arrow
Return

ASMCC+: A Secure Authentication Scheme for Mobile Cloud Computing Environment Based on Zero Trust Architecture

delete2024-08-01
delete1
PRE
AI
M
Md Jakir Hossain
A
Abegaz Mohammed Seid *
H
Hayla Nahom Abishu
F
Fayaz Ali Dharejo
R
Rutvij H. Jhaveri
A
Aiman Erbad
M
Moath Alathbah
DOI:10.1109/TCE.2024.3415437delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Authenticated key exchange (AKE) schemes that adopt public-key encryption (PKE) are comprehensively applied in mobile cloud computing environments. They grant consumer electronics users (CEUs) access to numerous services from diverse cloud servers by registering only once with a third party. However, most of the existing AKE-schemes, indistinguishability against chosen-ciphertext attacks (IND-CCA), and security against malicious private key generator (mPKG) are not well considered. Particularly, existing trapdoor-based PKE-schemes either require a large number of pairing operations or are unable to achieve at least one of the following properties: adaptive onewayness (ADOW), pseudorandom ciphertext property (PCP), randomness reproducibility (RRP), key-dependent message security (KDM); thereby, fail to achieve desired security notions. Additionally, mPKG inherently has the power to generate the public-private key pair for any identity; as a result, CEUs and cloud servers are incredibly concerned about the privacy of communication against mPKG. To cope with these issues, we design a PKE-scheme based on the ADOW trapdoor function, where the secret-key encryption algorithm employs the signalling technique to avoid the deadlock incidence and projection function used to ensure KDM-security; thus, the proposed scheme achieves PCP and RRP, and IND-CCA security. Furthermore, we employed the designed PKE-scheme to construct a secure authentication scheme dubbed ASMCC(+) based on zero trust architecture: the probability of knowing the CEU's and cloud server's master-secret key by any third party is negligible. Our rigorous security proof and an in-depth performance analysis demonstrates that ASMCC(+) is IND-CCA secure, achieves adaptive onewayness, and can thwart mPKG.
Keywords:
Security
Cloud computing
Encryption
Servers
Consumer electronics
Authentication
System recovery
Critical intermediate randomness
identity concealment
secure authentication
single-point-of-failure
clock synchronization
and zero trust model

Journal

IEEE Transactions on Consumer Electronics cover
IEEE Transactions on Consumer Electronics
IF:
10.9
Papers:
5.1K
Citations:
6.8K

Organization

K
King Saud University
Scholars:
3.4W
Papers: 3.8W
Citations: 815
P
pandit deendayal energy university
Scholars:
1.6K
Papers: 1.3K
Citations: 26
U
University of Wurzburg
Scholars:
2.5W
Papers: 2.0W
Citations: 2.5W
Q
Qatar University
Scholars:
8.9K
Papers: 9.0K
Citations: 16
H
Hamad Bin Khalifa University-Qatar
Scholars:
2.2K
Papers: 2.0K
Citations: 33
Q
qatar foundation (qf)
Scholars:
6.3K
Papers: 7.0K
Citations: 8
researcher View more organizations