Security Flaws in Dhillon and Kalra s User Authentication Scheme for IoT
Author
Abstract

Multifactor Authentication - Dhillon and Kalra proposed a multi-factor user authentication scheme for IoT. The authors claim their scheme to have practical utility for the IoT environment. However, we find that their scheme has numerous flaws such as insider attack and inefficient authentication. An adversary can work as a middle-man between the sensor node and the user, and the user can set-up a session key with the sensor node. Besides, the scheme does not establish the mutual authentication between every pair of entities. Thus, the scheme is inconvenient for practical use. We conclude this article by providing some suggestions for the improvement of the analysed scheme to remove the weaknesses identified in it.

Year of Publication
2022
Date Published
nov
Publisher
IEEE
Conference Location
Ghaziabad, India
ISBN Number
978-1-66548-268-4
URL
https://ieeexplore.ieee.org/document/10064577/
DOI
10.1109/ICICT55121.2022.10064577
Google Scholar | BibTeX | DOI