Comments on “Biometrics-Based Privacy-Preserving User Authentication Scheme for Cloud-Based Industrial Internet of Things Deployment”

dc.authoridhttps://orcid.org/0000-0003-1540-4940en_US
dc.authoridhttps://orcid.org/0000-0002-9321-6956en_US
dc.contributor.authorHussain, Sajid
dc.contributor.authorChaudhry, Shehzad Ashraf
dc.date.accessioned2023-11-10T12:41:08Z
dc.date.available2023-11-10T12:41:08Z
dc.date.issued2019en_US
dc.departmentMühendislik ve Mimarlık Fakültesien_US
dc.description.abstractVery recently, Das et al. (IEEE Internet of Things Journal, pp. 4900–4913, 5(6), DOI: 10.1109/JIOT.2018.2877690, 2018) presented a biometric-based solution for security and privacy in Industrial Internet of Things architecture. Das et al. claimed that their protocol is secure against known attacks. However, this comment shows that their protocol is defenseless against stolen verifier, stolen smart device, and traceability attacks. The attacker having access to public parameters and any of the verifier and parameters stored in smart device can easily expose the session key shared among the user and the smart device. Moreover, their protocol fails to provide perfect forward secrecy. Finally, this article also provides some necessary guidelines on attack resilience for the authentication schemes based on merely the symmetric key primitives, which are overlooked by Das et al.en_US
dc.identifier.doi10.1109/JIOT.2019.2934947en_US
dc.identifier.endpage10940en_US
dc.identifier.issn2327-4662
dc.identifier.issue6en_US
dc.identifier.scopus2-s2.0-85076767464en_US
dc.identifier.scopusqualityQ1en_US
dc.identifier.startpage10936en_US
dc.identifier.urihttps://hdl.handle.net/11363/6335
dc.identifier.urihttps://doi.org/
dc.identifier.volume6en_US
dc.identifier.wosWOS:000503985700139en_US
dc.identifier.wosqualityQ1en_US
dc.indekslendigikaynakWeb of Scienceen_US
dc.indekslendigikaynakScopusen_US
dc.institutionauthorChaudhry, Shehzad Ashraf
dc.language.isoenen_US
dc.publisherIEEE-INST ELECTRICAL ELECTRONICS ENGINEERS INC, 445 HOES LANE, PISCATAWAY, NJ 08855-4141en_US
dc.relation.ispartofIEEE Internet of Things Journalen_US
dc.relation.publicationcategoryMakale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanıen_US
dc.rightsinfo:eu-repo/semantics/openAccessen_US
dc.rightsAttribution-NonCommercial-NoDerivs 3.0 United States*
dc.rights.urihttp://creativecommons.org/licenses/by-nc-nd/3.0/us/*
dc.subjectIndustrial Internet of Things (IIoT)en_US
dc.subjectinsider attacken_US
dc.subjectperfect forward secrecyen_US
dc.subjectsecret key exposeen_US
dc.subjectstolen smart deviceen_US
dc.subjectstolen verifier attacken_US
dc.subjectkey establishmenten_US
dc.titleComments on “Biometrics-Based Privacy-Preserving User Authentication Scheme for Cloud-Based Industrial Internet of Things Deployment”en_US
dc.typeEditorialen_US

Dosyalar

Orijinal paket
Listeleniyor 1 - 1 / 1
Yükleniyor...
Küçük Resim
İsim:
Comments_on_Biometrics-Based_Privacy-Preserving_User_Authentication_Scheme_for_Cloud-Based_Industrial_Internet_of_Things_Deployment.pdf
Boyut:
538.59 KB
Biçim:
Adobe Portable Document Format
Açıklama:
Editör Yazısı / Editorial Material
Lisans paketi
Listeleniyor 1 - 1 / 1
Küçük Resim Yok
İsim:
license.txt
Boyut:
1.56 KB
Biçim:
Item-specific license agreed upon to submission
Açıklama: