<p>The rapid growth of fog-supported Internet of Things (IoT) networks presents significant challenges in securing efficient and scalable communication between heterogeneous devices. The age-old authentication and key management schemes like RSA and hash are prone to emergent attacks and are characterized by high computational cost. To address these challenges, the paper will present a lightweight Elliptic Curve Cryptography (ECC)-based mutual authentication and key management system, combined with the Advanced Encryption Standard (AES), to ensure the safety of data transmission. The suggested model uses a Gateway Node (GWN) as a semi-trusted intermediary to enhance the process of registration of devices, verifying their identities, and determining a session key between the IoT devices and fog nodes. Formal security analysis and mathematical formulations prove that the scheme has mutual authentication, freshness of keys, forward secrecy, and resistance to replay and impersonation attacks. Performance analysis based on NS-3 (v3.40) reveals that the proposed framework has 48% reduced latency and 35% lower cost of computation than the traditional RSA-based models, while also having good security properties. The findings affirm that the proposed ECC-AES model provides an efficient trade-off between security and computation efficiency, and can be used in real-time and resource-constrained fog-IoT systems.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Enhancing IoT communication in fog computing: a lightweight remote user authentication and key management scheme utilizing ECC

  • Nadeem Sarwar,
  • Raed S. Alharthi,
  • Hana Mohammed Mujlid,
  • Faris A. Almalki

摘要

The rapid growth of fog-supported Internet of Things (IoT) networks presents significant challenges in securing efficient and scalable communication between heterogeneous devices. The age-old authentication and key management schemes like RSA and hash are prone to emergent attacks and are characterized by high computational cost. To address these challenges, the paper will present a lightweight Elliptic Curve Cryptography (ECC)-based mutual authentication and key management system, combined with the Advanced Encryption Standard (AES), to ensure the safety of data transmission. The suggested model uses a Gateway Node (GWN) as a semi-trusted intermediary to enhance the process of registration of devices, verifying their identities, and determining a session key between the IoT devices and fog nodes. Formal security analysis and mathematical formulations prove that the scheme has mutual authentication, freshness of keys, forward secrecy, and resistance to replay and impersonation attacks. Performance analysis based on NS-3 (v3.40) reveals that the proposed framework has 48% reduced latency and 35% lower cost of computation than the traditional RSA-based models, while also having good security properties. The findings affirm that the proposed ECC-AES model provides an efficient trade-off between security and computation efficiency, and can be used in real-time and resource-constrained fog-IoT systems.