计算机科学
计算机安全
会话密钥
密钥协议
随机预言
认证(法律)
加密时值
短暂键
密码协议
密码学
椭圆曲线密码
身份验证协议
信息泄露
相互认证
计算机网络
反射攻击
智能卡
协议(科学)
智能电网
安全性分析
钥匙(锁)
前向保密
安全性令牌
安全传输
数字签名
报文认证码
Otway–Rees协议
可证明的安全性
公钥密码术
又称作
加密
密钥管理
共享秘密
通用可组合性
公钥基础设施
作者
Sijia Li,Hua Guo,Jianwei Liu,Yiran Han,Hutao Song
标识
DOI:10.1109/jiot.2025.3629755
摘要
The increasing complexity of the smart grid raises significant concerns regarding the security of smart grid communication. As a countermeasure, authentication and key agreement (AKA) protocol ensures the secure transmission of sensitive information between legitimate entities by achieving mutual authentication and establishing session keys. One of the most urgent and critical security threats in AKA protocol concerns ephemeral secret leakage (ESL) attack, due to its threat to session key secrecy. However, there remains a lack of systematic understanding of how to resist ESL attacks in smart grid environment. Therefore, we categorize the ESL attack into three different types, then conduct an in-depth analysis of their root causes and propose corresponding recommendations to mitigate it. To further illustrate the effectiveness of the recommendations, we design a secure and efficient AKA protocol based on elliptic curve cryptography accordingly. The proposed protocol is proven secure through rigorous security proof under the random oracle model and formally verified by AVISPA tool. Performance comparisons indicate that the proposed protocol outperforms other related protocols due to its lightweight nature and adherence to all fundamental security attributes, making it well-suited for deployment in resource-constrained smart grid environment.
科研通智能强力驱动
Strongly Powered by AbleSci AI