Cryptanalysis of Two-Factor Authentication in the Internet of Vehicles Network Environment

E Haodudin Nurkifli

Abstract


An Intelligent Transportation System (ITS) plays a vital role in smart city ecosystems by enabling vehicles to communicate with roadside units, cloud servers, and other vehicles through the Internet. Numerous authentication protocols have been proposed to secure communications in the Internet of Vehicles (IoV), and recent studies have focused on enhancing user privacy through two-factor authentication. However, a detailed cryptanalysis conducted in this study reveals that an existing authentication protocol still suffers from several security vulnerabilities. Furthermore, under a stronger attacker model, an adversary who physically captures a device may extract the stored credentials, impersonate a legitimate user, and clone the device. To address these limitations, this study first presents a cryptanalysis of the existing protocol and then proposes a new authentication protocol. The proposed protocol integrates biometric authentication with a fuzzy extractor to derive cryptographic keys from fingerprint data, thereby preventing attackers from obtaining valid secret credentials even if a device is physically captured. Formal security analysis based on the Real-or-Random (RoR) model demonstrates that the proposed authentication protocol achieves strong anonymity, mutual authentication, resilience against desynchronization, and perfect forward and backward secrecy while resisting replay, impersonation, denial-of-service (DoS), and physical attacks. Furthermore, formal verification using the Scyther tool confirms that the proposed authentication protocol satisfies all specified security claims without identifying any potential attacks. Performance evaluation demonstrates that the proposed authentication protocol achieves the lowest execution time among the compared protocols, indicating its suitability for resource-constrained IoV devices.


Keywords


Authentication; Cryptanalysis; Protocol Security

Full Text:

Link Download

References


Aman, M. N., & Javaid, U. (2021). A Privacy-Preserving and Scalable Authentication Protocol for the Internet of Vehicles. IEEE Internet of Things Journal, 8(2), 1123–1139.

Bagheri, N., Bendavid, Y., Safkhani, M., & Rostampour, S. (2024). Smart Grid Security: A PUF-Based Authentication and Key Agreement Protocol. Future Internet, 16(1), 1–18. https://doi.org/10.3390/fi16010009

Cremers, C. (2014). Scyther User Manual. The CISPA Helmholtz Center for Information Security, 2–52.

Dodis, Y., Reyzin, L., & Smith, A. (2004). Fuzzy Extractors : How to Generate Strong Keys from Biometrics and Other Noisy Data. In Advances in Cryptology— EUROCRYPT’2004 (Lecture Notes in Computer Science). Heidelberg, German: Springer, 523–540.

Dolev, D., & Yao, A. (1983). On the Security of Public Key Protocols. IEEE TRANSACTIONS ON INFORMATION THEORY, M, 198–208.

Gerenli, O., Karabulut-kurt, G., & Ozdemir, E. (2026). A user centric group authentication scheme for secure communication. Scientific Reports, 1–19.

Ghosh, H., Maurya, P. K., Bagchi, S., & Dwivedi, A. D. (2025). Lightweight RFID-enabled authentication protocol in post-quantum environment. Computers and Electrical Engineering, 124(PB), 110367. https://doi.org/10.1016/j.compeleceng.2025.110367

Huang, W., & Chen, S. (2026). Baa-iov : Blockchain-enabled anonymous authentication for internet of vehicles. PLoS ONE, 1–34. https://doi.org/10.1371/journal.pone.0347787

Javaid, U., & Aman, M. N. (2020). A Scalable Protocol for Driving Trust Management in Internet of Vehicles With Blockchain. IEEE Internet of Things Journal, 7(12), 11815–11829.

Khan, B., Malip, A., & Khan, A. (2026). Post-quantum blind signature-based authentication for intelligent transportation systems. Computer Networks, 287(January), 112513. https://doi.org/10.1016/j.comnet.2026.112513

Kumar, N., & Chaudhary, A. (2026). Secure and Lightweight Mechanism for UAV-GCS and UAV-UAV Authentication Based on PUF. IEEE Internet of Things Journal, PP(April 2025), 1. https://doi.org/10.1109/JIOT.2026.3669029

Kumar, S., Shariq, M., & Singh, G. (2026). An ultralightweight and reliable authentication protocol for secure communication in UAV-assisted IoAV systems. Computers and Electrical Engineering, 132(October 2025), 110998. https://doi.org/10.1016/j.compeleceng.2026.110998

Lee, J. Y., Oh, J. H., Kwon, D. K., Kim, M. H., Yu, S. J., Jho, N. S., & Park, Y. (2022). PUFTAP-IoT: PUF-Based Three-Factor Authentication Protocol in IoT Environment Focused on Sensing Devices. Sensors, 22(18), 1–24. https://doi.org/10.3390/s22187075

Lin, H., & Yang, H. (2026). Blockchain-PUF based two-factor authentication and key agreement scheme in IoV. Journal of Information Security and Applications, 100(May), 104494. https://doi.org/10.1016/j.jisa.2026.104494

Ryu, J., Oh, J., Kwon, D., Son, S., Lee, J., Park, Y., & Park, Y. (2022). Secure ECC-Based Three-Factor Mutual Authentication Protocol for Telecare Medical Information System. IEEE Access, 10, 11511–11526. https://doi.org/10.1109/ACCESS.2022.3145959

Saleem, M. A., Li, X., Mahmood, K., Tariq, T., Alenazi, M. J. F., & Das, A. K. (2024). Secure RFID-Assisted Authentication Protocol for Vehicular Cloud Computing Environment. IEEE Transactions on Intelligent Transportation Systems, 25(9), 12528–12537. https://doi.org/10.1109/TITS.2024.3371464

Shariq, M., Conti, M., Singh, K., Lal, C., Das, A. K., Chaudhry, S. A., & Masud, M. (2024). Anonymous and reliable ultralightweight RFID-enabled authentication scheme for IoT systems in cloud computing. Computer Networks, 252(July), 110678. https://doi.org/10.1016/j.comnet.2024.110678

Shi, D., Nie, X., Xu, M., Cheng, H., & Alam, M. (2025). A secure and efficient lattice-based conditional privacy-preserving authentication protocol for the VANET. Vehicular Communications, 55(November 2024), 100958. https://doi.org/10.1016/j.vehcom.2025.100958

Sibahee, M. A. Al, Nyangaresi, V. O., & Abduljabbar, Z. A. (2024). Two-Factor Privacy-Preserving Protocol for Efficient Authentication in Internet of Vehicles Networks. IEEE Internet of Things Journal, 11(8), 14253–14266. https://doi.org/10.1109/JIOT.2023.3340259

Singh, G., Sharma, S., Khader, A., Saudagar, J., & Kumar, S. (2026). A secure group-based authentication protocol for IoVT in 5G-enabled smart transportation and road safety systems. Scientific Reports, 1–24.

Tiwari, V. K., & Kumar, P. (2026). Secure authentication protocol for internet of vehicles using blockchain based authorized user detection. Peer-to-Peer Networking and Applications, 5.

Wang, J., Wu, L., Wang, H., Choo, K. K. R., Wang, L., & He, D. (2022). A Secure and Efficient Multiserver Authentication and Key Agreement Protocol for Internet of Vehicles. IEEE Internet of Things Journal, 9(23), 24398–24416. https://doi.org/10.1109/JIOT.2022.3188731

Wang, X., & Xie, Y. (2025). An improved biometric authentication and key agreement scheme based on fuzzy extractor for Wireless Body Area Networks. Journal of Information Security and Applications, 91(April), 104047. https://doi.org/10.1016/j.jisa.2025.104047

Wen, Y., & Su, Y. (2025). Post-Quantum Secure Multi-Factor Authentication Protocol. Entropy, 1–20. https://doi.org/https://doi.org/10.3390/e27070765

Xue, K., Luo, X., Ma, Y., Li, J., Liu, J., & Wei, D. S. L. (2022). A Distributed Authentication Scheme Based on Smart Contract for Roaming Service in Mobile Vehicular Networks. IEEE Transactions on Vehicular Technology, 71(5), 5284–5297. https://doi.org/10.1109/TVT.2022.3148303

Yafoz, A., Alsini, R., & Almagrabi, A. O. (2026). LEAP : VANET : A lightweight and efficient authentication protocol for intelligent transportation system using VANET. ICT Express, February, 0–5. https://doi.org/10.1016/j.icte.2026.03.013

Zahednejad, B., & Gao, C. zhi. (2023). A secure and efficient AKE scheme for IoT devices using PUF and cancellable biometrics. Internet of Things (Netherlands), 24(April), 100937. https://doi.org/10.1016/j.iot.2023.100937

Zhang, H., Lai, Y., & Chen, Y. (2023). Authentication methods for internet of vehicles based on trusted connection architecture. Simulation Modelling Practice and Theory, 122(June 2022), 102681. https://doi.org/10.1016/j.simpat.2022.102681




DOI: http://dx.doi.org/10.35671/telematika.v19i2.3366

Refbacks

  • There are currently no refbacks.


 



Indexed by:

   

Telematika
ISSN: 2442-4528 (online) | ISSN: 1979-925X (print)
Published by : Universitas Amikom Purwokerto
Jl. Let. Jend. POL SUMARTO Watumas, Purwonegoro - Purwokerto, Indonesia


Creative Commons License This work is licensed under a Creative Commons Attribution 4.0 International License .