Lightweight IoT Device Authentication
Lightweight IoT Device Authentication
Article
Light Weight Authentication Scheme for Smart Home
IoT Devices
Vipin Kumar 1 , Navneet Malik 1 , Jimmy Singla 1 , N. Z. Jhanjhi 2, * , Fathi Amsaad 3 and Abdul Razaque 4
1 Department of Computer Science and Engineering, Lovely Professional University, Phagwara 144001, India;
vipin.17730@[Link] (V.K.); subhash.14335@[Link] (N.M.); jimmy.21733@[Link] (J.S.)
2 School of Computer Science, Taylor’s University, Subang Jaya 47500, Malaysia
3 Department of Computer Science and Engineering, Wright State University, 3640 Colonel Glenn Hwy,
Dayton, OH 45435-0001, USA; [Link]@[Link]
4 Department of Computer Engineering, International Information Technology University,
Almaty 050000, Kazakhstan; [Link]@[Link]
* Correspondence: [Link]@[Link]
Abstract: In today’s world, the use of computer networks is everywhere, and to access the home
network we use the Internet. IoT networks are the new range of these networks in which we try
to connect different home appliances and try to give commands from a remote place. Access to
any device over an insecure network invites various types of attacks. User authentication can be
performed using some password or biometric technique. However, when it comes to authenticating
a device, it becomes challenging to maintain data security over a secure network such as the Internet.
Many encryptions and decryption algorithms assert confidentiality, and hash code or message
authentication code MAC is used for authentication. Traditional cryptographic security methods
are expensive in terms of computational resources such as memory, processing capacity, and power
Citation: Kumar, V.; Malik, N.; Singla,
consumption. They are incompatible with the Internet of Things devices that have limited resources.
J.; Jhanjhi, N.Z.; Amsaad, F.; Razaque,
Although automatic Device-to-Device communication enables new potential applications, the limited
A. Light Weight Authentication
Scheme for Smart Home IoT Devices.
resources of the networks’ machines and devices impose various constraints. This paper proposes a
Cryptography 2022, 6, 37. home device authentication scheme when these are accessed from a remote place. An authentication
[Link] device is used for the home network and controller device to control home appliances. Our scheme
cryptography6030037 can prevent various attacks such as replay attacks, server spoofing, and man-in-the-middle attack.
The proposed scheme maintains the confidentiality and authenticity of the user and devices in
Academic Editors: Cheng-Chi Lee,
the network. At the same time, we check the system in a simulated environment, and the results
Mehdi Gheisari, Mohammad
Javad Shayegan, Milad
show that the network’s performance does not degrade much in terms of delay, throughput, and
Taleby Ahvanooey and Yang Liu energy consumed.
Received: 26 May 2022 Keywords: authentication; confidentiality; internet of things; cryptography; security
Accepted: 8 July 2022
Published: 20 July 2022
network and website security. Message digests, encryption, and decryption are used for
these purposes [2]. In the cyber world, there are different types of communication between
clients and servers, and authentication is the process of verifying two communication
parties. There are different types of communication, such as client to server or peer to
peer [3].
It is vital to protect the physical and logical barriers between the data, software,
services, and the rest of the world. This is one of the parts of a multi-layered data protection
technique known as defense-in-depth [4]. The Internet has altered our reality by becoming
a global means of communication; it has transformed communication to the point where we
now use it as our primary way of communication. The Internet of Things (IoT) has forced
new research to secure these IoT devices and to use conventional classical cryptography to
protect data exchanges by applying mathematical approaches to minimize assaults, such as
eavesdropper attacks [5].
Machine authentication is beneficial since it confirms that the device connecting to
the network is a simple corporate device. In today’s society, it is likely to be a laptop
connected to a wireless or wired network. Person authentication is the process of a user
authenticating themselves to the network. Authentication, such as machine authentication,
may be performedvia certificates or credentials. The user certificate is usually downloaded
to the computer when a user registers for the first time.
On the other hand, machine authentication falls short when users share computers [6].
You cannot apply multiple privileges, such as VLANs, based on who is using the computer
since only the machine is authenticated, not the user. Here is a terrible example: a student
at a school logs onto a teacher’s computer. Because the device is shared, students and
teachers might share the same network. If a teacher previously used the computer, the
student now has access to the instructor’s network, which is rarely good [7].
used in conjunction with other systems throughout the workday. Employees may use
LDAP to connect to printers or check credentials [13].
4. Network authentication protocol (Kerberos): Kerberos is the authentication protocol
for internal networks. In this protocol, there are two servers used. One is the authenti-
cation server, AS, and one is the ticket granted server, TGT. A user that wants access
to any service in the network should authenticate itself to AS and generate a ticket to
access the services. This protocol prevents on-path or replay attacks. This is integrated
on Window 2000 and some other operating systems [14].
5. SSO with Kerberos: Used to authenticate cloud services as well. When it comes to
implementing security in a wireless network, key distribution is one of the most
common issues [15]. If every node has the same key and one of them is compromised
or evil, the key for the whole network will be exposed. If each node has a separate
key, it will be exceedingly difficult to maintain all of the keys due to the many devices.
In the case of the pool key distribution, if each node has a limited number of keys,
the network connection will suffer. If each node is given a more significant number
of keys, network resiliency will suffer. The benefit of public-key cryptography is
that it generally has many resources in demand. The multi-path random essential
pre-distribution approach cannot fully protect the system. The Kerberos network can
authenticate LDAP.
6. IEEE 802.1x: Based on hardware port network access control protocol. It works as
a physical layer and a data link layer. This protocol standard is used in conjunction
with an access database portal. It is also used in VPNs as the constrictor can talk to the
RADIUS server. This authentication scheme makes the access of systems standardized,
and any CISCO device can support it with tacacs+.
7. EAP: extensible authentication protocol integrated with IEEE 802.1x. To prevent
access to a network from authenticating access, this protocol is used. This protocol is
very strong and uses DES. The newer version of it uses the AES. It also uses MD5 and
SHA-1 for authentication. It also includes the IEEE802.1 standard protocol. It is used
in LAN device authentication. IEEE 802.1X describes the extensible authentication
protocol (EAP) encapsulation over IEEE 802.11, sometimes known as “EAP over LAN”
or EAPOL. It provides an authentication mechanism to devices wishing to attach to a
LAN or WLAN.
investigated as a method for data analysis. These networks exchange data between
sensor nodes, which are then sent to a distributed system to analyze the sensory data
collected [17].
3. Quality of Service: Throughput and bandwidth are the two most important factors
that influence the quality of service (QoS) of IoT applications. Data generated by
the Internet of Things (IoT) ranges from sensors linked to machine components or
environmental monitors to the words we shout at our smart speakers in enormous
numbers. Because of restrictions in resource allocation and management capabilities in
shared wireless media, the devices will need a specific frequency in order to transmit
data across the wireless medium. Another major research subject in cloud computing
is quality of service, which will become more essential as the data and tools required
for the Internet of Things become more readily available on the cloud [18].
4. Interoperability and Standardization: There is a lack of interoperability, platform
fragmentation, and widely accepted technological standards in the IoT networks.
While developing apps that will work consistently across diverse technical ecosystems,
it is critical to consider the broad range of Internet of Things devices accessible, both
in hardware variances and changes in the software that runs on them. Given the fact
that there will be a plethora of device makers in the future, technologies and services
that are accessible for one device may become unavailable for other devices within
the same period of time. Consequently, the standardization of all network objects and
sensor devices is essential to improve interoperability [19].
5. Object’s safety and security: It is difficult and potentially dangerous for attackers to
access the Internet of Things due to the enormous number of perceptual objects spread
across a vast deployment area. The things may be rendered unusable or physically
damaged if the attackers get access to the goods.
2. Related Work
For the low-energy device, it is very difficult to implement security. All the access to
the device or the network is through the Internet, so it is necessary to authenticate the user
and maintain confidentiality. Different types of encryption-decryption algorithms are used
in cryptography. Secret keys are used in these encryption-decryption algorithms. These
secret keys are only shared between communication parties. The process of distributing
and maintaining these keys is known as key management. It is difficult to create a single
key scheme that can be used for networks with varying topologies. Many key sensor
network management techniques that meet the majority of the requirements have been
developed. In addition to other security concerns, key management should consider the
sensor node’s limited energy and processing. As a result, any approach should be as light
in terms of storage and processing as feasible. It should not concentrate all of its efforts on
Cryptography 2022, 6, 37 6 of 15
the first setup. In [20], the SPINS protocol, suggested by the author. was one of the first
protocols for low-energy devices’ security. In this approach, the base station serves as the
key distribution center, or KDC, and two nodes can use the KDC to create a pairwise key.
The scheme discussed in [21] works in a client–server way. When the device wants to
connect to the server, it requests and sends a challenge the device has to solve and send
to the server. Another technique for server authentication given in [22] is a space-time
authentication technique and a location-based technique that employs a GPS to determine
the position. The second approach uses IQRF, unique communication technology for
position determination.
In [23], the author proposed a technique based on data analysis, and this scheme takes
the advantages of opportunistically leveraging physical layer characteristics and applying
intelligence to authentication; new authentication systems based on machine learning
algorithms provide more efficient security provisioning. There are other machine learning
paradigms available for use with parametric and non-parametric learning algorithms, as
well as supervised, unsupervised, and reinforcement learning algorithms.
In 2018, another algorithm was provided in [24], and a secure and efficient multi-factor
device authentication scheme was proposed. The proposed concept uses digital signatures
and device capabilities to authenticate a device. In the presented technique, a machine
will be allowed into the network only if multi-factor authentication has been successfully
established; otherwise, the authentication process will fail, and the entire authentication
procedure will be redone.
Another technique is given in [25] based on human biometrics. A per-packet authen-
tication is a research approach in which security mechanisms should be established to
ensure the authentication of a specific network flow. User biometrics are used for authenti-
cation and fall under the category of “something you have.” The author applies biometric
techniques to apply per-packet authentication rules in highly dynamic contexts.
In [26], a mutual authentication technique for low-energy devices was given, in which
each node in a WSN is assigned a Medium Access Control (MAC) address in order to
register with the nearest cluster head (CH) or base station module. Offline registration is
used to validate the legitimacy of both lawful nodes and base stations in a live network.
The suggested technique eliminates the black-hole attack problem since an invader node
must register with both the gateway and its neighbors, which is impossible. To increase the
acquired authenticity, confidentiality, and integrity data, a hybrid data encryption strategy,
elliptic curve integrated encryption standard (ECIES), and an elliptic curve Diffie–Hellman
problem (ECDDHP) are utilized [27].
By studying the different strategies for IoT network security, we discovered that
the schemes mostly concentrate on security rather than network performance [28]. The
Internet of Things (IoT) is employed in a range of applications, including smart cities, traffic
management, ambulance communication, and at home. These gadgets also raise a plethora
of security concerns. This is because the industry is young, and manufacturers and sellers
are more concerned with features; making devices have a more promising future and a
speedier market debut. However, for hackers, this may result in million-dollar breaches [29].
At the moment of conception, security is not a priority. If a hacker compromises a tiny IoT
device, the hacker has access to the whole infrastructure, including the sensitivity date.
Therefore, there is a need for a lightweight authentication scheme for these low-power
devices that also have the same performance level [30].
3. Proposed Scheme
In this section, we explain the proposed scheme and the implementation of the scheme.
IoT device manufacturers consider connectivity and performance, but they are uncon-
cerned about the device’s security, making the device vulnerable to various attacks. Before
accepting any instruction, this technique performs the appropriate authentication of users
and provides access control; as a result, it is capable of preventing a significant number of
assaults on IoT networks. The proposed scheme has to preserve data transfer security and
Cryptography 2022, 6, 37 7 of 15
provide user authentication. A user can control the home device from anywhere using a
mobile or laptop and an Internet connection. A central controller or authentication device
is used to control the communication between the user and the device. The controller is the
main source that has processing capability for data and transmission. The notations used
in the work are shown in Table 1.
Table 1. Notations.
Symbol Meaning
AD Authentication Device
CD Controlling Device
UD User device
HA Home Appliances
SK Session Key
Kp Private Kay
Ku Pubic Key
En(K,M) Message M encrypted with Key K
TS Time Stamp
Network Model and Adversarial Model: The network model is given in Figure 1. A
user wants to operate the home device from a remote location. The user uses the Internet
to send a command to the home appliances. The Internet channel may be insecure, and
Cryptography 2022, 6, x FOR PEER REVIEW 8 of 16
an attacker may impersonate themself as an authenticated user and try to access the
home devices.
Figure
[Link]
HomeIoT
IoTNetwork.
Network.
User
UserRegistration:
Registration:The
Thealgorithm
algorithmtotoauthenticate
authenticatehome
homedevices
devicesrequires
requiresthat
thatthe
theuser
user
device
devicemust
mustfirst
first have
havesome
some small
small software
software that
that has
has aa public-private
public-privatekey
key pair
pairwith
with the
the
authentication
authenticationdevice.
[Link]
Thisstep
step(Scheme
(Scheme1)1)isisoffline
offlineand
andmay
maybe beconsidered
consideredasasthe
theuser
user
registration
registrationwith
withthe
theauthentication
authentication device
device (AD).
(AD).
User Registration: The algorithm to authenticate home devices requires that the user
device must first have some small software that has a public-private key pair with the
Cryptography 2022, 6, 37 8 of 15
authentication device. This step (Scheme 1) is offline and may be considered as the user
registration with the authentication device (AD).
Scheme 1. User
Scheme Sends
1. User thethe
Sends Request to to
Request thethe
[Link].
The
The user
user wants
wants to to access
access appliances
appliances in in
thethe home.
home. Appliances
Appliances can
can bebe anything,
anything, such
such
as a bulb, tube light, fan, AC, fridge, or geyser. A home appliance is represented
asa bulb, tube light, fan, AC, fridge, or geyser. A home appliance is represented by HA. by HA.
There are three parties involved in the communication; theauthentication device, AD;thethe
There are three parties involved in the communication; theauthentication device, AD;
controller,
controller, CD;
CD; andandthethe user.
user. Before
Before creating
creating thethe connection
connection over
over thethe Internet,
Internet, it the
it the user
user
device uses an algorithm to generate the public key with the help of the user’s
device uses an algorithm to generate the public key with the help of the user’s password password
that
that can
can bebe used
used bybyanan authentication
authentication server
server asas a Public-Key
a Public-Key Infrastructure
Infrastructure (PKI).
(PKI).
1. 1. TheThe user
user sends
sends thethe request
request to to
anan authenticated
authenticated device
device forfor login.
login. This
This authentication
authentication
request is sent using a secure public-key encryption algorithm, such as as
request is sent using a secure public-key encryption algorithm, such RSA,
RSA, and
and
the AD authenticates the user by the public/private key pair shared offline at thethe
the AD authenticates the user by the public/private key pair shared offline at
time
time of of user
user registration.
registration. It gives
It gives thethe same
same level
level of of security
security provided
provided byby publickey
publickey
cryptography.
cryptography.
2. 2. TheThe authenticator
authenticator device
device generates
generates a session
a session keykey
andand performs
performs thethe following;
following;
a. a. Alice
Alice identity
identity andand Session
Session KeyKey
areare encrypted
encrypted bybya asymmetric
symmetricshared
sharedkey
keywith
with a
controller device called the Authentication Coupon
a controller device called the Authentication Coupon (AC). (AC).
b. b. TheThe Authentication
Authentication Device
Device sends
sends thethe Session
Session keykey
andand encrypted
encrypted ACAC with
with thethe
Cryptography 2022, 6, x FOR PEER REVIEW User public key to the user. 9 of 16
User public key to the user.
c. c. TheThe Authentication
Authentication Device
Device sends
sends thethe Timestamp,
Timestamp, Authentication
Authentication Coupon,
Coupon, andand
user Identity to the Controller
user Identity to the Controller [Link].
Above Above mentioned
mentioned stepssteps are shown
are shown in Scheme
in Scheme 2. 2.
Scheme
[Link] sends
The AD thethe
sends coupon to to
coupon thethe
user.
user.
The
3. 3. The user
user device
device requests
requests the
the controller
controller devicetotoaccess
device accessHA HAwith
withananAuthentication
Authentication
Coupon AC. The controlling device performs the
Coupon AC. The controlling device performs the following; following;
a. Decrypt
a. Decrypt
thethe coupon
coupon with
with the
the shared
shared key
key ofofADADand andfinds
findsthe
theidentity
identityofofthe
the
user.
user.
b. The
b. The Controlling
Controlling Device
Device already
already has
has the
the AC,AC, user
user identity,and
identity, andtime
timeofofrequest.
request.
c. The Controlling Device checks and authenticates the user
c. The Controlling Device checks and authenticates the user and sends the and sends the com-
mand to HA.
command to HA.
d. The Controller Device
d. The Controller Device adds
adds the
the entry
entry inin
thethe
loglog list
list record.
record.
Above mentioned
Above stepssteps
mentioned are shown in Scheme
are shown 3. 3.
in Scheme
4. The controller authenticates the user and asks for the command to give to the HA.
5. The user sends the command to the controller.
a.a. Decrypt
Decryptthe
thecoupon
couponwith
withthe
theshared
sharedkeykeyofofADADandandfinds
findsthe
theidentity
identityofofthe
the
user.
user.
b.b. The
TheControlling
ControllingDevice
Devicealready
alreadyhashasthe
theAC,
AC,user
useridentity,
identity,and
andtime
timeofofrequest.
request.
c.c. The
The Controlling
Controlling Device
Device checks
checks and
and authenticates
authenticates thethe user
user and
and sends
sends thethe
command
[Link].
Cryptography 2022, 6, 37 d.d. The 9 of 15
TheController
ControllerDevice
Deviceadds
addsthetheentry
entryininthe
thelog
loglist
listrecord.
record.
Above
Abovementioned
mentionedsteps
stepsare
areshown
shownininScheme
Scheme3.3.
Scheme
Scheme3.3.
Scheme [Link]
Usersends
User sendsthe
sends theAU
the AUand
AU andcommand
and commandto
command tothe
to theCD.
the CD.
CD.
4.4.4. Thecontroller
The
The controller authenticates
controllerauthenticates the
authenticatesthe user
theuser and
userand asks
andasks for
asksfor the
forthe command
thecommand
commandto to give
togive to
giveto the
tothe HA.
theHA.
HA.
5.5.5. The
The user
Theuser sends
usersends the
sendsthe command
thecommand to
commandtotothethe controller.
thecontroller.
controller.
6.6.6. Thecontroller
The
The controllersends
controller sendsthe
sends thecommand
the commandtoto
command tothe
thedevice
the deviceand
device andsends
and sendsaaanotification
sends notificationtoto
notification tothe
theuser.
the user.
user.
All
All these
Allthese steps
thesesteps are
stepsare shown
areshown below
belowinin
shownbelow Scheme
Scheme4.4.
inScheme 4.
Scheme
[Link]
Scheme 4. CDsends
[Link] sendsthe
thecommand
commandtotoHA.
HA.
4. Security and Performance Analysis
[Link]
Securityand
andPerformance
PerformanceAnalysis
Analysis
Cryptography 2022, 6, x FOR PEER REVIEW The security protocol must have strong user authentication and confidentiality 10 of 16of
The
Thesecurity
securityprotocol
protocolmust
musthave
havestrong
stronguser
userauthentication
authenticationand andconfidentiality
confidentialityofof
transmitted data. A security protocol may ensure very strong security in the network, but
transmitted
transmitteddata. AAsecurity protocol
protocolmay ensure
ensurevery strong security ininthe network, but
sometimes, itdata. security
degrades the network’s may veryA
performance. strong security
security protocol the network,
must but
be attack
sometimes,
sometimes, it degrades the network’s performance. A security protocol must be attack
resistant andit should
degradesbe the
ablenetwork’s
to stop andperformance. A security
prevent various protocol
attacks must be attack
by an adversary. We
analyze
resistantthe
resistant scheme
and
and onbe
should
should three
be different
able
abletotostop
stoptypes
and
and of parameters
prevent
prevent various[31].
various First,by
attacks
attacks it
by has
an
an to have an ef-
adversary.
adversary. We
analyze the scheme on three different types of parameters [31]. First, it has to have We
an
ficient level of security to effectively offer protection and meet all of the standards for
efficient level of security to effectively offer protection and meet all of the standards for
safety. Second, it must prevent all known attacks on the system and should not leave any
safety. Second, it must prevent all known attacks on the system and should not leave any
vulnerability in the [Link], atthe same time, it should not degrade the system’s
vulnerability in the system. Third, at the same time, it should not degrade the system’s
performance. We check that the protocol provides sufficient security, prevents all types
performance. We check that the protocol provides sufficient security, prevents all types of
of attacks, and gives good performance. The authentication message transitions are
attacks, and gives good performance. The authentication message transitions are shown in
shown in Figure 2.
Figure 2.
Figure 2.2.
Figure Authentication Message
Authentication Transitions.
Message Transitions.
Parameter Output
Parse Time 0.05 s
Search Time 1.2 s
Depth 12
Translation 222 States
Computation 0.45 s
Reachable 234 States
Figure3.3. Verification
Figure VerificationResults.
Results.
Masquerade:
Replay Attack: AnWhen
attacker may revealdevice
an appliance the identity of a legitimate
is accessed user and claim
by the authenticated user,that
the
Icontroller
am the person who can access the device. To stop this type of attack,
also stores the information and access used and maintains the log and backup authentication is
required, and the whole process is about authentication. The authentication
for future use. A request coming to the controller to access the device can only come techniques are
provided
through the by RSA or MD5 algorithms
authentication [35].same
device. The Therefore, if the first
information partsent
is also of the
bycommunication
the authentica-
istion
secure
device with a time stamp. This time stamp sharing between the AD depends
and a public key is securely exchanged and authenticated, it all and CD is onused
the
algorithm’s
to stop replaystrangeness.
attacks. We can use a backup log to analyze the different activities of the
Server Spoofing:
user, or Machine Learning An attacker may to
can be used divert the traffic
analyze from the
the behavior ofuser to a fake server by
the user.
serverMan-in-the-Middle
spoofing and getting attack: A man-in-the-middle attack is a form ofserver
user information or credentials. Any spoofed active does not
wiretap-
know
ping in which the attacker intercepts and selectively modifies communicated datathe
the keys used by the AD, and the scheme is as secure as the physical security of to
authentication
masquerade [Link] or All theofdata
more the coming
entities from the user
involved in a is encrypted by the
communication public key
association. of
This
the serverfor
process and only the AD can
authentication decryptbyit awith
is started keythe private
being [Link] devices. A password is
shared
Offline Password Guessing: The instruction of strong passwords is given by various
used to authenticate the user, but we have to also authenticate the devices. Therefore, this
security agencies, and if a user chooses a strong password, it is difficult to guess. Moreover,
communication is started by the user and the used device [34]. The communication be-
it is recommended to change the password at regular intervals. In the proposed scheme, the
tween the user and AD on an insecure channel is encrypted by the public key shared
password is set offline initially at the time of registration and may be extended by choosing
between the user and AD. This process is completely offline, so there is no chance of this
another online method of password changing, such as email or OTP verification.
key compromization or an authentication problem. All the subsequent keys are en-
User impersonation: A user is a person who wants to give the commands to the
crypted by this public key, and the authentication process is completed, which stops this
home device, and an attacker may impersonate the user and claim to be an authenticated
type of attack.
user. A user can communicate with the AD only if the password is offline resisted by the
Masquerade: An attacker may reveal the identity of a legitimate user and claim that
AD. Therefore, it is not possible for anyone to obtain the user’s password, and when it is
I am the person who can access the device. To stop this type of attack, authentication is
transferred over the Internet, it is protected by the private–public key of the user’s device
required, and the whole process is about [Link] authentication techniques
and the authentication device.
Figure 4.
Figure 4. Delay
Delay in
in the
the Communication.
Communication.
Storage Overhead
Storage Overhead and andEnergy
EnergyEfficiency:
Efficiency:Storage
Storageand
andenergy
energyrequirements
requirements forfor the
the
scheme are
scheme are given
given in
in the
the Table
Table4, 4,and
and check
check that
that less
less storage
storage is
is required
required compared
compared to to other
other
existing schemes.
existing schemes. The energy
energy requirements
requirements for the the scheme
scheme maymay be be slightly
slightly high,
high, but
but the
the
security provided is high. We run the simulation in various scenarios and
security provided is high. We run the simulation in various scenarios and check the en- check the energy
spent with security
ergy spent and without
with security security.
and without A maximum
security. A maximum of 1 Mb of 1ofMb
memory is required
of memory is re-
to store to
quired thestore
keys, and
the some
keys, andissome
computation required,
is computation as shown
required, in the previous
as shown table. We
in the previous ta-
separately analyze analyze
ble. We separately our proposed scheme scheme
our proposed on the plate
on theagainst securitysecurity
plate against attacks attacks
and find andit
robust
find it against various various
robust against attacks. attacks.
We check Weour scheme
check ourin the NS3
scheme in simulator and calculate
the NS3 simulator and
and compare
calculate andstorage
compare cost and computation
storage cost. We also
cost and computation check
cost. Wethe alsocommunication cost.
check the communi-
cation cost.
We implement the scheme and measure energy expenditure for different devices, as
shown in Figure 5. The graph in Figure 5 shows the energy consumption with and without
security for individual devices. With 1 mJ initial energy maximum energy expenditure
in the authentication device, the energy consumption of this scheme is calculated via
the average remaining energy in a device and the energy required for encryption and
Cryptography 2022, 6, x FOR PEER REVIEW 14 of 16
decryption. Insecure methods, a device sends a message after encryption, which consumes
more energy than an insecure scheme.
Figure5.5. Energy
Figure EnergyConsumption
Consumptionin
inProposed
ProposedScheme.
Scheme.
5.
5. Conclusions
Conclusions
Use
Use ofof the
the Internet,
Internet, Wi-Fi,
Wi-Fi, oror5G
5Gtechnology
technology to to access
access different
different personal
personal devices
devices oror
cloud
cloud storage is very common nowadays [36]. We use the Internet to access ourpersonal
storage is very common nowadays [36]. We use the Internet to access our personal
devices,
devices,office
officenetworks,
networks,office mail
office servers,
mail or laptops.
servers, Authenticating
or laptops. Authenticatingusers isusers
very is
impor-
very
tant to prevent data from getting into the wrong hands. Therefore, various
important to prevent data from getting into the wrong hands. Therefore, various au- authentication
techniques
thentication aretechniques
used to authenticate
are used tothe user. We develop
authenticate the [Link]
authentication
develop the technique that
authentication
mainly relies on asymmetric key cryptography. The scheme is checked
technique that mainly relies on asymmetric key cryptography. The scheme is checked against various
attacks
againstand givesattacks
various good results.
and gives This scheme
good canThis
results. be implemented
scheme can bewith IoT networks
implemented withandIoT
works well in a diluted network. We proposed a scheme for home
networks and works well in a diluted network. We proposed a scheme for home device device authentication
using public-key
authentication cryptography.
using public-key The scheme is used
cryptography. to send is
The scheme commands
used to send to home devices
commands to
securely. The results
home devices showThe
securely. thatresults
the proposed scheme
show that is secure, and
the proposed schemeit prevents many
is secure, andattacks.
it pre-
The authenticating device and controlling device check every step and scheme and also
vents many attacks. The authenticating device and controlling device check every step
prevents the server spoofing scheme. Biometric authentication enhances authentication,
and scheme and also prevents the server spoofing scheme. Biometric authentication en-
although it necessitates the purchase of additional gear. Authentication technology is
hances authentication, although it necessitates the purchase of additional gear. Authen-
continually changing, and as technology advances, companies must consider authentica-
tication technology is continually changing, and as technology advances, companies
tion and passwords to improve the user experience. Because of enhanced authentication
must consider authentication and passwords to improve the user experience. Because of
procedures and technology, attackers will be unable to exploit passwords, and security may
enhanced authentication procedures and technology, attackers will be unable to exploit
be improved.
passwords, and security may be improved.
Author Contributions: Conceptualization, V.K., N.M., J.S., N.Z.J., F.A. and A.R.; Data curation,
V.K., N.M., J.S., N.Z.J., F.A. and A.R.; Formal analysis, V.K., N.M., J.S., N.Z.J., F.A. and A.R.;
Funding acquisition, V.K., N.M., J.S., N.Z.J., F.A. and A.R.; Investigation, V.K., N.M., J.S., N.Z.J.,
F.A. and A.R.; Methodology, V.K., N.M., J.S., N.Z.J., F.A. and A.R.; Resources, V.K., N.M., J.S.,
Cryptography 2022, 6, 37 14 of 15
Author Contributions: Conceptualization, V.K., N.M., J.S., N.Z.J., F.A. and A.R.; Data curation, V.K.,
N.M., J.S., N.Z.J., F.A. and A.R.; Formal analysis, V.K., N.M., J.S., N.Z.J., F.A. and A.R.; Funding
acquisition, V.K., N.M., J.S., N.Z.J., F.A. and A.R.; Investigation, V.K., N.M., J.S., N.Z.J., F.A. and
A.R.; Methodology, V.K., N.M., J.S., N.Z.J., F.A. and A.R.; Resources, V.K., N.M., J.S., N.Z.J., F.A. and
A.R.; Software, N.M., J.S., N.Z.J. and F.A.; Supervision, N.M. and N.Z.J.; Validation, V.K. and F.A.;
Visualization, V.K., N.M., J.S., N.Z.J., F.A. and A.R.; Writing—original draft, V.K., N.M., J.S., N.Z.J.,
F.A. and A.R.; Writing—review & editing, V.K., J.S., N.Z.J., F.A. and A.R. All authors have read and
agreed to the published version of the manuscript.
Funding: This research received no external funding.
Data Availability Statement: Data is available on demand on request through first author.
Conflicts of Interest: The authors declare no conflict of interest.
References
1. Zhang, Y.; Xiao, Y.; Ghaboosi, K.; Zhang, J.; Deng, H. A survey of cyber crimesYanping. Secur. Commun. Netw. 2012, 5, 422–437.
[CrossRef]
2. Suo, H.; Wan, J.; Zou, C.; Liu, J. Security in the internet of things: A review. In Proceedings of the 2012 International Conference
on Computer Science and Electronics Engineering, Hangzhou, China, 23–25 March 2012; Volume 3, pp. 648–651.
3. Wazid, M.; Das, A.K.; Hussain, R.; Succi, G.; Rodrigues, J.J. Authentication in cloud-driven IoT-based big data environment:
Survey and outlook. J. Syst. Arch. 2019, 97, 185–196. [CrossRef]
4. Kizza, J.M. Guide to Computer Network Security, 5th ed.; Springer: Berlin/Heidelberg, Germany, 2017; Chapters 2 and 3.
5. Mamun, Q.; Islam, R.; Kaosar, M. Secured Communication Key Establishment for Cluster-Based Wireless Sensor Networks. Int. J.
Wirel. Netw. Broadband Technol. 2015, 4, 29–44. [CrossRef]
6. Schmitt, C.; Noack, M.; Stiller, B. TinyTO: Two-way authentication for constrained devices in the Internet of Things. In Internet of
Things; Elsevier: Amsterdam, The Netherlands, 2016; pp. 239–258.
7. Anthi, E.; Williams, L.; Slowinska, M.; Theodorakopoulos, G.; Burnap, P. A Supervised Intrusion Detection System for Smart
Home IoT Devices. IEEE Internet Things J. 2019, 6, 9042–9053. [CrossRef]
8. Zhu, W.T.; Zhou, J.; Deng, R.H.; Bao, F. Detecting node replication attacks in wireless sensor networks: A survey. J. Netw. Comput.
Appl. 2012, 35, 1022–1034. [CrossRef]
9. Ye, J.; Cheng, X.; Zhu, J.; Feng, L.; Song, L. A DDoS Attack Detection Method Based on SVM in Software Defined Network. Secur.
Commun. Netw. 2018, 2018, 9804061. [CrossRef]
10. Hema, B.R.K.; Sangeetha, S.; Bora, R.K.; Rao, K.S. Preference analysis of game theory for network security in WSN. J. Crit. Rev.
Synth. Adv. Sci. Res. 2020, 7, 2637–2642.
11. Smith, R.E. Authentication: From Passwords to Public Keys; Addison-Wesley Longman Publishing Co., Inc.: Boston, MA, USA, 2001.
12. Vithanage, N.N.N.; Thanthrige, S.S.H.; Kapuge, M.C.K.P.; Malwenna, T.H.; Liyanapathirana, C.; Wijekoon, J.L. A Secure
Corroboration Protocol for Internet of Things (IoT) Devices Using MQTT Version 5 and LDAP. In Proceedings of the 2021
International Conference on Information Networking (ICOIN), Jeju Island, Korea, 13–16 January 2021; pp. 837–841.
13. Cristescu, G.-C.; Croitoru, V. Spoofed Packet Injection Attack-Resistant AAA-RADIUS Solution Based on LDAP and EAP. In
Proceedings of the 2021 International Symposium on Signals, Circuits and Systems (ISSCS), Iasi, Romania, 15–16 July 2021;
pp. 1–4.
14. Motero, C.D.; Higuera, J.R.B.; Higuera, J.B.; Montalvo, J.A.S.; Gomez, N.G. On Attacking Kerberos Authentication Protocol in
Windows Active Directory Services: A Practical Survey. IEEE Access 2021, 9, 109289–109319. [CrossRef]
15. Takieldeen, A.; Elkhalik, S.A.; Samra, A.; Mohamed, M.; Khalifa, F. A Robust and Hybrid Cryptosystem for Identity Authentication.
Information 2021, 12, 104. [CrossRef]
16. Porkodi, R.; Bhuvaneswari, V. The internet of things (IOT) applications and communication enabling technology standards:
An overview. In Proceedings of the 2014 International Conference on Intelligent Computing Applications, Coimbatore, India,
6–7 March 2014; pp. 324–329.
17. Hong-Tan, L.I.; Cui-hua, K.; Muthu, B.; Sivaparthipan, C.B. Big data and ambient intelligence in IoT-based wireless student health
monitoring system. Aggress. Violent Behav. 2021, 101601. [CrossRef]
18. Sodhro, A.H.; Obaidat, M.S.; Abbasi, Q.H.; Pace, P.; Pirbhulal, S.; Fortino, G.; Qaraqe, M. Quality of service optimization in an
IoT-driven intelligent transportation system. IEEE Wirel. Commun. 2019, 26, 10–17. [CrossRef]
19. Hazra, A.; Adhikari, M.; Amgoth, T.; Srirama, S.N. A Comprehensive Survey on Interoperability for IIoT: Taxonomy, Standards,
and Future Directions. ACM Comput. Surv. 2021, 55, 1–35. [CrossRef]
20. Seshadri, A.; Luk, M.; Perrig, A.; van Doorn, L.; Khosla, P. Using Fire & Ice for Detecting and Recovering Compromised Nodes in Sensor
Networks; School of Computer Science, Carnegie Mellon University: Pittsburgh, PA, USA, 2004.
21. Falk, R.; Fries, S. Advanced Device Authentication Bringing Multi-Factor Authentication and Continuous Authentication to the
Internet of Things. In Proceedings of the First International Conference on Cyber-Technologies and Cyber-Systems, Venice, Italy,
9–13 October 2016; pp. 69–74.
Cryptography 2022, 6, 37 15 of 15
22. Jaros, D.; Kuchta, R. New location-based authentication techniques in the access management. In Proceedings of the 2010 6th
International Conference on Wireless and Mobile Communications, Chengdu, China, 23–25 September 2010; pp. 426–430.
23. Fang, H.; Wang, X.; Tomasin, S. Machine Learning for Intelligent Authentication in 5G and Beyond Wireless Networks. IEEE
Wirel. Commun. 2019, 26, 55–61. [CrossRef]
24. Alizai, Z.A.; Tareen, N.F.; Jadoon, I. Improved IoT Device Authentication Scheme Using Device Capability and Digital Signatures.
In Proceedings of the 2018 International Conference on Applied and Engineering Mathematics (ICAEM), Taxila, Pakistan,
4–5 September 2018; pp. 115–119. [CrossRef]
25. Nakouri, I.; Hamdi, M.; Kim, T.-H. Biometric-based Per-Packet Authentication Techniques in Communication Networks. In
Proceedings of the 2018 14th International Wireless Communications & Mobile Computing Conference (IWCMC), Limassol,
Cyprus, 25–29 June 2018; pp. 273–278.
26. Adil, M.; Khan, R.; Almaiah, M.A.; Al-Zahrani, M.; Zakarya, M.; Amjad, M.S.; Ahmed, R. MAC-AODV Based Mutual Authentica-
tion Scheme for Constraint Oriented Networks. IEEE Access 2020, 8, 44459–44469. [CrossRef]
27. Costello, C. B-SIDH: Supersingular isogeny Diffie-Hellman using twisted torsion. In Proceedings of the International Conference
on the Theory and Application of Cryptology and Information Security, Daejeon, Korea, 6–10 December 2020; pp. 440–463.
28. Tewari, A.; Gupta, B.B. Secure Timestamp-Based Mutual Authentication Protocol for IoT Devices Using RFID Tags. Int. J. Semantic
Web Inf. Syst. 2020, 16, 20–34. [CrossRef]
29. Majeed, U.; Khan, L.U.; Yaqoob, I.; Kazmi, S.M.A.; Salah, K.; Hong, C.S. Blockchain for IoT-based smart cities: Recent advances,
requirements, and future challenges. J. Netw. Comput. Appl. 2021, 181, 103007. [CrossRef]
30. Aboubakar, M.; Kellil, M.; Roux, P. A review of IoT network management: Current status and perspectives. J. King Saud Univ. Inf.
Sci. 2021, 34, 4163–4176. [CrossRef]
31. Hayashi, V.T.; Arakaki, R.; Ruggiero, W.V. OKIoT: Trade off analysis of smart speaker architecture on open knowledge IoT project.
Internet Things 2020, 12, 100310. [CrossRef]
32. Yin, J.; Zhu, H.; Fei, Y. Formal analysis and automated validation of privacy-preserving AICE protocol in mobile edge computing.
Mob. Networks Appl. 2021, 26, 2258–2271. [CrossRef]
33. Kampova, K.; Lovecek, T.; Rehak, D. Quantitative approach to physical protection systems assessment of critical infrastructure
elements: Use case in the Slovak Republic. Int. J. Crit. Infrastruct. Prot. 2020, 30, 100376. [CrossRef]
34. Mallik, A. Man-in-the-middle-attack: Understanding in simple words. Cybersp. J. Pendidik. Teknol. Inf. 2019, 2, 109–134.
35. Jo, H.J.; Kim, J.H.; Choi, H.-Y.; Choi, W.; Lee, D.H.; Lee, I. MAuth-CAN: Masquerade-Attack-Proof Authentication for In-Vehicle
Networks. IEEE Trans. Veh. Technol. 2019, 69, 2204–2218. [CrossRef]
36. Sathyadevan, S.; Achuthan, K.; Doss, R.; Pan, L. Protean Authentication Scheme—A Time-Bound Dynamic KeyGen Authentication
Technique for IoT Edge Nodes in Outdoor Deployments. IEEE Access 2019, 7, 92419–92435. [CrossRef]