Formal Analysis of Kang et al.'s Authentication Protocol using Tamarin-Prover
Alsita Putri Iriana, Sepha Siswantyo · 2021
The increasing use of IoT leads to additional IoT cloud data and also security and privacy issues. Therefore, it is necessary to have an authentication protocol on the IoT cloud. One of the authentication protocols proposed for cloud IoT is an improved version of Amin et al.'s protocol, Kang et al.'s authentication protocol. The protocol combines the pseudo-identity and actual identity of the cloud server or user with the secret number owned by control server to prevent impersonation attacks effectively. However, no formal analysis has been carried out to prove the strength of the protocol. This research proposed a formal analysis using Tamarin-Prover, which is one of the tools to model a protocol symbolically and analyze the protocol formally. The research steps were performed based on the protocol analysis methodology. Verification using Tamarin-Prover is carried out on secrecy and authentication aspects, including aliveness, weak agreements, non-injective agreements, and injective agreements. The verification results show that Kang et al.'s authentication protocol satisfies the secrecy aspect for each entity's nonce and session key, as well as the authentication aspect for the authentication process carried out by the control server to the user, the control server to the cloud server, the cloud server to the control server, and the user to the cloud server.