高级检索

    可证明安全的物联网抗隐式攻击轻量级认证协议

    A Provably Secure Lightweight Authentication Protocol Against Implicit Attacks for IoT

    • 摘要: 物联网终端资源受限与复杂攻击并存的环境,对认证协议的设计提出了严峻挑战。尤其值得关注的是,即便通过形式化工具验证的协议,在攻击者组合多种基础攻击能力(如信道控制、秘密提取)所构成的隐式攻击下仍显脆弱。为解决上述问题,提出一种面向物联网的、可证明安全、资源高效且轻量级的认证协议。该协议采用哈希函数与物理不可克隆函数(physical unclonable functions,PUF)作为核心密码原语,通过动态身份与消息融合机制,同步优化通信与计算开销。在安全层面构建了可刻画复合攻击场景的扩展ROR(real-or-random)模型,并在此模型下严格证明了所提协议会话密钥的语义安全性;启发式安全分析进一步证实,所提协议在面对各类最强隐式攻击时,仍能实现全部9项预设安全属性。性能对比实验表明,所提协议在智能设备上的计算耗时仅为0.525 ms,通信开销为3040 b,在达成全面安全目标的同时,其资源效率显著优于现有主流方案,为物联网应用提供了一个安全与轻量兼备的实用化解决方案。

       

      Abstract: The Internet of things (IoT) environment, characterized by resource-constrained terminals and sophisticated threats, poses severe challenges to the design of authentication protocols. Notably, even protocols verified by formal tools often remain vulnerable to implicit attacks, where adversaries combine multiple capabilities such as channel control and secret extraction, to launch more complex and concealed attack strategies. To address this issue, this paper proposes a provably secure, resource-efficient, and lightweight authentication protocol. The protocol employs lightweight cryptographic primitives, including hash functions and physical unclonable functions (PUFs), and optimizes both communication and computational overhead through dynamic identity and message fusion mechanisms, without relying on expensive public-key operations. To establish a solid security foundation, this paper constructs an extended real-or-random (ROR) model capable of characterizing composite attack scenarios, under which the semantic security of the session key is rigorously proven. Heuristic analysis further demonstrates that the protocol achieves all nine predefined security properties even under implicit attacks. Performance evaluation and comparative analysis indicate that the proposed protocol requires only 0.525 ms of computational time on smart devices and incurs a communication overhead of 3040 b. While fulfilling comprehensive security objectives, its resource efficiency significantly outperforms existing schemes, offering a practical solution that balances security and lightweight design for IoT applications.

       

    /

    返回文章
    返回