Work place: Department of Future Technology, Korea University of Technology and Education (KOREATECH), Cheonan 31253, South Korea
E-mail: bhwpuma@naver.com
Website: https://orcid.org/0000-0002-3363-390X
Research Interests:
Biography
Haewon Byeon received his academic training in interdisciplinary data science, artificial intelligence, and digital health research. He is affiliated with the Department of Future Technology, Korea University of Technology and Education, Cheonan, South Korea. His research interests include medical big data, explainable artificial intelligence, cybersecurity protocol analysis, smart-grid security, and secure data-driven systems.
By Haewon Byeon
DOI: https://doi.org/10.5815/ijem.2026.05.08, Pub. Date: 8 Oct. 2026
Industrial robotic controllers require identity assurance and command-level integrity within bounded control intervals. This study redesigns a fog-assisted three-factor scheme as IIoT-RoboAuth, a PUF-rooted protocol in which the session key is derived from the three participant nonces, an ephemeral P-256 secret, the policy epoch, and the current RPUF epoch; each command is then authenticated over its canonical payload, sequence, timestamp, role scope, and safety-profile hash. The protocol uses four handshake messages (two end-to-end round trips), 483 application-layer bytes, and a 224-byte command envelope. Evaluation used a Python 3.12 message-driven simulator rather than robot hardware or NS-3. Thirty fixed seeds generated 1,000 sessions and 1,000 trials for each of four attack classes per seed. The modeled mean authentication latency was 7.903 ms (95% CI, 7.896-7.909 ms), compared with 22.735 ms (95% CI, 22.698-22.773 ms) for the centralized baseline under the stated delay assumptions. The complete validator rejected 30,000 of 30,000 command modifications, replays, stale commands, and out-of-range commands in each class; removing the command MAC, sequence chain, 5-ms freshness check, or kinematic check caused the corresponding attack class to pass. The result establishes reproducible protocol-level command binding and an explicit deployment boundary; hardware timing, PUF reliability, physical tamper resistance, and safety certification remain outside the evidence provided here.
[...] Read more.By Haewon Byeon
DOI: https://doi.org/10.5815/ijieeb.2026.04.10, Pub. Date: 8 Aug. 2026
Advanced Metering Infrastructure (AMI) connects smart meters, data concentrator units, and utility control centers through persistent two-way communication. This architecture improves demand response and distributed-energy management, but it also exposes resource-constrained meters to replay, false-data injection, physical extraction, and long-term key compromise. This article develops a formally verified and statistically evaluated lightweight AMI authentication and key agreement protocol for resource-constrained smart-grid deployments. We first reconstruct the AMI authentication workflow as a four-message lightweight authenticated key exchange and map each entity, message, and key dependency to a smart-grid deployment model guided by NISTIR 7628 and IEC 62351. We then identify replay-within-window exposure, insufficient responder freshness, weak identity-to-key binding, missing key-compromise impersonation protection, and retrospective session-key recovery. To address these weaknesses, we propose AMI-AKE, a transcript-bound protocol using ephemeral Curve25519 contributions, session identifiers, nonce and timestamp binding, binding signatures, and separate key-derivation function (KDF) outputs for encryption and integrity. ProVerif-style verification queries and an extended Canetti-Krawczyk (eCK)-oriented game proof are provided for mutual authentication, secrecy, forward secrecy, and key-compromise impersonation (KCI) resistance. A Contiki-OS and ARM Cortex-M4 benchmark with 1,000 repeated trials reports 18.4 ± 1.2 ms authentication latency, 542 ± 9.1 sessions/s throughput, and 99.2 ± 0.4% false-data-injection detection under controlled prototype conditions. The proposed design replaces subjective security labels with objective metrics, confidence intervals, and a reproducible simulation plan for 1,000-10,000 smart meters.
[...] Read more.Subscribe to receive issue release notifications and newsletters from MECS Press journals