<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMC</journal-id>
<journal-id journal-id-type="nlm-ta">CMC</journal-id>
<journal-id journal-id-type="publisher-id">CMC</journal-id>
<journal-title-group>
<journal-title>Computers, Materials &#x0026; Continua</journal-title>
</journal-title-group>
<issn pub-type="epub">1546-2226</issn>
<issn pub-type="ppub">1546-2218</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">32553</article-id>
<article-id pub-id-type="doi">10.32604/cmc.2023.032553</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>A Secure and Efficient Information Authentication Scheme for E-Healthcare System</article-title>
<alt-title alt-title-type="left-running-head">A Secure and Efficient Information Authentication Scheme for E-Healthcare System</alt-title>
<alt-title alt-title-type="right-running-head">A Secure and Efficient Information Authentication Scheme for E-Healthcare System</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author">
<name name-style="western"><surname>Khan</surname><given-names>Naveed</given-names></name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-2" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Zhang</surname><given-names>Jianbiao</given-names></name><xref ref-type="aff" rid="aff-1">1</xref><email>zjb@bjut.edu.cn</email></contrib>
<contrib id="author-3" contrib-type="author">
<name name-style="western"><surname>Mallah</surname><given-names>Ghulam Ali</given-names></name><xref ref-type="aff" rid="aff-2">2</xref></contrib>
<contrib id="author-4" contrib-type="author">
<name name-style="western"><surname>Chaudhry</surname><given-names>Shehzad Ashraf</given-names></name><xref ref-type="aff" rid="aff-3">3</xref></contrib>
<aff id="aff-1"><label>1</label><institution>Faculty of Information Technology, Beijing University of Technology</institution>, <addr-line>Beijing, 100124</addr-line>, <country>China</country></aff>
<aff id="aff-2"><label>2</label><institution>Department of Computer Science, Shah Abdul Latif University</institution>, <addr-line>Khairpur, 66111</addr-line>, <country>Pakistan</country></aff>
<aff id="aff-3"><label>3</label><institution>Department of Computer Engineering, Faculty of Engineering Architecture, Nisantasi University</institution>, <addr-line>Istanbul, 34398</addr-line>, <country>Turkey</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Jianbiao Zhang. Email: <email>zjb@bjut.edu.cn</email></corresp>
</author-notes>
<pub-date date-type="collection" publication-format="electronic"><year>2023</year></pub-date>
<pub-date date-type="pub" publication-format="electronic"><day>08</day><month>10</month><year>2023</year></pub-date>
<volume>76</volume>
<issue>3</issue>
<fpage>3877</fpage>
<lpage>3896</lpage>
<history>
<date date-type="received"><day>22</day><month>5</month><year>2022</year></date>
<date date-type="accepted"><day>12</day><month>7</month><year>2022</year></date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2023 Khan et al.</copyright-statement>
<copyright-year>2023</copyright-year>
<copyright-holder>Khan et al.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMC_32553.pdf"></self-uri>
<abstract>
<p>The mobile cellular network provides internet connectivity for heterogeneous Internet of Things (IoT) devices. The cellular network consists of several towers installed at appropriate locations within a smart city. These cellular towers can be utilized for various tasks, such as e-healthcare systems, smart city surveillance, traffic monitoring, infrastructure surveillance, or sidewalk checking. Security is a primary concern in data broadcasting, particularly authentication, because the strength of a cellular network&#x2019;s signal is much higher frequency than the associated one, and their frequencies can sometimes be aligned, posing a significant challenge. As a result, that requires attention, and without information authentication, such a barrier cannot be removed. So, we design a secure and efficient information authentication scheme for IoT-enabled devices to mitigate the flaws in the e-healthcare system. The proposed protocol security shall check formally using the Real-or-Random (ROR) model, simulated using ProVerif2.03, and informally using pragmatic discussion. In comparison, the performance phenomenon shall tackle by the already result available in the MIRACL cryptographic lab.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>IoT-enable device</kwd>
<kwd>e-healthcare</kwd>
<kwd>authentication</kwd>
<kwd>edge computing</kwd>
</kwd-group>
<funding-group>
<award-group id="awg1">
<funding-source>Natural Science Foundation of Beijing Municipality</funding-source>
<award-id>M21039</award-id>
</award-group>
</funding-group>
</article-meta>
</front>
<body>
<sec id="s1"><label>1</label><title>Introduction</title>
<p>The IoT-enabled devices can be found in various domains, such as the healthcare system, cities, factories, homes, the Internet of Drones (IoD), and many more [<xref ref-type="bibr" rid="ref-1">1</xref>,<xref ref-type="bibr" rid="ref-2">2</xref>]. By 2025, IoT devices usages will have increased, and about 75 billion devices will be connected to the internet [<xref ref-type="bibr" rid="ref-3">3</xref>]. As a result, the e-healthcare market will expand by 16 percent between 2020 to 2027, while the current volume is 143.6 billion USD [<xref ref-type="bibr" rid="ref-4">4</xref>]. In an e-healthcare system, medical signals are used to monitor patients&#x2019; health activities. These signals are one-dimensional (1D) and two-dimensional (2D) signals, such as blood pressure, electrocardiograms, electromyograms, electroglottograph, body temperature, and electroencephalograms. Although, traditional hospital management monitors patient activities manually. Therefore, it is inefficient and can lead to medication errors. The medication error can be fatal and lead to patient harm. Furthermore, according to World Health Organization (WHO), medication error costs humans around 42 billion USD annually [<xref ref-type="bibr" rid="ref-5">5</xref>].</p>
<p>In contrast, edge computing plays a crucial role in medical emergencies and communication delays. Therefore, edge computing benefits the e-healthcare system in terms of real-time data collection, processing, and analyzation. Moreover, the edge architecture provides reliability and low latency in distributive applications such as IoT-enable sensors in e-healthcare. Although, the initial goal of edge computing was to reduce bandwidth costs. However, with the advancement of wireless networks such as 5G and even researchers working on 6G networks, edge computing will be able to support real-time applications such as self-driving cars, robotics, video processing, and medical enable IoT devices, to name a few. Edge computing is a distributed computing topology in which data storage and computation are located close to the devices in order to reduce latency. Latency is critical in the e-healthcare system because high latency can harm a patient&#x2019;s life. In contrast, low latency can sometimes save their lives [<xref ref-type="bibr" rid="ref-6">6</xref>].</p>
<p>Furthermore, IoT-enabled devices facilitate communication between doctors and patients. Doctors place these IoT-enabled devices on patients&#x2019; bodies to monitor their health activities. However, IoT-enabled devices improve doctor-patient interaction but generate massive amounts of data that must be carefully stored and processed at edge computing. Therefore, using IoT-enabled devices in the medical field is advantageous because it eliminates the need for medical personnel to manually manage patient data. Although, these IoT-enabled devices are vulnerable to security threats due to their resource and energy limitations. Because of this, it is impossible to eliminate these vulnerabilities without strong authentication. Therefore, several different e-healthcare authentications and key agreement schemes have been implemented. However, these schemes [<xref ref-type="bibr" rid="ref-7">7</xref>&#x2013;<xref ref-type="bibr" rid="ref-9">9</xref>] suffer from eavesdropping and forgery attacks. Furthermore, we identified security flaws in the scheme [<xref ref-type="bibr" rid="ref-10">10</xref>] and found out that the scheme suffers from different attacks such as spoofing, masquerading, and impersonation.</p>
<sec id="s1_1"><label>1.1</label><title>Motivation and Contribution</title>
<p>For academics, e-healthcare is a sensitive research area. Furthermore, any flaws in the protocol could result in the patients&#x2019; fatal accidents. As a result, we take advantage of the opportunity to propose a secure and efficient authentication scheme for e-healthcare that reduces complexity while improving security over existing schemes. Our protocol is efficient and lightweight for IoT-enabled devices because we only use the XOR and hash functions. Recently author [<xref ref-type="bibr" rid="ref-10">10</xref>] proposed an authentication scheme for the healthcare system. According to [<xref ref-type="bibr" rid="ref-10">10</xref>], the scheme achieves mutual authentication, untraceability, forward secrecy, and resistance to replay and desynchronization attacks. However, careful examination reveals that the scheme is vulnerable to spoofing, masquerading, and impersonation attacks. In the scheme [<xref ref-type="bibr" rid="ref-10">10</xref>], when the attacker copies <italic>M<sub>4</sub>&#x2009;&#x003D;&#x2009;&#x007B;X, A<sub>n</sub>&#x007D;</italic> and transmits it again later, the adversary (<inline-formula id="ieqn-1"><mml:math id="mml-ieqn-1"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula>) can easily spoof the reader&#x2019;s radio frequency identification (RFID) because for each session, the same message is transmitted over the public network channel. Furthermore, an attacker may also modify it to masquerade as a legitimate peer. Similarly, for <italic>M<sub>5</sub>&#x2009;&#x003D; &#x007B;Y, A<sub>R1</sub>, X, A<sub>n</sub>&#x007D;</italic>, the attacker can easily impersonate the server for a wrong decision due to its static nature. Therefore, the scheme suffers from spoofing, impersonation, and masquerading attacks. The following is our primary contribution:
<list list-type="bullet">
<list-item><p>We identified security vulnerabilities in [<xref ref-type="bibr" rid="ref-10">10</xref>] and rectified them using our proposed scheme, which is lightweight and efficient because it utilizes only XOR and a hash function.</p></list-item>
<list-item><p>Despite achieving some security objectives, the protocol [<xref ref-type="bibr" rid="ref-10">10</xref>] came at a high cost in terms of communication and computation. Since communication and computation costs are rising, we proposed a low-cost solution to address this issue.</p></list-item>
<list-item><p>The security of our proposed protocol is formally analyzed through the ROR model [<xref ref-type="bibr" rid="ref-11">11</xref>] and ProVerif2.03 [<xref ref-type="bibr" rid="ref-12">12</xref>]. Using ProVerif and ROR model, we demonstrated that our proposed scheme is secure against replay and man in the middle attacks while securely providing mutual authentication and session key security.</p></list-item>
<list-item><p>In the informal security analysis section, our proposed scheme demonstrates that our protocol is secure against various attacks.</p></list-item>
<list-item><p>Our proposed protocol outperforms existing state-of-the-art schemes regarding communication, computation costs, and security. Among many other applications, the scheme can realize a smart city environment.</p></list-item>
</list></p>
</sec>
<sec id="s1_2"><label>1.2</label><title>Threat Model</title>
<p>We extended the famous threat model developed by Dolev and Yao (DY), also called the DY model [<xref ref-type="bibr" rid="ref-13">13</xref>]. We are adopting a solid adversary <inline-formula id="ieqn-2"><mml:math id="mml-ieqn-2"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula>. According to the DY model, any danger to the system must be examined and analyzed before operationalizing it in real-world environments. We also consider the adversary model of Cannetti and Knawezk (CK) model [<xref ref-type="bibr" rid="ref-14">14</xref>] and utilized [<xref ref-type="bibr" rid="ref-15">15</xref>] for a more solid adversary. The CK model is the most used in authentication and key exchange protocols. In the DY model, the <inline-formula id="ieqn-3"><mml:math id="mml-ieqn-3"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> delivers the message, while in the CK model, the <inline-formula id="ieqn-4"><mml:math id="mml-ieqn-4"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> can also compromise the session key and secret key.</p>
<p>Furthermore, IoT-enabled devices or sensor nodes can be accessed by the <inline-formula id="ieqn-5"><mml:math id="mml-ieqn-5"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> physically. Thus, the <inline-formula id="ieqn-6"><mml:math id="mml-ieqn-6"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> will try to extract secret information from it. Further, the communication between IoT-enable devices or sensor nodes and edge computing can be intercepted by the <inline-formula id="ieqn-7"><mml:math id="mml-ieqn-7"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula>. Sensor nodes are connected to the edge node using a wireless network; therefore, the <inline-formula id="ieqn-8"><mml:math id="mml-ieqn-8"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> can access open channel data and modify, delete, or insert it. The <inline-formula id="ieqn-9"><mml:math id="mml-ieqn-9"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> can monitor the data between the IoT-enable sensor node and the user. The <inline-formula id="ieqn-10"><mml:math id="mml-ieqn-10"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> can pretend to be a legal user to the edge server and launch Man-In-The-Middle (MITM) to masquerade and impersonate attacks.</p>
</sec>
<sec id="s1_3"><label>1.3</label><title>System Model</title>
<p>Our system model consists of patients with IoT-enable sensor nodes, medical staff, edge server, and registration server, as shown in <xref ref-type="fig" rid="fig-1">Fig. 1</xref>. First, the IoT-enable sensor nodes and users need to register themself with the registration server. After that, medical staff can monitor patients&#x2019; activities in real-time using these IoT-enabled devices, whereas the edge server reduces latency. The registration server and edge server are the trusted authorities in our proposed scheme. The registration server is in charge of registering users and IoT-enabled devices. Finally, our system model detailed explanation is given in the proposed scheme.</p>
<fig id="fig-1"><label>Figure 1</label><caption><title>System model</title></caption><graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_32553-fig-1.tif"/></fig>
</sec>
<sec id="s1_4"><label>1.4</label><title>Paper Organization</title>
<p>The rest of the article is structured as follows: <xref ref-type="sec" rid="s2">Section 2</xref> describes the literature review in detail. Additionally, <xref ref-type="sec" rid="s3">Section 3</xref> contains the proposed scenario. Then, in <xref ref-type="sec" rid="s4">Section 4</xref>, we examine the proposed framework&#x2019;s security, <xref ref-type="sec" rid="s5">Section 5</xref> discusses informal security analysis, and <xref ref-type="sec" rid="s6">Section 6</xref> conducts a performance analysis. Finally, <xref ref-type="sec" rid="s7">Section 7</xref> concludes the paper.</p>
</sec>
</sec>
<sec id="s2"><label>2</label><title>Related Work</title>
<p>There are numerous advantages to having an e-healthcare system. Despite the benefits, there are multiple concerns, the most noteworthy of which is outsourcing data storage. As a result, it creates the possibility of unlawful physical access. However, encryption is the most effective method for preventing unauthorized access to outsourced data. Encrypting and storing data in the cloud can prevent malicious users or cloud service providers from accessing it [<xref ref-type="bibr" rid="ref-16">16</xref>]. These encryption techniques, however, could be improved. If an attacker obtains access to a secret key, the data must be protected from unauthorized access.</p>
<p>However, IoT-enabled devices have resource and energy limitations. As a result, these devices are susceptible to a wide range of security risks. In addition, traditional cryptographic protocols do not perform well on IoT-enabled devices due to resource and energy constraints. These devices are vulnerable to both passive and active security threats, and the attacks can be launched from inside or outside the network. These security breaches impede communication. As a result, Denial-of-Service (DoS) and Sybil attacks are potentially more dangerous because they deplete the device&#x2019;s resources and network bandwidth. Many researchers attempt to create security protocols that address authentication, confidentiality, and integrity. Authentication is one of the most visible aspects that ensures user identity and verifies it in order to protect data from malicious users. This section provides a brief overview and analysis of the existing schemes in e-healthcare systems.</p>
<p>The authors [<xref ref-type="bibr" rid="ref-7">7</xref>] proposed an authentication scheme for RFID-based IoT devices to prevent replay and data disclosure attacks. Their scheme also provides anonymity. However, their scheme has security flaws, such as the scheme cannot be resilient to impersonation, eavesdropping, and forgery attacks. Further, the authors [<xref ref-type="bibr" rid="ref-17">17</xref>] proposed an authentication scheme based on Chaotic-Map and Chebyshev. However, it provides better anonymity but suffers from offline password guessing, password disclosure, and impersonation attacks. Finally, in 2018, the authors [<xref ref-type="bibr" rid="ref-18">18</xref>] proposed a lightweight privacy preservation scheme using Physically Unclonable Functions (PUFs). However, their scheme also has security flaws such as perfect forward secrecy and heave storage and computation cost. Moreover, the schemes [<xref ref-type="bibr" rid="ref-8">8</xref>,<xref ref-type="bibr" rid="ref-9">9</xref>] cannot resist DoS, eavesdropping, and forgery attacks.</p>
<p>The authors [<xref ref-type="bibr" rid="ref-19">19</xref>] proposed an Elliptic Curve Cryptography (ECC) authentication protocol for the healthcare system. Nevertheless, their scheme suffers from password guessing and impersonation attacks. However, An authentication scheme based on Hash-based RFID was proposed [<xref ref-type="bibr" rid="ref-20">20</xref>]. Unfortunately, the scheme cannot resist forgery, privileged insiders, and Denial of Service (DoS) attacks. Furthermore, the scheme [<xref ref-type="bibr" rid="ref-21">21</xref>] cannot provide resistance against insider, MITM, session key security, and session-specific temporary information attacks. While the scheme [<xref ref-type="bibr" rid="ref-22">22</xref>] also cannot resist insider, offline password guessing, stolen smartcard, and session key security attacks. Furthermore, The scheme [<xref ref-type="bibr" rid="ref-23">23</xref>] cannot provide anonymity, insider, replay, and MITM attacks. The paper [<xref ref-type="bibr" rid="ref-24">24</xref>] proposed a high optimal path channel triggering scheme that offers data preservation and privacy with minimal network resources.</p>
<p>Elliptic Curve Cryptography (ECC) and integrated with a biometric authentication scheme were proposed by [<xref ref-type="bibr" rid="ref-25">25</xref>]. However, the scheme is vulnerable to machine learning [<xref ref-type="bibr" rid="ref-26">26</xref>] attacks and cannot provide perfect forward secrecy and perfect backward secrecy. The authors [<xref ref-type="bibr" rid="ref-27">27</xref>] proposed a certificateless authentication protocol, but their scheme cannot resist modification and impersonation attacks [<xref ref-type="bibr" rid="ref-28">28</xref>]. Another scheme was proposed in [<xref ref-type="bibr" rid="ref-29">29</xref>], which does not provide message integrity and physical security. An Intrusion Detection System (IDS) scheme was proposed in [<xref ref-type="bibr" rid="ref-30">30</xref>&#x2013;<xref ref-type="bibr" rid="ref-32">32</xref>] to detect Botnet, DoS, distributed denial of service (DDoS), Wireless Body Area Networks (WBAN), and many more attacks, but these methods consume time and the accuracy rate is also low. The scheme [<xref ref-type="bibr" rid="ref-33">33</xref>] failed to resist insider attacks and could not provide session key security and untraceability.</p>
<p>On the other hand, the approach [<xref ref-type="bibr" rid="ref-34">34</xref>] did not provide traceability or mutual authentication, as the name suggests. As a result, researchers [<xref ref-type="bibr" rid="ref-23">23</xref>,<xref ref-type="bibr" rid="ref-35">35</xref>] presented a three-factor authentication technique based on ECC to ensure perfect forward secrecy. However, these systems do not guarantee absolute forward secrecy, user anonymity, or the ability to withstand replay attacks. Over the cost of computation, the protocol [<xref ref-type="bibr" rid="ref-36">36</xref>] provides a security feature that is advantageous. The authors proposed a lightweight authentication technique in [<xref ref-type="bibr" rid="ref-37">37</xref>], but the key generation time was highly elongated. As a result, it is in conflict with the characteristic of a lightweight scenario. Blockchain technology has recently garnered the interest of healthcare researchers. However, the blockchain has issues with accessing medical records [<xref ref-type="bibr" rid="ref-38">38</xref>].</p>
<p>Furthermore, a scheme [<xref ref-type="bibr" rid="ref-39">39</xref>] was proposed using symmetric en/decryption, hash function, and chaotic maps that provide authentication and key agreements for multi-server environments. However, according to [<xref ref-type="bibr" rid="ref-40">40</xref>], the scheme is prone to offline password guessing attacks and biometric and smart card leaks. Moreover, the scheme [<xref ref-type="bibr" rid="ref-41">41</xref>] is vulnerable to DoS attacks. Furthermore, it cannot provide perfect forward secrecy and provision of smartcard revocation. In contrast, the scheme cannot resist anonymity, user impersonation, mutual authentication, and server impersonation attacks. Therefore, we propose a secure and efficient authentication protocol for e-healthcare in edge computing to improve the security vulnerabilities of the existing scheme and especially the protocol proposed in [<xref ref-type="bibr" rid="ref-10">10</xref>].</p>
</sec>
<sec id="s3"><label>3</label><title>Proposed Scheme</title>
<p>We proposed a secure and efficient information authentication protocol for an IoT-enable device in an e-healthcare system to improve the flaws in the protocol [<xref ref-type="bibr" rid="ref-10">10</xref>]. Our proposed approach is divided into four phases: setup, registration, login and authentication, and password changing. Detailed notation and their description are shown in <xref ref-type="table" rid="table-1">Table 1</xref>.</p>
<table-wrap id="table-1"><label>Table 1</label><caption><title>Notations and description</title></caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left">Notation</th>
<th align="left">Description</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">ID<sub>u</sub></td>
<td align="left">User identity</td>
</tr>
<tr>
<td align="left">ID<sub>e</sub></td>
<td align="left">Edge server identity</td>
</tr>
<tr>
<td align="left">ID<sub>w</sub></td>
<td align="left">IoT-enable sensor node identity</td>
</tr>
<tr>
<td align="left">PW<sub>u</sub></td>
<td align="left">User password</td>
</tr>
<tr>
<td align="left">r<sub>u</sub>, r<sub>u1</sub></td>
<td align="left">User random numbers</td>
</tr>
<tr>
<td align="left">r<sub>w</sub>, r<sub>w1</sub></td>
<td align="left">IoT-enable sensor node random numbers</td>
</tr>
<tr>
<td align="left">r<sub>e</sub></td>
<td align="left">The random number of an edge server</td>
</tr>
<tr>
<td align="left">r<sub>rs</sub></td>
<td align="left">The random number of the registration server</td>
</tr>
<tr>
<td align="left">SK<sub>rs</sub></td>
<td align="left">Registration server secret key</td>
</tr>
<tr>
<td align="left">V</td>
<td align="left">Edge server and IoT-enable sensor node shared secret key</td>
</tr>
<tr>
<td align="left">V<sub>1</sub></td>
<td align="left">User and edge server shared secret key</td>
</tr>
<tr>
<td align="left">S<sub>K</sub></td>
<td align="left">Session key</td>
</tr>
<tr>
<td align="left">h(.)</td>
<td align="left">One-way hash function</td>
</tr>
<tr>
<td align="left"><inline-formula id="ieqn-11"><mml:math id="mml-ieqn-11"><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula></td>
<td align="left">XOR</td>
</tr>
<tr>
<td align="left">&#x007C;&#x007C;</td>
<td align="left">Concatenation</td>
</tr>
</tbody>
</table>
</table-wrap>
<sec id="s3_1"><label>3.1</label><title>Setup Phase</title>
<p>The registration server generates the secret key SKrs in our proposed protocol. The edge server and IoT-enable sensor node both have their own unique identities, ID<sub>e</sub> and ID<sub>w</sub>, and a secret user key, PKu.</p>
</sec>
<sec id="s3_2"><label>3.2</label><title>Registration Phase</title>
<p>Our proposed scheme registration phase comprises of two-part. In the first portion, we will register the IoT-enable sensor node with the registration server, while in the second phase, we will register the user with the registration server. The process is under:</p>
<sec id="s3_2_1"><label>3.2.1</label><title>IoT-Enable Sensor Node Registration Phase</title>
<list list-type="roman-lower">
<list-item><p>In this step, the IoT-enable sensor node selects identity ID<sub>u</sub> and generates a random number r<sub>w</sub> to calculate X<sub>w</sub>&#x2009;&#x003D;&#x2009;h(ID<sub>u</sub>&#x007C;&#x007C;r<sub>w</sub>). The IoT-enable sensor node sends RM1&#x2009;&#x003D;&#x2009;&#x007B;X<sub>w</sub>, r<sub>w</sub>&#x007D; toward the registration server.</p></list-item>
<list-item><p>Upon receiving RM1&#x2009;&#x003D;&#x2009;&#x007B;X<sub>w</sub>, r<sub>w</sub>&#x007D; from IoT-enable sensor node, the registration server generates random number r<sub>rs</sub> to computes V&#x2009;&#x003D;&#x2009;h(X<sub>w</sub>&#x007C;&#x007C;r<sub>rs</sub>&#x007C;&#x007C;SK<sub>rs</sub>) and store &#x007B;X<sub>w</sub>, V, r<sub>rs</sub>&#x007D; in edge server database. After that the registration server send RM2&#x2009;&#x003D;&#x2009;&#x007B;V&#x007D; to IoT-enable sensor node over secure channel.</p></list-item>
<list-item><p>The IoT-enable sensor node further calculates S<sub>1&#x2009;</sub>&#x003D;&#x2009;h(ID<sub>w</sub>&#x007C;&#x007C;SK<sub>w</sub>)<inline-formula id="ieqn-12"><mml:math id="mml-ieqn-12"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula> r<sub>w</sub>, S<sub>2&#x2009;</sub>&#x003D;&#x2009;h(r<sub>w</sub>&#x007C;&#x007C;SK<sub>w</sub>)<inline-formula id="ieqn-13"><mml:math id="mml-ieqn-13"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula> V and Store &#x007B;X<sub>w</sub>, S<sub>1</sub>, S<sub>2</sub>&#x007D; in memory and the procedure as shown in <xref ref-type="table" rid="table-2">Table 2</xref>.</p>
</list-item>
</list>
<table-wrap id="table-2"><label>Table 2</label><caption><title>IoT-enable sensor node registration</title></caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left">IoT-enable sensor node</th>
<th align="left">Registration Server (RS)</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left" colspan="2">Select identity ID<sub>w</sub></td>
</tr>
<tr>
<td align="left" colspan="2">Generate random number r<sub>w</sub></td>
</tr>
<tr>
<td align="left" colspan="2">Calculate:</td>
</tr>
<tr>
<td align="left" colspan="2">X<sub>w</sub> &#x003D; h(ID<sub>w</sub>&#x007C;&#x007C;r<sub>w</sub>)</td>
</tr>
<tr>
<td align="left" colspan="2">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;<inline-formula id="ieqn-14"><mml:math id="mml-ieqn-14"><mml:munder><mml:mrow><mml:mrow><mml:mtext>RM1</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:msub><mml:mrow><mml:mtext>X</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>w</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mtext>r</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>w</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>}</mml:mo></mml:mrow></mml:mrow><mml:mo stretchy="false">&#x27F6;</mml:mo></mml:munder></mml:math></inline-formula></td>
</tr>
<tr>
<td align="left" colspan="2">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;Generate random number r<sub>rs</sub></td>
</tr>
<tr>
<td align="left" colspan="2">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;Computes:</td>
</tr>
<tr>
<td align="left" colspan="2">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;V &#x003D; h(X<sub>w</sub>&#x007C;&#x007C;r<sub>rs</sub>&#x007C;&#x007C;SK<sub>rs</sub>)</td>
</tr>
<tr>
<td align="left" colspan="2">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;Store &#x007B;X<sub>w</sub>, V, r<sub>rs</sub>&#x007D; in edge server database</td>
</tr>
<tr>
<td align="left" colspan="2">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;<inline-formula id="ieqn-15"><mml:math id="mml-ieqn-15"><mml:munder><mml:mrow><mml:mrow><mml:mtext>RM2</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:mrow><mml:mtext>V</mml:mtext></mml:mrow><mml:mo>}</mml:mo></mml:mrow></mml:mrow><mml:mo stretchy="false">&#x27F5;</mml:mo></mml:munder></mml:math></inline-formula></td>
</tr>
<tr>
<td align="left" colspan="2">Computes:</td>
</tr>
<tr>
<td align="left" colspan="2">S<sub>1&#x2009;</sub>&#x003D;&#x2009;h(ID<sub>w</sub>&#x007C;&#x007C;SK<sub>w</sub>)<inline-formula id="ieqn-16"><mml:math id="mml-ieqn-16"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula> r<sub>w</sub></td>
</tr>
<tr>
<td align="left" colspan="2">S<sub>2&#x2009;</sub>&#x003D;&#x2009;h(r<sub>w</sub>&#x007C;&#x007C;SK<sub>w</sub>)<inline-formula id="ieqn-17"><mml:math id="mml-ieqn-17"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula> V</td>
</tr>
<tr>
<td align="left" colspan="2">Store &#x007B;X<sub>w</sub>, S<sub>1</sub>, S<sub>2</sub>&#x007D; in memory</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s3_2_2"><label>3.2.2</label><title>User Registration Phase</title>
<p>In this section, the user registers with the registration server in our proposed protocol.
<list list-type="roman-lower">
<list-item><p>The user selects identity ID<sub>u</sub>, generates a random number r<sub>u</sub> and computes X<sub>u</sub>&#x2009;&#x003D; h(ID<sub>u</sub>&#x007C;&#x007C;r<sub>u</sub>), and sends RM3&#x2009;&#x003D;&#x2009;&#x007B;X<sub>u</sub>&#x007D; toward the registration server over a secure channel.</p></list-item>
<list-item><p>After receiving RM3&#x2009;&#x003D;&#x2009;&#x007B;X<sub>w</sub>&#x007D; from user, the registration server calculates V<sub>1</sub>&#x2009;&#x003D;&#x2009;h(X<sub>u</sub>&#x007C;&#x007C;SK<sub>rs</sub>&#x007C;&#x007C;r<sub>rs</sub>), XID<sub>u</sub>&#x2009;&#x003D;&#x2009;h (X<sub>u</sub>&#x007C;&#x007C;V<sub>1</sub>) and store &#x007B;X<sub>u</sub>, XIDu, V<sub>1</sub>&#x007D; in edge server database. After computation the registration server send RM4&#x2009;&#x003D;&#x2009;&#x007B;V<sub>1</sub>, XIDu&#x007D; to user over secure channel.</p></list-item>
<list-item><p>The user chooses a password PW<sub>u</sub> and computes HPW<sub>u</sub> &#x003D; h(PW<sub>u</sub>&#x007C;&#x007C;r<sub>u</sub>), B<sub>1&#x2009;</sub>&#x003D;&#x2009;h(ID<sub>u</sub>&#x007C;&#x007C;PW<sub>u</sub>) <inline-formula id="ieqn-18"><mml:math id="mml-ieqn-18"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula> r<sub>u</sub>, B<sub>2&#x2009;</sub>&#x003D;&#x2009;h(ID<sub>u</sub>&#x007C;&#x007C;PW<sub>u</sub>&#x007C;&#x007C;r<sub>u</sub>&#x007C;&#x007C;HPW<sub>u</sub>), B<sub>3&#x2009;</sub>&#x003D;&#x2009;h(HPW<sub>u</sub>&#x007C;&#x007C;r<sub>u</sub>)<inline-formula id="ieqn-19"><mml:math id="mml-ieqn-19"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula> XID<sub>u</sub>, B<sub>4&#x2009;</sub>&#x003D;&#x2009;h(HPW<sub>u</sub>&#x007C;&#x007C;XID<sub>u</sub>)<inline-formula id="ieqn-20"><mml:math id="mml-ieqn-20"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula> V<sub>1</sub> and Store &#x007B;X<sub>u</sub>, B<sub>1</sub>, B<sub>2</sub>, B<sub>3</sub>, B<sub>4</sub>&#x007D; and the procedure is illustrated in <xref ref-type="table" rid="table-2">Table 2</xref>.</p>
</list-item>
</list></p>
</sec>
</sec>
<sec id="s3_3"><label>3.3</label><title>Login and Authentication Phase</title>
<p>
<list list-type="roman-lower">
<list-item><p>The user input identity ID<sub>u</sub> and password PW<sub>u</sub> and computes, r<sub>u</sub> &#x003D; h(ID<sub>u</sub>&#x007C;&#x007C;PW<sub>u</sub>)<inline-formula id="ieqn-21"><mml:math id="mml-ieqn-21"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula> B<sub>1</sub>, HPW<sub>u</sub> &#x003D; h (PWu&#x007C;&#x007C;r<sub>u</sub>), B<sub>2</sub><sup>&#x002A;</sup>&#x2009;&#x003D; h(ID<sub>u</sub>&#x007C;&#x007C;PW<sub>u</sub>&#x007C;&#x007C;r<sub>u</sub>&#x007C;&#x007C;HPW<sub>u</sub>). The user check B<sub>2</sub><sup>&#x002A;</sup>? &#x003D;&#x2009;B<sub>2</sub> and if it corrects then proceed further otherwise terminate connection. The user generates random number r<sub>u1</sub> and calculates XID<sub>u</sub> &#x003D; h(HPW<sub>u</sub>&#x007C;&#x007C;r<sub>u</sub>) <inline-formula id="ieqn-22"><mml:math id="mml-ieqn-22"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula> B<sub>3</sub>, V<sub>1</sub>&#x2009;&#x003D; h(HPW<sub>u</sub>&#x007C;&#x007C;XID<sub>u</sub>)<inline-formula id="ieqn-23"><mml:math id="mml-ieqn-23"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula> B<sub>4</sub>, N&#x2009;&#x003D; h(X<sub>u</sub>&#x007C;&#x007C;XID<sub>u</sub>&#x007C;&#x007C;V<sub>1</sub>)<inline-formula id="ieqn-24"><mml:math id="mml-ieqn-24"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula> (X<sub>u</sub>&#x007C;&#x007C;r<sub>u1</sub>), D&#x2009;&#x003D;&#x2009;h (ID<sub>u</sub>&#x007C;&#x007C;r<sub>u</sub>) <inline-formula id="ieqn-25"><mml:math id="mml-ieqn-25"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula> h(V<sub>1</sub>&#x007C;&#x007C;r<sub>u1</sub>), F<sub>u</sub>&#x2009;&#x003D; h (X<sub>u</sub>&#x007C;&#x007C;XID<sub>u</sub> &#x007C;&#x007C;r<sub>u1</sub>&#x007C;&#x007C;X<sub>w</sub>&#x007C;&#x007C;V<sub>1</sub>). After calculations the user sends M1 &#x003D; &#x007B;N, D, F<sub>e</sub>, X<sub>u</sub>&#x007D; towards edge server.</p></list-item>
<list-item><p>The edge server extracts XID<sub>u</sub> and V<sub>1</sub> as per the X<sub>u</sub> and calculates (X<sub>w</sub><sup>&#x002A;</sup>&#x007C;&#x007C;r<sub>u1</sub><sup>&#x002A;</sup>) &#x003D; h(X<sub>u</sub>&#x007C;&#x007C;XID<sub>u</sub>&#x007C;&#x007C;V<sub>1</sub>), F<sub>u</sub><sup>&#x002A;</sup>&#x2009;&#x003D;&#x2009;h(X<sub>u</sub>&#x007C;&#x007C;XID<sub>u</sub>&#x007C;&#x007C;r<sub>u1</sub><sup>&#x002A;</sup>&#x007C;&#x007C;X<sub>w</sub><sup>&#x002A;</sup>&#x007C;&#x007C;V<sub>1</sub>) and Check F<sub>u</sub><sup>&#x002A;</sup>? &#x003D; F<sub>u</sub>, if edge authenticate user then proceed further otherwise terminate connection. The edge server selects random number r<sub>e</sub> and further calculates N<sub>2</sub> &#x003D; h(r<sub>e</sub>&#x007C;&#x007C;r<sub>u1</sub>), N<sub>3</sub> &#x003D; h(X<sub>w</sub>&#x007C;&#x007C;V&#x007C;&#x007C;r<sub>w</sub>)<inline-formula id="ieqn-26"><mml:math id="mml-ieqn-26"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula> N<sub>2</sub>, h(ID<sub>u</sub>&#x007C;&#x007C;r<sub>u1</sub>) &#x003D; E<sub>1</sub><inline-formula id="ieqn-27"><mml:math id="mml-ieqn-27"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula>h(V<sub>1</sub>&#x007C;&#x007C;r<sub>u1</sub>), E<sub>2</sub> &#x003D; (h(ID<sub>u</sub> &#x007C;&#x007C;r<sub>u1</sub>)&#x007C;&#x007C;h (ID<sub>e</sub>&#x007C;&#x007C;r<sub>e</sub>))<inline-formula id="ieqn-28"><mml:math id="mml-ieqn-28"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula>h(V&#x007C;&#x007C;r<sub>w</sub>), and F<sub>e</sub>&#x2009;&#x003D;&#x2009;h(X<sub>u</sub>&#x007C;&#x007C;N<sub>2</sub>&#x007C;&#x007C;V). After computation the edge server send M2&#x2009;&#x003D;&#x2009;&#x007B;X<sub>w</sub>, N<sub>1</sub>, E<sub>2</sub>&#x00B8;F<sub>e</sub>&#x007D; to IoT-enable sensor node.</p></list-item>
<list-item><p>The IoT-enable sensor node calculates r<sub>w</sub>&#x2009;&#x003D;&#x2009;h(ID<sub>w</sub>&#x007C;&#x007C;PK<sub>w</sub>), V&#x2009;&#x003D;&#x2009;h(r<sub>w</sub>&#x007C;&#x007C;PK<sub>w</sub>)<inline-formula id="ieqn-29"><mml:math id="mml-ieqn-29"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula>S<sub>2</sub>, N<sub>2</sub><sup>&#x002A;</sup>&#x2009;&#x003D;&#x2009;h(X<sub>w</sub>&#x007C;&#x007C; V&#x007C;&#x007C;r<sub>w</sub>)<inline-formula id="ieqn-30"><mml:math id="mml-ieqn-30"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula>N<sub>3</sub>, F<sub>e</sub><sup>&#x002A;</sup>&#x2009;&#x003D;&#x2009;h(X<sub>u</sub>&#x007C;&#x007C;N<sub>2</sub><sup>&#x002A;</sup>&#x007C;&#x007C;V). The IoT-enable sensor node authenticates edge server through Fe<sup>&#x002A;</sup>? &#x003D; F<sub>e</sub>, if correct then proceed further otherwise terminate connection. The IoT-enable sensor node generates random number r<sub>u1</sub> and computes ( h (ID<sub>u</sub> &#x007C;&#x007C;r<sub>u1</sub>) &#x007C;&#x007C;h (ID<sub>e</sub>&#x007C;&#x007C;r<sub>e</sub>)) &#x003D; E<sub>2</sub><inline-formula id="ieqn-31"><mml:math id="mml-ieqn-31"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula>h(V&#x007C;&#x007C;r<sub>w</sub>), S<sub>K</sub> &#x003D; h (h (ID<sub>u</sub>&#x007C;&#x007C;r<sub>u1</sub>)&#x007C;&#x007C;h(ID<sub>e</sub>&#x007C;&#x007C;r<sub>e</sub>)&#x007C;&#x007C;h(ID<sub>w</sub>&#x007C;&#x007C;r<sub>e</sub>), N<sub>4&#x2009;</sub>&#x003D;&#x2009;h (X<sub>w</sub>&#x007C;&#x007C;V &#x007C;&#x007C;r<sub>w</sub>)<inline-formula id="ieqn-32"><mml:math id="mml-ieqn-32"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;&#x00A0;</mml:mtext></mml:math></inline-formula>h(ID<sub>w</sub>&#x007C;&#x007C;r<sub>w1</sub>), F<sub>w</sub> &#x003D; h (X<sub>u</sub>&#x007C;&#x007C;X<sub>w</sub>&#x007C;&#x007C;N<sub>2</sub><sup>&#x002A;</sup>&#x007C;&#x007C;h(ID<sub>w</sub>&#x007C;&#x007C;r<sub>w1</sub>)&#x007C;&#x007C;V) and send M3&#x2009;&#x003D;&#x2009;&#x007B;F<sub>w</sub>, N<sub>4</sub>&#x007D; to edge server back.</p></list-item>
<list-item><p>The edge server calculates h(ID<sub>w</sub>&#x007C;&#x007C;r<sub>w1</sub>) &#x003D; h(X<sub>w</sub>&#x007C;&#x007C;V&#x007C;&#x007C;r<sub>w</sub>)<inline-formula id="ieqn-33"><mml:math id="mml-ieqn-33"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;&#x00A0;</mml:mtext></mml:math></inline-formula>N<sub>4</sub>, F<sub>w</sub><sup>&#x002A;</sup>&#x2009;&#x003D;&#x2009;h(X<sub>u</sub>&#x007C;&#x007C;X<sub>w</sub>&#x007C;&#x007C;N<sub>2</sub>&#x007C;&#x007C;h(ID<sub>w</sub>&#x007C;&#x007C;r<sub>w1</sub>&#x007C;&#x007C;V) and check F<sub>w</sub><sup>&#x002A;</sup>? &#x003D; F<sub>w</sub>. If it corrects the proceed further otherwise terminate connection. The edge server further calculates S<sub>K</sub>&#x2009;&#x003D;&#x2009;h(h(ID<sub>u</sub>&#x007C;&#x007C;r<sub>u1</sub>)&#x007C;&#x007C;h(ID<sub>e</sub>&#x007C;&#x007C;r<sub>e</sub>)&#x007C;&#x007C;h(ID<sub>w</sub>&#x007C;&#x007C;r<sub>w1</sub>), X<sub>u</sub><sup>new</sup>&#x2009;&#x003D;&#x2009;h(X<sub>u</sub>&#x007C;&#x007C;r<sub>u1</sub>), XID<sub>u</sub><sup>new</sup> &#x003D; h (X<sub>u</sub><sup>new</sup>&#x007C;&#x007C;V), N<sub>5&#x2009;</sub>&#x003D;&#x2009;h (XID<sub>u</sub>&#x007C;&#x007C;r<sub>u1</sub>) <inline-formula id="ieqn-34"><mml:math id="mml-ieqn-34"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;&#x00A0;</mml:mtext></mml:math></inline-formula> (h(ID<sub>e</sub>&#x007C;&#x007C;r<sub>e</sub>)&#x007C;&#x007C;h(ID<sub>w</sub>&#x007C;&#x007C;r<sub>w1</sub>)&#x007C;&#x007C;X<sub>u</sub><sup>new</sup>, and F<sub>ec</sub> &#x003D; h (X<sub>u</sub>&#x007C;&#x007C;r<sub>u1</sub>)&#x007C;&#x007C;h (ID<sub>e</sub>&#x007C;&#x007C;r<sub>e</sub>) &#x007C;&#x007C;h(ID<sub>w</sub>&#x007C;&#x007C;r<sub>w1</sub>)&#x007C;&#x007C;X<sub>u</sub><sup>new</sup>&#x007C;&#x007C;V). The edge server store &#x007B;X<sub>u</sub><sup>new</sup>, XID<sub>u</sub><sup>new</sup>&#x007D; and send M4 &#x003D; &#x007B;F<sub>ec</sub>, N<sub>5</sub>&#x007D; towards user.</p></list-item>
<list-item><p>The user calculates X<sub>u</sub><sup>new</sup>&#x2009;&#x003D;&#x2009;h(X<sub>u</sub>&#x007C;&#x007C;r<sub>u1</sub>), (h(ID<sub>e</sub>&#x007C;&#x007C;r<sub>e</sub>) &#x007C;&#x007C;h(ID<sub>w</sub>&#x007C;&#x007C;r<sub>w1</sub>) &#x007C;&#x007C;X<sub>u</sub><sup>new</sup>&#x2009;&#x003D;&#x2009;h(XID<sub>u</sub>&#x007C;&#x007C;r<sub>u1</sub>)<inline-formula id="ieqn-35"><mml:math id="mml-ieqn-35"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;&#x00A0;</mml:mtext></mml:math></inline-formula>N<sub>5</sub>, and F<sub>ec</sub><sup>&#x002A;</sup>&#x2009;&#x003D; h (Xu &#x007C;&#x007C;r<sub>u1</sub>)&#x007C;&#x007C;h(ID<sub>e</sub>&#x007C;&#x007C;r<sub>e</sub>) &#x007C;&#x007C;h(ID<sub>w</sub>&#x007C;&#x007C;r<sub>w1</sub>)&#x007C;&#x007C;X<sub>u</sub><sup>new</sup>&#x007C;&#x007C;V). The user Check F<sub>ec</sub><sup>&#x002A;</sup>? &#x003D; F<sub>ec</sub> and if it is correct then proceed further otherwise terminate connection. The user further calculates S<sub>K</sub> &#x003D; h (h(ID<sub>u</sub>&#x007C;&#x007C;r<sub>u</sub>)&#x007C;&#x007C;h (ID<sub>e</sub>&#x007C;&#x007C;r<sub>e</sub>) &#x007C;&#x007C;h(ID<sub>w</sub>&#x007C;&#x007C;r<sub>w1</sub>), XID<sub>u</sub><sup>new</sup> &#x003D; h(X<sub>u</sub><sup>new</sup>&#x007C;&#x007C;V), B<sub>3</sub><sup>new</sup>&#x2009;&#x003D;&#x2009;h(XID<sub>u</sub><sup>new</sup>&#x007C;&#x007C;HPW<sub>u</sub>)<inline-formula id="ieqn-36"><mml:math id="mml-ieqn-36"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;&#x00A0;</mml:mtext></mml:math></inline-formula> XID<sub>u</sub><sup>new</sup>, and B<sub>4</sub><sup>new</sup> &#x003D; h (XID<sub>u</sub><sup>new</sup>&#x007C;&#x007C;HPW<sub>u</sub>)<inline-formula id="ieqn-37"><mml:math id="mml-ieqn-37"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;&#x00A0;</mml:mtext></mml:math></inline-formula>V<sub>1</sub>. The user update &#x007B;B<sub>3</sub><sup>new</sup>, B<sub>4</sub><sup>new</sup>, X<sub>u</sub><sup>new</sup>&#x007D; and compute N<sub>6</sub>&#x2009;&#x003D;&#x2009;h(S<sub>K</sub>&#x007C;&#x007C;X<sub>u</sub><sup>new</sup>). The user sends M5 &#x003D; &#x007B;N<sub>6</sub>&#x007D; towards edge server.</p></list-item>
<list-item><p>The edge server N<sub>6</sub><sup>&#x002A;</sup>&#x2009;&#x003D;&#x2009;h(S<sub>K</sub>&#x007C;&#x007C;X<sub>u</sub><sup>new</sup>) and check N<sub>6</sub><sup>&#x002A;</sup>? &#x003D; N<sub>6</sub>. After calculations, the edge server deletes &#x007B;XID<sub>u</sub>, X<sub>u</sub>&#x007D; <xref ref-type="table" rid="table-3">Table 3</xref>. Further details are given in <xref ref-type="table" rid="table-4">Table 4</xref>.</p>
</list-item>
</list></p>
<table-wrap id="table-3"><label>Table 3</label><caption><title>User registration</title></caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left">User (u)</th>
<th align="left">Registration Server (RS)</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left" colspan="2">Select identity ID<sub>u</sub></td>
</tr>
<tr>
<td align="left" colspan="2">Generate random number r<sub>u</sub></td>
</tr>
<tr>
<td align="left" colspan="2">Computes:</td>
</tr>
<tr>
<td align="left" colspan="2">X<sub>u</sub> &#x003D; h(ID<sub>u</sub>&#x007C;&#x007C;r<sub>u</sub>)</td>
</tr>
<tr>
<td align="left" colspan="2">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;<inline-formula id="ieqn-38"><mml:math id="mml-ieqn-38"><mml:munder><mml:mrow><mml:mrow><mml:mtext>RM3</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:msub><mml:mrow><mml:mtext>X</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>u</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>}</mml:mo></mml:mrow></mml:mrow><mml:mo stretchy="false">&#x27F6;</mml:mo></mml:munder></mml:math></inline-formula></td>
</tr>
<tr>
<td align="left" colspan="2">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;Computes:</td>
</tr>
<tr>
<td align="left" colspan="2">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;V<sub>1&#x2009;</sub>&#x003D;&#x2009;h(X<sub>u</sub>&#x007C;&#x007C;SK<sub>rs</sub>&#x007C;&#x007C;r<sub>rs</sub>)</td>
</tr>
<tr>
<td align="left" colspan="2">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;XID<sub>u</sub> &#x003D; h(X<sub>u</sub>&#x007C;&#x007C;V<sub>1</sub>)</td>
</tr>
<tr>
<td align="left" colspan="2">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;Store &#x007B;X<sub>u</sub>, XID<sub>u</sub>, V<sub>1</sub>&#x007D; in edge server database</td>
</tr>
<tr>
<td align="left" colspan="2">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;<inline-formula id="ieqn-39"><mml:math id="mml-ieqn-39"><mml:munder><mml:mrow><mml:mrow><mml:mtext>RM4</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:msub><mml:mrow><mml:mtext>V</mml:mtext></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mtext>XID</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>u</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>}</mml:mo></mml:mrow></mml:mrow><mml:mo stretchy="false">&#x27F5;</mml:mo></mml:munder></mml:math></inline-formula></td>
</tr>
<tr>
<td align="left" colspan="2">Choose password</td>
</tr>
<tr>
<td align="left" colspan="2">PW<sub>u</sub></td>
</tr>
<tr>
<td align="left" colspan="2">Computes:</td>
</tr>
<tr>
<td align="left" colspan="2">HPW<sub>u</sub> &#x003D; h(PW<sub>u</sub>&#x007C;&#x007C;r<sub>u</sub>)</td>
</tr>
<tr>
<td align="left" colspan="2">B<sub>1&#x2009;</sub>&#x003D;&#x2009;h(ID<sub>u</sub>&#x007C;&#x007C;PW<sub>u</sub>) <inline-formula id="ieqn-40"><mml:math id="mml-ieqn-40"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula> r<sub>u</sub></td>
</tr>
<tr>
<td align="left" colspan="2">B<sub>2&#x2009;</sub>&#x003D;&#x2009;h(ID<sub>u</sub>&#x007C;&#x007C;PW<sub>u</sub>&#x007C;&#x007C;r<sub>u</sub>&#x007C;&#x007C;HPW<sub>u</sub>)</td>
</tr>
<tr>
<td align="left" colspan="2">B<sub>3&#x2009;</sub>&#x003D;&#x2009;h(HPW<sub>u</sub>&#x007C;&#x007C;r<sub>u</sub>)<inline-formula id="ieqn-41"><mml:math id="mml-ieqn-41"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula> XID<sub>u</sub></td>
</tr>
<tr>
<td align="left" colspan="2">B<sub>4&#x2009;</sub>&#x003D;&#x2009;h(HPW<sub>u</sub>&#x007C;&#x007C;XID<sub>u</sub>)<inline-formula id="ieqn-42"><mml:math id="mml-ieqn-42"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula> V<sub>1</sub></td>
</tr>
<tr>
<td align="left" colspan="2">Store &#x007B;X<sub>u</sub>, B<sub>1</sub>, B<sub>2</sub>, B<sub>3</sub>, B<sub>4</sub>&#x007D;</td>
</tr>
</tbody>
</table>
</table-wrap>
<table-wrap id="table-4"><label>Table 4</label><caption><title>Login and authentication phase</title></caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left">User</th>
<th align="left">Edge server</th>
<th align="left">IoT-enable sensor node</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left" colspan="3">Input ID<sub>u</sub>, PW<sub>u</sub></td>
</tr>
<tr>
<td align="left" colspan="3">Calculate:</td>
</tr>
<tr>
<td align="left" colspan="3">r<sub>u</sub> &#x003D; h(ID<sub>u</sub>&#x007C;&#x007C;PW<sub>u</sub>)<inline-formula id="ieqn-43"><mml:math id="mml-ieqn-43"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula> B<sub>1</sub></td>
</tr>
<tr>
<td align="left" colspan="3">HPW<sub>u</sub> &#x003D; h(PW<sub>u</sub>&#x007C;&#x007C;r<sub>u</sub>)</td>
</tr>
<tr>
<td align="left" colspan="3">B<sub>2</sub><sup>&#x002A;</sup>&#x003D; h(ID<sub>u</sub>&#x007C;&#x007C;PW<sub>u</sub>&#x007C;&#x007C;r<sub>u</sub>&#x007C;&#x007C;HPW<sub>u</sub>)</td>
</tr>
<tr>
<td align="left" colspan="3">Check B<sub>2</sub><sup>&#x002A;</sup>? &#x003D; B<sub>2</sub></td>
</tr>
<tr>
<td align="left" colspan="3">Generate random number r<sub>u1</sub></td>
</tr>
<tr>
<td align="left" colspan="3">Computes:</td>
</tr>
<tr>
<td align="left" colspan="3">XID<sub>u</sub> &#x003D; h(HPW<sub>u</sub>&#x007C;&#x007C;r<sub>u</sub>) <inline-formula id="ieqn-44"><mml:math id="mml-ieqn-44"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula> B<sub>3</sub></td>
</tr>
<tr>
<td align="left" colspan="3">V<sub>1</sub> &#x003D; h(HPW<sub>u</sub>&#x007C;&#x007C;XID<sub>u</sub>)<inline-formula id="ieqn-45"><mml:math id="mml-ieqn-45"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula> B<sub>4</sub></td>
</tr>
<tr>
<td align="left" colspan="3">N &#x003D; h(X<sub>u</sub>&#x007C;&#x007C;XID<sub>u</sub>&#x007C;&#x007C;V<sub>1</sub>)<inline-formula id="ieqn-46"><mml:math id="mml-ieqn-46"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula> (X<sub>u</sub>&#x007C;&#x007C;r<sub>u1</sub>)</td>
</tr>
<tr>
<td align="left" colspan="3">D &#x003D; h(ID<sub>u</sub>&#x007C;&#x007C;r<sub>u</sub>) <inline-formula id="ieqn-47"><mml:math id="mml-ieqn-47"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula> h(V<sub>1</sub>&#x007C;&#x007C;r<sub>u1</sub>)</td>
</tr>
<tr>
<td align="left" colspan="3">F<sub>u</sub> &#x003D; h(X<sub>u</sub>&#x007C;&#x007C;XID<sub>u</sub>&#x007C;&#x007C;r<sub>u1</sub>&#x007C;&#x007C;X<sub>w</sub>&#x007C;&#x007C;V<sub>1</sub>)&#x2002;&#x2002;&#x2002;&#x2002;Corresponding to X<sub>u</sub>, the XID<sub>u</sub> and V<sub>1</sub> are retrieved</td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;<inline-formula id="ieqn-48"><mml:math id="mml-ieqn-48"><mml:munder><mml:mrow><mml:mrow><mml:mtext>M1</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:mrow><mml:mtext>N</mml:mtext></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mtext>D</mml:mtext></mml:mrow><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mtext>F</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>u</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>X</mml:mi><mml:mrow><mml:mrow><mml:mtext>u</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>}</mml:mo></mml:mrow></mml:mrow><mml:mo stretchy="false">&#x27F6;</mml:mo></mml:munder></mml:math></inline-formula>&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;(X<sub>w</sub><sup>&#x002A;</sup>&#x007C;&#x007C;r<sub>u1</sub><sup>&#x002A;</sup>) &#x003D; h(X<sub>u</sub>&#x007C;&#x007C;XID<sub>u</sub>&#x007C;&#x007C;V<sub>1</sub>)</td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;F<sub>u</sub><sup>&#x002A;</sup> &#x003D; h(X<sub>u</sub>&#x007C;&#x007C;XID<sub>u</sub>&#x007C;&#x007C;r<sub>u1</sub><sup>&#x002A;</sup>&#x007C;&#x007C;X<sub>w</sub><sup>&#x002A;</sup>&#x007C;&#x007C;V<sub>1</sub>)</td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;Check F<sub>u</sub><sup>&#x002A;</sup>? &#x003D; F<sub>u</sub></td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;Generate random number r<sub>e</sub></td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;Calculates:</td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;N<sub>2</sub> &#x003D; h(r<sub>e</sub>&#x007C;&#x007C;r<sub>u1</sub>)</td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;N<sub>3</sub> &#x003D; h(X<sub>w</sub>&#x007C;&#x007C;V&#x007C;&#x007C;r<sub>w</sub>)<inline-formula id="ieqn-49"><mml:math id="mml-ieqn-49"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula> N<sub>2</sub></td>
</tr>
<tr>
<td align="left" colspan="2">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;h(ID<sub>u</sub>&#x007C;&#x007C;r<sub>u1</sub>) &#x003D; E<sub>1</sub><inline-formula id="ieqn-50"><mml:math id="mml-ieqn-50"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula>h(V<sub>1</sub>&#x007C;&#x007C;r<sub>u1</sub>)</td>
<td/>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;E<sub>2</sub> &#x003D; (h(ID<sub>u</sub>&#x007C;&#x007C;r<sub>u1</sub>) &#x007C;&#x007C;h(ID<sub>e</sub>&#x007C;&#x007C;r<sub>e</sub>))<inline-formula id="ieqn-51"><mml:math id="mml-ieqn-51"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula>h(V&#x007C;&#x007C;r<sub>w</sub>)</td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;F<sub>e</sub> &#x003D; h(X<sub>u</sub>&#x007C;&#x007C;N<sub>2</sub>&#x007C;&#x007C;V)</td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;<inline-formula id="ieqn-52"><mml:math id="mml-ieqn-52"><mml:munder><mml:mrow><mml:mrow><mml:mtext>M2</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:msub><mml:mrow><mml:mtext>X</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>u</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mtext>N</mml:mtext></mml:mrow><mml:mrow><mml:mn>3</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mtext>E</mml:mtext></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mrow><mml:mtext>Fe</mml:mtext></mml:mrow><mml:mo>}</mml:mo></mml:mrow></mml:mrow><mml:mo stretchy="false">&#x27F6;</mml:mo></mml:munder></mml:math></inline-formula>&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;Calculates:</td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;r<sub>w</sub> &#x003D; h(ID<sub>w</sub>&#x007C;&#x007C;PK<sub>w</sub>)</td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;V &#x003D; h(r<sub>w</sub>&#x007C;&#x007C;PK<sub>w</sub>)<inline-formula id="ieqn-53"><mml:math id="mml-ieqn-53"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula>S<sub>2</sub></td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;N<sub>2</sub><sup>&#x002A;</sup> &#x003D; h(X<sub>w</sub>&#x007C;&#x007C;V&#x007C;&#x007C;r<sub>w</sub>)<inline-formula id="ieqn-54"><mml:math id="mml-ieqn-54"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula>N<sub>3</sub></td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;F<sub>e</sub><sup>&#x002A;</sup> &#x003D; h(X<sub>u</sub>&#x007C;&#x007C;N<sub>2</sub><sup>&#x002A;</sup>&#x007C;&#x007C;V)</td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;Check F<sub>e</sub><sup>&#x002A;</sup>? &#x003D; F<sub>e</sub></td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;Generate random number r<sub>w1</sub></td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;Calculates:</td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;(h(ID<sub>u</sub>&#x007C;&#x007C;r<sub>u1</sub>) &#x007C;&#x007C;h(ID<sub>e</sub>&#x007C;&#x007C;r<sub>e</sub>)) &#x003D;</td></tr> 
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;E<sub>2</sub><inline-formula id="ieqn-55"><mml:math id="mml-ieqn-55"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula>h(V&#x007C;&#x007C;r<sub>w</sub>)</td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;S<sub>K</sub> &#x003D; h(h(ID<sub>u</sub>&#x007C;&#x007C;r<sub>u1</sub>) &#x007C;&#x007C;h(ID<sub>e</sub>&#x007C;&#x007C;r<sub>e</sub>)</td></tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002; &#x007C;&#x007C;h(ID<sub>w</sub>&#x007C;&#x007C;r<sub>e</sub>)</td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;N<sub>4</sub> &#x003D; h(X<sub>w</sub>&#x007C;&#x007C;V&#x007C;&#x007C;r<sub>w</sub>)<inline-formula id="ieqn-56"><mml:math id="mml-ieqn-56"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula>h(ID<sub>w</sub>&#x007C;&#x007C;</td></tr> <tr><td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;r<sub>w1</sub>)</td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;F<sub>w</sub> &#x003D; h(X<sub>u</sub>&#x007C;&#x007C;X<sub>w</sub>&#x007C;&#x007C;N<sub>2</sub><sup>&#x002A;</sup>&#x007C;&#x007C;h(ID<sub>w</sub></td></tr> <tr><td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x007C;&#x007C;r<sub>w1</sub>) &#x007C;&#x007C;V)</td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;<inline-formula id="ieqn-57"><mml:math id="mml-ieqn-57"><mml:munder><mml:mrow><mml:mrow><mml:mtext>M3</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:msub><mml:mrow><mml:mtext>F</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>w</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mtext>N</mml:mtext></mml:mrow><mml:mrow><mml:mn>4</mml:mn></mml:mrow></mml:msub><mml:mo>}</mml:mo></mml:mrow></mml:mrow><mml:mo stretchy="false">&#x27F5;</mml:mo></mml:munder></mml:math></inline-formula></td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;h(ID<sub>w</sub>&#x007C;&#x007C;r<sub>w1</sub>) &#x003D; h(X<sub>w</sub>&#x007C;&#x007C;V&#x007C;&#x007C;r<sub>w</sub>)<inline-formula id="ieqn-58"><mml:math id="mml-ieqn-58"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula>N<sub>4</sub></td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;F<sub>w</sub><sup>&#x002A;</sup> &#x003D; h(X<sub>u</sub>&#x007C;&#x007C;X<sub>w</sub>&#x007C;&#x007C;N<sub>2</sub>&#x007C;&#x007C;h(ID<sub>w</sub>&#x007C;&#x007C;r<sub>w1</sub>&#x007C;&#x007C;V)</td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;Check F<sub>w</sub><sup>&#x002A;</sup>? &#x003D; F<sub>w</sub></td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;Computes:</td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;S<sub>K</sub> &#x003D; h(h(ID<sub>u</sub>&#x007C;&#x007C;r<sub>u1</sub>) &#x007C;&#x007C;h(ID<sub>e</sub>&#x007C;&#x007C;r<sub>e</sub>) &#x007C;&#x007C;h(ID<sub>w</sub>&#x007C;&#x007C;r<sub>w1</sub>)</td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;X<sub>u</sub><sup>new</sup> &#x003D; h(X<sub>u</sub>&#x007C;&#x007C;r<sub>u1</sub>)</td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;XID<sub>u</sub><sup>new</sup> &#x003D; h(X<sub>u</sub><sup>new</sup>&#x007C;&#x007C;V)</td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;N<sub>5</sub> &#x003D; h(XID<sub>u</sub>&#x007C;&#x007C;r<sub>u1</sub>)<inline-formula id="ieqn-59"><mml:math id="mml-ieqn-59"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula>(h(ID<sub>e</sub>&#x007C;&#x007C;r<sub>e</sub>) &#x007C;&#x007C;h(ID<sub>w</sub>&#x007C;&#x007C;r<sub>w1</sub>) &#x007C;&#x007C;X<sub>u</sub><sup>new</sup></td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;F<sub>ec</sub> &#x003D; h(X<sub>u</sub>&#x007C;&#x007C;r<sub>u1</sub>) &#x007C;&#x007C;h(ID<sub>e</sub>&#x007C;&#x007C;r<sub>e</sub>) &#x007C;&#x007C;h(ID<sub>w</sub>&#x007C;&#x007C;r<sub>w1</sub>) &#x007C;&#x007C;X<sub>u</sub><sup>new</sup>&#x007C;&#x007C;V)</td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;Store &#x007B;X<sub>u</sub><sup>new</sup>, XID<sub>u</sub><sup>new</sup>&#x007D; in edge server</td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;<inline-formula id="ieqn-60"><mml:math id="mml-ieqn-60"><mml:munder><mml:mrow><mml:mrow><mml:mtext>M4</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:msub><mml:mrow><mml:mtext>F</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>ec</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mtext>N</mml:mtext></mml:mrow><mml:mrow><mml:mn>5</mml:mn></mml:mrow></mml:msub><mml:mo>}</mml:mo></mml:mrow></mml:mrow><mml:mo stretchy="false">&#x27F5;</mml:mo></mml:munder></mml:math></inline-formula></td>
</tr>
<tr>
<td align="left" colspan="3">Calculates:</td>
</tr>
<tr>
<td align="left" colspan="3">X<sub>u</sub><sup>new</sup> &#x003D; h(X<sub>u</sub>&#x007C;&#x007C;r<sub>u1</sub>)</td>
</tr>
<tr>
<td align="left" colspan="3">(h(ID<sub>e</sub>&#x007C;&#x007C;r<sub>e</sub>) &#x007C;&#x007C;h(ID<sub>w</sub>&#x007C;&#x007C;r<sub>w1</sub>) &#x007C;&#x007C;X<sub>u</sub><sup>new</sup> &#x003D; h(XID<sub>u</sub>&#x007C;&#x007C;r<sub>u1</sub>)<inline-formula id="ieqn-61"><mml:math id="mml-ieqn-61"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula>N<sub>5</sub></td>
</tr>
<tr>
<td align="left" colspan="3">F<sub>ec</sub><sup>&#x002A;</sup> &#x003D; h(X<sub>u</sub>&#x007C;&#x007C;r<sub>u1</sub>) &#x007C;&#x007C;h(ID<sub>e</sub>&#x007C;&#x007C;r<sub>e</sub>) &#x007C;&#x007C;h(ID<sub>w</sub>&#x007C;&#x007C;r<sub>w1</sub>) &#x007C;&#x007C;X<sub>u</sub><sup>new</sup>&#x007C;&#x007C;V)</td>
</tr>
<tr>
<td align="left" colspan="3">Check F<sub>ec</sub><sup>&#x002A;</sup>? &#x003D; F<sub>ec</sub></td>
</tr>
<tr>
<td align="left" colspan="3">Calculates:</td>
</tr>
<tr>
<td align="left" colspan="3">S<sub>K</sub> &#x003D; h(h(ID<sub>u</sub>&#x007C;&#x007C;r<sub>u</sub>) &#x007C;&#x007C;h(ID<sub>e</sub>&#x007C;&#x007C;r<sub>e</sub>) &#x007C;&#x007C;h(ID<sub>w</sub>&#x007C;&#x007C;r<sub>w1</sub>)</td>
</tr>
<tr>
<td align="left" colspan="3">XID<sub>u</sub><sup>new</sup> &#x003D; h(X<sub>u</sub><sup>new</sup>&#x007C;&#x007C;V)</td>
</tr>
<tr>
<td align="left" colspan="3">B<sub>3</sub><sup>new</sup> &#x003D; h(XID<sub>u</sub><sup>new</sup>&#x007C;&#x007C;HPW<sub>u</sub>)<inline-formula id="ieqn-62"><mml:math id="mml-ieqn-62"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula> XID<sub>u</sub><sup>new</sup></td>
</tr>
<tr>
<td align="left" colspan="3">B<sub>4</sub><sup>new</sup> &#x003D; h(XID<sub>u</sub><sup>new</sup>&#x007C;&#x007C;HPW<sub>u</sub>)<inline-formula id="ieqn-63"><mml:math id="mml-ieqn-63"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula>V<sub>1</sub></td>
</tr>
<tr>
<td align="left" colspan="3">Updates &#x007B;B<sub>3</sub><sup>new</sup>, B<sub>4</sub><sup>new</sup>, X<sub>u</sub><sup>new</sup>&#x007D;</td>
</tr>
<tr>
<td align="left" colspan="3">Computes:</td>
</tr>
<tr>
<td align="left" colspan="3">N<sub>6</sub> &#x003D; h(S<sub>K</sub>&#x007C;&#x007C;X<sub>u</sub><sup>new</sup>)</td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;<inline-formula id="ieqn-64"><mml:math id="mml-ieqn-64"><mml:munder><mml:mrow><mml:mrow><mml:mtext>M5</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:msub><mml:mrow><mml:mtext>N</mml:mtext></mml:mrow><mml:mrow><mml:mn>6</mml:mn></mml:mrow></mml:msub><mml:mo>}</mml:mo></mml:mrow></mml:mrow><mml:mo stretchy="false">&#x27F6;</mml:mo></mml:munder></mml:math></inline-formula></td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;N<sub>6</sub><sup>&#x002A;</sup> &#x003D; h(S<sub>K</sub>&#x007C;&#x007C;X<sub>u</sub><sup>new</sup>)</td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;Check N<sub>6</sub><sup>&#x002A;</sup>? &#x003D; N<sub>6</sub></td>
</tr>
<tr>
<td align="left" colspan="3">&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;&#x2002;Delete &#x007B;XID<sub>u</sub>, X<sub>u</sub>&#x007D;</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s3_4"><label>3.4</label><title>Password Change Phase</title>
<p>
<list list-type="roman-lower">
<list-item><p>The user enters their identity ID<sub>u</sub> and password PW<sub>u</sub>.</p></list-item>
<list-item><p>After input ID<sub>u</sub> and PW<sub>u</sub>, the device computes HPW<sub>u</sub> &#x003D; h(PW<sub>u</sub>&#x007C;&#x007C;r<sub>u</sub>), B<sub>1&#x2009;</sub>&#x003D;&#x2009;h(ID<sub>u</sub>&#x007C;&#x007C;PW<sub>u</sub>) <inline-formula id="ieqn-65"><mml:math id="mml-ieqn-65"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;&#x00A0;</mml:mtext></mml:math></inline-formula> r<sub>u</sub>, B<sub>2&#x2009;</sub>&#x003D;&#x2009;h(ID<sub>u</sub>&#x007C;&#x007C;PW<sub>u</sub>&#x007C;&#x007C;r<sub>u</sub>&#x007C;&#x007C;HPW<sub>u</sub>), B<sub>3&#x2009;</sub>&#x003D;&#x2009;h(HPW<sub>u</sub>&#x007C;&#x007C;r<sub>u</sub>)<inline-formula id="ieqn-66"><mml:math id="mml-ieqn-66"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;&#x00A0;</mml:mtext></mml:math></inline-formula> XID<sub>u</sub>, B<sub>4&#x2009;</sub>&#x003D;&#x2009;h (HPW<sub>u</sub>&#x007C;&#x007C;XID<sub>u</sub>)<inline-formula id="ieqn-67"><mml:math id="mml-ieqn-67"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;&#x00A0;</mml:mtext></mml:math></inline-formula> V<sub>1</sub>&#x00B8; r<sub>u</sub> &#x003D; h(ID<sub>u</sub>&#x007C;&#x007C;PW<sub>u</sub>)<inline-formula id="ieqn-68"><mml:math id="mml-ieqn-68"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;&#x00A0;</mml:mtext></mml:math></inline-formula> B<sub>1</sub>, and B<sub>2</sub><sup>&#x002A;</sup> &#x003D; h(ID<sub>u</sub>&#x007C;&#x007C;PW<sub>u</sub>&#x007C;&#x007C;r<sub>u</sub>&#x007C;&#x007C;HPW<sub>u</sub>). Then check B<sub>2</sub><sup>&#x002A;</sup>? &#x003D; B<sub>2</sub> and proceed further if correct otherwise terminate connection.</p></list-item>
<list-item><p>The user inputs a new password PW<sub>u</sub><sup>new</sup>.</p></list-item>
<list-item><p>After input new password then update the values of HPW<sub>u</sub><sup>&#x002A;</sup> &#x003D; h(PW<sub>u</sub><sup>new</sup>&#x007C;&#x007C;r<sub>u</sub>), B<sub>1</sub><sup>&#x002A;</sup> &#x003D; h (ID<sub>u</sub>&#x007C;&#x007C; PW<sub>u</sub><sup>new</sup>) <inline-formula id="ieqn-69"><mml:math id="mml-ieqn-69"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;&#x00A0;</mml:mtext></mml:math></inline-formula> r<sub>u</sub>, B<sub>2</sub><sup>&#x002A;&#x002A;</sup> &#x003D; h(ID<sub>u</sub>&#x007C;&#x007C;PW<sub>u</sub><sup>new</sup>&#x007C;&#x007C;r<sub>u</sub>&#x007C;&#x007C;HPW<sub>u</sub><sup>&#x002A;</sup>), B<sub>3</sub><sup>&#x002A;</sup> &#x003D; h(HPW<sub>u</sub><sup>&#x002A;</sup>&#x007C;&#x007C;r<sub>u</sub>)<inline-formula id="ieqn-70"><mml:math id="mml-ieqn-70"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;&#x00A0;</mml:mtext></mml:math></inline-formula> XID<sub>u</sub>, B<sub>4</sub><sup>&#x002A;</sup> &#x003D; h (HPW<sub>u</sub><sup>&#x002A;</sup> &#x007C;&#x007C;XID<sub>u</sub>)<inline-formula id="ieqn-71"><mml:math id="mml-ieqn-71"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;&#x00A0;</mml:mtext></mml:math></inline-formula> V<sub>1</sub>&#x00B8; r<sub>u</sub><sup>&#x002A;</sup> &#x003D; h(ID<sub>u</sub>&#x007C;&#x007C;PW<sub>u</sub><sup>new</sup>)<inline-formula id="ieqn-72"><mml:math id="mml-ieqn-72"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;&#x00A0;</mml:mtext></mml:math></inline-formula> B<sub>1</sub><sup>&#x002A;</sup>, B<sub>2</sub><sup>&#x002A;&#x002A;&#x002A;</sup> &#x003D; h(ID<sub>u</sub>&#x007C;&#x007C;PW<sub>u</sub><sup>new</sup>&#x007C;&#x007C;r<sub>u</sub>&#x007C;&#x007C;HPW<sub>u</sub><sup>&#x002A;</sup>) and update &#x007B;HPW<sub>u</sub><sup>&#x002A;</sup>, B<sub>1</sub><sup>&#x002A;</sup>, B<sub>2</sub><sup>&#x002A;&#x002A;</sup>, B<sub>3</sub><sup>&#x002A;</sup>, B<sub>4</sub><sup>&#x002A;</sup> B<sub>2</sub><sup>&#x002A;&#x002A;&#x002A;</sup>&#x007D;.</p></list-item>
</list></p>
</sec>
</sec>
<sec id="s4"><label>4</label><title>Security Analysis</title>
<p>This section analyzed and critiqued the proposed scheme&#x2019;s security using two distinct methodologies. Firstly, we utilized Real-or-Random (ROR) model to determine the security of our session key SK. Furthermore, we used the ProVerif simulation toolkit to demonstrate that the session secret is secure. Finally, further details are given below.</p>
<sec id="s4_1"><label>4.1</label><title>Formal Security Analysis Using Real-or-Random (ROR) Model</title>
<p>We used the ROR model [<xref ref-type="bibr" rid="ref-11">11</xref>] to demonstrate our proposed scheme&#x2019;s session key security <italic>SK</italic>. In our proposed scheme login and authentication phase, we have three participants <italic>P<sup>t</sup></italic>, user <italic>P<sup>t</sup><sub>u</sub></italic>, edge server <italic>P<sup>t</sup><sub>e</sub></italic>, and IoT-enable sensor node <italic>P<sup>t</sup><sub>w</sub></italic>. The <inline-formula id="ieqn-73"><mml:math id="mml-ieqn-73"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> has the ability to intercept, manipulate, and eavesdrop on data delivered across an unsecured connection. The <inline-formula id="ieqn-74"><mml:math id="mml-ieqn-74"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> may attack actively or passively by executing various queries outlined in the ROR model, including CorruptedMD, Executive, Send, Reveal, and Test queries. The exact instructions for these queries are included below:
<list list-type="bullet">
<list-item><p>CorruptedMD (<italic>P<sup>t</sup><sub>u</sub></italic>): The <inline-formula id="ieqn-75"><mml:math id="mml-ieqn-75"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> can obtain secret information stored on the user side.</p></list-item>
<list-item><p>Executive (<italic>P<sup>t</sup><sub>u</sub>, P<sup>t</sup><sub>e</sub>, P<sup>t</sup><sub>w</sub></italic>): The <inline-formula id="ieqn-76"><mml:math id="mml-ieqn-76"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> can capture transmitted data over an insecure channel among users, edge servers, and IoT-enable sensor nodes.</p></list-item>
<list-item><p>Send (<italic>P<sup>t</sup></italic>, <italic>m</italic>): The <inline-formula id="ieqn-77"><mml:math id="mml-ieqn-77"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> sends message m to <italic>P<sup>t</sup></italic><sup>,</sup> and <italic>P<sup>t</sup></italic> replies to <inline-formula id="ieqn-78"><mml:math id="mml-ieqn-78"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> according to the rule.</p></list-item>
<list-item><p>Reveal (<italic>P<sup>t</sup></italic>): The <inline-formula id="ieqn-79"><mml:math id="mml-ieqn-79"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> reveals the session key <italic>S<sub>K</sub></italic> between <italic>P<sup>t</sup><sub>u</sub></italic> and <italic>P<sup>t</sup><sub>w</sub></italic>. If the <inline-formula id="ieqn-80"><mml:math id="mml-ieqn-80"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> unable to reveal <italic>S<sub>K</sub></italic>, then it means that the session key is secure.</p></list-item>
<list-item><p>Test (<italic>P<sup>t</sup></italic>): The <inline-formula id="ieqn-81"><mml:math id="mml-ieqn-81"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> tossed a coin, and the result was only known to <inline-formula id="ieqn-82"><mml:math id="mml-ieqn-82"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula>. The <inline-formula id="ieqn-83"><mml:math id="mml-ieqn-83"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> uses the result to decide on the Test query and if <italic>S<sub>K</sub></italic> is fresh, then return <italic>1</italic> or <italic>0</italic>. Otherwise, return null.</p></list-item>
</list></p>
<p><italic>Theorem 1:</italic> The <inline-formula id="ieqn-84"><mml:math id="mml-ieqn-84"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> can access the session key security of our proposed scheme. The proof of Theorem 1 is similarly presented in [<xref ref-type="bibr" rid="ref-42">42</xref>]. The polynomial-time of <inline-formula id="ieqn-85"><mml:math id="mml-ieqn-85"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> as <italic>Adv</italic> <inline-formula id="ieqn-86"><mml:math id="mml-ieqn-86"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula>.
<disp-formula id="ueqn-1a">
<mml:math id="mml-ueqn-1a" display="block"><mml:mtext>&#x00A0;</mml:mtext><mml:mi>A</mml:mi><mml:mi>d</mml:mi><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>A</mml:mi></mml:mrow></mml:msub><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2264;</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mfrac><mml:mrow><mml:mi>q</mml:mi><mml:mn>2</mml:mn><mml:mi>h</mml:mi></mml:mrow><mml:mrow><mml:mo>|</mml:mo><mml:mi>H</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>h</mml:mi><mml:mo>|</mml:mo></mml:mrow></mml:mfrac><mml:mo>+</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:mi>c</mml:mi><mml:mo>.</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mi>q</mml:mi><mml:mn>2</mml:mn><mml:mi>s</mml:mi><mml:mi>e</mml:mi><mml:mi>n</mml:mi><mml:mi>d</mml:mi><mml:mo>}</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p><inline-formula id="ieqn-87"><mml:math id="mml-ieqn-87"><mml:mi>q</mml:mi><mml:mn>2</mml:mn><mml:mi>h</mml:mi></mml:math></inline-formula> denoted the number of hash queries, <italic>q<sub>send</sub></italic> is the number of send queries, and <italic>&#x007C;Hash&#x007C;</italic> is the range of hash function <italic>h(.)</italic> while c is a parameter from Zipf&#x2019;s law [<xref ref-type="bibr" rid="ref-43">43</xref>].</p>
<p><italic>Proof:</italic> We prove the session key security in four-game &#x201C;Game<sub>i</sub>&#x201D; where <italic>i</italic> <inline-formula id="ieqn-88"><mml:math id="mml-ieqn-88"><mml:mo>&#x2208;</mml:mo></mml:math></inline-formula> <italic>[0, 3].</italic> The <inline-formula id="ieqn-89"><mml:math id="mml-ieqn-89"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> use <italic>S<sub>A</sub>, i</italic> to win the <italic>Game<sub>i</sub></italic> by guessing the random bit fc correctly. <italic>Pr[S<sub>A</sub>, Game<sub>i</sub>]</italic> shows the advantage of <inline-formula id="ieqn-90"><mml:math id="mml-ieqn-90"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> to win <italic>Game<sub>i</sub></italic>. The games are described below:
<list list-type="roman-lower">
<list-item><p><italic>Game<sub>0</sub>:</italic> In this game, we allow the <inline-formula id="ieqn-91"><mml:math id="mml-ieqn-91"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> to launch an actual attack on our proposed scheme. The <inline-formula id="ieqn-92"><mml:math id="mml-ieqn-92"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> select random bit <italic>fc</italic> at the start of the Game<sub>0</sub>.
<disp-formula id="eqn-1"><label>(1)</label><mml:math id="mml-eqn-1" display="block"><mml:mi>A</mml:mi><mml:mi>d</mml:mi><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>A</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mn>2</mml:mn><mml:mtext>&#x00A0;</mml:mtext><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>A</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mi>G</mml:mi><mml:mi>A</mml:mi><mml:mi>M</mml:mi><mml:msub><mml:mi>E</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mstyle displaystyle="false" scriptlevel="0"><mml:mtext>&#x2013;</mml:mtext></mml:mstyle><mml:mtext>&#x00A0;</mml:mtext><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">|</mml:mo></mml:math></disp-formula></p></list-item>
<list-item><p><italic>Game<sub>1</sub>:</italic> The <inline-formula id="ieqn-93"><mml:math id="mml-ieqn-93"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> execute the Executive <italic>(P<sup>t</sup><sub>u</sub></italic>, <italic>P<sup>t</sup><sub>e</sub></italic>, <italic>P<sup>t</sup><sub>w</sub></italic>) queries and eavesdrops transmitted message &#x007B;<italic>N, D, F<sub>u</sub>, X<sub>u</sub></italic>&#x007D;, &#x007B;<italic>X<sub>u</sub>, N<sub>3</sub>, E<sub>2,</sub> F<sub>e</sub></italic>&#x007D;, &#x007B;<italic>F<sub>w</sub>, N<sub>4</sub></italic>&#x007D; and &#x007B;<italic>F<sub>ec</sub>, N<sub>5</sub></italic>&#x007D;. The <inline-formula id="ieqn-94"><mml:math id="mml-ieqn-94"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> run Reveal and Test queries to check whether the derived session key is real or not. Our proposed scheme session key is constructed as <italic>S<sub>K</sub> &#x003D; h(h(ID<sub>u</sub>&#x007C;&#x007C;r<sub>u1</sub>) &#x007C;&#x007C;h(ID<sub>e</sub>&#x007C;&#x007C;r<sub>e</sub>)&#x007C;&#x007C;h(ID<sub>w</sub>&#x007C;&#x007C;r<sub>w</sub>))</italic>. The <inline-formula id="ieqn-95"><mml:math id="mml-ieqn-95"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> needs random numbers and identities of a user, edge server, and IoT-enable sensor node. Therefore, the probability for <inline-formula id="ieqn-96"><mml:math id="mml-ieqn-96"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> is non to win the Game<sub>0</sub> and Game<sub>1</sub>. As a result of the paradox [<xref ref-type="bibr" rid="ref-44">44</xref>], we get the following result:
<disp-formula id="eqn-2"><label>(2)</label><mml:math id="mml-eqn-2" display="block"><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>A</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mi>G</mml:mi><mml:mi>A</mml:mi><mml:mi>M</mml:mi><mml:msub><mml:mi>E</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mrow><mml:mo>]</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mo>=</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mo>[</mml:mo></mml:mrow><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>A</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mi>G</mml:mi><mml:mi>A</mml:mi><mml:mi>M</mml:mi><mml:msub><mml:mi>E</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">]</mml:mo></mml:math></disp-formula></p></list-item>
<list-item><p><italic>Game<sub>2</sub>:</italic> The <inline-formula id="ieqn-97"><mml:math id="mml-ieqn-97"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> send and perform Hash to obtain the S<sub>K</sub>. The <inline-formula id="ieqn-98"><mml:math id="mml-ieqn-98"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> modify exchanged messages. However, our proposed scheme of exchange messages is constructed using a random number and secret keys and protected by <italic>h(.)</italic>, a one-way hash function. Therefore, we get the following result:
<disp-formula id="eqn-3"><label>(3)</label><mml:math id="mml-eqn-3" display="block"><mml:mrow><mml:mo>|</mml:mo><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mrow><mml:mo>[</mml:mo><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>A</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>G</mml:mi><mml:mi>A</mml:mi><mml:mi>M</mml:mi><mml:msub><mml:mi>E</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mrow><mml:mo>]</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mstyle displaystyle="false" scriptlevel="0"><mml:mtext>&#x2013;</mml:mtext></mml:mstyle><mml:mtext>&#x00A0;</mml:mtext><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mo>[</mml:mo></mml:mrow><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>A</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>G</mml:mi><mml:mi>A</mml:mi><mml:mi>M</mml:mi><mml:msub><mml:mi>E</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>]</mml:mo></mml:mrow><mml:mo>|</mml:mo></mml:mrow><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2264;</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mfrac><mml:mrow><mml:mi>q</mml:mi><mml:mn>2</mml:mn><mml:mi>h</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn><mml:mtext>&#x00A0;</mml:mtext><mml:mrow><mml:mo>|</mml:mo><mml:mi>H</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>h</mml:mi><mml:mo>|</mml:mo></mml:mrow></mml:mrow></mml:mfrac></mml:math></disp-formula></p></list-item>
<list-item><p><italic>Game<sub>3</sub>:</italic> In the last Game<sub>3</sub>, the <inline-formula id="ieqn-99"><mml:math id="mml-ieqn-99"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> tries to use the CorruptedMD query in order to obtain <italic>S<sub>K</sub></italic>. Using the CorruptedMD query, the <inline-formula id="ieqn-100"><mml:math id="mml-ieqn-100"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> can get &#x007B;<italic>B<sub>1</sub>, B<sub>2</sub>, B<sub>3</sub>, B<sub>4</sub></italic>&#x007D; stored on the user side. These values are expressed as <italic>B<sub>1</sub> &#x003D; h(ID<sub>u</sub>&#x007C;&#x007C;PW<sub>u</sub>)</italic><inline-formula id="ieqn-101"><mml:math id="mml-ieqn-101"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;&#x00A0;</mml:mtext></mml:math></inline-formula><italic>r<sub>u</sub>, B<sub>2</sub> &#x003D; h(ID<sub>u</sub>&#x007C;&#x007C;PW<sub>u</sub>&#x007C;&#x007C;r<sub>u</sub>&#x007C;&#x007C;HPW<sub>u</sub>), B<sub>3</sub> &#x003D; h(HPW<sub>u</sub>&#x007C;&#x007C;r<sub>u</sub>)</italic><inline-formula id="ieqn-102"><mml:math id="mml-ieqn-102"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;&#x00A0;</mml:mtext></mml:math></inline-formula><italic>XID<sub>u</sub></italic> and <italic>B<sub>4</sub> &#x003D; h(HPW<sub>u</sub>&#x007C;&#x007C; XID<sub>u</sub>)</italic><inline-formula id="ieqn-103"><mml:math id="mml-ieqn-103"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;&#x00A0;</mml:mtext></mml:math></inline-formula><italic>V<sub>1</sub></italic>. The <inline-formula id="ieqn-104"><mml:math id="mml-ieqn-104"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> cannot extract <italic>ID<sub>u</sub></italic>, <italic>PW<sub>u</sub></italic>, <italic>r<sub>u</sub></italic>, and <italic>V<sub>1</sub></italic> values. Therefore, we obtain
<disp-formula id="eqn-4"><label>(4)</label><mml:math id="mml-eqn-4" display="block"><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>A</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mi>G</mml:mi><mml:mi>A</mml:mi><mml:mi>M</mml:mi><mml:msub><mml:mi>E</mml:mi><mml:mrow><mml:mn>3</mml:mn></mml:mrow></mml:msub><mml:mrow><mml:mo>]</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mo>[</mml:mo></mml:mrow><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>A</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mi>G</mml:mi><mml:mi>A</mml:mi><mml:mi>M</mml:mi><mml:msub><mml:mi>E</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mo>&#x2264;</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mi>c</mml:mi><mml:mo>.</mml:mo><mml:msub><mml:mrow><mml:msup><mml:mi>q</mml:mi><mml:mrow><mml:mi>s</mml:mi></mml:mrow></mml:msup></mml:mrow><mml:mrow><mml:mi>s</mml:mi><mml:mi>e</mml:mi><mml:mi>n</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p></list-item>
</list></p>
<p>By running these games, the <inline-formula id="ieqn-105"><mml:math id="mml-ieqn-105"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> must guess the bit in order to win the game. Thus, we obtain
<disp-formula id="eqn-5"><label>(5)</label><mml:math id="mml-eqn-5" display="block"><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>A</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>G</mml:mi><mml:mi>A</mml:mi><mml:mi>M</mml:mi><mml:msub><mml:mi>E</mml:mi><mml:mrow><mml:mn>3</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:math></disp-formula></p>
<p>From <xref ref-type="disp-formula" rid="eqn-1">Eqs. (1)</xref> and <xref ref-type="disp-formula" rid="eqn-2">(2)</xref>, we get
<disp-formula id="eqn-6"><label>(6)</label><mml:math id="mml-eqn-6" display="block"><mml:mn>1</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mtext>&#x00A0;</mml:mtext><mml:mi>A</mml:mi><mml:mi>d</mml:mi><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>A</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>A</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>G</mml:mi><mml:mi>A</mml:mi><mml:mi>M</mml:mi><mml:msub><mml:mi>E</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mrow><mml:mo>]</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mo>=</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mo>|</mml:mo></mml:mrow><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mo>[</mml:mo></mml:mrow><mml:mi>S</mml:mi><mml:mi>A</mml:mi><mml:mo>,</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mi>G</mml:mi><mml:mi>A</mml:mi><mml:mi>M</mml:mi><mml:msub><mml:mi>E</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mo stretchy="false">]</mml:mo><mml:mo fence="false" stretchy="false">|</mml:mo></mml:math></disp-formula></p>
<p>By using <xref ref-type="disp-formula" rid="eqn-5">Eqs. (5)</xref> and <xref ref-type="disp-formula" rid="eqn-6">(6)</xref>.
<disp-formula id="eqn-7"><label>(7)</label><mml:math id="mml-eqn-7" display="block"><mml:mn>1</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mtext>&#x00A0;</mml:mtext><mml:mi>A</mml:mi><mml:mi>d</mml:mi><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>A</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mrow><mml:mo>[</mml:mo><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>A</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>G</mml:mi><mml:mi>a</mml:mi><mml:mi>m</mml:mi><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>]</mml:mo></mml:mrow><mml:mtext>&#x00A0;</mml:mtext><mml:mstyle displaystyle="false" scriptlevel="0"><mml:mtext>&#x2013;</mml:mtext></mml:mstyle><mml:mtext>&#x00A0;</mml:mtext><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mrow><mml:mo>[</mml:mo><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>A</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>G</mml:mi><mml:mi>a</mml:mi><mml:mi>m</mml:mi><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mn>3</mml:mn></mml:mrow></mml:msub><mml:mo>]</mml:mo></mml:mrow><mml:mo>|</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p>With <xref ref-type="disp-formula" rid="eqn-4">Eqs. (4)</xref>, <xref ref-type="disp-formula" rid="eqn-5">(5)</xref>, and <xref ref-type="disp-formula" rid="eqn-7">(7)</xref> and using triangular inequality, we obtain
<disp-formula id="ueqn-1">
<mml:math id="mml-ueqn-1" display="block"><mml:mn>1</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mtext>&#x00A0;</mml:mtext><mml:mi>A</mml:mi><mml:mi>d</mml:mi><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>A</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mrow><mml:mo>[</mml:mo><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>A</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>G</mml:mi><mml:mi>A</mml:mi><mml:mi>M</mml:mi><mml:msub><mml:mi>E</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mrow><mml:mo>]</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2212;</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mo>[</mml:mo></mml:mrow><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>A</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>G</mml:mi><mml:mi>A</mml:mi><mml:mi>M</mml:mi><mml:msub><mml:mi>E</mml:mi><mml:mrow><mml:mn>3</mml:mn></mml:mrow></mml:msub><mml:mo>]</mml:mo></mml:mrow><mml:mo>|</mml:mo></mml:mrow></mml:math></disp-formula>
<disp-formula id="ueqn-2">
<mml:math id="mml-ueqn-2" display="block"><mml:mtext>&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;</mml:mtext><mml:mo>&#x2264;</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mrow><mml:mo>|</mml:mo><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mrow><mml:mo>[</mml:mo><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>A</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>G</mml:mi><mml:mi>A</mml:mi><mml:mi>M</mml:mi><mml:msub><mml:mi>E</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mrow><mml:mo>]</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2212;</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mo>[</mml:mo></mml:mrow><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>A</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>G</mml:mi><mml:mi>A</mml:mi><mml:mi>M</mml:mi><mml:msub><mml:mi>E</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>]</mml:mo></mml:mrow><mml:mo>|</mml:mo></mml:mrow></mml:math></disp-formula>
<disp-formula id="ueqn-3">
<mml:math id="mml-ueqn-3" display="block"><mml:mtext>&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;</mml:mtext><mml:mo>+</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mrow><mml:mo>[</mml:mo><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>A</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>G</mml:mi><mml:mi>A</mml:mi><mml:mi>M</mml:mi><mml:msub><mml:mi>E</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mrow><mml:mo>]</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2212;</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mo>[</mml:mo></mml:mrow><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>A</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>G</mml:mi><mml:mi>A</mml:mi><mml:mi>M</mml:mi><mml:msub><mml:mi>E</mml:mi><mml:mrow><mml:mn>3</mml:mn></mml:mrow></mml:msub><mml:mo>]</mml:mo></mml:mrow><mml:mo>|</mml:mo></mml:mrow></mml:math></disp-formula>
<disp-formula id="eqn-8"><label>(8)</label><mml:math id="mml-eqn-8" display="block"><mml:mtext>&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;</mml:mtext><mml:mo>&#x2264;</mml:mo><mml:mfrac><mml:mrow><mml:mi>q</mml:mi><mml:mn>2</mml:mn><mml:mi>h</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn><mml:mtext>&#x00A0;</mml:mtext><mml:mrow><mml:mo>|</mml:mo><mml:mi>H</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>h</mml:mi><mml:mo>|</mml:mo></mml:mrow></mml:mrow></mml:mfrac><mml:mo>+</mml:mo><mml:mi>c</mml:mi><mml:mo>.</mml:mo><mml:msub><mml:mrow><mml:msup><mml:mi>q</mml:mi><mml:mrow><mml:mi>s</mml:mi></mml:mrow></mml:msup></mml:mrow><mml:mrow><mml:mi>s</mml:mi><mml:mi>e</mml:mi><mml:mi>n</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p>By multiplying both sides of <xref ref-type="disp-formula" rid="eqn-8">Eq. (8)</xref> by 2, we get
<disp-formula id="eqn-9"><label>(9)</label><mml:math id="mml-eqn-9" display="block"><mml:mi>A</mml:mi><mml:mi>d</mml:mi><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>A</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2264;</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mfrac><mml:mrow><mml:mi>q</mml:mi><mml:mn>2</mml:mn><mml:mi>h</mml:mi></mml:mrow><mml:mrow><mml:mo>|</mml:mo><mml:mi>H</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>h</mml:mi><mml:mo>|</mml:mo></mml:mrow></mml:mfrac><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mrow><mml:mo>{</mml:mo><mml:mi>c</mml:mi><mml:mo>.</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mrow><mml:mtext mathvariant="italic">qssend</mml:mtext></mml:mrow><mml:mo>}</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p>As we obtain in <xref ref-type="disp-formula" rid="eqn-9">Eq. (9)</xref>, we proved Theorem 1.</p>
</sec>
<sec id="s4_2"><label>4.2</label><title>Formal Security Analysis Using ProVerif</title>
<p>ProVerif2.03 verification software toolkit [<xref ref-type="bibr" rid="ref-12">12</xref>] is used to determine if the session secret is secure if it is computed confidentially, if it is exchanged securely among peers, and if an attacker may acquire it during a starting session. It is a popular simulation verification toolkit. <xref ref-type="fig" rid="fig-2">Fig. 2</xref> depicts ProVerif&#x2019;s results.</p>
<fig id="fig-2"><label>Figure 2</label><caption><title>ProVerif result</title></caption><graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_32553-fig-2.tif"/></fig>
</sec>
</sec>
<sec id="s5"><label>5</label><title>Informal Security Analysis</title>
<p>This section shows how our proposed scheme defends against various threats and incorporates security features such as mutual authentication and perfect forward secrecy to protect users&#x2019; data.</p>
<sec id="s5_1"><label>5.1</label><title>Offline Password Guessing Attack</title>
<p>In our proposed scheme the <inline-formula id="ieqn-106"><mml:math id="mml-ieqn-106"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> cannot get <italic>B<sub>1&#x2009;</sub>&#x003D;&#x2009;h(ID<sub>u</sub>&#x007C;&#x007C;PW<sub>u</sub>)</italic> <inline-formula id="ieqn-107"><mml:math id="mml-ieqn-107"><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;&#x00A0;</mml:mtext><mml:mi>r</mml:mi><mml:mi>u</mml:mi><mml:mo>,</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:msub><mml:mi>B</mml:mi><mml:mrow><mml:mrow><mml:mtext mathvariant="italic">2</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>h</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>I</mml:mi><mml:mi>D</mml:mi><mml:mi>u</mml:mi><mml:mrow><mml:mo>|</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mi>P</mml:mi><mml:mi>W</mml:mi><mml:mi>u</mml:mi><mml:mo>|</mml:mo></mml:mrow><mml:mo>|</mml:mo></mml:mrow><mml:mi>r</mml:mi><mml:mi>u</mml:mi><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mi>H</mml:mi><mml:mi>P</mml:mi><mml:mi>W</mml:mi><mml:mi>u</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:msub><mml:mi>B</mml:mi><mml:mrow><mml:mrow><mml:mtext mathvariant="italic">3</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>h</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>H</mml:mi><mml:mi>P</mml:mi><mml:mi>W</mml:mi><mml:mi>u</mml:mi><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mi>r</mml:mi><mml:mi>u</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mi>X</mml:mi><mml:mi>I</mml:mi><mml:mi>D</mml:mi><mml:mi>u</mml:mi><mml:mo>,</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:msub><mml:mi>B</mml:mi><mml:mrow><mml:mrow><mml:mtext mathvariant="italic">4</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>h</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>H</mml:mi><mml:mi>P</mml:mi><mml:mi>W</mml:mi><mml:mi>u</mml:mi><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mi>X</mml:mi><mml:mi>I</mml:mi><mml:mi>D</mml:mi><mml:mi>u</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2295;</mml:mo><mml:mtext>&#x00A0;</mml:mtext></mml:math></inline-formula> <italic>V<sub>1</sub>, X<sub>u</sub> &#x003D; h(ID<sub>u</sub>&#x007C;&#x007C;r<sub>u</sub>)</italic>. The values of B<sub>1</sub>, B<sub>2</sub>, B<sub>3</sub>, B<sub>4</sub>, and X<sub>u</sub> were constructed using ID<sub>u</sub>, PW<sub>u</sub>, and random number r<sub>u</sub>. Therefore, the <inline-formula id="ieqn-108"><mml:math id="mml-ieqn-108"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> cannot construct B<sub>1</sub>, B<sub>2</sub>, B<sub>3</sub>, B<sub>4</sub>, and X<sub>u</sub>. Thus, our proposed scheme resists offline password guessing attacks.</p>
</sec>
<sec id="s5_2"><label>5.2</label><title>Mutual Authentication</title>
<p>The user, edge server, and IoT-enable sensor node check the message&#x2019;s validity in the login and authentication phase. The user, edge server, and IoT-enable node checks <italic>F<sub>u</sub>? &#x003D; F<sub>u</sub>, F<sub>e</sub>? &#x003D; F<sub>e</sub>, F<sub>w</sub>? &#x003D; F<sub>w</sub>, F<sub>ec</sub>? &#x003D; F<sub>ec</sub></italic>, and <italic>N<sub>6</sub> ? &#x003D; N<sub>6</sub></italic>. If these values are correct, then the entities authenticate each other. Therefore, our proposed scheme provides mutual authentication property.</p>
</sec>
<sec id="s5_3"><label>5.3</label><title>Insider Attack</title>
<p>In registration phase, the <inline-formula id="ieqn-109"><mml:math id="mml-ieqn-109"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> might obtain X<sub>u</sub> &#x003D; h(ID<sub>u</sub>&#x007C;&#x007C;r<sub>u</sub>). The <inline-formula id="ieqn-110"><mml:math id="mml-ieqn-110"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> try to construct &#x007B;B<sub>1</sub>, B<sub>2</sub>, B<sub>3</sub>, B<sub>4</sub>, X<sub>u</sub>&#x007D; store on the user side. However, the <inline-formula id="ieqn-111"><mml:math id="mml-ieqn-111"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> cannot obtain actual ID<sub>u</sub>, PW<sub>u</sub>, and r<sub>u</sub>. Therefore, the <inline-formula id="ieqn-112"><mml:math id="mml-ieqn-112"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> cannot construct S<sub>K</sub>. Thus, our proposed scheme resists insider attacks.</p>
</sec>
<sec id="s5_4"><label>5.4</label><title>Desynchronization</title>
<p>The <inline-formula id="ieqn-113"><mml:math id="mml-ieqn-113"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> trying to modify and block the transmitted messages to the user, edge server, and IoT-enable sensor node cannot authenticate each other. However, the <inline-formula id="ieqn-114"><mml:math id="mml-ieqn-114"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> cannot do it because, according to our protocol, the <inline-formula id="ieqn-115"><mml:math id="mml-ieqn-115"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> cannot obtain ID<sub>u</sub>, PW<sub>u</sub>, r<sub>u</sub>, and S<sub>k</sub>. Thus, user and edge servers always have synchronized values. Therefore, in our proposed scheme, a desynchronization attack is not possible.</p>
</sec>
<sec id="s5_5"><label>5.5</label><title>Anonymity</title>
<p>The <inline-formula id="ieqn-116"><mml:math id="mml-ieqn-116"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> cannot obtain the actual identities of <italic>ID<sub>u</sub>, PW<sub>u</sub>, ID<sub>e</sub>, ID<sub>w</sub></italic>, to construct <italic>X<sub>u</sub></italic>&#x2009;<italic>&#x003D;</italic>&#x2009;<italic>h(ID<sub>u</sub>&#x007C;&#x007C;ru), X<sub>w</sub></italic>&#x2009;<italic>&#x003D;</italic>&#x2009;<italic>h(ID<sub>w</sub> &#x007C;&#x007C;r<sub>w</sub>)</italic>. Therefore, our proposed scheme provides anonymity.</p>
</sec>
<sec id="s5_6"><label>5.6</label><title>Untraceability</title>
<p>In our proposed protocol for every session, the edge server and user update <italic>X<sub>u</sub><sup>new</sup></italic>&#x2009;<italic>&#x003D;</italic>&#x2009;<italic>h(X<sub>u</sub>&#x007C;&#x007C;r<sub>u1</sub>)</italic>. Therefore, our protocol provides untraceability.</p>
</sec>
<sec id="s5_7"><label>5.7</label><title>Perfect Forward Secrecy</title>
<p>The <inline-formula id="ieqn-117"><mml:math id="mml-ieqn-117"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> obtains secret key SK<sub>rs</sub> and tries to create a session key S<sub>K</sub>. Although, the <inline-formula id="ieqn-118"><mml:math id="mml-ieqn-118"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> needs a random number &#x007B;<italic>r<sub>u</sub>, r<sub>u1</sub>, r<sub>e</sub>, r<sub>w</sub>, r<sub>w1</sub></italic>&#x007D; because the S<sub>K</sub> is composed of a random number for every session. Therefore, our proposed protocol; provides perfect forward secrecy.</p>
</sec>
<sec id="s5_8"><label>5.8</label><title>Known Session Attack</title>
<p>The <inline-formula id="ieqn-119"><mml:math id="mml-ieqn-119"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> attempts to obtain random numbers and construct the session key in accordance with the CK-adversary model. However, the <inline-formula id="ieqn-120"><mml:math id="mml-ieqn-120"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> needs the identities of a user, edge server, and IoT-enable sensor node. Because in our proposed scheme, the session key was constructed using the identities of the user, edge server, and IoT-enable sensor node. Thus, our proposed scheme resists known session attacks.</p>
</sec>
<sec id="s5_9"><label>5.9</label><title>MITM Attack</title>
<p>Let us suppose the <inline-formula id="ieqn-121"><mml:math id="mml-ieqn-121"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> gets a previous authentication request between the user and edge server. Further, the <inline-formula id="ieqn-122"><mml:math id="mml-ieqn-122"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> tries to send it again to the edge server. However, the edge server checks the freshness of the random number and rejects the request of <inline-formula id="ieqn-123"><mml:math id="mml-ieqn-123"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula>. Thus, our scheme resists the MITM attack.</p>
</sec>
<sec id="s5_10"><label>5.10</label><title>Session Key Leakage Attack</title>
<p>The <inline-formula id="ieqn-124"><mml:math id="mml-ieqn-124"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> might get &#x007B;<italic>B<sub>1</sub>, B<sub>2</sub>, B<sub>3</sub>, B<sub>4</sub>, X<sub>u</sub></italic>&#x007D; and &#x007B;<italic>S<sub>1</sub>, S<sub>1</sub>, X<sub>u</sub></italic>&#x007D; of the user and IoT-enable sensor node to calculate the S<sub>K</sub>. However, the <inline-formula id="ieqn-125"><mml:math id="mml-ieqn-125"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> need actual identities (<italic>ID<sub>u</sub>, ID<sub>w</sub>, ID<sub>e</sub></italic>&#x007D; and random numbers &#x007B;<italic>r<sub>u</sub>, r<sub>u1</sub>, r<sub>e</sub>, r<sub>w</sub>, r<sub>w1</sub></italic>&#x007D;. The identities and random numbers cannot obtain from transmitted messages because these values are encrypted. Thus, our proposed scheme resists session key leakage attacks.</p>
</sec>
<sec id="s5_11"><label>5.11</label><title>Replay Attack</title>
<p>Let us suppose the <inline-formula id="ieqn-126"><mml:math id="mml-ieqn-126"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> tries to modify the authentication request and pretend to be a user or edge server. However, the <inline-formula id="ieqn-127"><mml:math id="mml-ieqn-127"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> cannot change &#x007B;<italic>N, E<sub>1</sub>, F<sub>u</sub></italic>&#x007D; and &#x007B;<italic>F<sub>ec</sub>, N<sub>6</sub></italic>&#x007D; without the knowledge of <italic>ID<sub>u</sub></italic>, <italic>PW<sub>u</sub></italic>, <italic>r<sub>u</sub></italic>, <italic>ID<sub>e</sub> ID<sub>w</sub></italic>. Therefore, the proposed scheme resists replay attacks.</p>
</sec>
<sec id="s5_12"><label>5.12</label><title>User Impersonation Attack</title>
<p>Let us suppose the <inline-formula id="ieqn-128"><mml:math id="mml-ieqn-128"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> extract secret values &#x007B;<italic>X<sub>u</sub>, B<sub>1</sub>, B<sub>2</sub>, B<sub>3</sub>, B<sub>4</sub></italic>&#x007D;. The <inline-formula id="ieqn-129"><mml:math id="mml-ieqn-129"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> tries to impersonate the user using these values. However, the <inline-formula id="ieqn-130"><mml:math id="mml-ieqn-130"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> cannot send authentication messages towards the edge server because the <inline-formula id="ieqn-131"><mml:math id="mml-ieqn-131"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> needs ID<sub>u</sub>, PW<sub>u</sub>, r<sub>u</sub>, and HPW<sub>u</sub> to construct &#x007B;<italic>N, D, F<sub>u</sub>, X<sub>u</sub></italic>&#x007D;. Therefore, our proposed scheme resists user impersonation attacks.</p>
</sec>
<sec id="s5_13"><label>5.13</label><title>IoT-Enable Sensor Node Impersonation Attack</title>
<p>The <inline-formula id="ieqn-132"><mml:math id="mml-ieqn-132"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> found a lost IoT-enable sensor node to impersonate the IoT-enable sensor node. However, the <inline-formula id="ieqn-133"><mml:math id="mml-ieqn-133"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> cannot construct &#x007B;<italic>F<sub>u</sub>, r<sub>u</sub></italic>&#x007D; because the <inline-formula id="ieqn-134"><mml:math id="mml-ieqn-134"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> needs <italic>ID<sub>w</sub>, r<sub>w</sub></italic>, and r<sub>w1</sub> to construct &#x007B;<italic>F<sub>w</sub>, N<sub>4</sub></italic>&#x007D;. Therefore, our proposed scheme resists IoT-enable sensor node impersonation attacks.</p>
</sec>
<sec id="s5_14"><label>5.14</label><title>Stolen IoT-Enable Sensor Node Attack</title>
<p>Let suppose the <inline-formula id="ieqn-135"><mml:math id="mml-ieqn-135"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> get stolen IoT-enable sensor node and obtain secret &#x007B;<italic>S<sub>1</sub>, S<sub>2</sub>, X<sub>w</sub></italic>&#x007D; stored in the memory of IoT-enable sensor node. However, the <inline-formula id="ieqn-136"><mml:math id="mml-ieqn-136"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> cannot get ID<sub>w</sub>, r<sub>w</sub>, and r<sub>w1</sub>. Thus, our proposed scheme resists stolen IoT-enable sensor node attacks.</p>
</sec>
</sec>
<sec id="s6"><label>6</label><title>Performance and Security Analysis</title>
<p>This section compared our proposed scheme to similar protocols in terms of security characteristics, communication, and computation cost comparisons, among other things.</p>
<sec id="s6_1"><label>6.1</label><title>Security Features</title>
<p>In this section, we compare our protocol with [<xref ref-type="bibr" rid="ref-10">10</xref>,<xref ref-type="bibr" rid="ref-21">21</xref>&#x2013;<xref ref-type="bibr" rid="ref-23">23</xref>,<xref ref-type="bibr" rid="ref-33">33</xref>,<xref ref-type="bibr" rid="ref-45">45</xref>&#x2013;<xref ref-type="bibr" rid="ref-47">47</xref>] in terms of security features. <xref ref-type="table" rid="table-5">Table 5</xref> shows that our scheme achieved all security features and provided mutual authentication, anonymity, and untraceability.</p>
<table-wrap id="table-5"><label>Table 5</label><caption><title>Security feature comparison</title></caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left">Schemes</th>
<th align="left">[<xref ref-type="bibr" rid="ref-21">21</xref>]</th>
<th align="left"> [<xref ref-type="bibr" rid="ref-22">22</xref>]</th>
<th align="left">[<xref ref-type="bibr" rid="ref-23">23</xref>]</th>
<th align="left"> [<xref ref-type="bibr" rid="ref-33">33</xref>]</th>
<th align="left">[<xref ref-type="bibr" rid="ref-10">10</xref>]</th>
<th align="left"> [<xref ref-type="bibr" rid="ref-45">45</xref>]</th>
<th align="left">[<xref ref-type="bibr" rid="ref-46">46</xref>]</th>
<th align="left"> [<xref ref-type="bibr" rid="ref-47">47</xref>]</th>
<th align="left">[<xref ref-type="bibr" rid="ref-48">48</xref>]</th>
<th align="left"> Our</th>
</tr>
<tr>
<th align="left">Security features</th>
<th/>
<th/>
<th/>
<th/>
<th/>
<th/>
<th/>
<th/>
<th/>
<th/>
</tr>
</thead>
<tbody>
<tr>
<td align="left">Offline password guessing attack</td>
<td align="left">&#x2713;</td>
<td align="left"><inline-formula id="ieqn-137"><mml:math id="mml-ieqn-137"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula></td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left"><inline-formula id="ieqn-138"><mml:math id="mml-ieqn-138"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula></td>
<td align="left">-</td>
<td align="left"><inline-formula id="ieqn-139"><mml:math id="mml-ieqn-139"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula></td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
</tr>
<tr>
<td align="left">Mutual authentication</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left"><inline-formula id="ieqn-140"><mml:math id="mml-ieqn-140"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula></td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
</tr>
<tr>
<td align="left">Insider attack</td>
<td align="left"><inline-formula id="ieqn-141"><mml:math id="mml-ieqn-141"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula></td>
<td align="left"><inline-formula id="ieqn-142"><mml:math id="mml-ieqn-142"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula></td>
<td align="left"><inline-formula id="ieqn-143"><mml:math id="mml-ieqn-143"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula></td>
<td align="left"><inline-formula id="ieqn-144"><mml:math id="mml-ieqn-144"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula></td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
</tr>
<tr>
<td align="left">Desynchronization</td>
<td align="left">-</td>
<td align="left">-</td>
<td align="left">&#x2713;</td>
<td align="left"><inline-formula id="ieqn-145"><mml:math id="mml-ieqn-145"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula></td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left"><inline-formula id="ieqn-146"><mml:math id="mml-ieqn-146"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula></td>
<td align="left">-</td>
<td align="left">&#x2713;</td>
</tr>
<tr>
<td align="left">Anonymity</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left"><inline-formula id="ieqn-147"><mml:math id="mml-ieqn-147"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula></td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">-</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
</tr>
<tr>
<td align="left">Untraceability</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left"><inline-formula id="ieqn-148"><mml:math id="mml-ieqn-148"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula></td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
</tr>
<tr>
<td align="left">Perfect forward secrecy</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left"><inline-formula id="ieqn-149"><mml:math id="mml-ieqn-149"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula></td>
<td align="left">&#x2713;</td>
<td align="left"><inline-formula id="ieqn-150"><mml:math id="mml-ieqn-150"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula></td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
</tr>
<tr>
<td align="left">Known session attack</td>
<td align="left"><inline-formula id="ieqn-151"><mml:math id="mml-ieqn-151"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula></td>
<td align="left"><inline-formula id="ieqn-152"><mml:math id="mml-ieqn-152"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula></td>
<td align="left">&#x2713;</td>
<td align="left"><inline-formula id="ieqn-153"><mml:math id="mml-ieqn-153"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula></td>
<td align="left">&#x2713;</td>
<td align="left">-</td>
<td align="left"><inline-formula id="ieqn-154"><mml:math id="mml-ieqn-154"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula></td>
<td align="left">-</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
</tr>
<tr>
<td align="left">MITM attack</td>
<td align="left"><inline-formula id="ieqn-155"><mml:math id="mml-ieqn-155"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula></td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left"><inline-formula id="ieqn-156"><mml:math id="mml-ieqn-156"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula></td>
<td align="left"><inline-formula id="ieqn-157"><mml:math id="mml-ieqn-157"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula></td>
<td align="left">-</td>
<td align="left">-</td>
<td align="left"><inline-formula id="ieqn-158"><mml:math id="mml-ieqn-158"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula></td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
</tr>
<tr>
<td align="left">Session key leakage attack</td>
<td align="left"><inline-formula id="ieqn-159"><mml:math id="mml-ieqn-159"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula></td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">-</td>
<td align="left">-</td>
<td align="left">-</td>
<td align="left">-</td>
<td align="left">&#x2713;</td>
</tr>
<tr>
<td align="left">Replay attack</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left"><inline-formula id="ieqn-160"><mml:math id="mml-ieqn-160"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula></td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
</tr>
<tr>
<td align="left">User impersonation attack</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left"><inline-formula id="ieqn-161"><mml:math id="mml-ieqn-161"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula></td>
<td align="left"><inline-formula id="ieqn-162"><mml:math id="mml-ieqn-162"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula></td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
</tr>
<tr>
<td align="left">IoT-enable device impersonation attack</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">-</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
</tr>
<tr>
<td align="left">Edge server impersonation attack</td>
<td align="left">-</td>
<td align="left">-</td>
<td align="left">-</td>
<td align="left">-</td>
<td align="left">-</td>
<td align="left">-</td>
<td align="left">-</td>
<td align="left">-</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
</tr>
<tr>
<td align="left">Stolen IoT-enable device attack</td>
<td align="left">&#x2713;</td>
<td align="left"><inline-formula id="ieqn-163"><mml:math id="mml-ieqn-163"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula></td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
</tr>
</tbody>
</table>
<table-wrap-foot><fn id="tfn5_1"><p>Note: &#x2713;: secure, <inline-formula id="ieqn-164"><mml:math id="mml-ieqn-164"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula>: insecure, -: not considered.</p></fn>
</table-wrap-foot>
</table-wrap>
</sec>
<sec id="s6_2"><label>6.2</label><title>Communication Cost</title>
<p>In this section, we first calculate our proposed scheme communication cost and then compare it with recent related protocols [<xref ref-type="bibr" rid="ref-10">10</xref>,<xref ref-type="bibr" rid="ref-21">21</xref>&#x2013;<xref ref-type="bibr" rid="ref-23">23</xref>,<xref ref-type="bibr" rid="ref-33">33</xref>,<xref ref-type="bibr" rid="ref-45">45</xref>&#x2013;<xref ref-type="bibr" rid="ref-48">48</xref>] in <xref ref-type="table" rid="table-6">Table 6</xref>. The value of a hash function is (160 bits), the ECC point of multiplication is (320 bits), the symmetric key is (256 bits) timestamp is (32 bits), while the random number is (128 bits), and identities are (160 bits) [<xref ref-type="bibr" rid="ref-49">49</xref>]. Our proposed scheme exchange messages are &#x007B;<italic>N, D, F<sub>u</sub>, X<sub>u</sub></italic>&#x007D; is &#x007B;640 bits&#x007D;, &#x007B;<italic>X<sub>u</sub>, N<sub>3</sub>, E<sub>2</sub>, F<sub>e</sub></italic>&#x007D; is &#x007B;640 bits&#x007D;, &#x007B;<italic>F<sub>w</sub>, N<sub>4</sub></italic>&#x007D; is &#x007B;320 bits&#x007D;, &#x007B;<italic>F<sub>ec</sub>, N<sub>5</sub></italic>&#x007D; is &#x007B;320 bits&#x007D; and &#x007B;<italic>N<sub>6</sub></italic>&#x007D; is &#x007B;160&#x007D;. As a result, our suggested scheme&#x2019;s overall communication cost is equivalent to 2080 bits. The scheme [<xref ref-type="bibr" rid="ref-45">45</xref>] has a lower communication cost, but the computation cost is high, and the scheme is vulnerable to offline password guessing attacks and unable to provide perfect forward secrecy.</p>
<table-wrap id="table-6"><label>Table 6</label><caption><title>Communication cost comparison</title></caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left">[<xref ref-type="bibr" rid="ref-21">21</xref>]</th>
<th align="left">[<xref ref-type="bibr" rid="ref-22">22</xref>]</th>
<th align="left">[<xref ref-type="bibr" rid="ref-23">23</xref>]</th>
<th align="left">[<xref ref-type="bibr" rid="ref-33">33</xref>]</th>
<th align="left">[<xref ref-type="bibr" rid="ref-10">10</xref>]</th>
<th align="left">[<xref ref-type="bibr" rid="ref-45">45</xref>]</th>
<th align="left">[<xref ref-type="bibr" rid="ref-46">46</xref>]</th>
<th align="left">[<xref ref-type="bibr" rid="ref-47">47</xref>]</th>
<th align="left">[<xref ref-type="bibr" rid="ref-48">48</xref>]</th>
<th align="left">Our</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left"> 5088</td>
<td align="left">7648</td>
<td align="left">6080</td>
<td align="left">4608</td>
<td align="left">3648</td>
<td align="left">1344</td>
<td align="left">11008</td>
<td align="left">2112</td>
<td align="left">2688</td>
<td align="left">2080</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s6_3"><label>6.3</label><title>Computation Cost</title>
<p>We compared our proposed scheme computation cost with other related schemes [<xref ref-type="bibr" rid="ref-10">10</xref>,<xref ref-type="bibr" rid="ref-21">21</xref>&#x2013;<xref ref-type="bibr" rid="ref-23">23</xref>,<xref ref-type="bibr" rid="ref-33">33</xref>,<xref ref-type="bibr" rid="ref-45">45</xref>&#x2013;<xref ref-type="bibr" rid="ref-48">48</xref>]. First, we calculated our proposed scheme computation cost. According to [<xref ref-type="bibr" rid="ref-50">50</xref>], the ECC point of multiplication T<sub>M</sub> is (7.3529&#x2005;ms), hash function T<sub>h</sub> is (0.0004&#x2005;ms), symmetric key T<sub>S</sub> is (0.1303&#x2005;ms), and fuzzy extractor T<sub>R</sub> is (7.3529&#x2005;ms). Therefore, our scheme total computation cost is 66T<sub>h</sub> is equal to 0.264&#x2005;ms. Detail comparison of our proposed scheme computation and communication cost is shown in <xref ref-type="fig" rid="fig-3">Fig. 3</xref>. The scheme [<xref ref-type="bibr" rid="ref-22">22</xref>] has a lower computation cost. However, the communication cost of the scheme [<xref ref-type="bibr" rid="ref-22">22</xref>] is very high. In contrast, <xref ref-type="table" rid="table-5">Table 5</xref> shows that the scheme is vulnerable to offline password guessing attacks, insider attacks, and known session attacks.</p>
<fig id="fig-3"><label>Figure 3</label><caption><title>Computation cost comparison</title></caption><graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_32553-fig-3.tif"/></fig>
</sec>
<sec id="s6_4"><label>6.4</label><title>Storage Cost</title>
<p>In this portion of our research article, we consider the work [<xref ref-type="bibr" rid="ref-49">49</xref>]. The hash function is 160, multiplication point is 320, identity is 160, symmetric key 256, timestamp is 32, and random numbers are 128 bits. Keep view this in mind, our proposed scheme storage cost calculation is X<sub>w</sub>&#x2009;&#x003D; 160, S<sub>1&#x2009;</sub>&#x003D;&#x2009;160&#x2009;&#x002B;&#x2009;128, S<sub>2</sub>&#x2009;&#x003D; 160&#x2009;&#x002B;&#x2009;160, X<sub>u</sub>&#x2009;&#x003D; 160, B<sub>1&#x2009;</sub>&#x003D;&#x2009;160&#x2009;&#x002B;&#x2009;128, B<sub>2</sub>&#x2009;&#x003D; 160, B<sub>3</sub>&#x2009;&#x003D; 160&#x2009;&#x002B;&#x2009;160, B<sub>4</sub> &#x003D; 160&#x2009;&#x002B;&#x2009;160. Hence total storage cost is 2016 bits. <xref ref-type="table" rid="table-7">Table 7</xref> shows the comparison with other state-of-the-art schemes.</p>
<table-wrap id="table-7"><label>Table 7</label><caption><title>Storage cost</title></caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left">[<xref ref-type="bibr" rid="ref-21">21</xref>]</th>
<th align="left">[<xref ref-type="bibr" rid="ref-22">22</xref>]</th>
<th align="left">[<xref ref-type="bibr" rid="ref-23">23</xref>]</th>
<th align="left">[<xref ref-type="bibr" rid="ref-33">33</xref>]</th>
<th align="left">[<xref ref-type="bibr" rid="ref-10">10</xref>]</th>
<th align="left">[<xref ref-type="bibr" rid="ref-45">45</xref>]</th>
<th align="left">[<xref ref-type="bibr" rid="ref-46">46</xref>]</th>
<th align="left">[<xref ref-type="bibr" rid="ref-48">48</xref>]</th>
<th align="left">Our</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left"> 4480</td>
<td align="left">1856</td>
<td align="left">2880</td>
<td align="left">1280</td>
<td align="left">6464</td>
<td align="left">1696</td>
<td align="left">6240</td>
<td align="left">2880</td>
<td align="left">2016</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
</sec>
<sec id="s7"><label>7</label><title>Conclusion</title>
<p>In this research article, we proposed a secure and efficient authentication scheme. Our proposed scheme guarantees secure and efficient communication among the IoT-enable device, user, and edge server. E-healthcare is a prominent research area for researchers because any flaw in the protocol can lead to fatal damage to the patient. Therefore, we cryptanalysis the scheme of Zhu and find out that their scheme suffers from spoofing, impersonation, and masquerading attacks. To overcome the flaws of Zhu&#x2019;s scheme, we proposed a secure and efficient information authentication scheme for IoT-enabled devices in an e-healthcare system.</p>
<p>We choose edge computing to reduce latency for e-healthcare systems because latency is an essential factor. We performed the ROR model and ProVerif to demonstrate that our protocol provided session key security and resisted MITM. In the end, our proposed protocol achieved security features and lower computation costs than recent existing schemes. Therefore, we concluded that our scheme provides lower computation costs and better security.</p>
</sec>
</body>
<back>
<ack><p>The authors are thankful to the Natural Science Foundation of Beijing Municipality and Beijing University of Technology for funding this work under Grant M21039.</p></ack>
<sec><title>Funding Statement</title>
<p>This work was supported by the Natural Science Foundation of Beijing Municipality under Grant M21039.</p></sec>
<sec><title>Author Contributions</title>
<p>The authors confirm contribution to the paper as follows: study conception and design: Naveed Khan, Shehzad Ashraf Chaudhry and Jianbiao Zhang; security analysis: Naveed Khan; performance analysis: Naveed Khan, Ghulam Ali Mallah, and Shehzad Ashraf Chaudhry; draft manuscript preparation: Naveed Khan, and Shehzad Ashraf Chaudhry. All authors reviewed the results and approved the final version of the manuscript.</p></sec>
<sec sec-type="data-availability"><title>Availability of Data and Materials</title>
<p>The first author will provide the supporting data for this work upon reasonable request.</p></sec>
<sec sec-type="COI-statement"><title>Conflicts of Interest</title>
<p>The authors declare that they have no conflicts of interest to report regarding the present study.</p></sec>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>L.</given-names> <surname>Chettri</surname></string-name> and <string-name><given-names>R.</given-names> <surname>Bera</surname></string-name></person-group>, &#x201C;<article-title>A comprehensive survey on Internet of Things (IoT) toward 5G wireless systems</article-title>,&#x201D; <source>IEEE Internet of Things Journal</source>, vol. <volume>7</volume>, no. <issue>1</issue>, pp. <fpage>16</fpage>&#x2013;<lpage>32</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>H.</given-names> <surname>Habibzadeh</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Dinesh</surname></string-name>, <string-name><given-names>O. R.</given-names> <surname>Shishvan</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Boggio-Dandry</surname></string-name>, <string-name><given-names>G.</given-names> <surname>Sharma</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>A survey of Healthcare Internet of Things (HIoT): A clinical perspective</article-title>,&#x201D; <source>IEEE Internet of Things Journal</source>, vol. <volume>7</volume>, no. <issue>1</issue>, pp. <fpage>53</fpage>&#x2013;<lpage>71</lpage>, <year>2019</year>; <pub-id pub-id-type="pmid">33748312</pub-id></mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>I.</given-names> <surname>Cviti&#x0107;</surname></string-name>, <string-name><given-names>D.</given-names> <surname>Perakovi&#x0107;</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Peri&#x0161;a</surname></string-name> and <string-name><given-names>B.</given-names> <surname>Gupta</surname></string-name></person-group>, &#x201C;<article-title>Ensemble machine learning approach for classification of IoT devices in smart home</article-title>,&#x201D; <source>International Journal of Machine Learning and Cybernetics</source>, vol. <volume>12</volume>, no. <issue>11</issue>, pp. <fpage>3179</fpage>&#x2013;<lpage>3202</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><given-names>F.</given-names> <surname>Alshehri</surname></string-name> and <string-name><given-names>G.</given-names> <surname>Muhammad</surname></string-name></person-group>, &#x201C;<article-title>A comprehensive survey of the Internet of Things (IoT) and AI-based smart healthcare</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>9</volume>, pp. <fpage>3660</fpage>&#x2013;<lpage>3678</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"> <comment>World Health Organization</comment>, &#x201C;<article-title>Medication without harm</article-title>,&#x201D; <year>2017</year>. <comment>[Online]. Available:</comment> <ext-link ext-link-type="uri" xlink:href="https://www.bpsassessment.com/wp-content/themes/bpspsa/assets/Downloads/2.%20The%20third%20Global%20Patient%20Safety%20Challeng.pdf">https://www.bpsassessment.com/wp-content/themes/bpspsa/assets/Downloads/2.%20The%20third%20Global%20Patient%20Safety%20Challeng.pdf</ext-link></mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Al-Qerem</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Alauthman</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Almomani</surname></string-name> and <string-name><given-names>B. B.</given-names> <surname>Gupta</surname></string-name></person-group>, &#x201C;<article-title>IoT transaction processing through cooperative concurrency control on fog&#x2013;cloud computing environment</article-title>,&#x201D; <source>Soft Computing</source>, vol. <volume>24</volume>, no. <issue>8</issue>, pp. <fpage>5695</fpage>&#x2013;<lpage>5711</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>C. T.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>C. C.</given-names> <surname>Lee</surname></string-name>, <string-name><given-names>C. Y.</given-names> <surname>Weng</surname></string-name> and <string-name><given-names>C. M.</given-names> <surname>Chen</surname></string-name></person-group>, &#x201C;<article-title>Towards secure authenticating of cache in the reader for RFID-based IoT systems</article-title>,&#x201D; <source>Peer-to-Peer Networking and Applications</source>, vol. <volume>11</volume>, no. <issue>1</issue>, pp. <fpage>198</fpage>&#x2013;<lpage>208</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>F.</given-names> <surname>Al-Turjman</surname></string-name> and <string-name><given-names>S.</given-names> <surname>Alturjman</surname></string-name></person-group>, &#x201C;<article-title>Context-sensitive access in Industrial Internet of Things (IIoT) healthcare applications</article-title>,&#x201D; <source>IEEE Transactions on Industrial Informatics</source>, vol. <volume>14</volume>, no. <issue>6</issue>, pp. <fpage>2736</fpage>&#x2013;<lpage>2744</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Wazid</surname></string-name>, <string-name><given-names>A. K.</given-names> <surname>Das</surname></string-name>, <string-name><given-names>V.</given-names> <surname>Odelu</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Kumar</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Conti</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Design of secure user authenticated key management protocol for generic IoT networks</article-title>,&#x201D; <source>IEEE Internet of Things Journal</source>, vol. <volume>5</volume>, no. <issue>1</issue>, pp. <fpage>269</fpage>&#x2013;<lpage>282</lpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>F.</given-names> <surname>Zhu</surname></string-name></person-group>, &#x201C;<article-title>SecMAP: A secure RFID mutual authentication protocol for healthcare systems</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>8</volume>, pp. <fpage>192192</fpage>&#x2013;<lpage>192205</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>W.</given-names> <surname>Liu</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Wang</surname></string-name> and <string-name><given-names>W.</given-names> <surname>Peng</surname></string-name></person-group>, &#x201C;<article-title>Secure remote multi-factor authentication scheme based on chaotic map zero-knowledge proof for crowdsourcing Internet of Things</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>8</volume>, pp. <fpage>8754</fpage>&#x2013;<lpage>8767</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>B.</given-names> <surname>Blanchet</surname></string-name>, <string-name><given-names>B.</given-names> <surname>Smyth</surname></string-name>, <string-name><given-names>V.</given-names> <surname>Cheval</surname></string-name> and <string-name><given-names>M.</given-names> <surname>Sylvestre</surname></string-name></person-group>, &#x201C;<article-title>ProVerif 2.00: Automatic cryptographic protocol verifier, user manual and tutorial</article-title>,&#x201D; <year>2018</year>. <comment>[Online]. Available:</comment> <ext-link ext-link-type="uri" xlink:href="https://www.crs811.com/uploads/2019/01/manual.pdf">https://www.crs811.com/uploads/2019/01/manual.pdf</ext-link></mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>D.</given-names> <surname>Dolev</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Yao</surname></string-name></person-group>, &#x201C;<article-title>On the security of public key protocols</article-title>,&#x201D; <source>IEEE Transactions on Information Theory</source>, vol. <volume>29</volume>, no. <issue>2</issue>, pp. <fpage>198</fpage>&#x2013;<lpage>208</lpage>, <year>1983</year>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>R.</given-names> <surname>Canetti</surname></string-name> and <string-name><given-names>H.</given-names> <surname>Krawczyk</surname></string-name></person-group>, &#x201C;<article-title>Analysis of key-exchange protocols and their use for building secure channels</article-title>,&#x201D; in <conf-name>Int. Conf. on the Theory and Applications of Cryptographic Techniques</conf-name>, Innsbruck, Austria, pp. <fpage>453</fpage>&#x2013;<lpage>474</lpage>, <year>2001</year>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Z.</given-names> <surname>Ali</surname></string-name>, <string-name><given-names>S. A.</given-names> <surname>Chaudhry</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Mahmood</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Garg</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Lv</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>A clogging resistant secure authentication scheme for fog computing services</article-title>,&#x201D; <source>Computer Networks</source>, vol. <volume>185</volume>, pp. <fpage>107731</fpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>N.</given-names> <surname>Khan</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Zhang</surname></string-name> and <string-name><given-names>S. U.</given-names> <surname>Jan</surname></string-name></person-group>, &#x201C;<article-title>A robust and privacy-preserving anonymous user authentication scheme for public cloud server</article-title>,&#x201D; <source>Security and Communication Networks</source>, vol. <volume>2022</volume>, pp. <fpage>1</fpage>&#x2013;<lpage>14</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>C. T.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>C. L.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>C. C.</given-names> <surname>Lee</surname></string-name>, <string-name><given-names>C. Y.</given-names> <surname>Weng</surname></string-name> and <string-name><given-names>C. M.</given-names> <surname>Chen</surname></string-name></person-group>, &#x201C;<article-title>A novel three-party password-based authenticated key exchange protocol with user anonymity based on chaotic maps</article-title>,&#x201D; <source>Soft Computing</source>, vol. <volume>22</volume>, no. <issue>8</issue>, pp. <fpage>2495</fpage>&#x2013;<lpage>2506</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>P.</given-names> <surname>Gope</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Lee</surname></string-name> and <string-name><given-names>T. Q.</given-names> <surname>Quek</surname></string-name></person-group>, &#x201C;<article-title>Lightweight and practical anonymous authentication protocol for RFID systems using physically unclonable functions</article-title>,&#x201D; <source>IEEE Transactions on Information Forensics and Security</source>, vol. <volume>13</volume>, no. <issue>11</issue>, pp. <fpage>2831</fpage>&#x2013;<lpage>2843</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Ostad-Sharif</surname></string-name>, <string-name><given-names>D.</given-names> <surname>Abbasinezhad-Mood</surname></string-name> and <string-name><given-names>M.</given-names> <surname>Nikooghadam</surname></string-name></person-group>, &#x201C;<article-title>A robust and efficient ECC-based mutual authentication and session key generation scheme for healthcare applications</article-title>,&#x201D; <source>Journal of Medical Systems</source>, vol. <volume>43</volume>, no. <issue>1</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>22</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>B. D.</given-names> <surname>Deebak</surname></string-name>, <string-name><given-names>F.</given-names> <surname>Al-Turjman</surname></string-name> and <string-name><given-names>L.</given-names> <surname>Mostarda</surname></string-name></person-group>, &#x201C;<article-title>A hash-based RFID authentication mechanism for context-aware management in IoT-based multimedia systems</article-title>,&#x201D; <source>Sensors</source>, vol. <volume>19</volume>, no. <issue>18</issue>, pp. <fpage>3821</fpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>V.</given-names> <surname>Sureshkumar</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Amin</surname></string-name>, <string-name><given-names>V.</given-names> <surname>Vijaykumar</surname></string-name> and <string-name><given-names>S. R.</given-names> <surname>Sekar</surname></string-name></person-group>, &#x201C;<article-title>Robust secure communication protocol for smart healthcare system with FPGA implementation</article-title>,&#x201D; <source>Future Generation Computer Systems</source>, vol. <volume>100</volume>, pp. <fpage>938</fpage>&#x2013;<lpage>951</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>P.</given-names> <surname>Chandrakar</surname></string-name></person-group>, &#x201C;<article-title>A secure remote user authentication protocol for healthcare monitoring using wireless medical sensor networks</article-title>,&#x201D; <source>International Journal of Ambient Computing and Intelligence (IJACI</source><italic>)</italic>, vol. <volume>10</volume>, no. <issue>1</issue>, pp. <fpage>96</fpage>&#x2013;<lpage>116</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>X.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Peng</surname></string-name>, <string-name><given-names>M. S.</given-names> <surname>Obaidat</surname></string-name>, <string-name><given-names>F.</given-names> <surname>Wu</surname></string-name>, <string-name><given-names>M. K.</given-names> <surname>Khan</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>A secure three-factor user authentication protocol with forward secrecy for wireless medical sensor network systems</article-title>,&#x201D; <source>IEEE Systems Journal</source>, vol. <volume>14</volume>, no. <issue>1</issue>, pp. <fpage>39</fpage>&#x2013;<lpage>50</lpage>, <year>2019</year></mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Adil</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Attique</surname></string-name>, <string-name><given-names>M. M.</given-names> <surname>Khan</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Ali</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Farouk</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>HOPCTP: A robust channel categorization data preservation scheme for industrial healthcare Internet of Things</article-title>,&#x201D; <source>IEEE Transactions on Industrial Informatics</source>, vol. <volume>18</volume>, no. <issue>10</issue>, pp. <fpage>7151</fpage>&#x2013;<lpage>7161</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>X.</given-names> <surname>Cheng</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>F.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Zhao</surname></string-name>, <string-name><given-names>T.</given-names> <surname>Wang</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Secure identity authentication of community medical Internet of Things</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>7</volume>, pp. <fpage>115966</fpage>&#x2013;<lpage>115977</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>H.</given-names> <surname>Sun</surname></string-name> and <string-name><given-names>R.</given-names> <surname>Grishman</surname></string-name></person-group>, &#x201C;<article-title>Lexicalized dependency paths based supervised learning for relation extraction</article-title>,&#x201D; <source>Computer Systems Science and Engineering</source>, vol. <volume>43</volume>, no. <issue>3</issue>, pp. <fpage>861</fpage>&#x2013;<lpage>870</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Ji</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Gui</surname></string-name>, <string-name><given-names>T.</given-names> <surname>Zhou</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Yan</surname></string-name> and <string-name><given-names>J.</given-names> <surname>Shen</surname></string-name></person-group>, &#x201C;<article-title>An efficient and certificateless conditional privacy-preserving authentication scheme for wireless body area networks big data services</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>6</volume>, pp. <fpage>69603</fpage>&#x2013;<lpage>69611</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Z.</given-names> <surname>Guo</surname></string-name></person-group>, &#x201C;<article-title>Cryptanalysis of a certificateless conditional privacy-preserving authentication scheme for wireless body area networks</article-title>,&#x201D; <source>International Journal of Electronics and Information Engineering</source>, vol. <volume>11</volume>, no. <issue>1</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>8</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>B. D.</given-names> <surname>Deebak</surname></string-name>, <string-name><given-names>F.</given-names> <surname>Al-Turjman</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Aloqaily</surname></string-name> and <string-name><given-names>O.</given-names> <surname>Alfandi</surname></string-name></person-group>, &#x201C;<article-title>An authentic-based privacy preservation protocol for smart e-healthcare systems in IoT</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>7</volume>, pp. <fpage>135632</fpage>&#x2013;<lpage>135649</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Manimurugan</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Al-Mutairi</surname></string-name>, <string-name><given-names>M. M.</given-names> <surname>Aborokbah</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Chilamkurti</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Ganesan</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Effective attack detection in Internet of Medical Things smart environment using a deep belief neural network</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>8</volume>, pp. <fpage>77396</fpage>&#x2013;<lpage>77404</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Bengag</surname></string-name>, <string-name><given-names>O.</given-names> <surname>Moussaoui</surname></string-name> and <string-name><given-names>M.</given-names> <surname>Moussaoui</surname></string-name></person-group>, &#x201C;<article-title>A new IDS for detecting jamming attacks in WBAN</article-title>,&#x201D; in <conf-name>Third Int. Conf. on Intelligent Computing in Data Sciences (ICDS)</conf-name>, Marrakech-Morocco, pp. <fpage>1</fpage>&#x2013;<lpage>5</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Ren</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Guo</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Qian</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Yuan</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Hao</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Building an effective intrusion detection system by using hybrid data optimization based on machine learning algorithms</article-title>,&#x201D; <source>Security and Communication Networks</source>, vol. <volume>2019</volume>, pp. <fpage>1</fpage>&#x2013;<lpage>11</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-33"><label>[33]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>D.</given-names> <surname>Rangwani</surname></string-name> and <string-name><given-names>H.</given-names> <surname>Om</surname></string-name></person-group>, &#x201C;<article-title>A secure user authentication protocol based on ECC for cloud computing environment</article-title>,&#x201D; <source>Arabian Journal for Science and Engineering</source>, vol. <volume>46</volume>, no. <issue>4</issue>, pp. <fpage>3865</fpage>&#x2013;<lpage>3888</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-34"><label>[34]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S. A.</given-names> <surname>Chaudhry</surname></string-name>, <string-name><given-names>I. L.</given-names> <surname>Kim</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Rho</surname></string-name>, <string-name><given-names>M. S.</given-names> <surname>Farash</surname></string-name> and <string-name><given-names>T.</given-names> <surname>Shon</surname></string-name></person-group>, &#x201C;<article-title>An improved anonymous authentication scheme for distributed mobile cloud computing services</article-title>,&#x201D; <source>Cluster Computing</source>, vol. <volume>22</volume>, no. <issue>1</issue>, pp. <fpage>1595</fpage>&#x2013;<lpage>1609</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-35"><label>[35]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J. J.</given-names> <surname>Hathaliya</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Tanwar</surname></string-name> and <string-name><given-names>R.</given-names> <surname>Evans</surname></string-name></person-group>, &#x201C;<article-title>Securing electronic healthcare records: A mobile-based biometric authentication approach</article-title>,&#x201D; <source>Journal of Information Security and Applications</source>, vol. <volume>53</volume>, pp. <fpage>102528</fpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-36"><label>[36]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Nikooghadam</surname></string-name> and <string-name><given-names>H.</given-names> <surname>Amintoosi</surname></string-name></person-group>, &#x201C;<article-title>Secure communication in CloudIoT through design of a lightweight authentication and session key agreement scheme</article-title>,&#x201D; <source>International Journal of Communication Systems</source>, vol. <volume>36</volume>, pp. <fpage>e4332</fpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-37"><label>[37]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>H. A.</given-names> <surname>El Zouka</surname></string-name> and <string-name><given-names>M. M.</given-names> <surname>Hosni</surname></string-name></person-group>, &#x201C;<article-title>Secure IoT communications for smart healthcare monitoring system</article-title>,&#x201D; <source>Internet of Things</source>, vol. <volume>13</volume>, pp. <fpage>100036</fpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-38"><label>[38]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Ali</surname></string-name>, <string-name><given-names>H. A.</given-names> <surname>Rahim</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Ali</surname></string-name>, <string-name><given-names>M. F.</given-names> <surname>Pasha</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Masud</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>A novel secure blockchain framework for accessing electronic health records using multiple certificate authority</article-title>,&#x201D; <source>Applied Sciences</source>, vol. <volume>11</volume>, no. <issue>21</issue>, pp. <fpage>9999</fpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-39"><label>[39]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Chatterjee</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Roy</surname></string-name>, <string-name><given-names>A. K.</given-names> <surname>Das</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Chattopadhyay</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Kumar</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Secure biometric-based authentication scheme using chebyshev chaotic map for multi-server environment</article-title>,&#x201D; <source>IEEE Transactions on Dependable and Secure Computing</source>, vol. <volume>15</volume>, no. <issue>5</issue>, pp. <fpage>824</fpage>&#x2013;<lpage>839</lpage>, <year>2016</year>.</mixed-citation></ref>
<ref id="ref-40"><label>[40]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Qiu</surname></string-name>, <string-name><given-names>D.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>G.</given-names> <surname>Xu</surname></string-name> and <string-name><given-names>S.</given-names> <surname>Kumari</surname></string-name></person-group>, &#x201C;<article-title>Practical and provably secure three-factor authentication protocol based on extended chaotic-maps for mobile lightweight devices</article-title>,&#x201D; <source>IEEE Transactions on Dependable and Secure Computing</source>, vol. <volume>19</volume>, no. <issue>2</issue>, pp. <fpage>1338</fpage>&#x2013;<lpage>1351</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-41"><label>[41]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S. A.</given-names> <surname>Chaudhry</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Naqvi</surname></string-name> and <string-name><given-names>M. K.</given-names> <surname>Khan</surname></string-name></person-group>, &#x201C;<article-title>An enhanced lightweight anonymous biometric based authentication scheme for TMIS</article-title>,&#x201D; <source>Multimedia Tools and Applications</source>, vol. <volume>77</volume>, no. <issue>5</issue>, pp. <fpage>5503</fpage>&#x2013;<lpage>5524</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-42"><label>[42]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Rana</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Shafiq</surname></string-name>, <string-name><given-names>I.</given-names> <surname>Altaf</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Alazab</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Mahmood</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>A secure and lightweight authentication scheme for next generation IoT infrastructure</article-title>,&#x201D; <source>Computer Communications</source>, vol. <volume>165</volume>, pp. <fpage>85</fpage>&#x2013;<lpage>96</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-43"><label>[43]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>D.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Cheng</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Huang</surname></string-name> and <string-name><given-names>G.</given-names> <surname>Jian</surname></string-name></person-group>, &#x201C;<article-title>Zipf&#x2019;s law in passwords</article-title>,&#x201D; <source>IEEE Transactions on Information Forensics and Security</source>, vol. <volume>12</volume>, no. <issue>11</issue>, pp. <fpage>2776</fpage>&#x2013;<lpage>2791</lpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-44"><label>[44]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>V.</given-names> <surname>Boyko</surname></string-name>, <string-name><given-names>P.</given-names> <surname>MacKenzie</surname></string-name> and <string-name><given-names>S.</given-names> <surname>Patel</surname></string-name></person-group>, &#x201C;<article-title>Provably secure password-authenticated key exchange using diffie-hellman</article-title>,&#x201D; in <conf-name>Int. Conf. on the Theory and Applications of Cryptographic Techniques</conf-name>, pp. <fpage>156</fpage>&#x2013;<lpage>171</lpage>, <year>2000</year>.</mixed-citation></ref>
<ref id="ref-45"><label>[45]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Safkhani</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Vasilakos</surname></string-name></person-group>, &#x201C;<article-title>A new secure authentication protocol for telecare medicine information system and smart campus</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>7</volume>, pp. <fpage>23514</fpage>&#x2013;<lpage>23526</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-46"><label>[46]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Z.</given-names> <surname>Zhou</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Wang</surname></string-name> and <string-name><given-names>Z.</given-names> <surname>Li</surname></string-name></person-group>, &#x201C;<article-title>A quadratic residue-based RFID authentication protocol with enhanced security for TMIS</article-title>,&#x201D; <source>Journal of Ambient Intelligence and Humanized Computing</source>, vol. <volume>10</volume>, no. <issue>9</issue>, pp. <fpage>3603</fpage>&#x2013;<lpage>3615</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-47"><label>[47]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S. F.</given-names> <surname>Aghili</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Mala</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Kaliyar</surname></string-name> and <string-name><given-names>M.</given-names> <surname>Conti</surname></string-name></person-group>, &#x201C;<article-title>SecLAP: Secure and lightweight RFID authentication protocol for medical IoT</article-title>,&#x201D; <source>Future Generation Computer Systems</source>, vol. <volume>101</volume>, pp. <fpage>621</fpage>&#x2013;<lpage>634</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-48"><label>[48]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S. A.</given-names> <surname>Chaudhry</surname></string-name></person-group>, &#x201C;<article-title>Correcting &#x201C;PALK: Password-based anonymous lightweight key agreement framework for smart grid</article-title>,&#x201D; <source>International Journal of Electrical Power &#x0026; Energy Systems</source>, vol. <volume>125</volume>, pp. <fpage>106529</fpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-49"><label>[49]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Shuai</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Yu</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Wang</surname></string-name> and <string-name><given-names>L.</given-names> <surname>Xiong</surname></string-name></person-group>, &#x201C;<article-title>Anonymous authentication scheme for smart home environment with provable security</article-title>,&#x201D; <source>Computers &#x0026; Security</source>, vol. <volume>86</volume>, pp. <fpage>132</fpage>&#x2013;<lpage>146</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-50"><label>[50]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Mo</surname></string-name> and <string-name><given-names>H.</given-names> <surname>Chen</surname></string-name></person-group>, &#x201C;<article-title>A lightweight secure user authentication and key agreement protocol for wireless sensor networks</article-title>,&#x201D; <source>Security and Communication Networks</source>, vol. <volume>2019</volume>, pp. <fpage>1</fpage>&#x2013;<lpage>17</lpage>, <year>2019</year>.</mixed-citation></ref>
</ref-list>
</back></article>