4.8 Article

G2F: A Secure User Authentication for Rapid Smart Home IoT Management

期刊

IEEE INTERNET OF THINGS JOURNAL
卷 8, 期 13, 页码 10884-10895

出版社

IEEE-INST ELECTRICAL ELECTRONICS ENGINEERS INC
DOI: 10.1109/JIOT.2021.3050710

关键词

Authentication; Logic gates; Smart homes; Security; Internet of Things; Cloud computing; Protocols; Internet of Things (IoT); smart home; user authentication

资金

  1. National Key Research and Development Program of China [2020AAA0107700, 2018YFB0803600]
  2. National Natural Science Foundation of China [61972348, 62072398]
  3. Zhejiang Key Research and Development Plan [2019C03133]
  4. Leading Innovative and Entrepreneur Team Introduction Program of Zhejiang [2018R01005]
  5. Research Institute of Cyberspace Governance in Zhejiang University
  6. Alibaba-Zhejiang University Joint Institute of Frontier Technologies

向作者/读者索取更多资源

This article introduces a gateway-based 2 factor authentication (G2F) framework to enhance the security of IoT device management. By utilizing a hardware token to interact with the local gateway node, G2F ensures user authentication security and allows for multiple simultaneous operations. Through implementation on Alibaba Cloud, G2F demonstrates the ability to protect against malicious attacks with high authentication efficiency.
Internet-of-Things (IoT) devices are widely deployed nowadays. A large number of smart home IoT devices are hosted on a cloud server for easy management. Users can use their accounts to initiate operations and management on IoT devices through a cloud server, such as updating firmware and configuring devices. However, the cloud account may be hacked resulting in adversarial attacks to the hosted IoT devices. As a consequence, an adversary may perform malicious operations through the cloud remotely to the hosted IoT devices without user awareness. Motivated by this, in this article we propose gateway-based 2 factor authentication (G2F), a secure user authentication framework dedicated for a gateway based on the universal 2nd factor (U2F) protocol to enhance the security of IoT devices management. In G2F, the user authentication on the gateway is completed utilizing a hardware token that interacts with the local gateway node to guarantee the token owner's presence. Furthermore, G2F can grant multiple simultaneous operations on IoT devices through just one user authentication. We implement a prototype to further evaluate the performance of G2F. Based on our realization on the commercial IoT server, i.e., Alibaba Cloud, G2F demonstrates the ability to protect against malicious attacks with high authentication efficiency.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.8
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据