An improved lightweight anonymous user authenticated session key exchange scheme for Internet of Things

被引:9
|
作者
Kumar, Devender [1 ]
Jain, Siddharth [2 ]
Khan, Aasif [2 ]
Pathak, Pranav Sarv [2 ]
机构
[1] NSUT, Dept Informat Technol, New Delhi, India
[2] NSIT, Div Informat Technol, New Delhi, India
关键词
Internet of Things; User authentication; Session key agreement; Security; Smart card loss attack; Stolen verifier attack; AGREEMENT SCHEME; MUTUAL AUTHENTICATION; PROVABLY SECURE; 3-FACTOR AUTHENTICATION; ACCESS-CONTROL; PROTOCOL; PRIVACY; DEVICES;
D O I
10.1007/s12652-020-02532-8
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Due to the myriad applications of the Internet of Things (IoT) in various sectors like healthcare, military, industry, safety, etc., there is also a need to secure these systems efficiently. The devices in such networks need to provide services to users in a secure manner. User authentication is a mechanism through which we can provide secure communication between IoT devices. Recently Banerjee et al. outlined a lightweight anonymous user authenticated session key exchange scheme for Internet of Things deployment, which uses three-factor authentication of a user such as smart card, password and biometric. In this paper, we cryptanalyze their scheme and find that it is not secure against smart card loss attack and stolen verifier attack. Then we have proposed an improved scheme to overcome the weaknesses of their scheme. We present the formal security analysis of our scheme using the random oracle model and informal security analysis to show that our scheme is secure against many known attacks. Its formal security verification is carried out using ProVerif tool. Its performance analysis is carried out with the related schemes which shows that our scheme is more secure than other schemes. Also, our scheme does not contain any storage table at the gateway side for authentication.
引用
收藏
页码:5067 / 5083
页数:17
相关论文
共 50 条
  • [31] A Lightweight Anonymous Client-Server Authentication Scheme for the Internet of Things Scenario: LAuth
    Chen, Yuwen
    Martinez, Jose-Fernan
    Castillejo, Pedro
    Lopez, Lourdes
    [J]. SENSORS, 2018, 18 (11)
  • [32] Secure Lightweight User Authentication and Key Agreement Scheme for Wireless Sensor Networks Tailored for the Internet of Things Environment
    Jangirala, Srinivas
    Mishra, Dheerendra
    Mukhopadhyay, Sourav
    [J]. INFORMATION SYSTEMS SECURITY, 2016, 10063 : 45 - 65
  • [33] A secure and lightweight anonymous mutual authentication scheme for wearable devices in Medical Internet of Things
    Gupta, Ankur
    Tripathi, Meenakshi
    Muhuri, Samya
    Singal, Gaurav
    Kumar, Neeraj
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2022, 68
  • [34] A New Anonymous Ring Authenticated Key Exchange Protocol
    Hui Cui
    Cao, Tianjie
    [J]. ISIP: 2009 INTERNATIONAL SYMPOSIUM ON INFORMATION PROCESSING, PROCEEDINGS, 2009, : 221 - 224
  • [35] LAKE-IoD: Lightweight Authenticated Key Exchange Protocol for the Internet of Drone Environment
    Tanveer, Muhammad
    Zahid, Amjad Hussain
    Ahmad, Musheer
    Baz, Abdullah
    Alhakami, Hosam
    [J]. IEEE ACCESS, 2020, 8 : 155645 - 155659
  • [36] Anonymous password-based authenticated key exchange
    Viet, DQ
    Yamamura, A
    Tanaka, H
    [J]. PROGRESS IN CRYPTOLOGY - INDOCRYPT 2005, PROCEEDINGS, 2005, 3797 : 244 - 257
  • [37] Universally composable anonymous password authenticated key exchange
    Hu, Xuexian
    Zhang, Jiang
    Zhang, Zhenfeng
    Xu, Jing
    [J]. SCIENCE CHINA-INFORMATION SCIENCES, 2017, 60 (05)
  • [38] Universally composable anonymous password authenticated key exchange
    Xuexian HU
    Jiang ZHANG
    Zhenfeng ZHANG
    Jing XU
    [J]. Science China(Information Sciences), 2017, 60 (05) : 153 - 168
  • [39] Lightweight Authenticated-Encryption Scheme for Internet of Things Based on Publish-Subscribe Communication
    Diro, Abebe
    Reda, Haftu
    Chilamkurti, Naveen
    Mahmood, Abdun
    Zaman, Noor
    Nam, Yunyoung
    [J]. IEEE ACCESS, 2020, 8 : 60539 - 60551
  • [40] Anonymous Dynamic Group Authenticated Key Agreements Using Physical Unclonable Functions for Internet of Medical Things
    Lee, Tian-Fu
    Ye, Xiucai
    Lin, Syuan-Han
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (16) : 15336 - 15348