Suppr超能文献

无线传感器网络中“双因素用户认证”的密码分析和安全改进。

Cryptanalysis and security improvements of 'two-factor user authentication in wireless sensor networks'.

机构信息

Center of Excellence in Information Assurance (CoEIA), King Saud University, Saudi Arabia.

出版信息

Sensors (Basel). 2010;10(3):2450-9. doi: 10.3390/s100302450. Epub 2010 Mar 23.

Abstract

User authentication in wireless sensor networks (WSN) is a critical security issue due to their unattended and hostile deployment in the field. Since sensor nodes are equipped with limited computing power, storage, and communication modules; authenticating remote users in such resource-constrained environments is a paramount security concern. Recently, M.L. Das proposed a two-factor user authentication scheme in WSNs and claimed that his scheme is secure against different kinds of attack. However, in this paper, we show that the M.L. Das-scheme has some critical security pitfalls and cannot be recommended for real applications. We point out that in his scheme: users cannot change/update their passwords, it does not provide mutual authentication between gateway node and sensor node, and is vulnerable to gateway node bypassing attack and privileged-insider attack. To overcome the inherent security weaknesses of the M.L. Das-scheme, we propose improvements and security patches that attempt to fix the susceptibilities of his scheme. The proposed security improvements can be incorporated in the M.L. Das-scheme for achieving a more secure and robust two-factor user authentication in WSNs.

摘要

在无线传感器网络(WSN)中,用户认证是一个关键的安全问题,因为它们在野外无人值守且环境恶劣。由于传感器节点配备了有限的计算能力、存储和通信模块,因此在这种资源受限的环境中对远程用户进行认证是一个至关重要的安全问题。最近,M.L. Das 在 WSN 中提出了一种两因素用户认证方案,并声称他的方案可以抵御各种类型的攻击。然而,在本文中,我们表明 M.L. Das 方案存在一些严重的安全缺陷,不建议用于实际应用。我们指出,在他的方案中:用户无法更改/更新他们的密码,它没有提供网关节点和传感器节点之间的相互认证,并且容易受到网关节点旁路攻击和特权内部人员攻击。为了克服 M.L. Das 方案的固有安全弱点,我们提出了改进和安全补丁,试图修复他的方案的弱点。所提出的安全改进可以被合并到 M.L. Das 方案中,以实现 WSN 中更安全和强大的两因素用户认证。

相似文献

引用本文的文献

本文引用的文献

1
An overview on wireless sensor networks technology and evolution.无线传感器网络技术概述及其发展。
Sensors (Basel). 2009;9(9):6869-96. doi: 10.3390/s90906869. Epub 2009 Aug 31.

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验