This study re-evaluates Roy et al.’s lattice-based hybrid authentication protocol for fog-based IoT and proposes a compromise-containment-oriented improvement. The original protocol exhibits vulnerabilities, including long-term credential duplication during handover, identity linkability via static identifiers, and compromise propagation through shared-secret reuse. To address these, the proposed design eliminates direct long-term secret transfer, introducing bounded pseudonyms, short-lived authorization tokens, isolated recovery tokens, and event-based trust updates. Evaluations confirm that the improved protocol significantly enhances replay resistance, privacy, and compromise containment with moderate overhead.
한국어
본 연구는 포그 기반 IoT 환경에서 Roy 등의 격자 기반 하이브리드 인증 프로토콜을 재평가하고, 손상격리 중심의 개선 설계를 제안한다. 기존 프로토콜은 핸드오버 시 장기 자격증명 복제, 정적 식별자로 인한 링크가능성, fail-safe 단계의 공유 비밀 재사용으로 인한 손상 전파 한계를 보인다. 이에 본 논문은 장기 비밀 직접 전달을 제거하고, 제한적 가명, 단기 인증 토큰, 분리된 복구 토큰, 이벤트 기반 신뢰 업데이트를 도입한 개선안을 제안한다. 평가 결과, 제안 방식은 적당한 오버헤드로 재생 공격 저항성, 프라이버시, 손상 격리 능력을 크게 향상시킨다.
목차
요약 Abstract 1. 서론 2. 관련 연구 3. 연구 방법 4. 프로토콜 분석 4.1 기존의 인증 프로토콜 개요 4.2 식별된 취약점 5. 개선 방안 6. 모의 실험 분석 결과 7. 결론 REFERENCES