Suppr超能文献

基于 6LoWPAN 的物联网的安全远程用户认证方案。

A secure remote user authentication scheme for 6LoWPAN-based Internet of Things.

机构信息

Faculty of Computer Science and Engineering, GIK Institute of Engineering Sciences and Technology, Topi, Pakistan.

Telecommunications and Networking Research Center, GIK Institute of Engineering Sciences and Technology, Topi, Pakistan.

出版信息

PLoS One. 2021 Nov 8;16(11):e0258279. doi: 10.1371/journal.pone.0258279. eCollection 2021.

Abstract

One of the significant challenges in the Internet of Things (IoT) is the provisioning of guaranteed security and privacy, considering the fact that IoT devices are resource-limited. Oftentimes, in IoT applications, remote users need to obtain real-time data, with guaranteed security and privacy, from resource-limited network nodes through the public Internet. For this purpose, the users need to establish a secure link with the network nodes. Though the IPv6 over low-power wireless personal area networks (6LoWPAN) adaptation layer standard offers IPv6 compatibility for resource-limited wireless networks, the fundamental 6LoWPAN structure ignores security and privacy characteristics. Thus, there is a pressing need to design a resource-efficient authenticated key exchange (AKE) scheme for ensuring secure communication in 6LoWPAN-based resource-limited networks. This paper proposes a resource-efficient secure remote user authentication scheme for 6LoWPAN-based IoT networks, called SRUA-IoT. SRUA-IoT achieves the authentication of remote users and enables the users and network entities to establish private session keys between themselves for indecipherable communication. To this end, SRUA-IoT uses a secure hash algorithm, exclusive-OR operation, and symmetric encryption primitive. We prove through informal security analysis that SRUA-IoT is secured against a variety of malicious attacks. We also prove the security strength of SRUA-IoT through formal security analysis conducted by employing the random oracle model. Additionally, we prove through Scyther-based validation that SRUA-IoT is resilient against various attacks. Likewise, we demonstrate that SRUA-IoT reduces the computational cost of the nodes and communication overheads of the network.

摘要

物联网 (IoT) 面临的重大挑战之一是提供有保证的安全性和隐私性,因为 IoT 设备的资源有限。在许多 IoT 应用中,远程用户需要通过公共 Internet 从资源有限的网络节点获取具有安全性和隐私性保证的实时数据。为此,用户需要与网络节点建立安全链接。虽然低功耗无线个人区域网 (6LoWPAN) 的 IPv6 适配层标准为资源有限的无线网络提供了 IPv6 兼容性,但基本的 6LoWPAN 结构忽略了安全性和隐私性特征。因此,迫切需要设计一种资源高效的认证密钥交换 (AKE) 方案,以确保基于 6LoWPAN 的资源有限网络中的安全通信。本文提出了一种用于基于 6LoWPAN 的物联网资源有限网络的资源高效安全远程用户认证方案,称为 SRUA-IoT。SRUA-IoT 实现了远程用户的认证,并使用户和网络实体能够在彼此之间建立私有的会话密钥,以实现不可破译的通信。为此,SRUA-IoT 使用安全哈希算法、异或运算和对称加密原语。我们通过非正式安全分析证明了 SRUA-IoT 可以抵御各种恶意攻击。我们还通过采用随机 oracle 模型进行正式安全分析来证明 SRUA-IoT 的安全性强度。此外,我们通过 Scyther 验证证明了 SRUA-IoT 具有抵御各种攻击的能力。同样,我们证明了 SRUA-IoT 降低了节点的计算成本和网络的通信开销。

相似文献

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验