|国家科技期刊平台
首页|期刊导航|通信与信息网络学报(英文)|Insider Attack Prevention:LAPUP—Lightweight Authentication Protocol Using PUF

Insider Attack Prevention:LAPUP—Lightweight Authentication Protocol Using PUFOA

Insider Attack Prevention:LAPUP—Lightweight Authentication Protocol Using PUF

英文摘要

The incredible progress in technologies has drastically increased the usage of Web applications.Users share their credentials like userid and password or use their smart cards to get authenticated by the application servers.Smart cards are handy to use,but they are susceptible to stolen smart card attacks and few other notable security attacks.Users prefer to use Web applications that guarantee for security against several security attacks,especially insider attacks,which is cru-cial.Cryptanalysis of several existing schemes prove the security pitfalls of the protocols from preventing security attacks,specifically insider attacks.This paper introduces LAPUP:a novel lightweight authentication protocol using physically unclonable function(PUF)to prevent security attacks,principally insider attacks.The PUFs are used to generate the security keys,challenge-response pair(CRP)and hardware signature for designing the LAPUP.The transmitted messages are shared as hash values and encrypted by the keys generated by PUF.These messages are devoid of all possible attacks executed by any attacker,including insider attacks.LAPUP is also free from stolen verifier attacks,as the databases are secured by using the hardware signature generated by PUFs.Security analysis of the protocol exhibits the strength of LAPUP in preventing insider attacks and its resistance against several other security attacks.The evaluation results of the communication and computation costs of LAPUP clearly shows that it achieves better performance than existing protocols,despite providing enhanced security.

Siranjeevi Rajamanickam;Satyanarayana Vollala;N.Ramasubramanian

Department of Computer Engineering,Govern-ment Polytechnic College,Tiruchirappalli 620022,IndiaDepartment of Computer Science and Engineering,Shyama Prasad Mukherjee International Institute of Information Technology-Naya Raipur,Chhattisgarh 493661,IndiaDepartment of Computer Science and Engineer-ing,National Institute of Technology,Tiruchirappalli 620015,India

physically unclonable function(PUF)in-sider attacksauthentication key management server(AKMS)security

《通信与信息网络学报(英文)》 2024 (002)

192-206 / 15

评论