Forward Secrecy Attack on Privacy-Preserving Machine Authenticated Key Agreement for Internet of Things

Batamu Anderson Chiphiko , Hyunsung Kim , Patrick Ali , Levis Eneya

Archives of Advanced Engineering Science ›› 2025, Vol. 3 ›› Issue (1) : 29 -34.

PDF (795KB)
Archives of Advanced Engineering Science ›› 2025, Vol. 3 ›› Issue (1) :29 -34. DOI: 10.47852/bonviewAAES32021937
RESEARCH ARTICLE
research-article
Forward Secrecy Attack on Privacy-Preserving Machine Authenticated Key Agreement for Internet of Things
Author information +
History +
PDF (795KB)

Abstract

Internet of Things (IoT) is to connect billions of devices and machines via Internet and to have a smart system. Sensors and devices in IoT environment are connected and communicated together. Connecting such a huge number of devices requires high level of security and privacy. A crucial characteristic of ubiquitous IoT devices is their limited resources. In recent times, a scheme for privacy-preserving machine authenticated key agreement scheme (PPMAKA) has been introduced for the IoT environment. It was argued that PPMAKA provides security and privacy at the same time including forward secrecy. Nevertheless, this paper will demonstrate that PPMAKA lacks forward secrecy, a crucial security, and privacy feature in the IoT environment. We use Cannetti and Krawzyck threat model for the detailed analysis of PPMAKA. Furthermore, we provide remarks for the future research as it is recommendable to design any security and privacy schemes over IoT environments with lightweight operation and communication property, authenticated key agreement with forward secrecy, anonymity, and unlinkability.

Keywords

Internet of Things / authenticated key agreement / forward secrecy / privacy-preserving / information security

Cite this article

Download citation ▾
Batamu Anderson Chiphiko, Hyunsung Kim, Patrick Ali, Levis Eneya. Forward Secrecy Attack on Privacy-Preserving Machine Authenticated Key Agreement for Internet of Things. Archives of Advanced Engineering Science, 2025, 3 (1) : 29-34 DOI:10.47852/bonviewAAES32021937

登录浏览全文

4963

注册一个新账户 忘记密码

References

[1]

Aryavalli, S. N. G., & Kumar, G. H. (2024). Futuristic vigilance: Empowering chipko movement with cyber-savvy IoT to safeguard forests. Archives of Advanced Engineering Science, 2(4), 215-223. https://doi.org/10.47852/bonviewAAES32021480

[2]

Tao, W., Zhao, L., Wang, G., & Liang, R. (2021). Review of the Internet of Things communication technologies in smart agriculture and challenges. Computers and Electronics in Agriculture, 189, 106352. https://doi.org/10.1016/j.compag.2021.106352

[3]

Zhou, J., Hai, T., Jawawi, D. N. A., Wang, D., Lakshmanna, K., Maddikunta, P. K. R., & Iwendi, M. (2023). A lightweight energy consumption ensemble-based botnet detection model for IoT/6G networks. Sustainable Energy Technologies and Assessments, 60, 103454. https://doi.org/10.1016/j.seta.2023.103454

[4]

Srinivas, J., Das, A. K., Wazid, M., & Kumar, N. (2020). Anonymous lightweight chaotic map-based authenticated key agreement protocol for industrial Internet of Things. IEEE Transactions on Dependable and Secure Computing, 17(6), 1133-1146.

[5]

Wang, D., Wang, P., & Wang, C. (2020). Efficient multi-factor user authentication protocol with forward secrecy for real-time data access in WSNs. ACM Transactions on Cyber-Physical Systems, 4(3), 1-26. https://doi.org/10.1145/3325130

[6]

Kim, H., & Kapito, B. (2021). Security considerations on three-factor anonymous authentication scheme for WSNs. Journal of Computer and Communications, 9(3), 1-9.

[7]

Wang, Z., Huang, J., Miao, K., Lv, X., Chen, Y., Su, B., ..., & Han, M. (2023). Lightweight zero-knowledge authentication scheme for IoT embedded devices. Computer Networks, 236, 110021. https://doi.org/10.1016/j.comnet.2023.110021

[8]

Celdran, A. H., Sanchez, P. M. S., von der Assen, J., Shushack, D., Gómez, A. L. P., Bovet, G., ..., & Stiller, B. (2023). Behavioral fingerprinting to detect ransomware in resource-constrained devices. Computers & Security, 135, 103510. https://doi.org/10.1016/j.cose.2023.103510

[9]

Ding, H., Zhuang, C., & Liu, J. (2023). Extensions of the resource-constrained project scheduling problem. Automation in Construction, 153, 104958. https://doi.org/10.1016/j.autcon.2023.104958

[10]

Khan, M. K., & Alghathbar, K. (2010). Cryptanalysis and security improvements of two-factor user authentication in wireless sensor networks. Sensors, 10(3), 2450-2459. https://doi.org/10.3390/s100302450

[11]

Strahl, W. R., & Gounaris, C. E. (2023). A priority rule for scheduling shared due dates in the resource-constrained project scheduling problem. Computers & Industrial Engineering, 183, 109442. https://doi.org/10.1016/j.cie.2023.109442

[12]

Wong, K. H. M., Zheng, Y., Cao, J., & Wang, S. (2006). A dynamic user authentication scheme for wireless sensor networks. In IEEE International Conference on Sensor Networks, 1, 8.

[13]

Amin, R., Islam, S. K. H., Kumar, N., & Choo, K. K. R. (2018). An untraceable and anonymous password authentication protocol for heterogeneous wireless sensor networks. Journal of Network and Computer Applications, 104, 133-144. https://doi.org/10.1016/j.jnca.2017.12.012

[14]

Chang, C. C., & Le, H. D. (2016). A provably secure, efficient, and flexible authentication scheme for ad hoc wireless sensor networks. IEEE Transactions on Wireless Communications, 15(1), 357-366.

[15]

Chen, T. H., & Shih, W. K. (2010). A robust mutual authentication protocol for wireless sensor networks. ETRI Journal, 32(5), 704-712. https://doi.org/10.4218/etrij.10.1510.0134

[16]

Das, M. (2009). Two-factor user authentication in wireless sensor networks. IEEE Transactions on Wireless Communications, 8(3), 1086-1090.

[17]

Das, A. K., Sharma, P., Chatterjee, S., & Sing, J. K. (2012). A dynamic password-based user authentication scheme for hierarchical wireless sensor networks. Journal of Network and Computer Applications, 35(5), 1646-1656. https://doi.org/10.1016/j.jnca.2012.03.011

[18]

Fan, R., He, D., Pan, X., & Ping, L. (2011). An efficient and DoS-resistant user authentication scheme for two-tiered wireless sensor networks. Journal of Zhejiang University Science C, 12, 550-560. https://doi.org/10.1631/jzus.C1000377

[19]

Li, X., Niu, J., Bhuiyan, M. Z. A., Wu, F., Karuppiah, M., & Kumari, S. (2018). A robust ECC based provable secure authentication protocol with privacy protection for industrial Internet of Things. IEEE Transactions on Industrial Informatics, 14(8), 3599-3609.

[20]

Li, X., Niu, J., Kumari, S., Wu, F., Sangaiah, A. K., & Choo, K. K. R. (2018). A three factor anonymous authentication scheme for wireless sensor networks in Internet of Things environments. Journal of Network and Computer Applications, 103, 194-204. https://doi.org/10.1016/j.jnca.2017.07.001

[21]

Wang, D., & Wang, P. (2014). Understanding security failures of two-factor authentication schemes for real-time applications in hierarchical wireless sensor networks. Ad Hoc Networks, 20, 1-15. https://doi.org/10.1016/j.adhoc.2014.03.003

[22]

Jiang, Q., Ma, J., Wei, F., Tian, Y., Shen, J., & Yang, Y. (2016). An untraceable temporal-credential-based two factor authentication scheme using ECC for wireless sensor networks. Journal of Network and Computer Applications, 76, 37-48. https://doi.org/10.1016/j.jnca.2016.10.001

[23]

Kapito, B., Nyirenda, M., & Kim, H. (2021). Privacy-preserving machine authenticated key agreement for Internet of Things. International Journal of Computer Networks & Communications, 13(2), 99-120.

[24]

He, D., Kumar, N., & Chilamkurti, N. (2015). A secure temporal-credential-based mutual authentication and key agreement scheme with pseudo identity for wireless sensor networks. Information Sciences, 321, 263-277. https://doi.org/10.1016/j.ins.2015.02.010

[25]

Vaidya, B., Makrakis, D., & Mouftah, H. (2010). Improved two-factor user authentication in wireless sensor networks. In 2010 IEEE 6th International Conference on Wireless and Mobile Computing, Networking and Communications, 600-606.

[26]

Yeh, H., Chen, T., Liu, P., Kim, T.-H., & Wei, H. (2011). A secured authentication protocol for wireless sensor networks using elliptic curves cryptography. Sensors, 11(5), 4767-4779. https://doi.org/10.3390/s110504767

[27]

Shi, W., & Gong, P. (2013). A new user authentication protocol for wireless sensor networks using elliptic curves cryptography. International Journal Distributive Sensor Networks, 9(4). https://doi.org/10.1155/2013/730831

[28]

Choi, Y., Lee, D., Kim, J., Jung, J., Nam, J., & Won, D. (2014). Security enhanced user authentication protocol for wireless sensor networks using elliptic curves cryptography. Sensors, 14(6), 10081-10106. https://doi.org/10.3390/s140610081

[29]

Sarr, A. P., Elbaz-Vincent, P., & Bajard, J.-C. (2010). A new security model for authenticated key agreement. In J. A. Garay, & R. De Prisco (Eds.), Security and cryptography for networks (pp. 219-234). Springer.

[30]

Cerrudo, C. (2014). Why the shellshock bug is worse than heartbleed. Retrieved from: https://www.technologyreview.com/s/531286/why-the-shellshock-bug-is-worse-than-heartbleed/

[31]

Rescorla, E. (2018). The transport layer security (TLS) protocol version 1.3. Retrieved from: https://datatracker.ietf.org/doc/rfc8446/?include_text=1

[32]

Xue, K., Ma, C., Hong, P., & Ding, R. (2013). A temporal-credential-based mutual authentication and key agreement scheme for wireless sensor networks. Journal of Network and Computer Applications, 36(1), 316-323. https://doi.org/10.1016/j.jnca.2012.05.010

[33]

Wang, W. (2014). Heartbleed-OpenSSL zero-day bug leaves millions of websites vulnerable. Retrieved from: https://thehackernews.com/2014/04/heartbleed-openssl-zero-day-bug-leaves.html?utm_source=tuicool&utm_medium=referral

[34]

Lu, X., Yang, Y., & Gong, W. (2024). Challenges of ambient WiFi backscatter systems in healthcare applications. Computer Networks, 251, 110608.

PDF (795KB)

8

Accesses

0

Citation

Detail

Sections
Recommended

/