首页> 外文期刊>Internet of Things Journal, IEEE >A Provably Secure and Lightweight Anonymous User Authenticated Session Key Exchange Scheme for Internet of Things Deployment
【24h】

A Provably Secure and Lightweight Anonymous User Authenticated Session Key Exchange Scheme for Internet of Things Deployment

机译:一种适用于物联网部署的安全且轻量的匿名用户身份验证会话密钥交换方案

获取原文
获取原文并翻译 | 示例
       

摘要

With the ever increasing adoption rate of Internetenabled devices [also known as Internet of Things (IoT) devices] in applications such as smart home, smart city, smart grid, and healthcare applications, we need to ensure the security and privacy of data and communications among these IoT devices and the underlying infrastructure. For example, an adversary can easily tamper with the information transmitted over a public channel, in the sense of modification, deletion, and fabrication of data-in-transit and data-in-storage. Time-critical IoT applications such as healthcare may demand the capability to support external parties (users) to securely access IoT data and services in realtime. This necessitates the design of a secure user authentication mechanism, which should also allow the user to achieve security and functionality features such as anonymity and un-traceability. In this paper, we propose a new lightweight anonymous user authenticated session key agreement scheme in the IoT environment. The proposed scheme uses three-factor authentication, namely a user's smart card, password, and personal biometric information. The proposed scheme does not require the storing of user specific information at the gateway node. We then demonstrate the proposed scheme's security using the broadly accepted real-or-random (ROR) model, Burrows-Abadi-Needham (BAN) logic, and automated validation of Internet security protocols and applications (AVISPAs) software simulation tool, as well as presenting an informal security analysis to demonstrate its other features. In addition, through our simulations, we demonstrate that the proposed scheme outperforms existing related user authentication schemes, in terms of its security and functionality features, and computation costs.
机译:随着智能设备,智能城市,智能电网和医疗保健应用程序中启用Internet的设备(也称为物联网(IoT)设备)的采用率不断提高,我们需要确保数据和通信的安全性和隐私性这些物联网设备和基础设施之间。例如,从修改,删除和制造传输中数据和存储中数据的意义上来说,对手可以轻易地篡改通过公共渠道传输的信息。诸如医疗保健等对时间要求严格的物联网应用可能需要支持外部各方(用户)以安全地实时访问物联网数据和服务的功能。这需要设计安全的用户身份验证机制,该机制还应允许用户实现安全性和功能性功能,例如匿名性和不可追溯性。在本文中,我们提出了一种新的轻量级匿名用户身份验证的会话密钥协商方案,用于IoT环境。提议的方案使用三因素身份验证,即用户的智能卡,密码和个人生物特征信息。所提出的方案不需要在网关节点处存储用户特定信息。然后,我们使用广为接受的实时或随机(ROR)模型,Burrows-Abadi-Needham(BAN)逻辑以及Internet安全协议和应用程序(AVISPAs)软件仿真工具的自动验证来演示该方案的安全性。进行非正式的安全分析以展示其其他功能。另外,通过我们的仿真,我们证明了该方案在安全性和功能特性以及计算成本方面均优于现有的相关用户身份验证方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号