{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,21]],"date-time":"2026-05-21T02:28:49Z","timestamp":1779330529002,"version":"3.51.4"},"reference-count":35,"publisher":"MDPI AG","issue":"10","license":[{"start":{"date-parts":[[2019,5,22]],"date-time":"2019-05-22T00:00:00Z","timestamp":1558483200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100004083","name":"Ministry of Science ICT and Future Planning","doi-asserted-by":"publisher","award":["2017R1A2B1002147"],"award-info":[{"award-number":["2017R1A2B1002147"]}],"id":[{"id":"10.13039\/501100004083","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Ministry of Education","award":["21A20131600011"],"award-info":[{"award-number":["21A20131600011"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Internet of Things (IoT) environments such as smart homes, smart factories, and smart buildings have become a part of our lives. The services of IoT environments are provided through wireless networks to legal users. However, the wireless network is an open channel, which is insecure to attacks from adversaries such as replay attacks, impersonation attacks, and invasions of privacy. To provide secure IoT services to users, mutual authentication protocols have attracted much attention as consequential security issues, and numerous protocols have been studied. In 2017, Bae et al. presented a smartcard-based two-factor authentication protocol for multi-gateway IoT environments. However, we point out that Bae et al.\u2019s protocol is vulnerable to user impersonation attacks, gateway spoofing attacks, and session key disclosure, and cannot provide a mutual authentication. In addition, we propose a three-factor mutual authentication protocol for multi-gateway IoT environments to resolve these security weaknesses. Then, we use Burrows\u2013Abadi\u2013Needham (BAN) logic to prove that the proposed protocol achieves secure mutual authentication, and we use the Automated Validation of Internet Security Protocols and Applications (AVISPA) tool to analyze a formal security verification. In conclusion, our proposed protocol is secure and applicable in multi-gateway IoT environments.<\/jats:p>","DOI":"10.3390\/s19102358","type":"journal-article","created":{"date-parts":[[2019,5,23]],"date-time":"2019-05-23T03:22:03Z","timestamp":1558581723000},"page":"2358","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":60,"title":["Secure Three-Factor Authentication Protocol for Multi-Gateway IoT Environments"],"prefix":"10.3390","volume":"19","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8172-6182","authenticated-orcid":false,"given":"JoonYoung","family":"Lee","sequence":"first","affiliation":[{"name":"School of Electronics Engineering, Kyungpook National University, Daegu 41566, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3245-781X","authenticated-orcid":false,"given":"SungJin","family":"Yu","sequence":"additional","affiliation":[{"name":"School of Electronics Engineering, Kyungpook National University, Daegu 41566, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6172-9175","authenticated-orcid":false,"given":"KiSung","family":"Park","sequence":"additional","affiliation":[{"name":"School of Electronics Engineering, Kyungpook National University, Daegu 41566, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9011-8410","authenticated-orcid":false,"given":"YoHan","family":"Park","sequence":"additional","affiliation":[{"name":"IT Conversions, Korea Nazarene University, Cheonan, Chungcheongnam-do 31172, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0406-6547","authenticated-orcid":false,"given":"YoungHo","family":"Park","sequence":"additional","affiliation":[{"name":"School of Electronics Engineering, Kyungpook National University, Daegu 41566, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2019,5,22]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"72","DOI":"10.1016\/j.jnca.2016.12.008","article-title":"An efficient authentication and key agreement scheme for multi-gateway wireless sensor networks in IoT deployment","volume":"81","author":"Wu","year":"2017","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"2070","DOI":"10.1002\/sec.1464","article-title":"An efficient multi-gateway-based three-factor user authentication and key agreement scheme in hierarchical wireless sensor networks","volume":"9","author":"Das","year":"2016","journal-title":"Secur. Commun. Netw."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"1529","DOI":"10.1007\/s10916-010-9614-9","article-title":"A secure authentication scheme for telecare medicine information systems","volume":"36","author":"Wu","year":"2010","journal-title":"J. Med. Syst."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"9902","DOI":"10.1007\/s10916-012-9902-7","article-title":"A uniqueness-and-anonymity-preserving remote user authentication scheme for connected health care","volume":"37","author":"Chang","year":"2013","journal-title":"J. Med. Syst."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"96","DOI":"10.1016\/j.adhoc.2014.03.009","article-title":"A novel user authentication and key agreement scheme for heterogeneous ad hoc wireless sensor networks, based on the Internet of Things notion","volume":"20","author":"Brumen","year":"2014","journal-title":"Ad Hoc Netw."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"1989","DOI":"10.1007\/s10916-011-9658-5","article-title":"A more secure authentication scheme for telecare medicine information systems","volume":"36","author":"He","year":"2012","journal-title":"J. Med. Syst."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"9948","DOI":"10.1007\/s10916-013-9948-1","article-title":"A secure and efficient uniqueness-and-anonymity-preserving remote user authentication scheme for connected health care","volume":"37","author":"Das","year":"2013","journal-title":"J. Med. Syst."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"320","DOI":"10.1016\/j.future.2016.10.004","article-title":"Design of a provably secure biometrics-based multi-cloud-server authentication scheme","volume":"68","author":"Kumari","year":"2017","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"428","DOI":"10.1109\/TDSC.2016.2616876","article-title":"Secure biometric-based authentication scheme using chebyshev chaotic map for multi-server environment","volume":"15","author":"Chatterjee","year":"2018","journal-title":"IEEE Trans. Depend. Sec. Comput."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"58","DOI":"10.1016\/j.adhoc.2015.05.020","article-title":"A secure light weight scheme for user authentication and key agreement in multi-gateway based wireless sensor networks","volume":"36","author":"Amin","year":"2016","journal-title":"Ad Hoc Netw."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"19","DOI":"10.1016\/j.csi.2004.03.003","article-title":"A flexible biometrics remote user authentication scheme","volume":"27","author":"Lin","year":"2004","journal-title":"Comput. Stand. Interfaces"},{"key":"ref_12","first-page":"255","article-title":"A lightweight biometrics based remote user authentication scheme for IoT services","volume":"34","author":"Dhillon","year":"2017","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"147","DOI":"10.1016\/j.adhoc.2016.11.002","article-title":"Secure and efficient user authentication scheme for multi-gateway wireless sensor networks","volume":"54","author":"Srinivas","year":"2017","journal-title":"Ad Hoc Netw."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"727","DOI":"10.1016\/j.future.2017.08.042","article-title":"A lightweight and robust two-factor authentication scheme for personalized healthcare systems using wireless medical sensor networks","volume":"82","author":"Wu","year":"2018","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Bae, W., and Kwak, J. (2017). Smart card-based secure authentication protocol in multi-server IoT environment. Multimed. Tools. Appl., 1\u201319.","DOI":"10.20944\/preprints201705.0076.v1"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Xu, G., Qiu, S., Ahmad, H., Xu, G., Guo, Y., Zhang, M., and Xu, H. (2018). A multi-server two-factor authentication scheme with un-traceability using elliptic curve cryptography. Sensors, 18.","DOI":"10.3390\/s18072394"},{"key":"ref_17","first-page":"1","article-title":"Improving heterogeneous SOA-based IoT message stability by shortest processing time scheduling","volume":"99","author":"Leu","year":"2013","journal-title":"IEEE Trans. Serv. Comput."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"198","DOI":"10.1109\/TIT.1983.1056650","article-title":"On the security of public key protocols","volume":"29","author":"Dolev","year":"1983","journal-title":"IEEE Trans. Inf. Theory"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Kocher, P., Jaffe, J., and Jun, B. (1999). Differential power analysis. Advances in Cryptology, Springer Science+Business Media.","DOI":"10.1007\/3-540-48405-1_25"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Park, Y., and Park, Y. (2016). Three-factor user authentication and key agreement using elliptic curve cryptosystem in wireless sensor networks. Sensors, 16.","DOI":"10.3390\/s16122123"},{"key":"ref_21","first-page":"317","article-title":"A biometric identity based signature scheme","volume":"5","author":"Burnett","year":"2007","journal-title":"Int. J. Netw. Secur."},{"key":"ref_22","first-page":"523","article-title":"Fuzzy extractors: How to generate strong keys from biometrics and other noisy data","volume":"3027","author":"Dodis","year":"2004","journal-title":"Proc. Adv. Cryptol."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1177\/1550147717724308","article-title":"Security analysis and enhancements of an improved multi-factor biometric authentication scheme","volume":"13","author":"Park","year":"2017","journal-title":"Int. J. Distrib. Sens. Netw."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"7012","DOI":"10.1109\/ACCESS.2017.2694044","article-title":"On the design of fine grained access control with user authentication scheme for telecare medicine information systems","volume":"5","author":"Chatterjee","year":"2017","journal-title":"IEEE Access"},{"key":"ref_25","unstructured":"Von Oheimb, D. (2005, January 13\u201315). The high-level protocol specification language HLPSL developed in the EU project avispa. Proceedings of the APPSEM 2005 Workshop, Tallinn, Finland."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"25110","DOI":"10.1109\/ACCESS.2017.2773535","article-title":"Provably secure and efficient authentication protocol for roaming service in global mobility networks","volume":"5","author":"Park","year":"2017","journal-title":"IEEE Access"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"30225","DOI":"10.1109\/ACCESS.2018.2844190","article-title":"2PAKEP: Provably secure and efficient two-party authenticated key exchange protocol for mobile environment","volume":"6","author":"Park","year":"2018","journal-title":"IEEE Access"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Yu, S., Lee, J., Lee, K., Park, K., and Park, Y. (2018). Secure authentication protocol for wireless sensor networks in vehicular communications. Sensors, 18.","DOI":"10.3390\/s18103191"},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Turuani, M. (2006, January 12\u201314). The CL-Atse protocol analyser. Proceedings of the International Conference on Rewriting Techniques and Applications (RTA), Seattle, WA, USA.","DOI":"10.1007\/11805618_21"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"181","DOI":"10.1007\/s10207-004-0055-7","article-title":"OFMC: A symbolic model checker for security protocols","volume":"4","author":"Basin","year":"2005","journal-title":"Int. J. Inf. Secur."},{"key":"ref_31","unstructured":"AVISPA (2019, January 11). Automated Validation of Internet Security Protocols and Applications. Available online: http:\/\/www.avispa-project.org\/."},{"key":"ref_32","unstructured":"(2019, January 11). SPAN: A Security Protocol Animator for AVISPA. Available online: http:\/\/www.avispa-project.org\/."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1016\/j.comcom.2017.05.009","article-title":"A secure and robuts anonymous three-factor remote user authentication scheme for multi-server environment using ECC","volume":"110","author":"Preeti","year":"2017","journal-title":"Comput. Commun."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"2803","DOI":"10.1016\/j.comcom.2007.12.005","article-title":"A secure and efficient communication scheme with authenticated key establishment and privacy preserving for vehicular ad hoc networks","volume":"31","author":"Li","year":"2008","journal-title":"Comput. Commun."},{"key":"ref_35","first-page":"1","article-title":"A robust and efficient ECC-based mutual authentication and session key generation scheme for healthcare applications","volume":"43","author":"Nikooghadm","year":"2019","journal-title":"J. Med. Syst."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/19\/10\/2358\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T12:54:14Z","timestamp":1760187254000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/19\/10\/2358"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,5,22]]},"references-count":35,"journal-issue":{"issue":"10","published-online":{"date-parts":[[2019,5]]}},"alternative-id":["s19102358"],"URL":"https:\/\/doi.org\/10.3390\/s19102358","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,5,22]]}}}