Hash and Physical Unclonable Function (PUF)-Based Mutual Authentication Mechanism

被引:0
|
作者
Bhatia, Kavita [1 ]
Pandey, Santosh K. [2 ]
Singh, Vivek K. [1 ]
Gupta, Deena Nath [3 ]
机构
[1] Banaras Hindu Univ, Dept Comp Sci, Varanasi 221005, India
[2] Govt India, Minist Elect & IT, New Delhi 110003, India
[3] Ctr Dev Adv Comp, Mumbai 400049, India
关键词
hash; PUF; broken authentication; mutual authentication; privacy-preserving protocol; RFID AUTHENTICATION; PRIVACY; PROTOCOL; SECURE; ECC;
D O I
10.3390/s23146307
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
The security of web applications in an enterprise is of paramount importance. To strengthen the security of applications, the identification and mitigation of vulnerabilities through appropriate countermeasures becomes imperative. The Open Web Application Security Project (OWASP) Top 10 API Security Risks, 2023 Edition, indicates the prominent vulnerabilities of API security risks. Broken authentication, however, is placed in second position with level-3 exploitability, level-2 prevalence, level-3 detectability, and level-3 technical impact. To mitigate this vulnerability, many mitigation strategies have been proposed by using the cryptographic primitives wherein two techniques, namely hashing and PUF, are used. Some of the proposals have integrated the concepts of hashing and PUF. However, the unnecessarily lengthy and complex mathematics used in these proposals makes them unsuitable for current API-based application scenarios. Therefore, in this paper, the authors propose a privacy-preserving authentication protocol that incorporates the capability of both mechanisms in an easy and low-complexity manner. In addition to overcoming existing limitations, the proposed protocol is tested to provide more security properties over existing schemes. Analysis of their performance has demonstrated that the proposed solutions are secure, efficient, practical, and effective for API-based web applications in an enterprise environment.
引用
收藏
页数:15
相关论文
共 50 条
  • [1] Mutual Authentication in Wireless Body Sensor Networks (WBSN) based on Physical Unclonable Function (PUF)
    Lee, Young Sil
    Lee, Hoon Jae
    Alasaarela, Esko
    2013 9TH INTERNATIONAL WIRELESS COMMUNICATIONS AND MOBILE COMPUTING CONFERENCE (IWCMC), 2013, : 1314 - 1318
  • [2] A Lightweight RFID Mutual Authentication Protocol Based on Physical Unclonable Function
    Xu, He
    Ding, Jie
    Li, Peng
    Zhu, Feng
    Wang, Ruchuan
    SENSORS, 2018, 18 (03)
  • [3] UDhashing: Physical Unclonable Function-Based User-Device Hash for Endpoint Authentication
    Zheng, Yue
    Cao, Yuan
    Chang, Chip-Hong
    IEEE TRANSACTIONS ON INDUSTRIAL ELECTRONICS, 2019, 66 (12) : 9559 - 9570
  • [4] A Lightweight Mutual Authentication Protocol Based on Physical Unclonable Functions
    Abdolinezhad, Saeed
    Sikora, Axel
    2022 IEEE INTERNATIONAL SYMPOSIUM ON HARDWARE ORIENTED SECURITY AND TRUST (HOST), 2022, : 161 - 164
  • [5] A location-aware physical unclonable function and Chebyshev map-based mutual authentication mechanism for internet of surveillance drones
    Nair, Aiswarya S.
    Thampi, Sabu M.
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2023, 35 (19):
  • [6] Lightweight Authentication Protocol Based on Physical Unclonable Function
    Luo, Hanguang
    Zou, Tao
    Wu, Chunming
    Li, Dan
    Li, Shunbin
    Chu, Chu
    CMC-COMPUTERS MATERIALS & CONTINUA, 2022, 72 (03): : 5031 - 5040
  • [7] Mobile RFID Mutual Authentication Protocol Based on Hash Function
    Yu, Wenjin
    Jiang, Yixiang
    2017 INTERNATIONAL CONFERENCE ON CYBER-ENABLED DISTRIBUTED COMPUTING AND KNOWLEDGE DISCOVERY (CYBERC), 2017, : 358 - 361
  • [8] IoT Device Security: Challenging "A Lightweight RFID Mutual Authentication Protocol Based on Physical Unclonable Function"
    Bendavid, Ygal
    Bagheri, Nasour
    Safkhani, Masoumeh
    Rostampour, Samad
    SENSORS, 2018, 18 (12)
  • [9] Lightweight and Anonymous Mutual Authentication Protocol for Edge IoT Nodes with Physical Unclonable Function
    Wang, Hongyuan
    Meng, Jin
    Du, Xilong
    Cao, Tengfei
    Xie, Yong
    SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [10] TCO-PUF: A Subthreshold Physical Unclonable Function
    Mispan, Mohd Syafiq
    Halak, Basel
    Chen, Zufu
    Zwolinski, Mark
    2015 11TH CONFERENCE ON PH.D. RESEARCH IN MICROELECTRONICS AND ELECTRONICS (PRIME), 2015, : 105 - 108