首页> 外文期刊>Journal of supercomputing >A secure authentication scheme based on elliptic curve cryptography for IoT and cloud servers
【24h】

A secure authentication scheme based on elliptic curve cryptography for IoT and cloud servers

机译:基于椭圆曲线密码学的物联网和云服务器安全认证方案

获取原文
获取原文并翻译 | 示例
           

摘要

The Internet of Things (IoT) is now a buzzword for Internet connectivity which extends to embedded devices, sensors and other objects connected to the Internet. Rapid development of this technology has led to the usage of various embedded devices in our daily life. However, for resource sharing and communication among these devices, there is a requirement for connecting these embedded devices to a large pool of resources like a cloud. The promising applications of IoT in Government and commercial sectors are possible by integrating cloud servers with these embedded devices. But such an integration of technologies involves security issues like data privacy and authentication of devices whenever information is exchanged between them. Recently, Kalra and Sood proposed an authentication scheme based on elliptic curve cryptography (ECC) for IoT and cloud servers and claimed that their scheme satisfies all security requirements and is immune to various types of attacks. However, in this paper, we show that Kalra and Sood scheme is susceptible to offline password guessing and insider attacks and it does not achieve device anonymity, session key agreement, and mutual authentication. Keeping in view of the shortcomings of Kalra and Sood's scheme, we have proposed an authentication scheme based on ECC for IoT and cloud servers. In the proposed scheme in this paper, we have formally analyzed the security properties of the designed scheme by the most widely accepted and used Automated Validation of Internet Security Protocols and Applications tool. Security and performance analysis show that when compared with other related schemes, the proposed scheme is more powerful, efficient, and secure with respect to various known attacks.
机译:物联网(IoT)现在是Internet连接的流行语,它扩展到嵌入式设备,传感器和连接到Internet的其他对象。这项技术的飞速发展已导致人们在日常生活中使用各种嵌入式设备。但是,为了在这些设备之间进行资源共享和通信,需要将这些嵌入式设备连接到大型资源池(如云)。通过将云服务器与这些嵌入式设备集成在一起,可以将物联网在政府和商业领域的应用前景看好。但是,这种技术集成涉及安全问题,例如数据保密性以及每当在设备之间交换信息时对设备进行身份验证。最近,Kalra和Sood提出了一种基于椭圆曲线密码学(ECC)的IoT和云服务器身份验证方案,并声称它们的方案可以满足所有安全要求,并且不受各种类型的攻击。但是,在本文中,我们证明了Kalra and Sood方案容易受到离线密码猜测和内部人员攻击,并且无法实现设备匿名性,会话密钥一致性和相互认证。考虑到Kalra和Sood方案的缺点,我们提出了一种基于ECC的IoT和云服务器身份验证方案。在本文提出的方案中,我们已使用最广泛接受和使用的Internet安全协议和应用程序自动验证工具来正式分析设计方案的安全性。安全性和性能分析表明,与其他相关方案相比,该方案在各种已知攻击方面更强大,高效且安全。

著录项

  • 来源
    《Journal of supercomputing》 |2018年第12期|6428-6453|共26页
  • 作者单位

    Hunan Univ Sci & Technol, Sch Comp Sci & Engn, Xiangtan 411201, Peoples R China;

    Xiamen Inst Technol, Dept Comp Sci & Engn, Xiamen 361021, Peoples R China;

    VIT Univ, Sch Comp Sci & Engn, Vellore 632014, Tamil Nadu, India;

    Thapar Univ, Dept Comp Sci & Engn, Patiala 147004, Punjab, India;

    Int Inst Informat Technol, Ctr Secur Theory & Algorithm Res, Hyderabad 500032, Telangana, India;

    Ch Charan Singh Univ, Dept Math, Meerut 250005, Uttar Pradesh, India;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Authentication; Embedded device; Internet of Things; Cloud server; Cookies; Security;

    机译:身份验证;嵌入式设备;物联网;云服务器;Cookies;安全性;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号