{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,13]],"date-time":"2026-06-13T20:13:29Z","timestamp":1781381609672,"version":"3.54.1"},"reference-count":43,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2023,11,25]],"date-time":"2023-11-25T00:00:00Z","timestamp":1700870400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2023,11,25]],"date-time":"2023-11-25T00:00:00Z","timestamp":1700870400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100005713","name":"Technische Universit\u00e4t M\u00fcnchen","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100005713","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2024,4]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>With the rapid expansion of IoT devices and their applications, there is an increasing demand for efficient and secure authentication mechanisms to protect against unauthorized access. Traditional authentication mechanisms face limitations regarding computational speed, communication costs, and vulnerability to cyber-attacks. Zero-knowledge proof (ZKP) protocols have emerged as an effective solution for achieving secure and efficient authentication in such environments without revealing sensitive information. Among ZKP protocols, <jats:inline-formula><jats:alternatives><jats:tex-math>$$\\Sigma $$<\/jats:tex-math><mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mi>\u03a3<\/mml:mi>\n                <\/mml:math><\/jats:alternatives><\/jats:inline-formula>-protocols, a class of interactive ZKP protocols, have been employed for their efficiency and security. However, their interactive nature necessitates multiple rounds of communication, which can reduce efficiency and increase communication overhead for resource-constrained devices. Many works have aimed to eliminate the interaction of <jats:inline-formula><jats:alternatives><jats:tex-math>$$\\Sigma $$<\/jats:tex-math><mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mi>\u03a3<\/mml:mi>\n                <\/mml:math><\/jats:alternatives><\/jats:inline-formula>-protocols by utilizing a transformation called the Fiat\u2013Shamir transformation (FST). However, there is still a concern regarding the soundness of the FST as it can sometimes convert a secure <jats:inline-formula><jats:alternatives><jats:tex-math>$$\\Sigma $$<\/jats:tex-math><mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mi>\u03a3<\/mml:mi>\n                <\/mml:math><\/jats:alternatives><\/jats:inline-formula>-protocol into an insecure non-interactive zero-knowledge (NIZK) authentication scheme. In this paper, we propose an approach for transforming <jats:inline-formula><jats:alternatives><jats:tex-math>$$\\Sigma $$<\/jats:tex-math><mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mi>\u03a3<\/mml:mi>\n                <\/mml:math><\/jats:alternatives><\/jats:inline-formula>-protocols into a NIZK protocol based on the FST, yielding significant enhancements in efficiency, communication overhead reduction, and elimination of interaction. Our proposed protocol enables the completion of the authentication process in a single request while also strengthening the soundness of <jats:inline-formula><jats:alternatives><jats:tex-math>$$\\Sigma $$<\/jats:tex-math><mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mi>\u03a3<\/mml:mi>\n                <\/mml:math><\/jats:alternatives><\/jats:inline-formula>-protocols in comparison with the traditional FST by requiring two authentication factors instead of one. To demonstrate our approach\u2019s robustness, we conducted comprehensive informal and formal security analyses (using the Tamarin-Prover). Our protocol demonstrated completeness, soundness, zero-knowledge properties, and robustness against attacks, including eavesdropping, message modification, replay, and brute force attacks. Additionally, our performance analysis displayed a remarkable 50% improvement in computational cost compared to traditional <jats:inline-formula><jats:alternatives><jats:tex-math>$$\\Sigma $$<\/jats:tex-math><mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mi>\u03a3<\/mml:mi>\n                <\/mml:math><\/jats:alternatives><\/jats:inline-formula>-protocols, underscoring its efficiency for practical use.<\/jats:p>","DOI":"10.1007\/s10207-023-00779-8","type":"journal-article","created":{"date-parts":[[2023,11,25]],"date-time":"2023-11-25T12:01:45Z","timestamp":1700913705000},"page":"1131-1148","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["Enhancing security in Fiat\u2013Shamir transformation-based non-interactive zero-knowledge protocols for IoT authentication"],"prefix":"10.1007","volume":"23","author":[{"given":"Firas","family":"Hamila","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mohammad","family":"Hamad","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Daniel Costa","family":"Salgado","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sebastian","family":"Steinhorst","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2023,11,25]]},"reference":[{"key":"779_CR1","doi-asserted-by":"crossref","unstructured":"Abi-Char, P.E., Mhamed, A., Bachar, E.-H.: A fast and secure elliptic curve based authenticated key agreement protocol for low power mobile communications, In: The 2007 International Conference on Next Generation Mobile Applications, Services and Technologies (NGMAST 2007), pp. 235\u2013240. IEEE (2007)","DOI":"10.1109\/NGMAST.2007.4343427"},{"key":"779_CR2","doi-asserted-by":"crossref","unstructured":"Backes, M., Unruh, D.: Computational soundness of symbolic zero-knowledge proofs against active attackers. In: 2008 21st IEEE Computer Security Foundations Symposium, pp. 255\u2013269. IEEE (2008)","DOI":"10.1109\/CSF.2008.20"},{"key":"779_CR3","first-page":"206","volume":"13","author":"M Backes","year":"2013","unstructured":"Backes, M., Bendun, F., Unruh, D.: Computational soundness of symbolic zero-knowledge proofs: weaker assumptions and mechanized verification. POST 13, 206\u2013225 (2013)","journal-title":"POST"},{"key":"779_CR4","doi-asserted-by":"crossref","unstructured":"Backes, M., Maffei, M., Unruh, D.: Zero-knowledge in the applied pi-calculus and automated verification of the direct anonymous attestation protocol. In: 2008 IEEE Symposium on Security and Privacy (SP 2008), pp. 202\u2013215. IEEE (2008)","DOI":"10.1109\/SP.2008.23"},{"key":"779_CR5","doi-asserted-by":"crossref","unstructured":"Bellare, M., Shoup, S.: Two-tier signatures, strongly unforgeable signatures, and fiat-shamir without random oracles. In: Public Key Cryptography\u2013PKC 2007: 10th International Conference on Practice and Theory in Public-Key Cryptography Beijing, China, April 16\u201320, 2007. Proceedings 10, pp. 201\u2013216. Springer (2007)","DOI":"10.1007\/978-3-540-71677-8_14"},{"key":"779_CR6","doi-asserted-by":"crossref","unstructured":"Bernhard, D., Pereira,O., Warinschi, B.: How not to prove yourself: Pitfalls of the fiat-shamir heuristic and applications to helios. In: Advances in Cryptology\u2013ASIACRYPT 2012: 18th International Conference on the Theory and Application of Cryptology and Information Security, Beijing, China, December 2\u20136, 2012. Proceedings 18, pp. 626\u2013643. Springer (2012)","DOI":"10.1007\/978-3-642-34961-4_38"},{"key":"779_CR7","doi-asserted-by":"crossref","unstructured":"Bernstein, D.J.: Curve25519: new Diffie\u2013Hellman speed records. In: Public Key Cryptography-PKC 2006: 9th International Conference on Theory and Practice in Public-Key Cryptography, New York, NY, USA, April 24\u201326, Proceedings 9, pp. 207\u2013228. Springer (2006)","DOI":"10.1007\/11745853_14"},{"key":"779_CR8","doi-asserted-by":"crossref","unstructured":"Bertoni, G., Daemen, J., Peeters, M., Van\u00a0Assche, G.: Keccak. In: Advances in Cryptology\u2013EUROCRYPT 2013: 32nd Annual International Conference on the Theory and Applications of Cryptographic Techniques, Athens, Greece, May 26\u201330, 2013. Proceedings 32, pp. 313\u2013314. Springer (2013)","DOI":"10.1007\/978-3-642-38348-9_19"},{"key":"779_CR9","doi-asserted-by":"crossref","unstructured":"Bitansky, N., Dachman-Soled, D., Garg, S., Jain, A., Kalai, Y.T., L\u00f3pez-Alt, A., Wichs, D.: Why\" Fiat\u2013Shamir for Proofs\" Lacks a Proof. In: TCC, vol. 7785, pp. 182\u2013201. Springer (2013)","DOI":"10.1007\/978-3-642-36594-2_11"},{"key":"779_CR10","doi-asserted-by":"crossref","unstructured":"Canetti, R., Chen, Y., Reyzin, L.: On the correlation intractability of obfuscated pseudorandom functions. In: Theory of Cryptography: 13th International Conference, TCC 2016-A, Tel Aviv, Israel, January 10\u201313, 2016, Proceedings, Part I 13, pp. 389\u2013415. Springer (2016)","DOI":"10.1007\/978-3-662-49096-9_17"},{"key":"779_CR11","doi-asserted-by":"crossref","unstructured":"Canetti, R., Chen, Y., Reyzin, L., Rothblum, R.D.: Fiat\u2013Shamir and correlation intractability from strong KDM-secure encryption. In: Advances in Cryptology\u2013EUROCRYPT 2018: 37th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Tel Aviv, Israel, April 29\u2013May 3, 2018 Proceedings, Part I 37, pp. 91\u2013122. Springer (2018)","DOI":"10.1007\/978-3-319-78381-9_4"},{"key":"779_CR12","doi-asserted-by":"crossref","unstructured":"Canetti, R., Chen, Y., Holmgren, J., Lombardi, A., Rothblum, G.N., Rothblum, R.D., Wichs, D.: Fiat\u2013Shamir: from practice to theory. In: Proceedings of the 51st Annual ACM SIGACT Symposium on Theory of Computing, pp. 1082\u20131090 (2019)","DOI":"10.1145\/3313276.3316380"},{"key":"779_CR13","doi-asserted-by":"crossref","unstructured":"Chaidos, P., Groth, J.: Making sigma-protocols non-interactive without random oracles. In: Public-Key Cryptography\u2013PKC 2015: 18th IACR International Conference on Practice and Theory in Public-Key Cryptography, Gaithersburg, MD, USA, March 30\u2013April 1, 2015, Proceedings, pp. 650\u2013670. Springer (2015)","DOI":"10.1007\/978-3-662-46447-2_29"},{"key":"779_CR14","unstructured":"Chen, Y., Chou, J.-S., Lin, C.-F.: A novel non-interactive deniable authentication protocol with designated verifier on elliptic curve cryptosystem. Cryptology ePrint Archive (2010)"},{"issue":"5","key":"779_CR15","doi-asserted-by":"publisher","first-page":"1145","DOI":"10.3390\/electronics12051145","volume":"12","author":"Z Chen","year":"2023","unstructured":"Chen, Z., Jiang, Y., Song, X., Chen, L.: A survey on zero-knowledge authentication for internet of things. Electronics 12(5), 1145 (2023)","journal-title":"Electronics"},{"key":"779_CR16","doi-asserted-by":"crossref","unstructured":"Ciampi, M., Persiano, G., Siniscalchi, L., Visconti, I.: A transform for NIZK almost as efficient and general as the Fiat-Shamir transform without programmable random oracles. In: Theory of Cryptography: 13th International Conference, TCC 2016-A, Tel Aviv, Israel, January 10\u201313, 2016, Proceedings, Part II 13, pp. 83\u2013111. Springer (2016)","DOI":"10.1007\/978-3-662-49099-0_4"},{"key":"779_CR17","unstructured":"Damg\u00e5rd, I.: On $$\\sigma $$-protocols. Lecture Notes, University of Aarhus, Department for Computer Science, 84 (2002)"},{"key":"779_CR18","doi-asserted-by":"crossref","unstructured":"Damg\u00e5rd, I., Fazio, N., Nicolosi, A.: Non-interactive zero-knowledge from homomorphic encryption. In: Theory of Cryptography: 3rd Theory of Cryptography Conference, TCC 2006, New York, NY, USA, March 4\u20137, 2006. Proceedings 3, pp. 41\u201359. Springer (2006)","DOI":"10.1007\/11681878_3"},{"key":"779_CR19","doi-asserted-by":"crossref","unstructured":"Dammak, M., Boudia, O.R.M., Messous, M.A., Senouci, S.M., Gransart, C.: Token-based lightweight authentication to secure IoT networks. In: 2019 16th IEEE Annual Consumer Communications & Networking Conference (CCNC), pp. 1\u20134. IEEE (2019)","DOI":"10.1109\/CCNC.2019.8651825"},{"issue":"2","key":"779_CR20","doi-asserted-by":"publisher","first-page":"198","DOI":"10.1109\/TIT.1983.1056650","volume":"29","author":"D Dolev","year":"1983","unstructured":"Dolev, D., Yao, A.: On the security of public key protocols. IEEE Trans. Inf. Theory 29(2), 198\u2013208 (1983)","journal-title":"IEEE Trans. Inf. Theory"},{"key":"779_CR21","doi-asserted-by":"crossref","unstructured":"Dwivedi, A.D., Singh, R., Ghosh, U., Mukkamala, R.R., Tolba, A., Said, O.: Privacy preserving authentication system based on non-interactive zero knowledge proof suitable for internet of things. J. Ambient Intell. Human. Comput. 1\u201311 (2021)","DOI":"10.1007\/s12652-021-03459-4"},{"issue":"6","key":"779_CR22","doi-asserted-by":"publisher","first-page":"852","DOI":"10.1145\/950620.950623","volume":"50","author":"C Dwork","year":"2003","unstructured":"Dwork, C., Naor, M., Reingold, O., Stockmeyer, L.: Magic functions: in memoriam: Bernard m. dwork 1923\u20131998. JACM 50(6), 852\u2013921 (2003)","journal-title":"JACM"},{"key":"779_CR23","doi-asserted-by":"crossref","unstructured":"Faust, S., Kohlweiss, M., Marson, G.A., Venturi, D.: On the non-malleability of the Fiat\u2013Shamir transform. In: INDOCRYPT, vol. 7668, pp. 60\u201379. Springer (2012)","DOI":"10.1007\/978-3-642-34931-7_5"},{"key":"779_CR24","doi-asserted-by":"crossref","unstructured":"Fiat, A., Shamir, A.: How to prove yourself: practical solutions to identification and signature problems. In: Crypto, vol. 86, pp. 186\u2013194. Springer (1986)","DOI":"10.1007\/3-540-47721-7_12"},{"key":"779_CR25","unstructured":"Fischlin, S.: Formalising zero-knowledge proofs in the symbolic model. Master\u2019s thesis, ETH Zurich (2021)"},{"key":"779_CR26","doi-asserted-by":"publisher","unstructured":"Goldwasser, S., Kalai, Y.T.: On the (In)security of the Fiat\u2013Shamir paradigm. In: 44th Annual IEEE Symposium on Foundations of Computer Science. Proceedings., 2003, pp. 102\u2013113 (2003). https:\/\/doi.org\/10.1109\/SFCS.2003.1238185","DOI":"10.1109\/SFCS.2003.1238185"},{"key":"779_CR27","doi-asserted-by":"crossref","unstructured":"Haller, N.: The S\/KEY one-time password system. Technical report (1995)","DOI":"10.17487\/rfc1760"},{"key":"779_CR28","doi-asserted-by":"crossref","unstructured":"Hao, F.: Schnorr non-interactive zero-knowledge proof. Technical report (2017)","DOI":"10.17487\/RFC8235"},{"key":"779_CR29","doi-asserted-by":"crossref","unstructured":"Holmgren, J., Lombardi, A.: Cryptographic hashing from strong one-way functions (or: One-way product functions and their applications). In: 2018 IEEE 59th Annual Symposium on Foundations of Computer Science (FOCS), pp. 850\u2013858. IEEE (2018)","DOI":"10.1109\/FOCS.2018.00085"},{"key":"779_CR30","doi-asserted-by":"crossref","unstructured":"Iovino, V., Visconti, I.: Non-interactive zero knowledge proofs in the random oracle model. In: Codes, Cryptology and Information Security: 3rd International Conference, C2SI 2019, Rabat, Morocco, April 22\u201324, 2019, Proceedings-In Honor of Said El Hajji, pp. 118\u2013141. Springer (2019)","DOI":"10.1007\/978-3-030-16458-4_9"},{"key":"779_CR31","doi-asserted-by":"crossref","unstructured":"Kalai, Y.T., Rothblum, G.N., Rothblum, R.D.: From obfuscation to the security of Fiat\u2013Shamir for proofs. In: Advances in Cryptology\u2013CRYPTO 2017: 37th Annual International Cryptology Conference, Santa Barbara, CA, USA, August 20\u201324, 2017, Proceedings, Part II 37, pp. 224\u2013251. Springer (2017)","DOI":"10.1007\/978-3-319-63715-0_8"},{"key":"779_CR32","first-page":"185","volume":"800","author":"J Kelsey","year":"2016","unstructured":"Kelsey, J., Chang, S.-J., Perlner, R.: Sha-3 derived functions: cshake, kmac, tuplehash, and parallelhash. NIST Spec. Publ. 800, 185 (2016)","journal-title":"NIST Spec. Publ."},{"issue":"177","key":"779_CR33","doi-asserted-by":"publisher","first-page":"203","DOI":"10.1090\/S0025-5718-1987-0866109-5","volume":"48","author":"N Koblitz","year":"1987","unstructured":"Koblitz, N.: Elliptic curve cryptosystems. Math. Comput. 48(177), 203\u2013209 (1987)","journal-title":"Math. Comput."},{"key":"779_CR34","doi-asserted-by":"crossref","unstructured":"Lindell, Y.: An efficient transform from sigma protocols to NIZK with a CRS and non-programmable random oracle. Cryptology ePrint Archive (2014)","DOI":"10.1007\/978-3-662-46494-6_5"},{"key":"779_CR35","doi-asserted-by":"publisher","first-page":"663","DOI":"10.1007\/s10623-015-0103-5","volume":"77","author":"U Maurer","year":"2015","unstructured":"Maurer, U.: Zero-knowledge proofs of knowledge for group homomorphisms. Des. Codes Crypt. 77, 663\u2013676 (2015)","journal-title":"Des. Codes Crypt."},{"key":"779_CR36","doi-asserted-by":"publisher","first-page":"28","DOI":"10.1016\/j.tcs.2018.05.001","volume":"740","author":"A Mittelbach","year":"2018","unstructured":"Mittelbach, A., Venturi, D.: Fiat\u2013Shamir for highly sound protocols is instantiable. Theoret. Comput. Sci. 740, 28\u201362 (2018)","journal-title":"Theoret. Comput. Sci."},{"key":"779_CR37","doi-asserted-by":"crossref","unstructured":"Mumtaz, M., Akram, J., Ping, L.: An RSA based authentication system for smart IoT environment. In: 2019 IEEE 21st International Conference on High Performance Computing and Communications; IEEE 17th International Conference on Smart City; IEEE 5th International Conference on Data Science and Systems (HPCC\/SmartCity\/DSS), pp. 758\u2013765 (2019)","DOI":"10.1109\/HPCC\/SmartCity\/DSS.2019.00112"},{"key":"779_CR38","doi-asserted-by":"crossref","unstructured":"Nyangaresi, V.O., Ogundoyin, S.O.: Certificate based authentication scheme for smart homes. In: 2021 3rd Global Power, Energy and Communication Conference (GPECOM), pp. 202\u2013207. IEEE (2021)","DOI":"10.1109\/GPECOM52585.2021.9607322"},{"key":"779_CR39","doi-asserted-by":"crossref","unstructured":"Santoso, F.K., Vun, N.C.: Securing IoT for smart home system. In: 2015 International Symposium on Consumer Electronics (ISCE), pp. 1\u20132. IEEE (2015)","DOI":"10.1109\/ISCE.2015.7177843"},{"key":"779_CR40","doi-asserted-by":"crossref","unstructured":"Schmidt, B., Meier, S., Cremers, C., Basin, D.: Automated analysis of Diffie\u2013Hellman protocols and advanced security properties. In: 2012 IEEE 25th Computer Security Foundations Symposium, pp. 78\u201394. IEEE (2012)","DOI":"10.1109\/CSF.2012.25"},{"key":"779_CR41","doi-asserted-by":"publisher","DOI":"10.1201\/9781315282497","volume-title":"Cryptography: Theory and Practice","author":"DR Stinson","year":"2018","unstructured":"Stinson, D.R., Paterson, M.B.: Cryptography: Theory and Practice. Chapman and Hall\/CRC, Boca Raton (2018)"},{"key":"779_CR42","unstructured":"Whitefield, J.D.: Formal analysis and applications of direct anonymous attestation. PhD thesis, University of Surrey (2020)"},{"key":"779_CR43","doi-asserted-by":"crossref","unstructured":"Wu, H., Wang, F., et al.: A survey of noninteractive zero knowledge proof system and its applications. Sci. World J. 2014 (2014)","DOI":"10.1155\/2014\/560484"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-023-00779-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10207-023-00779-8\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-023-00779-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,27]],"date-time":"2024-03-27T07:39:52Z","timestamp":1711525192000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10207-023-00779-8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,25]]},"references-count":43,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2024,4]]}},"alternative-id":["779"],"URL":"https:\/\/doi.org\/10.1007\/s10207-023-00779-8","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"value":"1615-5262","type":"print"},{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,11,25]]},"assertion":[{"value":"25 November 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"This article does not contain any studies with human participants or animals performed by any of the authors.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical standards"}}]}}