An Analysis of Broadcast Authentication and Security Schemes in Wireless Sensor Networks
C. P. Suresh, Gnana Dhas · 2013
Wireless Sensor Networks (WSNs) are susceptible to various attacks as they are placed in hostile environments. Several security and authentication mechanisms are proposed for in terms of key exchange mechanisms, handshake protocols, and other routing protocols. The proposed triple key based broadcast authentication protocol is compared with the several other existing security schemes in WSN. The proposed triple key based broadcast authentication scheme works upon TESLA (Timed Efficient Stream Loss-tolerant Authentication) protocol and ECDH (Elliptic Curve Diffie-Hellman) key agreement scheme. The proposed WSN authentication performs better compared to other security schemes, in terms of accuracy, detection of attacks, resiliency, memory consumption, nodal detection, and average of total transmission energy consumed per node. Keyword- Base Station1, Elliptic Curve Diffie-Hellman2, Signature3, Timed Efficient Stream Loss- Tolerant4, Wireless Sensor Networks5. I. I NTRODUCTION Wireless Sensor Networks (WSNs) contain a large number of small sensing nodes. A secure multicast protocol is required to increase the cryptographic strength, authentication and confidentiality. The security in the WSNs is a trivial aspect, which can be enhanced by various measures like key management schemes, signatures, and cryptography methods like Elliptic Curve Diffie-Hellman (ECDH) key agreement protocol. Some of the techniques are analysed and compared with the proposed triple key management scheme using TESLA (Timed Efficient Stream Loss-tolerant Authentication) broadcast authentication protocol. The remaining part of the paper is organized as follows: Section II involves the works related to the broadcast authentication and security schemes in a WSN. Section III involves the detailed analysis of the existing and proposed broadcast authentication and security schemes in a WSN. Section IV involves the security analysis and comparison of the existing and proposed security schemes in a WSN. The paper is concluded in Section V. II. RELATED WORK The various authentication and security mechanisms are discussed in this section. In (1), a bandwidth- effective cooperative authentication (BECAN) is introduced for filtering the false data injection in WSN. This scheme can save energy by the early detection of false data injections. The sink involves only a small fraction of false data injection to be checked. In (2), the HIP DEX scheme is developed by the IETF (Internet Engineering Task Force) to establish a secure WSN. In (3), a novel scheme is developed to maintain the authenticity, secrecy, freshness, and integrity of the broadcast messages in single hop WSNs. This method uses time-varying keys for the broadcast encryption, which results in non-forgeability, allowance for dynamic data, and protection against old-key compromise. The key chain mechanism is also extended to the resistance against key loss, permitting legitimate users to recover. In (4), a security negotiation protocol has been developed for the WSNs based on TLS (Transport Layer Security) handshake. The comparative analyses involve RSA (Rivest-Shamir- Adleman) key transport, Identity Based Encryption and ECDH key agreements. The WSNs involving the mobile sinks, composite and pairwise key pre-distribution schemes involve a security constraint. In (5), a three-tier framework is used to use any pairwise key pre-distribution scheme as its main component. This scheme requires separate pools for the mobile sink and pairwise key establishment to access the network. In (6), (7) a fast and lightweight pairing-based cryptography method is used in the WSN. A singular elliptic curve is used as the pairing group. The security of the pairing-based cryptosystems depends on the elliptic curve discrete logarithm problem (ECDLP) in the elliptic curve group and discrete logarithm problem in the finite field. The solution to ECDLP is given by Polard's rho method. In (8), the scalability of the key management schemes is focussed. A highly scalable key management scheme is proposed based on unital design theory, resulting in high secure connectivity and coverage. The mapping from unitals to key pre-