An Anonymous Authentication Scheme with Low Overhead for Cross-Domain IoT
摘要
In a decentralized Internet of things (IoT) environment, it is inevitable that devices from different administrative domains communicate and collaborate with each other, yet there is often a lack of trust among them. In this case, it is necessary to design a reliable authentication scheme to ensure the secure cross-domain access of devices. However, existing cross-domain authentication schemes suffer from a number of issues that have not been fully considered. On the one hand, as one of techniques commonly used for cross-domain authentication, blockchain has limitations in storage capacity and throughput speed. On the other hand, users’ privacy and sensitive information are not strictly protected. In this paper, we propose a certificateless cross-domain authentication scheme that combines low overhead and anonymity, named CALA. The cryptographic theory of CALA is Certificateless Public Key Cryptography (CL-PKC) mechanism, which relies on a semi-trusted third party and gets rid of the key escrow problem. To reduce the storage overhead and enable light-weight data verification, we design a storage structure named Merkle Hash Tree Grid Combination (MHTGC) for data management. To preserve the privacy of users, we propose an anonymous authentication protocol based on Zero-Knowledge Proof (ZKP) algorithm. The security analysis and experimental results demonstrate the effectiveness of our scheme.