An IoT-Enabled Cloud Computing Model for Authentication and Data Confidentiality using Lightweight Cryptography
摘要
The Internet of Things (IoT) is a rapidly growing technology with diverse applications across various sectors to enhance service quality and productivity. With the emergence of advanced mobile communication technologies like 5G/6G, users and cloud service providers can seamlessly leverage IoT and sensor networks to transmit sensitive data. However, secure data transmission against modern threats remains a critical challenge, as existing mechanisms often lack robustness. This paper proposes a novel secure framework that integrates biometric-based multi-factor authentication for a user, a lightweight key exchange method for IoT devices, enabling mutual authentication with cloud server and a hybrid encryption approach utilizing elliptic curve cryptography (ECC) and the genetic algorithm. The process begins with user authentication using biometrics, username, and password, followed by the authentication of the IoT device. Subsequently, the encrypted sensor data are transmitted to the cloud server. The framework includes the SHA-512 algorithm in the authentication process to ensure integrity. To improve the security of the system, a dynamic secret key is generated using ECC to enhance cryptographic complexity and resilience against attacks. The cost of the computation of the suggested framework is 4 h + Et + Dt, presenting a reduction over to the existing methods. The average value of the avalanche effect is about 0.55, demonstrating the strength of the algorithm. The average time of encryption and decryption was 0.588 ms and 0.538 ms, respectively. The proposed algorithm’s performance is evaluated by comparing it with existing state-of-the-art algorithms, such as DES, AES, 3DES, RSA, and Blowfish.