Secure communication in CloudIoT through design of a lightweight authentication and session key agreement scheme

被引:19
|
作者
Nikooghadam, Mahdi [1 ]
Amintoosi, Haleh [1 ]
机构
[1] Ferdowsi Univ Mashhad, Fac Engn, Mashhad, Razavi Khorasan, Iran
关键词
authentication; cloud server; embedded device; Internet of Things; lightweight; security; 2-FACTOR USER AUTHENTICATION; WIRELESS; INTERNET; THINGS; CRYPTANALYSIS; NETWORKS; PROTOCOL; IOT;
D O I
10.1002/dac.4332
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Internet of Things (IoT) is a newly emerged paradigm where multiple embedded devices, known as things, are connected via the Internet to collect, share, and analyze data from the environment. In order to overcome the limited storage and processing capacity constraint of IoT devices, it is now possible to integrate them with cloud servers as large resource pools. Such integration, though bringing applicability of IoT in many domains, raises concerns regarding the authentication of these devices while establishing secure communications to cloud servers. Recently, Kumari et al proposed an authentication scheme based on elliptic curve cryptography (ECC) for IoT and cloud servers and claimed that it satisfies all security requirements and is secure against various attacks. In this paper, we first prove that the scheme of Kumari et al is susceptible to various attacks, including the replay attack and stolen-verifier attack. We then propose a lightweight authentication protocol for secure communication of IoT embedded devices and cloud servers. The proposed scheme is proved to provide essential security requirements such as mutual authentication, device anonymity, and perfect forward secrecy and is robust against security attacks. We also formally verify the security of the proposed protocol using BAN logic and also the Scyther tool. We also evaluate the computation and communication costs of the proposed scheme and demonstrate that the proposed scheme incurs minimum computation and communication overhead, compared to related schemes, making it suitable for IoT environments with low processing and storage capacity.
引用
收藏
页数:17
相关论文
共 50 条
  • [31] A Lightweight Mutual Authentication and Key Agreement Scheme for Medical Internet of Things
    Xu, Zisang
    Xu, Cheng
    Liang, Wei
    Xu, Jianbo
    Chen, Haixian
    IEEE ACCESS, 2019, 7 : 53922 - 53931
  • [32] Lightweight and Energy-Efficient Mutual Authentication and Key Agreement Scheme With User Anonymity for Secure Communication in Global Mobility Networks
    Gope, Prosanta
    Hwang, Tzonelih
    IEEE SYSTEMS JOURNAL, 2016, 10 (04): : 1370 - 1379
  • [33] A Lightweight, Efficient, and Physically Secure Key Agreement Authentication Protocol for Vehicular Networks
    Wang, Shaoqiang
    Fan, Ziyao
    Su, Yu
    Zheng, Baosen
    Liu, Zhaoyuan
    Dai, Yinfei
    ELECTRONICS, 2024, 13 (08)
  • [34] Secure anonymity-preserving password-based user authentication and session key agreement scheme for telecare medicine information systems
    Sutrala, Anil Kumar
    Das, Ashok Kumar
    Odelu, Vanga
    Wazid, Mohammad
    Kumari, Saru
    COMPUTER METHODS AND PROGRAMS IN BIOMEDICINE, 2016, 135 : 167 - 185
  • [35] A secure and computationally efficient authentication and key agreement scheme for Internet of Vehicles
    Xu, Zisang
    Li, Xiong
    Xu, Jianbo
    Liang, Wei
    Choo, Kim-Kwang Raymond
    COMPUTERS & ELECTRICAL ENGINEERING, 2021, 95
  • [36] A secure authentication and key agreement scheme with dynamic management for vehicular networks
    Zhou, Yuxiang
    Tan, Haowen
    Iroshan, Karunarathina Chandrathilaka Appuhamilage Asiria
    CONNECTION SCIENCE, 2023, 35 (01)
  • [37] A Secure Two-Factor Remote User Authentication and Session Key Agreement Scheme
    Chandrakar, Preeti
    Om, Hari
    INTERNATIONAL JOURNAL OF BUSINESS DATA COMMUNICATIONS AND NETWORKING, 2016, 12 (02) : 62 - 79
  • [38] Provably Secure Session Key Agreement Protocol for Unmanned Aerial Vehicles Packet Exchanges
    Nyangaresi, Vincent Omollo
    Ibrahim, Ayad
    Abduljabbar, Zaid Ameen
    Hussain, Mohammed Abdulridha
    Al Sibahee, Mustafa A.
    Hussien, Zaid Alaa
    Ghrabat, Mudhafar Jalil Jassim
    INTERNATIONAL CONFERENCE ON ELECTRICAL, COMPUTER AND ENERGY TECHNOLOGIES (ICECET 2021), 2021, : 278 - 283
  • [39] An anonymous mutual authentication and key agreement scheme in WMSN using physiological data
    Rai, Shanvendra
    Paul, Rituparna
    Banerjee, Subhasish
    Meher, Preetisudha
    WIRELESS NETWORKS, 2024, 30 (04) : 2733 - 2752
  • [40] A lightweight anonymous mutual authentication and key agreement scheme for WBAN
    Xu, Zisang
    Xu, Cheng
    Chen, Haixian
    Yang, Fang
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2019, 31 (14)