Netinfo Security ›› 2025, Vol. 25 ›› Issue (9): 1407-1417.doi: 10.3969/j.issn.1671-1122.2025.09.009

Previous Articles     Next Articles

Dynamic Three-Factor Authentication Key Agreement Protocol for IoT Scenarios

YANG Yukun, XIAO Weien, LIANG Boxuan, HUANG Xin()   

  1. Department of Computer Science and Technology (College of Data Science), Taiyuan University of Technology, Taiyuan 030024, China
  • Received:2025-03-25 Online:2025-09-10 Published:2025-09-18

Abstract:

In recent years, the widespread adoption of Internet of Things (IoT) devices has significantly enhanced both the quality of life and work efficiency. However, the data sharing between IoT devices occurs over networks, making it susceptible to attacks and breaches. This paper aims to enhance the security of data exchange among IoT devices, focusing on Multi-Factor Authentication and Key Agreement (MFAKA) protocols. The research was centered on the security of data sharing between IoT devices, utilizing BioHash technology and Elliptic Curve Cryptography (ECC), and conducting theoretical analysis based on the Real-Or-Random (ROR) model in provable security. A novel dynamic three-factor authentication and key agreement protocol, named D3FAKAP, was proposed. This protocol integrated BioHash technology and ECC to achieve genuine three-factor authentication, This ensures user anonymity and unlinkability during the login process. Additionally, the proposed scheme is proven to be semantically secure under the Real-Or-Random model. Performance analysis indicates that the proposed scheme is well-suited for IoT environments in terms of security and resource efficiency.

Key words: IoT, multi-factor authentication, authentication key agreement protocol, provable security

CLC Number: