Faculty of Computing and Information Sciences, University of Bisha, Bisha, Saudi Arabia.
Higher Education Department of Khyber Pakhtunkhwa, Govt College Wari (Dir Upper), Peshawar, Pakistan.
PLoS One. 2024 Mar 21;19(3):e0298276. doi: 10.1371/journal.pone.0298276. eCollection 2024.
The Internet has advanced so quickly that we can now access any service at any time, from any location. As a result of this capability, People around the world can benefit from the popularity and convenience of teleworking systems. Teleworking systems, however, are vulnerable to a range of attacks; as an unauthorized user enters the open communication line and compromises the whole system, that, in turn, creates a big hurdle for the teleworkers. Professional groups have presented numerous mechanisms for the security of teleworking systems to stop any harm, but there are still a lot of security issues like insider, stolen verifier, masquerade, replay, traceability and impersonation threats. In this paper, we propose that one of the security issues with teleworking systems is the lack of a secure authentication mechanism. In order to provide a secure teleworking environment, we have proposed a lightweight and secure protocol to authenticate all the participants and make the requisite services available in an efficient manner. The security analysis of the presented protocol has been investigated formally using the random oracle model (ROM) and ProVerif simulation and informally through illustration/attack discussions. Meanwhile, the performance metrics have been measured by considering computation and communication overheads. Upon comparing the proposed protocol with prior works, it has been demonstrated that our protocol is superior to its competitors. It is suitable for implementation because it achieved a 73% improvement in computation and 34% in communication costs.
互联网发展迅速,现在人们可以随时随地访问任何服务。由于这种功能,世界各地的人们都可以从远程办公系统的普及和便利中受益。然而,远程办公系统容易受到各种攻击;当未经授权的用户进入开放的通信线路并危及整个系统时,这反过来又给远程办公人员带来了很大的障碍。专业团体已经提出了许多远程办公系统安全机制来阻止任何伤害,但仍存在许多安全问题,如内部人员、被盗验证器、伪装、重放、可追溯性和冒充威胁。在本文中,我们提出远程办公系统的安全问题之一是缺乏安全的身份验证机制。为了提供安全的远程办公环境,我们提出了一种轻量级和安全的协议来对所有参与者进行身份验证,并以高效的方式提供必要的服务。通过随机Oracle 模型(ROM)和 ProVerif 模拟以及通过说明/攻击讨论进行的非正式安全分析,对提出的协议进行了研究。同时,通过考虑计算和通信开销来衡量性能指标。通过将提出的协议与先前的工作进行比较,证明了我们的协议优于竞争对手。它适合实施,因为它在计算方面提高了 73%,在通信成本方面提高了 34%。