EDBT 2026 Demo / reviewers in the wild / expert
Kemal Akkaya
dblp:88/755
· DBLP profile ↗
160ranked-venue papers
16as first author
45since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 97 · 12 first-author · 21 since 2021Security and privacy · 23 · 10 since 2021Systems, architecture and hardware · 9 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 2Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PQ-CKEM: Efficient Quantum-Resistant Group Key Creation for Large-Scale LEO Satellite Networks
Yacoub Hanna, Maryna Veksler, Kemal Akkaya |
LANMAN | 3 |
| 2026 | Digital Forensic AI You Can Explain: A Case Study on Video Source Camera IdentificationabstractIn recent years, artificial intelligence (AI) has significantly impacted digital forensics, yet its broader deployment remains limited due to the difficulty of explaining AI decisions. Explainable AI (XAI) presents a promising solution to increase transparency and trust, but its application in digital forensics is still underexplored. In this work, we present a practical and structured explainable digital forensics AI (xDFAI) approach tailored to the forensic task of video source camera identification (VSCI). Our method enables forensic examiners to interpret the behavior of AI models, assess whether decisions are driven by intended logic or arise from random or content-dependent artifacts, and establish the integrity and reliability of explanations. We implement and evaluate this approach on two state-of-the-art VSCI models, providing step-by-step analysis of explanation quality, spatial consistency of high-impact features, and content dependence. Our results reveal that although models achieve strong classification accuracy, their explanations lack spatial stability and are impacted by video content, raising concerns about forensic reliability. To support reproducibility and future research, we provide an open-source implementation. This work underscores the potential of XAI to improve transparency in digital forensics and highlights the challenges of interpreting and presenting results. Our study takes an important step toward the operational deployment of xDFAI in multimedia forensics. Maryna Veksler, Kemal Akkaya, A. Selcuk Uluagac |
WACV | 2 |
| 2026 | Towards a standardized secure MPC outsourcing and management framework
Oscar G. Bautista, Kemal Akkaya, Soamar Homsi |
Future Gener. Comput. Syst. | 2 |
| 2025 | "I will always be by your side": A Side-Channel Aided PWM-based Holistic Attack Recovery for Unmanned Aerial VehiclesabstractUnmanned aerial vehicles (UAVs) play a crucial role across diverse applications but remain vulnerable to sophisticated cyber-physical attacks targeting their sensor-control-actuation systems. Traditional recovery mechanisms often focus narrowly on sensor or control system disruptions, neglecting the interconnected vulnerabilities, particularly at the actuator level. To address these gaps, we propose SHIELD: Side-channel analysis-based multimodal Holistic Intrusion Evaluation with Layered Defense. It is a comprehensive security framework that leverages side-channel data for robust detection, precise attack categorization, and tailored recovery processes across the entire UAV system. Side channels provide critical, hard-to-manipulate information that enhances the detection of sophisticated, stealthy attacks. By categorizing the specific nature of an attack, SHIELD selects the most appropriate recovery strategy, focusing on the integrity of pulse width modulation (PWM) signals to ensure effective recovery and mission continuity. This makes SHIELD a holistic approach across the sensor-control-actuation spectrum. Muneeba Asif, Jean Carlos Tonday Rodriguez, Mohammad Kumail Kazmi, Mohammad Ashiqur Rahman, Kemal Akkaya |
DSN | 5 |
| 2025 | Adaptive Solutions for DeFi: Leveraging T2EMA's Dynamic Oracle Protection
Haiyun Deng, Abdulhadi Sahin, Kemal Akkaya, A. Selcuk Uluagac |
ICBC | 3 |
| 2025 | A Cheating Detection and Recovery Framework for Robust Multiparty Computation in the CloudabstractStandard multiparty computation (MPC) protocols in dishonest-majority settings lack mechanisms to identify malicious actors or preserve computational progress, leaving them vulnerable to denial-of-service attacks in real-world deployments. Adversaries can force premature termination, resulting in wasted computational resources and significant financial losses. To address this challenge, we propose a comprehensive solution that integrates detection and recovery through three components: (1) a block-based computation model that decomposes monolithic MPC protocols into verifiable units for easy recovery; (2) lightweight cryptographic "canary values" that help detect and attribute malicious behavior without compromising privacy; and (3) a game-theoretic framework that creates economic incentives for honest protocol participation. Experimental evaluations demonstrate a reduction of up to 56.65% in recovery time compared to full restarts, with a computational overhead of 4.5%-11.8% depending on the configuration. The solution offers a practical trade-off between security and performance, thereby improving the viability of MPC in malicious cloud environments. Richard Hernandez, Kemal Akkaya, Soamar Homsi |
LCN | 2 |
| 2025 | Ensuring Continuous Connected Movement for a Swarm of Relocating DronesabstractCollaboration among drone swarms in various applications often requires dynamic data exchange to optimize their missions. When employing device-to-device (D2D) communications, drones must form connected topologies enabling multi-hop communication. Maintaining a connected topology during their movement to new locations is a major challenge that has not been tackled in the literature. In this paper, we first formalize this problem, proving the decision version is NP-Hard, and break it into sub-problems, detailing their complexity under certain constraints. We then propose polynomial time solutions to these subproblems. Our proposed approach first makes a location assignment for each drone to determine where to move as their next locations. Next, our approach relocates each drone to their designated target location without losing in-network connectivity of the drone topology. We achieve this by leveraging a two-step approach: contraction and re-expansion. In the contraction phase, drones converge towards a specific location, reducing network diameter and increasing connectivity. In the expansion phase, drones disperse to their new target positions. Mathematical proofs and extensive simulations validate our method’s effectiveness in maintaining connectivity during drone relocations. Fatih Senel, Kemal Akkaya, Mirko H. Wagner, Fritz Bökler, Nils Aschenbruck |
LCN | 2 |
| 2025 | Cryptocurrency forensics automation: a deep learning and NLP-based approach for mobile platformsabstractAs cryptocurrencies have become increasingly used as an alternative to regular cash and credit card payments, the wallet solutions/apps that facilitate their use have also become increasingly popular. This has also intensified the involvement of these crypto wallet apps in criminal activities such as ransom requests, money laundering, and transactions on dark markets. From a digital forensics point of view, it is crucial to have tools and reliable approaches to detect these wallets on devices and extract their artifacts quickly with greater efficiency. However, with current research and trends, forensic investigators still need to manually extract these file artifacts, which delays the time-sensitive investigation findings. As mobile devices increasingly facilitate cryptocurrency transactions, there emerges a critical gap and need for automated evidence extraction to detect crucial artifacts preventing illicit activities. Therefore, in this paper, we present a comprehensive framework that incorporates various machine learning (ML), image processing, and natural language processing (NLP) approaches to enable fast and automated extraction/triage of crypto-related artifacts from Android and iOS devices. Specifically, our method can automatically detect which crypto wallet exists on the device, their artifacts (i.e., database/log files), along with the crypto-related images, web browsing data, and SMS conversations. For each type of data, we offer a specific ML technique, such as Support Vector Machine, Logistic Regression, and Neural Networks, to detect and classify these files. Our evaluation results show very high accuracy compared to alternative tools: our wallet classification model achieves 91% recall, crypto-related image classification achieves 75% accuracy, browsing data achieves 100% accuracy, and the SMS message model achieves 85% accuracy. Abhishek Bhattarai, Abdulhadi Sahin, Maryna Veksler, Ahmet Kurt, Devrim Aras, Carlos Imery, Kemal Akkaya |
Discov. Comput. | 7 |
| 2024 | ConFIDe: A PWM-Driven Control-Fused Intrusion Detection System for Hardware Security in Unmanned Aerial VehiclesabstractWith the rise in the application of unmanned aerial vehicles (UAVs), security concerns associated with them have become paramount. Similar to other cyber-physical systems, the primary working principle behind UAVs follows the sensor-controller-actuation cycle. Errors between the setpoints and sensor data are computed through a PID controller and translated to pulse width modulated (PWM) signals that control the orientation and movement of a UAV. Recent research has demonstrated intentional electromagnetic interference (IEMI)-based alteration of PWM signals causing unauthorized maneuvers and crashes in UAVs. PWM alteration attacks can be carried out in various ways. For instance, hardware Trojans (HTs) can manipulate the PWM signals, and given the untrusted supply chain, HTs are a critical threat. Adversaries can exploit the PWM signals to manipulate UAV operations subtly, bypassing traditional intrusion detection systems (IDSs) that only monitor sensor data. Therefore, ensuring the integrity of PWM signals and their correlation with sensor and controller data is crucial for end-to-end UAV security. We address this need by proposing ConFIDe (Control-Fused Intrusion Detection system), a novel defense technique for UAVs. It verifies the integrity of the flight controller-generated PWM signals, ensuring the motors receive the signals free from hidden exploits. We validated our proposed IDS on different PWM alteration attack scenarios. In particular, we implemented a hardware Trojan attack targeting the PWM signals on a PX4-UAV to test the efficacy of the proposed IDS on a real system. ConFIDe performed well on all the attack scenarios, achieving a high ROC-AUC, including sensor attacks like GPS spoofing. Muneeba Asif, Mohammad Ashiqur Rahman, Kemal Akkaya, Ahmad Mohammad |
AsiaCCS | 3 |
| 2024 | Catch me if you can: Covert Information Leakage from Drones using MAVLink ProtocolabstractThe number of applications of unmanned aerial vehicles (UAVs) (aka drones) is rapidly expanding. However, the wireless and broadcast nature of communications between the drones and their operators (i.e., Ground control station (GCS)) presents a risk for this channel to be exploited by outsiders. Specifically, an attacker can abuse benign communications as a cover to leak sensitive drone data secretly to nearby adversaries within the transmission range of a drone. Therefore, in this paper, we investigate the threat of information leakage through MAVLink, a drone control protocol that is widely used in the majority of drone autopilot systems and is considered a de-facto standard. We show that multiple covert channels can be created in MAVLink by exploiting its lack of security mechanisms, default broadcast messages, and redundant features. We design and implement the novel covert channels on a realistic drone testbed in practical settings and assess their feasibility. Our extensive results demonstrate that attackers can effectively exfiltrate different types of sensitive data from drones with a high throughput via MAVLink-based covert channels in the presence of an active warden at the GCS. Finally, we provide an in-depth analysis of several countermeasures for MAVLink-based covert channels to improve the protocol's security. To the best of our knowledge, this is the first work exploiting the popular MAVLink protocol for covert communications and demonstrating how it can be manipulated by the adversary for secret communications over commodity drones. Maryna Veksler, Kemal Akkaya, A. Selcuk Uluagac |
AsiaCCS | 2 |
| 2024 | Optimizing the Parameters of Pipelined Multi-Party Computation for Privacy-Preserving Machine Learning ApplicationsabstractCloud Service Providers (CSPs) have recently significantly improved, allowing for outsourcing Machine Learning (ML) training and inference. However, due to the data privacy needs in most of the ML applications, several privacy-preserving technologies, such as Multi-party Computation (MPC), have been proposed to protect the data privacy. MPC offers splitting and exchanging of data among multiple parties, typically managed on cloud environments. Although MPC performs better than other alternatives, it still lags behind regular clear-text ML processing in terms of performance. To reduce the execution time of Privacy-Preserving ML (PPML) via MPC, parallelization of computation and communication among the parties (i.e., pipelined MPC), can be employed. However, the complex nature of these systems makes it challenging to select an optimal network and node configuration for executing a pipelined MPC. To address these challenges, in this paper, we propose a Multi-Objective Optimization (MOO) model focusing on achieving optimal configuration to minimize the MPC execution time along with its costs. We formulate an optimization model and propose two distinct approaches to solve it. Our evaluation clearly demonstrates a reduction in execution time and cost with respect to regular MPC execution. The evaluation results also provide valuable insights into the impact of latency and bandwidth considerations on our system's performance, contributing to PPML optimization. Richard Hernandez, Oscar G. Bautista, Kemal Akkaya |
ICC | 3 |
| 2024 | Integrating Post-Quantum TLS into the Control Plane of 5G NetworksabstractSignificant performance improvements in bandwidth and latency make 5G a suitable candidate for a wide range of applications, particularly those requiring real-time communication, such as Industrial Control Systems (ICS) and autonomous vehicles. However, today’s security, including modern cryptographic systems, is prone to different attacks caused by the high computational power of quantum computing, highlighting the need for integrating quantum-resistant security measures. To accommodate attacks targeted at 5G networks, there are efforts to move towards TLS-based security, which is the widely accepted standard across networks. However, integrating post-quantum algorithms must also be considered in such a transition. Thus, this paper is the first to perform the integration of Post-quantum TLS (PQ-TLS) protocols into 5G networks and offer a realistic performance evaluation. Our approach focuses on integrating PQ-TLS into the 5G control plane (CP) without requiring a major overhaul, thus ensuring communications’ interoperability even with legacy components of 5G, which may not support TLS. Specifically, we have updated the registration and authentication protocols for both core network functions and user equipment (UE) by implementing a TLS tunneling approach through virtualization. We then evaluate the performance and feasibility of PQ-TLS in enhancing the security of 5G communications on an actual testbed. Our results demonstrate that while PQ algorithms introduce some overhead, they remain viable for 5G applications, particularly for protocols that can run on the core network. Yacoub Hanna, Diana Pineda, Maryna Veksler, Manish Paudel, Kemal Akkaya, Mila Anastasova, Reza Azarderakhsh |
IPCCC | 5 |
| 2024 | Enhanced Outsourced and Secure Inference for Tall Sparse Decision TreesabstractA decision tree is an easy-to-understand tool that has been widely used for classification tasks. On the one hand, due to privacy concerns, there has been an urgent need to create privacy-preserving classifiers that conceal the user’s input from the classifier. On the other hand, with the rise of cloud computing, data owners are keen to reduce risk by outsourcing their model, but want security guarantees that third parties cannot steal their decision tree model. To address these issues, Joye and Salehi introduced a theoretical protocol that efficiently evaluates decision trees while maintaining privacy by leveraging their comparison protocol that is resistant to timing attacks. However, their approach was not only inefficient but also prone to side-channel attacks. Therefore, in this paper, we propose a new decision tree inference protocol in which the model is shared and evaluated among multiple entities. We partition our decision tree model by each level to be stored in a new entity we refer to as a "level-site." Utilizing this approach, we were able to gain improved average run time for classifier evaluation for a non-complete tree, while also having strong mitigations against side-channel attacks. Andrew Quijano, Spyros T. Halkidis, Kevin Gallagher 0001, Kemal Akkaya, Nikolaos Samaras |
IPCCC | 4 |
| 2024 | Privacy-Preserving Drone Navigation Through Homomorphic Encryption for Collision AvoidanceabstractAs drones increasingly deliver packages in neighborhoods, concerns about collisions arise. One solution is to share flight paths within a specific zip code, but this compromises business privacy by revealing delivery routes. For example, it could disclose which stores send packages to certain addresses. To avoid exposing path information, we propose using homomorphic encryption based comparison to compute path intersections. This allows drones to identify potential collisions without revealing path and destination details, allowing them to adjust altitude to avoid crashes. We implemented and tested our approach on resource-limited virtual machines to mimic the computational power of drones. Our results demonstrate that our method is significantly faster and requires less network communication compared to a garbled circuit-based approach. We also provide a security analysis of the approach against potential attacks. Allan Luedeman, Nicholas Baum, Andrew Quijano, Kemal Akkaya |
LCN | 4 |
| 2024 | DDoS Attack Detection and Mitigation in 5G Networks using P4 and SDNabstract5G is expected to support numerous Internet of Things (IoT) devices. However, the inherent vulnerabilities and limited resources of IoT devices make them susceptible to compromise and exploitation, potentially leading to Distributed Denial of Service (DDoS) attacks on 5G infrastructure from within. While conventional Intrusion Detection Systems (IDS) can assist, 5G’s unique protocols, such as the General Packet Radio Service (GPRS) Tunneling Protocol User Plane (GTP-U), pose challenges due to the inability to analyze packet headers. Therefore, we propose using Software-Defined Networking (SDN), Machine Learning (ML), and programmable switches that utilize the Programming Protocol-independent Packet Processors (P4) language to analyze GTP traffic on the fly for DDoS attack detection. Our framework enhances the efficiency of DDoS attack detection and mitigation, as demonstrated through evaluations on an actual 5G testbed using real datasets. Compared to an alternative solution that forwards GTP packets to the SDN controller, our method significantly reduces attack detection time while enhancing throughput on the SDN switch. Diana Pineda, Kemal Akkaya, Alexander Perez-Pons, A. Selcuk Uluagac, Abdulhadi Sahin |
LCN | 2 |
| 2024 | Cost-Based Modeling and Optimization of Secure Matrix Multiplication in the CloudabstractMachine Learning (ML) applications are prominent in many fields due to their ability to derive insights and automate processes. Many services utilize data from smart devices to offer personalized services to users. However, privacy concerns arise when sensitive data is collected by such devices for ML operations and outsourced to the cloud, along with the high liability costs associated with a security breach. Multiparty computation (MPC) is a promising method for privacy-preserving ML. Nonetheless, it has a significant computational overhead, mainly due to the large number of associated Matrix Multiplications (MM) in ML training and inference. This paper improves the arithmetic complexity of secure MM over MPC using the Strassen algorithm. We formulated a Multi-Objective Optimization Problem (MOOP) to optimize the trade-off among resource costs, execution time of secure MM, and the potential security loss due to a cyberattack. We implemented and analyzed the performance of several classical solutions to the MOOP, including Brute Force and the Non-Dominated Sorting Genetic Algorithm (NSGA). Using insights from these evaluations, we developed a solution, DepthSwift, which judiciously, efficiently, and quickly solves the MOOP for all required MMs in ML training or inference. Our implementation over SPDZ shows that we can significantly reduce resource costs and minimize potential security loss with respect to the naive MM over MPC. Richard Hernandez, Kemal Akkaya, Soamar Homsi |
SMARTCOMP | 2 |
| 2024 | D-LNBot: A Scalable, Cost-Free and Covert Hybrid Botnet on Bitcoin's Lightning NetworkabstractWhile various covert botnets were proposed in the past, they still lack complete anonymization for their servers/botmasters or suffer from slow communication between the botmaster and the bots. In this paper, we first propose a new generation hybrid botnet that covertly and efficiently communicates over Bitcoin Lightning Network (LN), called LNBot. Exploiting various anonymity features of LN, we show the feasibility of a scalable two-layer botnet which completely anonymizes the identity of the botmaster. In the first layer, the botmaster anonymously sends the commands to the command and control (C&C) servers through regular LN payments. Specifically, LNBot allows botmaster's commands to be sent in the form of surreptitious multi-hop LN payments, where the commands are either encoded with the payments or attached to the payments to provide covert communications. In the second layer, C&C servers further relay those commands to the bots in their mini-botnets to launch any type of attacks to victim machines. We further improve on this design by introducing D-LNBot; a distributed version of LNBot that generates its C&C servers by infecting users on the Internet and forms the C&C connections by opening channels to the existing nodes on LN. In contrary to the LNBot, the whole botnet formation phase is distributed and the botmaster is never involved in the process. By utilizing Bitcoin's Testnet and the new message attachment feature of LN, we show that D-LNBot can be run for free and commands are propagated faster to all the C&C servers compared to LNBot. We presented proof-of-concept implementations for both LNBot and D-LNBot on the actual LN and extensively analyzed their delay and cost performance. Finally, we also provide and discuss a list of potential countermeasures to detect LNBot and D-LNBot activities and minimize their impacts. Ahmet Kurt, Enes Erdin, Kemal Akkaya, A. Selcuk Uluagac, Mumin Cebe |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | LNGate$^{2}$2: Secure Bidirectional IoT Micro-Payments Using Bitcoin's Lightning Network and Threshold CryptographyabstractBitcoin has emerged as a revolutionary payment system with its decentralized ledger concept; however it has significant problems such as high transaction fees and low throughput. Lightning Network (LN), which was introduced much later, solves most of these problems with an innovative concept called off-chain payments. With this advancement, Bitcoin has become an attractive venue to perform micro-payments which can also be adopted in many IoT applications (e.g., toll payments). Nevertheless, it is not feasible to host LN and Bitcoin on IoT devices due to the storage, memory, and processing restrictions. Therefore, in this paper, we propose a secure and efficient protocol that enables an IoT device to use LN's functions through an untrusted gateway node. Through this gateway which hosts the LN and Bitcoin nodes, the IoT device can open & close LN channels and send & receive LN payments. This delegation approach is powered by a threshold cryptography based scheme that requires the IoT device and the LN gateway to jointly perform all LN operations. Specifically, we propose thresholdizing LN's Bitcoin public and private keys as well as its public and private keys for the new channel states (i.e., commitment points). We prove with a game theoretical security analysis that the IoT device is secure against collusion attacks. We implemented the proposed protocol by changing LN's source code and thoroughly evaluated its performance using several Raspberry Pis. Our evaluation results show that the protocol; is fast, does not bring extra cost overhead, can be run on low data rate wireless networks, is scalable and has negligible energy consumption overhead. To the best of our knowledge, this is the first work that implemented threshold cryptography in LN. Ahmet Kurt, Kemal Akkaya, Sabri Yilmaz, Suat Mercan, Omer Shlomovits, Enes Erdin |
IEEE Trans. Mob. Comput. | 2 |
| 2023 | Adversarial Data-Augmented Resilient Intrusion Detection System for Unmanned Aerial VehiclesabstractWith the growing adoption of unmanned aerial vehicles (UAVs) across various domains, the security of their operations is paramount. UAVs, heavily dependent on GPS navigation, are at risk of jamming and spoofing cyberattacks, which can severely jeopardize their performance, safety, and mission integrity. Intrusion detection systems (IDSs) are typically employed as defense mechanisms, often leveraging traditional machine learning techniques. However, these IDSs are susceptible to adversarial attacks that exploit machine learning models by introducing input perturbations. In this work, we propose a novel IDS for UAVs to enhance resilience against such attacks using generative adversarial networks (GAN). We also comprehensively study several evasion-based adversarial attacks and utilize them to compare the performance of the proposed IDS with existing ones. The resilience is achieved by generating synthetic data based on the identified weak points in the IDS and incorporating these adversarial samples in the training process to regularize the learning. The evaluation results demonstrate that the proposed IDS is significantly robust against adversarial machine learning-based attacks compared to the state-of-the-art IDSs while maintaining a low false positive rate. Muneeba Asif, Mohammad Ashiqur Rahman, Kemal Akkaya, Hossain Shahriar, Alfredo Cuzzocrea |
IEEE Big Data | 3 |
| 2023 | Performance Evaluation of Quantum-Resistant TLS for Consumer IoT DevicesabstractPost-quantum (PQ) cryptographic algorithms are currently being developed to be able to resist attacks by quantum computers. The practical use of these algorithms for securing networks will depend on their computational and communication efficiency. In particular, this is critical for the security of wireless communications within the context of consumer IoT devices that may have limited computational power and depend on a constrained wireless bandwidth. To this end, there is a need to evaluate the performance of widely used application layer security standards such as transport layer security (TLS) to understand the use of the existing PQ algorithms that are being evaluated by NIST as a replacement to the current cryptographic algorithms. This paper focuses on two widely used IoT standards Bluetooth Low Energy (BLE) and WiFi to find out the optimal performing PQ algorithm for their security when used in end-to-end connections over the Internet. By implementing the capability for IP over BLE and all options of TLS connection establishment, we developed a client-server IoT testbed to measure the efficiency of PQ key encapsulation mechanisms (KEMs) and PQ digital signature algorithms. The test results showed that Kyber512 is the ideal KEM while Falcon-512 and Dilithium2 are the best signatures for BLE and WiFi devices. Based on this outcome, we developed a mechanism for IoT devices with multiple communication interfaces, that dynamically chooses a PQ KEM algorithm based on the MAC layer protocol being used at the time. Jessica Bozhko, Yacoub Hanna, Ricardo Harrilal-Parchment, Samet Tonyali, Kemal Akkaya |
CCNC | 5 |
| 2023 | Outsourcing Privacy-Preserving Federated Learning on Malicious Networks through MPCabstractWhile Federated Learning (FL) enables training by only sharing model updates rather than data, FL can still be prone to privacy leaks. Therefore, many efforts have been made to adopt homomorphic encryption or differential privacy approaches to prevent this. However, these solutions come with several issues that may limit their widespread adoption in applications that involve sensitive data sitting in silos. Such issues include but are not limited to trust in the aggregation server, the accuracy of the model, potential collusion among clients, and limited aggregation function support. To address these issues, we advocate using secure Multiparty Computation (MPC) to offer privacy-preserving computation. Specifically, we propose an FL framework that enables outsourcing the model aggregation to MPC parties on untrusted cloud environments and offers correctness verification to the model owners. Unlike differential privacy-based solutions, the proposed framework offers the same level of accuracy as models that are trained on the clear and minimize the possibility of collusion among clients and MPC parties. We implemented and evaluated the proposed framework under various conditions. The results showed that our framework can match the accuracy of centralized FL training while maintaining the required level of privacy and security in malicious cross-silo settings. Richard Hernandez, Oscar G. Bautista, Mohammad Hossein Manshaei, Abdulhadi Sahin, Kemal Akkaya |
LCN | 5 |
| 2023 | Privacy-Preserving Collision Detection for Drone-based Aerial Package Delivery using Secure Multi-Party ComputationabstractAs drones become more widely available, they find applications in many different fields. One of the most promising applications of drones is to use them in deliveries of items/food within certain distances to offer quick service for the customers. In such cases, we will see many different companies deploying drone ducking stations within a neighborhood and fly drones frequently during the day. However, as more companies get into this domain, this will increase the potential for collisions as several drones will simultaneously fly to destinations that are close to each other. Therefore, there is a need to coordinate their trajectory planning in advance by sharing information about their trajectories and destinations. Nevertheless, since drones belong to different companies sharing this information may violate the privacy of their customers and also expose their business privacy. The sharing needs to be done in a privacy-preserving manner just in time so that collisions can be avoided. In this paper, we propose a secure multi-party computation based trajectory planning among the drones. Specifically, a drone shares information with others via wireless communication within their range and performs local computation to check if there is any potential for collisions using Shamir's secret sharing. If there is, the trajectory can be modified (e.g., by changing the altitude of the drone). As part of the computation, we propose an approach which enables comparison of the trajectories by representing them as matrices and performing addition on these matrices since comparison operation is challenging to achieve in Shamir's secret sharing. We implemented a preliminary prototype of this approach using Raspberry PI devices. We demonstrated the feasibility and overhead of the proposed approach under a variety of conditions. Anushka Desai, Oscar G. Bautista, Kemal Akkaya |
MobiHoc | 3 |
| 2023 | MPC-as-a-Service: A Customizable Management Protocol for Running Multi-party Computation on IoT DevicesabstractTechniques to perform computations without disclosing the input values have notably improved in the last decade. One such technology, called Secure Multiparty Computation (MPC), where two or more computation nodes hold secret pieces of private data and jointly execute a protocol to obtain a function output, has proven effective for preserving privacy in many applications (e.g., distributed signing, financial scores, machine learning, and more). Nonetheless, in many cases, the data source and computation nodes are often assumed to be the same, with the existence of a manually preconfigured network before they start the computation. This challenge is typical of many IoT applications where the IoT devices need to collaborate using MPC but do not have the resources, and thus outsource the tasks to powerful MPC nodes. Nonetheless, in such a scenario, the IoT devices do not know the MPC nodes, and vice-versa to manage the overall process. To fill this gap, we propose an MPC management protocol that automates the registration and authentication of a group of clients (i.e., sources and consumers of data) and MPC servers (the private computation providers), the requesting of MPC jobs, and receiving the results thereafter. Our experiments over a cloud environment demonstrate the first protocol that efficiently and securely automates the management of MPC systems on many use cases, which would otherwise take considerable time and effort. Oscar G. Bautista, Kemal Akkaya |
NOMS | 2 |
| 2023 | SDN-based GTP-U Traffic Analysis for 5G Networksabstract5G networks denote a revolutionary improvement in wireless communication by introducing three service grades: Enhanced Mobile Broadband (eMBB), Ultra-Reliable Low Latency Communications (URLLC), and Massive Machine Type Communications (mMTC). These three service grades represent a cost-efficient solution and enhanced user experience with higher data rates and lower latency. However, at the same time, these aspects can benefit attackers (e.g., by leveraging the support for mMTC) to launch various attacks effectively. mMTC comes with a massive number of unattended Internet of Things (IoT) devices known for having low-security capabilities. One of the biggest security concerns related to IoT is that it increases the chances of internal DDoS attacks, which can disrupt 5G core network services. In this paper, we propose our ongoing work on monitoring the GPRS Tunneling Protocol User Plane (GTP-U) traffic, which is used to transport user data from User Equipment (UE) devices. We offer internal traffic filtering mechanisms using Software Defined Networks (SDN) to block the IoT traffic that appears to be malicious. The proposed approach is implemented in a 5G testbed to evaluate the performance and efficiency of factual scenarios. Diana Pineda, Ricardo Harrilal-Parchment, Kemal Akkaya, Alexander Perez-Pons |
NOMS | 3 |
| 2023 | ReplayMPC: A Fast Failure Recovery Protocol for Secure Multiparty Computation Applications using BlockchainabstractAlthough recent performance improvements to Secure Multiparty Computation (SMPC) made it a practical solution for complex applications such as privacy-preserving machine learning (ML), other characteristics such as robustness are also critical for its practical viability. For instance, since ML training under SMPC may take longer times (e.g., hours or days in many cases), any interruption of the computation will require restarting the process, which results in more delays and waste of computing resources. While one can maintain exchanged SMPC messages in a separate database, their integrity and authenticity should be guaranteed to be able to re-use them later. Therefore, in this paper, we propose ReplayMPC, an efficient failure recovery mechanism for SMPC based on blockchain technology that enables resuming and re-synchronizing SMPC parties after any type of communication or system failures. Our approach allows SMPC parties to save computation state snapshots they use as restoration points during the recovery and then reproduce the last computation rounds by retrieving information from immutable messages stored on a blockchain. Our experiment results on Algorand blockchain show that recovery is much faster than starting the whole process from scratch, saving time, computation, and networking resources. Oscar G. Bautista, Kemal Akkaya, Soamar Homsi |
SMARTCOMP | 2 |
| 2023 | Privacy-Preserving V2V Charge Sharing Coordination using the Hungarian AlgorithmabstractElectric Vehicles (EVs) are being widely adopted as a green alternative to fossil-based vehicles. However, the current charging infrastructure for EVs is inadequate to meet the growing charge demand. Vehicle-to-Vehicle (V2V) charging offers a promising solution that enables a charge supplier EV to provide charging services to a charge demander EV in a distributed manner. Nevertheless, V2V matching and charge scheduling can disclose sensitive location information about the drivers, such as their whereabouts and driving patterns. In this paper, we propose a privacy-preserving scheme for centralized optimal matching of demander EVs with supplier EVs, while protecting their sensitive information. In our scheme, charge demanders report to a matching server their encrypted location information and the requested energy quantities, whereas charge suppliers report encrypted charge costs such that the matching server can learn only the cost to match each demander to each supplier without revealing any location information or the exchanged charge amount. Then, the Hungarian algorithm is used to match demanders to suppliers while minimizing the total cost. The security analysis and simulation results show that our scheme can achieve optimal V2V matching while preserving drivers’ privacy with negligible computation overhead. Overall, our proposed scheme provides an effective solution for V2V charging, while maintaining privacy and confidentiality of sensitive drivers’ information. Ahmed Bakr, Mahmoud Srewa, Eyuphan Bulut, Kemal Akkaya, Ahmad Alsharif |
VTC2023-Spring | 4 |
| 2023 | LNMesh: Who Said You need Internet to send Bitcoin? Offline Lightning Network Payments using Community Wireless Mesh NetworksabstractBitcoin is undoubtedly a great alternative to today’s existing digital payment systems. Even though Bitcoin’s scalability has been debated for a long time, we see that it is no longer a concern thanks to its layer-2 solution Lightning Network (LN). LN has been growing non-stop since its creation and enabled fast, cheap, anonymous, censorship-resistant Bitcoin transactions. However, as known, LN nodes need an active Internet connection to operate securely which may not be always possible. For example, in the aftermath of natural disasters or power outages, users may not have Internet access for a while. Thus, in this paper, we propose LNMesh which enables offline LN payments on top of wireless mesh networks. Users of a neighborhood or a community can establish a wireless mesh network to use it as an infrastructure to enable offline LN payments when they do not have any Internet connection. As such, we first present proof-of-concept implementations where we successfully perform offline LN payments utilizing Bluetooth Low Energy and WiFi. For larger networks with more users where users can also move around, channel assignments in the network need to be made strategically and thus, we propose 1) minimum connected dominating set; and 2) uniform spanning tree based channel assignment approaches. Finally, to test these approaches, we implemented a simulator in Python along with the support of BonnMotion mobility tool. We then extensively tested the performance metrics of large-scale realistic offline LN payments on mobile wireless mesh networks. Our simulation results show that, success rates up to %95 are achievable with the proposed channel assignment approaches when channels have enough liquidity. Ahmet Kurt, Abdulhadi Sahin, Ricardo Harrilal-Parchment, Kemal Akkaya |
WoWMoM | 4 |
| 2023 | Ivycide: Smart Intrusion Detection System Against E-IoT Driver ThreatsabstractThe rise of Internet of Things (IoT) devices has led to the proliferation of smart environments worldwide. Although commodity IoT devices are employed by ordinary end users, complex environments, such as smart buildings, government, or private offices, or conference rooms require customized and highly reliable IoT solutions. Enterprise IoT (E-IoT) connect such environments to the Internet and are professionally managed solutions usually offered by dedicated vendors As E-IoT systems require specialized training, closed-source software, and proprietary equipment to deploy. In effect, E-IoT systems present an unprecedented, under-researched, and unexplored threat vector for an attacker. In this work, we focus on E-IoT drivers, software modules used to integrate devices into E-IoT systems, as an attack mechanism. We first present PoisonIvy, a series of generalized proof-of-concept attacks used to demonstrate that an attacker can use a malicious driver to perform denial-of-service attacks, gain remote control, and abuse E-IoT system resources. To defend against E-IoT driver-based threats, we introduce Ivycide, a novel intrusion detection system used to detect unexpected E-IoT network traffic from an E-IoT system. Ivycide operates as a passive monitoring system within an E-IoT system using machine learning and signature-based classification to detect Poisonivy attacks. We evaluated the performance of Ivycide in a realistic E-IoT deployment. Our detailed evaluation results show that Ivycide achieves an average accuracy of 97% in classifying the type of Poisonivy attack and operates without modifications or operational overhead to the existing E-IoT systems. Luis Puche Rondon, Leonardo Babun, Ahmet Aris, Kemal Akkaya, A. Selcuk Uluagac |
IEEE Internet Things J. | 4 |
| 2022 | On Algorand Transaction Fees: Challenges and Mechanism DesignabstractAlgorand is a public proof-of-stake (PoS) blockchain with a throughput of 750 MB of transactions per hour, 125 times more than Bitcoin. While the throughput of Algorand depends on the participation of most of its nodes, rational nodes may behave selfishly and not cooperate with others. To encourage nodes to participate in the consensus protocol, Algorand rewards nodes in each round. However, currently Algorand does not pay transaction fees to participating nodes, rather storing it for future use. In this paper, we show that this current approach of Algorand motivates selfish block proposers to increase their profits by creating empty blocks. Such selfish behavior reduces the throughput of Algorand. Therefore, the price of Algo will decrease in the long run. Because of this price reduction, nodes will leave Algorand, compromising its security. Moreover, lack of an appropriate mechanism to pay fees to participants causes additional issues, such as lack of transparency, centralization, and inability of nodes to prioritize transactions. To overcome this challenge, we design a perfectly competitive market and propose an algorithm for computing optimal transaction fees and block size in Algorand We also propose an algorithm that reduces the cost of Algorand, without compromising its security. We further simulate the Algorand network and show how the optimal transaction fee and block size can be calculated in practice. Maryam Abbasi, Mohammad Hossein Manshaei, Mohammad Ashiqur Rahman, Kemal Akkaya, Murtuza Jadliwala |
ICC | 4 |
| 2022 | Crypto Wallet Artifact Detection on Android Devices Using Advanced Machine Learning Techniques
Abhishek Bhattarai, Maryna Veksler, Hadi Sahin, Ahmet Kurt, Kemal Akkaya |
ICDF2C | 5 |
| 2022 | Image-to-Image Translation Generative Adversarial Networks for Video Source Camera Falsification
Maryna Veksler, Clara Caspard, Kemal Akkaya |
ICDF2C | 3 |
| 2022 | Optimal Incentive Mechanisms for Fair and Equitable Rewards in PoS BlockchainsabstractBlockchain technology that came with the introduction of Bitcoin offers many powerful use-cases while promising the establishment of distributed autonomous organizations (DAOs) that may transform our current understanding of client-server interactions on the cyberspace. They employ distributed consensus mechanisms that were subject to a lot of research in recent years. While most of such research focused on security and performance of consensus protocols, less attention was given to their incentive mechanisms which relate to a critical feature of blockchains. Unfortunately, while blockchains are advocating decentralized operations, they are not egalitarian due to existing incentive mechanisms. Many current consensus protocols inadvertently incentivize centralization of mining power and inequitable participation. This paper explores and evaluates alternative incentive mechanisms for a more decentralized and equitable participation. We first evaluate inequality in existing Proof of Stake (PoS) based incentive mechanisms, then we examine three alternatives in which rewards scheme is more partial to low-stakeholders. Through simulation, we show that two of our alternative mechanisms can reduce inequality and offer an attractive solution for sustainability of blockchain-based applications and DAOs. Hadi Sahin, Kemal Akkaya, Sukumar Ganapati |
IPCCC | 2 |
| 2022 | Network-Efficient Pipelining-Based Secure Multiparty Computation for Machine Learning ApplicationsabstractSecure multi-party computation (SMPC) allows mutually distrusted parties to evaluate a function jointly without revealing their private inputs. This technique helps organizations collaborate on a common goal without disclosing confidential or protected data. Despite its suitability for privacy-preserving computation, SMPC suffers from network-based performance limitations. Specifically, the SMPC parties perform the techniques in rounds, where they execute a local computation and then share their round output with the other parties. This network interchange creates a bottleneck as parties need to wait until the data propagates before resuming the execution. To reduce the SMPC execution time, we propose a pipelining-like approach for each round’s computation and communication by dividing the data and readjusting the execution order. Targeting deep learning applications, we propose strategies for the case of matrix multiplication, a core component of such applications. Our results on a distributed cloud deployment show a significant reduction in the SMPC execution time. Oscar G. Bautista, Kemal Akkaya |
LCN | 2 |
| 2022 | Survey on Enterprise Internet-of-Things systems (E-IoT): A security perspective
Luis Puche Rondon, Leonardo Babun, Ahmet Aris, Kemal Akkaya, A. Selcuk Uluagac |
Ad Hoc Networks | 4 |
| 2021 | A General and Practical Framework for Realization of SDN-based Vehicular NetworksabstractWith the recent developments of communication technologies surrounding vehicles, we will be witnessing the simultaneous availability of multiple on-board communication interfaces on vehicles. While most of the current interfaces already include Bluetooth, WiFi, and LTE, they will be augmented further by IEEE 802.11p and the 5G interfaces, which will serve for safety, maintenance, and infotainment applications. However, dynamic management of interfaces depending on application needs will become a significant issue that can be best addressed by Software Defined Networking (SDN) technology. While SDN-based vehicular networks have been promoted previously, none of these works dealt with their practical challenges. In this paper, we propose and develop a practical framework that will realize SDN-based vehicular networks for a wide range of applications. Through this framework, we demonstrate a platoon example which demonstrates the use of SDN for quick and efficient multi-hop messaging. The route from source vehicle to destination is computed with the help of the SDN Controller to transmit the Beacon Safety Messages through Road Side Units (RSUs) at the MAC layer without relying on IP for proper platooning operations. The results show the efficiency of the SDN-based approach compared to the traditional routing approaches. Juan V. Leon, Oscar G. Bautista, Abdullah Aydeger, Suat Mercan, Kemal Akkaya |
IPCCC | 5 |
| 2021 | Outsourcing Secure MPC to Untrusted Cloud Environments with Correctness VerificationabstractWith the increasing interest in Secure Multi-Party Computation protocols (MPC), there have been several works such as the SPDZ1protocol that tackled this problem under a malicious security with dishonest majority attack model. However, most of these MPC efforts assume that the nodes running the computations are also supplying the inputs, which is not a realistic assumption for many real-life applications. In this paper, we extend the SPDZ protocol to enable clients outsource data and computation to the clouds while ensuring the correctness of the results, in addition to integrity and confidentiality of the input and output. We guarantee that the computation among nodes is done correctly by verifying their output’s Message Authentication Codes (MACs) at the end. Specifically, we delegate this task to an honest server. Our approach strives to minimize the burden on clients while enabling cheating detection even when assuming a malicious attack model with dishonest majority. Oscar G. Bautista, Kemal Akkaya, Soamar Homsi |
LCN | 2 |
| 2021 | A Proxy Signature-Based Drone Authentication in 5G D2D Networksabstract5G is the beginning of a new era in cellular communication, bringing up a highly connected network with the incorporation of the Internet of Things (IoT). To flexibly operate all the IoT devices over a cellular network, Device-to-Device (D2D) communication standard was developed. However, IoT devices such as drones utilizing 5G D2D services could be a perfect target for malicious attacks as they pose several safety threats if they are compromised. Furthermore, there will be heavy traffic with an increased number of IoT devices connected to the 5G core. Therefore, we propose a lightweight, fast, and reliable authentication mechanism compatible with the 5G D2D ProSe standard mechanisms. Specifically, we propose a distributed authentication with a delegation-based scheme instead of the repeated access to the 5G core network key management functions. Hence, a legitimate drone is authorized by the core network via offering a proxy signature to authenticate itself to other drones. We implemented the proposed protocol in ns-3 that supports 5G D2D-based communication. We also conducted computational calculations on the RaspberryPi3 IoT device to mimic the drone calculation process and delays. The results demonstrate that the proposed protocol is lightweight and reliable. Mai A. Abdel-Malek, Kemal Akkaya, Arupjyoti Bhuyan, Ahmed S. Ibrahim 0001 |
VTC Spring | 2 |
| 2021 | LNGate: powering IoT with next generation lightning micro-payments using threshold cryptographyabstractBitcoin has emerged as a revolutionary payment system with its decentralized ledger concept however it has significant problems such as high transaction fees and long confirmation times. Lightning Network (LN), which was introduced much later, solves most of these problems with an innovative concept called off-chain payments. With this advancement, Bitcoin has become an attractive venue to perform micro-payments which can also be adopted in many IoT applications (e.g. toll payments). Nevertheless, it is not feasible to host LN and Bitcoin on IoT devices due to the storage, memory, and processing requirements. Therefore, in this paper, we propose an efficient and secure protocol that enables an IoT device to use LN through an untrusted gateway node. The gateway hosts LN and Bitcoin nodes and can open & close LN channels, send LN payments on behalf of the IoT device. This delegation approach is powered by a (2,2)-threshold scheme that requires the IoT device and the LN gateway to jointly perform all LN operations which in turn secures both parties' funds. Specifically, we propose to thresholdize LN's Bitcoin public and private keys as well as its commitment points. With these and several other protocol level changes, IoT device is protected against revoked state broadcast, collusion, and ransom attacks. We implemented the proposed protocol by changing LN's source code and thoroughly evaluated its performance using a Raspberry Pi. Our evaluation results show that computational and communication delays associated with the protocol are negligible. To the best of our knowledge, this is the first work that implemented threshold cryptography in LN. Ahmet Kurt, Suat Mercan, Omer Shlomovits, Enes Erdin, Kemal Akkaya |
WISEC | 5 |
| 2021 | LightningStrike: (in)secure practices of E-IoT systems in the wildabstractThe widespread adoption of specialty smart ecosystems has changed the everyday lives of users. As a part of smart ecosystems, Enterprise Internet of Things (E-IoT) allows users to integrate and control more complex installations in comparison to off-the-shelf IoT systems. With E-IoT, users have a complete control of audio, video, scheduled events, lightning fixtures, shades, door access, and relays via available user interfaces. As such, these systems see widespread use in government or smart private offices, schools, smart buildings, professional conference rooms, hotels, smart homes, yachts, and similar professional settings. However, even with their widespread use, the security of many E-IoT systems has not been researched in the literature. Further, many E-IoT systems utilize proprietary communication protocols that rely mostly on security through obscurity, which has perhaps led many users to mistakenly assume that these systems are secure. To address this open research problem and determine if E-IoT systems are vulnerable, we focus on one of the core E-IoT components, E-IoT communication buses. Communication buses are used by E-IoT proprietary protocols to connect multiple E-IoT devices (e.g., keypads and touchscreens) and trigger pre-configured events upon user actions. In this study, we introduce LightningStrike, the implementation of four proof-of-concept attacks that demonstrate several weaknesses in E-IoT proprietary communication protocols through communication buses. With LightningStrike, we show that it is feasible for an attacker to compromise E-IoT systems using E-IoT communication buses. We demonstrate that popular E-IoT proprietary communication protocols are susceptible to Denial-of-Service, eavesdropping, impersonation, and replay attacks. As E-IoT systems control physical access, safety components, and emergency equipment, an attacker with a low level of knowledge and effort can easily exploit E-IoT vulnerabilities to impact the security and safety of users, smart systems, and smart buildings worldwide. Luis Puche Rondon, Leonardo Babun, Ahmet Aris, Kemal Akkaya, A. Selcuk Uluagac |
WISEC | 4 |
| 2021 | Improving transaction success rate in cryptocurrency payment channel networks
Suat Mercan, Enes Erdin, Kemal Akkaya |
Comput. Commun. | 3 |
| 2021 | Communication-efficient certificate revocation management for Advanced Metering Infrastructure and IoT Integration
Mumin Cebe, Kemal Akkaya |
Future Gener. Comput. Syst. | 2 |
| 2021 | A scalable private Bitcoin payment channel network with privacy guarantees
Enes Erdin, Mumin Cebe, Kemal Akkaya, Eyuphan Bulut, A. Selcuk Uluagac |
J. Netw. Comput. Appl. | 3 |
| 2021 | A Lightweight Privacy-Aware Continuous Authentication Protocol-PACAabstractAs many vulnerabilities of one-time authentication systems have already been uncovered, there is a growing need and trend to adopt continuous authentication systems. Biometrics provides an excellent means for periodic verification of the authenticated users without breaking the continuity of a session. Nevertheless, as attacks to computing systems increase, biometric systems demand more user information in their operations, yielding privacy issues for users in biometric-based continuous authentication systems. However, the current state-of-the-art privacy technologies are not viable or costly for the continuous authentication systems, which require periodic real-time verification. In this article, we introduce a novel, lightweight, privacy-aware, and secure continuous authentication protocol called PACA. PACA is initiated through a password-based key exchange (PAKE) mechanism, and it continuously authenticates users based on their biometrics in a privacy-aware manner. Then, we design an actual continuous user authentication system under the proposed protocol. In this concrete system, we utilize a privacy-aware template matching technique and a wearable-assisted keystroke dynamics-based continuous authentication method. This provides privacy guarantees without relying on any trusted third party while allowing the comparison of noisy user inputs (due to biometric data) and yielding an efficient and lightweight protocol. Finally, we implement our system on an Apple smartwatch and perform experiments with real user data to evaluate the accuracy and resource consumption of our concrete system. Abbas Acar, Shoukat Ali, Koray Karabina, Cengiz Kaygusuz, Hidayet Aksu, Kemal Akkaya, A. Selcuk Uluagac |
ACM Trans. Priv. Secur. | 6 |
| 2021 | Distributed Connectivity Maintenance in Swarm of Drones During Post-Disaster Transportation ApplicationsabstractConsidering post-disaster scenarios for intelligent traffic management and damage assessment where communication infrastructure may not be available, we advocate a swarm-of-drones mesh communication architecture that can sustain in-network connectivity among drones. The connectivity sustenance requirement stems from the fact that drones may move to various locations in response to service requests but they still need to cooperate for data collection and transmissions. To address this need, we propose a fully distributed connectivity maintenance heuristic which enables the swarm to quickly adapt its formation in response to the service requests. To select the moving drone(s) that would bring minimal overhead in terms of time and moving distance, the connected dominating set (CDS) concept from graph theory is utilized. Specifically, a variation of CDS, namely E-CDS, is introduced to address the needs of 3-D mobile swarm-of-drones. We then show that E-CDS is NP-Complete and propose a new distributed heuristic to solve it. Once the E-CDS is determined in advance, drones not part of this E-CDS set are picked for movement tasks. When the movement is to cause any disconnection with the rest of the swarm, other drones are also relocated to restore the connectivity. The proposed heuristics are implemented in ns-3 network simulator as part of the existing IEEE 802.11s mesh standard and the effectiveness is tested in terms of providing undisturbed services under different conditions. The results indicate that the proposed distributed heuristic almost matches the performance of a centralized solution and suits perfectly the needs of post-disaster traffic management. Ahmet Kurt, Nico Saputro, Kemal Akkaya, A. Selcuk Uluagac |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2021 | A Usable and Robust Continuous Authentication Framework Using WearablesabstractOne-time login process in conventional authentication systems does not guarantee that the identified user is the actual user throughout the session. However, it is necessary to re-verify the user identity periodically throughout a login session, which is lacking in existing one-time login systems. Continuous authentication, which re-verifies the user identity without breaking the continuity of the session, can address this issue. However, existing methods for Continuous Authentication are either not reliable or not usable. In this paper, we introduce a usable and reliable Wearable-Assisted Continuous Authentication (WACA), which relies on the sensor-based keystroke dynamics and the authentication data is acquired through the built-in sensors of a wearable (e.g., smartwatch) while the user is typing. The acquired data is periodically and transparently compared with the registered profile of the initially logged-in user with one-way classifiers. With this, WACA continuously ensures that the current user is the user who logged-in initially. We implemented the WACA framework and evaluated its performance extensively on real devices with real users. The empirical evaluation of WACA reveals that WACA is feasible, and its error rate is as low as 1 percent with 30 seconds of processing time and 2-3 percent for 20 seconds. The computational overhead is minimal. Furthermore, WACA is capable of identifying insider threats with very high accuracy (99.2 percent) and also robust against powerful adversaries such as imitation and statistical attackers. We believe that this work has practical and far-reaching implications for the future of the usable authentication field. Abbas Acar, Hidayet Aksu, A. Selcuk Uluagac, Kemal Akkaya |
IEEE Trans. Mob. Comput. | 4 |
| 2020 | Towards Secure Smart Parking System Using Blockchain TechnologyabstractOver the last few years, finding vacant parking spaces has become a hassle for drivers especially in crowded cities. This problem leads to wasting drivers' time, traffic congestion, and air pollution. Recently, smart parking systems aim to address this problem by enabling drivers to have real-time parking information about vacant parking spaces. However, the existing parking systems rely on a central third party to organize the service, which makes them subject to a single point of failure and privacy breach concerns by both internal and external attackers. In this paper, we propose a secure smart parking system using blockchain technology. Specifically, a consortium blockchain is made of parking lots to ensure security, transparency, and availability of the parking system. Then, to protect the drivers' location privacy, we use cloaking technique to hide the drivers' locations. The blockchain validators return available parking offers with in the cloaked area. Finally, the driver selects the best offer and makes reservation directly with the parking lot. Evaluations are conducted to evaluate the proposed scheme, and results indicate practicality of our scheme. Wesam Al Amiri, Mohamed Baza, Karim A. Banawan, Mohamed Mahmoud 0001, Waleed Alasmary, Kemal Akkaya |
CCNC | 6 |
| 2020 | LNBot: A Covert Hybrid Botnet on Bitcoin Lightning Network for Fun and Profit
Ahmet Kurt, Enes Erdin, Mumin Cebe, Kemal Akkaya, A. Selcuk Uluagac |
ESORICS (2) | 4 |
| 2020 | Efficient Authentication of Drones to mmWave Wireless Mesh Networks in Post-Disaster ScenariosabstractUnmanned Aerial Vehicles (UAVs), or drones, are increasingly being utilized for public safety circumstances including post-disaster recovery of destroyed communication infrastructure. For instance, drones are temporarily positioned within an affected area to create a wireless mesh network among public safety personnel. To serve the need for high-rate video-based damage assessment, drone-assisted communication can utilize high-bandwidth millimeter wave (mm Wave) technologies such as IEEE 802.11ad. However, short-range mm Wave communication makes it hard for optimally-positioned drones to be authenticated with a centralized network control center. Therefore and assuming that there are potential imposters, we propose two lightweight and fast authentication mechanisms that take into account the physical limitations of mm Wave communication. First, we propose a drone-to-drone authentication mechanism, which is based on proxy signatures from a control center. Accordingly, any newly joining drone can authenticate itself to an exist one rather than attempting to authenticate to the out-of-reach control center. Second, we propose a drone-to-ground authentication mechanism, to enable each drone to authenticate itself to its associated ground users. Such authentication approach is based on challenge-response broadcast type, and it is still utilizing fast proxy signature approach. The evaluation of the proposed authentication mechanisms, conducted using NS-3 implementation of IEEE 802.11ad protocol, show their efficiency and practicality. Mai A. Abdel-Malek, Kemal Akkaya, Nico Saputro, Ahmed S. Ibrahim 0001 |
GLOBECOM | 2 |
| 2020 | Z-IoT: Passive Device-class Fingerprinting of ZigBee and Z-Wave IoT DevicesabstractIn addition to traditional networking devices (e.g., gateways, firewalls), current corporate and industrial networks integrate resource-limited Internet of Things (IoT) devices like smart outlets and smart sensors. In these settings, cyber attackers can bypass traditional security solutions and spoof legitimate IoT devices to gain illegal access to the systems. Thus, IoT device-class identification is crucial to protect critical networks from unauthorized access. In this paper, we propose Z-IoT, the first fingerprinting framework used to identify IoT device classes that utilize ZigBee and Z-Wave protocols. Z-IoT monitors idle network traffic among IoT devices to implement signature-based device-class fingerprinting mechanisms. Utilizing passive packet capturing techniques and optimal selection of filtering criteria and machine learning algorithms, Z-IoT identifies different types of IoT devices while guaranteeing the anonymity of the network data. To test Z-IoT's efficacy, we implemented several testbeds, including a total of 39 commodity IoT devices that communicate over ZigBee and Z-Wave protocols. Our experimental results showed an excellent performance in identifying different classes of IoT devices with average precision and recall of over 91%. Finally, the proposed framework yields no overhead to the IoT devices or the network traffic. Leonardo Babun, Hidayet Aksu, Lucas Ryan, Kemal Akkaya, Elizabeth S. Bentley, A. Selcuk Uluagac |
ICC | 4 |
| 2020 | Cloud-based Deception against Network Reconnaissance Attacks using SDN and NFVabstractAn attacker's success crucially depends on the reconnaissance phase of Distributed Denial of Service (DDoS) attacks, which is the first step to gather intelligence. Although several solutions have been proposed against network reconnaissance attacks, they fail to address the needs of legitimate users' requests. Thus, we propose a cloud-based deception framework which aims to confuse the attacker with reconnaissance replies while allowing legitimate uses. The deception is based on for-warding the reconnaissance packets to a cloud infrastructure through tunneling and SDN so that the returned IP addresses to the attacker will not be genuine. For handling legitimate requests, we create a reflected virtual topology in the cloud to match any changes in the original physical network to the cloud topology using SDN. Through experimentations on GENI platform, we show that our framework can provide reconnaissance responses with negligible delays to the network clients while also reducing the management costs significantly. Abdullah Aydeger, Nico Saputro, Kemal Akkaya |
LCN | 3 |
| 2020 | A Bitcoin payment network with reduced transaction fees and confirmation times
Enes Erdin, Mumin Cebe, Kemal Akkaya, Senay Solak, Eyuphan Bulut, A. Selcuk Uluagac |
Comput. Networks | 3 |
| 2020 | Heuristic approach for jointly optimising FeICIC and UAV locations in multi-tier LTE-advanced public safety HetNetabstractUnmanned aerial vehicles (UAVs) enabled networks can enhance wireless connectivity and support emerging services. However, this would require system‐level understanding to modify and extend the existing terrestrial network infrastructure. In this study, the authors integrated UAVs as user equipment and base stations into an existing long term evolution (LTE)‐Advanced heterogeneous network (HetNet) and provide system‐level insights of this three‐tier LTE‐Advanced air‐ground HetNet (AG‐HetNet). The performance of AG‐HetNet was evaluated through brute‐force technique and heuristics algorithms in terms of the fifth percentile spectral efficiency (5pSE) and coverage probability. In particular, system‐wide 5pSE and coverage probability were compared, when unmanned aerial base stations (UABSs) are deployed on a fixed hexagonal grid and when their locations are optimised using a genetic algorithm (GA) and elitist harmony search algorithm based on the genetic algorithm (eHSGA); while jointly optimising the inter‐cell interference coordination (ICIC) and cell range expansion (CRE) network parameters for different ICIC techniques. The simulation results show that the heuristic algorithms (GA and eHSGA) outperform the brute‐force technique and achieve better peak values of coverage probability and 5pSE. Simulation results also show that a trade‐off exists between peak values and computation time when using heuristic algorithms. Furthermore, the three‐tier hierarchical structuring of reduced power subframes further‐enhanced ICIC (FeICIC) defined in 3GPP Rel‐11 provides considerably better 5pSE and coverage probability than the 3GPP Rel‐10 with almost blank subframes eICIC. They also investigated the network performance for different practical deployment heights of UABS and they found low‐altitude UABSs to perform sparsely better than medium‐altitude UABSs. Abhaykumar Kumbhar, Hamidullah Binol, Simran Singh, Ismail Güvenç, Kemal Akkaya |
IET Commun. | 5 |
| 2019 | HDMI-walk: attacking HDMI distribution networks via consumer electronic control protocolabstractThe High Definition Multimedia Interface (HDMI) is the backbone and the de-facto standard for Audio/Video interfacing between video-enabled devices. Today, almost tens of billions of HDMI devices exist in the world and are widely used to distribute A/V signals in smart homes, offices, concert halls, and sporting events making HDMI one of the most highly deployed systems in the world. An important component in HDMI is the Consumer Electronics Control (CEC) protocol, which allows for the interaction between devices within an HDMI distribution network. Nonetheless, existing network security mechanisms only protect traditional networking components, leaving CEC outside of their scope. In this work, we identify and tap into CEC protocol vulnerabilities, using them to implement realistic proof-of-work attacks on HDMI distribution networks. We study, how current insecure CEC protocol practices and carelessly implemented HDMI distributions may grant an adversary a novel attack surface for HDMI devices otherwise thought to be unreachable through traditional means. To introduce this novel attack surface, in this paper, we present HDMI-Walk, which opens a realm of remote and local CEC attacks to HDMI devices. Specifically, with HDMI-Walk, an attacker can perform malicious analysis of devices, eavesdropping, Denial of Service attacks, targeted device attacks, and even facilitate other well-known existing attacks through HDMI. With HDMI-Walk, we prove that it is feasible for an attacker to gain arbitrary control of HDMI devices. We demonstrate the implementations of both local and remote attacks with commodity HDMI devices including Smart TVs and Media Players. Our work aims to uncover vulnerabilities in a very well deployed system like HDMI distributions. The consequences of which can largely impact HDMI users as well as other systems which depend on these distributions. Finally, we discuss security mechanisms to provide impactful and comprehensive security evaluation to these real-world systems while guaranteeing deployability and providing minimal overhead, while considering the current limitations of the CEC protocol. To the best of our knowledge, this is the first work solely investigating the security of HDMI device distribution networks. Luis Puche Rondon, Leonardo Babun, Kemal Akkaya, A. Selcuk Uluagac |
ACSAC | 3 |
| 2019 | A Replay Attack-Resistant 0-RTT Key Management Scheme for Low-Bandwidth Smart Grid CommunicationsabstractWith the increasing digitization of different components of Smart Grid, there is an ongoing effort to design secure protocols and deploy them for different applications. A major need along with these efforts is to deal with key management for a large number of devices which are resource constrained and deployed within a very legacy communication environment. As the utilities rightly request to build the new systems on top of the legacy systems with limited investment, the research community needs to re-think the adaptation of the existing security approaches to such non-traditional environments. Assuming a legacy (i.e., 2G) radio communication infrastructure with bandwidths in the order of kilobits, the goal of this study is to enable basic security services in Smart Grid via a lightweight key management scheme. Specifically, the proposed scheme provides mutual authentication, key agreement, and key refreshment by utilizing a 0-RTT message exchange that relies neither on PKI or session resumption. It depends on dynamic hash chains to enable authentication and prevent any replay attacks. The evaluations results show that the proposed scheme out-performs other conventional approaches such as TLS and IKE and is suitable for Smart Grid legacy environments. Mumin Cebe, Kemal Akkaya |
GLOBECOM | 2 |
| 2019 | A novel routing metric for IEEE 802.11s-based swarm-of-drones applicationsabstractWith the proliferation of drones in our daily lives, there is an increasing need for handling their numerous challenges. One of such challenge arises when a swarm-of-drones are deployed to accomplish a specific task which requires coordination and communication among the drones. While this swarm-of-drones is essentially a special form of mobile ad hoc networks (MANETs) which has been studied for many years, there are still some unique requirements of drone applications that necessitates re-visiting MANET approaches. These challenges stem from 3--D environments the drones are deployed in, and their specific way of mobility which adds to the wireless link management challenges among the drones. In this paper, we consider an existing routing standard that is used to enable meshing capability among Wi-Fi enabled nodes, namely IEEE 802.11s and adopt its routing capabilities for swarm-of-drones. Specifically, we propose a link quality metric called SrFTime as an improvement to existing Airtime metric which is the 802.11s default routing metric to enable better network throughput for drone applications. This new metric is designed to fit the link characteristics of drones and enable more efficient routes from drones to their gateway. The evaluations in the actual 802.11s standard indicates that our proposed metric outperforms the existing one consistently under various conditions. Oscar G. Bautista, Nico Saputro, Kemal Akkaya, A. Selcuk Uluagac |
MobiQuitous | 3 |
| 2019 | Preserving privacy of drone videos using proxy re-encryption technique: posterabstractUnmanned Aerial Vehicles (UAVs) also known as drones are being used in many applications where they can record or stream video. One of such applications is the Intelligent Transportation Systems (ITS) where drones may need to record videos and send a control center to be shared by various clients such as law enforcement or emergency personnel. In such cases, the recording might include faces of civilians or other sensitive information that might pose privacy concerns. While the video can be encrypted and stored in the cloud that way, it can still be accessed once the keys are exposed to third parties. To prevent such cases, in this paper, we propose a proxy re-encryption technique that will provide a key to third parties that can be used only once to access the videos. The key management is handled by a trusted control center. The implementation results indicate that there is almost no additional overhead with the approach while it can still preserve the privacy. Vashish Baboolal, Kemal Akkaya, Nico Saputro, Khaled Rabieh |
WiSec | 2 |
| 2019 | Privacy preserving distributed matching for device-to-device IoT communications: posterabstractDevice-to-device (D2D) communication enables machine-type devices (MTD) in Internet-of-Things (IoT) network communicate directly with each other and offload the cellular network. However, it may introduce interference as they share the same spectrum with the other devices that are directly connected to the base station. In this study, we look at the problem of assigning D2D communicating IoT pairs to the IoT devices that are directly connected to the base station such that the overall system throughput is not only maximized but also a stable matching is obtained. Different than previous work, we study many-to-one matching and propose a distributed privacy preserving stable matching process for efficient resource allocation without releasing location information. Eyuphan Bulut, Ismail Güvenç, Kemal Akkaya |
WiSec | 3 |
| 2019 | Performance evaluation of key management schemes for wireless legacy smart grid environments: posterabstractWith the increasing digitization of different components of Smart Grid, there is an ongoing effort to design secure protocols and deploy them for different applications. A major need along with these efforts is to deal with key management for a large number of devices. While key management can be easily addressed by transferring the existing protocols to Smart Grid domain, this is not an easy task as one needs to deal with the limitations of the current communication infrastructures and resource-constrained devices. As the utilities rightly requests to build the new systems on top of the legacy systems with limited investment, the research community needs to re-think the adaptation of the existing security approaches to such non-traditional environments. This poster aims to tackle one of these problems, namely, symmetric key management in a severely constrained wireless communication environment. Assuming a legacy radio communication infrastructure with bandwidths in the order of kilobits, the objective is to evaluate the feasibility and performance of the existing sophisticated key management protocols. We developed a realistic ns-3 environment and analyze the delay overhead via simulations. Mumin Cebe, Kemal Akkaya |
WiSec | 2 |
| 2019 | On the overhead of using zero-knowledge proofs for electric vehicle authentication: posterabstractAs Electric Vehicles (EVs) are becoming widely available, their secure management is crucial to fully enable their potential. For instance, for convenient charging, they may require quick authentication with the charging stations while they are on the go. As charging is frequently needed, exposing one's charging frequency to the stations may risk the exposure of privacy for the EV driver. Therefore, a mechanism is needed to hide EV information. In this paper, we propose using zero-knowledge proofs to achieve this goal. While zero-knowledge proofs can provide anonymous authentication, they require computation for generation of witnesses. Therefore, we assess the overhead of generating a witness and proof computation at the resource constrained on-board units (OBUs) which are deployed on EVs that utilize wireless communications for scheduling. The results indicate that computation overhead is minimal and can be delployed on resource contrained devices. David Gabay, Mumin Cebe, Kemal Akkaya |
WiSec | 3 |
| 2019 | Attacking HDMI distribution networks: posterabstractThe High Definition Multimedia Interface or HDMI is the core and primary standard for Audio/Video communication in various media devices. HDMI allows flexible interaction between devices within HDMI distribution networks. Existing security standards and mechanism only protect traditional networking components. A user may mistakenly believe that a device is secure and an adversary may prove them otherwise. In this ongoing work, we show that by leveraging CEC to an attackers advantage. It is feasible for an attacker to reach devices which were formerly unreachable, and gain arbitrary control of HDMI devices. Specifically, we demonstrate it is possible to execute malicious device analysis, eavesdrop, and perform targeted Denial-of-Service attacks. Luis Puche Rondon, Leonardo Babun, Kemal Akkaya, A. Selcuk Uluagac |
WiSec | 3 |
| 2019 | Efficient certificate revocation management schemes for IoT-based advanced metering infrastructures in smart cities
Mumin Cebe, Kemal Akkaya |
Ad Hoc Networks | 2 |
| 2019 | Efficient and privacy preserving supplier matching for electric vehicle charging
Fatih Yucel, Kemal Akkaya, Eyuphan Bulut |
Ad Hoc Networks | 2 |
| 2019 | A moving target defense and network forensics framework for ISP networks using SDN and NFV
Abdullah Aydeger, Nico Saputro, Kemal Akkaya |
Future Gener. Comput. Syst. | 3 |
| 2019 | EPIC: Efficient Privacy-Preserving Scheme With EtoE Data Integrity and Authenticity for AMI NetworksabstractIn this paper, we propose EPIC, an efficient and privacy-preserving data collection scheme with EtoE data integrity verification for advanced metering infrastructure networks. Using efficient cryptographic operations, each meter should send a masked reading to the utility such that all the masks are canceled after aggregating all meters' masked readings, and thus the utility can only obtain an aggregated reading to preserve consumers' privacy. The utility can verify the aggregated reading integrity without accessing the individual readings to preserve privacy. It can also identify the attackers and compute electricity bills efficiently by using the fine-grained readings without violating privacy. Furthermore, EPIC can resist collusion attacks in which the utility colludes with a relay node to extract the meters' readings. A formal proof and probabilistic analysis are used to evaluate the security of EPIC, and ns-3 is used to implement EPIC and evaluate the network performance. In addition, we compare EPIC to existing data collection schemes in terms of overhead and security/privacy features. Ahmad Alsharif, Mahmoud Nabil 0001, Samet Tonyali, Hawzhin Mohammed, Mohamed Mahmoud 0001, Kemal Akkaya |
IEEE Internet Things J. | 6 |
| 2019 | SDN-enabled recovery for Smart Grid teleprotection applications in post-disaster scenarios
Abdullah Aydeger, Nico Saputro, Kemal Akkaya, A. Selcuk Uluagac |
J. Netw. Comput. Appl. | 3 |
| 2018 | Assessing the overhead of authentication during SDN-enabled restoration of smart grid inter-substation communicationsabstractSince real-time and resilient recovery of link failures is crucial for power grid infrastructure to continue its services, emerging technologies such as Software Defined Networking (SDN) has started to be employed for such purposes. SDN switches can be remotely controlled to change their configurations by exploiting the wireless communication options. However, when wireless is to be used in Smart Grid communications, security and reliability become important issues due to the specific characteristics of wireless communications. This paper investigates the overhead of providing such services on wireless links when SDN is utilized. Specifically, we consider the establishment of authentication services when wireless back-up links (i.e., WiFi or LTE) are employed as a result of a reactive link failure detection mechanism. To the best of our knowledge, this work is the first to consider authentication of such an SDN-enabled Smart Grid inter-substation communication with WiFi and LTE. To be able to effectively evaluate the performance of this proposed SDN-enabled framework, we developed it in Mininet emulator. Since Mininet does not support the authentication services for WiFi or LTE, we proposed several novel extensions to Mininet by integrating it with ns-3 simulator that supports the LTE/WiFi protocol stacks. We conducted extensive experiments by considering a general application using Smart Grid Manufacturing Message Specification (MMS) standard to assess the recovery performance of the proposed secure SDN-enabled recovery system. The results show that when authentication and reliable protocols such as TCP are to be employed, the proposed framework can still meet the deadlines of 100 ms with WiFi while LTE misses only a few packets. Abdullah Aydeger, Nico Saputro, Kemal Akkaya, A. Selcuk Uluagac |
CCNC | 3 |
| 2018 | A secure and cloud-based medical records access scheme for on-road emergenciesabstractOn-road emergencies necessitates the availability of the patient's medical records to the emergency centers for better treatment. However, these medical records are often encrypted to preserve the patient's privacy. Revealing the secret key used to encrypt these records to the emergency center would not only give unlimited unauthorized future access to the medical records but also pose privacy concerns for the patient. In this paper, we propose a secure medical records access scheme that can be used to serve the patient effectively. An emergency medical center is able to decrypt a patient's medical records without revealing the secret key used to encrypt them with the help of the patient's smart phone and the cloud server. We use proxy re-encryption scheme to trigger a re-encryption process at the cloud server by sending the required credentials. With the help of the cloud server, only a specific emergency center is able to decrypt the medical records and access the patient's medical history. Our scheme allows in-time and more efficient health care and recovery in extreme life-threatening situations. Our analysis and evaluations show that the proposed scheme can secure the medical records and preserve the privacy of the patient with acceptable computation and communication overhead. Khaled Rabieh, Kemal Akkaya, Umit Karabiyik, Jennifer Qamruddin |
CCNC | 2 |
| 2018 | A scalable protocol stack for IEEE 802.11s-based advanced metering infrastructure networksabstractThe utility companies and the researchers have been developing new applications and communication protocols for the Smart Grid Advanced Metering Infrastructure (AMI) network. Since the AMI network consists of thousands of smart meters, it is built as a wireless mesh network (WMN) because it requires far less cabling work, thereby lowering the infrastructure, deployment and maintenance costs. However, WMNs suffer from scalability issues as the network grows. Therefore, in this paper, we present a scalable protocol stack for the IEEE 802.11s-based AMI applications. We propose several modifications and parameter adjustments at different layers of the protocol stack. Specifically, several parameters at the MAC layer are adjusted. Furthermore, we integrate a modified Address Resolution Protocol to take advantage of Hybrid Wireless Mesh Protocol's proactive route requests/replies, which is IEEE 802.11s standards default routing protocol. Moreover, we propose five novel retransmission timeout (RTO) calculation functions for the application layer protocol, CoAP, in order to increase the reliability. We assessed the performance of the proposed protocol stack under the widely used ns-3 simulator. The simulation results have shown that the proposed stack can reliably scale to thousands of nodes. Samet Tonyali, Kemal Akkaya |
CCNC | 2 |
| 2018 | Efficient Public-Key Revocation Management for Secure Smart Meter Communications Using One-Way Cryptographic AccumulatorsabstractAdvanced Metering Infrastructure (AMI) forms a communication network for the collection of power data from smart meters in Smart Grid. As the communication within an AMI needs to be secure, public-key cryptography can be used to reduce the overhead of key management. However, it still has certain challenges in terms of certificate revocation and management. In particular, distribution and storage of the Certificate Revocation List (CRL), which holds the revoked certificates, is a major challenge due to its overhead. To address this challenge, in this paper, we propose a novel revocation management scheme by utilizing cryptographic accumulators which not only reduces the space requirements for revocation information but also enables convenient distribution of revocation information to all smart meters. We implemented this one-way cryptographic accumulator-based revocation scheme on ns- 3 using IEEE 802.11s mesh standard as a model for AMI and demonstrated its superior performance with respect to traditional methods of CRL management through extensive simulations. Mumin Cebe, Kemal Akkaya |
ICC | 2 |
| 2018 | U-PoT: A Honeypot Framework for UPnP-Based IoT DevicesabstractThe ubiquitous nature of the IoT devices has brought serious security implications to its users. A lot of consumer IoT devices have little to no security implementation at all, thus risking user's privacy and making them target of mass cyber-attacks. Indeed, recent outbreak of Mirai botnet and its variants have already proved the lack of security on the IoT world. Hence, it is important to understand the security issues and attack vectors in the IoT domain. Though significant research has been done to secure traditional computing systems, little focus was given to the IoT realm. In this work, we reduce this gap by developing a honeypot framework for IoT devices. Specifically, we introduce U-PoT: a novel honeypot framework for capturing attacks on IoT devices that use Universal Plug and Play (UPnP) protocol. A myriad of smart home devices including smart switches, smart bulbs, surveillance cameras, smart hubs, etc. uses the UPnP protocol. Indeed, a simple search on Shodan IoT search engine lists 1,676,591 UPnP devices that are exposed to public network. The popularity and ubiquitous nature of UPnP-based IoT device necessitates a full-fledged IoT honeypot system for UPnP devices. Our novel framework automatically creates a honeypot from UPnP device description documents and is extendable to any device types or vendors that use UPnP for communication. To the best of our knowledge, this is the first work towards a flexible and configurable honeypot framework for UPnP-based IoT devices. We released U-PoT under an open source license for further research on IoT security and created a database of UPnP device descriptions. We also evaluated our framework on two emulated deices. Our experiments show that the emulated devices are able to mimic the behavior of a real IoT device and trick vendor-provided device management applications or popular IoT search engines while having minimal performance ovherhead. Muhammad A. Hakim, Hidayet Aksu, A. Selcuk Uluagac, Kemal Akkaya |
IPCCC | 4 |
| 2018 | A Network Coding Based Information Spreading Approach for Permissioned Blockchain in IoT SettingsabstractPermissioned Blockchain (PBC) has become a prevalent data structure to ensure that the records are immutable and secure. However, PBC still has significant challenges before it can be realized in different applications. One of such challenges is the overhead of the communication which is required to execute the Byzantine Agreement (BA) protocol that is needed for consensus building. As such, it may not be feasible to implement PBC for resource constrained environments such as Internet-of-Things (IoT). In this paper, we assess the communication overhead of running BA in an IoT environment that consists of wireless nodes (e.g., Raspberry PIs) with meshing capabilities. As the the packet loss ratio is significant and makes BA unfeasible to scale, we propose a network coding based approach that will reduce the packet overhead and minimize the consensus completion time of the BA. Specifically, various network coding approaches are designed as a replacement to TCP protocol which relies on unicasting and acknowledgements. The evaluation on a network of Raspberry PIs demonstrates that our approach can significantly improve scalability making BA feasible for medium size IoT networks. Mumin Cebe, Berkay Kaplan, Kemal Akkaya |
MobiQuitous | 3 |
| 2018 | Time Optimal Multi-UAV Path Planning for Gathering its Data from Roadside UnitsabstractIn this paper, we address the problem of path planning for multiple unmanned aerial vehicles (UAVs), to gather data from a number of roadside units (RSUs). The problem involves finding time-optimal paths for multiple UAVs so that they collectively visit all the RSUs, while also exchanging information at their own point when they fly from a starting point to the final location. We solve the problem by applying modified evolutionary methods based on genetic algorithm (GA) and harmony search (HS). The modified search methods seek to determine the overall shortest path utilizing various evolutionary operators regarding each UAV which has identical properties at the start location. Numerical results are introduced under different scenarios and the performances of the proposed algorithms are evaluated. Hamidullah Binol, Eyuphan Bulut, Kemal Akkaya, Ismail Güvenç |
VTC Fall | 3 |
| 2018 | Drone-Assisted Multi-Purpose Roadside Units for Intelligent Transportation SystemsabstractAs drones are becoming prevalent to be deployed in various civic applications, there is a need to integrate them into efficient and secure communications with the existing infrastructure. In this paper, considering emergency scenarios for intelligent transportation applications, we design a secure hybrid communication infrastructure for mobile road-side units (RSUs) that are based on drones. The architecture tackles interoperability issues when Dedicated Short Range Communications (DSRC), wireless mesh, and LTE need to coexist for coordination. Specifically, we propose a novel tunneling protocol to integrate LTE with IEEE 802.11s mesh network. In addition, we ensure that only legitimate users can connect and control the mobile RSUs by integrating an authentication framework built on top of the recent OAuth 2.0 standard. A detailed communication protocol is proposed within the elements of the architecture from vehicles to control center for emergency operations. The proposed secure architecture is implemented in ns-3 and tested for its performance under heavy multimedia traffic. The results indicate that the proposed hybrid architecture can enable smooth multimedia traffic delivery via the mobile RSU. Nico Saputro, Kemal Akkaya, Ramazan Algin, A. Selcuk Uluagac |
VTC Fall | 2 |
| 2018 | Privacy Preserving Distributed Stable Matching of Electric Vehicles and Charge SuppliersabstractThe potential of electric vehicles (EV) to reduce foreign-oil dependence and improve urban air quality has triggered lots of investment by automotive companies recently and mass penetration and market dominance of EVs is imminent. However, EVs need to be charged more frequently than fossil-based vehicles and the charging durations are much longer. This necessitates in advance scheduling and matching depending on the route of the EVs. However, such scheduling and frequent charging may leak sensitive information about the users which may expose their driving patterns, whereabouts, schedules, etc. The situation is compounded with the proliferation of EV chargers such as V2V charging where there can be a lot of privacy exposure if matching of suppliers and EVs is achieved in a centralized manner. To address this issue, in this paper, we propose a privacy-preserving distributed stable matching of EVs with suppliers (i.e., public/private stations, V2V chargers) using preference lists formed by partially homomorphic encryption-based distance calculations while hiding the locations. The simulation results indicate that such a local matching of supplier and demanders can be achieved in a distributed fashion within reasonable computation and convergence times while preserving privacy of users. Fatih Yucel, Eyuphan Bulut, Kemal Akkaya |
VTC Fall | 3 |
| 2018 | Privacy-preserving protocols for secure and reliable data aggregation in IoT-enabled Smart Metering systems
Samet Tonyali, Kemal Akkaya, Nico Saputro, A. Selcuk Uluagac, Mehrdad Nojoumian |
Future Gener. Comput. Syst. | 2 |
| 2018 | Occupancy Counting With Burst and Intermittent Signals in Smart BuildingsabstractZone-level occupancy counting is a critical technology for smart buildings and can be used for applications, such as building energy management, surveillance, and public safety. Existing occupancy counting techniques typically require installation of large number of occupancy monitoring sensors inside a building and an established wireless network. In this paper, in order to achieve occupancy counting, we consider the use of Wi-Fi probe requests that are continuously transmitted from Wi-Fi enabled smart devices for discovering nearby access points. To this end, Wi-Fi Pineapple equipment are used for passively capturing ambient probe requests from Wi-Fi devices, such as smart phones and tablets, where no connectivity to a Wi-Fi network is required. This information is then used to localize users within coarsely defined occupancy zones, and subsequently to obtain occupancy count within each zone at different time scales. An interacting multimodel (IMM) Kalman filter technique is developed to improve occupancy counting accuracy. Our numerical results using Wi-Fi data collected at a university building show that the use of Wi-Fi probe requests in conjunction with IMM-based Kalman filters can be a viable solution for zone-level occupancy monitoring in smart buildings. Bekir Sait Ciftler, Sener Dikmese, Ismail Güvenç, Kemal Akkaya, Abdullah Kadri |
IEEE Internet Things J. | 4 |
| 2018 | A realistic performance evaluation of privacy-preserving protocols for smart grid AMI networks
Samet Tonyali, Ruben Munoz, Kemal Akkaya, Utku Ozgur |
J. Netw. Comput. Appl. | 3 |
| 2018 | The Internet of Microgrids: A Cloud-Based Framework for Wide Area Networked MicrogridsabstractThis paper presents a cloud-based and hybrid wireless mesh communication framework for bilevel, nested, distributed optimization of networked clusters of microgrids. The proposed optimization framework implements a diffusion-based, fully distributed algorithm on local wireless network and a quasi-distributed approach on wide-area internet-based cloud. The lower level of the bilevel optimization implements a distributed optimal economic dispatch solution for intramicrogrid among distributed energy resources, and the upper level implements a global optimal dispatch for intermicrogrid energy exchange. To demonstrate industrial applicability of the proposed framework, the IEC 61850 interoperability protocol is adopted to achieve a certain delay performance so that the distributed optimization convergence is guaranteed. First, hardware-based prototype intelligent electronic devices are developed using embedded systems. Then, the bilevel nested optimization algorithm is implemented for integration of networked microgrids. Finally, experimental results are demonstrated from a real-time smart grid testbed featuring realistic microgrids. The results demonstrate that the proposed framework meets communication requirements for distributed optimization of networked microgrids. Eric Harmon, Utku Ozgur, Mehmet Hazar Cintuglu, Ricardo de Azevedo, Kemal Akkaya, Osama Mohammed 0001 |
IEEE Trans. Ind. Informatics | 5 |
| 2017 | An Attribute & Network Coding-Based Secure Multicast Protocol for Firmware Updates in Smart Grid AMI NetworksabstractSmart meters operate based on their firmware ruling the hardware. The firmware occasionally needs to be updated to fix bugs and improve the services. Since the smart meter firmware is proprietary, the update file should be communicated to the smart meters in a secure way. In addition, the firmware update may target a specific subgroup of the smart meters rather than all of them in which case access control is required. In this paper, we address the problem of updating the smart meter firmware securely in an IEEE 802.11s-based AMI network and develop a secure and reliable multicast-over-broadcast protocol by making use of ciphertext-policy attribute-based signcryption (CP-ABSC) to provide not only confidentiality and access control but also message authentication. CP-ABSC is employed to signcrypt both the firmware update file and the firmware update request based on an access tree such that the signcrypted update file and request can be designcrypted by the smart meters possessing the attributes that can satisfy the access tree. The preliminary tests showed that increased size of the request due to signcryption reduces reliability of the protocol. Therefore, we employ random linear network coding along with CP- ABSC in order to increase the reliability and use the bandwidth and processing resources efficiently. We assessed the performance of the proposed protocol under ns-3 network simulator. The simulation results have shown that the protocol can accomplish the process of downloading a firmware update without needing any human intervention while consuming less bandwidth when compared to a baseline that employs unicasting. Samet Tonyali, Kemal Akkaya, Nico Saputro, Xiuzhen Cheng |
ICCCN | 2 |
| 2017 | Efficient Management of Certificate Revocation Lists in Smart Grid Advanced Metering InfrastructureabstractAdvanced Metering Infrastructure (AMI) forms a communication network for the collection of power data from smart meters in Smart Grid. As the communication within an AMI needs to be secure, key management becomes an issue due to overhead and limited resources. While using public-keys eliminate some of the overhead of key management, there is still challenges regarding certificates that store and certify the public-keys. In particular, distribution and storage of certificate revocation list (CRL) is major a challenge due to cost of distribution and storage in AMI networks which typically consist of wireless multi-hop networks. Motivated by the need of keeping the CRL distribution and storage cost effective and scalable, in this paper, we present a distributed CRL management model utilizing the idea of distributed hash trees (DHTs) from peer-to-peer (P2P) networks. The basic idea is to share the burden of storage of CRLs among all the smart meters by exploiting the meshing capability of the smart meters among each other. Thus, using DHTs not only reduces the space requirements for CRLs but also makes the CRL updates more convenient. We implemented this structure on ns-3 using IEEE 802.11s mesh standard as a model for AMI and demonstrated its superior performance with respect to traditional methods of CRL management through extensive simulations. Mumin Cebe, Kemal Akkaya |
MASS | 2 |
| 2017 | An Authentication Framework for Electric Vehicle-to-Electric Vehicle Charging ApplicationsabstractElectric vehicles are becoming parts of our daily lives with the increasing investment from auto industry. However, their charging is an issue as this requires frequent charging and longer waiting times compared to traditional gasoline-based vehicles. The charging is typically done at residential or public charging stations. With the increased dominance of electric vehicles, one potential solution is to exploit vehicle-to-vehicle charging (V2V) where an electric vehicle can charge another one through a converter-cable assembly. In such cases, however, there needs to be a protocol between the charge supplier and receiver to authenticate each other and authorize the vehicle to open its charging ports. In this paper, we study this problem of authentication and propose a protocol that will utilize key exchange among the users without relying on certificates. We implemented the proposed protocols under WiFi-direct and Bluetooth and demonstrated that the approach can provide the necessary framework of communication before charging starts without any additional overhead. Braden Roberts, Kemal Akkaya, Eyuphan Bulut, Mithat C. Kisacikoglu |
MASS | 2 |
| 2017 | Privacy-Preserving Power Injection Over a Hybrid AMI/LTE Smart Grid NetworkabstractThe future smart grid will enable homes to have energy storage units that can store the excess power generated from renewable energy sources and sell it to the grid during the peak hours. Realization of this process, however, requires the utility company to be able to communicate with the storage units whenever needed. Nonetheless, the security and the privacy of this communication is essential to not only ensure a fair energy selling market but also eliminate any privacy concerns of the users due to potential exposure of their energy levels. In this paper, we propose a secure and privacy-preserving power injection querying scheme by exploiting the already available advanced metering infrastructure (AMI) and long-term evolution (LTE) cellular networks. The idea is based on collecting power injection bids from storage units and sending their aggregated value to the utility rather than the individual bids in order to preserve user privacy. We also develop a bilinear pairing-based technique to enable the utility company to ensure the integrity and authenticity of the aggregated bid without accessing the individual bids. In this way, no party will have access to the storage units' individual bids and use them to achieve unfair financial gains. We implemented the proposed scheme in an integrated AMI/LTE network using the ns-3 network simulator. Our evaluations have demonstrated that the proposed scheme is secure and can protect user privacy with acceptable communication and computation overhead. Mohamed Mahmoud 0001, Nico Saputro, Prem Akula, Kemal Akkaya |
IEEE Internet Things J. | 4 |
| 2017 | Investigation of Smart Meter Data Reporting Strategies for Optimized Performance in Smart Grid AMI NetworksabstractDesigning efficient and reliable wireless mesh-based advanced metering infrastructure (AMI) networks is challenging. In AMI networks, fine-grained regular data collections from smart meters (SMs) create a lot of traffic and interference. The location of the gateway that collects data from SMs may also add to this interference by impacting the length of routes. Furthermore, TCP-like protocols that are employed for reliability may bring additional overhead. Therefore, it is critical to pick the suitable data collection strategy and gateway location to meet some smart grid performance requirements. In this paper, we proposed three novel data collection mechanisms to set the periodic reporting time of each SM to improve TCP performance in IEEE 802.11s-based wireless mesh AMI networks. The first idea was based on the nature of IEEE 802.11s routing protocol. Each SM is assigned a reporting time based on its location in the spanning tree network. The second idea was inspired by the time division multiple access methods where each meter is given a separate slot. The third idea was based on both previous ideas and clustering to increase the number of meters that can send at the same slot. For the gateway location, we also proposed a novel mechanism based on p-center facility problem to minimize data delivery delay. The simulation results indicate that the packet delay can be improved significantly without any negative impact on the other performance metrics. Nico Saputro, Kemal Akkaya |
IEEE Internet Things J. | 2 |
| 2017 | Scalable Certificate Revocation Schemes for Smart Grid AMI Networks Using Bloom FiltersabstractGiven the scalability of the advanced metering infrastructure (AMI) networks, maintenance and access of certificate revocation lists (CRLs) pose new challenges. It is inefficient to create one large CRL for all the smart meters (SMs) or create a customized CRL for each SM since too many CRLs will be required. In order to tackle the scalability of the AMI network, we divide the network into clusters of SMs, but there is a tradeoff between the overhead at the certificate authority (CA) and the overhead at the clusters. We use Bloom filters to reduce the size of the CRLs in order to alleviate this tradeoff by increasing the clusters' size with acceptable overhead. However, since Bloom filters suffer from false positives, there is a need to handle this problem so that SMs will not discard important messages due to falsely identifying the certificate of a sender as invalid. To this end, we propose two certificate revocation schemes that can identify and nullify the false positives. While the first scheme requires contacting the gateway to resolve them, the second scheme requires the CA additionally distribute the list of certificates that trigger false positives. Using mathematical models, we have demonstrated that the probability of contacting the gateway in the first scheme and the overhead of the second scheme can be very low by properly designing the Bloom filters. In order to assess the scalability and validate the mathematical formulas, we have implemented the proposed schemes using Visual C. The results indicate that our schemes are much more scalable than the conventional CRL and the mathematical and simulation results are almost identical. Moreover, we simulated the distribution of the CRLs in a wireless mesh-based AMI network using ns-3 network simulator and assessed its distribution overhead. Khaled Rabieh, Mohamed Mahmoud 0001, Kemal Akkaya, Samet Tonyali |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2016 | A novel storage covert channel on wearable devices using status bar notificationsabstractCovert channels have been used as a means to circumvent security measures and send sensitive data undetectable to an onlooker. Many covert channels in Android systems have been documented utilizing various system resources or settings available to the entire system. Nonetheless, this paper introduces a new storage covert channel on the emerging field of wearables that sends data to other applications, or even to other nearby devices, through the use of notifications that are normally displayed on the status bar of an Android device. In this paper, we present the design of our ongoing work for this covert channel using Android-based wearable devices. Furthermore, we evaluate the performance of this covert channel using real equipment. Our evaluation demonstrates the functionality and feasibility of the proposed covert channel. Kyle Denney, A. Selcuk Uluagac, Kemal Akkaya, Shekhar Bhansali |
CCNC | 3 |
| 2016 | A reliable data aggregation mechanism with Homomorphic Encryption in Smart Grid AMI networksabstractOne of the most common methods to preserve consumers' private data is using secure in-network data aggregation. The security can be provided through the emerging fully (FHE) or partial (PHE) homomorphic encryption techniques. However, an FHE aggregation scheme generates significantly big-size data when compared to traditional encryption methods. The overhead is compounded in hierarchical networks such as Smart Grid Advanced Metering Infrastructure (AMI) as data packets are routed towards the core of the AMI networking infrastructure from the smart meters. In this paper, we first investigate the feasibility and performance of FHE aggregation in AMI networks utilizing the reliable data transport protocol, TCP. Then, we introduce the packet reassembly problem. To address this challenge, we propose a novel packet reassembly mechanism for TCP. We evaluated the effectiveness of our proposed mechanism using both PHE and FHE-based aggregation approaches in AMI in terms throughput and end-to-end delay on an 802.11s-based wireless mesh network by using the ns-3 network simulator. The results indicate significant gains in terms of delay and bandwidth usage with the proposed mechanism. Samet Tonyali, Kemal Akkaya, Nico Saputro, A. Selcuk Uluagac |
CCNC | 2 |
| 2016 | Efficient Privacy-Preserving Data Collection Scheme for Smart Grid AMI NetworksabstractIn this paper, we propose an efficient scheme that utilizes symmetric-key-cryptography and hashing operations to collect consumption data. The idea is based on sending masked power consumption readings from the meters and removing these masks by adding all the meters' messages, so that the utility can learn the aggregated reading but cannot learn the individual readings. We also introduce a key management procedure that uses asymmetric key operations, but unlike the power consumption collection that is done very frequently, the key management procedure is run every long time for key renewals. Our evaluations indicate that the cryptographic operations needed in our scheme are much more efficient than the operations needed in the existing schemes. In addition, we have shown that the proposed scheme can preserve the consumers' privacy and provide high protection level against collusion attacks. Finally, ns-3 simulation results demonstrate that the network performance of the proposed scheme outperforms the performance of the existing schemes due to reducing the packet size and computational overhead. Hawzhin Mohammed, Samet Tonyali, Khaled Rabieh, Mohamed Mahmoud 0001, Kemal Akkaya |
GLOBECOM | 5 |
| 2016 | Software defined networking for resilient communications in Smart Grid active distribution networksabstractEmerging Software Defined Networking (SDN) technology provides excellent flexibility to large-scale networks in terms of control, management, security, and maintenance. In this paper, we propose an SDN-based communication infrastructure for Smart Grid distribution networks among substations. A Smart Grid communication infrastructure consists of a large number of heterogenous devices that exchange real-time information for monitoring the status of the grid. We then investigate how SDN-enabled Smart Grid infrastructure can provide resilience to active distribution substations with self-recovery. Specifically, by introducing redundant and wireless communication links that can be used during the emergencies, we show that SDN controllers can be effective for restoring the communication while providing a lot of flexibility. Furthermore, to be able to effectively evaluate the performance of the proposed work in terms of various fine-grained network metrics, we developed a Mininet-based testing framework and integrated it with ns-3 network simulator. Finally, we conducted experiments by using actual Smart Grid communication data to assess the recovery performance of the proposed SDN-based system. The results show that SDN is a viable technology for the Smart Grid communications with almost negligible delays in switching to backup wireless links during the times of link failures in reliable fashion. Abdullah Aydeger, Kemal Akkaya, Mehmet Hazar Cintuglu, A. Selcuk Uluagac, Osama Mohammed 0001 |
ICC | 2 |
| 2016 | Comparative evaluation of Smart Grid AMI networks: Performance under privacyabstractAdvanced Metering Infrastructure (AMI) is an indispensable part of a Smart Grid (SG) initiative. AMI applications collect data measured by smart meters in the SG. This process may leak information about consumers. In this paper, we build an IEEE 802.11s-based SG AMI network testbed consisting of Beaglebone Black boards and investigate the performance of privacy-preserving protocols in real-life and compare it with the ns-3 simulations. We develop an application that collects data periodically. This mechanism runs in two modes: Hop-by-hop and end-to-end aggregation. The application is tested on TCP and UDP. We use Paillier cryptosystem for privacy, and ECDSA for authentication. The application is also simulated in ns-3. The testbed results are compared with the ns-3 results in terms of packet delivery ratio, throughput and data collection completion time. Comparison showed that the tested privacy-preserving protocol behavior may not accurately reflect that of ns-3, especially with data completion time metric. Utku Ozgur, Samet Tonyali, Kemal Akkaya, Fatih Senel |
ISCC | 3 |
| 2016 | Drones for smart cities: Issues in cybersecurity, privacy, and public safetyabstractIt is expected that drones will take a major role in the connected smart cities of the future. They will be delivering goods and merchandise, serving as mobile hot spots for broadband wireless access, and maintaining surveillance and security of smart cities. However, pervasive use of drones for future smart cities also brings together several technical and societal concerns and challenges that needs to be addressed, including in the areas of cybersecurity, privacy, and public safety. Drones, while can be used for the betterment of the society, can also be used by malicious entities to conduct physical and cyber attacks, and threaten the society. The goal of this survey paper is to review various aspects of drones in future smart cities, relating to cybersecurity, privacy, and public safety. We will also provide representative results on cyber attacks using drones. Edwin Vattapparamban, Ismail Güvenç, Ali Ihsan Yurekli, Kemal Akkaya, A. Selcuk Uluagac |
IWCMC | 4 |
| 2016 | Mitigating Crossfire Attacks Using SDN-Based Moving Target DefenseabstractRecent research demonstrated that software defined networking (SDN) can be leveraged to enable moving target defense (MTD) to mitigate distributed denial of service (DDoS) attacks. The network states are continuously changed in MTD by effectively collecting information from the network and enforcing certain security measures on the fly in order to deceive the attackers. Being motivated from the success of SDN-based maneuvering, this work targets an emerging type of DDoS attacks, called Crossfire, and proposes an SDN-based MTD mechanism to defend against such attacks. We analyze Crossfire attack planning and utilize the analyzed results to develop the defense mechanism which in turn reorganize the routes in such a way that the congested links are avoided during packet forwarding. The detection and mitigation techniques are implemented using Mininet emulator and Floodlight SDN controller. The evaluation results show that the route mutation can effectively reduce the congestion in the targeted links without making any major disruption on network services. Abdullah Aydeger, Nico Saputro, Kemal Akkaya, Mohammad Ashiqur Rahman |
LCN | 3 |
| 2016 | Addressing Network Interoperability in Hybrid IEEE 802.11s/LTE Smart Grid CommunicationsabstractEnsuring network interoperability when IEEE 802.11s-based NAN and LTE-based WAN is deployed for Smart Grid (SG) Advanced Metering Infrastructure (AMI) poses significant challenges. Besides the QoS mismatch between networks, LTE tunneling mechanism becomes an issue when forwarding downlink traffic to IEEE 802.11s network since the gateway of these networks is supposed to be the end device in LTE setup. Yet, inherent security/privacy overhead in SG traffic makes it even more challenging. To address these issues, a novel UE access list is proposed for LTE network to enable the downlink traffic identification to IEEE 802.11s network and accordingly selects the corresponding gateway. For the QoS mismatch, Dual-Queues (DQs) for each Access Category of the underlying MAC protocol, namely Enhanced Distributed Channel Access (EDCA) in IEEE 802.11s network is proposed. By using ns-3 network simulator, extensive performance evaluations under heavy security overhead are conducted to assess the performance of the proposed mechanisms. Nico Saputro, Kemal Akkaya, Samet Tonyali |
LCN | 2 |
| 2016 | Privacy-aware power charging coordination in future smart gridabstractIn this paper, we propose a privacy-preserving power charging coordination scheme. Each energy storage unit (ESU) should send a charging request to an aggregator. The request does not reveal any private information to the aggregator. The aggregator forwards the requests to a charging controller that can know enough data to run a charging coordination scheme, but it cannot link the data to particular ESUs. Temporal charging coordination scheme is then proposed based on a modified knapsack problem formulation. The goal is to maximize the amount of power delivered to the ESUs before the charging requests expire without exceeding the available maximum charging capacity. Our simulation results demonstrate that both the optimal charging coordination and the privacy-aware charging coordination exhibit an improved performance compared with a first-come-first-serve charging coordination. More importantly, the privacy-aware scheme offers an attractive trade-off between the charging coordination performance and privacy preservation. Mohamed Mahmoud 0001, Muhammad Ismail 0001, Prem Akula, Kemal Akkaya, Erchin Serpedin, Khalid A. Qaraqe |
WCNC | 4 |
| 2016 | Secure Data Obfuscation Scheme to Enable Privacy-Preserving State Estimation in Smart Grid AMI NetworksabstractWhile the newly envisioned smart(er) grid (SG) will result in a more efficient and reliable power grid, its collection and use of fine-grained meter data has widely raised concerns on consumer privacy. While a number of approaches are available for preserving consumer privacy, these approaches are mostly not very practical to be used due to two reasons. 1) Since the data is hidden, this reduces the ability of the utility company to use the data for distribution state estimation. 2) The approaches were not tested under realistic wireless infrastructures that are currently in use. In this paper, we propose to implement a meter data obfuscation approach to preserve consumer privacy that has the ability to perform distribution state estimation. We then assess its performance on a large-scale advanced metering infrastructure (AMI) network built upon the new IEEE 802.11s wireless mesh standard. For the data obfuscation approach, we propose two secure obfuscation value distribution mechanisms on this 802.11s-based wireless mesh network (WMN). Using obfuscation values provided via this approach, the meter readings are obfuscated to protect consumer privacy from eavesdroppers and the utility companies while preserving the utility companies' ability to use the data for state estimation. We assessed the impact of this approach on data goodput, delay, and packet delivery ratio (PDR) under a variety of conditions. Simulation results have shown that the proposed approach can provide very similar performance to that of nonprivacy approach with negligible overheads on the meters and network. Samet Tonyali, Ozan Cakmak, Kemal Akkaya, Mohamed Mahmoud 0001, Ismail Güvenç |
IEEE Internet Things J. | 3 |
| 2015 | Distributed connectivity restoration in Underwater Acoustic Sensor Networks via depth adjustmentabstractIn most applications of Underwater Acoustic Sensor Networks, network connectivity is required for data exchange, data aggregation and relaying the data to a surface station. However, such connectivity can be lost due to failure of some sensor nodes which creates disruptions to the network operations. In this paper, we present two algorithms, namely BMR and DURA, which can detect network partitioning due to such node failures and re-establish network connectivity through controlled depth adjustment of nodes in a distributed manner. The idea is to first identify whether the failure of each node will cause partitioning or not based on localized information. If partitioning is to occur as a result of the possible failure of a particular node, both BMR and DURA designates backup nodes to handle the recovery in the future. While DURA aims to localize the recovery process and minimize the movement overhead on the nodes, BMR strives to reduce the recovery completion time at the expense of increased movement overhead by employing a two-phase block movement. The performance of the proposed approaches is validated through extensive simulations. The results indicated that DURA can provide energy savings as much as a centralized exhaustive approach while BMR provided the fastest recovery time. Erkay Uzun, Fatih Senel, Kemal Akkaya, Adnan Yazici |
ICC | 3 |
| 2015 | Implementation and Analysis of Dutch-style Sealed-bid Auctions - Computational vs Unconditional SecurityabstractDesigning a sealed-bid auction protocol is a challenging problem in the field of applied cryptography. In the
last couple of decades, numerous protocols have been proposed in the literature where each one has its own
property in terms of the security model, communication and computation complexities. To the best of our
knowledge, there has been no study to implement and compare a similar class of sealed-bid auction protocols.
This paper therefore implements and evaluates five different Dutch-style sealed-bid auction protocols, of which
three protocols are computationally secure and two protocols are unconditionally secure. It mainly focuses on
the computational cost of the initialization and verification phases of these privacy-preserving protocols. Sriram Krishnamachari, Mehrdad Nojoumian, Kemal Akkaya |
ICISSP | 3 |
| 2015 | Efficient camera selection for maximized target coverage in underwater acoustic sensor networksabstractIn addition to sensors, cameras have started to be deployed in underwater acoustic sensor networks (UWASNs) for improved monitoring. However, since cameras already consume a lot of energy, they are kept in sleep mode most of the time and only activated when sensors detect a target. Due to random deployment and lack of cameras, there may not be any cameras within the vicinity of a detected target. A possible solution to this problem is to relocate remote cameras via vertical movements to certain locations to capture the target. In this paper, we propose a distributed camera selection and relocation scheme in UWASNs to maximize the coverage of the detected targets with the least vertical movement of cameras. The problem is modeled as a weighted set covering problem and solved using a greedy heuristic. The performance of the proposed approach is assessed through extensive simulations under a variety of conditions. Bilal Gonen, Kemal Akkaya, Fatih Senel |
LCN | 2 |
| 2015 | Efficient Privacy-Preserving Fingerprint-Based Indoor Localization Using CrowdsourcingabstractIndoor localization has been widely studied due to the inability of GPS to function indoors. Numerous approaches have been proposed in the past and a number of these approaches are currently being used commercially. However, little attention was paid to the privacy of the users especially in the commercial products. Malicious individuals can determine a client's daily habits and activities by simply analyzing their WiFi signals and tracking information. In this paper, we implemented a privacy-preserving indoor localization scheme that is based on a fingerprinting approach to analyze the performance issues in terms of accuracy, complexity, scalability and privacy. We developed an Android app and collected a large number of data on the third floor of the FIU Engineering Center. The analysis of data provided excellent opportunities for performance improvement which have been incorporated to the privacy-preserving localization scheme. Patrick Armengol, Rachelle Tobkes, Kemal Akkaya, Bekir Sait Ciftler, Ismail Güvenç |
MASS | 3 |
| 2015 | An Attribute-Based Signcryption Scheme to Secure Attribute-Defined Multicast Communications
Chunqiang Hu, Xiuzhen Cheng, Zhi Tian, Jiguo Yu, Kemal Akkaya, Limin Sun 0001 |
SecureComm | 5 |
| 2015 | Self-deployment of mobile underwater acoustic sensor networks for maximized coverage and guaranteed connectivity
Fatih Senel, Kemal Akkaya, Melike Erol-Kantarci, Turgay Yilmaz |
Ad Hoc Networks | 2 |
| 2015 | PARP-S: A secure piggybacking-based ARP for IEEE 802.11s-based Smart Grid AMI networks
Nico Saputro, Kemal Akkaya |
Comput. Commun. | 2 |
| 2015 | Investigating Public-Key Certificate Revocation in Smart GridabstractThe public key cryptography (PKC) is essential for securing many applications in smart grid. For the secure use of the PKC, certificate revocation schemes tailored to smart grid applications should be adopted. However, little work has been done to study certificate revocation in smart grid. In this paper, we first explain different motivations that necessitate revoking certificates in smart grid. We also identify the applications that can be secured by PKC and thus need certificate revocation. Then, we explain existing certificate revocation schemes and define several metrics to assess them. Based on this assessment, we identify the applications that are proper for each scheme and discuss how the schemes can be modified to fully satisfy the requirements of its potential applications. Finally, we study certificate revocation in pseudonymous public key infrastructure (PPKI), where a large number of certified public/private keys are assigned for each node to preserve privacy. We target vehicles-to-grid communications as a potential application. Certificate revocation in this application is a challenge because of the large number of certificates. We discuss an efficient certificate revocation scheme for PPKI, named compressed certificate revocation lists (CRLs). Our analytical results demonstrate that one revocation scheme cannot satisfy the overhead/security requirements of all smart grid applications. Rather, different schemes should be employed for different applications. Moreover, we used simulations to measure the overhead of the schemes. Mohamed Mahmoud 0001, Jelena V. Misic, Kemal Akkaya, Xuemin Shen |
IEEE Internet Things J. | 3 |
| 2014 | Communication-constrained p-center problem for event coverage in theme parksabstractWireless sensor networks with mobile sinks can be deployed for efficient handling of the events that may occur in a theme park. In such a case, the success of event handling depends on the positions of the mobile sinks and the selection of the most suitable sink to cover an event. While this problem can be solved by using the classical vertex p-center problem, such a solution does not guarantee connectivity among the mobile sinks. The connectivity among mobile sinks is crucial since they need to communicate to share information and perform collaborative event handling. In this paper, we introduce a new variant of vertex p-center problem which we name communication-constrained p-center problem. We propose an exact algorithm as a solution based on identifying connected subnets among the vertices. The performance of the proposed solution is validated through simulations with respect to other approaches as well as the unconstrained case. Giirkan Solmaz, Kemal Akkaya, Danila Turgut |
GLOBECOM | 2 |
| 2014 | An efficient certificate revocation scheme for large-scale AMI networksabstractGiven the large geographic deployment and scalability of the Advanced Metering Infrastructure (AMI) networks, it is inefficient to create one large certificate revocation list (CRL) for all the networks. It is also inefficient to create a CRL for each meter having the certificates it needs because too many CRLs will be required. It is beneficial to balance the size of the CRLs and the overhead of forming and distributing them. In this paper, the certificate authority (CA) groups the AMI networks and composes one CRL for each group. We use Bloom filter to reduce the number of CRLs by increasing the groups size with acceptable overhead on the meters. However, Bloom filters suffer from false positives which is not acceptable in AMI networks because meters may miss important messages. We propose a novel scheme to identify and mitigate the false positives by making use of the fact that Bloom filters are free of false negatives. The meters should contact the gateway to resolve the false positives. We use Merkle tree to enable the gateway to provide efficient proof for certificate revocation without contacting the CA. We derive a mathematical formula to the probability of contacting the gateway as a function of the filter's parameters. We will show that this probability can be low by properly designing the Bloom filter. In order to assess the performance and the applicability of the proposed scheme, we use ns-3 network simulator to implement the scheme in a IEEE 802.11s-based mesh AMI networks. The results demonstrate that our scheme can be used efficiently for AMI networks. Mohamed Mahmoud 0001, Kemal Akkaya, Khaled Rabieh, Samet Tonyali |
IPCCC | 2 |
| 2014 | Performance evaluation of background subtraction algorithms for Android devices deployed in Wireless Multimedia Sensor NetworksabstractWith the increased use of smart phones, Wireless Multimedia Sensor Networks (WMSNs) will have opportunities to deploy such devices in several contexts for data collection and processing. While smart phones come with richer resources and can do complex processing, their battery is still limited. Therefore, data reduction techniques can be used on these devices to reduce energy consumption. One of the common techniques for energy reduction is background subtraction, which has been used for camera sensors in WMSNs. In this paper, we investigate the performance of various BS algorithms on Android devices in terms of computation and communication energy, time and quality. To this end, we picked five different BS algorithms and implemented them in an Android platform. Considering the fact that these BS algorithms will be run within the context of WMSNs where the data is subject to packet losses and errors, we also investigated the performance in terms of packet loss ratio in the network under various packet sizes. The experiment results indicated that the most energy-efficient BS algorithm could also provide the best quality in terms of the foreground detected. The results also indicate that BS algorithms can provide significant energy savings in terms of transmission energy costs. Pinar Bölük, Kemal Akkaya |
IWCMC | 2 |
| 2014 | Editorial for the special issue on routing in smart grid communication networks
Kemal Akkaya, Suleyman Uludag, Xiuzhen Cheng, King-Shan Lui |
Ad Hoc Networks | 1 |
| 2014 | Relay placement for restoring connectivity in partitioned wireless sensor networks under limited information
Izzet F. Senturk, Kemal Akkaya, Sabri Yilmaz |
Ad Hoc Networks | 2 |
| 2014 | Topology management techniques for tolerating node failures in wireless sensor networks: A survey
Mohamed F. Younis, Izzet F. Senturk, Kemal Akkaya, Sookyoung Lee, Fatih Senel |
Comput. Networks | 3 |
| 2014 | On preserving user privacy in Smart Grid advanced metering infrastructure applicationsabstractAdvanced metering infrastructure AMI enables real-time collection of power consumption data through the Smart Grid communication network. With the current deployment of smart meters SMs, one of the concerns that started to be raised by the customers is on the privacy of their power consumption data. The exposure of these data can lead to several privacy problems that need to be addressed before the customers can be convinced for the use of SMs. This paper has two contributions. First, it identifies the threats regarding user and data privacy in AMI applications and comprehensively surveys the existing solutions to address these threats. We categorize the existing approaches on privacy and discuss pros and cons of these approaches with respect to some criteria. Second, we pick one of the existing solutions on privacy, namely the homomorphic encryption, and evaluate its feasibility and impact on performance when used in data aggregation for real-time AMI applications. We investigate and compare the performance of homomorphic encryption in terms of data size and end-to-end delay with that of hop-by-hop secure data aggregation and data concatenation within a network of SMs via extensive simulations. We finally conclude the paper with some future privacy issues that are subject to further research. Copyright © 2013 John Wiley & Sons, Ltd. Nico Saputro, Kemal Akkaya |
Secur. Commun. Networks | 2 |
| 2014 | Optimal Camera Placement for Providing Angular Coverage in Wireless Video Sensor NetworksabstractWireless Video Sensor Networks (WVSNs) provide opportunities to use large number of low-cost low-resolution wireless camera sensors for large-scale outdoor remote surveillance missions. Camera sensor deployment is crucial in achieving good coverage, accuracy and fault tolerance. In particular, with the decreased costs of wireless cameras, redundant camera deployment is attractive in order to get multiple disparate views of events for improved event identification. If the capturing of an event spans${\ 360^\circ}$, this is referred to as angular coverage. In this paper, we consider the problem of determining optimal camera placement to achieve angular coverage continuously over a given region. We develop a bi-level algorithm to find the minimum-cost camera placement. In the first level, we run a master problem that identifies the camera placement points to achieve angular coverage of a discrete set of points selected from the region of interest. Next, we use a sub-problem to identify points in the continuous region that are not covered by the cameras placed in the previous run of the master problem. We then add these uncovered points to discrete point set of the master problem and re-run the master problem. We continue running the master and sub-problems iteratively until the sub-problem becomes infeasible indicating that the entire region is covered. In the numerical experiments, we consider two cases 1) placement of homogeneous cameras with fixed resolutions; and 2) placement of heterogeneous cameras with different characteristics and resolutions. We also introduce varying resolution requirements for different parts of the region and place the cameras such that the required resolution is satisfied. The numerical results show the superiority of the bi-level approach respect to existing approaches. Enes Yildiz, Kemal Akkaya, Esra Sisikoglu, Mustafa Y. Sir |
IEEE Trans. Computers | 2 |
| 2013 | Energy and coverage trade-offs in deploying a mix of mobile and stationary relays for disjoint Wireless Sensor NetworksabstractAdditional relay nodes (RNs) can be deployed within a partitioned Wireless Sensor Network (WSN) to restore connectivity among the partitions. In the case of lack of sufficient RNs to link all the partitions, some of the RNs can act as mobile data collectors (MDCs) to visit partitions for providing intermittent connection for the nodes. Determining the number of MDCs and stationary RNs is a challenge that deals with the trade-off between minimizing the maximum tour length and maximizing the coverage provided by both sensors and the stationary RNs. This paper proposes an RN placement algorithm to guarantee network connectivity while striving to balance the number of MDCs and stationary RNs so that the maximum tour length of MDCs is minimized and an imposed coverage constraint is satisfied. The proposed approach first determines Steiner points to connect partitions by using a Steiner Minimum Tree (SMT) heuristic. The number and location of these Steiner points to be occupied by stationary RNs is determined by using a cost function for each partition. The cost is computed based on the required RN count to connect a partition to the sink. The minimum cost partition is picked iteratively until the coverage constraint is met. The rest of the RNs are employed as MDCs which can tour the remaining partitions using existing algorithms. The proposed approach is evaluated with extensive simulations under a variety of conditions. Izzet F. Senturk, Kemal Akkaya |
GLOBECOM | 2 |
| 2013 | Connectivity restoration in disjoint wireless sensor networks using limited number of mobile relaysabstractDisjoint Wireless Sensor Networks (WSNs) can be reconnected by placing additional relay nodes in the damaged areas. However, in some cases there may not be enough relays to reconnect all the partitions with the sink node. In such a case, some of the relays can exploit their motion capabilities and temporarily act as a mobile data collector (MDC) between partitions providing intermittent connectivity for the nodes sitting in those partitions. Nonetheless, due to increased data latency intermittent connectivity creates, the number of such MDCs need to be minimized. On the other hand, given that the energy resources for an MDC is limited, an upper bound on the travel distance overhead for an MDC needs to be imposed. This paper proposes a relay placement algorithm which guarantees connectivity by maximizing the number of stable connections while meeting the maximum tour constraint on the MDCs. The approach first determines the number and location of relays to restore connectivity by establishing stable links using a Steiner Minimum Tree (SMT) heuristic. Assuming that the number of available relays is less than the needed count, the algorithm determines how many of the available relays need to be stationary and how many of them should act as MDCs. By initially assuming all relays as MDCs, an iterative procedure is followed to reduce the MDC count while meeting the maximum tour length constraint. Specifically, groups of partitions are created and assigned to MDCs for touring. The proposed approach is validated with extensive simulations under a variety of conditions. Izzet F. Senturk, Kemal Akkaya, Fatih Senel, Mohamed F. Younis |
ICC | 2 |
| 2013 | Message from the demonstrations chairabstractIt is my pleasure to welcome you to the fifth Demonstration Session at the IEEE Conference on Local Computer Networks (LCN) 2013. Kemal Akkaya |
LCN | 1 |
| 2013 | An efficient ARP for large-scale IEEE 802.11s-based Smart Grid networksabstractRecently, wireless mesh networks (WMNs) have been touted as one of the suitable communication infrastructure for Smart Grid (SG) Advanced Metering Infrastructure (AMI) applications due to their ease of deployment and reasonable costs. These WMNs are typically based on the upcoming IEEE standard, namely IEEE 802.11s. However, 802.11s has performance related issues regarding scalability. One of the inefficiencies is related to the Address Resolution Protocol (ARP) when creating and maintaining the ARP cache and issuing path discovery within large-scale networks. In this paper, we propose an efficient ARP scheme for large-scale AMI networks. Specifically, we utilize the proactive Path Request (PREQ) message of 802.11s standard to perform the MAC address resolution during routing tree creation and maintenance and hence eliminate the broadcasting of ARP requests. Simulation results with the implementation of 802.11s in Network Simulator 3 (NS-3) show that compared to the original broadcast operations our approach improves the packet delivery ratio and throughput significantly. Nico Saputro, Kemal Akkaya |
LCN | 2 |
| 2013 | Autonomous deployment of sensors for maximized coverage and guaranteed connectivity in Underwater Acoustic Sensor NetworksabstractSelf-deployment of sensors with maximized coverage in Underwater Acoustic Sensor Networks (UWASNs) is challenging due to difficulty of access to 3-D underwater environments. The problem is further compounded if the connectivity of the final network is required. One possible approach is to drop the sensors on the surface and then move them to certain depths in the water to maximize the 3-D coverage while maintaining the connectivity. In this paper, we propose a purely distributed node deployment scheme for UWASNs which only requires random dropping of sensors on the water surface. The goal is to expand the initial network to 3-D with maximized coverage and guaranteed connectivity with a surface station. The idea is based on determining the connected dominating set of the initial network and then adjust the depths of all dominatee and dominator neighbors of a particular dominator node for minimizing the coverage overlaps among them while still keeping the connectivity with the dominator. The process starts with a leader node and spans all the dominators in the network for repositioning. Simulations results indicate that connectivity can be guaranteed regardless of the transmission and sensing range ratio with a coverage very close to a coverage-aware deployment approach. Fatih Senel, Kemal Akkaya, Turgay Yilmaz |
LCN | 2 |
| 2013 | Handling large-scale node failures in mobile sensor/robot networks
Kemal Akkaya, Izzet F. Senturk, Shanthi Vemulapalli |
J. Netw. Comput. Appl. | 1 |
| 2012 | An effective and scalable connectivity restoration heuristic for Mobile Sensor/Actor NetworksabstractDue to inhospitable environments, the actors/sensors in Mobile Sensor/Actor Networks are subject to various damages which can disrupt the data delivery and cooperation. Typically, the damages affect the existing routes and may even cause network partitioning. In such a case, the set of actors/sensors disconnected from the rest of the network, namely a partition, can be re-connected with the network through topology adjustment by exploiting node mobility. However, movement of the nodes consumes significant energy which needs to be minimized. In this paper, we propose an effective yet scalable heuristic approach for restoring network connectivity while minimizing the total movement distance of the nodes. Given that the nodes can move to infinitely many locations in the damaged area, the basic motivation of the heuristic is to reduce the number of locations where the nodes can move. For this purpose, a minimum set of relay points is identified first by running a relay node placement heuristic that can ensure connectivity. Existing nodes in the partitions are then used to fill the relay points based on a greedy heuristic. When selecting nodes from the partitions, the nodes that do not cause further disconnectivity in the partition are picked. This is done by determining the connected dominating set of the partition and identifying the dominatee nodes. The experiment results show that the proposed approach not only performs very close to a near-optimal solution but also scales well when the number of nodes or partitions are increased. Izzet F. Senturk, Kemal Akkaya, Fatih Senel |
GLOBECOM | 2 |
| 2012 | Performance evaluation of wireless mesh networks using IEEE 802.11s and IEEE 802.11nabstractWith the recent approval of IEEE 802.11n standard and progress on IEEE 802.11s mesh standardization efforts, performance evaluation of such standards has gained acceleration. In particular, several wireless testbeds have been created to form wireless mesh networks (WMNs) in order to test various aspects of these new standards. However, none of these considered multi-hop performance of WMNs when 802.11n based nodes are employed. While IEEE 802.11s is geared for implementing multi-hopping capability among the nodes, current studies still assume IEEE 802.11a/g based nodes. This paper presents a performance evaluation of WMNs using both 802.11s (in conjunction with 802.11a/g) and 802.11n on a real academic testbed. While a draft version of 802.11s has been used for creating a linear WMN using 802.11a/g based routers, the same linear WMN using 802.11n has been created using virtualized interfaces at the IP layer. Using such WMNs, throughput performance of TCP and UDP at both the 2.4 GHz and 5 GHz spectrums with different number of hops has been examined. The experiment results have shown that multi-hopping significantly degrades the expected performance of IEEE 802.11n. Tom Imboden, Kemal Akkaya, Zach Moore |
ICC | 2 |
| 2012 | A Game-Theoretic approach to connectivity restoration in Wireless Sensor and Actor NetworksabstractNetwork partitioning can happen due to node failures in Wireless Sensor and Actor Networks (WSANs) that are deployed in inhospitable environments. In case of multiple actor damages, the network can be easily partitioned into several partitions which disrupt the communication among actors. In such a case, the nodes can relocate to re-establish the network connectivity. Such movement, however, should be minimized due to high energy cost for movement. In this paper, we tackle the problem of connectivity restoration in partitioned WSAN with minimized movement overhead by using a Game Theory based heuristic. The idea is based on the comparison of Nash equilibrium of the partitions. Specifically, the nodes staying in the partitions with greater equilibrium will be stationary while the nodes that are in partitions with the less equilibrium are relocated. In this way, partitions become a part of a federated partition and this federation process takes place until reaching the system-wide unique equilibrium. The effectiveness of the approach is evaluated under a variety of conditions and has been shown to be scalable and effective. Izzet F. Senturk, Sabri Yilmaz, Kemal Akkaya |
ICC | 3 |
| 2012 | Efficient and Accurate Object Classification in Wireless Multimedia Sensor NetworksabstractObject classification from video frames has become more challenging in the context of Wireless Multimedia Sensor Networks (WMSNs). This is mainly due to the fact that these networks are severely resource constrained in terms of the deployed camera sensors. The resources refer to battery, processor, memory and storage of the camera sensor. Limited resources mandates the need for efficient classification techniques in terms of energy consumption, space usage and processing power. In this paper, we propose an efficient yet accurate classification algorithm for WMSNs using a genetic algorithm-based classifier. The efficiency of the algorithm is achieved by extracting two simple but effective features of the objects from the video frames, namely shape of the minimum bounding box of the object and the speed of the object in the monitored region. The accuracy of the classification, on the other hand, is provided through using a genetic algorithm whose space/memory requirements are minimal. The training of this genetic algorithm based classifier is done offline and it is stored at each camera in advance to perform online classification during surveillance missions. The experiments indicate that a promising classification accuracy can be achieved without introducing a major energy and storage overhead on camera sensors. Hakan Öztarak, Turgay Yilmaz, Kemal Akkaya, Adnan Yazici |
ICCCN | 3 |
| 2012 | Distributed relay node positioning for connectivity restoration in partitioned Wireless Sensor NetworksabstractDue to limited battery life of sensors and harsh deployment environments where they are deployed, Wireless Sensor Networks (WSNs) can be subjected to node failures. This can split the network into partitions containing healthy but unreachable nodes by the rest of the network including the sink node. One possible solution to this problem is deploying relay nodes assuming that the damaged area, the number of partitions and the location of the partitions are known to a centralized party. However, depending on the application, some of this information may not always be available, requiring a distributed self-deployment placement strategy. Such a strategy should not only guarantee the network connectivity but also strive to minimize the movement overhead on the relay nodes assuming that they are also battery-operated. In this paper, we present a distributed relay node positioning approach to address the problem of connectivity restoration in partitioned WSNs. The approach exploits Game Theory among the relay nodes and the partitions. Relay nodes determine the partitions to connect based on the probability distribution function (pdf) of the partitions. If the partition has a higher pdf, it is recovered earlier and becomes the part of the connected network. The recovery process takes place until reaching the system-wide unique Nash equilibrium. Game Theoretic approach has been shown to outperform baseline approaches under all conditions. Izzet F. Senturk, Kemal Akkaya, Sabri Yilmaz |
ISCC | 2 |
| 2012 | On the performance of sensor node repositioning under realistic terrain constraintsabstractNode mobility has been exploited in many context of Mobile Sensor Networks (MSNs) and Wireless Sensor and Actor Networks (WSANs) to improve network performance. In particular, network partitioning due to node failures has been addressed via repositioning of some of the mobile nodes. In all of these studies, the application terrain is assumed to be obstacle free and the movements are performed by following the direct path from the source to destination. However, in reality, this is not the case since the terrains would not be obstacle free and the nodes cannot move freely and smoothly to every requested location. The terrain type, elevation as well as the obstacles should be taken into account before the nodes start moving. In this paper, we claim that most of the existing approaches would either not work or produce wrong results if realistic assumptions regarding the terrain are not considered. To demonstrate our claims regarding the mobility issues, we consider two of the existing heuristics on the connectivity restoration problem in disjoint MSNs. Rather than following the direct path for movement as done in these works, we propose to use a path planning algorithm for determining the least-cost path in terms of energy consumption. In the experiments, we simulate several varieties of terrain types, obstacles and elevations in the region. Simulation results indicate that the movement cost is significantly higher and this should be taken into account to redesign the existing approaches. Izzet F. Senturk, Kemal Akkaya |
LCN | 2 |
| 2012 | Performance evaluation of Smart Grid data aggregation via homomorphic encryptionabstractHomomorphic encryption allows arithmetic operations to be performed on ciphertext and gives the same result as if the same arithmetic operation is done on the plaintext. Homomorphic encryption has been touted as one of the promising methods to be employed in Smart Grid (SG) to provide data privacy which is one of the main security concerns in SG. In addition to data privacy, real-time data flow is crucial in SG to provide on-time detection and recovery of possible failures. In this paper, we investigate the overhead of using homomorphic encryption in SG in terms of bandwidth and end-to-end data delay when providing data privacy. Specifically, we compare the latency and data size of end-to-end (ETE) and hop-by-hop (HBH) homomorphic encryption within a network of Smart Meters (SMs). In HBH encryption, at each intermediate node, the received encrypted data from downstream nodes are decrypted first before the aggregation, and then the result is encrypted again for transmission to upstream nodes. On the other hand, the intermediate node in ETE encryption only performs aggregation on ciphertexts for transmission to upstream nodes. We implemented secure data aggregation using Paillier cryptosystem and tested it under various conditions. The experiment results have shown that even though HBH homomorphic encryption has additional computational overhead at intermediate nodes, surprisingly it provides comparable latency and fixed data size passing through the network compared to ETE homomorphic encryption. Nico Saputro, Kemal Akkaya |
WCNC | 2 |
| 2012 | A survey of routing protocols for smart grid communications
Nico Saputro, Kemal Akkaya, Suleyman Uludag |
Comput. Networks | 2 |
| 2011 | Camera Deployment for Video Panorama Generation in Wireless Visual Sensor NetworksabstractIn this paper, we tackle the problem of providing coverage for video panorama generation in Wireless Heterogeneous Visual Sensor Networks (VSNs) where cameras may have different price, resolution, Field-of-View (FoV) and Depth-of-Field (DoF). We utilize multi-perspective coverage (MPC) which refers to the coverage of a point from given disparate perspectives simultaneously. For a given minimum average resolution, area boundaries, and variety of camera sensors, we propose a deployment algorithm which minimizes the total cost while guaranteeing full MPC of the area (i.e., the coverage needed for video panorama generation) and the minimum required resolution. Specifically, the approach is based on a bi-level mixed integer program (MIP), which runs two models, namely master problem and sub-problem, iteratively. Master-problem provides coverage for initial set of identified points while meeting the minimum resolution requirement with minimum cost. Sub-problem which follows the master-problem finds an uncovered point and extends the set of points to be covered. It then sends this set back to the master-problem. Master-problem and sub-problem continue to run iteratively until sub-problem becomes infeasible, which means full MPC has been achieved with the resolution requirements. The numerical results show the superiority of our approach with respect to existing approaches. Enes Yildiz, Kemal Akkaya, Esra Sisikoglu, Mustafa Y. Sir, Ismail Guneydas |
ISM | 2 |
| 2011 | An exact algorithm for providing multi-perspective event coverage in Wireless Multimedia Sensor NetworksabstractDeployment of cameras in Wireless Multimedia Sensor Networks (WMSNs) is crucial in achieving good coverage, accuracy and fault tolerance. With the decreased costs of wireless cameras, WMSNs provide opportunities for redundant camera deployment in order to get multiple disparate views of events. Referred to as multi-perspective coverage (MPC), this paper proposes an optimal solution for camera deployment that can achieve full MPC for a given region. The solution is based on a Bi-Level mixed integer program (MIP) which works by solving two sub-problems named master and sub-problems. The master problem identifies a solution based on an initial set of points and then calls the sub-problem to cover the uncovered points iteratively. Experiments show that our solution can provide full MPC with less number of cameras compared to traditional solutions. Enes Yildiz, Kemal Akkaya, Esra Sisikoglu, Mustafa Y. Sir |
IWCMC | 2 |
| 2011 | Distributed collaborative camera actuation for redundant data elimination in wireless multimedia sensor networks
Andrew Newell, Kemal Akkaya |
Ad Hoc Networks | 2 |
| 2011 | A survey of authentication schemes for vehicular ad hoc networksabstractAbstract Vehicular ad hoc networks (VANETs) are planned to be deployed within the next decade to improve driver safety, prevent collisions, and provide traffic optimization. Recent years have witnessed an increasing interest in the security schemes for VANETs as this area was relatively less explored compared to other areas such as medium access and routing. In particular, efficient authentication of the messages in a VANET with other desirable security features have been heavily studied. However, there are still several issues to be addressed before such authentication mechanisms can be readily and widely used in real‐life deployments. In this paper, we examine several proposed authentication solutions and categorize them based on certain criteria. We provide a comparison of the advantages and disadvantages of the proposed schemes identifying their suitability under various conditions. Finally, to foster further research in the area, we address some of the challenges that need to be tackled in the future in order to realize the deployment of VANETs. Copyright © 2010 John Wiley & Sons, Ltd. Marshall Riley, Kemal Akkaya, Kenny Fong |
Secur. Commun. Networks | 2 |
| 2011 | Group-based hybrid authentication scheme for cooperative collision warnings in VANETsabstractAbstract Cooperative collision warnings (CCWs) is one of the important applications of Vehicular Ad‐Hoc Networks (VANETs) where secure and timely delivery of messages to the neighboring vehicles are needed. Secure communication is as important as timely communication to take proper actions in order to avoid collisions and thus prevent fatal accidents. However, security and delay are two competing metrics since security brings additional processing overhead, increasing the packet delays. While symmetric‐key‐based security techniques can be more efficient as opposed to public‐key cryptography (PKC) in terms of delay, they introduce significant key maintenance overheads with the increased number of vehicles in VANETs. To alleviate this overhead and take the advantage of faster processing, we exploit the natural group behavior in CCW applications. We propose a delay efficient authentication scheme for VANETs which is based on group communication. Groups are created and maintained dynamically led by leader vehicles. Since the data communication within the groups will be dominating the overall packet traffic, we utilize symmetric‐key techniques within each group which is handled by the group leader. Group creations on the other hand are less frequent events and thus are done by PKC. We analyzed the security properties of our proposed scheme and tested it with real‐world vehicle data. Simulations results confirmed the efficiency in terms of delay with respect to other existing techniques. Copyright © 2011 John Wiley & Sons, Ltd. Marshall Riley, Kemal Akkaya, Kenny Fong |
Secur. Commun. Networks | 2 |
| 2010 | Providing multi-perspective event coverage in wireless multimedia sensor networksabstractThe increasing availability of low-cost battery-operated wireless cameras has motivated the deployment of large-scale Wireless Multimedia Sensor Networks (WMSNs) which can be leveraged for gathering disparate views of events from multiple perspectives. Such multi-perspective coverage not only provides better visual knowledge about the events but also helps reduce occlusions in many critical applications. Different than traditional k-coverage in Wireless Sensor Networks (WSNs), multi-perspective coverage computation considers the orientation of cameras in addition to their locations. In this paper, we first introduce a new metric which can measure multi-perspective coverage for a particular region from a given number of perspectives. Using this metric, we then propose camera placement techniques based on binary integer programming and heuristics to achieve full multi-perspective coverage with the least camera count. Finally, to be used as a baseline, we come up with a formula which can analytically compute the multi-perspective coverage for a given network of randomly placed cameras in a certain region. We evaluated the performance of these camera placement approaches (e.g., integer programming, heuristic and random) in terms of coverage and number of cameras needed under different number of perspectives. Andrew Newell, Kemal Akkaya, Enes Yildiz |
LCN | 2 |
| 2010 | Delay-efficient geodynamic group-based authentication in VANETsabstractSecure and timely delivery of messages for safety applications in Vehicular Ad Hoc Networks (VANETs) is crucial to prevent fatal accidents. However, security and delay are two competing metrics since security brings additional processing overhead, increasing the packet delays. While symmetric-key based security techniques can be more efficient as opposed to public-key cryptography (PKC) in terms of delay, they introduce significant key maintenance overheads with the increased number of vehicles in VANETs. To alleviate this overhead and take the advantage of faster processing, we exploit the natural group behavior in VANET applications. We propose a delay efficient authentication scheme for VANETs which is based on group communication. Groups are created and maintained geo-dynamically led by leader vehicles. Since the data communication within the groups will be dominating the overall packet traffic, we utilize symmetric-key techniques within each group which is handled by the group leader. Group creations on the other hand are less frequent events and thus done by PKC. We analyzed the security and efficiency properties of our proposed scheme to show its spueriority with respect to other existing techniques. Marshall Riley, Kemal Akkaya, Kenny Fong |
LCN | 2 |
| 2010 | Mobility-based self route recovery from multiple node failures in mobile sensor networksabstractIn wireless sensor networks (WSNs), maintaining connectivity with the sink node is a crucial issue to collect data from sensors without any interruption. While sensors are typically deployed in abundance to tolerate possible node failures, a large number of such failures within the same region simultaneously may result in losing the connectivity with the sink node which eventually reduces the quality and efficiency of the network operation. Given that WSNs are deployed in inhospitable environments, such multiple node failures are very likely due to storms, fires, floods, etc. To recover from these multiple node failures, in this paper, we first present a local partition detection algorithm which makes the sensors aware of the damage and thus the partitioning in the network. We then utilize this information to recover the paths by exploiting sensor mobility. The idea is to locate the failed nodes by keeping complete routing information from each sensor to the sink node and move some of the sensors to such locations to re-establish the routes with the sink node. When performing the recovery, we make sure that the least number of nodes will be moving so that total movement distance can be minimized to improve the lifetime of the WSN. Our proposed approach depends only on the local information to not only minimize the messaging overhead on the sensors but also to ensure the scalability when large-scale failures and larger networks are considered. The effectiveness of the proposed route recovery approach is validated through simulation experiments. Shanthi Vemulapalli, Kemal Akkaya |
LCN | 2 |
| 2010 | A conceptual model for data management and distribution in peer-to-peer systems
Ramazan Savas Aygün, Kemal Akkaya, Glenn W. Cox, Ali Biçak |
Peer-to-Peer Netw. Appl. | 3 |
| 2010 | Distributed Recovery from Network Partitioning in Movable Sensor/Actor Networks via Controlled MobilityabstractMobility has been introduced to sensor networks through the deployment of movable nodes. In movable wireless networks, network connectivity among the nodes is a crucial factor in order to relay data to the sink node, exchange data for collaboration, and perform data aggregation. However, such connectivity can be lost due to a failure of one or more nodes. Even a single node failure may partition the network, and thus, eventually reduce the quality and efficiency of the network operation. To handle this connectivity problem, we present PADRA to detect possible partitions, and then, restore the network connectivity through controlled relocation of movable nodes. The idea is to identify whether or not the failure of a node will cause partitioning in advance in a distributed manner. If a partitioning is to occur, PADRA designates a failure handler to initiate the connectivity restoration process. The overall goal in this process is to localize the scope of the recovery and minimize the overhead imposed on the nodes. We further extend PADRA to handle multiple node failures. The approach, namely, MDAPRA strives to provide a mutual exclusion mechanism in repositioning the nodes to restore connectivity. The effectiveness of the proposed approaches is validated through simulation experiments. Kemal Akkaya, Fatih Senel, Aravind Thimmapuram, Suleyman Uludag |
IEEE Trans. Computers | 1 |
| 2009 | Lightweight Object Localization with a Single Camera in Wireless Multimedia Sensor NetworksabstractAdvances in wireless multimedia sensor networks (WMSNs) stimulated interest in designing lightweight solutions in terms of processing and energy consumption for traditional problems due to severe resources constraints on camera sensors. Finding the exact object location is one of such traditional problems which has been well studied in the past. However, the proposed solutions mostly involve complex processing with multiple cameras and thus cannot be applied to surveillance applications which need to be deployed for extended periods. In this paper, we propose an object localization scheme for WMSNs which can be run on a single camera sensor by only using the sensor's location information. Our approach first extracts the detected object using frame differencing. To reduce the processing cost of this operation, each frame size is reduced with some video pre-processing. The location of the object can then be estimated using the distance of the object to the camera and camera/frame size properties. In addition to being energy-efficient, since a single camera sensor is involved, the required time for localization is reduced immensely as opposed to approaches which involve multiple camera sensors. Our experiments indicates that a promising accuracy can be achieved in determining the exact object location without introducing a major energy overhead. Hakan Öztarak, Kemal Akkaya, Adnan Yazici |
GLOBECOM | 2 |
| 2009 | Self-Actuation of Camera Sensors for Redundant Data Elimination in Wireless Multimedia Sensor NetworksabstractWith the increasing interest in the deployment of wireless multimedia sensor networks (WMSNs), new challenges arouse with effective use of camera sensors to provide maximized event coverage with the least amount of redundancy in the collected multimedia data. Given that the processing and transmission of multimedia data are costly in terms of energy, camera sensors should only be actuated when an event is detected within their vicinity. While achieving maximum coverage with such actuation is desirable, multiple camera sensors' field-of- view (FoV) can be covering the same spots and thus redundant multimedia data can unnecessarily be sent to the base-station. In this paper, assuming camera sensors with fixed orientation, we propose a low-cost distributed actuation scheme which strives to turn on the least number of camera sensors to avoid possible redundancy in the multimedia data while still providing the necessary event coverage. The basic idea of this distributed scheme is the collaboration of camera sensors that have heard from scalar sensors about an occurring event in order to minimize the possible coverage overlaps among their FoVs. The scheme requires only 1-hop information for camera sensors and its messaging overhead is negligible. Through simulation, we show how the distributed scheme performs with respect to the cases when all the cameras within the vicinity or the region are actuated and assess the performance under various conditions. Andrew Newell, Kemal Akkaya |
ICC | 2 |
| 2009 | Static worst-case energy and lifetime estimation of wireless sensor networksabstractWith the advance of computer and communication technologies, wireless sensor networks (WSNs) are increasingly used in many aspects of our daily life. However, since the battery lifetime of WSN nodes is restricted, the WSN lifetime is also limited. Therefore, it is crucial to determine this limited lifetime in advance for preventing service interruptions in critical applications. This paper proposes a feasible static analysis approach to estimate the worst-case lifetime of a WSN. Assuming known routes with a given sensor network topology and S-MAC as the underlying MAC protocol, we statically estimate the lifetime of each sensor node with a fixed initial energy budget. These estimations are then compared with the results obtained through simulation which run with the same energy budget on each node. Experimental results of our research on TinyOS applications indicate that our approach can safely and accurately estimate the worst-case lifetime of WSNs. To the best of our knowledge, our work is the first one to estimate the worst-case lifetime of WSNs through static analysis method. Yu Liu 0037, Wei Zhang 0002, Kemal Akkaya |
IPCCC | 3 |
| 2009 | C2AM: an algorithm for application-aware movement-assisted recovery in wireless sensor and actor networksabstractIn Wireless Sensor and Actor Networks (WSANs) a connected interactor topology is desirable in order for the deployed actors to work collaboratively. If a critical actor fails causing the inter-actor network to get partitioned into disjoint segments, the other actors close to the faulty node often exploit their mobility to autonomously restore the lost inter-actor connectivity. However, such a solution focuses on resource efficiency and assumes no constraints on the mobility of actors which can be impractical in the real scenarios. In addition, since actors need to carry out tasks to meet the application level requirements, unconstrained movement of actor(s) to restore interactor connectivity can cause a major failure at the application level. This paper presents C2AM; a recovery algorithm that factors in application level constraints on actor's mobility while restoring the network connectivity. In addition to considering physical level requirements, C2AM accounts for application level concerns as well in order to avoid major disruptions to ongoing missions. Simulation results have validated the effectiveness of the algorithm in maintaining both objectives. Ameer Ahmed Abbasi, Uthman A. Baroudi, Mohamed F. Younis, Kemal Akkaya |
IWCMC | 4 |
| 2009 | A robust relay node placement heuristic for structurally damaged wireless sensor networksabstractWireless sensor networks (WSN) can increase the efficiency of many real-life applications through the collaboration of thousands of miniaturized sensors which can be deployed unattended in inhospitable environments. Due to the harsh surroundings and violent nature of the applications, the network sometimes suffers a large scale damage that involves many nodes and would thus create multiple disjoint partitions. This paper investigates a strategy for recovering from such damage through the placement of relay nodes and promotes a novel approach. The proposed approach opts to re-establish connectivity using the least number of relays while ensuring certain quality in the formed topology. Unlike contemporary schemes that form a minimum spanning tree among the isolated segments, the proposed approach establishes a topology that resembles a spider web, for which the segments are situated at the perimeter. Such a topology not only exhibits stronger connectivity than a minimum spanning tree but also achieves better sensor coverage and enables balanced distribution of traffic load among the employed relays. The simulation results demonstrate the effectiveness of the proposed recovery algorithm. Fatih Senel, Mohamed F. Younis, Kemal Akkaya |
LCN | 3 |
| 2009 | Detecting and connecting disjoint sub-networks in wireless sensor and actor networks
Kemal Akkaya, Fatih Senel |
Ad Hoc Networks | 1 |
| 2009 | Self-deployment of sensors for maximized coverage in underwater acoustic sensor networks
Kemal Akkaya, Andrew Newell |
Comput. Commun. | 1 |
| 2009 | Clustering of wireless sensor and actor networks based on sensor distribution and connectivity
Kemal Akkaya, Fatih Senel, Brian McLaughlan |
J. Parallel Distributed Comput. | 1 |
| 2009 | Movement-Assisted Connectivity Restoration in Wireless Sensor and Actor NetworksabstractRecent years have witnessed a growing interest in applications of wireless sensor and actor networks (WSANs). In these applications, a set of mobile actor nodes are deployed in addition to sensors in order to collect sensors' data and perform specific tasks in response to detected events/objects. In most scenarios, actors have to respond collectively, which requires interactor coordination. Therefore, maintaining a connected interactor network is critical to the effectiveness of WSANs. However, WSANs often operate unattended in harsh environments where actors can easily fail or get damaged. An actor failure may lead to partitioning the interactor network and thus hinder the fulfillment of the application requirements. In this paper, we present DARA, a distributed actor recovery algorithm, which opts to efficiently restore the connectivity of the interactor network that has been affected by the failure of an actor. Two variants of the algorithm are developed to address 1- and 2-connectivity requirements. The idea is to identify the least set of actors that should be repositioned in order to reestablish a particular level of connectivity. DARA strives to localize the scope of the recovery process and minimize the movement overhead imposed on the involved actors. The effectiveness of DARA is validated through simulation experiments. Ameer Ahmed Abbasi, Mohamed F. Younis, Kemal Akkaya |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2008 | Real-time routing for mobile sensor/actor networksabstractWith the increasing interest in the application of wireless ad hoc networks, the demand for providing QoS in such applications also grows. Particularly, in sensor and actor networks, providing certain delay bounds is crucial for the actors as they perform their actions based on the received data from sensors. The usefulness of the content from sensors is based on its timeliness. In this paper, we present Ad Hoc On Demand Delay Constrained Distance Vector Routing (AOD2V) which is an extension to the widely used routing protocol AODV for providing delay constrained data delivery in mobile sensor/actor networks. The admission control is based on Delay-EDD scheduling algorithm. The idea is to reserve the resources while routes are being determined in the route discovery phase of AODV. The reservation considers the service time at each node till the destination node. As long as the cumulative delay which is received at the destination is less than the desired delay bound, a positive acknowledgment is sent back to all the nodes on the path with AODVpsilas route reply packet and the connection request is admitted. Otherwise, the connection request is rejected and the reserved resources at the intermediate nodes are released. When the data transmission starts, Earliest Deadline First (EDF) scheduling algorithm is used to determine the departure order of the packets at the intermediate nodes. The performance of AOD2V is validated through extensive simulations and has been shown to outperform AODV in terms of delay and data delivery ratio without introducing any major extra overhead. Aravind R. Sama, Kemal Akkaya |
LCN | 2 |
| 2008 | Distributed channel assignment in Wireless Mesh Networks with guaranteed connectivityabstractUsing multiple radios/channels in wireless mesh networks (WMNs) can significantly boost the throughput of the network and brings broadband wireless access to more users with reduced cost. However, this requires careful assignment of channels to each radio so that interference due to parallel communications can be minimized and the network is not partitioned. We propose a distributed channel assignment protocol for WMNs to maximize the total number of non-interfering concurrent active links and guarantee the network connectivity. The motivation for maximizing the number of links is to give as much leeway to the routing subsystem as possible. The problem is modeled as a list coloring problem where each channel corresponds to a color. The main idea is to determine the minimum degree spanning tree (MDST) of the network for providing more parallel transmissions and guaranteeing connectivity. The links that are not part of the MDST are assigned channels based on a 5-way handshake protocol to resolve arising conflicting requests in the distributed approach. We validate the performance by comparing our approach to a greedy channel assignment that does not guarantee connectivity. Suleyman Uludag, Kemal Akkaya |
LCN | 2 |
| 2008 | Distributed Recovery of Actor Failures in Wireless Sensor and Actor NetworksabstractWireless sensor and actor networks (WSANs) additionally employ actor nodes within the wireless sensor network (WSN) which can process the sensed data and perform certain actions based on this collected data. In most applications, inter-actor coordination is required to provide the best response. This suggests that the employed actors should form and maintain a connected inter-actor network at all times. However, WSANs often operate unattended in harsh environments where actors can easily fail or get damaged. Such failures can partition the inter-actor network and thus eventually make the network useless. In order to handle such failures, we present a connected dominating set (CDS) based partition detection and recovery algorithm. The idea is to identify whether the failure of a node causes partitioning or not in advance. If a partitioning is to occur, the algorithm designates one of the neighboring nodes to initiate the connectivity restoration process. This process involves repositioning of a set of actors in order to restore the connectivity. The overall goal in this restoration process is to localize the scope of the recovery and minimize the movement overhead imposed on the involved actors. The effectiveness of the approach is validated through simulation experiments. Kemal Akkaya, Aravind Thimmapuram, Fatih Senel, Suleyman Uludag |
WCNC | 1 |
| 2008 | Strategies and techniques for node placement in wireless sensor networks: A survey
Mohamed F. Younis, Kemal Akkaya |
Ad Hoc Networks | 2 |
| 2008 | Maximizing connected coverage via controlled actor relocation in wireless sensor and actor networks
Kemal Akkaya, S. Janapala |
Comput. Networks | 1 |
| 2008 | The impact of data aggregation on the performance of wireless sensor networksabstractAbstract With the increasing need for different energy saving mechanisms in Wireless Sensor Networks (WSNs), data aggregation techniques for reducing the number of data transmissions by eliminating redundant information have been studied as a significant research problem. These studies have shown that data aggregation in WSNs may produce various trade‐offs among some network related performance metrics such as energy, latency, accuracy, fault‐tolerance and security. In this paper, we investigate the impact of data aggregation on these networking metrics by surveying the existing data aggregation protocols in WSNs. Our aim is twofold: First, providing a comprehensive summary and comparison of the existing data aggregation techniques with respect to different networking metrics. Second, pointing out both the possible future research issues and the need for collaboration between data management and networking research communities working on data aggregation in WSNs. Copyright © 2006 John Wiley & Sons, Ltd. Kemal Akkaya, Murat Demirbas, Ramazan Savas Aygün |
Wirel. Commun. Mob. Comput. | 1 |
| 2007 | An Efficient Mechanism for Establishing Connectivity in Wireless Sensor and Actor NetworksabstractWireless sensor and actor networks (WSANs) employ powerful and mobile actor nodes that can perform application specific actions based on the received data from the sensors. As most of these actions are performed collaboratively among the actors, inter-actor connectivity is one of the desirable features of WSANs. In this paper, we propose a novel distributed algorithm for establishing a connected inter-actor network topology. Considering an initially partitioned actor network with intra-connected sub-networks, our algorithm pursues a coordinated actor movement in order to connect the sub-networks. The goal of this movement is to both minimize the total and maximum travel distances of the individual actors. Our algorithm considers the minimum connected dominating set of each sub-network when picking the appropriate actor to move so that the connectivity of each sub-network is not violated. We analytically study the performance of our algorithm. Extensive simulation experiments validate the analytical results and confirm the effectiveness of our approach. Fatih Senel, Kemal Akkaya, Mohamed F. Younis |
GLOBECOM | 2 |
| 2007 | C2AP: Coverage-aware and Connectivity-constrained Actor Positioning in Wireless Sensor and Actor NetworksabstractIn addition to the miniaturized sensor nodes, wireless sensor and actor networks (WSANs) employ significantly more capable actor nodes that can perform application specific actions to deal with events detected and reported by the sensors. Since these actions can be taken at any spot within the monitored area, the actors should be carefully placed in order to provide maximal coverage. Moreover, the actors often coordinate among themselves in order to arbitrate tasks and thus inter-actor connectivity is usually a requirement. In this paper, we propose a distributed actor positioning algorithm that maximizes the coverage of actors without violating the connectivity requirement. The approach applies repelling forces between neighboring actors, similar to molecular particles in Physics, in order to spread them in the region. However, the movement of each actor is restricted in order to maintain the connectivity of the inter-actor network. The performance of the approach is validated through simulations. Kemal Akkaya, Mohamed F. Younis |
IPCCC | 1 |
| 2007 | A Distributed Connectivity Restoration Algorithm in Wireless Sensor and Actor NetworksabstractThere has been an increased interest in applications of wireless sensor and actor networks (WSANs) in recent years. In such applications, a set of mobile actor nodes are deployed in addition to sensors in order to collect sensors' data and perform specific tasks in response to detected events/objects. In most scenarios actors have to respond collectively which requires an inter-actor coordination. Therefore, maintaining a connected inter-actor network is crucial to the effectiveness of WSANs. However, WSANs often operate unattended in harsh environments where actors can easily fail or get damaged. Due to such failures an actor will be unable to communicate with its neighbors which may lead to partitioning the inter-actor network. In this paper we present DARA; a Distributed Actor Recovery Algorithm, which opts to efficiently restore the connectivity of the inter-actor network that has been affected by the failure of an actor. The idea is to identify the least set of actors that should be repositioned in order to establish connectivity among disjoint network partitions. DARA strives to localize the scope of the recovery process and minimize the movement overhead imposed on the involved actors. The effectiveness of DARA is validated through simulation experiments. Ameer Ahmed Abbasi, Kemal Akkaya, Mohamed F. Younis |
LCN | 2 |
| 2007 | Quality-of-service provisioning via stochastic path selection under Weibullian link delaysabstractWe study the problem of finding the most likely path satisfying a requested additive Quality-of-Service (QoS) value, such as delay. The link metrics are defined as random variables following Weibull probability distributions as empirically reported in [13] and analytically derived in [12]. The problem of finding the most likely path is NP-Hard [24]. Our approach involves reducing the complicated probability convolutions necessary to calculate the most probable path that satisfies a requested delay value. With the reduction of the objective function, an extended Bellman-Ford algorithm is devised to solve the problem. The resulting approach have the same complexity as the standard Bellman-Ford algorithm. Our reduced objective function only needs the location parameter of the Weibull distributions, hence avoiding the complexity of inferring the shape and scale parameters. We evaluate the performance of our approach by simulations and conclude with possible extensions of our work. Suleyman Uludag, Ljubomir Perkovic, Anna Kashkanova, Kemal Akkaya |
QSHINE | 4 |
| 2006 | An Intelligent Safety-Aware Gateway Relocation Scheme for Wireless Sensor NetworksabstractRecently, wireless sensor networks (WSN) have received enormous attentions due to their potential use in many applications. They can be used to enrich our understanding of natural events, such as earthquakes and volcanoes, and to increase the efficiency of surveillance operations in secure installation, border control and military reconnaissance. Sensors are placed in harsh environments to collect and deliver data to a central node, called the gateway. The gateway analyzes the received data and decides on appropriate actions. Therefore, protecting the gateway is critical for ensuring the robustness of WSN. Since the location of the gateway significantly affects the efficiency of the network operation, many research have been conducted for the gateway placement problem. However, most of the proposed solutions are geared for boosting network-related performance metrics, such as throughput and energy consumption. We argue that relocating without taking safety concerns into consideration may cause the gateway to move dangerously close to one or multiple serious events in the environment. In this paper, we present GRENN, a new algorithm for gateway relocation in wireless sensor networks considering both the network performance and the gateway safety. Our experimental validation has demonstrated the effectiveness of GRENN in protecting the gateway while keeping the performance at an acceptable level. Waleed A. Youssef, Mohamed F. Younis, Kemal Akkaya |
ICC | 3 |
| 2006 | COLA: A Coverage and Latency Aware Actor Placement for Wireless Sensor and Actor NetworksabstractIn addition to the sensors, wireless sensor and actor networks (WSANs) employ significantly more capable actor nodes that can perform application specific actions. In these setups responsiveness to serious events is of utmost importance and thus requires minimal latency in both data gathering and action completion. In addition, since these actions are often taken at or close to where events are detected, which can be any spot within the monitored area, the actors should strive to provide maximal coverage of the area. In this paper, we propose COLA, an actor placement mechanism that considers both the delay requirements of data collection and the coverage. COLA first evenly distributes the actors in the region for maximized coverage. Actors then collaboratively partition the sensors, forming clusters. Each individual actor then repositions itself at a location that enables minimal latency in collecting data. The effectiveness of COLA is evaluated by extensive simulations. Kemal Akkaya, Mohamed F. Younis |
VTC Fall | 1 |
| 2005 | Efficient aggregation of delay-constrained data in wireless sensor networksabstractAbstract: Recent years have witnessed a growing interest in the application of wireless sensor networks in unattended environments. Nodes in such applications are equipped with limited energy supply and need careful management in order to extend their lifetime. In order to conserve energy, many of the routing protocols proposed for wireless sensor networks reduce the number of transmitted packets by pursuing in-network data aggregation. Almost all of the aggregation schemes presented in the literature strive to save sensor’s energy while considering unconstrained data traffic. However, aggregation extends the queuing delay at the relay nodes and can thus complicate the handling of latencyconstrained data. In this paper, we analyze the conditions for effective aggregation of data traffic that is subject to end-to-end delay constraints. We present an algorithm for achieving maximal possible energy saving through data aggregation while meeting the desired level of timeliness. A Weighted Fair Queuing based mechanism for packet scheduling is employed at each node in order to perform service differentiation and ensure bounded delay for constrained traffic. The performance of the proposed approach is qualified via simulation. 1. Kemal Akkaya, Mohamed F. Younis, Moustafa Youssef 0001 |
AICCSA | 1 |
| 2005 | A survey on routing protocols for wireless sensor networks
Kemal Akkaya, Mohamed F. Younis |
Ad Hoc Networks | 1 |
| 2005 | Sink repositioning for enhanced performance in wireless sensor networks
Kemal Akkaya, Mohamed F. Younis, Meenakshi Bangad |
Comput. Networks | 1 |
| 2004 | Relocation of gateway for enhanced timeliness in wireless sensor networksabstractIn recent years, due to increasing interest in applications of wireless sensor networks that demand certain quality of service (QoS) guarantees, new routing protocols have been proposed for providing energy-efficient real-time relaying of data. However, none of these protocols considered any possible movement of the sink node for performance purposes. In this paper, we propose possible relocation of sink (gateway) for improving the timeliness of real-time packets. Our approach searches for a location close to the most loaded node. The gateway is then relocated to the new location so that the load of that node is alleviated and the real-time traffic can be split. As long as the gateway stays within the transmission range of all last hop nodes, it can be moved to that location without affecting the current route setup. Otherwise routes are adjusted by introducing new forwarders. Simulation results demonstrate the effectiveness of the proposed approach. Kemal Akkaya, Mohamed F. Younis |
IPCCC | 1 |
| 2003 | Optimization of Task Allocation in a Cluster-Based Sensor NetworkabstractSensor networks have recently gained a lot of attention from the research community. Sensors are significantly resource-constrained devices and last till the depletion of their batteries. Sensor networks typically have a large number of nodes. To ensure scalability sensor networks are often partitioned into clusters, each managed by a cluster head (gateway). Efficient management of a sensor network for extending the lifetime of the network is among the prominent areas of research in this domain. While most of the previous research focused on the optimal use of sensor's energy, very little attention has been paid to the efficiency of energy usage at the gateway. Tasks need to be allocated to gateways in such a way that maximizes the life of these cluster-heads and eventually the whole network. In this paper, we present an optimization scheme for task allocation to gateways. The task allocation problem is modeled as a zero-one nonlinear program. Simulation results show that substantial energy savings can be obtained with the proposed method. Mohamed F. Younis, Kemal Akkaya, Anugeetha Kunjithapatham |
ISCC | 2 |