Hash and Physical Unclonable Function (PUF)-Based Mutual Authentication Mechanism

被引:0
|
作者
Bhatia, Kavita [1 ]
Pandey, Santosh K. [2 ]
Singh, Vivek K. [1 ]
Gupta, Deena Nath [3 ]
机构
[1] Banaras Hindu Univ, Dept Comp Sci, Varanasi 221005, India
[2] Govt India, Minist Elect & IT, New Delhi 110003, India
[3] Ctr Dev Adv Comp, Mumbai 400049, India
关键词
hash; PUF; broken authentication; mutual authentication; privacy-preserving protocol; RFID AUTHENTICATION; PRIVACY; PROTOCOL; SECURE; ECC;
D O I
10.3390/s23146307
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
The security of web applications in an enterprise is of paramount importance. To strengthen the security of applications, the identification and mitigation of vulnerabilities through appropriate countermeasures becomes imperative. The Open Web Application Security Project (OWASP) Top 10 API Security Risks, 2023 Edition, indicates the prominent vulnerabilities of API security risks. Broken authentication, however, is placed in second position with level-3 exploitability, level-2 prevalence, level-3 detectability, and level-3 technical impact. To mitigate this vulnerability, many mitigation strategies have been proposed by using the cryptographic primitives wherein two techniques, namely hashing and PUF, are used. Some of the proposals have integrated the concepts of hashing and PUF. However, the unnecessarily lengthy and complex mathematics used in these proposals makes them unsuitable for current API-based application scenarios. Therefore, in this paper, the authors propose a privacy-preserving authentication protocol that incorporates the capability of both mechanisms in an easy and low-complexity manner. In addition to overcoming existing limitations, the proposed protocol is tested to provide more security properties over existing schemes. Analysis of their performance has demonstrated that the proposed solutions are secure, efficient, practical, and effective for API-based web applications in an enterprise environment.
引用
收藏
页数:15
相关论文
共 50 条
  • [11] Low latency synchronous design in SRAM based physical unclonable function (PUF)
    Radhika, R.
    Madhavi, B. K.
    INTERNATIONAL JOURNAL OF EARLY CHILDHOOD SPECIAL EDUCATION, 2022, 14 (04) : 1236 - 1248
  • [12] Neuron-PUF: Physical Unclonable Function Based on a Single Spiking Neuron
    Elshamy, Mohamed
    Stratigopoulos, Haralampos-G
    2021 IEEE 27TH INTERNATIONAL SYMPOSIUM ON ON-LINE TESTING AND ROBUST SYSTEM DESIGN (IOLTS), 2021,
  • [13] Physical Unclonable Function (PUF)-Based e-Cash Transaction Protocol (PUF-Cash)
    Calhoun, Jeff
    Minwalla, Cyrus
    Helmich, Charles
    Saqib, Fareena
    Che, Wenjie
    Plusquellic, Jim
    CRYPTOGRAPHY, 2019, 3 (03) : 1 - 24
  • [14] ProHys PUF: A Proteresis- Hysteresis switch based Physical Unclonable Function
    Khan, Salma
    Azeemuddin, Syed
    Sohel, Mohammed Arifuddin
    INTEGRATION-THE VLSI JOURNAL, 2023, 89 : 207 - 216
  • [15] A survey on physical unclonable function (PUF)-based security solutions for Internet of Things
    Shamsoshoara, Alireza
    Korenda, Ashwija
    Afghah, Fatemeh
    Zeadally, Sherali
    COMPUTER NETWORKS, 2020, 183
  • [16] PMAKE: Physical Unclonable Function-based Mutual Authentication Key Exchange Scheme for Digital Aeronautical Communications
    Maeurer, Nils
    Graeupl, Thomas
    Schmitt, Corinna
    Rodosek, Gabi Dreo
    2021 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM 2021), 2021, : 206 - 214
  • [17] Design and Optimization of Strong Physical Unclonable Function (PUF) Based on RRAM Array
    Pang, Yachuan
    Wu, Huaqiang
    Gao, Bin
    Liu, Rui
    Wang, Shan
    Yu, Shimeng
    Chen, An
    Qian, He
    2017 INTERNATIONAL SYMPOSIUM ON VLSI TECHNOLOGY, SYSTEMS AND APPLICATION (VLSI-TSA), 2017,
  • [18] Evaluation and Optimization of Physical Unclonable Function (PUF) based on the Variability of FinFET SRAM
    Zhang, Shen
    Gao, Bin
    Wu, Dong
    Wu, Huaqiang
    Qian, He
    2017 INTERNATIONAL CONFERENCE ON ELECTRON DEVICES AND SOLID-STATE CIRCUITS (EDSSC), 2017,
  • [19] Mutual Authentication in IoT Systems Using Physical Unclonable Functions
    Aman, Muhammad Naveed
    Chua, Kee Chaing
    Sikdar, Biplab
    IEEE INTERNET OF THINGS JOURNAL, 2017, 4 (05): : 1327 - 1340
  • [20] PHYSICAL UNCLONABLE FUNCTION FOR LOW COST AUTHENTICATION
    Archana, P.
    Kumar, S. Vijaya
    Venkatalakshmi, B.
    PROCEEDINGS OF THE 2016 IEEE INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, SIGNAL PROCESSING AND NETWORKING (WISPNET), 2016, : 1098 - 1101