A Lightweight 2-factor Authentication Scheme for Smart Homes
DOI:
https://doi.org/10.31272/jeasd.2706Keywords:
Authentication, Home gateway, Scyther tool, Smart homes, Time-based one-time passwordAbstract
Smart home technology provides the ability for homeowners to remotely monitor and control home appliances by connecting them to the internet. Despite its benefits, many people around the world are reluctant to adopt smart devices into their home for security reasons. Namely, connecting smart homes to the internet opens an attack surface for hackers to gain access and possibly control the smart home. Also, most smart home devices have low computational power and therefore cannot provide complex security protocols. In that case, to achieve the goal of remote user authentication, this paper proposes a 2-factor authentication scheme that consists of local biometric authentication and remote authentication with user identity and a time-based one-time password (TOTP). The security of the scheme is validated with formal and informal security checks. The proposed system outperforms similar systems since its computation overhead is (0.02 ms) and its communication overhead is (416 bits). A possible avenue of future work may involve using this authentication scheme in wider IoT applications such as wireless sensor networks.
References
H. Touqeer, S. Zaman, R. Amin, M. Hussain, F. Al-Turjman, and M. Bilal, “Smart home security: challenges, issues and solutions at different IoT layers,” Journal of Supercomputing, vol. 77, no. 12, pp. 14053–14089, Dec. 2021, doi: https://doi.org/10.1007/s11227-021-03825-1
Y. Meng, W. Zhang, H. Zhu, and X. S. Shen, “Securing Consumer IoT in the Smart Home: Architecture, Challenges, and Countermeasures,” IEEE Wirel Commun, vol. 25, no. 6, pp. 53–59, Dec. 2018, doi: https://doi.org/10.1109/MWC.2017.1800100
R. Yu, X. Zhang, and M. Zhang, “Smart Home Security Analysis System Based on the Internet of Things,” in 2021 IEEE 2nd International Conference on Big Data, Artificial Intelligence and Internet of Things Engineering, ICBAIE 2021, Institute of Electrical and Electronics Engineers Inc., Mar. 2021, pp. 596–599. doi: https://doi.org/10.1109/ICBAIE52039.2021.9389849
J. Oh, S. Yu, J. Lee, S. Son, M. Kim, and Y. Park, “A secure and lightweight authentication protocol for IoT-based smart homes,” Sensors, vol. 21, no. 4, pp. 1–24, Feb. 2021, doi: https://doi.org/10.3390/s21041488
D. Kaur and D. Kumar, “Cryptanalysis and improvement of a two-factor user authentication scheme for smart home,” Journal of Information Security and Applications, vol. 58, May 2021, doi: https://doi.org/10.1016/j.jisa.2021.102787
M. Shuai, N. Yu, H. Wang, and L. Xiong, “Anonymous authentication scheme for smart home environment with provable security,” Comput Secur, vol. 86, pp. 132–146, Sep. 2019, doi: https://doi.org/10.1016/j.cose.2019.06.002
M. Tanveer, G. Abbas, Z. H. Abbas, M. Bilal, A. Mukherjee, and K. S. Kwak, “LAKE-6SH: Lightweight User Authenticated Key Exchange for 6LoWPAN-Based Smart Homes,” IEEE Internet Things J, vol. 9, no. 4, pp. 2578–2591, Feb. 2022, doi: https://doi.org/10.1109/JIOT.2021.3085595
K. Nimmy, S. Sankaran, K. Achuthan, and P. Calyam, “Lightweight and Privacy-Preserving Remote User Authentication for Smart Homes,” IEEE Access, vol. 10, pp. 176–190, 2022, doi: https://doi.org/10.1109/ACCESS.2021.3137175
D. Dolev and A. Yao, “On the security of public key protocols,” IEEE Trans Inf Theory, vol. 29, no. 2, pp. 198–208, 1983, doi: https://doi.org/10.1109/TIT.1983.1056650
S. Dargan and M. Kumar, “A comprehensive survey on the biometric recognition systems based on physiological and behavioral modalities,” Expert Syst Appl, vol. 143, p. 113114, 2020, doi: https://doi.org/10.1016/j.eswa.2019.113114
I. Gordin, A. Graur, and A. Potorac, “Two-factor authentication framework for private cloud,” in 2019 23rd International Conference on System Theory, Control and Computing (ICSTCC), 2019, pp. 255–259. doi: https://doi.org/10.1109/ICSTCC.2019.8885460
S. Babkin and A. Epishkina, “Authentication Protocols Based on One-Time Passwords,” in 2019 IEEE Conference of Russian Young Researchers in Electrical and Electronic Engineering (EIConRus), 2019, pp. 1794–1798. doi: https://doi.org/10.1109/EIConRus.2019.8656839
C. Sudar, S. K. Arjun, and L. R. Deepthi, “Time-based one-time password for Wi-Fi authentication and security,” in 2017 International Conference on Advances in Computing, Communications and Informatics (ICACCI), 2017, pp. 1212–1216. doi: https://doi.org/10.1109/ICACCI.2017.8126007
D. Eastlake 3rd and P. Jones, “US Secure Hash Algorithm 1 (SHA1),” RFC 3174, Sep. 2001, doi: https://doi.org/10.17487/RFC3174
Z. Al-Odat, A. Abbas, and S. U. Khan, “Randomness Analyses of the Secure Hash Algorithms, SHA-1, SHA-2 and Modified SHA,” in 2019 International Conference on Frontiers of Information Technology (FIT), 2019, pp. 316–3165. doi: https://doi.org/10.1109/FIT47737.2019.00066
A. J. Mohamed Abdul Cader, J. Banks, and V. Chandran, “Fingerprint Systems: Sensors, Image Acquisition, Interoperability and Challenges,” Sensors, vol. 23, no. 14, Jul. 2023, doi: https://doi.org/10.3390/s23146591
J. Priesnitz, C. Rathgeb, N. Buchmann, C. Busch, and M. Margraf, “An overview of touchless 2D fingerprint recognition,” Dec. 01, 2021, Springer Science and Business Media Deutschland GmbH. doi: https://doi.org/10.1186/s13640-021-00548-4
H. Seta, T. Wati, and I. C. Kusuma, “Implement Time-Based One-Time Password and Secure Hash Algorithm 1 for Security of Website Login Authentication,” in 2019 International Conference on Informatics, Multimedia, Cyber and Information System (ICIMCIS), 2019, pp. 115–120. doi: https://doi.org/10.1109/ICIMCIS48181.2019.8985196
D. M’Raihi, S. Machani, M. Pei, and J. Rydell, “TOTP: Time-Based One-Time Password Algorithm,” RFC 6238, May 2011, doi: https://doi.org/10.17487/RFC6238
C. J. F. Cremers, “The Scyther Tool: Verification, Falsification, and Analysis of Security Protocols,” Lecture Notes in Computer Science, vol. 5123, pp. 414–418, 2008, doi: https://doi.org/10.1007/978-3-540-70545-1_38
Downloads
Key Dates
Received
Revised
Accepted
Published Online First
Published
Issue
Section
License
Copyright (c) 2026 Ali T. Al-Hachami, Mohammed F. Al-Gailani (Author)

This work is licensed under a Creative Commons Attribution 4.0 International License.










