Secure communication in CloudIoT through design of a lightweight authentication and session key agreement scheme

被引:19
|
作者
Nikooghadam, Mahdi [1 ]
Amintoosi, Haleh [1 ]
机构
[1] Ferdowsi Univ Mashhad, Fac Engn, Mashhad, Razavi Khorasan, Iran
关键词
authentication; cloud server; embedded device; Internet of Things; lightweight; security; 2-FACTOR USER AUTHENTICATION; WIRELESS; INTERNET; THINGS; CRYPTANALYSIS; NETWORKS; PROTOCOL; IOT;
D O I
10.1002/dac.4332
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Internet of Things (IoT) is a newly emerged paradigm where multiple embedded devices, known as things, are connected via the Internet to collect, share, and analyze data from the environment. In order to overcome the limited storage and processing capacity constraint of IoT devices, it is now possible to integrate them with cloud servers as large resource pools. Such integration, though bringing applicability of IoT in many domains, raises concerns regarding the authentication of these devices while establishing secure communications to cloud servers. Recently, Kumari et al proposed an authentication scheme based on elliptic curve cryptography (ECC) for IoT and cloud servers and claimed that it satisfies all security requirements and is secure against various attacks. In this paper, we first prove that the scheme of Kumari et al is susceptible to various attacks, including the replay attack and stolen-verifier attack. We then propose a lightweight authentication protocol for secure communication of IoT embedded devices and cloud servers. The proposed scheme is proved to provide essential security requirements such as mutual authentication, device anonymity, and perfect forward secrecy and is robust against security attacks. We also formally verify the security of the proposed protocol using BAN logic and also the Scyther tool. We also evaluate the computation and communication costs of the proposed scheme and demonstrate that the proposed scheme incurs minimum computation and communication overhead, compared to related schemes, making it suitable for IoT environments with low processing and storage capacity.
引用
收藏
页数:17
相关论文
共 50 条
  • [1] Provably Secure and Lightweight Authentication Key Agreement Scheme for Smart Meters
    Chai, Sheng
    Yin, Haotian
    Xing, Bin
    Li, Zhukun
    Guo, Yunyi
    Zhang, Di
    Zhang, Xin
    He, Da
    Zhang, Jie
    Yu, Xiaoling
    Wang, Wei
    Huang, Xin
    IEEE TRANSACTIONS ON SMART GRID, 2023, 14 (05) : 3816 - 3827
  • [2] An Efficient Lightweight Key Agreement and Authentication Scheme for WBAN
    Rehman, Zia Ur
    Altaf, Saud
    Iqbal, Saleem
    IEEE ACCESS, 2020, 8 : 175385 - 175397
  • [3] A secure authentication and key agreement scheme for roaming service with user anonymity
    Arshad, Hamed
    Rasoolzadegan, Abbas
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2017, 30 (18)
  • [4] SLAK: secure lightweight scheme for authentication and key-agreement in internet of things
    Nahnah, Oussama
    Cherbal, Sarra
    INTERNATIONAL JOURNAL OF INFORMATION AND COMPUTER SECURITY, 2024, 23 (02)
  • [5] A Lightweight Anonymous Authentication and Secure Communication Scheme for Fog Computing Services
    Weng, Chi-Yao
    Li, Chun-Ta
    Chen, Chin-Ling
    Lee, Cheng-Chi
    Deng, Yong-Yuan
    IEEE ACCESS, 2021, 9 : 145522 - 145537
  • [6] Provably Secure Lightweight Mutual Authentication and Key Agreement Scheme for Cloud-Based IoT Environments
    Ju, Sieun
    Park, Yohan
    SENSORS, 2023, 23 (24)
  • [7] Lightweight and Secure Session-Key Establishment Scheme in Smart Home Environments
    Kumar, Pardeep
    Gurtov, Andrei
    Iinatti, Jari
    Ylianttila, Mika
    Sain, Mangal
    IEEE SENSORS JOURNAL, 2016, 16 (01) : 254 - 264
  • [8] A Lightweight Key Agreement and Authentication Scheme for Satellite-Communication Systems
    Altaf, Izwa
    Saleem, Muhammad Asad
    Mahmood, Khalid
    Kumari, Saru
    Chaudhary, Pradeep
    Chen, Chien-Ming
    IEEE ACCESS, 2020, 8 : 46278 - 46287
  • [9] A Secure One-to-Many Authentication and Key Agreement Scheme for Industrial IoT
    Ming, Yang
    Yang, Pengfei
    Mahdikhani, Hassan
    Lu, Rongxing
    IEEE SYSTEMS JOURNAL, 2023, 17 (02): : 2225 - 2236
  • [10] An anonymous and secure authentication and key agreement scheme for session initiation protocol
    Lin, Hao
    Wen, Fengtong
    Du, Chunxia
    MULTIMEDIA TOOLS AND APPLICATIONS, 2017, 76 (02) : 2315 - 2329