{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,16]],"date-time":"2026-01-16T05:19:47Z","timestamp":1768540787834,"version":"3.49.0"},"reference-count":47,"publisher":"MDPI AG","issue":"11","license":[{"start":{"date-parts":[[2018,10,29]],"date-time":"2018-10-29T00:00:00Z","timestamp":1540771200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100003329","name":"Ministerio de Econom\u00eda y Competitividad","doi-asserted-by":"publisher","award":["TIN2016-79095-C2-2-R"],"award-info":[{"award-number":["TIN2016-79095-C2-2-R"]}],"id":[{"id":"10.13039\/501100003329","id-type":"DOI","asserted-by":"publisher"}]},{"name":"CAM","award":["S2013\/ICE-3095"],"award-info":[{"award-number":["S2013\/ICE-3095"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Heterogeneous wireless sensor networks (HWSNs) are employed in many real-time applications, such as Internet of sensors (IoS), Internet of vehicles (IoV), healthcare monitoring, and so on. As wireless sensor nodes have constrained computing, storage and communication capabilities, designing energy-efficient authentication protocols is a very important issue in wireless sensor network security. Recently, Amin et al. presented an untraceable and anonymous three-factor authentication (3FA) scheme for HWSNs and argued that their protocol is efficient and can withstand the common security threats in this sort of networks. In this article, we show how their protocol is not immune to user impersonation, de-synchronization and traceability attacks. In addition, an adversary can disclose session key under the typical assumption that sensors are not tamper-resistant. To overcome these drawbacks, we improve the Amin et al.\u2019s protocol. First, we informally show that our improved scheme is secure against the most common attacks in HWSNs in which the attacks against Amin et al.\u2019s protocol are part of them. Moreover, we verify formally our proposed protocol using the BAN logic. Compared with the Amin et al.\u2019s scheme, the proposed protocol is both more efficient and more secure to be employed which renders the proposal suitable for HWSN networks.<\/jats:p>","DOI":"10.3390\/s18113663","type":"journal-article","created":{"date-parts":[[2018,10,29]],"date-time":"2018-10-29T11:10:41Z","timestamp":1540811441000},"page":"3663","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":13,"title":["Securing Heterogeneous Wireless Sensor Networks: Breaking and Fixing a Three-Factor Authentication Protocol"],"prefix":"10.3390","volume":"18","author":[{"given":"Seyed Farhad","family":"Aghili","sequence":"first","affiliation":[{"name":"Department of Information Technology Engineering, Faculty of Computer Engineering, University of Isfahan, Hezar Jerib St., Isfahan 81746-73441, Iran"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7789-452X","authenticated-orcid":false,"given":"Hamid","family":"Mala","sequence":"additional","affiliation":[{"name":"Department of Information Technology Engineering, Faculty of Computer Engineering, University of Isfahan, Hezar Jerib St., Isfahan 81746-73441, Iran"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6943-0760","authenticated-orcid":false,"given":"Pedro","family":"Peris-Lopez","sequence":"additional","affiliation":[{"name":"Department of Computer Science, University Carlos III of Madrid, Avda. de la Universidad 30, 28911 Legan\u00e9s, Spain"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2018,10,29]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"182","DOI":"10.1016\/j.compeleceng.2017.03.016","article-title":"Efficient end-to-end authentication protocol for wearable health monitoring systems","volume":"63","author":"Jiang","year":"2017","journal-title":"Comput. Electr. Eng."},{"key":"ref_2","unstructured":"Karl, H., and Willig, A. (2007). Protocols and Architectures for Wireless Sensor Networks, John Wiley & Sons."},{"key":"ref_3","unstructured":"Yarvis, M., Kushalnagar, N., Singh, H., Rangarajan, A., Liu, Y., and Singh, S. (2005, January 13\u201317). Exploiting heterogeneity in sensor networks. Proceedings of the 24th Annual Joint Conference of the IEEE Computer and Communications Societies, INFOCOM 2005, Miami, FL, USA."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"313","DOI":"10.1016\/j.future.2015.11.026","article-title":"Secure group communication schemes for dynamic heterogeneous distributed computing","volume":"74","author":"Castiglione","year":"2017","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.jpdc.2017.06.019","article-title":"An efficient and secure recoverable data aggregation scheme for heterogeneous wireless sensor networks","volume":"111","author":"Zhong","year":"2018","journal-title":"J. Parallel Distrib. Comput."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"152","DOI":"10.1016\/j.adhoc.2015.05.014","article-title":"An efficient user authentication and key agreement scheme for heterogeneous wireless sensor network tailored for the Internet of Things environment","volume":"36","author":"Farash","year":"2016","journal-title":"Ad Hoc Netw."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"316","DOI":"10.1016\/j.jnca.2012.05.010","article-title":"A temporal-credential-based mutual authentication and key agreement scheme for wireless sensor networks","volume":"36","author":"Xue","year":"2013","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"1042","DOI":"10.1016\/j.procs.2015.07.376","article-title":"Effect of Heterogeneous nodes location on the performance of clustering algorithms for wireless sensor networks","volume":"57","author":"Pal","year":"2015","journal-title":"Procedia Comput. Sci."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"1464","DOI":"10.1016\/j.jcss.2014.12.022","article-title":"Modeling energy-efficient secure communications in multi-mode wireless mobile devices","volume":"81","author":"Castiglione","year":"2015","journal-title":"J. Comput. Syst. Sci."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"704","DOI":"10.4218\/etrij.10.1510.0134","article-title":"A robust mutual authentication protocol for wireless sensor networks","volume":"32","author":"Chen","year":"2010","journal-title":"ETRI J."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"1086","DOI":"10.1109\/TWC.2008.080128","article-title":"Two-factor user authentication in wireless sensor networks","volume":"8","author":"Das","year":"2009","journal-title":"IEEE Trans. Wirel. Commun."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"2450","DOI":"10.3390\/s100302450","article-title":"Cryptanalysis and security improvements of \u2018two-factor user authentication in wireless sensor networks\u2019","volume":"10","author":"Khan","year":"2010","journal-title":"Sensors"},{"key":"ref_13","first-page":"631","article-title":"Improvement of Das\u2019s Two-Factor Authentication Protocol in Wireless Sensor Networks","volume":"2009","author":"Nyang","year":"2009","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"895","DOI":"10.1007\/s00779-012-0540-3","article-title":"On the security and improvement of a two-factor user authentication scheme in wireless sensor networks","volume":"17","author":"Sun","year":"2013","journal-title":"Pers. Ubiquitous Comput."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"133","DOI":"10.1016\/j.jnca.2017.12.012","article-title":"An untraceable and anonymous password authentication protocol for heterogeneous wireless sensor networks","volume":"104","author":"Amin","year":"2017","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_16","unstructured":"Wong, K.H., Zheng, Y., Cao, J., and Wang, S. (2006, January 5\u20137). A dynamic user authentication scheme for wireless sensor networks. Proceedings of the IEEE International Conference on Sensor Networks, Ubiquitous, and Trustworthy Computing, Taichung, Taiwan."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"1646","DOI":"10.1016\/j.jnca.2012.03.011","article-title":"A dynamic password-based user authentication scheme for hierarchical wireless sensor networks","volume":"35","author":"Das","year":"2012","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"171","DOI":"10.1002\/sec.517","article-title":"Two-factor mutual authentication with key agreement in wireless sensor networks","volume":"9","author":"Vaidya","year":"2016","journal-title":"Secur. Commun. Netw."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"263","DOI":"10.1016\/j.ins.2015.02.010","article-title":"A secure temporal-credential-based mutual authentication and key agreement scheme with pseudo identity for wireless sensor networks","volume":"321","author":"He","year":"2015","journal-title":"Inf. Sci."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"79","DOI":"10.1007\/s12083-015-0408-1","article-title":"Efficient anonymous authentication with key agreement protocol for wireless medical sensor networks","volume":"10","author":"Mir","year":"2017","journal-title":"Peer-to-peer Netw. Appl."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"49","DOI":"10.1007\/s00530-013-0346-9","article-title":"Robust anonymous authentication protocol for health-care applications using wireless medical sensor networks","volume":"21","author":"He","year":"2015","journal-title":"Multimed. Syst."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"96","DOI":"10.1016\/j.adhoc.2014.03.009","article-title":"A novel user authentication and key agreement scheme for heterogeneous ad hoc wireless sensor networks, based on the Internet of Things notion","volume":"20","author":"Brumen","year":"2014","journal-title":"Ad Hoc Netw."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"58","DOI":"10.1016\/j.adhoc.2015.05.020","article-title":"A secure light weight scheme for user authentication and key agreement in multi-gateway based wireless sensor networks","volume":"36","author":"Amin","year":"2016","journal-title":"Ad Hoc Netw."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"7124","DOI":"10.1109\/TIE.2016.2585081","article-title":"A realistic lightweight anonymous authentication protocol for securing real-time application data access in wireless sensor networks","volume":"63","author":"Gope","year":"2016","journal-title":"IEEE Trans. Ind. Electron."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Adavoudi-Jolfaei, A., Ashouri-Talouki, M., and Aghili, S.F. (2017). Lightweight and anonymous three-factor authentication and access control scheme for real-time applications in wireless sensor networks. Peer-to-peer Netw. Appl., 1\u201317.","DOI":"10.1007\/s12083-017-0627-8"},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"42","DOI":"10.1016\/j.comnet.2016.01.006","article-title":"Design of an anonymity-preserving three-factor authenticated key exchange protocol for wireless sensor networks","volume":"101","author":"Amin","year":"2016","journal-title":"Comput. Netw."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Arasteh, S., Aghili, S.F., and Mala, H. (2016, January 7\u20138). A new lightweight authentication and key agreement protocol for Internet of Things. Information Security and Cryptology (ISCISC). Proceedings of the 2016 13th International Iranian Society of Cryptology Conference, Tehran, Iran.","DOI":"10.1109\/ISCISC.2016.7736451"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"3376","DOI":"10.1109\/ACCESS.2017.2673239","article-title":"Lightweight three-factor authentication and key agreement protocol for internet-integrated wireless sensor networks","volume":"5","author":"Jiang","year":"2017","journal-title":"IEEE Access"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"1061","DOI":"10.1007\/s12652-017-0516-2","article-title":"Security analysis and improvement of bio-hashing based three-factor authentication scheme for telecare medical information systems","volume":"9","author":"Jiang","year":"2018","journal-title":"J. Ambient Intell. Humaniz. Comput."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"32","DOI":"10.1007\/s10916-015-0221-7","article-title":"An enhanced biometric-based authentication scheme for telecare medicine information systems using elliptic curve cryptosystem","volume":"39","author":"Lu","year":"2015","journal-title":"J. Med. Syst."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"357","DOI":"10.1109\/TWC.2015.2473165","article-title":"A provably secure, efficient, and flexible authentication scheme for ad hoc wireless sensor networks","volume":"15","author":"Chang","year":"2016","journal-title":"IEEE Trans. Wirel. Commun."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"4767","DOI":"10.3390\/s110504767","article-title":"A secured authentication protocol for wireless sensor networks using elliptic curves cryptography","volume":"11","author":"Yeh","year":"2011","journal-title":"Sensors"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"1070","DOI":"10.1007\/s12083-014-0285-z","article-title":"An efficient two-factor user authentication scheme with unlinkability for wireless sensor networks","volume":"8","author":"Jiang","year":"2015","journal-title":"Peer-to-peer Netw. Appl."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"198","DOI":"10.1109\/TIT.1983.1056650","article-title":"On the security of public key protocols","volume":"29","author":"Dolev","year":"1983","journal-title":"IEEE Trans. Inf. Theory"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Dodis, Y., Reyzin, L., and Smith, A. (2004). Fuzzy extractors: How to generate strong keys from biometrics and other noisy data. International Conference on the Theory and Applications of Cryptographic Techniques, Springer.","DOI":"10.1007\/978-3-540-24676-3_31"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"1953","DOI":"10.1109\/TIFS.2015.2439964","article-title":"A secure biometrics-based multi-server authentication protocol using smart cards","volume":"10","author":"Odelu","year":"2015","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Ouafi, K., and Phan, R.C.W. (2008). Privacy of recent rfid authentication protocols. International Conference on Information Security Practice and Experience, Springer.","DOI":"10.1007\/978-3-540-79104-1_19"},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"11229","DOI":"10.1109\/ACCESS.2018.2796539","article-title":"Two-Factor Authenticated Key Agreement Supporting Unlinkability in 5G-Integrated Wireless Sensor Networks","volume":"6","author":"Shin","year":"2018","journal-title":"IEEE Access"},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"72","DOI":"10.1016\/j.jnca.2016.12.008","article-title":"An efficient authentication and key agreement scheme for multi-gateway wireless sensor networks in IoT deployment","volume":"89","author":"Wu","year":"2017","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"194","DOI":"10.1016\/j.jnca.2017.07.001","article-title":"A three-factor anonymous authentication scheme for wireless sensor networks in internet of things environments","volume":"103","author":"Li","year":"2018","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1145\/77648.77649","article-title":"A logic of authentication","volume":"8","author":"Burrows","year":"1990","journal-title":"ACM Trans. Comput. Syst."},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Armando, A., Basin, D., Boichut, Y., Chevalier, Y., Compagna, L., Cu\u00e9llar, J., Drielsma, P.H., H\u00e9am, P.C., Kouchnarenko, O., and Mantovani, J. (2005). The AVISPA tool for the automated validation of internet security protocols and applications. International Conference on Computer Aided Verification, Springer.","DOI":"10.1007\/11513988_27"},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Blanchet, B. (2014). Automatic verification of security protocols in the symbolic model: The verifier proverif. Foundations of Security Analysis and Design VII, Springer.","DOI":"10.1007\/978-3-319-10082-1_3"},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"1377","DOI":"10.1007\/s11277-015-2288-3","article-title":"A secure and efficient user anonymity-preserving three-factor authentication protocol for large-scale distributed wireless sensor networks","volume":"82","author":"Das","year":"2015","journal-title":"Wirel. Pers. Commun."},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"223","DOI":"10.1007\/s12083-014-0324-9","article-title":"A secure and robust temporal credential-based three-factor user authentication scheme for wireless sensor networks","volume":"9","author":"Das","year":"2016","journal-title":"Peer-to-peer Netw. Appl."},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"173","DOI":"10.1016\/j.comnet.2017.08.006","article-title":"Energy-efficient mechanisms in security of the internet of things: A survey","volume":"127","author":"Hellaoui","year":"2017","journal-title":"Comput. Netw."},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"30","DOI":"10.1109\/TCE.2014.6780922","article-title":"Enhanced three-factor security protocol for consumer USB mass storage devices","volume":"60","author":"He","year":"2014","journal-title":"IEEE Trans. Consum. Electron."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/18\/11\/3663\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T15:26:42Z","timestamp":1760196402000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/18\/11\/3663"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,10,29]]},"references-count":47,"journal-issue":{"issue":"11","published-online":{"date-parts":[[2018,11]]}},"alternative-id":["s18113663"],"URL":"https:\/\/doi.org\/10.3390\/s18113663","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,10,29]]}}}