Provable Secure Anonymous Device Authentication Protocol in IoT Environment

Provable Secure Anonymous Device Authentication Protocol in IoT Environment
复制标题

DOI:
10.1109/jiot.2023.3332943
复制
发表时间:
2024-04
影响因子:
10.6
通讯作者:
S. Ren;Yizhong Liu;Beiyuan Yu;Jianwei Liu;Dongyu Li
S. Ren;Yizhong Liu;Beiyuan Yu;Jianwei Liu;Dongyu Li
中科院分区:
计算机科学1区
文献类型:
--
作者:
S. Ren;Yizhong Liu;Beiyuan Yu;Jianwei Liu;Dongyu Li

文献摘要

相似文献

物联网(IoT)中固有的大量异构设备和开放通道为设备和云服务器之间的身份认证带来了重大挑战。在这个问题上,可靠协议保证了参与者的合法性,是提供认证安全性的重要手段。在以前的研究中,研究人员设计的方案表现出一定的安全漏洞,使其难以抵御全面的网络攻击,例如,此外,一些协议具有复杂的交互过程,这导致显著的计算冗余和资源损失。基于此,本文提出了一种基于椭圆曲线密码体制的匿名无证书轻量级认证协议(ACID),用于设备到服务器和设备到设备的认证。它提高了设备与云服务器之间的通信质量,解决了身份验证中的安全风险。在该方案中,我们利用设备用户的密码和生物特征作为验证凭证,而无需在云服务器上存储任何可信证据。我们解决了物联网环境中众多设备造成的资源消耗问题。通过形式化的安全性分析和与其他协议的比较,我们的协议具有较好的安全性能,有效地节省了用于认证的通信资源。仿真结果验证了该方案的可行性和实际意义。
The inherent massive heterogeneous devices and open channels in the Internet of Things (IoT) present significant challenges for identity authentication between devices and cloud servers. For this issue, reliable protocols ensure the legality of participants and act as a crucial method to provide security for authentication. In previous research, schemes devised by researchers exhibit certain security vulnerabilities, making it challenging to withstand comprehensive network attacks, e.g., stolen device attacks, replay attacks, impersonation, etc. Additionally, some protocols have complex interaction processes, which incur significant computational redundancy and resource loss. Motivated by this, this article proposes an anonymous and certificateless lightweight authentication protocol (ACLAP) for device-to-server and device-to-device based on elliptic curve cryptography. It improves the communication quality between devices and cloud servers and solves the security risks in authentication. In the scheme, we utilize device users’ passwords and biometric features as verification credentials without storing any trusted proofs on the cloud server. We address the issue of resource consumption caused by numerous devices in the IoT environment. From formal security analysis and comparisons with other works, our protocol has preferable security performance and effectively saves communication resources for authentication. Simulation results demonstrate the feasibility and practical significance of the scheme.