Because of its closeness to users, fog computing responds faster than cloud computing. Thus, it has been deployed to various applications, such as healthcare system. Recently, to ensure the secure communication of the fog-based healthcare system, Jia et al. proposed an authenticated key agreement scheme. Moreover, in view of the high computation cost existing in Jia et al.’s scheme, Ma et al. presented an efficient one using elliptic curve cryptography. In this paper, we observe that both the two schemes may potentially risk ephemeral key compromise attacks and need improving. Therefore, to overcome this potential risk, we propose a new authenticated scheme based on Jia et al.’s scheme using elliptic curve computational Diffie-Hellman hypothesis and hash functions. Additionally, we provide provable security under the adopted adversarial model and ProVerif simulation, and also analyze the performance in terms of computation and communication costs by comparisons. The analysis results show that the improved scheme resists the common attacks, reduces computation overhead, and has a certain significance.
1 Introduction and contributions The rapid advancement in 5G networks calls for more key technologies to support.To promote its wide deployment and application,ultra-dense network(UDN)plays a significant part by providing high data rate and realizing seamless coverage and low delay.There have proposed many related works on 5G UDN,such as the literatures[1,2].
>Dear editor,Numerous three-party authenticated key exchange(3 PAKE)protocols have been presented, which allow the establishment of a secure session by utilizing a session key shared between two clients with the assistance of a server trusted by both the clients via an unprotected network communication environment. The 3 PAKE protocols can be applied to various scenarios, including mobile commerce environment.
This letter claimed that Mahmood et al.’s scheme still exhibited some vulnerabilities. Concretely, their scheme cannot withstand an impersonation attack and fails to realize perfect forward secrecy and mutual authentication with the absence of the trusted authority. Moreover, their scheme could suffer from an ephemeral key compromise attack under the CK threat model. We, therefore, fixed those weaknesses and proposed a new security-enhanced scheme where we changed the session keys’ format and added robust authentication between the smart meter and utility control. The computation cost, however, is higher in the new scheme (seen in Appendix D) and we do not solve the key escrow problem. In the future, we wish to design protocol with computation cost declined and give solutions to the key escrow problem for the smart grid infrastructure.