首页> 外文期刊>Sensors >An Anonymous User Authentication and Key Agreement Scheme Based on a Symmetric Cryptosystem in Wireless Sensor Networks
【24h】

An Anonymous User Authentication and Key Agreement Scheme Based on a Symmetric Cryptosystem in Wireless Sensor Networks

机译:无线传感器网络中基于对称密码系统的匿名用户认证和密钥协商方案

获取原文
       

摘要

In wireless sensor networks (WSNs), a registered user can login to the network and use a user authentication protocol to access data collected from the sensor nodes. Since WSNs are typically deployed in unattended environments and sensor nodes have limited resources, many researchers have made considerable efforts to design a secure and efficient user authentication process. Recently, Chen et al. proposed a secure user authentication scheme using symmetric key techniques for WSNs. They claim that their scheme assures high efficiency and security against different types of attacks. After careful analysis, however, we find that Chen et al.’s scheme is still vulnerable to smart card loss attack and is susceptible to denial of service attack, since it is invalid for verification to simply compare an entered ID and a stored ID in smart card. In addition, we also observe that their scheme cannot preserve user anonymity. Furthermore, their scheme cannot quickly detect an incorrect password during login phase, and this flaw wastes both communication and computational overheads. In this paper, we describe how these attacks work, and propose an enhanced anonymous user authentication and key agreement scheme based on a symmetric cryptosystem in WSNs to address all of the aforementioned vulnerabilities in Chen et al.’s scheme. Our analysis shows that the proposed scheme improves the level of security, and is also more efficient relative to other related schemes.
机译:在无线传感器网络(WSN)中,注册用户可以登录网络并使用用户身份验证协议来访问从传感器节点收集的数据。由于WSN通常部署在无人值守的环境中,并且传感器节点的资源有限,因此许多研究人员已经做出了巨大的努力来设计安全有效的用户身份验证过程。最近,Chen等。提出了一种针对WSN使用对称密钥技术的安全用户身份验证方案。他们声称他们的方案可确保针对不同类型攻击的高效性和安全性。然而,经过仔细分析,我们发现Chen等人的方案仍然容易受到智能卡丢失攻击的影响,并且容易受到拒绝服务攻击的影响,因为简单地比较输入的ID和存储在ID中的ID对验证无效智能卡。此外,我们还观察到他们的方案不能保留用户匿名。此外,他们的方案无法在登录阶段快速检测到错误的密码,并且此缺陷浪费了通信和计算开销。在本文中,我们描述了这些攻击的工作方式,并提出了一种基于WSN中对称密码系统的增强的匿名用户身份验证和密钥协商方案,以解决Chen等人方案中的所有上述漏洞。我们的分析表明,提出的方案提高了安全级别,并且相对于其他相关方案也更有效。

著录项

获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号