Li Momo, Hu Shunfang
School of Mathematics and Computer Science, Yunnan Minzu University, Kunming 650504, China.
Sensors (Basel). 2024 Dec 13;24(24):7967. doi: 10.3390/s24247967.
Due to the openness of communication channels and the sensitivity of the data being collected and transmitted, securing data access and communication in IoT systems requires robust ECC-based authentication and key agreement (AKA) protocols. However, designing an AKA protocol for IoT presents significant challenges, as most IoT sensors are deployed in resource-constrained, unattended environments with limited computational power, connectivity, and storage. To achieve anonymous authentication, existing solutions typically rely on shared temporary public keys to mask device IDs or validate sender certificates, which increases the computational overhead. Furthermore, these protocols often fail to address crucial security concerns, such as nonresistance to ephemeral secret leakage (ESL) attacks and a lack of perfect forward security. To mitigate the computational burden, we propose a dynamic authenticated credentials (DACs) synchronization framework for anonymous authentication. Then, we introduce an ECC-based AKA scheme that employs DACs in place of temporary public keys or sender credentials, enabling efficient and secure anonymous authentication. The security of the proposed protocol was rigorously verified under the Real-or-Oracle model and validated using ProVerif. Performance comparisons demonstrate that our scheme offered significant improvements in security, with an over 37% reduction in communication cost and computational overhead.
由于通信渠道的开放性以及所收集和传输数据的敏感性,在物联网系统中确保数据访问和通信安全需要强大的基于椭圆曲线密码体制(ECC)的认证和密钥协商(AKA)协议。然而,为物联网设计一个AKA协议面临重大挑战,因为大多数物联网传感器部署在资源受限、无人值守的环境中,其计算能力、连接性和存储都有限。为了实现匿名认证,现有解决方案通常依赖共享临时公钥来掩盖设备ID或验证发送方证书,这增加了计算开销。此外,这些协议往往未能解决关键的安全问题,如无法抵御临时密钥泄露(ESL)攻击以及缺乏完美前向安全性。为了减轻计算负担,我们提出了一种用于匿名认证的动态认证凭证(DACs)同步框架。然后,我们引入了一种基于ECC的AKA方案,该方案使用DACs代替临时公钥或发送方凭证,实现高效且安全的匿名认证。所提出协议的安全性在真实或预言机模型下得到了严格验证,并使用ProVerif进行了验证。性能比较表明,我们的方案在安全性方面有显著提升,通信成本和计算开销降低了超过37%。