[Resource Topic] 2023/1497: A note on ``authenticated key agreement protocols for dew-assisted IoT systems''

A note on ``authenticated key agreement protocols for dew-assisted IoT systems’’

Authors: Zhengjun Cao, Lihua Liu


We show that the key agreement scheme [J. Supercomput., 78:12093-12113, 2022] is flawed. (1) It neglects the representation of a point over an elliptic curve and the basic requirement for bit-wise XOR, which results in a trivial equality. By the equality, an adversary can recover a target device’s identity, which means the scheme fails to keep anonymity. (2) It falsely requires that the central server should share its master secret key with each dew server. (3) The specified certificate is almost nonsensical.

ePrint: https://eprint.iacr.org/2023/1497

