<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMES</journal-id>
<journal-id journal-id-type="nlm-ta">CMES</journal-id>
<journal-id journal-id-type="publisher-id">CMES</journal-id>
<journal-title-group>
<journal-title>Computer Modeling in Engineering &#x0026; Sciences</journal-title>
</journal-title-group>
<issn pub-type="epub">1526-1506</issn>
<issn pub-type="ppub">1526-1492</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">62082</article-id>
<article-id pub-id-type="doi">10.32604/cmes.2025.062082</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Software Defined Range-Proof Authentication Mechanism for Untraceable Digital ID</article-title>
<alt-title alt-title-type="left-running-head">Software Defined Range-Proof Authentication Mechanism for Untraceable Digital ID</alt-title>
<alt-title alt-title-type="right-running-head">Software Defined Range-Proof Authentication Mechanism for Untraceable Digital ID</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author">
<name name-style="western"><surname>Jeon</surname><given-names>So-Eun</given-names></name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-2" contrib-type="author">
<name name-style="western"><surname>Lee</surname><given-names>Yeon-Ji</given-names></name><xref ref-type="aff" rid="aff-2">2</xref></contrib>
<contrib id="author-3" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Lee</surname><given-names>Il-Gu</given-names></name><xref ref-type="aff" rid="aff-1">1</xref><xref ref-type="aff" rid="aff-2">2</xref><email>iglee@sungshin.ac.kr</email></contrib>
<aff id="aff-1"><label>1</label><institution>Department of Future Convergence Technology Engineering, Sungshin Women&#x2019;s University</institution>, <addr-line>Seoul, 02844</addr-line>, <country>Republic of Korea</country></aff>
<aff id="aff-2"><label>2</label><institution>Department of Convergence Security Engineering, Sungshin Women&#x2019;s University</institution>, <addr-line>Seoul, 02844</addr-line>, <country>Republic of Korea</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Il-Gu Lee. Email: <email>iglee@sungshin.ac.kr</email></corresp>
</author-notes>
<pub-date date-type="collection" publication-format="electronic">
<year>2025</year>
</pub-date>
<pub-date date-type="pub" publication-format="electronic">
<day>03</day><month>03</month><year>2025</year>
</pub-date>
<volume>142</volume>
<issue>3</issue>
<fpage>3213</fpage>
<lpage>3228</lpage>
<history>
<date date-type="received">
<day>09</day>
<month>12</month>
<year>2024</year>
</date>
<date date-type="accepted">
<day>07</day>
<month>2</month>
<year>2025</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2025 The Authors.</copyright-statement>
<copyright-year>2025</copyright-year>
<copyright-holder>Published by Tech Science Press.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMES_62082.pdf"></self-uri>
<abstract>
<p>The Internet of Things (IoT) is extensively applied across various industrial domains, such as smart homes, factories, and intelligent transportation, becoming integral to daily life. Establishing robust policies for managing and governing IoT devices is imperative. Secure authentication for IoT devices in resource-constrained environments remains challenging due to the limitations of conventional complex protocols. Prior methodologies enhanced mutual authentication through key exchange protocols or complex operations, which are impractical for lightweight devices. To address this, our study introduces the privacy-preserving software-defined range proof (SDRP) model, which achieves secure authentication with low complexity. SDRP minimizes the overhead of confidentiality and authentication processes by utilizing range proof to verify whether the attribute information of a user falls within a specific range. Since authentication is performed using a digital ID sequence generated from indirect personal data, it can avoid the disclosure of actual individual attributes. Experimental results demonstrate that SDRP significantly improves security efficiency, increasing it by an average of 93.02% compared to conventional methods. It mitigates the trade-off between security and efficiency by reducing leakage risk by an average of 98.7%.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Internet of Things</kwd>
<kwd>authentication</kwd>
<kwd>digital ID</kwd>
<kwd>security</kwd>
</kwd-group>
<funding-group>
<award-group id="awg1">
<funding-source>Training Industrial Security Specialist for High-Tech Industry</funding-source>
<award-id>RS-2024-00415520</award-id>
</award-group>
<award-group id="awg2">
<funding-source>ICAN (ICT Challenge and Advanced Network of HRD) program</funding-source>
<funding-source>Institute of Information &#x0026; Communication Technology Planning and Evaluation (IITP)</funding-source>
<award-id>IITP-2022-RS-2022-00156310</award-id>
</award-group>
</funding-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>The Internet of Things (IoT) encompasses wirelessly connected devices that interface with Internet networks [<xref ref-type="bibr" rid="ref-1">1</xref>]. These devices are employed in various domains, including smart grids, homes, cities, and energy management. The proliferation of IoT devices in localized contexts, including campuses, healthcare, and logistics, is projected to increase significantly, rapidly expanding their applications [<xref ref-type="bibr" rid="ref-2">2</xref>&#x2013;<xref ref-type="bibr" rid="ref-6">6</xref>]. Consequently, organizations must establish robust policies for governing and managing these devices within the comprehensive Internet environment. Software-defined technology, crucial for efficient network management and control [<xref ref-type="bibr" rid="ref-7">7</xref>], is hardware-independent and facilitates the rapid establishment of flexible IT infrastructure by defining and controlling resources through software. The concept of &#x201C;software-defined&#x201D; originated with software-defined networking (SDN) and has expanded to include software-defined storage (SDS), software-defined data centers (SDDC), and the broader notion of software-defined everything (SDx) [<xref ref-type="bibr" rid="ref-8">8</xref>]. Notably, smart data exchange is gaining prominence as a core method for IoT management, offering an effective approach to managing and optimizing large-scale data flows between IoT devices. This method significantly enhances the flexibility of network resource management and ensures real-time data communication within IoT networks [<xref ref-type="bibr" rid="ref-9">9</xref>,<xref ref-type="bibr" rid="ref-10">10</xref>]. Recent studies have reported improvements in the safety and efficiency of data exchange in IoT environments through the application of SDx technology [<xref ref-type="bibr" rid="ref-11">11</xref>,<xref ref-type="bibr" rid="ref-12">12</xref>].</p>
<p>Despite diverse and valuable applications of IoT technologies, several critical challenges persist. Securing IoT networks against advanced cyberattacks remains a significant concern [<xref ref-type="bibr" rid="ref-13">13</xref>]. The increasing proliferation of connected IoT devices raises significant issues regarding personal information leakage and privacy breaches [<xref ref-type="bibr" rid="ref-14">14</xref>]. Additionally, data from wearable devices that directly collect individual sensor data are stored in the cloud. However, the general access policy of the ciphertext-policy attribute-based encryption (CP-ABE) system, designed for information protection and efficient control, may compromise privacy and integrity [<xref ref-type="bibr" rid="ref-15">15</xref>]. Hence, robust authentication mechanisms are essential for ensuring trust among networked devices within IoT technology [<xref ref-type="bibr" rid="ref-16">16</xref>].</p>
<p>Extensive research has investigated secure authentication for IoT-enabled devices [<xref ref-type="bibr" rid="ref-17">17</xref>&#x2013;<xref ref-type="bibr" rid="ref-19">19</xref>]. Sureshkumar et al. [<xref ref-type="bibr" rid="ref-17">17</xref>] implemented mutual authentication using standardized Burrows&#x2013;Abadi&#x2013;Needham (BAN) logic, enhancing mutual authentication and key exchange protocols for chaotic map-based medical information systems. However, this method incurs high computational costs and remains vulnerable to asynchronous attacks. Vinoth et al. [<xref ref-type="bibr" rid="ref-18">18</xref>] proposed a secure authentication protocol for IoT devices, employing hash functions, exclusive OR (XOR) operations, and symmetric encryption, enabling trusted users to access sensing devices remotely. While suitable for resource-limited IoT environments, this protocol incurs significant power consumption and presents considerable cryptographic complexity. Conventional protocols, such as Rivest-Shamir-Adleman (RSA)-based public key infrastructure (PKI) and elliptic curve cryptography (ECC), widely used for secure authentication in traditional networks, are often impractical for IoT devices due to high computational overhead and energy consumption. These protocols require substantial processing power and memory, which resource-constrained IoT devices generally lack. Consequently, the implementation of advanced security features, such as robust authentication protocols, strong encryption algorithms, and real-time intrusion detection systems, becomes impractical in many real-world scenarios. These limitations render such devices vulnerable to security breaches [<xref ref-type="bibr" rid="ref-20">20</xref>]. Furthermore, existing IoT security mechanisms are difficult to apply in real-world environments due to their high computational costs and energy requirements, which are critical considerations for IoT devices with limited battery life and low processing capacity [<xref ref-type="bibr" rid="ref-18">18</xref>,<xref ref-type="bibr" rid="ref-19">19</xref>,<xref ref-type="bibr" rid="ref-21">21</xref>,<xref ref-type="bibr" rid="ref-22">22</xref>]. Given the increasing cyberattacks on IoT devices, the development of lightweight and secure authentication techniques is essential [<xref ref-type="bibr" rid="ref-23">23</xref>].</p>
<p>This study introduces the software-defined range proof (SDRP) technique for secure, low-complexity authentication, addressing the trade-off between security and efficiency. SDRP minimizes the overhead of confidentiality and authentication processes by utilizing range proof [<xref ref-type="bibr" rid="ref-24">24</xref>] to verify whether the attribute information of a user falls within a specific range. The authentication (auth) node determines authentication and transmits de-identified random rules to the user node based on the purpose of authentication. The user generates a digital ID sequence and authenticates it using indirect personal information, avoiding the disclosure of actual individual attributes. Consequently, SDRP generates and authenticates a digital ID that prevents personal information inference, ensuring secure and accurate authentication even if the ID is compromised.</p>
<p>The contributions of this study are as follows:
<list list-type="bullet">
<list-item>
<p>SDRP mitigates leakage risk and enhances efficiency by generating an untraceable digital ID using user attribute information in a ruleset of elementary operations.</p></list-item>
<list-item>
<p>We propose a framework to evaluate authentication methods, considering both privacy and efficiency.</p></list-item>
<list-item>
<p>To evaluate the performance of SDRP, we created a practical authentication environment using a user information dataset. The proposed model demonstrated superior performance compared to the conventional zero-knowledge proof model, a standard privacy-preserving authentication method.</p></list-item>
</list></p>
<p>The structure of this study is as follows: <xref ref-type="sec" rid="s2">Section 2</xref> reviews prior research, <xref ref-type="sec" rid="s3">Section 3</xref> introduces SDRP, <xref ref-type="sec" rid="s4">Section 4</xref> evaluates conventional models and SDRP, and <xref ref-type="sec" rid="s5">Section 5</xref> concludes the study.</p>
</sec>
<sec id="s2">
<label>2</label>
<title>Related Work</title>
<p>This section reviews prior research on conventional authentication methods, categorizing them into privacy-focused and lightweight techniques. <xref ref-type="table" rid="table-1">Table 1</xref> offers a comparative analysis of these methods.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>Previous studies of conventional authentication methods</title>
</caption>
<table>
<colgroup>
<col align="center" width="28mm"/>
<col align="center" width="20mm"/>
<col align="center" width="52mm"/>
<col align="center" width="50mm"/>
</colgroup>
<thead>
<tr>
<th>Features</th>
<th>Previous studies</th>
<th>Method</th>
<th>Limitation</th>
</tr>
</thead>
<tbody>
<tr>
<td>Privacy-preserving authentication</td>
<td>Shah et al. [<xref ref-type="bibr" rid="ref-24">24</xref>]</td>
<td><list list-type="bullet">
<list-item>
<p>Proposing a multi-key-based mutual authentication mechanism</p></list-item>
<list-item>
<p>The password set for secure storage is updated after each successful communication session</p></list-item>
</list></td>
<td><list list-type="bullet">
<list-item>
<p>Frequent updates and sharing of key values introduce limitations, increasing complexity and latency</p></list-item>
</list></td>
</tr>
<tr>
<td>Lightweight authentication</td>
<td>Santos et al. [<xref ref-type="bibr" rid="ref-21">21</xref>]</td>
<td><list list-type="bullet">
<list-item>
<p>Proposing an IoT-exclusive FIdM protocol that substitutes for complex technologies with streamlined, user-friendly alternatives within conventional FIdM</p></list-item>
</list></td>
<td><list list-type="bullet">
<list-item>
<p>Insufficient experimentation compromises the reliability of the results</p></list-item>
</list></td>
</tr>
<tr>
<td/>
<td>Li et al. [<xref ref-type="bibr" rid="ref-20">20</xref>]</td>
<td><list list-type="bullet">
<list-item>
<p>A novel lightweight authentication protocol, designed to satisfy privacy requirements using hash functions and XOR operations, is introduced</p></list-item>
</list></td>
<td><list list-type="bullet">
<list-item>
<p>Previous studies lacked performance comparison, thereby impeding the evaluation of computational cost and performance enhancement</p></list-item>
</list></td>
</tr>
<tr>
<td/>
<td>Rana et al. [<xref ref-type="bibr" rid="ref-25">25</xref>]</td>
<td><list list-type="bullet">
<list-item>
<p>Optimized computational processes by implementing lightweight XOR operations alongside symmetric key-based encryption</p></list-item>
<list-item>
<p>Optimized network bandwidth usage by developing an authentication mechanism that requires only a single request-response exchange</p></list-item>
<list-item>
<p>Engineered to store only essential security parameters, thereby minimizing the data size retained on the smart card.</p></list-item>
</list></td>
<td><list list-type="bullet">
<list-item>
<p>Substantial computational power required presents challenges for operation on IoT devices with severely constrained resources</p></list-item>
</list></td>
</tr>
<tr>
<td>Privacy-preserving lightweight authentication</td>
<td>Gaba et al. [<xref ref-type="bibr" rid="ref-26">26</xref>]</td>
<td><list list-type="bullet">
<list-item>
<p>A novel lightweight authentication protocol, designed to satisfy privacy requirements using hash functions and XOR operations, is introduced</p></list-item>
</list></td>
<td><list list-type="bullet">
<list-item>
<p>Determining the precise computational cost is challenging, as performance assessments have primarily relied on mathematical analysis</p></list-item>
</list></td>
</tr>
<tr>
<td/>
<td>Chistousov et al. [<xref ref-type="bibr" rid="ref-27">27</xref>]</td>
<td><list list-type="bullet">
<list-item>
<p>Implement zero-knowledge proof with session keys to streamline authentication processes</p></list-item>
<list-item>
<p>In a specific context, it can enhance authentication speed by lowering confidentiality levels</p></list-item>
</list></td>
<td><list list-type="bullet">
<list-item>
<p>A trade-off exists: increasing speed necessitates reducing confidentiality levels, while the strength of the authentication protocol relies on the computational cost of solving the Diffie-Hellman problem.</p></list-item>
</list></td>
</tr>
</tbody>
</table>
</table-wrap>
<p>Shah et al. [<xref ref-type="bibr" rid="ref-24">24</xref>] analyzed the security vulnerabilities of password-based authentication methods in IoT systems, focusing on side-channel and dictionary attacks. They proposed a multikey-based mutual authentication mechanism to enhance security between IoT devices and servers. This mechanism securely manages secret keys within an encrypted vault, ensuring that servers and IoT devices share equal-sized keys. A significant advantage of the proposed method is the dynamic updating of securely stored password content with each successful communication session, thereby eliminating reliance on a single key value. However, they did not address the increased latency due to frequent key-value updates and sharing.</p>
<p>Conventional authentication methods are unsuitable for resource-constrained IoT environments, prompting the exploration of lightweight alternatives. Santos et al. [<xref ref-type="bibr" rid="ref-21">21</xref>] identified the shortcomings of traditional identity management (IdM) for lightweight IoT devices and introduced a federated identity management (FIdM) protocol tailored to IoT specifications. Although this protocol simplifies conventional FIdM, it lacks performance comparisons with existing FIdM technologies, leaving its relative efficacy undetermined.</p>
<p>Li et al. [<xref ref-type="bibr" rid="ref-20">20</xref>] addressed security challenges in data transmission within vehicular <italic>ad hoc</italic> networks (VANET) by identifying inefficiencies in conventional authentication methods characterized by excessive computation and security flaws. They introduced a lightweight authentication protocol utilizing hash functions and XOR operations to enhance privacy protection and secure authentication. While their approach preserves vehicle information anonymity and ensures secure authentication, the lack of a comparative analysis with existing research leaves the claimed improvements in computational cost and performance unverified.</p>
<p>Rana et al. [<xref ref-type="bibr" rid="ref-25">25</xref>] proposed a lightweight authentication mechanism tailored for IoT environments. This study introduces a technique leveraging a hash function and symmetric encryption to achieve mutual authentication between users and servers. The implementation of symmetric encryption and a non-collision hash function effectively reduces computational overhead, minimizes communication instances, and decreases the data storage requirements on smart cards. Nevertheless, this mechanism faces challenges with IoT devices with extremely severe resource constraints attributed to relatively high computational demands.</p>
<p>Gaba et al. [<xref ref-type="bibr" rid="ref-26">26</xref>] identified significant security vulnerabilities in wearable IoT devices, which can be exploited to alter medical reports, thereby leading to inaccurate diagnoses and treatments. They proposed various cybersecurity solutions, such as fog, edge, cloud, blockchain, password, biometrics, hash, and elliptic curve cryptography. However, these solutions are prone to cyberattacks and entail high computational and communication costs, rendering them unsuitable for IoT environments. Consequently, the authors introduced a zero-knowledge proof (ZKP)-based authenticated key agreement protocol for Internet of Healthcare Applications (IoHA). This protocol prevents unauthorized access and ensures secure authentication while minimizing computational and communication overhead. Despite ensuring confidentiality, integrity, and availability, its performance evaluation relies solely on mathematical proofs, complicating cost assessment.</p>
<p>Chistousov et al. [<xref ref-type="bibr" rid="ref-27">27</xref>] demonstrated that while encryption systems ensure robust confidentiality for vehicle authentication in VANETs, they require extensive key management infrastructure. Moreover, the compromise of a cryptographic key can significantly weaken the protection of transmitted data within VANETs. To mitigate this issue, a ZKP protocol was proposed, offering strong confidentiality without relying on encryption. This method leverages session-key-based ZKP to streamline the authentication process, allowing for adjustable confidentiality levels to enhance authentication speed. Furthermore, they increased the complexity of ZKPs, proposing a more secure authentication method. Nonetheless, the inherent trade-off remains unresolved: reducing confidentiality to improve authentication speed while considering the computational overhead of Diffie&#x2013;Hellman operations, which impacts both efficiency and security.</p>
<p>Numerous studies aimed at enhancing conventional authentication technologies have often overlooked key factors such as latency, computational cost, and the balance between security and performance metrics. Furthermore, conventional security research frequently relies on complex mathematical models and algorithms, thereby increasing computational overhead. Conversely, studies prioritizing authentication speed have emphasized efficiency at the expense of security, resulting in a trade-off. Despite considering both evaluation metrics, previous research has often compromised confidentiality for efficiency gains or accepted higher computational costs to maintain privacy. Consequently, the trade-off between efficiency and security remains unresolved.</p>
<p>In this study, we present novel metrics for assessing privacy and efficiency in IoT environments, addressing the limitations of prior research. We also introduce a lightweight authentication method that balances these metrics, ensuring high reliability and efficiency.</p>
</sec>
<sec id="s3">
<label>3</label>
<title>Software Defined Range Proof (SDRP)</title>
<p>This section presents SDRP, a methodology for generating digital ID sequences using a ruleset to ensure secure and efficient authentication.</p>
<sec id="s3_1">
<label>3.1</label>
<title>Anonymous Credential</title>
<p>Self-sovereign identity (SSI) introduces a novel identity management systems (IMS) paradigm, offering a privacy-preserving mechanism for identity verification [<xref ref-type="bibr" rid="ref-28">28</xref>]. SSI adheres to ten fundamental principles: existence, control, access, transparency, persistence, portability, interoperability, consent, minimization, and protection [<xref ref-type="bibr" rid="ref-29">29</xref>]. Existence denotes the independent status of users, and control refers to their ability to manage their identity. Access enables data retrieval, transparency ensures algorithmic and infrastructural clarity, and persistence guarantees long-term ID maintenance. Portability supports the transfer of identity-related information, while interoperability ensures broad usability. Consent signifies user agreement for identity use, minimization reduces data disclosure, and protection safeguards users&#x2019; rights.</p>
<p>Conventional authentication methods frequently employ sensitive personal identifiers encapsulated in encrypted tokens, which are vulnerable to information leakage if intercepted during transmission. Consequently, research on anonymous credential authentication&#x2014;which verifies user eligibility without disclosing personal identities&#x2014;has become increasingly prominent. Recent SSI techniques utilize anonymous credentials to protect personal information. These credentials enable users to authenticate themselves without unnecessary identity disclosure [<xref ref-type="bibr" rid="ref-28">28</xref>]. Generating anonymous credentials involves inputting the public key, message, proposition information, credential, and attribute proof signing key of the system. The attributes linked to the credential are identified based on the proposition details, and appropriate proof values are generated for each attribute. Upon receiving the anonymous credential, the server separates the attribute information according to the proposition details and conducts primary verification. Finally, the server authenticates the anonymous credentials by verifying the information of each attribute separately.</p>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>Operation Method of SDRP</title>
<p><xref ref-type="fig" rid="fig-1">Fig. 1</xref> illustrates the operation of SDRP through a flowchart. SDRP interacts with the authorization node (auth node) for identity verification, evaluates authentication permissions, and requests authentication from the user node. Initially, SDRP establishes rules to generate a digital ID that conceals personal information. Within this framework, a rule comprising all de-identification or specific identifiable operations related to the required attribute is stochastically generated and transmitted to the user node based on the authentication purpose. Certain de-identification rules permit the specification of attributes verifiable as sequences, such as age, gender, and affiliation. Upon receiving the rule, the user node computes a digital ID from its personal information and forwards it to the auth node. Subsequently, the auth node verifies whether the user falls within the authorized group range using the received digital ID. If the user node has an invalid ID outside the specified group range, the authentication process is flagged as abnormal, leading to authentication failure. Extending the auth request interval when the user node re-initiates authentication can prevent an infinite authentication loop caused by an abnormal node. Conversely, duplicate users are verified and authorized for authentication if the user node is identified as a legacy ID within the group range under verification. The duplicate user undergoes re-authentication considering the potential derivation of the same digital ID, despite the application of different rulesets. Unlike encrypting and transmitting personal identification information over the network, SDRP generates indirect personal information by performing operations on the attributes&#x2019; characteristics in the received rule set to derive a digital ID. Consequently, even if an attacker intercepts a digital ID through a side-channel attack, identifying an individual remains impossible, thus mitigating privacy infringement risks. Furthermore, SDRP achieves lightweight performance by employing simple arithmetic operations for digital ID generation.</p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>Flowchart for SDRP operation method</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_62082-fig-1.tif"/>
</fig>
<p><xref ref-type="fig" rid="fig-2">Fig. 2</xref> presents the system architecture of the auth and user nodes.</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>System architecture of auth node and user node</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_62082-fig-2.tif"/>
</fig>
<p>In this architecture, the auth node employs the ruleset generator to create rules that can be fully or partially identifiable, depending on specific authentication requirements. A fully identifiable rule is applied when attributes requiring authentication contain personally sensitive information that needs protection and belong to rule types where sequences undergo specific transformations. Conversely, partially identifiable rules are used for low-sensitivity attributes, posing no significant disclosure issues. This rule permits attributes such as age and gender to be directly identified through a digital ID sequence without additional operations. <xref ref-type="fig" rid="fig-3">Fig. 3</xref> provides an example of the SDRP digital ID generation process.</p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>Example of SDRP&#x2019;s digital ID generation process</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_62082-fig-3.tif"/>
</fig>
<p>As illustrated in <xref ref-type="fig" rid="fig-3">Fig. 3</xref>, rules are generated based on the required attributes to formulate an operation-based ruleset that ensures the anonymity of personal information. For instance, if the attribute is a string, a ruleset such as &#x201C;Replace the spelling order of &#x2018;name&#x2019; with numbers, then offset it at the sequence start&#x201D; can function by substituting the alphabetical order with numbers. After the ruleset is created, it is transmitted to the user node via the sender. The user node applies the personal information stored in the personal information database (DB) to the ruleset within the digital ID generator to produce a digital ID, which is then transmitted to the auth node. The communication protocol between the auth node and the user node is depicted in <xref ref-type="fig" rid="fig-4">Fig. 4</xref>.</p>
<fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>Communication format between auth node and user node</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_62082-fig-4.tif"/>
</fig>
<p><xref ref-type="fig" rid="fig-4">Fig. 4</xref> illustrates that the auth node manages authentication performance by incorporating the ruleset field into the communication packet format. Concurrently, the user node initiates authentication using the digital ID field. Upon receiving the digital ID from the user node, the discriminator assesses its validity and checks for duplicate IDs in the authentication history DB before making a decision.</p>
<p>Algorithm 1 outlines the pseudocode for SDRP encompassing rule generation, ruleset transmission to the user node, digital ID creation and return to the auth node, legitimacy assessment of the user node, and verification of duplicate digital IDs in the DB. In Step 1, fully or partially unidentifiable rules are generated and transmitted to the user node. In Step 2, upon receiving the ruleset, the user node applies a personal attribute to generate a digital ID, which is then returned to the auth node. In Step 3, the auth node calculates the ID condition to verify the authenticity of the user node. The calculated ID is compared with the digital ID received from the user node to determine authentication eligibility. In Step 4, if the ID is authorized for authentication, it undergoes a duplication check by comparing it with the digital ID stored in the authenticated history DB.</p>
<fig id="fig-9">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_62082-fig-9.tif"/>
</fig>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Performance Evaluation</title>
<sec id="s4_1">
<label>4.1</label>
<title>Evaluation Environment</title>
<p>This section describes the experimental setup used to evaluate the performance of SDRP. The evaluation framework, depicted in <xref ref-type="fig" rid="fig-5">Fig. 5</xref>, was implemented to compare and assess the performances of conventional and SDRP-based authentication methods.</p>
<fig id="fig-5">
<label>Figure 5</label>
<caption>
<title>Evaluation framework of digital ID-based authentication techniques</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_62082-fig-5.tif"/>
</fig>
<p>The auth node of SDRP generates a ruleset for the required attributes and transmits it to the user node. The user node then computes the digital ID based on this ruleset, which the auth node subsequently uses to determine authentication permission. In this experiment, the parameter &#x03B1;, representing the number of required attributes, was varied to evaluate leakage risk, efficiency, and computational cost.</p>
<p>User data were obtained from the company&#x2013;employee dataset [<xref ref-type="bibr" rid="ref-30">30</xref>], which includes information from 5000 users. <xref ref-type="table" rid="table-2">Table 2</xref> details the features of the data utilized in this experiment.</p>
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>Configuration of user information datasets</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Features</th>
<th>Type</th>
<th>Contents</th>
</tr>
</thead>
<tbody>
<tr>
<td>ID</td>
<td>int64</td>
<td>0&#x007E;4999</td>
</tr>
<tr>
<td>Company</td>
<td>str</td>
<td>Glasses, Cheerper, Pear</td>
</tr>
<tr>
<td>Department</td>
<td>str</td>
<td>Bigdata, AI, Support, Design, Search Engine, Sales</td>
</tr>
<tr>
<td>Age</td>
<td>int64</td>
<td>30&#x007E;49</td>
</tr>
<tr>
<td>Gender</td>
<td>str</td>
<td>Female, male</td>
</tr>
<tr>
<td>SocialNumber</td>
<td>int64</td>
<td>6-digit number</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>Personal information attributes of the user node, including ID, company, department, age, gender, and social number, were extracted from the total features. Only integer (int) and string (str) data types were employed. This dataset served as authentication data to simulate the authentication environment.</p>
<p>In this study, we benchmarked the zero-knowledge proof model (ZKPM) [<xref ref-type="bibr" rid="ref-31">31</xref>] and the identifiable attribute model (IAM) [<xref ref-type="bibr" rid="ref-27">27</xref>] to evaluate the performance of SDRP. ZKPM model employs an AES-based zero-knowledge proof technique for range proof. Here, the user node calculates <inline-formula id="ieqn-6"><mml:math id="mml-ieqn-6"><mml:mi>y</mml:mi><mml:mo>=</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:mi>m</mml:mi><mml:mi>o</mml:mi><mml:mi>d</mml:mi><mml:mi>p</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> to transmit <italic>y</italic> as an unidentifiable secret value <italic>x</italic> to the auth node. Subsequently, the user node generates a random number <italic>r</italic> and calculates <inline-formula id="ieqn-7"><mml:math id="mml-ieqn-7"><mml:mi>C</mml:mi><mml:mo>=</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:mi>r</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">(</mml:mo><mml:mi>m</mml:mi><mml:mi>o</mml:mi><mml:mi>d</mml:mi><mml:mi>p</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> to transmit <italic>C</italic> to the auth node. Upon receiving this, the auth node iterates the process <italic>N</italic> times, requesting either <italic>r</italic> or <inline-formula id="ieqn-8"><mml:math id="mml-ieqn-8"><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>+</mml:mo><mml:mi>r</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>m</mml:mi><mml:mi>o</mml:mi><mml:mi>d</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>p</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo>)</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> from the user node to estimate <italic>x</italic> and perform authentication. Parameters were set with <italic>g</italic> &#x003D; 2, and <italic>N</italic> &#x003D; 3. The random value <italic>r</italic> was chosen between 1 and 20, while <italic>p</italic> was selected from prime numbers between 100 and 200. User attributes from the company-employee dataset [<xref ref-type="bibr" rid="ref-30">30</xref>] served as the secret value <inline-formula id="ieqn-9"><mml:math id="mml-ieqn-9"><mml:mi>x</mml:mi></mml:math></inline-formula>. Conversely, IAM [<xref ref-type="bibr" rid="ref-27">27</xref>] leverages lightweight zero-knowledge authentication protocols (ZKAP) with a session key for encrypting communication sessions, thereby reducing the number of authentication steps and ensuring confidentiality. IAM is designed for lightweight performance by dynamically adjusting the level of confidentiality. In this study, we compared the IAM environment at the lowest level of confidentiality.</p>
<p>To evaluate the performance of SDRP, we employed computational cost, leakage risk, and security efficiency as metrics. Computational complexity was assessed using Big-O notation.</p>
<p>Leakage risk denotes the potential for ID leakage by an attacker when utilizing SDRP, calculated as described in <xref ref-type="disp-formula" rid="eqn-1">Eq. (1)</xref>.
<disp-formula id="eqn-1"><label>(1)</label><mml:math id="mml-eqn-1" display="block"><mml:mi>L</mml:mi><mml:mi>e</mml:mi><mml:mi>a</mml:mi><mml:mi>k</mml:mi><mml:mi>a</mml:mi><mml:mi>g</mml:mi><mml:mi>e</mml:mi><mml:mspace width="thinmathspace" /><mml:mi>r</mml:mi><mml:mi>i</mml:mi><mml:mi>s</mml:mi><mml:mi>k</mml:mi><mml:mo>=</mml:mo><mml:mfrac><mml:msub><mml:mi>I</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mi>R</mml:mi><mml:msub><mml:mi>I</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>O</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>N</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:mfrac></mml:math></disp-formula>where <inline-formula id="ieqn-10"><mml:math id="mml-ieqn-10"><mml:mi>R</mml:mi><mml:msub><mml:mi>I</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> denotes the request interval at time <italic>t</italic>, <inline-formula id="ieqn-11"><mml:math id="mml-ieqn-11"><mml:msub><mml:mi>O</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>N</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> represents the computational cost of the ruleset at time <italic>t</italic>, and <inline-formula id="ieqn-12"><mml:math id="mml-ieqn-12"><mml:msub><mml:mi>I</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> indicates the importance of the required attributes at time <italic>t</italic>. In this experiment, upon authentication failure, <inline-formula id="ieqn-13"><mml:math id="mml-ieqn-13"><mml:mi>R</mml:mi><mml:msub><mml:mi>I</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> increased by 10 s. <inline-formula id="ieqn-14"><mml:math id="mml-ieqn-14"><mml:msub><mml:mi>O</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>N</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> is the computation cost based on Big-O notation, and <inline-formula id="ieqn-15"><mml:math id="mml-ieqn-15"><mml:msub><mml:mi>I</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> is determined by assigning importance to each attribute. Given that Social Number corresponds to sensitive personal information, its importance was set to 5, age and gender were set to 3, and company and department were set to 1 [<xref ref-type="bibr" rid="ref-32">32</xref>].</p>
<p>Security efficiency was calculated using <xref ref-type="disp-formula" rid="eqn-2">Eq. (2)</xref> as a metric for evaluating the security efficiency of the authentication model.
<disp-formula id="eqn-2"><label>(2)</label><mml:math id="mml-eqn-2" display="block"><mml:mi>S</mml:mi><mml:mi>e</mml:mi><mml:mi>c</mml:mi><mml:mi>u</mml:mi><mml:mi>r</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>y</mml:mi><mml:mtext>&#x00A0;</mml:mtext><mml:mi>E</mml:mi><mml:mi>f</mml:mi><mml:mi>f</mml:mi><mml:mi>i</mml:mi><mml:mi>c</mml:mi><mml:mi>i</mml:mi><mml:mi>e</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mi>y</mml:mi><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mi>i</mml:mi><mml:mi>v</mml:mi><mml:mi>a</mml:mi><mml:mi>c</mml:mi><mml:mi>y</mml:mi><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:mi>s</mml:mi><mml:mi>e</mml:mi><mml:mi>r</mml:mi><mml:mi>v</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>g</mml:mi><mml:mspace width="thinmathspace" /><mml:mi>c</mml:mi><mml:mi>a</mml:mi><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>i</mml:mi><mml:mi>l</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>y</mml:mi></mml:mrow><mml:mrow><mml:msub><mml:mi>O</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>N</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:mfrac></mml:math></disp-formula></p>
<p>Security efficiency is inversely proportional to the latency and computational cost of authentication, and directly proportional to privacy-preserving capability, quantified as the proportion of preserved privacy, as calculated by <xref ref-type="disp-formula" rid="eqn-3">Eq. (3)</xref>.
<disp-formula id="eqn-3"><label>(3)</label><mml:math id="mml-eqn-3" display="block"><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mi>i</mml:mi><mml:mi>v</mml:mi><mml:mi>a</mml:mi><mml:mi>c</mml:mi><mml:mi>y</mml:mi><mml:mtext>&#x00A0;</mml:mtext><mml:mi>p</mml:mi><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:mi>s</mml:mi><mml:mi>e</mml:mi><mml:mi>r</mml:mi><mml:mi>v</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>g</mml:mi><mml:mtext>&#x00A0;</mml:mtext><mml:mi>c</mml:mi><mml:mi>a</mml:mi><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>i</mml:mi><mml:mi>l</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>y</mml:mi><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mrow><mml:mi>L</mml:mi><mml:mi>e</mml:mi><mml:mi>a</mml:mi><mml:mi>k</mml:mi><mml:mi>a</mml:mi><mml:mi>g</mml:mi><mml:mi>e</mml:mi><mml:mtext>&#x00A0;</mml:mtext><mml:mi>r</mml:mi><mml:mi>i</mml:mi><mml:mi>s</mml:mi><mml:mi>k</mml:mi></mml:mrow></mml:mfrac><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mi>R</mml:mi><mml:msub><mml:mi>I</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>O</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>N</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow><mml:msub><mml:mi>I</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:mfrac></mml:math></disp-formula></p>
<p>SDRP presents an efficient authentication mechanism designed for lightweight devices to enhance security and minimize data leakage risk&#x2014;a key security metric. The performance across three evaluation metrics was analyzed by progressively increasing the number of required attributes. To ensure experimental reliability, the average results from 10,000 simulation repetitions were calculated.</p>
</sec>
<sec id="s4_2">
<label>4.2</label>
<title>Evaluation Results and Analysis</title>
<p>This section analyzes the performance of SDRP relative to conventional models, ZKPM and IAM, concerning computational cost, leakage risk, and security efficiency. <xref ref-type="fig" rid="fig-6">Fig. 6</xref> illustrates the comparative leakage risk between SDRP and conventional models.</p>
<fig id="fig-6">
<label>Figure 6</label>
<caption>
<title>Leakage risk of SDRP by the number of required attributes</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_62082-fig-6.tif"/>
</fig>
<p>As the number of required attributes increased, the probability of incorporating critical attributes also rose. Consequently, the risk of information leakage to potential attackers escalated, with the highest risk observed in the IAM model, followed by SDRP and ZKPM. The IAM model, which transmits and receives personal information at the lowest confidentiality level, exhibited the highest privacy leakage risk. In contrast, SDRP, which uses digital IDs containing only indirect personal information characteristics, and ZKPM, which relies on complex knowledge proof equations, demonstrated a maximum privacy leakage risk that was <inline-formula id="ieqn-16"><mml:math id="mml-ieqn-16"><mml:msup><mml:mn>10</mml:mn><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula> times lower than that of IAM.</p>
<p><xref ref-type="fig" rid="fig-7">Fig. 7</xref> illustrates the comparative results of SDRP and the conventional model regarding computational cost.</p>
<fig id="fig-7">
<label>Figure 7</label>
<caption>
<title>Computational cost of SDRP by the number of required attributes</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_62082-fig-7.tif"/>
</fig>
<p>As the number of required attributes increased, the computational burden for de-identification escalated, consistently increasing overall computational costs. Among the methods, ZKPM, a zero-knowledge proof-based technique, exhibited inefficiencies due to the repeated exchange of complex operational formulas during secret-value de-identification. Conversely, SDRP, which computes a simple ruleset, reduced computational cost by up to <inline-formula id="ieqn-17"><mml:math id="mml-ieqn-17"><mml:mn>10</mml:mn></mml:math></inline-formula> times compared to conventional ZKPM. Additionally, the IAM model, which bypasses de-identification processing, demonstrated optimal efficiency by avoiding separate operations. However, the most critical evaluation index for safe authentication, leakage risk, revealed a significant limitation: confidentiality cannot be guaranteed, as it presented the most inefficient results.</p>
<p><xref ref-type="fig" rid="fig-8">Fig. 8</xref> illustrates the comparative security efficiency of SDRP <italic>vs</italic>. the conventional model.</p>
<fig id="fig-8">
<label>Figure 8</label>
<caption>
<title>Security efficiency of SDRP by the number of required attributes</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_62082-fig-8.tif"/>
</fig>
<p>Overall, an increase in the number of required attributes correspondingly elevated the computational cost of authentication, diminishing security efficiency. The SDRP model demonstrated up to five times higher security efficiency compared to conventional models. This enhanced efficiency is due to the superior leakage risk performance of SDRP relative to IAM, coupled with its lower computational cost compared to ZKPM. Conversely, while ZKPM achieved optimal leakage risk outcomes, its overall security performance was hindered by significantly higher computational costs.</p>
<p>In summarizing the experimental findings, this study assessed IAM, ZKPM, and the proposed SDRP method across three metrics: leakage risk, computational cost, and security efficiency. For leakage risk, the ranking was ZKPM, SDRP, and IAM, suggesting that more complex techniques offer stronger security. The evaluation of computational cost revealed the ranking as IAM, SDRP, and ZKPM, indicating a trade-off between security and efficiency. Therefore, security efficiency was the final metric, identifying the model that best balanced security and efficiency. In this metric, SDRP, ZKPM, and IAM were ranked accordingly. Since security efficiency is inversely proportional to authentication latency and computational cost while directly proportional to privacy preservation performance, it can be concluded that SDRP achieves the optimal balance between security and efficiency among the three models.</p>
</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>Conclusion</title>
<p>Various technologies have been developed to protect IoT networks from increasing cyber threats targeting IoT devices. However, due to the resource constraints of these devices, implementing secure and sophisticated algorithms becomes challenging. Consequently, secure and lightweight authentication methods are essential to balance complexity and security in conventional research. This study proposed the SDRP model, which securely generates a digital ID sequence based on a ruleset without directly transmitting user attribute information over the network. In SDRP, the auth node generates random rulesets that are either fully or partially de-identified. These rulesets are then transmitted to the user node, which generates a digital ID sequence for authentication using indirect personal information rather than actual user attributes. Therefore, even if advanced attacks such as side-channel attacks or timing attacks occur, the attacker cannot identify personal information solely based on the digital ID transmitted over the network. Furthermore, by minimizing the computational load and the number of communication exchanges, the proposed method achieves lightweight authentication, making it efficient regarding energy consumption&#x2014;a critical factor for IoT devices. The experimental results indicate that SDRP enhances security efficiency by an average of 93.02% over conventional methods and reduces the risk of information leakage by an average of 98.7%. This balance between security and efficiency demonstrates the efficacy of SDRP. The primary limitation of this study is its focus on a simulated authentication environment. Future research will address this by incorporating advanced attacker nodes in realistic settings and optimizing the request interval of the SDRP to establish an optimal defense environment and validate its performance. Additionally, we will model network environments with varying traffic loads and analyze energy consumption, a critical metric in IoT environments, to demonstrate the scalability and reliability of the SDRP.</p>
</sec>
</body>
<back>
<ack>
<p>The authors thank the Korea Institute for Advancement of Technology (KIAT) under the Korean Government&#x2019;s Ministry of Trade, Industry, and Energy (MOTIE) grant and from the Ministry of Science and ICT (MSIT) through the ICAN (ICT Challenge and Advanced Network of HRD) program managed by the Institute of Information &#x0026; Communication Technology Planning and Evaluation (IITP).</p>
</ack>
<sec>
<title>Funding Statement</title>
<p>This study received partial funding from the Korea Institute for Advancement of Technology (KIAT) through a grant provided by the Korean Government Ministry of Trade, Industry, and Energy (MOTIE) (RS-2024-00415520, Training Industrial Security Specialist for High-Tech Industry). Additional support was received from the Ministry of Science and ICT (MSIT) under the ICAN (ICT Challenge and Advanced Network of HRD) program (No. IITP-2022-RS-2022-00156310) overseen by the Institute of Information &#x0026; Communication Technology Planning and Evaluation (IITP).</p>
</sec>
<sec>
<title>Author Contributions</title>
<p>The authors have contributed to the paper as follows: So-Eun Jeon was responsible for conceptualization, methodology, software, validation, visualization, and writing&#x2014;original draft. Yeon-Ji Lee contributed to resources, validation, writing&#x2014;review and editing. Il-Gu Lee contributed to conceptualization, validation, writing&#x2014;review and editing, supervision, project administration, and funding acquisition. All authors reviewed the results and approved the final version of the manuscript.</p>
</sec>
<sec sec-type="data-availability">
<title>Availability of Data and Materials</title>
<p>The data that support the findings of this study are available from the first and corresponding authors upon reasonable request.</p>
</sec>
<sec>
<title>Ethics Approval</title>
<p>Not applicable.</p>
</sec>
<sec sec-type="COI-statement">
<title>Conflicts of Interest</title>
<p>The authors declare no conflicts of interest to report regarding the present study.</p>
</sec>
<glossary content-type="abbreviations" id="glossary-1">
<title>Abbreviations</title>
<def-list>
<def-item>
<term>IoT</term>
<def>
<p>Internet of Things</p>
</def>
</def-item>
<def-item>
<term>SDN</term>
<def>
<p>Software-defined networking</p>
</def>
</def-item>
<def-item>
<term>SDS</term>
<def>
<p>Software-defined storage</p>
</def>
</def-item>
<def-item>
<term>SDDC</term>
<def>
<p>Software-defined data centers</p>
</def>
</def-item>
<def-item>
<term>SDx</term>
<def>
<p>Software-defined everything</p>
</def>
</def-item>
<def-item>
<term>CP-ABE</term>
<def>
<p>Ciphertext-policy attribute-based encryption</p>
</def>
</def-item>
<def-item>
<term>BAN</term>
<def>
<p>Burrows&#x2013;Abadi&#x2013;Needham</p>
</def>
</def-item>
<def-item>
<term>XOR</term>
<def>
<p>Exclusive OR</p>
</def>
</def-item>
<def-item>
<term>SDRP</term>
<def>
<p>Software-defined range proof</p>
</def>
</def-item>
<def-item>
<term>VANET</term>
<def>
<p>Vehicular <italic>ad hoc</italic> networks</p>
</def>
</def-item>
<def-item>
<term>IdM</term>
<def>
<p>Identity management</p>
</def>
</def-item>
<def-item>
<term>FIdM</term>
<def>
<p>Federated identity management</p>
</def>
</def-item>
<def-item>
<term>ZKP</term>
<def>
<p>Zero-knowledge proof</p>
</def>
</def-item>
<def-item>
<term>IoHA</term>
<def>
<p>Internet of Healthcare Applications</p>
</def>
</def-item>
<def-item>
<term>SSI</term>
<def>
<p>Self-sovereign identity</p>
</def>
</def-item>
<def-item>
<term>IMS</term>
<def>
<p>Identity management systems</p>
</def>
</def-item>
<def-item>
<term>DB</term>
<def>
<p>Database</p>
</def>
</def-item>
<def-item>
<term>ZKPM</term>
<def>
<p>Zero-knowledge proof model</p>
</def>
</def-item>
<def-item>
<term>IAM</term>
<def>
<p>Identifiable attribute model</p>
</def>
</def-item>
<def-item>
<term>ZKAP</term>
<def>
<p>Zero-knowledge authentication protocols</p>
</def>
</def-item>
</def-list>
</glossary>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Quy</surname> <given-names>VK</given-names></string-name>, <string-name><surname>Hau</surname> <given-names>NV</given-names></string-name>, <string-name><surname>Anh</surname> <given-names>DV</given-names></string-name>, <string-name><surname>Quy</surname> <given-names>NM</given-names></string-name>, <string-name><surname>Ban</surname> <given-names>NT</given-names></string-name>, <string-name><surname>Lanza</surname> <given-names>S</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>IoT-enabled smart agriculture: architecture, applications, and challenges</article-title>. <source>Appl Sci</source>. <year>2022</year>;<volume>12</volume>(<issue>7</issue>):<fpage>3396</fpage>. doi:<pub-id pub-id-type="doi">10.3390/app12073396</pub-id>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Yun</surname> <given-names>SW</given-names></string-name>, <string-name><surname>Park</surname> <given-names>NE</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>IG</given-names></string-name></person-group>. <article-title>Wake-up security: effective security improvement mechanism for low power internet of things</article-title>. <source>Intell Autom Soft Comput</source>. <year>2023</year>;<volume>37</volume>(<issue>3</issue>):<fpage>2897</fpage>&#x2013;<lpage>917</lpage>. doi:<pub-id pub-id-type="doi">10.32604/iasc.2023.039940</pub-id>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Chamoun</surname> <given-names>MM</given-names></string-name>, <string-name><surname>Fadlallah</surname> <given-names>A</given-names></string-name>, <string-name><surname>Serhrouchni</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Taxonomy of authentication techniques in internet of things (IoT)</article-title>. In: <conf-name>15th Student Conference on Research and Development (SCOReD)</conf-name>; <year>2017</year>; <publisher-loc>Wilayah Persekutuan Putrajaya</publisher-loc>: <publisher-name>IEEE Publications</publisher-name>. p. <fpage>67</fpage>&#x2013;<lpage>71</lpage>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Sutjarittham</surname> <given-names>T</given-names></string-name>, <string-name><surname>Habibi</surname> <given-names>HH</given-names></string-name>, <string-name><surname>Kanhere</surname> <given-names>SS</given-names></string-name>, <string-name><surname>Sivaraman</surname> <given-names>V</given-names></string-name></person-group>. <article-title>Experiences with IoT and AI in a smart campus for optimizing classroom usage</article-title>. <source>IEEE Internet Things J</source>. <year>2019</year>;<volume>6</volume>(<issue>5</issue>):<fpage>7595</fpage>&#x2013;<lpage>607</lpage>. doi:<pub-id pub-id-type="doi">10.1109/JIOT.2019.2902410</pub-id>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhou</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Yu</surname> <given-names>H</given-names></string-name>, <string-name><surname>Shi</surname> <given-names>H</given-names></string-name></person-group>. <article-title>Human activity recognition based on improved bayesian convolution network to analyze health care data using wearable IoT device</article-title>. <source>IEEE Access</source>. <year>2020</year>;<volume>8</volume>:<fpage>86411</fpage>&#x2013;<lpage>8</lpage>. doi:<pub-id pub-id-type="doi">10.1109/ACCESS.2020.2992584</pub-id>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Jeon</surname> <given-names>SE</given-names></string-name>, <string-name><surname>Oh</surname> <given-names>YS</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>YJ</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>IG</given-names></string-name></person-group>. <article-title>Suboptimal feature selection techniques for effective malicious traffic detection on lightweight devices</article-title>. <source>Comput Model Eng Sci</source>. <year>2024</year>;<volume>140</volume>(<issue>2</issue>):<fpage>1669</fpage>&#x2013;<lpage>87</lpage>. doi:<pub-id pub-id-type="doi">10.32604/cmes.2024.047239</pub-id>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Amin</surname> <given-names>R</given-names></string-name>, <string-name><surname>Hussain</surname> <given-names>M</given-names></string-name>, <string-name><surname>Bilal</surname> <given-names>M</given-names></string-name></person-group>. <chapter-title>Network policies in software defined Internet of everything</chapter-title>. In: <person-group person-group-type="editor"><string-name><surname>Aujla</surname> <given-names>GS</given-names></string-name>, <string-name><surname>Garg</surname> <given-names>S</given-names></string-name>, <string-name><surname>Kaur</surname> <given-names>K</given-names></string-name>, <string-name><surname>Sikdar</surname> <given-names>B</given-names></string-name></person-group>, editors. <source>Software defined internet of everything</source>. <publisher-loc>Cham</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2022</year>. p. <fpage>79</fpage>&#x2013;<lpage>96</lpage>. doi: <pub-id pub-id-type="doi">10.1007/978-3-030-89328-6_5</pub-id>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Pajila</surname> <given-names>PJB</given-names></string-name>, <string-name><surname>Jenifer</surname> <given-names>P</given-names></string-name>, <string-name><surname>Karpagavalli</surname> <given-names>CK</given-names></string-name>, <string-name><surname>Angeline</surname> <given-names>AV</given-names></string-name>, <string-name><surname>Muthu</surname> <given-names>R</given-names></string-name></person-group>. <article-title>Software defined networking based protection against DDOS in IoT</article-title>. <source>Int J Innov Technol Explor Eng</source>. <year>2020</year>;<volume>9</volume>(<issue>5</issue>):<fpage>739</fpage>&#x2013;<lpage>45</lpage>. doi:<pub-id pub-id-type="doi">10.35940/ijitee.E2521.039520</pub-id>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Benson</surname> <given-names>K</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>G</given-names></string-name>, <string-name><surname>Venkatasubramanian</surname> <given-names>N</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Ride: a resilient IoT data exchange middleware leveraging SDN and edge cloud resources</article-title>. In: <conf-name>2018 IEEE/ACM Third International Conference on Internet-of-Things Design and Implementation (IoTDI)</conf-name>; <year>2018</year>;<publisher-loc>Orlando, FL, USA</publisher-loc>. p. <fpage>72</fpage>&#x2013;<lpage>83</lpage>. doi:<pub-id pub-id-type="doi">10.1109/IoTDI.2018.00017</pub-id>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Albulayhi</surname> <given-names>A</given-names></string-name>, <string-name><surname>Alsukayti</surname> <given-names>I</given-names></string-name></person-group>. <article-title>A blockchain-centric IoT architecture for effective smart contract-based management of IoT data communications</article-title>. <source>Electronics</source>. <year>2023</year>;<volume>12</volume>(<issue>12</issue>):<fpage>2564</fpage>. doi:<pub-id pub-id-type="doi">10.3390/electronics12122564</pub-id>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Gharaibeh</surname> <given-names>A</given-names></string-name>, <string-name><surname>Salahuddin</surname> <given-names>M</given-names></string-name>, <string-name><surname>Hussini</surname> <given-names>S</given-names></string-name>, <string-name><surname>Khreishah</surname> <given-names>A</given-names></string-name>, <string-name><surname>Khalil</surname> <given-names>I</given-names></string-name>, <string-name><surname>Guizani</surname> <given-names>M</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Smart cities: a survey on data management, security, and enabling technologies</article-title>. <source>IEEE Commun Surv Tutor</source>. <year>2017</year>;<volume>19</volume>:<fpage>2456</fpage>&#x2013;<lpage>501</lpage>. doi:<pub-id pub-id-type="doi">10.1109/COMST.2017.2736886</pub-id>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Liu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>C</given-names></string-name>, <string-name><surname>Yan</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>X</given-names></string-name>, <string-name><surname>Tian</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>J</given-names></string-name></person-group>. <article-title>A semi-centralized trust management model based on blockchain for data exchange in IoT system</article-title>. <source>IEEE Trans Serv Comput</source>. <year>2023</year>;<volume>16</volume>:<fpage>858</fpage>&#x2013;<lpage>71</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TSC.2022.3181668</pub-id>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Meneghello</surname> <given-names>F</given-names></string-name>, <string-name><surname>Calore</surname> <given-names>M</given-names></string-name>, <string-name><surname>Zucchetto</surname> <given-names>D</given-names></string-name>, <string-name><surname>Polese</surname> <given-names>M</given-names></string-name>, <string-name><surname>Zanella</surname> <given-names>A</given-names></string-name></person-group>. <article-title>IoT: internet of threats? a survey of practical security vulnerabilities in real IoT devices</article-title>. <source>IEEE Internet Things J</source>. <year>2019</year>;<volume>6</volume>:<fpage>8182</fpage>&#x2013;<lpage>201</lpage>. doi:<pub-id pub-id-type="doi">10.1109/JIOT.2019.2935189</pub-id>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kumar</surname> <given-names>KP</given-names></string-name>, <string-name><surname>Prathap</surname> <given-names>BR</given-names></string-name>, <string-name><surname>Thiruthuvanathan</surname> <given-names>MM</given-names></string-name>, <string-name><surname>Murthy</surname> <given-names>H</given-names></string-name>, <string-name><surname>Pillai</surname> <given-names>VJ</given-names></string-name></person-group>. <article-title>Secure approach to sharing digitized medical data in a cloud environment</article-title>. <source>Data Sci Manage</source>. <year>2023</year>. doi: <pub-id pub-id-type="doi">10.1016/j.dsm.2023.12.001</pub-id>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>El-Hajj</surname> <given-names>M</given-names></string-name>, <string-name><surname>Fadlallah</surname> <given-names>A</given-names></string-name>, <string-name><surname>Chamoun</surname> <given-names>M</given-names></string-name>, <string-name><surname>Serhrouchni</surname> <given-names>A</given-names></string-name></person-group>. <article-title>A survey of Internet of Things (IoT) authentication schemes</article-title>. <source>Sensors</source>. <year>2019</year>;<volume>19</volume>(<issue>5</issue>):<fpage>1141</fpage>. doi:<pub-id pub-id-type="doi">10.3390/s19051141</pub-id>; <pub-id pub-id-type="pmid">30845760</pub-id></mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Saqib</surname> <given-names>M</given-names></string-name>, <string-name><surname>Moon</surname> <given-names>AH</given-names></string-name></person-group>. <article-title>A systematic security assessment and review of Internet of things in the context of authentication</article-title>. <source>Comput Secur</source>. <year>2023</year>;<volume>125</volume>:<fpage>103053</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.cose.2022.103053</pub-id>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Sureshkumar</surname> <given-names>V</given-names></string-name>, <string-name><surname>Amin</surname> <given-names>R</given-names></string-name>, <string-name><surname>Obaidat</surname> <given-names>MS</given-names></string-name>, <string-name><surname>Karthikeyan</surname> <given-names>I</given-names></string-name></person-group>. <article-title>An enhanced mutual authentication and key establishment protocol for TMIS using chaotic map</article-title>. <source>J Inf Secur Appl</source>. <year>2020</year>;<volume>53</volume>:<fpage>102539</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.jisa.2020.102539</pub-id>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Vinoth</surname> <given-names>R</given-names></string-name>, <string-name><surname>Deborah</surname> <given-names>LJ</given-names></string-name>, <string-name><surname>Vijayakumar</surname> <given-names>P</given-names></string-name>, <string-name><surname>Kumar</surname> <given-names>N</given-names></string-name></person-group>. <article-title>Secure multi-factor authenticated key agreement scheme for industrial IoT</article-title>. <source>IEEE Internet of Things</source>. <year>2020</year>;<volume>8</volume>(<issue>5</issue>):<fpage>3801</fpage>&#x2013;<lpage>11</lpage>. doi:<pub-id pub-id-type="doi">10.1109/JIOT.2020.3024703</pub-id>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Deebak</surname> <given-names>BD</given-names></string-name></person-group>. <article-title>Lightweight authentication and key management in mobile-sink for smart IoT-assisted systems</article-title>. <source>Sustain Cities Soc</source>. <year>2020</year>;<volume>63</volume>:<fpage>102416</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.scs.2020.102416</pub-id>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>X</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>T</given-names></string-name>, <string-name><surname>Obaidat</surname> <given-names>MS</given-names></string-name>, <string-name><surname>Wu</surname> <given-names>F</given-names></string-name>, <string-name><surname>Vijayakumar</surname> <given-names>P</given-names></string-name>, <string-name><surname>Kumar</surname> <given-names>N</given-names></string-name></person-group>. <article-title>A lightweight privacy-preserving authentication protocol for VANETs</article-title>. <source>IEEE Syst J</source>. <year>2020</year>;<volume>14</volume>(<issue>3</issue>):<fpage>3547</fpage>&#x2013;<lpage>57</lpage>. doi:<pub-id pub-id-type="doi">10.1109/JSYST.2020.2991168</pub-id>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Santos</surname> <given-names>MLBA</given-names></string-name>, <string-name><surname>Carneiro</surname> <given-names>JC</given-names></string-name>, <string-name><surname>Franco</surname> <given-names>AMR</given-names></string-name>, <string-name><surname>Teixeira</surname> <given-names>FA</given-names></string-name>, <string-name><surname>Henriques</surname> <given-names>MAA</given-names></string-name>, <string-name><surname>Oliveira</surname> <given-names>LB</given-names></string-name></person-group>. <article-title>FLAT: federated lightweight authentication for the Internet of things</article-title>. <source>Ad Hoc Netw</source>. <year>2020</year>;<volume>107</volume>:<fpage>102253</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.adhoc.2020.102253</pub-id>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kil</surname> <given-names>YS</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>YJ</given-names></string-name>, <string-name><surname>Jeon</surname> <given-names>SE</given-names></string-name>, <string-name><surname>Oh</surname> <given-names>YS</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>IG</given-names></string-name></person-group>. <article-title>Optimization of privacy-utility trade-off for efficient feature selection of secure Internet of Things</article-title>. <source>IEEE Access</source>. <year>2024</year>;<volume>12</volume>:<fpage>142582</fpage>&#x2013;<lpage>91</lpage>. doi:<pub-id pub-id-type="doi">10.1109/ACCESS.2024.3467049</pub-id>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Couteau</surname> <given-names>G</given-names></string-name>, <string-name><surname>Kloo&#x00DF;</surname> <given-names>M</given-names></string-name>, <string-name><surname>Lin</surname> <given-names>H</given-names></string-name>, <string-name><surname>Reichle</surname> <given-names>M</given-names></string-name></person-group>. <chapter-title>Efficient range proofs with transparent setup from bounded integer commitments</chapter-title>. In: <person-group person-group-type="editor"><string-name><surname>Canteaut</surname> <given-names>A</given-names></string-name>, <string-name><surname>Standaert</surname> <given-names>FX</given-names></string-name></person-group>, editors. <source>Advances in cryptology&#x2014;EUROCRYPT 2021</source>. Vol. <volume>12698</volume>. <publisher-loc>Cham</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2021</year>. doi: <pub-id pub-id-type="doi">10.1007/978-3-030-77883-5_9</pub-id>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Shah</surname> <given-names>T</given-names></string-name>, <string-name><surname>Venkatesan</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Authentication of IoT device and IoT server using secure vaults</article-title>. In: <conf-name>17th IEEE International Conference on Trust, Security and Privacy in Computing and Communications</conf-name>; <year>2018</year>; <publisher-loc>New York, NY, USA</publisher-loc>. doi: <pub-id pub-id-type="doi">10.1109/TrustCom/BigDataSE.2018.00117</pub-id>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Rana</surname> <given-names>M</given-names></string-name>, <string-name><surname>Shafiq</surname> <given-names>A</given-names></string-name>, <string-name><surname>Altaf</surname> <given-names>I</given-names></string-name>, <string-name><surname>Alazab</surname> <given-names>M</given-names></string-name>, <string-name><surname>Mahmood</surname> <given-names>K</given-names></string-name>, <string-name><surname>Chaudhry</surname> <given-names>SA</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>A secure and lightweight authentication scheme for next generation IoT infrastructure</article-title>. <source>Comput Commun</source>. <year>2021</year>;<volume>165</volume>:<fpage>85</fpage>&#x2013;<lpage>96</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.comcom.2020.11.002</pub-id>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Gaba</surname> <given-names>GS</given-names></string-name>, <string-name><surname>Hedabou</surname> <given-names>M</given-names></string-name>, <string-name><surname>Kumar</surname> <given-names>P</given-names></string-name>, <string-name><surname>Braeken</surname> <given-names>A</given-names></string-name>, <string-name><surname>Liyanage</surname> <given-names>M</given-names></string-name>, <string-name><surname>Alazab</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Zero knowledge proofs based authenticated key agreement protocol for sustainable healthcare</article-title>. <source>Sustain Cities Soc</source>. <year>2020</year>;<volume>80</volume>:<fpage>103766</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.scs.2022.103766</pub-id>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Chistousov</surname> <given-names>NK</given-names></string-name>, <string-name><surname>Kalmykov</surname> <given-names>IA</given-names></string-name>, <string-name><surname>Dukhovnyj</surname> <given-names>DV</given-names></string-name>, <string-name><surname>Kalmykov</surname> <given-names>MI</given-names></string-name>, <string-name><surname>Olenev</surname> <given-names>AA</given-names></string-name></person-group>. <article-title>Adaptive authentication protocol based on zero-knowledge proof</article-title>. <source>Algorithms</source>. <year>2020</year>;<volume>15</volume>(<issue>2</issue>):<fpage>50</fpage>. doi:<pub-id pub-id-type="doi">10.3390/a15020050</pub-id>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Bosk</surname> <given-names>D</given-names></string-name>, <string-name><surname>Frey</surname> <given-names>D</given-names></string-name>, <string-name><surname>Gestin</surname> <given-names>M</given-names></string-name>, <string-name><surname>Piolle</surname> <given-names>G</given-names></string-name></person-group>. <article-title>Hidden issuer anonymous credential</article-title>. In: <conf-name>Proceedings on Privacy Enhancing Technologies</conf-name>; <year>2022</year>;<publisher-loc>Warsaw, Poland</publisher-loc>. p. <fpage>571</fpage>&#x2013;<lpage>607</lpage>. doi:<pub-id pub-id-type="doi">10.56553/popets-2022-0123</pub-id>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Gr&#x00FC;ner</surname> <given-names>A</given-names></string-name>, <string-name><surname>M&#x00FC;hle</surname> <given-names>A</given-names></string-name>, <string-name><surname>Meinel</surname> <given-names>C</given-names></string-name></person-group>. <article-title>Analyzing interoperability and portability concepts for self-sovereign identity</article-title>. In: <conf-name>2021 IEEE 20th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom)</conf-name>; <year>2021</year>; <publisher-loc>Shenyang, China</publisher-loc>. p. <fpage>587</fpage>&#x2013;<lpage>97</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TrustCom53373.2021.00089</pub-id>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Iqman</surname> <given-names>SB</given-names></string-name></person-group>. <article-title>Company-employee dataset</article-title>. <comment>[cited 2025 Feb 06]</comment>. Available from: <ext-link ext-link-type="uri" xlink:href="https://www.kaggle.com/datasets/iqmansingh/company-employee-dataset">https://www.kaggle.com/datasets/iqmansingh/company-employee-dataset</ext-link>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Rasheed</surname> <given-names>AA</given-names></string-name>, <string-name><surname>Mahapatra</surname> <given-names>RN</given-names></string-name>, <string-name><surname>Hamza-Lup</surname> <given-names>FG</given-names></string-name></person-group>. <article-title>Adaptive group-based zero knowledge proof-authentication protocol in vehicular <italic>ad hoc</italic> networks</article-title>. <source>IEEE Trans Intell Transp Syst</source>. <year>2020</year>;<volume>21</volume>(<issue>2</issue>):<fpage>867</fpage>&#x2013;<lpage>81</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TITS.2019.2899321</pub-id>.</mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>SensitivityScore</collab></person-group>. <article-title>Sensitive data protection documentation | Google cloud</article-title>. <year>2023</year>. [cited 2025 Feb 06]. Available from: <ext-link ext-link-type="uri" xlink:href="https://cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/SensitivityScore">https://cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/SensitivityScore</ext-link>.</mixed-citation></ref>
</ref-list>
</back></article>