The Experts below are selected from a list of 69978 Experts worldwide ranked by ideXlab platform
Kimkwang Raymond Choo - One of the best experts on this subject based on the ideXlab platform.
-
on the design of mutual authentication and key agreement protocol in internet of vehicles enabled intelligent transportation system
IEEE Transactions on Vehicular Technology, 2021Co-Authors: Palak Bagga, Kimkwang Raymond Choo, Ashok Kumar Das, Mohammad Wazid, Joel J P C Rodrigues, Youngho ParkAbstract:internet of Vehicles (IoV), a distributed network involving connected vehicles and Vehicular Ad Hoc Networks (VANETs), allows connected vehicles to communicate with other internet-connected entities in real time. The communications among these entities (e.g. vehicles, pedestrians, fleet management systems, and road-side infrastructure) generally take place via an open channel. in other words, such an open communication can be targeted by the adversary to eavesdrop, modify, insert fabricated (or malicious) messages, or delete any Data-in-Transit; thus, resulting in replay, impersonation, man-in-the-middle, privileged-insider, and other related attacks. in addition to security, anonymity and untraceability are two other important features that should be achieved in an authentication protocol. in this paper, we propose a new mutual authentication and key agreement protocol in an IoV-enabled intelligent Transportation System (ITS). Using both formal and informal security analysis, as well as formal security verification using an automated verification tool, we show that the proposed scheme is secure against several known attacks in an IoV-enabled ITS environment. Furthermore, a detailed comparative analysis shows that the proposed scheme has low communication and computational overheads, and offers better security and functionality attributes in comparison to seven other competing schemes. We also evaluate the performance of the proposed scheme using NS2.
-
secure and efficient two party signing protocol for the identity based signature scheme in the ieee p1363 standard for public key cryptography
IEEE Transactions on Dependable and Secure Computing, 2020Co-Authors: Yudi Zhang, Ding Wang, Kimkwang Raymond ChooAbstract:Mobile device and application (app) security are increasingly important, partly due to the constant and fast-paced cyberthreat evolution. To ensure the security of communication (e.g., Data-in-Transit), a number of identity-based signature schemes have been designed to facilitate authorization identification and validation of messages. However, in many of these schemes, a user's private key may leak when a new signature is generated since the private keys are stored on the device. Seeking to improve the security of the private key, we propose the first two-party distributed signing protocol for the identity-based signature scheme in the IEEE P1363 standard. This protocol requires that two devices separately store one part of the user's private key, and allows these two devices to generate a valid signature without revealing the entire private key of the user. We formally prove that the security of the protocol in the random oracle model. Then, we implement the protocol using the MIRACL library and evaluate the protocol on two mobile devices. Compared with the protocol of Lindell (CRYPTO'17) that uses the zero-knowledge proof for its security, our protocol is more suitable for deployment in the mobile environment.
-
a provably secure and lightweight identity based two party authenticated key agreement protocol for vehicular ad hoc networks
Security and Communication Networks, 2019Co-Authors: Chingfang Hsu, Kimkwang Raymond ChooAbstract:As an important part of smart cities, vehicle ad hoc networks (VANETs) have attracted much attention from both industry and academia. in a VANET, generating a secure session key to facilitate subsequent Data-in-Transit transfer between two or more vehicles is crucial, which can be achieved by using an authenticated key agreement protocol. However, most of the existing identity-based two-party authenticated key agreement protocols have significant computational requirements or are known to be insecure. Thus, in this paper, a secure and efficient identity-based two-party authenticated key agreement protocol is presented by us. This protocol does not involve complex bilinear pairing computations and can generate a valid session key in two rounds. The security of the proposed protocol is proved in the eCK model which has better capability to describe a protocol’s security than the famous CK model, and it has been widely used in the security proof of ID-based key agreement protocols currently. Additionally, we also evaluate its performance for potential utility in a VANET.
-
a provably secure and lightweight anonymous user authenticated session key exchange scheme for internet of things deployment
IEEE Internet of Things Journal, 2019Co-Authors: Soumya Banerjee, Ashok Kumar Das, Vanga Odelu, Jangirala Srinivas, Neeraj Kumar, Samiran Chattopadhyay, Kimkwang Raymond ChooAbstract:With the ever increasing adoption rate of internet-enabled devices [also known as internet of Things (IoT) devices] in applications such as smart home, smart city, smart grid, and healthcare applications, we need to ensure the security and privacy of Data and communications among these IoT devices and the underlying infrastructure. For example, an adversary can easily tamper with the information transmitted over a public channel, in the sense of modification, deletion, and fabrication of Data-in-Transit and Data-in-storage. Time-critical IoT applications such as healthcare may demand the capability to support external parties (users) to securely access IoT Data and services in real-time. This necessitates the design of a secure user authentication mechanism, which should also allow the user to achieve security and functionality features such as anonymity and un-traceability. in this paper, we propose a new lightweight anonymous user authenticated session key agreement scheme in the IoT environment. The proposed scheme uses three-factor authentication, namely a user’s smart card, password, and personal biometric information. The proposed scheme does not require the storing of user specific information at the gateway node. We then demonstrate the proposed scheme’s security using the broadly accepted real-or-random (ROR) model, Burrows–Abadi–Needham (BAN) logic, and automated validation of internet security protocols and applications (AVISPAs) software simulation tool, as well as presenting an informal security analysis to demonstrate its other features. in addition, through our simulations, we demonstrate that the proposed scheme outperforms existing related user authentication schemes, in terms of its security and functionality features, and computation costs.
-
privacy preserving content oriented wireless communication in internet of things
IEEE Internet of Things Journal, 2018Co-Authors: Keke Gai, Kimkwang Raymond Choo, Meikang Qiu, Liehuang ZhuAbstract:With mobile devices (e.g., Android and iOS devices) and other resource constrained internet-connected devices (e.g., sensors) becoming the norm in our digitalized society, the capacity to ensure security of Data-in-Transit and at-rest without incurring unrealistic performance overheads is crucial. Rather than using conventional encryption, in this paper we propose the dynamic privacy protection model. The model is designed for ensuring mobile device user privacy even in large volume of Data transmissions, which uses dynamic programming to produce an optimal solution of maximizing privacy protection levels even for resource constrained devices. We then develop an Android app and use it to evaluate the effectiveness of the model. The findings suggest that the proposed model allows us to achieve improved privacy protection.
Ashok Kumar Das - One of the best experts on this subject based on the ideXlab platform.
-
on the design of mutual authentication and key agreement protocol in internet of vehicles enabled intelligent transportation system
IEEE Transactions on Vehicular Technology, 2021Co-Authors: Palak Bagga, Kimkwang Raymond Choo, Ashok Kumar Das, Mohammad Wazid, Joel J P C Rodrigues, Youngho ParkAbstract:internet of Vehicles (IoV), a distributed network involving connected vehicles and Vehicular Ad Hoc Networks (VANETs), allows connected vehicles to communicate with other internet-connected entities in real time. The communications among these entities (e.g. vehicles, pedestrians, fleet management systems, and road-side infrastructure) generally take place via an open channel. in other words, such an open communication can be targeted by the adversary to eavesdrop, modify, insert fabricated (or malicious) messages, or delete any Data-in-Transit; thus, resulting in replay, impersonation, man-in-the-middle, privileged-insider, and other related attacks. in addition to security, anonymity and untraceability are two other important features that should be achieved in an authentication protocol. in this paper, we propose a new mutual authentication and key agreement protocol in an IoV-enabled intelligent Transportation System (ITS). Using both formal and informal security analysis, as well as formal security verification using an automated verification tool, we show that the proposed scheme is secure against several known attacks in an IoV-enabled ITS environment. Furthermore, a detailed comparative analysis shows that the proposed scheme has low communication and computational overheads, and offers better security and functionality attributes in comparison to seven other competing schemes. We also evaluate the performance of the proposed scheme using NS2.
-
a provably secure and lightweight anonymous user authenticated session key exchange scheme for internet of things deployment
IEEE Internet of Things Journal, 2019Co-Authors: Soumya Banerjee, Ashok Kumar Das, Vanga Odelu, Jangirala Srinivas, Neeraj Kumar, Samiran Chattopadhyay, Kimkwang Raymond ChooAbstract:With the ever increasing adoption rate of internet-enabled devices [also known as internet of Things (IoT) devices] in applications such as smart home, smart city, smart grid, and healthcare applications, we need to ensure the security and privacy of Data and communications among these IoT devices and the underlying infrastructure. For example, an adversary can easily tamper with the information transmitted over a public channel, in the sense of modification, deletion, and fabrication of Data-in-Transit and Data-in-storage. Time-critical IoT applications such as healthcare may demand the capability to support external parties (users) to securely access IoT Data and services in real-time. This necessitates the design of a secure user authentication mechanism, which should also allow the user to achieve security and functionality features such as anonymity and un-traceability. in this paper, we propose a new lightweight anonymous user authenticated session key agreement scheme in the IoT environment. The proposed scheme uses three-factor authentication, namely a user’s smart card, password, and personal biometric information. The proposed scheme does not require the storing of user specific information at the gateway node. We then demonstrate the proposed scheme’s security using the broadly accepted real-or-random (ROR) model, Burrows–Abadi–Needham (BAN) logic, and automated validation of internet security protocols and applications (AVISPAs) software simulation tool, as well as presenting an informal security analysis to demonstrate its other features. in addition, through our simulations, we demonstrate that the proposed scheme outperforms existing related user authentication schemes, in terms of its security and functionality features, and computation costs.
Youngho Park - One of the best experts on this subject based on the ideXlab platform.
-
on the design of mutual authentication and key agreement protocol in internet of vehicles enabled intelligent transportation system
IEEE Transactions on Vehicular Technology, 2021Co-Authors: Palak Bagga, Kimkwang Raymond Choo, Ashok Kumar Das, Mohammad Wazid, Joel J P C Rodrigues, Youngho ParkAbstract:internet of Vehicles (IoV), a distributed network involving connected vehicles and Vehicular Ad Hoc Networks (VANETs), allows connected vehicles to communicate with other internet-connected entities in real time. The communications among these entities (e.g. vehicles, pedestrians, fleet management systems, and road-side infrastructure) generally take place via an open channel. in other words, such an open communication can be targeted by the adversary to eavesdrop, modify, insert fabricated (or malicious) messages, or delete any Data-in-Transit; thus, resulting in replay, impersonation, man-in-the-middle, privileged-insider, and other related attacks. in addition to security, anonymity and untraceability are two other important features that should be achieved in an authentication protocol. in this paper, we propose a new mutual authentication and key agreement protocol in an IoV-enabled intelligent Transportation System (ITS). Using both formal and informal security analysis, as well as formal security verification using an automated verification tool, we show that the proposed scheme is secure against several known attacks in an IoV-enabled ITS environment. Furthermore, a detailed comparative analysis shows that the proposed scheme has low communication and computational overheads, and offers better security and functionality attributes in comparison to seven other competing schemes. We also evaluate the performance of the proposed scheme using NS2.
Utz Roedig - One of the best experts on this subject based on the ideXlab platform.
-
Securing communication in 6LoWPAN with compressed IPsec
2011 International Conference on Distributed Computing in Sensor Systems and Workshops (DCOSS), 2011Co-Authors: Shahid Raza, Tony Chung, Dogan Yazar, Simon Duquennoy, Thiemo Voigt, Utz RoedigAbstract:Real-world deployments of wireless sensor networks (WSNs) require secure communication. It is important that a receiver is able to verify that sensor Data was generated by trusted nodes. It may also be necessary to encrypt sensor Data in Transit. Recently, WSNs and traditional IP networks are more tightly integrated using IPv6 and 6LoWPAN. Available IPv6 protocol stacks can use IPsec to secure Data exchange. Thus, it is desirable to extend 6LoWPAN such that IPsec communication with IPv6 nodes is possible. It is beneficial to use IPsec because the existing end-points on the internet do not need to be modified to communicate securely with the WSN. Moreover, using IPsec, true end-to-end security is implemented and the need for a trustworthy gateway is removed. in this paper we provide End-to-End (E2E) secure communication between IP enabled sensor networks and the traditional internet. This is the first compressed lightweight design, implementation, and evaluation of 6LoWPAN extension for IPsec. Our extension supports both IPsec's Authentication Header (AH) and Encapsulation Security Payload (ESP). Thus, communication endpoints are able to authenticate, encrypt and check the integrity of messages using standardized and established IPv6 mechanisms.
-
Securing internet of Things with Lightweight IPsec
Security, 2010Co-Authors: Shahid Raza, Tony Chung, Dogan Yazar, Simon Duquennoy, Utz RoedigAbstract:Real-world deployments of wireless sensor networks (WSNs) require secure communication. It is important that a receiver is able to verify that sensor Data was generated by trusted nodes. in some cases it may also be necessary to encrypt sensor Data in Transit. Recently, WSNs and traditional IP networks are more tightly integrated using IPv6 and 6LoWPAN. Available IPv6 protocol stacks can use IPsec to secure Data exchange. Thus, it is desirable to extend 6LoWPAN such that IPsec communication with IPv6 nodes is possible. It is beneficial to use IPsec because the existing end-points on the internet do not need to be modified to communicate securely with the WSN. Moreover, using IPsec, true end-to-end security is implemented and the need for a trustworthy gateway is removed. in this paper we provide End-to-End (E2E) secure communication between an IP enabled sensor nodes and a device on traditional internet. This is the first compressed lightweight design, implementation, and evaluation of 6LoW- PAN extension for IPsec on Contiki. Our extension supports both IPsecs Au- thentication Header (AH) and Encapsulation Security Payload (ESP). Thus, communication endpoints are able to authenticate, encrypt and check the in- tegrity of messages using standardized and established IPv6 mechanisms
Roedig Utz - One of the best experts on this subject based on the ideXlab platform.
-
Securing Communication in 6LoWPAN with Compressed IPsec
Computer Systems Laboratory, 2011Co-Authors: Raza Shahid, Duquennoy Simon, Chung Tony, Yazar Dogan, Voigt Thiemo, Roedig UtzAbstract:Real-world deployments of wireless sensor networks (WSNs) require secure communication. It is important that a receiver is able to verify that sensor Data was generated by trusted nodes. It may also be necessary to encrypt sensor Data in Transit. Recently, WSNs and traditional IP networks are more tightly integrated using IPv6 and 6LoWPAN. Available IPv6 protocol stacks can use IPsec to secure Data exchange. Thus, it is desirable to extend 6LoWPAN such that IPsec communication with IPv6 nodes is possible. It is beneficial to use IPsec because the existing end-points on the internet do not need to be modified to communicate securely with the WSN. Moreover, using IPsec, true end-to-end security is implemented and the need for a trustworthy gateway is removed. in this paper we provide End-to-End (E2E) secure communication between IP enabled sensor networks and the traditional internet. This is the first compressed lightweight design, implementation, and evaluation of 6LoWPAN extension for IPsec. Our extension supports both IPsec’s Authentication Header (AH) and Encapsulation Security Payload (ESP). Thus, communication endpoints are able to authenticate, encrypt and check the integrity of messages using standardized and established IPv6 mechanisms.CONE
-
Securing internet of Things with Lightweight IPsec
Kista Sweden : Swedish Institute of Computer Science, 2010Co-Authors: Raza Shahid, Duquennoy Simon, Chung Tony, Yazar Dogan, Voigt Thiemo, Roedig UtzAbstract:Real-world deployments of wireless sensor networks (WSNs) require secure communication. It is important that a receiver is able to verify that sensor Data was generated by trusted nodes. in some cases it may also be necessary to encrypt sensor Data in Transit. Recently, WSNs and traditional IP networks are more tightly integrated using IPv6 and 6LoWPAN. Available IPv6 protocol stacks can use IPsec to secure Data exchange. Thus, it is desirable to extend 6LoWPAN such that IPsec communication with IPv6 nodes is possible. It is beneficial to use IPsec because the existing end-points on the internet do not need to be modified to communicate securely with the WSN. Moreover, using IPsec, true end-to-end security is implemented and the need for a trustworthy gateway is removed. in this paper we provide End-to-End (E2E) secure communication between an IP enabled sensor nodes and a device on traditional internet. This is the first compressed lightweight design, implementation, and evaluation of 6LoWPAN extension for IPsec on Contiki. Our extension supports both IPsec's Authentication Header (AH) and Encapsulation Security Payload (ESP). Thus, communication endpoints are able to authenticate, encrypt and check the integrity of messages using standardized and established IPv6 mechanisms.CONE