Scispace (Formerly Typeset)
  1. Home
  2. Topics
  3. Authentication protocol
  4. 2018
  1. Home
  2. Topics
  3. Authentication protocol
  4. 2018
Showing papers on "Authentication protocol published in 2018"
Journal Article•10.1109/TII.2017.2773666•
A Robust ECC-Based Provable Secure Authentication Protocol With Privacy Preserving for Industrial Internet of Things

[...]

Xiong Li1, Jianwei Niu2, Zakirul Alam Bhuiyan3, Fan Wu, Marimuthu Karuppiah4, Saru Kumari5 •
Hunan University of Science and Technology1, Beihang University2, Fordham University3, VIT University4, Chaudhary Charan Singh University5
01 Aug 2018-IEEE Transactions on Industrial Informatics
TL;DR: A user authentication protocol scheme with privacy protection for IIoT is proposed and the security of the proposed scheme is proved under a random oracle model, and other security discussions show that the proposed protocol is robust to various attacks.
Abstract: Wireless sensor networks (WSNs) play an important role in the industrial Internet of Things (IIoT) and have been widely used in many industrial fields to gather data of monitoring area. However, due to the open nature of wireless channel and resource-constrained feature of sensor nodes, how to guarantee that the sensitive sensor data can only be accessed by a valid user becomes a key challenge in IIoT environment. Some user authentication protocols for WSNs have been proposed to address this issue. However, previous works more or less have their own weaknesses, such as not providing user anonymity and other ideal functions or being vulnerable to some attacks. To provide secure communication for IIoT, a user authentication protocol scheme with privacy protection for IIoT has been proposed. The security of the proposed scheme is proved under a random oracle model, and other security discussions show that the proposed protocol is robust to various attacks. Furthermore, the comparison results with other related protocols and the simulation by NS-3 show that the proposed protocol is secure and efficient for IIoT.

410 citations

Journal Article•10.1109/ACCESS.2018.2864189•
A Privacy-Preserving Trust Model Based on Blockchain for VANETs

[...]

Zhaojun Lu1, Wenchao Liu1, Qian Wang2, Gang Qu2, Zhenglin Liu1 •
Huazhong University of Science and Technology1, University of Maryland, College Park2
07 Aug 2018-IEEE Access
TL;DR: A blockchain-based anonymous reputation system (BARS) is proposed to establish a privacy-preserving trust model for VANETs and the results show that BARS is able to established a trust model with transparency, conditional anonymity, efficiency, and robustness for VIANETs.
Abstract: The public key infrastructure-based authentication protocol provides basic security services for the vehicular ad hoc networks (VANETs). However, trust and privacy are still open issues due to the unique characteristics of VANETs. It is crucial to prevent internal vehicles from broadcasting forged messages while simultaneously preserving the privacy of vehicles against the tracking attacks. In this paper, we propose a blockchain-based anonymous reputation system (BARS) to establish a privacy-preserving trust model for VANETs. The certificate and revocation transparency is implemented efficiently with the proofs of presence and absence based on the extended blockchain technology. The public keys are used as pseudonyms in communications without any information about real identities for conditional anonymity. In order to prevent the distribution of forged messages, a reputation evaluation algorithm is presented relying on both direct historical interactions and indirect opinions about vehicles. A set of experiments is conducted to evaluate BARS in terms of security, validity, and performance, and the results show that BARS is able to establish a trust model with transparency, conditional anonymity, efficiency, and robustness for VANETs.

366 citations

Proceedings Article•10.1145/3243734.3243846•
A Formal Analysis of 5G Authentication

[...]

David Basin1, Jannik Dreier2, Lucca Hirschi1, Saša Radomirović3, Ralf Sasse1, Vincent Stettler1 •
ETH Zurich1, University of Lorraine2, University of Dundee3
15 Oct 2018
TL;DR: In this article, the authors provide the first comprehensive formal model of a protocol from the AKA family: 5G AKA, and conduct a full, systematic, security evaluation of the model with respect to the 5G security goals.
Abstract: Mobile communication networks connect much of the world's population. The security of users' calls, SMSs, and mobile data depends on the guarantees provided by the Authenticated Key Exchange protocols used. For the next-generation network (5G), the 3GPP group has standardized the 5G AKA protocol for this purpose. We provide the first comprehensive formal model of a protocol from the AKA family: 5G AKA. We also extract precise requirements from the 3GPP standards defining 5G and we identify missing security goals. Using the security protocol verification tool Tamarin, we conduct a full, systematic, security evaluation of the model with respect to the 5G security goals. Our automated analysis identifies the minimal security assumptions required for each security goal and we find that some critical security goals are not met, except under additional assumptions missing from the standard. Finally, we make explicit recommendations with provably secure fixes for the attacks and weaknesses we found.

328 citations

Journal Article•10.1016/J.FUTURE.2016.05.032•
A robust and anonymous patient monitoring system using wireless medical sensor networks

[...]

Ruhul Amin1, SK Hafizul Islam2, G. P. Biswas1, Muhammad Khurram Khan3, Neeraj Kumar4 •
Indian Institute of Technology Dhanbad1, Birla Institute of Technology and Science2, King Saud University3, Thapar University4
01 Mar 2018-Future Generation Computer Systems
TL;DR: An architecture for patient monitoring health-care system in WMSN is proposed and an anonymity-preserving mutual authentication protocol for mobile users is designed and it is demonstrated that the proposed protocol is efficient and robust.

326 citations

Journal Article•10.1109/ACCESS.2018.2812844•
RBAC-SC: Role-Based Access Control Using Smart Contract

[...]

Jason Paul Cruz1, Yuichi Kaji2, Naoto Yanai1•
Osaka University1, Nagoya University2
07 Mar 2018-IEEE Access
TL;DR: The RBAC-SC uses smart contracts and blockchain technology as versatile infrastructures to represent the trust and endorsement relationship that are essential in the RBAC and to realize a challenge-response authentication protocol that verifies a user’s ownership of roles.
Abstract: The role-based access control (RBAC) framework is a mechanism that describes the access control principle. As a common interaction, an organization provides a service to a user who owns a certain role that was issued by a different organization. Such trans-organizational RBAC is common in face-to-face communication but not in a computer network, because it is difficult to establish both the security that prohibits the malicious impersonation of roles and the flexibility that allows small organizations to participate and users to fully control their own roles. In this paper, we present an RBAC using smart contract (RBAC-SC), a platform that makes use of Ethereum’s smart contract technology to realize a trans-organizational utilization of roles. Ethereum is an open blockchain platform that is designed to be secure, adaptable, and flexible. It pioneered smart contracts, which are decentralized applications that serve as “autonomous agents” running exactly as programmed and are deployed on a blockchain. The RBAC-SC uses smart contracts and blockchain technology as versatile infrastructures to represent the trust and endorsement relationship that are essential in the RBAC and to realize a challenge-response authentication protocol that verifies a user’s ownership of roles. We describe the RBAC-SC framework, which is composed of two main parts, namely, the smart contract and the challenge-response protocol, and present a performance analysis. A prototype of the smart contract is created and deployed on Ethereum’s Testnet blockchain, and the source code is publicly available.

325 citations

Journal Article•10.1016/J.FUTURE.2016.12.028•
A light weight authentication protocol for IoT-enabled devices in distributed Cloud Computing environment

[...]

Ruhul Amin1, Neeraj Kumar1, G. P. Biswas2, Rahat Iqbal3, Victor Chang4 •
Thapar University1, Indian Institute of Technology Dhanbad2, Coventry University3, Xi'an Jiaotong-Liverpool University4
01 Jan 2018-Future Generation Computer Systems
TL;DR: Security vulnerabilities of the multi-server cloud environment of the protocols proposed by Xue et al. and Chuang et al are shown and an informal cryptanalysis confirms that the protocol is protected against all possible security threats.

311 citations

Proceedings Article•10.1109/TRUSTCOM/BIGDATASE.2018.00025•
BARS: A Blockchain-Based Anonymous Reputation System for Trust Management in VANETs

[...]

Zhaojun Lu1, Qian Wang2, Gang Qu3, Zhenglin Liu1•
Huazhong University of Science and Technology1, Wuhan University2, University of Maryland, College Park3
1 Aug 2018
TL;DR: Wang et al. as mentioned in this paper proposed a blockchain-based anonymous reputation system (BARS) to break the linkability between real identities and public keys to preserve privacy in VANETs.
Abstract: The public key infrastructure (PKI) based authentication protocol provides the basic security services for vehicular ad-hoc networks (VANETs). However, trust and privacy are still open issues due to the unique characteristics of vehicles. It is crucial for VANETs to prevent internal vehicles from broadcasting forged messages while simultaneously protecting the privacy of each vehicle against tracking attacks. In this paper, we propose a blockchain-based anonymous reputation system (BARS) to break the linkability between real identities and public keys to preserve privacy. The certificate and revocation transparency is implemented efficiently using two blockchains. We design a trust model to improve the trustworthiness of messages relying on the reputation of the sender based on both direct historical interactions and indirect opinions about the sender. Experiments are conducted to evaluate BARS in terms of security and performance and the results show that BARS is able to establish distributed trust management, while protecting the privacy of vehicles.

263 citations

Journal Article•10.1016/J.FUTURE.2016.11.033•
A lightweight multi-layer authentication protocol for wireless body area networks

[...]

Jian Shen1, Shaohua Chang1, Jun Shen1, Qi Liu1, Xingming Sun1 •
Nanjing University of Information Science and Technology1
01 Jan 2018-Future Generation Computer Systems
TL;DR: A one-to-many group authentication protocol and a group key establishment algorithm between personal digital assistance (PDA) and each of sensor nodes with energy efficiency and low computational cost and the validation of the proposed protocol can be proved.

262 citations

Journal Article•10.1109/TDSC.2016.2616876•
Secure Biometric-Based Authentication Scheme Using Chebyshev Chaotic Map for Multi-Server Environment

[...]

Santanu Chatterjee, Sandip Roy1, Ashok Kumar Das2, Samiran Chattopadhyay3, Neeraj Kumar4, Athanasios V. Vasilakos5 •
Asansol Engineering College1, International Institute of Information Technology, Hyderabad2, Jadavpur University3, Thapar University4, Luleå University of Technology5
01 Sep 2018-IEEE Transactions on Dependable and Secure Computing
TL;DR: A new authentication scheme for multi-server environments using Chebyshev chaotic map that provides strong authentication, and also supports biometrics & password change phase by a legitimate user at any time locally, and dynamic server addition phase.
Abstract: Multi-server environment is the most common scenario for a large number of enterprise class applications. In this environment, user registration at each server is not recommended. Using multi-server authentication architecture, user can manage authentication to various servers using single identity and password. We introduce a new authentication scheme for multi-server environments using Chebyshev chaotic map. In our scheme, we use the Chebyshev chaotic map and biometric verification along with password verification for authorization and access to various application servers. The proposed scheme is light-weight compared to other related schemes. We only use the Chebyshev chaotic map, cryptographic hash function and symmetric key encryption-decryption in the proposed scheme. Our scheme provides strong authentication, and also supports biometrics & password change phase by a legitimate user at any time locally, and dynamic server addition phase. We perform the formal security verification using the broadly-accepted Automated Validation of Internet Security Protocols and Applications (AVISPA) tool to show that the presented scheme is secure. In addition, we use the formal security analysis using the Burrows-Abadi-Needham (BAN) logic along with random oracle models and prove that our scheme is secure against different known attacks. High security and significantly low computation and communication costs make our scheme is very suitable for multi-server environments as compared to other existing related schemes.

225 citations

Journal Article•10.1109/TIFS.2018.2832849•
Lightweight and Practical Anonymous Authentication Protocol for RFID Systems Using Physically Unclonable Functions

[...]

Prosanta Gope1, Jemin Lee2, Tony Q. S. Quek1•
Singapore University of Technology and Design1, Daegu Gyeongbuk Institute of Science and Technology2
03 May 2018-IEEE Transactions on Information Forensics and Security
TL;DR: This paper proposes a lightweight privacy-preserving authentication protocol for the RFID system by considering the ideal PUF environment, and introduces an enhanced protocol which can support the noisyPUF environment.
Abstract: Radio frequency identification (RFID) has been considered one of the imperative requirements for implementation of Internet-of-Things applications. It helps to solve the identification issues of the things in a cost-effective manner, but RFID systems often suffer from various security and privacy issues. To solve those issues for RFID systems, many schemes have been recently proposed by using the cryptographic primitive, called physically uncloneable functions (PUFs), which can ensure a tamper-evident feature. However, to the best of our knowledge, none of them has succeeded to address the problem of privacy preservation with the resistance of DoS attacks in a practical way. For instance, existing schemes need to rely on exhaustive search operations to identify a tag, and also suffer from several security and privacy related issues. Furthermore, a tag needs to store some security credentials (e.g., secret shared keys), which may cause several issues such as loss of forward and backward secrecy and large storage costs. Therefore, in this paper, we first propose a lightweight privacy-preserving authentication protocol for the RFID system by considering the ideal PUF environment. Subsequently, we introduce an enhanced protocol which can support the noisy PUF environment. It is argued that both of our protocols can overcome the limitations of existing schemes, and further ensure more security properties. By analyzing the performance, we have shown that the proposed solutions are secure, efficient, practical, and effective for the resource-constraint RFID tag.

225 citations

Journal Article•10.1109/JIOT.2017.2787800•
A Robust and Energy Efficient Authentication Protocol for Industrial Internet of Things

[...]

Xiong Li1, Jieyao Peng1, Jianwei Niu2, Fan Wu, Junguo Liao1, Kim-Kwang Raymond Choo3 •
Hunan University of Science and Technology1, Beihang University2, University of Texas at San Antonio3
01 Jun 2018-IEEE Internet of Things Journal
TL;DR: A three-factor user authentication protocol for WSN is presented to remove the weaknesses of previous protocols and is compared with other related protocols to show that the proposed protocol is robust and energy efficient for IoT applications.
Abstract: The Internet of Things (IoT) is an emerging technology and expected to provide solutions for various industrial fields. As a basic technology of the IoT, wireless sensor networks (WSNs) can be used to collect the required environment parameters for specific applications. Due to the resource limitation of sensor node and the open nature of wireless channel, security has become an enormous challenge in WSN. Authentication as a basic security service can be used to guarantee the legality of data access in WSN. Recently, Chang and Le proposed two authentication protocols for WSN for different security requirements. However, their protocol cannot provide proper mutual authentication and has other security and functionality defects. We present a three-factor user authentication protocol for WSN to remove the weaknesses of previous protocols. The security of the proposed protocol is analyzed, and the security, functionality and performance of our protocol are compared with other related protocols. The comparison results and simulation results by NS-3 show that the proposed protocol is robust and energy efficient for IoT applications.
Proceedings Article•10.1145/3266444.3266452•
Behavioral Fingerprinting of IoT Devices

[...]

Bruhadeshwar Bezawada1, Maalvika Bachani1, Jordan Peterson1, Hossein Shirazi1, Indrakshi Ray1, Indrajit Ray1 •
Colorado State University1
15 Jan 2018
TL;DR: This work presents a methodology to perform IoT device behavioral fingerprinting that can be employed to undertake strong device identification, and shows preliminary results for fingerprinting device categories, i.e., identifying different devices having similar functionality.
Abstract: The Internet-of-Things (IoT) has brought in new challenges in device identification --what the device is, and authentication --is the device the one it claims to be. Traditionally, the authentication problem is solved by means of a cryptographic protocol. However, the computational complexity of cryptographic protocols and/or problems related to key management, render almost all cryptography based authentication protocols impractical for IoT. The problem of device identification is, on the other hand, sadly neglected. Almost always an artificially created identity is softly associated with the device. We believe that device fingerprinting can be used to solve both these problems effectively. In this work, we present a methodology to perform IoT device behavioral fingerprinting that can be employed to undertake strong device identification. A device behavior is approximated using features extracted from the network traffic of the device. These features are used to train a machine learning model that can be used to detect similar device-types. We validate our approach using five-fold cross validation; we report a identification rate of 93-100 and a mean accuracy of 99%, across all our experiments. Furthermore, we show preliminary results for fingerprinting device categories, i.e., identifying different devices having similar functionality.
Journal Article•10.1109/JBHI.2017.2753464•
Design of Secure and Lightweight Authentication Protocol for Wearable Devices Environment

[...]

Ashok Kumar Das1, Mohammad Wazid1, Neeraj Kumar2, Muhammad Khurram Khan3, Kim-Kwang Raymond Choo4, Young-Ho Park5 •
International Institute of Information Technology, Hyderabad1, Thapar University2, King Saud University3, University of Texas at San Antonio4, Kyungpook National University5
01 Jul 2018-IEEE Journal of Biomedical and Health Informatics
TL;DR: A new lightweight authentication scheme suitable for wearable device deployment that allows a user to mutually authenticate his/her wearable device(s) and the mobile terminal and establish a session key among these devices (worn and carried by the same user) for secure communication between the wearable device and theMobile terminal.
Abstract: Wearable devices are used in various applications to collect information including step information, sleeping cycles, workout statistics, and health-related information. Due to the nature and richness of the data collected by such devices, it is important to ensure the security of the collected data. This paper presents a new lightweight authentication scheme suitable for wearable device deployment. The scheme allows a user to mutually authenticate his/her wearable device(s) and the mobile terminal (e.g., Android and iOS device) and establish a session key among these devices (worn and carried by the same user) for secure communication between the wearable device and the mobile terminal. The security of the proposed scheme is then demonstrated through the broadly accepted real-or-random model, as well as using the popular formal security verification tool, known as the Automated validation of Internet security protocols and applications. Finally, we present a comparative summary of the proposed scheme in terms of the overheads such as computation and communication costs, security and functionality features of the proposed scheme and related schemes, and also the evaluation findings from the NS2 simulation.
Journal Article•10.3390/SYM10080352•
PUF based authentication protocol for IoT

[...]

An Braeken
01 Aug 2018-Symmetry
TL;DR: This paper shows that the key agreement scheme of a recently proposed PUF based protocol is vulnerable for man-in-the-middle, impersonation, and replay attacks in the Yao–Dolev security model, and proposes an alternative scheme, which is able to solve these issues and can provide in addition a more efficient key agreement and subsequently a communication phase between two IoT devices connected to the same authentication server.
Abstract: Key agreement between two constrained Internet of Things (IoT) devices that have not met each other is an essential feature to provide in order to establish trust among its users. Physical Unclonable Functions (PUFs) on a device represent a low cost primitive exploiting the unique random patterns in the device and have been already applied in a multitude of applications for secure key generation and key agreement in order to avoid an attacker to take over the identity of a tampered device, whose key material has been extracted. This paper shows that the key agreement scheme of a recently proposed PUF based protocol, presented by Chatterjee et al., for Internet of Things (IoT) is vulnerable for man-in-the-middle, impersonation, and replay attacks in the Yao–Dolev security model. We propose an alternative scheme, which is able to solve these issues and can provide in addition a more efficient key agreement and subsequently a communication phase between two IoT devices connected to the same authentication server. The scheme also offers identity based authentication and repudiation, when only using elliptic curve multiplications and additions, instead of the compute intensive pairing operations.
Journal Article•10.1039/C7CS00287D•
Molecules for security measures: from keypad locks to advanced communication protocols

[...]

Joakim Andréasson1, Uwe Pischel2•
Chalmers University of Technology1, University of Huelva2
03 Apr 2018-Chemical Society Reviews
TL;DR: This Tutorial Review highlights the diversity of the molecular platforms and the analytical techniques used for this purpose, some of which are highlighted in this Tutorial Review, and how those molecular systems can be used to emulate a broad spectrum of security measures.
Abstract: The idea of using molecules in the context of information security has sparked the interest of researchers from many scientific disciplines. This is clearly manifested in the diversity of the molecular platforms and the analytical techniques used for this purpose, some of which we highlight in this Tutorial Review. Moreover, those molecular systems can be used to emulate a broad spectrum of security measures. For a long time, molecular keypad locks enjoyed a clear preference and the review starts off with a description of how these devices developed. In the last few years, however, the field has evolved into something larger. Examples include more complex authentication protocols (multi-factor authentication and one-time passwords), the recognition of erroneous procedures in data transmission (parity devices), as well as steganographic and cryptographic protection.
Journal Article•10.1007/S11227-017-2105-8•
On the security of a new ultra-lightweight authentication protocol in IoT environment for RFID tags

[...]

King-Hang Wang1, Chien-Ming Chen2, Weicheng Fang2, Tsu-Yang Wu3•
Hong Kong University of Science and Technology1, Harbin Institute of Technology Shenzhen Graduate School2, Fujian University of Technology3
01 Jan 2018-The Journal of Supercomputing
TL;DR: In this attack, an attacker can obtain the key shared between a back-end database server and a tag in a ultra-lightweight mutual authentication protocol in IoT environments for RFID tags.
Abstract: Recently, Tewari and Gupta proposed a ultra-lightweight mutual authentication protocol in IoT environments for RFID tags. Their protocol aims to provide secure communication with least cost in both storage and computation. Unfortunately, in this paper, we exploit the vulnerability of this protocol. In this attack, an attacker can obtain the key shared between a back-end database server and a tag. We also explore the possibility in patching the system with some modifications.
Journal Article•10.1109/JSYST.2016.2585681•
On the Challenges in Designing Identity-Based Privacy-Preserving Authentication Schemes for Mobile Devices

[...]

Ding Wang1, Haibo Cheng1, Debiao He2, Ping Wang1•
Peking University1, Wuhan University2
01 Mar 2018-IEEE Systems Journal
TL;DR: Three representative identity-based remote user authentication schemes are employed as case studies to reveal the challenges and subtleties in designing a practical authentication scheme for mobile devices and a “provably secure” scheme for roaming services in mobile networks is scrutinized.
Abstract: Providing secure, efficient, and privacy-preserving user authentication in mobile networks is a challenging problem due to the inherent mobility of users, variety of attack vectors, and resource-constrained nature of user devices. Recent studies show that identity-based cryptosystems can eliminate the certificate overhead and thus address the issues associated with public-key infrastructure technology—which is a rare bit of good news in today's computer security world. In this paper, we employ three representative identity-based remote user authentication schemes (i.e., Truong et al. 's scheme, Li et al. 's scheme, and Zhang et al. 's scheme) as case studies to reveal the challenges and subtleties in designing a practical authentication scheme for mobile devices. First, we demonstrate that Truong et al. 's scheme, which was presented at the IEEE AINA 2012, cannot achieve a few important security goals under our new attacking scenarios: 1) it fails to resist against known session-specific temporary information attack; 2) it cannot withstand key compromise impersonation attack; and 3) it is of poor usability. Second, we show that Li et al. 's privacy-preserving scheme, which was proposed at GLOBECOM 2012, is subject to some subtle (yet severe) efficiency problems that make it virtually impossible for any practical use. Third, we scrutinize a “provably secure” scheme for roaming services in mobile networks designed by Zhang et al. at SCN 2015 and find it prone to collusion attack and replay attack. Further, we investigate into the underlying causes for these identified failures, and figure out an improvement over Truong et al. 's scheme to overcome the revealed challenges while maintaining reasonable efficiency.
Journal Article•10.1016/J.CMPB.2018.02.002•
Cloud-assisted mutual authentication and privacy preservation protocol for telecare medical information systems.

[...]

Chun-Ta Li1, Dong-Her Shih2, Chun-Cheng Wang2•
Tainan University of Technology1, National Yunlin University of Science and Technology2
01 Apr 2018-Computer Methods and Programs in Biomedicine
TL;DR: An enhanced version of Mohit et al.'s authentication protocol for cloud-assisted TMIS is introduced, which can ensure patient anonymity and patient unlinkability and prevent the security threats of report revelation and report forgery attacks.
Journal Article•10.1007/S12652-017-0516-2•
Security analysis and improvement of bio-hashing based three-factor authentication scheme for telecare medical information systems

[...]

Qi Jiang1, Zhiren Chen1, Bingyan Li1, Jian Shen2, Li Yang1, Jianfeng Ma1 •
Xidian University1, Nanjing University of Information Science and Technology2
01 Aug 2018-Journal of Ambient Intelligence and Humanized Computing
TL;DR: An improved 3FA scheme is presented and it is shown that the new scheme fulfills session key secrecy and mutual authentication using the formal verification tool ProVerif and is capable of withstanding various attacks, and provides desired security features.
Abstract: The deployment of telecare medical information system (TMIS) over public networks gives rise to the threat of exposing sensitive medical information to illegal entities. Although a number of three-factor authentication (3FA) schemes have been developed to address this challenge, most of them are found to be flawed. Understanding security and privacy failures of authentication protocols is a prerequisite to both fixing existing protocols and designing future ones. In this paper, we investigate the 3FA protocol of Lu et al. for TMIS (J Med Syst 39:32, 2015) and reveal that it cannot achieve the claimed security and privacy goals. (1) It fails to provide anonymity and untraceability, and is susceptible to the following attacks targeting user privacy: identity revelation attack, identity guessing attack and tracking attack. (2) It is susceptible to offline password guessing attack, user impersonation attack, and server impersonation attack. Then we present an improved 3FA scheme and show that the new scheme fulfills session key secrecy and mutual authentication using the formal verification tool ProVerif. Moreover, detailed heuristic security analysis is also presented to demonstrate that our new scheme is capable of withstanding various attacks, and provides desired security features. Additionally, performance analysis shows that our proposed protocol is a practical solution for TMIS.
Journal Article•10.1007/S11042-017-5376-4•
Efficient authentication protocol for secure multimedia communications in IoT-enabled wireless sensor networks

[...]

Dheerendra Mishra1, Pandi Vijayakumar2, Venkatasamy Sureshkumar3, Ruhul Amin4, SK Hafizul Islam5, Prosanta Gope6 •
LNM Institute of Information Technology1, University College of Engineering2, PSG College of Technology3, International Institute of Information Technology4, Indian Institutes of Information Technology5, National University of Singapore6
01 Jul 2018-Multimedia Tools and Applications
TL;DR: This article proved that Kumari and Om’s protocol has some design flaws and is susceptible to various security attacks including, user and sensor node impersonation attacks, and a robust authentication protocol using smartcard is constructed to solve the security issues found in Kumar and Om's protocol.
Abstract: In current times, multimedia application includes integrated sensors, mobile networks and Internet-of-Things (IoT) services. In IoT services, if more devices are connected without much constrains, the problem of security, trust and privacy remain a challenge. For multimedia communications through Wireless Sensor Network (WSN), sensor nodes transmit confidential data to the gateway nodes via public channels. In such an environment, the security remains a serious issue from past many years. Only few works are available to support secure multimedia communications performed in IoT-enabled WSNs. Among the few works, Kumari and Om recently proposed an authentication protocol for multimedia communications in IoT-enabled WSNs, which is applicable in coal mine for safety monitoring. The authors claimed in their work that their contributory protocol strongly withstands several security threats such as, user impersonation attack, sensor node impersonation attack, sensor node anonymity issue and others technical design issues. However, this article proved that Kumari and Om’s protocol has some design flaws and is susceptible to various security attacks including, user and sensor node impersonation attacks. As a remedy, a robust authentication protocol using smartcard is constructed to solve the security issues found in Kumari and Om’s protocol. The proof of correctness of mutual authentication is performed using the BAN logic model. In addition, our further security investigation claimed strong protection against known security attacks. Our protocol is analyzed comprehensively and compared against the similar protocols and the results showed that it is efficient and robust than earlier protocols.
Posted Content•
IoTSense: Behavioral Fingerprinting of IoT Devices.

[...]

Bruhadeshwar Bezawada, Maalvika Bachani, Jordan Peterson, Hossein Shirazi, Indrakshi Ray, Indrajit Ray 
11 Apr 2018-arXiv: Cryptography and Security
TL;DR: This work presents a methodology to perform device behavioral fingerprinting that can be employed to undertake device type identification, and shows preliminary results for fingerprinting device categories, i.e., identifying different device types having similar functionality.
Abstract: The Internet-of-Things (IoT) has brought in new challenges in, device identification --what the device is, and, authentication --is the device the one it claims to be. Traditionally, the authentication problem is solved by means of a cryptographic protocol. However, the computational complexity of cryptographic protocols and/or scalability problems related to key management, render almost all cryptography based authentication protocols impractical for IoT. The problem of device identification is, on the other hand, sadly neglected. We believe that device fingerprinting can be used to solve both these problems effectively. In this work, we present a methodology to perform device behavioral fingerprinting that can be employed to undertake device type identification. A device behavior is approximated using features extracted from the network traffic of the device. These features are used to train a machine learning model that can be used to detect similar device types. We validate our approach using five-fold cross validation; we report a identification rate of 86-99% and a mean accuracy of 99%, across all our experiments. Our approach is successful even when a device uses encrypted communication. Furthermore, we show preliminary results for fingerprinting device categories, i.e., identifying different device types having similar functionality.
Journal Article•10.1016/J.COMPELECENG.2017.12.045•
Advanced formal authentication protocol using smart cards for network applicants

[...]

Trupil Limbasiya1, Mukesh Soni, Sajal Kumar Mishra1•
NIIT1
01 Feb 2018-Computers & Electrical Engineering
TL;DR: This study shows that Nikooghadam etal's proposed authentication and key agreement protocol is susceptible to insider, replay, and password-guessing attacks, and proposes a more secure authentication system that can withstand discrete attacks.
Proceedings Article•10.1109/DSC.2018.00143•
BlockCAM: A Blockchain-Based Cross-Domain Authentication Model

[...]

Wentong Wang1, Ning Hu1, Xin Liu2•
National University of Defense Technology1, Changsha University2
18 Jun 2018
TL;DR: A blockchain-based cross-domain authentication model called BlockCAM is proposed, which has the characteristics of decentralization, anonymity and temper-resistant, and the existing public key infrastructure cross- domain authentication schemes at efficiency.
Abstract: In a distributed network environment, companies and institutions have their own sharing resource. To prevent unauthorized users to access these shared resources, cross-domain authentication is necessary. For ensuring the safety and efficiency to access resources in different domain, we propose a blockchain-based cross-domain authentication model called BlockCAM and designed the cross-domain authentication protocol. BlockCAM employs consortium blockchain technology to construct a decentralized network with the root Certificate Authorities as the verification nodes. The hash values of the authorized certificates are stored in each block and the verification process only needs to compare whether the hash calculated by the certificate provided by the user is consistent with the hash stored in the blockchain. The authentication process omits the key encryption and decryption overhead. BlockCAM has the characteristics of decentralization, anonymity and temper-resistant. Analyses show that BlockCAM has the advantage over the existing public key infrastructure (PKI) cross-domain authentication schemes at efficiency.
Journal Article•10.1007/S11227-016-1861-1•
A secure ECC-based RFID mutual authentication protocol for internet of things

[...]

Amjad Ali Alamr1, Firdous Kausar1, Jongsung Kim2, Changho Seo3•
Islamic University1, Kookmin University2, Kongju National University3
01 Sep 2018-The Journal of Supercomputing
TL;DR: A new radio-frequency identification authentication protocol based on elliptic curve cryptography (ECC) to eliminate vulnerabilities in RFID systems, which is implemented in real RFID system using Omnikey smartcard reader and NXP Java smartcards.
Abstract: Progression of the internet technologies has led to the emergence of internet of things (IoT). One of the familiar deployment of IoT is through radio-frequency identification (RFID) technology. In recent times, RFID based systems are one of the most widely spread applications for tagging and keep tracking purposes in IoT deployment. This is due to their powerful features compared to their counterparts of similar techniques such as barcodes. In contrast, radio-frequency identification systems suffer from various attacks and security threats. The wireless channel used for communication is responsible for the majority of these vulnerabilities. In this paper, we propose a new radio-frequency identification authentication protocol based on elliptic curve cryptography (ECC) to eliminate these vulnerabilities. In addition, we use elliptic curve Diffie–Hellman (ECDH) key agreement protocol to generate a temporary shared key used to encrypt the later transmitted messages. Our protocol achieves a set of security properties likes mutual authentication, anonymity, confidentiality, forward security, location privacy, resistance of man-in-the-middle attack, resistance of replay attack and resistance of impersonation attack. We implement our proposed protocol in real RFID system using Omnikey smartcard reader (Omnikey 5421) and NXP Java smartcards (J3A040). Implementation results shows that our proposed protocol outperform in term of time complexity as compared to other similar protocols and requires less number of operations.
Journal Article•10.1109/TII.2017.2778090•
Privacy-Preserving Authentication and Key Agreement Protocols for D2D Group Communications

[...]

Mingjun Wang1, Zheng Yan1•
Xidian University1
01 Aug 2018-IEEE Transactions on Industrial Informatics
TL;DR: This paper proposes two privacy-preserving authentication and key Agreement protocols (PPAKA-HAMC and PPAka-IBS) to guarantee secure and anonymous D2D group communications.
Abstract: Device-to-Device (D2D) communications play a key role in the next generation mobile communication networks and wireless systems (5G) and the Internet of Things ecosystem. D2D group communications are significant for group based services. In spite of its benefits, new application scenarios and new system architecture expose the D2D group communications to unique security threats. Although there are numerous studies on security and privacy in two-user D2D communications, a lack of solutions on secure and privacy-preserving D2D group communications would restrict their wide usage. In this paper, we propose two privacy-preserving authentication and key Agreement protocols (PPAKA-HAMC and PPAKA-IBS) to guarantee secure and anonymous D2D group communications. In our protocols, a group of D2D users mutually authenticate with each other without leaking their identity information while negotiate a common D2D group session key for secure communications in a D2D session. Formal security analysis and comprehensive performance evaluation show security and effectivity of our protocols.
Journal Article•10.1007/S12652-018-1006-X•
Authentication protocols for the internet of drones: taxonomy, analysis and future directions

[...]

Mohammad Wazid, Ashok Kumar Das1, Jong-Hyouk Lee2•
International Institute of Information Technology, Hyderabad1, Sangmyung University2
31 Aug 2018-Journal of Ambient Intelligence and Humanized Computing
TL;DR: An authentication model used in the IoD communication is discussed, and a rigorous comparative study of the existing schemes is done based on functionality features, security attacks, and also communication and computation costs.
Abstract: The Internet of Drones (IoD) provides the coordinated access to controlled airspace for the Unmanned Aerial Vehicles (called drones). The on-going cheaper costs of sensors and processors, and also wireless connectivity make it feasible to use the drones for several applications ranging from military to civilian. Since most of the applications using the drones involved in the IoD are real-time based applications, the users (external parties) usually have their interest in getting the real-time services from the deployed drones belonging to a particular fly zone. To address this important issue in the IoD, there is a great need of an efficient and secure user authentication approach in which an authorized user (for example, a driver of an ambulance) in the IoD environment can be given access to the data directly from an accessed drone. In this article, we first discuss an authentication model used in the IoD communication. We then discuss some security challenges and requirements for the IoD environment. A taxonomy of various security protocols in the IoD environment is also discussed. We then emphasis on the study of some recently proposed user authentication schemes for the IoD communication. A detailed comparative study is done based on functionality features, security attacks, and also communication and computation costs. Through the rigorous comparative study of the existing schemes, we identify the strengths and weaknesses of the user authentication schemes for the IoD communication. Finally, we identify some of the challenges for the IoD that need to be addressed in the coming future.
Journal Article•10.1109/TITS.2017.2712772•
Reliable Cooperative Authentication for Vehicular Networks

[...]

Hyo Jin Jo1, In Seok Kim2, Dong Hoon Lee2•
University of Pennsylvania1, Center for Information Security Technologies2
01 Apr 2018-IEEE Transactions on Intelligent Transportation Systems
TL;DR: This paper proposes an anonymous authentication protocol based on a cooperative authentication method that does not require mode synchronization between cooperative and non-cooperative authentication, and designs a two-layer pseudo-identity generation method and construct a key update tree for efficient revocation.
Abstract: Vehicular ad-hoc networks (VANETs) have been researched with regard to enhance driver’s safety and comfort. In VANETs, all vehicles share their status and road conditions with neighboring nodes by periodically generating safety messages. To provide reliable VANET services, message authentication is an important feature. In particular, anonymous message authentication has attracted considerable interest, because periodic broadcast messages from a vehicle can be used to track its location. Unfortunately, previously proposed anonymous message authentication protocols had serious practical shortcomings, including high communication, authentication, and revocation costs, as well as reliability issues. Thus, in this paper, we propose an anonymous authentication protocol based on a cooperative authentication method. The proposed method does not require mode synchronization between cooperative and non-cooperative authentication. In addition, we design a two-layer pseudo-identity generation method and construct a key update tree for efficient revocation. Simulations show that our protocol does not result in packet losses caused by authentication overheads, even when the vehicle density is 200/km2.
Journal Article•10.1109/TIFS.2017.2777787•
PrivBioMTAuth: Privacy Preserving Biometrics-Based and User Centric Protocol for User Authentication From Mobile Phones

[...]

Hasini Gunasinghe1, Elisa Bertino1•
Purdue University1
01 Apr 2018-IEEE Transactions on Information Forensics and Security
TL;DR: A privacy preserving biometrics-based authentication solution by which users can authenticate to different service providers from mobile phones without involving identity providers in the transactions by using a machine learning-based classification technique.
Abstract: We introduce a privacy preserving biometrics-based authentication solution by which users can authenticate to different service providers from mobile phones without involving identity providers in the transactions. Authentication is performed via zero-knowledge proof of knowledge, based on a cryptographic identity token that encodes the biometric identifier of the user and a secret provided by the user, making it three-factor authentication. Our approach for generating a unique, repeatable, and revocable biometric identifier from the user’s biometric image is based on a machine learning-based classification technique, which involves the features extracted from the user’s biometric image. We have implemented a prototype of the proposed authentication solution and evaluated our solution with respect to its performance, security, and privacy. The evaluation has been performed on a public data set of face images.
Proceedings Article•10.1145/3243734.3243839•
PASTA: PASsword-based Threshold Authentication

[...]

Shashank Agrawal, Peihan Miao1, Payman Mohassel, Pratyay Mukherjee•
University of California, Berkeley1
15 Oct 2018
TL;DR: This work is the first to introduce and formalize the notion of password-based threshold token-based authentication which distributes the role of an identity provider among n servers, and introduces PASTA, a general framework that can be instantiated using any threshold token generation scheme.
Abstract: Token-based authentication is commonly used to enable a single-sign-on experience on the web, in mobile applications and on enterprise networks using a wide range of open standards and network authentication protocols: clients sign on to an identity provider using their username/password to obtain a cryptographic token generated with a master secret key, and store the token for future accesses to various services and applications. The authentication server(s) are single point of failures that if breached, enable attackers to forge arbitrary tokens or mount offline dictionary attacks to recover client credentials. Our work is the first to introduce and formalize the notion of password-based threshold token-based authentication which distributes the role of an identity provider among n servers. Any t servers can collectively verify passwords and generate tokens, while no t-1 servers can forge a valid token or mount offline dictionary attacks. We then introduce PASTA, a general framework that can be instantiated using any threshold token generation scheme, wherein clients can "sign-on" using a two-round (optimal) protocol that meets our strong notions of unforgeability and password-safety. We instantiate and implement our framework in C++ using two threshold message authentication codes (MAC) and two threshold digital signatures with different trade-offs. Our experiments show that the overhead of protecting secrets and credentials against breaches in PASTA, i.e. compared to a naive single server solution, is extremely low (1-5%) in the most likely setting where client and servers communicate over the internet. The overhead is higher in case of MAC-based tokens over a LAN (though still only a few milliseconds) due to public-key operations in PASTA. We show, however, that this cost is inherent by proving a symmetric-key only solution impossible.
Journal Article•10.1007/S12652-017-0485-5•
A lightweight and anonymous RFID tag authentication protocol with cloud assistance for e-healthcare applications

[...]

Fan Wu, Lili Xu1, Saru Kumari2, Xiong Li3, Ashok Kumar Das4, Jian Shen5 •
Xiamen University1, Chaudhary Charan Singh University2, Hunan University of Science and Technology3, International Institute of Information Technology4, Nanjing University of Information Science and Technology5
01 Aug 2018-Journal of Ambient Intelligence and Humanized Computing
TL;DR: This work proposes a novel and lightweight RFID authentication scheme with cloud for e-healthcare applications that not only resists the common attacks, but also keeps mutual authentication, information integrity, forward untraceability and backwardUntraceability.
Abstract: As an important part of Internet of Things, Radio Frequency Identification (RFID) system employs low-cost RFID tag to communicate with everything containing animate and inanimate objects. This technology is widely used in the e-healthcare applications. However, the malicious communication environment makes people more and more worried. In order to overcome the hazards in the network, RFID authentication schemes for e-healthcare have been proposed by researchers. But since the computation ability of the tag is relatively weak, it is necessary to put forward a lightweight and secure scheme for medical systems. Moreover, cloud is widely accepted by people and used in many kinds of systems. So we propose a novel and lightweight RFID authentication scheme with cloud for e-healthcare applications. We use an enhanced formal security model to prove the security of our scheme. In this model the channel between the server and the reader is considered to be insecure and informal analysis is used to prove the security of the proposed scheme. Through the formal and informal analysis, our scheme not only resists the common attacks, but also keeps mutual authentication, information integrity, forward untraceability and backward untraceability. Moreover, both the tag and the reader can reach the anonymity. Our scheme is only hash-based and suitable to realize various security requirements. Compared to recent schemes of the same sort, it is more applicable in e-healthcare.
...

Tools

SciSpace AgentBiomedical AgentSciSpace RecruitSciSpace for EnterpriseAgent GalleryChat with PDFLiterature ReviewAI WriterFind TopicsParaphraserCitation GeneratorExtract DataAI DetectorCitation Booster

Learn

ResourcesLive Workshops

SciSpace

CareersSupportBrowse PapersPricingSciSpace Affiliate ProgramCancellation & Refund PolicyTermsPrivacyData Sources

Directories

PapersTopicsJournalsAuthorsConferencesInstitutionsCitation StylesWriting templates

Extension & Apps

SciSpace Chrome ExtensionSciSpace Mobile App

Contact

support@scispace.com
SciSpace

© 2026 | PubGenius Inc. | Suite # 217 691 S Milpitas Blvd Milpitas CA 95035, USA

soc2
Secured by Delve