<p>With the rapid advancement of Internet of Things (IoT) applications, the frequency of data interactions has increased significantly, exposing security vulnerabilities in key storage due to the constrained security capabilities of IoT devices. To address these challenges, this paper proposes a lightweight IoT authentication and key exchange protocol based on SRAM PUF Key Generator (SPUF-KG) and Semiconductor Superlattice True Random Number Generator (SSL-TRNG), designed for IoT Device-to-Server (D2S) and Device-to-Device (D2D) scenarios. SPUF-KG eliminates repeated helper data transmission during protocol interaction, while SSL-TRNG provides a highly secure initial challenge for the protocol. Security analysis demonstrates that the number produced by SPUF-KG exhibits excellent uniformity, uniqueness, and reliability, while SSL-TRNG is capable of generating random numbers that pass the NIST SP 800–22 Statistical Testing. The protocol is verified by using scyther automatic verification tool and informal security analysis to confirm that the protocol has resistance to&#xa0;Man-in-the-Middle (MiTM),&#xa0;Replay,&#xa0;Physical,&#xa0;Quantum Computing, and&#xa0;Modeling attacks. In terms of performance, our approach has significantly low computational complexity while reducing D2S communication costs by 18.99%, D2D by 5.09%, and server storage overhead by 17.4% compared to existing PUF-based protocols.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

SPUF-KG and SSL-TRNG Enhanced lightweight IoT authentication and key exchange protocol

  • Qian Zhang,
  • Yanfei Liu,
  • Nana Wu,
  • Cheng Chen,
  • Ziang Du

摘要

With the rapid advancement of Internet of Things (IoT) applications, the frequency of data interactions has increased significantly, exposing security vulnerabilities in key storage due to the constrained security capabilities of IoT devices. To address these challenges, this paper proposes a lightweight IoT authentication and key exchange protocol based on SRAM PUF Key Generator (SPUF-KG) and Semiconductor Superlattice True Random Number Generator (SSL-TRNG), designed for IoT Device-to-Server (D2S) and Device-to-Device (D2D) scenarios. SPUF-KG eliminates repeated helper data transmission during protocol interaction, while SSL-TRNG provides a highly secure initial challenge for the protocol. Security analysis demonstrates that the number produced by SPUF-KG exhibits excellent uniformity, uniqueness, and reliability, while SSL-TRNG is capable of generating random numbers that pass the NIST SP 800–22 Statistical Testing. The protocol is verified by using scyther automatic verification tool and informal security analysis to confirm that the protocol has resistance to Man-in-the-Middle (MiTM), Replay, Physical, Quantum Computing, and Modeling attacks. In terms of performance, our approach has significantly low computational complexity while reducing D2S communication costs by 18.99%, D2D by 5.09%, and server storage overhead by 17.4% compared to existing PUF-based protocols.