A Secure, Lightweight, and Anonymous User Authentication Protocol for IoT Environments

被引:19
|
作者
Son, Seunghwan [1 ]
Park, Yohan [2 ]
Park, Youngho [1 ,3 ]
机构
[1] Kyungpook Natl Univ, Sch Elect & Elect Engn, Daegu 41566, South Korea
[2] Keimyung Univ, Sch Comp Engn, Daegu 42601, South Korea
[3] Kyungpook Natl Univ, Sch Elect Engn, Daegu 41566, South Korea
基金
新加坡国家研究基金会;
关键词
mutual authentication; key agreement; lightweight; anonymity; IoT environment; BAN logic; ROR model; AVISPA simulation; KEY AGREEMENT PROTOCOL; PROVABLY SECURE; ACCESS-CONTROL; SCHEME; INTERNET; DESIGN; EXCHANGE; DRONES;
D O I
10.3390/su13169241
中图分类号
X [环境科学、安全科学];
学科分类号
08 ; 0830 ;
摘要
The Internet of Things (IoT) is being applied to various environments such as telecare systems, smart homes, and intelligent transportation systems. The information generated from IoT devices is stored at remote servers, and external users authenticate to the server for requesting access to the stored data. In IoT environments, the authentication process is required to be conducted efficiently, and should be secure against various attacks and ensure user anonymity and untraceability to ensure sustainability of the network. However, many existing protocols proposed in IoT environments do not meet these requirements. Recently, Rajaram et al. proposed a paring-based user authentication scheme. We found that the Rajaram et al. scheme is vulnerable to various attacks such as offline password guessing, impersonation, privileged insider, and known session-specific temporary information attacks. Additionally, as their scheme uses bilinear pairing, it requires high computation and communication costs. In this study, we propose a novel authentication scheme that resolves these security problems. The proposed scheme uses only hash and exclusive-or operations to be applicable in IoT environments. We analyze the proposed protocol using informal analysis and formal analysis methods such as the BAN logic, real-or-random (ROR) model, and the AVISPA simulation, and we show that the proposed protocol has better security and performance compared with existing authentication protocols. Consequently, the proposed protocol is sustainable and suitable for real IoT environments.
引用
收藏
页数:21
相关论文
共 50 条
  • [1] A Physically Secure, Lightweight Three-Factor and Anonymous User Authentication Protocol for IoT
    Liu, Zhenhua
    Guo, Changbo
    Wang, Baocang
    [J]. IEEE ACCESS, 2020, 8 : 195914 - 195928
  • [2] A Provably Secure, Lightweight Protocol for Anonymous Authentication
    Katz, Jonathan
    [J]. SECURITY AND CRYPTOGRAPHY FOR NETWORKS (SCN 2022), 2022, 13409 : 271 - 288
  • [3] A Lightweight and Secure Anonymous User Authentication Protocol for Wireless Body Area Networks
    Zhang, Junsong
    Zhang, Qikun
    Li, Zhigang
    Lu, Xianling
    Gan, Yong
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2021, 2021
  • [4] Secure and lightweight authentication protocol for anonymous data access in cloud assisted IoT system
    Mahor, Vinod
    Padmavathy, R.
    Chatterjee, Santanu
    [J]. PEER-TO-PEER NETWORKING AND APPLICATIONS, 2024, 17 (01) : 321 - 336
  • [5] Secure and lightweight authentication protocol for anonymous data access in cloud assisted IoT system
    Vinod Mahor
    R. Padmavathy
    Santanu Chatterjee
    [J]. Peer-to-Peer Networking and Applications, 2024, 17 : 321 - 336
  • [6] Anonymous and lightweight secure authentication protocol for mobile Agent system
    Berguig, Yousra
    Laassiri, Jalal
    Hanaoui, Sanae
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2021, 63
  • [7] Provable Secure Anonymous Device Authentication Protocol in IoT Environment
    Ren, Shanyao
    Liu, Yizhong
    Yu, Beiyuan
    Liu, Jianwei
    Li, Dongyu
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (07): : 12266 - 12277
  • [8] A Robust Anonymous Remote User Authentication Protocol for IoT Services
    Ghahramani, Meysam
    Javidan, Reza
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2021, 121 (03) : 2347 - 2369
  • [9] A Secure and Lightweight Three-Factor Remote User Authentication Protocol for Future IoT Applications
    Taher, Bahaa Hussein
    Liu, Huiyu
    Abedi, Firas
    Lu, Hongwei
    Yassin, Ali A.
    Mohammed, Alzahraa J.
    [J]. JOURNAL OF SENSORS, 2021, 2021
  • [10] A Robust Anonymous Remote User Authentication Protocol for IoT Services
    Meysam Ghahramani
    Reza Javidan
    [J]. Wireless Personal Communications, 2021, 121 : 2347 - 2369