Lightweight certificateless authenticated key agreement protocol for IIoT
摘要
The Industrial Internet of Things (IIoT) plays a significant role in the manufacturing industry and promotes the development of industrial intelligence. However, industrial data are extremely confidential, and securing their transmission remains essential yet challenging. Authenticated key agreement (AKA) is a promising strategy for ensuring secure communication in IIoT. For resource-limited IoT devices, there has been a gradual shift toward the development of lightweight protocol schemes. Thus, certificateless AKA (CL-AKA) protocols are gradually being used in the IoT field. However, in recent years, many lightweight schemes have exhibited security loopholes and noted to be unable to resist key compromise impersonation attacks. To address these limitations, we propose a novel lightweight CL-AKA protocol scheme that can effectively avoid KCI attacks and is suitable for IIoT scenarios. The effectiveness of the proposed scheme is formally proven under the standard security model, demonstrating that it can satisfy the security requirement for communication between industrial devices and cloud servers. The proposed protocol outperforms existing IoT schemes in terms of computational cost, communication cost, and security and is more suitable for embedded low-power devices in IoT contexts, including the IIoT.