{"title":"A continuous authentication scheme for zero-trust architecture in industrial internet of things","authors":"Tao Wan , Buhai Shi , Huan Wang","doi":"10.1016/j.aej.2025.03.012","DOIUrl":null,"url":null,"abstract":"<div><div>Industrial Internet of Things (IIoT) allows users to access industrial devices and their data, but it also poses certain challenges to industrial data security. Authentication protocols are highly effective security techniques for protecting industrial data. This paper establishes a zero-trust architecture in the IIoT and proposes an authentication protocol suitable for zero-trust IIoT. The proposed scheme utilizes physical unclonable functions (PUF) for device authentication. Initial device authentication employs PUF to verify identity and establish session keys before session initiation, while continuous authentication verifies device location during the session to ensure that authenticated devices remain unaltered. Meanwhile, the scheme integrates three-factor authentication for user verification, ensuring secure user access. The proposed scheme establishes secure session key for users, gateways and IIoT devices, effectively guaranteeing the security of subsequent communications. Formal security analysis proves the security. Additionally, detailed informal security discussions demonstrate that the scheme can withstand known attacks and meet design objectives. Furthermore, performance evaluation reveals that the proposed scheme incurs low costs while providing enhanced security.</div></div>","PeriodicalId":7484,"journal":{"name":"alexandria engineering journal","volume":"122 ","pages":"Pages 555-563"},"PeriodicalIF":6.8000,"publicationDate":"2025-03-20","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"alexandria engineering journal","FirstCategoryId":"5","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S111001682500300X","RegionNum":2,"RegionCategory":"工程技术","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"ENGINEERING, MULTIDISCIPLINARY","Score":null,"Total":0}
引用次数: 0
Abstract
Industrial Internet of Things (IIoT) allows users to access industrial devices and their data, but it also poses certain challenges to industrial data security. Authentication protocols are highly effective security techniques for protecting industrial data. This paper establishes a zero-trust architecture in the IIoT and proposes an authentication protocol suitable for zero-trust IIoT. The proposed scheme utilizes physical unclonable functions (PUF) for device authentication. Initial device authentication employs PUF to verify identity and establish session keys before session initiation, while continuous authentication verifies device location during the session to ensure that authenticated devices remain unaltered. Meanwhile, the scheme integrates three-factor authentication for user verification, ensuring secure user access. The proposed scheme establishes secure session key for users, gateways and IIoT devices, effectively guaranteeing the security of subsequent communications. Formal security analysis proves the security. Additionally, detailed informal security discussions demonstrate that the scheme can withstand known attacks and meet design objectives. Furthermore, performance evaluation reveals that the proposed scheme incurs low costs while providing enhanced security.
期刊介绍:
Alexandria Engineering Journal is an international journal devoted to publishing high quality papers in the field of engineering and applied science. Alexandria Engineering Journal is cited in the Engineering Information Services (EIS) and the Chemical Abstracts (CA). The papers published in Alexandria Engineering Journal are grouped into five sections, according to the following classification:
• Mechanical, Production, Marine and Textile Engineering
• Electrical Engineering, Computer Science and Nuclear Engineering
• Civil and Architecture Engineering
• Chemical Engineering and Applied Sciences
• Environmental Engineering