<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMC</journal-id>
<journal-id journal-id-type="nlm-ta">CMC</journal-id>
<journal-id journal-id-type="publisher-id">CMC</journal-id>
<journal-title-group>
<journal-title>Computers, Materials &#x0026; Continua</journal-title>
</journal-title-group>
<issn pub-type="epub">1546-2226</issn>
<issn pub-type="ppub">1546-2218</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">14035</article-id>
<article-id pub-id-type="doi">10.32604/cmc.2021.014035</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Authenblue: A New Authentication Protocol for the Industrial Internet of Things</article-title>
<alt-title alt-title-type="left-running-head">Authenblue: A New Authentication Protocol for the Industrial Internet of Things</alt-title>
<alt-title alt-title-type="right-running-head">Authenblue: A New Authentication Protocol for the Industrial Internet of Things</alt-title>
</title-group>
<contrib-group content-type="authors">
<contrib id="author-1" contrib-type="author" corresp="yes">
<name name-style="western">
<surname>Zagrouba</surname>
<given-names>Rachid</given-names>
</name>
<xref ref-type="aff" rid="aff-1">1</xref>
<email>rmzagrouba@iau.edu.sa</email>
</contrib>
<contrib id="author-2" contrib-type="author">
<name name-style="western">
<surname>AlAbdullatif</surname>
<given-names>Asayel</given-names>
</name>
<xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-3" contrib-type="author">
<name name-style="western">
<surname>AlAjaji</surname>
<given-names>Kholood</given-names>
</name>
<xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-4" contrib-type="author">
<name name-style="western">
<surname>Al-Serhani</surname>
<given-names>Norah</given-names>
</name>
<xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-5" contrib-type="author">
<name name-style="western">
<surname>Alhaidari</surname>
<given-names>Fahd</given-names>
</name>
<xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-6" contrib-type="author">
<name name-style="western">
<surname>Almuhaideb</surname>
<given-names>Abdullah</given-names>
</name>
<xref ref-type="aff" rid="aff-2">2</xref></contrib>
<contrib id="author-7" contrib-type="author">
<name name-style="western">
<surname>Atta-ur-Rahman</surname>
</name>
<xref ref-type="aff" rid="aff-2">2</xref></contrib>
<aff id="aff-1"><label>1</label><institution>Department of Computer Information System, College of Computer Science and Information Technology (CCSIT), Imam Abdulrahman Bin Faisal University</institution>, <addr-line>Dammam, 31441</addr-line>, <country>Saudi Arabia</country></aff>
<aff id="aff-2"><label>2</label><institution>Department of Computer Science, College of Computer Science and Information Technology (CCSIT), Imam Abdulrahman Bin Faisal University</institution>, <addr-line>Dammam, 31441</addr-line>, <country>Saudi Arabia</country></aff>
</contrib-group>
<author-notes><corresp id="cor1">&#x002A;Corresponding Author: Rachid Zagrouba. Email: <email>rmzagrouba@iau.edu.sa</email></corresp></author-notes>
<pub-date pub-type="epub" date-type="pub" iso-8601-date="2020-12-07">
<day>07</day>
<month>12</month>
<year>2020</year>
</pub-date>
<volume>67</volume>
<issue>1</issue>
<fpage>1103</fpage>
<lpage>1119</lpage>
<history>
<date date-type="received">
<day>30</day>
<month>08</month>
<year>2020</year>
</date>
<date date-type="accepted">
<day>22</day>
<month>11</month>
<year>2020</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2021 Zagrouba et al.</copyright-statement>
<copyright-year>2021</copyright-year>
<copyright-holder>Zagrouba et al.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMC_14035.pdf"></self-uri>
<abstract>
<p>The Internet of Things (IoT) is where almost anything can be controlled and managed remotely by means of sensors. Although the IoT evolution led to quality of life enhancement, many of its devices are insecure. The lack of robust key management systems, efficient identity authentication, low fault tolerance, and many other issues lead to IoT devices being easily targeted by attackers. In this paper we propose a new authentication protocol called Authenblue that improve the authentication process of IoT devices and Coordinators of Personal Area Network (CPANs) in an Industrial IoT (IIoT) environment. This study proposed Authenblue protocol as a new Blockchain-based authentication protocol. To enhance the authentication process and make it more secure, Authenblue modified the way of generating IIoT identifiers and the shared secret keys used by the IIoT devices to raise the efficiency of the authentication protocol. Authenblue enhance the authentication protocol that other models rely on by enhancing the approach used to generate the User Identifier (UI). The UI values changed from being static values, sensors MAC addresses, to be generated values in the inception phase. This approach makes the process of renewing the sensor keys more secure by renewing their UI values instead of changing the secret key. In this study, Authenblue has been simulated in the Network Simulator 3 (NS3). Simulation results show an improved performance compared to the related work.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Authentication</kwd>
<kwd>industrial internet of things</kwd>
<kwd>security</kwd>
<kwd>Authenblue</kwd>
<kwd>blockchain</kwd>
<kwd>NS3</kwd>
</kwd-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>The Internet of Things (IoT) is where almost anything can be controlled and managed remotely. The IoT evolution led to making life much easier, enhancing devices&#x2019; functionalities and features [<xref ref-type="bibr" rid="ref-1">1</xref>]. For example, during a rainy day, a person can close the home windows and turn on the heaters remotely from his/her office. IoT devices consist of physical components, such as microcontrollers, transceivers, and memory. In addition to that, they are integrated with a set of simple protocols, which establish communication between IoT devices and their users, and written codes for managing and controlling the IoT devices [<xref ref-type="bibr" rid="ref-2">2</xref>]. IoT helps in making the internet universal and immersive by allowing simple broad communications with many devices, such as house devices, automobile, monitoring cameras, and sensors [<xref ref-type="bibr" rid="ref-2">2</xref>,<xref ref-type="bibr" rid="ref-3">3</xref>]. Additionally, IoT assists in the development of many applications that make use of the excessive amount of data, that is generated by these devices for giving new services to people, governments, and organizations [<xref ref-type="bibr" rid="ref-2">2</xref>]. Furthermore, it is noticed that many industries have started manufacturing IoT devices where there are many IoT products to be used for smart homes, medical support, vehicles manufacturers, and in a variety of other domains [<xref ref-type="bibr" rid="ref-2">2</xref>,<xref ref-type="bibr" rid="ref-4">4</xref>&#x2013;<xref ref-type="bibr" rid="ref-6">6</xref>]. Regardless of IoT advanced functionalities, the IoT devices themselves are insecure. The lack of a robust key management systems, efficient identity authentication, low fault tolerance and many other issues lead IoT devices to being easily targeted by attackers [<xref ref-type="bibr" rid="ref-7">7</xref>&#x2013;<xref ref-type="bibr" rid="ref-12">12</xref>].</p>
<p>To overcome these root issues, many research works have urged to utilize the Blockchain technology, since its features can provide promising solutions for a variety of IoT security issues. Blockchain has many advanced features that distinguish it from any other technology [<xref ref-type="bibr" rid="ref-13">13</xref>]. Initially, blockchain was linked with bitcoin, which is mostly known for proof-of-work and hash-based-mechanisms. Nowadays, blockchain is known for providing security and functional assurances [<xref ref-type="bibr" rid="ref-14">14</xref>,<xref ref-type="bibr" rid="ref-15">15</xref>]. Blockchain can be used by many industries in different applications to enhance both, the functionality and security [<xref ref-type="bibr" rid="ref-16">16</xref>,<xref ref-type="bibr" rid="ref-17">17</xref>]. The robust authentication systems used in the cryptocurrency for authenticating the transactions made the cryptocurrency field protected against a variety of attacks [<xref ref-type="bibr" rid="ref-18">18</xref>]. Having a robust identity authentication management system that authenticates devices is what IIoT security needs. Moreover, considering the limited capabilities of IIoT devices by reducing the resource consumption as much as possible is crucial for the sustainability of IIoT field.</p>
<p>Currently, the applied identity authentication management systems in IIoT have two main challenges that hinder them from being widely adopted. These challenges are the low speed and storage of its devices [<xref ref-type="bibr" rid="ref-19">19</xref>]. Developing a strong lightweight authentication protocol for mutually authenticating the identities of IIoT devices and coordinators along with their messages is the main problem to be tackled in this paper. Having such protocol protects against various types of attacks, such as identity spoofing, and modification and fabrication of messages. This work aims to answer the following questions:
<list list-type="bullet">
<list-item><p>How to develop an effective authentication protocol for authenticating IIoT identities and messages yet it is light enough to suit IIoT limited capabilities?</p></list-item>
<list-item><p>How can this protocol enhance IIoT security and protects it against many attacks?</p></list-item>
</list></p>
<p>The rest of this paper is organized as follows. Section 2 presents background for IoT and blockchain technologies. In Section 3, we present the related literature review along with our findings and gap analysis. Section 4 depicts the proposed solution and Section 6 shows the simulation work conducted to validate the prosed work. Finally, Section 7 gives the conclusion of this research paper.</p>
</sec>
<sec id="s2">
<label>2</label>
<title>Literature Review</title>
<p>Although the use of blockchain technology in IoT is an emerging field, many research have shown its effectiveness in increasing IoT overall functionalities [<xref ref-type="bibr" rid="ref-16">16</xref>,<xref ref-type="bibr" rid="ref-20">20</xref>,<xref ref-type="bibr" rid="ref-21">21</xref>]. However, the focus of this paper is on the security perspective. This section consists of six subsections. The first three subsections address recent research works on IoT security. The related works are discussed based on their proposed solutions. The first subsection includes research works related to the security in IoT communications. As for the second subsection, papers related to the utilization of blockchain for trust management and authentication in the IoT field are discussed. The third subsection covers some papers related to the utilization of blockchain for controlling IoT devices. Lastly, after discussing the related works, comparisons, analysis, and findings are addressed in Subsections 4, 5, and 6 respectively.</p>
<sec id="s2_1">
<label>2.1</label>
<title>Security in IoT Communications</title>
<p>Wireless sensors network is a pivotal part of the IoT domain. Many research works have targeted the wireless sensors networks (WSN) for enhancing their security [<xref ref-type="bibr" rid="ref-22">22</xref>,<xref ref-type="bibr" rid="ref-23">23</xref>]. In 2013, Li et al. [<xref ref-type="bibr" rid="ref-24">24</xref>] proposed a heterogeneous signcryption scheme for WSN in the paper entitled by &#x201C;Practical Secure Communication for Integrating Wireless Sensor Networks into the Internet of Things&#x201D;. The proposed scheme algorithms are applied in two stages, offline and online. The scheme aims to secure the communication between the wireless sensors and the internet hosts by providing confidentiality, integrity, authenticity, and nonrepudiation [<xref ref-type="bibr" rid="ref-24">24</xref>]. The authors used the Identity-Based Cryptography (IBC) for the sensors where there are no certificates as in the Public Key Infrastructure (PKI) which can cause an overhead for managing their validity [<xref ref-type="bibr" rid="ref-25">25</xref>]. The main feature of this scheme is the ability of the wireless sensors, which apply IBC, to communicate with the internet hosts, that apply PKI, with high confidentiality, integrity, authenticity, and nonrepudiation. For measuring the scheme&#x2019;s security, the authors proved that their scheme satisfies IND-CCA2, for measuring the encryption security, and EUF-CMA, which measures the signature scheme security [<xref ref-type="bibr" rid="ref-25">25</xref>]. What distinguishes Li and Xiong scheme is its heterogeneous nature, the ability of devices applying IBC to communicate with others that use PKI. Although the dominant of the signcryption schemes are homogeneous, however, heterogeneous schemes suite in many IoT domains, where Internet hosts must communicate directly with servers, and other internet hosts that use different cryptography paradigm [<xref ref-type="bibr" rid="ref-8">8</xref>].</p>
<p>As an enhancement on this scheme, Ting et al. [<xref ref-type="bibr" rid="ref-8">8</xref>] have proposed a scheme with lower computation costs yet has higher security and efficiency [<xref ref-type="bibr" rid="ref-7">7</xref>,<xref ref-type="bibr" rid="ref-26">26</xref>]. The scheme aims to provide a holistic approach for enhancing the four aforementioned main security aspects, which are confidentiality, integrity, authenticity, and nonrepudiation. As in Li and Xiong scheme, this scheme has two stages, offline and online where most of the computations are done in the offline stage.</p>
</sec>
<sec id="s2_2">
<label>2.2</label>
<title>Utilization of Blockchain for Trust Management and Authentication in the IoT</title>
<p>In 2017, the paper entitled by &#x201C;Blockchain Based Trust &#x0026; Authentication for Decentralized Sensor Networks&#x201D; posed a security model that uses blockchain data structure to save the sensors decentralized authentication and trust data for achieving integrity and validity, to have cryptographic authenticated data, and trust in peer to peer wireless sensors network, which is heavily used in IoT environment [<xref ref-type="bibr" rid="ref-9">9</xref>]. Additionally, handling of security and privacy in WSN cause problems like, low resource on computation, constraints in energy consumption, and hardware functionality [<xref ref-type="bibr" rid="ref-9">9</xref>]. Moreover, the paper focused on two subjects, security and privacy of data, node authentication and trust management [<xref ref-type="bibr" rid="ref-9">9</xref>]. First, authentication and trust management; WSN has security constraints on node authentication to confirm validity and confidentiality of data [<xref ref-type="bibr" rid="ref-9">9</xref>]. Second, trust management, which is considered upon authentication mechanism to recognize the trustee and trustor [<xref ref-type="bibr" rid="ref-9">9</xref>]. Furthermore, the paper mentioned briefly about the blockchain and the usage of it in financial transactions, where it uses blocks of cryptographic hashes in a linear order that have the previous and next block hash to ensure continuity [<xref ref-type="bibr" rid="ref-9">9</xref>]. The framework is a service-oriented architecture that handles the data in a decentralized network, which consists of resource constrained nodes that uses embedded system in them.</p>
<p>The proposed module is Blockchain Authentication and Trust Module (BATM), where it uses public key infrastructure for achieving confidentiality by encryption, digital signature authentication, and trust by Peer&#x2019;s identity validation [<xref ref-type="bibr" rid="ref-9">9</xref>]. BATM authentication uses a master key to generate secondary keys for encryption and digital signature, so the key management has a great importance in the module [<xref ref-type="bibr" rid="ref-9">9</xref>]. BATM block mining, where the data payload contains the information of Network Node (NN) condition and cryptographic data. In the case of authentication, the node gives its credentials including the master key, secondary keys [<xref ref-type="bibr" rid="ref-9">9</xref>]. Also, to reduce the number of attacks, the key renewal is done by having key validity timeouts, where the key is renewed when the timer timeouts [<xref ref-type="bibr" rid="ref-9">9</xref>]. Moreover, the privacy of network security depends on the blockchain data, so BATM prevents adding new block unless it&#x2019;s from an authenticated node that did not create any payload in the block, where the choice of the payload to be included in the block is done by the miner. Additionally, to have a valid block it must resolve a problem and include the miner&#x2019;s approved valid payload (include digital signature of random value from the previous authenticated block), that both are created by the miner. As demonstrated in the algorithm below [<xref ref-type="bibr" rid="ref-9">9</xref>].</p>
<fig id="fig-7">
<graphic mimetype="image" mime-subtype="png" xlink:href="fig-7.png"/>
</fig>
<p>BATM trust management, which is accomplished by maintaining the reputation level of nodes, where the reputation is made up of mutual surveillance of all the nodes in the network, that can be known from the node payload where it contains the node behavior that came from its actions, and it is collected over time to ensure its credibility [<xref ref-type="bibr" rid="ref-9">9</xref>]. Additionally, the trust level is calculated from the number of authenticated nodes to the node. This way of trust management made it unfeasible for attackers to overload the network of validated nodes by having, timers, key validity timeouts, and event reputation [<xref ref-type="bibr" rid="ref-9">9</xref>]. In conclusion, this paper introduces a new module that uses blockchain in decentralized sensor networks; which is one of the main components of IoT, that ensures trust management and authentication, security and privacy of data for the goal of a better handling of users&#x2019; information. Another mechanism that discusses IoT devices authentication was proposed in 2018 named BCTrust [<xref ref-type="bibr" rid="ref-27">27</xref>]. BCTrust was proposed by Hammi et al. [<xref ref-type="bibr" rid="ref-27">27</xref>]. It is based on the blockchain technology and it targets the IoT field since it does not overload its devices [<xref ref-type="bibr" rid="ref-27">27</xref>]. The mechanism has been implemented through Ethereum platform, with an extra layer for making the blockchain network private [<xref ref-type="bibr" rid="ref-27">27</xref>]. Moreover, certain nodes were given high privileges as stated in the smart contract. These nodes are named Coordinator of Personal Area Network (CPAN) [<xref ref-type="bibr" rid="ref-27">27</xref>]. CPAN nodes are the only ones who can make transactions, and to make this securer, each node has its own pair of keys [<xref ref-type="bibr" rid="ref-27">27</xref>].</p>
<p>Each CPAN node manages a set of nodes under it. In BCTrust mechanism, the principle of &#x201C;The friend of my friend is my friend&#x201D; is what the mechanism relies on [<xref ref-type="bibr" rid="ref-27">27</xref>]. By that, if a node named n is managed by the CPAN of the name N, then N initially authenticates n. Once n is authenticated, a transaction is sent to the blockchain to be validated by the CPANs [<xref ref-type="bibr" rid="ref-27">27</xref>]. This transaction shows that N authenticates and manages n, and as a result, N has n&#x2019;s shared symmetric keys to be used for exchanging data securely [<xref ref-type="bibr" rid="ref-27">27</xref>]. This whole process is done by exchanging four messages. If n wants to change its CPAN, to be within a different set of nodes, exchanging two messages for this process is enough. Firstly, the new CPAN checks for the aforementioned transaction in the blockchain. Secondly, if this new CPAN found that n is already authenticated by N, it asks for n&#x2019;s key through a secure channel that uses a key and an initialization vector [<xref ref-type="bibr" rid="ref-27">27</xref>]. Now that the new CPAN has n&#x2019;s key, n officially is considered to be managed by this CPAN, which therefore has to send a transaction just as the one before [<xref ref-type="bibr" rid="ref-27">27</xref>]. The work in [<xref ref-type="bibr" rid="ref-27">27</xref>] have showed how their mechanism has less time and power consumption compared with previous mechanisms. The main reason behind this would be the reduction of the needed messages to be exchanged when associating a node to a new CPAN [<xref ref-type="bibr" rid="ref-27">27</xref>].</p>
</sec>
<sec id="s2_3">
<label>2.3</label>
<title>Utilization of Blockchain for Controlling IoT Devices</title>
<p>This section discusses two related works on the use of blockchain technology for controlling IoT devices in terms of resources consumption. Both papers used Ethereum platform for controlling the devices. In the first paper, the proposed approach showed its effectiveness for limiting power consumption. For the second paper, it intended to control the IoT network traffic for enhancing security.</p>
<p>Huh et al. [<xref ref-type="bibr" rid="ref-19">19</xref>] have proposed a new approach for managing IoT devices and securing them [<xref ref-type="bibr" rid="ref-16">16</xref>]. What differentiates their approach than others are their adoption of blockchain technology. Nevertheless, the approach considered the limitations of IoT capabilities and proposes an energy-saving mode. The adopted blockchain platform here is Ethereum, and the used cryptosystem is RSA. The public keys are stored through Ethereum, while the private keys are kept on the devices themselves [<xref ref-type="bibr" rid="ref-19">19</xref>]. Ethereum uses smart contracts, in this approach, the contracts are used to include codes for controlling the IoT devices.</p>
<p>Javid et al. [<xref ref-type="bibr" rid="ref-7">7</xref>] have proposed an integration of blockchain with IoT using a blockchain-based decentralized platform. Their work aimed to prevent unauthorized access to the network by using Ethereum&#x2019;s smart contract functionality. They have also proposed a method of resource allocation that can tackle the issue of turning IoT devices into zombies for performing DDoS attacks. The proposed solution of integrating Ethereum with the IoT device-to-server communication architecture has three security and architectural properties, a blockchain-based framework to detect and prevent IoT DDoS attacks; a distributed framework to control and enable trust-free IoT operations; and the integration of legacy IoT devices with low computational capabilities [<xref ref-type="bibr" rid="ref-7">7</xref>].</p>
<p>As [<xref ref-type="bibr" rid="ref-13">13</xref>] mentioned the single-point-of-failure issues that the IoT centralized-server introduces; the IoT-Ethereum framework proposed in [<xref ref-type="bibr" rid="ref-7">7</xref>] utilizes the smart contract functionality to avoid such issues, as well as other issues related to authentication and trust. The single-point-of-failure can be eliminated through distributing control and trust among multiple participant nodes; where the computational requirements for running the blockchain are distributed among the nodes, and trust is established through a consensus protocol instead of a third party; the framework can be considered decentralized by the previous ways [<xref ref-type="bibr" rid="ref-7">7</xref>].</p>
</sec>
<sec id="s2_4">
<label>2.4</label>
<title>Comparison</title>
<p>To analyze the current solutions for enhancing IoT security, and to decide about the possible contribution to be proposed, six of the aforementioned research works proposed solutions are used as references. As shown in <xref ref-type="table" rid="table-1">Tab. 1</xref>, the solutions are BATM [<xref ref-type="bibr" rid="ref-9">9</xref>], BCTrust [<xref ref-type="bibr" rid="ref-27">27</xref>], Li et al. [<xref ref-type="bibr" rid="ref-24">24</xref>], Ting et al. [<xref ref-type="bibr" rid="ref-8">8</xref>], Huh et al. [<xref ref-type="bibr" rid="ref-19">19</xref>], and IoT-Ethereum Framework [<xref ref-type="bibr" rid="ref-7">7</xref>]. The comparison is done based on the security aspects they target, these aspects are Confidentiality (C), integrity (I), Availability (A), Authentication (AN), authorization (AR), Non-Repudiation (NR), and an efficient management of keys (KM). Beside the security aspects, further factors are chosen, which are BloCkchain utilization (BC), whether the solution uses blockchain or not, and the Resources Consumption (RC), whether the proposed solution highly considers the low capabilities of IoT devices and uses their resources efficiently with a relatively low consumption or not.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>Comparison between the related works&#x2019; proposed solutions</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Factor</th>
<th>Description</th>
<th colspan="6">Solution</th>
</tr>
<tr>
<th></th>
<th></th>
<th>BATM [<xref ref-type="bibr" rid="ref-9">9</xref>]</th>
<th>BCTrust [<xref ref-type="bibr" rid="ref-27">27</xref>]</th>
<th>LX [<xref ref-type="bibr" rid="ref-24">24</xref>]</th>
<th>TTW [<xref ref-type="bibr" rid="ref-8">8</xref>]</th>
<th>HCK [<xref ref-type="bibr" rid="ref-19">19</xref>]</th>
<th>IoT-Ethereum framework [<xref ref-type="bibr" rid="ref-7">7</xref>]</th>
</tr>
</thead>
<tbody>
<tr>
<td><bold>C</bold></td>
<td>The secrecy of the transmitted and stored data</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td><inline-formula id="ieqn-1"><alternatives><inline-graphic xlink:href="ieqn-1.png"/><tex-math id="tex-ieqn-1"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-1"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
</tr>
<tr>
<td><bold>I</bold></td>
<td>The accuracy and non-alteration of the transmitted and stored data</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td><inline-formula id="ieqn-2"><alternatives><inline-graphic xlink:href="ieqn-2.png"/><tex-math id="tex-ieqn-2"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-2"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
</tr>
<tr>
<td><bold>A</bold></td>
<td>The timely service and information accessibility for IoT devices</td>
<td><inline-formula id="ieqn-3"><alternatives><inline-graphic xlink:href="ieqn-3.png"/><tex-math id="tex-ieqn-3"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-3"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td>&#x2713;</td>
<td><inline-formula id="ieqn-4"><alternatives><inline-graphic xlink:href="ieqn-4.png"/><tex-math id="tex-ieqn-4"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-4"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td><inline-formula id="ieqn-5"><alternatives><inline-graphic xlink:href="ieqn-5.png"/><tex-math id="tex-ieqn-5"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-5"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td><inline-formula id="ieqn-6"><alternatives><inline-graphic xlink:href="ieqn-6.png"/><tex-math id="tex-ieqn-6"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-6"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td>&#x2713;</td>
</tr>
<tr>
<td><bold>AN</bold></td>
<td>The verification of IoT device&#x2019;s identity</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
</tr>
<tr>
<td><bold>AR</bold></td>
<td>The granting of privileges to the authorized IoT device</td>
<td><inline-formula id="ieqn-7"><alternatives><inline-graphic xlink:href="ieqn-7.png"/><tex-math id="tex-ieqn-7"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-7"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td>&#x2713;</td>
<td><inline-formula id="ieqn-8"><alternatives><inline-graphic xlink:href="ieqn-8.png"/><tex-math id="tex-ieqn-8"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-8"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td><inline-formula id="ieqn-9"><alternatives><inline-graphic xlink:href="ieqn-9.png"/><tex-math id="tex-ieqn-9"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-9"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td><inline-formula id="ieqn-10"><alternatives><inline-graphic xlink:href="ieqn-10.png"/><tex-math id="tex-ieqn-10"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-10"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td>&#x2713;</td>
</tr>
<tr>
<td><bold>NR</bold></td>
<td>The protection against deniability of actions</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
</tr>
<tr>
<td><bold>RC</bold></td>
<td>The consumption of IoT devices&#x2019; resources is within an acceptable range</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td><inline-formula id="ieqn-11"><alternatives><inline-graphic xlink:href="ieqn-11.png"/><tex-math id="tex-ieqn-11"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-11"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td>&#x2713;</td>
<td><inline-formula id="ieqn-12"><alternatives><inline-graphic xlink:href="ieqn-12.png"/><tex-math id="tex-ieqn-12"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-12"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td>&#x2713;</td>
</tr>
<tr>
<td><bold>KM</bold></td>
<td>The use of an efficient key management mechanism</td>
<td>&#x2713;</td>
<td><inline-formula id="ieqn-13"><alternatives><inline-graphic xlink:href="ieqn-13.png"/><tex-math id="tex-ieqn-13"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-13"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td><inline-formula id="ieqn-14"><alternatives><inline-graphic xlink:href="ieqn-14.png"/><tex-math id="tex-ieqn-14"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-14"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td><inline-formula id="ieqn-15"><alternatives><inline-graphic xlink:href="ieqn-15.png"/><tex-math id="tex-ieqn-15"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-15"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td>&#x2713;</td>
<td><inline-formula id="ieqn-16"><alternatives><inline-graphic xlink:href="ieqn-16.png"/><tex-math id="tex-ieqn-16"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-16"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s2_5">
<label>2.5</label>
<title>Analysis</title>
<p>This section provides analysis for the compared solutions in <xref ref-type="table" rid="table-1">Tab. 1</xref>. It analyzes each solution based on the addressed factors. In BATM model, it utilizes blockchain to ensure two of the main information security model components, which  are confidentiality and integrity via encryption. Moreover, it provides authentication by using public key infrastructure and digital signature while it ensures non-repudiation by using digital signature. Furthermore, it consumes less power and takes less time according to RESTful Model [<xref ref-type="bibr" rid="ref-28">28</xref>], additionally, it consumes less resources since it is low in resource wastage referring to Service-Oriented Architecture, that BATM is based on [<xref ref-type="bibr" rid="ref-29">29</xref>].</p>
<p>For the second solution, BCTrust mechanism, all security aspects are considered. It uses a customized private Ethereum platform, this made it satisfies both, the security aspects applied in Ethereum [<xref ref-type="bibr" rid="ref-27">27</xref>]. Moreover, the use of symmetric and asymmetric keys and the procedure it follows for authenticating IoT devices satisfy the confidentiality, integrity and authentication aspects [<xref ref-type="bibr" rid="ref-27">27</xref>]. As for resources consumption, BCTrust has less power consumption compared with previous mechanisms [<xref ref-type="bibr" rid="ref-27">27</xref>]. The main reason behind this would be the reduction of the needed messages to be exchanged when associating a node to a new CPAN, as clarified previously [<xref ref-type="bibr" rid="ref-27">27</xref>].</p>
<p>For LX and TTW schemes, both consider the same security aspects, which are confidentiality, integrity, authentication, and non-repudiation. They do not consider the authorization aspect as in BATM. Moreover, these schemes do not utilize blockchain technology. LX and TTW varies in their resources&#x2019; consumption ranges. TTW scheme consumes less memory and energy compared to LX [<xref ref-type="bibr" rid="ref-8">8</xref>,<xref ref-type="bibr" rid="ref-24">24</xref>]. Nevertheless, TTW scheme has better utilization for the microcontrollers in which it made it faster than LX by approximately 30%. Unlike LX scheme which highly consumes the microcontrollers during one of its phases, which is the unsigncrypt phase [<xref ref-type="bibr" rid="ref-8">8</xref>].</p>
<p>As for HCK approach, it adopts the blockchain technology, unlike LX and TTW. As for the considered security aspects, it covers the same as LX and TTW schemes. For the resources&#x2019; consumption, HCK has an energy-saving mode [<xref ref-type="bibr" rid="ref-19">19</xref>]. This assists in saving IoT devices energy. As for the memory consumption, HCK requires a high storage medium, which is not applicable in IoT devices [<xref ref-type="bibr" rid="ref-19">19</xref>]. Therefore, a solution for this weakness must be addressed in future works.</p>
<p>Lastly, as for the IoT-Ethereum framework, it targets and considers the availability, authentication, authorization, and non-repudiation security aspects. Additionally, it utilizes the blockchain technology, as it uses Ethereum, a blockchain variant. Furthermore, the transactions and data exchange are verified in this framework using high computational and processing capabilities [<xref ref-type="bibr" rid="ref-7">7</xref>].</p>
<p>After comparing and analyzing the proposed solutions in the related works, it is found that BCTrust is the only solution that considered the six specified security aspects. In addition to that, BCTrust mechanism had the least overhead on the IoT devices where it does not exhaust their limited capabilities. Based on this, working on further enhancements on this mechanism may lead into having a powerful mechanism for authenticating and managing IoT devices.</p>
</sec>
</sec>
<sec id="s3">
<label>3</label>
<title>The Proposed Solution</title>
<p>Authenblue protocol aims to improve the authentication mechanism in BCTruct protocol. BCTrust has an authentication mechanism for authenticating IIoT devices and CPANs in OCARI networks. Furthermore, it utilizes the blockchain technology for enhancing the association feature. As for Authenblue, it is to be applied in Zigbee-based WSN environment. The focus is on the personalization, association, authentication, and the encryption/decryption functions. Authenblue authenticates IIoT identities and messages in a better way. Furthermore, it has better key management than the one in BCTrust. Authenblue aims to provide a high authentication of IIoT devices identities and packets, along with a good encryption and integrity. Meanwhile, ensure its lightness and suitability for the limited capabilities in the IIoT environments Authenblue provides a mutual lightweight authentication and a key management method for the IIoT devices and their CPANs in the WSN. In a WSN, there are different clusters. Each cluster has IIoT devices and is coordinated by a CPAN. All CPANs and nodes should have their own unique keys. These keys and other unique identifiers (UI) are set by a trusted authority in the network, known as Provider. With these unique values, IIoT devices and the CPANs start association and authentication procedures. When the association and authentication are done successfully, secure channels between the IIoT nodes and their CPANs are established. Through these channels, CPANs and IIoT nodes can exchange packets securely. All these functions are addressed below in phases followed by their functional requirements.</p>
<sec id="s3_1">
<label>3.1</label>
<title>Preparation Phases</title>
<p>Initially, CPANs and IIoT devices need to be configured to have unique keys and values. The values generated in the preparation phase give each device a distinctive identity, <xref ref-type="table" rid="table-2">Tab. 2</xref> illustrates this phase.</p>
<p><xref ref-type="table" rid="table-1">Tab. 2</xref>. Preparation phase in Authenblue protocol.</p>
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>Preparation phases</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
</colgroup>
<tbody>
<tr>
<td><bold>Actor</bold></td>
<td>Provider and administrator.</td>
</tr>
<tr>
<td><bold>Description</bold></td>
<td>CPANs need to have initial keys, and IIoT devices need to have unique identifiers along with devices keys. The Provider must generate these values, and the administrator must set them on the CPANs and the IIoT devices. This process is to be done once a new CPAN/IIoT device is brought. After that, the administrator has the choice whether to renew these values such as annually or every five years.</td>
<td/>
</tr>
<tr>
<td><bold>Priority</bold></td>
<td>This phase must be at first. Without this preparation phase, Authenblue cannot function.</td>
<td/>
</tr>
<tr>
<td><bold>Process</bold></td>
<td>Generating CPAN keys:</td>
<td/>
</tr>
<tr>
<td/>
<td><inline-formula id="ieqn-17"><alternatives><inline-graphic xlink:href="ieqn-17.png"/><tex-math id="tex-ieqn-17"><![CDATA[$\bullet$]]></tex-math><mml:math id="mml-ieqn-17"><mml:mo>&#x2219;</mml:mo></mml:math></alternatives></inline-formula> Administrator inputs the MAC addresses of the CPANs to the Provider.</td>
<td/>
</tr>
<tr>
<td/>
<td><inline-formula id="ieqn-18"><alternatives><inline-graphic xlink:href="ieqn-18.png"/><tex-math id="tex-ieqn-18"><![CDATA[$\bullet$]]></tex-math><mml:math id="mml-ieqn-18"><mml:mo>&#x2219;</mml:mo></mml:math></alternatives></inline-formula> The provider generates a secret key for each CPAN.</td>
<td/>
</tr>
<tr>
<td/>
<td><inline-formula id="ieqn-19"><alternatives><inline-graphic xlink:href="ieqn-19.png"/><tex-math id="tex-ieqn-19"><![CDATA[$\bullet$]]></tex-math><mml:math id="mml-ieqn-19"><mml:mo>&#x2219;</mml:mo></mml:math></alternatives></inline-formula> The administrator set each key in its CPAN.</td>
<td/>
</tr>
<tr>
<td/>
<td>Generating IIoT device keys:</td>
<td/>
</tr>
<tr>
<td/>
<td><inline-formula id="ieqn-20"><alternatives><inline-graphic xlink:href="ieqn-20.png"/><tex-math id="tex-ieqn-20"><![CDATA[$\bullet$]]></tex-math><mml:math id="mml-ieqn-20"><mml:mo>&#x2219;</mml:mo></mml:math></alternatives></inline-formula> Administrator inputs the MAC addresses of the device into the Provider.</td>
<td/>
</tr>
<tr>
<td/>
<td><inline-formula id="ieqn-21"><alternatives><inline-graphic xlink:href="ieqn-21.png"/><tex-math id="tex-ieqn-21"><![CDATA[$\bullet$]]></tex-math><mml:math id="mml-ieqn-21"><mml:mo>&#x2219;</mml:mo></mml:math></alternatives></inline-formula> The Administrator specifies a CPAN that would coordinate this IIoT device.</td>
<td/>
</tr>
<tr>
<td/>
<td><inline-formula id="ieqn-22"><alternatives><inline-graphic xlink:href="ieqn-22.png"/><tex-math id="tex-ieqn-22"><![CDATA[$\bullet$]]></tex-math><mml:math id="mml-ieqn-22"><mml:mo>&#x2219;</mml:mo></mml:math></alternatives></inline-formula> The Provider generates a unique identifier for the IIoT device.</td>
<td/>
</tr>
<tr>
<td/>
<td><inline-formula id="ieqn-23"><alternatives><inline-graphic xlink:href="ieqn-23.png"/><tex-math id="tex-ieqn-23"><![CDATA[$\bullet$]]></tex-math><mml:math id="mml-ieqn-23"><mml:mo>&#x2219;</mml:mo></mml:math></alternatives></inline-formula> The Provider generates a device key derived from the UI and CPAN&#x2019;s initial key.</td>
<td/>
</tr>
<tr>
<td/>
<td><inline-formula id="ieqn-24"><alternatives><inline-graphic xlink:href="ieqn-24.png"/><tex-math id="tex-ieqn-24"><![CDATA[$\bullet$]]></tex-math><mml:math id="mml-ieqn-24"><mml:mo>&#x2219;</mml:mo></mml:math></alternatives></inline-formula> The administrator set each value and key in the IIoT device.</td>
<td/>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>Authenticated Encryption/Decryption</title>
<p>IIoT nodes associated with their CPANs can communicate through a secured channel resulted from the association and authentication phases. CPANs need to have initial keys, and IIoT devices need to have unique identifiers along with devices keys. The Provider must generate these values, and the administrator must set them on the CPANs and the IIoT devices. This process is to be done once a new CPAN/IIoT device is brought. The packets sent by CPANs and IIoT nodes can be authenticated by encrypting them and sending them with a tag. Through this,  confidentiality, integrity, and authentication of both, the identity and the message are accomplished. <xref ref-type="table" rid="table-3">Tab. 3</xref> illustrates this phase.</p>
<table-wrap id="table-3">
<label>Table 3</label>
<caption>
<title>Authenticated encryption/decryption functions</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
</colgroup>
<tbody>
<tr>
<td><bold>Actor</bold></td>
<td>IIoT devices and CPANs.</td>
</tr>
<tr>
<td><bold>Description</bold></td>
<td>The packets sent by CPANs and IIoT nodes can be authenticated by encrypting them and sending them with a tag. Through this, confidentiality, integrity, and authentication of both, the identity, and the message, are accomplished.</td>
<td/>
</tr>
<tr>
<td><bold>Priority</bold></td>
<td>Authenticated encryption/decryption can be performed after a successful association with a CPAN.</td>
<td/>
</tr>
<tr>
<td><bold>Process</bold></td>
<td>Authenticated encryption:</td>
<td/>
</tr>
<tr>
<td/>
<td><inline-formula id="ieqn-25"><alternatives><inline-graphic xlink:href="ieqn-25.png"/><tex-math id="tex-ieqn-25"><![CDATA[$\bullet$]]></tex-math><mml:math id="mml-ieqn-25"><mml:mo>&#x2219;</mml:mo></mml:math></alternatives></inline-formula> The sender encrypts the data to be sent using the authenticated encryption<break/> function in AES-GCM.</td>
<td/>
</tr>
<tr>
<td/>
<td><inline-formula id="ieqn-26"><alternatives><inline-graphic xlink:href="ieqn-26.png"/><tex-math id="tex-ieqn-26"><![CDATA[$\bullet$]]></tex-math><mml:math id="mml-ieqn-26"><mml:mo>&#x2219;</mml:mo></mml:math></alternatives></inline-formula> The sender generates a tag for the encrypted data.</td>
<td/>
</tr>
<tr>
<td/>
<td>Authenticated decryption:</td>
<td/>
</tr>
<tr>
<td/>
<td><inline-formula id="ieqn-27"><alternatives><inline-graphic xlink:href="ieqn-27.png"/><tex-math id="tex-ieqn-27"><![CDATA[$\bullet$]]></tex-math><mml:math id="mml-ieqn-27"><mml:mo>&#x2219;</mml:mo></mml:math></alternatives></inline-formula> The receiver checks the received tag, if it is found to be incorrect, it drops the<break/> packet, otherwise, it proceeds to the next step.</td>
<td/>
</tr>
<tr>
<td/>
<td><inline-formula id="ieqn-28"><alternatives><inline-graphic xlink:href="ieqn-28.png"/><tex-math id="tex-ieqn-28"><![CDATA[$\bullet$]]></tex-math><mml:math id="mml-ieqn-28"><mml:mo>&#x2219;</mml:mo></mml:math></alternatives></inline-formula> The receiver decrypts the ciphertext based on the authenticated decryption<break/> function in AES-GCM.</td>
<td/>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s3_3">
<label>3.3</label>
<title>Personalization</title>
<p>The <xref ref-type="fig" rid="fig-1">Fig. 1</xref> illustrates how the initial key Ki is generated for the CPAN. At first, the administrator has to manually input the MAC address and the name of the CPAN into the Provider, which in turn generates the key [Ki = HMAC (MAC, random)] and stores it in the local database. The generated key will be received and manually inserted into the CPAN by the administrator.</p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>Personalization of the CPAN 
</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="fig-1.png"/>
</fig>
<p>The <xref ref-type="fig" rid="fig-2">Fig. 2</xref> illustrates how the UI and Kd are generated for a device. At first, the administrator has to manually input the MAC address of the device into the Provider, which in turn generates UI, the 8 byes address, and the derived key Kd [UI = Func (MAC, random), Kd = HMAC (Ki, UI)] and stores them in the local database. The generated values will be received and manually inserted into the device by the administrator.</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>Personalization of IoT devices</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="fig-2.png"/>
</fig>
</sec>
<sec id="s3_4">
<label>3.4</label>
<title>Associating a Device to a CPAN</title>
<p>The process of associating a device to a CPAN in the mutual authentication protocol the BCTrust [<xref ref-type="bibr" rid="ref-27">27</xref>] is illustrated in the diagram below. At first, the device sends an association request that contains its UI to the CPAN, which in turn generates a challenge (a random number) and sends it to the device as an authentication request. The device then computes otp1 using its derived key Kd and the received challenge [<inline-formula id="ieqn-29"><alternatives><inline-graphic xlink:href="ieqn-29.png"/><tex-math id="tex-ieqn-29"><![CDATA[$\textrm{otp1}= \textrm{HOTP}$]]></tex-math><mml:math id="mml-ieqn-29"><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">otp1</mml:mtext></mml:mstyle><mml:mo>=</mml:mo><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">HOTP</mml:mtext></mml:mstyle></mml:math></alternatives></inline-formula> (Kd, challenge)], then sends the computed otp1 to the CPAN as an authentication response. The CPAN computes Kd of the device through the personalization function, where it inserts its initial key Ki and the device&#x2019;s UI [<inline-formula id="ieqn-30"><alternatives><inline-graphic xlink:href="ieqn-30.png"/><tex-math id="tex-ieqn-30"><![CDATA[$\textrm{Kd}= \textrm{HMAC}$]]></tex-math><mml:math id="mml-ieqn-30"><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">Kd</mml:mtext></mml:mstyle><mml:mo>=</mml:mo><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">HMAC</mml:mtext></mml:mstyle></mml:math></alternatives></inline-formula> (Ki, UI)], then generates otp1&#x2019; using the device&#x2019;s Kd and the challenge [<inline-formula id="ieqn-31"><alternatives><inline-graphic xlink:href="ieqn-31.png"/><tex-math id="tex-ieqn-31"><![CDATA[$\textrm{otp1'}= \textrm{HOTP}$]]></tex-math><mml:math id="mml-ieqn-31"><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">otp1&#x2019;</mml:mtext></mml:mstyle><mml:mo>=</mml:mo><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">HOTP</mml:mtext></mml:mstyle></mml:math></alternatives></inline-formula> (Kd, challenge)].</p>
<p>The CPAN then compares between the received otp1 and the computed otp1&#x2019;; if they differ, the device authentication fails and its association_req_count (failed association request counter) will be compared to association_req_max (maximum number of failed association request attempts), if they are equal, the device&#x2019;s UI will be blacklisted and the association operation stops, if they are different, the association_req_count for the device will be incremented and the association operation stops. Otherwise, if the computed otp1&#x2019; is equal to the received otp1, the device is authenticated successfully, and the CPAN generates a symmetric key Ku (unicast mode), signature, hiddenKeyBroadcast and otp2 [<inline-formula id="ieqn-32"><alternatives><inline-graphic xlink:href="ieqn-32.png"/><tex-math id="tex-ieqn-32"><![CDATA[$\textrm{Ku}= \textrm{PRF}$]]></tex-math><mml:math id="mml-ieqn-32"><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">Ku</mml:mtext></mml:mstyle><mml:mo>=</mml:mo><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">PRF</mml:mtext></mml:mstyle></mml:math></alternatives></inline-formula> (Kd, challenge), <inline-formula id="ieqn-33"><alternatives><inline-graphic xlink:href="ieqn-33.png"/><tex-math id="tex-ieqn-33"><![CDATA[$\textrm{signature}= \textrm{HMAC}$]]></tex-math><mml:math id="mml-ieqn-33"><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">signature</mml:mtext></mml:mstyle><mml:mo>=</mml:mo><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">HMAC</mml:mtext></mml:mstyle></mml:math></alternatives></inline-formula> (Ku, otp1), <inline-formula id="ieqn-34"><alternatives><inline-graphic xlink:href="ieqn-34.png"/><tex-math id="tex-ieqn-34"><![CDATA[$\textrm{hiddenKeyBroadcast}= \textrm{signature}\oplus \textrm{Kb}$]]></tex-math><mml:math id="mml-ieqn-34"><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">hiddenKeyBroadcast</mml:mtext></mml:mstyle><mml:mo>=</mml:mo><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">signature</mml:mtext></mml:mstyle><mml:mo>&#x2295;</mml:mo><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">Kb</mml:mtext></mml:mstyle></mml:math></alternatives></inline-formula>, <inline-formula id="ieqn-35"><alternatives><inline-graphic xlink:href="ieqn-35.png"/><tex-math id="tex-ieqn-35"><![CDATA[$\textrm{otp2}= \textrm{HOTP}$]]></tex-math><mml:math id="mml-ieqn-35"><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">otp2</mml:mtext></mml:mstyle><mml:mo>=</mml:mo><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">HOTP</mml:mtext></mml:mstyle></mml:math></alternatives></inline-formula> (Ku, hiddenKeyBroadcast)].</p>
<p>The CPAN sends the device an association response that contains otp2 and hiddenKeyBroadcast. The device in turn computes Ku, signature, Kb and otp2&#x2019; [<inline-formula id="ieqn-36"><alternatives><inline-graphic xlink:href="ieqn-36.png"/><tex-math id="tex-ieqn-36"><![CDATA[$\textrm{Ku}= \textrm{PRF}$]]></tex-math><mml:math id="mml-ieqn-36"><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">Ku</mml:mtext></mml:mstyle><mml:mo>=</mml:mo><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">PRF</mml:mtext></mml:mstyle></mml:math></alternatives></inline-formula> (Kd, challenge), <inline-formula id="ieqn-37"><alternatives><inline-graphic xlink:href="ieqn-37.png"/><tex-math id="tex-ieqn-37"><![CDATA[$\textrm{signature}= \textrm{HMAC}$]]></tex-math><mml:math id="mml-ieqn-37"><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">signature</mml:mtext></mml:mstyle><mml:mo>=</mml:mo><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">HMAC</mml:mtext></mml:mstyle></mml:math></alternatives></inline-formula> (Ku, otp1), <inline-formula id="ieqn-38"><alternatives><inline-graphic xlink:href="ieqn-38.png"/><tex-math id="tex-ieqn-38"><![CDATA[$\textrm{Kb}= \textrm{signature}\oplus \textrm{hiddenKeyBroadcast}$]]></tex-math><mml:math id="mml-ieqn-38"><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">Kb</mml:mtext></mml:mstyle><mml:mo>=</mml:mo><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">signature</mml:mtext></mml:mstyle><mml:mo>&#x2295;</mml:mo><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">hiddenKeyBroadcast</mml:mtext></mml:mstyle></mml:math></alternatives></inline-formula>, <inline-formula id="ieqn-39"><alternatives><inline-graphic xlink:href="ieqn-39.png"/><tex-math id="tex-ieqn-39"><![CDATA[$\textrm{otp2'}= \textrm{HOTP}$]]></tex-math><mml:math id="mml-ieqn-39"><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">otp2&#x2019;</mml:mtext></mml:mstyle><mml:mo>=</mml:mo><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">HOTP</mml:mtext></mml:mstyle></mml:math></alternatives></inline-formula> (Ku, hiddenKeyBroadcast)]. If the computed otp2&#x2019; equals the received otp2, the CPAN is authenticated successfully, a mutual authentication is successful, and a secured channel is created. Otherwise, the CPAN authentication fails and the association operation stops.</p>
<p><xref ref-type="fig" rid="fig-3">Fig. 3</xref> also demonstrates how an attacker can leverage the blacklisting mechanism to blacklist the UI of innocent legitimate devices; where an attacker sends the CPAN an association request that contains the spoofed UI of device a2, then receives an authentication request from the CPAN that contains a challenge. Upon computing otp1 using an incorrect Kd [<inline-formula id="ieqn-40"><alternatives><inline-graphic xlink:href="ieqn-40.png"/><tex-math id="tex-ieqn-40"><![CDATA[$\textrm{otp1}= \textrm{HOTP}$]]></tex-math><mml:math id="mml-ieqn-40"><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">otp1</mml:mtext></mml:mstyle><mml:mo>=</mml:mo><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">HOTP</mml:mtext></mml:mstyle></mml:math></alternatives></inline-formula> (Kd, challenge)] and sending it to the CPAN as an authentication response, the CPAN compares it to the computed otp1&#x2019;, which will turn to be different, causing device authentication failure. The CPAN then will either blacklist the UI of device a2 if its association_req_count is equal to the association_req_max, or increment the device&#x2019;s association_req_count, then the association operation stops. This UI-based blacklisting mechanism is a weakness in BCTrust 27, as an attacker can repeat the illustrated process causing innocent devices to be blacklisted in the network.</p>
<fig id="fig-3">
<label>Figure 3</label> 
<caption>
<title>Associating a device to a CPAN</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="fig-3.png"/>
</fig>
<p>As opposed to what is illustrated in <xref ref-type="fig" rid="fig-3">Fig. 3</xref>, where the blacklisting mechanism that is based on blacklisting devices&#x2019; UI can be leveraged by attackers to cause legitimate devices to be blacklisted, eliminating this mechanism from the protocol would prevent the occurrence of such attacks. <xref ref-type="fig" rid="fig-4">Fig. 4</xref> illustrates how the protocol would operate after eliminating the blacklisting mechanism.</p>
<fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>Eliminating the blacklisting mechanism in associating a device to a CPAN</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="fig-4.png"/>
</fig>
</sec>
<sec id="s3_5">
<label>3.5</label>
<title>Authenticated Encryption and Decryption</title>
<p>Now that the IIoT devices are associated to the CPANs and each IIoT node has the Ku and Kb, both IIoT nodes and CPANs can encrypt and decrypt their packets. The encryption and decryption functions are the authenticated encryption/decryption functions in AES-GCM, which are adopted in BCTrust [<xref ref-type="bibr" rid="ref-24">24</xref>].</p>
<p><xref ref-type="fig" rid="fig-5">Fig. 5</xref> shows a sequence diagram that illustrates how an IIoT device can encrypt data (P) and send them to the CPAN as n blocks of ciphertext (C) concatenated with a tag (T). Firstly, the device generates an IV based on its key (K), Ku if the packet is to be sent to the CPAN and a Kb if the packet is to be sent to all the nodes in the cluster, and a counter. After that, the device uses an additional authenticated data (A) that is preconfigured and known for both sides. The device then computes H by encrypting 128 zeros with the K. After that, it set a counter (Y) that is initialized to the value of the IV concatenated with 31 zeros and a1. The counter keeps incrementing until it reaches (n), the number of plaintext blocks to be encrypted. These blocks are encrypted by computing the Exclusive OR of their values along with the counter Y after it is encrypted by K. Lastly, a tag is generated and concatenated with the C to be sent to the CPAN. The tag is computed as follows: <inline-formula id="ieqn-41"><alternatives><inline-graphic xlink:href="ieqn-41.png"/><tex-math id="tex-ieqn-41"><![CDATA[$\textrm{T}= \textrm{MSBt}$]]></tex-math><mml:math id="mml-ieqn-41"><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">T</mml:mtext></mml:mstyle><mml:mo>=</mml:mo><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">MSBt</mml:mtext></mml:mstyle></mml:math></alternatives></inline-formula> <inline-formula id="ieqn-42"><alternatives><inline-graphic xlink:href="ieqn-42.png"/><tex-math id="tex-ieqn-42"><![CDATA[$(\textrm{GHASH}(\textrm{H},~\textrm{A},~\textrm{C},~\textrm{len(A)},~\textrm{len}(\textrm{C})) \oplus \textrm{E}(\textrm{K}, \textrm{Y0}))$]]></tex-math><mml:math id="mml-ieqn-42"><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">GHASH</mml:mtext></mml:mstyle><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">H</mml:mtext></mml:mstyle><mml:mo>,</mml:mo><mml:mspace width=".3em" /><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">A</mml:mtext></mml:mstyle><mml:mo>,</mml:mo><mml:mspace width=".3em" /><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">C</mml:mtext></mml:mstyle><mml:mo>,</mml:mo><mml:mspace width=".3em" /><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">len(A)</mml:mtext></mml:mstyle><mml:mo>,</mml:mo><mml:mspace width=".3em" /><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">len</mml:mtext></mml:mstyle><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">C</mml:mtext></mml:mstyle></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2295;</mml:mo><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">E</mml:mtext></mml:mstyle><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">K</mml:mtext></mml:mstyle><mml:mo>,</mml:mo><mml:mstyle class="text"><mml:mtext class="textrm" mathvariant="normal">Y0</mml:mtext></mml:mstyle></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:math></alternatives></inline-formula>, where MSBt refers to taking the left t bits of the result.</p>
<fig id="fig-5">
<label>Figure 5</label>
<caption>
<title>Authenticated encryption and decryption [<xref ref-type="bibr" rid="ref-27">27</xref>]</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="fig-5.png"/>
</fig>
<p>The same process is to be done on the CPAN side, however, the order is different where the CPAN has to compute the tag and compare it with the received one, if they are matched, then it decrypts the packet by computing the Exclusive OR of their values along with the counter Y after it is encrypted by K. Otherwise, it drops the received packets.</p>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Simulation Work</title>
<sec id="s4_1">
<label>4.1</label>
<title>Simulation Architecture</title>
<p>Authenblue protocol consists of different types of devices and goes through multiple phases, <xref ref-type="fig" rid="fig-6">Fig. 6</xref> summarizes Authenblue general architecture. The main phases that need to be simulated are the association request and response, and the authentication request and response. To simulate these phases, the simulation environment must be fully prepared. Moreover, the functions to be used in these phases must be finalized and programmed.</p>
<fig id="fig-6">
<label>Figure 6</label>
<caption>
<title>The general architecture of Authenblue</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="fig-6.png"/>
</fig>
<p>This section covers the work done on NS3 simulator for preparing Authenblue environment and the inception phase where a sample of keys are generated. The section also presents a comprehensive simulation of the Association Request phase. As for the rest of the phases, the used functions and values are demonstrated along with the expected simulation results.</p>
</sec>
<sec id="s4_2">
<label>4.2</label>
<title>Performance Testing</title>
<p>Performance testing has been conducted with a focus on measuring the time consumption. The test is conducted by calculating the association request packet received time. After measuring the time it takes an association request packet to be received by the CPAN, it is found that the association request phase takes 0.008536 s as shown in <xref ref-type="table" rid="table-4">Tab. 4</xref>. As for the overall time consumption, it is required to have a comprehensive simulation of Authenblue to have an estimated time.</p>
<table-wrap id="table-4">
<label>Table 4</label>
<caption>
<title>Transmission time</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Device</th>
<th>Sent time</th>
<th>Transmit time</th>
</tr>
</thead>
<tbody>
<tr>
<td>Sensor 1</td>
<td>0.0</td>
<td>0.003296</td>
</tr>
<tr>
<td>Sensor 2</td>
<td>1.0</td>
<td>0.0015</td>
</tr>
<tr>
<td>Sensor 3</td>
<td>2.0</td>
<td>0.00374</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s4_3">
<label>4.3</label>
<title>Analysis</title>
<p>After coding and simulating Authenblue, this section compares it with the solutions discussed previously in the literature review, <xref ref-type="table" rid="table-5">Tab. 5</xref> shows this comparison. The main two aspects that differentiate Authenblue than the other solutions are its management of keys.</p>
<table-wrap id="table-5">
<label>Table 5</label>
<caption>
<title>Comparing Authenblue with other solutions</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Factor</th>
<th>Description</th>
<th colspan="6">Solution</th>
<th>Authenblue</th>
</tr>
<tr>
<th></th>
<th></th>
<th>BATM</th>
<th>BCTrust</th>
<th>LX</th>
<th>TTW</th>
<th>HCK</th>
<th>IoT-Ethereum Framework</th>
<th></th>
</tr>
</thead>
<tbody>
<tr>
<td>C</td>
<td>The secrecy of the transmitted and stored data</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td><inline-formula id="ieqn-43"><alternatives><inline-graphic xlink:href="ieqn-43.png"/><tex-math id="tex-ieqn-43"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-43"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td>&#x2713;</td>
</tr>
<tr>
<td>I</td>
<td>The accuracy and non-alteration of the transmitted and stored data</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td><inline-formula id="ieqn-44"><alternatives><inline-graphic xlink:href="ieqn-44.png"/><tex-math id="tex-ieqn-44"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-44"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td>&#x2713;</td>
</tr>
<tr>
<td>A</td>
<td>The timely service and information accessibility for IoT devices</td>
<td><inline-formula id="ieqn-45"><alternatives><inline-graphic xlink:href="ieqn-45.png"/><tex-math id="tex-ieqn-45"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-45"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td>&#x2713;</td>
<td><inline-formula id="ieqn-46"><alternatives><inline-graphic xlink:href="ieqn-46.png"/><tex-math id="tex-ieqn-46"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-46"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td><inline-formula id="ieqn-47"><alternatives><inline-graphic xlink:href="ieqn-47.png"/><tex-math id="tex-ieqn-47"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-47"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td><inline-formula id="ieqn-48"><alternatives><inline-graphic xlink:href="ieqn-48.png"/><tex-math id="tex-ieqn-48"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-48"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td>&#x2713;</td>
<td>&#x2713;</td>
</tr>
<tr>
<td>AN</td>
<td>The verification of IoT device&#x2019;s identity</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
</tr>
<tr>
<td>AR</td>
<td>The granting of privileges to the authorized IoT device</td>
<td><inline-formula id="ieqn-49"><alternatives><inline-graphic xlink:href="ieqn-49.png"/><tex-math id="tex-ieqn-49"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-49"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td>&#x2713;</td>
<td><inline-formula id="ieqn-50"><alternatives><inline-graphic xlink:href="ieqn-50.png"/><tex-math id="tex-ieqn-50"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-50"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td><inline-formula id="ieqn-51"><alternatives><inline-graphic xlink:href="ieqn-51.png"/><tex-math id="tex-ieqn-51"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-51"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td><inline-formula id="ieqn-52"><alternatives><inline-graphic xlink:href="ieqn-52.png"/><tex-math id="tex-ieqn-52"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-52"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td>&#x2713;</td>
<td>&#x2713;</td>
</tr>
<tr>
<td>NR</td>
<td>The protection against deniability of actions</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
</tr>
<tr>
<td>RC</td>
<td>The consumption of IoT devices&#x2019; resources is within an acceptable range</td>
<td>&#x2713;</td>
<td>&#x2713;</td>
<td><inline-formula id="ieqn-53"><alternatives><inline-graphic xlink:href="ieqn-53.png"/><tex-math id="tex-ieqn-53"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-53"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td>&#x2713;</td>
<td><inline-formula id="ieqn-54"><alternatives><inline-graphic xlink:href="ieqn-54.png"/><tex-math id="tex-ieqn-54"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-54"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td>&#x2713;</td>
<td>&#x2713;</td>
</tr>
<tr>
<td>KM</td>
<td>The use of an efficient key management mechanism</td>
<td>&#x2713;</td>
<td><inline-formula id="ieqn-55"><alternatives><inline-graphic xlink:href="ieqn-55.png"/><tex-math id="tex-ieqn-55"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-55"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td><inline-formula id="ieqn-56"><alternatives><inline-graphic xlink:href="ieqn-56.png"/><tex-math id="tex-ieqn-56"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-56"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td><inline-formula id="ieqn-57"><alternatives><inline-graphic xlink:href="ieqn-57.png"/><tex-math id="tex-ieqn-57"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-57"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td>&#x2713;</td>
<td><inline-formula id="ieqn-58"><alternatives><inline-graphic xlink:href="ieqn-58.png"/><tex-math id="tex-ieqn-58"><![CDATA[$\times$]]></tex-math><mml:math id="mml-ieqn-58"><mml:mo>&#x00D7;</mml:mo></mml:math></alternatives></inline-formula></td>
<td>&#x2713;</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>The <xref ref-type="table" rid="table-3">Tab. 3</xref> shows how Authenblue has an efficient key management mechanism. This is due to the way of generating the unique identifiers (UI) of the sensors. In Authenblue, UIs are generated based on a random generator to produce a 128-bit length. Unlike the static value which was presented in BCTrust solution. This makes it easier for renewing the identifiers and the secret keys of the sensors themselves.</p>
</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>Conclusion</title>
<p>This paper covered the blockchain based solutions on IoT security, especially the security in IoT communications, the utilization of blockchain for trust management and authentication in the IoT field, and the utilization of blockchain for controlling IoT devices.</p>
<p>Additionally, several solutions regarding the IoT security were compared and analyzed, with the conclusion that working on the enhancements of BCTrust mechanism would lead to having a powerful blockchain-based identity authentication system for managing. We proposed a new authentication protocol named Authenblue that helps in the authentication process of sensors, IIoT nodes, and coordinators in an IIoT environment. It is a security solution that aims to enhance the authentication process in san IIoT environment, by assisting in the mitigation of the occurrence of some cyber-attacks. Authenblue enhance the authentication protocol that BCTrust and other models rely on by enhancing the way of generating the UIs. The unique identifiers (UI) values changed from being static values, sensors MAC addresses, to be generated values in the inception phase. Such modification is crucial for the key managed process. It makes the process of renewing the sensor keys more efficient by renewing their UI values instead of changing the secret key of the CPAN. Furthermore, this paper has simulated parts of the protocol through NS3. Such simulation contributes to the present NS3 authentication models. The simulation result show that Authenblue has an efficient key management mechanism. This is due to the way of generating the UI of the sensors. In Authenblue, UIs are generated based on a random generator to produce a 128-bit length. Unlike the static value which was presented in BCTrust solution. This makes it easier for renewing the identifiers and the secret keys of the sensors themselves.</p>
</sec>
</body>
<back>
<fn-group><fn fn-type="other"><p><bold>Funding Statement:</bold> The author(s) received no specific funding for this study.</p></fn>
<fn fn-type="conflict"><p><bold>Conflicts of Interest:</bold> The authors declare that they have no conflicts of interest to report regarding the present study.</p></fn></fn-group>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>B.</given-names> <surname>Marsh</surname></string-name> and <string-name><given-names>P.</given-names> <surname>Piscioneri</surname></string-name></person-group>, &#x201C;<article-title>The Internet of Postal Things</article-title>,&#x201D; in <conf-name>Proc. Int. Conf. on Collaboration Technologies and Systems</conf-name>, Atlanta, USA, pp. <fpage>3</fpage>&#x2013;<lpage>4</lpage>, <year>2015</year>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>R.</given-names> <surname>Alhajri</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Zagrouba</surname></string-name> and <string-name><given-names>F.</given-names> <surname>Alhaidari</surname></string-name></person-group>, &#x201C;<article-title>Survey for anomaly detection of IoT botnets using machine learning auto-encoders</article-title>,&#x201D; <source>International Journal of Applied Engineering Research</source>, vol. <volume>14</volume>, no. <issue>10</issue>, pp. <fpage>2417</fpage>&#x2013;<lpage>2242</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Kardi</surname></string-name> and <string-name><given-names>R.</given-names> <surname>Zagrouba</surname></string-name></person-group>, &#x201C;<article-title>Attacks classification and security mechanisms in wireless sensor networks Advances in Science</article-title>,&#x201D; <source>Technology and Engineering Systems Journal</source>, vol. <volume>4</volume>, no. <issue>6</issue>, pp. <fpage>229</fpage>&#x2013;<lpage>243</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Jha</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Nkenyereye</surname></string-name>, <string-name><given-names>G.</given-names> <surname>Prasad Joshi</surname></string-name> and <string-name><given-names>E.</given-names> <surname>Yang</surname></string-name></person-group>, &#x201C;<article-title>Mitigating and monitoring smart city using Internet of Things</article-title>,&#x201D; <source>Computers, Materials &#x0026; Continua</source>, vol. <volume>65</volume>, no. <issue>2</issue>, pp. <fpage>1059</fpage>&#x2013;<lpage>1079</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Abbas</surname></string-name>, <string-name><given-names>M. A.</given-names> <surname>Khan</surname></string-name>, <string-name><given-names>L. E.</given-names> <surname>Falcon-Morales</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Rehman</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Saeed</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>Modelling, simulation and optimization of power plan energy sustainability for IoT enabled smart cities empowered with deep extreme leaning machine</article-title>,&#x201D; <source>IEEE ACCESS</source>, vol. <volume>8</volume>, no. <issue>1</issue>, pp. <fpage>39982</fpage>&#x2013;<lpage>39997</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Ata</surname></string-name>, <string-name><given-names>M. A.</given-names> <surname>Khan</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Abbas</surname></string-name>, <string-name><given-names>M. S.</given-names> <surname>Khan</surname></string-name> and <string-name><given-names>G.</given-names> <surname>Ahmad</surname></string-name></person-group>, &#x201C;<article-title>Adaptive IoT empowered smart road traffic congestion control system using supervised machine learning algorithm</article-title>,&#x201D; <source> Computer Journal</source>, vol. <volume>3</volume>, pp. <fpage>1</fpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>U.</given-names> <surname>Javaid</surname></string-name>, <string-name><given-names>A. K.</given-names> <surname>Siang</surname></string-name>, <string-name><given-names>M. N.</given-names> <surname>Aman</surname></string-name> and <string-name><given-names>B.</given-names> <surname>Sikdar</surname></string-name></person-group>, &#x201C;<article-title>Mitigating IoT device based DDoS attacks using blockchain</article-title>,&#x201D; in <conf-name>Proc. 1st Workshop on Cryptocurrencies and Blockchains for Distributed Systems</conf-name>, Munich, Germany, pp. <fpage>71</fpage>&#x2013;<lpage>76</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>P. Y.</given-names> <surname>Ting</surname></string-name>, <string-name><given-names>J. L.</given-names> <surname>Tsai</surname></string-name> and <string-name><given-names>T. S.</given-names> <surname>Wu</surname></string-name></person-group>, &#x201C;<article-title>Signcryption method suitable for low-power IoT devices in a wireless sensor network</article-title>,&#x201D; <source>IEEE Systems Journal</source>, vol. <volume>12</volume>, no. <issue>3</issue>, pp. <fpage>2385</fpage>&#x2013;<lpage>2394</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Moinet</surname></string-name>, <string-name><given-names>B.</given-names> <surname>Darties</surname></string-name> and <string-name><given-names>J. L.</given-names> <surname>Baril</surname></string-name></person-group>, &#x201C;<article-title>Blockchain based trust &#x0026; authentication for decentralized sensor networks</article-title>,&#x201D; vol. <volume>1</volume>, pp. <fpage>1</fpage>&#x2013;<lpage>6</lpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Sohail</surname></string-name>, <string-name><given-names>M. A.</given-names> <surname>Khan</surname></string-name>, <string-name><given-names>I.</given-names> <surname>Ahmad</surname></string-name> and <string-name><given-names>O.</given-names> <surname>Sohail</surname></string-name></person-group>, &#x201C;<article-title>Intelligent data encryption scheme for light weighted AIoT enabled devices</article-title>,&#x201D; <source>Journal of Information Assurance and Security</source>, vol. <volume>15</volume>, no. <issue>1</issue>,  pp. <fpage>17</fpage>&#x2013;<lpage>25</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Afzal</surname></string-name>, <string-name><given-names>M. A.</given-names> <surname>Khan</surname></string-name> and <string-name><given-names>S.</given-names> <surname>Abbas</surname></string-name></person-group>, &#x201C;<article-title>Secure communication of IoT based devices using EPEB algorithm</article-title>,&#x201D; <source>Journal of Information Assurance and Security</source>, vol. <volume>13</volume>, no. <issue>3</issue>, pp. <fpage>91</fpage>&#x2013;<lpage>97</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>F.</given-names> <surname>Alhaidari</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Rahman</surname></string-name> and <string-name><given-names>R.</given-names> <surname>Zagrouba</surname></string-name></person-group>, &#x201C;<article-title>Cloud of things: Architecture, applications and challenges</article-title>,&#x201D; <source>Journal of Ambient Intelligence and Humanized Computing</source>, vol. <volume>3</volume>, no. <issue>6</issue>, pp. <fpage>1099</fpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>H.</given-names> <surname>Atlam</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Alenezi</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Alassafi</surname></string-name> and <string-name><given-names>G.</given-names> <surname>Wills</surname></string-name></person-group>, &#x201C;<article-title>Blockchain with Internet of Things: Benefits, challenges, and future directions</article-title>,&#x201D; <source>International Journal of Intelligent Systems and Applications</source>, vol. <volume>10</volume>, no. <issue>6</issue>, pp. <fpage>40</fpage>&#x2013;<lpage>48</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>G.</given-names> <surname>Karame</surname></string-name> and <string-name><given-names>S.</given-names> <surname>Capkun</surname></string-name></person-group>, &#x201C;<article-title>Blockchain security and privacy</article-title>,&#x201D; <source>IEEE Security &#x0026; Privacy</source>, vol. <volume>16</volume>, no. <issue>4</issue>, pp. <fpage>11</fpage>&#x2013;<lpage>12</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M. T.</given-names> <surname>Hammi</surname></string-name>, <string-name><given-names>B.</given-names> <surname>Hammi</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Bellot</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Serhrouchni</surname></string-name></person-group>, &#x201C;<article-title>Bubbles of trust: A decentralized blockchain-based authentication system for IoT</article-title>,&#x201D; <source>Computers &#x0026; Security</source>, vol. <volume>78</volume>, pp. <fpage>126</fpage>&#x2013;<lpage>142</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Shen</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>T.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Huang</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>Secure data uploading scheme for a smart home system</article-title>,&#x201D; <source>Information Sciences</source>, vol. <volume>453</volume>, pp. <fpage>186</fpage>&#x2013;<lpage>197</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Maqsood</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Rahman</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Malrey</surname></string-name> and <string-name><given-names>J. Y.</given-names> <surname>Choi</surname></string-name></person-group>, &#x201C;<article-title>Evolutionary-based image encryption using RNA codons truth table</article-title>,&#x201D; <source>Optics &#x0026; Laser Technology</source>, vol. <volume>121</volume>, pp. <fpage>105818</fpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>F. H.</given-names> <surname>Al-Naji</surname></string-name> and <string-name><given-names>R.</given-names> <surname>Zagrouba</surname></string-name></person-group>, &#x201C;<article-title>A survey on continuous authentication methods in Internet of Things environment</article-title>,&#x201D; <source>Computer Communications Journal</source>, vol. <volume>163</volume>, pp. <fpage>109</fpage>&#x2013;<lpage>133</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Huh</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Cho</surname></string-name> and <string-name><given-names>S.</given-names> <surname>Kim</surname></string-name></person-group>, &#x201C;<article-title>Managing IoT devices using blockchain platform</article-title>,&#x201D; in <conf-name>Proc. 19th Int. Conf. on Advanced Communication Technology</conf-name>, Bongpyeong, pp. <fpage>464</fpage>&#x2013;<lpage>467</lpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M. A.</given-names> <surname>Khan</surname></string-name> and <string-name><given-names>K.</given-names> <surname>Salah</surname></string-name></person-group>, &#x201C;<article-title>IoT security: Review, blockchain solutions, and open challenges</article-title>,&#x201D; <source>Future Generation Computer Systems</source>, vol. <volume>82</volume>, pp. <fpage>395</fpage>&#x2013;<lpage>411</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>F. H.</given-names> <surname>Al-Naji</surname></string-name> and <string-name><given-names>R.</given-names> <surname>Zagrouba</surname></string-name></person-group>, &#x201C;<article-title>Secure IoT based on blockchain: Quantitative evaluation and analysis of the correlation between block mining time and blockchain efficiency</article-title>,&#x201D; <source>International Journal of Applied Engineering Research</source>, vol. <volume>15</volume>, no. <issue>4</issue>, pp. <fpage>377</fpage>&#x2013;<lpage>384</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>R.</given-names> <surname>Zagrouba</surname></string-name></person-group>, &#x201C;<article-title>AMIS: Authentication mechanism for IoT security</article-title>,&#x201D; <source>ACTA Scientific Computer Sciences</source>, vol. <volume>2</volume>, no. <issue>7</issue>, pp. <fpage>32</fpage>&#x2013;<lpage>37</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Kardi</surname></string-name> and <string-name><given-names>R.</given-names> <surname>Zagrouba</surname></string-name></person-group>, &#x201C;<article-title>Attacks classification and security mechanisms in wireless sensor networks, Advances in Science</article-title>,&#x201D; <source>Technology and Engineering Systems Journal</source>, vol. <volume>4</volume>, no. <issue>6</issue>,  pp. <fpage>229</fpage>&#x2013;<lpage>243</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>F.</given-names> <surname>Li</surname></string-name> and <string-name><given-names>P.</given-names> <surname>Xiong</surname></string-name></person-group>, &#x201C;<article-title>Practical secure communication for integrating wireless sensor networks into the internet of things</article-title>,&#x201D; <source>IEEE Sensors Journal</source>, vol. <volume>13</volume>, no. <issue>10</issue>, pp. <fpage>3677</fpage>&#x2013;<lpage>3684</lpage>, <year>2013</year>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Masdari</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Jabbehdari</surname></string-name> and <string-name><given-names>J.</given-names> <surname>Bagherzadeh</surname></string-name></person-group>, &#x201C;<article-title>Improving OCSP-based certificate validations in wireless ad hoc networks</article-title>,&#x201D; <source>Wireless Personal Communications</source>, vol. <volume>82</volume>, no. <issue>1</issue>, pp. <fpage>377</fpage>&#x2013;<lpage>400</lpage>, <year>2015</year>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Al-Mousa</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Al-Qomri</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Al-Hajri</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Zagrouba</surname></string-name> and <string-name><given-names>S.</given-names> <surname>Chaabani</surname></string-name></person-group>, &#x201C;<article-title>Environment based IoT security risks and vulnerabilities management</article-title>,&#x201D; in <conf-name>Proc. IEEE 2020 Int. Conf. on Computing and Information Technology</conf-name>, Al-Jouf, KSA, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>M. T.</given-names> <surname>Hammi</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Bellot</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Serhrouchni</surname></string-name></person-group>, &#x201C;<article-title>BCTrust: A decentralized authentication blockchain-based mechanism</article-title>,&#x201D; in <conf-name>Proc. IEEE Wireless Communications and Networking Conf.</conf-name>, Barcelona, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>L. H.</given-names> <surname>Nunes</surname></string-name>, <string-name><given-names>L. H. V.</given-names> <surname>Nakamura</surname></string-name>, <string-name><given-names>H. F.</given-names> <surname>Vieira</surname></string-name>, <string-name><given-names>R. M. O.</given-names> <surname>Libardi</surname></string-name>, <string-name><given-names>E. M.</given-names> <surname>Olivera</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>Performance and energy evaluation of RESTful web services in Raspberry Pi</article-title>,&#x201D; in <conf-name>Proc. IEEE 33rd Int. Performance Computing and Communications Conf.</conf-name>, Austin, TX, pp. <fpage>1</fpage>&#x2013;<lpage>9</lpage>, <year>2014</year>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>H. A.</given-names> <surname>Moniem</surname></string-name> and <string-name><given-names>H. H.</given-names> <surname>Ammar</surname></string-name></person-group>, &#x201C;<article-title>Performance prediction of service-oriented architecture, a survey</article-title>,&#x201D; <source>International Journal of Computer Applications Technology and Research</source>, vol. <volume>3</volume>, no. <issue>12</issue>, pp. <fpage>831</fpage>&#x2013;<lpage>835</lpage>, <year>2014</year>.</mixed-citation></ref>
</ref-list>
</back>
</article>