Chen Yongle, Wang Xiaojian, Yang Yuli, Li Hong
College of Information and Computer, Taiyuan University of Technology, Taiyuan 030024, China.
Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100089, China.
Sensors (Basel). 2020 Feb 15;20(4):1062. doi: 10.3390/s20041062.
Advanced wireless technology in Internet of Things (IoT) devices is increasing and facing various security threats. The authentication of IoT devices is the first line of defense for the wireless network. Especially in a Wi-Fi network, the existing authentication methods mainly use a password or digital certificate, these methods are inconvenient to manage due to certificate issuance or prone to be attacked because passwords are easily cracked. In this paper, we propose a location-aware authentication scheme using smart contracts to ensure that IoT devices can securely perform Wi-Fi network authentication. The scheme adopts the concept of secondary authentication and consists of two phases: the registration phase, which is mainly designed to complete the generation of the public and private keys, and to link the device information with its related device information; the authentication phase, which is mainly designed to determine whether the requesting device is within a legal location range. We use the smart contract to ensure the credibility and irreparability of the authentication process. Analysis of the attack model and the attacks at different stages proves that this certification scheme is assured, and the simulation results show that the overhead introduced by this scheme is acceptable, this scheme can provide greater security for the Wi-Fi authentication of IoT devices.
物联网(IoT)设备中先进的无线技术不断发展,同时面临着各种安全威胁。物联网设备的认证是无线网络的第一道防线。特别是在Wi-Fi网络中,现有的认证方法主要使用密码或数字证书,这些方法由于证书颁发而管理不便,或者由于密码容易被破解而容易受到攻击。在本文中,我们提出了一种使用智能合约的位置感知认证方案,以确保物联网设备能够安全地进行Wi-Fi网络认证。该方案采用二次认证的概念,由两个阶段组成:注册阶段,主要用于完成公钥和私钥的生成,并将设备信息与其相关设备信息进行关联;认证阶段,主要用于确定请求设备是否在合法位置范围内。我们使用智能合约来确保认证过程的可信度和不可修复性。对攻击模型和不同阶段攻击的分析证明了该认证方案是可靠的,仿真结果表明该方案引入的开销是可接受的,该方案可以为物联网设备的Wi-Fi认证提供更高的安全性。