{"title":"A distributed identity management and cross-domain authentication scheme for the Internet of Things","authors":"Miaomiao Wang, Ze Wang","doi":"10.1016/j.future.2025.107818","DOIUrl":null,"url":null,"abstract":"<div><div>Reliable identity management and authentication are prerequisites for secure information communication. Traditional centralized schemes rely on the Certificate Authority (CA), and their cross-domain authentication is complex, posing a risk of centralized data leakage. The advancement of blockchain technology has disrupted the traditional model, leading to the emergence of Self-Sovereign Identity (SSI) management and authentication schemes. However, the widespread adoption of SSI still faces some challenges, such as key loss and the inefficiency of MerkleTree verification. Therefore, we propose an improved distributed identity management and cross-domain authentication scheme for the Internet of Things (IoT). In this scheme, a key creation and recovery mechanism is first proposed to prevent identity unavailability caused by key loss. Then, a double one-way accumulator algorithm is designed to improve identity authentication and enhance the authentication efficiency. Our scheme has passed formal and informal security analyses, and has robust performance.</div></div>","PeriodicalId":55132,"journal":{"name":"Future Generation Computer Systems-The International Journal of Escience","volume":"169 ","pages":"Article 107818"},"PeriodicalIF":6.2000,"publicationDate":"2025-03-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Future Generation Computer Systems-The International Journal of Escience","FirstCategoryId":"94","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S0167739X2500113X","RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, THEORY & METHODS","Score":null,"Total":0}
引用次数: 0
Abstract
Reliable identity management and authentication are prerequisites for secure information communication. Traditional centralized schemes rely on the Certificate Authority (CA), and their cross-domain authentication is complex, posing a risk of centralized data leakage. The advancement of blockchain technology has disrupted the traditional model, leading to the emergence of Self-Sovereign Identity (SSI) management and authentication schemes. However, the widespread adoption of SSI still faces some challenges, such as key loss and the inefficiency of MerkleTree verification. Therefore, we propose an improved distributed identity management and cross-domain authentication scheme for the Internet of Things (IoT). In this scheme, a key creation and recovery mechanism is first proposed to prevent identity unavailability caused by key loss. Then, a double one-way accumulator algorithm is designed to improve identity authentication and enhance the authentication efficiency. Our scheme has passed formal and informal security analyses, and has robust performance.
期刊介绍:
Computing infrastructures and systems are constantly evolving, resulting in increasingly complex and collaborative scientific applications. To cope with these advancements, there is a growing need for collaborative tools that can effectively map, control, and execute these applications.
Furthermore, with the explosion of Big Data, there is a requirement for innovative methods and infrastructures to collect, analyze, and derive meaningful insights from the vast amount of data generated. This necessitates the integration of computational and storage capabilities, databases, sensors, and human collaboration.
Future Generation Computer Systems aims to pioneer advancements in distributed systems, collaborative environments, high-performance computing, and Big Data analytics. It strives to stay at the forefront of developments in grids, clouds, and the Internet of Things (IoT) to effectively address the challenges posed by these wide-area, fully distributed sensing and computing systems.