A Secure, Lightweight, and Anonymous User Authentication Protocol for IoT Environments

被引:19
|
作者
Son, Seunghwan [1 ]
Park, Yohan [2 ]
Park, Youngho [1 ,3 ]
机构
[1] Kyungpook Natl Univ, Sch Elect & Elect Engn, Daegu 41566, South Korea
[2] Keimyung Univ, Sch Comp Engn, Daegu 42601, South Korea
[3] Kyungpook Natl Univ, Sch Elect Engn, Daegu 41566, South Korea
基金
新加坡国家研究基金会;
关键词
mutual authentication; key agreement; lightweight; anonymity; IoT environment; BAN logic; ROR model; AVISPA simulation; KEY AGREEMENT PROTOCOL; PROVABLY SECURE; ACCESS-CONTROL; SCHEME; INTERNET; DESIGN; EXCHANGE; DRONES;
D O I
10.3390/su13169241
中图分类号
X [环境科学、安全科学];
学科分类号
08 ; 0830 ;
摘要
The Internet of Things (IoT) is being applied to various environments such as telecare systems, smart homes, and intelligent transportation systems. The information generated from IoT devices is stored at remote servers, and external users authenticate to the server for requesting access to the stored data. In IoT environments, the authentication process is required to be conducted efficiently, and should be secure against various attacks and ensure user anonymity and untraceability to ensure sustainability of the network. However, many existing protocols proposed in IoT environments do not meet these requirements. Recently, Rajaram et al. proposed a paring-based user authentication scheme. We found that the Rajaram et al. scheme is vulnerable to various attacks such as offline password guessing, impersonation, privileged insider, and known session-specific temporary information attacks. Additionally, as their scheme uses bilinear pairing, it requires high computation and communication costs. In this study, we propose a novel authentication scheme that resolves these security problems. The proposed scheme uses only hash and exclusive-or operations to be applicable in IoT environments. We analyze the proposed protocol using informal analysis and formal analysis methods such as the BAN logic, real-or-random (ROR) model, and the AVISPA simulation, and we show that the proposed protocol has better security and performance compared with existing authentication protocols. Consequently, the proposed protocol is sustainable and suitable for real IoT environments.
引用
收藏
页数:21
相关论文
共 50 条
  • [41] A LIGHTWEIGHT SYMMETRIC CRYPTOGRAPHY BASED USER AUTHENTICATION PROTOCOL FOR IOT BASED APPLICATIONS
    Reddy A.M.
    Gudivada D.
    Rao M.K.
    [J]. Scalable Computing, 2024, 25 (03): : 1647 - 1657
  • [42] Secure and Lightweight Cluster-Based User Authentication Protocol for IoMT Deployment †
    Su, Xinzhong
    Xu, Youyun
    [J]. Sensors, 2024, 24 (22)
  • [43] A Lightweight Three-Factor User Authentication Protocol for the Information Perception of IoT
    Kou, Liang
    Shi, Yiqi
    Zhang, Liguo
    Liu, Duo
    Yang, Qing
    [J]. CMC-COMPUTERS MATERIALS & CONTINUA, 2019, 58 (02): : 545 - 565
  • [44] A Secure Three-Factor Anonymous User Authentication Scheme for Internet of Things Environments
    Chang, Ya-Fen
    Tai, Wei-Liang
    Hou, Po-Lin
    Lai, Kuan-Yu
    [J]. SYMMETRY-BASEL, 2021, 13 (07):
  • [45] A Lightweight Secure User Authentication and Key Agreement Protocol for Wireless Sensor Networks
    Mo, Jiaqing
    Chen, Hang
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2019, 2019
  • [46] A More Secure and Revocable Anonymous Authentication Scheme for IoT
    Mao, Mana
    Yu, Jiujiu
    Wang, Yimin
    [J]. International Journal of Network Security, 2023, 25 (04): : 595 - 602
  • [47] A Secure and LoRaWAN Compatible User Authentication Protocol for Critical Applications in the IoT Environment
    Jabbari, Abdollah
    Mohasefi, Jamshid Bagherzadeh
    [J]. IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2022, 18 (01) : 56 - 65
  • [48] A Secure Anonymous Authentication Protocol for Roaming Service in Resource-Constrained Mobility Environments
    R. Madhusudhan
    R. Shashidhara
    [J]. Arabian Journal for Science and Engineering, 2020, 45 : 2993 - 3014
  • [49] A Secure Anonymous Authentication Protocol for Roaming Service in Resource-Constrained Mobility Environments
    Madhusudhan, R.
    Shashidhara, R.
    [J]. ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2020, 45 (04) : 2993 - 3014
  • [50] PLAKE: PUF-Based Secure Lightweight Authentication and Key Exchange Protocol for IoT
    Roy, Sourav
    Das, Dipnarayan
    Mondal, Anindan
    Mahalat, Mahabub Hasan
    Sen, Bibhash
    Sikdar, Biplab
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (10) : 8547 - 8559