论文标题
EBAKE-SE:使用安全元素的工业物联网设备之间的一种新型基于ECC的经过验证的密钥交换
EBAKE-SE: A Novel ECC Based Authenticated Key Exchange between Industrial IoT Devices using Secure Element
论文作者
论文摘要
工业物联网(IIT)旨在增强由制造和产品加工等各种行业提供的服务。 IIOT面临各种挑战,安全是这些挑战中的主要挑战之一。对于任何基于工业物联网(IIT)的工业部署而言,身份验证和访问控制是两个值得注意的挑战。任何基于物联网的行业4.0企业设计网络在数百个小设备(例如传感器,执行器,雾器设备和网关)之间。因此,在感应设备或传感设备和用户设备之间阐明安全的身份验证协议是IoT安全性的重要步骤。在本文中,首先,我们针对Das等人为类似环境提出的基于证书的方案提供了密码分析。并证明他们的方案容易受到各种传统攻击的攻击,例如设备匿名,MITM和DOS。然后,我们使用ECC(椭圆曲线密码学)提出了一个跨设备身份验证方案,该方案与类似环境的其他方案相比高度安全且轻巧。此外,我们使用基于Oracle的ROR模型和通过Doleve-YAO渠道进行了正式的安全性分析。在本文中,我们根据沟通成本,计算成本和安全指数介绍了拟议方案与现有方案的比较,以证明与其他现有方案相比,提出的Ebake-SE具有高效,可靠和可信赖的效率。最后,我们使用MQTT协议提出了针对拟议的Ebake-SE的实现
Industrial IoT (IIoT) aims to enhance services provided by various industries such as manufacturing and product processing. IIoT suffers from various challenges and security is one of the key challenge among those challenges. Authentication and access control are two notable challenges for any Industrial IoT (IIoT) based industrial deployment. Any IoT based Industry 4.0 enterprise designs networks between hundreds of tiny devices such as sensors, actuators, fog devices and gateways. Thus, articulating a secure authentication protocol between sensing devices or a sensing device and user devices is an essential step in IoT security. In this paper, first, we present cryptanalysis for the certificate-based scheme proposed for similar environment by Das et al. and prove that their scheme is vulnerable to various traditional attacks such as device anonymity, MITM, and DoS. We then put forward an inter-device authentication scheme using an ECC (Elliptic Curve Cryptography) that is highly secure and lightweight compared to other schemes for a similar environment. Furthermore, we set forth a formal security analysis using the random oracle based ROR model and informal security analysis over the Doleve-Yao channel. In this paper, we present the comparison of the proposed scheme with existing schemes based on communication cost, computation cost and security index to prove that the proposed EBAKE-SE is highly efficient, reliable, and trustworthy compared to other existing schemes for inter-device authentication. At long last, we present an implementation for the proposed EBAKE-SE using MQTT protocol