SPrivAD: A secure and privacy-preserving mutually dependent authentication and data access scheme for smart communities

被引:8
作者
Sani, Abubakar Sadiq [1 ]
Bertino, Elisa [2 ]
Yuan, Dong [3 ]
Meng, Ke [4 ]
Dong, Zhao Yang [5 ,6 ]
机构
[1] Univ Greenwich, Sch Comp & Math Sci, London SE10 9LS, England
[2] Purdue Univ, Comp Sci, W Lafayette, IN 47907 USA
[3] Univ Sydney, Sch Elect & Informat Engn, Sydney, NSW 2006, Australia
[4] Univ New South Wales, Sch Elect Engn & Telecommun, Sydney, NSW 2052, Australia
[5] Univ New South Wales, UNSW Digital Grid Futures Inst, Sydney, NSW 2052, Australia
[6] Nanyang Technol Univ, Singapore 639798, Singapore
关键词
Smart communities; Authentication; Data access; Security; Privacy; PROTOCOL;
D O I
10.1016/j.cose.2022.102610
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recent studies show that attackers evade authentication by exploiting valid credentials and crafting authentication request messages to compromise assets and illegitimately access data in smart communities such as smart campuses and smart cities. In addition, attackers can send large numbers of authentication and data access requests to spread malware across the smart communities' network and cause Distributed Denial of Service (DDoS) attacks. This paper proposes SPrivAD, a secure and privacy-preserving mutually dependent authentication and data access solution by which smart communities' assets such as users, devices, and apps can authenticate each other before allowing data access. SPrivAD uses an Inter-Attribute-based Zero Knowledge Proof of Knowledge (IA-ZKPK) protocol based on computational attributes of cryptographic operations, and cryptographic identities of the assets to perform Mutually Dependent Multi-Factor Authentication and Data Access (MDMFA). The computational attributes such as message size and number of executed steps of cryptographic operations are features derived from the knowledge of cryptographic operations between the assets. Our approach for deriving a unique, deactivatable, and revocable cryptographic identity is based on the secrets of an asset in a modified Elliptic Curve Pedersen Commitment Scheme (EC-PCS) with security and privacy guarantees. We implement a prototype of SPrivAD and evaluate it with respect to its security, privacy, and performance. The results show that it is secure, privacy-preserving, and efficient for mutually dependent authentication and data access in smart communities. Furthermore, we design and analyse a new attack, Smart Communities Authentication Bypass Attack (SCABA), on real-world authentication and secure access schemes such as Ruckus Cloudpath Enrollment System and Duo Multi-Factor Authentication (MFA). This type of attack exploits valid credentials of smart communities' assets. We show that SPrivAD mitigates SCABA. (C) 2022 Elsevier Ltd. All rights reserved.
引用
收藏
页数:16
相关论文
共 40 条
  • [1] Securing Smart City Surveillance: A Lightweight Authentication Mechanism for Unmanned Vehicles
    Ali, Zeeshan
    Chaudhry, Shehzad Ashraf
    Ramzan, Muhammad Sher
    Al-Turjman, Fadi
    [J]. IEEE ACCESS, 2020, 8 : 43711 - 43724
  • [2] Registration Center Based User Authentication Scheme for Smart E-Governance Applications in Smart Cities
    Alotaibi, Saud S.
    [J]. IEEE ACCESS, 2019, 7 : 5819 - 5833
  • [3] Amazon, AMAZON SMART COMMUNI
  • [4] Hierarchical and Flat-Based Hybrid Naming Scheme in Content-Centric Networks of Things
    Arshad, Sobia
    Shahzaad, Babar
    Azam, Muhammad Awais
    Loo, Jonathan
    Ahmed, Syed Hassan
    Aslam, Saleem
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2018, 5 (02): : 1070 - 1080
  • [5] AVISPA, AUT VAL INT SEC PROT
  • [6] CAPEC, CAPEC90
  • [7] Cisco, CISCO SMART CITIES
  • [8] CWE, CWE301
  • [9] ON THE SECURITY OF PUBLIC KEY PROTOCOLS
    DOLEV, D
    YAO, AC
    [J]. IEEE TRANSACTIONS ON INFORMATION THEORY, 1983, 29 (02) : 198 - 208
  • [10] Secure Message Communication Protocol Among Vehicles in Smart City
    Dua, Amit
    Kumar, Neeraj
    Das, Ashok Kumar
    Susilo, Willy
    [J]. IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2018, 67 (05) : 4359 - 4373