Secure communication in CloudIoT through design of a lightweight authentication and session key agreement scheme

被引:19
|
作者
Nikooghadam, Mahdi [1 ]
Amintoosi, Haleh [1 ]
机构
[1] Ferdowsi Univ Mashhad, Fac Engn, Mashhad, Razavi Khorasan, Iran
关键词
authentication; cloud server; embedded device; Internet of Things; lightweight; security; 2-FACTOR USER AUTHENTICATION; WIRELESS; INTERNET; THINGS; CRYPTANALYSIS; NETWORKS; PROTOCOL; IOT;
D O I
10.1002/dac.4332
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Internet of Things (IoT) is a newly emerged paradigm where multiple embedded devices, known as things, are connected via the Internet to collect, share, and analyze data from the environment. In order to overcome the limited storage and processing capacity constraint of IoT devices, it is now possible to integrate them with cloud servers as large resource pools. Such integration, though bringing applicability of IoT in many domains, raises concerns regarding the authentication of these devices while establishing secure communications to cloud servers. Recently, Kumari et al proposed an authentication scheme based on elliptic curve cryptography (ECC) for IoT and cloud servers and claimed that it satisfies all security requirements and is secure against various attacks. In this paper, we first prove that the scheme of Kumari et al is susceptible to various attacks, including the replay attack and stolen-verifier attack. We then propose a lightweight authentication protocol for secure communication of IoT embedded devices and cloud servers. The proposed scheme is proved to provide essential security requirements such as mutual authentication, device anonymity, and perfect forward secrecy and is robust against security attacks. We also formally verify the security of the proposed protocol using BAN logic and also the Scyther tool. We also evaluate the computation and communication costs of the proposed scheme and demonstrate that the proposed scheme incurs minimum computation and communication overhead, compared to related schemes, making it suitable for IoT environments with low processing and storage capacity.
引用
收藏
页数:17
相关论文
共 50 条
  • [21] On the Security of a Secure and Lightweight Authentication Scheme for Next Generation IoT Infrastructure
    Das, Ashok Kumar
    Bera, Basudeb
    Wazid, Mohammad
    Jamal, Sajjad Shaukat
    Park, Youngho
    IEEE ACCESS, 2021, 9 : 71856 - 71867
  • [22] A secure authentication with key agreement scheme using ECC for satellite communication systems
    Qi, Mingping
    Chen, Jianhua
    Chen, Yitao
    INTERNATIONAL JOURNAL OF SATELLITE COMMUNICATIONS AND NETWORKING, 2019, 37 (03) : 234 - 244
  • [23] Secure Remote User Mutual Authentication Scheme with Key Agreement for Cloud Environment
    Karuppiah, Marimuthu
    Das, Ashok Kumar
    Li, Xiong
    Kumari, Saru
    Wu, Fan
    Chaudhry, Shehzad Ashraf
    Niranchana, R.
    MOBILE NETWORKS & APPLICATIONS, 2019, 24 (03) : 1046 - 1062
  • [24] Secure Multifactor Authenticated Key Agreement Scheme for Industrial IoT
    Vinoth, R.
    Deborah, Lazarus Jegatha
    Vijayakumar, Pandi
    Kumar, Neeraj
    IEEE INTERNET OF THINGS JOURNAL, 2021, 8 (05) : 3801 - 3811
  • [25] A lightweight authentication and key agreement scheme for Internet of Drones
    Zhang, Yunru
    He, Debiao
    Li, Li
    Chen, Biwen
    COMPUTER COMMUNICATIONS, 2020, 154 : 455 - 464
  • [26] Provably secure three-factor authentication and key agreement scheme for session initiation protocol
    Challa, Sravani
    Das, Ashok Kumar
    Kumari, Saru
    Odelu, Vanga
    Wu, Fan
    Li, Xiong
    SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (18) : 5412 - 5431
  • [27] Design and Analysis of Secure Lightweight Remote User Authentication and Key Agreement Scheme in Internet of Drones Deployment
    Wazid, Mohammad
    Das, Ashok Kumar
    Kumar, Neeraj
    Vasilakos, Athanasios V.
    Rodrigues, Joel J. P. C.
    IEEE INTERNET OF THINGS JOURNAL, 2019, 6 (02): : 3572 - 3584
  • [28] Secure and Lightweight Authentication With Key Agreement for Smart Wearable Systems
    Li, Jiping
    Zhang, Ning
    Ni, Jianbing
    Chen, Jing
    Du, Ruiying
    IEEE INTERNET OF THINGS JOURNAL, 2020, 7 (08): : 7334 - 7344
  • [29] Secure Lightweight User Authentication and Key Agreement Scheme for Wireless Sensor Networks Tailored for the Internet of Things Environment
    Jangirala, Srinivas
    Mishra, Dheerendra
    Mukhopadhyay, Sourav
    INFORMATION SYSTEMS SECURITY, 2016, 10063 : 45 - 65
  • [30] A New Enhanced Secure Anonymous Communication with Authentication and Session Key Agreement in Global Mobility Network
    Roy, Prasanta Kumar
    Parai, Krittibas
    Ball, Sathi
    Kumar, Bipin
    2017 THIRD IEEE INTERNATIONAL CONFERENCE ON RESEARCH IN COMPUTATIONAL INTELLIGENCE AND COMMUNICATION NETWORKS (ICRCICN), 2017, : 109 - 113