{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,27]],"date-time":"2026-05-27T16:09:13Z","timestamp":1779898153486,"version":"3.53.1"},"reference-count":39,"publisher":"MDPI AG","issue":"16","license":[{"start":{"date-parts":[[2020,8,5]],"date-time":"2020-08-05T00:00:00Z","timestamp":1596585600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Internet of Things (IoT) has become the driving force in modern day technology with an increasing and rapid urge to create an intelligent, efficient, and connected world. IoT is used in manufacturing, agriculture, transportation, education, healthcare and many other business environments as well as home automation. Authentication for IoT devices is essential because many of these devices establish communication with servers through public networks. A rigorous lightweight device authentication scheme is needed to secure its physical hardware from cloning or side-channel attacks and accommodate the limited storage and computational power of IoT devices in an efficient manner. In this paper, we introduce a lightweight mutual two-factor authentication mechanism where an IoT device and the server authenticate each other. The proposed mechanism exploits Physical Unclonable Functions (PUFs) and a hashing algorithm with the purpose of achieving a secure authentication and session key agreement between the IoT device and the server. We conduct a type of formal analysis to validate the protocol\u2019s security. We also validate that the proposed authentication mechanism is secure against different types of attack scenarios and highly efficient in terms of memory storage, server capacity, and energy consumption with its low complexity cost and low communication overhead. In this sense, the proposed authentication mechanism is very appealing and suitable for resource-constrained and security-critical environments.<\/jats:p>","DOI":"10.3390\/s20164361","type":"journal-article","created":{"date-parts":[[2020,8,5]],"date-time":"2020-08-05T06:02:21Z","timestamp":1596607341000},"page":"4361","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":27,"title":["Physical Unclonable Function and Hashing Are All You Need to Mutually Authenticate IoT Devices"],"prefix":"10.3390","volume":"20","author":[{"given":"Ahmed","family":"Mostafa","sequence":"first","affiliation":[{"name":"TSYS School of Computer Science, Columbus State University, Columbus, GA 31907, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3285-0806","authenticated-orcid":false,"given":"Suk Jin","family":"Lee","sequence":"additional","affiliation":[{"name":"TSYS School of Computer Science, Columbus State University, Columbus, GA 31907, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yesem Kurt","family":"Peker","sequence":"additional","affiliation":[{"name":"TSYS School of Computer Science, Columbus State University, Columbus, GA 31907, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2020,8,5]]},"reference":[{"key":"ref_1","first-page":"1327","article-title":"Mutual Authentication in IoT Systems using Physical Unclonable Functions","volume":"4","author":"Aman","year":"2017","journal-title":"IEEE IoT"},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Hung, C., and Hsu, W. (2018). Power Consumption and Calculation Requirement Analysis of AES for WSN IoT. Sensors, 18.","DOI":"10.3390\/s18061675"},{"key":"ref_3","first-page":"580","article-title":"Lightweight and Privacy-Preserving Two-Factor Authentication Scheme for IoT Devices","volume":"6","author":"Gope","year":"2019","journal-title":"IEEE IoT"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Rabiah, A.B., Ramakrishnan, K.K., Liri, E., and Kar, K. (2018). Lightweight Authentication and Key Exchange Protocol for IoT. Workshop of Decentralized IoT Security and Standards (DISS), NDSS.","DOI":"10.14722\/diss.2018.23004"},{"key":"ref_5","unstructured":"(2020, July 30). Who Needs to Worry About Firmware Attacks?. Available online: https:\/\/www.opswat.com\/blog\/who-needs-worry-about-firmware-attacks."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Mughal, M.A., Luo, X., Mahmood, Z., and Ullah, A. (2018, January 17\u201319). Physical Unclonable Function Based Authentication Scheme for Smart Devices in Internet of Things. Proceedings of the IEEE International Conference on (SmartIoT), Xi\u2019an, China.","DOI":"10.1109\/SmartIoT.2018.00037"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Alizai, Z.A., Tareen, N.F., and Jadoon, I. (2018, January 4\u20135). Improved IoT Device Authentication Scheme Using Device Capability and Digital Signatures. Proceedings of the 2018 International Conference on Applied and Engineering Mathematics (ICAEM), Taxila, Pakistan.","DOI":"10.1109\/ICAEM.2018.8536261"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Han, J., and Kim, J. (2017, January 18\u201320). A Lightweight authentication mechanism between IoT. Proceedings of the 2017 International Conference on (ICTC), Jeju, Korea.","DOI":"10.1109\/ICTC.2017.8190883"},{"key":"ref_9","unstructured":"Rajaguru, K., and Hansdah, R.C. (2018, January 16\u201318). Symmetric Key-Based Lightweight Authentication Protocols for RFID Security. Proceedings of the 2018 32nd International Conference on (WAINA), Krakow, Poland."},{"key":"ref_10","first-page":"1","article-title":"Using Elliptic Curves on RFID Tags","volume":"8","author":"Braun","year":"2008","journal-title":"IJCSNS"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Tewari, A., and Gupta, B.B. (2018, January 11\u201312). A Mutual Authentication Protocol for IoT Devices Using Elliptic Curve Cryptography. Proceedings of the 2018 8th International Conference on Cloud Computing, Data Science & Engineering, Noida, India.","DOI":"10.1109\/CONFLUENCE.2018.8442962"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Kumari, A., Kumar, V., YahyaAbbasi, M., and Alam, M. (2018, January 12\u201313). The Cryptanalysis of a Secure Authentication Scheme Based on Elliptic Curve Cryptography for IOT and Cloud Servers. Proceedings of the 2018 International Conference on Advances in Computing, Communication Control and Networking (ICACCCN), Greater Noida, India.","DOI":"10.1109\/ICACCCN.2018.8748591"},{"key":"ref_13","unstructured":"Costin, A., Zaddach, J., Francillon, A., and Balzarotti, D. (2014, January 20\u201322). A Large Scale Analysis of the Security of Embedded Firmwares. Proceedings of the 23rd USENIX Security Symposium, San Diego, CA, USA. Available online: https:\/\/www.usenix.org\/conference\/usenixsecurity14\/technical-sessions\/presentation\/costin\/."},{"key":"ref_14","unstructured":"Balakrishnan, M. (2020, July 30). Freescale Trust Computing and Security in the Smart Grid, Freescale White Paper, Document Number: TRCMPSCSMRTGRDWP REV 1. Available online: http:\/\/cache.nxp.com\/files\/32bit\/doc\/white_paper\/TRCMPSCSMRTGRDWP.pdf."},{"key":"ref_15","unstructured":"Akgul, F., Ye, Y., Pahlavan, K., Steger, C., Alizadeh-shabdiz, F., and Morgan, T. (2020, August 02). Taking Positioning Indoors: Wi-Fi Localization and GNSS. Available online: https:\/\/www.academia.edu\/4255217\/Taking_Positioning_Indoors_Wi_Fi_Localization_and_GNSS."},{"key":"ref_16","unstructured":"e Silva, P.F., Kaseva, V., and Lohan, E.S. (2018). Wireless Positioning in IoT: A Look at Current and Future Trends. Sensors, 8."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Zhang, F., Kondoro, A., and Muftic, S. (2012, January 25\u201327). Location-Based Authentication and Authorization Using Smart Phones. Proceedings of the 2012 IEEE 11th International Conference on Trust, Security and Privacy in Computing and Communications, Liverpool, UK.","DOI":"10.1109\/TrustCom.2012.198"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Babaei, A., and Schiele, G. (2019). Physical Unclonable Functions in the Internet of Things: State of the Art and Open Challenges. Sensors, 19.","DOI":"10.3390\/s19143208"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"1126","DOI":"10.1109\/JPROC.2014.2320516","article-title":"Physical Unclonable Functions and Applications: A Tutorial","volume":"102","author":"Herder","year":"2014","journal-title":"Proc. IEEE"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"R\u00fchrmair, U., Sehnke, F., S\u00f6lter, J., Dror, G., Devadas, S., and Schmidhuber, J. (2010, January 4\u20138). Modeling attacks on physical unclonable functions. Proceedings of the 17th ACM Conference on (CCS), Chicago, Illinois, USA.","DOI":"10.1145\/1866307.1866335"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Maes, R., Tuyls, P., and Verbauwhede, I. (2009, January 6\u20139). Low-overhead implementation of a soft decision helper data algorithm for SRAM PUFs. Proceedings of the Cryptographic Hardware and Embedded Systems\u2014CHES 2009: 11th International Workshop, Lausanne, Switzerland.","DOI":"10.1109\/ISIT.2009.5205263"},{"key":"ref_22","unstructured":"Schrijen, G., and Garlati, C. (2020, July 30). Physical Unclonable Functions to the Rescue A New Way to Establish Trust in Silicon. Available online: https:\/\/pdfs.semanticscholar.org\/79b1\/8f8641ae94e90a4558de822ce0d2a0bd4f6c.pdf?_ga=2.260509514.692675847.1586827044-134552544.1586827044."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Suh, G.E., and Devadas, S. (2007, January 4\u20138). Physical Unclonable Functions for Device Authentication and Secret Key Generation. Proceedings of the 2007 44th ACM\/IEEE Design Automation Conference 2007, San Diego, CA, USA.","DOI":"10.1109\/DAC.2007.375043"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Gassend, B., Clarke, D., van Dijk, M., and Devadas, S. (2002, January 18\u201322). Silicon physical random functions. Proceedings of the 9th ACM Conference on (CCS), Washington, DC, USA.","DOI":"10.1145\/586110.586132"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"2026","DOI":"10.1126\/science.1074376","article-title":"Physical one-way functions","volume":"297","author":"Pappu","year":"2002","journal-title":"Science"},{"key":"ref_26","unstructured":"(2020, July 30). TOTP: Time-Based One-Time Password Algorithm. Available online: https:\/\/tools.ietf.org\/html\/rfc6238."},{"key":"ref_27","unstructured":"(2020, July 30). Computer Network|HMAC Algorithm. Available online: https:\/\/www.geeksforgeeks.org\/computer-network-hmac-algorithm\/."},{"key":"ref_28","unstructured":"(2020, July 30). What You Need to Know About SHA-3 for Embedded System Security. Available online: https:\/\/www.electronicdesign.com\/technologies\/embedded-revolution\/article\/21808025\/what-you-need-to-know-about-sha3-for-embedded-system-security."},{"key":"ref_29","unstructured":"(2020, July 30). The Constrained Application Protocol (CoAP). Available online: https:\/\/tools.ietf.org\/html\/rfc7252."},{"key":"ref_30","unstructured":"(2020, July 30). Invasive Attacks. Available online: https:\/\/www.sec.ei.tum.de\/en\/research\/invasive-attacks\/."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"van der Leest, V., Maes, R., Schrijen, G.J., and Tuyls, P. (2014). Hardware intrinsic security to protect value in the mobile market. ISSE 2014 Securing Electronic Business Processes, Springer.","DOI":"10.1007\/978-3-658-06708-3_15"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Xu, H., Ding, J., Li, P., Zhu, F., and Wang, R. (2018). A Lightweight RFID mutual authentication protocol based on physical unclonable function. Sensors, 18.","DOI":"10.3390\/s18030760"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"85627","DOI":"10.1109\/ACCESS.2019.2926578","article-title":"Physically Secure Lightweight Anonymous User Authentication Protocol for Internet of Things Using Physically Unclonable Functions","volume":"7","author":"Banerjee","year":"2019","journal-title":"IEEE Access"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1145\/77648.77649","article-title":"A logic of authentication","volume":"8","author":"Burrows","year":"1990","journal-title":"ACM Trans. Comput. Syst."},{"key":"ref_35","unstructured":"(2020, July 30). Advanced Encryption Standard (AES) Ciphersuites for Transport layer Security (TLS). Available online: https:\/\/tools.ietf.org\/html\/rfc3268."},{"key":"ref_36","first-page":"30","article-title":"A Comparative Study on AES 128 BIT AND AES 256 BIT","volume":"6","author":"Suchithra","year":"2018","journal-title":"Int. J. Sci. Res. Comput. Sci. Eng."},{"key":"ref_37","unstructured":"(2020, July 30). IoT Specific IPv6 Stateless Address Autoconfiguration with Modified EUI-64. Available online: https:\/\/tools.ietf.org\/html\/draft-pskim-iot-ipv6-eui64-00."},{"key":"ref_38","unstructured":"(2020, July 30). AES-CCM Cipher Suites for Transport Layer Security (TLS). Available online: https:\/\/tools.ietf.org\/html\/rfc6655."},{"key":"ref_39","unstructured":"(2020, July 30). Using HMAC-SHA-256, HMAC-SHA-384, and HMAC-SHA-512 with IPsec. Available online: https:\/\/tools.ietf.org\/html\/rfc4868."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/20\/16\/4361\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T09:54:27Z","timestamp":1760176467000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/20\/16\/4361"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,8,5]]},"references-count":39,"journal-issue":{"issue":"16","published-online":{"date-parts":[[2020,8]]}},"alternative-id":["s20164361"],"URL":"https:\/\/doi.org\/10.3390\/s20164361","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,8,5]]}}}