0% found this document useful (0 votes)
8 views40 pages

Iot PDF Notes

The Internet of Things (IoT) refers to a network of devices with unique identities that are connected to the internet, enabling them to communicate and interact with their environment. IoT devices are characterized by their dynamic adaptability, self-configuration, and integration into information networks, differing from Machine to Machine (M2M) communication in their reliance on IP-based protocols and software emphasis. The architecture of IoT includes various layers such as perception, middleware, and application layers, and is supported by enabling technologies like wireless sensor networks for data collection and analysis.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
8 views40 pages

Iot PDF Notes

The Internet of Things (IoT) refers to a network of devices with unique identities that are connected to the internet, enabling them to communicate and interact with their environment. IoT devices are characterized by their dynamic adaptability, self-configuration, and integration into information networks, differing from Machine to Machine (M2M) communication in their reliance on IP-based protocols and software emphasis. The architecture of IoT includes various layers such as perception, middleware, and application layers, and is supported by enabling technologies like wireless sensor networks for data collection and analysis.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Internet of Things

Introduction to IoT:
• Internet of Things (IoT) comprises things that have unique identities
and are connected to the internet.
• Existing devices , such as networked computers or 4G enabled mobile
phones already have some form of unique identities and are also
connected to the internet, the focus on IoT is in the configuration,
control and networking via the internet of devices or things , that are
traditionally not associated with the Internet.
• Experts forecast that by the year 2020 there will be a total of 50 billion
devices/ things connected to the internet.
Definition and characteristics of IoT:
Definition
• A dynamic global network infrastructure with self – configuring based on
standard and interoperable communication protocols where physical and
virtual “things” have identified, physical attributes, and virtual personalities
and use intelligent interfaces, often communicate data associated with users
and their environments.
Characteristics
• Dynamic and self-Adapting:
• IoT devices and systems may have the capability to dynamically adapt with
the changing contexts and take actions based on their operating [Link]:
Surveillance cameras can adapt their modes based on whether it is day or
night.
• Self – Configuring:
• IoT devices may have self-Configuring capability allowing a large number of
devices to work together to provide certain functionality .
• Interoperable communication protocols:
• IoT Devices may support a number of interoperable communication protocols
and can communicate with other devices and also with the infrastructure.
• Unique Identity:
• Each IoT devices has a unique identity and a unique [Link],
URI).IoT systems may have intelligent interfaces which adapt based on the
context, allow communication with users and the environment contexts.
• Integrated into information network:
• IoT devices are usually integrated into the information network that allows
them to communicate and exchange data with other devices and systems.
DIFFERENCE BETWEEN IOT AND M2M
Communication protocols:
• M2M uses other proprietary or not IP based communication protocol
for communication with in the M2M area networks. Commonly uses
M2M protocol include zigbee, Bluetooth, ModBus, wireless M-Bus
,power line communication.
• The focus of communication in M2M is usually on the protocols
below the network layer.
• Focus of communication in IoT is usually a protocol in network layer
such as http web sockets, MQTT, XMPP, DDS, AMQP.
Machines in M2M vs Things in IoT:
• The " things " IoT refers to Physical objects that have unique identifier
and can sense and communicate with the external environment or their
internal physical status. The unique identifier things in IoT are the IP
addresses. Things have software component for accessing processing
and storing sensor information on controlling actuator connector.
Hardware versus software emphasis:
• while the emphasis of M2M is more on hardware with embedded
modules, the emphasis modules, the emphasis of IoT is more on
software . IoT devices run specialist software sensor Data Collection,
data analysis and interfacing with cloud through IP based
communication.
Data collection and analysis:
• M2M data is collected in point solutions and often in on premises
storage infrastructure. In contrast to M2M,the data in IoT is connected
in the cloud. The analytical component analysis the data and stores the
result in the cloud database. Data and analysis results are visualized
with the cloud based applications. The centralized controller is aware
of the status of all the nodes and send Control Commands to the nodes.
Applications:
• M2m data is collected in point solutions and can be accessed by on
premises application diagnosis applications, service management
applications , and on-premises enterprise application. IoT data is
collected in cloud and can be accessed by cloud applications such as
analytics,enterprise, remote diagnosis and management applications.
Basic building blocks of an IoT Device
• Sensing
• Sensors can be either on-board the IoT device or attached to the device.
• Actuation
• IoT devices can have various types of actuators attached that allow taking actions
upon the physical entities in the vicinity of the device.
• Communication
• Communication modules are responsible for sending collected data to other
devices or cloud-based servers/storage and receiving data from other devices and
commands from remote applications.
• Analysis & Processing
• Analysis and processing modules are responsible for making sense of the collected
data.
Physical Design of IoT
Things of IoT
• The “Things” in IoT usually refers to IoT devices which have unique
identities and can perform remote sensing, Actuating and monitoring
capabilities. IoT devices can exchange data with other connected devices
and applications (directly or indirectly), or collect data from other
devices and process the data locally or send the data to Centralized
servers or cloud based applications back ends for processing the data or
from some task locally and other task within the IoT infrastructure, based
on temporal and space constraints (ie : Memory, processing calibrators,
communication latencies and speed and deadlines).
• An IoT device may consist of several interfaces connections to other
devices, both wired and wireless. These include I)IoT interfaces for
sensors II) interfaces for internet connectivity III) memory and storage
interfaces IV) audio video interfaces.
• An IoT Device can collect various types of data from the the onboard
or attached sensors, such as temperature e , humidity, light intensity.
• IoT devices can also be varied types, for instance, wearable sensors,
smart watches, LED light automobiles and industrial machines.
Almost all I would advise generate data in Some form or the other
which when processed by Data Analytics systems leads to Useful
information to guide further actions locally or remotely.
IoT Protocol:
• Link Layer:
• Link Layer protocols determine how the data is physically sent over the
networks physical layer or medium (example copper wire, electrical cable, or
radio wave). The Scope of The Link Layer is the Last Local Network
connections to which host is attached. Host on the same link exchange data
packets over the link layer using the link layer protocol. Link layer determines
how the packets are coded and signaled by the hardware device over the
medium to which the host is attached.
• 802.3 Ethernet:
• 802.3 is a collections of wired Ethernet standards for the link layer. For
example 802.3 10BASE5 Ethernet that uses coaxial cable as a shared medium,
802.3.i is standard for 10 BASET Ethernet over copper twisted pair
connection, Standards provide data rates from 10 Mb/s to 40 gigabits per
second and the higher. The shared medium in Ethernet can be a coaxial cable ,
twisted pair wire or and Optical fiber. Shared medium carries the
communication for all the devices on the network.
• 802.1- WI-FI:
• IEEE 802.3 is a collections of wireless Local area network.(WLAN) communication
standards, including extensive descriptions of the link layer. For example 802.11a operate
in the 5 GHz band, 802.11b and 802.11g operate in the 2.4 GHz band. 802.11ac operates
in the 5G hertz band.
• 802.16 wiMAX:
• IEEE 802.16 is a collection of wirless broadband and Standards, including extensive
descriptions for the link layer also called WiMAX wimax standard provides a data rates
from from 1.5 Mb/s to 1Gb/s the recent update provides data rates of hundred megabits
per second for mobile station.
• 802.15.4 LR-WPAN:
• IEEE 802.1 5.4 is a collections of standard for low rate wireless personal area
network(LR-WPAN).These standard form the basis of specifications for high level
communication Zigbee. LR-WPAN standards provide data rates from 40 k b/ s. These
standards provide low cost and low speed Communications for power constrained
devices.
• 2G / 3G / 4G mobile communications:
• These are the different generations of mobile communication
standards including second generation (2G including GSM and
CDMA). 3rd Generation (3G including UMTS and CDMA2000) and
4th generation 4G including LTE.
• Network / internet layer :
• The network layer are responsible for sending of IP datagrams from
the source network to the destination network. This layer Performs the
host addressing and packet routing. The datagrams contains a source
and destination address which are used to route them from the source
to the destination across multiple networks. Host Identification is done
using the hierarchy IP addressing schemes such as ipv4 or IPv6.
• IPV4: Internet protocol versions for open parents close (IPV4) is there
most deployed internet protocol that is used to identify the device is on
a network using a hierarchy latest schemes. It uses 32 bit addresses
scheme that allows total of 2 32 address.
• IPv6: It is the newest versions of internet protocol and successor to
IPv4. IPv6 uses 128 bit address schemes that are lost total of 2 128
address.
• 6LoWPAN:
• IPv6 over low power wireless personal area networks brings IP
protocol to the low power device which have limited processing
capability it operate in the 2.4 GHz frequency range and provide the
data transfer rate off to 50 kb/s.
• Transport layer :
• The Transport layer protocols provides end-to-end message
transfer capability independent of the underlying network.
The message transfer capability can be set up on
connections, either using handshake or without handshake
acknowledgements. Provides functions such as error control ,
segmentation, flow control and congestion control.
• TCP: Transmission control protocol is the most widely used to transport layer
protocol that is used by the web browsers along with HTTP , HTTPS
application layer protocols email program (SMTP application layer protocol)
and file transfer protocol. TCP is a connection Oriented and stateful protocol
while IP protocol deals with sending packets, TCP ensures reliable
transmissions of packets in order. TCP also provide error deduction capability
so that duplicate packets can be discarded and low packets are retransmitted .
The flow control capability ensures that the rate at which the sender since the
data is now to too to high for the receiver to process.
• UDP: unlike TCP, which requires carrying out an initial setup procedure, UDP
is a connection less protocol. UDP is useful for time sensitive application they
have very small data units to exchange and do not want the overhead of
connection setup. UDP is a transactions oriented and stateless protocol. UDP
does not provide guaranteed delivery, ordering of messages and duplicate
eliminations.
• Application layer :
• Application layer protocol define how the application interfaces with the lower
layer protocols to send the data over the network. Data are typically in files, is
encoded by the application layer protocol and encapsulated in the transport layer
protocol .Application layer protocol enable process-to-process connection using
ports. Http: Hypertext transfer protocol is the application layer protocol that forms
the foundations of world wide web http includes, ,commands such as GET, PUT,
POST, DELETE, HEAD, TRACE, OPTIONS etc. The protocol follows a
requestresponse model where are client sends request to server using the http,
commands. Http is a stateless protocol and each http request is independent father
request and http client can be a browser or an application running on the client
example and application running on an IoT device ,mobile mobile applications or
other software.
• CoAP: Constrained application protocol is an application layer protocol
for machine to machine application M2M meant for constrained
environment with constrained devices and constrained networks. Like
http CoAP is a web transfer protocol and uses a request- response model,
however it runs on the top of the UDP instead of TC CoAP uses a client
–server architecture where client communicate with server using
connectionless [Link] is designed to easily interface with http like
http,CoAP supports method such as GET, PUT, DELETE .
Websocket:Websocket protocol allows full duplex communication over a
single socket connections for sending message between client and server.
Websocket is based on TCP and Allows streams of messages to be sent
back and forth between the client and server while keeping the TCP
connection open. The client can be a browser, a mobile application and
IoT device
• MQTT :Message Queue Telemetry Transport it is a lightweight message
protocol based on public -subscribe model MQTT uses a client server
Architecture by the clients such as an IoT device connect to the server
also called the MQTT broker and publishers message to topic on the
server. The broker forward the message to the clients subscribed to topic
MQTT is well suited for constrained and environments.
• XMPP: Extensible Messaging and Presence Protocol it is a protocol for
real-time communication and streaming XML data between network
entities XMPP powers wide range of applications including messaging,
presence, data syndication, gaming multiparty chat and voice / voice
calls. XMPP Allows sending small chunks of XML data from one
network entity to another in real time. XMPP supports both client to
server and server –client communication path.
• DDS: Data distribution service is the date centric middleware standard
for device to-device , machine to machine communication DDS uses a
publish subscribe model where publisher example device that generate
data create topics to which subscribers per can subscribe publisher is an
object responsible for data distributions and the subscriber responsible
for receiving published data. DDS provide quality of service (QoS)
control and configurable reliability
• AMQP: Advanced Message Queuing protocols. it is an open application
layer protocol for business messaging. AMQP support point to point and
publish -subscribe model routing and queuing. AMQP broker receive
message from publishers example devices or applications that generate
data and about them over connections to consumers publishers publish
the message to exchange which then distribute message copies to queues.
Layered IoT Architecture
• The standardization organizations are working on designing layered
architecture for IoT. However, as of now, IoT devices have no standard
architecture; there are few tentative models that are being used by the
researchers. The existing IoT architectures have three, four, or five layers;
the most widely used is the three-layered architecture: application layer,
middleware layer, and sensor layer, as shown in figure.
• Perception/sensor layer: This layer identifies objects uniquely within the
IoT networks. It also uses sensors to collect data from its surroundings and
other objects. This layer deploys WSN or RFID tags depending upon the
applications’ requirements. The data collected by the sensors is transferred
to the middleware layer for further processing.
• Middleware layer: This layer provides a set of communication protocols and
network support methodologies to IoT devices. In this layer has been divided
into two or more layers each providing different services depending upon the
requirements of IoT network.
• In some four-layered architectures, A processing layer that collects and
processes data from the sensor layer; the processed data is then sent to a
transport layer, which provides access to communication technologies such as
Bluetooth and Wi-Fi to send and receive [Link] layer also assigns unique
addresses to objects within a network using IPv6 addressing.
• Application layer: This layer receives processed data from its subsequent
layers and uses it according to the applications’ requirements. Some
architectures divide this layer into two parts: the business layer deals with the
security and privacy requirements of an application and manages the data, and
the upper application layer deals with interoperability and distinguishes among
various applications.
IoT enabling Technologies
• 1 wireless sensor network
• Wireless sensor network ( wsn) comprise of distributed devices with
the sensor which are used to monitor the environmental and physical
conditions. A WSN consists of a number of end nodes and routers and
a coordinator. End nodes have several sensors attached to them. End
node can also act as a routers. Routers are responsible for routing the
data packet from end nodes to the coordinator. The coordinator node
collect the data from all the notes coordinator also act as a Gateway
that connects the WSN to the internet. IoT systems are described as
follows
• Weather monitoring system using WSN in which the nodes collect
temperature, humidity and other data which is aggregated and analyzed .
• Indoor air quality monitoring system using WSN to collect data on the
indoor air quality and connections of various gases.
• Soil moisture monitoring system using WSN to monitor soil moisture
at various location.
• Surveillance systems use WSN for collecting surveillance data(motion
detection data)
• Smart grid use wireless sensor network for monitoring the grid at
various point.
• Structural health monitoring systems use WSN to monitor the health
of structure by writing vibration data from sensor nodes deployed at
various points in the structure.
• 2 Cloud computing:
• Cloud Computing is a transformative computing paradigm that involves delivering
applications and services over the internet.
• Cloud Computing involves provisioning of computing networking and storage resources
on demand and providing these resources as metered services to the users, in a “ pay as
you go” model.
• cloud Computing resources can be provisioned on demand by the user without requiring
interactions with the Cloud Service Provider. The process of provisioning resources used
automatic Cloud Computing resources can be accessed then it worked using standard
access mechanism that provide platform-independent access through the use of
heterogeneous client platforms such as workstations laptops tablets and Smartphones the
computing and storage resources provided by Cloud Service Provider.
• Cloud Computing services are offered to user in different forms
• Infrastructure as a service(IAAS) :
• IaaS provides the user the ability provision computing and storage resources. These resources are
provided to the users as virtual machine instances and virtual storage. Users can start, stop configure
and manage the virtual machines instance on the virtual storage using can deploy operating systems
and applications on their choice on the actual resources provisions in the cloud . Cloud Service
Provider manages the underlying infrastructure.
• Platform as a service(PaaS) :
• platform as a service provides the user the ability to develop and deploy application in the cloud
using the deployment tool application programming interfaces API, software libraries and services
provided by the Cloud Service Provider. The Cloud Service Provider manages the underlying cloud
infrastructure including servers, network, operating systems and storage .
• Software as a service(SaaS) :
• Provide the user a complete software applications of the user interface to the application itself . The
Cloud Service Provider manage the underlying cloud infrastructure including server, network storage
and application software, and the user is unaware of the underlying architecture of the cloud.
Applications are provided to the user through a thin client interface example Browser application.
SaaS applications are accessed from various client smartphones running different operating system.
• 3 Big Data Analytics
• Big data is defined as collections of data set whose volume, velocity in terms of its
temporal variations )or variety, is so large that it is difficult to store, manage,
process and analyze the data using traditional database and data processing tools.
Big Data Analytics involving several steps starting from Data cleaning data
munging data processing and visualization. Some examples of big data generated
by IoT systems are described as follows
• 1. Sensor data generated by IoT system such as weather monitoring stations
• 2. Machine sensor data collected from sensor embedded in Industrial and energy
system for monitoring their files and protecting failure
• 3. Health and fitness data generated by IoT devices such as wearable fitness band.
• 4. Data generated by IoT system for Location tracking of vehicle.
• 5. Data generated by retail inventory monitoring system.
• Characteristics of data include:
• Volume: Though there is no fixed threshold for volume of data to be
considered as big data, however the term big data is used for massive scale
data that is difficult to store,manage and process using traditional data bases
and data processing architecture. The volume of data generated by modern IT,
industrial and Healthcare systems for example is a growing exponentially
driven by the lowering cost of data storage and processing architectures and
the need to extract valuable insights from the data to improve business
processes, efficiency and services to consumer.
• Velocity: Velocity is another important characteristics of big data and the
primary reasons for exponential growth of data velocity of the data of a store
how fast the data is generated and how frequently it varies. Modern IT
Industrial and other systems are generating data at increasing the highest
speeds.
• Variety: Variety refers to the forms of the data. Big data comes in for different
forms such as structured or unstructured data including text data, audio, video
and sensor data .
• [Link] protocol:
• Communications protocols form the backbone of IoT system and enable
network connectivity and coupling to applications. Communications protocols
allow device to exchange data over the network. These protocols define the
data exchange formats and data encoding schemes for devices and routing of
packets from source to destination. Other function of the protocol include
sequence control flow control and transmissions of Lost packet.
• 5 Embedded systems
• An Embedded system is computer system that has computer hardware and
software embedded perform specific task. In contrast to general purpose
computers or personal computers which can perform various types of tasks,
embedded systems are designed to perform a specific set of tasks. Embedded
system include Microprocessor and Microcontroller memory Ram ROM cache
networking units (Ethernet WI-FI adaptor) input/output unit display keyboard ,
display and storage such as Flash Memory.
SECURITY AND PRIVACY ISSUES WITH IoT
ARCHITECTURE
• In order to ensure security in IoT applications, our primary aim is to address the security- and
privacy-related issues at each layer of IoT architecture. The existing architectures require strong
security checks and traffic monitoring at regular intervals.
1 Perception-Layer Security Problems
• The primary technologies used in the perception layers are WSN, RFID, and other types of sensing
and identification techniques. The most common types of threats faced by this layer are as follows:
a. Node capture: The nodes present at the network gateway are more likely to be compromised,
which may result in the leakage of important information that poses a serious threat to the security
of the entire network.
b. Fake node and malicious data: The adversary can add a malicious node to the existing system
through which they can circulate malicious codes and information over the network, and can infect
the whole system.
c. Replay attack: The adversary replays a previous message to the destination node so as to
compromise the network trust and authentication schemes.
2 Network-Layer Security Problems
• At the network layer, we have to deal with threats to confidentiality, integrity,
and availability. Attacks such as eavesdropping, man-in-the middle,
DoS/DDoS, and network intrusion are common threats at this layer.
a. Heterogeneity: Due to the use of different technologies and protocols,
security and network coordination are hard to maintain, thus making the
system vulnerable.
b. Scalability issues: IoT comprises a large number of devices within a
network, and more devices may enter or leave the network at different times,
which raises issues such as a lack of authentication and network congestion. It
also depletes a lot of resources.
c. Data disclosure: Using social engineering techniques, the adversary might
be able to obtain sensitive information from the network. The IoT devices
collectively have huge amounts of data; therefore, using certain data retrieval
techniques makes it easy to extract information from the nodes.
• 3 Application-Layer Security Problems
• This layer needs different security standards as per the application’s requirements, which
makes the task of securing the application hard and complicated. Some of the security and
privacy issues at this layer are as follows:
a. Mutual authentication and node identification: Each application has a different set of
users, which requires various degrees of access privileges. Thus, to prevent any illegal
access, effective authentication schemes should be applied.
b. Information privacy: User privacy should be ensured for each communication session.
However, in some cases, the techniques that are being used to process data might be
vulnerable, which leads to data loss. Over a long term, it can create huge damages to the
system.
c. Data management: Due to huge data collections, the system complexity increases,
which requires a lot of resources and complex algorithms for data management. It may
also result in data loss.
d. Application-specific vulnerabilities: While developing modules for an application,
some vulnerabilities might be left behind, which are unknown to the user. These can be
exploited by the adversary later on.
Tools for IoT-Introduction
• Managing IoT infrastructure and configuring and integrating various
components can be complex.
• The complexity of infrastructure grows with increasing the number of
components.
• To minimise the manual effort, a new paradigm of infrastructure as a
code has been popularised by infrastructure automation and
configuration management tools such as Chef and Puppet.
• In the infrastructure as a code paradigm the computing, storage and
network infrastructure is modeled using declarative modelling
languages.
• A modular approach is adopted for modeling the infrastructure to
improve code re-usability.
• The infrastructure models are compiled and run by infrastructure
automation tools to generate the desired infrastructure.
• infrastructure as a code improves the repeatability of the infrastructure.
• Modular code design along with the automation capabilities improve
the scalability of systems.
• Moreover, in the event of system failures or catastrophic events, the
entire infrastructure can be restored from the infrastructure code.
An Internet of Things (IoT)-Based Security
Approach Ensuring Robust Location Privacy
for the Healthcare Environment
• Recently, various applications of IoT are being developed for the
healthcare domain. In this our contribution is to design a lightweight
security approach for the Internet of Things (IoT) devices in healthcare.
The main goal is to make patients’ lives easier and comfortable and to
provide them more effective treatment. In addition, intend to address the
issues related to location privacy and security due to the deployment of
IoT devices.
• Proposed a very simple mutual authentication protocol, which provides
strong location privacy using hash function, pseudo-random number
generator (PRNG), and bitwise operation. The security strength of
protocol is verified through a formal proof model for location privacy.
• PROBLEM DEFINITION
• In order to ensure privacy in the healthcare domain, the identity of tags must remain a secret to all
unauthorized parties. Tag’s identity is disclosed to authorized readers only. Every reader should
authenticate itself to the tag before any communication. The location privacy can be protected if the tag
identifier (ID) is protected. The ID is a fixed integer value set during manufacturing that uniquely identifies
a tag. This ID is permanent until the tag dies or is destroyed. Sometimes tag ID leaves certain traces
analyzing which the adversary can find out the tag ID. The disclosure of tag ID poses a serious threat to
devices in a network. Therefore, designed a very simple mutual authentication algorithm, which aims to
secure the tag ID.
• The proposed solution is a challenge response-based scheme. In this case, to ensure location privacy, the
solution provides indistinguishability and forward secrecy.
• First, ensuring that the adversary is not able to identify which tag is communicating with the reader, that is,
indistinguishability.
• Second, ensure that in case the current secret parameters are revealed, it does not compromise the security
of earlier parameters.
• In order to ensure the security of an IoT system, we need to ensure the basic security requirements at the radio
frequency identification (RFID) level.
• 1 Location Privacy-Based Mutual Authentication Protocol: Location privacy is one of the most prominent threats to
IoT devices. In case of RFID tags, the message exchange between the server and the tag is done via radio frequency,
thus making it easier for attackers to extract the information during communication. If the messages are not properly
secured or encrypted, it might lead to the infringement in the devices’ location privacy. Each RFID tag has
information for computation purposes; thus, security issues are there automatically.
• In healthcare sector, the problem of location tracking is of utmost concern as it may disclose a person’s private and
sensitive information. By being able to trace a tag’s location, the adversary might also detect a patient’s movements
and activities, which poses a very serious threat. For any protocol to ensure strong location privacy, two conditions
need to be satisfied :
Indistinguishability: The parameters sent by various tags cannot be distinguished by any adversary.
Forward secrecy: It ensures that even if the adversary obtains secret parameters of a tag, they are not able to track its
location with the help of messages from previous sessions.
• 2 Authentication of IoT Devices
• Before initiating a communication with a new device, users must ensure that it is legitimate (either from the hospital
or from the patient). Therefore, the requesting party should initialize an authentication session before any information
transfer. The hosting party, if legitimate, will then correctly authenticate itself using random challenge parameters. To
ensure security, the ID of the devices must always be protected. Whenever a party is required to send its ID value,
proper encryption must be done. For such requirements, various lightweight cryptographic mechanisms are used.
• IoT AUTHENTICATION SCHEME ENSURING LOCATION PRIVACY
• The idea of a simple authentication protocol to ensure location privacy for
devices in [Link] shows Secure communication among IoT
sensors and server.
Setup: Here, tuple (ID, k) of the devices are stored by the reader. The
devices and the reader also have PRNGs for generating fresh nonce
values for authentication in every session. The messages in transit are
encrypted using one-way hash (h()). The attacker analyzes the traffic
for secret information, which is sent via radio frequency, and records
the communication between the server and the tag. However, it is not
possible for the attacker to decrypt the hash values; therefore, each
message has a new random variable value. For each tag, these values
will be different; thus, the intercepted information is of no use to the
attacker.
• Concept of a Basic Location Privacy-Based Authentication Scheme
• i. The reader sends a session initialization message to the tag.
• ii. The tag generates a random nonce value Nt , calculates X =h((ID ≪
k) ≪ Nt), and then sends (X, Nt) to the reader.
• iii. On receiving tag’s response, the reader now calculates X ′ = h((ID
≪ k) ≪ Nt) and compares it with X. If X ′ = X, then the reader
generates another random nonce value Nr, calculates Y = h((ID ≪ Nr)
≪ Nt), and sends (Y, Nr) to the tag.
• iv. On receiving the response from the reader, if the tag is able to
calculate the value of Y and it matches the value received, then the
session will be successful. If the computed value Y does not match the
received value, then the session is immediately dropped.

You might also like