TARU PUBLICATIONS
Journal of Information and Optimization Sciences cover
Open Access ·Peer-reviewed·ISSN (Online): 2169-0103·ISSN (Print): 0252-2667

WoS  JIF 2026 : 0.4 (Q4)

Powered by:Powered by

Monthly Journal: Publishes theoretical and applied research on topics in information and optimization sciences.

Issues up to 2022 co-published with and available at:Taylor & Francis
submissions@tarupublications.com
Open Access Research Article

PUF-based user access control scheme for IoT environment

* , , ,

* Corresponding author · click or hover a name for details

pp. 1347–1364Vol. 44Issue 7October 2023DOI: 10.47974/JIOS-1321XML
Received:
03 Nov 2021
Accepted:
05 Jul 2022
Published Online:
19 Oct 2023
Article type:
Research Article
Language:
EN
Article no.:
JIOS-1321
Pages:
1347–1364

Abstract

A very important part of any software or hardware associated with the Internet of Things (IoT) is the User Access Control. User Access Control deals with the important security features like authenticating a legitimate user, authorizing a user, etc. A very effective and secure way to ensure the user access control is: three factor user access control. Some three factor user authentication schemes have been developed in the past, brief details regarding them can be found in further sections of the paper. In this paper, we propose a new three factor user access control scheme. Our proposed scheme is based on Mandal et. al.’s user access control scheme published recently. Our scheme involves the use of lightweight cryptographic primitives like Physically Unclonable Function (PUF), one way cryptographic hash function and bitwise exclusive OR (XOR) operations. PUFs make the scheme very lightweight and efficient as compared to other schemes of similar nature. The three factors used in our scheme are: registered device of the user, personal biometrics of the user and password of the user. We present the informal security analysis to show that our scheme is safe from several known attacks.

Keywords

Subject Classifications

94A62

References

[1] “The internet of things: a movement, not a market,” tech. rep., HIS Markit (2017).
[2] M. Wazid, A. K. Das, R. Hussain, G. Succi, and J. J. Rodrigues, “Authentication in cloud-driven iot-based big data environment: urvey and outlook,” Journal of Systems Architecture, vol. 97, pp. 185–196 (2019).
[3] D. Dolev and A. Yao, “On the security of public key protocols,” IEEE Transactions on Information Theory, vol. 29, no. 2, pp. 198–208 (1983).
[4] S. Mandal, B. Bera, A. K. Sutrala, A. K. Das, K.-K. R. Choo, and Y. Park, “Certificateless-signcryption-based three-factor user access control scheme for iot environment,” IEEE Internet of Things Journal, vol. 7, no. 4, pp. 3184–3197 (2020).
[5] M. Luo, Y. Luo, Y. Wan, and Z. Wang, “Secure and efficient access control scheme for wireless sensor networks in the cross-domain context of the iot,” Security and Communication Networks, vol. 2018 (2018).
[6] J. Xue, C. Xu, and Y. Zhang, “Private blockchain-based secure access control for smart home systems.,” KSII Transactions on Internet & Information Systems, vol. 12, no. 12 (2018).
[7] X. Zeng, G. Xu, X. Zheng, Y. Xiang, and W. Zhou, “E-aua: An efficient anonymous user authentication protocol for mobile iot,” IEEE Internet of Things Journal, vol. 6, no. 2, pp. 1506–1519 (2018).
[8] H. Yu, J. He, T. Zhang, P. Xiao, and Y. Zhang, “Enabling end-to-end secure communication between wireless sensor networks and the internet,” World Wide Web, vol. 16, no. 4, pp. 515–540 (2013).
[9] F. Li, J. Hong, and A. A. Omala, “Efficient certificateless access control for industrial internet of things,” Future Generation Computer Systems, vol. 76, pp. 285–292 (2017).
[10] D. Kumar, “A secure and efficient user authentication protocol for wireless sensor network,” Multimedia Tools and Applications, vol. 80, no. 18, pp. 27131–27154 (2021).
[11] D. Kaur, K. K. Saini, and D. Kumar, “Cryptanalysis and enhancement of an authentication protocol for secure multimedia communications in iot-enabled wireless sensor networks,” Multimedia Tools and Applications, pp. 1–19 (2022).
[12] P. Kumar, A. Gurtov, J. Iinatti, M. Sain, and P. Ha, “Access control protocol with node privacy in wireless sensor networks,” IEEE Sensors Journal, vol. PP, pp. 1–1 (09 2016).
[13] C. Ma, K. Xue, and P. Hong, “Distributed access control with adaptive privacy preserving property for wireless sensor networks,” Security and Communication Networks, vol. 7, no. 4, pp. 759–773 (2014).
[14] D. Q. Bala, S. Maity, and S. K. Jena, “Mutual authentication for iot smart environment using certificate-less public key cryptography,” in 2017 Third International Conference on Sensing, Signal Processing and Security (ICSSS), pp. 29–34, IEEE (2017).
[15] A. Karati, S. H. Islam, and G. Biswas, “A pairing-free and provably secure certificateless signature scheme,” Information Sciences, vol. 450, pp. 378–391 (2018).
[16] N. Pakniat and B. A. Vanda, “Cryptanalysis and improvement of a pairing-free certificateless signature scheme,” in 2018 15th International ISC (Iranian Society of Cryptology) Conference on Information Security and Cryptology (ISCISC), pp. 1–5, IEEE (2018).
[17] A. Robinson and R. Steinwandt, “Group key establishment with physical unclonable functions,” Journal of Information and Optimization Sciences, vol. 40, no. 1, pp. 69–80 (2019).
[18] P. Gope, A. K. Das, N. Kumar, and Y. Cheng, “Lightweight and physically secure anonymous mutual authentication protocol for real-time data access in industrial wireless sensor networks,” IEEE Transactions on Industrial Informatics, vol. 15, no. 9, pp. 4957–4968 (2019).
[19] S. Banerjee, V. Odelu, A. K. Das, S. Chattopadhyay, J. J. Rodrigues, and Y. Park, “Physically secure lightweight anonymous user authentication protocol for internet of things using physically unclonable functions,” IEEE Access, vol. 7, pp. 85627–85644 (2019).
[20] P. Gope, J. Lee, and T. Q. Quek, “Lightweight and practical anonymous authentication protocol for rfid systems using physically unclonable functions,” IEEE Transactions on Information Forensics and Security, vol. 13, no. 11, pp. 2831–2843 (2018).

Views: 191Downloads: 68Citations: 0