A lightweight pairing-free authentication key agreement protocol with anonymity for mobile edge computing infrastructure
摘要
Due to the significance of mobile edge computing (MEC) in people’s daily lives, both its security and efficiency have drawn a lot of attention. In the MEC environment, Internet of Things (IoT) terminal equipment (TE) are typically resource-constrained devices. It becomes crucial to design a provably secure lightweight authentication key agreement (AKA) protocol to guarantee data security. However, existing AKA protocols struggle to meet lightweight requirements due to their reliance on bilinear pairings. Recently, Xie et al. construct an AKA protocol by using bilinear pairings for MEC infrastructure. Unfortunately, we find that their AKA protocol is vulnerable to known session-specific temporary information (KSSTI) attack and temporary key leakage impersonation attack. To resolve these issues, an improved lightweight anonymous AKA protocol without bilinear pairing for MEC infrastructure is proposed in this paper. We conduct a comprehensive security analysis of the new protocol by utilizing BAN logic. In additional, the new protocol is untraceable, offline register center, perfect forward security, resistant to replay attacks, insider attacks, etc. Compared to previous protocols, our solution offers higher security and lower computational and communication overheads.