Abstract:
The Internet of things (IoT) environment, characterized by resource-constrained terminals and sophisticated threats, poses severe challenges to the design of authentication protocols. Notably, even protocols verified by formal tools often remain vulnerable to implicit attacks, where adversaries combine multiple capabilities such as channel control and secret extraction, to launch more complex and concealed attack strategies. To address this issue, this paper proposes a provably secure, resource-efficient, and lightweight authentication protocol. The protocol employs lightweight cryptographic primitives, including hash functions and physical unclonable functions (PUFs), and optimizes both communication and computational overhead through dynamic identity and message fusion mechanisms, without relying on expensive public-key operations. To establish a solid security foundation, this paper constructs an extended real-or-random (ROR) model capable of characterizing composite attack scenarios, under which the semantic security of the session key is rigorously proven. Heuristic analysis further demonstrates that the protocol achieves all nine predefined security properties even under implicit attacks. Performance evaluation and comparative analysis indicate that the proposed protocol requires only 0.525 ms of computational time on smart devices and incurs a communication overhead of
3040 b. While fulfilling comprehensive security objectives, its resource efficiency significantly outperforms existing schemes, offering a practical solution that balances security and lightweight design for IoT applications.