Hash and Physical Unclonable Function (PUF)-Based Mutual Authentication Mechanism

被引:0
|
作者
Bhatia, Kavita [1 ]
Pandey, Santosh K. [2 ]
Singh, Vivek K. [1 ]
Gupta, Deena Nath [3 ]
机构
[1] Banaras Hindu Univ, Dept Comp Sci, Varanasi 221005, India
[2] Govt India, Minist Elect & IT, New Delhi 110003, India
[3] Ctr Dev Adv Comp, Mumbai 400049, India
关键词
hash; PUF; broken authentication; mutual authentication; privacy-preserving protocol; RFID AUTHENTICATION; PRIVACY; PROTOCOL; SECURE; ECC;
D O I
10.3390/s23146307
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
The security of web applications in an enterprise is of paramount importance. To strengthen the security of applications, the identification and mitigation of vulnerabilities through appropriate countermeasures becomes imperative. The Open Web Application Security Project (OWASP) Top 10 API Security Risks, 2023 Edition, indicates the prominent vulnerabilities of API security risks. Broken authentication, however, is placed in second position with level-3 exploitability, level-2 prevalence, level-3 detectability, and level-3 technical impact. To mitigate this vulnerability, many mitigation strategies have been proposed by using the cryptographic primitives wherein two techniques, namely hashing and PUF, are used. Some of the proposals have integrated the concepts of hashing and PUF. However, the unnecessarily lengthy and complex mathematics used in these proposals makes them unsuitable for current API-based application scenarios. Therefore, in this paper, the authors propose a privacy-preserving authentication protocol that incorporates the capability of both mechanisms in an easy and low-complexity manner. In addition to overcoming existing limitations, the proposed protocol is tested to provide more security properties over existing schemes. Analysis of their performance has demonstrated that the proposed solutions are secure, efficient, practical, and effective for API-based web applications in an enterprise environment.
引用
收藏
页数:15
相关论文
共 50 条
  • [31] RFID mutual-authentication protocol with synchronous updatedkeys based on Hash function
    Zhang Xiaohong
    Hu Yingmeng
    The Journal of China Universities of Posts and Telecommunications, 2015, (06) : 27 - 35
  • [32] RFID mutual-authentication protocol with synchronous updatedkeys based on Hash function
    Zhang Xiaohong
    Hu Yingmeng
    The Journal of China Universities of Posts and Telecommunications, 2015, 22 (06) : 27 - 35
  • [33] A PUF-based hardware mutual authentication protocol
    Barbareschi, Mario
    De Benedictis, Alessandra
    Mazzocca, Nicola
    JOURNAL OF PARALLEL AND DISTRIBUTED COMPUTING, 2018, 119 : 107 - 120
  • [34] A Review-Hardware Security Using PUF (Physical Unclonable Function)
    Sakhare, Shruti
    Sakhare, Dipti
    ICCCE 2019: PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON COMMUNICATIONS AND CYBER-PHYSICAL ENGINEERING, 2020, 570 : 373 - 377
  • [35] TV-PUF : A Fast Lightweight Analog Physical Unclonable Function
    Saha, Tanujay
    Schwag, Vikash
    PROCEEDINGS OF 2016 IEEE INTERNATIONAL SYMPOSIUM ON NANOELECTRONIC AND INFORMATION SYSTEMS (INIS), 2016, : 182 - 186
  • [36] High-efficient RFID Authentication Protocol Based on Physical Unclonable Function
    He, ZhangQing
    Zou, Ling
    2012 INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND MOBILE COMPUTING (WICOM), 2012,
  • [37] A secure and efficient mutual authentication protocol using hash function
    Lin, Sida
    Xie, Qi
    2009 WRI INTERNATIONAL CONFERENCE ON COMMUNICATIONS AND MOBILE COMPUTING: CMC 2009, VOL 3, 2009, : 545 - +
  • [38] PSECAS: A physical unclonable function based secure authentication scheme for Internet of Drones
    Sharma, Muskan
    Narwal, Bhawna
    Anand, Revika
    Mohapatra, Amar Kumar
    Yadav, Richa
    COMPUTERS & ELECTRICAL ENGINEERING, 2023, 108
  • [39] Physical Unclonable Function Based Authentication Scheme for Smart Devices in Internet of Things
    Mughal, Muhammad Arif
    Luo, Xiong
    Mahmood, Zahid
    Ullah, Ata
    2018 IEEE INTERNATIONAL CONFERENCE ON SMART INTERNET OF THINGS (SMARTIOT 2018), 2018, : 160 - 165
  • [40] Physical Unclonable Function Based Authentication Protocol for Unit IoT and Ubiquitous IoT
    Zhao, Min
    Yao, Xuanxia
    Ning, Huansheng
    Liu, Hong
    2016 INTERNATIONAL CONFERENCE ON IDENTIFICATION, INFORMATION AND KNOWLEDGE IN THE INTERNET OF THINGS (IIKI), 2016, : 179 - 184