MSAUPL:基于用户隐私级别的工业物联网多服务器认证和密钥协议协议

IF 3.8 2区 计算机科学 Q2 COMPUTER SCIENCE, INFORMATION SYSTEMS
Yi Wu , Tao Feng , Chunhua Su , Chunyan Liu
{"title":"MSAUPL:基于用户隐私级别的工业物联网多服务器认证和密钥协议协议","authors":"Yi Wu ,&nbsp;Tao Feng ,&nbsp;Chunhua Su ,&nbsp;Chunyan Liu","doi":"10.1016/j.jisa.2025.103991","DOIUrl":null,"url":null,"abstract":"<div><div>With the rapid development of the Industrial Internet of Things (IIoT), industrial control systems are characterized by increasing complexity of access users and diversity of data sources, making it crucial to implement hierarchical data transmission protocols for industrial servers based on user privacy level. However, traditional industrial systems often lack the flexibility to provide hierarchical services to access users according to their privacy level, leading to frequent incidents of data or privacy disclosure. This study addresses the need for hierarchical data services for various access users in an IIoT environment by proposing a multi-server authentication and key agreement protocol based on user privacy level (MSAUPL). To enhance the security and integrity of message transmission, a multi-factor authentication mechanism is adopted. Considering the computational and storage limitations of IIoT devices, the MSAUPL protocol primarily relies on hash functions for authentication and key agreement. Moreover, to allow access users to derive keys with lower privilege level after completing a single authentication for their privacy level, a key derivation scheme based on a directed graph is introduced. Additionally, to alleviate the storage burden on servers, a multi-level user privilege scheme based on a Merkle tree structure is proposed, enabling servers to efficiently compute different user access level. Finally, security analysis and comprehensive performance evaluation demonstrate that the MSAUPL protocol not only enhances functionality but also significantly reduces resource consumption, making it well-suited for multi-server IIoT environments.</div></div>","PeriodicalId":48638,"journal":{"name":"Journal of Information Security and Applications","volume":"89 ","pages":"Article 103991"},"PeriodicalIF":3.8000,"publicationDate":"2025-02-11","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"MSAUPL: A multi-server authentication and key agreement protocol for industrial IoT based on user privacy level\",\"authors\":\"Yi Wu ,&nbsp;Tao Feng ,&nbsp;Chunhua Su ,&nbsp;Chunyan Liu\",\"doi\":\"10.1016/j.jisa.2025.103991\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><div>With the rapid development of the Industrial Internet of Things (IIoT), industrial control systems are characterized by increasing complexity of access users and diversity of data sources, making it crucial to implement hierarchical data transmission protocols for industrial servers based on user privacy level. However, traditional industrial systems often lack the flexibility to provide hierarchical services to access users according to their privacy level, leading to frequent incidents of data or privacy disclosure. This study addresses the need for hierarchical data services for various access users in an IIoT environment by proposing a multi-server authentication and key agreement protocol based on user privacy level (MSAUPL). To enhance the security and integrity of message transmission, a multi-factor authentication mechanism is adopted. Considering the computational and storage limitations of IIoT devices, the MSAUPL protocol primarily relies on hash functions for authentication and key agreement. Moreover, to allow access users to derive keys with lower privilege level after completing a single authentication for their privacy level, a key derivation scheme based on a directed graph is introduced. Additionally, to alleviate the storage burden on servers, a multi-level user privilege scheme based on a Merkle tree structure is proposed, enabling servers to efficiently compute different user access level. Finally, security analysis and comprehensive performance evaluation demonstrate that the MSAUPL protocol not only enhances functionality but also significantly reduces resource consumption, making it well-suited for multi-server IIoT environments.</div></div>\",\"PeriodicalId\":48638,\"journal\":{\"name\":\"Journal of Information Security and Applications\",\"volume\":\"89 \",\"pages\":\"Article 103991\"},\"PeriodicalIF\":3.8000,\"publicationDate\":\"2025-02-11\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Journal of Information Security and Applications\",\"FirstCategoryId\":\"94\",\"ListUrlMain\":\"https://www.sciencedirect.com/science/article/pii/S2214212625000298\",\"RegionNum\":2,\"RegionCategory\":\"计算机科学\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q2\",\"JCRName\":\"COMPUTER SCIENCE, INFORMATION SYSTEMS\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Information Security and Applications","FirstCategoryId":"94","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2214212625000298","RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q2","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0

摘要

随着工业物联网(IIoT)的快速发展,工业控制系统接入用户的复杂性和数据源的多样性日益增加,实现基于用户隐私级别的工业服务器分层数据传输协议变得至关重要。然而,传统工业系统往往缺乏灵活性,无法根据用户的隐私级别提供分层服务来访问用户,导致数据或隐私泄露事件频繁发生。本研究通过提出基于用户隐私级别(msaul)的多服务器身份验证和密钥协议协议,解决了工业物联网环境中各种访问用户对分层数据服务的需求。为了提高消息传输的安全性和完整性,采用了多因素认证机制。考虑到工业物联网设备的计算和存储限制,msaul协议主要依靠哈希函数进行身份验证和密钥协议。此外,为了允许访问用户在完成对其隐私级别的单次认证后获得更低权限级别的密钥,引入了一种基于有向图的密钥派生方案。此外,为了减轻服务器的存储负担,提出了一种基于Merkle树结构的多级用户权限方案,使服务器能够高效地计算不同的用户访问级别。最后,安全分析和综合性能评估表明,msaul协议不仅增强了功能,而且显著降低了资源消耗,非常适合多服务器IIoT环境。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
MSAUPL: A multi-server authentication and key agreement protocol for industrial IoT based on user privacy level
With the rapid development of the Industrial Internet of Things (IIoT), industrial control systems are characterized by increasing complexity of access users and diversity of data sources, making it crucial to implement hierarchical data transmission protocols for industrial servers based on user privacy level. However, traditional industrial systems often lack the flexibility to provide hierarchical services to access users according to their privacy level, leading to frequent incidents of data or privacy disclosure. This study addresses the need for hierarchical data services for various access users in an IIoT environment by proposing a multi-server authentication and key agreement protocol based on user privacy level (MSAUPL). To enhance the security and integrity of message transmission, a multi-factor authentication mechanism is adopted. Considering the computational and storage limitations of IIoT devices, the MSAUPL protocol primarily relies on hash functions for authentication and key agreement. Moreover, to allow access users to derive keys with lower privilege level after completing a single authentication for their privacy level, a key derivation scheme based on a directed graph is introduced. Additionally, to alleviate the storage burden on servers, a multi-level user privilege scheme based on a Merkle tree structure is proposed, enabling servers to efficiently compute different user access level. Finally, security analysis and comprehensive performance evaluation demonstrate that the MSAUPL protocol not only enhances functionality but also significantly reduces resource consumption, making it well-suited for multi-server IIoT environments.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
Journal of Information Security and Applications
Journal of Information Security and Applications Computer Science-Computer Networks and Communications
CiteScore
10.90
自引率
5.40%
发文量
206
审稿时长
56 days
期刊介绍: Journal of Information Security and Applications (JISA) focuses on the original research and practice-driven applications with relevance to information security and applications. JISA provides a common linkage between a vibrant scientific and research community and industry professionals by offering a clear view on modern problems and challenges in information security, as well as identifying promising scientific and "best-practice" solutions. JISA issues offer a balance between original research work and innovative industrial approaches by internationally renowned information security experts and researchers.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信