Enhancing security in Fiat–Shamir transformation-based non-interactive zero-knowledge protocols for IoT authentication


연구 분야: Networking



학회: International Journal of Information Security


초록

With the rapid expansion of IoT devices and their applications, there is an increasing demand for efficient and secure authentication mechanisms to protect against unauthorized access. Traditional authentication mechanisms face limitations regarding computational speed, communication costs, and vulnerability to cyber-attacks. Zero-knowledge proof (ZKP) protocols have emerged as an effective solution for achieving secure and efficient authentication in such environments without revealing sensitive information. Among ZKP protocols, -protocols, a class of interactive ZKP protocols, have been employed for their efficiency and security. However, their interactive nature necessitates multiple rounds of communication, which can reduce efficiency and increase communication overhead for resource-constrained devices. Many works have aimed to eliminate the interaction of -protocols by utilizing a transformation called the Fiat–Shamir transformation (FST). However, there is still a concern regarding the soundness of the FST as it can sometimes convert a secure -protocol into an insecure non-interactive zero-knowledge (NIZK) authentication scheme. In this paper, we propose an approach for transforming -protocols into a NIZK protocol based on the FST, yielding significant enhancements in efficiency, communication overhead reduction, and elimination of interaction. Our proposed protocol enables the completion of the authentication process in a single request while also strengthening the soundness of -protocols in comparison with the traditional FST by requiring two authentication factors instead of one. To demonstrate our approach’s robustness, we conducted comprehensive informal and formal security analyses (using the Tamarin-Prover). Our protocol demonstrated completeness, soundness, zero-knowledge properties, and robustness against attacks, including eavesdropping, message modification, replay, and brute force attacks. Additionally, our performance analysis displayed a remarkable 50% improvement in computational cost compared to traditional -protocols, underscoring its efficiency for practical use.


Author Profile
Firas Hamila

Technical University of Munich Munich Germany

Germany
Author Profile
Mohammad Hamad

Technical University of Munich Munich Germany

Germany
Author Profile
Daniel Costa Salgado

Exxeta AG Mannheim Germany

Antigua and Barbuda

📄 논문 정보

발행 연도 2023년
인용수 5
출판 국가 Germany, Antigua and Barbuda
사이트 Springer
좋아요 수 0

연관 논문 목록 (197건)