Secure multi-factor remote user authentication scheme for Internet of Things environments

Secure multi-factor remote user authentication scheme for Internet of Things environments
复制标题

DOI:
10.1002/dac.3323
复制
发表时间:
2017-11-10
影响因子:
2.1
通讯作者:
Kalra, Sheetal
Kalra, Sheetal
中科院分区:
计算机科学4区
文献类型:
--
作者:
Dhillon, Parwinder Kaur;Kalra, Sheetal

文献摘要

被引文献

相似文献

由于物联网(IoT)的指数级增长,正在开发几种服务。用户可以在任何地点、任何时间、任何地点通过智能设备访问这些服务。这使得安全和隐私成为物联网环境的核心。在本文中,我们为物联网环境提出了一种轻量级、鲁棒性和多因素远程用户身份验证和密钥协议方案。使用该协议,任何授权用户都可以访问和收集来自物联网节点的实时传感器数据。在访问任何物联网节点之前,用户必须首先通过网关节点和物联网节点进行身份验证。提议的协议基于异或和哈希操作,包括:(i)三因素身份验证(即密码、生物识别和智能设备);(二)相互认证;(iii)共享会话密钥;(四)关键的新鲜度。它满足理想的安全属性,并在资源受限的物联网环境的计算开销方面保持可接受的效率。此外,利用AVISPA进行了非正式和正式的安全分析,证明了协议的安全强度及其对所有可能的安全威胁的鲁棒性。仿真结果也证明了该方案的安全性。
Because of the exponential growth of Internet of Things (IoT), several services are being developed. These services can be accessed through smart gadgets by the user at any place, every time and anywhere. This makes security and privacy central to IoT environments. In this paper, we propose a lightweight, robust, and multi-factor remote user authentication and key agreement scheme for IoT environments. Using this protocol, any authorized user can access and gather real-time sensor data from the IoT nodes. Before gaining access to any IoT node, the user must first get authenticated by the gateway node as well as the IoT node. The proposed protocol is based on XOR and hash operations, and includes: (i) a 3-factor authentication (ie, password, biometrics, and smart device); (ii) mutual authentication; (iii) shared session key; and (iv) key freshness. It satisfies desirable security attributes and maintains acceptable efficiency in terms of the computational overheads for resource constrained IoT environment. Further, the informal and formal security analysis using AVISPA proves security strength of the protocol and its robustness against all possible security threats. Simulation results also prove that the scheme is secure against attacks.