Skip to main navigation Skip to search Skip to main content

Physically Secure Lightweight Anonymous User Authentication Protocol for Internet of Things Using Physically Unclonable Functions

  • Soumya Banerjee
  • , Vanga Odelu
  • , Ashok Kumar Das
  • , Samiran Chattopadhyay
  • , Joel J.P.C. Rodrigues
  • , Youngho Park
  • Jadavpur University
  • Birla Institute of Technology and Science Pilani
  • International Institute of Information Technology Hyderabad
  • Instituto Nacional de Telecomunicações
  • Instituto de Telecomunicaçies
  • Universidade Federal do Piauí

Research output: Contribution to journalArticlepeer-review

96 Scopus citations

Abstract

The Internet of Things (IoT) acts as an umbrella for the Internet-enabled devices for various applications, such as smart home, smart city, smart grid, and smart healthcare. The emergence of the immense economic potential necessitates a robust authentication mechanism that needs to be lightweight and suitable for real-time applications. Moreover, the physical integrity of these devices cannot be assumed as these are designed to be deployed in an unattended environment with minimum human supervision. A user authentication mechanism for the IoT, in addition to guaranteeing user anonymity and un-traceability functionality requirements, must also be resistant to device physical capture and related misuses. In this paper, we present a novel lightweight anonymous user authentication protocol for the IoT environment by utilizing 'cryptographic one-way hash function', 'physically unclonable function (PUF)' and 'bitwise exclusive-OR (XOR)' operations. The broadly accepted Real-Or-Random (ROR) model-based formal security analysis, formal security verification using the automated software verification tool, namely 'automated validation of internet security protocols and applications (AVISPA)' and also non-mathematical (informal) security analysis have been carried out on the proposed scheme. It is shown that the proposed scheme has the ability to resist various well-known attacks that are crucial for securing the IoT environment. Through a detailed comparative study, we show that the proposed scheme outperforms other existing related schemes in terms of computation and communication costs, and also security functionality features. Finally, a practical demonstration of the proposed scheme using the NS3 simulation has been provided for measuring various network performance parameters.

Original languageEnglish
Article number8754672
Pages (from-to)85627-85644
Number of pages18
JournalIEEE Access
Volume7
DOIs
StatePublished - 2019

UN SDGs

This output contributes to the following UN Sustainable Development Goals (SDGs)

  1. SDG 3 - Good Health and Well-being
    SDG 3 Good Health and Well-being
  2. SDG 7 - Affordable and Clean Energy
    SDG 7 Affordable and Clean Energy
  3. SDG 11 - Sustainable Cities and Communities
    SDG 11 Sustainable Cities and Communities

Keywords

  • AVISPA
  • Internet of Things (IoT)
  • key agreement
  • mutual authentication
  • physically unclonable function
  • security

Fingerprint

Dive into the research topics of 'Physically Secure Lightweight Anonymous User Authentication Protocol for Internet of Things Using Physically Unclonable Functions'. Together they form a unique fingerprint.

Cite this