Dynamic User Authentication Protocol for Industrial IoT without Timestamping

M. Eldefrawy, Nico Ferrari, M. Gidlund
{"title":"Dynamic User Authentication Protocol for Industrial IoT without Timestamping","authors":"M. Eldefrawy, Nico Ferrari, M. Gidlund","doi":"10.1109/WFCS.2019.8757984","DOIUrl":null,"url":null,"abstract":"Internet of Things (IoT) technology has drawn the attention of the industry, where it has been able to, and still can, solve many industrial intractable issues. However, the emerging technology suffers from severe security shortcomings. Authentication is a cornerstone of IoT security, as it presents the measures of checking the legitimacy of communication entities. The Industrial IoT (IIoT) technology has special conditions, resulting from a lack of resources and a shortage of security skills. As far as we can tell, from the literature, IIoT user authentication has not been studied extensively. In 2017 Tai et al. presented an authenticated key agreement for IoT networks. Here we prove that Tai et al. scheme is susceptible to sever security weaknesses, such as; i. unknown key share attacks, ii. node capturing attacks, iii node information secrecy. In this research article, we offer an innovative IIoT user authentication protocol that can achieve secure remote user authentication without timestamping requiring precise synchronization, our protocol only needs Hashing and Xor-ing. We examine the efficiency of the presented protocol using Tmote Sky node over an MSP430 microcontroller using a COOJA simulator. we also show its correctness using the Scyther verification tool.","PeriodicalId":373657,"journal":{"name":"2019 15th IEEE International Workshop on Factory Communication Systems (WFCS)","volume":"4 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-05-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 15th IEEE International Workshop on Factory Communication Systems (WFCS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/WFCS.2019.8757984","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

Internet of Things (IoT) technology has drawn the attention of the industry, where it has been able to, and still can, solve many industrial intractable issues. However, the emerging technology suffers from severe security shortcomings. Authentication is a cornerstone of IoT security, as it presents the measures of checking the legitimacy of communication entities. The Industrial IoT (IIoT) technology has special conditions, resulting from a lack of resources and a shortage of security skills. As far as we can tell, from the literature, IIoT user authentication has not been studied extensively. In 2017 Tai et al. presented an authenticated key agreement for IoT networks. Here we prove that Tai et al. scheme is susceptible to sever security weaknesses, such as; i. unknown key share attacks, ii. node capturing attacks, iii node information secrecy. In this research article, we offer an innovative IIoT user authentication protocol that can achieve secure remote user authentication without timestamping requiring precise synchronization, our protocol only needs Hashing and Xor-ing. We examine the efficiency of the presented protocol using Tmote Sky node over an MSP430 microcontroller using a COOJA simulator. we also show its correctness using the Scyther verification tool.
无时间戳的工业物联网动态用户认证协议
物联网(IoT)技术已经引起了业界的关注,它已经能够并且仍然可以解决许多工业棘手的问题。然而,这种新兴技术存在严重的安全缺陷。身份验证是物联网安全的基石,因为它提供了检查通信实体合法性的措施。工业物联网(IIoT)技术具有特殊的条件,这是由于缺乏资源和缺乏安全技能造成的。据我们所知,从文献来看,工业物联网用户认证并没有得到广泛的研究。2017年,Tai等人提出了物联网网络的认证密钥协议。这里我们证明了Tai等人的方案容易受到严重的安全漏洞的影响,例如;1 .未知密钥共享攻击;节点捕获攻击,iii节点信息保密。在本文中,我们提供了一种创新的IIoT用户认证协议,该协议可以实现安全的远程用户认证,而不需要精确同步的时间戳,我们的协议只需要哈希和Xor-ing。我们使用COOJA模拟器在MSP430微控制器上使用Tmote Sky节点来检查所提出协议的效率。我们还使用Scyther验证工具证明了其正确性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信