A novel lightweight multi-factor authentication scheme for MQTT-based IoT applications

被引:0
|
作者
Saqib, Manasha [1 ]
Moon, Ayaz Hassan [2 ]
机构
[1] Islamic Univ Sci & Technol, Sch Engn & Technol, Awantipora 192122, J&K, India
[2] Islamic Univ Sci & Technol, Awantipora 192122, J&K, India
关键词
Internet of Things; Machine-to-machine communication; mutual authentication; Elliptical curve cryptography; Message queue telemetry transport; PROVABLY SECURE; KEY EXCHANGE; INTERNET; THINGS; EFFICIENT; PROTOCOL; COMMUNICATION; MANAGEMENT; DESIGN;
D O I
10.1016/j.micpro.2024.105088
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The present authentication solutions employed in the Internet of Things (IoT) are either inadequate or computationally intensive, given the resource-constrained nature of IoT devices. This challenges the researchers to devise efficient solutions to embed an important security tenet like authentication. In IoT, the most popular machine-to-machine communication protocol used at the application layer is Message Queuing Telemetry Transport (MQTT). However, the MQTT protocol inherently lacks security-related functions, like authentication, authorization, confidentiality, access control, and data integrity, which is unacceptable for IoT-driven mission-critical applications when connected over public networks. In such a situation, the security is hardened by employing a transport layer security protocol like TLS, which entails significant computational overheads. This paper presents a novel scheme to enhance MQTT security by providing a lightweight multi-factor authentication scheme based on Elliptical curve cryptography. The proposed scheme uses a low-cost signature and a fuzzy extractor to correct errors in imprinted biometrics in noisy environments. This scheme attains mutual authentication, generates a securely agreed-upon session key for secret communication, and guarantees perfect forward secrecy. Furthermore, the rigorous informal security analysis shows the proposed scheme resists cryptographic attacks, including known session critical attacks. Furthermore, an empirical study has been carried out to assess the effectiveness of the proposed scheme in the Cooja simulated environment.
引用
收藏
页数:20
相关论文
共 50 条
  • [21] An efficient multi-factor authentication scheme based CNNs for securing ATMs over cognitive-IoT
    Shalaby, Ahmed
    Gad, Ramadan
    Hemdan, Ezz El-Din
    El-Fishawy, Nawal
    [J]. PEERJ COMPUTER SCIENCE, 2021, 7 : 1 - 28
  • [22] MFSPV: A Multi-Factor Secured and Lightweight Privacy-Preserving Authentication Scheme for VANETs
    Alfadhli, Saad Ali
    Lu, Songfeng
    Chen, Kai
    Sebai, Meriem
    [J]. IEEE ACCESS, 2020, 8 : 142858 - 142874
  • [23] A Lightweight Authentication and Privacy Preservation Scheme for MQTT
    Tian, Sijia
    Vassilakis, Vassilios G.
    [J]. 38TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, SAC 2023, 2023, : 1289 - 1292
  • [24] Lightweight Authentication for MQTT to improve the Security of IoT Communication
    Bali, Ranbir Singh
    Jaafar, Fehmi
    Zavarasky, Pavol
    [J]. PROCEEDINGS OF 2019 THE 3RD INTERNATIONAL CONFERENCE ON CRYPTOGRAPHY, SECURITY AND PRIVACY (ICCSP 2019) WITH WORKSHOP 2019 THE 4TH INTERNATIONAL CONFERENCE ON MULTIMEDIA AND IMAGE PROCESSING (ICMIP 2019), 2019, : 6 - 12
  • [25] A lightweight three factor authentication framework for IoT based critical applications
    Saqib, Manasha
    Jasra, Bhat
    Moon, Ayaz Hassan
    [J]. JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2022, 34 (09) : 6925 - 6937
  • [26] Cryptanalysis of a Multi-factor Biometric-Based Remote Authentication Scheme
    Boonkrong, Sirapat
    [J]. RECENT ADVANCES IN INFORMATION AND COMMUNICATION TECHNOLOGY 2018, 2019, 769 : 232 - 242
  • [27] A location-based multi-factor authentication scheme for mobile devices
    Meher, Bimal Kumar
    Amin, Ruhul
    [J]. INTERNATIONAL JOURNAL OF AD HOC AND UBIQUITOUS COMPUTING, 2022, 41 (03) : 181 - 190
  • [28] A Higher Performance Data Backup Scheme Based on Multi-Factor Authentication
    Wu, Lingfeng
    Wen, Yunhua
    Yi, Jinghai
    [J]. ENTROPY, 2024, 26 (08)
  • [29] A Lightweight and Secure Authentication Scheme for IoT Based E-Health Applications
    Almulhim, Maria
    Islam, Nazurl
    Zaman, Noor
    [J]. INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2019, 19 (01): : 107 - 120
  • [30] Biometric multi-factor authentication: On the usability of the FingerPIN scheme
    Marasco, Emanuela
    Albanese, Massimiliano
    Patibandla, Venkata Vamsi Ram
    Vurity, Anudeep
    Sriram, Sumanth Sai
    [J]. SECURITY AND PRIVACY, 2023, 6 (01):