Hash and Physical Unclonable Function (PUF)-Based Mutual Authentication Mechanism

被引:0
|
作者
Bhatia, Kavita [1 ]
Pandey, Santosh K. [2 ]
Singh, Vivek K. [1 ]
Gupta, Deena Nath [3 ]
机构
[1] Banaras Hindu Univ, Dept Comp Sci, Varanasi 221005, India
[2] Govt India, Minist Elect & IT, New Delhi 110003, India
[3] Ctr Dev Adv Comp, Mumbai 400049, India
关键词
hash; PUF; broken authentication; mutual authentication; privacy-preserving protocol; RFID AUTHENTICATION; PRIVACY; PROTOCOL; SECURE; ECC;
D O I
10.3390/s23146307
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
The security of web applications in an enterprise is of paramount importance. To strengthen the security of applications, the identification and mitigation of vulnerabilities through appropriate countermeasures becomes imperative. The Open Web Application Security Project (OWASP) Top 10 API Security Risks, 2023 Edition, indicates the prominent vulnerabilities of API security risks. Broken authentication, however, is placed in second position with level-3 exploitability, level-2 prevalence, level-3 detectability, and level-3 technical impact. To mitigate this vulnerability, many mitigation strategies have been proposed by using the cryptographic primitives wherein two techniques, namely hashing and PUF, are used. Some of the proposals have integrated the concepts of hashing and PUF. However, the unnecessarily lengthy and complex mathematics used in these proposals makes them unsuitable for current API-based application scenarios. Therefore, in this paper, the authors propose a privacy-preserving authentication protocol that incorporates the capability of both mechanisms in an easy and low-complexity manner. In addition to overcoming existing limitations, the proposed protocol is tested to provide more security properties over existing schemes. Analysis of their performance has demonstrated that the proposed solutions are secure, efficient, practical, and effective for API-based web applications in an enterprise environment.
引用
收藏
页数:15
相关论文
共 50 条
  • [41] CMOS-MEMS TUNED-MASS-DAMPER BASED PHYSICAL UNCLONABLE FUNCTION (PUF)
    Chung, I-Fei
    Chen, Ting-Yi
    Liou, Ting-Jui
    Li, Wei-Chang
    2024 IEEE 37TH INTERNATIONAL CONFERENCE ON MICRO ELECTRO MECHANICAL SYSTEMS, MEMS, 2024, : 517 - 520
  • [42] Hash-based RFID Mutual Authentication Protocol
    Liu, Yang
    Peng, Yu
    Wang, Bailing
    Qu, Yun
    Bai, Xuefengi
    Yuan, Xinling
    Yin, Zelong
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2013, 7 (03): : 183 - 194
  • [43] An One-way Hash Function Based Lightweight Mutual Authentication RFID Protocol
    Ren, Xuping
    Xu, Xianghua
    Li, Yunfa
    JOURNAL OF COMPUTERS, 2013, 8 (09) : 2405 - 2412
  • [44] A PUF-based Lightweight and Secure Mutual Authentication Mechanism for Remote Keyless Entry Systems
    Parameswarath, Rohini Poolat
    Sikdar, Biplab
    2022 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM 2022), 2022, : 1776 - 1781
  • [45] A PUF-based Lightweight and Secure Mutual Authentication Mechanism for Remote Keyless Entry Systems
    Parameswarath, Rohini Poolat
    Sikdar, Biplab
    Proceedings - IEEE Global Communications Conference, GLOBECOM, 2022, : 1776 - 1781
  • [46] A PUF-based Mutual Authentication Protocol for Internet of Things
    Satamraju, Krishna Prasad
    Malarkodi, B.
    PROCEEDINGS OF THE 2020 5TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND SECURITY (ICCCS-2020), 2020,
  • [47] Application of Physical Unclonable Function for Lightweight Authentication in Internet of Things
    Aseeri, Ahmad O.
    Chauhdary, Sajjad Hussain
    Alkatheiri, Mohammed Saeed
    Alqarni, Mohammed A.
    Zhuang, Yu
    CMC-COMPUTERS MATERIALS & CONTINUA, 2023, 75 (01): : 1901 - 1918
  • [48] Physical Unclonable Functions (PUF) for IoT Devices
    Al-Meer, Abdulaziz
    Al-Kuwari, Saif
    ACM COMPUTING SURVEYS, 2023, 55 (14S)
  • [49] Proving authentication property of PUF-based mutual authentication protocol based on logic of events
    Song, Jiawen
    Xiao, Meihua
    Zhang, Tong
    Zhou, Haoyang
    SOFT COMPUTING, 2022, 26 (02) : 841 - 852
  • [50] A LIGHTWEIGHT RFID AUTHENTICATION PROTOCOL USING PHYSICAL UNCLONABLE FUNCTION
    Zhang Zi-nan
    Guo Yuan-bo
    Liu-Wei
    2011 INTERNATIONAL CONFERENCE ON INSTRUMENTATION, MEASUREMENT, CIRCUITS AND SYSTEMS (ICIMCS 2011), VOL 2: FUTURE COMMUNICATION AND NETWORKING, 2011, : 265 - 268