The advent of Internet of Things (IoT) ushers in a significant potential to integrate individuals, devices, and data, leading to a profound change in our professional and social environments. The small, resource-constrained IoT devices are usually deployed to collect various types of critical data in remote or unmonitored locations. Due to extensive interconnectivity, limited resources, and inadequate security design, IoT systems are vulnerable to communication-specific cyber threats, which aim to disrupt operations, steal sensitive information, or cause damage. To resolve the security concerns in IoT communications, many recent efforts have been devoted to designing authenticated key agreement protocols for IoT systems. However, not only most of the existing solutions fail to adopt cost-effective techniques for resource-limited IoT devices, but also they ignore the differentiation among various data types in the established session keys. A few approaches use traditional physical unclonable functions (PUFs) to address resource concerns, yet they introduce new security issues into IoT systems. Once the PUF cryptographic information is compromised by machine learning attacks, the entire authentication framework collapses. Therefore, in this paper we propose an authenticated key agreement protocol for device-to-gateway communication in IoT systems based on Chebyshev polynomial and probability-based PUF. We examine the proposed protocol’s security features through formal security validation. We also conduct performance evaluation through a simulation-oriented study, and the results clearly prove that the proposed protocol offers superior security and privacy, while maintaining low computational overhead.
更多
查看译文
关键词
Mutual authentication,key agreement,security,device-to-gateway,Internet of Things (IoT)