School of Electronics Engineering, Kyungpook National University, Daegu 41566, Korea.
Sensors (Basel). 2020 Jul 25;20(15):4143. doi: 10.3390/s20154143.
Wireless sensor networks (WSN) are composed of multiple sensor nodes with limited storage, computation, power, and communication capabilities and are widely used in various fields such as banks, hospitals, institutes to national defense, research, and so on. However, useful services are susceptible to security threats because sensitive data in various fields are exchanged via a public channel. Thus, secure authentication protocols are indispensable to provide various services in WSN. In 2019, Mo and Chen presented a lightweight secure user authentication scheme in WSN. We discover that Mo and Chen's scheme suffers from various security flaws, such as session key exposure and masquerade attacks, and does not provide anonymity, untraceability, and mutual authentication. To resolve the security weaknesses of Mo and Chen's scheme, we propose a secure and lightweight three-factor-based user authentication protocol for WSN, called SLUA-WSN. The proposed SLUA-WSN can prevent security threats and ensure anonymity, untraceability, and mutual authentication. We analyze the security of SLUA-WSN through the informal and formal analysis, including Burrows-Abadi-Needham (BAN) logic, Real-or-Random (ROR) model, and Automated Verification of Internet Security Protocols and Applications (AVISPA) simulation. Moreover, we compare the performance of SLUA-WSN with some existing schemes. The proposed SLUA-WSN better ensures the security and efficiency than previous proposed scheme and is suitable for practical WSN applications.
无线传感器网络(WSN)由具有有限存储、计算、电力和通信能力的多个传感器节点组成,广泛应用于银行、医院、研究所、国防、研究等各个领域。然而,由于各个领域的敏感数据通过公共通道交换,因此有用的服务容易受到安全威胁。因此,安全认证协议对于在 WSN 中提供各种服务是不可或缺的。2019 年,Mo 和 Chen 在 WSN 中提出了一种轻量级安全用户认证方案。我们发现 Mo 和 Chen 的方案存在各种安全缺陷,例如会话密钥暴露和伪装攻击,并且不提供匿名性、不可追踪性和相互认证。为了解决 Mo 和 Chen 方案的安全弱点,我们提出了一种用于 WSN 的安全且轻量级的三因素用户认证协议,称为 SLUA-WSN。所提出的 SLUA-WSN 可以防止安全威胁,并确保匿名性、不可追踪性和相互认证。我们通过非正式和形式分析,包括 Burrows-Abadi-Needham (BAN) 逻辑、Real-or-Random (ROR) 模型和自动化验证互联网安全协议和应用程序 (AVISPA) 模拟,分析了 SLUA-WSN 的安全性。此外,我们还比较了 SLUA-WSN 与一些现有方案的性能。与以前提出的方案相比,所提出的 SLUA-WSN 更好地确保了安全性和效率,适用于实际的 WSN 应用。