Security Analysis on a Two-Factor Privacy-Preserving Protocol for Efficient Authentication in Internet of Vehicles Networks
Shuangshuang Liu, Zhi Wang · IEEE Internet of Things Journal · 2025
In Vehicular Ad Hoc Networks(VANETs) environments, information needs to be exchanged frequently between vehicles, Road Side Units (RSUs), and management centers to support safe and efficient traffic management. However, due to the openness of wireless communication and dynamic network topology, VANETs face many security threats such as forging, eavesdropping, and man-in-the-middle attacks. Therefore, it is crucial to design efficient and secure authentication protocols. To address this problem, Sibahee et al. proposed a two-factor privacy-preserving authentication protocol in IEEE Internet of Things Journal (pp. 14253-14266, DOI: 10.1109/JIOT.2023.3340259, April 15, 2024) and claimed that it can resist multiple attacks. However, we find that the protocol cannot resist temporary random number leakage attacks and privileged insider attacks, and does not have perfect forward security. To address the above problems, this paper proposes an improved authentication scheme based on elliptic curve cryptography (ECC) to enhance the security of the scheme. We conduct formal (Real-Or-Random Model) and informal security analyses of the improved scheme and evaluate its performance in terms of computational overhead and communication cost. The experimental results show that the improved scheme has significant advantages in both security and performance.