Omar Alruwaili , Muhammad Tanveer , Saud Alhajaj Aldossari , Saad Alanazi , Ammar Armghan
{"title":"RAAF-MEC: Reliable and anonymous authentication framework for IoT-enabled mobile edge computing environment","authors":"Omar Alruwaili , Muhammad Tanveer , Saud Alhajaj Aldossari , Saad Alanazi , Ammar Armghan","doi":"10.1016/j.iot.2024.101459","DOIUrl":null,"url":null,"abstract":"<div><div>The Internet of Things (IoT) devices are becoming increasingly integral to daily life, with cloud computing platforms serving as essential hubs for managing and processing the vast data generated by distributed IoT devices and sensors. The advent of 6G-powered cloud services facilitates applications such as augmented reality, virtual reality, autonomous driving, and healthcare, all of which require rapid data processing. Mobile edge computing (MEC) extends cloud capabilities to the network’s edge, enabling large-scale, real-time data processing. However, this transition introduces security challenges due to the open nature of MEC infrastructures, which increases the risk of data breaches and privacy violations. To address these challenges, RAAF-MEC is proposed as an innovative authentication framework designed specifically for IoT-enabled MEC environments. The framework incorporates hash functions, PUF, ECC, and GIFT-COFB. GIFT-COFB, a lightweight encryption mechanism, and NIST finalist, ensures data authenticity and integrity. PUF technology, integrated on the MEC server side, dynamically derives secret keys, mitigating the risk of privileged insider attacks by eliminating the need to store keys in the MEC server’s database. This approach enhances security by preventing unauthorized access to sensitive key material. RAAF-MEC also supports single sign-on for seamless access across MEC servers. The effectiveness of RAAF-MEC has been validated through comprehensive formal and informal security assessments, as well as performance evaluations against existing authentication frameworks. Our results show that RAAF-MEC reduces computational costs by 27.3% to 52.12% and communication costs by 69.44% to 75%, while significantly enhancing security features.</div></div>","PeriodicalId":29968,"journal":{"name":"Internet of Things","volume":"29 ","pages":"Article 101459"},"PeriodicalIF":6.0000,"publicationDate":"2025-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Internet of Things","FirstCategoryId":"94","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2542660524004001","RegionNum":3,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0
Abstract
The Internet of Things (IoT) devices are becoming increasingly integral to daily life, with cloud computing platforms serving as essential hubs for managing and processing the vast data generated by distributed IoT devices and sensors. The advent of 6G-powered cloud services facilitates applications such as augmented reality, virtual reality, autonomous driving, and healthcare, all of which require rapid data processing. Mobile edge computing (MEC) extends cloud capabilities to the network’s edge, enabling large-scale, real-time data processing. However, this transition introduces security challenges due to the open nature of MEC infrastructures, which increases the risk of data breaches and privacy violations. To address these challenges, RAAF-MEC is proposed as an innovative authentication framework designed specifically for IoT-enabled MEC environments. The framework incorporates hash functions, PUF, ECC, and GIFT-COFB. GIFT-COFB, a lightweight encryption mechanism, and NIST finalist, ensures data authenticity and integrity. PUF technology, integrated on the MEC server side, dynamically derives secret keys, mitigating the risk of privileged insider attacks by eliminating the need to store keys in the MEC server’s database. This approach enhances security by preventing unauthorized access to sensitive key material. RAAF-MEC also supports single sign-on for seamless access across MEC servers. The effectiveness of RAAF-MEC has been validated through comprehensive formal and informal security assessments, as well as performance evaluations against existing authentication frameworks. Our results show that RAAF-MEC reduces computational costs by 27.3% to 52.12% and communication costs by 69.44% to 75%, while significantly enhancing security features.
期刊介绍:
Internet of Things; Engineering Cyber Physical Human Systems is a comprehensive journal encouraging cross collaboration between researchers, engineers and practitioners in the field of IoT & Cyber Physical Human Systems. The journal offers a unique platform to exchange scientific information on the entire breadth of technology, science, and societal applications of the IoT.
The journal will place a high priority on timely publication, and provide a home for high quality.
Furthermore, IOT is interested in publishing topical Special Issues on any aspect of IOT.