- Research Article
- 10.1145/3748328
A Unified Approach to a Secure and Lightweight Mutual Authentication Protocol Using Pre-Characterized COTS SRAM ICs for IoT Applications
- Jul 15, 2025
- ACM Transactions on Embedded Computing Systems
- Aranya Gupta + 3 more +3
Traditional Physical Unclonable Function (PUF)-based authentication protocols are vulnerable to machine learning attacks and evolving cyber threats. Moreover, these protocols lack suitability for resource-constrained IoT devices due to the involvement of heavy cryptographic primitives, error correction modules, and significant computational overhead. This article proposes a mutual authentication protocol and session key agreement utilizing commercial-off-the-shelf (COTS) SRAM integrated circuits (ICs) to extract a secret key. We introduce a block-based lightweight fuzzy extractor to minimize the overhead associated with error correction modules on IoT devices. Our protocol relies only hash, XOR and masking functions for the identity verification for both parties and stores only one challenge-response pair (CRP) on the server, reducing memory overhead on the authentication server. In addition, we perform a rigorous informal security analysis against well-known attacks and formal security analysis using Verifpal tool considering an active attacker in the communication link. Furthermore, the performance evaluation and comparative analysis indicate that the proposed protocol significantly outperforms the state-of-the-art protocols in terms of communication, computational overhead, storage overhead, and energy consumption by up to 69%, 81%, 87.5% and 76.6% respectively. We have implemented the proposed authentication protocol on ESP32 and Raspberry Pi 3 boards to show its applicability and scalability in a real-world IoT framework.
Read more