TY - JOUR
T1 - An Improved Lightweight PUF-PKI Digital Certificate Authentication Scheme for the Internet of Things
AU - Siddiqui, Zeeshan
AU - Gao, Jiechao
AU - Khan, Muhammad Khurram
N1 - Funding information: King Saud University (Grant Number: RSP-2021/12).
PY - 2022/4/19
Y1 - 2022/4/19
N2 - Prosanta and Biplab presented a lightweight two-factor authentication scheme for the Internet of Things (IoT) devices based on Physical Unclonable Function (PUF). Their presented scheme was based on Fuzzy Extractor and analyzed various security reasonings, such as mutual authentication, session key agreement, privacy and protection against impersonation, message tampering and replay attacks. In this paper, we present sufficient security analysis to demonstrate that the scheme has various security and privacy issues in its setup and authentication phases. We propose a highly secure and robust authentication protocol based on a PKI digital certificate based on two Certificate Authority (CA) for cloud IoT systems. The proposed authentication method is verified and validated using Tamarin Prover and supported with a detailed security and performance analysis discussion. The scheme security and privacy attributes are compared with other IoT authentication schemes. The analysis has proved that the proposed authentication scheme is more secure and highly reliable as compared to Prosanta and Biplab authentication scheme.
AB - Prosanta and Biplab presented a lightweight two-factor authentication scheme for the Internet of Things (IoT) devices based on Physical Unclonable Function (PUF). Their presented scheme was based on Fuzzy Extractor and analyzed various security reasonings, such as mutual authentication, session key agreement, privacy and protection against impersonation, message tampering and replay attacks. In this paper, we present sufficient security analysis to demonstrate that the scheme has various security and privacy issues in its setup and authentication phases. We propose a highly secure and robust authentication protocol based on a PKI digital certificate based on two Certificate Authority (CA) for cloud IoT systems. The proposed authentication method is verified and validated using Tamarin Prover and supported with a detailed security and performance analysis discussion. The scheme security and privacy attributes are compared with other IoT authentication schemes. The analysis has proved that the proposed authentication scheme is more secure and highly reliable as compared to Prosanta and Biplab authentication scheme.
KW - Authentication
KW - Digital Certificate.
KW - Internet of Things
KW - IoT Security
KW - Performance evaluation
KW - Physical Unclonable Function (PUF)
KW - Physical unclonable function
KW - Protocols
KW - Remote User Authentication
KW - Security
KW - Servers
UR - http://www.scopus.com/inward/record.url?scp=85129152623&partnerID=8YFLogxK
U2 - 10.1109/JIOT.2022.3168726
DO - 10.1109/JIOT.2022.3168726
M3 - Article
SN - 2327-4662
JO - IEEE Internet of Things Journal
JF - IEEE Internet of Things Journal
ER -