Martínez-Peláez Rafael, Toral-Cruz Homero, Parra-Michel Jorge R, García Vicente, Mena Luis J, Félix Vanessa G, Ochoa-Brust Alberto
Facultad de Tecnologías de Información, Universidad De La Salle Bajío, Av. Universidad 602, León 37150, Mexico.
Department of Sciences and Engineering, University of Quintana Roo, Blvd Bahía S/N, Chetumal 77019, Mexico.
Sensors (Basel). 2019 May 6;19(9):2098. doi: 10.3390/s19092098.
With the rapid deployment of the Internet of Things and cloud computing, it is necessary to enhance authentication protocols to reduce attacks and security vulnerabilities which affect the correct performance of applications. In 2019 a new lightweight IoT-based authentication scheme in cloud computing circumstances was proposed. According to the authors, their protocol is secure and resists very well-known attacks. However, when we evaluated the protocol we found some security vulnerabilities and drawbacks, making the scheme insecure. Therefore, we propose a new version considering login, mutual authentication and key agreement phases to enhance the security. Moreover, we include a sub-phase called evidence of connection attempt which provides proof about the participation of the user and the server. The new scheme achieves the security requirements and resists very well-known attacks, improving previous works. In addition, the performance evaluation demonstrates that the new scheme requires less communication-cost than previous authentication protocols during the registration and login phases.
随着物联网和云计算的快速部署,有必要增强认证协议,以减少影响应用程序正确运行的攻击和安全漏洞。2019年,提出了一种适用于云计算环境的基于物联网的新型轻量级认证方案。据作者称,他们的协议是安全的,能很好地抵御一些广为人知的攻击。然而,当我们评估该协议时,发现了一些安全漏洞和缺陷,这使得该方案并不安全。因此,我们提出了一个新版本,考虑了登录、相互认证和密钥协商阶段,以增强安全性。此外,我们还纳入了一个名为连接尝试证据的子阶段,该子阶段提供了关于用户和服务器参与情况的证明。新方案满足了安全要求,能很好地抵御一些广为人知的攻击,改进了先前的工作。此外,性能评估表明,新方案在注册和登录阶段所需的通信成本比先前的认证协议更低。