{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,16]],"date-time":"2026-06-16T07:41:17Z","timestamp":1781595677510,"version":"3.54.5"},"reference-count":30,"publisher":"MDPI AG","issue":"21","license":[{"start":{"date-parts":[[2019,10,24]],"date-time":"2019-10-24T00:00:00Z","timestamp":1571875200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Wireless sensor networks (WSNs) are of prominent use in unmanned surveillance applications. This peculiar trait of WSNs is actually the underlying technology of various applications of the Internet of Things (IoT) such as smart homes, smart cities, smart shopping complexes, smart traffic, smart health, and much more. Over time, WSNs have evolved as a strong base for laying the foundations of IoT infrastructure. In order to address the scenario in which a user wants to access the real-time data directly from the sensor node in wireless sensor networks (WSNs), Das recently proposed an anonymity-preserving three-factor authentication protocol. Das\u2019s protocol is suitable for resource-constrained sensor nodes because it only uses lightweight cryptographic primitives such as hash functions and symmetric encryption schemes as building blocks. Das\u2019s protocol is claimed to be secure against different known attacks by providing formal security proof and security verification using the Automated Validation of Internet Security Protocols and Applications tool. However, we find that Das\u2019s protocol has the following security loopholes: (1) By using a captured sensor node, an adversary can impersonate a legal user to the gateway node, impersonate other sensor nodes to deceive the user, and the adversary can also decrypt all the cipher-texts of the user; (2) the gateway node has a heavy computational cost due to user anonymity and thus the protocol is vulnerable to denial of service (DoS) attacks. We overcome the shortcomings of Das\u2019s protocol and propose an improved protocol. We also prove the security of the proposed protocol in the random oracle model. Compared with the other related protocols, the improved protocol enjoys better functionality without much enhancement in the computation and communication costs. Consequently, it is more suitable for applications in WSNs<\/jats:p>","DOI":"10.3390\/s19214625","type":"journal-article","created":{"date-parts":[[2019,10,25]],"date-time":"2019-10-25T04:41:27Z","timestamp":1571978487000},"page":"4625","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":30,"title":["Cryptanalysis and Improvement of a Privacy-Preserving Three-Factor Authentication Protocol for Wireless Sensor Networks"],"prefix":"10.3390","volume":"19","author":[{"given":"Km","family":"Renuka","sequence":"first","affiliation":[{"name":"Department of Mathematics, Ch. Charan Singh University, Meerut, Uttar Pradesh 250004, India"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5324-2156","authenticated-orcid":false,"given":"Sachin","family":"Kumar","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Ajay Kumar Garg Engineering College, Ghaziabad 201009, India"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Saru","family":"Kumari","sequence":"additional","affiliation":[{"name":"Department of Mathematics, Ch. Charan Singh University, Meerut, Uttar Pradesh 250004, India"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6502-472X","authenticated-orcid":false,"given":"Chien-Ming","family":"Chen","sequence":"additional","affiliation":[{"name":"College of Computer Science and Engineering, Shandong University of Science and Technology, Qingdao 266590, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2019,10,24]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"71","DOI":"10.1109\/MCOM.2015.7010518","article-title":"Authentication protocol for an ambient assisted living system","volume":"53","author":"He","year":"2015","journal-title":"Commun. Mag."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"229","DOI":"10.1007\/s11277-013-1282-x","article-title":"Cryptanalysis and Improvement of an anonymous authentication protocol for wireless access networks","volume":"74","author":"He","year":"2014","journal-title":"Wirel. Pers. Commun."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"1086","DOI":"10.1109\/TWC.2008.080128","article-title":"Two-Factor user authentication in wireless sensor networks","volume":"8","author":"Das","year":"2009","journal-title":"IEEE Trans. Wirel. Commun."},{"key":"ref_4","first-page":"631","article-title":"Improvement of Das\u2019s two-factor authentication protocol in wireless sensor networks","volume":"2009","author":"Nyang","year":"2009","journal-title":"ePrint Arch."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"704","DOI":"10.4218\/etrij.10.1510.0134","article-title":"A robust mutual authentication protocol for wireless sensor networks","volume":"32","author":"Chen","year":"2010","journal-title":"ETRI J."},{"key":"ref_6","first-page":"1","article-title":"An enhanced two-factor user authentication scheme in wireless sensor networks","volume":"10","author":"He","year":"2010","journal-title":"Ad Hoc Sens. Wirel. Netw."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"2450","DOI":"10.3390\/s100302450","article-title":"Cryptanalysis and security improvements of two-factor user authentication in wireless sensor networks","volume":"10","author":"Khan","year":"2010","journal-title":"Sensors"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"895","DOI":"10.1007\/s00779-012-0540-3","article-title":"On the security and improvement of a two-factor user authentication scheme in wireless sensor networks","volume":"17","author":"Sun","year":"2012","journal-title":"Pers. Ubiquitous Comput."},{"key":"ref_9","unstructured":"Bellare, M., and Rogaway, P. (1993, January 22\u201326). Entity Authentication and Key Distribution. Proceedings of the 13th Annual International Cryptology Conference (Crypto\u201993), Santa Barbara, CA, USA."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"105","DOI":"10.1007\/s11235-013-9755-5","article-title":"An enhanced two-factor user authentication in wireless sensor networks","volume":"55","author":"Yuan","year":"2013","journal-title":"Telecommun. Syst."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Gong, L., Needham, R., and Yahalom, R. (1990, January 6\u20138). Reasoning About Belief in Cryptographic Protocols. Proceedings of the IEEE Computer Society Symposium Research in Security and Privacy (SP\u201990), Oakland, CA, USA.","DOI":"10.1109\/RISP.1990.63854"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s12083-016-0485-9","article-title":"An improved and provably secure three-factor user authentication scheme for wireless sensor networks","volume":"11","author":"Wu","year":"2018","journal-title":"Peer Peer Netw. Appl."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"159","DOI":"10.1016\/j.adhoc.2014.11.018","article-title":"User authentication schemes for wireless sensor networks: A review","volume":"27","author":"Kumari","year":"2015","journal-title":"Ad Hoc Netw."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"194","DOI":"10.1016\/j.jnca.2017.07.001","article-title":"A three-factor anonymity authentication scheme for wireless sensor networks in internet of things environments","volume":"103","author":"Li","year":"2018","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Wu, F., Xu, L., Kumari, S., Li, X., Shen, J., Raymond Choo, K.K., Wazid, M., and Kumar Das, A. (2016). An efficient authentication and key agreement scheme for multi-gateway wireless sensor networks in IoT deployment. J. Netw. Comput. Appl.","DOI":"10.1016\/j.jnca.2016.12.008"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Renuka, K., Kumari, S., Zhao, D., and Li, L. (2019). Design of a secure password-based authentication scheme for m2m networks in iot enabled cyber-physical systems. IEEE Access.","DOI":"10.1109\/ACCESS.2019.2908499"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"3599","DOI":"10.1109\/TII.2017.2773666","article-title":"A robust ECC based provable secure authentication protocol with privacy preserving for industrial internet of things","volume":"14","author":"Li","year":"2018","journal-title":"IEEE Trans. Ind. Inf."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"1377","DOI":"10.1007\/s11277-015-2288-3","article-title":"A secure and efficient user anonymity-preserving three-factor authentication protocol for large-scale distributed wireless sensor networks","volume":"82","author":"Das","year":"2015","journal-title":"Wirel. Pers. Commun."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"229","DOI":"10.1016\/j.engappai.2018.10.010","article-title":"Mining of skyline patterns by considering both frequent and utility constraints","volume":"77","author":"Lin","year":"2019","journal-title":"Eng. Appl. Artif. Intell."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"65","DOI":"10.1007\/s11227-017-2105-8","article-title":"On the security of a new ultra-lightweight authentication protocol in iot environment for RFID tags","volume":"74","author":"Wang","year":"2018","journal-title":"J. Supercomput."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Dodis, Y., Reyzin, L., and Smith, A. (2004, January 2\u20136). Fuzzy Extractors: How to Generate Strong Keys from Biometrics and Other Noisy Datas. Proceedings of the International Europe Cryptology Conference (Eurocrypto\u201904), Interlaken, Switzerland.","DOI":"10.1007\/978-3-540-24676-3_31"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Wang, D., He, D., Wang, P., and Chu, C.-H. (2014). Anonymous two-factor authentication in distributed systems: Certain goals are beyond attainment. IEEE Trans. Depend. Secure Comput.","DOI":"10.1109\/TDSC.2014.2355850"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"25359","DOI":"10.1109\/ACCESS.2019.2899831","article-title":"A sanitization approach to secure shared data in an iot environment","volume":"7","author":"Lin","year":"2019","journal-title":"IEEE Access"},{"key":"ref_24","unstructured":"Gan, W., Lin, C.W., Fournier-Viger, P., Chao, H.C., Tseng, V., and Yu, P. (2019). A survey of utility-oriented pattern mining. IEEE Trans. Knowl. Data Eng."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"1614","DOI":"10.1109\/TVLSI.2019.2903289","article-title":"Novel systolization of subquadratic space complexity multipliers based on toeplitz matrix\u2013vector product approach","volume":"27","author":"Pan","year":"2019","journal-title":"IEEE Trans. Very Large Scale Integr. Syst."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"12047","DOI":"10.1109\/ACCESS.2019.2891105","article-title":"A secure authentication protocol for internet of vehicles","volume":"7","author":"Chen","year":"2019","journal-title":"IEEE Access"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"20","DOI":"10.1080\/02533839.2018.1537807","article-title":"A provably secure certificateless public key encryption with keyword search","volume":"42","author":"Wu","year":"2019","journal-title":"J. Chin. Inst. Eng."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"3133","DOI":"10.1007\/s12652-018-1029-3","article-title":"Attacks and solutions on a three-party password-based authenticated key exchange protocol for wireless communications","volume":"10","author":"Chen","year":"2019","journal-title":"J. Ambient Intell. Hum. Comput."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"453","DOI":"10.1016\/j.future.2019.03.008","article-title":"Partially policy-hidden attribute-based broadcast encryption with secure delegation in edge computing","volume":"97","author":"Xiong","year":"2019","journal-title":"Fut. Gener. Comput. Syst."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Lin, J.C.W., Zhang, Y., Zhang, B., Fournier-Viger, P., and Djenouri, Y. (2019). Hiding sensitive itemsets with multiple objective optimization. Soft Comput.","DOI":"10.1007\/s00500-019-03829-3"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/19\/21\/4625\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T13:29:03Z","timestamp":1760189343000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/19\/21\/4625"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,10,24]]},"references-count":30,"journal-issue":{"issue":"21","published-online":{"date-parts":[[2019,11]]}},"alternative-id":["s19214625"],"URL":"https:\/\/doi.org\/10.3390\/s19214625","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,10,24]]}}}