Cryptanalysis and Countermeasures of "LAAKA: Lightweight Anonymous Authentication and Key Agreement Scheme for Secure Fog-Driven IoT Systems

Citations

WEB OF SCIENCE

1
Citations

SCOPUS

1

초록

Fog computing is a technology that fog servers cover the computational tasks of cloud server. Therefore, end devices can receive more real-time and localized services from fog servers. Therefore, researchers integrate fog computing and Internet of Things (IoT) to supplement the resource constraint problem of IoT devices and process data services in network edge. In 2024, Ali et al. proposed a mutual authentication and key agreement protocol to preserve anonymous and lightweight communications in fog-driven IoT environments. They utilized only hash functions and exclusive-OR (XOR) operators considering hardware specifications of IoT devices. In this work, we cryptanalysis Ali et al.'s authentication protocol to prove that "ephemeral secret leakage (ESL)" and "stolen verifier attacks" can be performed in their protocol. Moreover, we discover that Ali et al.'s protocol has a "desynchronization problem" where network entities cannot conduct authentication after initial communication. To supplement these security flaws, we conduct a discussion and present countermeasures, such as physically unclonable function (PUF), dynamic update of temporary identity, and usage of long-term secret parameters.

키워드

Authentication; countermeasure; cryptanalysis; ephemeral secret leakage; stolen verifier; TECHNOLOGIES; EXCHANGE
제목
Cryptanalysis and Countermeasures of "LAAKA: Lightweight Anonymous Authentication and Key Agreement Scheme for Secure Fog-Driven IoT Systems
저자
Kwon, DeokKyu; Son, Seunghwan; Park, Youngho
DOI
10.1109/ICOIN63865.2025.10993049
발행일
2025
유형
Proceedings Paper
저널명
2025 INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING, ICOIN
페이지
286 ~ 290