<p>Sensory data emanating from IoT for mission-critical applications warrants proper authentication and access control for its acceptance and usage. It becomes challenging to develop such efficient solutions to commensurate with the resource constraint nature of devices forming IoT. The paper addresses the critical need for robust authentication and access control in IoT applications, considering resource constraints. It presents a novel 3-factor authentication scheme, blending smart card, password, and fuzzy commitment for enhanced security. The mutual authentication attained between the key agents like remote user, Gateway node, and IoT device, with low overheads, adds novelty to our proposed scheme. Additionally, it supports dynamic key exchange for forward secrecy and time stamping to prevent replay attacks. Leveraging Elliptical Curve Cryptography and validation through Scyther and BAN logic, the scheme is resistant to attacks. Performance evaluation against existing schemes demonstrates its efficiency in communication, computation, and energy consumption, which is validated through NS3 simulation. Numeric findings reveal that the proposed scheme uses 17 hash operations, 10 ECC multiplications and 1 fuzzy extractor operation, which works out to a computational time of 88.10 ms, communication overhead of 280 bytes and energy consumption of 5241&#xa0;mJ compared to similar schemes, affirming its effectiveness.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Design of a Three-Factor Authentication and Key Agreement Scheme Using Biometric Approach for Internet of Things

  • Manasha Saqib,
  • Ayaz Hassan Moon

摘要

Sensory data emanating from IoT for mission-critical applications warrants proper authentication and access control for its acceptance and usage. It becomes challenging to develop such efficient solutions to commensurate with the resource constraint nature of devices forming IoT. The paper addresses the critical need for robust authentication and access control in IoT applications, considering resource constraints. It presents a novel 3-factor authentication scheme, blending smart card, password, and fuzzy commitment for enhanced security. The mutual authentication attained between the key agents like remote user, Gateway node, and IoT device, with low overheads, adds novelty to our proposed scheme. Additionally, it supports dynamic key exchange for forward secrecy and time stamping to prevent replay attacks. Leveraging Elliptical Curve Cryptography and validation through Scyther and BAN logic, the scheme is resistant to attacks. Performance evaluation against existing schemes demonstrates its efficiency in communication, computation, and energy consumption, which is validated through NS3 simulation. Numeric findings reveal that the proposed scheme uses 17 hash operations, 10 ECC multiplications and 1 fuzzy extractor operation, which works out to a computational time of 88.10 ms, communication overhead of 280 bytes and energy consumption of 5241 mJ compared to similar schemes, affirming its effectiveness.