Secure communication in CloudIoT through design of a lightweight authentication and session key agreement scheme

被引:19
|
作者
Nikooghadam, Mahdi [1 ]
Amintoosi, Haleh [1 ]
机构
[1] Ferdowsi Univ Mashhad, Fac Engn, Mashhad, Razavi Khorasan, Iran
关键词
authentication; cloud server; embedded device; Internet of Things; lightweight; security; 2-FACTOR USER AUTHENTICATION; WIRELESS; INTERNET; THINGS; CRYPTANALYSIS; NETWORKS; PROTOCOL; IOT;
D O I
10.1002/dac.4332
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Internet of Things (IoT) is a newly emerged paradigm where multiple embedded devices, known as things, are connected via the Internet to collect, share, and analyze data from the environment. In order to overcome the limited storage and processing capacity constraint of IoT devices, it is now possible to integrate them with cloud servers as large resource pools. Such integration, though bringing applicability of IoT in many domains, raises concerns regarding the authentication of these devices while establishing secure communications to cloud servers. Recently, Kumari et al proposed an authentication scheme based on elliptic curve cryptography (ECC) for IoT and cloud servers and claimed that it satisfies all security requirements and is secure against various attacks. In this paper, we first prove that the scheme of Kumari et al is susceptible to various attacks, including the replay attack and stolen-verifier attack. We then propose a lightweight authentication protocol for secure communication of IoT embedded devices and cloud servers. The proposed scheme is proved to provide essential security requirements such as mutual authentication, device anonymity, and perfect forward secrecy and is robust against security attacks. We also formally verify the security of the proposed protocol using BAN logic and also the Scyther tool. We also evaluate the computation and communication costs of the proposed scheme and demonstrate that the proposed scheme incurs minimum computation and communication overhead, compared to related schemes, making it suitable for IoT environments with low processing and storage capacity.
引用
收藏
页数:17
相关论文
共 50 条
  • [41] A New Lightweight User Authentication and Key Agreement Scheme for WSN
    Foroozan Ghosairi Darbandeh
    Masoumeh Safkhani
    Wireless Personal Communications, 2020, 114 : 3247 - 3269
  • [42] Lightweight batch authentication and key agreement scheme for IIoT gateways
    Ding, Xiaohui
    Wang, Jian
    Zhao, Yongxuan
    Zhang, Zhiqiang
    JOURNAL OF SYSTEMS ARCHITECTURE, 2025, 160
  • [43] An efficient authentication and key agreement scheme for secure smart grid communication services
    Hammami, Hamza
    Obaidat, Mohammad S.
    Ben Yahia, Sadok
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2020, 33 (15)
  • [44] Three party secure data transmission in IoT networks through design of a lightweight authenticated key agreement scheme
    Ostad-Sharif, Arezou
    Arshad, Hamed
    Nikooghadam, Morteza
    Abbasinezhad-Mood, Dariush
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2019, 100 : 882 - 892
  • [45] Secure user authentication and key agreement scheme for IoT device access control based smart home communications
    Uppuluri, Sirisha
    Lakshmeeswari, G.
    WIRELESS NETWORKS, 2023, 29 (03) : 1333 - 1354
  • [46] LAAKA: Lightweight Anonymous Authentication and Key Agreement Scheme for Secure Fog-Driven IoT Systems
    Ali, Hala
    Ahmed, Irfan
    COMPUTERS & SECURITY, 2024, 140
  • [47] On the Security of "Secure and Lightweight Authentication with Key Agreement for Smart Wearable Systems"
    Nikooghadam, Mahdi
    Amintoosi, Haleh
    Kumari, Saru
    WIRELESS PERSONAL COMMUNICATIONS, 2021, 120 (01) : 1 - 8
  • [48] On the Security of “Secure and Lightweight Authentication with Key Agreement for Smart Wearable Systems”
    Mahdi Nikooghadam
    Haleh Amintoosi
    Saru Kumari
    Wireless Personal Communications, 2021, 120 : 1 - 8
  • [49] GASE: A Lightweight Group Authentication Scheme With Key Agreement for Edge Computing Applications
    Nakkar, Mouna
    AlTawy, Riham
    Youssef, Amr
    IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (01) : 840 - 854
  • [50] A PUF-Based Secure Authentication and Key Agreement Scheme for the Internet of Drones
    Choi, Jihye
    Son, Seunghwan
    Kwon, Deokkyu
    Park, Youngho
    SENSORS, 2025, 25 (03)