Choi Younsung, Lee Donghoon, Kim Jiye, Jung Jaewook, Nam Junghyun, Won Dongho
College of Information and Communication Engineering, Sungkyunkwan University, Jangangu, Suwonsi, Gyeonggido 440-746, Korea.
Department of Computer Engineering, Konkuk University, 268 Chungwondaero, Chungju, Chungcheongbukdo 380-701, Korea.
Sensors (Basel). 2014 Jun 10;14(6):10081-106. doi: 10.3390/s140610081.
Wireless sensor networks (WSNs) consist of sensors, gateways and users. Sensors are widely distributed to monitor various conditions, such as temperature, sound, speed and pressure but they have limited computational ability and energy. To reduce the resource use of sensors and enhance the security of WSNs, various user authentication protocols have been proposed. In 2011, Yeh et al. first proposed a user authentication protocol based on elliptic curve cryptography (ECC) for WSNs. However, it turned out that Yeh et al.'s protocol does not provide mutual authentication, perfect forward secrecy, and key agreement between the user and sensor. Later in 2013, Shi et al. proposed a new user authentication protocol that improves both security and efficiency of Yeh et al.'s protocol. However, Shi et al.'s improvement introduces other security weaknesses. In this paper, we show that Shi et al.'s improved protocol is vulnerable to session key attack, stolen smart card attack, and sensor energy exhausting attack. In addition, we propose a new, security-enhanced user authentication protocol using ECC for WSNs.
无线传感器网络(WSN)由传感器、网关和用户组成。传感器广泛分布以监测各种状况,如温度、声音、速度和压力,但它们的计算能力和能量有限。为了减少传感器的资源使用并增强无线传感器网络的安全性,人们提出了各种用户认证协议。2011年,Yeh等人首次为无线传感器网络提出了一种基于椭圆曲线密码学(ECC)的用户认证协议。然而,事实证明,Yeh等人的协议并未提供相互认证、完美前向保密性以及用户与传感器之间的密钥协商。后来在2013年,Shi等人提出了一种新的用户认证协议,该协议提高了Yeh等人协议的安全性和效率。然而,Shi等人的改进引入了其他安全弱点。在本文中,我们表明Shi等人的改进协议容易受到会话密钥攻击、智能卡被盗攻击和传感器能量耗尽攻击。此外,我们提出了一种新的、使用椭圆曲线密码学增强安全性的无线传感器网络用户认证协议。