节点文献

基于PUF的轻量级雾辅助物联网认证协议

PUF-Based Lightweight Authentication Protocols for Fog Assisted IoT

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 郭奕旻张振峰熊平郭亚军

【Author】 GUO Yi-Min;ZHANG Zhen-Feng;XIONG Ping;GUO Ya-Jun;School of Information and Safety Engineering,Zhongnan University of Economics and Law;Trusted Computing and Information Assurance Laboratory,Institute of Software,Chinese Academy of Sciences;School of Computer,Central China Normal University;

【机构】 中南财经政法大学信息与安全工程学院中国科学院软件研究所可信计算与信息保障实验室华中师范大学计算机学院

【摘要】 雾计算将云计算的功能扩展到网络边缘,是各类物联网应用的最佳解决方案.但是雾计算独特的特性给雾辅助的物联网也带来了新的安全性问题,特别是物联网设备与雾节点之间的认证问题.在雾辅助的物联网中,一些雾节点和物联网设备是部署在公共场所,这使得它们更容易受到各种攻击.因此,为雾辅助的物联网系统设计认证协议首先应确保安全性,即认证协议能够抵抗各种已知的攻击,特别是在雾节点不完全可信或者物联网设备被捕获时也应该是安全的.其次,认证协议应该是低延迟的,低延迟是雾计算的基本特征.最后,由于许多物联网设备资源受限,认证协议也应该是轻量级的.为了解决这些问题,本文提出了雾辅助物联网两个场景中的轻量级认证协议.两个协议都采用了物理不可克隆函数这一硬件安全原语,一种实现了物联网设备与雾节点之间的相互认证,另一种实现了远程用户通过雾节点安全访问物联网设备.协议中任何实体均不存储显式的挑战-响应对和其他敏感信息,具备显著安全优势.对两个协议的形式化安全、非形式化安全和性能分析表明,所提出的认证协议不仅在各种已知攻击下具有鲁棒性,且具有较少的计算和通信代价.

【Abstract】 Fog computing is a new distributed computing paradigm that extends cloud computing services to the edge of the network,which has the characteristics of low latency,low bandwidth consumption,high reliability,high security,and high quality of experience.Therefore,fog computing is considered to be the most effective solution for supporting IoT applications.However,the unique characteristics of fog computing have also brought new security issues to the fog-assisted IoT,especially the authentication problem between IoT devices and fog nodes.Fog-enabled IoT is composed of the cloud layer,fog layer,and device layer.It is a decentralized distributed computing environment with multiple different trust domains.Among them,the cloud layer is trustworthy,but the fog layer and the device layer are not necessarily trustworthy.Fog nodes are usually deployed by different providers,and they can also automatically join or leave the network.Moreover,some fog nodes are deployed in public places and are easily destroyed.IoT devices belong to different owners and do not trust each other.In addition,IoT devices are usually deployed in places that are not strictly monitored and protected and are easy to be invaded,destroyed,or stolen by attackers.Therefore,the authentication protocol designed for the fog-assisted IoT system first ensures the security,that is,the authentication protocol can resist various known attacks,especially when the fog nodes are not completely trusted or the IoT devices are captured.Secondly,the authentication protocol should also be low-latency,which is the basic feature of fog computing.Finally,since many IoT devices are resource-constrained,the authentication protocol should also be lightweight.In order to solve these problems,this paper proposes two lightweight authentication protocols in two scenarios of fog-assisted IoT.Both protocols use the hardware security primitive of Physically Unclonable Functions(PUF).One implements mutual authentication between IoT devices and fog nodes,and the other implements remote users to securely access IoT devices through fog nodes.The two proposed protocols have the following advantages:(1) The two protocols can ensure the physical security of IoT devices and user devices,and can resist the compromised attack of fog nodes.(2) In the two protocols,no explicit challenge-response pairs(CRPs) are stored in any party participating in the authentication,thereby eliminating the security risk that CRPs must be stored in the "challenge-response" authentication mechanism using PUFs.(3) In the authentication process,the piggyback method is used to check the synchronization of the message,which can effectively prevent the desynchronization attack without adding any burden.(4) Both authentication protocols are lightweight.We employ the widely-accepted ROR model to perform formal security analysis on the two proposed protocols,and the results show that the two protocols are provably secure.We further use informal security analysis to find that the proposed scheme has robust security and can resist more known attacks than other existing schemes.Finally,we evaluate the performance of the two proposed protocols from the aspects of security features,communication cost,and computation cost.The results show that the proposed protocols outperform the existing protocols.

【基金】 国家自然科学基金(62102453);中南财经政法大学中央高校基本科研业务费专项资金(2722022BQ049)资助~~
  • 【文献出处】 计算机学报 ,Chinese Journal of Computers , 编辑部邮箱 ,2022年07期
  • 【分类号】TP391.44;TN929.5
  • 【下载频次】139
节点文献中: 

本文链接的文献网络图示:

本文的引文网络