<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="review-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMC</journal-id>
<journal-id journal-id-type="nlm-ta">CMC</journal-id>
<journal-id journal-id-type="publisher-id">CMC</journal-id>
<journal-title-group>
<journal-title>Computers, Materials &#x0026; Continua</journal-title>
</journal-title-group>
<issn pub-type="epub">1546-2226</issn>
<issn pub-type="ppub">1546-2218</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">48796</article-id>
<article-id pub-id-type="doi">10.32604/cmc.2024.048796</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Review</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Recent Developments in Authentication Schemes Used in Machine-Type Communication Devices in Machine-to-Machine Communication: Issues and Challenges</article-title>
<alt-title alt-title-type="left-running-head">Recent Developments in Authentication Schemes Used in Machine-Type Communication Devices in Machine-to-Machine Communication: Issues and Challenges</alt-title>
<alt-title alt-title-type="right-running-head">Recent Developments in Authentication Schemes Used in Machine-Type Communication Devices in Machine-to-Machine Communication: Issues and Challenges</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author">
<name name-style="western"><surname>Ullah</surname><given-names>Shafi</given-names></name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-2" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Bazai</surname><given-names>Sibghat Ullah</given-names></name><xref ref-type="aff" rid="aff-1">1</xref><email>sibghat.ullah@buitms.edu.pk</email></contrib>
<contrib id="author-3" contrib-type="author">
<name name-style="western"><surname>Imran</surname><given-names>Mohammad</given-names></name><xref ref-type="aff" rid="aff-2">2</xref></contrib>
<contrib id="author-4" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Ilyas</surname><given-names>Qazi Mudassar</given-names></name><xref ref-type="aff" rid="aff-3">3</xref><email>qilyas@kfu.edu.sa</email></contrib>
<contrib id="author-5" contrib-type="author">
<name name-style="western"><surname>Mehmood</surname><given-names>Abid</given-names></name><xref ref-type="aff" rid="aff-4">4</xref></contrib>
<contrib id="author-6" contrib-type="author">
<name name-style="western"><surname>Saleem</surname><given-names>Muhammad Asim</given-names></name><xref ref-type="aff" rid="aff-5">5</xref></contrib>
<contrib id="author-7" contrib-type="author">
<name name-style="western"><surname>Rafique</surname><given-names>Muhmmad Aasim</given-names></name><xref ref-type="aff" rid="aff-3">3</xref></contrib>
<contrib id="author-8" contrib-type="author">
<name name-style="western"><surname>Haider</surname><given-names>Arsalan</given-names></name><xref ref-type="aff" rid="aff-6">6</xref></contrib>
<contrib id="author-9" contrib-type="author">
<name name-style="western"><surname>Khan</surname><given-names>Ilyas</given-names></name><xref ref-type="aff" rid="aff-7">7</xref></contrib>
<contrib id="author-10" contrib-type="author">
<name name-style="western"><surname>Iqbal</surname><given-names>Sajid</given-names></name><xref ref-type="aff" rid="aff-3">3</xref></contrib>
<contrib id="author-11" contrib-type="author">
<name name-style="western"><surname>Gulzar</surname><given-names>Yonis</given-names></name><xref ref-type="aff" rid="aff-4">4</xref></contrib>
<contrib id="author-12" contrib-type="author">
<name name-style="western"><surname>Hameed</surname><given-names>Kauser</given-names></name><xref ref-type="aff" rid="aff-3">3</xref></contrib>
<aff id="aff-1"><label>1</label><institution>Department of Computer Engineering, Balochistan University of Information Technology, Engineering and Management Sciences</institution>, <addr-line>Quetta, 87300</addr-line>, <country>Pakistan</country></aff>
<aff id="aff-2"><label>2</label><institution>Department of Information Technology, Balochistan University of Information Technology, Engineering, and Management Sciences</institution>, <addr-line>Quetta, 87300</addr-line>, <country>Pakistan</country></aff>
<aff id="aff-3"><label>3</label><institution>Department of Information Systems, College of Computer Sciences and Information Technology, King Faisal University</institution>, <addr-line>Hofuf in Al-Ahsa, 31982</addr-line>, <country>Saudi Arabia</country></aff>
<aff id="aff-4"><label>4</label><institution>Department of Management Information Systems, College of Business Administration, King Faisal University</institution>, <addr-line>Hofuf in Al-Ahsa, 31982</addr-line>, <country>Saudi Arabia</country></aff>
<aff id="aff-5"><label>5</label><institution>Department of Software Engineering, College of Computing, Riphah International University</institution>, <addr-line>Faisalabad, 44000</addr-line>, <country>Pakistan</country></aff>
<aff id="aff-6"><label>6</label><institution>Department of Electrical Engineering Balochistan University of Information Technology, Engineering, and Management Sciences</institution>, <addr-line>Quetta, 87300</addr-line>, <country>Pakistan</country></aff>
<aff id="aff-7"><label>7</label><institution>Department of Mathematics, College of Science Al-Zulfi, Majmaah University</institution>, <addr-line>Al-Majmaah, 11952</addr-line>, <country>Saudi Arabia</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Authors: Sibghat Ullah Bazai. Email: <email>sibghat.ullah@buitms.edu.pk</email>; Qazi Mudassar Ilyas. Email: <email>qilyas@kfu.edu.sa</email></corresp>
</author-notes>
<pub-date date-type="collection" publication-format="electronic"><year>2024</year></pub-date>
<pub-date date-type="pub" publication-format="electronic"><day>25</day><month>4</month><year>2024</year></pub-date>
<volume>79</volume>
<issue>1</issue>
<fpage>93</fpage>
<lpage>115</lpage>
<history>
<date date-type="received"><day>19</day><month>12</month><year>2023</year></date>
<date date-type="accepted"><day>14</day><month>2</month><year>2024</year></date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2024 Ullah et al.</copyright-statement>
<copyright-year>2024</copyright-year>
<copyright-holder>Ullah et al.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMC_48796.pdf"></self-uri>
<abstract>
<p>Machine-to-machine (M2M) communication plays a fundamental role in autonomous IoT (Internet of Things)-based infrastructure, a vital part of the fourth industrial revolution. Machine-type communication devices (MTCDs) regularly share extensive data without human intervention while making all types of decisions. These decisions may involve controlling sensitive ventilation systems maintaining uniform temperature, live heartbeat monitoring, and several different alert systems. Many of these devices simultaneously share data to form an automated system. The data shared between machine-type communication devices (MTCDs) is prone to risk due to limited computational power, internal memory, and energy capacity. Therefore, securing the data and devices becomes challenging due to factors such as dynamic operational environments, remoteness, harsh conditions, and areas where human physical access is difficult. One of the crucial parts of securing MTCDs and data is authentication, where each device must be verified before data transmission. Several M2M authentication schemes have been proposed in the literature, however, the literature lacks a comprehensive overview of current M2M authentication techniques and the challenges associated with them. To utilize a suitable authentication scheme for specific scenarios, it is important to understand the challenges associated with it. Therefore, this article fills this gap by reviewing the state-of-the-art research on authentication schemes in MTCDs specifically concerning application categories, security provisions, and performance efficiency.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Authentication</kwd>
<kwd>cyber security</kwd>
<kwd>internet of things</kwd>
<kwd>machine-type communication devices</kwd>
<kwd>machine-to-machine communication</kwd>
</kwd-group>
<funding-group>
<award-group id="awg1">
<funding-source>Deanship of Scientific Research, Vice Presidency for Graduate Studies and Scientific Research, King Faisal University, Saudi Arabia</funding-source>
<award-id>GRANT5,208</award-id>
</award-group>
</funding-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>Internet usage has become an indispensable part of routine life. It has become integral in every facet of human lives, whether directly or indirectly, encompassing finance, education, healthcare, and social interactions. As of 2023, the global count of internet users has reached 5.18 billion, which indicates that approximately two-thirds of the world&#x2019;s population is presently linked to the World Wide Web [<xref ref-type="bibr" rid="ref-1">1</xref>,<xref ref-type="bibr" rid="ref-2">2</xref>]. Besides, the world of automation has also created a surge. It has not only enabled humans to communicate over the Internet but also enabled machines to communicate with each other through M2M (machine-to-machine) and MTCDs (machine-type communication devices) technologies where human intervention is no longer a mandate. It is estimated that by 2025, over fifty billion devices will be employed in the cause. Compact and well-designed equipment, also known as MTC (machine-type communication) devices, are handed down in everyone&#x2019;s life, ranging from smart refrigerators, televisions, and air-conditioner controllers to smart health devices, smart offices, and smart parking. These devices serve multiple functions, such as monitoring air quality in homes, sensing the environment in cities, granting access to authorized personnel in the office via smart doors, regulating specific machines controlled by the ventilation system, and tracking vital signs like heart rate and body temperature, transmitting this health data to physicians, securing parking spots in advance on busy streets, and generating environmental data for informed decision-making and future predictions. These devices utilize internet connectivity to share data and execute tasks based on pre-programmed logic. Despite their small size, cost-effectiveness, and limited computational abilities, these diminutive yet intelligent devices communicate, exchanging information as depicted in <xref ref-type="fig" rid="fig-1">Fig. 1</xref>.</p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>M2M communication applications</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_48796-fig-1.tif"/>
</fig>
<p>The information exchanged by these MTCs can range from public data to overly sensitive information. For instance, a device might share temperature data from a power station to regulate fans, while another might transmit a remote heart patient&#x2019;s heartbeat data to their doctor. Similarly, life-threatening dangers can arise from hacking into medical device MTCDs. In smart grids, unauthorized access can potentially interfere with electricity distribution and cause blackouts. In the case of industrial IoT (Internet of Things) networks, unauthorized access can impact safety and manufacturing operations. In the context of smart homes, unauthorized control of IoT devices threatens the privacy and security of residents [<xref ref-type="bibr" rid="ref-1">1</xref>]. Similarly, certain devices control access to secure military facilities. In these scenarios, the shared data is exceptionally sensitive. However, as MTCDs lack inherent security measures, external physical safeguards are not always feasible since these devices are meant to function remotely and autonomously.</p>
<p>Moreover, securing data and devices becomes challenging due to various factors, including limited connectivity, harsh environmental conditions, restricted physical access, power constraints, and limited maintenance opportunities. MTCDs deployed in remote locations often suffer from brittle network connectivity, which may compromise real-time communication with security infrastructure. As a result, security updates, patches, and monitoring activities are delayed, which increases devices&#x2019; vulnerability to emerging security threats. Harsh environmental conditions, temperature variations, and exposure to dust or moisture harm the physical integrity of MTCDs, which causes hardware degradation and compromises the device&#x2019;s ability to enforce security measures. Restricted physical access to MTCDs makes physical security measures challenging to implement. It also raises concerns about unauthorized access, tampering, or theft of devices. MTCDs deployed in remote environments usually lack reliable power sources and rely on batteries. Insufficient power can lead to unexpected device shutdowns, leaving systems unprotected during critical times. Finally, there are limited maintenance and update opportunities for MTCDs in remote or harsh environments, which results in outdated firmware or security protocols that may expose devices to known vulnerabilities.</p>
<p>The threats mentioned above may be mitigated by carefully implementing device, data, and user authentication mechanisms. A robust device authentication mechanism involves a secure device provisioning through device identity verification during device enrollment on the network, a mutual authentication mechanism to enforce mutual authentication between devices and network servers, and multi-factor authentication by requiring multiple credentials, e.g., digital certificates, hardware tokens, or passwords for device access. Data authentication can be implemented through digital signatures, message authentication codes, and hash functions. User authentication can be implemented through strong password policies, role-based access control, and biometric authentication.</p>
<p>Consequently, these devices rely solely on software-based security measures. Owing to their limited computational and memory capacities, conventional Internet security protocols do not always apply to these IoTs [<xref ref-type="bibr" rid="ref-3">3</xref>]. Effectively operating MTC communication necessitates a network of MTC-based devices. This network may, in turn, consist of several connected devices, and every device must be trusted to ensure security. This is achieved via authentication, where every device in the network must authenticate itself so that the data is considered trusted.</p>
<p>This review is based on authentication techniques proposed in different applications for securing MTC devices under the IoT (Internet of Things) framework. This article represents a thorough review of the authentication of MTC devices in M2M (machine-to-machine) communication in three categories, i.e., <italic>local</italic>, <italic>group</italic>, and <italic>factor-based</italic> authentication techniques, where several related techniques are analyzed regarding performance efficiency, security, and adaptability.</p>
<sec id="s1_1">
<label>1.1</label>
<title>Contribution of Research</title>
<p>This work offers a thorough idea to the researcher related to the perceptual layer security requirements and features in M2M communication networks, as MTC devices are best suited for efficient performance in the perceptual layer. Moreover, the work categorizes authentication schemes into three categories and compares different authentication schemes. Furthermore, the authentication taxonomy in the last section offers a thorough understanding of authentication features and processes in the recent IoT security developments.</p>
<p>The paper is organized in the following manner. <xref ref-type="sec" rid="s2">Section 2</xref> represents Authentication in MTC devices, including perception layer security threats and requirements. <xref ref-type="sec" rid="s3">Section 3</xref> offers comparative analysis features adopted to analyze the categorized authentication schemes in the M2M communication network. <xref ref-type="sec" rid="s3">Section 3</xref> highlights issues and challenges. The paper is concluded in <xref ref-type="sec" rid="s5">Section 5</xref>.</p>
</sec>
</sec>
<sec id="s2">
<label>2</label>
<title>Machine-Type Communication Devices</title>
<p>MTC devices are autonomous IoT devices whose core functionality is to operate in remote areas in M2M communication networks. These devices are mostly battery-powered that collect, process, and transmit data to central nodes or gateways to be stored on the cloud for further processes [<xref ref-type="bibr" rid="ref-4">4</xref>].</p>
<sec id="s2_1">
<label>2.1</label>
<title>MTC Device Layers</title>
<p>The functions of these devices are distributed in four layers, as summarized in <xref ref-type="table" rid="table-1">Table 1</xref>.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>Generic four-layer architecture of IoT</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Layers</th>
<th>Name</th>
<th>Function</th>
<th>Devices/Applications</th>
</tr>
</thead>
<tbody valign="top">
<tr>
<td>Layer 4 [<xref ref-type="bibr" rid="ref-5">5</xref>]</td>
<td>Application layer</td>
<td><list list-type="bullet">
<list-item>
<p>Representation of collected and processed data into a pre-defined graphical interface.</p></list-item>
<list-item>
<p>To automate and make smart decisions by the device.</p></list-item>
<list-item>
<p>Smart IoT business applications.</p></list-item>
</list></td>
<td><list list-type="bullet">
<list-item>
<p>Smart home automation system</p></list-item>
<list-item>
<p>Smart healthcare system</p></list-item>
<list-item>
<p>Smart industry</p></list-item>
</list></td>
</tr>
<tr>
<td>Layer 3 [<xref ref-type="bibr" rid="ref-6">6</xref>]</td>
<td>Middle-ware layer</td>
<td><list list-type="bullet">
<list-item>
<p>Data management functions.</p></list-item>
<list-item>
<p>Automate the flow of tasks based on received information from the perception or network layer.</p></list-item>
<list-item>
<p>Inclusion of database-related actions for storage.</p></list-item>
</list></td>
<td><list list-type="bullet">
<list-item>
<p>Software-based</p></list-item>
<list-item>
<p>Built-in circuitry</p></list-item>
</list></td>
</tr>
<tr>
<td>Layer 2 [<xref ref-type="bibr" rid="ref-7">7</xref>]</td>
<td>Network layer</td>
<td><list list-type="bullet">
<list-item>
<p>Data generated from sensors is converted into packets to match standard protocol patterns.</p></list-item>
<list-item>
<p>Forwarding data packets to 3G, LTE structured packets in wire/wireless medium.</p></list-item>
</list></td>
<td><list list-type="bullet">
<list-item>
<p>Utilizing standard communication equipment</p></list-item>
<list-item>
<p>Software-based</p></list-item>
<list-item>
<p>Built-in circuitry</p></list-item>
</list></td>
</tr>
<tr>
<td>Layer 1 [<xref ref-type="bibr" rid="ref-8">8</xref>]</td>
<td>Perception layer</td>
<td><list list-type="bullet">
<list-item>
<p>Data generation layer, sensing environmental data from sensors and actuators and converting it to digital information.</p></list-item>
<list-item>
<p>These sensors collect data and send it to MTC devices, which are further processed for transmission.</p></list-item>
</list></td>
<td><list list-type="bullet">
<list-item>
<p>Temperature, pressure, humidity, and heartbeat sensors</p></list-item>
<list-item>
<p>RFID, barcode readers</p></list-item>
<list-item>
<p>ZigBee, Bluetooth</p></list-item>
</list></td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s2_2">
<label>2.2</label>
<title>Security Features in the Perception Layer of MTC Devices</title>
<p>Research offered by [<xref ref-type="bibr" rid="ref-4">4</xref>] and [<xref ref-type="bibr" rid="ref-9">9</xref>] shows that the perceptual layer security can be separated into two categories, i.e., security and technological challenges. The technological category focuses on challenges due to the dynamic topologies of MTC devices and the ubiquitous behavior of IoT and M2M network applications. It includes areas such as energy, power, distributed features, and risks. Whereas, security challenges primarily aim to address solutions and weaknesses in end-to-end encryption, data integrity, data confidentiality, and scalability to ensure authentication between these devices [<xref ref-type="bibr" rid="ref-9">9</xref>]. Moreover, the authentication scheme is chosen considering the nature of communication within the network and the type of business application required, and with certain cryptosystem techniques.</p>
<p><xref ref-type="table" rid="table-2">Table 2</xref> represents perceptual layer security features for MTC devices in the M2M communication network. Each perceptual layer security feature enhances resilience against the perceptual layer security threats, as shown in <xref ref-type="table" rid="table-3">Table 3</xref>. The represented authentication schemes are tested for performance efficiency and verified for security proofs against several features, as shown in <xref ref-type="table" rid="table-4">Table 4</xref>.</p>
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>Perception layer security features in M2M communication</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th></th>
<th>Features</th>
<th>Description</th>
<th>Ref.</th>
</tr>
</thead>
<tbody valign="top">
<tr>
<td/>
<td>Data integrity</td>
<td>Data integrity is the accuracy of data shared between devices. It ensures that data from the sender device is trusted, accurate, and clean from intended or unintended interference, usually made possible by imposing end-to-end encryption.</td>
<td>[<xref ref-type="bibr" rid="ref-10">10</xref>]</td>
</tr>
<tr>
<td>BASIC</td>
<td>Privacy</td>
<td>Privacy of shared sensitive data is paramount. The sensitivity of data mainly depends on the type of IoT application. It refers to both the confidentiality of data and the privacy of the device that shares it.</td>
<td>[<xref ref-type="bibr" rid="ref-3">3</xref>]</td>
</tr>
<tr>
<td/>
<td>Authentication</td>
<td>It is a key security feature because communication between numerous devices of heterogeneous nature makes it vital for the data sender to be trusted. During authentication, all participating devices in the communication must be authenticated to establish trust.</td>
<td>[<xref ref-type="bibr" rid="ref-11">11</xref>]</td>
</tr>
<tr>
<td/>
<td>Data availability</td>
<td>It serves devices with a constant flow of data whenever data is required. The main purpose of MTC devices is to operate all the time under any circumstances with minimal cost, even during times of failure, despite the system facing a disastrous situation.</td>
<td>[<xref ref-type="bibr" rid="ref-12">12</xref>]</td>
</tr>
<tr>
<td/>
<td>Data confidentiality</td>
<td>Data transmitted from a device is not only kept secret from other users but from neighboring devices as well. It is maintained by combining features of authentication and integrity, where authentication establishes trust between devices (operated by either user or device), and integrity ensures the shared data is reliable.</td>
<td>[<xref ref-type="bibr" rid="ref-13">13</xref>]</td>
</tr>
<tr>
<td/>
<td>Access control</td>
<td>It manipulates access of MTC devices to back-end servers during requested access. Only authorized devices can be granted access to certain entities, including servers and other crucial devices.</td>
<td>[<xref ref-type="bibr" rid="ref-14">14</xref>]</td>
</tr>
<tr>
<td>ADVANCED</td>
<td>Data freshness</td>
<td>Data freshness ensures that only currently transmitted messages from MTC devices are received. Previously transmitted messages are discarded and cannot be read by newly added devices or devices that have left the system.</td>
<td>[<xref ref-type="bibr" rid="ref-15">15</xref>]</td>
</tr>
<tr>
<td/>
<td>Data secrecy</td>
<td>Data secrecy focuses on message security from newly joined MTC devices or devices that have left the network. Each message header represents a new encrypted key that can only be decrypted or decoded by current devices.</td>
<td>[<xref ref-type="bibr" rid="ref-15">15</xref>]</td>
</tr>
<tr>
<td/>
<td>Forward secrecy</td>
<td>It ensures that encrypted keys cannot be compromised, and long-term secrets can be kept despite adding more devices and users.</td>
<td>[<xref ref-type="bibr" rid="ref-15">15</xref>]</td>
</tr>
<tr>
<td/>
<td>Backward secrecy</td>
<td>It assures that the adversary who knows a subset of keys cannot discover the previous keys despite adding and removing new and old devices.</td>
<td>[<xref ref-type="bibr" rid="ref-16">16</xref>]</td>
</tr>
<tr>
<td/>
<td>Non-repudiation</td>
<td>It improves message delivery by not denying message packets once MTC devices transmit them.</td>
<td>[<xref ref-type="bibr" rid="ref-15">15</xref>]</td>
</tr>
<tr>
<td/>
<td>Collision detection</td>
<td>It is a combination of several inputs that produce the same hash value. It must be kept highly random and challenging to acquire a proper set of these inputs.</td>
<td>[<xref ref-type="bibr" rid="ref-17">17</xref>]</td>
</tr>
</tbody>
</table>
</table-wrap><table-wrap id="table-3">
<label>Table 3</label>
<caption>
<title>Perception layer security attacks in M2M communication devices</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Attacks</th>
<th>Description</th>
<th>Ref.</th>
</tr>
</thead>
<tbody valign="top">
<tr>
<td>Trojan hardware</td>
<td>It is an integrated circuity fabricated attack to influence the data by attaching a fictitious IC on a device to exploit functionality. Attackers use such ICs to copy ongoing shared data for a certain period.</td>
<td>[<xref ref-type="bibr" rid="ref-18">18</xref>,<xref ref-type="bibr" rid="ref-19">19</xref>]</td>
</tr>
<tr>
<td>Non-network side channel</td>
<td>The wireless signals generate electromagnetic waves that transmit critical data. Researchers demonstrated acoustic, electromagnetic signals leaking from an isolated MTC device that released sensitive information, resulting in data privacy and confidentially vulnerabilities.</td>
<td>[<xref ref-type="bibr" rid="ref-20">20</xref>]</td>
</tr>
<tr>
<td>DoS</td>
<td>Such attacks on IoTs and MTC devices stop functionality by transmitting sensors&#x2019; HIGH/LOW-status signals to keep the device occupied. It further aims to deplete the device from power and sleep to waste power and energy.</td>
<td>[<xref ref-type="bibr" rid="ref-21">21</xref>]</td>
</tr>
<tr>
<td>Power depletion</td>
<td>MTC devices are mostly attached to external batteries with limited energy due to mobility. These Devices consume energy during operation; otherwise, devices go into standby mode to reduce power usage. DoS power depletion attacks aim to send consecutively fake data via sensing circuitry so that devices are kept on consuming power. For example, the device&#x2019;s battery life is so depleted that it cannot work or report in crisis.</td>
<td>[<xref ref-type="bibr" rid="ref-22">22</xref>,<xref ref-type="bibr" rid="ref-23">23</xref>]</td>
</tr>
<tr>
<td>Sleep deprivation</td>
<td>Such an attack bars the device from going into sleep mode by posting undesired requests of HIGH states. The adversary attempts to send bogus signals that are genuine.</td>
<td>[<xref ref-type="bibr" rid="ref-23">23</xref>,<xref ref-type="bibr" rid="ref-24">24</xref>]</td>
</tr>
<tr>
<td>Malfunction</td>
<td>It is an effect of an accidental or intended blunder during sleep deprivation, hardware assembly, code infusion, or power depletion.</td>
<td>[<xref ref-type="bibr" rid="ref-25">25</xref>]</td>
</tr>
<tr>
<td>Outage/blackout attack</td>
<td>Devices suffer blackouts by halting the execution of their typical task. A master MTC device regulates several slave sensing and actuating devices. Thus, if the master device halts functionality, the attached slave devices are also affected.</td>
<td>[<xref ref-type="bibr" rid="ref-26">26</xref>]</td>
</tr>
<tr>
<td>Physical attack</td>
<td>MTC devices are exceptionally vulnerable to physical attacks due to the remote operational ability where human intervention is undesired. The adversary&#x2019;s physical access can extract crucial data, penetrate internal circuitry, modify data transmission lines, and alter functional tasks.</td>
<td>[<xref ref-type="bibr" rid="ref-27">27</xref>]</td>
</tr>
<tr>
<td>Device capture/replication</td>
<td>The adversary captures and replicates with a malicious device, which then intrudes into the network by imitating genuine device features. The attacker will be able to redirect packets to the desired network and can cause damage to the network by discovering pre-shared keys.</td>
<td>[<xref ref-type="bibr" rid="ref-28">28</xref>,<xref ref-type="bibr" rid="ref-29">29</xref>]</td>
</tr>
<tr>
<td>Sensor capture</td>
<td>Sensor capture may result in a DoS attack. Such an attack occurs when the attacker attempts to misguide and manipulate control over the sensor-driven functions.</td>
<td>[<xref ref-type="bibr" rid="ref-29">29</xref>]</td>
</tr>
<tr>
<td>Disguised device</td>
<td>The attacker embeds a fake device or attacks an approved device to cover up at the perception level to store critical data in the flow and divert the traffic.</td>
<td>[<xref ref-type="bibr" rid="ref-29">29</xref>,<xref ref-type="bibr" rid="ref-30">30</xref>]</td>
</tr>
<tr>
<td>Infusing malicious device</td>
<td>A fraudulent device is connected to the network that produces fake and illegitimate requests and attempts to obtain access to neighboring devices. It also attempts to virtually control the system or neighboring devices via the infused malicious code.</td>
<td>[<xref ref-type="bibr" rid="ref-30">30</xref>]</td>
</tr>
<tr>
<td>Eavesdropping</td>
<td>It is the most lethal attack in IoT. Deprived of any significant data encrypting protocol, typical security protocols in MTC devices cannot hide data from such attacks. Eavesdropping is when transmitted data over physical lines of communication is monitored by another device.</td>
<td>[<xref ref-type="bibr" rid="ref-31">31</xref>]</td>
</tr>
<tr>
<td>MiTM</td>
<td>A device monitors the traffic forcibly connected between sender and receiver, and both transmitting and receiving devices have no clue that the communication is being monitored. The monitored data is read thoroughly, interpreted, and decrypted.</td>
<td>[<xref ref-type="bibr" rid="ref-32">32</xref>]</td>
</tr>
<tr>
<td>Spoofing</td>
<td>The transmitting data is monitored briefly, capturing sufficient packets to be interpreted, make sense of the data, and then combined with malicious packets that mimic genuine packets. It is applied on physical transmitting devices over both wired and wireless media.</td>
<td>[<xref ref-type="bibr" rid="ref-31">31</xref>]</td>
</tr>
<tr>
<td>Routing attacks/sybil</td>
<td>Routing protocols that redirect the traffic are targeted during such attacks. A malicious device generates duplicate nodes in the network that redirect traffic to affect performance.</td>
<td>[<xref ref-type="bibr" rid="ref-33">33</xref>]</td>
</tr>
<tr>
<td>Wormhole</td>
<td>It is a combined attack of Spoofing and Sybil. The attacker stores packets over time, interprets the packet, and then redirects the recorded packets to other unauthorized networks.</td>
<td>[<xref ref-type="bibr" rid="ref-34">34</xref>]</td>
</tr>
</tbody>
</table>
</table-wrap><table-wrap id="table-4">
<label>Table 4</label>
<caption>
<title>Comparative analysis tools and features used in M2M communication</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th></th>
<th>Analysis features</th>
<th>Description</th>
<th>Ref.</th>
</tr>
</thead>
<tbody valign="top">
<tr>
<td>Performance</td>
<td>Computational cost</td>
<td>CPU time consumed in successful mutual authentication between two devices.</td>
<td>[<xref ref-type="bibr" rid="ref-35">35</xref>,<xref ref-type="bibr" rid="ref-36">36</xref>]</td>
</tr>
<tr>
<td/>
<td>Communication cost</td>
<td>Time taken in transmitting and receiving packets during a successful mutual authentication process.</td>
<td>[<xref ref-type="bibr" rid="ref-10">10</xref>]</td>
</tr>
<tr>
<td/>
<td>Energy cost</td>
<td>Total power consumption (CPU, idle, transmit, and listen power) in a successful mutual authentication process.</td>
<td>[<xref ref-type="bibr" rid="ref-37">37</xref>]</td>
</tr>
<tr>
<td/>
<td>Storage cost</td>
<td>The total memory consumed (RAM and ROM) in storing pre-shared keys, code size, and heap during a successful mutual authentication process.</td>
<td>[<xref ref-type="bibr" rid="ref-35">35</xref>,<xref ref-type="bibr" rid="ref-36">36</xref>]</td>
</tr>
<tr>
<td rowspan="4">Encrypted key exchange</td>
<td>Key sensitivity</td>
<td>Ability to change whole encrypted block in case of a single bit change in (pre-shared, dynamic, static, public, and private) encrypted keys.</td>
<td>[<xref ref-type="bibr" rid="ref-38">38</xref>]</td>
</tr>
<tr>
<td>Randomness</td>
<td>Ability to produce unique and random key pairs/encrypted blocks. It is also measured as the ratio of bit difference before and after the encryption.</td>
<td>[<xref ref-type="bibr" rid="ref-39">39</xref>]</td>
</tr>
<tr>
<td>Key generation cost</td>
<td>Execution Time and memory consumed during the generation of pre-shared, dynamic, public, or private keys.</td>
<td>[<xref ref-type="bibr" rid="ref-40">40</xref>]</td>
</tr>
<tr>
<td>Cross-correlation</td>
<td>There must be tight cross-correlation between key pairs before and after the encryption of keys.</td>
<td>[<xref ref-type="bibr" rid="ref-1">1</xref>]</td>
</tr>
<tr>
<td rowspan="4">Verification tools</td>
<td>NIST</td>
<td>The robustness of encrypted blocks is analysed by forcibly cracking and decoding the encryption through several advanced statistical procedures.</td>
<td>[<xref ref-type="bibr" rid="ref-39">39</xref>]</td>
</tr>
<tr>
<td>AVISPA</td>
<td>Mutual authentication processes are verified through tight security communication procedures by visualizing the processes of sender and receiver devices.</td>
<td>[<xref ref-type="bibr" rid="ref-41">41</xref>]</td>
</tr>
<tr>
<td>BAN</td>
<td>Logically evaluates transmission messages and ensures the exchanged data&#x2019;s trustworthiness over the media by verifying data origin, freshness, and reliability.</td>
<td>[<xref ref-type="bibr" rid="ref-42">42</xref>]</td>
</tr>
<tr>
<td>ProVerif</td>
<td>This tool is used for automated reasoning related to the security properties in formal cryptographic techniques.</td>
<td>[<xref ref-type="bibr" rid="ref-43">43</xref>,<xref ref-type="bibr" rid="ref-44">44</xref>]</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
</sec>
<sec id="s3">
<label>3</label>
<title>Authentication in MTC Devices</title>
<p>Authentication is a software-based security technique used in different topologies. MTC devices form three types of authentications in M2M communication, i.e., local, group-based, and hybrid (factor-based). In the local authentication, all devices authenticate within the connected network. Any other device outside the network cannot share the data. In comparison, group-based authentication is used for a large number of devices working in simultaneous prospects of applications. Several devices form a group using local authentication techniques and cluster single groups. These groups authenticate other groups, and data is shared. Such authentication processes usually occur in LTE (long-term evolution)/CDMA (code-division multiple access) and 3GPP (3rd Generation Partnership Project)-based network infrastructures.</p>
<p>Moreover, in hybrid or factor-based authentication, M2M communication occurs between an end device, i.e., MTC, and a gateway, making it two-factor authentication. The process of key sharing, encryption, and decryption is performed for both MTC and gateway. Similarly, three-factor authentication involves servers or clouds as the third tier of communication. In such a technique, servers and gateways must utilize similar distributed encrypted keys for authentication. Additionally, mutual authentication is an important part of authentication where data transmitting and receiving devices must mutually authenticate each other before sharing the actual data.</p>
<sec id="s3_1">
<label>3.1</label>
<title>Group-Based Authentication</title>
<p>Such authentication protocols are used when a network consists of a large number of MTC devices. Single-device authentication is costly, and it includes extreme network overheads. Moreover, the area coverage is extremely large. Thus, numerous devices communicate simultaneously, so group-based authentication is effective against network overheads [<xref ref-type="bibr" rid="ref-45">45</xref>]. Standard encryption systems use either symmetric, asymmetric, or hybrid cryptographies. With extreme growth in wireless sensor networks [<xref ref-type="bibr" rid="ref-4">4</xref>], MTC devices are also introduced in LTE-A (long-term evolution-Advanced) networks, implementing 4G heterogeneous networks with low latency. LTE/LET-A networks tend to have a pre-defined authentication system between communication units for MTC network architecture, which was introduced by the 3GPP committee [<xref ref-type="bibr" rid="ref-2">2</xref>]. The network comprises MME (mobile management entity) and HSS (home subscriber server). The architecture includes users or MTC devices and servers, whereas the user is outside the network domain. Users or MTC devices and servers communicate over an API (application programmable interface), as shown in <xref ref-type="fig" rid="fig-2">Fig. 2</xref>. Users or MTC devices must authenticate over the LTE/LTE-A network. In this regard, the EPS-AKA (evolved packet system-based authentication and key agreement) developed a packet delivery system for the 3GPP network with an extended version called EAP-AKA (extensible authentication protocol-authentication and key agreement) for the non-3GPP network over WLAN (wireless local area network)/WiMAX (worldwide interoperability for microwave access) was implemented for the objective of secure data transfer between MTC devices and server [<xref ref-type="bibr" rid="ref-46">46</xref>].</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>Local authentication network structure based on [<xref ref-type="bibr" rid="ref-1">1</xref>]</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_48796-fig-2.tif"/>
</fig>
<p>Several key agreeing protocols use the 3GPP network architecture. These protocols improve security and lessen network overheads. Jung et al. [<xref ref-type="bibr" rid="ref-47">47</xref>] devised congestion avoidance to prevent signaling congestion. In extension, Chen et al. [<xref ref-type="bibr" rid="ref-48">48</xref>] applied a similar grouping approach in G-AKA where the initiator device is verified by HSS, which then authorizes the MME entity. Still, it is susceptible to MiTM (man in the middle) and DoS (denial of service) threats. Lai et al. [<xref ref-type="bibr" rid="ref-49">49</xref>] proposed SE-AKA (secure and efficient authentication and key agreement), where a novel asymmetric method of encoding keys was introduced, which later proved less useful <italic>vs.</italic> signaling congestion. Jiang et al. [<xref ref-type="bibr" rid="ref-50">50</xref>] proposed EG-AKA (EAP-based group authentication and key agreement) to validate a local group of MTC devices. Still, the procedure is susceptible to MiTM, DoS, and re-directional threats. The MTC-AKA (machine-type communication authentication and key agreement) by Lai et al. [<xref ref-type="bibr" rid="ref-51">51</xref>] first used fully authenticated MTC devices with HSS, which authenticated reaming MTC devices through a group temporary key&#x2014;however, the protocol suffered from security attacks. Choi et al. [<xref ref-type="bibr" rid="ref-52">52</xref>] endorsed the GROUP-AKA protocol to alleviate signaling congestion where groups of devices were validated with reduced signaling congestion. Devices could easily join and leave the group but lacked in device privacy preservation. Cao et al. [<xref ref-type="bibr" rid="ref-53">53</xref>] developed GBAAM-AKA (group-based access authentication for MTC-authentication and key agreement) to address the privacy preservation challenge. Moreover, High-level computation overheads were created as GBAAM-AKA followed an asymmetric cryptosystem. Fu et al. [<xref ref-type="bibr" rid="ref-54">54</xref>] introduced the PRIVACY-AKA protocol that creates pseudo-identity via elliptic curve cryptography through group leaders, where the group leaders receive MAC from devices and produce an accumulated MAC. The scheme responds to primary security risk without key secrecy and produces network overheads. Lai et al. [<xref ref-type="bibr" rid="ref-55">55</xref>] recommended GLARM-AKA (group lightweight authentication scheme for resource-constrained M2M-authentication and key agreement), which is lightweight and produces less network signaling overheads in comparison to primitive AKA protocols but it fails due to unlink-capability. The protocol deteriorates from newly joining and old devices leaving the system, which gives a chance to DoS assaults and privacy issues. Li et al. [<xref ref-type="bibr" rid="ref-38">38</xref>] improved GR-AKA&#x2019;s unlinkability by endorsing a dynamic policy in LTE-A. However, strong cryptography resulted in heavy bandwidth consumption. Yao et al. [<xref ref-type="bibr" rid="ref-56">56</xref>] proposed GBS-AKA (group-based secure authentication and key agreement) and improved overhead and bandwidth consumption but failed to incorporate privacy preservation.</p>
<p><xref ref-type="table" rid="table-5">Table 5</xref> shows the group-based techniques that attempt to improve performance and adapt resilience against several security threats. Each work achieves a specific goal but lacks a thorough security-resilient mutual authentication scheme.</p>
<table-wrap id="table-5">
<label>Table 5</label>
<caption>
<title>Summary of discussed group-based authentication schemes</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead valign="top">
<tr>
<th rowspan="2">Schemes</th>
<th rowspan="2">Features</th>
<th align="center" colspan="4">Basic security features</th>
<th align="center" colspan="5">Threat vulnerabilities</th>
<th rowspan="2">Performance weaknesses</th>
</tr>
<tr>
<th>S1</th>
<th>S2</th>
<th>S3</th>
<th>S4</th>
<th>T1</th>
<th>T2</th>
<th>T3</th>
<th>T4</th>
<th>T5</th>
</tr>
</thead>
<tbody valign="top">
<tr>
<td>G-AKA [<xref ref-type="bibr" rid="ref-52">52</xref>]</td>
<td>Entity-based mutual authentication</td>
<td>N</td>
<td>N</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>High computational overhead</td>
</tr>
<tr>
<td>SE-AKA [<xref ref-type="bibr" rid="ref-49">49</xref>]</td>
<td>Asymmetric cryptosystem</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>N</td>
<td>N</td>
<td>Y</td>
<td>Network signalling congestion</td>
</tr>
<tr>
<td>EG-AKA [<xref ref-type="bibr" rid="ref-50">50</xref>]</td>
<td>Non-3gpp network authentication</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>Computation overload at the network</td>
</tr>
<tr>
<td>MTC-AKA [<xref ref-type="bibr" rid="ref-51">51</xref>]</td>
<td>Entity-based mutual authentication</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>N</td>
<td>N</td>
<td>N</td>
<td>Y</td>
<td>DOS-infused redirection attacks</td>
</tr>
<tr>
<td>GBAAM-AKA [<xref ref-type="bibr" rid="ref-53">53</xref>]</td>
<td>Signature-based authentication</td>
<td>N</td>
<td>N</td>
<td>Y</td>
<td>N</td>
<td>N</td>
<td>N</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>High computational overheads</td>
</tr>
<tr>
<td>GROUP-AKA [<xref ref-type="bibr" rid="ref-52">52</xref>]</td>
<td>Improved unlink-ability</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>N</td>
<td>N</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>Weak key forward secrecy</td>
</tr>
<tr>
<td>GLARM-AKA [<xref ref-type="bibr" rid="ref-55">55</xref>]</td>
<td>Group-bases lightweight cryptography</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>N</td>
<td>N</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>Weak unlink-ability (both KFS/KBS)</td>
</tr>
<tr>
<td>Privacy &#x2013;AKA [<xref ref-type="bibr" rid="ref-54">54</xref>]</td>
<td>Pseudo-identity via ECC-based mutual authentication</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>N</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>N</td>
<td>Weak key forward secrecy</td>
</tr>
<tr>
<td>GR-AKA [<xref ref-type="bibr" rid="ref-38">38</xref>]</td>
<td>Flexible policy by lagrange component (LC)</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>N</td>
<td>N</td>
<td>N</td>
<td>Y</td>
<td>N</td>
<td>High bandwidth consumption</td>
</tr>
<tr>
<td>GBS-AKA [<xref ref-type="bibr" rid="ref-52">52</xref>,<xref ref-type="bibr" rid="ref-56">56</xref>]</td>
<td>Secure entity-based mutual authentication</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>N</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>Weak unlink-ability (both KFS/KBS)</td>
</tr>
<tr>
<td>SEGB-AKA [<xref ref-type="bibr" rid="ref-39">39</xref>]</td>
<td>Public key-based mutual entity authentication</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>N</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>Weak unlink-ability (both KFS/KBS)</td>
</tr>
</tbody>
</table>
<table-wrap-foot><fn>
<p>Note: Y: Yes. N: No, S1: Integrity, S2: Confidentiality, S3: Authentication, S4: Privacy Preservation,</p>
<p>T1: MiTM, T2: DoS attacks, T3: Impersonation attack, T4: Node-Replication Threat, T5: Spoofing.</p>
</fn>
</table-wrap-foot>
</table-wrap>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>Local Authentication</title>
<p>Local authentication is adopted when devices are near or in close vicinity. It requires user equipment to be within reach of MTC devices and does not require Internet or remote access. For example, for patients&#x2019; clinical tests via sensors, the patient has to be available within the medical facility. Similarly, for sensitive laboratories, the door has to be opened by the user through RFID (radio frequency identification), thus accessing the facilities only, and smart parking where parking space is allocated to drivers within the parking station [<xref ref-type="bibr" rid="ref-23">23</xref>]. In such circumstances, local authentication is more suitable and less costly regarding security and operational feasibility. However, unlike the GBA schemes, the communication protocols are less robust than those of 4G or mobile networks. This is why operating local authentication-based systems is challenging [<xref ref-type="bibr" rid="ref-1">1</xref>], especially when numerous users are authenticated simultaneously. Local authentication is usually designed for access control systems where users have different privileges, such as two users with different hierarchies. One is granted full access, while the other is granted half access for certain system features. The local authentication network consists of M2M devices, a gateway, and communication channels where gateways can transfer data over the Internet and the cloud. During the transmission, the M2M device encounters three major challenges.
<list list-type="bullet">
<list-item>
<p>All devices must be authenticated to ensure secure data transfer because an impersonator can easily use fake nodes to monitor data transmission and obtain crucial information related to security. In contrast, with malicious nodes, the integrity of the entire network could be at risk. To authenticate both, a mutual authentication scheme is mostly adopted [<xref ref-type="bibr" rid="ref-57">57</xref>]. Mutual authentication in MTC devices happens with encrypted shared keys. These keys are generated via symmetric or asymmetric crypto-mechanism with the cost of complex MAC and high computation power.</p></list-item>
<list-item>
<p>All M2M communicating devices must ensure user privacy through anonymity. It is very crucial to ensure secrecy. During communication, MTC devices must not share any data relating to the data sender&#x2019;s identity [<xref ref-type="bibr" rid="ref-58">58</xref>]. If such privacy is neglected, logs generated by devices may reveal sensitive information related to who, when, and where access was granted to a particular privileged user. Furthermore, a service provider could also reveal the information of all M2M devices&#x2019; access control operations. That is why anonymity will ensure that the information is kept hidden from other devices [<xref ref-type="bibr" rid="ref-26">26</xref>,<xref ref-type="bibr" rid="ref-59">59</xref>].</p></list-item>
<list-item>
<p>Since MTC devices possess low computational power, limited memory, and heterogeneity with dynamic topology, computational complexity must be designed so that 8-16-bit microprocessors can process smoothly. These limitations make the authentication process more difficult as traditional robust authentication methods may strain the limited resources. Complex encryption algorithm implementation may result in higher processing demands, which could impair the device responsiveness and performance.</p></list-item>
</list></p>
<p>Thus, it becomes essential to strike a balance between the requirement to save resources and strong security measures in order to guarantee that the authentication process stays efficient without unnecessarily straining the limited capabilities of MTCDs. Lightweight cryptography is also adopted to ensure privacy and mutual authentication. However, achieving all basic security features with efficiency is an ongoing research.</p>
<p><xref ref-type="table" rid="table-6">Table 6</xref> provides a summary of local authentication schemes according to <xref ref-type="table" rid="table-4">Table 4</xref>. Local authentication and access scheme in WSN (wireless sensor network) using a public key with a symmetric cryptosystem for healthcare applications was proposed by Le et al. [<xref ref-type="bibr" rid="ref-60">60</xref>]. Sensor nodes&#x2019; task was to perform symmetric-key encryption computation and were verified online by third-party coordinate nodes. Shen [<xref ref-type="bibr" rid="ref-61">61</xref>] designed a user access control scheme based on a symmetric encryption system using Merkle tree and hash chain functions. The scheme reduced space complexity but did not achieve basic security features. Due to compromised user anonymity, a user&#x2019;s sensitive information is exposed during communication. Wang et al. [<xref ref-type="bibr" rid="ref-62">62</xref>] introduced hybrid authentication by merging local and remote access control system features and incorporating ECC (elliptical curve cryptography) lightweight cryptography [<xref ref-type="bibr" rid="ref-63">63</xref>]. However, the sensor authentication property is ignored and thus is vulnerable to impersonator/fake nodes. Zhang et al. [<xref ref-type="bibr" rid="ref-36">36</xref>] proposed RSA (Rivest-Shamir-Adleman)-based blind signatures as tokens for users to obtain access rights. The proposed mechanism ensured user privacy and sensor node anonymity. He et al. [<xref ref-type="bibr" rid="ref-35">35</xref>] highlighted that Zhang&#x2019;s mechanism did not account for double-spending, resulting in heavy memory consumption and network overheads. He et al. introduced an improved mechanism version by adding ring signatures based on elliptic curve cryptography to achieve user anonymity and reduce memory and communication overheads. The technique was also vulnerable to MiTM attacks using the ECDH (elliptic curve Deffie-Hellman) algorithm [<xref ref-type="bibr" rid="ref-63">63</xref>]. He et al. further attempted to improve the scheme by adding node accountability [<xref ref-type="bibr" rid="ref-64">64</xref>] to implement network-based rules. Sophisticated privacy-ensuring mechanisms resulted in high computation costs and memory consumption, which MTC devices cannot afford. Similar related works [<xref ref-type="bibr" rid="ref-60">60</xref>&#x2013;<xref ref-type="bibr" rid="ref-62">62</xref>] aimed to compensate operations in resource-constrained MTC devices by ignoring privacy. Both schemes [<xref ref-type="bibr" rid="ref-60">60</xref>,<xref ref-type="bibr" rid="ref-62">62</xref>] are based on certificate-based authentication. Users can identify logs and logging activities by verifying their certificates. On the contrary, references [<xref ref-type="bibr" rid="ref-36">36</xref>,<xref ref-type="bibr" rid="ref-64">64</xref>] required the MTC devices to execute complex computation for acheivement of privacy. Furthermore, references [<xref ref-type="bibr" rid="ref-35">35</xref>,<xref ref-type="bibr" rid="ref-36">36</xref>], and [<xref ref-type="bibr" rid="ref-61">61</xref>,<xref ref-type="bibr" rid="ref-62">62</xref>] did not incorporate device authentication properly and lacked in achieving basic security features. Meanwhile, computational tasks are offloaded to another powerful sever to mitigate MTC devices&#x2019; computational and memory overheads while achieving privacy and efficiency. However, it is challenging as the whole network relies on the server for computations. Any delay in servers can result in increased latency and network losses. In [<xref ref-type="bibr" rid="ref-60">60</xref>], mutual authentication is carried out through the authority of coordinated nodes despite authenticating each node directly. However, the user cannot access sensor nodes when controlled by coordinate nodes if coordinate nodes face any malfunction. Cai et al. [<xref ref-type="bibr" rid="ref-1">1</xref>] proposed a scheme that improve resource management for resource-constrained MTC devices inclduing user anonymity where computation is transferred to third part server which authenticates all devices via pre-shared keys. However, the mechanism could not perform well in noisy signals and did not register lost bytes in noisy signal losses. The proposed mechanism is also prone to failure if the authenticating server either loses the communincation ability or malfuncations. Moreover, there are security problems in the schemes where users&#x2019; secrets are unprotected throughout the communication. He et al. [<xref ref-type="bibr" rid="ref-64">64</xref>] accomplished user privacy in contradiction to the service provider but their proposed method consumes more energy. Energy consumption increases with the increase of group member devices sharing similar access privileges. The schemes of [<xref ref-type="bibr" rid="ref-36">36</xref>] and [<xref ref-type="bibr" rid="ref-62">62</xref>] devour continuous energy for the MTC device for every user access operation despite unguaranteed user privacy. For the execution costs on MTC devices and users, proposed schemes [<xref ref-type="bibr" rid="ref-35">35</xref>,<xref ref-type="bibr" rid="ref-61">61</xref>,<xref ref-type="bibr" rid="ref-62">62</xref>] need to include a certificate generation and verification function, which necessitate exponentiation and inversion executions. Furthermore, associated with [<xref ref-type="bibr" rid="ref-35">35</xref>], LACS&#x2019;s multiplication cost does not raise with the increase in group members. However, references [<xref ref-type="bibr" rid="ref-61">61</xref>,<xref ref-type="bibr" rid="ref-62">62</xref>] cost significantly more energy.</p>
<table-wrap id="table-6">
<label>Table 6</label>
<caption>
<title>Summary of mentioned local authentication schemes</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead valign="top">
<tr>
<th>Schemes</th>
<th rowspan="2">Achievements</th>
<th align="center" colspan="4">Basic security features</th>
<th align="center" colspan="5">Threat vulnerabilities</th>
<th rowspan="2">Weaknesses</th>
</tr>
<tr>
<th/>
<th>S1</th>
<th>S2</th>
<th>S3</th>
<th>S4</th>
<th>T1</th>
<th>T2</th>
<th>T3</th>
<th>T4</th>
<th>T5</th>
</tr>
</thead>
<tbody valign="top">
<tr>
<td>[<xref ref-type="bibr" rid="ref-60">60</xref>]</td>
<td>Resource constraint authentication</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>User privacy is ignored</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-61">61</xref>]</td>
<td>Reduced memory consumption</td>
<td>N</td>
<td>N</td>
<td>N</td>
<td>N</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>Sensor node authentication is ignored</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-62">62</xref>]</td>
<td>Distributed access control for local and remote access</td>
<td>N</td>
<td>N</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>Sensor node authentication is ignored</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-35">35</xref>]</td>
<td>Group-based ring signatures</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>N</td>
<td>Sensor node authentication is ignored</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-36">36</xref>]</td>
<td>Token-based authentication</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>N</td>
<td>Double-spending tokens consume more memory</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-64">64</xref>]</td>
<td>Improved security via network-based rules</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>N</td>
<td>N</td>
<td>N</td>
<td>High computational and network overheads</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-1">1</xref>]</td>
<td>Computational offloading</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>N</td>
<td>N</td>
<td>N</td>
<td>Y</td>
<td>Network vulnerable to failure if a server does malfunction</td>
</tr>
</tbody>
</table>
<table-wrap-foot><fn><p>Note: Y: Achieved, N: Not Achieved, S1: Data integrity, S2: Mutual Authentication, S3: Key Confidentiality, S4: User Privacy, T1: MiTM, T2: DoS attacks, T3: Impersonation attack, T4: Node-Replication Threat, T5: Spoofing.</p>
</fn>
</table-wrap-foot>
</table-wrap>
</sec>
<sec id="s3_3">
<label>3.3</label>
<title>Factor-Based Authentication</title>
<p>Apart from group and local-based authentication, several other works have been proposed in securing MTC device communication with efficiency by adding additional unique parameters, including encryption, pre-shared unique identity keys, two factors such as user and device by using encrypted keys, three-factor such as user to device and device to the gateway, device signatures and implementing secure hash-functions. Each parameter is addressed to a particular environment and topological structure of the WSN network. Such authentication schemes are used for specific business applications requiring specific networks with user-controlled privileges.</p>
<p><xref ref-type="table" rid="table-7">Table 7</xref> summarizes hybrid and factor-based authentication schemes analyzed through features presented in <xref ref-type="table" rid="table-4">Table 4</xref>. Das [<xref ref-type="bibr" rid="ref-65">65</xref>] proposed a two-factor user verification method for WSN by securing secret key risking, mimicking, and DoS attacks. Vaidya et al. [<xref ref-type="bibr" rid="ref-66">66</xref>] pointed out that such a scheme had some security flaws by not offering users to change passwords and shared authorization between the gateway, sensors, and nodes. Vaidya et al. brought up a strategy that proposed an improved method. However, the proposed method offered no defense against malicious insider and brute-force attacks [<xref ref-type="bibr" rid="ref-67">67</xref>]. Additionally, they proposed a scheme to counter such attacks by merging keys and XORing the results. However, the scheme could not withstand insider and disconnected secret key-guessing attacks. Reference [<xref ref-type="bibr" rid="ref-11">11</xref>] devised a simple architecture for mutual authentication by prioritizing low computational and lesser memory consumption. The scheme met low computation and less memory consumption criteria but lacked database-related security measures. Reference [<xref ref-type="bibr" rid="ref-13">13</xref>] proposed an improved AKA scheme specifically for M2M correspondences in 6LoWPAN (IPv6 over low-power wireless personal area networks) systems. To overcome the weaknesses referenced in AKAES (authentication and key agreeing encrypted system), a combination of cryptography is utilized for secure authentication and shared keys with thought of resource constraints at 6LoWPAN utilizing MTC devices. A handover ticket is produced for a mobile device (6LR) to accomplish quick authentication when performing handovers. Therefore, a full authentication process may be performed once the ticket is terminated. In addition, the proposition has a remarkable element of giving security backing to both static and portable devices in 6LoWPAN systems. Reference [<xref ref-type="bibr" rid="ref-68">68</xref>] proposed model of authentication using IBC (Identity Based Cryptography) known as AIBCwKE (authentication via identity-based cryptography without key escrow), where all devices were assigned encrypted identities via ECC cryptography, excluding key agreeing mechanisms by third parties. The MSP (Machine to Machine Service Provider) was the main connectivity server and established communication between two entities (device, gateway, and user) using a public key. Reference [<xref ref-type="bibr" rid="ref-69">69</xref>] proposed three-factor authentication to target user anonymity, an extension to [<xref ref-type="bibr" rid="ref-70">70</xref>] and [<xref ref-type="bibr" rid="ref-71">71</xref>]. Jiang et al. [<xref ref-type="bibr" rid="ref-70">70</xref>] incorporated two-factor-based ECC authentication where a user would log in, authenticate, and share data. Only the shared was encrypted by lightweight cryptography based on ECC, thus achieving data integrity and a low resource-occupying mechanism, an extension of [<xref ref-type="bibr" rid="ref-71">71</xref>]. Choi et al.'s work [<xref ref-type="bibr" rid="ref-71">71</xref>] proposed an enhanced scheme to improve its predecessor&#x2019;s ECC techniques for user anonymity. The proposed mechanism improved authentication and disabled security faults through BAN logic. Reference [<xref ref-type="bibr" rid="ref-69">69</xref>] discussed security flaws in [<xref ref-type="bibr" rid="ref-70">70</xref>] and pointed to a lack of user-friendliness, password updating method, and missing function to detect unauthorized login.</p>
<table-wrap id="table-7">
<label>Table 7</label>
<caption>
<title>Summary of discussed factor-based schemes in M2M communicating networks</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead valign="top">
<tr>
<th>Schemes</th>
<th>Factors</th>
<th>Achievements</th>
<th align="center" colspan="4">Basic security features</th>
<th align="center" colspan="5">Threat vulnerabilities</th>
<th>Weaknesses</th>
</tr>
<tr>
<th/>
<th/>
<th/>
<th>S1</th>
<th>S2</th>
<th>S3</th>
<th>S4</th>
<th>T1</th>
<th>T2</th>
<th>T3</th>
<th>T4</th>
<th>T5</th>
<th/>
</tr>
</thead>
<tbody valign="top">
<tr>
<td>[<xref ref-type="bibr" rid="ref-65">65</xref>]</td>
<td>User verification and pre-shared keys</td>
<td>Oppose key guessing attacks</td>
<td>N</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>Password updates and shared authorization are ignored</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-66">66</xref>]</td>
<td>Login and user authentication</td>
<td>Improved two-factor authentication</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>Weak against Malicious insider and password-guessing attacks</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-70">70</xref>]</td>
<td>ECC-based two-factor authentication</td>
<td>User and login-based authentication</td>
<td>Y</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>User-friendliness and password-changing methods</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-11">11</xref>]</td>
<td>Pre-shared keys</td>
<td>Low computational and less memory consumption</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>N</td>
<td>Physical layer M2M security is Ignored.</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-13">13</xref>]</td>
<td>EASKES6LO</td>
<td>AKA for 6LOWPAN</td>
<td>Y</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>N</td>
<td>N</td>
<td>N</td>
<td>N</td>
<td>Presumed smaller threat model for test</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-68">68</xref>]</td>
<td>AIBCwKE</td>
<td>Hybrid key-based secure communication</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>N</td>
<td>N</td>
<td>Public key with MSP creates computational and network overheads</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-71">71</xref>]</td>
<td>BAN logic</td>
<td>Mutual authentication</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>Data not secured during transmission</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-69">69</xref>]</td>
<td>User biometric signature</td>
<td>Novel password mechanism</td>
<td>Y</td>
<td>Y</td>
<td>Y</td>
<td>N</td>
<td>Y</td>
<td>N</td>
<td>N</td>
<td>N</td>
<td>N</td>
<td>Biometric signature is required for all nodes</td>
</tr>
</tbody>
</table>
<table-wrap-foot><fn><p>Note: Y: Achieved, N: Not Achieved, S1: Data integrity, S2: Mutual Authentication, S3: Key Confidentiality, S4: User Privacy, T1: MiTM, T2: DoS attacks, T3: Impersonation attack, T4: Node-Replication Threat, T5: Spoofing.</p>
</fn>
</table-wrap-foot>
</table-wrap>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Issues and Challenges</title>
<p>The evidence from <xref ref-type="table" rid="table-5">Tables 5</xref>&#x2013;<xref ref-type="table" rid="table-7">7</xref> suggests that the methods with good encryptions successfully achieved data integrity. Good encryption on data transmission ensured countering the MiTM attacks and data spoofing attacks. Meanwhile, the schemes with mutual authentication and good encrypted keys achieved user and device privacy. Schemes with only key encryption techniques are liable to MiTM and impersonator attacks because an impersonator can guess that the encrypted MACs are predominantly keys, so it will be easier to retrieve secrets. However, to our knowledge, an efficient scheme with end-to-end encryption, encrypted keys, and mutual authentication has not been found in any of the mentioned authentication types. The two-layer encryption would prove robust against MiTM and spoofing attacks while ensuring user and device privacy, including authentication. On the contrary, efficient two-layer encryption for keys and end-to-end encryption would be challenging as it might produce network overheads and prove costly in computation and memory consumption. Achieving optimal security protocol for MTC devices is still challenging because many devices work simultaneously in one network.</p>

<p>Our study elaborates on the weaknesses and strengths of current protocols and schemes used to counter certain challenges in communication, as discussed in the following. <xref ref-type="fig" rid="fig-3">Fig. 3</xref> shows a taxonomy of authentication schemes used in M2M communication.</p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>Taxonomy of authentication in M2M communication</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_48796-fig-3.tif"/>
</fig>
<p><list list-type="bullet">
<list-item>
<p>Groups-based authentication suits a network of large amounts of devices that require remote access via the Internet or use cloud services for data storage and access control. Such schemes require 3GPP or 4G infrastructure that provides seamless connectivity for remote users and mobility for mobile devices. However, MiTM and spoofing attacks are yet to be encountered efficiently in remote areas.</p></list-item>
<list-item>
<p>Local authentication schemes better counter MiTM and Spoofing attacks due to easy access in sensitive and crucial business applications, which must ensure user privacy. That is why security features must be addressed, assuming risky threat models. However, efficient computational power and memory consumption are still lacking in the proposed schemes in <xref ref-type="table" rid="table-5">Table 5</xref>.</p>
</list-item>
<list-item>
<p>With no 3GPP or 4G infrastructure, several devices must communicate simultaneously via a well-organized network that ensures user privacy and mutual authentication. However, forward and back security is still challenging for such big networks. The risk extends to the whole network if a single device faces vulnerability. A complete collision detection text must be taken out for all devices in the network, which is time-consuming, costly, and highly complex.</p></list-item>
<list-item>
<p>No scheme mentioned in this article addressed data availability during communication failure scenarios. If the network faces communication failure for any reason, the devices will also lose functionality and data. A system enabling such devices to work even during communication failure is still challenging.</p></list-item>
<list-item>
<p>There is a gap in achieving a standard authentication model for a general authentication scheme that can address all general M2M communication applications.</p></list-item>
</list></p>
</sec>
<sec id="s5">
<label>5</label>
<title>Conclusion</title>
<p>In conclusion, establishing fool-proof security in the domain of Internet of Things (IoT) remains a formidable challenge. Authentication, as a fundamental component of security provisions, plays a crucial role in ensuring the integrity and confidentiality of Machine-Type Communication (MTC) devices. Our study delves into various authentication techniques aimed at achieving optimal performance efficiency and security while minimizing associated costs. The investigation sheds light on persistent challenges and outlines potential avenues for enhancing security in the future. Despite the advancements in two-layer encryption, which ensures user and device privacy and guards against spoofing and Man-in-the-Middle (MiTM) attacks, it comes with noticeable computational and network overheads. Group-based authentication emerges as a suitable solution for large networks, but its efficacy requires efficient countermeasures in remote areas. Local authentication schemes effectively address MiTM and spoofing attacks but encounter computational power challenges, while the unresolved issue of data availability during communication failures persists.</p>
<p>This study can further benefit from state-of-the-art techniques in the evolving landscape of IoT security, such as edge and fog computing, biometric authentication, blockchain-based authentication, risk-based authentication, machine learning, and anomaly detection. Furthermore, quantum-resistant authentication can be used to cope up with dynamic nature of IoT security. In this context, some prominent works on state-of-the-art concepts in IoT security can be used as a basis for further research, such as [<xref ref-type="bibr" rid="ref-72">72</xref>&#x2013;<xref ref-type="bibr" rid="ref-74">74</xref>], that emphasizes who has described the security implications of quantum cryptography, artificial intelligence and lightweight peer-to-peer authentication. Additionaly, the research of Bonandrini et al. [<xref ref-type="bibr" rid="ref-75">75</xref>] has also contributed to anomaly detection in IoT networks, while researches in [<xref ref-type="bibr" rid="ref-76">76</xref>,<xref ref-type="bibr" rid="ref-77">77</xref>] proposed a Blockchain-based scheme for authentication and cloud based security in IoT environments. Furthermore, a secure authentication and protocol for M2M communication by Thammarat et al. [<xref ref-type="bibr" rid="ref-78">78</xref>] and the research of Zareen et al. [<xref ref-type="bibr" rid="ref-73">73</xref>] on authentication and authorization of IoT devices using AI can also be further research direction. These works further propose innovative approaches to address the multifaceted challenges in IoT security. As the field continues to evolve, embracing these trends and leveraging their unique contributions will be pivotal in establishing a standardized authentication model for general M2M communication applications.</p>
</sec>
</body>
<back>
<ack><p>The authors acknowledge the gracious support provided by the King Faisal University, Saudi Arabia.</p>
</ack>
<sec><title>Funding Statement</title>
<p>This work was funded by the Deanship of Scientific Research, Vice Presidency for Graduate Studies and Scientific Research, King Faisal University, Saudi Arabia (Grant No. GRANT5,208).</p>
</sec>
<sec><title>Author Contributions</title>
<p>The authors worked together on different parts of the research. S.U. started with problem formulation and conducted initial studies. S.U.B. performed problem analysis and critical review of related studies. M.I. checked for mistakes and planned research methodology. Q.M.I. and A.M. critically analyzed and interpreted the results. M.A.S. analyzed the research challenges, while M.A.R. and I.K. proposed potential future works. A.H. critically reviewed and revised the draft. S.I., Y.G., and K.H. helped with the manuscript write-up.</p>
</sec>
<sec sec-type="data-availability"><title>Availability of Data and Materials</title>
<p>All data used in this research are available from the corresponding authors upon request.</p>
</sec>
<sec sec-type="COI-statement"><title>Conflicts of Interest</title>
<p>The authors declare that they have no conflicts of interest to report regarding the present study.</p>
</sec>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Z.</given-names> <surname>Cai</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Mao</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>D.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>J.</given-names> <surname>He</surname></string-name> and <string-name><given-names>X.</given-names> <surname>Fan</surname></string-name></person-group>, &#x201C;<article-title>Associations between problematic internet use and mental health outcomes of students: A meta-analytic review</article-title>,&#x201D; <source>Adolesc. Res. Rev.</source>, vol. <volume>8</volume>, no. <issue>1</issue>, pp. <fpage>45</fpage>&#x2013;<lpage>62</lpage>, <month>Mar</month>. <year>2023</year>. doi: <pub-id pub-id-type="doi">10.1007/s40894-022-00201-9</pub-id>; <pub-id pub-id-type="pmid">36744121</pub-id></mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>Statista</collab></person-group>, &#x201C;<article-title>Internet usage worldwide&#x2014;statistics &#x0026; facts</article-title>,&#x201D; <source>Statista</source>. <comment>Accessed: Dec. 06, 2023</comment>. [Online]. Available: <ext-link ext-link-type="uri" xlink:href="https://www.statista.com/topics/1145/internet-usage-worldwide/#topicOverview">https://www.statista.com/topics/1145/internet-usage-worldwide/#topicOverview</ext-link></mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>F.</given-names> <surname>Kamalov</surname></string-name>, <string-name><given-names>B.</given-names> <surname>Pourghebleh</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Gheisari</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Liu</surname></string-name>, and <string-name><given-names>S.</given-names> <surname>Moussa</surname></string-name></person-group>, &#x201C;<article-title>Internet of medical things privacy and security: Challenges, solutions, and future trends from a new perspective</article-title>,&#x201D; <source>Sustainability</source>, vol. <volume>15</volume>, no. <issue>4</issue>, pp. <fpage>3317</fpage>, <year>Feb. 2023</year>. doi: <pub-id pub-id-type="doi">10.3390/su15043317</pub-id>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>N. G.</given-names> <surname>Vasilescu</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Pocatilu</surname></string-name>, and <string-name><given-names>M.</given-names> <surname>Doinea</surname></string-name></person-group>, &#x201C;<article-title>IoT security challenges for smart homes</article-title>,&#x201D; in <conf-name>Proc. 21st Int. Conf. Inf. in Eco. (IE 2022)</conf-name>, <publisher-loc>Singapore</publisher-loc>, <publisher-name>Springer Nature Singapore</publisher-name>, <year>2023</year>, pp. <fpage>41</fpage>&#x2013;<lpage>49</lpage>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>Y. R.</given-names> <surname>Shi</surname></string-name> and <string-name><given-names>T.</given-names> <surname>Hou</surname></string-name></person-group>, &#x201C;<article-title>Internet of things key technologies and architectures research in information processing</article-title>,&#x201D; in <conf-name>Proc. 2nd Int. Conf. Comput. Sci. Electron. Eng. (ICCSEE)</conf-name>, <publisher-loc>France</publisher-loc>, <publisher-name>Atlantis Press</publisher-name>, <year>2013</year>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>R.</given-names> <surname>Khan</surname></string-name>, <string-name><given-names>S. U.</given-names> <surname>Khan</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Zaheer</surname></string-name>, and <string-name><given-names>S.</given-names> <surname>Khan</surname></string-name></person-group>, &#x201C;<article-title>Future internet: The internet of things architecture, possible applications and key challenges</article-title>,&#x201D; in <conf-name>10th Int. Conf. Front. Inf. Technol. (FIT)</conf-name>, <publisher-loc>Islamabad, Pakistan</publisher-loc>, <publisher-name>IEEE</publisher-name>, <year>2012</year>, pp. <fpage>257</fpage>&#x2013;<lpage>260</lpage>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><given-names>X.</given-names> <surname>Yang</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Geng</surname></string-name>, and <string-name><given-names>H.</given-names> <surname>Zhang</surname></string-name></person-group>, &#x201C;<chapter-title>A multi-layer security model for internet of things</chapter-title>,&#x201D; in <source>Internet of Things</source>, <publisher-name>Springer</publisher-name>, <publisher-loc>Changsha, China</publisher-loc>, <year>2012</year>, pp. <fpage>388</fpage>&#x2013;<lpage>393</lpage>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>Y.</given-names> <surname>Zhang</surname></string-name></person-group>, &#x201C;<article-title>Technology framework of the Internet of Things and its application</article-title>,&#x201D; in <conf-name>2011 Int. Conf. Electric. Cont. Eng.</conf-name>, <publisher-loc>Yichang, China</publisher-loc>, <publisher-name>IEEE</publisher-name>, <year>2011</year>, pp. <fpage>4109</fpage>&#x2013;<lpage>4112</lpage>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>I. H.</given-names> <surname>Sarker</surname></string-name>, <string-name><given-names>A. I.</given-names> <surname>Khan</surname></string-name>, <string-name><given-names>Y. B.</given-names> <surname>Abushark</surname></string-name>, and <string-name><given-names>F.</given-names> <surname>Alsolami</surname></string-name></person-group>, &#x201C;<article-title>Internet of things (IoT) security intelligence: A comprehensive overview, machine learning solutions and research directions</article-title>,&#x201D; <source>Mobile Netw. Appl.</source>, vol. <volume>28</volume>, no. <issue>1</issue>, pp. <fpage>296</fpage>&#x2013;<lpage>312</lpage>, <year>Feb. 2023</year>. doi: <pub-id pub-id-type="doi">10.1007/s11036-022-01937-3</pub-id>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>V. G.</given-names> <surname>Garagad</surname></string-name>, <string-name><given-names>N. C.</given-names> <surname>Iyer</surname></string-name>, and <string-name><given-names>H. G.</given-names> <surname>Wali</surname></string-name></person-group>, &#x201C;<article-title>Data integrity: A security threat for internet of things and cyber-physical systems</article-title>,&#x201D; in <conf-name>2020 Int. Conf. Comput. Performance Evaluation (ComPE)</conf-name>, <publisher-loc>Meghalaya, India</publisher-loc>, <publisher-name>IEEE</publisher-name>, <year>Jul. 2, 2020</year>, pp. <fpage>244</fpage>&#x2013;<lpage>249</lpage>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>B. D.</given-names> <surname>Deebak</surname></string-name> and <string-name><given-names>A. T.</given-names> <surname>Fadi</surname></string-name></person-group>, &#x201C;<article-title>Lightweight authentication for IoT/Cloud-based forensics in intelligent data computing</article-title>,&#x201D; <source>Future Gener. Comput. Syst.</source>, vol. <volume>116</volume>, no. <issue>1</issue>, pp. <fpage>406</fpage>&#x2013;<lpage>425</lpage>, <year>Mar. 2021</year>. doi: <pub-id pub-id-type="doi">10.1016/j.future.2020.11.010</pub-id>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>P. M.</given-names> <surname>Chanal</surname></string-name> and <string-name><given-names>M. S.</given-names> <surname>Kakkasageri</surname></string-name></person-group>, &#x201C;<article-title>Security and privacy in IoT: A survey</article-title>,&#x201D; <source>Wirel. Person. Commun.</source>, vol. <volume>115</volume>, no. <issue>2</issue>, pp. <fpage>1667</fpage>&#x2013;<lpage>1693</lpage>, <year>Nov. 2020</year>. doi: <pub-id pub-id-type="doi">10.1007/s11277-020-07649-9</pub-id>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>P. M.</given-names> <surname>Chanal</surname></string-name> and <string-name><given-names>M. S.</given-names> <surname>Kakkasageri</surname></string-name></person-group>, &#x201C;<article-title>Preserving data confidentiality in Internet of Things</article-title>,&#x201D; <source>SN Comput. Sci.</source>, vol. <volume>2</volume>, no. <issue>1</issue>, pp. <fpage>53</fpage>, <year>Feb. 2021</year>. doi: <pub-id pub-id-type="doi">10.1007/s42979-020-00429-z</pub-id>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Eckardt</surname></string-name> and <string-name><given-names>W.</given-names> <surname>Kerber</surname></string-name></person-group>, &#x201C;<article-title>Property rights theory, bundles of rights on IoT data, and the EU data act</article-title>,&#x201D; <source>Eur. J. Law Econ.</source>, vol. <volume>19</volume>, no. <issue>5</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>31</lpage>, <year>Jan. 2024</year>. doi: <pub-id pub-id-type="doi">10.1007/s10657-023-09791-8</pub-id>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>D.</given-names> <surname>Chen</surname></string-name> and <string-name><given-names>G.</given-names> <surname>Chang</surname></string-name></person-group>, &#x201C;<article-title>A survey on security issues of M2M communications in cyber-physical systems</article-title>,&#x201D; <source>KSII Trans. Internet Inf. Syst.</source>, vol. <volume>6</volume>, no. <issue>1</issue>, <year>2012</year>. doi: <pub-id pub-id-type="doi">10.3837/tiis.2012.01.002</pub-id>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>V. L.</given-names> <surname>Narayana</surname></string-name> and <string-name><given-names>C.</given-names> <surname>Bharathi</surname></string-name></person-group>, &#x201C;<article-title>Identity based cryptography for mobile ad hoc networks</article-title>,&#x201D; <source>J. Theor. Appl. Inf. Technol.</source>, vol. <volume>95</volume>, no. <issue>5</issue>, p. <fpage>1173</fpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>D.</given-names> <surname>Garcia-Carrillo</surname></string-name>, <string-name><given-names>X. G.</given-names> <surname>Pa&#x00F1;eda</surname></string-name>, <string-name><given-names>D.</given-names> <surname>Melendi</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Garcia</surname></string-name>, <string-name><given-names>V.</given-names> <surname>Corcoba</surname></string-name> and <string-name><given-names>D.</given-names> <surname>Mart&#x00ED;nez</surname></string-name></person-group>, &#x201C;<article-title>Ad-hoc collision avoidance system for industrial IoT</article-title>,&#x201D; <source>J. Ind. Inf. Integration</source>, vol. <volume>17</volume>, no. <issue>1</issue>, pp. <fpage>100575</fpage>, <year>Jan. 2024</year>. doi: <pub-id pub-id-type="doi">10.1016/j.jii.2024.100575</pub-id>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Bhasin</surname></string-name> and <string-name><given-names>F.</given-names> <surname>Regazzoni</surname></string-name></person-group>, &#x201C;<article-title>A survey on hardware trojan detection techniques</article-title>,&#x201D; in <conf-name>IEEE Int. Symp. Circ. Syst.</conf-name>, <publisher-loc>Lisbon, Portugal</publisher-loc>, <year>2015</year>, pp. <fpage>2021</fpage>&#x2013;<lpage>2024</lpage>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Tehranipoor</surname></string-name> and <string-name><given-names>F.</given-names> <surname>Koushanfar</surname></string-name></person-group>, &#x201C;<article-title>A survey of hardware trojan taxonomy and detection</article-title>,&#x201D; <source>IEEE Des. Test Comput.</source>, vol. <volume>27</volume>, no. <issue>1</issue>, pp. <fpage>10</fpage>&#x2013;<lpage>25</lpage>, <year>2010</year>. doi: <pub-id pub-id-type="doi">10.1109/MDT.2010.7</pub-id>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>H.</given-names> <surname>Tanaka</surname></string-name></person-group>, &#x201C;<article-title>Information leakage via electromagnetic emanation and effectiveness of averaging technique</article-title>,&#x201D; in <conf-name>2008. Int. Conf. Inf. Secur. Assur.</conf-name>, <publisher-loc>Busan, Korea</publisher-loc>, <publisher-name>IEEE</publisher-name>, <year>2008</year>, pp. <fpage>98</fpage>&#x2013;<lpage>101</lpage>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Brandt</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Buron</surname></string-name>, and <string-name><given-names>G.</given-names> <surname>Porcu</surname></string-name></person-group>, &#x201C;<article-title>Home automation routing requirements in low-power and lossy networks</article-title>,&#x201D; <comment>Internet Engineering Task Force (IETF)</comment>, <year>2010</year>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Seys</surname></string-name> and <string-name><given-names>B.</given-names> <surname>Preneel</surname></string-name></person-group>, &#x201C;<article-title>Authenticated and efficient key management for wireless ad hoc networks</article-title>,&#x201D; in <conf-name>Proc. 24th Symp. Inf. Theory Benelux</conf-name>, <publisher-loc>Haasrode, Belgium</publisher-loc>, <publisher-name>Werkgemeenschap voor Informatie-en Communicatietheorie</publisher-name>, <year>2003</year>, pp. <fpage>195</fpage>&#x2013;<lpage>202</lpage>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>E. Y.</given-names> <surname>Vasserman</surname></string-name> and <string-name><given-names>N.</given-names> <surname>Hopper</surname></string-name></person-group>, &#x201C;<article-title>Vampire attacks: Draining life from wireless ad hoc sensor networks</article-title>,&#x201D; <source>IEEE Trans. Mobile Comput.</source>, vol. <volume>12</volume>, no. <issue>2</issue>, pp. <fpage>318</fpage>&#x2013;<lpage>332</lpage>, <year>2013</year>. doi: <pub-id pub-id-type="doi">10.1109/TMC.2011.274</pub-id>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>F.</given-names> <surname>Stajano</surname></string-name> and <string-name><given-names>R.</given-names> <surname>Anderson</surname></string-name></person-group>, &#x201C;<article-title>The resurrecting duckling: Security issues for ubiquitous computing</article-title>,&#x201D; <source>Comput.</source>, vol. <volume>35</volume>, no. <issue>4</issue>, pp. <fpage>supl22</fpage>&#x2013;<lpage>supl26</lpage>, <year>2002</year>. doi: <pub-id pub-id-type="doi">10.1109/MC.2002.1012427</pub-id>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>A. A.</given-names> <surname>C&#x00E1;rdenas</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Amin</surname></string-name>, <string-name><given-names>Z. S.</given-names> <surname>Lin</surname></string-name>, <string-name><given-names>Y. L.</given-names> <surname>Huang</surname></string-name>, <string-name><given-names>C. Y.</given-names> <surname>Huang</surname></string-name> and <string-name><given-names>S.</given-names> <surname>Sastry</surname></string-name></person-group>, &#x201C;<article-title>Attacks against process control systems: Risk assessment, detection, and response</article-title>,&#x201D; in <conf-name>Proc. 6th ACM Symp. Inf., Comput. Commun. Secur.</conf-name>, <publisher-loc>Hong Kong, China</publisher-loc>, <publisher-name>ACM</publisher-name>, <year>2011</year>, pp. <fpage>355</fpage>&#x2013;<lpage>366</lpage>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Mart&#x00ED;nez-Ballest&#x00E9;</surname></string-name>, <string-name><given-names>P. A.</given-names> <surname>P&#x00E9;rez-Mart&#x00ED;nez</surname></string-name>, and <string-name><given-names>A.</given-names> <surname>Solanas</surname></string-name></person-group>, &#x201C;<article-title>The pursuit of citizens&#x2019; privacy: A privacy-aware smart city is possible</article-title>,&#x201D; <source>IEEE Commun. Mag.</source>, vol. <volume>51</volume>, no. <issue>6</issue>, pp. <fpage>136</fpage>&#x2013;<lpage>141</lpage>, <year>2013</year>. doi: <pub-id pub-id-type="doi">10.1109/MCOM.2013.6525606</pub-id>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><given-names>G.</given-names> <surname>Hernandez</surname></string-name>, <string-name><given-names>O.</given-names> <surname>Arias</surname></string-name>, <string-name><given-names>D.</given-names> <surname>Buentello</surname></string-name>, and <string-name><given-names>Y.</given-names> <surname>Jin</surname></string-name></person-group>, &#x201C;<article-title>Smart nest thermostat: A smart spy in your home</article-title>,&#x201D; <source>Black Hat USA</source>, <year>2014</year>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>B.</given-names> <surname>Parno</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Perrig</surname></string-name>, and <string-name><given-names>V.</given-names> <surname>Gligor</surname></string-name></person-group>, &#x201C;<article-title>Distributed detection of node replication attacks in sensor networks</article-title>,&#x201D; in <conf-name>2005 Symp. Secur. Priv.</conf-name>, <publisher-loc>Oakland, CA, USA</publisher-loc>, <year>2005</year>, pp. <fpage>49</fpage>&#x2013;<lpage>63</lpage>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><given-names>J. P.</given-names> <surname>Walters</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Liang</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Shi</surname></string-name>, and <string-name><given-names>V.</given-names> <surname>Chaudhary</surname></string-name></person-group>, &#x201C;<chapter-title>Wireless sensor network security: A survey</chapter-title>,&#x201D; in <source>Security in Distributed, Grid, Mobile, and Pervasive Computing</source>, <publisher-loc>Auerbach Publications</publisher-loc>, <year>2007</year>, vol. <volume>1</volume>, pp. <fpage>367</fpage>&#x2013;<lpage>409</lpage>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><given-names>D. G.</given-names> <surname>Padmavathi</surname></string-name> and <string-name><given-names>M.</given-names> <surname>Shanmugapriya</surname></string-name></person-group>, &#x201C;<article-title>A survey of attacks, security mechanisms and challenges in wireless sensor networks</article-title>,&#x201D; <comment>arXiv preprint arXiv:0909.0576</comment>, <year>2009</year>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Mitrokotsa</surname></string-name>, <string-name><given-names>M. R.</given-names> <surname>Rieback</surname></string-name>, and <string-name><given-names>A. S.</given-names> <surname>Tanenbaum</surname></string-name></person-group>, &#x201C;<article-title>Classification of RFID attacks</article-title>,&#x201D; <source>Gen.</source>, vol. <volume>15693</volume>, pp. <fpage>14443</fpage>, <year>2010</year>.</mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M. M.</given-names> <surname>Ogonji</surname></string-name>, <string-name><given-names>G.</given-names> <surname>Okeyo</surname></string-name>, and <string-name><given-names>J. M.</given-names> <surname>Wafula</surname></string-name></person-group>, &#x201C;<article-title>A survey on privacy and security of Internet of Things</article-title>,&#x201D; <source>Comput. Sci. Rev.</source>, vol. <volume>38</volume>, no. <issue>7</issue>, pp. <fpage>100312</fpage>, <year>2020</year>. doi: <pub-id pub-id-type="doi">10.1016/j.cosrev.2020.100312</pub-id>.</mixed-citation></ref>
<ref id="ref-33"><label>[33]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>R.</given-names> <surname>Somasundaram</surname></string-name> and <string-name><given-names>M.</given-names> <surname>Thirugnanam</surname></string-name></person-group>, &#x201C;<article-title>Review of security challenges in healthcare internet of things</article-title>,&#x201D; <source>Wirel. Netw.</source>, vol. 27, no. 8, pp. <fpage>5503</fpage>&#x2013;<lpage>5509</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-34"><label>[34]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Qiu</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Tian</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Du</surname></string-name>, <string-name><given-names>Q.</given-names> <surname>Zuo</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Su</surname></string-name> and <string-name><given-names>B.</given-names> <surname>Fang</surname></string-name></person-group>, &#x201C;<article-title>A survey on access control in the age of internet of things</article-title>,&#x201D; <source>IEEE Internet Things J.</source>, vol. <volume>7</volume>, no. <issue>6</issue>, pp. <fpage>4682</fpage>&#x2013;<lpage>4696</lpage>, <year>2020</year>. doi: <pub-id pub-id-type="doi">10.1109/JIOT.2020.2969326</pub-id>.</mixed-citation></ref>
<ref id="ref-35"><label>[35]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>D.</given-names> <surname>He</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Bu</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Zhu</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Chan</surname></string-name>, and <string-name><given-names>C.</given-names> <surname>Chen</surname></string-name></person-group>, &#x201C;<article-title>Distributed access control with privacy support in wireless sensor networks</article-title>,&#x201D; <source>IEEE Trans. Wirel. Commun.</source>, vol. <volume>10</volume>, no. <issue>10</issue>, pp. <fpage>3472</fpage>&#x2013;<lpage>3481</lpage>, <year>2011</year>. doi: <pub-id pub-id-type="doi">10.1109/TWC.2011.072511.102283</pub-id>.</mixed-citation></ref>
<ref id="ref-36"><label>[36]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>R.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Zhang</surname></string-name>, and <string-name><given-names>K.</given-names> <surname>Ren</surname></string-name></person-group>, &#x201C;<article-title>DP&#x00B2;AC: Distributed privacy-preserving access control in sensor networks</article-title>,&#x201D; in <conf-name>IEEE INFOCOM 2009</conf-name>, <publisher-loc>Rio de Janeiro, Brazil</publisher-loc>, <publisher-name>IEEE</publisher-name>, <year>2009</year>, pp. <fpage>1251</fpage>&#x2013;<lpage>1259</lpage>.</mixed-citation></ref>
<ref id="ref-37"><label>[37]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>X.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Peng</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Niu</surname></string-name>, <string-name><given-names>F.</given-names> <surname>Wu</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Liao</surname></string-name>, and <string-name><given-names>K. K. R.</given-names> <surname>Choo</surname></string-name></person-group>, &#x201C;<article-title>A robust and energy efficient authentication protocol for industrial internet of things</article-title>,&#x201D; <source>IEEE Internet Things</source>, vol. <volume>5</volume>, no. <issue>3</issue>, pp. <fpage>1606</fpage>&#x2013;<lpage>1615</lpage>, <year>2017</year>. doi: <pub-id pub-id-type="doi">10.1109/JIOT.2017.2787800</pub-id>.</mixed-citation></ref>
<ref id="ref-38"><label>[38]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Wen</surname></string-name>, and <string-name><given-names>T.</given-names> <surname>Zhang</surname></string-name></person-group>, &#x201C;<article-title>Group-based authentication and key agreement with dynamic policy updating for MTC in LTE-A networks</article-title>,&#x201D; <source>IEEE Internet Things J.</source>, vol. <volume>3</volume>, no. <issue>3</issue>, pp. <fpage>408</fpage>&#x2013;<lpage>417</lpage>, <year>2016</year>. doi: <pub-id pub-id-type="doi">10.1109/JIOT.2015.2495321</pub-id>.</mixed-citation></ref>
<ref id="ref-39"><label>[39]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>B. L.</given-names> <surname>Parne</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Gupta</surname></string-name>, and <string-name><given-names>N. S.</given-names> <surname>Chaudhari</surname></string-name></person-group>, &#x201C;<article-title>SEGB: Security enhanced group based AKA protocol for M2M communication in an IoT enabled LTE/LTE-A network</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>6</volume>, pp. <fpage>3668</fpage>&#x2013;<lpage>3684</lpage>, <year>2018</year>. doi: <pub-id pub-id-type="doi">10.1109/ACCESS.2017.2788919</pub-id>.</mixed-citation></ref>
<ref id="ref-40"><label>[40]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S. G.</given-names> <surname>Oliver</surname></string-name> and <string-name><given-names>T.</given-names> <surname>Purusothaman</surname></string-name></person-group>, &#x201C;<article-title>Lightweight and secure mutual authentication scheme for IoT devices using CoAP protocol</article-title>,&#x201D; <source>Comput. Syst. Sci. Eng.</source>, vol. <volume>41</volume>, no. <issue>2</issue>, pp. <fpage>767</fpage>&#x2013;<lpage>780</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-41"><label>[41]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Jangirala</surname></string-name>, <string-name><given-names>A. K.</given-names> <surname>Das</surname></string-name>, and <string-name><given-names>A. V.</given-names> <surname>Vasilakos</surname></string-name></person-group>, &#x201C;<article-title>Designing secure lightweight blockchain-enabled RFID-based authentication protocol for supply chains in 5G mobile edge computing environment</article-title>,&#x201D; <source>IEEE Trans. Ind. Inf.</source>, vol. <volume>16</volume>, no. <issue>11</issue>, pp. <fpage>7081</fpage>&#x2013;<lpage>7093</lpage>, <year>2019</year>. doi: <pub-id pub-id-type="doi">10.1109/TII.2019.2942389</pub-id>.</mixed-citation></ref>
<ref id="ref-42"><label>[42]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>R.</given-names> <surname>Amin</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Kumar</surname></string-name>, <string-name><given-names>G.</given-names> <surname>Biswas</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Iqbal</surname></string-name>, and <string-name><given-names>V.</given-names> <surname>Chang</surname></string-name></person-group>, &#x201C;<article-title>A light weight authentication protocol for IoT-enabled devices in distributed cloud computing environment</article-title>,&#x201D; <source>Future Gener. Comput. Syst.</source>, vol. <volume>78</volume>, no. <issue>11</issue>, pp. <fpage>1005</fpage>&#x2013;<lpage>1019</lpage>, <year>2018</year>. doi: <pub-id pub-id-type="doi">10.1016/j.future.2016.12.028</pub-id>.</mixed-citation></ref>
<ref id="ref-43"><label>[43]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>F.</given-names> <surname>Wu</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Xu</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Kumari</surname></string-name>, and <string-name><given-names>X.</given-names> <surname>Li</surname></string-name></person-group>, &#x201C;<article-title>A privacy-preserving and provable user authentication scheme for wireless sensor networks based on internet of things security</article-title>,&#x201D; <source>J. Amb. Intell. Human. Comput.</source>, vol. <volume>8</volume>, no. <issue>1</issue>, pp. <fpage>101</fpage>&#x2013;<lpage>116</lpage>, <year>2017</year>. doi: <pub-id pub-id-type="doi">10.1007/s12652-016-0345-8</pub-id>.</mixed-citation></ref>
<ref id="ref-44"><label>[44]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><given-names>B.</given-names> <surname>Blanchet</surname></string-name>, <string-name><given-names>V.</given-names> <surname>Cheval</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Allamigeon</surname></string-name>, and <string-name><given-names>B.</given-names> <surname>Smyth</surname></string-name></person-group>, &#x201C;<article-title>ProVerif: Cryptographic protocol verifier in the computational model</article-title>,&#x201D; <publisher-loc>Oxford, UK: IEEE</publisher-loc>, pp. <fpage>16</fpage>&#x2013;<lpage>30</lpage>, <year>2010</year>.</mixed-citation></ref>
<ref id="ref-45"><label>[45]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>H. A. H.</given-names> <surname>Hassan</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Pelov</surname></string-name>, and <string-name><given-names>L.</given-names> <surname>Nuaymi</surname></string-name></person-group>, &#x201C;<article-title>Integrating cellular networks, smart grid, and renewable energy: Analysis, architecture, and challenges</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>3</volume>, pp. <fpage>2755</fpage>&#x2013;<lpage>2770</lpage>, <year>2015</year>. doi: <pub-id pub-id-type="doi">10.1109/ACCESS.2015.2507781</pub-id>.</mixed-citation></ref>
<ref id="ref-46"><label>[46]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Mi&#x0161;i&#x0107;</surname></string-name>, <string-name><given-names>V. B.</given-names> <surname>Mi&#x0161;i&#x0107;</surname></string-name>, and <string-name><given-names>N.</given-names> <surname>Khan</surname></string-name></person-group>, &#x201C;<article-title>Sharing it my way: Efficient M2M access in LTE/LTE-A networks</article-title>,&#x201D; <source>IEEE Trans. Veh. Technol.</source>, vol. <volume>66</volume>, no. <issue>1</issue>, pp. <fpage>696</fpage>&#x2013;<lpage>709</lpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-47"><label>[47]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>K. R.</given-names> <surname>Jung</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Park</surname></string-name>, and <string-name><given-names>S.</given-names> <surname>Lee</surname></string-name></person-group>, &#x201C;<article-title>Machine-type-communication (MTC) device grouping algorithm for congestion avoidance of MTC oriented LTE network</article-title>,&#x201D; in <conf-name>Int. Conf. Securi-Enriched Urban Comput. Smart Grid</conf-name>, <publisher-loc>Daejeon, Korea</publisher-loc>, <publisher-name>Springer</publisher-name>, <year>2010</year>, pp. <fpage>167</fpage>&#x2013;<lpage>178</lpage>.</mixed-citation></ref>
<ref id="ref-48"><label>[48]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y. W.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>J. T.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>K. H.</given-names> <surname>Chi</surname></string-name>, and <string-name><given-names>C. C.</given-names> <surname>Tseng</surname></string-name></person-group>, &#x201C;<article-title>Group-based authentication and key agreement</article-title>,&#x201D; <source>Wirel. Person. Commun.</source>, vol. <volume>62</volume>, no. <issue>4</issue>, pp. <fpage>965</fpage>&#x2013;<lpage>979</lpage>, <year>2012</year>. doi: <pub-id pub-id-type="doi">10.1007/s11277-010-0104-7</pub-id>.</mixed-citation></ref>
<ref id="ref-49"><label>[49]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>C.</given-names> <surname>Lai</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Lu</surname></string-name>, and <string-name><given-names>X. S.</given-names> <surname>Shen</surname></string-name></person-group>, &#x201C;<article-title>SE-AKA: A secure and efficient group authentication and key agreement protocol for LTE networks</article-title>,&#x201D; <source>Comput. Netw.</source>, vol. <volume>57</volume>, no. <issue>17</issue>, pp. <fpage>3492</fpage>&#x2013;<lpage>3510</lpage>, <year>2013</year>. doi: <pub-id pub-id-type="doi">10.1016/j.comnet.2013.08.003</pub-id>.</mixed-citation></ref>
<ref id="ref-50"><label>[50]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>R.</given-names> <surname>Jiang</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Lai</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Luo</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Wang</surname></string-name>, and <string-name><given-names>H.</given-names> <surname>Wang</surname></string-name></person-group>, &#x201C;<article-title>EAP-based group authentication and key agreement protocol for machine-type communications</article-title>,&#x201D; <source>Int. J. Distrib. Sens. Netw.</source>, vol. <volume>9</volume>, no. <issue>11</issue>, pp. <fpage>304601</fpage>, <year>2013</year>. doi: <pub-id pub-id-type="doi">10.1155/2013/304601</pub-id>.</mixed-citation></ref>
<ref id="ref-51"><label>[51]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>C.</given-names> <surname>Lai</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Li</surname></string-name>, and <string-name><given-names>J.</given-names> <surname>Cao</surname></string-name></person-group>, &#x201C;<article-title>A novel group access authentication and key agreement protocol for machine-type communication</article-title>,&#x201D; <source>Trans. Emerg. Telecommun. Technol.</source>, vol. <volume>26</volume>, no. <issue>3</issue>, pp. <fpage>414</fpage>&#x2013;<lpage>431</lpage>, <year>2015</year>. doi: <pub-id pub-id-type="doi">10.1002/ett.2635</pub-id>.</mixed-citation></ref>
<ref id="ref-52"><label>[52]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>D.</given-names> <surname>Choi</surname></string-name>, <string-name><given-names>H. K.</given-names> <surname>Choi</surname></string-name>, and <string-name><given-names>S. Y.</given-names> <surname>Lee</surname></string-name></person-group>, &#x201C;<article-title>A group-based security protocol for machine-type communications in LTE-advanced</article-title>,&#x201D; <source>Wirel. Netw.</source>, vol. <volume>21</volume>, no. <issue>2</issue>, pp. <fpage>405</fpage>&#x2013;<lpage>419</lpage>, <year>2015</year>. doi: <pub-id pub-id-type="doi">10.1007/s11276-014-0788-9</pub-id>.</mixed-citation></ref>
<ref id="ref-53"><label>[53]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Cao</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Ma</surname></string-name>, and <string-name><given-names>H.</given-names> <surname>Li</surname></string-name></person-group>, &#x201C;<article-title>GBAAM: Group-based access authentication for MTC in LTE networks</article-title>,&#x201D; <source>Secur. Commun. Netw.</source>, vol. <volume>8</volume>, no. <issue>17</issue>, pp. <fpage>3282</fpage>&#x2013;<lpage>3299</lpage>, <year>2015</year>. doi: <pub-id pub-id-type="doi">10.1002/sec.1252</pub-id>.</mixed-citation></ref>
<ref id="ref-54"><label>[54]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Fu</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Song</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>G.</given-names> <surname>Zhang</surname></string-name>, and <string-name><given-names>Y.</given-names> <surname>Zhang</surname></string-name></person-group>, &#x201C;<article-title>A privacy-preserving group authentication protocol for machine-type communication in LTE/LTE-A networks</article-title>,&#x201D; <source>Secur. Commun. Netw.</source>, vol. <volume>9</volume>, no. <issue>13</issue>, pp. <fpage>2002</fpage>&#x2013;<lpage>2014</lpage>, <year>2016</year>. doi: <pub-id pub-id-type="doi">10.1002/sec.1455</pub-id>.</mixed-citation></ref>
<ref id="ref-55"><label>[55]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>C.</given-names> <surname>Lai</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Lu</surname></string-name>, <string-name><given-names>D.</given-names> <surname>Zheng</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Li</surname></string-name>, and <string-name><given-names>X. S.</given-names> <surname>Shen</surname></string-name></person-group>, &#x201C;<article-title>GLARM: Group-based lightweight authentication scheme for resource-constrained machine to machine communications</article-title>,&#x201D; <source>Comput. Netw.</source>, vol. <volume>99</volume>, no. <issue>4</issue>, pp. <fpage>66</fpage>&#x2013;<lpage>81</lpage>, <year>2016</year>. doi: <pub-id pub-id-type="doi">10.1016/j.comnet.2016.02.007</pub-id>.</mixed-citation></ref>
<ref id="ref-56"><label>[56]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Yao</surname></string-name>, <string-name><given-names>T.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Wang</surname></string-name>, and <string-name><given-names>G.</given-names> <surname>Chen</surname></string-name></person-group>, &#x201C;<article-title>GBS-AKA: Group-based secure authentication and key agreement for M2M in 4G network</article-title>,&#x201D; in <conf-name>Int. Conf. Cloud Comput. Res. Innov. (ICCCRI)</conf-name>, <publisher-loc>Singapore</publisher-loc>, <publisher-name>IEEE</publisher-name>, <year>2016</year>, pp. <fpage>42</fpage>&#x2013;<lpage>48</lpage>.</mixed-citation></ref>
<ref id="ref-57"><label>[57]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>Krebsonsecurity</collab></person-group>, &#x201C;<article-title>all about skimmers</article-title>,&#x201D; <year>2017</year>. <comment>Accessed: Dec. 06, 2023</comment>. [Online]. Available: <ext-link ext-link-type="uri" xlink:href="http://krebsonsecurtiy.com/all-about-skimmers/">http://krebsonsecurtiy.com/all-about-skimmers/</ext-link></mixed-citation></ref>
<ref id="ref-58"><label>[58]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>K.</given-names> <surname>Islam</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Shen</surname></string-name>, and <string-name><given-names>X.</given-names> <surname>Wang</surname></string-name></person-group>, &#x201C;<article-title>Security and privacy considerations for wireless sensor networks in smart home environments</article-title>,&#x201D; in <conf-name>Proc. 2012 IEEE 16th Int. Conf. Comput. Support. Cooperat. Work Des.(CSCWD)</conf-name>, <publisher-loc>Wuhan, China</publisher-loc>, <publisher-name>IEEE</publisher-name>, <year>2012</year>, pp. <fpage>626</fpage>&#x2013;<lpage>633</lpage>.</mixed-citation></ref>
<ref id="ref-59"><label>[59]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Liu</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Xiao</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Liang</surname></string-name>, and <string-name><given-names>C. P.</given-names> <surname>Chen</surname></string-name></person-group>, &#x201C;<article-title>Cyber security and privacy issues in smart grids</article-title>,&#x201D; <source>IEEE Commun. Surv. Tutor.</source>, vol. <volume>14</volume>, no. <issue>4</issue>, pp. <fpage>981</fpage>&#x2013;<lpage>997</lpage>, <year>2012</year>. doi: <pub-id pub-id-type="doi">10.1109/SURV.2011.122111.00145</pub-id>.</mixed-citation></ref>
<ref id="ref-60"><label>[60]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>X. H.</given-names> <surname>Le</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Khalid</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Sankar</surname></string-name>, and <string-name><given-names>S.</given-names> <surname>Lee</surname></string-name></person-group>, &#x201C;<article-title>An efficient mutual authentication and access control scheme for wireless sensor networks in healthcare</article-title>,&#x201D; <source>J. Netw.</source>, vol. <volume>6</volume>, no. <issue>3</issue>, pp. <fpage>355</fpage>, <year>2011</year>. doi: <pub-id pub-id-type="doi">10.4304/jnw.6.3.355-364</pub-id>.</mixed-citation></ref>
<ref id="ref-61"><label>[61]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>Y. </given-names> <surname>Shen</surname></string-name></person-group>, &#x201C;<article-title>An access control scheme in wireless sensor networks</article-title>,&#x201D; in <conf-name>Proc. 4th IFIP Int. Conf. Netw. Parallel Comput. Works. (NPC2007)</conf-name>, <publisher-loc>USA</publisher-loc>, <year>Sep. 2007</year>, pp. <fpage>362</fpage>&#x2013;<lpage>367</lpage>.</mixed-citation></ref>
<ref id="ref-62"><label>[62]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>H.</given-names> <surname>Wang</surname></string-name> and <string-name><given-names>Q.</given-names> <surname>Li</surname></string-name></person-group>, &#x201C;<article-title>Achieving distributed user access control in sensor networks</article-title>,&#x201D; <source>Ad Hoc Netw.</source>, vol. <volume>10</volume>, no. <issue>3</issue>, pp. <fpage>272</fpage>&#x2013;<lpage>283</lpage>, <year>2012</year>. doi: <pub-id pub-id-type="doi">10.1016/j.adhoc.2011.01.011</pub-id>.</mixed-citation></ref>
<ref id="ref-63"><label>[63]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>D.</given-names> <surname>Hankerson</surname></string-name>, <string-name><given-names>A. J.</given-names> <surname>Menezes</surname></string-name>, and <string-name><given-names>S.</given-names> <surname>Vanstone</surname></string-name></person-group>, &#x201C;<article-title>Guide to elliptic curve cryptography</article-title>,&#x201D; <source>Comput. Rev.</source>, vol. <volume>46</volume>, no. <issue>1</issue>, pp. <fpage>13</fpage>, <year>2005</year>.</mixed-citation></ref>
<ref id="ref-64"><label>[64]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>D.</given-names> <surname>He</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Chan</surname></string-name>, and <string-name><given-names>M.</given-names> <surname>Guizani</surname></string-name></person-group>, &#x201C;<article-title>Accountable and privacy-enhanced access control in wireless sensor networks</article-title>,&#x201D; <source>IEEE Trans. Wirel. Commun.</source>, vol. <volume>14</volume>, no. <issue>1</issue>, pp. <fpage>389</fpage>&#x2013;<lpage>398</lpage>, <year>2015</year>. doi: <pub-id pub-id-type="doi">10.1109/TWC.2014.2347311</pub-id>.</mixed-citation></ref>
<ref id="ref-65"><label>[65]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M. L.</given-names> <surname>Das</surname></string-name></person-group>, &#x201C;<article-title>Two-factor user authentication in wireless sensor networks</article-title>,&#x201D; <source>IEEE Trans. Wirel. Commun.</source>, vol. <volume>8</volume>, no. <issue>3</issue>, pp. <fpage>1086</fpage>&#x2013;<lpage>1090</lpage>, <year>2009</year>. doi: <pub-id pub-id-type="doi">10.1109/TWC.2008.080128</pub-id>.</mixed-citation></ref>
<ref id="ref-66"><label>[66]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>B.</given-names> <surname>Vaidya</surname></string-name>, <string-name><given-names>D.</given-names> <surname>Makrakis</surname></string-name>, and <string-name><given-names>H. T.</given-names> <surname>Mouftah</surname></string-name></person-group>, &#x201C;<article-title>Improved two-factor user authentication in wireless sensor networks</article-title>,&#x201D; in <conf-name>Wirel. Mobile Comput., Netw. Commun. (WiMob), 2010 IEEE 6th Int. Conf.</conf-name>, <publisher-loc>Niagara Falls, Canada</publisher-loc>, <publisher-name>IEEE</publisher-name>, <year>2010</year>, pp. <fpage>600</fpage>&#x2013;<lpage>606</lpage>.</mixed-citation></ref>
<ref id="ref-67"><label>[67]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>W. B.</given-names> <surname>Hsieh</surname></string-name> and <string-name><given-names>J. S.</given-names> <surname>Leu</surname></string-name></person-group>, &#x201C;<article-title>A robust ser authentication scheme sing dynamic identity in wireless sensor networks</article-title>,&#x201D; <source>Wireless Person. Commun.</source>, vol. <volume>77</volume>, no. <issue>2</issue>, pp. <fpage>979</fpage>&#x2013;<lpage>989</lpage>, <year>2014</year>.</mixed-citation></ref>
<ref id="ref-68"><label>[68]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Ma</surname></string-name>, and <string-name><given-names>Z.</given-names> <surname>Luo</surname></string-name></person-group>, &#x201C;<article-title>An authentication scheme with identity-based cryptography for M2M security in cyber-physical systems</article-title>,&#x201D; <source>Secur. Commun. Netw.</source>, vol. <volume>9</volume>, no. <issue>10</issue>, pp. <fpage>1146</fpage>&#x2013;<lpage>1157</lpage>, <year>2016</year>. doi: <pub-id pub-id-type="doi">10.1002/sec.1407</pub-id>.</mixed-citation></ref>
<ref id="ref-69"><label>[69]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>X.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Niu</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Kumari</surname></string-name>, <string-name><given-names>F.</given-names> <surname>Wu</surname></string-name>, <string-name><given-names>A. K.</given-names> <surname>Sangaiah</surname></string-name>, and <string-name><given-names>K. K. R.</given-names> <surname>Choo</surname></string-name></person-group>, &#x201C;<article-title>A three-factor anonymous authentication scheme for wireless sensor networks in internet of things environments</article-title>,&#x201D; <source>J. Netw. Comput. Appl.</source>, vol. <volume>103</volume>, pp. <fpage>194</fpage>&#x2013;<lpage>204</lpage>, <year>2018</year>. doi: <pub-id pub-id-type="doi">10.1016/j.jnca.2017.07.001</pub-id>.</mixed-citation></ref>
<ref id="ref-70"><label>[70]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Q.</given-names> <surname>Jiang</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Ma</surname></string-name>, <string-name><given-names>F.</given-names> <surname>Wei</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Tian</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Shen</surname></string-name> and <string-name><given-names>Y.</given-names> <surname>Yang</surname></string-name></person-group>, &#x201C;<article-title>An untraceable temporal-credential-based two-factor authentication scheme using ECC for wireless sensor networks</article-title>,&#x201D; <source>J. Netw. Comput. Appl.</source>, vol. <volume>76</volume>, no. <issue>1</issue>, pp. <fpage>37</fpage>&#x2013;<lpage>48</lpage>, <year>2016</year>. doi: <pub-id pub-id-type="doi">10.1016/j.jnca.2016.10.001</pub-id>.</mixed-citation></ref>
<ref id="ref-71"><label>[71]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y.</given-names> <surname>Choi</surname></string-name>, <string-name><given-names>D.</given-names> <surname>Lee</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Kim</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Jung</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Nam</surname></string-name> and <string-name><given-names>D.</given-names> <surname>Won</surname></string-name></person-group>, &#x201C;<article-title>Security enhanced user authentication protocol for wireless sensor networks using elliptic curves cryptography</article-title>,&#x201D; <source>Sens.</source>, vol. <volume>14</volume>, no. <issue>6</issue>, pp. <fpage>10081</fpage>&#x2013;<lpage>10106</lpage>, <year>Jun. 2014</year>. doi: <pub-id pub-id-type="doi">10.3390/s140610081</pub-id>; <pub-id pub-id-type="pmid">24919012</pub-id></mixed-citation></ref>
<ref id="ref-72"><label>[72]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>F.</given-names> <surname>Cavaliere</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Mattsson</surname></string-name>, and <string-name><given-names>B.</given-names> <surname>Smeets</surname></string-name></person-group>, &#x201C;<article-title>The security implications of quantum cryptography and quantum computing</article-title>,&#x201D; <source>Netw. Secur.</source>, vol. <volume>2020</volume>, no. <issue>9</issue>, pp. <fpage>9</fpage>&#x2013;<lpage>15</lpage>, <year>2020</year>. doi: <pub-id pub-id-type="doi">10.1016/s1353-4858(20)30105-7</pub-id>.</mixed-citation></ref>
<ref id="ref-73"><label>[73]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><given-names>M. S.</given-names> <surname>Zareen</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Tahir</surname></string-name>, and <string-name><given-names>B.</given-names> <surname>Aslam</surname></string-name></person-group>, &#x201C;<chapter-title>Authentication and authorization of IoT edge devices using artificial intelligence</chapter-title>,&#x201D; in <person-group person-group-type="editor"><string-name><given-names>D.</given-names> <surname>Cham</surname></string-name>, <string-name><given-names>D.</given-names> <surname>Puthal</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Mohanty</surname></string-name>, <string-name><given-names>B. Y.</given-names> <surname>Choi</surname></string-name></person-group> (Eds.), <source>Internet of Things. Advances in Information and Communication Technology</source>. <publisher-loc>Switzerland</publisher-loc>: <publisher-name>Springer Nature</publisher-name>, <year>2024</year>, pp. <fpage>442</fpage>&#x2013;<lpage>453</lpage>.</mixed-citation></ref>
<ref id="ref-74"><label>[74]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y.</given-names> <surname>Zheng</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Liu</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Gu</surname></string-name>, and <string-name><given-names>C. H.</given-names> <surname>Chang</surname></string-name></person-group>, &#x201C;<article-title>PUF-based mutual authentication and key exchange protocol for peer-to-peer IoT applications</article-title>,&#x201D; <source>IEEE Trans. Depend. Secure Comput.</source>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-75"><label>[75]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><given-names>V.</given-names> <surname>Bonandrini</surname></string-name>, <string-name><given-names>J. F.</given-names> <surname>Bercher</surname></string-name>, and <string-name><given-names>N.</given-names> <surname>Zangar</surname></string-name></person-group>, &#x201C;<chapter-title>Machine learning methods for anomaly detection in IoT networks, with illustrations</chapter-title>,&#x201D; in <source>Machine Learning for Networking</source>, Paris, France, <year>2019</year>, pp. <fpage>287</fpage>&#x2013;<lpage>295</lpage>.</mixed-citation></ref>
<ref id="ref-76"><label>[76]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>N.</given-names> <surname>Sivaselvan</surname></string-name>, <string-name><given-names>K. B.</given-names> <surname>Vivekananda</surname></string-name>, and <string-name><given-names>M.</given-names> <surname>Rajarajan</surname></string-name></person-group>, &#x201C;<article-title>Blockchain-based scheme for authentication and capability-based access control in IoT environment</article-title>,&#x201D; in <conf-name>2020 11th IEEE Annual Ubiquit. Comput., Electron. Mobile Commun. Conf. (UEMCON)</conf-name>, <year>Oct. 28&#x2013;31, 2020</year>, pp. <fpage>0323</fpage>&#x2013;<lpage>0330</lpage>. doi: <pub-id pub-id-type="doi">10.1109/UEMCON51285.2020.9298116</pub-id>.</mixed-citation></ref>
<ref id="ref-77"><label>[77]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>P. K.</given-names> <surname>Panda</surname></string-name> and <string-name><given-names>S.</given-names> <surname>Chattopadhyay</surname></string-name></person-group>, &#x201C;<article-title>An enhanced mutual authentication and security protocol for IoT and cloud server</article-title>,&#x201D; <source>Inf. Secur. J.: A Global Perspect.</source>, vol. <volume>31</volume>, no. <issue>2</issue>, pp. <fpage>144</fpage>&#x2013;<lpage>156</lpage>, <year>2022</year>. doi: <pub-id pub-id-type="doi">10.1080/19393555.2020.1871534</pub-id>.</mixed-citation></ref>
<ref id="ref-78"><label>[78]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><given-names>C.</given-names> <surname>Thammarat</surname></string-name> and <string-name><given-names>C.</given-names> <surname>Techapanupreeda</surname></string-name></person-group>, <source>A Secure Authentication and Key Exchange Protocol for M2M Communication</source>. <year>2021</year>. [Online]. Available: <ext-link ext-link-type="uri" xlink:href="http://dx.doi.org/10.1109/iEECON51072.2021.9440355">https://dx.doi.org/10.1109/iEECON51072.2021.9440355</ext-link></mixed-citation></ref>
</ref-list>
</back></article>