A novel lightweight multi-factor authentication scheme for MQTT-based IoT applications

被引:0
|
作者
Saqib, Manasha [1 ]
Moon, Ayaz Hassan [2 ]
机构
[1] Islamic Univ Sci & Technol, Sch Engn & Technol, Awantipora 192122, J&K, India
[2] Islamic Univ Sci & Technol, Awantipora 192122, J&K, India
关键词
Internet of Things; Machine-to-machine communication; mutual authentication; Elliptical curve cryptography; Message queue telemetry transport; PROVABLY SECURE; KEY EXCHANGE; INTERNET; THINGS; EFFICIENT; PROTOCOL; COMMUNICATION; MANAGEMENT; DESIGN;
D O I
10.1016/j.micpro.2024.105088
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The present authentication solutions employed in the Internet of Things (IoT) are either inadequate or computationally intensive, given the resource-constrained nature of IoT devices. This challenges the researchers to devise efficient solutions to embed an important security tenet like authentication. In IoT, the most popular machine-to-machine communication protocol used at the application layer is Message Queuing Telemetry Transport (MQTT). However, the MQTT protocol inherently lacks security-related functions, like authentication, authorization, confidentiality, access control, and data integrity, which is unacceptable for IoT-driven mission-critical applications when connected over public networks. In such a situation, the security is hardened by employing a transport layer security protocol like TLS, which entails significant computational overheads. This paper presents a novel scheme to enhance MQTT security by providing a lightweight multi-factor authentication scheme based on Elliptical curve cryptography. The proposed scheme uses a low-cost signature and a fuzzy extractor to correct errors in imprinted biometrics in noisy environments. This scheme attains mutual authentication, generates a securely agreed-upon session key for secret communication, and guarantees perfect forward secrecy. Furthermore, the rigorous informal security analysis shows the proposed scheme resists cryptographic attacks, including known session critical attacks. Furthermore, an empirical study has been carried out to assess the effectiveness of the proposed scheme in the Cooja simulated environment.
引用
收藏
页数:20
相关论文
共 50 条
  • [1] Advanced lightweight multi-factor remote user authentication scheme for cloud-IoT applications
    Geeta Sharma
    Sheetal Kalra
    [J]. Journal of Ambient Intelligence and Humanized Computing, 2020, 11 : 1771 - 1794
  • [2] Advanced lightweight multi-factor remote user authentication scheme for cloud-IoT applications
    Sharma, Geeta
    Kalra, Sheetal
    [J]. JOURNAL OF AMBIENT INTELLIGENCE AND HUMANIZED COMPUTING, 2020, 11 (04) : 1771 - 1794
  • [3] A lightweight multi-factor secure smart card based remote user authentication scheme for cloud-IoT applications
    Sharma, Geeta
    Kalra, Sheetal
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2018, 42 : 95 - 106
  • [4] A lightweight multi-factor mobile user authentication scheme
    Sun, Jianguo
    Zhong, Qi
    Kou, Liang
    Wang, Wenshan
    Da, Qingan
    Lin, Yun
    [J]. IEEE INFOCOM 2018 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (INFOCOM WKSHPS), 2018, : 831 - 836
  • [5] Lightweight and Secure Multi-Factor Authentication Scheme in VANETs
    Tahir, Haseeb
    Mahmood, Khalid
    Ayub, Muhammad Faizan
    Saleem, Muhammad Asad
    Ferzund, Javed
    Kumar, Neeraj
    [J]. IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2023, 72 (11) : 14978 - 14986
  • [6] A Lightweight Multi-factor Authentication Scheme based on Digital Watermarking Technique
    Trong-Minh Hoang
    Van-Hau Bui
    Ngoc-Tan Nguyen
    [J]. 2021 INTERNATIONAL CONFERENCE ON ADVANCED TECHNOLOGIES FOR COMMUNICATIONS (ATC 2021), 2021, : 270 - 274
  • [7] Lightweight multi-factor mutual authentication protocol for IoT devices
    Melki, Reem
    Noura, Hassan N.
    Chehab, Ali
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2020, 19 (06) : 679 - 694
  • [8] Lightweight multi-factor mutual authentication protocol for IoT devices
    Reem Melki
    Hassan N. Noura
    Ali Chehab
    [J]. International Journal of Information Security, 2020, 19 : 679 - 694
  • [9] Security risks in MQTT-based Industrial IoT Applications
    Boppana, Tej Kiran
    Bagade, Priyanka
    [J]. 2022 IEEE INTERNATIONAL CONFERENCE ON OMNI-LAYER INTELLIGENT SYSTEMS (IEEE COINS 2022), 2022, : 348 - 352
  • [10] A Secure Multi-factor Remote User Authentication Scheme for Cloud-IoT Applications
    Lee, JoonYoung
    Kim, MyeongHyun
    Yu, SungJin
    Park, KiSung
    Park, YoungHo
    [J]. 2019 28TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATION AND NETWORKS (ICCCN), 2019,