S2-Code: A Resilient and Lightweight Self-Synchronizing Authentication Protocol for Unreliable IoT Networks
Yuning Cao, Menglei Kou, Yujia Lai, Ziqing Mei · IEEE Access · 2025
Reliable authentication in resource-constrained IoT remains challenging on lossy wireless links, which induce desynchronization and amplify denial-of-service (DoS) risk. We present S²-Code, a self-synchronizing symmetric protocol that couples a dual-window state machine with an AEAD-protected bidirectional token. We derive practical window-sizing bounds from packet loss/reordering, request rate, and offline duration, and validate the design via symbolic verification in ProVerif, network emulation in Mininet, and hardware experiments on Raspberry Pi and ESP32-C3. S²-Code achieves 100% session recovery after a catastrophic 50-count desynchronization where rolling codes fail. Under 30% packet loss, it sustains 60% success versus 20% for the rolling-code baseline (p < 10⁻⁸). A layered DoS defense—kernel-level rate limiting (nftables) plus an adaptive protocol mechanism—raises legitimate success from ≈17% under flooding to ≈92.9% under protocol-aware attack. The protocol has a small footprint (<8 KB flash, <4 KB RAM), low overhead (≈114-byte packets, <17 ms latency), and scales to 100 concurrent devices in emulation. S²-Code offers a practical, robust middle ground between fragile rolling codes and heavyweight PKI for resource-constrained IoT.