<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMC</journal-id>
<journal-id journal-id-type="nlm-ta">CMC</journal-id>
<journal-id journal-id-type="publisher-id">CMC</journal-id>
<journal-title-group>
<journal-title>Computers, Materials &#x0026; Continua</journal-title>
</journal-title-group>
<issn pub-type="epub">1546-2226</issn>
<issn pub-type="ppub">1546-2218</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">20774</article-id>
<article-id pub-id-type="doi">10.32604/cmc.2022.020774</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>A Secure Key Agreement Scheme for Unmanned Aerial Vehicles-Based Crowd Monitoring System</article-title>
<alt-title alt-title-type="left-running-head">A Secure Key Agreement Scheme for Unmanned Aerial Vehicles-Based Crowd Monitoring System</alt-title>
<alt-title alt-title-type="right-running-head">A Secure Key Agreement Scheme for Unmanned Aerial Vehicles-Based Crowd Monitoring System</alt-title>
</title-group>
<contrib-group content-type="authors">
<contrib id="author-1" contrib-type="author">
<name name-style="western"><surname>Alzahrani</surname><given-names>Bander</given-names></name>
<xref ref-type="aff" rid="aff-1">1</xref>
</contrib>
<contrib id="author-2" contrib-type="author">
<name name-style="western"><surname>Barnawi</surname><given-names>Ahmed</given-names></name>
<xref ref-type="aff" rid="aff-1">1</xref>
</contrib>
<contrib id="author-3" contrib-type="author">
<name name-style="western"><surname>Irshad</surname><given-names>Azeem</given-names></name>
<xref ref-type="aff" rid="aff-2">2</xref>
</contrib>
<contrib id="author-4" contrib-type="author">
<name name-style="western"><surname>Alhothali</surname><given-names>Areej</given-names></name>
<xref ref-type="aff" rid="aff-1">1</xref>
</contrib>
<contrib id="author-5" contrib-type="author">
<name name-style="western"><surname>Alotaibi</surname><given-names>Reem</given-names></name>
<xref ref-type="aff" rid="aff-1">1</xref>
</contrib>
<contrib id="author-6" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Shafiq</surname><given-names>Muhammad</given-names></name>
<xref ref-type="aff" rid="aff-3">3</xref>
<email>shafiq@ynu.ac.kr</email>
</contrib>
<aff id="aff-1"><label>1</label><institution>Faculty of Computing and Information Technology, King Abdulaziz University</institution>, <addr-line>Jeddah</addr-line>, <country>Saudi Arabia</country></aff>
<aff id="aff-2"><label>2</label><institution>Department of Computer Science and Software Engineering, International Islamic University Islamabad</institution>, <country>Pakistan</country></aff>
<aff id="aff-3"><label>3</label><institution>Department of Information and Communication Engineering, Yeungnam University</institution>, <addr-line>Gyeongsan, 38541</addr-line>, <country>Korea</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Muhammad Shafiq. Email: <email>shafiq@ynu.ac.kr</email></corresp>
</author-notes>
<pub-date pub-type="epub" date-type="pub" iso-8601-date="2021-10-02"><day>2</day><month>10</month><year>2021</year>
</pub-date>
<volume>70</volume>
<issue>3</issue>
<fpage>6141</fpage>
<lpage>6158</lpage>
<history>
<date date-type="received"><day>07</day><month>6</month><year>2021</year></date>
<date date-type="accepted"><day>16</day><month>8</month><year>2021</year></date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2022 Alzahrani et al.</copyright-statement>
<copyright-year>2022</copyright-year>
<copyright-holder>Alzahrani et al.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMC_20774.pdf"></self-uri>
<abstract>
<p>Unmanned aerial vehicles (UAVs) have recently attracted widespread attention in civil and commercial applications. For example, UAVs (or drone) technology is increasingly used in crowd monitoring solutions due to its wider air footprint and the ability to capture data in real time. However, due to the open atmosphere, drones can easily be lost or captured by attackers when reporting information to the crowd management center. In addition, the attackers may initiate malicious detection to disrupt the crowd-sensing communication network. Therefore, security and privacy are one of the most significant challenges faced by drones or the Internet of Drones (IoD) that supports the Internet of Things (IoT). In the literature, we can find some authenticated key agreement (AKA) schemes to protect access control between entities involved in the IoD environment. However, the AKA scheme involves many vulnerabilities in terms of security and privacy. In this paper, we propose an enhanced AKA solution for crowd monitoring applications that require secure communication between drones and controlling entities. Our scheme supports key security features, including anti-forgery attacks, and confirms user privacy. The security characteristics of our scheme are analyzed by NS2 simulation and verified by a random oracle model. Our simulation results and proofs show that the proposed scheme sufficiently guarantees the security of crowd-aware communication.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>IoT</kwd>
<kwd>unmanned aerial vehicles</kwd>
<kwd>authentication</kwd>
<kwd>crowd monitoring</kwd>
</kwd-group>
</article-meta>
</front>
<body>
<sec id="s1"><label>1</label><title>Introduction</title>
<p>Crowding usually occurs in major occasions, such as international games and sports competitions, cultural festivals, concerts, religious gatherings, etc. We cannot ignore the possibility of accidents in large gatherings, such as the Hajj 2006 or Love Parade 2010 in Germany, and the Kumbh Mela stampede reported in 2013 in the past few years [<xref ref-type="bibr" rid="ref-1">1</xref>,<xref ref-type="bibr" rid="ref-2">2</xref>]. The demand for crowd management solutions in urban metropolises is also becoming more and more common. Such gatherings always have risks, so precautions need to be taken in advance to ensure public safety. In addition, it is also important to use technology to identify anti-social and atypical behaviors in the population, and to distinguish these factors in order to take preventive measures to enhance public safety and security. Recently, the pandemic riot phenomenon needs to perceive crowd behavior without involving human factors, and further requires technological innovation to deal with it. In order to ensure public safety, the administrator or event manager must foresee and check the indicators of real-time data captured from the crowded terrain, and finally make timely decisions to curb unforeseen situations.</p>
<p>In the follow-up of major catastrophic situations such as floods, earthquakes, fire outbreaks, and rescue operations, Unmanned Aerial Vehicles (UAVs) are the first responders. According to observations, surveillance is one of the emerging fields, which has expanded the application range of UAVs (or drones). The sensors in drones help these devices effortlessly expand the scope of mission execution, so they are very suitable for surveillance-based rescue and monitoring operations [<xref ref-type="bibr" rid="ref-3">3</xref>,<xref ref-type="bibr" rid="ref-4">4</xref>]. The drone can focus on their target location and can easily provide the control team with key information about what is happening at that location. The economy of its use and the technological improvement of drones make these devices a strong competitor to improve the safety of surveillance and crowd monitoring operations.</p>
<p>UAVs can help police officers ensure the security and safety of large cities, because these devices can be introduced in real time to collect real-time updates on various actions on the spot. For example, police officers in the United Kingdom use drones to catch suspected robbers [<xref ref-type="bibr" rid="ref-5">5</xref>]. However, it becomes very challenging to manage the efficiency and effectiveness of such monitoring systems in cities. Other agencies such as the US Congress and the US Department of Justice have allowed the use of drones to manage large-scale events in large cities [<xref ref-type="bibr" rid="ref-6">6</xref>]. The combination of drones with multimedia streaming, safe wireless interaction, forensic applications, video detection technology for abnormal motion [<xref ref-type="bibr" rid="ref-7">7</xref>], and video recognition of human abnormal behavior [<xref ref-type="bibr" rid="ref-8">8</xref>] may help to achieve a peaceful living place.</p>
<p>Nevertheless, this development of drone network technology exposes new ways of cyber threats, such as eavesdropping, privacy, forgery, and data reconciliation issues, which makes crowd management very challenging. If any malicious adversary accesses surveillance-related data, it may disrupt the entire surveillance activity. If any legal mobile user wants to access the data collected by a specific drone introduced in the flight area, this must be possible in the follow-up process of the mutual authentication process, leading to an agreed session key. The gateway is a trusted entity that cannot be hacked by opponents, and the mobile user&#x0027;s equipment and drones may be physically compromised. Therefore, designing a secure and lightweight authentication key agreement is essential for the Internet of Drones (IoD) architecture to overcome the above shortcomings.</p>
<p>The salient features of the contribution are as follows:
<list list-type="bullet">
<list-item><p>We propose a secure key agreement scheme for UAVs-based crowd sensing system. In the proposed scheme, police or intelligence personnel can safely obtain the real-time status of crowd dynamics with mobile devices by using crowd-sensing drones. These drones are used to report the perceived crowd information to the mobile user/police officer (CMD<sub>i</sub>) through the reliable registration agency GRS<sub>j</sub> after adopting an appropriate authentication process and using a mutually shared session key. However, this communication must be carried out between legitimate members after using a successful authentication procedure and establishing a mutually agreed session key</p></list-item>
<list-item><p>We have verified the session key security of the proposed scheme using the ROR (Real-Or-Random) trusted model [<xref ref-type="bibr" rid="ref-9">9</xref>]. In addition, an informal security analysis was conducted to prove the security function of the proposed schemes against a capable adversary.</p></list-item>
<list-item><p>We developed a simulation in NS2 to verify the efficiency of the proposed model in terms of throughput and latency benchmarks. The performance evaluation results show that the proposed scheme is sufficiently safe and efficient in computation and communication.</p></list-item>
</list></p>
<p>The rest of this article is organized as follows. Section 2 describes the related work. Section 3 explains the system model and adversary model. Section 4 demonstrates the proposed model. Section 5 analyzes the methods proposed on the formal and informal routes. Section 6 introduces the performance evaluation and comparative study of the proposed models. The conclusion is drawn in the last section.</p>
</sec>
<sec id="s2"><label>2</label><title>Related Works</title>
<p>We can find some research articles on protecting drone-based surveillance [<xref ref-type="bibr" rid="ref-10">10</xref>]. In [<xref ref-type="bibr" rid="ref-11">11</xref>], for example, the authors proposed a UAV communication scheme for rescue operations. In [<xref ref-type="bibr" rid="ref-12">12</xref>], the authors demonstrated the advantages and disadvantages of using drones to monitor the US border. In [<xref ref-type="bibr" rid="ref-13">13</xref>], the authors proposed a security method based on multi-UAV architecture to manage catastrophic scenarios. In [<xref ref-type="bibr" rid="ref-14">14</xref>], the authors discussed equipment for monitoring crowds. In [<xref ref-type="bibr" rid="ref-15">15</xref>], the hierarchical intrusion detection is designed as a lightweight detection and response method to protect drone-based networks from known attacks. Since then, the Time Credential-based Anonymous Lightweight Authentication Scheme (TCALAS) has tried to solve the problems in key protocols related to drone networks. In [<xref ref-type="bibr" rid="ref-16">16</xref>], a certificate-less group key authentication protocol for untrusted drone architecture is proposed. In [<xref ref-type="bibr" rid="ref-17">17</xref>], the authors proposed another lightweight authentication protocol for drone Internet. However, this scheme does not support mutual authentication and so lacks a secure key agreement. In [<xref ref-type="bibr" rid="ref-18">18</xref>], the authors proposed a mobile user authentication protocol for wireless sensor networks related to the Internet-of-Things (IoTs) framework, which establishes an agreed session key with sensor nodes. However, this protocol is particularly suitable for sensor nodes with insufficient resources only and so it uses minimal hash-based operations and XOR operations to support mutual authentication among sensor nodes, mobile users, and gateway server nodes. In [<xref ref-type="bibr" rid="ref-19">19</xref>], authors proved that the scheme in [<xref ref-type="bibr" rid="ref-18">18</xref>] is vulnerable because it does not support anonymity and untraceability. In addition, this solution is susceptible to forgery attacks, stolen card attacks, and man-in-the-middle attacks. In [<xref ref-type="bibr" rid="ref-20">20</xref>], authors proposed a novel and efficient signature-based authentication protocol for IoT-based architecture, in which data is accessed from IoT sensors in real time after a mutual authentication process. However, no solution can meet the goals of real-world online application scenarios to make full use of a secure drone-based crowd sensing system.</p>
</sec>
<sec id="s3"><label>3</label><title>Preliminaries</title>
<p>There is always a communication security threat between entities in the IoD environment. This requires the development of effective and efficient authentication protocols. The network model of the proposed framework is shown in <?A3B2 "fig1",5,"anchor"?><xref ref-type="fig" rid="fig-1">Fig. 1</xref>, including three participating roles, such as control room (CR), ground registration station (GRS<sub>j</sub>), mobile user (MU<sub>i</sub>), and crowd monitoring drone (CMD<sub>i</sub>). The IoD network consists of multiple flight zones with specific identifiers (FZ<sub>i</sub>), and a specific UAV is deployed to any specific FZ<sub>i</sub>, and at the same time it can fly and communicate with other GRS<sub>j</sub> and drones of the same FZ<sub>i</sub>. GRS<sub>j</sub> acts as a trusted entity and is connected to the CR endpoint. GRS<sub>j</sub> registers all mobile users and remote drones by providing long-term keys based on their identity. Mobile user MU<sub>i</sub> or police officer with smart device obtain is/her own long-term key through GRS<sub>j</sub>. The drone CMD<sub>i</sub> introduced in a specific FZ<sub>i</sub> can report to GRS<sub>j</sub> in real time after scanning and monitoring crowd-based information.</p>
<fig id="fig-1"><label>Figure 1</label><caption><title>System model</title></caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_20774-fig-1.png"/></fig>
<p>We use the Dolev-Yao (DY) threat model to assume the capabilities of malicious adversaries. Under the DY threat model, adversary<inline-formula id="ieqn-1"><mml:math id="mml-ieqn-1"><mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">A</mml:mi></mml:mrow></mml:mrow></mml:mrow></mml:math></inline-formula> can intercept, delete, modify, append or replay any eavesdropping messages exchanged on public channels. The adversary can physically capture the deployed drone in any FZ<sub>i</sub>, steal the information stored in its memory and manipulate it to achieve its malicious objectives. It may also attempt to use this information to expose secret network communications by disrupting the data exchanged between the hijacked drone and other un-compromised drones. In addition, the <inline-formula id="ieqn-2"><mml:math id="mml-ieqn-2"><mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">A</mml:mi></mml:mrow></mml:mrow></mml:mrow></mml:math></inline-formula> can also obtain smart card credentials such as identity, password, and biometric secrets by using power differential analysis attacks [<xref ref-type="bibr" rid="ref-21">21</xref>]. For the current solution, compared with the DY model, we assume another powerful threat model, namely the adversary model of Canetti and Krawczyk (also known as the CK-adversary model). Under the CK model, <inline-formula id="ieqn-3"><mml:math id="mml-ieqn-3"><mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">A</mml:mi></mml:mrow></mml:mrow></mml:mrow></mml:math></inline-formula> can physically access the credentials of a single entity by recovering its content and calculating its corresponding session key and its session state.However, a sound agreement must retain the forward and backward secrecy under the CK model in the follow-up actions of the exposed credentials. In addition, assume that GRS<sub>j</sub> is deployed in a physically protected lock system as a trusted entity in our IoD-based architecture, which is reliably protected from malicious attackers.</p>
</sec>
<sec id="s4"><label>4</label><title>Proposed Scheme</title>
<p>Our proposed scheme consists of three sub-phases, namely the network establishment phase, the MU<sub>i</sub> registration phase, the CMD<sub>i</sub> registration phase and the mutual authentication procedure. Before we proceed, we have listed a summary of the symbols used in <?A3B2 "tbl1",5,"anchor"?><xref ref-type="table" rid="table-1">Tab. 1</xref>.</p>
<sec id="s4_1"><label>4.1</label><title>Network Setup</title>
<p>In the network setting, entities in the IoD network are initialized with key secret parameters before deployment on site. First, GRS<italic><sub>j</sub> </italic>constructs its master secret key and auxiliary parameters required in the protocol, as shown in the following.
<list list-type="bullet">
<list-item><p>The GRS<sub>j</sub> selects its 160-bit master secret key <italic>K<sub>G</sub></italic> as well as bit-mask key <italic>m<sub>k</sub></italic> along with a high entropy parameter <italic>n</italic>.</p></list-item>
<list-item><p>The GRS<sub>j</sub> selects its identity <italic>ID<sub>GR</sub></italic> and calculates <italic>PID<sub>G</sub>&#x2009;&#x003D;&#x2009;h(ID<sub>GR</sub> &#x007C;&#x007C; m<sub>k</sub>)</italic>.</p></list-item>
<list-item><p>Next, GRS<sub>j</sub> stores the parameters (<italic>K<sub>G</sub></italic>, <italic>m<sub>k</sub></italic>) secretly and publicizes the vector (<italic>h, n, PID<sub>G</sub></italic>).</p></list-item>
</list></p>
<table-wrap id="table-1"><label>Table 1</label><caption><title>Summary of the notations</title></caption>

<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left">Notation</th>
<th align="left">Description</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left"><italic>MU<sub>i</sub>, CMD<sub>i</sub></italic></td>
<td align="left"><italic>i</italic>-th mobile user, <italic>i</italic>-th crowd monitoring drone</td>
</tr>
<tr>
<td align="left"><italic>GRS<sub>j</sub></italic></td>
<td align="left"><italic>j</italic>-th ground registration server, a trusted controlling authority</td>
</tr>
<tr>
<td align="left"><italic>CR</italic></td>
<td align="left">Control room</td>
</tr>
<tr>
<td align="left"><italic>ID<sub>u</sub>, PW<sub>u</sub></italic></td>
<td align="left">Identity and password of MU<sub>i</sub></td>
</tr>
<tr>
<td align="left"><italic>ID<sub>d</sub>, ID<sub>GR</sub></italic></td>
<td align="left">Identities of CMD<sub>i</sub> and GRS<sub>j</sub></td>
</tr>
<tr>
<td align="left"><italic>K<sub>G</sub>, m<sub>k</sub>:</italic></td>
<td align="left">Master secret key and mask key of GRS<sub>j</sub></td>
</tr>
<tr>
<td align="left"><italic>PID<sub>u</sub>, PID<sub>d</sub>, PID<sub>G</sub></italic></td>
<td align="left">Respective pseudonyms for MU<sub>i</sub>, CMD<sub>i</sub> and GRS<sub>j</sub></td>
</tr>
<tr>
<td align="left">||, &#x2295;:</td>
<td align="left">Concatenation and exclusive-OR based functions</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s4_2"><label>4.2</label><title>MU<sub>i</sub> Registration Phase</title>
<p>In the MU<sub>i</sub> registration phase, the user MU<sub>i</sub> becomes part of the IoD system through the registration process. GRS<italic><sub>j</sub></italic> uses confidential channels to perform MU<sub>i</sub> registration by issuing secret parameters. This stage includes the following steps:
<list list-type="bullet">
<list-item><p>The MU<sub>i</sub> chooses its identity <italic>ID<sub>u</sub></italic> and password <italic>PW<sub>u</sub></italic>, and submits the identity <italic>ID<sub>u</sub></italic> as request message for registration towards GRS<sub>j</sub>.</p></list-item>
<list-item><p>Upon the receipt of registration message request from MU<sub>i</sub>, the GRS<sub>j</sub> calculates <italic>PID<sub>u</sub> &#x003D; h(ID<sub>u</sub> &#x007C;&#x007C; k), B<sub>i</sub>&#x2009;&#x003D; h(ID<sub>u</sub> &#x007C;&#x007C; K<sub>G</sub>)</italic>. Then, it stores the factors {<italic>ID<sub>u</sub>, B<sub>i</sub>, PID<sub>u</sub></italic>} in its repository, and forwards the message {<italic>B<sub>i</sub>, PID<sub>u</sub>, PID<sub>d</sub></italic>} to MU<sub>i</sub> as shown in <?A3B2 "fig2",5,"anchor"?><xref ref-type="fig" rid="fig-2">Fig. 2</xref>.</p></list-item>
<list-item><p>The MU<sub>i</sub> after receiving the message calculates <italic>B<sub>i</sub>&#x0027;&#x2009;&#x003D; h(ID<sub>u</sub> &#x007C;&#x007C; PW<sub>u</sub>) &#x2295; B<sub>i</sub>, PID<sub>u</sub>&#x0027;&#x2009;&#x003D;&#x2009;h(ID<sub>u</sub> &#x007C;&#x007C; PW<sub>u</sub>) &#x2295; PID<sub>u</sub></italic> , and finally stores (<italic>B<sub>i&#x2019;</sub>, PID<sub>u&#x2019;</sub>, PID<sub>d</sub></italic>) in its memory.</p></list-item>
</list></p>
</sec>
<sec id="s4_3"><label>4.3</label><title>CMD<sub>i</sub> Registration Phase</title>
<p>The crowd monitoring drone CMD<sub>i</sub> registers itself with GRS<italic><sub>j</sub></italic> and becomes part of the IoD environment. In order to complete the registration, CMD<sub>i</sub> performs the following steps:
<list list-type="bullet">
<list-item><p>The CMD<sub>i</sub> chooses its identity <italic>ID<sub>d</sub></italic> on random basis, and submits the same towards GRS<sub>j</sub> to initiate the registration process.</p></list-item>
<list-item><p>The GRS<sub>j</sub>, then computes <italic>PID<sub>d</sub> &#x003D;&#x2009;h(ID<sub>d</sub> &#x007C;&#x007C; k)</italic> , <italic>B<sub>j</sub>&#x2009;&#x003D; h(ID<sub>d</sub> &#x007C;&#x007C; K<sub>G</sub>)</italic> and stores the parameters <italic>{ID<sub>d</sub>, B<sub>j</sub>, PID<sub>d</sub>}</italic> in its repository, and forwards the message <italic>{B<sub>j</sub>, PID<sub>d</sub>}</italic> to CMD<sub>i</sub>.</p></list-item>
<list-item><p>The CMD<sub>i</sub>, ultimately stores the same factors in its memory.</p></list-item>
</list></p>
<fig id="fig-2"><label>Figure 2</label><caption><title>Proposed authentication model</title></caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_20774-fig-2.png"/></fig>
</sec>
<sec id="s4_4"><label>4.4</label><title>Login and Authentication Phase</title>
<p>The MU<sub>i</sub> and CMD<sub>i</sub> participate in this stage to establish a mutual authentication session key at the end of the authentication session so that these entities can safely forward their data. The main steps at this stage can be described as follows:
<list list-type="bullet">
<list-item><p>The MU<sub>i</sub> inputs the identity <italic>ID<sub>u</sub></italic> and password <italic>PW<sub>u</sub></italic> into the mobile phone device. Then, the device calculates <italic>PID<sub>u</sub>&#x2009;&#x003D;&#x2009;h(ID<sub>u</sub> &#x007C;&#x007C; PW<sub>u</sub>) &#x2295; PID<sub>u&#x2019;</sub>, B<sub>i</sub>&#x2009;&#x003D; h(ID<sub>u</sub> &#x007C;&#x007C; PW<sub>u</sub>) &#x2295; B<sub>i&#x2019;</sub></italic>. Next, it selects a random integer <italic>a<sub>1</sub></italic><inline-formula id="ieqn-4"><mml:math id="mml-ieqn-4"><mml:mtext>&#xA0;</mml:mtext><mml:mi>&#x03F5;</mml:mi></mml:math></inline-formula> <italic>Z<sub>n</sub>&#x002A;</italic> and a fresh timestamp <italic>T<sub>1</sub></italic>. Next, it further computes <italic>R<sub>1</sub>&#x2009;&#x003D;&#x2009;h(PID<sub>G</sub> &#x007C;&#x007C;T<sub>1</sub>)&#x2295;PID<sub>u</sub>, R<sub>2</sub>&#x2009;&#x003D;&#x2009;h(PID<sub>u</sub> &#x007C;&#x007C; PID<sub>G</sub> &#x007C;&#x007C;B<sub>i</sub> &#x007C;&#x007C;T<sub>1</sub>) &#x2295; a<sub>1</sub>, R<sub>3</sub>&#x2009;&#x003D;&#x2009;h(PID<sub>u</sub> &#x007C;&#x007C; PID<sub>G</sub> &#x007C;&#x007C; B<sub>i</sub>&#x007C;&#x007C; a<sub>1</sub> &#x007C;&#x007C;T<sub>1</sub>) &#x2295; PID<sub>d</sub></italic> and <italic>R<sub>4</sub>&#x2009;&#x003D;&#x2009;h(PID<sub>u</sub> &#x007C;&#x007C; PID<sub>d</sub> &#x007C;&#x007C; PID<sub>G</sub> &#x007C;&#x007C; h(B<sub>i</sub> &#x007C;&#x007C; a<sub>1</sub>&#x007C;&#x007C; T<sub>1</sub>))</italic>. Next, it submits the message {<italic>R<sub>1</sub>, R<sub>2</sub>, R<sub>3</sub>, R<sub>4</sub>, T<sub>1</sub></italic>} to the GRS<italic><sub>j</sub></italic>.</p></list-item>
<list-item><p>Upon the receipt of message from MU<sub>i</sub>, the GRS<sub>j</sub> verifies the freshness for <italic>T<sub>1</sub></italic>. If it is fresh, it calculates <italic>PID<sub>u&#x2019;</sub> &#x003D; R<sub>1</sub>&#x2295;h(PID<sub>G</sub> &#x007C;&#x007C;T<sub>1</sub>)</italic> and retrieves <italic>B<sub>i&#x2019;</sub></italic> from repository LR, otherwise, rejects the session. Next, it calculates <italic>a<sub>1&#x0027;</sub>&#x2009;&#x003D;&#x2009;R<sub>2</sub>&#x2295;h(PID<sub>u</sub>&#x0027;&#x007C;&#x007C;PID<sub>G</sub>&#x007C;&#x007C;B<sub>i</sub>&#x0027;&#x007C;&#x007C;T<sub>1</sub>)</italic>, <italic>PID<sub>d</sub>&#x0027;&#x2009;&#x003D;&#x2009;R<sub>3</sub>&#x2295;h(PID<sub>u</sub>&#x0027;&#x007C;&#x007C;PID<sub>G</sub>&#x007C;&#x007C;B<sub>i</sub>&#x0027;&#x007C;&#x007C;a<sub>1</sub>&#x0027;&#x007C;&#x007C;T<sub>1</sub>)</italic>, <italic>R<sub>4</sub>&#x0027;&#x2009;&#x003D;&#x2009;h(PID<sub>u</sub>&#x2019; &#x007C;&#x007C; PID<sub>d</sub>&#x0027;&#x007C;&#x007C; PID<sub>G</sub> &#x007C;&#x007C; B<sub>i</sub>&#x2019; &#x007C;&#x007C; a<sub>1</sub>&#x0027;&#x007C;&#x007C;T<sub>1</sub>)</italic>. Next, GRS<italic><sub>j</sub></italic> verifies <italic>R<sub>4</sub>&#x2019; ?&#x2009;&#x003D; R<sub>4</sub></italic>, if it is false, it aborts the session. On the other hand, it calculates <italic>R<sub>5</sub>&#x2009;&#x003D;&#x2009;h(PID<sub>G</sub> &#x007C;&#x007C; PID<sub>d</sub>&#x2019; &#x007C;&#x007C; B<sub>j</sub>&#x2019;)&#x2295; a<sub>1</sub>&#x2019;</italic>, <italic>R<sub>6</sub>&#x2009;&#x003D;&#x2009;h(PID<sub>d</sub>&#x2019; &#x007C;&#x007C; PID<sub>G</sub> &#x007C;&#x007C; B<sub>j</sub>&#x2019; &#x007C;&#x007C; a<sub>1</sub>&#x2019;) &#x2295; PID<sub>u</sub>&#x2019;</italic>, <italic>R<sub>7</sub>&#x2009;&#x003D;&#x2009;h(PID<sub>u</sub>&#x0027;&#x007C;&#x007C; PID<sub>d</sub>&#x0027;&#x007C;&#x007C; PID<sub>G</sub> &#x007C;&#x007C; B<sub>j</sub>&#x2019; &#x007C;&#x007C; a<sub>1</sub>&#x2019;)</italic>. In the last, it submits the message R<italic><sub>5</sub></italic>, R<italic><sub>6</sub></italic>, R<italic><sub>7</sub></italic> towards CMD<sub>i</sub>.</p></list-item>
<list-item><p>The CMD<sub>i</sub>, after getting the message (<italic>R<sub>5</sub>, R<sub>6</sub>, R<sub>7</sub></italic>), calculates <italic>a<sub>1</sub>&#x02033;&#x2009;&#x003D;&#x2009;h(PID<sub>G</sub> &#x007C;&#x007C; PID<sub>d</sub> &#x007C;&#x007C; B<sub>j</sub> )</italic> &#x2295; <italic>R<sub>5</sub>, PID<sub>u</sub> &#x2033; &#x003D;&#x2009;h(PID<sub>d</sub>&#x007C;&#x007C; PID<sub>G</sub> &#x007C;&#x007C; B<sub>j</sub> &#x007C;&#x007C; a<sub>1</sub>&#x2033;)</italic> &#x2295; <italic>R<sub>6</sub></italic> and <italic>R<sub>7</sub>&#x02033;&#x2009;&#x003D;&#x2009;h(PID<sub>u</sub> &#x02033;&#x007C;&#x007C; PID<sub>d</sub> &#x007C;&#x007C; PID<sub>G</sub> &#x007C;&#x007C; B<sub>j</sub> &#x007C;&#x007C; a<sub>1</sub>&#x2033;)</italic>. Next, the CMD<sub>i</sub> verifies the equality <italic>R<sub>7</sub>&#x2033; ?&#x2009;&#x003D; R<sub>7</sub></italic> , it aborts the session if it is not true. On the other hand, it randomly selects a 160-bit integer <italic>a<sub>2</sub></italic><inline-formula id="ieqn-5"><mml:math id="mml-ieqn-5"><mml:mtext>&#xA0;</mml:mtext><mml:mi>&#x03F5;</mml:mi></mml:math></inline-formula> <italic>Z<sub>n</sub>&#x002A;</italic> and calculates <italic>R<sub>8</sub>&#x2009;&#x003D; h(PID<sub>d</sub> &#x007C;&#x007C; PID<sub>u</sub>&#x2033; &#x007C;&#x007C; a<sub>1</sub>&#x2033;)</italic> &#x2295; <italic>a<sub>2</sub></italic> , R<italic><sub>9</sub>&#x2009;&#x003D; h(PID<sub>u</sub>&#x02033; &#x007C;&#x007C; a<sub>1</sub>&#x2033; &#x007C;&#x007C; a<sub>2</sub>), SK<sub>du</sub> &#x003D; h(PID<sub>u</sub>&#x02033; &#x007C;&#x007C; PID<sub>d</sub> &#x007C;&#x007C; PID<sub>G</sub>&#x007C;&#x007C; R<sub>9</sub>)</italic> and <italic>R<sub>10</sub>&#x2009;&#x003D; h(PID<sub>u</sub>&#x02033; &#x007C;&#x007C; PID<sub>d</sub> &#x007C;&#x007C; PID<sub>G</sub>&#x007C;&#x007C; a<sub>1</sub>&#x2033; &#x007C;&#x007C; a<sub>2</sub> &#x007C;&#x007C;R<sub>9</sub>)</italic>. Finally, it submits the message <italic>R<sub>8</sub>, R<sub>10</sub></italic> towards MU<sub>i</sub>.</p></list-item>
<list-item><p>The MU<sub>i</sub> after getting the message (<italic>R<sub>8</sub>, R<sub>10</sub></italic>) calculates <italic>a<sub>2</sub>&#x02032; &#x003D; h(PID<sub>d</sub> &#x007C;&#x007C; PID<sub>u</sub>&#x007C;&#x007C; a<sub>1</sub>) &#x2295; R<sub>8</sub>, R<sub>9</sub>&#x2032; &#x003D; h(PID<sub>u</sub> &#x007C;&#x007C; a<sub>1</sub> &#x007C;&#x007C; a<sub>2</sub>&#x2032;)</italic> and <italic>R<sub>10</sub>&#x02032;&#x2009;&#x003D; h(PID<sub>u</sub> &#x007C;&#x007C; PID<sub>d</sub> &#x007C;&#x007C; PID<sub>G</sub> &#x007C;&#x007C; a<sub>1</sub> &#x007C;&#x007C; a2&#x2032; &#x007C;&#x007C;R<sub>9</sub>&#x2032;)</italic>. Next, it verifies the equation <italic>R<sub>10</sub> ?&#x2009;&#x003D;&#x2009;R<sub>10</sub></italic>. If it does not hold valid, it terminates the session. On the other hand, it authenticates the CMD<sub>i</sub> and calculates a mutual session key as <italic>SK<sub>ud</sub> &#x003D; h(PID<sub>u</sub>&#x2032; &#x007C;&#x007C; PID<sub>d</sub> &#x007C;&#x007C; PID<sub>G</sub>&#x007C;&#x007C; R<sub>9</sub>&#x2032;)</italic>.</p></list-item>
</list></p>
</sec>
</sec>
<sec id="s5"><label>5</label><title>Security Evaluations and Analysis</title>
<p>We here formally prove that our scheme can resist the known attacks under the random oracle model. In addition, we informally stated that our plan is protected from contemporary threats. The following subsections consider both formal and informal security analysis.</p>
<sec id="s5_1"><label>5.1</label><title>Formal Security Analysis</title>
<p>We describe a model related to formal security analysis, which is described with the help of a game played between malicious <inline-formula id="ieqn-6"><mml:math id="mml-ieqn-6"><mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">A</mml:mi></mml:mrow></mml:mrow></mml:mrow></mml:math></inline-formula> and challenger <italic>L</italic>. The adversary<inline-formula id="ieqn-7"><mml:math id="mml-ieqn-7"><mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">A</mml:mi></mml:mrow></mml:mrow></mml:mrow></mml:math></inline-formula> is modeled as a Turing machine, which is simulated to operate in a possible polynomial amount of time (PPT) [<xref ref-type="bibr" rid="ref-22">22</xref>]. The challenger <italic>L</italic> models each oracle in the system. <inline-formula id="ieqn-8"><mml:math id="mml-ieqn-8"><mml:munderover><mml:mo>&#x220F;</mml:mo><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:munderover></mml:math></inline-formula> represents the x<sup>th</sup> instance of the interactive participant <italic>g</italic> &#x003D; (MU<sub>i</sub>, GRS<sub>j</sub>, CMD<sub>i</sub>). These oracles allow opponents to randomly issue a series of queries and trigger corresponding responses. The hash-based oracle keeps the hash list <italic>L<sub>Hs</sub></italic>. If <inline-formula id="ieqn-9"><mml:math id="mml-ieqn-9"><mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">A</mml:mi></mml:mrow></mml:mrow></mml:mrow></mml:math></inline-formula> would execute hash-based query on message y, the challenger initially verifies the parameter using <italic>L<sub>Hs</sub></italic>. Upon the successful verification, the challenger returns the response <italic>h(y)</italic> to the adversary and stores the vector (<italic>y, Y</italic>) in the list <italic>L<sub>Hs</sub></italic>. This query indicates the ability of an attacker to destroy a legitimate drone and obtain its private key. After the attacker executes the extraction query on the UAV <italic>ID<sub>u</sub></italic>&#x0027;s identity, the query returns the relevant key to the attacker. This oracle represents the capability of adversary for initiating an active attack. Upon submitting m to <inline-formula id="ieqn-10"><mml:math id="mml-ieqn-10"><mml:munderover><mml:mo>&#x220F;</mml:mo><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:munderover></mml:math></inline-formula>, the attacker may receive the response from <inline-formula id="ieqn-11"><mml:math id="mml-ieqn-11"><mml:munderover><mml:mo>&#x220F;</mml:mo><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:munderover></mml:math></inline-formula> along with message <italic>m</italic>. In relation to the new oracle instance <inline-formula id="ieqn-12"><mml:math id="mml-ieqn-12"><mml:munderover><mml:mo>&#x220F;</mml:mo><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:munderover><mml:mo>,</mml:mo></mml:math></inline-formula> the attacker may launch submitting &#x201C;Send (<inline-formula id="ieqn-13"><mml:math id="mml-ieqn-13"><mml:munderover><mml:mo>&#x220F;</mml:mo><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:munderover><mml:mo>,</mml:mo></mml:math></inline-formula> <italic>Start</italic>)&#x201D; towards oracle.</p>
<p>The &#x201C;Reveal&#x201D; query models the erroneous use of the session key in the session. Upon the execution of Reveal query, in case the instance is effectively created, the challenger would return the session key SK for the instance <inline-formula id="ieqn-14"><mml:math id="mml-ieqn-14"><mml:munderover><mml:mo>&#x220F;</mml:mo><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:munderover></mml:math></inline-formula>. On the other hand, it will return <inline-formula id="ieqn-15"><mml:math id="mml-ieqn-15"><mml:mi mathvariant="normal">&#x22A5;</mml:mi></mml:math></inline-formula>. Using the Execute query (Execute (<inline-formula id="ieqn-16"><mml:math id="mml-ieqn-16"><mml:mi>M</mml:mi><mml:mrow><mml:msub><mml:mi>U</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi>C</mml:mi><mml:mi>M</mml:mi><mml:mrow><mml:msub><mml:mi>D</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:math></inline-formula>)), the adversary may eavesdrop all communication messages exchanged previously on insecure channel.</p>
<p>After the use of Test query (Test (<inline-formula id="ieqn-17"><mml:math id="mml-ieqn-17"><mml:munderover><mml:mo>&#x220F;</mml:mo><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:munderover></mml:math></inline-formula>)), the attacker may distinguish among original session key and the randomly selected key. The adversary may execute this query just one time. The challenger selects a bit <italic>b</italic><inline-formula id="ieqn-18"><mml:math id="mml-ieqn-18"><mml:mtext>&#xA0;</mml:mtext><mml:mi>&#x03F5;</mml:mi></mml:math></inline-formula> <italic>(0, 1)</italic> at random and would return valid session key to adversary in case <italic>b&#x2009;&#x003D;&#x2009;1</italic>. On the other hand, it would return randomly selected secret key of the same size (i.e., <italic>b&#x2009;&#x003D;&#x2009;0</italic>). Alternatively, in case the queried oracle does not about the session key, challenger would return <inline-formula id="ieqn-19"><mml:math id="mml-ieqn-19"><mml:mi mathvariant="normal">&#x22A5;</mml:mi></mml:math></inline-formula> to adversary.</p>
<p>The adversary may employ the above mentioned queries, i.e., <italic>Send, Reveal, Extract</italic> after initiating the <italic>Test</italic> query [<xref ref-type="bibr" rid="ref-23">23</xref>]. Here, one disadvantage to <inline-formula id="ieqn-20"><mml:math id="mml-ieqn-20"><mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">A</mml:mi></mml:mrow></mml:mrow></mml:mrow></mml:math></inline-formula> is that it may not launch the Reveal query either for oracle or the pattern oracle which employed the Test query for its execution. Finally, the adversary returns the output <italic>&#x003A6;&#x2019;</italic> after making its guess <italic>&#x003A6;</italic>. Here we can remark that the adversary could auspiciously win this game as a result of breaking the authenticated key agreement (AKE) of contributed protocol <inline-formula id="ieqn-21"><mml:math id="mml-ieqn-21"><mml:mrow><mml:mi mathvariant="normal">&#x03A3;</mml:mi></mml:mrow></mml:math></inline-formula> in case <italic>&#x003A6;&#x2019;</italic> becomes equal to <italic>&#x003A6;</italic>. The benefit of <inline-formula id="ieqn-22"><mml:math id="mml-ieqn-22"><mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">A</mml:mi></mml:mrow></mml:mrow></mml:mrow></mml:math></inline-formula> may be described as <inline-formula id="ieqn-23"><mml:math id="mml-ieqn-23"><mml:mi>a</mml:mi><mml:mi>d</mml:mi><mml:msubsup><mml:mi>v</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x03A3;</mml:mi></mml:mrow><mml:mrow><mml:mi>A</mml:mi><mml:mi>K</mml:mi><mml:mi>E</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>(<inline-formula id="ieqn-24"><mml:math id="mml-ieqn-24"><mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">A</mml:mi></mml:mrow></mml:mrow></mml:mrow></mml:math></inline-formula>) &#x003D; &#x007C;2Pr [<italic>&#x003A6;&#x2019; &#x003D; &#x003A6;</italic>]<italic>&#x2009;</italic>&#x2212;<italic>&#x2009;</italic>1&#x007C;.</p>
<p>Definition 1 (AKE-secure): When there is a negligible polynomial probability, the adversary may auspiciously win that game with a non-negligible benefit <inline-formula id="ieqn-25"><mml:math id="mml-ieqn-25"><mml:mi>a</mml:mi><mml:mi>d</mml:mi><mml:msubsup><mml:mi>v</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x03A3;</mml:mi></mml:mrow><mml:mrow><mml:mi>A</mml:mi><mml:mi>K</mml:mi><mml:mi>E</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>(<inline-formula id="ieqn-26"><mml:math id="mml-ieqn-26"><mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">A</mml:mi></mml:mrow></mml:mrow></mml:mrow></mml:math></inline-formula>), and we may infer that the contributed protocol <inline-formula id="ieqn-27"><mml:math id="mml-ieqn-27"><mml:mrow><mml:mi mathvariant="normal">&#x03A3;</mml:mi></mml:mrow></mml:math></inline-formula> is AKE-secure.</p>
<p>The adversary may positively compromise the mutual authenticity of the contributed protocol <inline-formula id="ieqn-28"><mml:math id="mml-ieqn-28"><mml:mrow><mml:mi mathvariant="normal">&#x03A3;</mml:mi></mml:mrow></mml:math></inline-formula>, in case the adversary could forge the legitimate authentication message, i.e., either authentication request or corresponding response. Suppose E<sub>MU-GRS</sub> represents the event that the adversary forges the MU<sub>i</sub> and constructs the login request acknowledged by GRS<sub>j</sub>. Also E<sub>MU-CMD</sub> characterizes the event that <inline-formula id="ieqn-29"><mml:math id="mml-ieqn-29"><mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">A</mml:mi></mml:mrow></mml:mrow></mml:mrow></mml:math></inline-formula> masquerades the CMD<sub>i</sub> and produces the response which is acknowledged by MU<sub>i</sub>. The benefit of the adversary for being successful in this game can be described as <inline-formula id="ieqn-30"><mml:math id="mml-ieqn-30"><mml:mi>a</mml:mi><mml:mi>d</mml:mi><mml:msubsup><mml:mi>v</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x03A3;</mml:mi></mml:mrow><mml:mrow><mml:mi>M</mml:mi><mml:mi>E</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>(<inline-formula id="ieqn-31"><mml:math id="mml-ieqn-31"><mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">A</mml:mi></mml:mrow></mml:mrow></mml:mrow></mml:math></inline-formula>) &#x003D; Pr[E<sub>MU-GRS</sub>] &#x002B; Pr[E<sub>MU-CMD</sub>].</p>
<p>Definition 2 (ME-secure): In case there exists no probability for any polynomial time attacker such that one may auspiciously win the game with considerable benefit <inline-formula id="ieqn-32"><mml:math id="mml-ieqn-32"><mml:mi>a</mml:mi><mml:mi>d</mml:mi><mml:msubsup><mml:mi>v</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x03A3;</mml:mi></mml:mrow><mml:mrow><mml:mi>M</mml:mi><mml:mi>E</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>(<inline-formula id="ieqn-33"><mml:math id="mml-ieqn-33"><mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">A</mml:mi></mml:mrow></mml:mrow></mml:mrow></mml:math></inline-formula>), we term the proposed protocol <inline-formula id="ieqn-34"><mml:math id="mml-ieqn-34"><mml:mrow><mml:mi mathvariant="normal">&#x03A3;</mml:mi></mml:mrow></mml:math></inline-formula> as ME-Secure.</p>
</sec>
<sec id="s5_2"><label>5.2</label><title>Proof</title>
<p>We acknowledge that there lies no adversary <inline-formula id="ieqn-35"><mml:math id="mml-ieqn-35"><mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">A</mml:mi></mml:mrow></mml:mrow></mml:mrow></mml:math></inline-formula> that may impersonate as a legitimate authentication and response message with non-negligible chance. This certifies that the contributed protocol is AKE-secure and ME-secure regarding the provable security strength.</p>
<p>Lemma1: We assume that a polynomial time attacker <inline-formula id="ieqn-36"><mml:math id="mml-ieqn-36"><mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">A</mml:mi></mml:mrow></mml:mrow></mml:mrow></mml:math></inline-formula> may compute a legitimate authentication request and response message with non-negligible chance. Thus, there lies a challenger C who may estimate a 160-bit randomly defined integer with success having non-negligible probability.</p>
<p>Proof: The challenger chooses a 160-bit randomly generated integer <italic>q</italic>, and submits the factors {<italic>h, n</italic>} towards the adversary. The challenger produces a new hash-list <italic>L<sub>Hs</sub></italic>, which is blank on initial basis, and is meant for recording the query inputs as well as outputs for hash-based oracles. Then, it chooses two random drone identities, such as <italic>ID<sub>U</sub></italic> and <italic>ID<sub>D</sub></italic> to proceed. We assume that the rest of the oracles may be queried once the hash-based oracles perform their function. The queries&#x2019; responses are illustrated as under:</p>
<p><italic>h(y<sub>i</sub>)</italic>: The challenger initially verifies the occurrence of <italic>y<sub>i</sub></italic> in the <italic>L<sub>Hs</sub></italic> list. If it exists in the list, the challenger would return <italic>Y<sub>i</sub></italic> to attacker. Otherwise, it selects a random integer <italic>Y<sub>i</sub></italic>, inserts (<italic>y<sub>i</sub></italic>, <italic>Y<sub>i</sub></italic>) in the <italic>L<sub>Hs</sub></italic> list and returns the same <italic>Y<sub>i</sub></italic> to attacker.</p>
<p>Extract (ID<sub>U</sub>): In case <italic>u</italic> <inline-formula id="ieqn-37"><mml:math id="mml-ieqn-37"><mml:mo>&#x2260;</mml:mo></mml:math></inline-formula><italic>&#x2009;U</italic>, D, the challenger searches for the tuple (<italic>ID<sub>u</sub> &#x007C;&#x007C; K<sub>G</sub>, B<sub>i</sub></italic>) in <italic>L<sub>Hs</sub></italic> list, and would return B<sub>i</sub> to the <inline-formula id="ieqn-38"><mml:math id="mml-ieqn-38"><mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">A</mml:mi></mml:mrow></mml:mrow></mml:mrow></mml:math></inline-formula>. On the other hand, the challenger aborts the oracle query and terminates the game. Send (<inline-formula id="ieqn-39"><mml:math id="mml-ieqn-39"><mml:munderover><mml:mo>&#x220F;</mml:mo><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:munderover><mml:mo>,</mml:mo></mml:math></inline-formula> <italic>m</italic>): The attacker may use the Send query for modeling this active threat in four ways:</p>
<p>Send (<inline-formula id="ieqn-40"><mml:math id="mml-ieqn-40"><mml:munderover><mml:mo>&#x220F;</mml:mo><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:munderover></mml:math></inline-formula><italic>Start</italic>): The challenger searches for the hashing list <italic>L<sub>Hs</sub></italic> to find the secret key <italic>B<sub>i</sub></italic> for MU<sub>i</sub> by checking the inequality for <italic>u</italic> <inline-formula id="ieqn-41"><mml:math id="mml-ieqn-41"><mml:mo>&#x2260;</mml:mo></mml:math></inline-formula> <italic>U</italic> in the list. Using the secret key B<sub>i</sub>, the challenger selects a randomly defined integer <italic>n<sub>1</sub> </italic><inline-formula id="ieqn-42"><mml:math id="mml-ieqn-42"><mml:mi>&#x03F5;</mml:mi></mml:math></inline-formula><italic>Z<sub>n</sub>&#x002A;</italic>, the fresh timestamp <italic>T<sub>1</sub></italic>, and calculates (<italic>R<sub>1</sub>, R<sub>2</sub>, R<sub>3</sub>, R<sub>4</sub>, T<sub>1</sub></italic>). However if the equality does not hold, the challenger chooses three random integers <italic>V<sub>1</sub>, V<sub>2</sub>, V<sub>3</sub></italic><inline-formula id="ieqn-43"><mml:math id="mml-ieqn-43"><mml:mtext>&#xA0;</mml:mtext><mml:mi>&#x03F5;</mml:mi><mml:mtext>&#xA0;</mml:mtext></mml:math></inline-formula>Z<sub>n</sub>&#x002A; and would set <italic>R<sub>1</sub></italic><inline-formula id="ieqn-44"><mml:math id="mml-ieqn-44"><mml:mo stretchy="false">&#x2190;</mml:mo></mml:math></inline-formula><italic>V<sub>1</sub>, R<sub>2</sub></italic><inline-formula id="ieqn-45"><mml:math id="mml-ieqn-45"><mml:mo stretchy="false">&#x2190;</mml:mo></mml:math></inline-formula><italic>V<sub>2</sub>, R<sub>3</sub></italic><inline-formula id="ieqn-46"><mml:math id="mml-ieqn-46"><mml:mo stretchy="false">&#x2190;</mml:mo></mml:math></inline-formula><italic>R<sub>3</sub></italic>. It then calculates <italic>V<sub>1</sub>&#x2009;&#x003D;&#x2009;h(PID<sub>G</sub> &#x007C;&#x007C;T<sub>1</sub>)</italic> &#x2295; <italic>PID<sub>U</sub></italic> and returns the (<italic>R<sub>1</sub>, R<sub>2</sub>, R<sub>3</sub>, R<sub>4</sub></italic>) to the attacker.</p>
<p>Send (<inline-formula id="ieqn-47"><mml:math id="mml-ieqn-47"><mml:msubsup><mml:mrow><mml:mo movablelimits="false">&#x220F;</mml:mo></mml:mrow><mml:mrow><mml:mrow><mml:mtext>CM</mml:mtext></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mtext>D</mml:mtext></mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:msub></mml:mrow></mml:mrow><mml:mi>k</mml:mi></mml:msubsup><mml:mo>,</mml:mo></mml:math></inline-formula> (<italic>R<sub>5</sub>, R<sub>6</sub>, R<sub>7</sub></italic>)): The challenger upon the receipt of message, verifies the inequality for <italic>d</italic> <inline-formula id="ieqn-48"><mml:math id="mml-ieqn-48"><mml:mo>&#x2260;</mml:mo></mml:math></inline-formula><italic>&#x2009;D</italic>. If the equality holds, the challenger discards the message and chooses randomly two integers <italic>V<sub>2</sub>, V<sub>3</sub></italic><inline-formula id="ieqn-49"><mml:math id="mml-ieqn-49"><mml:mtext>&#xA0;</mml:mtext><mml:mi>&#x03F5;</mml:mi></mml:math></inline-formula>Z<sub>n</sub>&#x002A; and will set <italic>R<sub>8</sub></italic><inline-formula id="ieqn-50"><mml:math id="mml-ieqn-50"><mml:mo stretchy="false">&#x2190;</mml:mo></mml:math></inline-formula><italic>V<sub>4</sub>, R<sub>10</sub></italic><inline-formula id="ieqn-51"><mml:math id="mml-ieqn-51"><mml:mo stretchy="false">&#x2190;</mml:mo></mml:math></inline-formula><italic>V<sub>5</sub>, R<sub>3</sub></italic><inline-formula id="ieqn-52"><mml:math id="mml-ieqn-52"><mml:mo stretchy="false">&#x2190;</mml:mo></mml:math></inline-formula><italic>V<sub>3</sub>.</italic> On the other hand, the challenger searches for the hash list <italic>L<sub>Hs</sub></italic> to find the secret key <italic>B<sub>j</sub></italic> for CMD<sub>i</sub> and proceeds with the normal execution of the protocol.</p>
<p>Send (<inline-formula id="ieqn-53"><mml:math id="mml-ieqn-53"><mml:msubsup><mml:mrow><mml:mo movablelimits="false">&#x220F;</mml:mo></mml:mrow><mml:mrow><mml:mrow><mml:mtext>M</mml:mtext></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mtext>U</mml:mtext></mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:msub></mml:mrow></mml:mrow><mml:mi>t</mml:mi></mml:msubsup><mml:mo>,</mml:mo></mml:math></inline-formula> (<italic>R<sub>8</sub>, R<sub>10</sub></italic>)): The challenger now confirms the equality for <italic>d</italic> <inline-formula id="ieqn-54"><mml:math id="mml-ieqn-54"><mml:mo>&#x2260;</mml:mo></mml:math></inline-formula><italic>&#x2009;D</italic>. If it is valid, then searches for CMD<sub>i</sub>&#x0027;s secret <italic>B<sub>j</sub></italic> in the hash-list <italic>L<sub>Hs</sub></italic>. It generates randomly an integer <italic>n<sub>2</sub> </italic><inline-formula id="ieqn-55"><mml:math id="mml-ieqn-55"><mml:mi>&#x03F5;</mml:mi><mml:mtext>&#xA0;</mml:mtext></mml:math></inline-formula><italic>Z<sub>n</sub>&#x002A;</italic> and computes (<italic>R<sub>8</sub>, R<sub>10</sub></italic>) using <italic>B<sub>j</sub></italic>. If the inequality does not hold, it chooses three integers on random basis as <italic>V<sub>4</sub>, V<sub>5</sub>, V<sub>6</sub></italic><inline-formula id="ieqn-56"><mml:math id="mml-ieqn-56"><mml:mtext>&#xA0;</mml:mtext><mml:mi>&#x03F5;</mml:mi><mml:mtext>&#xA0;</mml:mtext></mml:math></inline-formula>Z<sub>n</sub>&#x002A;, and would set <italic>n<sub>2</sub></italic><inline-formula id="ieqn-57"><mml:math id="mml-ieqn-57"><mml:mtext>&#xA0;</mml:mtext><mml:mo stretchy="false">&#x2190;</mml:mo></mml:math></inline-formula><italic>V<sub>4</sub>, R<sub>8</sub></italic><inline-formula id="ieqn-58"><mml:math id="mml-ieqn-58"><mml:mo stretchy="false">&#x2190;</mml:mo></mml:math></inline-formula><italic>V<sub>5</sub>, R<sub>10</sub></italic><inline-formula id="ieqn-59"><mml:math id="mml-ieqn-59"><mml:mo stretchy="false">&#x2190;</mml:mo></mml:math></inline-formula><italic>V<sub>6</sub></italic> and returns the tuple (<italic>R<sub>8</sub>, R<sub>10</sub></italic>) to MU<sub>i</sub>.</p>
<p>Reveal (<inline-formula id="ieqn-60"><mml:math id="mml-ieqn-60"><mml:munderover><mml:mo>&#x220F;</mml:mo><mml:mi>g</mml:mi><mml:mi>t</mml:mi></mml:munderover></mml:math></inline-formula>)): In case the instance <inline-formula id="ieqn-61"><mml:math id="mml-ieqn-61"><mml:munderover><mml:mo>&#x220F;</mml:mo><mml:mi>g</mml:mi><mml:mi>t</mml:mi></mml:munderover></mml:math></inline-formula> is accepted, the challenger would return the valid session key as <italic>SK<sub>ud</sub></italic>, otherwise it will return <inline-formula id="ieqn-62"><mml:math id="mml-ieqn-62"><mml:mi mathvariant="normal">&#x22A5;</mml:mi></mml:math></inline-formula>. We assume that an attacker may compute valid login message request or response with success, or alternatively it may compute the responses (<italic>R<sub>1</sub>, R<sub>2</sub>, R<sub>3</sub>, R<sub>4</sub></italic>) to Send (<inline-formula id="ieqn-63"><mml:math id="mml-ieqn-63"><mml:msubsup><mml:mrow><mml:mo movablelimits="false">&#x220F;</mml:mo></mml:mrow><mml:mrow><mml:mrow><mml:mtext>M</mml:mtext></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mtext>U</mml:mtext></mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:msub></mml:mrow></mml:mrow><mml:mi>t</mml:mi></mml:msubsup><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext></mml:math></inline-formula><italic>Start</italic>) oracle query having <italic>u&#x2009;&#x003D;&#x2009;U</italic> and (<italic>R<sub>8</sub>, R<sub>10</sub></italic>) to Send (<inline-formula id="ieqn-64"><mml:math id="mml-ieqn-64"><mml:msubsup><mml:mrow><mml:mo movablelimits="false">&#x220F;</mml:mo></mml:mrow><mml:mrow><mml:mrow><mml:mtext>CM</mml:mtext></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mtext>D</mml:mtext></mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:msub></mml:mrow></mml:mrow><mml:mi>k</mml:mi></mml:msubsup><mml:mo>,</mml:mo></mml:math></inline-formula> (<italic>R<sub>5</sub>, R<sub>6</sub>, R<sub>7</sub></italic>)) oracle query with d&#x003D;D are verified by the GRS<sub>j</sub> and MU<sub>i</sub> entities. For computing the advantage for the challenger, we define the under-mentioned events as: E<sub>v1</sub>: The modeling is not terminated. E<sub>v2</sub>: The attacker sends the computed login request (<italic>R<sub>1</sub>, R<sub>2</sub>, R<sub>3</sub>, R<sub>4</sub></italic>) by employing Send (<inline-formula id="ieqn-65"><mml:math id="mml-ieqn-65"><mml:msubsup><mml:mrow><mml:mo movablelimits="false">&#x220F;</mml:mo></mml:mrow><mml:mrow><mml:mrow><mml:mtext>M</mml:mtext></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mtext>U</mml:mtext></mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:msub></mml:mrow></mml:mrow><mml:mi>t</mml:mi></mml:msubsup><mml:mo>,</mml:mo></mml:math></inline-formula> <italic>Start</italic>) or some valid response message (<italic>R<sub>8</sub>, R<sub>10</sub></italic>) using Send (<inline-formula id="ieqn-66"><mml:math id="mml-ieqn-66"><mml:msubsup><mml:mrow><mml:mo movablelimits="false">&#x220F;</mml:mo></mml:mrow><mml:mrow><mml:mrow><mml:mtext>CM</mml:mtext></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mtext>D</mml:mtext></mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:msub></mml:mrow></mml:mrow><mml:mi>k</mml:mi></mml:msubsup><mml:mo>,</mml:mo></mml:math></inline-formula> (<italic>R<sub>5</sub>, R<sub>6</sub>, R<sub>7</sub></italic>)), however the queries Extract(ID<sub>U</sub>) and Extract(ID<sub>D</sub>) were never employed. E<sub>v3</sub>: MU<sub>i</sub>&#x003D;MU<sub>U</sub> or CMD<sub>i</sub>&#x003D;CMD<sub>D</sub>. E<sub>v4</sub>: The challenger may select any of the valid records from hash-list <italic>L<sub>Hs</sub></italic>.</p>
<p>We assume <italic>q<sub>sd</sub></italic>, <italic>q<sub>LR</sub></italic> and <italic>q<sub>LHs</sub></italic> represent the number of <italic>Send</italic>, <italic>L<sub>R</sub></italic> and <italic>L<sub>Hs</sub></italic> queries executed by the adversary.</p>
<p><disp-formula id="eqn-1"><label>(1)</label><mml:math id="mml-eqn-1" display="block"><mml:mrow><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">r</mml:mi></mml:mrow><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="normal">E</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">v</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mo>&#x2265;</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mrow><mml:mrow><mml:msub><mml:mi>q</mml:mi><mml:mrow><mml:mi>s</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mrow></mml:mfrac></mml:math></disp-formula></p>
<p><disp-formula id="eqn-2"><label>(2)</label><mml:math id="mml-eqn-2" display="block"><mml:mrow><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">r</mml:mi></mml:mrow><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="normal">E</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">v</mml:mi><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mrow><mml:mi mathvariant="normal">E</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">v</mml:mi></mml:mrow></mml:msub><mml:mn>1</mml:mn><mml:mo stretchy="false">]</mml:mo><mml:mo>&#x2265;</mml:mo><mml:mi>&#x03F5;</mml:mi></mml:math></disp-formula></p>
<p><disp-formula id="ueqn-1">
<mml:math id="mml-ueqn-1" display="block"><mml:mrow><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mo stretchy="false">[</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi mathvariant="normal">E</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="normal">v</mml:mi></mml:mrow><mml:mn>4</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi mathvariant="normal">E</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="normal">v</mml:mi></mml:mrow><mml:mn>3</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>&#x2227;</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi mathvariant="normal">E</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="normal">v</mml:mi></mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>&#x2227;</mml:mo><mml:mrow><mml:mi mathvariant="normal">E</mml:mi><mml:mi mathvariant="normal">v</mml:mi></mml:mrow><mml:mn>1</mml:mn><mml:mo stretchy="false">]</mml:mo><mml:mo>&#x2265;</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mrow><mml:mrow><mml:msub><mml:mi>q</mml:mi><mml:mrow><mml:mi>L</mml:mi><mml:mi>R</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mrow></mml:mfrac><mml:mfrac><mml:mn>1</mml:mn><mml:mrow><mml:mrow><mml:msub><mml:mi>q</mml:mi><mml:mrow><mml:mi>L</mml:mi><mml:mi>R</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow></mml:mrow></mml:mfrac><mml:mo>+</mml:mo><mml:mfrac><mml:mi>a</mml:mi><mml:mrow><mml:mrow><mml:msub><mml:mi>q</mml:mi><mml:mrow><mml:mi>L</mml:mi><mml:mi>H</mml:mi><mml:mi>s</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mrow></mml:mfrac><mml:mfrac><mml:mi>b</mml:mi><mml:mrow><mml:mrow><mml:msub><mml:mi>q</mml:mi><mml:mrow><mml:mi>L</mml:mi><mml:mi>H</mml:mi><mml:mi>s</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>a</mml:mi></mml:mrow></mml:mfrac></mml:math>
</disp-formula>
where <italic>a</italic> represents the valid record index in Send (<inline-formula id="ieqn-67"><mml:math id="mml-ieqn-67"><mml:msubsup><mml:mrow><mml:mo movablelimits="false">&#x220F;</mml:mo></mml:mrow><mml:mrow><mml:mrow><mml:mtext>M</mml:mtext></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mtext>U</mml:mtext></mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:msub></mml:mrow></mml:mrow><mml:mi>t</mml:mi></mml:msubsup><mml:mo>,</mml:mo></mml:math></inline-formula><italic>Start</italic>) oracle, while b characterizes the frequency of Send (<inline-formula id="ieqn-68"><mml:math id="mml-ieqn-68"><mml:msubsup><mml:mrow><mml:mo movablelimits="false">&#x220F;</mml:mo></mml:mrow><mml:mrow><mml:mrow><mml:mtext>M</mml:mtext></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mtext>U</mml:mtext></mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:msub></mml:mrow></mml:mrow><mml:mi>t</mml:mi></mml:msubsup><mml:mo>,</mml:mo></mml:math></inline-formula> (<italic>R<sub>8</sub>, R<sub>10</sub></italic>)) queries. Thus, the challenger would guess 160-bit random integer auspiciously with non-negligible prospect as shown in <xref ref-type="disp-formula" rid="eqn-1">Eqs. (1)</xref> and <xref ref-type="disp-formula" rid="eqn-2">(2)</xref>.</p>
<p><disp-formula id="eqn-3"><label>(3)</label><mml:math id="mml-eqn-3" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd /><mml:mtd><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">v</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>&#x2227;</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">v</mml:mi><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>&#x2227;</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">v</mml:mi><mml:mn>3</mml:mn></mml:mrow></mml:msub><mml:mo>&#x2227;</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">v</mml:mi><mml:mn>4</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mo>=</mml:mo><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">v</mml:mi><mml:mn>4</mml:mn></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">v</mml:mi><mml:mn>3</mml:mn></mml:mrow></mml:msub><mml:mo>&#x2227;</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">v</mml:mi><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>&#x2227;</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">v</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">v</mml:mi><mml:mn>3</mml:mn></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">v</mml:mi><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>&#x2227;</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">v</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">v</mml:mi><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">v</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">]</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mi></mml:mi><mml:mspace width="1em" /><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msub><mml:mi>q</mml:mi><mml:mrow><mml:mi>s</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:mfrac><mml:mfrac><mml:mn>1</mml:mn><mml:msub><mml:mi>q</mml:mi><mml:mrow><mml:mi>L</mml:mi><mml:mi>R</mml:mi></mml:mrow></mml:msub></mml:mfrac><mml:mrow><mml:mo>(</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msub><mml:mi>q</mml:mi><mml:mrow><mml:mi>L</mml:mi><mml:mi>R</mml:mi></mml:mrow></mml:msub></mml:mfrac><mml:mfrac><mml:mn>1</mml:mn><mml:msub><mml:mi>q</mml:mi><mml:mrow><mml:mi>L</mml:mi><mml:mi>R</mml:mi></mml:mrow></mml:msub></mml:mfrac><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo>+</mml:mo><mml:mfrac><mml:mi>a</mml:mi><mml:msub><mml:mi>q</mml:mi><mml:mrow><mml:mi>L</mml:mi><mml:mi>H</mml:mi><mml:mi>s</mml:mi></mml:mrow></mml:msub></mml:mfrac><mml:mfrac><mml:mi>b</mml:mi><mml:mrow><mml:msub><mml:mi>q</mml:mi><mml:mrow><mml:mi>L</mml:mi><mml:mi>H</mml:mi><mml:mi>s</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mi>a</mml:mi></mml:mrow></mml:mfrac><mml:mo>)</mml:mo></mml:mrow><mml:mi>&#x03F5;</mml:mi></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>
Nonetheless, this shows the contradiction regarding the hardness for guessing 160-bit random integer as shown in <xref ref-type="disp-formula" rid="eqn-3">Eq. (3)</xref>. Alternatively, the attacker may not construct a legitimate login request or response message, so the drones in the protocol may verify the authenticity of one another.</p>
<p>Theorem 1. The proposed protocol is ME-Secure for rigid guessing of 160-bit random integer.</p>
<p>According to Lemma1, no adversary may construct a legitimate login request or response message for guessing the high entropy 160-bit random integer. Thus, the contributed protocol is ME-Secure.</p>
<p>Theorem 2. The proposed protocol is AKE-Secure for rigid guessing of 160-bit random integer.</p>
<p>Proof. We assume that the probabilistic polynomial-time attacker produces the valid <italic>b&#x0027;&#x003D;b</italic> with non-negligible chance <inline-formula id="ieqn-69"><mml:math id="mml-ieqn-69"><mml:mi>&#x03F5;</mml:mi></mml:math></inline-formula> upon the execution of Test oracle query. Consequently the challenger may deduce 160-bit randomly defined integer with success having non-negligible prospect. For calculating the advantage of challenger, the understated events are described here:
<list list-type="bullet">
<list-item><p>E<sub>SKi</sub>: The adversary may get the legitimate session key upon the execution of Test query.</p></list-item>
<list-item><p>E<sub>MU</sub>: The adversary runs the Test query for the instance <inline-formula id="ieqn-70"><mml:math id="mml-ieqn-70"><mml:msub><mml:mrow><mml:mo movablelimits="false">&#x220F;</mml:mo></mml:mrow><mml:mrow><mml:mrow><mml:mtext>CM</mml:mtext></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mtext>D</mml:mtext></mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:msub></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> auspiciously.</p></list-item>
<list-item><p>E<sub>CMD</sub>: The adversary runs the Test query with success for the instance <inline-formula id="ieqn-71"><mml:math id="mml-ieqn-71"><mml:msub><mml:mrow><mml:mo movablelimits="false">&#x220F;</mml:mo></mml:mrow><mml:mrow><mml:mrow><mml:mtext>CM</mml:mtext></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mtext>D</mml:mtext></mml:mrow><mml:mrow><mml:mtext>D</mml:mtext></mml:mrow></mml:msub></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula>.</p></list-item>
</list></p>
<p>E<sub>MUi-GRSj-CMDi</sub>: The adversary may disrupt the authentication session between MU<sub>i</sub> and GRS<sub>j</sub>, as well as between MU<sub>i</sub> and CMD<sub>i</sub>. It is known that the attacker may guess the valid <italic>b</italic> with the missing information of <italic>b</italic> as <inline-formula id="ieqn-1000"><mml:math id="mml-ieqn-1000"><mml:mfrac><mml:mn>1</mml:mn><mml:mn>2</mml:mn></mml:mfrac></mml:math></inline-formula>. Hence we have the equation Pr[E<sub>SKi</sub>] <inline-formula id="ieqn-72"><mml:math id="mml-ieqn-72"><mml:mo>&#x2265;</mml:mo><mml:mi>&#x03F5;</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:math></inline-formula></p>
<p><disp-formula id="eqn-4"><label>(4)</label><mml:math id="mml-eqn-4" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mrow><mml:mo>[</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">S</mml:mi><mml:mi mathvariant="normal">K</mml:mi><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:msub><mml:mo>]</mml:mo></mml:mrow><mml:mo>=</mml:mo></mml:mtd><mml:mtd><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mrow><mml:mo>[</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">S</mml:mi><mml:mi mathvariant="normal">K</mml:mi><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2227;</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">C</mml:mi><mml:mi mathvariant="normal">M</mml:mi><mml:mi mathvariant="normal">D</mml:mi><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:msub><mml:mo>]</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">S</mml:mi><mml:mi mathvariant="normal">K</mml:mi><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2227;</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">C</mml:mi><mml:mi mathvariant="normal">M</mml:mi><mml:mi mathvariant="normal">D</mml:mi><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2227;</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">M</mml:mi><mml:mi mathvariant="normal">U</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi mathvariant="normal">G</mml:mi><mml:mi mathvariant="normal">R</mml:mi><mml:mi mathvariant="normal">S</mml:mi><mml:mi mathvariant="normal">j</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi mathvariant="normal">C</mml:mi><mml:mi mathvariant="normal">M</mml:mi><mml:mi mathvariant="normal">D</mml:mi><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mo>+</mml:mo><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">S</mml:mi><mml:mi mathvariant="normal">K</mml:mi><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2227;</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">C</mml:mi><mml:mi mathvariant="normal">M</mml:mi><mml:mi mathvariant="normal">D</mml:mi><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2227;</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mspace width="1em" /><mml:mi mathvariant="normal">&#x00AC;</mml:mi><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">M</mml:mi><mml:mi mathvariant="normal">U</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi mathvariant="normal">G</mml:mi><mml:mi mathvariant="normal">R</mml:mi><mml:mi mathvariant="normal">S</mml:mi><mml:mi mathvariant="normal">j</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi mathvariant="normal">C</mml:mi><mml:mi mathvariant="normal">M</mml:mi><mml:mi mathvariant="normal">D</mml:mi><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mo>&#x2264;</mml:mo><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">S</mml:mi><mml:mi mathvariant="normal">K</mml:mi><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2227;</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">M</mml:mi><mml:mi mathvariant="normal">U</mml:mi><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mo>+</mml:mo><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">M</mml:mi><mml:mi mathvariant="normal">U</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi mathvariant="normal">G</mml:mi><mml:mi mathvariant="normal">R</mml:mi><mml:mi mathvariant="normal">S</mml:mi><mml:mi mathvariant="normal">j</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi mathvariant="normal">C</mml:mi><mml:mi mathvariant="normal">M</mml:mi><mml:mi mathvariant="normal">D</mml:mi><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">]</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mi></mml:mi><mml:mspace width="1em" /><mml:mo>+</mml:mo><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">S</mml:mi><mml:mi mathvariant="normal">K</mml:mi><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2227;</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">C</mml:mi><mml:mi mathvariant="normal">M</mml:mi><mml:mi mathvariant="normal">D</mml:mi><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2227;</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">M</mml:mi><mml:mi mathvariant="normal">U</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi mathvariant="normal">G</mml:mi><mml:mi mathvariant="normal">R</mml:mi><mml:mi mathvariant="normal">S</mml:mi><mml:mi mathvariant="normal">j</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi mathvariant="normal">C</mml:mi><mml:mi mathvariant="normal">M</mml:mi><mml:mi mathvariant="normal">D</mml:mi><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">]</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p>
<p>Hence</p>
<p><disp-formula id="eqn-5"><label>(5)</label><mml:math id="mml-eqn-5" display="block"><mml:mtable columnalign="left" rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">S</mml:mi><mml:mi mathvariant="normal">K</mml:mi><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2227;</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">M</mml:mi><mml:mi mathvariant="normal">U</mml:mi><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mo>+</mml:mo><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">S</mml:mi><mml:mi mathvariant="normal">K</mml:mi><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2227;</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">C</mml:mi><mml:mi mathvariant="normal">M</mml:mi><mml:mi mathvariant="normal">D</mml:mi><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2227;</mml:mo><mml:mi mathvariant="normal">&#x00AC;</mml:mi><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">M</mml:mi><mml:mi mathvariant="normal">U</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi mathvariant="normal">G</mml:mi><mml:mi mathvariant="normal">R</mml:mi><mml:mi mathvariant="normal">S</mml:mi><mml:mi mathvariant="normal">j</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi mathvariant="normal">C</mml:mi><mml:mi mathvariant="normal">M</mml:mi><mml:mi mathvariant="normal">D</mml:mi><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mo>&#x2265;</mml:mo><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">S</mml:mi><mml:mi mathvariant="normal">k</mml:mi><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">]</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mo>&#x2212;</mml:mo><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">M</mml:mi><mml:mi mathvariant="normal">U</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi mathvariant="normal">G</mml:mi><mml:mi mathvariant="normal">R</mml:mi><mml:mi mathvariant="normal">S</mml:mi><mml:mi mathvariant="normal">j</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi mathvariant="normal">C</mml:mi><mml:mi mathvariant="normal">M</mml:mi><mml:mi mathvariant="normal">D</mml:mi><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">M</mml:mi><mml:mi mathvariant="normal">U</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi mathvariant="normal">G</mml:mi><mml:mi mathvariant="normal">S</mml:mi><mml:mi mathvariant="normal">R</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi mathvariant="normal">C</mml:mi><mml:mi mathvariant="normal">M</mml:mi><mml:mi mathvariant="normal">D</mml:mi><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mo>&#x2265;</mml:mo><mml:mi>&#x03B5;</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mo>&#x2212;</mml:mo><mml:mi mathvariant="normal">P</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi mathvariant="normal">E</mml:mi><mml:mrow><mml:mi mathvariant="normal">M</mml:mi><mml:mi mathvariant="normal">U</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi mathvariant="normal">G</mml:mi><mml:mi mathvariant="normal">S</mml:mi><mml:mi mathvariant="normal">R</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi mathvariant="normal">C</mml:mi><mml:mi mathvariant="normal">M</mml:mi><mml:mi mathvariant="normal">D</mml:mi><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">]</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>
</p>
<p>In relation to Pr[E<sub>CMDi</sub>E<sub>MUi-GRSj-CMDi</sub>] &#x003D; Pr[E<sub>CMDi</sub>]</p>
<p>We have Pr[E<sub>SKi</sub><inline-formula id="ieqn-73"><mml:math id="mml-ieqn-73"><mml:mo>&#x2227;</mml:mo></mml:math></inline-formula> E<sub>CMDi</sub>] <inline-formula id="ieqn-74"><mml:math id="mml-ieqn-74"><mml:mo>&#x2265;</mml:mo><mml:mfrac><mml:mi>&#x03F5;</mml:mi><mml:mn>4</mml:mn></mml:mfrac><mml:mo>&#x2212;</mml:mo><mml:mfrac><mml:mrow><mml:mrow><mml:mtext>Pr</mml:mtext></mml:mrow><mml:mo stretchy="false">[</mml:mo><mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mtext>E</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>MUi</mml:mtext></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mtext>GRSj</mml:mtext></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mtext>CMDi</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:mrow></mml:mrow><mml:mo stretchy="false">]</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:mfrac></mml:math></inline-formula></p>
<p>The events E<sub>SKi</sub><inline-formula id="ieqn-75"><mml:math id="mml-ieqn-75"><mml:mo>&#x2227;</mml:mo></mml:math></inline-formula> E<sub>CMDi</sub> depicts that the adversary forges MU<sub>i</sub> and receives the valid session key with success. In accordance with the Lemma 1, E<sub>MUi-GRSj-CMDi</sub> has quite insignificant probability, hence the probability <inline-formula id="ieqn-76"><mml:math id="mml-ieqn-76"><mml:mfrac><mml:mi>&#x03F5;</mml:mi><mml:mn>4</mml:mn></mml:mfrac></mml:math></inline-formula> &#x02212; <inline-formula id="ieqn-77"><mml:math id="mml-ieqn-77"><mml:mfrac><mml:mrow><mml:mrow><mml:mtext>Pr</mml:mtext></mml:mrow><mml:mo stretchy="false">[</mml:mo><mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mtext>E</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>MUi</mml:mtext></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mtext>GRSj</mml:mtext></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mtext>CMDi</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:mrow></mml:mrow><mml:mo stretchy="false">]</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:mfrac></mml:math></inline-formula> is not negligible as shown in <xref ref-type="disp-formula" rid="eqn-4">Eqs. (4)</xref> and <xref ref-type="disp-formula" rid="eqn-5">(5)</xref>. This suggests that the probability the adversary may compromise the legitimate session key is not negligible which contradicts the hardness assumption for guessing 160-bit random integer.</p>
</sec>
<sec id="s5_3"><label>5.3</label><title>Informal Security Analysis</title>
<sec id="s5_3_1"><label>5.3.1</label><title>Mutual Authentication</title>
<p>The proposed scheme provides mutual authenticity to both participants by devising a unique and mutual agreed session key between them. We know that the benefit that adversary may take by launching the login as well as an authentication request and response message is quite negligible due to illustrated lemma1 in above section [<xref ref-type="bibr" rid="ref-24">24</xref>]. Hence, the MU<sub>i</sub> and CMD<sub>i</sub> could mutually authenticate one another with the assistance of GRS<sub>j</sub>. Hence, the proposed approach supports mutual authentication.</p>
</sec>
<sec id="s5_3_2"><label>5.3.2</label><title>Anonymity</title>
<p>In the contributed protocol the MU<sub>i</sub> does not send its identity plainly on pubic channel, rather it is masked in the form of <italic>PID<sub>u</sub> &#x003D;&#x2009;h(ID<sub>u</sub> &#x007C;&#x007C; k)</italic>. Furthermore, <italic>PID<sub>u</sub></italic> is integrated in the message <italic>R<sub>1</sub>&#x003D;h(PID<sub>G</sub> &#x007C;&#x007C;T<sub>1</sub>) &#x2295;PID<sub>u</sub></italic> during mutual authentication process. It is hard problem in polynomial terms to recover the 160-bit random integer on account of guessing the values [<xref ref-type="bibr" rid="ref-25">25</xref>], so it is not feasible to calculate the legitimate identity of mobile drone CMD<sub>i</sub> without compromising the high entropy factor <italic>k</italic>. Thus our scheme affirms anonymity to the participants in protocol.</p>
</sec>
<sec id="s5_3_3"><label>5.3.3</label><title>Un-traceability</title>
<p>We employ random integers <italic>a<sub>1</sub></italic> and <italic>a<sub>2</sub></italic> along with fresh timestamps in different sessions which enable the constructed messages (<italic>R<sub>1</sub>, R<sub>2</sub>, R<sub>3</sub>, R<sub>4</sub></italic>) in a session to be unique each time these are generated [<xref ref-type="bibr" rid="ref-26">26</xref>,<xref ref-type="bibr" rid="ref-27">27</xref>]. The attacker may not be able to distinguish the exchanged messages among for MU<sub>i</sub> and CMD<sub>i</sub> across various sessions. Furthermore, the legal identifies such as <italic>ID<sub>u</sub></italic> or <italic>PID<sub>u</sub></italic> are used in collision-resistant one hash function which enables the protocol in affording the untraceability feature.</p>
</sec>
<sec id="s5_3_4"><label>5.3.4</label><title>Protected Session Key</title>
<p>In the proposed scheme, the MU<italic><sub>i</sub></italic> confirms the authenticity of CMD<sub>i</sub> through validating <italic>R<sub>10</sub></italic>, which ensures that both of these entities are having the legitimate randomly generated factors, <italic>a<sub>1</sub></italic> and <italic>a<sub>2</sub></italic>. In this manner both entities construct a secure session key <italic>SK &#x003D; SK<sub>ud</sub> &#x003D; SK<sub>du</sub> &#x003D; h(PID<sub>u</sub> &#x007C;&#x007C; PID<sub>d</sub> &#x007C;&#x007C; PID<sub>G</sub>&#x007C;&#x007C; R<sub>9</sub>)</italic> to interact in the future. Hence our scheme supports secure key agreement between the members.</p>
</sec>
<sec id="s5_3_5"><label>5.3.5</label><title>Impersonation Threat</title>
<p>In case the adversary is able to capture the legal drone physically, it may access all of the stored information in its memory including pseudonym identities for CMD<sub>i</sub> [<xref ref-type="bibr" rid="ref-28">28</xref>,<xref ref-type="bibr" rid="ref-29">29</xref>]. Then if the adversary attempts to forge the legal MU<sub>i</sub>, it would construct the legal messages (<italic>R<sub>1</sub>, R<sub>4</sub></italic>) and submit towards GRS<sub>j</sub>. Now the adversary may compute the correct <italic>R<sub>1</sub>&#x2009;&#x003D;&#x2009;h(PID<sub>G</sub> &#x007C;&#x007C;T<sub>1</sub>) &#x2295;PID<sub>u</sub></italic> and <italic>R<sub>4</sub>&#x2009;&#x003D; h(PID<sub>u</sub> &#x007C;&#x007C; PID<sub>d</sub> &#x007C;&#x007C; PID<sub>G</sub> &#x007C;&#x007C; h(B<sub>i</sub> &#x007C;&#x007C; a<sub>1</sub>&#x007C;&#x007C; T<sub>1</sub>))</italic>, while <italic>a<sub>1</sub></italic> and <italic>B<sub>i</sub></italic> depict the random integers as chosen by the adversary for random number and the protected key, respectively. After the receipt of (<italic>R<sub>1</sub>, R<sub>4</sub></italic>), the GRS<sub>j</sub> initially would parse from <italic>R<sub>1</sub></italic> and recover the related secret as <italic>B<sub>i</sub></italic> in the list LHs. Thereafter, the GRS<sub>j</sub> calculates the parameter <italic>R<sub>4</sub>&#x2019;</italic> along with another factor <italic>B<sub>i</sub></italic> and verifies the equation validity as <italic>R<sub>1</sub>&#x2019; &#x003D; R<sub>1</sub></italic>. Therefore, the attacker does not expose the valid parameter <italic>B<sub>i</sub></italic>, and make the GRS<sub>j</sub> distinguish the MU<sub>u</sub> from legal user.</p>
</sec>
<sec id="s5_3_6"><label>5.3.6</label><title>Server Masquerading Attack</title>
<p>The attacker may impersonate himself as GRS<sub>j</sub> and submits the message <italic>R<sub>7</sub></italic> towards the CMD<sub>i</sub>. Then the attacker calculates <italic>R<sub>7</sub>&#x2009;&#x003D;&#x2009;h(PID<sub>u</sub>&#x02032;&#x007C;&#x007C; PID<sub>d</sub>&#x02032;&#x007C;&#x007C; PID<sub>G</sub> &#x007C;&#x007C; B<sub>j</sub>&#x2032; &#x007C;&#x007C; a<sub>1</sub>&#x2032;)</italic>, where <italic>B<sub>j</sub></italic> acts as a random integer chosen as CMD<sub>i</sub>&#x0027;s private key by the adversary. After the receipt of <italic>R<sub>7</sub></italic>, the CMD<sub>i</sub> constructs <italic>R<sub>4</sub>&#x2019;</italic> along with <italic>B<sub>j</sub></italic> and also checks the equality for <italic>R<sub>7</sub>&#x2019; ?&#x2009;&#x003D; R<sub>7</sub></italic>. Nonetheless, the adversary may not access the <italic>B<sub>j</sub></italic> parameter or the CMD<sub>i</sub> accesses the malicious server. Thus, our scheme is resistant to the spoofing attack.</p>
</sec>
<sec id="s5_3_7"><label>5.3.7</label><title>CMD<sub>i</sub> Capture Threat</title>
<p>The drones are vulnerable in the hands of adversaries, and could be physically compromised at any time. We assume that the adversary captures <italic>e</italic> number of drones and access the stored contents including <italic>B<sub>j</sub>&#x2009;&#x003D; h(ID<sub>d</sub> &#x007C;&#x007C; K<sub>G</sub>)</italic>, <italic>PID<sub>d</sub> &#x2009;&#x003D;&#x2009;h(ID<sub>d</sub> &#x007C;&#x007C; k)</italic>, and <italic>SK<sub>ud</sub> &#x003D; h(PID<sub>u</sub>&#x007C;&#x007C; PID<sub>d</sub> &#x007C;&#x007C; PID<sub>G</sub>&#x007C;&#x007C; R<sub>9</sub>&#x2032;)</italic> where <italic>j&#x2009;&#x003D;&#x2009;(1</italic><inline-formula id="ieqn-78"><mml:math id="mml-ieqn-78"><mml:mo>&#x2264;</mml:mo></mml:math></inline-formula> <italic>j</italic> <inline-formula id="ieqn-79"><mml:math id="mml-ieqn-79"><mml:mo>&#x2264;</mml:mo></mml:math></inline-formula> <italic>e)</italic> [<xref ref-type="bibr" rid="ref-30">30</xref>]. The master secret <italic>K<sub>G</sub></italic> and other masking key k are also used to mask the crucial factors in collision resistant hash function. Despite the access of information in the compromised several drones e, the adversary might not be able to access the <italic>K<sub>G</sub></italic> and <italic>k</italic>. At the same time, the session key <italic>SK<sub>ud</sub> &#x003D; h(PID<sub>u</sub>&#x007C;&#x007C; PID<sub>d</sub> &#x007C;&#x007C; PID<sub>G</sub>&#x007C;&#x007C; R<sub>9</sub>&#x2032;)</italic> is composed of random integers and pseudonyms, the attacker may not calculate the subsequent session keys if it is not able to access the random integers. Consequently, our proposed model is immune to all physical drone capture threats.</p>
</sec>
<sec id="s5_3_8"><label>5.3.8</label><title>Stolen MU<sub>i</sub>&#x0027;s Smart Device Threat</title>
<p>In case the adversary is able to approach the MU<sub>i</sub>&#x0027;s smart device and recover its contents (<italic>B<sub>i</sub>&#x2032;, PID<sub>u</sub>&#x2032;, PID<sub>d</sub></italic>) using differential analysis, where <italic>B<sub>i</sub>&#x2032;&#x2009;&#x003D; h(ID<sub>u</sub> &#x007C;&#x007C; PW<sub>u</sub>) &#x2295; B<sub>i</sub></italic> and <italic>PID<sub>u</sub>&#x2032;&#x2009;&#x003D;&#x2009;h(ID<sub>u</sub> &#x007C;&#x007C; PW<sub>u</sub>) &#x2295;PID<sub>u</sub></italic>. The attacker may guess the password from <italic>B<sub>i</sub>&#x2032;</italic> only if it can test its accuracy, however without the MU<sub>i</sub>&#x0027;s identity it cannot verify it. Thus, our scheme is resistant to the stolen device threat.</p>
</sec>
<sec id="s5_3_9"><label>5.3.9</label><title>Replay Attack</title>
<p>The participants MU<sub>i</sub> and GRS<sub>j</sub> select random numbers and compute the login request message and response message as <italic>R<sub>4</sub></italic> and <italic>R<sub>10</sub></italic>, respectively. Since the random nonces are fresh, the participants GRS<sub>j</sub>, CMD<sub>i</sub> and MU<sub>i</sub> might discern the legitimate requests from the replayed messages through verification checks. Hence, our scheme is immune to this replay attack threat.</p>
</sec>
<sec id="s5_3_10"><label>5.3.10</label><title>Known Session Key Attack</title>
<p>If an attacker becomes familiar about the current session key of any session in our scheme, it may not compute the previous session keys employing the current session key [<xref ref-type="bibr" rid="ref-31">31</xref>]. This is because the attacker needs to approach crucial pseudonym parameters besides the random nonces to construct the legal session key, however these parameters are protected under collision resistant one way hash function and cannot be compromised in polynomial amount of time.</p>
</sec>
</sec>
</sec>
<sec id="s6"><label>6</label><title>Performance Evaluations</title>
<p>This section evaluates the performance of contributed protocol against the comparative studies including Wazid et al., Singh et al., Challa et al., and Turkanovic et al. on the basis of computational and communicational costs. The execution latency for the crypto-primitives employed by the comparative schemes [<xref ref-type="bibr" rid="ref-17">17</xref>,<xref ref-type="bibr" rid="ref-18">18</xref>,<xref ref-type="bibr" rid="ref-20">20</xref>,<xref ref-type="bibr" rid="ref-22">22</xref>] is depicted as <italic>T<sub>fe</sub></italic> to execute fuzzy extractor operation, <italic>T<sub>h</sub></italic> to execute one-way hash operation, <italic>T<sub>ex</sub></italic> to execute modular exponentiation operation, <italic>T<sub>m</sub></italic> to execute modular multiplication operation, <italic>T<sub>ecm</sub></italic> to execute (Elliptic Curve Cryptography) ECC-based point multiplication [<xref ref-type="bibr" rid="ref-31">31</xref>]. These crypto-primitive operations have been implemented for mobile user device as client and desktop computer as server. The mobile drones or user devices are equipped with biochemical detectors, infrared, microphone and camera-based sensors. We calculate the cost of computations with the help of MIRACL library [<xref ref-type="bibr" rid="ref-23">23</xref>] and Android-enabled MU<sub>i</sub>/CMD<sub>i</sub> client (Lenovo Zuk Z1 having 2.5Ghz Quad-core microprocessor, Android V5.1.2 OS, and 4GB RAM). To simulate the GRS<sub>j</sub> environment we used desktop computer (HP E8300 Core i5 2.96Ghz, Ubuntu 16.12 OS and 8GB RAM). The experiments were conducted on the discussed client and server hardware platform that provides varying execution costs for various primitives. We select a multiplicative cyclic group G with order <italic>n</italic> having 160-bit prime integer.</p>
<p>This group G helps to achieve the 1024-bit RSA level of security. Using the above simulation, the execution timing of various crypto-primitives such as <italic>T<sub>fe</sub></italic> &#x2248; <italic>T<sub>ecm</sub></italic>, <italic>T<sub>h</sub></italic>, <italic>T<sub>ex</sub></italic>, <italic>T<sub>m</sub></italic> and <italic>T<sub>ecm</sub></italic> is computed as 16.403, 0.078, 3.943, 0.012 and 0.012&#x2005;ms for MU<sub>i</sub>/CMD<sub>i</sub>, and 6.276, 0.013, 0.438, 0.003 and 0.003&#x2005;ms, respectively. In [<xref ref-type="bibr" rid="ref-17">17</xref>], the mobile user takes 1<italic>T<sub>fe</sub>&#x2009;</italic>&#x002B;<italic>&#x2009;</italic>16<italic>T<sub>h</sub></italic> computational cost with 17.6&#x2005;ms of execution latency. The CMD<sub>i</sub> takes seven <italic>T<sub>h</sub></italic> operations and GRS<sub>j</sub> incurs eight <italic>T<sub>h</sub></italic> operations with computational cost 0.54&#x2005;ms and 0.104&#x2005;ms respectively. In [<xref ref-type="bibr" rid="ref-22">22</xref>], the GRS<sub>j</sub> does not participate in the mutual authentication process. Therefore, in this phase the MU<sub>i</sub> and CMD<sub>i</sub> require 2<italic>T<sub>ex</sub>&#x2009;</italic>&#x002B;<italic>&#x2009;</italic>5<italic>T<sub>m</sub></italic> and 2<italic>T<sub>ex</sub>&#x2009;</italic>&#x002B;<italic>&#x2009;</italic>7<italic>T<sub>m</sub></italic>, i.e., 7.946&#x2005;ms and 7.97&#x2005;ms of computational cost, respectively. In [<xref ref-type="bibr" rid="ref-20">20</xref>], the MU<sub>i</sub> and CMD<sub>i</sub> entities bear 98.8&#x2005;ms and 65.8&#x2005;ms computational cost with given primitives 1<italic>T<sub>fe</sub>&#x2009;</italic>&#x002B;<italic>&#x2009;</italic>5<italic>T<sub>ecm</sub>&#x2009;</italic>&#x002B;<italic>&#x2009;</italic>5<italic>T<sub>h</sub></italic> and 3<italic>T<sub>h</sub>&#x2009;</italic>&#x002B;<italic>&#x2009;</italic>4<italic>T<sub>ecm</sub></italic> respectively. On the server&#x0027;s end, it bears 31.43&#x2005;ms of computational latency with 4<italic>T<sub>h</sub>&#x2009;</italic>&#x002B;<italic>&#x2009;</italic>5<italic>T<sub>ecm</sub></italic> computations [<xref ref-type="bibr" rid="ref-18">18</xref>] bears 0.54&#x2005;ms latency for both MU<sub>i</sub> and CMD<sub>i</sub> with 7 hash operations (7<italic>T<sub>h</sub></italic>) each, while on the GRS<sub>j</sub>&#x0027;s end it incurs 19 hash operations with 1.482&#x2005;ms computational latency. The proposed scheme employs 10<italic>T<sub>h</sub></italic>, 7<italic>T<sub>h</sub></italic>, 7<italic>T<sub>h</sub></italic> operations with 0.78&#x2005;ms, 0.54&#x2005;ms, and 0.54&#x2005;ms of computational costs for MU<sub>i</sub>, CMD<sub>i</sub> and GRS<sub>j</sub>, respectively. <?A3B2 "tbl2",5,"anchor"?><xref ref-type="table" rid="table-2">Tab. 2</xref> describes the computational costs of [<xref ref-type="bibr" rid="ref-17">17</xref>,<xref ref-type="bibr" rid="ref-18">18</xref>,<xref ref-type="bibr" rid="ref-20">20</xref>,<xref ref-type="bibr" rid="ref-22">22</xref>] that are compared with the proposed schemes. For being lightweight symmetric crypto-operation, the hash function <italic>h(.)</italic> with <italic>T<sub>h</sub></italic> is suitable for crowd sensing drone-based ecosystem to save the energy of mobile devices and ultimately improve their uptime.</p>
<p>In order to compare communication costs, we assume that &#x007C;G&#x007C; characterize 1024-bit element size, while &#x007C;<italic>Z<sub>n</sub></italic>&#x007C; represents the 160-bit of each element in <italic>Z<sub>n</sub></italic>. Similarly, the &#x007C;ID&#x007C; depict the 32-bit size of timestamp as well as MUi&#x0027;s identity. We make the functionality comparison of our scheme against Wazid, Singh, Challa and Turkanovic et al. schemes in <?A3B2 "tbl4",5,"anchor"?><xref ref-type="table" rid="table-4">Tab. 4</xref>. The incurred communication cost of protocols [<xref ref-type="bibr" rid="ref-17">17</xref>,<xref ref-type="bibr" rid="ref-18">18</xref>,<xref ref-type="bibr" rid="ref-20">20</xref>,<xref ref-type="bibr" rid="ref-22">22</xref>] is compared against the proposed scheme as shown in <?A3B2 "tbl3",5,"anchor"?><xref ref-type="table" rid="table-3">Tab. 3</xref>. The Wazid et al. [<xref ref-type="bibr" rid="ref-17">17</xref>] bears the communication cost of 1696-bits which is calculated as 10&#x007C;<italic>Z<sub>n</sub></italic>&#x007C; &#x002B; 3&#x007C;ID&#x007C; having 10 <italic>Z<sub>n</sub></italic> operations and 3 ID operations. Similarly, the [<xref ref-type="bibr" rid="ref-22">22</xref>,<xref ref-type="bibr" rid="ref-20">20</xref>,<xref ref-type="bibr" rid="ref-18">18</xref>] bear 4256-bits, 2528-bits, 2720-bits against 4&#x007C;G&#x007C; &#x002B; 4&#x007C;ID&#x007C;, 10&#x007C;<italic>Z<sub>n</sub></italic>&#x007C; &#x002B; 3&#x007C;ID&#x007C; and 10&#x007C;<italic>Z<sub>n</sub></italic>&#x007C; &#x002B; 3&#x007C;ID&#x007C; crypto-operations, respectively. In comparison with other schemes, the proposed scheme has remarkably less communication cost of 1472-bits against 9&#x007C;<italic>Z<sub>n</sub></italic>&#x007C; &#x002B; &#x007C;ID&#x007C; operations.</p>
<table-wrap id="table-2"><label>Table 2</label><caption><title>Computational cost</title></caption>

<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left" charoff="8"/>
<col align="left" charoff="8"/>
<col align="left" charoff="8"/>
<col align="left" charoff="8"/>
</colgroup>
<thead>
<tr>
<th align="left"/>
<th align="left">User&#x0027;s end</th>
<th align="left">&#x00A0;Mobile drone</th>
<th align="left">Server&#x0027;s end</th>
<th align="left">Total</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">[<xref ref-type="bibr" rid="ref-17">17</xref>]</td>
<td align="left">1<italic>T<sub>fe</sub>&#x2009;&#x002B;&#x2009;</italic>16<italic>T<sub>h</sub>&#x2009;&#x2248; 17.651&#x2005;</italic>ms</td>
<td align="left">7<italic>T<sub>h</sub>&#x2009;&#x2248; 0.54&#x2005;</italic>ms</td>
<td align="left">8<italic>T<sub>h</sub>&#x2009;&#x2248; 0.104&#x2005;</italic>ms</td>
<td align="left">31<italic>T<sub>h</sub>&#x2009;&#x002B;&#x2009;</italic>1<italic>T<sub>fe</sub>&#x2009;&#x2248; 18.295&#x2005;</italic>ms</td>
</tr>
<tr>
<td align="left">[<xref ref-type="bibr" rid="ref-22">22</xref>]</td>
<td align="left">2<italic>T<sub>ex</sub>&#x2009;&#x002B;&#x2009;</italic>5<italic>T<sub>m</sub> &#x2248; 7.946&#x2005;</italic>ms</td>
<td align="left">2<italic>T<sub>ex</sub>&#x2009;&#x002B;&#x2009;</italic>7<italic>T<sub>m</sub> &#x2248; 7.97&#x2005;</italic>ms</td>
<td align="left">-</td>
<td align="left">12<italic>T<sub>m</sub>&#x2009;&#x002B;&#x2009;</italic>4<italic>T<sub>ex</sub>&#x2009;&#x2248; 15.916&#x2005;</italic>ms</td>
</tr>
<tr>
<td align="left">[<xref ref-type="bibr" rid="ref-20">20</xref>]</td>
<td align="left">1<italic>T<sub>fe</sub>&#x2009;&#x002B;&#x2009;</italic>5<italic>T<sub>ecm</sub>&#x002B;</italic>5<italic>T<sub>h</sub>&#x2009;&#x2248; 98.8&#x2005;</italic>ms</td>
<td align="left">3<italic>T<sub>h&#x2009;</sub>&#x002B;</italic>&#x2009;4<italic>T<sub>ecm</sub>&#x2009;&#x2248; 65.8&#x2005;</italic>ms</td>
<td align="left">4<italic>T<sub>h</sub>&#x002B;</italic>5<italic>T<sub>ecm</sub>&#x2248; 31.43&#x2005;</italic>ms</td>
<td align="left">12<italic>T<sub>h</sub>&#x2009;&#x002B;&#x2009;</italic>14<italic>T<sub>ecm</sub>&#x2009;&#x002B;&#x2009;</italic>1<italic>T<sub>fe</sub>&#x2009;&#x2248; 196.03&#x2005;</italic>ms</td>
</tr>
<tr>
<td align="left">[<xref ref-type="bibr" rid="ref-18">18</xref>]</td>
<td align="left">7<italic>T<sub>h</sub>&#x2009;&#x2248; 0.54&#x2005;</italic>ms</td>
<td align="left">7<italic>T<sub>h</sub>&#x2009;&#x2248; 0.54&#x2005;</italic>ms</td>
<td align="left">5<italic>T<sub>h</sub>&#x2009;&#x2248; 0.065&#x2005;</italic>ms</td>
<td align="left">19<italic>T<sub>h</sub>&#x2009;&#x2248; 1.482&#x2005;</italic>ms</td>
</tr>
<tr>
<td align="left">Ours</td>
<td align="left">10<italic>T<sub>h</sub>&#x2009;&#x2248; 0.78&#x2005;</italic>ms</td>
<td align="left">7<italic>T<sub>h</sub>&#x2009;&#x2248;&#x2009;0.54&#x2005;</italic>ms</td>
<td align="left">7<italic>T<sub>h</sub>&#x2009;&#x2248;&#x2009;0.091&#x2005;</italic>ms</td>
<td align="left">24<italic>T<sub>h</sub>&#x2009;&#x2248; 1.872&#x2005;</italic>ms</td>
</tr>
</tbody>
</table>
</table-wrap>
<table-wrap id="table-3"><label>Table 3</label><caption><title>Communication cost</title></caption>

<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left"/>
<th align="left">Communication cost</th>
<th align="left">Length (bits)</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">[<xref ref-type="bibr" rid="ref-17">17</xref>]</td>
<td align="left">10&#x007C;<italic>Z<sub>n</sub></italic>&#x007C; &#x002B; 3&#x007C;<italic>ID</italic>&#x007C;</td>
<td align="left">1696</td>
</tr>
<tr>
<td align="left">[<xref ref-type="bibr" rid="ref-22">22</xref>]</td>
<td align="left">4&#x007C;<italic>G</italic>&#x007C; &#x002B; 4&#x007C;<italic>ID</italic>&#x007C;</td>
<td align="left">4256</td>
</tr>
<tr>
<td align="left">[<xref ref-type="bibr" rid="ref-20">20</xref>]</td>
<td align="left">10&#x007C;<italic>Z<sub>n</sub></italic>&#x007C; &#x002B; 3&#x007C;<italic>ID</italic>&#x007C;</td>
<td align="left">2528</td>
</tr>
<tr>
<td align="left">[<xref ref-type="bibr" rid="ref-18">18</xref>]</td>
<td align="left">10&#x007C;<italic>Z<sub>n</sub></italic>&#x007C; &#x002B; 3&#x007C;<italic>ID</italic>&#x007C;</td>
<td align="left">2720</td>
</tr>
<tr>
<td align="left">Ours</td>
<td align="left">9&#x007C;<italic>Z<sub>n</sub></italic>&#x007C; &#x002B; &#x007C;<italic>ID</italic>&#x007C;</td>
<td align="left">1472</td>
</tr>
</tbody>
</table>
</table-wrap>
<table-wrap id="table-4"><label>Table 4</label><caption><title>Functionality comparison</title></caption>

<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left"/>
<th align="left">[<xref ref-type="bibr" rid="ref-17">17</xref>]</th>
<th align="left">&#x00A0;[<xref ref-type="bibr" rid="ref-22">22</xref>]</th>
<th align="left">[<xref ref-type="bibr" rid="ref-20">20</xref>]</th>
<th align="left">&#x00A0;[<xref ref-type="bibr" rid="ref-18">18</xref>]</th>
<th align="left">[Ours]</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">Supports mutual authentication</td>
<td align="left">&#x00D7;</td>
<td align="left">&#x00D7;</td>
<td align="left">&#x00D7;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
</tr>
<tr>
<td align="left">Supports anonymity</td>
<td align="left">&#x2713;</td>
<td align="left">&#x00D7;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x00D7;</td>
<td align="left">&#x2713;</td>
</tr>
<tr>
<td align="left">Unlinkability</td>
<td align="left">&#x2713;</td>
<td align="left">&#x00D7;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x00D7;</td>
<td align="left">&#x2713;</td>
</tr>
<tr>
<td align="left">Supports session key agreement</td>
<td align="left">&#x00D7;</td>
<td align="left">&#x00D7;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x00D7;</td>
<td align="left">&#x2713;</td>
</tr>
<tr>
<td align="left">Resists forgery attack</td>
<td align="left">&#x2713;</td>
<td align="left">&#x00D7;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x00D7;</td>
<td align="left">&#x2713;</td>
</tr>
<tr>
<td align="left">Resists server impersonation attack</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x00D7;</td>
<td align="left">&#x2713;</td>
</tr>
<tr>
<td align="left">Immune to CMD<sub>i</sub> physical capture threat</td>
<td align="left">&#x2713;</td>
<td align="left">&#x00D7;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
</tr>
<tr>
<td align="left">Immune to stolen device threat</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x00D7;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
</tr>
<tr>
<td align="left">Resists replay attack</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
</tr>
<tr>
<td align="left">Resists man in the middle threat</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
</tr>
<tr>
<td align="left">Resists offline password guessing attack</td>
<td align="left">&#x2713;</td>
<td align="left">&#x00D7;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x00D7;</td>
<td align="left">&#x2713;</td>
</tr>
<tr>
<td align="left">Resists denial of service threat</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
</tr>
<tr>
<td align="left">Supports formal analysis using ROM</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
<td align="left">&#x2713;</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>We now discuss the simulation details of the proposed model based on NS2 and the simulation details of the comparison schemes in [<xref ref-type="bibr" rid="ref-17">17</xref>,<xref ref-type="bibr" rid="ref-18">18</xref>,<xref ref-type="bibr" rid="ref-20">20</xref>,<xref ref-type="bibr" rid="ref-22">22</xref>]. We performed the simulation by using Ubuntu 14.04 long-term support (LTS platform) on the NS2 2.35 simulator [<xref ref-type="bibr" rid="ref-27">27</xref>]. We discussed the simulation parameters in <?A3B2 "tbl5",5,"anchor"?><xref ref-type="table" rid="table-5">Tab. 5</xref>. The total time taken by simulation is set as 2400&#x2005;s (40&#x2005;min). The entities CMDi, MUi, and Sj symbolize for i<sup>th</sup> drone, i<sup>th</sup> mobile user device, and j<sup>th</sup> IoT sensor in the compared schemes. We consider the various mobility parameters as 20, 30 and 40 mps for CMDi, MUi and Sj. We also assume a fixed server gateway across all of these schemes. The communication messages as exchanged among these participants are shown in <xref ref-type="table" rid="table-3">Tab. 3</xref>. In the simulated experiment, three network performance-based benchmarks are evaluated, i.e., packet loss rate (number of packets), EED (sec) and throughput (bps). We now discuss the impact on these factors in the experiment in the following.</p>
<table-wrap id="table-5"><label>Table 5</label><caption><title>Simulation parameters</title></caption>

<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left">Parameter</th>
<th align="left">Semantics</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">Operating system</td>
<td align="left">Ubuntu 14.04</td>
</tr>
<tr>
<td align="left">Simulation tool</td>
<td align="left">NS2 2.35</td>
</tr>
<tr>
<td align="left">Domain(m)</td>
<td align="left">450&#x2005;m<italic>&#x2009;</italic><inline-formula id="ieqn-82"><mml:math id="mml-ieqn-82"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula><italic>&#x2009;</italic>150&#x2005;m<italic>&#x2009;</italic><inline-formula id="ieqn-83"><mml:math id="mml-ieqn-83"><mml:mo>&#x00D7;</mml:mo><mml:mspace width="thinmathspace" /><mml:mn>20</mml:mn><mml:mrow><mml:mtext>&#xA0;m</mml:mtext></mml:mrow></mml:math></inline-formula></td>
</tr>
<tr>
<td align="left">Number of servers</td>
<td align="left">1</td>
</tr>
<tr>
<td align="left">Number of mobile users (MU<sub>i</sub>)</td>
<td align="left">3</td>
</tr>
<tr>
<td align="left">Number of CMD<sub>i</sub>/sensors</td>
<td align="left">50</td>
</tr>
<tr>
<td align="left">Mobility for MU<sub>i</sub>/CMD<sub>i</sub></td>
<td align="left">3&#x2005;mps&#x2013;20&#x2005;mps/25&#x2005;mps&#x2013;35&#x2005;mps</td>
</tr>
<tr>
<td align="left">Communication range (CMD<sub>i</sub>)</td>
<td align="left">250&#x2005;m</td>
</tr>
<tr>
<td align="left">Total time for simulation</td>
<td align="left">2400 sec</td>
</tr>
</tbody>
</table>
</table-wrap>
<sec id="s6_1"><label>6.1</label><title>Throughput</title>
<p>We calculate the throughput based on the number of bits transmitted per unit of time i.e., (<italic>r<sub>p</sub>&#x2009;</italic><inline-formula id="ieqn-80"><mml:math id="mml-ieqn-80"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula> <italic>&#x007C;p<sub>s</sub>&#x007C;)/T<sub>s</sub></italic>, where <italic>T<sub>s</sub></italic> represents the total amount of time in seconds, &#x007C;<italic>p<sub>s</sub></italic>&#x007C; shows the size of the packet, and r<italic><sub>p</sub></italic> represents the received The total number of packets. The total simulation time is 2400 s. <?A3B2 "fig3",5,"anchor"?><xref ref-type="fig" rid="fig-3">Fig. 3</xref> shows that the throughput of contribution models [<xref ref-type="bibr" rid="ref-17">17</xref>,<xref ref-type="bibr" rid="ref-22">22</xref>,<xref ref-type="bibr" rid="ref-20">20</xref>,<xref ref-type="bibr" rid="ref-18">18</xref>] are 297.21, 225.34, 216.53, 284.76 and 267.12 bps, respectively. Obviously, the throughput of our model is higher than other protocols. This ensures that the proposed solution generates less communication cost for the small-sized communication messages exchanged during the protocol.</p>
<fig id="fig-3"><label>Figure 3</label><caption><title>Throughput</title></caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_20774-fig-3.png"/></fig>
</sec>
<sec id="s6_2"><label>6.2</label><title>End-to-End Delay (EED)</title>
<p>The EED shows the average time of packets to get to the sink or destination. This factor may be represented in numeric terms as <inline-formula id="ieqn-81"><mml:math id="mml-ieqn-81"><mml:munderover><mml:mrow><mml:mo movablelimits="false">&#x2211;</mml:mo></mml:mrow><mml:mrow><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>p</mml:mi><mml:mi>k</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mrow></mml:munderover><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mrow><mml:msub><mml:mi>T</mml:mi><mml:mi>r</mml:mi></mml:msub></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:msub><mml:mi>T</mml:mi><mml:mi>s</mml:mi></mml:msub></mml:mrow></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>p</mml:mi><mml:mi>k</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula>, where <italic>T<sub>r</sub></italic> and <italic>T<sub>s</sub></italic> show the receiving and forwarding time of the exchanged packet, and <italic>n<sub>pkt</sub></italic> shows the number of packets to the destination. According to the <?A3B2 "fig4",5,"anchor"?><xref ref-type="fig" rid="fig-4">Fig. 4</xref>, the EED values for [<xref ref-type="bibr" rid="ref-17">17</xref>,<xref ref-type="bibr" rid="ref-22">22</xref>,<xref ref-type="bibr" rid="ref-20">20</xref>,<xref ref-type="bibr" rid="ref-18">18</xref>] and proposed scheme are 0.041, 0.105, 0.29152, 0.04621, 0.033 sec, respectively. It is obvious that the EED factor of the contributed model is considerably less than the compared schemes and this attributes to the small size of the authentication messages.</p>
<fig id="fig-4"><label>Figure 4</label><caption><title>End-to-end delay</title></caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_20774-fig-4.png"/></fig>
</sec>
<sec id="s6_3"><label>6.3</label><title>Packet Loss Rate (PLR)</title>
<p>The PLR factor describes the number of lost data packets per unit time and can be expressed as (<italic>n<sub>ip</sub>/T<sub>d</sub></italic>), where <italic>T<sub>d</sub></italic> represents the total time in seconds, and <italic>n<sub>ip</sub></italic> represents the number of lost data packets. This factor must be as small as possible to make network-based communication more reliable. <?A3B2 "fig5",5,"anchor"?><xref ref-type="fig" rid="fig-5">Fig. 5</xref> shows the packet loss rate of different scenarios considering the comparison scheme and the contribution model. Obviously, the contribution model has a lower PLR compared with other schemes.</p>
<fig id="fig-5"><label>Figure 5</label><caption><title>Packet loss ratio</title></caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_20774-fig-5.png"/></fig>
</sec>
</sec>
<sec id="s7"><label>7</label><title>Conclusions</title>
<p>The security and privacy requirements for reliable distribution of aerial monitoring and surveillance-based services have received increasing attention due to the vulnerability of the drone terrain. If the underlying authentication key agreement between the participating entities is not secure, the attacker may launch various attacks to disrupt the communication. In order to solve the security and privacy issues in such networks, we demonstrated a new identity verification protocol based on crowd monitoring drones, which enables participants to establish an agreed session key between them, and secure communication afterwards. Formal analysis under the Random Oracle Model (ROM) proved the proposed scheme. In addition, we used NS2 simulation to compare the proposed scheme with the existing scheme. Our analysis proves that the proposed scheme outperforms other schemes in terms of throughput, end-to-end delay and packet loss rate. Performance evaluation and benchmark factors show that the proposed scheme is secure compared with other contemporary studies in the same field. In the future, we can explore the prospect of using distributed systems based on blockchain to protect air surveillance.</p>
</sec>
</body>
<back>
<ack><p>The authors express their gratitude to the Deputyship for Research &#x0026; Innovation, Ministry of Education in Saudi Arabia for funding this research work through the Project Number (227).</p>
</ack>
<fn-group>
<fn fn-type="other"><p><bold>Funding Statement:</bold> This work was supported by the Deputyship for Research &#x0026; Innovation, Ministry of Education (in Saudi Arabia) through the Project Number (227).</p></fn>
<fn fn-type="conflict"><p><bold>Conflicts of Interest:</bold> The authors declare that they have no conflicts of interest to report regarding the present study.</p></fn>
</fn-group>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation  publication-type="journal"><person-group person-group-type="author"><string-name><given-names>W.</given-names> <surname>Xiao</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>B.</given-names> <surname>Alzahrani</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Alotaibi</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Barnawi</surname></string-name> <etal>et al.</etal></person-group>, &#x201C;<article-title>A blockchain-based secure crowd monitoring system using UAV swarm</article-title>,&#x201D; <source>IEEE Network</source>, vol. <volume>35</volume>, no. <issue>1</issue>, pp. <fpage>108</fpage>&#x2013;<lpage>115</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation  publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Trotta</surname></string-name>, <string-name><given-names>U.</given-names> <surname>Muncuk</surname></string-name>, <string-name><given-names>M. F.</given-names> <surname>Di and K</surname></string-name></person-group>. <person-group person-group-type="author"><string-name><given-names>R.</given-names> <surname>Chowdhury</surname></string-name></person-group>, &#x201C;<article-title>Persistent crowd tracking using unmanned aerial vehicle swarms: A novel framework for energy and mobility management</article-title>,&#x201D; <source>IEEE Vehicular Technology Magazine</source>, vol. <volume>15</volume>, no. <issue>2</issue>, pp. <fpage>96</fpage>&#x2013;<lpage>103</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation  publication-type="journal"><person-group person-group-type="author"><string-name><given-names>T.</given-names> <surname>Alladi</surname></string-name>, <string-name><given-names>V.</given-names> <surname>Chamola</surname></string-name> and <string-name><given-names>N.</given-names> <surname>Kumar</surname></string-name></person-group>, &#x201C;<article-title>PARTH: A two-stage lightweight mutual authentication protocol for UAV surveillance networks</article-title>,&#x201D; <source>Computer Communications</source>, vol. <volume>160</volume>, pp. <fpage>81</fpage>&#x2013;<lpage>90</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation  publication-type="journal"><person-group person-group-type="author"><string-name><given-names>L.</given-names> <surname>Nkenyereye</surname></string-name>, <string-name><given-names>S. R.</given-names> <surname>Islam</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Bilal</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Abdullah-Al-Wadud</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Alamri</surname></string-name> <etal>et al.</etal></person-group>, &#x201C;<article-title>Secure crowd-sensing protocol for fog-based vehicular cloud</article-title>,&#x201D; <source>Future Generation Computer Systems</source>, vol. <volume>120</volume>, pp. <fpage>61</fpage>&#x2013;<lpage>75</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation  publication-type="journal"><person-group person-group-type="author"><string-name><given-names>G.</given-names> <surname>Cardone</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Cirri</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Corradi</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Foschini</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Ianniello</surname></string-name> <etal>et al.</etal></person-group>, &#x201C;<article-title>Crowdsensing in urban areas for city-scale mass gathering management: Geofencing and activity recognition</article-title>,&#x201D; <source>IEEE Sensors Journal</source>, vol. <volume>14</volume>, no. <issue>12</issue>, pp. <fpage>4185</fpage>&#x2013;<lpage>4195</lpage>, <year>2014</year>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation  publication-type="journal"><person-group person-group-type="author"><string-name><given-names>B.</given-names> <surname>Alzahrani</surname></string-name>, <string-name><given-names>O. S.</given-names> <surname>Oubbati</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Barnawi</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Atiquzzaman</surname></string-name> and <string-name><given-names>D.</given-names> <surname>Alghazzawi</surname></string-name></person-group>, &#x201C;<article-title>UAV assistance paradigm: State-of-the-art in applications and challenges</article-title>,&#x201D; <source>Journal of Networks and Computer Applications</source>, vol. <volume>166</volume>, pp. <fpage>102706</fpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation  publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y.</given-names> <surname>Jiang</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Miao</surname></string-name>, <string-name><given-names>B.</given-names> <surname>Alzahrani</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Barnawi</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Alotaibi</surname></string-name> <etal>et al.</etal></person-group>, &#x201C;<article-title>Ultra large-scale crowd monitoring system architecture and design issues</article-title>,&#x201D; <source>IEEE Internet of Things Journal</source>, vol. <volume>8</volume>, no. <issue>13</issue>, pp. <fpage>10356</fpage>&#x2013;<lpage>10366</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation  publication-type="journal"><person-group person-group-type="author"><string-name><given-names>O. P.</given-names> <surname>Popoola</surname></string-name> and <string-name><given-names>K.</given-names> <surname>Wang</surname></string-name></person-group>, &#x201C;<article-title>Video-based abnormal human behavior recognition&#x2014;a review</article-title>,&#x201D; <source>IEEE Transactions on Systems, Man and Cybernetics</source>, vol. <volume>42</volume>, no. <issue>6</issue>, pp. <fpage>865</fpage>&#x2013;<lpage>878</lpage>, <year>2012</year>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation  publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Abdalla</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Fouque</surname></string-name> and <string-name><given-names>D.</given-names> <surname>Pointcheval</surname></string-name></person-group>, &#x201C;<article-title>Password-based authenticated key exchange in the three-party setting</article-title>,&#x201D; in <conf-name>Proc. IWPKC</conf-name>, <conf-loc>Les Diablerets, Switzerland</conf-loc>, vol. <volume>3386</volume>, pp. <fpage>65</fpage>&#x2013;<lpage>84</lpage>, <year>2005</year>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation  publication-type="journal"><person-group person-group-type="author"><string-name><given-names>C.</given-names> <surname>Lin</surname></string-name>, <string-name><given-names>D.</given-names> <surname>He</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Kumar</surname></string-name>, <string-name><given-names>K. K. R.</given-names> <surname>Choo</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Vinel</surname></string-name> <etal>et al.</etal></person-group>, &#x201C;<article-title>Security and privacy for the internet of drones: Challenges and solutions</article-title>,&#x201D; <source>IEEE Magazine</source>, vol. <volume>56</volume>, no. <issue>1</issue>, pp. <fpage>64</fpage>&#x2013;<lpage>69</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation  publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Silvagni</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Tonoli</surname></string-name>, <string-name><given-names>E.</given-names> <surname>Zenerino</surname></string-name> and <string-name><given-names>M.</given-names> <surname>Chiaberge</surname></string-name></person-group>, &#x201C;<article-title>Multipurpose UAV for search and rescue operations in mountain avalanche events</article-title>,&#x201D; <source>Geomatics, Natural Hazards and Risk</source>, vol. <volume>8</volume>, no. <issue>1</issue>, pp. <fpage>18</fpage>&#x2013;<lpage>33</lpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation  publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Blazakis</surname></string-name></person-group>, &#x201C;<article-title>Border security and unmanned aerial vehicles</article-title>,&#x201D; <source>Connections</source>, vol. <volume>5</volume>, no. <issue>2</issue>, pp. <fpage>154</fpage>&#x2013;<lpage>159</lpage>, <year>2006</year>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation  publication-type="journal"><person-group person-group-type="author"><string-name><given-names>I.</given-names> <surname>Maza</surname></string-name>, <string-name><given-names>F.</given-names> <surname>Caballero</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Capit&#x00E1;n</surname></string-name>, <string-name><given-names>J. R.</given-names> <surname>Mart&#x00ED;nez-de Dios</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Ollero</surname></string-name></person-group>, &#x201C;<article-title>Experimental results in multi-uAV coordination for disaster management and civil security applications</article-title>,&#x201D; <source>Journal of Intelligent &#x0026; Robotic Systems</source>, vol. <volume>61</volume>, no. <issue>1</issue>, pp. <fpage>563</fpage>&#x2013;<lpage>585</lpage>, <year>2011</year>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation  publication-type="journal"><person-group person-group-type="author"><string-name><given-names>N. H.</given-names> <surname>Motlagh</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Bagaa</surname></string-name> and <string-name><given-names>T.</given-names> <surname>Taleb</surname></string-name></person-group>, &#x201C;<article-title>UAV-Based IoT platform: A crowd surveillance use case</article-title>,&#x201D; <source>IEEE Communications Magazine</source>, vol. <volume>55</volume>, no. <issue>2</issue>, pp. <fpage>128</fpage>&#x2013;<lpage>134</lpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation  publication-type="journal"><person-group person-group-type="author"><string-name><given-names>H.</given-names> <surname>Sedjelmaci</surname></string-name>, <string-name><given-names>S. M.</given-names> <surname>Senouci</surname></string-name> and <string-name><given-names>N.</given-names> <surname>Ansari</surname></string-name></person-group>, &#x201C;<article-title>A hierarchical detection and response system to enhance security against lethal cyber-attacks in UAV networks</article-title>,&#x201D; <source>IEEE Transactions on Systems, Man and Cybernetics</source>, vol. <volume>48</volume>, no. <issue>9</issue>, pp. <fpage>1594</fpage>&#x2013;<lpage>1606</lpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation  publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>B.</given-names> <surname>Semal</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Markantonakis</surname></string-name> and <string-name><given-names>R. N.</given-names> <surname>Akram</surname></string-name></person-group>, &#x201C;<article-title>A certificateless group authenticated key agreement protocol for secure communication in untrusted UAV networks</article-title>,&#x201D; in <conf-name>Proc. DASC</conf-name>, <conf-loc>London, UK</conf-loc>, pp. <fpage>1</fpage>&#x2013;<lpage>8</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation  publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Wazid</surname></string-name>, <string-name><given-names>A. K.</given-names> <surname>Das</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Kumar</surname></string-name>, <string-name><given-names>A. V.</given-names> <surname>Vasilakos</surname></string-name> and <string-name><given-names>J. J.</given-names> <surname>Rodrigues</surname></string-name></person-group>, &#x201C;<article-title>Design and analysis of secure lightweight remote user authentication and key agreement scheme in internet of drones deployment</article-title>,&#x201D; <source>IEEE Internet of Things Journal</source>, vol. <volume>6</volume>, no. <issue>2</issue>, pp. <fpage>3572</fpage>&#x2013;<lpage>3584</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation  publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Turkanovic</surname></string-name>, <string-name><given-names>B.</given-names> <surname>Brumen</surname></string-name> and <string-name><given-names>M.</given-names> <surname>H&#x00F6;lbl</surname></string-name></person-group>, &#x201C;<article-title>A novel user authentication and key agreement scheme for heterogeneous ad hoc wireless sensor networks, based on the internet of things notion</article-title>,&#x201D; <source>Ad Hoc Networks</source>, vol. <volume>20</volume>, pp. <fpage>96</fpage>&#x2013;<lpage>112</lpage>, <year>2014</year>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation  publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M. S.</given-names> <surname>Farash</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Turkanovic</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Kumari</surname></string-name> and <string-name><given-names>M.</given-names> <surname>H&#x00F6;lbl</surname></string-name></person-group>, &#x201C;<article-title>An efficient user authentication and key agreement scheme for heterogeneous wireless sensor network tailored for the internet of things environment</article-title>,&#x201D; <source>Ad Hoc Networks</source>, vol. <volume>36</volume>, pp. <fpage>152</fpage>&#x2013;<lpage>176</lpage>, <year>2016</year>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation  publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Challa</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Wazid</surname></string-name>, <string-name><given-names>A. K.</given-names> <surname>Das</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Kumar</surname></string-name>, <string-name><given-names>A. G.</given-names> <surname>Reddy</surname></string-name> <etal>et al.</etal></person-group>, &#x201C;<article-title>Secure signature-based authenticated key establishment scheme for future IoT applications</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>5</volume>, pp. <fpage>3028</fpage>&#x2013;<lpage>3043</lpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation  publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S. T.</given-names> <surname>Messerges</surname></string-name>, <string-name><given-names>E. A.</given-names> <surname>Dabbish</surname></string-name> and <string-name><given-names>R. H.</given-names> <surname>Sloan</surname></string-name></person-group>, &#x201C;<article-title>Examining smart-card security under the threat of power analysis attacks</article-title>,&#x201D; <source>IEEE Transactions on Computers</source>, vol. <volume>51</volume>, no. <issue>5</issue>, pp. <fpage>541</fpage>&#x2013;<lpage>552</lpage>, <year>2002</year>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation  publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Singh</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Gimekar</surname></string-name> and <string-name><given-names>S.</given-names> <surname>Venkatesan</surname></string-name></person-group>, &#x201C;<article-title>An efficient lightweight authentication scheme for human-centered industrial internet of things</article-title>,&#x201D; <source>International Journal of Communication Systems</source>, pp. <fpage>e4189</fpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation  publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>D.</given-names> <surname>He</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Zeadally</surname></string-name>, <string-name><given-names>D.</given-names> <surname>Wang</surname></string-name> and <string-name><given-names>K. K. R.</given-names> <surname>Choo</surname></string-name></person-group>, &#x201C;<article-title>Efficient and provably secure distributed signing protocol for mobile devices in wireless networks</article-title>,&#x201D; <source>IEEE Internet of Things Journal</source>, vol. <volume>5</volume>, no. <issue>6</issue>, pp. <fpage>5271</fpage>&#x2013;<lpage>5280</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation  publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Tao</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Yuan</surname></string-name> and <string-name><given-names>W.</given-names> <surname>Wei</surname></string-name></person-group>, &#x201C;<article-title>UAV-Aided trustworthy data collection in federated-WSN-enabled IoT applications</article-title>,&#x201D; <source>Information Sciences</source>, vol. <volume>532</volume>, pp. <fpage>155</fpage>&#x2013;<lpage>169</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation  publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A. S.</given-names> <surname>Abdalla</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Powell</surname></string-name>, <string-name><given-names>V.</given-names> <surname>Marojevic</surname></string-name> and <string-name><given-names>G.</given-names> <surname>Geraci</surname></string-name></person-group>, &#x201C;<article-title>UAV-Assisted attack prevention, detection, and recovery of 5G networks</article-title>,&#x201D; <source>IEEE Wireless Communications</source>, vol. <volume>27</volume>, no. <issue>4</issue>, pp. <fpage>40</fpage>&#x2013;<lpage>47</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation  publication-type="journal"><person-group person-group-type="author"><string-name><given-names>K.</given-names> <surname>Gai</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Wu</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Zhu</surname></string-name>, <string-name><given-names>K. K. R.</given-names> <surname>Choo</surname></string-name> and <string-name><given-names>B.</given-names> <surname>Xiao</surname></string-name></person-group>, &#x201C;<article-title>Blockchain-enabled trustworthy group communications in UAV networks</article-title>,&#x201D; <source>IEEE Transactions on Intelligent Transportation Systems</source>, vol. <volume>22</volume>, no. <issue>7</issue>, pp. <fpage>4118</fpage>&#x2013;<lpage>4130</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation  publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>J. W.</given-names> <surname>Jung</surname></string-name>, <string-name><given-names>S. W.</given-names> <surname>Chang</surname></string-name> and <string-name><given-names>S. S.</given-names> <surname>Lee</surname></string-name></person-group>, &#x201C;<article-title>Appropriate module configuration for vehicular networking using NS2 simulator</article-title>,&#x201D; in <conf-name>Proc. ICTC</conf-name>, <conf-loc>Busan, Korea</conf-loc>, pp. <fpage>611</fpage>&#x2013;<lpage>612</lpage>, <year>2014</year>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation  publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>R.</given-names> <surname>Canetti</surname></string-name> and <string-name><given-names>H.</given-names> <surname>Krawczyk</surname></string-name></person-group>, &#x201C;<article-title>Analysis of key-exchange protocols and their use for building secure channels</article-title>,&#x201D; in <conf-name>Proc. EUROCRYPT &#x2018;21&#x2019;</conf-name>, <conf-loc>Innsbruck, Austria</conf-loc>, <publisher-name>Springer</publisher-name>, pp. <fpage>453</fpage>&#x2013;<lpage>74</lpage>, <year>2001</year>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation  publication-type="journal"><person-group person-group-type="author"><string-name><given-names>I. U.</given-names> <surname>Khan</surname></string-name>, <string-name><given-names>I. M.</given-names> <surname>Qureshi</surname></string-name>, <string-name><given-names>M. A.</given-names> <surname>Aziz</surname></string-name>, <string-name><given-names>T. A.</given-names> <surname>Cheema</surname></string-name> and <string-name><given-names>S. B. H.</given-names> <surname>Shah</surname></string-name></person-group>, &#x201C;<article-title>Smart IoT control-based nature inspired energy efficient routing protocol for flying ad hoc network (FANET)</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>8</volume>, pp. <fpage>56371</fpage>&#x2013;<lpage>56378</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation  publication-type="journal"><person-group person-group-type="author"><string-name><given-names>I. U.</given-names> <surname>Khan</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Alturki</surname></string-name>, <string-name><given-names>H. J.</given-names> <surname>Alyamani</surname></string-name>, <string-name><given-names>M. A.</given-names> <surname>Ikram</surname></string-name> and <string-name><given-names>M. A.</given-names> <surname>Aziz</surname></string-name></person-group>, &#x201C;<article-title>RSSI-Controlled long-range communication in secured IoT-enabled unmanned aerial vehicles</article-title>,&#x201D; <source>Mobile Information Systems</source>, vol. <volume>2021</volume>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation  publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>I. U.</given-names> <surname>Khan</surname></string-name>, <string-name><given-names>S. Z.</given-names> <surname>Zukhraf</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Abdollahi</surname></string-name>, <string-name><given-names>S. A.</given-names> <surname>Imran</surname></string-name>, <string-name><given-names>I. M.</given-names> <surname>Qureshi</surname></string-name> <etal>et al.</etal></person-group> &#x201C;<article-title>Reinforce based optimization in wireless communication technologies and routing techniques using internet of flying vehicles</article-title>,&#x201D; in <conf-name>Proc. ICFNDS</conf-name>, <conf-loc>New York, NY, USA</conf-loc>, pp. <fpage>1</fpage>&#x2013;<lpage>6</lpage>, <year>2020</year>.</mixed-citation></ref>
</ref-list>
</back>
</article>