Main Article Content

Provably secure and channel characteristic aware authentication and key agreement scheme for cloud-based IoT environments


Ashiru Musa
Mubarak Umar
Muhammad Yusuf Muhammad
Hafsa Kabir Ahmad

Abstract

The incorporation of cloud computing into IoT environments mitigates storage limitations and offers opportunities across various industries. However, security and privacy challenges remain due to the open wireless channels, leading to vulnerabilities like privileged insider and impersonation attacks. Recently, researchers have proposed various authentication and key agreement schemes suitable for resource-constrained devices. However, privileged insider attacks are among the most dangerous and persistent threats, enabling impersonation of legitimate entities in cloud-based IoT environments. To address these security threats, we proposed a secure and reliable authentication mechanism for cloud-based IoT environments that utilises wireless channel characteristics to protect the critical security parameters in the control server using the Received Signal Strength (RSS) parameter. To show the robustness of our scheme, we conducted an experiment and a security analysis using the Scyther simulation tool, MATLAB, and BAN-logic. The results show that we achieved a False Rejection Rate (FRR) of 8.8% and a False Acceptance Rate (FAR) of 10%, and an Equal Error Rate (EER) 9.40% with lower communication costs and slightly higher computational costs.


 


Journal Identifiers


eISSN: 2635-3490
print ISSN: 2476-8316