Wireless sensor networks (WSNs) are getting popular for their deployment in unattended environments, where a registered user can log in to the network and access data collected from the desired sensor. Because of limited resources and computation power in sensor nodes, an authentication protocol should be simple and efficient. M.L. Das proposed a two-factor authentication scheme for WSNs. Because his scheme uses only one-way hash function and XOR operation, it is well suited for resource-constrained environments. Because of some flaws in Das's scheme, several improved schemes have been introduced. In this paper, we show that Das's scheme and its derivatives not only have security imperfections but also do not provide key agreement. To overcome their security shortcomings, we propose a novel user authentication scheme with key agreement for WSN. We furnish security analysis of the proposed protocol to show its robustness to various attacks as well as analyze its performance to determine its efficiency. We provide protocol analysis and verification of the proposed protocol. Compared with the existing schemes, it is more robust and offers better security. Copyright (c) 2012 John Wiley & Sons, Ltd.
无线传感器网络(WSNs)因其可部署在无人值守的环境中而日益流行,在这种环境中,注册用户可以登录网络并访问从所需传感器收集的数据。由于传感器节点的资源和计算能力有限,认证协议应该简单高效。M.L.达斯为无线传感器网络提出了一种双因素认证方案。由于他的方案仅使用单向哈希函数和异或运算,因此非常适合资源受限的环境。由于达斯方案存在一些缺陷,人们已经提出了几种改进方案。在本文中,我们表明达斯的方案及其衍生方案不仅存在安全缺陷,而且没有提供密钥协商。为了克服它们的安全缺陷,我们为无线传感器网络提出了一种新颖的具有密钥协商的用户认证方案。我们对所提出的协议进行了安全分析,以表明其对各种攻击的鲁棒性,并分析其性能以确定其效率。我们对所提出的协议进行了协议分析和验证。与现有方案相比,它更具鲁棒性,并提供更好的安全性。版权所有(c)2012约翰威立父子有限公司