论文标题
建立轻巧的连续身份验证协议,用于设备到设备通信
Towards a Lightweight Continuous Authentication Protocol for Device-to-Device Communication
论文作者
论文摘要
连续身份验证(CA)已被提议作为应对复杂的网络安全攻击的潜在解决方案,以利用传统的静态身份验证机制,该机制仅在入口点进行身份验证用户。但是,经过广泛研究的基于人类用户特征的CA机制不能扩展以连续身份验证物联网(IoT)设备。随着关键基础设施中设备对设备(D2D)通信的采用增加,挑战加剧了挑战。文献中提出的现有D2D身份验证协议要么容易颠覆,要么在计算上不可行,可以在受约束的IoT设备上部署。鉴于这些挑战,我们提出了一个新颖,轻巧且安全的CA协议,该协议利用通信通道属性和可调的数学功能来生成动态变化的会话键。我们的初步非正式协议分析表明,该提议的协议对已知攻击向量具有抵抗力,因此在确保关键和资源约束的D2D通信方面具有强大的部署潜力。
Continuous Authentication (CA) has been proposed as a potential solution to counter complex cybersecurity attacks that exploit conventional static authentication mechanisms that authenticate users only at an ingress point. However, widely researched human user characteristics-based CA mechanisms cannot be extended to continuously authenticate Internet of Things (IoT) devices. The challenges are exacerbated with increased adoption of device-to-device (d2d) communication in critical infrastructures. Existing d2d authentication protocols proposed in the literature are either prone to subversion or are computationally infeasible to be deployed on constrained IoT devices. In view of these challenges, we propose a novel, lightweight, and secure CA protocol that leverages communication channel properties and a tunable mathematical function to generate dynamically changing session keys. Our preliminary informal protocol analysis suggests that the proposed protocol is resistant to known attack vectors and thus has strong potential for deployment in securing critical and resource-constrained d2d communication.