Sensors | |
Cryptanalysis and Security Improvements of ‘Two-Factor User Authentication in Wireless Sensor Networks’ | |
Muhammad Khurram Khan1  | |
[1] Center of Excellence in Information Assurance (CoEIA), King Saud University, Saudi Arabia | |
关键词: authentication; wireless sensor network; security; smart card; cryptanalysis; | |
DOI : 10.3390/s100302450 | |
来源: mdpi | |
【 摘 要 】
User authentication in wireless sensor networks (WSN) is a critical security issue due to their unattended and hostile deployment in the field. Since sensor nodes are equipped with limited computing power, storage, and communication modules; authenticating remote users in such resource-constrained environments is a paramount security concern. Recently, M.L. Das proposed a two-factor user authentication scheme in WSNs and claimed that his scheme is secure against different kinds of attack. However, in this paper, we show that the M.L. Das-scheme has some critical security pitfalls and cannot be recommended for real applications. We point out that in his scheme: users cannot change/update their passwords, it does not provide mutual authentication between gateway node and sensor node, and is vulnerable to gateway node bypassing attack and privileged-insider attack. To overcome the inherent security weaknesses of the M.L. Das-scheme, we propose improvements and security patches that attempt to fix the susceptibilities of his scheme. The proposed security improvements can be incorporated in the M.L. Das-scheme for achieving a more secure and robust two-factor user authentication in WSNs.
【 授权许可】
CC BY
© 2010 by the authors; licensee Molecular Diversity Preservation International, Basel, Switzerland.
【 预 览 】
Files | Size | Format | View |
---|---|---|---|
RO202003190054371ZK.pdf | 75KB | download |