EDBT 2026 Demo / reviewers in the wild / expert
Maode Ma
dblp:74/1079
· DBLP profile ↗
221ranked-venue papers
13as first author
67since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 139 · 13 first-author · 27 since 2021Security and privacy · 22 · 10 since 2021Applied, interdisciplinary, general and emerging computing · 20 · 14 since 2021Systems, architecture and hardware · 14 · 3 since 2021Artificial intelligence and machine learning · 13 · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 4 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Lightweight Blockchain-Based Cross-Domain Authentication and Key Agreement Protocol for Industrial IoT
Maode Ma, Hui Wang 0156, Yuankun Xia |
ICC | 2 |
| 2026 | An adaptive intrusion detection system for the internet of things using large language models and post-quantum-secure blockchain
Yunfan Huang, Maode Ma, Jee Keen Raymond Wong, Chee Onn Chow |
Comput. Networks | 2 |
| 2026 | An explainable and adaptive Internet of Things intrusion detection system supported by Large Language Models
Yunfan Huang, Maode Ma, Jee Keen Raymond Wong, Chee Onn Chow |
Eng. Appl. Artif. Intell. | 2 |
| 2026 | LBCM: A Scalable and DDoS-Resistant Cross-Domain Authentication Protocol for IIoT Using Chaotic Maps and Merkle TreeabstractTo overcome the challenges of trust isolation and scalability bottlenecks in cross-domain collaboration within the Industrial Internet of Things (IIoT), this paper proposes LBCM, a lightweight authentication protocol based on consortium blockchain and Chebyshev chaotic mapping. The protocol establishes a hybrid on-chain storage and off-chain verification trust architecture, and leverages the semi-group property of Chebyshev polynomials to achieve efficient and secure mutual authentication and key agreement. To address the storage limitations of blockchain, we design a global Merkle Tree commitment mechanism governed by smart contracts. Acting as consortium nodes, Trusted Authorities collaboratively maintain the global Merkle Root through a Propose-Vote-Execute consensus process, thus fixing the on-chain storage overhead at a constant level (O(1)), regardless of network scale. Furthermore, the protocol incorporates a “Filter-First, Access-Later” proactive defense strategy, enabling core nodes to rapidly filter out malicious traffic at the edge and effectively defending against Distributed Denial of Service (DDoS) attacks. Formal verification using ProVerif and comprehensive performance evaluations demonstrate that LBCM significantly outperforms existing mainstream schemes in terms of computational efficiency, communication overhead, and storage cost, while maintaining high security guarantees. Maode Ma, Hui Wang 0156, Yuankun Xia, Yinjuan Shi |
IEEE Internet Things J. | 2 |
| 2026 | AFSF: An Anti-Fallback Security Framework Toward U2U-Assited by Ground StationsabstractAs mission requirements continue to expand, the ability to communicate between unmanned aerial vehicles (UAVs) has become increasingly vital. However, security has also become a critical issue. UAVs typically operate in open wireless communication networks, which are highly susceptible to various attacks and pose significant threats to the overall security of UAV systems. Therefore, it is imperative to develop robust security protocols. Existing authentication schemes, while effective in ensuring security, mainly focus on lightweight design. However, the session keys between UAVs are generated with the assistance of the ground station. Should the communication link between the drone and the ground station come under attack, the session keys between drones cannot be updated. To address this issue, we propose the Anti-Fallback Security Framework (AFSF). This framework, based on a lightweight design philosophy, ensures UAV anonymity and effectively counters threats such as de-synchronization attacks and replay attacks. AFSF is specifically designed to secure communications between UAVs. Through formal proof, verification using the Scyther tool, and cryptographic analysis, we have conducted a comprehensive security evaluation of AFSF. The results demonstrate that AFSF is highly effective in withstanding a variety of security attacks. Moreover, we compared AFSF with two state-of-the-art existing schemes in terms of computational overhead, communication overhead, and energy consumption. The computational overhead of the proposed solution is 11.4 μs, the communication overhead is 18 μs, and the energy consumption is 7.04 μj. The findings indicate that AFSF outperforms the others in both resource consumption and security. Chun-Peng Liu, Maode Ma |
IEEE Internet Things J. | 3 |
| 2026 | Privacy-Preserving Platoon Control - Constrained Cooperative-Tracking Control via Time-Varying Heterogeneous Directed NetworksabstractDistributed cooperative tracking control has emerged as a pivotal research focus in multi-agent systems, particularly for platoon control applications where its decentralized architecture offers significant advantages over centralized approaches. However, the direct exchange of sensitive data between agents raises critical privacy risks, hindering its broader adoption across safety-critical applications. This paper presents a privacy-preserving cooperative tracking framework that rigorously maintains bounded coupling errors, which is a crucial requirement for collision avoidance in vehicular platoons. Departing from conventional methods that compromise privacy through explicit state sharing for error mitigation, our proposed algorithm achieves dual objectives: maintaining prescribed error constraints while preserving agent state confidentiality in directed communication networks with time-varying interaction weights. We establish sufficient conditions for achieving cooperative-tracking consensus with predefined error constraints and characterize the quantitative relationship between the asymptotic convergence rate and control gain parameters. Furthermore, we analyse the privacy-preserving performance against internal and external adversaries, demonstrating that the probability of an adversary inferring states within a finite neighborhood of ground-truth values can be rendered arbitrarily small, even while adversaries retain access to identical communication data streams. This extends classical initial-state privacy to the entire operational timeline under time-varying directed topologies. Numerical examples including an application of cooperative adaptive cruise control demonstrate our proposed algorithm’s efficacy. Lingying Huang, Rong Su 0001, Maode Ma, Yun Lu 0002, Peihu Duan |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2025 | MTC-Kansformer: Malware Traffic Classification by Kansformer with Self-Superivised LearningabstractMalware Traffic Classification (MTC) is a key area of research in cybersecurity. Accurate and efficient classification is vital for defending against malware. Many methods use supervised learning, especially Convolutional Neural Networks (CNNs), to train feature extractors. However, obtaining a large number of labeled samples is costly, and relying solely on CNNs may limit the local receptive fields, compromising the retention of key features. Additionally, existing Transformer backbone networks have quadratic computational complexity. This paper proposes the MTC-Kansformer, a traffic classification model that addresses these issues and improves classification accuracy and efficiency. The model integrates a self-supervised learning framework with a Kansformer. The Kansformer encoder replaces the traditional Multi-Layer Perceptron (MLP) layer with fasterKAN, enhancing the representation and interpretability of nonlinear features. Initially, the raw traffic is converted into gray images. Then, the Kansformer self-supervised model is used to extract key features from randomly masked images, and the prediction module is employed to predict the masked images. Finally, the encoder is finetuned using a downstream malware dataset to perform effective malware traffic classification tasks. Experimental results show that the MTC-Kansformer outperforms existing models, achieving a classification accuracy of$\mathbf{9 8. 7 8 \%}$on the USTC-TFC2016 dataset, surpassing existing models. Maode Ma, Hui Wang 0156, Chenjun He, Yingjuan Shi |
ICC | 2 |
| 2025 | Fully Automated XSS Vulnerability Detection by Reinforcement Learning
Tingting Qiao, Maode Ma |
ICIC (12) | 3 |
| 2025 | Dynamic Trajectory-Based Adaptive Scheduling MAC Protocol for AUV-assisted Data Collection in UASNsabstractIn this paper, we propose a dynamic trajectory-based adaptive scheduling medium access control (DTAS-MAC) protocol, which aims to illustrate where the AUV should hover to receive data and how the AUV should interact with sensor nodes in AUV-assisted underwater data collection. While cruising in the sea, the AUV wakes up sensor nodes with data transmission demands and obtains their real-time status information through message exchanges. Then, the AUV dynamically determines a hovering point to receive data from the sensor nodes with the goal of maximizing data collection efficiency. Movement energy consumption, hovering energy consumption, and the number of error-free packets received by the AUV are considered in the data collection efficiency model. To reduce packet collisions and improve channel utilization, a scheduling-based mechanism is proposed to organize data transmission from sensor nodes. When scheduling sensor nodes to send data to the AUV, the transmission priority is assigned based on their upload urgency. The experimental results verify the effectiveness of the DTAS-MAC protocol in improving data collection efficiency and throughput, while reducing data loss. Weinan Cao, Lvqingyun Xiao, En Cheng, Maode Ma |
IWCMC | 5 |
| 2025 | A Lightweight Authentication Protocol for Wide-Range Drone Communications
Maode Ma |
Networking | 2 |
| 2025 | 5G-GRAKA: An efficient group based authentication and key agreement protocol for machine-type communication in 5G networks
Ronghao Ma, Maode Ma |
Comput. Networks | 3 |
| 2025 | A high-security batch message authentication protocol assisted by edge servers in industrial Internet of Things
Maode Ma |
J. Inf. Secur. Appl. | 3 |
| 2025 | QRMA-IOMT: Quantum-resilient mutual authentication for IoMT using RLWE and Boneh-Boyen signatures
Yakubu Abdulai, Maode Ma, Hui Wang 0156 |
Peer Peer Netw. Appl. | 2 |
| 2025 | AILL-IDS: An Automatic Incremental Lifetime Learning Intrusion Detection System for Vehicular Ad Hoc NetworksabstractVehicular Ad Hoc Networks (VANETs) play a critical role in enabling communication among intelligent vehicles, yet their dynamic and decentralized nature makes them highly vulnerable to cyber-attacks. Traditional Intrusion Detection Systems (IDSs) provide limited defense against these evolving threats, as they rely on static rules or machine learning (ML) models that lack the capacity for real-time updates. The Incremental Lifetime Learning IDS (ILL-IDS) was introduced to address this limitation by enabling adaptive learning of new attack types. However, ILL-IDS depends heavily on large volumes of high-quality labeled data, making the model update process costly and labor-intensive. In response, this study proposes the Automatic Incremental Lifetime Learning IDS (AILL-IDS), a novel IDS framework that significantly reduces the need for labeled data through incremental semi-supervised learning. This approach not only enables AILL-IDS to detect unknown attacks and adapt its model dynamically with minimal labeled data but also ensures continuous detection during the model update process, enhancing both speed and accuracy in threat detection. Experimental results demonstrate that AILL-IDS achieves a high detection rate of 0.97 and an average F1 score of 0.90, using only 5.5% labeled data, thereby offering an efficient and scalable solution for securing VANETs against emerging cyber threats. Yunfan Huang, Maode Ma |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2024 | ESMA-IOMT: Efficient and Secure Mutual Authentication in IoMT With RLWE-Based Encryption and Boneh-Boyen SignaturesabstractThe Internet of Medical Things (IoMT) is a promising new frontier in healthcare, enabling remote patient monitoring and telemedicine services. However, it also raises significant security and privacy concerns. To address these challenges, we propose a mutual authentication schema for IoMT using the Ring Learning with Errors (RLWE) and Boneh-Boyen signatures. Our scheme utilizes RLWE-based encryption and Boneh-Boyen signatures to ensure the confidentiality and integrity of data. We validate the authentication of the proposed scheme using Scyther verification and demonstrate its efficiency by performance evaluation. The results of performance evaluation demonstrate that our proposed scheme takes less computation and communication costs compared with other existing solutions. Therefore, it is a fairly attractive solution for efficient and secure mutual authentication in IoMT. Yakubu Abdulai, Maode Ma, Hui Wang 0156 |
HealthCom | 2 |
| 2024 | An EWMA-Based Mitigation Scheme Against Interest Flooding Attacks in Named Data Networks
Zhihao Shi, Yaozong Xu, Maode Ma |
ICIC (9) | 3 |
| 2024 | Design of a Blockchain-Based Trust Model for Detecting Cache Poisoning Attakcs in NDN
Yuwen Xiong, Cong Wang 0004, Maode Ma |
ICIC (10) | 5 |
| 2024 | DM-CIFA: Detection and Mitigation of Collusion Interesting Flooding Attacks in NDNs
Jingru Xing, Yaozong Xu, Maode Ma, Cong Wang 0004 |
ICIC (9) | 4 |
| 2024 | A Blockchain-assisted Group Handover Authentication Protocol for 5G Wireless NetworksabstractThe fifth-generation (5G) wireless cellular network with its high-density connectivity enables the support of massive Internet of Things (IoT) applications, where massive machine-type communication (MTC) is a core communication scenario in the IoT domain. However, when a group of MTC devices (MTCD) simultaneously access a new target base station, much more frequent mutual authentication processes take place leading to high signaling overheads in both access and core networks, thus reducing overall network efficiency. In this paper, we propose an efficient and secure handover authentication protocol supported by blockchain technology for a group of MTCD. The protocol leverages blockchain to decentralize the authentication function from centralized servers to all base stations. It can prevent single points of failure, increase the difficulty of DDoS attacks, and simultaneously achieve mutual authentication and key negotiation between group MTCD and base stations. The proposed protocol has been formally evaluated by using Scyther tools demonstrating its resilience against major typical malicious attacks. Furthermore, the performance evaluation results show that the proposed protocol is efficient in terms of computation and communication costs. Ronghao Ma, Maode Ma |
IWCMC | 3 |
| 2024 | ECCIA: An Identity Authentication Scheme against IFAs in NDNsabstractRecently, Named Data Networking (NDN) has been attractive as an alternative to the TCP/IP-based Internet. It adopts a content-driven communication approach to provide name-based routing. The new network architecture enhances privacy but cannot escape the threats caused by Interest Flooding Attacks (IFAs). The goal of the IFAs is to inject a Pending Interest Table (PIT) with a large number of invalid Interest packets into the NDNs. In recent years, numerous IFA detection and mitigation schemes have been designed, most of which cannot prevent IFAs even may block legitimate Interest packets. To prevent IFAs, we propose an Elliptic Curve Cryptography-based Identity Authentication scheme (ECCIA) for NDNs. The key of the ECCIA is that consumers confirm their identity by attaching an Elliptic Curve Cryptography (ECC) digital signature to the Interest packet, while routers reject any unsolicited Interest packet without identity authentication. Finally, the results of the security analysis show that ECCIA is flexible, secure, and effective Yingjuan Shi, Maode Ma |
IWCMC | 2 |
| 2024 | Enhanced collaborative intrusion detection for industrial cyber-physical systems using permissioned blockchain and decentralized federated learning networks
Junwei Liang 0004, Muhammad Sadiq, Tie Cai, Maode Ma |
Eng. Appl. Artif. Intell. | 6 |
| 2024 | A literature review on V2X communications security: Foundation, solutions, status, and futureabstractAbstract With the refinement and development of the Vehicle to Everything (V2X) concept, its security issues have gradually come to the fore, revealing many security risks and increasing security requirements for V2X, and many protective measures have likewise emerged. The article first introduces the development history of the past Internet of Vehicles(IoV), summarizes some common V2X security threats, surveys the security technologies used for V2X communication, and outlines the development of each technology and the proposed security protocols in the last 3 years. Due to the different advantages and disadvantages of previous protection schemes, the idea of using National Cryptography to supplement the security scheme or designing a new security scheme article based on the National Cryptography Algorithms((AKA SM algorithms) is proposed. The survey then introduces the SM2, SM3, SM9, and ZUC algorithms, describes the development and application of the SM commercial algorithm in recent years, and finally, statistics and introduces the part of the development process of the security protocols currently used in IoV regarding the SM algorithms and gives some application prospects. Zuobin Ying, Kaichao Wang, Jinbo Xiong, Maode Ma |
IET Commun. | 4 |
| 2024 | A Novel Security Scheme Supported by Certificateless Digital Signature and Blockchain in Named Data NetworkingabstractNamed Data Networking (NDN) is a promising network architecture that differs from the traditional TCP/IP network, as it focuses on data rather than the host. A new secure model is required to provide the data‐oriented trust instead of the host‐oriented trust. This paper proposes a new secure solution in the NDNs named Secure Mechanism supported by Certificateless Digital Signature and Blockchain (CLDS‐B). The CLDS‐B scheme employs a certificateless digital signature to guarantee the authentication and integrity of data. On the one hand, the key escrow problem has been solved to eliminate the risks of compromised private key generators; on the other hand, the data name has been bound to the public key to prevent the false public key. Moreover, the blockchain is used to manage cryptographic information. Each domain designates an information service entity to join the blockchain so that the consumer could retrieve the cryptographic information public parameter in the local domain if necessary. Furthermore, due to the decentralization of the blockchain, the CLDS‐B would be robust to resist the single‐node failure. Simulation results show that the CLDS‐B scheme outperforms a classic NDN scheme, although it shows slightly inferior to the other secure NDN scheme. The security verification and analysis show that the CLDS‐B would resist the key escrow attack. The CLDS‐B would be a competitive solution in scenarios with a high‐security level. Bing Li 0004, Mingxuan Zheng 0003, Maode Ma |
IET Inf. Secur. | 3 |
| 2024 | Trusted Location Sharing on Enhanced Privacy-Protection IoT Without Trusted CenterabstractMany IoT applications require users to share their devices’ location, and enhanced privacy-protection means sharing location anonymously, unlinkably and without relying on any administrators. But under such protection, it is difficult to trust shared location data, which may be from unregistered devices or from the same one’s multiple logins or from the cloned device ID, even be generated by an attacker without any devices! Such untrusted location sharing cheats system, misleads users, even attacks system. To the best of our knowledge, such problems have not been solved in a decentralized system. To solve them in one scheme, we put forward the first decentralized accumulator for device registration and construct the first practical decentralized anonymous authentication for device login. When logging in, the device provides a special knowledge proof, which integrates zero-knowledge (for privacy) with knowledge-leakage (for identifying abnormal behaviors) designing for blockchain (for decentralization). Therefore, in our system, only registered IoT devices can upload location data and their logins are anonymous and unlinkable, while login exceeding${K}$times in a system period or cloning ID to login concurrently can be identified and tracked without any trusted centers. In addition, we provide the security proofs and the application examples of the proposed scheme. And the efficiency analysis and experimental data show that the performance of our scheme can meet the needs of real-world location sharing on IoT. Bin Lian, Jialin Cui, Hongyuan Chen, Xianghong Zhao, Fuqun Wang, Kefei Chen, Maode Ma |
IEEE Internet Things J. | 7 |
| 2024 | An efficient certificateless blockchain-enabled authentication scheme to secure producer mobility in named data networks
Maode Ma, Yuwen Xiong, Xiankun Zhang |
J. Netw. Comput. Appl. | 3 |
| 2024 | A secure location management scheme in an LEO-satellite network with dual-mobility
Qinglei Kong, Maode Ma, Haiyong Bao |
Peer Peer Netw. Appl. | 3 |
| 2024 | Reinventing Multi-User Authentication Security From Cross-Chain PerspectiveabstractBlockchain systems encompass many distinct and autonomous entities, each utilizing its own self-contained identity authentication algorithm. Unlike identity authentication within a singular blockchain, cross-chain scenarios demand special attention due to their pivotal role in enabling the acknowledgment of users’ identities across diverse domains. This capability is the foundational prerequisite for the circulation of resources across different chains. Consequently, the central challenge for cross-chain systems lies in establishing mutual recognition and trust in users’ digital identities. This paper proposes a Multi-User Proxy Re-Signature (MU-PRS) algorithm, facilitating the cross-chain conversion of signatures from multiple users. Concurrently, This paper propose the Multi-Notary Signature Conversion (MN-SC) mechanism, designed to address the challenge posed by disparate system mechanisms across blockchains during cross-chain authentication. Leveraging the MU-PRS algorithm and MN-SC mechanism, we present a Multi-User Cross-Chain Authentication Scheme (MU-CCAS) within a heterogeneous blockchain environment. This scheme enables the verification of identities of multiple cross-chain users through a single signature verification. This innovative approach not only addresses the centralization issues inherent in third-party cross-chain authentication but also significantly enhances the efficiency of identity authentication. The evaluation results demonstrate MU-CCAS’s superior security over existing solutions in three dimensions: BAN logic, Scyther verification, and security attribute analysis. Additionally, it establishes that MU-PRS and MU-CCAS have low computational overhead, easy implementation, and excel in algorithm, scheme, and cross-chain performance. Overall, our work provides a robust and efficient framework for cross-chain authentication, addressing centralization challenges and enhancing digital security. Yongyang Lv, Maode Ma, Manqing Zhu, Hanwei Wu, Xiaohong Li 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | A novel blockchain-enabled zero-trust-based authentication scheme in power IoT environments
Maode Ma, Cong Wang 0004 |
J. Supercomput. | 4 |
| 2023 | ADMBIFA: Accurate Detection and Mitigation of Blended Interest Flooding Attacks in NDNsabstractThe Named Data Network (NDN) is a future network architecture to transit conventional host-centric networks into data-centric networks. A routing attack, represented by Interest Flooding Attack (IFA), is a major security concern in NDNs. IFAs seriously harm NDNs by sending excessive fallacious Interest packets to overwhelm the routers to serve legitimate users. It is easy to launch, but difficult to defend, especially when legitimate Interest packets are blended with the IFAs as bIFAs. In this paper, we propose an accurate approach to detect and mitigate IFAs and bIFAs, named Accurate Detection and Mitigation of Blended Interest Flooding Attacks (ADMBIFA). It utilizes fuzzy logic to detect IFAs and bIFAs. And then it identifies malicious Interest prefixes with K-means. Finally, it restrains attackers to mitigate the damage to the networks. The simulation results show that the ADMBIFA is very sensitive to detect attacks with an ability to mitigate IFAs and bIFAs. And it can effectively reduce the negative impacts on NDNs. Xin-Xin Guo, Maode Ma |
HPSR | 3 |
| 2023 | DQN based Blockchain Data Storage in Resource-constrained IoT SystemabstractApplying blockchain technology in the Internet of Things (IoT) systems to realize massive data storage is a promising technology, which can eliminate the dependence of IoT on central servers and protect data security effectively. However, in legacy IoT systems, it is hardly to store a complete blockchain at all nodes due to the limited storage space. In order to securely store massive data in the resource-constrained IoT systems, we design a blockchain-assisted distributed storage mechanism, by which multiple nodes collaboratively store a complete blockchain. Meanwhile, we design a deep reinforcement learning (DRL) based algorithm to obtain the optimal block allocation strategy for the collaborative storage. The optimal strategy can maximize the number of storage blocks so as to maximize the utilization of the limited storage space under the premise of meeting the requirements of user query delay and reliability. The simulation results show that compared with the random search algorithm and the policy gradients algorithm, the proposed Deep Q Network algorithm can achieve the maximum number of storage blocks in the same storage space, and the fastest storage speed. Boyi Lei, Maode Ma, Xianhua Niu |
WCNC | 3 |
| 2023 | Efficient-Lightweight CRL Distribution in VANETs: A Multilayer Coded Caching MethodologyabstractRecently, Vehicular Ad Hoc Networks (VANETs) have emerged as a promising approach to improve ride comfortability and safety, as well as increase the competition of highway. Certificate Revocation List (CRL)-based schemes are the most widely used recovery mechanism for VANETs to eliminate the negative effect of security and privacy attacks. However, providing an efficient and low-cost CRL-based scheme for certificate revocation is still a challenging issue since the communication resources must be capable of carrying various applications apart from the security and privacy purposes. Thus, in this paper, a Multilayer Coded Caching CRL scheme, called MCC-CRL, is proposed in VANETs. The MCC-CRL is able to distribute the minimum bits of CRLs that satisfies the revocation requirements, aiming to reduce the communication overhead and shorten the processing time cost. In addition, the efficient authentication mechanism, i.e., EAAP, is employed with our MCC-CRL scheme to realize conditional privacy preservation in a computationally efficient way. Extensive simulations demonstrate that the MCC-CRL scheme is secure and computationally efficient for vehicles’ revocation. Junwei Liang 0004, Maode Ma |
WCNC | 2 |
| 2023 | ILL-IDS: An incremental lifetime learning IDS for VANETs
Yunfan Huang, Maode Ma |
Comput. Secur. | 2 |
| 2023 | Edge intelligence-enabled cyber-physical systemsabstractWith the advent of the Internet of everything era, people's demand for intelligent Internet of Things (IoT) devices is steadily increasing. A more intelligent cyber-physical system (CPS) is needed to meet the diverse business requirements of users, such as ultra-reliable low-latency communication, high quality of services (QoS), and quality of experience (QoE). Edge intelligence (EI) is recognized by academia and industry as one of the key emerging technologies for the CPS, which provides the ability to analyze data at the edge rather than sending it to the cloud for analysis, and will be a key enabler to realize a world of a trillion hyperconnected smart sensing devices.As a distributed intelligent computing paradigm in which computation is largely or completely performed at distributed nodes, EI provides for the rapid development of artificial intelligence (AI) and edge computing resources to support real-time insight and analysis for applications in CPS, which brings memory, computing power and processing ability closer to the location where it is needed, reduces the volumes of data that must be moved, the consequent traffic, and the distance the data must travel. As an emerging intelligent computing paradigm, EI can accelerate content delivery and improve the QoS of applications, which is attracting more and more research attentions from academia and industry because of its advantages in throughput, delay, network scalability and intelligence in CPS. Rongbo Zhu, Ashiq Anjum, Maode Ma |
Concurr. Comput. Pract. Exp. | 4 |
| 2023 | A watermark detection scheme based on non-parametric model applied to mute machine voice
Yangxia Hu, Wenhuan Lu, Jianguo Wei, Junhai Xu, Maode Ma |
Multim. Tools Appl. | 5 |
| 2023 | Efficient Group Handover Authentication for Secure 5G-Based Communications in PlatoonsabstractIn recent years, the world of vehicular communication is in full progress. With the emergence of the fifth-generation (5G) technology, the high bandwidth and low latency features in the 5G vehicle to everything (5G-V2X) network become possible. However, the current 5G mechanism specified by the Third Generation Partnership Project (3GPP) Release 16 incurs high signaling overhead over the radio access network and the core network when a vehicle platoon moves from a source base station to the target base station. Moreover, it also has several security problems in terms of the failure of key forward secrecy (KFS) and lack of mutual authentication. In this paper, we propose an efficient authentication protocol for vehicle platoons in all handover scenarios. By the proposal, the identities of base stations and vehicles are mutually authenticated by certificateless aggregated signatures, which can also reduce signaling overhead and is free from key escrow problems. The proposed protocol has been formally evaluated by BAN-logic and the Scyther tool to show its ability to resist major typical malicious attacks. It has also been analyzed on its security functionality. The performance evaluation demonstrates that the proposed protocol is efficient in terms of signaling, computational and communication cost. Xiaobei Yan, Maode Ma, Rong Su 0001 |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2023 | Federated Deep Reinforcement Learning-Based Spectrum Access Algorithm With Warranty Contract in Intelligent Transportation SystemsabstractCognitive radio (CR) provides an effective solution to meet the huge bandwidth requirements in intelligent transportation systems (ITS), which enables secondary users (SUs) to access the idle spectrum of the primary users (PUs). However, the high mobility of users and real-time service requirements result in the additional transmission collisions and interference, which degrades the spectrum access rate and the quality of service (QoS) of users in ITS. This paper proposes a spectrum access algorithm (Feilin) based on federated deep reinforcement learning (FDRL) to improve spectrum access rate, which maximizes the QoS reward function with considering the hybrid benefits of delay, transmission power and utility of SUs. To guarantee the utility of SUs, the warranty contract is designed for SUs to obtain compensation for data transmission failure, which promotes SUs to compete for more spectrum resources. To meet the real-time requirements and improve QoS in ITS, a spectrum access model called FDQN-W is proposed based on federated deep Q-network (DQN), which adopts the asynchronous federated weighted learning algorithm (AFWLA) to share and update the weights of DQN in multiple agents to decrease time cost and accelerate the convergence. Detailed simulation results show that, in the multiuser scenario, compared with the existing methods, the proposed algorithm Feilin increases the spectrum access success rate by 15.1%, and reduces the collision rate with SUs and the collision rate with PUs by 46.4% and 6.8%, respectively. Rongbo Zhu, Hao Liu 0056, Lu Liu 0001, Maode Ma |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2023 | MetaVSID: A Robust Meta-Reinforced Learning Approach for VSI-DDoS Detection on the EdgeabstractThe explosive growth of end devices that generate massive amounts of data requires close-proximity computing resources for processing at the network’s edge. Having geographic distributions and limited resources of edge nodes or servers opens several doors for attackers to exploit them primarily to the detriment of deployed services; one of the recent attacks is Very Short Intermittent Distributed Denial of Services (VSI-DDoS). Deep learning-based models have been developed to detect and mitigate such attacks but cause the degrading quality of models due to covariate shifts when deployed in real-world environments. Therefore, we propose a new approach, called MetaVSID, to detect VSI-DDoS attacks in edge clouds using meta-reinforcement learning followed by ensemble learning to increase the robustness of the model in detecting VSI-DDoS attacks early. The proposed model can capture dynamic patterns of VSI-DDoS attacks, from which it identifies manipulated services and increase service availability when covariate shifts at deployment time. We carry out extensive experiments to validate the MetaVSID using both testbed and benchmark datasets. Via the meta-reinforced downsampling process, the proposed method improves sample efficiency, leading to cost-effective policies. Moreover, the optimized policies are generalized to adapt to dynamic changes in the training distribution. Our experimental results demonstrate that MetaVSID stably achieves better performance in multiple evaluation settings with the difference from baseline models from 1.5% to 7.5% in terms of AUC for both VSI-DDoS and DDoS detection, especially under covariate shift settings. Xuan-Son Vu, Maode Ma, Monowar Bhuyan |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2022 | Self-Adaptive IDS in VANETs: A Game Theory and Deep Q-Learning Network Based Generic SchemeabstractBecause of the nature of high mobility and dynamic network topology, Intrusion Detection Systems (IDSs) in Vehicular Ad-hoc Networks (VANETs) face the challenge in balancing the accuracy and efficiency of detection. Two crucial problems are remained unsolved in existing studies: 1) how to perceive the environmental change in the perspective of an IDS? 2) how to make the IDS adaptive in different scenarios? In this paper, a self-adaptive scheme is proposed for IDSs in VANETs based on Bayesian game theory and Deep Q-learning Network (DQN). In the scheme, the interactions between an IDS and attackers are formulated as a dynamic intrusion detection game, in which the proposed scheme decides either to just adjust or to completely retrain the IDS. The Nash Equilibria (NE) of the game is derived to reveal how the optimal decision of the IDS depends on the detection performance and road conditions. Moreover, a DQN-Adjustment is proposed to realize the self-adaptation of the IDS in the dynamic game. Simulation results show that the IDS with the proposed self-adaptive scheme has better performance than other existing IDSs with higher detection rate as well as lower detection time and overhead. Junwei Liang 0004, Maode Ma |
GLOBECOM | 2 |
| 2022 | Novel Position Falsification Attacks Detection in the Internet of Vehicles using Machine LearningabstractIn an Internet of Vehicles (IoV) network, vehicles periodically broadcast Basic Safety Messages (BSMs) that contain the vehicle's current position, speed, and acceleration. Safety-critical applications like blind-spot warning and lane change warning systems use these BSMs to ensure the safety of road users. However, an attacker can affect the efficacy of such applications by injecting false information into the messages. One such attack is the position falsification attack, where the attacker inserts incorrect information regarding the vehicle's position in the BSMs. The literature has explored the use of Misbehavior Detection Systems (MDSs) to detect position falsification attacks. But the limitation of the existing MDSs is that they are signature-based and require prior knowledge about the attacks for effective detection. To overcome this shortcoming, we propose a Novel Position Falsification Attack Detection System for the Internet of Vehicles (NPFADS for the IoV)that learns and detects new position falsification attacks emerging in IoV networks. The performance of NPFADS is quantitatively measured using the metrics precision, recall, F1 score, and ROC. The Vehicular Reference Misbehavior (VeReMi) dataset is used as the benchmark to analyze the performance of NPFADS. The performance of NPFADS is compared to existing MDSs in the literature, and the analysis shows that NPFADS performs on par with the existing signature-based detection models even when initialized with zero initial knowledge. Harun Surej Ilango, Maode Ma, Rong Su 0001 |
ICARCV | 2 |
| 2022 | Effective Authentication to Prevent Sybil Attacks in Vehicular PlatoonsabstractThe potential ability to increase the capacity and safety on roads, as well as fuel economy gains has made vehicle platooning an appealing prospect. However, its use is yet to be widespread, partially due to the security concerns on it. One particular concern is the admission of fake virtual vehicles into the platoons, allowing them to wreak havoc on the platoon, which is known as a Sybil attack. In this paper, we propose a secure vehicular authentication scheme for platoon admission which is resistant to the threats of Sybil attacks. The proposed scheme offers a mutual authentication on both vehicle identity and message through a combination of a key exchange, a digital signature and an encryption scheme based on Elliptic Curve Cryptography (ECC). The scheme holds its outstanding feature to provide both perfect forward secrecy and group backward secrecy to ensure the protection of anonymity of vehicles and platoons while typical malicious attacks such as replay, and man-in-the-middle attacks can also be resisted. A formal evaluation of the security of the scheme by Canetti-Krawczyk (CK) adversary and random oracle model has been conducted to demonstrate its security functionality. Finally, the performance of the proposed scheme has been evaluated to show its efficiency. Danial Ritzuan Junaidi, Maode Ma, Rong Su 0001 |
ICARCV | 2 |
| 2022 | A Certificateless Efficient and Secure Group Handover Authentication Protocol in 5G Enabled Vehicular NetworksabstractIn recent years, the world of vehicular communication is in full progress. With the emerge of the fifth-generation (5G) technology, the high bandwidth and low latency features in the 5G vehicle to everything (5G-V2X) network become possible. However, the current 5G mechanism specified by the Third Generation Partnership Project (3GPP) Release 16 incurs high signaling overhead over the radio access network and the core network when a vehicle platoon moves from a source base station to the target base station. Moreover, it also has several security problems in terms of the failure of key forward secrecy (KFS) and lack of mutual authentication. In this paper, we propose an efficient authentication protocol for vehicle platoons in all handover scenarios. The proposed protocol has been formally evaluated by the Scyther tool to show its ability to resist major typical malicious attacks. It has also been analysed on its security functionality. The performance evaluation demonstrates that the proposed protocol is efficient in terms of signaling and computational cost. Xiaobei Yan, Maode Ma, Rong Su 0001 |
ICC | 2 |
| 2022 | Federated Learning for Heterogeneous Mobile Edge Device: A Client Selection GameabstractIn the federated learning (FL) paradigm, edge devices use local datasets to participate in machine learning model training, and servers are responsible for aggregating and maintaining public models. FL cannot only solve the bandwidth limitation problem of centralized training, but also protect data privacy. However, it is difficult for heterogeneous edge devices to obtain optimal learning performance due to limited computing and communication resources. Specifically, in each round of the global aggregation process by the FL, clients in a ‘strong group’ have a greater chance to contribute their own local training results, while those clients in a ‘weak group’ have a low opportunity to participate, resulting in a negative impact on the final training result. In this paper, we consider a federated learning multi-client selection (FL-MCS) problem, which is an NP-hard problem. To find the optimal solution, we model the FL global aggregation process for clients participation as a potential game. In this game, each client will selfishly decide whether to participate in the FL global aggregation process based on its efforts and rewards. By the potential game, we prove that the competition among clients eventually reaches a stationary state, i.e. the Nash equilibrium point. We also design a distributed heuristic FL multi-client selection algorithm to achieve the maximum reward for the client in a finite number of iterations. Extensive numerical experiments prove the effectiveness of the algorithm. Tongfei Liu, Hui Wang 0156, Maode Ma |
MSN | 3 |
| 2022 | A Novel and Efficient Anonymous Authentication Scheme Based on Extended Chebyshev Chaotic Maps for Smart GridabstractIn a smart grid, the identity authentication between a smart meter and an aggregator is a prerequisite for both parties to establish a secure channel. All existing authentication schemes have their own shortcomings in either security or efficiency to make them difficult to meet the security requirements of the smart grid. In this paper, we are motivated to propose an efficient and secure mutual authentication scheme based on the extended Chebyshev chaotic maps. The smart meters and aggregators are registered with a trusted third party to conduct a mutual authentication. The proposed scheme provides anonymity protection for smart meters to achieve perfect forward secrecy. Through security analysis, we conclude that the proposed scheme has the characteristics of high security. In addition, we compare the proposed scheme with other three schemes in terms of number of encryption operations, computation delay. The performance comparison demonstrates that the proposed scheme is efficient without sacrificing the desired security properties. Cong Wang 0004, Maode Ma, Yiying Zhang 0004 |
WoWMoM | 3 |
| 2022 | A flexible and lightweight privacy-preserving handshake protocol based on DTLShps for IoT
Lei Yan 0006, Maode Ma, Xiaohong Huang 0003, Yan Ma 0003, Kun Xie 0003 |
Comput. Networks | 2 |
| 2022 | Real-time cooperative data routing and scheduling in software defined vehicular networks
Kushan Sudheera Kalupahana Liyanage, Maode Ma, Peter Han Joo Chong |
Comput. Commun. | 2 |
| 2022 | A privacy-preserving handover authentication protocol for a group of MTC devices in 5G networks
Xiaobei Yan, Maode Ma |
Comput. Secur. | 2 |
| 2022 | A FeedForward-Convolutional Neural Network to Detect Low-Rate DoS in IoTabstractThe lack of standardization and the heterogeneous nature of the Internet of Things (IoT) has exacerbated the issue of security and privacy. In literature, to improve security at the network layer of the IoT architecture, the possibility of using Software-Defined Networking (SDN) was explored. SDN is also plagued by network threats that affect conventional networks. One such threat to a network is the Low-Rate Denial of Service (LR DoS) attack, where the attacker sends precise traffic bursts that force a TCP flow to enter a retransmission timeout state. LR DoS attacks are difficult to detect as their attack signature is similar to benign network traffic. The existing AI-based detection algorithms in the literature are signature-based, and their efficacy in detecting unknown LR DoS attacks was not explored. In this work, an AI-based anomaly detection scheme called FeedForward–Convolutional Neural Network (FFCNN) is proposed to detect LR DoS attacks in IoT-SDN. The Canadian Institute of Cybersecurity Denial of Service 2017 (CIC DoS 2017) dataset is used for the study. An iterative wrapper-based feature selection using Support Vector Machine (SVM) is used to derive the significant features required for detection. The performance of FFCNN is compared to the machine learning algorithms-J48, Random Forest, Random Tree, REP Tree, SVM, and Multi-Layer Perceptron (MLP). The performance of the models is measured using the metrics accuracy, precision, recall, F1 score, detection time per flow, and ROC curves. The empirical analysis shows that FFCNN outperforms other machine learning algorithms on all metrics. Harun Surej Ilango, Maode Ma, Rong Su 0001 |
Eng. Appl. Artif. Intell. | 2 |
| 2022 | A misbehavior detection system to detect novel position falsification attacks in the Internet of Vehicles
Harun Surej Ilango, Maode Ma, Rong Su 0001 |
Eng. Appl. Artif. Intell. | 2 |
| 2022 | A Novel PUF-Based Group Authentication and Data Transmission Scheme for NB-IoT in 3GPP 5G NetworksabstractWith the gradual commercialization of the fifth-generation (5G) network, the narrowband Internet of Things (NB-IoT) system would have potential and prospective applications in future relying on the infrastructure. Meanwhile, predictably, there are several security requirements to be satisfied, including concurrent access authentication for massive devices, identity privacy protection, physical attack resistance, application traffic security, etc. In this article, we present a novel group authentication and data transmission scheme using the physically unclonable function (PUF) for NB-IoT in which the output of PUF is viewed as shared root key to achieve the mutual authentication along with key agreement. By this scheme, a Group Leader is employed to aggregate and relay authentication information and, thus, it reduces the signaling cost and communication cost followed by activating attach request messages from a sea of devices. The network side as well can surely find fake ones through individual truncated authentication code and detect honest devices with high probability when aggregated authentication code is invalid. Furthermore, the revised security model and the formal verification tool Scyther are employed to evaluate the security of the scheme. Finally, performance analysis results show that our solution has the desired efficiency. Xiongpeng Ren, Jin Cao 0001, Maode Ma, Hui Li 0006, Yinghui Zhang 0002 |
IEEE Internet Things J. | 3 |
| 2022 | A semi fragile watermarking algorithm based on compressed sensing applied for audio tampering detection and recovery
Yangxia Hu, Wenhuan Lu, Maode Ma, Qilong Sun, Jianguo Wei |
Multim. Tools Appl. | 3 |
| 2022 | Competitive teaching-learning-based optimization for multimodal optimization problems
Aining Chi, Maode Ma, Zhigang Jin |
Soft Comput. | 2 |
| 2022 | EAP-DDBA: Efficient Anonymity Proximity Device Discovery and Batch Authentication Mechanism for Massive D2D Communication Devices in 3GPP 5G HetNetabstractDevice-to-device (D2D) communication as direct communication technology has many application scenarios and plays a very important role in the fifth-generation (5G) era. Using D2D communication in third generation partnership project (3GPP) 5G Heterogeneous Network (HetNet) can effectively relieve the network traffic pressure and reduce the energy consumption of the base station. However, there are numerous security threats in D2D applications since the D2D communication remains in the early stage. The existing standards and solutions rarely consider device discovery, efficient authentication, mutual authentication, and key negotiation with privacy protection for D2D user equipment (UE) in heterogeneous access scenarios. In this article, we present a unified efficient anonymity proximity device discovery and batch authentication mechanism for heterogeneous D2D UEs based on a new proposed efficient pairing-free certificateless batch signature (CLBS), the identity-based prefix encryption and Chinese remainder theorem (CRT). Our proposed scheme can be applied to all the 5G heterogeneous access scenarios of D2D communication. The security analysis and performance results show that our scheme can achieve mutual authentication, key agreement, identity privacy protection, batch verification, and resist several protocol attacks with ideal efficiency. Yunqing Sun, Jin Cao 0001, Maode Ma, Yinghui Zhang 0002, Hui Li 0006, Ben Niu 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | FS-MOEA: A Novel Feature Selection Algorithm for IDSs in Vehicular NetworksabstractFor Intrusion Detection Systems (IDSs) in Vehicular Ad Hoc Networks (VANETs), single-objective optimization algorithm has inherited limitations for the feature selection problem with the multiple objectives. Moreover, the imbalanced problem commonly exists in various datasets. Thus, in this paper, a feature selection algorithm based on a many-objective optimization algorithm (FS-MOEA) is proposed for IDSs in VANETs, in which Adaptive Non-dominant Sorting GeneticAlgorithm-III(A-NSGA-III) serves as the many-objective optimization algorithm. Two improvements, called Bias and Weighted (B&W) niche-preservation and Information Gain (IG)-Analytic Hierarchy Process (AHP) prioritizing, are further designed in FS-MOEA. The former is used to counterbalance the imbalanced problem in datasets by assigning rare classes higher priorities, while the latter is employed to search the optimal feature subset for FS-MOEA. In IG-AHP prioritizing, a more distinct measurement, i.e. average IG, is used as the dominant factor to guide the decision analysis of AHP. Experimental results show that the proposed FS-MOEA can not only improve the performance of IDSs in VANETs but also alleviate the negative impact of the imbalanced problem. Junwei Liang 0004, Maode Ma |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2022 | GaDQN-IDS: A Novel Self-Adaptive IDS for VANETs Based on Bayesian Game Theory and Deep Reinforcement LearningabstractDue to the nature of high mobility and dynamic network topology, Intrusion Detection Systems (IDSs) in Vehicular Ad-hoc Networks (VANETs) face lots of challenges, especially in balancing the accuracy and efficiency of detection. Current researches about the deployment of IDSs in VANETs mainly focus on a tradeoff between the effectiveness and efficiency, but few efforts have been done about the adaptability of the tradeoff in the changeable networks. Thus, we address two crucial problems: 1) how to perceive the environmental change in the perspective of an IDS? 2) how to make the IDS adaptive in different scenarios? In this paper, a Bayesian Game theory and Deep Q-learning Network-based IDS is proposed for VANETs, called GaDQN-IDS. The interactions between an IDS and attackers are formulated as a dynamic intrusion detection game, in which the IDS decides either to just adjust the tradeoff between the accuracy and efficiency or to be retrained completely when its detection capacity has declined. The Nash Equilibria (NE) of the game is derived to reveal how the optimal decision of the IDS depends on the detection performance and road conditions. Moreover, a Deep Q-learning Network (DQN)-Adjustment is proposed to realize the self-adaptation of the IDS in the dynamic game, while an Error Priority Learning (EPL) is further designed for IDS retraining in changing VANETs. Simulation results show that the GaDQN-IDS has better performance than other existing IDSs with higher detection rate as well as lower detection time and overhead. Junwei Liang 0004, Maode Ma |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2021 | An Efficiency-Accuracy Tradeoff for IDSs in VANETs with Markov-based Reputation SchemeabstractVehicle Ad Hoc Networks (VANETs) are considered to be a next big thing that will remarkably change our lives, since this kind of technology is able to make our lives and roads safer. Intrusion Detection Systems (IDS) is an important technology that can mitigate both inner and outer threats for the vulnerable networks like VANETs. However, it is difficult to adopt the same IDSs that have been appropriately used in wired networks, due to the fast moving and highly dynamic nature of VANETs. Thus, in this paper, an Efficient IDS with a Markov-based Reputation Scheme is proposed, called EIDS-MRS. In EIDS-MRS, the Non-Linear Programming (NLP)-Optimization is designed as the efficient mechanism to reduce the execution time of IDSs in VANETs. Moreover, considering the security risks of NLP-Optimization, a Reputation Scheme based on the Hidden Generalized Mixture Transition Distribution (HgMTD) model, namely RS-HgMTD, is proposed for each vehicle in VANETs to evaluate the creditworthiness of their neighbors. Experiments show that the EIDS-MRS has better performance than other available IDSs in terms of detection rate, detection time and overhead. Junwei Liang 0004, Maode Ma |
ICC | 2 |
| 2021 | A Blockchain-Assisted Seamless Handover Authentication for V2I Communication in 5G Wireless NetworksabstractThe Fifth Generation (5G) wireless network needs many base stations to provide ultra-high throughput. Thus, the vehicles in Vehicles to Infrastructure (V2I) communication over a 5G wireless network have to perform more frequent mutual authentications than before, which will greatly reduce the efficiency of the entire network. To address this issue, in this paper, we propose a novel handover authentication protocol that incorporates the blockchain based smart contracts to remove redundancy in the traditional handover authentication. Our proposed scheme can achieve the mutual authentication and key agreement between vehicles and base stations in 5G wireless networks, while it can largely reduce the cost for the handover authentication at the same time. The formal verification by Scyther indicates that the proposed protocol can resist various malicious attacks. In addition, the performance evaluation results show that the delay incurred by handover authentication can be significantly reduced indicating that the proposed protocol is feasible and holds potential to be used in the deployment of 5G wireless networks. Fengye Yu, Maode Ma, Xiaohong Li 0001 |
ICC | 2 |
| 2021 | Improved Handshaking Procedures for Transport Layer Security in Software Defined NetworksabstractSoftware defined networking (SDN) has emerged as a new technology to enhance the flexibility, resilience, and automated centralized management of a network. Recently several reports have identified possible vulnerabilities, which may affect its authenticity, availability, confidentiality and integrity. This paper analyzes several types of security issues in SDNs, especially on how to secure the communication between the control plane and the data plane. The state-of-the-art security protocol TLS in SDNs has been verified using the Scyther Tool. Two security schemes, namely TLSHPS and TLSIHP are proposed to improve the handshaking procedures of the TLS. Security analysis with the Scyther tool shows that both proposed schemes work well to prevent various cyber attacks. Xue Jun Li, Maode Ma, Cho Wai Hlaing |
TENCON | 2 |
| 2021 | A Blockchain-Based Security Scheme for Vehicular Ad Hoc Networks in Smart CitiesabstractThe development of Vehicular Ad Hoc Networks (VANET) has brought many advantages to facilitate the deployment of the Intelligent Transportation System (ITS). However, without proper protection, VANETs can be vulnerable to severe cyber-attacks. This paper explores the threats to the VANETs and proposes a security scheme for VANETs with a Blockchain (VNB). Furthermore, the proposed VNB with Ethereum was developed. With a graphical user interface, experiments were conducted. For ad hoc communications, a vehicle can randomly select another vehicle, and VNB will authenticate the selected vehicle with the Blockchain and Trusted Authority (TA). Preliminary test results successfully proved that Blockchain can be the key technology to mitigate the security threats to VANETs. Xue Jun Li, Maode Ma, Yong Xing Yong |
TENCON | 2 |
| 2021 | An enhanced handover authentication solution for 6LoWPAN networks
Lyuye Zhang, Maode Ma, Yue Qiu 0004 |
Comput. Secur. | 2 |
| 2021 | Game-Theory-Based Clustering Scheme for Energy Balancing in Underwater Acoustic Sensor NetworksabstractThe underwater acoustic sensor network (UASN) is a specific deployment of Internet-of-Things (IoT) technology in the underwater environment, since energy constraints limit the lifetime of UASNs, effectively balancing the energy consumption of acoustic sensor nodes in UASNs is important to maximize the amount of information collected and to prolong the network lifetime. Node clustering is widely regarded as one of the most important energy-efficient schemes for UASNs. However, most existing clustering schemes focus on the cooperation-based election of cluster headers (CHs) in a centralized manner. Due to the limited energy capacity, acoustic sensor nodes are designed to save their own energy, hindering the realization of such cooperation. To address this issue in this article, game theory is applied to UASNs to balance network energy consumption and model acoustic sensor nodes as rational and selfish players. Specifically, a game-theory-based clustering (GTC) scheme for UASNs is developed. In the CH election phase, each node makes a decision in pursuit of a greater payoff based on the Nash equilibrium. An incentive mechanism is invented to induce nodes to make more beneficial collective decisions and plays a role in the CH rotation to effectively balance the energy consumption. Meanwhile, the network area is divided into nonuniform sectors to ensure the energy consumption of the CH is more evenly distributed. Simulation results show that the proposed GTC scheme can effectively balance network energy consumption and extend the network lifetime. Guanglin Xing, Yumeng Chen, Rui Hou 0003, Mianxiong Dong, Deze Zeng, Jiangtao Luo, Maode Ma |
IEEE Internet Things J. | 7 |
| 2021 | A lightweight and secure handover authentication scheme for 5G network using neighbour base stations
Xiaobei Yan, Maode Ma |
J. Netw. Comput. Appl. | 2 |
| 2021 | CPPHA: Capability-Based Privacy-Protection Handover Authentication Mechanism for SDN-Based 5G HetNetsabstractUltra-dense Heterogeneous network (HetNet) technique can significantly improve wireless link quality, spectrum efficiency and system capacity, and satisfy different requirements for coverage in hotspots, which has been viewed as one of the key technologies in fifth Generation (5G) network. Due to the existence of many different types of base stations (BSs) and the complexity of the network topology in the 5G HetNets, there are a lot of new challenges in security and mobility management aspects for this multi-tier 5G architecture including insecure access points and potential frequent handovers among several different types of base stations. In this paper, we integrate user capability and Software Defined Network (SDN) technique, and propose a capability-based privacy protection handover authentication mechanism in SDN-based 5G HetNets. Our proposed scheme can achieve the mutual authentication and key agreement between User Equipments (UEs) and BSs in 5G HetNets at the same time largely reduce the authentication handover cost. We demonstrate that our proposed scheme indeed can provide robust security protection by employing several security analysis methods including the BAN logic and the formal verification tool Scyther. In addition, the performance evaluation results show that our scheme outperforms other existing schemes. Jin Cao 0001, Maode Ma, Hui Li 0006, Yinghui Zhang 0002 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | Compact E-Cash with Efficient Coin-TracingabstractCompact E-cash achieves an efficient system by withdrawing 2n coins within O(1) operations and storing the coins in O(n) bits. For preventing a double-spender from cheating again, it is necessary to trace his e-coins. So full-tracing in compact E-cash system means tracing double-spender and tracing his coins. However, the efficiency problem caused by coin-tracing without TTP (trusted third party) has not been solved. For solving this problem, we introduce a non-standard construction into zero-knowledge proof of payment protocol, which leaks coin information when double-spending but is proven to be perfect zero-knowledge to verifier when spending a coin only once. Therefore, it achieves tracing dishonest users' coins and preserving the anonymity of honest users. Comparing with the existing most efficient method of coin-tracing without TTP, we improve computational complexity from O(k) to O(1) with less storage space. In addition, to improve efficiency and practicality further, batch-spending (spending any number of coins in one operation) and compact-spending (spending all coins in one operation) had been proposed. Based on the non-standard zero-knowledge proof, our scheme provides more efficient batch/compact-spending. Moreover, we also make a comparison with Bitcoin and Bitcoin Lightning Network, which have attracted considerable attention. Bin Lian, Gongliang Chen, Jialin Cui, Maode Ma |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2021 | ECF-MRS: An Efficient and Collaborative Framework With Markov-Based Reputation Scheme for IDSs in Vehicular NetworksabstractVehicle Ad Hoc Networks (VANETs) are considered to be a next big thing that will remarkably change our lives, since this kind of technology is able to make our lives and roads safer. Intrusion Detection Systems (IDS) is an important technology that can mitigate both inner and outer threats for the vulnerable networks like VANETs. However, it is difficult to adopt the same IDSs that have been appropriately used in wired networks, due to the fast moving and highly dynamic nature of VANETs. Thus, in this article, an Efficient and Collaborative Framework with a Markov-based Reputation Scheme is proposed, namely ECF-MRS. In the proposed framework, the collaborative mechanism is achieved by using Non-dominant Sorting Genetic Algorithm-III (NSGA-III)-Collaboration to merge the advantages of IDSs in VANETs to generate a more superior IDS, while Non-Linear Programming (NLP)-Optimization is designed as the efficient mechanism to reduce the execution time of IDSs in VANETs. Moreover, considering the security risks of collaboration, a Reputation Scheme based on the Hidden Generalized Mixture Transition Distribution (HgMTD) model, namely RS-HgMTD, is proposed for each vehicle in VANETs to evaluate the creditworthiness of their neighbors. Experiments show that the IDS with ECF-MRS has better performance than other existing IDSs in terms of detection rate, detection time and overhead. Junwei Liang 0004, Maode Ma |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2021 | Achieving Privacy-Preserving and Verifiable Data Sharing in Vehicular Fog With BlockchainabstractVehicular sensing is advocated to perform data collection by exploiting a plethora of vehicular on-board sensors; meanwhile, with the merging of vehicular sensing and fog computing, the deployed road side units (RSUs) can act as fog nodes to collect and share vehicular sensory data at the network edge. However, there are still several problems in terms of the secure and reliable sharing of sensory data in vehicular fog. To resolve these issues, in this paper, we present an efficient, privacy-preserving and verifiable sensory data collection and sharing scheme with a permissioned blockchain in vehicular fog. During the data collection phase, by combining the homomorphic 2-DNF (Disjunctive Normal Form) cryptosystem and an identity-based signcryption scheme, our proposed scheme achieves the secure and verifiable computation of the average and variance of the collected vehicular sensory data. Meanwhile, to achieve efficient and reliable data sharing, we exploit a permissioned blockchain to maintain an immutable and tamper-proof record of the derived sensory data. Security analysis demonstrates the security properties of the proposed scheme, in terms of location privacy preservation, verifiability and immutability. Performance evaluations are conducted to validate the efficiency of the proposed scheme, i.e., improvements in computation and communication efficiency in comparison with a scheme without exploiting blockchain. Qinglei Kong, Le Su, Maode Ma |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2021 | Smart healthcare in smart cities: wireless patient monitoring system using IoT
M. Poongodi, Ashutosh Sharma 0004, Mounir Hamdi, Maode Ma, Naveen K. Chilamkurti |
J. Supercomput. | 4 |
| 2021 | Co-Maintained Database Based on Blockchain for IDSs: A Lifetime Learning FrameworkabstractIntrusion Detection System (IDS) is one of the most important approaches in cyber security to protect networks against both inner and outer threats. Apart from traditional networks, IDSs have been implemented in various emerging networks, such as mobile networks and Vehicle Ad hoc Networks (VANETs). However, a critical problem in IDSs is that the detection capacity is gradually decaying with the emergence of unknown attacks. It is necessary to constantly retrain IDSs with a more extensive database, but the security institutes usually lack the motivation to persistently update and maintain the database for public. Thus, in this paper, a lifetime learning framework is proposed for IDSs with a blockchain-based database (bc-DB). In the proposed framework, the blockchain-based database is multilaterally maintained by the security institutes and universities using Data Coins (DCoins) as the incentives. In addition, a Lifetime Learning IDS (LL-IDS) is further designed as the supplement of the bc-DB for common IDS users. For the LL-IDS, the Growing Hierarchical Self-Organizing Map with probabilistic relabeling (GHSOM-pr) having flexible and hierarchical architecture is employed as the classifier, which grows to make itself perfectly fit the changeable bc-DB. Security analysis and simulation experiments show that the proposed lifetime learning framework are both secure and effective in attacks detection. Junwei Liang 0004, Maode Ma |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2020 | Incremental Database Based on Distributed Ledger Technology for IDSs
Junwei Liang 0004, Maode Ma |
GLOBECOM | 2 |
| 2020 | Privacy-preserving Intelligent Traffic Light ControlabstractA new trend of using deep reinforcement learning for traffic light control has become a spotlight in the Intelligent Transportation System (ITS). Meanwhile, some promising accomplishments have also been made. However, the traditional intelligent traffic signal control system always collects and transmits vehicle information (e.g., vehicle location, speed, etc.) in the form of plaintext, which would result in the leakage of commuters' privacy. Privacy leaks cause unnecessary trouble for users. For example, the personal interests and health information of the commuter can be inferred based on the driving route of the vehicle, or receive harassment advertisements for surrounding services, etc. In this paper, we propose a privacy-preserving intelligent traffic light control (PTLC) system with Deep Q-network. To achieve practicality and confidentiality simultaneously, a series of secure and efficient interactive protocols is designed depending on additive secret sharing to perform the DQN. Moreover, the security of PTLC is testified, meanwhile, the system effectiveness, and the overall efficiency of PTLC is demonstrated through theoretical analysis and simulation experiments. Zuobin Ying, Shuanglong Cao, Shengmin Xu, Ximeng Liu, Maode Ma |
GLOBECOM | 5 |
| 2020 | FKR: An efficient authentication scheme for IEEE 802.11ah networks
Lyuye Zhang, Maode Ma |
Comput. Secur. | 2 |
| 2020 | Backtracking search algorithm with competitive learning for identification of unknown parameters of photovoltaic systems
Maode Ma, Zhigang Jin |
Expert Syst. Appl. | 2 |
| 2020 | Blockchain-based mobility management for 5G
Han Lee, Maode Ma |
Future Gener. Comput. Syst. | 2 |
| 2020 | Intelligent data fusion algorithm based on hybrid delay-aware adaptive clustering in wireless sensor networks
Xiaozhu Liu, Rongbo Zhu, Ashiq Anjum, Jun Wang 0027, Maode Ma |
Future Gener. Comput. Syst. | 6 |
| 2020 | Cognitive-inspired Computing: Advances and Novel Applications
Rongbo Zhu, Lu Liu 0001, Maode Ma |
Future Gener. Comput. Syst. | 3 |
| 2020 | DTLShps: SDN-Based DTLS Handshake Protocol Simplification for IoTabstractDatagram transport layer security (DTLS) protocol is widely used in Internet of Things (IoT) for providing security services. The computational overhead makes it hard to implement DTLS on resource-constrained IoT devices. The two significant costly computations in the DTLS handshake are the Diffie-Hellman (DH) key exchange and the certificate verification. A simplified handshake protocol of DTLS (DTLShps) is proposed to reduce the computational overhead of the IoT devices for a general scenario of end-to-end communications based on software-defined networking (SDN). First, a controller is utilized to generate a symmetric key dynamically, then encrypt and distribute this key to two communicating IoT devices. Second, the certificate verification is shifted from the IoT device to the more powerful controller. Third, the controller replaces the DTLS server to make a cookie exchange with the DTLS client. Furthermore, the BAN logic and the tool Scyther are used to validate the security of our scheme. The performance evaluation shows that not only the computational overhead and the energy consumption in the IoT devices are effectively decreased but also the overall duration of the whole handshake is reduced. Yan Ma 0003, Lei Yan 0006, Xiaohong Huang 0003, Maode Ma |
IEEE Internet Things J. | 4 |
| 2020 | WiDIGR: Direction-Independent Gait Recognition System Using Commercial Wi-Fi DevicesabstractGait recognition enables many potential applications requiring identification. Wi-Fi-based gait recognition is predominant because of its noninvasive and ubiquitous advantages. However, since the gait information changes with the walking direction, the existing Wi-Fi-based gait recognition systems require the subject to walk along a predetermined path. This direction dependence restriction impedes Wi-Fi-based gait recognition from being widely used. In order to address this issue, a direction-independent gait recognition system, called WiDIGR is proposed. WiDIGR can recognize a subject through the gait no matter what straight-line walking path it is. This relaxes the strict constraint of the other Wi-Fi-based gait recognition. Specifically, based on the Fresnel model, a series of signal processing techniques are proposed to eliminate the differences among induced signals caused by walking in different directions and generate a high-quality direction-independent signal spectrogram. Furthermore, effective features are extracted both manually and automatically from the direction-independent spectrogram. The experimental results in a typical indoor environment demonstrate the superior performance of WiDIGR, with mean accuracy ranging from 78.28% for a group of six subjects to 92.83% for a group of three. Lei Zhang 0024, Cong Wang 0017, Maode Ma, Daqing Zhang 0001 |
IEEE Internet Things J. | 3 |
| 2020 | Multi-access edge computing enabled internet of things: advances and novel applications
Rongbo Zhu, Lu Liu 0001, Houbing Song, Maode Ma |
Neural Comput. Appl. | 4 |
| 2020 | A Secure Group-Oriented Device-to-Device Authentication Protocol for 5G Wireless NetworksabstractWith the rising demand for the digital world and the emergence of new application scenarios, 5G wireless networks have become the key enabler of a new era. As one of the promising technologies, group-oriented device-to-device (D2D) communications are expected to improve spectral efficiency and reduce latency. However, to negotiate a group session key securely and effectively has become an urgent problem. In this paper, we propose an authentication and key agreement protocol, which merges the advantages of certificateless public key cryptography (CL-PKC) and elliptic curve cryptography (ECC), to guarantee secure and anonymous D2D group communications in 5G cellular networks. The security evaluation by using the Burrows-Abadi-Needham logic (BAN Logic) and the Automated Validation of Internet Security Protocols and Applications (AVISPA) shows that the security goal can be achieved. Furthermore, based on extensive simulation experiments, we evaluate the performance of the proposed solution in terms of computational costs, communication costs, and energy costs. The results demonstrate that the proposal is lightweight and efficient. Zhengyi Shang, Maode Ma, Xiaohong Li 0001 |
IEEE Trans. Wirel. Commun. | 2 |
| 2020 | BEHT: Blockchain-Based Efficient Highway Toll Paradigm for Opportunistic Autonomous Vehicle PlatoonabstractAutonomous vehicle platoon is a promising paradigm towards traffic congestion problems in the intelligent transportation system. However, under certain circumstances, the advantage of the platoon cannot be fully developed. In this paper, we focus on the highway Electronic Toll Collection (ETC) charging problem. We try to let the opportunistic platoon pass the ETC as a whole. There are three main issues in this scenario. Firstly, the opportunistic platoon is temporarily composed; vehicles do not trust each other. Secondly, single vehicle may try to escape from the ETC charging by following the platoon. Finally, platoon members may collude with each other and try to underreport the number of vehicles in the platoon so as to evade payment. To solve these challenges, we propose a blockchain-based efficient highway toll paradigm for the opportunistic platoon. The driving history, credential information of every registered vehicle, is recorded and verified from the blockchain. A roadside unit (RSU) is adopted to distinguish the single vehicle from the platoon and in charge of lane allocation. Additionally, an aggregate signature is introduced to accelerate the authentication procedure in the RSU. We analyse the potential security threats in this scenario. The experimental result indicates that our scheme is efficient and practical. Zuobin Ying, Longyang Yi, Maode Ma |
Wirel. Commun. Mob. Comput. | 3 |
| 2019 | A Certificateless Authentication Protocol for D2D Group Communications in 5G Cellular NetworksabstractWith the rising demand for digital world and the emergence of new application scenarios, 5G wireless networks have become the key enabler of a new era. As one of the promising technologies, device-to-device (D2D) group communications are expected to improve spectral efficiency and reduce latency. However, to negotiate a group session key securely and effectively has become an urgent problem. In this paper, we propose a certificateless authentication and key agreement protocol using elliptic curve cryptosystem (ECC) and digital signature to guarantee secure and anonymous D2D group communications in 5G cellular networks. The security analysis based on the formal verification by using the Automated Validation of Internet Security Protocols and Applications (AVISPA) shows that the security goal can be achieved. Furthermore, we evaluate the performance of the proposed solution in terms of computation and communication costs based on extensive simulation experiments. The results demonstrate that our proposal is lightweight and efficient. Zhengyi Shang, Maode Ma, Xiaohong Li 0001 |
GLOBECOM | 2 |
| 2019 | Privacy-Preserving Fine-Grained Outsourcing PHR with Efficient Policy Updating
Zuobin Ying, Ximeng Liu, Maode Ma |
ICA3PP (2) | 4 |
| 2019 | Information-Theoretic Ensemble Learning for DDoS Detection with Adaptive BoostingabstractDDoS (Distributed Denial of Service) attacks pose a serious threat to the Internet as they use large numbers of zombie hosts to forward massive numbers of packets to the target host. Here, we present an adaptive boosting-based ensemble learning model for detecting low-and high-rate DDoS attacks by combining information divergence measures. Our model is trained against a baseline model that does not use labeled traffic data and draws on multiple baseline models developed in parallel to improve its accuracy. Incoming traffic is sampled time-periodically to characterize the normal behavior of input traffic. The model's performance is evaluated using the UmU testbed, MIT legitimate, and CAIDA DDoS datasets. We demonstrate that our model offers superior accuracy to established alternatives, reducing the incidence of false alarms and achieving an F1-score that is around 3% better than those of current state-of-the-art DDoS detection models. Monowar Bhuyan, Maode Ma, Youki Kadobayashi, Erik Elmroth |
ICTAI | 2 |
| 2019 | An Efficient Handover Authentication Mechanism for 5G Wireless NetworkabstractIn an ultra-dense fifth-generation (5G) wireless network, the deployment of dense cells with a large number of base stations can cause frequent handovers, which could lead to higher handover delays and some security issues to make the network difficult to meet various requirements of 5G wireless networks. To target this problem, we propose to employ Mobile Edge Computing (MEC) servers into the traditional authentication architecture for re-authentication. Moreover, we improve the existing Extensible Authentication Protocol-Authentication and Key Agreement (EAP-AKA) protocol to design a new authentication mechanism over this authentication architecture. To enhance security functionality, pseudonyms are used instead of permanent names and a one-way hash function is used for the authentication. The results of formal verification and performance evaluation show that the proposed handover authentication mechanism can reduce the authentication delays and ensuring the security of the proposed handover authentication scheme. Kaihong Han, Maode Ma, Xiaohong Li 0001, Zhiyong Feng 0002, Jianye Hao |
WCNC | 2 |
| 2019 | CETVSP: Cost Efficient Trust-Based Vehicle Selection for PlatoonabstractThe vehicular ad hoc networks (VANETs) are increasingly progressing towards advancement to provide a more comfortable and sophisticated experience to users. Platooning is one of such examples in the pool of these advancements where a lead vehicle provides the driving parameters wirelessly to the vehicles following it so that they have a more comfortable and quality experience on the road. However, since the lead vehicle has so much control, ensuring the trustworthy behavior of the lead vehicle is critical. Our scheme, Cost Efficient Trust-Based Vehicle Selection for Platoon (CETVSP), ensures that capability by granting each lead vehicle with a trust score. The same trust model has also been expanded to be applied to selection of a reliable vehicle if the message has to be relayed through it. This only requires a small modification and hence reduces redundancy. Our simulation results show that our scheme is more efficient while requiring less computational expense. The security analysis proves that the scheme is safe against user attacks such as badmouthing and on-off attacks. Gurbakshish Singh Toor, Maode Ma |
WCNC | 2 |
| 2019 | Quantum-Resistance Authentication and Data Transmission Scheme for NB-IoT in 3GPP 5G NetworksabstractThe Narrow Band Internet of Things (NB-IoT) system has become an important branch of the Internet of Everything and is an indispensable part in future fifth Generation (5G) network. However, there is currently no effective access authentication scheme for the NB-IoT system in the future 5G network. According to the current 3GPP standard, NB-IoT devices still use the traditional access authentication method to perform the mutual authentication with the network, which may bring a lot of signaling and communication overheads. This problem will be more prominent when sea of NB-IoT devices simultaneously are activated in the 5G network. In this paper, we propose a quantum-resistance access authentication and data distribution scheme for massive NB-IoT devices. This scheme can implement access authentication and data transmission for a group of NB-IoT devices at the same time based on the lattice-based homomorphic encryption technology. Our scheme can not only greatly reduce the network burden, but also can achieve the strong security including privacy protection and resisting quantum attacks. Performance analysis results show that our solution has the desired efficiency. Pu Yu, Jin Cao 0001, Maode Ma, Hui Li 0006, Ben Niu 0001, Fenghua Li 0001 |
WCNC | 3 |
| 2019 | Secure and Efficient Fast Initial Link Setup Scheme DesignabstractWith the increasing demands for fast and secure wireless link connections to the access points (APs) supporting large quantities of devices in wireless local networks (WLANs), Fast Initial Link Setup (FILS) has been proposed. It is the initial link setup mechanism specified in IEEE 802.11ai, which is a new amendment to IEEE 802.11 standard family to support massively deployed wireless nodes. However, security concerns on the link connection have not been fully eliminated, especially for the authentication process. For example, a type of recently revealed malicious attack, Key Reinstallation Attack (KRA) might be a threat to the FILS authentication. To prevent the success of the KRAs, in this paper, we propose a Secure and Efficient FILS (SEF) protocol as its optional substitute. The SEF is designed to eradicate potential threats from the KRAs without degrading the network performance. Lyuye Zhang, Maode Ma |
WCNC | 2 |
| 2019 | Connectivity aware tribrid routing framework for a generalized software defined vehicular networkabstractData dissemination is a fundamental, yet one of the pressing issues in vehicular communication due to the associated high dynamicity. The vehicular network topology frequently keeps changing, limiting the lifetime of the links. This imposes serious difficulties in data transmission, especially in multi-hop applications as the vulnerability escalates when the packets are transmitted over multiple hops. The broadcasting based Vehicular Ad-hoc Network (VANET) routing protocols struggle to cope with this dilemma due to the lack of global network information. But, with novel Software Defined Vehicular Network (SDVN), link stability can be better scrutinized pertaining to the availability of global network view . Yet, the architectural challenges in SDVN can limit the availability of network information confining the empowerment of Software Defined Networking (SDN). Thus, in this paper, we introduce a link connectivity aware novel routing framework for a general SDVN acknowledging the limitations in data availability as well. The routing protocol comprises of both centralized and distributed routing techniques and makes use of unicast , broadcast, and store, carry and forward concepts. The resulting tribrid routing framework focuses on finding stable enough shortest routes that can deliver a given set of packets satisfying the required Quality of Services (QoSs) in terms of latency. In case of network uncertainties, the protocol incorporates broadcasting based distributed techniques along with unicast routing . In sparse network conditions, the model aims to deliver the packets in the optimal path with the least store and carry time within the QoS requirement. The routing protocol follows an incremental algorithm where extracted paths are tested for the feasibility on a case by case basis. Kushan Sudheera Kalupahana Liyanage, Maode Ma, Peter Han Joo Chong |
Comput. Networks | 2 |
| 2019 | A privacy-preserving sensory data sharing scheme in Internet of Vehicles
Qinglei Kong, Rongxing Lu, Maode Ma, Haiyong Bao |
Future Gener. Comput. Syst. | 3 |
| 2019 | Fast Authentication and Data Transfer Scheme for Massive NB-IoT Devices in 3GPP 5G NetworkabstractThe emergence of narrowband Internet of Things (NB-IoT) has brought hope for the popularization and application of mobile Internet standards. Nowadays, NB-IoT technology has been introduced into the Third Generation Partnership Project (3GPP) standards, where low-overhead, low-data-transmission IoT devices can securely access the fifth generation (5G) core network through the 3GPP access network. However, according to the current 3GPP standard, these NB-IoT devices still employ the traditional authentication process of normal user equipment to implement mutual authentication between NB-IoT devices and 5G core networks, which brings a lot of communication and storage overhead, and it will be more serious when lots of NB-IoT devices are activated simultaneously. In this paper, we propose a fast mutual authentication and data transfer scheme for massive NB-IoT devices, which integrates the access authentication and secure data transmission process and achieves the authentications and data transmissions of a group of NB-IoT devices at the same time. Our scheme can not only greatly simplify the authentication process and alleviate the load of the networks but also ensure robust security protection including user anonymity and nonrepudiation. The performance analysis results show that the proposed scheme can withstand a variety of security attacks with ideal efficiency. Jin Cao 0001, Pu Yu, Maode Ma, Weifeng Gao |
IEEE Internet Things J. | 3 |
| 2019 | Anti-Quantum Fast Authentication and Data Transmission Scheme for Massive Devices in 5G NB-IoT SystemabstractThe narrowband Internet of Things (NB-IoT) system has become an integral part of the future fifth generation (5G) network. Although the NB-IoT system has gradually been improved in the traditional LTE network currently, the NB-IoT system does not have an effective access authentication scheme in the future 5G network. According to the current 3rd Generation Partnership Project (3GPP) standard, NB-IoT devices still use the traditional access authentication method to perform mutual authentication with the network, which may bring a large amount of signaling and communication overhead. This problem will be magnified in a large-scale device environment in the future 5G network. In this article, a quantum resistance access authentication and data distribution scheme is proposed for large-scale NB-IoT devices. The scheme can simultaneously implement access authentication and data transmission of a group of NB-IoT devices based on the lattice-based homomorphic encryption technology. Our scheme not only greatly reduce the network burden but also achieve strong security, including privacy protection and anti-quantum attacks. The performance analysis results show that our scheme has the ideal efficiency. Jin Cao 0001, Pu Yu, Xinyin Xiang, Maode Ma, Hui Li 0006 |
IEEE Internet Things J. | 4 |
| 2019 | A filter model for intrusion detection system in Vehicle Ad Hoc Networks: A hidden Markov methodology
Junwei Liang 0004, Maode Ma, Muhammad Sadiq, Alan Kai-Hau Yeung |
Knowl. Based Syst. | 2 |
| 2019 | Centroid opposition with a two-point full crossover for the partially attracted firefly algorithm
Maode Ma, Lixin Ding, Wan Tang |
Soft Comput. | 2 |
| 2019 | Fog-Based Pub/Sub Index With Boolean Expressions in the Internet of Industrial VehiclesabstractStructured publish/subscribe (pub/sub) is a promising technique adopted on kinds of vehicle applications of Internet of industrial vehicles (IoIV), which uses Boolean expressions to capture the items with thousands of different attributes, values and spatial locations, and then processes and analyzes the vast amounts of data collected to obtain users' interests. However, existing pub/sub work with Boolean expressions either ignores spatial requirement or focuses on Euclidean space. This paper aims to fill this gap by addressing the issue of fog-based spatial-textual pub/sub problem with Boolean expressions in IoIV. A novel hybrid index called RnetBE is proposed, which exquisitely organizes traffic network structure, Boolean expressions, and spatial information of subscriptions. And RnetBE can prune huge numbers of unqualified subscriptions based on both spatial constraint and Boolean expressions, thus achieving high efficiency in indexing and matching. Moreover, range-tree deletion and orderly group processing optimization techniques are proposed to save storage space and further improve the subscription pruning efficiency. Simulation results show that RnetBE and the proposed algorithm are efficient in terms of memory consumption and matching time. Wang Zhang 0002, Rongbo Zhu, Guohui Li 0001, Maode Ma, LihChyun Shu, Changyin Luo |
IEEE Trans. Ind. Informatics | 5 |
| 2018 | A Privacy-Preserving Proximity Testing for Location-Based ServicesabstractLocation-based service (LBS) applications have become increasingly popular in the past few years. These applications request users' mobile devices to provide location data in terms of a mobile user's position, movement direction, and speed. The proximity testing, as a core application of Location-based services in social networking, enables a user to know whether people are within a given geometric range. However, private location data may be leaked due to the lack of corresponding privacy protection mechanism, which could result in serious security issues. To protect users' confidential location data, a privacy-preserving proximity testing (PPPT) using location grids is designed to improve the efficiency while protecting users' location privacy. The proposed scheme can test whether a person is within a given search area without the disclosure of any private location information. The security analysis and the performance evaluation results show that the proposed PPPT scheme is not only privacy-preserving, but also more efficient. Yue Qiu 0004, Maode Ma |
GLOBECOM | 2 |
| 2018 | A Weighted Context Graph Model for Fast Data Leak DetectionabstractData leakage prevention (DLP) uses a series of techniques to detect and prevent the sensitive data leakage caused by insider threat. Current detection methods either fail to achieve high accuracy toward transformed data or fail to reduce computational complexity. To ensure high detection accuracy and reduce computational complexity, we propose a Weighted Context Graph Model (WCGM) in this paper. The main goal of WCGM is three folds. First, the weighted context graph is proposed to build the contextual relation of data, based on which sub-graph matching method is used to calculate similarity features between tested data and pre-defined template. Second, machine learning algorithms are used to classify the tested data based on the similarity features of its context graphs. Third, privacy- preserving graph masking method is proposed to protect the data privacy of data holders. Extensive simulation results show that the proposed WCGM is able to achieve significant enhancement in terms of running time and accuracy. Xiaohong Huang 0003, Yan Ma 0003, Maode Ma |
ICC | 4 |
| 2018 | Link Stability Based Hybrid Routing Protocol for Software Defined Vehicular NetworksabstractThe dynamic nature of vehicular networks imposes a lot of challenges in multi-hop data transmission as links are vulnerable in their existence. Thus, the packets frequently find it difficult to get through to the destination as links only exist for a limited amount of time. The broadcasting based conventional routing protocols struggle to cope with these situations due to the lack of global network information. But, with the novel Software Defined Vehicular Network (SDVN) architecture, link stability can be better scrutinized pertaining to the availability of global network view. However, due to the imperfections in the SDVN architectures and dynamicity in vehicular networks, the control plane may not possess all the network information at a given point in time. Considering all these factors, in this paper, we introduce a novel routing framework for SDVN which is composed of both centralized and distributed routing mechanisms. The resulting hybrid routing framework focuses on finding stable multiple short routes that can deliver a given number of packets, and in case of uncertain network conditions, a broadcasting approach is adopted. The overall problem is formulated as a minimum cost capacitated flow problem and the effectiveness is demonstrated comparatively via extensive simulations. Kushan Sudheera Kalupahana Liyanage, Maode Ma, Peter Han Joo Chong |
ICC | 2 |
| 2018 | Balance-Based SDN Controller Placement and Assignment with Minimum Weight MatchingabstractGiven a software defined wide-area network (WAN), how to choose location of controllers and how to assign the controllers to forwarding devices are two significant issues. Previously, most of solutions to these two problems focus on the propagation delay but ignore the balance of controllers, because it's difficult to solve them with consideration of balance of controllers. In this paper, a novel approach which can efficiently and accurately solve SDN controller placement problem and assignment problem for WAN is proposed. The SDN controller assignment problem is formulated as a minimum weight matching of bipartite graph, and it also considers the balance of controllers. The Kuhn- Munkres algorithm based solution is used to find optimal matching between switches and controllers. Then, a genetic algorithm is proposed to solve the controller placement problem based on the controller assignment scheme. The performance shows that our approach has good performance in reducing the average propagation delay between SDN forwarding devices and controllers, and it also achieves better balance of controllers. Tingting Yuan 0001, Xiaohong Huang 0003, Maode Ma, Jie Yuan 0001 |
ICC | 3 |
| 2018 | Modeling and analysis on double-tiered device-to-device communications in vehicle networksabstractIn vehicle networks, how to implement V2V (vehicle-to-vehicle) communications is always one hot issue, because of the structure which is similar to D2D communications proposed by cellular networks, we try to achieve an efficient V2V communication model through D2D techniques. In this paper, we propose a double-tiered D2D communication mode with the ratio coefficient of interference distance. The Tier-I of mode accomplishes the pairing among D2D terminals based on Voronoi diagram, and the Tier-II of mode achieves the shared channel selections as many as possible. According to the description of hypergraph geometry structure to the double-tiered D2D pairing algorithm, and the algorithm is split into two sub-problems, which refer to both bipartite graph and Voronoi diagram match under the constraint of SINR. According to the convergence of match between ratio factors introduced in the double-tiered mode, the double-tiered mode can be proved to be an optimal mode of channel reusing. Finally, we perform computer simulations to verify the performance based on the double-tiered D2D communication mode, and results indicate that the proposed mode possesses better performance compared with the spectrum sharing D2D communication mode. Chun-Peng Liu, Maode Ma, Weixiao Meng 0001 |
WCNC | 2 |
| 2018 | Controller placement optimization in hierarchical distributed software defined vehicular networksabstractRecently, a new paradigm has emerged, named as Software Defined Vehicular Network (SDVN) which applies the concept of Software Defined Networking (SDN) in Vehicular Ad-hoc Network (VANET), to overcome the shortcomings in vehicular networks. With the introduction of SDN, VANET has been provided with flexibility and programmability along with a performance improvement . However, the improvement comes at a cost of higher operational delay because, the controllers are placed far away from the data plane in the existing SDVN architectures . As an alternative, we have previously proposed to bring the control plane down to Road Side Unit (RSU). In this study, we further extend this work and introduce a hierarchical distributed controller architecture where the top tier of controllers are regionally distributed on the Internet and the bottom tier of controllers are placed in several selected RSUs closer to the vehicles so that the latency induced by the system becomes low. We further present a novel controller placement model for the RSU level controllers based on the p-median facility location problem with the delay and the significance of the RSU location as the factors to achieve the optimization heuristically as an integer quadratic programming problem . With the help of the simulation results, we show that our proposed controller placement model can optimize the placements of controllers with a lower latency compared to other possible controller placement methods including the existing SDVN architectures and conventional VANETs. Kushan Sudheera Kalupahana Liyanage, Maode Ma, Peter Han Joo Chong |
Comput. Networks | 2 |
| 2018 | Improving Quality of Experience in multimedia Internet of Things leveraging machine learning on big data
Xiaohong Huang 0003, Kun Xie 0003, Supeng Leng, Tingting Yuan 0001, Maode Ma |
Future Gener. Comput. Syst. | 5 |
| 2018 | Secure Group Mobility Support for 6LoWPAN NetworksabstractThe Internet Protocol version 6 (IPv6) over low power wireless personal area networks (6LoWPANs) has introduced IP technologies to wireless sensor networks, which significantly promotes the development of the Internet of Things. To support effective mobility management of these resource constrained IP-based sensor nodes, the Proxy Mobile IPv6 has been proposed as a standard to minimize the communication over-head of those nodes. Although the standard has specified some issues of security and mobility in 6LoWPANs, the issues of supporting secure group handovers have not been addressed much by the currently existing solutions. To further reduce the handover latency and signaling overhead, a fast group authentication scheme is proposed in this paper to support secure and seamless handovers for multiple resource constrained 6LoWPAN devices. With the consideration of mobile sensors with limited energy, only simple hash functions and symmetric encryption algorithms are used. The security analysis and the performance evaluation show that the proposed 6LoWPAN group handover scheme could enhance the security functionalities with high efficiency to achieve a fast authentication for handovers. Yue Qiu 0004, Maode Ma |
IEEE Internet Things J. | 2 |
| 2018 | EGHR: Efficient group-based handover authentication protocols for mMTC in 5G wireless networks
Jin Cao 0001, Maode Ma, Hui Li 0006, Xuefeng Liu 0002 |
J. Netw. Comput. Appl. | 2 |
| 2018 | UPPGHA: Uniform Privacy Preservation Group Handover Authentication Mechanism for mMTC in LTE-A NetworksabstractMachine Type Communication (MTC), as one of the most important wireless communication technologies in the future wireless communication, has become the new business growth point of mobile communication network. It is a key point to achieve seamless handovers within Evolved-Universal Terrestrial Radio Access Network (E-UTRAN) for massive MTC (mMTC) devices in order to support mobility in the Long Term Evolution-Advanced (LTE-A) networks. When mMTC devices simultaneously roam from a base station to a new base station, the current handover mechanisms suggested by the Third-Generation Partnership Project (3GPP) require several handover signaling interactions, which could cause the signaling load over the access network and the core network. Besides, several distinct handover procedures are proposed for different mobility scenarios, which will increase the system complexity. In this paper, we propose a simple and secure uniform group-based handover authentication scheme for mMTC devices based on the multisignature and aggregate message authentication code (AMAC) techniques, which is to fit in with all of the mobility scenarios in the LTE-A networks. Compared with the current 3GPP standards, our scheme can achieve a simple authentication process with robust security protection including privacy preservation and thus avoid signaling congestion. The correctness of the proposed group handover authentication protocol is formally proved in the Canetti-Krawczyk (CK) model and verified based on the AVISPA and SPAN. Jin Cao 0001, Hui Li 0006, Maode Ma, Fenghua Li 0001 |
Secur. Commun. Networks | 3 |
| 2018 | An Anonymous Handover Authentication Scheme Based on LTE-A for Vehicular NetworksabstractVehicular networks play an important role in the intelligent transportation systems which have gained technical supports from car industry. Due to the mobility and the broadcast nature of wireless communication, security of the vehicular networks is a critical issue for the academia and industry. Many solutions have been proposed to target the security provisioning. However, most of them have various shortcomings. Based on the elliptic curve public key cryptography algorithm, in this paper, we propose a new anonymous roaming authentication protocol for the Long Term Evolution‐Advanced (LTE‐A) supported vehicular networks. For a vehicular LTE‐A network, an authentication protocol should be able to fulfill a variety of security requirements, which can be met by our proposal and proved by using Burrows–Abadi–Needham (BAN) logic. Compared with some existing solutions, our scheme has lower communication costs with stronger security functionality. The analyses on the security functions and the performance of the proposed solution show that our scheme is secure and efficient with ability against various types of malicious attacks. Cheng Xu 0005, Xiaohong Huang 0003, Maode Ma, Hong Bao |
Wirel. Commun. Mob. Comput. | 3 |
| 2017 | DC and CoMP Authentication in LTE-Advanced 5G HetNetabstractUse of Heterogeneous networks is essential to achieve the goal of 5G networks. In 5G LTE- Advanced HetNet, latency requirements make secure authentication and key establishment challenging. Dual Connectivity and Coordinated Multi Point are key technologies for LTE-Advanced HetNet. They require performing multiple authentications with low latency. We propose a scheme which uses software-defined networking architecture and creates a Merkle-Tree for fast authentication and key establishment. Furthermore, it can fulfill 5G latency requirements. We present a formal proof of logic correctness and performance analysis with existing schemes. Compared with existing methods our scheme can reduce communication, computation and energy cost. M. Jawad Alam, Maode Ma |
GLOBECOM | 2 |
| 2017 | Utility-Based Network Bandwidth Allocation in the Hybrid SDNsabstractSoftware Defined Networking (SDN) provides flexible and convenient means to support fine-grained management by the logically centralized control. Thus SDN can not only result in better network capacity utilization but can offer better customer satisfaction. In this paper, we analyze and consolidate the utility theory of network bandwidth allocation to offer better customers' satisfaction in SDNs especially when SDNs are incrementally introduced into an existing network. The utilities are modeled as sigmoid curves, since they are well-known functions and often used to describe the perception of Quality of Service (QoS). We propose an optimization bandwidth allocation strategy to maximize the network utility and thus increase the customer satisfaction. The results show that the network utility based on customer satisfaction improvements are possible with proper bandwidth allocation even only a part of SDN forwarding devices in a network topology. Compared with other bandwidth allocation strategies based on fairness, our strategy is more efficient in fulfilling the basic demand of customers. Xiaohong Huang 0003, Tingting Yuan 0001, Maode Ma, Pei Zhang 0003 |
GLOBECOM | 3 |
| 2017 | Link Dynamics Based Packet Routing Framework for Software Defined Vehicular NetworksabstractData transmission in vehicular networks suffers heavily from its inherent dynamic nature as the connections between vehicles exist only for a limited amount of time. Therefore, the packets frequently find it hard to get through to the destination in multi hop data transmission as links are vulnerable in their existence. Conventional Vehicular Ad-hoc Network (VANET) routing protocols struggle in this sense, as they do not have a global network view to tackle these scenarios. But Software Defined Networking (SDN) fills this gap in VANET, and the packets can be routed better by coping with the dynamic nature of the network more effectively. However, existing routing schemes in Software Defined Vehicular Networks (SDVN) have utilized this advantage only in finding the shortest path. As an alternative, we introduce a novel packet routing framework which scrutinizes the dynamic nature of wireless links. Rather than just focusing on the shortest path, we also bring the focus to the stability of the route in finding the optimal paths. Thus, we formulate the packet routing problem as a minimum cost capacitated flow problem and find multiple paths which are stable enough to deliver a given number of packets successfully. Kushan Sudheera Kalupahana Liyanage, Maode Ma, Peter Han Joo Chong |
GLOBECOM | 2 |
| 2017 | An Efficient EAP-Based Pre-Authentication Scheme for Handovers in WRANs over TVWSabstractA whole extensible authentication protocol (EAP)-based authentication scheme is time-consuming due to the operations of public key cryptography and validation of certificates which is unacceptable for the wireless regional area networks (WRANs) handover. In this paper, an EAP-based pre-authentication scheme for WRANs handover (EPH) over TV white space is proposed. By applying the proposed pre-authentication scheme, the customer premises equipment and the target secondary user base station can accomplish a seamless handover using a symmetric key. Approved by the logic derivation by Burrows, Abadi, and Needham (BAN) logic, we conclude that the proposed EPH scheme can obtain mutual authentication and hold key secrecy. Additionally, the performance of the EPH scheme has been investigated by simulation experiments with the results showing that the EPH scheme is much more efficient in terms of lower computation delay required than the security scheme regulated in IEEE 802.22 standard. Cong Wang 0004, Maode Ma, Zenghua Zhao |
GLOBECOM | 2 |
| 2017 | Trajectory prediction-based handover authentication mechanism for mobile relays in LTE-A high-speed rail networksabstractThe handover mechanism with the assist of mobile relay mounted in high-speed trains has been researched to support continuous communication services for Long-Term Evolution Advanced (LTE-A) high-speed rail networks. According to the third Generation Partnership Project (3GPP) standard, the handover process for Mobile Relay Nodes (MRNs) from a donor eNB (DeNB) to another is the same as that for the common User Equipment (UE), which requires several rounds of message exchange with a complex key management mechanism. In addition, it cannot achieve the mutual authentication in handover procedures. In this paper, we propose a handover authentication mechanism based on trajectory prediction for mobile relays. In our scheme, the mutual authentication and key agreement between a MRN and the target DeNB is accomplished with ideal efficiency. Compared with the current 3GPP standards and other related schemes, our scheme effectively reduces the handover delays and at the same time provides strong security protection. Security analysis by using the formal verification tool AVISPA and SPAN and performance evaluation results show the security and efficiency of our scheme. Jin Cao 0001, Maode Ma, Hui Li 0006, Ben Niu 0001, Fenghua Li 0001 |
ICC | 2 |
| 2017 | A secure PMIPv6-based group mobility scheme for 6L0WPAN networksabstractThe Internet Protocol version 6 (IPv6) over Low Power Wireless Personal Area Networks (6LoWPAN), which is a promising technology to promote the development of the Internet of Things (IoT), has been proposed to connect millions of IP-based sensing devices over the open Internet. To support the mobility of these resource constrained sensing nodes, the Proxy Mobile IPv6 (PMIPv6) has been proposed as the standard. Although the standard has specified some issues of security and mobility in 6LoWPANs, the issues of supporting secure group handovers have not been addressed much by the current existing solutions. In this paper, to reduce the handover latency and signaling cost, an efficient and secure group mobility scheme is designed to support seamless handovers for a group of resource constrained 6LoWPAN devices. With the consideration of the devices holding limited energy capacities, only simple hash and symmetric encryption method is used. The security analysis and the performance evaluation results show that the proposed 6LoWPAN group handover scheme could not only enhance the security functionalities but also support fast authentication for handovers. Yue Qiu 0004, Maode Ma |
ICC | 2 |
| 2017 | Achieving Secure CoMP Joint Transmission Handover in LTE-A Vehicular NetworksabstractIn the duration of handover, coordinated multipoint (CoMP) joint transmission can help not only improve the throughput but also reduce the interference at cell edges. However, the current secure handover key management scheme in LTE-A system has not yet supported the CoMP joint transmission handover. Therefore, to solve the problem, in this paper, we present a novel secure CoMP joint transmission handover key management scheme in LTE-A vehicular networks. Specifically, to achieve the diversity gain brought by the CoMP joint transmission and accommodate to protect the backward/forward key separation, the session key is generated by the vehicle and securely delivered towards the cooperating eNBs, and then decrypted by each cooperating eNB respectively. Security analysis shows that the proposed scheme can successfully establish session keys with the cooperating eNBs during the CoMP joint transmission handover with backward/forward key separation. In addition, performance evaluation is conducted to demonstrate the feasibility of the proposed scheme. Qinglei Kong, Maode Ma, Rongxing Lu |
VTC Fall | 2 |
| 2017 | Efficient Flow Instantiation via Source Routing in Software Defined Vehicular NetworksabstractSoftware Defined Vehicular Networks (SDVN) brings a set of attractive features to vehicular networks along with an upgrade in the performance. Yet, SDVN suffers from frequently compelling to contact the centralized control plane, which in turn generates a high latency and packet overhead in the communication. The current solution to reduce the delay, proactive approach, does not bring the packet overhead down and impose a lot of stress on the controller with a decline of Packet Delivery Ratio (PDR). As an alternative, we introduce a source routing based flow instantiation operation with intelligent route caching that reduces the extent of communication with the control plane, but still manages to utilize the knowledge of controller while maintaining a lower latency and packet overhead. Kushan Sudheera Kalupahana Liyanage, Maode Ma, Peter Han Joo Chong |
VTC Fall | 2 |
| 2017 | An anonymous authentication scheme for multi-domain machine-to-machine communication in cyber-physical systems
Yue Qiu 0004, Maode Ma |
Comput. Networks | 2 |
| 2017 | A proxy signature-based handover authentication scheme for LTE wireless networksabstractA seamless and secure handover is always one of the important design goals of the cellular networks . The handover scheme of 4G Long Term Evolution (LTE) wireless networks is complex due to the presence of two possible different types of base stations . In LTE communication systems , a normal base station is referred to as an eNodeB (eNB). What increases the level of complexity of the system is the fact that the other kind of base stations, namely, Home eNodeB (HeNB), cannot directly communicate with eNB. In the LTE networks , the handover scenarios involving a HeNB could result in a complicated handover procedure . Besides, since key chains have been used in the handover processes , it is found to be lack of backward security. Therefore, in order to handle the handover involving a HeNB efficiently with security provisioning, in this paper, a proxy signature-based handover scheme is proposed. The proposed scheme works based on the Elliptic Curve Cryptography (ECC) algorithm, which makes the computational cost of the handover process smaller compared to other handover schemes. Yue Qiu 0004, Maode Ma, Xilei Wang |
J. Netw. Comput. Appl. | 2 |
| 2017 | Design of a novel dynamic trust model for spectrum management in WRANs of TV white space
Cong Wang 0004, Maode Ma, Zenghua Zhao |
J. Netw. Comput. Appl. | 2 |
| 2017 | Optimal Relay Node Placement and Flow Allocation in Underwater Acoustic Sensor NetworksabstractIn recent years, underwater acoustic sensor networks (UASNs) have attracted widespread attention in academia. Prolonging the network lifetime is a crucial issue for UASNs. Compared with traditional wireless sensor networks (WSNs), stringent energy becomes more critical in UASNs because the battery equipped at sensor nodes has the limited amount of energy and it is much more difficult to replace or recharge in underwater circumstance. This fact motivates us to pursue the solutions to reduce power consumption by using relay nodes and flow allocation mechanism in order to extend the network lifetime. In this paper, the issues of relay node placement and the flow allocation have been considered as a joint problem and are formulated into an integer nonlinear programming problem, which is node placement-hard in general. To solve the problem efficiently, this paper proposes a novel heuristic scheme for UASNs, which works based on a 3-D architecture. The proposed scheme consists of three algorithms, named as Alternative Flow and Relay-node Adjustment as a whole. Extensive simulation experiments demonstrate that the proposed scheme offers a simple yet attractive solution to the problem. Maode Ma, Chunfeng Liu 0001, Yantai Shu |
IEEE Trans. Commun. | 2 |
| 2017 | Near-Optimal Cross-Layer Forward Error Correction Using Raptor and RCPC Codes for Prioritized Video Transmission Over Wireless ChannelsabstractCross-layer forward error correction (FEC) aims at utilizing available bandwidth more efficiently, which has been applied to error-prone video transmission over imperfect wireless channels. In this paper we propose a new near-optimal cross-layer FEC scheme in which systematic Raptor codes are used at the application layer and rate compatible punctured convolutional (RCPC) codes are used at the physical layer for H.264/AVC encoded video streaming with channel bandwidth constraints. In the proposed scheme, in order to fully exploit the unequal importance of compressed video data, we assign each source packet a different priority according to its contribution to the reconstructed video quality. We first obtain the transmission parameters, which satisfies the conditions for optimal video transmission, for the optimal cross-layer Raptor-RCPC FEC in the ideal situation through a theoretical analysis, and then we propose a heuristic algorithm searching from the optimal solution point to obtain the transmission parameters, which are near optimal in the practical situation. Computer simulation results show that the proposed scheme can achieve significant performance improvements in both the additive white Gaussian noise and Rayleigh channels compared with the previous work. Yonghong Hou, Wei Xiang 0001, Maode Ma, Jianjun Lei 0001 |
IEEE Trans. Circuits Syst. Video Technol. | 4 |
| 2017 | Resource management for symmetrical applications over heterogeneous services in IEEE 802.16
Wee Kiat New, Chee Onn Chow, Maode Ma |
Wirel. Networks | 3 |
| 2016 | A PMIPv6-Based Secured Mobility Scheme for 6LoWPANabstractIn order to promote the development of the IoT, the Internet Engineering Task Force (IETF) has been developing a standard named Internet Protocol Version 6 (IPv6) over Low Power Wireless Personal Area Networks (6LoWPAN) to enable IP-based devices to connect to the Internet. Besides, to support mobility management, a network-based localized mobility management (NETLMM) protocol named Proxy Mobile IPv6 (PMIPv6) is proposed. Although the 6LoWPAN standard has specified the important issues, some security and mobility issues have not been addressed. In this paper, a secure PMIPv6-based mobility scheme is designed. The proposed scheme enables a 6LoWPAN device to efficiently and securely roam in the 6LoWPAN networks. The formal verification by the Automated Validation of Internet Security Protocols and Applications (AVISPA) and the simulation by JAVA show that the proposed scheme in 6LoWPAN could efficiently enhance the security functionalities to prevent various malicious attacks with less computational cost. Yue Qiu 0004, Maode Ma |
GLOBECOM | 2 |
| 2016 | Parameter estimation of inverse Gaussian channel for diffusion-based molecular communicationabstractMolecular communication is a very promising research field. It has a broad range of prospective potential applications in biomedical engineering, material manufacturing, etc. Getting the knowledge of the diffusive molecular channel is important for the design and analysis of the molecular communication system. This paper investigates the channel parameter estimation based on a typical inverse Gaussian distributed channel. The estimator of propagation distance, medium velocity and diffusion coefficient are derived by maximum likelihood estimation method. The simulation results validate the effectiveness of the proposed estimators. Lin Lin 0002, Chengfeng Yang, Shiwei Ma, Maode Ma |
WCNC | 4 |
| 2016 | Offset estimation for clock synchronization in mobile molecular communication systemabstractNano communication is a novel communication paradigm. The nano-devices communicate with each other by molecular communication at the nano- or micro-scale. Clock synchronization is an essential issue for the collaboration of the nano-devices. How to synchronize the nanomachine in a mobile scenario is a challenge. This paper propose a method to estimate the clock offset in mobile molecular communication systems. First, we introduce a simple model of clock synchronization in mobile molecular communication system. Next, we propose a method to estimate the clock offset base on Maximum-Likelihood Estimation (MLE) in mobile molecular communication system. Finally, simulations by MATLAB are performed and the results show that the mean square error (MSE) of the estimated clock offsets can be reduced and converges after a number of rounds of message exchange, which manifests the effectiveness of the proposed solution. Zhan Luo, Lin Lin 0002, Maode Ma |
WCNC | 3 |
| 2016 | Two-stage frequency-domain oversampling receivers for cyclic prefix orthogonal frequency-division multiplexing systemsabstractOrthogonal frequency‐division multiplexing (OFDM) is a widely adopted technique in most wireless applications. It has been shown that zero padded OFDM (ZP‐OFDM) with frequency‐domain oversampling (FDO) can exhibit better performance than cyclic prefix OFDM (CP‐OFDM) if the whole OFDM symbol is oversampled in the frequency domain. In this study, the authors propose a novel FDO‐based scheme for CP‐OFDM, which consists of two stages. First, the conventional CP‐OFDM receiver is adopted to estimate the transmitted data and channel information. Second, the received symbol is reconstructed to reduce inter‐symbol interference and oversampled in the frequency domain. The proposed scheme combines FDO and symbol reconstruction together, which enables the minimum mean square error (MMSE) and zero forcing (ZF) equalisers to exploit the channel information in high‐dimensional non‐orthogonal subcarrier domain and thus significantly suppress the interference on multipath channels. Simulation results show that the proposed FDO‐MMSE CP‐OFDM receiver can achieve much better bit error rate performance than the traditional CP‐OFDM receiver and is comparable to the ZP‐OFDM receiver with FDO. Yanxin Yan, Yi Gong 0001, Maode Ma |
IET Commun. | 3 |
| 2016 | An authentication scheme with identity-based cryptography for M2M security in cyber-physical systemsabstractThe Internet has made the world smaller while there is still a gap between the cyber world and our physical world. In the future cyber-physical system (CPS), all objects in cyber world and physical world would be connected, and the concepts of cyber world and physical world will no longer exist. The speed of information transmitting and processing will be faster, the abilities of controlling facilities and handling events will be more powerful, and our lives will be better. In the CPS, machine to machine (M2M) communication is in charge of data collecting and transmitting, which utilizes both wireless and wired systems to monitor physical or environmental conditions and exchange the information among different systems without direct human intervention. As a part of CPS, M2M communication is considerably important while being fragile at the same time because M2M communication still faces lots of security threats that are not only from outside but also from inside. In traditional M2M communication, the M2M service provider (MSP) is always assumed to be trusted. However, the MSP could be compromised in real world. In that case, the previous security solutions would fail because the most confidential materials are kept in the MSP by the conventional solutions. How to protect the entire system from the compromised MSP is one important problem the paper intends to solve. In addition, the communication bandwidth and energy resource for the M2M devices are precious. Another issue the paper is addressing is the design of efficient security schemes being able to save both energy and communication bandwidth. In this paper, an authentication scheme applying authenticated identity-based cryptography without key-escrow mechanism has been proposed. In the proposed scheme, only partial secrets instead of full secrets are stored in the MSP, which could prevent the compromised MSP from endangering the whole system. The authenticated encryption property of the proposed scheme could leave out the work of signature generation, transmission, and verification so as to save the computation and communication resource of the whole system. The security analysis with Burrows–Abadi–Needham logic (BAN Logic) and Simple Promela Interpreter (SPIN) shows that the proposed scheme is well designed and could withstand Man-in-the-Middle attacks, impersonation attacks, replay attacks, DoS attacks, and compromised attacks. Copyright © 2016 John Wiley & Sons, Ltd. Maode Ma, Zhenxing Luo |
Secur. Commun. Networks | 2 |
| 2016 | Security enhancement for dynamic key refreshment in neighborhood area network of smart gridabstractWireless mesh networks are being considered as the most adequate topology for deployment in the neighborhood area network NAN domain in the smart-grid infrastructure, because its features such as self-organizing, scalability, and cost-efficiency complement to the NAN requirements. To provide security functionality to the NAN, the key refreshment strategy of the simultaneous authentication of equals or the efficient mesh security association protocol is an efficient way to make the network more resilient against various cyberattacks. However, it is discovered that when the key refreshment strategy is used, the efficient mesh security association protocol demonstrates a security vulnerability, leading to denial of service attacks. In this paper, a simple hash-based encryption scheme is proposed to prevent the unprotected messages from being replayed by the adversary with an enhancement to the key refreshment scheme to improve the resilience of the mesh key holder security handshake. The Protocol Composition Logic is used to describe the logical correctness of the proposed scheme, while the Process Analysis Toolkit is used to formally verify the security functionality against the malicious attacks. The efficiency analysis and the simulation results prove that the proposed scheme is reliable and efficient. Copyright © 2016 John Wiley & Sons, Ltd. Gurbakshish Singh Toor, Maode Ma |
Secur. Commun. Networks | 2 |
| 2016 | Conjunctive Keyword Search With Designated Tester and Timing Enabled Proxy Re-Encryption Function for E-Health CloudsabstractAn electronic health (e-health) record system is a novel application that will bring great convenience in healthcare. The privacy and security of the sensitive personal information are the major concerns of the users, which could hinder further development and widely adoption of the systems. The searchable encryption (SE) scheme is a technology to incorporate security protection and favorable operability functions together, which can play an important role in the e-health record system. In this paper, we introduce a novel cryptographic primitive named as conjunctive keyword search with designated tester and timing enabled proxy reencryption function (Re-dtPECK), which is a kind of a time-dependent SE scheme. It could enable patients to delegate partial access rights to others to operate search functions over their records in a limited time period. The length of the time period for the delegatee to search and decrypt the delegator’s encrypted documents can be controlled. Moreover, the delegatee could be automatically deprived of the access and search authority after a specified period of effective time. It can also support the conjunctive keywords search and resist the keyword guessing attacks. By the solution, only the designated tester is able to test the existence of certain keywords. We formulate a system model and a security model for the proposed Re-dtPECK scheme to show that it is an efficient scheme proved secure in the standard model. The comparison and extensive simulations demonstrate that it has a low computation and storage overhead. Maode Ma |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2016 | A Mutual Authentication and Key Establishment Scheme for M2M Communication in 6LoWPAN NetworksabstractThe machine-to-machine (M2M) communication, which plays a vital role in the Internet of Things (IoT), allows wireless and wired systems to monitor environments and exchange the information among various machines automatically without human interventions. In order to promote the development of the IoT and exploit the M2M applications, the Internet Engineering Task Force (IETF) has been developing a standard named Internet Protocol version 6 (IPv6) over low-power wireless personal area networks (6LoWPAN) to enable IP-based M2M devices to connect to the open Internet. Although the 6LoWPAN standard has specified the important issues in the M2M communications, various security issues have not been addressed. In this paper, an enhanced mutual authentication and key establishment scheme is designed for the M2M communications in 6LoWPAN networks. The proposed scheme enables a 6LoWPAN device to securely authenticate with the remote server with a session key established between them. The security proof by the protocol composition logic can prove the logic correctness of the proposed scheme. The formal verification and the simulation show that the proposed scheme in 6LoWPAN could not only enhance the security functionality with the ability to prevent various malicious attacks, but also incur less computational and transmission overhead. Yue Qiu 0004, Maode Ma |
IEEE Trans. Ind. Informatics | 2 |
| 2016 | A symmetric key-based pre-authentication protocol for secure handover in mobile WiMAX networks
Maode Ma, Thuy Ngoc Nguyen 0002 |
J. Supercomput. | 2 |
| 2016 | Uplink Energy-Delay Trade-Off under Optimized Relay Placement in Cellular NetworksabstractRelay nodes-enhanced architectures are deemed a viable solution to enhance coverage and capacity of nowadays cellular networks. Besides a number of desirable features, these architectures reduce the average distance between users and network nodes, thus allowing for battery savings for users transmitting on the uplink. In this paper, we investigate the extent of these savings, by optimizing relay nodes deployment in terms of uplink energy consumption per transmitted bit, while taking into account a minimum uplink average user delay that has to be guaranteed. A novel performance evaluation framework for uplink relay networks is first proposed to study this energy-delay trade-off. A simulated annealing is then run to find an optimized relay placement solution under a delay constraint; exterior penalty functions are used in order to deal with a difficult energy landscape, in particular when the constraint is tight. Finally, results show that relay nodes deployment consistently improve users uplink energy efficiency, under a wide range of traffic conditions and that relays are particularly efficient in non-uniform traffic scenarios. Mattia Minelli, Maode Ma, Marceau Coupechoux, Jean-Marc Kelif, Marc Sigelle, Philippe Godlewski |
IEEE Trans. Mob. Comput. | 2 |
| 2016 | Elastic bandwidth allocation scheme with softened peak interference power constraint for the dynamic cognitive radio systems
Kiam Cheng How, Maode Ma |
Wirel. Networks | 2 |
| 2015 | A Lightweight Secure VANET-Based Navigation SystemabstractRecently, large scale vehicle ad hoc networks (VANETs)-based navigation systems have drawn much research attention. Although an enhanced secure and privacy VANET-based navigation (EVSPN) scheme has been proposed to prevent the replay and man-in-the- middle attacks, providing signature and verification on the public key infrastructure (PKI) based signatures of all messages relayed costs much computation resource and incurs a high authentication delay for not only the vehicles but also the roadside units (RSUs), especially when the navigation service is busy. In this paper, we propose a lightweight secure VANET-based navigation scheme (LSVN) that has a lower computation cost and a lower authentication delay. By the LSVN, a vehicle firstly initiates the navigation service with a RSU nearby to request a shared symmetric key for further communication with other RSUs in the VANET. Then, the best route will be calculated. The pseudo identity of the vehicle and the shared keying materials are sent to the RSUs on the route of the vehicle to its destination. At last, the vehicle will be led to the destination by these RSUs in series. We formally verify, by BAN Logic, that the LSVN scheme can provide the guarantee of the integrity of messages and mutual authentication. Performance analysis shows that the LSVN can minimize the use of cryptographic operations and reduce authentication delay significantly comparing with the VSPN scheme and the EVSPN scheme. Maode Ma, Chunfeng Liu 0001, Yantai Shu |
GLOBECOM | 2 |
| 2015 | GAHAP: A group-based anonymity handover authentication protocol for MTC in LTE-A networksabstractMachine Type Communication (MTC) has quickly become the driving force of the mobile operators for a large number of real-time network applications. The design of the MTC security mechanisms in the mobile environments of the Long Term Evaluation-Advanced (LTE-A) networks is the major point of the future research for the LTE-A security. When a good deal of MTC devices simultaneously move to a new eNodeB (eNB), the current third Generation Partnership Project (3GPP) handover mechanisms require several handover signaling interactions, which could not only cause the signaling load over the access network and the core network, but also increase the energy consumption of MTC devices. In this paper, we enhance the current handover mechanisms and propose an efficient group-based anonymity handover authentication protocol for a lot of MTC devices with mobility, which is to fit in with all of the mobility scenarios in the LTE-A networks. Compared with the current 3GPP standards, our scheme can not only largely reduce the signaling costs in both the access network and the core network, but also achieve the privacy preservation. Jin Cao 0001, Hui Li 0006, Maode Ma |
ICC | 3 |
| 2015 | UGHA: Uniform group-based handover authentication for MTC within E-UTRAN in LTE-A networksabstractMachine Type Communication (MTC) as one of the most important wireless communication technologies in the future wireless communication, has become the new business growth point of mobile communication network. It is a key point to achieve seamless handovers within Evolved Universal Terrestrial Radio Access Network (E-UTRAN) for a large number of MTC devices in order to support mobility in the Long Term Evolution Advanced (LTE-A) networks. When a good deal of MTC devices simultaneously roam from a base station to another, the current handover mechanisms suggested by the third Generation Partnership Project (3GPP) require several handover signaling interactions, which could cause the signaling load over the network nodes. Besides, several distinct handover procedures are proposed for different mobility scenarios, which will increase the system complexity. In this paper, we propose a simple and secure uniform group-based handover authentication scheme for a lot of MTC devices based on the multi-signature and aggregate message authentication codes (AMAC) techniques, which is to fit in with all of the mobility scenarios in the LTE-A networks. Compared with the current 3GPP standards, our scheme can achieve a simple authentication process with robust security protection, and thus avoid signaling congestion. Jin Cao 0001, Hui Li 0006, Maode Ma, Fenghua Li 0001 |
ICC | 3 |
| 2015 | GBAAM: group-based access authentication for MTC in LTE networksabstractMachine Type Communication (MTC), as one of the most important communication approaches in the future mobile communication, has drawn more and more attention. To meet the requirements of low power consumption of devices and mass device transmission is the key issue to achieve MTC applications security in the Long Term Evolution (LTE) networks. When a large number of MTC devices simultaneously connect to the network, each MTC device needs to implement an independent access authentication procedure in the current third Generation Partnership Project (3GPP) standard, which will cause a severe signaling congestion in the LTE network. In this paper, we propose a group-based access authentication scheme, by which a good deal of MTC devices can be simultaneously authenticated by the network and establish an independent session key with the network respectively. Our scheme cannot only greatly reduce the signal transmission for mass of devices to the network and thus avoid the signaling overload over the LTE network, but also achieve robust security including Key Forward/Backward Secrecy (KFS/KBS) and non-repudiation verification. The experimental results and formal verification by using the TLA+ and TLC show that the proposed scheme is secure against various malicious attacks. Jin Cao 0001, Maode Ma, Hui Li 0006 |
Secur. Commun. Networks | 2 |
| 2015 | An enhanced authentication protocol for WRANs in TV white spaceabstractCognitive radio technique has been recognized as an effective solution to the dilemma introduced by the rapid growth of wireless communications and the scarcity of spectrum resources. One example of the cognitive radio systems is the wireless regional area network operating in television white space TVWS spectrum, which has been specified by IEEE 802.22 standard. The wireless regional area networks in TVWS face not only the traditional security threats but also cognitive security challenges. Especially, the authentication between the base station and the customer premises equipment is vital for secure communication. We discovered that the authentication protocol specified in IEEE 802.22 is vulnerable to the interleaving attacks and cannot achieve mutual key confirmation. In this paper, an Enhanced Certificate-based Authentication scheme ECA has been proposed to overcome the vulnerability of the authentication scheme in IEEE 802.22 standard with much less requirements on the computation and communication resources. The drawbacks of the authentication protocol in IEEE 802.22 standard has been explored followed by the presentation of the proposed enhanced authentication protocol, ECA. The ECA protocol has been evaluated in terms of security functionality and the performance. The correctness of the Enhanced Certificate-based Authentication scheme is analyzed by the Burrows, Abadi, and Needham logic. Copyright © 2015 John Wiley & Sons, Ltd. Cong Wang 0004, Maode Ma, Zenghua Zhao |
Secur. Commun. Networks | 2 |
| 2015 | Periodic K-Times Anonymous Authentication With Efficient Revocation of Violator's CredentialabstractIn a periodic K-times anonymous authentication system, user can anonymously show credential at most K times in one time period. In the next time period, user can automatically get another K-times authentication permission. If a user tries to show credential beyond K times in one time period, anyone can identify the dishonest user (the violator). But identifying violators is not enough for some systems, where it is also desirable to revoke violators' credentials for preventing them from abusing the anonymous property again. However, the problem of revoking credential without trusted third party has not been solved efficiently and practically. To solve it, we present an efficient scheme with efficient revocation of violator's credential. In fact, our method also solves an interesting problem-leaking information in a statistic zero-knowledge way, so our solution to the revocation problem outperforms all prior solutions. For achieving it, we use the special zero-knowledge proof with special information leak for revoking the violator's credential, but it can still be proven to be perfect statistic zero knowledge for guaranteeing the honest user's anonymity. Comparing with existing schemes, our scheme is efficient, and moreover, our method of revoking violator's credential is more practical with the least additional costs. Bin Lian, Gongliang Chen, Maode Ma, Jianhua Li 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2014 | Bandwidth efficient multicast in HetNetsabstractIn this paper, we propose a joint network selection and rate selection scheme for the multicasting in heterogeneous networks, with an aim to minimize the overall bandwidth resources consumed by the multicast stream. We first formulate the scheme as a binary integer programming problem, and then derive a computationally efficient Lagrangian heuristic algorithm to solve the problem with the architecture of heterogeneous networks taken into account. Simulation results show that the proposed scheme will cost the minimum system bandwidth compared to other reference schemes. Maode Ma |
GLOBECOM | 2 |
| 2014 | A novel authenticated multi-party key agreement for private cloudabstractCloud computing technology is an emerging technology for various types of vast information to be processed in the data centers to overcome the serious shortage of resource such as space, power and cost, etc. Along with the development of cloud computing, security of cloud computing is becoming more and more critical. In this paper, we aim to propose a set of secure and efficient authenticated multi-party key agreement protocols based on the hierarchical identity-based cryptography (HIBC) for private cloud. For different scenarios, we design loop-level and cascade-level authentication protocols among users in a private cloud of hierarchical structure, respectively. The new multi-party protocols are supposed to be more efficient and secure than the other existing solutions. Tuo He, Maode Ma, Wenping Ma 0002, Bingsheng He |
ICC | 2 |
| 2014 | Iterative frequency-domain fractionally spaced receiver for zero-padded multi-carrier code division multiple access systemsabstractIn this study, the authors propose an improved frequency‐domain fractionally spaced (FDFS) minimum mean square error (MMSE) receiver for zero‐padded multi‐carrier code division multiple access (MC‐CDMA) systems when the guard interval is not enough to avoid the inter‐symbol interference (ISI) caused by the multipath channel. The proposed novel iterative FDFS‐based receivers firstly reconstruct the received symbol to reduce the ISI and then followed by the FDFS‐based equalisers to minimise the effect of ISI and inter‐carrier interference (ICI) caused by carrier frequency offset (CFO) and Doppler shifts. A few iterations are performed to achieve the expected bit error rate (BER) performance. To reduce the receiver complexity, the novel simplified diagonal FDFS‐based receivers with a fixed noise variance are developed with slight performance degradation. The proposed iterative receivers have never been studied in the existing literature. Simulation results show that the proposed iterative FDFS‐based receivers can significantly improve the BER performance of the conventional FDFS‐MMSE receiver in severe multiple interferences environments caused by multipath, CFO and Doppler shift. Yanxin Yan, Yi Gong 0001, Maode Ma, Qinghua Shi |
IET Commun. | 3 |
| 2014 | An ultralightweight RFID authentication protocol with CRC and permutation
Maode Ma, Yantai Shu, Yuhua Wei |
J. Netw. Comput. Appl. | 2 |
| 2014 | Network selection and resource allocation for multicast in HetNets
Maode Ma |
J. Netw. Comput. Appl. | 2 |
| 2014 | Optimal Relay Placement in Cellular NetworksabstractIn this paper, we address the problem of optimally placing relay nodes in a cellular network with the aim of maximizing cell capacity. In order to accurately model interference, we use a dynamic framework, in which users arrive at random time instants and locations, download a file and leave the system. A fixed point equation is solved to account for the interactions between stations. We also propose an extension of a fluid model to relay based cellular networks. This allows us to obtain quick approximations of the Signal to Interference plus Noise Ratio (SINR) that are very close to 3GPP LTE-A guideline results in terms of SINR distribution. We then use these formulas to develop a dedicated Simulated Annealing (SA) algorithm, which adapts dynamically the temperature to energy variations and uses a combination of coarse and fine grids to accelerate the search for an optimized solution. Simulations results are provided for both in-band and out-of-band relays. They show how relays should be placed in a cell in order to increase the capacity in case of uniform and non-uniform traffic. The crucial impact of the backhaul link is analyzed for in-band relays. Insights are given on the influence of shadowing. Mattia Minelli, Maode Ma, Marceau Coupechoux, Jean-Marc Kelif, Marc Sigelle, Philippe Godlewski |
IEEE Trans. Wirel. Commun. | 2 |
| 2013 | A dynamic-encryption authentication scheme for M2M security in cyber-physical systemsabstractMachine to machine (M2M) communication is the technology that utilizes both wireless and wired systems to monitor physical or environmental conditions and exchange the information among different systems without direct human intervention. In the future cyber-physical system, M2M will play a very important role in data collecting. While being a promising technology, M2M communication still faces lots of security threats. There are some security vulnerabilities that yet to be solved. In this paper, we propose a dynamic-encryption authentication scheme, by which a mobile device could be authenticated by the network and a shared one-time-password could be generated. The security analysis shows that the proposed scheme could withstand Man-in-the-Middle attacks, impersonation attacks, reply attacks and DoS attacks. Our scheme is also formally verified. Maode Ma |
GLOBECOM | 2 |
| 2013 | CCS-DTN: Efficient routing in social DTNs based on clustering and network codingabstractWith the development of mobile internet, wireless communications via mobile devices, which is typically in the form of Delay Tolerant Networks (DTNs), becomes a hot research topic. One critical issue in the development of DTNs is the routing. Although there are a lot research works addressing routing issues in DTNs, they handle routing problem from only one or two aspects, which cannot produce an advanced solution to this comprehensive challenge. In view of these defects in the existing works, we propose a novel solution to address the routing issue of one type of DTNs in which mobile nodes can be divided into different clusters. A simple routing protocol can be used for the intra-cluster communication, while, for the inter-cluster one, messages will be forwarded to a relay node, which is selected by a new selection policy, supported by the network coding technique. The simulation results show that our proposed scheme can significantly improve the performance of the routing in DTNs. Zhenjing Zhang, Maode Ma, Zhigang Jin |
GLOBECOM | 2 |
| 2013 | Efficient localization for mobile sensor networks based on constraint rules optimized Monte Carlo method
Ze Wang 0016, Maode Ma, Jigang Wu |
Comput. Networks | 3 |
| 2013 | An novel three-party authenticated key exchange protocol using one-time key
Maode Ma, Hui Li 0006, Jianfeng Ma 0001 |
J. Netw. Comput. Appl. | 2 |
| 2013 | Proactive load balancing with admission control for heterogeneous overlay networksabstractABSTRACT The next generation wireless networks will be the coexistence of heterogeneous wireless technologies. Balancing the traffic load among different networks can effectively utilize the overall radio resources in the system. In this paper, we propose an efficient load balancing scheme for the heterogeneous overlay systems, which is applied in the call admission control process. If the available network(s) cannot provide enough resource for the request call without degrading the quality‐of‐service (QoS) obtained by the ongoing calls, the system will perform load balancing operations first by initiating vertical handoffs among networks in order to create more rooms for the request call. The load balancing algorithm is to minimize the variance between the network utilizations of the entire system, which can be formulated as a quadratic binary programming problem. Simulation results show that the proposed scheme can admit more calls into the system compared with the other three reference schemes and then improve the overall throughput. Meanwhile, the scheme can keep the networks working in effective states and provide a better QoS support for users. Copyright © 2011 John Wiley & Sons, Ltd. Maode Ma |
Wirel. Commun. Mob. Comput. | 2 |
| 2012 | A group-based authentication and key agreement for MTC in LTE networksabstractMachine Type Communication (MTC), as one of the most important communication approaches in the future mobile communication, has drawn more and more attention. To meet the requirements of low power consumption of devices and mass device transmission is the key issue to achieve MTC applications security in the Long Term Evolution (LTE) networks. When a large number of MTC devices simultaneously connect to the network, each MTC device needs to implement an independent access authentication process according to the current third Generation Partnership Project (3GPP) standard, which will cause a severe signaling congestion in the LTE network. In this paper, we propose a group-based access authentication scheme, by which a good deal of MTC devices can be simultaneously authenticated by the network and establish an independent session key with the network respectively. The experimental results show that the proposed scheme can achieve robust security with desirable efficiency and avoid the signaling overload over the LTE networks. Jin Cao 0001, Maode Ma, Hui Li 0006 |
GLOBECOM | 2 |
| 2012 | Unified handover authentication between heterogeneous access systems in LTE networksabstractTo achieve seamless handovers between the Evolved Universal Terrestrial Radio Access Network (E-UTRAN) and other access networks is a challenging task as it requires comprehensive real-time interconnectivity in the LTE networks. The third Generation Partnership Project (3GPP) has suggested support the mobility between the E-UTRAN and non-3GPP access networks, which requires full access authentication procedures and distinct procedures for different mobility scenarios, which will bring a lot of message exchanges and increase the system complexity. Besides, the existing handover schemes for other wireless networks are not suitable for the mobility scenarios in the LTE networks due to their inherent vulnerabilities. In this paper, we propose a fast and secure handover authentication scheme to fit in with all of the mobility scenarios in the LTE networks. Compared with other handover schemes, our scheme cannot only provide strong security guarantees including Perfect Forward Secrecy (PFS) and Master Key Forward Secrecy (MKFS) and user anonymity, but also achieve a simple authentication process with robust efficiency in terms of communication cost, storage cost and computational cost. The analysis results show that the proposed scheme is efficient and secure against various malicious attacks. Jin Cao 0001, Maode Ma, Hui Li 0006 |
GLOBECOM | 2 |
| 2012 | An pre-authentication protocol with symmetric keys for secure handover in mobile WiMAX networksabstractMobile users expect quick and secured handovers to achieve seamless service connection. However, long delay due to the time-consuming authentication procedure is a well-known bottleneck of the mobile WiMAX handover schemes. In this paper, a pre-authentication based handover scheme using symmetric key cryptography is proposed to facilitate fast and secure handovers for mobile WiMAX networks. The scheme is formally verified by BAN logic to prove its ability to achieve the security goals of an authentication scheme. Thuy Ngoc Nguyen 0002, Maode Ma |
ICC | 2 |
| 2012 | A collusion-resilient self-healing key distribution scheme for wireless sensor networksabstractSecure group communication for large wireless sensor networks sparkles the research on efficient key distribution and key management mechanism. By a self-healing key distribution scheme, even if during a certain session, some broadcast messages are lost due to network faults, the users are capable of recovering the lost session keys on their own without requesting additional information exchange with the group manager. However, some self-healing key distribution schemes are unable to prevent collusion attacks effectively. In this paper, a general self-healing session key distribution approach is devised to thwart collusion attacks. Furthermore, an effective collusion resilient key distribution scheme is proposed for the secure group communication in wireless sensor networks. Ze Wang 0016, Maode Ma |
ICC | 2 |
| 2012 | Hybrid multimedia broadcast encryption schemesabstractBroadcast encryption in a pay television system is actually a key management issue, where smaller key storage and shorter header length are required to assure the quality of service. The existing solutions come up with two typical structures. One is the matrix-based structure without revocation capability and the other is the tree-based structure in Advanced Access Content System. In this paper, we propose two promising schemes that exploit the combination of the two structures to solve the revocation problem in the matrix-based structure to meet the requirements of the small key storage and short header. Mathematical derivations and calculations are performed to prove the feasibility of the proposed schemes. Huaqun Guo, Maode Ma |
WCNC | 3 |
| 2012 | A simple and robust handover authentication between HeNB and eNB in LTE networks
Jin Cao 0001, Hui Li 0006, Maode Ma, Yueyu Zhang, Chengzhe Lai |
Comput. Networks | 3 |
| 2012 | An altruistic differentiated service protocol in dynamic cognitive radio networks against selfish behaviors
Kiam Cheng How, Maode Ma |
Comput. Networks | 2 |
| 2012 | Utility-based scheduling in wireless multi-hop networks over non-deterministic fading channels
Maode Ma, Jufeng Dai |
Comput. Networks | 2 |
| 2012 | Securing wireless mesh networks in a unified security framework with corruption-resilience
Ze Wang 0016, Maode Ma, Jigang Wu |
Comput. Networks | 2 |
| 2012 | Investigation of a large-scale P2P VoD overlay network by measurements
Bing Li 0004, Maode Ma, Zhigang Jin, Dongxue Zhao |
Peer-to-Peer Netw. Appl. | 2 |
| 2012 | Cryptanalysis of some conference schemes for mobile communicationsabstractABSTRACT To allow many users to hold a secure teleconference in mobile networks, a secure conference scheme with dynamic participation is necessary. However, designing a secure and efficient conference scheme is a difficult task because wireless networks are susceptible to attacks and wireless devices have limited resources. Recently, a lightweight and secure conference scheme has been suggested. Later, it has been found that this solution has security weaknesses and a modified version to overcome them has been presented. Compared with other conference schemes, these two schemes have many advantages. In this short paper, security study of these conference schemes in mobile networks has been performed with the following findings: (1) both the original scheme and the modified version are still vulnerable to our proposed impersonation attack; (2) they lack a mechanism to confirm the delivery of relevant messages, leading to protocol disruption. Therefore, these two schemes cannot be deployed for the real world applications without further development. Then, some efficient countermeasures are given for enhancing the security of both schemes. Further, the security properties of the improved protocol are formally validated by a model checking tool called AVISPA. Finally, several basic principles are suggested for the design of a secure conference scheme. Copyright © 2011 John Wiley & Sons, Ltd. Daojing He, Chun Chen 0001, Maode Ma, Jiajun Bu |
Secur. Commun. Networks | 3 |
| 2012 | A security enhanced authentication and key distribution protocol for wireless networksabstractABSTRACT Authentication and key distribution (AKD) protocols become more and more important in the design of wireless networks. Especially, the communication efficiency and security are the critical factors. In this paper, we first analyse the vulnerabilities of an AKD protocol for wireless networks under three types of attacks. Then, we propose an enhanced AKD protocol to overcome those vulnerabilities with the security functionality to prevent those malicious attacks. Security analysis and formal verification mainly using Automated Validation of Internet Security Protocols and Applications toolkit show that the proposed protocol is secure against those attacks. Copyright © 2011 John Wiley & Sons, Ltd. Maode Ma, Hui Li 0006, Jianfeng Ma 0001, Ben Niu 0001 |
Secur. Commun. Networks | 2 |
| 2012 | Security enhancement of the communication-efficient AUTHMAC_DH protocolsabstractABSTRACT Authentication and key distribution (AKD) protocols have become more important in the design of communication systems. The design criteria of the AKD protocols include the scalability, the communication efficiency, the computational efficiency, and the robustness of security. In this paper, we first analyze the vulnerability of an AKD protocol under the off‐line guessing attack. Then, we propose an enhanced AKD protocol to overcome the vulnerability. Security analysis and formal verification by using AVISPA toolkit show that the proposed protocol can keep all the previous properties and is secure against the off‐line guessing attack. Copyright © 2011 John Wiley & Sons, Ltd. Maode Ma, Hui Li 0006, Jianfeng Ma 0001, Ben Niu 0001 |
Secur. Commun. Networks | 2 |
| 2012 | A Server Independent Authentication Scheme for RFID SystemsabstractThe significance of radio frequency identification (RFID) security is increasing explosively, leading to a research trend. The current most severe RFID security issues are privacy and authentication security. The renewable identity (ID) approach with a central database is the current dominating approach to achieve user privacy and authentication security. Although, the approach will cause more problems that renewable ID will increase RFID tag cost and will enable denial of service (DoS) attacks while the central database will reduce system mobility. To solve the dilemma, a new protocol with two original approaches, which are the label sharing approach to protect customer and the removable central database approach to enhance system mobility is proposed in this paper. The security properties of the new scheme are verified by using Colored Petri Net (CPN) and algebra proofs. Maode Ma |
IEEE Trans. Ind. Informatics | 2 |
| 2012 | A QoS Oriented Vertical Handoff Scheme for WiMAX/WLAN Overlay NetworksabstractRecently, a number of wireless communication technologies are migrating toward heterogeneous overlay networks. The integration of Mobile WiMAX and WLAN seems to be a promising approach due to their homogeneous nature and complementary characteristics. In this paper, we investigate several important issues for the interworking of Mobile WiMAX and WLAN networks. We address a tightly coupled interworking architecture. Further, a seamless and proactive vertical handoff scheme is designed based on the architecture with aims to provide always the best quality of service (QoS) for users. Both the performance of applications and network conditions are considered in the handoff process. Moreover, we derive evaluation algorithms to estimate the conditions of both WiMAX and WLAN networks in terms of available bandwidth and packet delay. A simulation study has demonstrated that the proposed schemes can keep stations always being best connected. Maode Ma |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2012 | An Uniform Handover Authentication between E-UTRAN and Non-3GPP Access NetworksabstractTo achieve seamless handovers between the Evolved Universal Terrestrial Radio Access Network (E-UTRAN) and other access networks is a challenging task as it requires comprehensive real-time interconnectivity in the LTE networks. The third Generation Partnership Project (3GPP) has suggested support the mobility between the E-UTRAN and non-3GPP access networks, which requires full access authentication procedures and distinct procedures for different mobility scenarios, which will bring a lot of message exchanges and increase the system complexity. Besides, the existing handover schemes for other wireless networks are not suitable for the mobility scenarios in the LTE networks due to their inherent vulnerabilities. In this paper, we propose a fast and secure handover authentication scheme to fit in with all of the mobility scenarios in the LTE networks. Compared with other handover schemes, our scheme cannot only provide strong security guarantees including Perfect Forward Secrecy (PFS) and Master Key Forward Secrecy (MKFS) and user anonymity, but also achieve a simple authentication process with robust efficiency in terms of communication cost, storage cost and computational cost. The experimental results and formal verification by using the TLA+ and TLC show that the proposed scheme is secure against various malicious attacks. Jin Cao 0001, Maode Ma, Hui Li 0006 |
IEEE Trans. Wirel. Commun. | 2 |
| 2012 | Enhanced EAP-Based Pre-Authentication for Fast and Secure Inter-ASN Handovers in Mobile WiMAX NetworksabstractMobile WiMAX is yet to meet the expectation from mobile users to provide secured and seamless services. Long delay in the time-consuming authentication procedure is a well-known bottleneck of the IEEE 802.16e handover scheme, causing service disruption when a mobile user moves between base stations. A pre-authentication-based handover scheme for mobile WiMAX networks aims to achieve fast and secure inter-ASN handovers. However, it is shown to be vulnerable to Denial of Service (DoS) and replay attacks. In this paper, we propose an Enhanced EAP-based pre-authentication (EEP) scheme to overcome the vulnerability of the above-mentioned scheme with much less requirements on the computation and communication resources. Thuy Ngoc Nguyen 0002, Maode Ma |
IEEE Trans. Wirel. Commun. | 2 |
| 2011 | Scalable Rekeying Algorithm in IEEE 802.16eabstractIEEE 802.16e standard provides wide coverage and high bandwidth for subscribers in a metropolitan area network. It introduces Multicast and Broadcast Rekeying Algorithm (MBRA) which is a multicasting scheme to communicate with many users concurrently. Although ELAPSE (for Efficient sub-Linear rekeying Algorithm with Perfect SEcrecy) improves on the deficiencies of MBRA, the algorithm poorly responds to scalability issue. This paper proposes a Scalable Rekeying Algorithm (SRA) based on a complete binary tree structure. SRA is introduced with linear linked list structure in order to make the system more scalable. Evaluation analysis shows that SRA manages to improve the scalability issue in MBRA for Mobile WiMAX. Mohammad Mehdi Gilanian Sadeghi, Borhanuddin Mohd Ali, Maode Ma, Jamalul-lail Ab Manan, Nor Kamariah Noordin, Sabira Khatun |
APCC | 3 |
| 2011 | HASVC: An Efficient Hybrid Authentication Scheme for Vehicular CommunicationabstractThe emerging vehicular communications will enable a variety of applications for safety, traffic efficiency, driver assistance and infotainment. Due to high vehicular speed, sporadic connection, limited communication range, and large volume of data that need to be transmitted, vehicular communications have the crucial requirements of fast authentication and encryption/decryption. This paper addresses the new and special challenges related to vehicular communications, such as large overhead and latency, presents our Hybrid scheme HASVC to address the authentication issue, and evaluates its performance so as to meet the stringent requirement of real time vehicular communications. The experimental results show that our authentication protocol can securely protect the exchanged information with less overhead and less authentication latency. Huaqun Guo, Zonghua Zhang, Lawrence Wai-Choong Wong, Maode Ma, Yongdong Wu |
ICC | 5 |
| 2011 | A Unified Security Framework for Multi-domain Wireless Mesh NetworksabstractThe research issues of large scale wireless mesh networks (WMNs) have attracted increasing attention due to the excellent properties of WMNs. Although some proposals for WMN security framework with different security aspects have been put forward recently, it is a challenging issue of employing uniform public key cryptography to maintain trust relationships flexibly among domains and to achieve key-escrow-free anonymous access control. In this paper, a unified security framework (USF) for multi-domain wireless mesh networks is proposed, which unifies id-based encryption and certificateless signature in a single public key cryptography context. Trust relationship between different domains and anonymous access control of wireless clients can be realized by employing of cryptography operations on bilinear groups. To achieve perfect forward secrecy and attack-resilience, trust domain construction methods and authentication protocols are devised within the security framework without key escrow. Ze Wang 0016, Maode Ma, Xixi Wei |
ICICS | 2 |
| 2011 | Performance benchmarking for wireless body area networks at 2.4 GHzabstractThis paper investigates wireless body area network (WBAN) performance to capture packet reception ratio (PRR) and its correlation with received signal strength indicator (RSSI), and the minimum transmission powers required for the targeted performance. We design and carry out experiments on IEEE 802.15.4 based WBAN prototype to measure the performance metrics in different activities and environments. It is observed that RSSI values for a given on-body link has radical variation in a minute-scale period in a realistic environment. This observation implies that a few of RSSI samples cannot be used as an estimate of the average RSSI over many packets transmitted over an on-body link. In postural mobility, the periodicity pattern of link property is more obviously observed at links with clearer line-of-sight and at higher transmission powers. The objective of the performance benchmarking is to provide insights and guidelines for the design of resource management schemes for WBANs. Yu Ge 0001, Jeng Wai Kwan, Jaya Shankar Pathmasuntharam, Zhengye Di, Terence S. P. See, Chee Wee Kim, Tat Meng Chiam, Maode Ma |
PIMRC | 9 |
| 2011 | Routing and QoS provisioning in cognitive radio networks
Kiam Cheng How, Maode Ma |
Comput. Networks | 2 |
| 2011 | Cognitive radio-based framework and self-optimizing temporal-spectrum block scheduling for QoS provisioning in WiMAX
Jinchang Lu, Maode Ma |
Comput. Networks | 2 |
| 2011 | A strong user authentication scheme with smart cards for wireless communications
Daojing He, Maode Ma, Yan Zhang 0002, Chun Chen 0001, Jiajun Bu |
Comput. Commun. | 2 |
| 2011 | Quality of service provisioning in worldwide interoperability for microwave access networks based on cooperative game theoryabstractQuality of service (QoS) is a critical issue in the design and management of worldwide interoperability for microwave access (WIMAX) networks. In this study, the authors propose a novel two-tier QoS framework and a scheduling scheme for QoS provisioning in WiMAX networks based on the Nash bargaining solution (NBS) obtained from cooperative game theory. The framework cannot only offer Pareto optimality for the entire system, but also assure fairness for each service and connection. They apply the NBS into the issue of QoS service in WiMAX networks. They utilise the equivalent optimisation problem to obtain the bargaining point. The parameters of the optimisation model have been verified by analysing the characteristics of each service flow in the WiMAX networks. A heuristic scheduling algorithm has been designed to implement the optimised solution. The effectiveness of the proposal has been verified by experimental results, which can show much better performance in terms of delay, loss rate and throughput. Y. Jiao, Maode Ma, K. Yi |
IET Commun. | 2 |
| 2011 | A performance model for differentiated service over single-hop passive star coupled WDM optical networks
Xiaohong Huang 0003, Maode Ma |
J. Netw. Comput. Appl. | 2 |
| 2011 | A heuristic adaptive QoS prediction scheme in single-hop passive star coupled WDM optical networks
Xiaohong Huang 0003, Maode Ma |
J. Netw. Comput. Appl. | 2 |
| 2011 | Cross-layer QoS support framework and holistic opportunistic scheduling for QoS in single carrier WiMAX system
Jinchang Lu, Maode Ma |
J. Netw. Comput. Appl. | 2 |
| 2011 | Group mobility support in mobile WiMAX networks
Maode Ma |
J. Netw. Comput. Appl. | 2 |
| 2011 | Design of parameter tunable robust controller for active queue management based on H∞ control theory
Maode Ma, Weidong Hu, Zibo Shi, Yantai Shu |
J. Netw. Comput. Appl. | 2 |
| 2010 | An Opportunistic Service Differentiation Routing Protocol for Cognitive Radio NetworksabstractCognitive Radio (CR) is a new paradigm that enable nodes to exploit unoccupied frequency spectrum for transmissions. Cognitive Radio Networks (CRNs) have been proposed to enable wireless mesh networks to communicate via dynamic channels. Many existing research consider routing in static CRNs with relatively stable communication channel where the duration of the availability of the communication channel is much longer than the communication time. However, there is limited routing related research in dynamic CRNs where the average available duration of the communication channel can be much shorter than the communication time. To address this, we propose a cross-layer cognitive routing protocol, the Opportunistic Service Differentiation Routing Protocol (OSDRP) for the dynamic CRNs. OSDRP discovers the minimum delay - maximum stability route in CRNs by considering the availability of spectrum opportunity in addition to switching delay and queuing delay across primary user networks. In addition, service differentiation is achieved through a combination of transmit power control and opportunistic routing. Simulation results demonstrate that OSDRP can achieve much better performance in terms of lower delay compared to other existing routing protocols in various scenarios. Kiam Cheng How, Maode Ma |
GLOBECOM | 2 |
| 2010 | Cross-Layer Self-Optimizing Temporal-Spectrum Block Scheduling for QoS Provisioning in WiMAXabstractQoS provisioning is an important issue in the deployment of broadband wireless access networks. The scheduling scheme is essential to guarantee the QoS requirements of different service classes. WiMAX Orthogonal Frequency Division Multiple Access (OFDMA) system specifies the Orthogonal Frequency Division Multiplexing (OFDM) symbol mapping in a rectangular shape manner. In this paper, we propose a novel cross-layer self-optimizing Temporal-Spectrum Block (TSB) scheduling which is a joint sub-carrier allocation and symbol duration scheduling cum mapping scheme (SOS2M) in WiMAX point-to-multipoint (PMP) OFDMA/TDD systems. Extensive simulation experiments have been carried out to evaluate the performance of our proposal. The simulation results show that our proposed solution can provide QoS to real-time and non-real-time traffic while achieving high system efficiency. Jinchang Lu, Maode Ma |
GLOBECOM | 2 |
| 2010 | A cross-layer elastic CAC and holistic opportunistic scheduling for QoS support in WiMAX
Jinchang Lu, Maode Ma |
Comput. Networks | 2 |
| 2010 | An energy-efficient and low-latency MAC protocol with Adaptive Scheduling for multi-hop wireless sensor networks
Yi Zhi Zhao, Maode Ma, Chunyan Miao, T. N. Nguyen |
Comput. Commun. | 2 |
| 2010 | Hierarchical scheduling framework for QoS service in WiMAX point-to-multi-point networksabstractQuality of service (QoS) is an important issue in the deployment of broadband wireless access networks with real-time and non-real-time traffic integration. In this study, the authors propose a three-tier QoS service architecture and scheduling schemes to provide QoS supports in WiMAX networks with point-to-multi-point (PMP) topology. The distinct feature of the proposal is that QoS provisioning has been dynamically distributed to three tiers and implemented independently by both base station (BS) and subscriber stations (SSs). The performance of the proposed solution has been evaluated by extensive simulations and the theoretical analysis. The evaluation results show that our proposal can improve the performance of WiMAX PMP network much in terms of packet delay, packet loss rate and throughput. Maode Ma, C. P. Fu |
IET Commun. | 1 |
| 2010 | Network lifetime optimization in wireless sensor networksabstractNetwork lifetime (NL) is a critical metric in the design of energy-constrained wireless sensor networks (WSNs). In this paper, we investigate a joint optimal design of the physical, medium access control (MAC) and routing layers to maximize NL of a multiple-sources and single-sink (MSSS) WSN with energy constraints. The problem of NL maximization (NLM) can be formulated as a mixed integer-convex optimization problem with adoption of time division multiple access (TDMA) technique. When the integer constraints are relaxed to take real values, the problem can be transformed into a convex problem and the solution achieves the upper bounds. We provide an analytical framework for the relaxed NLM problem of a WSN in general planar topology. We first restrict the topologies to the planar networks on a small scale, including triangle and regular quadrangle topologies. In this special case, we employ the Karush-Kuhn-Tucker (KKT) optimality conditions to derive analytical expressions of the globally optimal NL, which take the influence of data rate, link access and routing into account. To handle larger scale planar networks, an iterative algorithm is proposed using the D&C approach. Numerical results illustrate that the proposed algorithm can be extended to the large planar case and its performance is close to globally optimal performance. Hui Wang 0006, Nazim Agoulmine, Maode Ma, Yanliang Jin |
IEEE J. Sel. Areas Commun. | 3 |
| 2010 | Narrowband Interference Mitigation in DS-UWB SystemsabstractInterference suppression is important for ultra-wideband (UWB) systems to operate over spectrum occupied by pre-existing narrowband systems. In this letter, we first extend the code-aided interference suppression technique to a direct sequence (DS) UWB system which has been proposed for narrowband interference (NBI) suppression in direct sequence spread spectrum (DSSS) systems. Then, we introduce a new type of spreading sequence, which significantly improves the NBI suppression capability of the code-aided technique. We also discuss a preamble-aided synchronization scheme for utilizing the new type of spreading sequence. Maode Ma, Rendong Ying |
IEEE Signal Process. Lett. | 2 |
| 2009 | A QoS-Based Vertical Handoff Scheme for Interworking of WLAN and WiMAXabstractIn this paper, we investigate the issue of vertical handoffs in heterogeneous wireless networks. A QoS-based vertical handoff scheme for WLAN and WiMAX interworking networks is proposed with aim to provide always best service to users. We also present a simple, yet efficient method to estimate the available bandwidth in WLAN and WiMAX networks to evaluate the real-time status of the overlay networks and make a handoff decision based on the information. By our proposal, a handoff process will not only be triggered by unaccepted signal strength but also by unsatisfied QoS parameters. Simulation results show that the proposed scheme can keep stations always be best connected with their QoS requirements met. Maode Ma |
GLOBECOM | 2 |
| 2009 | An energy-efficient MAC protocol with Adaptive Scheduling for wireless sensor networksabstractMedium access control (MAC) protocols play a crucial role in energy-efficiency, latency reduction for sensor networks. Many research efforts have been made to reduce energy consumption and shorten delay in multi-hop WSNs. Although some existing MAC protocols are energy-efficient and are able to mitigate the end-to-end delivery latency, there are great potential for further improvements. In this paper, we propose a new MAC protocol by introducing a new Adaptive Scheduling (AS) period within which the node's active duration is made adaptive to variable traffic load and able to resiliently schedule data packets for transmission in the Sleep period. The algorithm is designated to schedule more data packets for transmission in bursty and high traffic loads, thus enabling rapid dissemination of data and reduction of the end-to-end delivery latency. While in the light traffic loads, nodes enters the Sleep mode, mitigating idle listening and saving energy. Experiment results show that the proposed protocol is a great advancement of some existing protocols on performance, especially with heavy traffic loads. Yi Zhi Zhao, Thuy Ngoc Nguyen 0001, Maode Ma, Chunyan Miao |
INDIN | 3 |
| 2009 | A hybrid load balancing strategy of sequential tasks for grid computing environments
Ya-jun Li 0002, Maode Ma, Liang Zhou 0002 |
Future Gener. Comput. Syst. | 3 |
| 2009 | A utility-based joint power and rate adaptive algorithm in wireless ad hoc networksabstractIn this paper, a utility-based joint power and rate adaptive algorithm (UPRA) is proposed to alleviate the influence of channel variation by using softened signal-to-interference-and-noise ratio (SINR) requirements. The transmission power and rate of each user will be adjusted to maximize its own net-utility according to the states of channel, which results in a balance between the effective transmission rate and power consumption. Although the UPRA works based on a non-cooperative game, cooperation among users can be achieved so that the throughput of the whole network will be improved. The convergence of the algorithm has also been studied in both feasible and infeasible cases. Jialing Zheng, Maode Ma |
IEEE Trans. Commun. | 2 |
| 2009 | Design and Verification of Enhanced Secure Localization Scheme in Wireless Sensor NetworksabstractIn this paper, we focus on the need for secure and efficient localization for wireless sensor networks in adversarial settings. An attack-resistant and efficient localization scheme is developed, which extends the scheme proposed in [1]. The method offers strong defense against not only distance reduction attacks but also distance enlargement attacks. Furthermore, our method does not employ any device-dependent variables, hence yields more accurate localization. An attack-driven model is also specified using Petri net. It provides a formal method for the verification of our scheme when considering distance enlargement attacks. The state analysis shows that the potential insecure states are unreachable, implying that the model can offer strong defense against these attacks. To the best of our knowledge, it is the first time that the Petri net has been introduced to validate security scheme for wireless sensor networks in the literature. Daojing He, Hejiao Huang, Maode Ma |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2008 | Task scheduling by Mean Field Annealing algorithm in grid computingabstractDesirable goals for grid task scheduling algorithms would shorten average delay, maximize system utilization and fulfill user constraints. In this work, an agent-based grid management infrastructure coupled with mean field annealing (MFA) scheduling algorithm has been proposed. An agent in grid utilizes a neural network algorithm to manage and schedule tasks. The Hopfield neural network is good at finding optimal solution with multi-constraints and can be fast to converge to the result. However, it is often trapped in a local minimum. Stochastic simulated annealing algorithm has an advantage in finding the optimal solution and escaping from the local minimum. Both significant characteristics of Hopfield neural network structure and stochastic simulated annealing algorithm are combined together to yield a mean field annealing scheme. A modified cooling procedure to accelerate reaching equilibrium for normalized mean field annealing has been applied to this scheme. The simulation results show that the scheduling algorithm of MFA works effectively. Guixiang Xue, Maode Ma, Tonghua Su, Tianwen Zhang |
IEEE Congress on Evolutionary Computation | 3 |
| 2008 | AOA Cooperative Position LocalizationabstractIn wireless sensor networks, it is very important to obtain an accurate position of each sensor node. In this paper, we consider the potential of Ultra Wideband (UWB) signals for positioning due to its special characteristics. Accurate angle of arrival (AOA) can be obtained using UWB antenna arrays. We propose a new cooperative positioning method based on the AOA's. The method takes advantages of the pair-wise AOA's information among all the sensor nodes while existing positioning method only utilizes the AOA's from the anchor nodes. Then, the Cramer-Rao Lower Bound (CRLB) for Cooperative AOA localization is analyzed. Through the simulation experiments, we show that our proposed method could achieve higher positioning accuracy than existing non-cooperative positioning methods and its accuracy increases with the number of blind nodes. Maode Ma, Choi Look Law |
GLOBECOM | 2 |
| 2008 | Fluid-Based Modeling of TCP VenoabstractThis paper makes use of the fluid-based approach to model the throughput of TCP Veno flow over wired/wireless networks. A generalized formula is derived between Veno's throughput and its window evolution parameters, packet loss rate and round-trip time. Simulation experiments and real network measurements are conducted to validate the accuracy of this model. Ke Zhang 0025, Cheng Peng Fu, Chuan Heng Foh, Maode Ma, Jian Ling Zhang |
GLOBECOM | 4 |
| 2008 | Experimental evaluation of an adaptive PI rate controller for congestion controlabstractIn order to eliminate oscillation arisen from AIMD window control strategy in TCP, an adaptive PI rate controller (PI-RCA) was proposed to smooth the traffic and to prevent network from congestion. Theoretical analysis and simulation evaluation showed that PI-RCA can make flow control system achieve stability robustness and adapt to sudden changes in network environment, thus providing the network with good transient behaviors. In this paper, we present an implemental evaluation of PI-RCA. We first implemented PI-RCA in the Linux kernel and solved various system issues. Second, we conducted some experiments to validate the previous simulation results. Compared with TCP, the experimental results show that the PI-RCA is much more easily to maximize link/per-flow utilization, to achieve fairness and nearly zero packet drops rate. Maode Ma |
SMC | 2 |
| 2008 | An Analysis of K-Connectivity in Shadowing and Nakagami Fading Wireless Multi-Hop NetworksabstractIn this paper, we develop kappa-connectivity in wireless multi-hop networks in the presence of both the log-normal shadowing and Nakagami-m fading. The formula are generally applicable in a variety of realistic physical situations. Based on the results, we are able to find the critical node density to satisfy node kappa-connectivity almost with probability 1. In addition, kappa-connectivity shows significant difference with distinct channel conditions, which necessitates a generic result. The result is useful for the design of a wireless multi-hop network in practice. Lili Zhang 0004, Boon-Hee Soong, Yan Zhang 0002, Maode Ma, Yong Liang Guan 0001 |
VTC Spring | 4 |
| 2008 | A Queue Based Scheduling Approach for WMAN with Adaptive AugmentationabstractIEEE 802.16 Wireless Broadband is a promising technology for providing last mile access. Quality of Service (QoS) is an important factor that has been addressed by the standard which defines four types of multimedia traffic classes. However resource allocation and scheduling between the traffic classes is vital in providing QoS which the standard has left undefined. In this paper we propose a Markov Chain analytical model for a queue based uplink scheduling algorithm proposed earlier. The algorithm is based on resource sharing between real time and non real time traffic depending on their queue size and latency requirements. We then compare the analytical and simulation results. We also propose an adaptive scheduling scheme based on the delay feed back for the real-time flows and compare its performance with fixed scheduling. K. R. Raghu, Sanjay K. Bose, Maode Ma |
WCNC | 3 |
| 2008 | Packet delay analysis on IEEE 802.11 DCF under finite load traffic in multi-hop ad hoc networks
Linfang Dong, Yantai Shu, Haiming Chen 0002, Maode Ma |
Sci. China Ser. F Inf. Sci. | 4 |
| 2008 | Providing delay guaranteed service in CDMA wireless networks
Maode Ma, Qichao Zhu |
Comput. Commun. | 1 |
| 2008 | Providing differentiated services in CDMA wireless networksabstractWith much more advanced techniques employed, various applications can be supported by 3G CDMA-based wireless networks. Providing differentiated service over wireless networks has become a very important issue in the design of wireless networks. A new media access control protocol with a hierarchical scheduling algorithm to provide differentiated service for CDMA-based wireless networks is proposed. This protocol evolves from the distributed queuing random access protocol for CDMA wireless network. The proposed protocol has been designed to have an ability to accommodate integrated traffic in the networks with effective scheduling schemes. A series of simulation experiments have been carried out to evaluate the performance of the proposed protocol with the hierarchical scheduling algorithm. The results reveal that the proposed solution performs effectively in the integrated traffic composed of messages with or without time constraints and achieves proportional fairness among different types of traffic. Maode Ma, Qichao Zhu |
IET Commun. | 1 |
| 2008 | Optimal Scheduling for Minimum Delay in Passive Star Coupled WDM Optical NetworksabstractIn this paper, a local optimization framework is proposed, which is able to include system constraints including channel availability, receiver availability and tuning overhead by linear mathematical formulations so that it is sufficient to obtain the optimal performance in terms of message delay. A mixed integer linear programming (MILP) based scheme for passive star coupled WDM optical networks is presented. Based on the new solution, the wavelength assignment and message sequence that guarantee the delivery of the given traffic request, while minimizing the average delay can be achieved. Moreover, the negative effect of the tuning overhead has been incorporated into the new algorithm, which has been ignored in most of the previous work. Numerical results obtained suggest that the proposed scheme is a promising approach for optimizing the network performance in terms of average message delay. Xiaohong Huang 0003, Maode Ma |
IEEE Trans. Commun. | 2 |
| 2008 | Network lifetime maximization with cross-layer design in wireless sensor networksabstractThis paper investigates a cross-layer design approach for minimizing energy consumption and maximizing network lifetime (NL) of a multiple-source and single-sink (MSSS) WSN with energy constraints. The optimization problem for MSSS WSN can be formulated as a mixed integer convex optimization problem with the adoption of time division multiple access (TDMA) in medium access control (MAC) layer, and it becomes a convex problem by relaxing the integer constraint on time slots. Impacts of data rate, link access and routing are jointly taken into account in the optimization problem formulation. Both linear and planar network topologies are considered for NL maximization (NLM). With linear MSSS and planar single-source and single-sink (SSSS) topologies, we successfully use Karush-Kuhn-Tucker (KKT) optimality conditions to derive analytical expressions of the optimal NL when all nodes are exhausted simultaneously. The problem for planar MSSS topology is more complicated, and a decomposition and combination (D&C) approach is proposed to compute suboptimal solutions. An analytical expression of the suboptimal NL is derived for a small scale planar network. To deal with larger scale planar network, an iterative algorithm is proposed for the D&C approach. Numerical results show that the upper-bounds of the network lifetime obtained by our proposed optimization models are tight. Important insights into the NL and benefits of cross-layer design for WSN NLM are obtained. Hui Wang 0006, Maode Ma, Jianhua He 0001 |
IEEE Trans. Wirel. Commun. | 3 |
| 2007 | Network Lifetime Global Optimization by Duality Approach in Wireless Sensor NetworksabstractThe multi-source and single-sink (MSSS) topology of wireless sensor networks (WSNs) is defined as the network topology, where all of nodes can gather, receive and transmit data to the sink. We study the issue of finding the joint optimal scheme with consideration of physical, medium access control (MAC), and network layers to maximize the network lifetime (NL) for such topology in the energy-constrained WSNs. This paper presents a duality approach by utilizing the Karush-Kuhn- Tucker (KKT) optimality conditions to analytically provide a solution to this optimization problem. Analytical expression of the globally optimal NL is derived as a function of the amount of nodes, the initial energy and the data rate arrived at the nodes, taking the influence of data rates, link access and routing method into account. The analytical result agrees well with numerical result of the optimization solver and can be applied to algorithms in WSNs aiming at maximizing NL. Hui Wang 0006, Maode Ma |
GLOBECOM | 3 |
| 2007 | Theoretical Lower Bound for UWB TDOA PositioningabstractIndoor radio channels suffer multipath and non- line-of-sight (NLOS) fading, which is undesirable for accurate indoor positioning. High bandwidth of Ultra-wideband (UWB) implies high temporal resolution and hence high ranging accuracy. Furthermore, its robustness to multipath fading makes UWB perfect for indoor applications. This paper analyses the theoretical bounds of position estimation based on UWB time-difference-of-arrival (TDOA) measurements in multipath and NLOS environments. The TDOA range errors are modeled as range dependent, where the variance of the range errors is a function of the interested TDOA range. Cramer-Rao Lower Bound (CRLB) for distance- independent and distance-dependent TDOA range errors has been derived and compared. Maode Ma, Choi Look Law |
GLOBECOM | 2 |
| 2007 | A Utility-Based Joint Power and Rate Adaptive Algorithm for Wireless Ad Hoc NetworksabstractJoint power and rate adaptation mechanisms based on hard signal-to-interference-and-noise ratio (SINR) thresholds might suffer from variations of channel conditions. We propose a utility-based joint power and rate adaptation mechanism (UPRA) that is flexible against channel variations. Our mechanism selects power and rate by trading off among transmission rates, frame error rate and power consumption. By setting soft SINR requirement (utility) and considering the penalty of power consumption (cost), balancing could be achieved. The scheme is based on the non-cooperative game theory resulting in cooperation among nodes. This framework provides a promising policy when both the power and rate are controllable. Simulation results show significant improvements on throughput and energy consumption over the algorithm based on hard SINR thresholds. Jialing Zheng, Maode Ma |
GLOBECOM | 2 |
| 2007 | Backup Routing for Multimedia Transmissions over Mesh NetworksabstractA significant issue in mesh networks is to support multimedia transmissions while providing quality of service (QoS) guarantees to mobile users. For real-time multimedia streaming, unstable throughput or insufficient bandwidth will incur unexpected delay or jitter, and it remains difficult to provide comprehensive service guarantees for wireless mesh environment. In this paper, we target the problem of providing multimedia QoS in wireless mesh networks. We have designed and implemented a campus wireless mesh network testbed, and propose an available bandwidth estimation algorithm plus a QoS backup route mechanism to accommodate multimedia traffic flows in mobile wireless mesh networks. Moreover, to validate the correctness of our proposed algorithm, we have implemented the algorithm on the campus wireless mesh network testbed. Our implementation and experiments show that our mechanisms can improve the network stability, throughput, and delivery ratio effectively, while decreasing the number of route failures. Chungui Liu, Yantai Shu, Lianfang Zhang, Maode Ma |
ICC | 4 |
| 2007 | Network Lifetime Optimization by Duality Approach for Multi-Source and Single-Sink Topology in Wireless Sensor NetworksabstractThe multi-source and single-sink (MSSS) topology, in wireless sensor networks, is defined as the network topology, where all of nodes can gather, receive and transmit data to the sink. We consider the problem of finding the joint optimal scheme with consideration of physical, medium access control (MAC), and network layers to maximize the network lifetime (NL) for the MSSS topology in the energy-constrained wireless sensor networks (WSNs). The optimization problem, when the link access is an interference-free time division multiple access (TDMA) scheme, can be formulated as a mixed integer-convex programming and relaxed to the convex programming. According to the transcendental equations in programming model, we take two rather different approaches to maximize the NL in such network. First, based on the result of the SSSS network, we decompose the MSSS problem into the various SSSS issues. Another approach is to utilize the Karush-Kuhn-Tucker (KKT) optimization conditions to analytically solve this convex problem. Analytical expression of the optimal NL is a function of the initial energy and quantities of data held by the sources, taking the influence of data rates, link access and routing method into account. Although some dual gaps exist, the analytical result agrees well with numerical result of optimization solver, and can be applied to algorithms in WSNs aiming at maximizing NL. Hui Wang 0006, Maode Ma |
ICC | 3 |
| 2006 | A Power-Controlled Rate-Adaptive MAC Protocol to Support Differentiated Service in Wireless Ad Hoc NetworksabstractTo provide differentiated service is one of important issues in the design of wireless ad hoc networks. Traditionally, the provisioning of the differentiated service to different types of traffic streams is mainly supported at the medium access control layer with strict priority scheduling or weighted priority scheduling. In this paper, we propose a novel solution, named as Power-Controlled Rate-Adaptive medium access control (PCRA-MAC) scheme, to provide differentiated service by cross-layer consideration and design. The PCRA-MAC scheme exploits the features of multi-rate and power adjustable wireless transceiver system to achieve different transmission rates to support differentiated service. To the best of our knowledge, the PCRA-MAC scheme is the first and the only MAC scheme that generates different transmission rates for different types of traffic by tuning transmission power. Simulation experiments have proved that the PCRA-MAC scheme can effectively supports differentiated service in the wireless ad hoc networks. Maode Ma, Jialing Zheng, Yan Zhang 0002, Zhenhai Shao, Masayuki Fujise |
GLOBECOM | 1 |
| 2006 | SVM-Based Models for Predicting WLAN TrafficabstractA novel type of learning machine called support vector machine (SVM) has been receiving increasing interests in the areas ranging from its original application in pattern recognition to other applications such as regression estimation due to its remarkable generalization performance. In this paper, we employ the SVM to forecast traffic in WLANs. We study the issues of one-step-ahead prediction and multi-step-ahead prediction without any assumption on the statistical property of actual WLAN traffic. We also evaluate the performance of different prediction models using four real WLAN traffic traces. The simulation results will show that among these methods, SVM outperforms other prediction models in WLAN traffic forecasting for both one-step-ahead and multi-step-ahead prediction. Huifang Feng 0002, Yantai Shu, Shuyi Wang 0005, Maode Ma |
ICC | 4 |
| 2006 | Dynamic admission control in hybrid QoS networks with WiFi access
Yantai Shu, Hua Wang 0002, Maode Ma |
Sci. China Ser. F Inf. Sci. | 4 |
| 2006 | Hierarchical scheduling to support differentiated services in Ethernet passive optical networks
Maode Ma, Tee Hiang Cheng |
Comput. Networks | 2 |
| 2006 | Modeling location management in wireless networks with generally distributed parameters
Yan Zhang 0002, Jun Zheng 0003, Lili Zhang 0004, Yifan Chen 0001, Maode Ma |
Comput. Commun. | 5 |
| 2005 | An urgency fair queuing scheduling to support differentiated services in EPONsabstractThe Ethernet passive optical network (EPON) has recently attracted more attentions from the academic research and industry since it could be a perfect candidate for next generation access networks. Supporting differentiated services is an important issue for service providers to design an EPON system. In this paper, we propose an urgency fair queuing (UFQ) scheme to support DiffServ among multiple users in EPONs. It can achieve fairness by providing better services to best-effort users while guaranteeing the services for QoS users. The simulation results show that the UFQ scheme can effectively provide differentiated services for different classes of traffic Maode Ma, Tee Hiang Cheng |
GLOBECOM | 2 |
| 2004 | Message scheduling in WDM optical networks with reduced transmitter tuning overheadabstractRelatively large transmitter/receiver tuning overhead is one major difficulty when designing a medium access control scheme for a single hop passive star-coupled WDM optical network. Most schemes proposed so far have ignored the tuning overhead. To overcome this difficulty, two algorithms, namely continuous channel scheduling (CCS) and continuous channel-minimum scheduling latency (CC-MSL) is proposed to reduce the negative impact of tuning overhead as much as possible. Extensive simulations have been conducted. And the results show that there is significant improvement in average delay, which is achieved by the new proposed algorithms. Xiaohong Huang 0003, Maode Ma |
ICC | 2 |
| 2004 | Adaptive scheduling for integrated traffic on WDM optical networks
Maode Ma, Xiaohong Huang 0003 |
Comput. Networks | 1 |
| 2004 | An adaptive scheduling algorithm for differentiated services on WDM optical networks
Maode Ma, Mounir Hamdi |
Comput. Commun. | 1 |
| 2003 | A novel multiple access scheme for Ethernet passive optical networksabstractMultiple access control is an important issue in Ethernet passive optical networks (EPON). It is needed for traffic from different ONUs to share the upstream channel. The IEEE 802.3ah Ethernet in the first mile (EFM) task force has specified a multipoint control protocol (MPCP) for this purpose. We propose a novel multiple access control scheme consisting of a parameter-based call admission control (CAC) mechanism, the evenly distributed algorithm (EDA), and the bandwidth guarantee polling (BGP) algorithm. Our scheme can guarantee bandwidth for high-demand customers while providing best-effort service to low-demand customers according to the service level agreement (SLA). Simulation results show that the proposed scheme is very efficient. Maode Ma, Tee Hiang Cheng |
GLOBECOM | 2 |
| 2003 | A Bandwidth Guaranteed Polling MAC Protocol for Ethernet Passive Optical NetworksabstractWhile the backbone networks have experienced substantial changes in the last decade; the access networks have not changed much. Recently, passive optical networks (PONs) seem to be ready for commercial deployment in access networks due to the maturity of a number of enabling technologies, long distance and reduced maintenance. Among PON technologies, the Ethernet PON (EPON) presently being standardized by the IEEE 802.3ah Ethernet in the first miles (EFM) task force is most attractive because of its high speed, low cost, familiarity, interoperability and low overhead. In this paper, we propose a novel bandwidth guarantee polling (BGP) scheme that will allow the upstream bandwidth to be shared based on the service level agreement (SLA) between each subscriber and the operator. It is able to provide bandwidth guarantee for premium subscribers according to the SLAs while providing best-effort service to other subscribers. The analytical and simulation results prove that the proposed scheme does best in what it is designed to do compared to another well-known scheme that has not considered providing differentiated services. With business customers preferring premium services with guaranteed bandwidth and residential users preferring low-cost best effort services, our scheme could benefit both groups of subscribers as well as the operators. Maode Ma |
INFOCOM | 1 |
| 2001 | An adaptive scheduling algorithm for differentiated services on WDM optical networksabstractOne of the important issues in the design of next generation high-speed networks is to provide Differentiated Services to different types of applications with various time constraints. In this paper, we study the problem of providing real-time service to either hard or soft real-time messages in conjunction with a normal transmission service to variable-length messages without time constraints in wavelength division multiplexing (WDM) optical networks. We propose an adaptive scheduling algorithm to schedule and manage message transmissions in single-hop passive-star coupler based WDM optical networks. In particular, we develop an adaptive scheme for scheduling message transmissions in order to improve the network performance when both real-time and non real-time messages are transmitted in one single topology. In addition, we have conducted extensive discrete-event simulations to evaluate the performance of the proposed algorithm. This study suggests that when scheduling message transmission in WDM networks, a differentiated service should be considered to benefit the transmission of both real-time and non real-time messages so that the overall performance of the network could be improved. Maode Ma, Mounir Hamdi |
GLOBECOM | 1 |
| 2000 | Providing guaranteed deterministic performance service to multimedia applications on WDM optical networksabstractA major challenge in design of high-speed networks is to provide guaranteed quality of service for multimedia applications. We propose an admission control policy, a traffic regulator and a scheduling algorithm for the single-hop passive star coupled WDM optical networks. All of them are combined to ensure guaranteed deterministic performance service to multimedia applications. We set up an analytical model to evaluate the deterministic bounded message delay in the specified network based on the max-plus algebra. We conduct a trace-driven simulation with real MPEG traffic. We model MPEG traffic with the parameters of the real MPEG traffic and use them in discrete event simulations. Both simulation results show that our systematic scheme and our analysis are feasible to multimedia applications. Maode Ma, Mounir Hamdi |
GLOBECOM | 1 |
| 2000 | A Systematic Scheme for Guaranteed Deterministic Performance Service on WDM Optical NetworksabstractA major challenge in the design of future generation high-speed networks is to provide guaranteed quality of service for the real-time multimedia applications. In this paper, we study the problem of providing guaranteed deterministic performance service to the real-time and variable length messages in wavelength division multiplexing (WDM) optical networks. In particular, we propose an admission control policy, a traffic regulator and a scheduling algorithm for the single-hop passive star coupled WDM optical networks. All of them are combined to form a systematic scheme to ensure guaranteed performance service. We set up an analytical model to evaluate the deterministic bounded message delay in the specified network base on the max-plus algebra. Our simulation result shows that the delay bound we have set up is valid. Maode Ma, Mounir Hamdi |
ICC (3) | 1 |
| 2000 | Providing deterministic quality-of-service guarantees on WDM optical networksabstractA major challenge in the design of future generation high-speed networks is the provision of guaranteed quality-of-service (QoS) for a wide variety of multimedia applications. In this paper we investigate the problem of providing QoS guarantees to real-time variable length messages (e.g., IP packets) in wavelength division multiplexing (WDM) optical networks. In particular, we propose a systematic mechanism comprised of admission control, traffic regulation, and message scheduling that provide guaranteed performance service for real-time application streams made up of variable-length messages. We formulate an analytical model based on the theory of max-plus algebra to evaluate the deterministic bounded message delay in a WDM network environment using our proposed QoS guarantee mechanism to determine the "schedulability conditions" of multimedia application streams, We also conduct a series of discrete-event and trace-driven simulations to verify the accuracy of the analytical model. The simulation results demonstrate that the analytic delay bound we obtained for our WDM optical network is valid and accurate. Maode Ma, Mounir Hamdi |
IEEE J. Sel. Areas Commun. | 1 |
| 1999 | An Efficient Message Scheduling Algorithm for WDM Lightwave Networks
Maode Ma, Babak Hamidzadeh, Mounir Hamdi |
Comput. Networks | 1 |
| 1998 | Efficient Scheduling Algorithms for Real-Time Service on WDM Optical NetworksabstractWe study the problem of providing real-time service to hard and soft real-time messages in wavelength division multiplexing (WDM) optical networks. We propose and evaluate a set of scheduling algorithms which schedule message transmissions in single-hop WDM passive star networks based on specific time constraints. We compare the performances of our algorithms with that of the typical WDM scheduling algorithm which does not consider the time constraint of the transmitted messages by discrete-event simulations and an analytical model. We find that the improvement on real-time performance can be attributed to our scheduling algorithms where the time constraint of messages has been taken into consideration. This study suggests that when scheduling real-time messages in WDM networks, one has to consider not only the problem of resources allocation in the network but also the problem of sequencing messages based on their time constraints. Maode Ma, Babak Hamidzadeh, Mounir Hamdi |
ICCCN | 1 |