated using the publicly available TEXBAT dataset and simulated datasets. Our results show that the proposed detector achieves a True Positive Rate (TPR) above 99% for a low False Positive Rate (FPR) of 2% in both static and dynamic attack scenarios. Additionally, for the sophisticated attack scenario (DS-7) in the TEXBAT dataset, our detector achieved a TPR of 89% for an FPR of 3%, highlighting its robustness against different types of spoofing attacks.
Asif Iqbal 0007, Muhammad Naveed Aman, Biplab Sikdar 0001
CCNC2
2025 Enhancing 5G and 6G Communication with Tripartite Perfect W-States and LOCC Approach
abstract
The rapid evolution of communication networks to 5G/6G has introduced significant challenges, particularly in ensuring data security, low latency, high throughput, efficient energy consumption, dynamic access to multiple connection types, and managing the influx of connected devices. Quantum communication, leveraging entangled states like the perfect W-state, offers a promising solution with its high degree of entanglement, secure information transmission, and resilience against decoherence. However, practical applications and experimental validations remain limited, especially regarding the integration with Local Operations and Classical Communication (LOCC) protocols. Additionally, optimizing perfect W-state-based communication protocols for the splitting and sharing of quantum information has been scarcely explored. This article presents a Quantum Information Sharing and Splitting (QISS) protocol that integrates perfect W-states with LOCC to enhance 5G and 6G communication. Using the Eagle r3 processor based on superconducting qubits, our experiments demonstrated a fidelity of 0.82 ± 0.02 for the perfect W-state circuit and 0.55 ± 0.03 for the integrated W-state + LOCC in the QISS communication prototype. These findings, quantified through Quantum State Tomography, significantly improve communication security, network densification, and effectiveness. Furthermore, our research addresses existing gaps in quantum communication implementation, paving the way for scalable quantum networks and advanced encryption methods. This work marks a substantial step towards secure and efficient data transmission in next-generation communication systems.
Mansoor Ali Khan, Muhammad Naveed Aman, Biplab Sikdar 0001
CCNC2
2025 Securing Consumer IoT Swarms Using Graph Transformers and SRAM for Firmware Attestation
abstract
Consumer Internet of Things (IoT) networks have gained widespread popularity due to their convenience, automation, and security provisions in personal and home environments. Ubiquitous resource-constrained devices, however, are plagued with security issues that often arise from firmware-related issues and their propagated effects. While various studies on firmware attestation are available, they require firmware copies, specific hardware, and complex computation on the IoT device. This paper presents a study on the application of Graph Transformer Networks (GTN) in verifying the firmware integrity of consumer IoT swarms using SRAM as an attestation feature. The proposed method achieves an overall 0.99 accuracy on authentic samples from development and physical twin networks, 0.99 on malware, and 0.97 on propagated misbehavior at a$\sim 10^{-4}$second inference latency on a laptop CPU.
Varun Kohli, Bhavya Kohli, Muhammad Naveed Aman, Biplab Sikdar 0001
CCNC3
2025 RapidAtt: A Fast Attestation Technique for Industrial Internet of Things
abstract
The industrial Internet of things (IIoT) relies on programmable logic controllers (PLCs) for critical operations, therefore making them prime targets for cyber-attacks especially when the program is manipulated with malevolent intent. Current attestation methods either need ongoing monitoring of the PLC program during runtime which results in substantial computational burden, or rely on physical models that are challenging to accurately develop and maintain with precision. This paper introduces a novel and efficient attestation method exclusively developed for IIoT settings, which effectively combines efficiency and security, particularly in legacy PLCs that may not have sufficient computing capabilities. Contrary to continuous attestation, this approach conducts periodic attestation at intervals and selectively validates different parts of the PLC program randomly against the legitimate PLC program. Implementing this focused strategy decreases the computational load while ensuring a strong probability of detecting unauthorized modifications. Experimental verification demonstrates that our approach achieves a total verification time of 11.93 ms (i.e. improving execution time by up to 17.67% over existing techniques), and maintains detection accuracy above 90%, thereby offering superior efficiency and security for both contemporary and older Programmable Logic Controllers in industrial environments.
Syed Owais Athar, Muhammad Naveed Aman, Biplab Sikdar 0001
GLOBECOM2
2025 DuAtt: A Dual-Layer Attestation Scheme for PLC-Based Industrial Internet of Things
Syed Owais Athar, Muhammad Naveed Aman, Biplab Sikdar 0001
IEEE Internet Things J.2
2025 QuSIM-Enhanced GSM Security: A Quantum Prover Authentication Protocol (QuPAP) for Mobile Communication
abstract
As the world rapidly embraces quantum technologies, the need for robust quantum security protocols becomes increasingly paramount. Quantum key distribution (QKD) has been at the forefront of secure key exchange, but establishing a root of trust remains unaddressed. This research article presents a pioneering approach for global system for mobile communications (GSM) that bridges the gap between QKD and device identity verification. Our approach utilizes single-qubit states and amplitude encoding, integrating the BB84 protocol to securely share secret keys between entities. We implement two-factor authentication (2FA) to further protect against attacks and unauthorized access. Unlike entangled state-based schemes that require quantum memory and face practical implementation challenges, our single-qubit approach avoids these issues, making it feasible with current technology. Central to our approach is the verification of the subscriber identity module (SIM) card holder’s authenticity using the quantum prover authentication protocol (QuPAP) at the mobile authentication Center. This quantum cryptography-based process enhances GSM communication security and can be integrated into existing networks with minimal modifications. Our proposed smartphone, equipped with dual SIM capabilities—one conventional (cSIM) and one quantum (QuSIM)—ensures compatibility with both current and future networks, allowing the benefits of quantum security without requiring a complete system overhaul. By integrating quantum security into classical GSM protocols, our scheme not only enhances security but also addresses crucial aspects of device identity authentication, attestation, and trust establishment. The security and performance analysis of the QuPAP prototype demonstrates a quantum leap in mobile security, fostering a future of trust, privacy, and resilience in the ever-evolving landscape of communication technologies.
Mansoor Ali Khan, Muhammad Naveed Aman, Biplab Sikdar 0001
IEEE Internet Things J.2
2025 Swarm-Net: Firmware Attestation in IoT Swarms Using Graph Neural Networks and Volatile Memory
abstract
Amidst the large-scale deployment of Internet of Things (IoT) networks worldwide, studies have highlighted critical security concerns many of which stem from firmware-related issues. IoT swarms have become more prevalent in industries, smart homes, and agricultural applications and malicious activity on one node can propagate to other network sections. While several remote attestation (RA) techniques have been proposed in the literature, they are limited by their latency, availability, complexity, hardware assumptions, and uncertain access to firmware copies under intellectual property (IP) rights. To address these problems, we present Swarm-Net, a novel swarm attestation technique that uses graph neural networks (GNNs) to exploit the inherent, interconnected, graph-like structure of IoT networks and the runtime information stored in the static random access memory (SRAM). We also present the first datasets on SRAM-based swarm attestation encompassing different types of firmware and edge relationships. In addition, a secure swarm attestation protocol is proposed to ensure authentication, availability, and attestation. Swarm-Net is computationally lightweight and does not require a copy of the firmware. It achieves a 99.96% attestation rate on authentic firmware, 100% detection rate (DR) on anomalous firmware, and 99% DR on propagated anomalies, at a communication overhead and inference latency of ~1 s and$\sim 10^{-5}$s (on a laptop CPU), respectively. In addition to the collected datasets, Swarm-Net’s effectiveness is evaluated on simulated trace replay, random trace perturbation, and dropped attestation responses, showing robustness against such threats. Lastly, we compare Swarm-Net with past works and present a security analysis.
Varun Kohli, Bhavya Kohli, Muhammad Naveed Aman, Biplab Sikdar 0001
IEEE Internet Things J.3
2025 Guest Editorial: On Advancing Healthcare Informatics With Large Language Models
Saru Kumari, Chien-Ming Chen 0001, Mohammad Shojafar, Muhammad Naveed Aman
IEEE J. Biomed. Health Informatics4
2024 IoT Device Authentication via RAM Trace Analysis: A Representation Learning Framework
abstract
Recent advances in IoT, machine learning, and edge computing have driven transformative paradigms like smart cities, grids, healthcare, and transportation systems, providing efficient solutions. This has led to a pervasive proliferation of connected devices, ranging from high-power computers to low-power sensors. Yet, the complex IoT architecture poses numerous vulnerabilities, demanding robust security measures. Existing firmware attestation techniques often encounter obstacles due to proprietary constraints, necessitating access to the device’s authentic firmware. To address this challenge, this paper proposes a novel software-based attestation framework that utilizes RAM traces from IoT devices for remote verification. By employing deep learning models trained in a representation learning paradigm, our framework empowers the remote verifier to authenticate the internal state of IoT devices. Leveraging data collected from real-world prototype devices, our approach achieves an impressive 100% detection rate for critical attacks on IoT devices with a false positive rate of 10−3. Remarkably, our framework preserves device availability and maintains low authentication latency, highlighting its efficacy and practicality for securing IoT ecosystems.
Asif Iqbal 0007, Muhammad Naveed Aman, Biplab Sikdar 0001
GLOBECOM2
2024 A Representation Learning Induced Property Inference Attack on Machine Learning Models for E-Health
abstract
Privacy concerns have become increasingly prominent as machine learning (ML) models are adopted in an increasing number of sectors. The potential of unintended or malicious exposure of sensitive data, especially in E-Health solutions, has increased as these models are shared and deployed more broadly. In order to highlight the important problem of property inference attacks, which can result in privacy and data confidentiality breaches, this study focuses on inferring global characteristics of the underlying datasets used to train the ML models. Building upon the intriguing work by Ateniese et al. on property inference attacks on ML models, we present a novel property inference attack using Variational Auto-Encoders (VAEs). VAEs offer a strong answer to the difficult problem of inferring dataset attributes because of their reputation for being successful in modeling complex data distributions and producing synthetic data samples. Experiments on three healthcare and the US census datasets show that the proposed attack can effectively reveal underlying patterns in the training dataset with up to 94.29% accuracy. A comparison with the popular meta-classifier based property inference attacks shows that the proposed attack not only has better success rate, but can do so with half training data and a smaller number of shadow models.
Moomal Bukhari, Asif Iqbal 0007, Muhammad Naveed Aman, Biplab Sikdar 0001
GLOBECOM3
2024 A Fuzzy-Logic-Based Smart Irrigation Controller for Precision Agriculture
abstract
Precision irrigation utilizing sensors and IoT devices was introduced for efficient utilization of natural water resources in the agriculture sector. Most existing precision irrigation techniques are computationally complex. To solve this issue, a precision irrigation controller using a fuzzy inference system (FIS) is proposed. The proposed FIS uses the deviation from the reference soil moisture and the crop coefficient as inputs. Then, the optimal incremental control of irrigation volume is computed using a 28-rules rule base. While discrete linear quadratic regulator (DLQR) is considered one of the most accurate techniques in the control of closed-loop systems, it is computationally expensive and not feasible for real-time control using the IoT. On the other hand, proportional-integral (PI) controllers are computationally lightweight but struggle to achieve higher accuracy. Simulations using actual data in MATLAB show that the proposed fuzzy-based model predictive control (MPC) controller not only closely follows the behavior of DLQR but it does so with significantly lower computational complexity of$(O(r^{k}))$, approximately the same as a PI-based controller. The proposed fuzzy-based MPC controller is implemented on real hardware for validation and testing using an IoT device. The IoT device not only exhibits similar behavior as the simulations, an improvement of up to 37% in execution time as compared to the state-of-the-art existing techniques is observed. The proposed technique is a step forward to the development of a simple and fast irrigation controller that will enable better scalability and application to a wide range of agricultural environments.
Moomal Bukhari, Syed Owais Athar, Mukhtar Ullah, Muhammad Naveed Aman
IEEE Internet Things J.4
2024 RAM-Based Firmware Attestation for IoT Security: A Representation Learning Framework
abstract
With the proliferation of 4G and 5G mobile networks in smart cities, the adoption of Internet of Things (IoT) devices has surged, emphasizing the critical need for robust security measures. Existing firmware attestation techniques often require high computational budget or access to the device’s authentic firmware, posing challenges due to resource and proprietary constraints. To counter these two fundamental challenges, this article introduces a novel software-based attestation framework utilizing RAM traces from IoT devices for remote verification. In the proposed framework, the need for an authentic firmware copy is eliminated, and the most computationally intensive task is assigned to the gateway node of the IoT ecosystem. This approach yields a robust and highly accurate device attestation strategy, while imposing minimal computational demands on the verification device itself. Employing deep learning models trained in a representation learning paradigm, our framework enables the remote verifier to authenticate the internal state of IoT devices. Leveraging data collected from real-world prototype devices, under eight different applications, our approach achieves a remarkable 100% accuracy in detecting critical attacks on IoT devices with a false positive rate of$10^{-3}$. Notably, our framework preserves device availability and maintains low authentication latency, underscoring its efficacy and practicality for securing IoT ecosystems.
Asif Iqbal 0007, Usman Zia, Muhammad Naveed Aman, Biplab Sikdar 0001
IEEE Internet Things J.3
2024 Soteria: A Quantum-Based Device Attestation Technique for Internet of Things
abstract
The number of the Internet of Things (IoT) devices is growing at a rapid pace. Although the IoT has and continues to enable many new and exciting applications, recent studies show that cyberattacks on these Internet-connected low-powered devices are constantly increasing. One crucial security aspect for the IoT is device attestation, i.e., verifying the integrity of an IoT device’s firmware/software. Existing techniques for IoT device attestation are either vulnerable to physical attacks or rely on unrealistic assumptions in terms of hardware requirements. To solve these issues, this article presents Soteria, a novel quantum-powered remote attestation technique using quantum physical unclonable functions (QPUFs) which offer enhanced security by leveraging the unique properties of quantum mechanics. Soteria also exploits quantum superposition to attest multiple memory locations in parallel, and thus, protecting it from roving malware. A security analysis of Soteria shows that it is secure against various types of attacks, while a performance analysis shows that it achieves its desired security properties while maintaining low-computational complexity.
Mansoor Ali Khan, Muhammad Naveed Aman, Biplab Sikdar 0001
IEEE Internet Things J.2
2024 Runtime Self-Attestation of FPGA-Based IoT Devices
abstract
Flexibility and reconfigurability make field-programmable gate arrays (FPGAs) ideal for IoT applications because they enable efficient customization and optimization of hardware acceleration tasks in diverse IoT applications. Malicious hardware trojans pose a significant security threat, capable of compromising the integrity of reconfigurable devices such as FPGAs. The majority of current attestation schemes either demonstrate complexity and demand significant resources or lack versatility. To solve this issue, this article proposes a novel lightweight runtime attestation approach to detect hardware trojans or malicious modifications in a hardware design. The proposed technique can verify the integrity of both the hardware design’s finite state machine (FSM) and its datapath. Attesting the FSM ensures the accuracy of state transitions and control behavior while verifying the datapath validates the data processing operations. When combined, these provide a comprehensive validation of the overall hardware functionality. A trusted verifier initiates challenges by stipulating a starting state and an input sequence to the prover. The prover then executes these challenges and reports the observed responses, i.e., state transitions, control outputs, status outputs, and timing metrics. Anomalies between the expected and observed behaviors serve as indicators of potential trojan interventions. The proposed method’s efficacy is substantiated through simulation and implementation on a Zynq-7000 SoC, showcasing its efficiency in terms of resource utilization overhead. Collectively, this study advances the capabilities of remote attestation while bolstering the security of reconfigurable platforms.
Muhammad Naveed Aman, Biplab Sikdar 0001
IEEE Internet Things J.2
2023 Machine Learning based Time Synchronization Attack Detection for Synchrophasors
abstract
The reliable operation of phasor measurement units (PMU) in modern power grid monitoring system like wide-area measurement systems (WAMS) relies on accurate time synchronization, which is provided by the Global Positioning System (GPS). However, the open nature of civilian GPS signals makes PMUs vulnerable to time synchronization attacks (TSA), where attackers manipulate PMU time stamps by transmitting deceptive GPS signals near the PMUs. In this paper, we propose a framework for detecting TSA on PMUs using machine learning (ML) methods. We evaluate five ML algorithms, including Support Vector Machines, Random Forest, K-Nearest Neighbors, Gradient Boost, and Artificial Neural Network, and select seven complementary features that can be computed at the radio frequency (RF) and tracking stages of any commercial GPS receiver. Our detection protocol stands out from other similar ML-based methods in terms of speed, as it does not rely on waiting for the PVT solution. The Texas Spoofing Test Battery (TEXBAT) dataset is used to evaluate the proposed framework. We demonstrate that the ML models can effectively detect GPS spoofing with up to 99.9 % probability while maintaining less than 0.5 % false alarm and mis-detection probabilities. By providing early detection of GPS spoofing attacks on PMUs, the proposed framework has the potential to enhance the cybersecurity of WAMS.
Asif Iqbal 0007, Muhammad Naveed Aman, Biplab Sikdar 0001
GLOBECOM2
2022 Blockchain based Secure Group Data Collaboration in Cloud with Differentially Private Synthetic Data and Trusted Execution Environment
abstract
Data collaboration with cloud technologies is becoming more popular for personal use as well as business applications. Due to the increasing data protection regulations worldwide, different cryptographic techniques have been designed to enable secure data sharing for a user or a group of users. Although, these techniques have seen enterprise adoption, they fail to offer data visibility as data remains encrypted throughout the data sharing routine. This is why these techniques fail to offer a key features to data users, e.g., joining different datasets together and sharing it with all the users involved. This paper presents a blockchain based architecture for secure data collaboration in cloud using differentially private synthetic data and trusted execution environment (TEE). The proposed solution protects data confidentiality and integrity with TEEs, supports public-key infrastructure (PKI) with blockchain, and prevents privacy leakages with synthetic data. The results show that our synthetic data performs as good as real data and demonstrates how different users can securely aggregate their datasets and openly share among themselves.
Uzair Javaid, Muhammad Naveed Aman, Dongxu Shao, Kevin Yee, Biplab Sikdar 0001
IEEE Big Data3
2022 MaDe: Malicious Aerial Vehicle Detection using Generalized Likelihood Ratio Test
abstract
The use of unmanned aerial vehicles (UAVs) for diverse activities has increased rapidly in recent years. Nonetheless, if operational cyber security is not handled effectively, these technologies offer a significant hazard which can cause catastrophic harm. Therefore, it is important to identify the potential attacks that can be implemented by an adversary. Traditional methods for data integrity designed for the Internet are not suitable for UAV assisted vehicular or wireless sensor networks due to the high communication overhead and latency required. This paper proposes a lightweight data integrity technique called MaDe to address this problem. Every device, at regular intervals, generates an authentication parameter that depends on the packets transmitted. The authentication parameters are only delivered to a central server or the device where the integrity of the packets is verified. At the server, MaDe takes the final decision about an UAV using a generalized likelihood ratio test. MaDe can identify malicious UAVs effectively as demonstrated through our performance analysis. The results show that MaDe detects malicious UAVs with minimum communication overhead and latency.
Nalam Venkata Abhishek, Muhammad Naveed Aman, Teng Joon Lim, Biplab Sikdar 0001
ICC2
2022 DRiVe: Detecting Malicious Roadside Units in the Internet of Vehicles With Low Latency Data Integrity
abstract
The Internet of Vehicles (IoV) may enhance road safety, improve traffic flow, etc. However, Internet-connected intelligent vehicles (IVs) are vulnerable to cyber-attacks. One of the important challenges in IoV is thus, verifying data integrity with strict latency requirements. The conventional way of providing data integrity in the Internet cannot be applied to IoV due to excessive overhead and latency. Therefore, most commercially available IVs do not use any security mechanisms for delay-sensitive traffic. However, if a road side unit (RSU) has been compromised, it can tamper with the data sent or received by IVs. To solve this issue, this article presents a light-weight mechanism called DRiVe to establish data integrity for the IVs and detect malicious RSUs. The DRiVe is based on a probabilistic model to identify malicious RSUs using specially constructed authentication techniques. The authentication parameters are only sent when a vehicle leaves the coverage area of one RSU and enters that of another. DRiVe does not employ any computationally intensive cryptographic primitives. This significantly reduces the security overhead introduced by sending message authentication codes (MACs) with each packet. A security and performance analysis shows that DRiVe can not only identify malicious RSUs effectively but can do so without introducing any significant communication overhead or latency. The proposed scheme reduces the number of bits transmitted by approximately 7% and decreases the latency incurred by 7.5%. For the scenario where malicious vehicles are present, the proposed scheme achieves a probability of detection close to 99%.
Nalam Venkata Abhishek, Muhammad Naveed Aman, Teng Joon Lim, Biplab Sikdar 0001
IEEE Internet Things J.2
2022 Machine-Learning-Based Attestation for the Internet of Things Using Memory Traces
abstract
The advent of 4G and 5G mobile networks has made the Internet of Things (IoT) devices an essential part of smart nation drives. Firmware integrity is crucial to the security of IoT systems. Most of the existing techniques for firmware attestation require a legitimate copy of an IoT device’s firmware. However, firmware is considered an intellectual property (IP) of the manufacturer and may not be available. To solve this issue, this article proposes a software-based attestation technique where remote verifiers use machine learning (ML) classifiers on an IoT device’s memory dump to verify the integrity of an IoT device’s internal state. The experimental results from an actual prototype show that the proposed technique not only successfully detects attacks with high accuracy but also results in about 96% lower latency as compared to existing techniques. All this is achieved with high availability, low computational complexity, and without requiring a legitimate copy of the device’s original firmware.
Muhammad Naveed Aman, Mohamed Haroon Basheer, Jun Wen Wong, Jia Xu 0006, Hoon Wei Lim, Biplab Sikdar 0001
IEEE Internet Things J.1
2022 Security, Trust and Privacy for Cloud, Fog and Internet of Things
Chien-Ming Chen 0001, Shehzad Ashraf Chaudhry, Kuo-Hui Yeh, Muhammad Naveed Aman
Secur. Commun. Networks4
2021 A Privacy-Preserving and Scalable Authentication Protocol for the Internet of Vehicles
abstract
One of the most important and critical requirements for the Internet of Vehicles (IoV) is security under strict latency. Typically, authentication protocols for vehicular ad hoc networks need to authenticate themselves frequently. This results in reduced application traffic and increased overhead. Moreover, the mobile nature of vehicles makes them a prime target for physical, side channel, and cloning attacks. To address these issues, this article presents an efficient protocol for authentication in the IoV. The proposed protocol uses physical unclonable functions to provide the desired security characteristics. To reduce the overhead of authentication and improve the throughput of application layer packets, the proposed protocol uses a three-layered infrastructure architecture for IoVs, i.e., roadside units (RSUs), RSU gateways, and trusted authority. A vehicle needs to authenticate only once when it enters the area of an RSU gateway which may engulf multiple RSUs. A performance analysis of the protocol shows that the proposed strategy significantly reduces the number of authentication packets and MAC/PHY overhead while the security analysis demonstrates its robustness against various types of attacks.
Muhammad Naveed Aman, Uzair Javaid, Biplab Sikdar 0001
IEEE Internet Things J.1
2020 Defining trust in IoT environments via distributed remote attestation using blockchain
abstract
The constantly growing number of Internet of Things (IoT) devices and their resource-constrained nature makes them particularly vulnerable and increasingly attractive for exploitation by cyber criminals. Current estimates commonly reach the tens of billions for the number of connected 'things'. The heterogeneous capabilities of these devices serve as a motivation for resource sharing among them. However, for effective resource sharing, it is essential that trust be retained in the multitude of pervasive and diverse IoT devices. Remote attestation is a well-known technique used to build such trust. Thus, this paper proposes a blockchain based remote attestation protocol to establish trust between IoT devices. The blockchain offers a secure framework for device registration while the attestation is based on Physical Unclonable Functions (PUF). This combination of technologies results in a tamper resistant scheme with protection against physical and proxy attacks.
Uzair Javaid, Muhammad Naveed Aman, Biplab Sikdar 0001
MobiHoc2
2020 HAtt: Hybrid Remote Attestation for the Internet of Things With High Availability
abstract
The critical and sensitive nature of data that the Internet-of-Things (IoT) devices produce makes them an attractive target for cyber attacks. Among the various types of attacks, malware is becoming a major concern for the IoT device. This article proposes a remote attestation protocol, hybrid remote attestation, which ensures the high availability of IoT devices during the software attestation process. The proposed attestation technique uses a randomized approach to attest different parts of an IoT device's memory. We use physical unclonable functions (PUFs) to protect the secrets of an IoT device from physical attacks. The security analysis shows that the proposed attestation technique can effectively detect roving malware. Implementation of the proposed protocol on Raspberry Pi and AVR/ARM-based ATMEL microcontrollers and comparison with existing techniques shows that the proposed protocol results in significantly higher availability and lower energy consumption.
Muhammad Naveed Aman, Mohamed Haroon Basheer, Siddhant Dash, Jun Wen Wong, Jia Xu 0006, Hoon Wei Lim, Biplab Sikdar 0001
IEEE Internet Things J.1
2020 A Scalable Protocol for Driving Trust Management in Internet of Vehicles With Blockchain
abstract
Recent developments in IoT have facilitated advancements in the Internet of Vehicles (IoV) with autonomous vehicles and roadside infrastructure as its key components. IoV aims to provide new innovative services for different modes of transport with adaptive traffic management and enables vehicles to broadcast messages to improve traffic safety and efficiency. However, due to nontrusted environments, it is difficult for vehicles to evaluate the credibility of the messages that they receive. Therefore, trust establishment in IoV is a key security concern that is constantly limited by scalability challenges. This article proposes a blockchain-based protocol for IoV using smart contracts, physical unclonable functions (PUFs), certificates, and a dynamic Proof-of-Work (dPoW) consensus algorithm. The blockchain, in conjunction with contracts, provides a secure framework for registering trusted vehicles and blocking malicious ones. PUFs are used to assign a unique identity to each vehicle via which trust is established. Certificates are issued by roadside units that preserve the privacy of vehicles, whereas the dPoW consensus allows the protocol to scale according to the incoming traffic generated by the vehicles. To demonstrate the feasibility and scalability of the proposed protocol, security and performance analyses are presented. A case study is also discussed along with a comparative analysis, which confirms that our protocol can provide superior decentralized trust management for IoV.
Uzair Javaid, Muhammad Naveed Aman, Biplab Sikdar 0001
IEEE Internet Things J.2
2019 Data Provenance for IoT using Wireless Channel Characteristics and Physically Unclonable Functions
abstract
IoT can provide many new exciting services in energy management, home and commercial automation, environmental monitoring etc. Data provenance establishes the trust in the origin and location of data. This paper takes an information theoretic approach to solve the problem of data provenance in IoT systems. The proposed protocol uses Physically Unclonable Functions to prove the origin of data and wireless fingerprints derived from the received signal strength indicator (RSSI) measurements to verify the location of the IoT device producing the data. The security analysis of the proposed protocol shows that it is robust against different types of attacks. Experimental results show that the proposed technique can improve the accuracy of detecting attacks by 100% as compared to existing techniques.
Muhammad Naveed Aman, Mohamed Haroon Basheer, Biplab Sikdar 0001
ICC1
2019 DrivMan: Driving Trust Management and Data Sharing in VANETs with Blockchain and Smart Contracts
abstract
The development of Internet of Things (IoT) has paved way for the Internet of Vehicles (IoV) and intelligent transportation systems (ITS). Vehicular ad-hoc networks (VANETs) are indispensable for ITS with intelligent vehicles (IV) as their key players. To ensure proper and reliable VANET operation, IVs need secure inter- and intra-network communication with trust and reliability of data (provenance). This paper aims to provide trust management in VANETs by proposing a trustless system model using blockchain and a certificate authority (CA) for registering IVs as well as revoking their registration if need be. Furthermore, to preserve data reliability, this paper uses physical unclonable functions (PUFs). Implementation of DrivMan shows that it is able to establish distributed trust management and enables secure data sharing while preserving the privacy of IVs.
Uzair Javaid, Muhammad Naveed Aman, Biplab Sikdar 0001
VTC Spring2
2019 Two-Factor Authentication for IoT With Location Information
abstract
The number of Internet of Things (IoT) devices is expected to grow exponentially in the near future and produce large amounts of potentially sensitive data. The simple and low cost nature of IoT devices makes them an attractive target for spoofing or impersonation attacks. To solve this issue, this paper proposes a two-factor authentication protocol using physically unclonable functions and the characteristics of the wireless signal from an IoT device. The security analysis and results on MICAz motes shows that the proposed protocol can be used as an effective tool to secure IoT systems from spoofing as well as various other attacks. A performance analysis of the proposed protocol shows that it has a significantly lower computational overhead and energy consumption compared to existing techniques.
Muhammad Naveed Aman, Mohamed Haroon Basheer, Biplab Sikdar 0001
IEEE Internet Things J.1
2019 Data Provenance for IoT With Light Weight Authentication and Privacy Preservation
abstract
The Internet of Things (IoT) engulfs a large number of interconnected heterogeneous devices from a wide range of pervasive application areas including health-care systems, energy management, environmental monitoring, and home and commercial automation. Although IoT is considered an enabling technology for a variety of services, it also raises many security and privacy concerns. This article focuses on developing secure protocols for data provenance with authentication and privacy preservation in IoT systems. Protocols for two scenarios are presented, one when an IoT device is directly connected to a wireless gateway and the other when an IoT device is indirectly connected to the wireless gateway through multiple hops of other IoT devices. The proposed protocols use physically unclonable functions along with wireless link fingerprints derived from the wireless channel characteristics between two communicating entities. This results in protocols which are not only efficient in terms of computational complexity and energy requirements but are also safe against various types of attacks including physical and cloning attacks. Experimental results show that in comparison to existing protocols, the proposed protocols are up to 100% more accurate in detecting attacks on data provenance and can save up to 83.8% and 73.5% energy consumption for the IoT devices in terms of CPU and radio energy, respectively.
Muhammad Naveed Aman, Mohamed Haroon Basheer, Biplab Sikdar 0001
IEEE Internet Things J.1
2019 Token-Based Security for the Internet of Things With Dynamic Energy-Quality Tradeoff
abstract
In this paper, token-based security protocols with dynamic energy-security level tradeoff for Internet of Things (IoT) devices are explored. To assure scalability in the mechanism to authenticate devices in large-sized networks, the proposed protocol is based on the OAuth 2.0 framework, and on secrets generated by on-chip physically unclonable functions. This eliminates the need to share the credentials of the protected resource (e.g., server) with all connected devices, thus overcoming the weaknesses of conventional client-server authentication. To reduce the energy consumption associated with secure data transfers, dynamic energy-quality tradeoff is introduced to save energy when lower security level (or, equivalently, quality in the security subsystem) is acceptable. Energy-quality scaling is introduced at several levels of abstraction, from the individual components in the security subsystem to the network protocol level. The analysis on an MICA 2 mote platform shows that the proposed scheme is robust against different types of attacks and reduces the energy consumption of IoT devices by up to 69% for authentication and authorization, and up to 45% during data transfer, compared to a conventional IoT device with fixed key size.
Muhammad Naveed Aman, Sachin Taneja, Biplab Sikdar 0001, Kee Chaing Chua, Massimo Alioto
IEEE Internet Things J.1
2018 ATT-Auth: A Hybrid Protocol for Industrial IoT Attestation With Authentication
abstract
This paper addresses the problem of developing attestation techniques for Industrial Internet of Things systems. To ensure hardware security, the proposed attestation protocols are based on physically unclonable functions. Moreover, to achieve scalability, the proposed protocols do not calculate the reference checksum for every prover at the verifier, instead they use timing information. Thus, to attest multiple devices in large-scale networks, such as device swarms, the proposed protocols use timing information to detect any unintentional or malicious modification to a device’s memory contents. The analysis on an Atmel micro controller shows that the proposed protocols have a high probability of detecting malware with significantly lower computation overhead.
Muhammad Naveed Aman, Biplab Sikdar 0001
IEEE Internet Things J.1
2018 Low Power Data Integrity in IoT Systems
abstract
Devices in the Internet of Things (IoT) produce large amounts of sensitive data. However, the use of the public Internet for data transfer by IoT devices makes them susceptible to cyber attacks. Among these attacks, data tampering or modification attacks to disrupt or bias the states of applications using these data may result in widespread damage and outages. To detect such attacks, this paper proposes an efficient and simple technique to detect data tampering in IoT systems. The proposed mechanism uses a random time hopping sequence and random permutations to hide validation information. We also present a formal security analysis of the proposed protocol. Performance analysis of the proposed protocol shows that it has low computational complexity and is suitable for IoT systems.
Muhammad Naveed Aman, Biplab Sikdar 0001, Kee Chaing Chua, Anwar Ali 0001
IEEE Internet Things J.1
2017 A Light-Weight Mutual Authentication Protocol for IoT Systems
abstract
One of the most important and critical requirements for Internet-of-Things (IoT) based systems is security under limited resources. The simple and low-cost nature of many IoT devices makes them a prime target for physical, side-channel, and cloning attacks. To address this issue, this paper presents an efficient protocol for mutual authentication in IoT systems. The proposed protocol uses a Physical Unclonable Function to provide the desired security characteristics. An analysis of the protocol shows that it is not only robust against different kind of attacks, but also very efficient in terms of memory, computations, energy, and communication overhead.
Muhammad Naveed Aman, Kee Chaing Chua, Biplab Sikdar 0001
GLOBECOM1
2017 Mutual Authentication in IoT Systems Using Physical Unclonable Functions
abstract
The Internet of Things (IoT) represents a great opportunity to connect people, information, and things, which will in turn cause a paradigm shift in the way we work, interact, and think. IoT devices are usually small, low cost, and have limited resources, which makes them vulnerable to physical, side-channel, and cloning attacks. Therefore, any protocol designed for IoT systems should not only be secure but also efficient in terms of usage of chip area, energy, storage, and processing. To address this issue, we present light-weight mutual authentication protocols for IoT systems based on physical unclonable functions. Protocols for two scenarios are presented, one when an IoT device and server wish to communicate and the other when two IoT devices want to establish a session. A security and performance analysis of the protocols shows that they are not only robust against different types of attacks, but are also very efficient in terms of computation, memory, energy, and communication overhead. The proposed protocols are suitable for real time applications and are an attractive choice for implementing mutual authentication in IoT systems.
Muhammad Naveed Aman, Kee Chaing Chua, Biplab Sikdar 0001
IEEE Internet Things J.1
2014 A wireless MAC protocol with efficient packet recovery
abstract
Existing wireless medium access control (MAC) protocols provi reliability against corrupted packets by providing mechanisms for packet error detection and retransmission. The efficiency of existing mechanisms for providing reliability is usually low since they require the entire packet to be retransmitted even though only parts of it may have been corrupted. To address this issue, this paper presents a MAC protocol with an efficient packet recovery mechanism for packets corrupted due to both channel errors and collisions. The proposed MAC protocol first determines the cause of the errors in a packet and then uses the acknowledgment (ACK) packets to provide feedback on the sections of the packets that have errors. To minimize the packet recovery time, the proposed MAC protocol allows the sender to retransmit the corrupted sections of the packet immediately, without requiring a new channel access. Using simulations, it is shown that the proposed MAC protocol has higher efficiency and increases the achieved throughput.
Muhammad Naveed Aman, Biplab Sikdar 0001
LANMAN1
2014 Efficient packet recovery in wireless networks
abstract
Wireless medium access control (MAC) protocols usually provide reliability in the presence of packet errors. The efficiency of these reliability mechanisms is generally low since they require the entire packet to be retransmitted even though only parts of it may have been corrupted. To address this issue, this paper presents an efficient mechanism for the recovery of packets corrupted due to both channel errors and collisions. The proposed mechanism first determines the cause of the errors. Next, the symbols with errors are isolated by using the error vector magnitude (EVM) of received symbols as the feature for detection. Using explicit feedback about which blocks of symbols have errors, only the erroneous blocks are then retransmitted. Our results show that the proposed mechanism increases the efficiency of the MAC protocol by providing higher throughput.
Muhammad Naveed Aman, Biplab Sikdar 0001, Wai Kin Chan
WCNC1
2012 Collision detection in IEEE 802.11 networks by error vector magnitude analysis
abstract
There are two causes of packet losses during a wireless transmission: losses caused by collisions and losses caused by poor channel conditions. The throughput and spatial reuse of IEEE 802.11 based wireless networks, as well as the effectiveness of the rate adaptation algorithms they use, is adversely affected by their inability to determine the real cause of a packet loss. To address this issue, this paper proposes a mechanism based on Error Vector Magnitude (EVM) to discern random channel errors from collisions in wireless networks. The proposed mechanism is based on first developing an analytic model to characterize the EVM of a packet in the presence and absence of a collision. A threshold based classifier is then proposed that selects the threshold value such that the crossover error rate is achieved. Simulation results are presented to demonstrate the accuracy of the proposed collision detection mechanism.
Muhammad Naveed Aman, Wai Kin Chan, Biplab Sikdar 0001
GLOBECOM1
2009 Scalable Peer-to-Peer Video Streaming in WiMAX Networks
abstract
The increasing popularity and success of web-based peer-to-peer (P2P) systems for streaming video applications make them likely candidates for injecting large volumes of traffic in the emerging WiMAX networks. This paper develops a lightweight mechanism for P2P streaming in WiMAX networks that significantly reduces the load on the network and improves the scalability of the streaming system. The proposed system uses the broadcast mechanism provided in the IEEE 802.16 mechanism for providing the scalability, without breaking the P2P semantics. The scalability of the proposed system is analytically evaluated and also quantified using simulations. Our results show that the degree of improvement in the performance of the proposed system is lower bounded by the average number of peers served by an Access Service Network Gateway in the WiMAX networks.
Muhammad Naveed Aman, Biplab Sikdar 0001, Shyam Parekh
GLOBECOM1