Suppr超能文献

通过智能卡撤销/重新发行改进无线传感器网络基于生物特征的认证方案。

Improving Biometric-Based Authentication Schemes with Smart Card Revocation/Reissue for Wireless Sensor Networks.

作者信息

Moon Jongho, Lee Donghoon, Lee Youngsook, Won Dongho

机构信息

Department of Electrical and Computer Engineering, Sungkyunkwan University, 2066 Seobu-ro, Jangan-gu, Suwon-si, Gyeonggi-do 16419, Korea.

Department of Cyber Security, Howon University, 64 Howondae 3-gil, Impi-myeon, Gunsan-si, Jeonrabuk-do 54058, Korea.

出版信息

Sensors (Basel). 2017 Apr 25;17(5):940. doi: 10.3390/s17050940.

Abstract

User authentication in wireless sensor networks is more difficult than in traditional networks owing to sensor network characteristics such as unreliable communication, limited resources, and unattended operation. For these reasons, various authentication schemes have been proposed to provide secure and efficient communication. In 2016, Park et al. proposed a secure biometric-based authentication scheme with smart card revocation/reissue for wireless sensor networks. However, we found that their scheme was still insecure against impersonation attack, and had a problem in the smart card revocation/reissue phase. In this paper, we show how an adversary can impersonate a legitimate user or sensor node, illegal smart card revocation/reissue and prove that Park et al.'s scheme fails to provide revocation/reissue. In addition, we propose an enhanced scheme that provides efficiency, as well as anonymity and security. Finally, we provide security and performance analysis between previous schemes and the proposed scheme, and provide formal analysis based on the random oracle model. The results prove that the proposed scheme can solve the weaknesses of impersonation attack and other security flaws in the security analysis section. Furthermore, performance analysis shows that the computational cost is lower than the previous scheme.

摘要

由于无线传感器网络具有诸如通信不可靠、资源有限和无人值守操作等特点,其用户认证比传统网络更困难。基于这些原因,已经提出了各种认证方案来提供安全高效的通信。2016年,Park等人提出了一种基于生物特征的安全认证方案,用于无线传感器网络,并具有智能卡撤销/重新发行功能。然而,我们发现他们的方案仍然无法抵御伪装攻击,并且在智能卡撤销/重新发行阶段存在问题。在本文中,我们展示了攻击者如何伪装成合法用户或传感器节点、进行非法的智能卡撤销/重新发行,并证明Park等人的方案无法提供撤销/重新发行功能。此外,我们提出了一种增强方案,该方案不仅提供了效率,还提供了匿名性和安全性。最后,我们对先前的方案和所提出的方案进行了安全性和性能分析,并基于随机预言模型进行了形式化分析。结果证明,所提出的方案可以解决安全分析部分中伪装攻击的弱点和其他安全缺陷。此外,性能分析表明,计算成本低于先前的方案。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/a312/5461064/3592ac36ccf9/sensors-17-00940-g001.jpg

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验