Modeling cryptographic authentication approaches for automated trusted access management in cyberphysical systems
Main Article Content
Abstract
This study models and evaluates cryptographic authentication approaches to enhance secure automated access in Cyber-Physical Systems (CPS), such as smart grids and autonomous vehicles. Three models—PKI-based, Zero Knowledge Proof (ZKP)-based, and ECC with Challenge-Response—are compared through simulations using MATLAB and NS3. Evaluation metrics include latency, computational overhead, scalability, and resistance to cyber-attacks. The ECC model demonstrated the best overall performance in real-time, resource-constrained environments. The ZKP model offered superior privacy and attack resilience, ideal for sensitive applications. The PKI model, while strong in identity assurance, exhibited high latency and is best suited for structured networks. The study emphasizes the contextual suitability of each model and suggests hybrid approaches and future directions, such as quantum-safe cryptography and biometric integration. This research provides a framework for selecting authentication mechanisms tailored to CPS-specific operational and security requirements.
Article Details
References
Aghili, S., Rahmani, A. M., & Hosseinzadeh, M. (2022). A survey on secure authentication and access control solutions in the Internet of Things. Journal of Network and Computer Applications, 200, 103319. https://doi.org/10.1016/j.jnca.2021.103319 DOI: https://doi.org/10.1016/j.jnca.2021.103319
Alshahrani, A., et al. (2023). Lightweight hybrid authentication protocol for time-sensitive industrial CPS using ECC and ZKP. IEEE Internet of Things Journal, 10(6), 5125–5138. https://doi.org/10.1109/JIOT.2022.3220004
Ben-Sasson, E., Chiesa, A., Tromer, E., & Virza, M. (2014). Succinct Non-Interactive Zero Knowledge for a von Neumann Architecture. In Proceedings of the 23rd USENIX Security Symposium (pp. 781–796).
Camenisch, J., Groß, T., Leenes, R., & Schneider, G. (2016). Digital Privacy: Theory, Technologies, and Practices. Springer.
ISO/IEC. (2013). ISO/IEC 29115:2013 – Information technology – Security techniques – Entity authentication assurance framework. International Organization for Standardization.
Li, X., Wang, X., Lin, C., & Zhang, Y. (2021). Secure and lightweight authentication protocol for IoT-based CPS. Future Generation Computer Systems, 115, 795–807. https://doi.org/10.1016/j.future.2020.10.036 DOI: https://doi.org/10.1016/j.future.2020.10.036
Liu, A., & Ning, P. (2008). TinyECC: A configurable library for elliptic curve cryptography in wireless sensor networks. In IPSN '08: Proceedings of the 7th International Conference on Information Processing in Sensor Networks (pp. 245–256). DOI: https://doi.org/10.1109/IPSN.2008.47
NIST. (2020). Digital Identity Guidelines: Authentication and Lifecycle Management (Special Publication 800-63B). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-63b DOI: https://doi.org/10.6028/NIST.SP.800-63b
Rajkumar, R., Lee, I., Sha, L., & Stankovic, J. (2010). Cyber-Physical Systems: The Next Computing Revolution. In Proceedings of the 47th Design Automation Conference (DAC) (pp. 731–736). https://doi.org/10.1145/1837274.1837461 DOI: https://doi.org/10.1145/1837274.1837461
Sadeghi, A. R., Wachsmann, C., & Waidner, M. (2015). Security and privacy challenges in industrial internet of things. In Proceedings of the 52nd Annual Design Automation Conference (pp. 1–6). https://doi.org/10.1145/2744769.2747942 DOI: https://doi.org/10.1145/2744769.2747942
Stallings, W. (2017). Cryptography and Network Security: Principles and Practice (7th ed.). Pearson.
Wang, X., Wang, J., & Zhang, M. (2019). Lightweight mutual authentication protocol for smart grid communications based on ECC and hash functions. IEEE Transactions on Smart Grid, 10(4), 4393–4403. https://doi.org/10.1109/TSG.2018.2889420
Zhang, Y., Wu, L., Long, R., Wang, X., & Liu, J. (2020). Secure access control based on identity and attribute-based encryption for CPS. Sensors, 20(4), 1135. https://doi.org/10.3390/s20041135 DOI: https://doi.org/10.3390/s20041135
