<p>The Internet of Things (IoT) constitutes an ecosystem of 6LoWPAN networked resource-constrained devices that entail lightweight security solutions. Owing to the resource limitation of these devices and the delay-sensitive nature of applications running on them, an efficient authentication mechanism is required to validate requesters’ identities with minimum resources and delay. In this work, we adopted the Hessian curve, a variant of the elliptic curve and unexplored in Elliptic Curve Cryptography, to propose a distributed authentication mechanism called <i>HessianAuth</i>. Unlike other elliptic curves, it avoids using the expensive “point inversion” curve operation. We leveraged this property to generate digital signatures for authenticating device identities for low-power devices in IoT networks. We simulate a 6LoWPAN environment on the Contiki-based Cooja simulator and empirically show that our approach outperformed three baselines: AES-CBC, the standard Weierstrass curve-based ECC, and the Edward curve-based ECC regarding CPU usage, latency, and power consumption. Finally, we conduct a theoretical security analysis to deduce the validity of mutual authentication done by <i>HessianAuth</i> and its robustness to various identity theft attacks.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

HessianAuth: A Secure and Efficient Authentication Mechanism for Resource-Constrained IoT Networks

  • Debasmita Dey,
  • Nirnay Ghosh

摘要

The Internet of Things (IoT) constitutes an ecosystem of 6LoWPAN networked resource-constrained devices that entail lightweight security solutions. Owing to the resource limitation of these devices and the delay-sensitive nature of applications running on them, an efficient authentication mechanism is required to validate requesters’ identities with minimum resources and delay. In this work, we adopted the Hessian curve, a variant of the elliptic curve and unexplored in Elliptic Curve Cryptography, to propose a distributed authentication mechanism called HessianAuth. Unlike other elliptic curves, it avoids using the expensive “point inversion” curve operation. We leveraged this property to generate digital signatures for authenticating device identities for low-power devices in IoT networks. We simulate a 6LoWPAN environment on the Contiki-based Cooja simulator and empirically show that our approach outperformed three baselines: AES-CBC, the standard Weierstrass curve-based ECC, and the Edward curve-based ECC regarding CPU usage, latency, and power consumption. Finally, we conduct a theoretical security analysis to deduce the validity of mutual authentication done by HessianAuth and its robustness to various identity theft attacks.